> For the complete documentation index, see [llms.txt](https://nytshift.gitbook.io/nytshift-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://nytshift.gitbook.io/nytshift-docs/implementation-ledger/tickets.md).

# Ticket corpus and milestone index

Latest: `NS-446` makes the complete Hyperliquid validation campaign mechanically verifiable from private redacted evidence without making a venue request. `NS-445` makes Hyperliquid symbol and first-canary leverage scope independently signer-enforced and readiness-proven without performing a venue mutation. `NS-444` adds an explicitly enabled, hard-$12-capped supervised Hyperliquid mainnet canary process. `NS-443` adds the durable authenticated customer/profile/PAPER trading ledger without moving signer authority into PostgreSQL. `NS-438` through `NS-442` build and qualify Bring Your Own Agent: a scoped MCP foundation, honest Market Brief and Agent Command Center, hosted customer OAuth, deterministic paper/policy-bound testnet modes and exact-release production evidence. None grants model-held credentials or implicit mainnet authority. `NS-437-production-owner-action-lanes.md` turns every fail-closed production-activation state into an explicit non-secret owner action without granting authority.

Execute in order. Each ticket is intentionally narrow enough to review and revert.

| Ticket    | Outcome                               | Depends on                 |
| --------- | ------------------------------------- | -------------------------- |
| `RHC-101` | Safe Chainlink price context          | RHC-0 read-only adapter    |
| `RHC-102` | Wallet balances and ERC-8056 UI units | RHC-101 shared read models |
| `RHC-103` | Price/portfolio terminal UX           | RHC-101, RHC-102           |
| `RHC-104` | Resilience, drift and security gates  | RHC-101–103                |

No ticket authorizes activating a user signer key, wallet session keys, token approvals, RFQ submission or any testnet/mainnet order. NS-321 implements the protected Arcus boundary; NS-322 and NS-374 supervise only offline/test-process proof while every external activation, registration, eligibility, funding, rehearsal and authorization gate remains pending.

## Runtime milestone

* `NS-446-hyperliquid-validation-evidence-verifier.md` - generates an exact private checklist and verifies complete testnet/mainnet campaign, fresh per-mutation authorization, database, recovery and final-flat proof offline.
* `NS-445-hyperliquid-signer-policy-scope.md` - enforces canonical signer-side symbol and leverage policy, binds the redacted policy digest into health/BFF readiness and preserves protective exits.
* `NS-443-durable-customer-trading-ledger.md` - stores authenticated preferences and PAPER order/fill/position/PnL/risk/audit history in a customer-scoped PostgreSQL ledger while preserving the isolated signer database and guest-local simulation.
* `NS-444-supervised-hyperliquid-mainnet-canary.md` - promotes the isolated Hyperliquid signer supervisor to explicit mainnet with a compiled $12 first-canary ceiling, offline scope proof and real-process lifecycle verification.
* `NS-442-agent-production-qualification.md` - qualifies hosted BYO-agent interoperability, security, operations and testnet evidence while retaining independent mainnet locks.
* `NS-441-agent-paper-testnet-modes.md` - adds separately versioned deterministic PAPER and existing DPoP policy-bound Hyperliquid testnet tools without cancel/retry/signer access.
* `NS-440-hosted-agent-authorization.md` - adds customer-owned OAuth 2.1/PKCE, exact resource audiences, consent/revocation and a separately disabled remote-MCP activation gate.
* `NS-439-agent-command-center.md` - renames deterministic Copilot to Market Brief and adds a real external-agent connection, policy, activity and kill-switch workspace.
* `NS-438-byo-agent-mcp-foundation.md` - exposes exact read/proposal/status/activity tools over strict MCP with expiring scoped credentials and no execution authority.
* `NS-437-production-owner-action-lanes.md` - renders the exact next owner action for Privy, licensed charts, redundant RHC data and order authority without exposing secrets or changing any safety gate.
* `NS-436-readable-zoomable-market-integrity.md` - defaults unsigned sessions to comfortable density, adds bounded chart zoom and audits every public oracle/index against its authoritative venue mark.
* `NS-435-user-owned-arcus-withdrawal-lifecycle.md` - extends the no-send preflight into a separately disabled, exact-wallet EIP-712, at-most-once submission and exact-ID durable reconciliation lifecycle without custody or blind retry.
