> For the complete documentation index, see [llms.txt](https://nytshift.gitbook.io/nytshift-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://nytshift.gitbook.io/nytshift-docs/evidence-and-handoff-records/first-sprint.md).

# First sprint backlog

## HL-001 — Canonical event and API schemas

**Delivered baseline:** Runtime Zod schemas now generate deterministic JSON Schema Draft 2020-12 plus OpenAPI 3.1.1 development, signer and separately versioned public-market/public-account/public-RHC-readiness/public-RHC-data documents. Named v1 definitions and operation request/parameter/security/response boundaries are immutable, committed-artifact drift fails release, all eight TypeScript/Python signer requests have structural parity tests, and Hyperliquid joins Arcus in using exact decimal strings across the loopback signer boundary. The additive Hyperliquid v2 order DTO binds its native builder address and fee without changing v1; the additive leverage DTO binds reviewed current/target leverage and unchanged margin mode. The complete anonymous market family, all three venue account reads, five Robinhood Chain readiness reads and four price/portfolio/activity/radar reads validate strict normalized responses before serialization and fail closed without leaking producer data, addresses, endpoints or paths into violation telemetry.

**Next acceptance:** extend separately versioned strict response contracts to the public-address Robinhood Chain holdings/activity, oracle and radar read families before publishing generated clients; retain provider-specific raw payloads behind adapters.

## HL-002 — WebSocket manager

**Delivered baseline:** one pooled browser connection per venue with ref-counted exact subscriptions, replay/unsubscribe, heartbeat, byte/message/connection budgets, stale and freshness state, bounded reconnect jitter and deterministic reconnect tests. Arcus and Hyperliquid order books accept complete replacement snapshots; Lighter accepts a complete initial snapshot and applies changes only across an exact `begin_nonce`/`nonce` chain. REST bootstraps and repairs the selected book, while a Lighter gap fails closed and forces resubscription.

**Next acceptance:** retain sanitized server-side aggregate stream metrics if an operator destination is configured; add a durable event producer only when a reviewed downstream consumer requires it. Redis is not a prerequisite for browser-stream correctness.

## HL-003 — Metadata and asset resolver

**Delivered baseline:** bounded official Info client plus a shared strict perpetual metadata authority. Primary and sparse-index HIP-3 DEX records derive canonical L1 asset IDs, exact size precision, price decimal caps, leverage, delisting and current margin modes. Public discovery rejects an incomplete DEX set, reports aggregate schema health and excludes provider-native fields; execution review uses the same parser and rejects additive drift.

**Next acceptance:** extend the same reviewed authority to `spotMeta` only when spot trading enters scope; retain versioned historical metadata only when a concrete replay or audit consumer requires it.

## HL-004 — Portfolio reconciler

**Delivered baseline:** strict idempotent order/fill/position/funding/account reducer plus boot, reconnect and periodic venue reconciliation. The configured Hyperliquid signer account is normalized from every discovered perp DEX, exact order status, bounded unaggregated fills/funding and explicit account mode. Concurrent reads coalesce, partial attempts preserve the accepted remote clock, and every execution/automation path requires a fresh converged opaque-account generation. Complete position snapshots replace local authority; unavailable coverage preserves prior state and degrades health. `allPerpMetas` binds each DEX to its official collateral token; strict `spotMeta` identity and reserve-oracle rows convert Standard, Unified and Portfolio Margin state plus HIP-3 fills/fees/PnL/funding into the USD risk model. Portfolio Margin debt is included, unrelated Unified spot balances are not promoted and borrowing/headroom stays venue-computed. Fresh review requires exact `activeAssetData` leverage, maximum size and available capacity. A mismatch now enters a separate operator-confirmed, unchanged-mode, exact-once leverage action, reconciles from fresh `activeAssetData` and requires a new order review; automation receives no leverage authority. Authenticated Time Machine and Trade Autopsy projections now expose only the configured signer's locally reconciled lifecycle, fill, fee, PnL, builder-revenue and event-time lineage with explicit 10,000-fill/1,000-event bounds; they do not persist arbitrary public accounts or weaken current-capital authority. Fixed-code divergence evidence, bounded fee/PnL/funding summaries, atomic persistence, aggregate health and verified backup/restore are covered by deterministic tests.

**Next acceptance:** rehearse a dedicated non-USDC collateral order through testnet leverage update, submit, terminal reconciliation, emergency stop and Trade Autopsy with an explicitly authorized funded account.

