Governed portfolio intelligence for unstable regimes

ATLAS

A regime-aware decision system that measures structural state, tactical instability, confidence, disagreement, portfolio risk, and allocation constraints within one auditable framework.

Designed to know when to allocate, when to reduce risk, and when not to act.


Regime intelligence

Structural regime, transition geometry, velocity, acceleration, and persistence over macro-financial state space.

Tactical instability

Flip risk, confidence decay, disagreement, and fast reversible controls that restrict exposure without redefining regime.

SHELOB allocation

Governed portfolio and sleeve allocation under uncertainty, constraints, and explicit decision authority.

AI briefings

Machine-readable briefing selection and governed narrative generation from authoritative system state.

Audit and governance

Model-change audit, pipeline lineage, provenance, freshness controls, reason codes, and operator authority.

Abstention

Explicit transitional and indeterminate states with explainable triggers, episode lifecycle, and outcome assessment.

Self-Service Demo

Explore ATLAS with sample portfolio data in a sandboxed demo environment. No account required. Demo sessions use delayed market data and include no live portfolio information.

What ATLAS Is

ATLAS is decision-support infrastructure for portfolio governance and macro-regime monitoring. It is used to manage exposure to uncertainty in global markets.

Rather than forecasting short-term prices, ATLAS measures whether the current macro-financial environment is stable, transitional, or indeterminate; whether confidence in that assessment is rising or decaying; and whether the resulting posture should be to allocate, reduce, or abstain.

  • Regime-aware. The structural regime is a slow, persistent classification of macro conditions, estimated on a declared calibration window and held out from live evaluation.
  • Uncertainty-aware. Confidence, flip risk, score disagreement, and data freshness are explicit inputs to the admissibility map, not afterthoughts.
  • Governed. Every artifact carries schema, keys, dates, provenance, and freshness state. Overrides require operator identity and reason codes.
  • Abstention-first. When evidence is insufficient or unstable, the legitimate output is to reduce or abstain. Abstention is tracked, attributed, and evaluated after the fact.

What ATLAS Is Not

  • ATLAS is not a trading bot or execution engine.
  • ATLAS is not a short-term market-prediction system.
  • ATLAS is not a signal-stacking or black-box alpha platform.
  • ATLAS does not convert every analytical result into a trade.

The system provides a structured, auditable framework for evaluating macroeconomic conditions and portfolio alignment across regimes. Analytical strength does not automatically create operational authority.

SHELOB: Governed Allocation Under Uncertainty

SHELOB is ATLAS's governed allocation and portfolio-construction capability. It combines portfolio mathematics with structural regime state, tactical instability, sleeve constraints, optionality requirements, and explicit decision authority.

  • More than an optimizer. The live allocation baseline (TILT) is governed and produced by the pipeline. Shadow optimizer families (MVO, Black-Litterman, equal-weight) run as diagnostics and counterfactuals, not as live instructions.
  • Regime- and confidence-aware. Target changes are gated by abstention state, tactical instability, and portfolio constraints. An unstable or indeterminate state can block or scale a proposed adjustment.
  • Constraint-bound. Sleeve limits, single-position caps, liquidity-tier scalers, and cash-absorption rules are enforced before any target is emitted.
  • Descriptive outputs. SHELOB surfaces explain weights, availability, and readiness; the ANDURIL allocation overlay returns an explanatory permission and reason stack, not trade instructions.
  • Fail-closed. Missing inputs, stale data, unresolved disagreement, or an inactive governance posture routes the output to a restricted or informational state.

Read the SHELOB formalization in the Technical Specification →

AI Briefings: Governed Narrative from Machine-Readable State

ATLAS exposes its governed state through a machine-readable briefing catalog. Structured requests are resolved to approved briefing types, populated from authoritative artifacts, checked against policy and entitlement constraints, and rendered as human-readable analysis.

  • Catalog-driven. Briefing types, required payload fields, and policy boundaries are registered in a closed vocabulary before any prose is generated.
  • Parser-based. A structured adapter resolves requests to the correct briefing builder, validates inputs, and enforces guardrails.
  • Governed context. The AI layer reads pre-computed artifacts—regime state, tactical instability, portfolio health, optionality, governance status—not live market feeds or internal paths.
  • Policy-checked. Forbidden intents, trade-generation language, and allocation authority are blocked by construction.
  • Same facts, multiple surfaces. The same governed context can produce operator briefs, sidebar narratives, audit appendices, and research diagnostics.

The AI layer explains governed system state; it does not create the state.

Advanced Capabilities

Measure

  • Structural and tactical horizon separation
  • Cross-asset score trajectory and geometry
  • State velocity, acceleration, and persistence
  • Confidence decay and transition risk
  • Cross-model disagreement
  • Portfolio and sleeve health

Decide

  • Allocate / Reduce / Abstain posture map
  • Abstention episode lifecycle
  • SHELOB governed allocation baseline
  • Shadow optimizer counterfactuals
  • Optionality and protection planning
  • Stress and risk analytics

Govern

  • Tenant-aware routing and operator scope
  • Reason-coded overrides with expiry
  • Promotion committee and candidate evaluation
  • Model-change reader and changelog
  • Research-to-production separation
  • Production / beta / shadow boundary

Explain

  • Machine-readable AI briefing catalog
  • Structured parser and context contract
  • Layered decision explanation
  • Pipeline manifests and provenance
  • Freshness and staleness labels
  • Truthfulness contract per surface