* `NS-433-live-oracle-divergence-quarantine.md` - quarantines an oracle/index more than 5% from the authoritative venue mark, preserving the mark and candles while removing the reference from chart, basis and other numeric consumers.
* `NS-432-readable-collapsible-chart-chrome.md` - defaults the custom drawing/history rail to collapsed, persists explicit user choice and raises chart-control contrast without changing data or execution authority.
* `NS-431-advanced-charts-production-evidence.md` - binds native licensed-chart readiness to a fresh exact-release/tree production rehearsal without bundling proprietary assets.
* `NS-430-privy-production-activation-evidence.md` - binds customer-access readiness to a fresh private exact-app production rehearsal without retaining a token, user, email, wallet or trading authority.
* `NS-429-production-activation-audit.md` - validates the exact public release, Privy, licensed charts and redundant RHC data lanes from bounded live evidence while keeping every private capital proof explicitly unproven.
* `NS-428-verified-customer-rhc-funding-handoff.md` - turns the generic signed-in bridge placeholder into an exact-wallet canonical funding review with reviewed contracts, provider confirmation requirements, destination-receipt finality and zero transaction authority.
* `NS-426-explicit-vps-hosting-boundary.md` - removes the stale Sites manifest and mechanically limits releases to localhost or a separately approved exact-artifact VPS workflow; Privy's challenge origin remains an identity dependency, not hosting authority.
* `NS-425-held-mark-consumer-isolation.md` - projects every retained perpetual mark through one consumer-safe boundary so held values cannot trigger alerts or masquerade as current in paper trading, chart risk, watchlists, search, briefs or book evidence.
* `NS-424-corroborated-streaming-mark-authority.md` - consumes exact Hyperliquid all-DEX mark/oracle contexts, rejects midpoint-as-mark updates and retains the last accepted mark/time while every chart, order and paper authority remains locked on an uncorroborated large move.
* `NS-412-rebuild-aware-local-restart.md` - stops the supervised web child before preflight/build, honors `if-needed`/`always`/`never`, launches only after success and retains a fixed childless failure state instead of serving stale or partial output.

## Execution safety milestone

* `NS-423-hyperliquid-reviewed-notional-ceilings.md` - requires canonical market-position and all-DEX gross-notional ceilings, forces fresh complete configured-account evidence, binds both limits into the one-use ticket and rechecks before signer I/O without trapping reduce-only exits.
* `NS-422-hyperliquid-reviewed-slippage-ceiling.md` - requires a canonical 1-30 bps manual price envelope, preserves the tighter platform/automation limit, binds it into the one-use ticket and rechecks before signer I/O.
* `NS-421-hyperliquid-reviewed-total-fee-ceiling.md` - requires a user/operator current-leg total-fee ceiling, applies exact live account and HIP-3 fee evidence, rechecks before signer I/O and revokes legacy automation policy authority during schema-v3 migration.

## Paper milestone

* `NS-420-paper-notional-limits.md` - binds exact user-defined market and portfolio open-entry-notional ceilings to the immutable PAPER risk checkpoint and reserves/fills standard entries without trapping reduce-only exits.
* `NS-419-paper-entry-spread.md` - binds a user-defined bid/ask spread ceiling to the strict ledger risk checkpoint and enforces exact midpoint-relative price quality across immediate and GTC standard entries.
* `NS-418-paper-visible-depth-slippage.md` - binds a user-defined entry-slippage ceiling to the strict ledger risk checkpoint and enforces exact first-level-to-average adverse depth across immediate and GTC standard entries.
* `NS-417-paper-loss-drawdown-lock.md` - binds immutable user-defined loss limits to one strict local ledger, checkpoints only fully marked equity, pauses standard immediate/GTC exposure fail-closed and preserves risk-reducing exits.
* `NS-416-cross-market-paper-equity.md` adds exact cross-market venue marks and unrealized PnL to the local portfolio, with total mark-to-market paper equity available only when every retained position is fresh.
* `NS-415-cross-market-paper-portfolio.md` - adds a compact exact-context portfolio navigator over the strict local ledger, GTC and protection books with away PnL explicitly unavailable until the market has a fresh selected book.
* `NS-414-cross-market-paper-order-management.md` - expands the away-GTC aggregate into exact oldest-first local order rows with per-context monitor state and one-order local cancellation, retaining zero venue authority.
* `NS-413-multi-market-paper-protection-book.md` - retains as many as eight exact browser-local stop/take-profit plans, monitors selected and away markets independently, pauses only matching local GTC contexts and migrates the strict legacy plan in place.