## HL-005 — RiskPolicy v1

**Delivered baseline:** pure evaluator, immutable-v1 reason codes and a validated deterministic policy. Reduce-only approval now requires a fresh non-flat matching position, the true closing side and a venue-normalized quantity no larger than the open position. The default policy also caps combined BTC/ETH/SOL/HYPE projected exposure at 20% of equity, emits bounded group metrics, preserves entry-only circuit-breaker bypass only for valid reductions and has deterministic property-style plus execution-integration coverage.

**Next acceptance:** move policy version review into a durable operator workflow only when a concrete multi-policy consumer exists; keep the existing signed risk-decision ID and signer audit as execution evidence.

## HL-006 — Paper broker and replay

**Delivered baseline:** idempotent broker, crossing rules, fee/slippage model and deterministic replay. Production live-book paper mode additionally consumes exact fresh visible depth, records partial remainder, enforces a replay-verified account-wide one-times entry-notional envelope and strict reduce-only direction/size. A separate bounded local GTC book accepts only non-crossing limits, reserves capital/position capacity, consumes at most one oldest eligible order per newer book observation and retains partial/fill/cancel/reject lifecycle without claiming a venue order or queue position. A separate strict local position-protection record watches a fresh venue mark, requires post-trigger fresh book evidence, executes only a reduce-only paper exit, retains exact partial remainder and invalidates on position drift without claiming venue-native TP/SL semantics.

**Next acceptance:** deterministic latency and funding, plus a production-isolated fixture recorder and replay report. Keep fees, margin, liquidation and venue queue priority explicitly unmodeled until a reviewed per-venue paper model exists; browser-local GTC monitoring is not that venue model.

## HL-007 — Read-only terminal

**Delivered baseline:** responsive Next.js terminal shell with live cross-venue discovery, deep history and technical analysis, canonical Robinhood Chain coverage, public-address holdings, and a selectable 25-asset dossier that joins reviewed contract/class identity, independently eligible oracle evidence, live ERC-8056 token state, venue schedules and bounded displayed book depth without implying execution authority. A bounded private operations runner now samples all normalized public rails, hash-chains fixed-code evidence, proves a real supervised child-generation restart and distinguishes short operational proof from a 24-hour managed-topology qualification.

**Next acceptance:** run and retain a full 24-hour soak after managed Robinhood fallback/WSS/archive configuration, then complete the remaining funded account-specific testnet rehearsals; keep every public read and unavailable state strict during upstream drift.

## HL-008 — Audit, tracing and dashboards

**Delivered baseline:** protected Arcus/Hyperliquid requests now have fresh server spans plus a review-created durable flow root that crosses signed tickets, signer audit, cancel and exact-ID reconciliation; strict schema-v3 local retention migrates v1/v2 and records outcomes, p95 boundary time, rolling fixed-code SLO incidents and a durable HMAC delivery outbox; the authenticated dashboard joins flow/span evidence, alert delivery, public-feed age and Robinhood Chain divergence. Hyperliquid mainnet requires healthy operator delivery. Operator-imported analysis has strict durable validity, optional exact review reservation and pre-signer single-use consumption without bypassing AEGIS.

**Next acceptance:** portable trace export and worker/provider spans only after an operator-controlled telemetry destination and disclosure review exist.

## HL-009 — Transparent revenue and premium boundaries

**Delivered baseline:** Hyperliquid reviews use live account fee rates and max-builder approval, disclose the 2 bps fill-only NIGHTSHIFT fee plus total immediate range, bind that exact scope into the confirmation ticket and require the isolated signer to match and send the native builder object. Fee-unbound v1 submission is locked while signing is enabled. Arcus/Lighter receive no invented surcharge. Exact deduplicated fills now feed a private token/month revenue aggregate; proposal and testnet-automation capacity require signed metered entitlements, remain revocable and never expose a signer or key to a model. The operator cockpit keeps premium usage unpriced and payment collection unconfigured without provider evidence. A separate operator-only venue statement resolves exact per-token Hyperliquid builder reward state, redacts identity and labels combined claim balances, archive coverage and claim authority truthfully.

**Next acceptance:** after an explicit payment-provider and pricing decision, verify checkout/webhook evidence and idempotently drive license issuance/renewal/revocation. Extend archive reconciliation only after Hyperliquid publishes or otherwise authoritatively versions the builder-fill CSV schema; design any `claimRewards` path as a separate main-wallet-authorized, ledger-reconciled capability.

## Sprint exit

All TypeScript/Python tests green; no key required; terminal renders; live public feed soaks for 24 hours; forced reconnect converges; risk rejects are visible and typed; every change satisfies `CONTRIBUTING.md`.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://nytshift.gitbook.io/nytshift-docs/evidence-and-handoff-records/first-sprint.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
