Kalkasautonomous decisions

How it works

The loop, one stage at a time.

Every run walks the same six stages in the same order, and every stage names the point where it refuses. This page walks one sample run end to end, then takes each stage in turn: what it admits, what it produces, and where it stops.

Worked example

One sample run, walked through all six stages.

Stage by stage, this is the shape of one record: what was admitted, what the belief looked like, which check bound the decision, and what closed the loop. The values are samples.

sample dataAscot 15:40 — 8-runner handicap
Admitted act

the six stages

  1. Evidence
  2. Calibrated belief
  3. Mandate and risk
  4. Act or abstain
  5. Admitted effect
  6. Settlement and learning

Sport and racing

Full-field belief separated two runners above the confidence floor, stake stayed inside the ruin bound, and the simulated wager settled against the published result.

decision clock 14 Mar 2026, 15:32 UTC

1. Evidence

Sealed, point-in-time observations
  • Field and drawDeclared racing corpus · sealed digest
    observed 14 Mar 2026, 14:05 UTC · available 14 Mar 2026, 14:06 UTC8 declared runners, 2 late non-runners excluded before inference.
  • Pre-off quotesQuote snapshot · per-runner availability time
    observed 14 Mar 2026, 15:20 UTC · available 14 Mar 2026, 15:20 UTCBest reachable price per runner; stale quotes past the window refused.
  • Going and conditionsCourse bulletin
    observed 14 Mar 2026, 13:40 UTC · available 14 Mar 2026, 13:41 UTCGoing updated twice; only the reading available at decision time was used.

refusal boundary · Evidence published after the decision time is refused before inference.

2. Calibrated belief

A distribution, not a vibe
0.00belief density1.00
p = 0.62interval 0.54–0.69interval width 15%

Ranked statistical model v3.4.1 — Ranked belief across the field, renormalised after non-runners.

believed against observed, sealed holdout

0.50.60.70.80.9
believed (x) against observed frequency (y) · dashed line is perfect calibration

refusal boundary · A belief without usable uncertainty, or with mismatched lineage on replay, is refused.

3. Mandate and risk

Explicit authority, explicit bounds

Objective: Paper-first racing decisions under a fixed stake ceiling

  • Mandate presentSigned, unexpired authoritypass
  • Confidence floorat least 0.58 after interval shrinkpass
  • Stake bound1.5% of declared bankroll or lesspass
  • Ruin policyWorst-case drawdown inside policypass
  • Permitted effectSimulation adapter onlypass

authority expires 01 Apr 2026, 00:00 UTC

refusal boundary · No mandate, an expired mandate, or a violated bound means no action is requested.

4. Act or abstain

One replayable decision receipt

DecisionAdmitted under mandate

The pre-off window had not closed, the quote was still reachable, and the stake stayed inside both the mandate bound and the ruin policy.

refusal boundary · Rejected candidates and final abstentions never invoke an effect adapter.

5. Admitted effect

Idempotent, receipt-bound, simulated today
adapter
simulation
adapter calls
1 · idempotent
idempotency key
sport-2026-03-14-1540-runner-4
effect receipt
sha256:6b31c2f7…a9d4

refusal boundary · A conflicting idempotency key fails closed and the original receipt stands.

6. Settlement and learning

Outcomes close the loop
settlement
Observed outcome: 1 winner; simulated stake settled at the quoted price.
evaluation
Evaluation receipt bound to run and effect identity.
learning
Learning receipt: belief stood above the floor; price was the binding constraint.

run fingerprint sha256:1f0a94be…7c22replay deterministiclive:false

refusal boundary · An unbound or replayed settlement fails closed instead of crediting a run twice.

Illustrative worked example. Field names match a real run receipt; the values are samples, and no production run exists yet.

Stage 1 of 6 · Sealed, point-in-time observations

Evidence

Every fact carries when it was observed, when it became available, and where it came from.

Evidence is admitted against the decision clock, not the wall clock. An observation that was published after the decision time is refused before any model runs, so a run can never learn from its own future. Source, feature, and dataset lineage are sealed into the run fingerprint.

  • Observation time and availability time are separate, both required.
  • Source identity and content digest travel with the observation.
  • Quote snapshots bind the price that was actually reachable at decision time.

LimitRefusal boundary

Evidence published after the decision time is refused before inference.

Stage 2 of 6 · A distribution, not a vibe

Calibrated belief

Versioned models turn evidence into one belief with explicit uncertainty and lineage.

Formula, statistical, recorded-ML, and recorded-LLM models all emit the same typed belief: a probability with a bounded interval and the model, artifact, and dataset lineage that produced it. Recorded models replay an immutable inference receipt instead of calling a provider again, so the same run always produces the same number.

  • Uncertainty is part of the output; a bare point estimate is invalid.
  • Model, artifact, configuration, and dataset identities are bound to the belief.
  • Replay recomputes the belief; a mismatch stops the run before anything else happens.

LimitRefusal boundary

A belief without usable uncertainty, or with mismatched lineage on replay, is refused.

Stage 3 of 6 · Explicit authority, explicit bounds

Mandate and risk

Nothing acts by default. A mandate states the objective, the bounds, and the expiry.