* `NS-411-cross-market-paper-protection-monitor.md` - keeps one exact local stop/take-profit plan under pooled mark/book observation across market switches, rejects Hyperliquid mids as mark authority and leaves Lighter book repair REST-only without a verified market index.
* `NS-410-cross-market-paper-gtc-monitor.md` - keeps eligible local GTC orders under exact-context observation across market switches while the tab is open, using pooled Hyperliquid/Arcus streams and bounded REST repair while refusing to guess Lighter WebSocket scope.
* `NS-409-browser-local-gtc-paper-orders.md` - places bounded non-crossing local GTC limits, consumes at most one eligible order per fresh book observation and retains partial/fill/cancel/rejection evidence with explicit open-terminal limits.
* `NS-408-live-mark-paper-protection.md` - arms exact-position local stop/take-profit plans from a fresh venue mark and exits only through synchronized fresh visible depth, with partial retention and explicit open-terminal limits.
* `NS-407-production-release-capacity-observability.md` - joins coarse verified-release capacity to health, command-deck and terminal trust surfaces with a fail-closed reserve and no implicit pruning.
* `NS-406-robinhood-bridge-evidence.md` - adds a drift-audited public bridge registry and readable Funding Rails panel for one canonical route, five partner families and 16 official contracts with no transaction capability.
* `NS-405-production-activation-readiness.md` - renders exact external setup and safety locks from fail-closed health plus live provider evidence, clearing stale or contradictory capability claims.
* `NS-404-canonical-spot-venue-evidence.md` - separates source-attributed spot ecosystem listings from router deployments, liquidity, quotes and execution capability for every canonical Robinhood Chain asset.
* `NS-403-multichain-spot-execution-roadmap.md` - defines the evidence, wallet, routing, simulation, conditional-order, reconciliation and staged-mainnet boundaries for a Padre-class multichain spot terminal.
* `NS-402-stream-reference-quarantine.md` - makes the venue mark authoritative while quarantining malformed or materially divergent oracle/index values across terminal, chart-risk and asset-dossier projections; NS-433 sets the current ceiling to 5%.
* `NS-401-customer-terminal-preferences.md` - activates saved customer market-density and chart-preset choices, rejects late older profile revisions and clears the identifier-free projection on lost verification.
* `NS-400-licensed-advanced-charts-runtime.md` - adds license-attested private-asset installation, exact manifest/SRI/CSP verification, native TradingView tools and persistent layouts/templates without bundling proprietary files.
* `NS-399-platform-readability-and-mobile-chart-density.md` - adds measured landing/terminal/deck readability, explicit compact venue labels, non-dimming dossier loading and a persistent mobile-first chart-overlay collapse control.
* `NS-398-advanced-charts-datafeed-boundary.md` - adds provider-only TradingView UDF routes and a supervised custom streaming Datafeed without demos, iframes or unlicensed library assets.
* `NS-397-customer-capital-workspace.md` - groups one verified wallet into real capital-workspace tabs and calculates returned-window Arcus/Hyperliquid performance without an all-time or cross-venue total.
* `NS-396-verified-customer-venue-activity.md` - adds private newest-first Arcus and Hyperliquid order/fill/funding activity for one verified wallet, excludes provider identifiers and keeps Lighter history auth-locked.
* `NS-395-verified-customer-venue-portfolio.md` - adds a private exact-wallet Arcus, Hyperliquid and Lighter portfolio with normalized equity, margin and positions, explicit provider gaps and no cross-domain total.
* `NS-394-verified-customer-funding-ledger.md` - adds a private exact-wallet Arcus deposit/withdrawal/transfer ledger with terminal venue status, strict newest-first evidence and an honest external Fun deposit handoff.
* `NS-435-user-owned-arcus-withdrawal-lifecycle.md` - extends the no-send preflight into a separately disabled, exact-wallet EIP-712, at-most-once submission and exact-ID durable reconciliation lifecycle without custody or blind retry.
* `NS-393-arcus-production-withdrawal-preflight.md` - builds an exact production withdraw-to-self EIP-712 review after chain, account, collateral and compliance checks while retaining zero signing or submission capability.
* `NS-392-privy-session-and-wallet-continuity.md` - revalidates authenticated customer sessions before expiry, reuses the exact Privy/JWKS client and prevents linked-wallet changes or stale reads from crossing portfolio scope.
