← Pilot dashboard

Robinhood Cielo prospective research pilot — version 2

The September 22 collection repair is a separate prospective cohort. The detailed revision below overrides conflicting operational dates/storage descriptions in the inherited protocol; policy thresholds remain unchanged.

Approved objective: implement buyer-support measurement, wallet holding-style features, broader discovery, post-entry monitoring, and matched policy comparisons. This pilot has no order or signing capability and does not change any frozen Arm C files or live configuration.

Fourteen days from commissioning, plus 24 hours of outcome follow-up. Read-only native databases and the existing pre-veto decision journal. Capture only new journal records after commissioning. All logged decisions, including vetoed decisions, remain in the cohort; first token/arm observations identify the independent discovery cohort. Actual funded attempts join by exact decision_capture_event_id. Never imply the pre-veto journal includes candidates rejected at earlier gates.

Native retention is explicitly a curve buy/sell inventory proxy, not actual ownership: recipient buys minus actor sells, with attribution caveats. Membership must have been published before the buy and captured locally before the decision. Immutable archived decision inputs must match their hashes and precede decision time. Missing or stale data is unknown. Current head parity is not established by this logger.

Cielo rows are indexed by contract/chain and transaction/row index; transfers remain transfers. Feed swap directions are provider-reported legs, not independently verified economic trades. Style measures observed buy-to-first-sell intervals (with unmatched buys censored), never wallet profitability. Historical rows cannot enter decisions before their first local receipt. Fresh sampled balances supplement support observations but API response time is not proof of state block/finality. No external request blocks the live bot.

Comparison: current logged policy is the baseline; native challenger overlays a fixed research exclusion when all eligible buyer proxies have sold at least half their observed curve inventory. Cielo challenger additionally excludes when at least two eligible wallets each have at least five observed first-sell intervals, every measured wallet's median interval is below 480 seconds, and there are no unmeasured eligible wallets. This is a deliberately fixed hypothesis, not a trained model. Unknown data defaults to the baseline with a separate coverage flag. Fresh balance support is reported independently until block-resolved attribution can be certified; it does not veto. Challenger decisions can only remove baseline admissions, never admit new tokens. Native input failures make both challengers unknown, not apparent passes.

Exact original stake and recorded exit outcome are reused for conditional filtered-funded-book comparisons. Show outcome completeness, net quote cashflow including recorded gas, realized drawdown and excluded winners/losses. Different quote currencies must not be summed. Rejected/unfunded candidates have no invented P&L. This is not a full executable counterfactual or training-ready economic proof. No automatic promotion.

Discovery is the selected-wallet universe, not all RH: native scorer members selected deterministically without future returns, plus qualifying wallets observed during the pilot. New Cielo buy legs are checked against native launches/graduations; outside-native and graduated tokens go to a research watchlist, never the trading universe. Token symbols are not trusted for matching.

API: one request per 15 minutes, 300 listed-credit equivalents per UTC day, 4,200 lifetime. Reserve 3 credits before every feed/balance request even on failure, never refund uncertain billing. No retries outside the same budget; 202/empty/busy/partial pagination are distinct and not negative evidence. Balance endpoint RH support is experimental (previous empirical probe succeeded; published enum omits RH). Authentication failures pause requests. No new subscription, tracking-list mutation or messaging.

Storage: private independent SQLite and JSON artifacts on /mnt/solana-data; 64 GiB cap, 20 GiB disk reserve. A timer runs one bounded collector tick each minute; publisher separately runs every 30 minutes and verifies public SHA256. Pilot expires automatically, persists final status and follows existing attempts for one day. Secrets never enter public artifacts. Public site contains aggregates, protocol and operating limitations only; no raw addresses or journal records.

Minimum review conditions after maturity: at least 100 first-token/arm observations and 30 matched closed native-quote attempts, 95% decision input validity and 80% Cielo style coverage. These are review eligibility gates, not statistical significance or proof of profitability. Below threshold = inconclusive. Even above threshold requires human economic validation and uncertainty assessment before any funded change.

Frozen operational and feature details

Eligibility: buys in the preceding 3,600 seconds, with at least one such eligible buy in the preceding 180 seconds for the token. Use the own-list version stamped in the decision and locally archived before decision time. A wallet's active_since must be strictly earlier than its buy timestamp. Retention denominator is all positive raw curve token buys for that wallet in the archived token prefix; subtract positive actor-attributed curve sells, clamp to [0,1]. At least one eligible wallet is required. Routed activity and transfers can make this proxy inaccurate, so it is never labelled an ownership fact.

Style: RH non-quote token provider swap legs in the preceding seven days; order by chain timestamp, transaction hash and index, deduplicate identical observations. First buy starts an episode, repeated buys do not reset it; first later sell ends it (a partial sell also counts). Same-transaction route legs do not create a holding episode; any wallet/token/transaction containing both directions is excluded. Transfers interrupt an open episode as unknown. Open episodes are right-censored at decision time. Any censoring or interrupted episode, partial feed window, missing pagination, fewer than five completed episodes, or stale latest feed receipt (>24h) makes style ineligible for exclusion. Completed-episode medians remain descriptive, not estimates of the full holding-time distribution. Provider classification remains unverified and this challenger is a research hypothesis only.