The mandate is the authority to act: objective, permitted effects, exposure or stake bounds, and an expiry. It composes with the domain’s risk policy — ruin bounds for wagering, capital risk for markets, analysis-only for reports. Unknown, expired, or under-scoped authority produces a reasoned abstention, never an effect request.

  • Missing, expired, or invalid mandates refuse every effect intent.
  • Exposure and ruin bounds are evaluated before a decision is emitted, not after.
  • A prohibited effect is refused even when the belief is strong.

LimitRefusal boundary

No mandate, an expired mandate, or a violated bound means no action is requested.

Stage 4 of 6 · One replayable decision receipt

Act or abstain

Each run ends in exactly one typed outcome: an admitted act, or a reasoned abstention.

Abstention is not a failure mode to be hidden; it is the correct answer when authority, confidence, coverage, or timing does not hold. It carries a reason, it is reproducible, and it settles like any other run — which is why abstention rates are visible, not buried.

  • Exactly one decision receipt per run, replayable from the same inputs.
  • A rejected candidate can never plan or reach an effect.
  • Abstention states its reason and remains in evaluation coverage.

LimitRefusal boundary

Rejected candidates and final abstentions never invoke an effect adapter.

Stage 5 of 6 · Idempotent, receipt-bound, simulated today

Admitted effect

Only a replay-verified admitted act reaches an adapter, under the requested idempotency key.

The first call returns a receipt bound to that key; a retry returns the same receipt rather than acting twice; a conflicting key fails closed. Today the only shipped adapter is simulation — no broker, sportsbook, exchange, or provider is contacted and no funds or accounts are touched.

  • Effect receipts bind the run, the decision, and the idempotency key.
  • Identical retries read the original receipt; conflicting retries fail closed.
  • Replay performs zero adapter calls.

LimitRefusal boundary

A conflicting idempotency key fails closed and the original receipt stands.

Stage 6 of 6 · Outcomes close the loop

Settlement and learning

Acted and abstained runs settle against the real outcome and emit evaluation and learning receipts.

A run is only useful once the world answers it. Settlement binds the resolved outcome to the exact run, evaluation compares what was believed against what happened, and the learning receipt records the lesson under the same lineage. Corrections append; they never rewrite what was recorded.

  • Every verified outcome satisfies the same seven conditions.
  • The North Star is weekly verified outcomes — not calls, orders, bets, or profit.
  • Correction appends a new record and leaves the original intact.

LimitRefusal boundary

An unbound or replayed settlement fails closed instead of crediting a run twice.

People

Who does what.

Kalkas does not invent authority, and it does not explain itself in a wall of charts. Three human roles sit around the loop, and each one reads something different.

The mandate

A person states the authority.

Authority comes from whoever carries the exposure: a person names the objective, the bounds, and the expiry in one mandate. The kernel reads that mandate and enforces it. It never widens it, and it never substitutes its own judgement for the bounds it was given.

The receipt

A person reads the decision.

The reader is whoever has to account for the decision later: an operator picking up the next shift, an auditor with a question, or you in three months. One run leaves one receipt — the evidence it admitted, the belief it formed, the gate that bound it, and the outcome that closed it. Where a run refused, the receipt names the refusal.

The console

An operator watches the ledger.

The operator surface shows recorded runs with their decision, effect, settlement, and learning receipts, the evidence admitted to each run, evaluation against the sealed holdout, and the service posture. What it does not show is a production number: the hosted service is not live, and every surface says so.

Product constraints

What the kernel will not do.

These hold in every domain module and on every surface. They are design constraints rather than release notes, and they do not change with a deployment.

  • neverNo live decision, order, wager, or external effect exists in the shipped adapter.
  • neverNo custody of funds, accounts, or customer assets, and no counterparty reach-through.
  • neverNo guaranteed profit, no promised strike rate, and no performance claim sold as fact.
  • neverNo action when evidence, authority, replay, settlement, or effect identity is incomplete.

LimitWhat happens when a check cannot be proven

A run pauses and refuses rather than guessing: a fact published after the decision time never reaches a model, a rejected candidate never plans and never reaches an adapter, and a retry that conflicts with a recorded effect fails closed.

What happens to the refusal depends on the boundary: a reasoned abstention settles with its run and stays in coverage, a rejected candidate is recorded against the candidate version and appends nothing, and a fact refused before inference ends the run with a named error and no receipt at all. Read the boundaries below, or the full list in the refusal reference.

Refusal boundaries

Every stage can refuse. Here is where.

Pick a boundary to see what triggers it and what the run does instead of acting. The scenario tokens are the same ones the operator entry exposes.

Filter refusals by stage

All fifteen named scenarios the operator entry exposes: fourteen boundaries and the admitted path.

Unavailable evidence

evidence

Trigger

A fact was published after the decision time.

What the run does

Refused before inference. No belief is produced and nothing downstream runs.

Scenario token

--scenario unavailable-evidence

Scenario tokens are the published operator contract: the same input path, one named boundary. Full commands live in the quickstart.

Start where the evidence starts.

Run the loop locally against sealed corpora and read the receipt it hands back. Nothing is hosted yet, the effect adapter is simulation-only, and nothing leaves your machine.