* `NS-391-chart-scale-authority-and-contrast.md` - projects mark, oracle/index, entry and liquidation guides through an inert collision-aware SVG layer and binds compact operational copy to measured 7:1-plus contrast tokens.
* `NS-390-customer-access-taxonomy.md` - adds a strict server-derived Research, Account, Portfolio, Trading + funds and Agent API map with exact prerequisite and lock reasons.
* `NS-389-verified-wallet-portfolio-boundary.md` - adds a private dual-token wallet-selection boundary, live canonical chain-4663 holdings and honest bridge/deposit/withdrawal/trading capability locks without requesting a signature.
* `NS-384-chart-funding-liquidation-context.md` - adds exact-market historical funding statistics, a strict additive liquidation-context API and bounded Lighter venue tags with explicit undocumented states elsewhere.
* `NS-383-chart-native-carry-performance.md` - adds exact-market bounded closed PnL and position funding/carry to the chart with venue-specific labels and complete, partial, unavailable and stale states.
* `NS-382-chart-native-account-margin.md` - adds exact-scope venue equity, available collateral, margin usage, capital buffer and position leverage/mode/notional/PnL to the chart with explicit partial, unavailable and stale states.
* `NS-381-chart-native-perpetual-risk.md` - adds fresh mark/oracle-or-index context plus exact account entry/liquidation chart lines, side-correct distance and explicit stale/partial/ambiguous states without inferred liquidation authority.
* `NS-380-terminal-release-trust.md` - adds a top-bar, keyboard and command-palette build-trust surface that clears stale proof on failed health reads and never grants execution authority.
* `NS-379-visible-release-readiness.md` - projects public health through a strict browser parser and visibly separates verified deployment identity from read-only execution, diagnostic RHC and venue-data readiness.
* `NS-378-public-release-provenance.md` - publishes exact commit and artifact identity only from a stable matching release-marker pair, leaving source checkouts unversioned and deployed marker failures unsafe.
* `NS-377-rhc-provider-attestation-refresh.md` - renews only an already reviewed exact provider scope, preserves prior evidence on partial failure, refuses bootstrap/rotation and exposes secret-free expiry state without adding credentials or execution authority.
* `NS-376-rhc-provider-attestation.md` - replaces archive-access booleans with fresh endpoint-bound HTTPS historical-state and WSS `newHeads` evidence from two independent providers.
* `NS-375-release-capacity.md` - validates release identity and exact capacity, protects current plus verified rollback releases, and requires a content-addressed plan before pruning.
* `NS-374-hyperliquid-testnet-signer-supervisor.md` - adds a path-only API-wallet doctor and dedicated testnet loopback supervisor with lazy official-SDK initialization, exact authenticated health, store locking, bounded recovery and secret-free evidence; it grants no order authority.
* `NS-373-signed-execution-eligibility.md` - adds strict 30-day-max signed eligibility, exact venue/network/account scope, signer parity, offline issuance and expiry-safe cancellation/reconciliation.
* `NS-372-hyperliquid-venue-dead-man-switch.md` - adds durable `scheduleCancel` arm/heartbeat/disarm/reconciliation, exact testnet rehearsal proof and a signer-enforced fresh mainnet deadline without treating ACK as cancellation.
* `NS-371-hyperliquid-bracket-trade-autopsy.md` - adds a strict retained-only bracket autopsy with exact parent/TP/SL lifecycle, fill and lineage attribution; standalone, missing, corrupt or unsynchronized groups fail closed.
* `NS-370-grouped-hyperliquid-bracket-lifecycle.md` - adds strict parent/TP/SL group reconciliation, one shared bounded fill scan, exact sibling-cancellation proof and actionable fail-closed terminal UI states.
* `NS-369-atomic-hyperliquid-brackets.md` - adds optional user-reviewed Hyperliquid take profit through one official-SDK `normalTpsl` batch, preserving the existing V2/V3 contracts and tracking each bracket leg under execution-store schema v6.
* `NS-368-capital-aware-paper-risk.md` - replays the complete schema-v2 live-book paper tape, enforces account-wide entry-notional against realized user-defined equity, and makes reduce-only incapable of opening, adding or flipping while keeping venue margin and liquidation explicitly unmodeled.
* `NS-366-live-feed-soak-evidence.md` - records bounded normalized public-feed availability, a real supervised child-generation change and post-restart convergence; only a full managed-topology 24-hour run can qualify production.
