How the desk decides
The owner, the runner and the ledger have distinct jobs; practice desks are paper, and a live desk is a Daml mandate that trades this venue's own markets.
The desk spans the browser, an off-ledger runner and, when live, a Daml mandate on Canton. The owner picks the names and limits. The runner reads prices and proposes a buy, a sell or a checkpoint. Every decision is written down as a desk.v1 record and fingerprinted before anything moves.
The owner sets the mandate; the operator chooses only when; the ledger checks every trade.
Choose a stage to read its responsibility and authority.01 · Owner authority
02 · Decision and checks
03 · Record and settlement
Owner seat
The owner picks the pre-IPO names (their 60-minute Series), the premium ceiling and the caps, and funds the desk from the seat's demo credits.
Only the owner changes limits, deposits, withdraws or closes.
A practice desk is a paper ledger kept by the runner. A live DeskMandate has been opened, funded, paused, resumed and checkpointed on a local Canton sandbox; it has not traded there yet, because no model key was set. Demo credits only.
Download diagram Full size| Part | Authority |
|---|---|
| Owner (your seat) | Picks the names and limits; approves practice decisions by signing a message. Only the owner can unpause, change limits, withdraw or close. |
| Desk runner | Chooses timing and proposes allowed actions, as the operator party. It can pause the desk but cannot unpause it, change the owner's limits or withdraw. |
| Price reference | For a live desk, the Window's fair price posted as marks by the oracle parties: the lower median of at least two, none older than 15 minutes. |
Practice desks
A practice desk uses paper cash and an off-ledger decision record. Its price references and runner must be available for a check to complete. Check it recomputes a record's fingerprint and compares it with the stored one. The source gate for going live requires six hourly practice checks. The hosted desk created on 8 October was still waiting for its first check; no valuation or completed decision was observed.
The live desk
A live desk is a DeskMandate the owner opens with their own demo credits, signed by the owner and the venue. It holds the allowed names, a premium ceiling and an agent grant with its caps (per trade, per day, budget, open positions), kept inside the mandate so the operator never holds a standing grant.
- Buy (
Mandate_Trade): Up lots on an allowed name's current Window, from the owner's firm quote, within the premium ceiling and every grant cap. The ledger refuses anything else. - Sell (
Mandate_Sell): only lots the desk bought, through a venue buy-back quote worth at least 92% of the attested value; proceeds go back to the desk's budget. - Record: every trade, sale or daily checkpoint leaves a
DeskDecisionand advances a hash chain, so the record can be re-verified and a forked one is refused.
A bought lot is an ordinary position of the owner's party, and a settled Window pays the owner's seat. There is no external exchange route and no real money: the desk trades this venue's own markets with demo credits.
Earlier local-sandbox evidence records a funded mandate being opened, paused, resumed, checkpointed and shared. That check did not record a trade: the runner could not obtain a model decision. This documentation pass did not establish a hosted funded desk trade. See Build a desk for the studio and Source map for where the code lives.