OwarineDocs
Open app
How it works

How the desk decides

The owner, the runner and the ledger have distinct jobs; practice desks are paper, and a live desk is a Daml mandate that trades this venue's own markets.

Reviewed 2026-10-06

The desk spans the browser, an off-ledger runner and, when live, a Daml mandate on Canton. The owner picks the names and limits. The runner reads prices and proposes a buy, a sell or a checkpoint. Every decision is written down as a desk.v1 record and fingerprinted before anything moves.

The desk on CantonOwarine

The owner sets the mandate; the operator chooses only when; the ledger checks every trade.

Choose a stage to read its responsibility and authority.

01 · Owner authority

signed mandate
owner's cash
owner-only

02 · Decision and checks

reference
decision hash
or sell back

03 · Record and settlement

settles to seat
sealed record
read and compare
STAGE 1.1

Owner seat

The owner picks the pre-IPO names (their 60-minute Series), the premium ceiling and the caps, and funds the desk from the seat's demo credits.

AUTHORITY BOUNDARY

Only the owner changes limits, deposits, withdraws or closes.

A practice desk is a paper ledger kept by the runner. A live DeskMandate has been opened, funded, paused, resumed and checkpointed on a local Canton sandbox; it has not traded there yet, because no model key was set. Demo credits only.

Download diagram Full size
PartAuthority
Owner (your seat)Picks the names and limits; approves practice decisions by signing a message. Only the owner can unpause, change limits, withdraw or close.
Desk runnerChooses timing and proposes allowed actions, as the operator party. It can pause the desk but cannot unpause it, change the owner's limits or withdraw.
Price referenceFor a live desk, the Window's fair price posted as marks by the oracle parties: the lower median of at least two, none older than 15 minutes.

Practice desks

A practice desk uses paper cash and an off-ledger decision record. Its price references and runner must be available for a check to complete. Check it recomputes a record's fingerprint and compares it with the stored one. The source gate for going live requires six hourly practice checks. The hosted desk created on 8 October was still waiting for its first check; no valuation or completed decision was observed.

The live desk

A live desk is a DeskMandate the owner opens with their own demo credits, signed by the owner and the venue. It holds the allowed names, a premium ceiling and an agent grant with its caps (per trade, per day, budget, open positions), kept inside the mandate so the operator never holds a standing grant.

  • Buy (Mandate_Trade): Up lots on an allowed name's current Window, from the owner's firm quote, within the premium ceiling and every grant cap. The ledger refuses anything else.
  • Sell (Mandate_Sell): only lots the desk bought, through a venue buy-back quote worth at least 92% of the attested value; proceeds go back to the desk's budget.
  • Record: every trade, sale or daily checkpoint leaves a DeskDecision and advances a hash chain, so the record can be re-verified and a forked one is refused.

A bought lot is an ordinary position of the owner's party, and a settled Window pays the owner's seat. There is no external exchange route and no real money: the desk trades this venue's own markets with demo credits.

Earlier local-sandbox evidence records a funded mandate being opened, paused, resumed, checkpointed and shared. That check did not record a trade: the runner could not obtain a model decision. This documentation pass did not establish a hosted funded desk trade. See Build a desk for the studio and Source map for where the code lives.

On this page