* `NS-365-hyperliquid-builder-reward-state.md` - reports official per-token referral builder rewards behind operator authentication, rejects token/schema drift and grants no archive ingestion or claim authority.
* `NS-364-canonical-asset-dossier.md` - exposes every reviewed canonical asset's identity, multiplier/pause evidence, independent oracle state, live-discovered perp context and bounded preferred-book depth while preserving exact unavailable and execution-lock reasons.
* `NS-363-hyperliquid-time-machine-trade-autopsy.md` - projects only the configured signer's durable reconciled order evidence into an authenticated Time Machine index and exact per-CLOID Trade Autopsy; it never persists arbitrary public accounts or grants execution authority.
* `NS-362-hyperliquid-explicit-leverage-authority.md` - resolves an active-leverage mismatch through a separate short-lived review and exact-once signer action; it never changes margin mode, never submits an order in the same step and never grants automation leverage authority.
* `NS-361-hyperliquid-collateral-and-active-capacity-authority.md` - converts Standard, Unified and Portfolio Margin collateral plus HIP-3 lifecycle rows through strict token/oracle authority and binds execution to `activeAssetData` capacity without guessing venue borrowing.
* `NS-360-unified-portfolio-spot-balance-authority.md` - reconciles USDC-only Unified and Portfolio Margin capital through strict spot clearinghouse state and keeps malformed, unsafe or non-USDC collateral fail-closed through execution review.
* `NS-359-configured-hyperliquid-portfolio-adapter.md` - normalizes strict multi-DEX Hyperliquid account evidence into the private reconciliation checkpoint and binds its fresh converged generation into every execution path without persisting account identity.
* `NS-358-authoritative-portfolio-reconciliation.md` - converges complete boot/reconnect account state across orders, fills, positions, funding and PnL while preserving last-known capital on partial/stale evidence, retaining fixed drift records and backing the opaque checkpoint with health and verified recovery.
* `NS-357-position-safe-risk-envelope.md` - rejects flat, wrong-side and position-flipping reduce-only orders, caps correlated crypto-beta exposure and validates every dynamic policy before deterministic evaluation.
* `NS-356-strict-hyperliquid-metadata-authority.md` - derives canonical primary/HIP-3 asset identity and precision from bounded official metadata, alarms additive drift and rejects invalid or partial DEX state before discovery or execution review can disagree.
* `NS-355-commercial-revenue-cockpit.md` - joins exact retained native builder-fee aggregates with proposal/automation usage while keeping claim, archive, payment and premium-revenue gaps explicit.
* `NS-354-metered-automation-entitlement.md` - requires an additive signed automation allowance for policy creation/submission and meters each new request ID atomically without charging exact replay or status reconciliation.
* `NS-353-agent-automation-client-kit.md` - generates external P-256 identities and performs strict DPoP submit/status calls through a typed, byte-bounded, loopback-only client with no retry, cancellation, funding or signer surface.
* `NS-352-policy-bound-agent-automation.md` - adds operator-created expiring testnet policies, sender-constrained submit/status, deterministic one-attempt execution and reconcile-only replay without giving an agent a key or cancellation authority.
* `NS-351-agent-pro-entitlements-and-usage.md` - requires a strict signed commercial entitlement for new Agent Pro credentials, atomically meters shared UTC-month attempts, exports aggregate usage and isolates the issuer private key from supervised production.
* `NS-350-policy-bound-agent-proposal-api.md` - issues one-time digest-only credentials for exact proposal mandates, durable quotas/audit, individual and global revocation, a versioned proposal-only API and strict rejection by every execution boundary.
* `NS-344-live-order-book-continuity.md` - streams exact venue-native L2 on the existing pooled sockets, normalizes full snapshots versus Lighter nonce changes, repairs from strict REST and exposes the real transport/freshness in the terminal.
* `NS-345-transparent-revenue-rail.md` - quotes live Hyperliquid trading costs and binds a user-approved native two-basis-point builder fee through review, one-use ticket and isolated signer.
* `NS-367-live-book-paper-trading.md` - adds explicit PAPER / APPROVAL / LIVE terminal modes with strict local simulation over fresh normalized live L2 depth, bounded validated browser state, and no fixture or signer authority.
* `NS-346-builder-revenue-reconciliation.md` - retains exact fee-bound CLOID scopes and recognizes builder revenue only from deduplicated venue fills with explicit coverage limits.