Commissioning seeks to journal EOF once and stores the byte offset/inode and wall-clock start. Every input requires local first receipt no later than the decision; decisions also require decision_ts >= commissioning. Membership ingestion before processing a line does not override this fence. Incomplete trailing lines wait; event_id is immutable. Rotation or truncation increments a coverage-break counter and reads the new journal from zero with the same decision-time fence and deduplication. Malformed/oversized lines count coverage failures. A tick reads at most 4 MiB/500 records, each line <=256 KiB, each prefix <=8 MiB, and archives at most 16 MiB of new evidence. Source SQLite queries have a 3-second VM deadline. HTTP has a 25-second timeout and 4 MiB response limit. One page per scheduled request, at most three pages per window; unresolved windows remain partial and are eventually replaced by a fresh window, with no claim of exhaustive coverage. Tick runtime capped by systemd at 50 seconds; flock prevents overlap. Storage size includes SQLite/WAL/SHM, private raw files and public staging under the archive root; stop collection at 64 GiB or <20 GiB available. Errors/heartbeat remain bounded. No external requests during the follow-up day.

Coverage denominators: report all unique captured decision event IDs, first token/arm pairs, and exact matched funded attempts separately. Decision input validity uses unique decision events. Cielo style coverage requires every eligible wallet to meet all eligibility conditions and uses input-valid decision events. Only fully closed matched native-quote outcomes with receipt-net-v1 recorded accounting, nonnegative integer stake/proceeds/gas and native gas conversion enter the conditional diagnostic. Realized drawdown orders closed cashflows by (closed_ts, attempt_id), starts equity at zero, and excludes open attempts from P&L while disclosing their count. No mark-to-market or opportunity-cost interpretation.

Native timing is established by the producer's hashed input/revalidation records and predecision capture reference. Reused unchanged prefixes may be old; the revalidation read must finish within five seconds before the decision. Cielo and membership availability use their first collector receipt. These distinct clocks are never substituted for one another. Malformed or revised provider rows disqualify the entire feed window for style exclusions; zero-quantity swaps cannot create or close holding episodes.

Revision 2: collection repair and advisory watchlist, 2026-09-22

Version 1 remains immutable and inconclusive: storage stopped collection, feed cursors used the live next_cursor field rather than the documented next_object_id, and zero decisions had eligible Cielo style coverage. 52 first-token/arm observations and 12 matched closed trades were recorded; all policies retained those trades, recorded net -0.270219503984416111 ETH. These are a partial recorded-book diagnostic, not the account's overall return.

Create a fresh prospective cohort starting at commissioning. Do not replay past journal lines or rewrite old policy outputs. Preserve October 5 10:53:50 UTC collection end and October 6 10:53:50 UTC follow-up end. Retain a private frozen prior-status snapshot, separate public prior summary and protocol link. Prior 90 reserved credits count toward the original 4,200 overall limit. No new subscription or external notifications.

Fix live cursor support with strict disagreement/type/missing/repeated-cursor handling, preserving partial/unknown states and three-page limit. Follow-up requests carry startFrom within the same fixed time window. Cursor correctness is not full wallet-history proof. Preserve current style rules and uncertainty handling; unknown transaction types continue to make style ineligible.

Use compressed content-addressed evidence, store repeated prefixes separately, verify round-trip SHA256, and keep a compatible reader. Raw bytes remain the hash identity. Keep the 16MiB decoded-evidence-per-tick bound; track persisted compressed bytes without rescanning all evidence files for each decision. Raise this isolated archive's storage cap to 64GiB with the existing 20GiB disk reserve. Archive scan once per tick. Skip redundant unchanged wallet-registration writes. These operational changes are part of a separately frozen version, not a silent update of V1.

Monitor captured decision time and journal byte lag, in addition to process heartbeat. A successful timer tick does not establish current data freshness. Explicitly retain the V1 gap; no historical recovery is represented as prospective data. Record source journal sizes and last source / captured decision timestamps.

Publish the token discovery review queue (native contract metadata when available, contract address and first provider observation, no wallet identities). Include version and classification time; labels indicate discovery provenance, not safety or buy recommendations. Prior discoveries remain marked V1 and are not counted as V2 coverage. Quotes are excluded by contract identity only. Show why live entries remain unchanged.

Acceptance: regression tests for actual cursor shape through two mocked HTTP pages; conflicting and repeated cursors; compression/hash round-trip/dedup/cap; carried API budget; prior/V2 separation and no retroactive policy changes; all prior tests; read-only live-source validation; code review; active timer/HTTP API verification; remote public file hash and mobile checks.

A 100-record replay reduced stored evidence by77.4%, but extrapolation from the original event rate can still exceed8GiB over the remaining window. The isolated V2 cap is therefore64GiB on the archive disk (over900GiB free at commissioning), with the same20GiB reserve. Decision-validity flags are recorded transactionally with each immutable decision, avoiding repeated scans of full JSON feature payloads during minute reports. API budget and funded behaviour are unchanged.

Provider references

Cielo feed and costs · Token balance support