← Pilot dashboardRobinhood Cielo prospective research pilot
Approved objective: implement buyer-support measurement, wallet holding-style features, broader discovery, post-entry monitoring, and matched policy comparisons. This pilot has no order or signing capability and does not change any frozen Arm C files or live configuration.
Fourteen days from commissioning, plus 24 hours of outcome follow-up. Read-only native databases and the existing pre-veto decision journal. Capture only new journal records after commissioning. All logged decisions, including vetoed decisions, remain in the cohort; first token/arm observations identify the independent discovery cohort. Actual funded attempts join by exact decision_capture_event_id. Never imply the pre-veto journal includes candidates rejected at earlier gates.
Native retention is explicitly a curve buy/sell inventory proxy, not actual ownership: recipient buys minus actor sells, with attribution caveats. Membership must have been published before the buy and captured locally before the decision. Immutable archived decision inputs must match their hashes and precede decision time. Missing or stale data is unknown. Current head parity is not established by this logger.
Cielo rows are indexed by contract/chain and transaction/row index; transfers remain transfers. Feed swap directions are provider-reported legs, not independently verified economic trades. Style measures observed buy-to-first-sell intervals (with unmatched buys censored), never wallet profitability. Historical rows cannot enter decisions before their first local receipt. Fresh sampled balances supplement support observations but API response time is not proof of state block/finality. No external request blocks the live bot.
Comparison: current logged policy is the baseline; native challenger overlays a fixed research exclusion when all eligible buyer proxies have sold at least half their observed curve inventory. Cielo challenger additionally excludes when at least two eligible wallets each have at least five observed first-sell intervals, every measured wallet's median interval is below 480 seconds, and there are no unmeasured eligible wallets. This is a deliberately fixed hypothesis, not a trained model. Unknown data defaults to the baseline with a separate coverage flag. Fresh balance support is reported independently until block-resolved attribution can be certified; it does not veto. Challenger decisions can only remove baseline admissions, never admit new tokens. Native input failures make both challengers unknown, not apparent passes.
Exact original stake and recorded exit outcome are reused for conditional filtered-funded-book comparisons. Show outcome completeness, net quote cashflow including recorded gas, realized drawdown and excluded winners/losses. Different quote currencies must not be summed. Rejected/unfunded candidates have no invented P&L. This is not a full executable counterfactual or training-ready economic proof. No automatic promotion.
Discovery is the selected-wallet universe, not all RH: native scorer members selected deterministically without future returns, plus qualifying wallets observed during the pilot. New Cielo buy legs are checked against native launches/graduations; outside-native and graduated tokens go to a research watchlist, never the trading universe. Token symbols are not trusted for matching.
API: one request per 15 minutes, 300 listed-credit equivalents per UTC day, 4,200 lifetime. Reserve 3 credits before every feed/balance request even on failure, never refund uncertain billing. No retries outside the same budget; 202/empty/busy/partial pagination are distinct and not negative evidence. Balance endpoint RH support is experimental (previous empirical probe succeeded; published enum omits RH). Authentication failures pause requests. No new subscription, tracking-list mutation or messaging.
Storage: private independent SQLite and JSON artifacts on /mnt/solana-data; 2 GiB cap, 20 GiB disk reserve. A timer runs one bounded collector tick each minute; publisher separately runs every 30 minutes and verifies public SHA256. Pilot expires automatically, persists final status and follows existing attempts for one day. Secrets never enter public artifacts. Public site contains aggregates, protocol and operating limitations only; no raw addresses or journal records.
Minimum review conditions after maturity: at least 100 first-token/arm observations and 30 matched closed native-quote attempts, 95% decision input validity and 80% Cielo style coverage. These are review eligibility gates, not statistical significance or proof of profitability. Below threshold = inconclusive. Even above threshold requires human economic validation and uncertainty assessment before any funded change.
Frozen operational and feature details
Eligibility: buys in the preceding 3,600 seconds, with at least one such eligible buy in the preceding 180 seconds for the token. Use the own-list version stamped in the decision and locally archived before decision time. A wallet's active_since must be strictly earlier than its buy timestamp. Retention denominator is all positive raw curve token buys for that wallet in the archived token prefix; subtract positive actor-attributed curve sells, clamp to [0,1]. At least one eligible wallet is required. Routed activity and transfers can make this proxy inaccurate, so it is never labelled an ownership fact.
Style: RH non-quote token provider swap legs in the preceding seven days; order by chain timestamp, transaction hash and index, deduplicate identical observations. First buy starts an episode, repeated buys do not reset it; first later sell ends it (a partial sell also counts). Same-transaction route legs do not create a holding episode; any wallet/token/transaction containing both directions is excluded. Transfers interrupt an open episode as unknown. Open episodes are right-censored at decision time. Any censoring or interrupted episode, partial feed window, missing pagination, fewer than five completed episodes, or stale latest feed receipt (>24h) makes style ineligible for exclusion. Completed-episode medians remain descriptive, not estimates of the full holding-time distribution. Provider classification remains unverified and this challenger is a research hypothesis only.
Commissioning seeks to journal EOF once and stores the byte offset/inode and wall-clock start. Every input requires local first receipt no later than the decision; decisions also require decision_ts >= commissioning. Membership ingestion before processing a line does not override this fence. Incomplete trailing lines wait; event_id is immutable. Rotation or truncation increments a coverage-break counter and reads the new journal from zero with the same decision-time fence and deduplication. Malformed/oversized lines count coverage failures. A tick reads at most 4 MiB/500 records, each line <=256 KiB, each prefix <=8 MiB, and archives at most 16 MiB of new evidence. Source SQLite queries have a 3-second VM deadline. HTTP has a 25-second timeout and 4 MiB response limit. One page per scheduled request, at most three pages per window; unresolved windows remain partial and are eventually replaced by a fresh window, with no claim of exhaustive coverage. Tick runtime capped by systemd at 50 seconds; flock prevents overlap. Storage size includes SQLite/WAL/SHM, private raw files and public staging under the archive root; stop collection at 2 GiB or <20 GiB available. Errors/heartbeat remain bounded. No external requests during the follow-up day.
Coverage denominators: report all unique captured decision event IDs, first token/arm pairs, and exact matched funded attempts separately. Decision input validity uses unique decision events. Cielo style coverage requires every eligible wallet to meet all eligibility conditions and uses input-valid decision events. Only fully closed matched native-quote outcomes with receipt-net-v1 recorded accounting, nonnegative integer stake/proceeds/gas and native gas conversion enter the conditional diagnostic. Realized drawdown orders closed cashflows by (closed_ts, attempt_id), starts equity at zero, and excludes open attempts from P&L while disclosing their count. No mark-to-market or opportunity-cost interpretation.
Native timing is established by the producer's hashed input/revalidation records and predecision capture reference. Reused unchanged prefixes may be old; the revalidation read must finish within five seconds before the decision. Cielo and membership availability use their first collector receipt. These distinct clocks are never substituted for one another. Malformed or revised provider rows disqualify the entire feed window for style exclusions; zero-quantity swaps cannot create or close holding episodes.
Provider references
Cielo feed and costs · Token balance support