* `NS-347-hyperliquid-order-lifecycle.md` - reconciles strict pending/open/partial/fill/cancel/reject/trigger state, exact fills and fees atomically instead of presenting an acknowledgement or venue-native JSON as finality.
* `NS-348-arcus-schema-v4-readiness.md` - historical schema-v4 milestone that pinned Arcus ordinary and emergency authority to the signer's exact current application/schema, integrity and WAL evidence; NS-362 advanced that gate to schema v5, NS-369 to schema v6, and NS-372 through schema v7 to account-bound rehearsal schema v8.
* `NS-349-durable-arcus-rehearsal-evidence.md` - derives mainnet testnet-order and emergency-stop gates from same-account signer audit finality within 30 days; configuration booleans cannot manufacture proof.
* `NS-342-public-rhc-readiness-contracts.md` - validates chain connectivity, provider topology/health/incidents and aggregate activity health before serialization, commits a dedicated immutable-v1 OpenAPI artifact and makes public-RPC non-promotion a contract invariant.
* `NS-343-public-rhc-data-contracts.md` - validates reviewed price context, canonical holdings, bounded wallet activity and the immutable-provenance asset radar before serialization, with exact headers and address-free contract-failure telemetry.
* `NS-341-public-account-response-contracts.md` - validates every Arcus, Lighter and Hyperliquid public account response before serialization, commits a dedicated immutable-v1 OpenAPI artifact and excludes provider-native/private account fields from the browser and violation telemetry.
* `NS-340-public-market-response-contracts.md` - validates every anonymous market catalog/candle/book/trade/funding/health response before serialization, commits a dedicated immutable-v1 OpenAPI artifact and prevents venue-native payload leakage.
* `NS-339-versioned-contract-artifacts.md` - generates immutable-v1 JSON Schema/OpenAPI artifacts, rejects contract drift, keeps TypeScript/Python signer payloads in parity and uses exact decimal strings across both venue signer boundaries.
* `NS-338-execution-flow-tracing.md` - separates request spans from durable execution roots, carries only server-trusted lineage through signed tickets and signer audit, and rejoins later CLOID/client-ID reconciliation without storing order identity in telemetry.
* `NS-337-durable-proposal-lifecycle.md` - validates strict advisory analysis, persists only bounded identity/hash/state, binds an optional exact proposal to one reviewed Hyperliquid intent and consumes it before signer I/O while retaining fresh AEGIS authority.
* `NS-336-control-plane-slo-alerts.md` - evaluates rolling protected-route SLOs, atomically persists lifecycle incidents and delivers secret-free stable IDs through an optional leased HMAC outbox required for Hyperliquid mainnet.
* `NS-335-control-plane-observability.md` - assigns server-owned traces across protected routes and signer audit, persists only fixed timing/outcome fields, and exposes authenticated feed-age/divergence telemetry without fabricating proposal validity.
* `NS-334-arcus-operator-audit.md` - persists review verdicts before approval delivery and exposes only strict Arcus signer evidence to the authenticated exact-account terminal panel.
* `NS-331-arcus-execution-alert-delivery.md` - atomically queues secret-free Arcus execution events, delivers stable HMAC-authenticated IDs with bounded restart-safe retry, and gates ordinary execution on delivery health.
* `NS-332-versioned-execution-store.md` - application-identifies and transactionally migrates the Arcus signer database, preserves legacy rows, rejects unsafe/future schemas, and gates all execution authority on integrity and WAL health.
* `NS-333-signer-store-backup-recovery.md` - snapshots the sensitive signer database through SQLite, seals it with schema/integrity/checksum evidence, excludes live runtimes, and preserves database/WAL/SHM rollback state during restore.
* `NS-329-chainlink-oracle-coverage.md` - joins 21 current official Chainlink Robinhood proxy records to independently verified canonical token identity, leaving four assets explicitly identity-only and adding a fail-closed connected drift audit.
* `NS-330-arcus-reconciliation-fail-safe.md` - persists reviewed Arcus order scope before place, makes at most one automatic cancel on unknown reconciliation, locks ordinary entry across restart, and requires terminal venue proof to recover.
* `NS-328-arcus-emergency-cancel-all.md` - implements the exact official account-wide emergency cancel path while treating its asynchronous acknowledgement as non-final and requiring zero-open-order reconciliation.
* `NS-327-native-eth-activity.md` - adds strict Alchemy external native-ETH wallet activity, bounded pagination, v1-to-v2 migration and separate gap evidence without weakening the canonical-token index or claiming internal transfers.
* `NS-326-arcus-testnet-funding-plan.md` - attests Arcus's current Robinhood Chain testnet contracts and wallet state, builds exact simulated mint/approval/deposit calldata and preserves a strict no-sign/no-send production lock.
* `NS-325-lighter-read-only-terminal.md` - promotes Lighter into a complete read-only terminal and bounded public account surface with no private lifecycle or execution authority.
* `NS-324-lighter-public-market-coverage.md` - adds independently supervised Lighter public markets while keeping its undocumented Robinhood Chain funding path unavailable.
* `RHC-201-paper-rfq-replay.md` — implemented deterministic, mock-only RFQ fixtures, paper portfolio replay and discipline scoring. This is not live RFQ submission.
* `NS-301-nightshift-command-centre.md` — implemented the local Nightshift product surface, deterministic Tape intelligence, mandate compiler, versioned paper agents, DCA/rebalance replay, agent league, alerts and emergency stop. This is not autonomous execution.
* `NS-307-verified-watchlists.md` — implemented strict venue-scoped Arcus, Hyperliquid and Robinhood Chain favorites with live availability intersection, keyboard controls and reload persistence. Favorites are display preferences only.
* `NS-308-command-deck-readiness.md` — bound landing readiness to the monitored Robinhood Chain provider topology so public diagnostic connectivity can never be mislabeled production.
* `NS-309-production-paper-boundary.md` — removed the disconnected deterministic paper compiler from the production HTTP surface while retaining it for tests and non-production development.
* `NS-310-verified-price-alerts.md` — implemented strict venue-scoped, terminal-open price rules evaluated only against fresh verified live marks or selected-asset Robinhood Chain Chainlink context.
* `NS-311-saved-workspace-layouts.md` — implemented strictly persisted responsive pane presets and up to eight named preference-only terminal views with keyboard/focus controls.
* `NS-312-safe-command-palette.md` — implemented bounded cross-venue live-market and canonical-asset search plus keyboard-accessible safe terminal actions with degraded-feed exclusion and no execution commands.
* `NS-313-retained-candle-continuity.md` — retained validated paginated chart history across authoritative refreshes, added race-safe stream/REST merging, visible continuity telemetry and non-destructive repair degradation.
* `NS-314-configurable-incremental-charts.md` — added strict configurable technical-study periods, persistent style/study preferences, incremental live series updates, UTC OHLCV inspection and contained mobile controls.
* `NS-315-accessible-dialogs-reduced-motion.md` — added contained/restored dialog focus, mutation-safe Escape semantics, visible keyboard focus and comprehensive reduced-motion behavior.
* `NS-316-read-only-wallet-boundary.md` — added strict EIP-6963/EIP-1193 injected-wallet discovery, account/chain observation and explicit Robinhood Chain switching without signing or transaction authority.
* `NS-317-durable-market-history.md` — added migrated, bounded provider-candle persistence, explicit aged outage fallback, health telemetry and verified backup/restore coverage.
* `NS-318-rhc-live-perp-coverage.md` — joins the complete canonical Robinhood catalog to current Arcus and Hyperliquid live discovery with Arcus-first market handoff, venue session/activity evidence and explicit degraded/execution-locked states.
* `NS-319-arcus-no-send-order-preflight.md` — re-reads live Arcus market, book, account, positions and compliance to prove exact ticks/quantums and deterministic policy evidence without signing or submission authority.
* `NS-320-arcus-account-lifecycle-reconciliation.md` — combines Arcus public account REST with address-scoped `orders` and `userFills` snapshots/updates, freezes on sequence gaps and recovers only from a new venue snapshot.
* `NS-321-arcus-protected-execution-boundary.md` — implements official Arcus Ed25519 canonical place/cancel requests, exact ticks/quantums, ten-second one-use reviews, durable unknown-outcome handling and client-ID reconciliation behind independent disabled-by-default gates.
* `NS-322-arcus-testnet-signer-supervisor.md` — adds an offline doctor plus a separate testnet-only loopback supervisor with strict health binding, bounded restart, clean stop and account/key/token-free state and logs.
* `NS-323-canonical-contract-provenance.md` — derives every contract-bearing balance/coverage identity from one immutable official registry, publishes review provenance and adds deterministic plus live source-drift auditing.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://nytshift.gitbook.io/nytshift-docs/implementation-ledger/tickets.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