Why Trust ATLAS

Every decision has a lineage

  • Governed source data and versioned analytical artifacts
  • Explicit freshness and observability labels
  • Model, schema, and stage-definition versions
  • Decomposed decision logic and reason-coded restrictions
  • Operator-attributed overrides with provenance
  • Reproducible pipeline runs and run manifests

Research does not equal authority

  • Lab, shadow, validation, approval, and production are separate states
  • Inconclusive and falsified results remain visible
  • No new model receives decision authority by default
  • Promotion is an explicit, operator-gated event

AI explains; governance decides

  • Machine-readable briefing parser and catalog
  • Governed context populated from authoritative artifacts
  • Policy and entitlement checks before rendering
  • No independent allocation or trading authority

Development Status

Production · governed Beta · canary Shadow · diagnostics

ATLAS runs in production for governed regime monitoring, portfolio state, and operator-isolated decision tooling. The beta environment hosts canary surfaces and experimental capabilities. Shadow and diagnostic outputs are labeled and do not carry decision authority.

Pricing

For pricing inquiries, institutional licensing, and operator onboarding, please visit the Contact page.

Updates

Release notes and development milestones


May 2026 Production

Production Update — Decision Ledger, Surface Honesty & Calibrated Caution

A production update is live at app.atlas-portal.ca. The release sharpens how ATLAS represents what it knows, what it does not know, and how the platform talks to operators about both.

  • Unified decision ledger. Decisions, realized economics, regime context, and forward evidence now live behind a single auditable surface, so that the end-to-end story of any decision — from input artifact to outcome — can be reviewed in one place. The unified ledger is a measurement and audit reference; it has no allocation authority of its own.
  • Surface-level truthfulness. Decision-facing panels now declare their evidence basis explicitly, indicating whether a view is backed by live governance, a shadow replay, a diagnostic model, or insufficient evidence. Missing or stale inputs surface as labeled states rather than silent fallbacks.
  • Calibrated caution. The platform now maps measurement-uncertainty states to a graduated, minimal-response policy. Where the system cannot yet make a confident statement, it says so, and the appropriate degree of caution is recorded against the abstention ledger for outcome evaluation.
  • Research discipline for new strategy contexts. Candidate trend and momentum strategy contexts are now tracked through a formal evidence dossier — forward evidence, reconstructed historical evidence, and live-portfolio context — before any promotion into governance. Authorization gates are explicit and time-bound; nothing promotes itself by default.
  • Adversarial review of decision-facing surfaces. A broad audit was run across the platform’s advisory and shadow surfaces, looking specifically for ways a panel could imply a claim it could not back. Findings were closed before the release shipped.
  • Operator-visible pipeline state. Pipeline telemetry, run health, and tenant-aware run identifiers are now consistently visible across observability surfaces, so operators can tell at a glance whether what they are reading is current, partial, or stale.
April 2026 Production

Production Update — Multi-Operator Governance, Pipeline Reliability & Structural Forecasting

A major production update is now live at app.atlas-portal.ca. The release brings ATLAS’s multitenant governance posture, pipeline reliability, and structural forecasting capabilities to production grade.

  • Multi-operator governance. Operator and sleeve identity now flow end-to-end through the platform. Overrides, audit trails, entitlements, and portfolio visibility are isolated by operator context, so each operator sees and acts on only their own scope.
  • Structural forecasting in production. Regime flip-probability estimation, persistence modeling, and hazard-rate diagnostics are now operational in production across multiple forward horizons. Forecasts are surfaced as diagnostic context, separated from exposure policy.
  • Forecast calibration. A dedicated calibration artifact now measures how well structural forecasts have matched realized outcomes across horizons, so the platform can be honest about where its forecasts have been reliable and where they have not.
  • Fail-fast pipeline. The pipeline now validates governance readiness, configuration, and stage prerequisites before expensive computation begins. Problems surface immediately at startup rather than late in a run.
  • One source of truth for abstention. Abstention state was consolidated behind a single authoritative source feeding both the UI and portfolio gating, eliminating the possibility of disagreement between views.
  • More robust portfolio ingest. Multi-file upload handling, timestamp safety, and collation were hardened, reducing operator friction during portfolio refreshes.
  • Forecast observatory. Structural-transition surfaces, horizon-specific transition probabilities, and forecast diagnostics now render consistently across the operator UI.
  • Abstention economics. Regime-conditioned breakdowns and the abstention economics panel were restored, including episode outcome classification and false-caution tracking by regime.
  • Sleeve-scoped optionality. The optionality view is now strictly scoped to the selected sleeve, with no silent fallback to an aggregate view when sleeve context is missing.
  • Production infrastructure. Entitlements infrastructure was modernized with automated migration and operator backfill, provenance guarding was added for containerized runs, and deployment tooling was extended to support the multitenant production surface.
March 26, 2026 Beta

Beta v2 — Regime-Conditioned Model, GitPortfolio & Forecasting

A new beta version is now available at beta.atlas-portal.ca incorporating significant new capabilities:

  • Regime-Conditioned Model — Portfolio analytics and risk assessments are conditioned on the latest classified macro regime, with its as-of date.
  • GitPortfolio — Live portfolio replay and counterfactual analysis. Track how portfolio decisions would have played out under alternative regime paths and allocation strategies.
  • Forecasting — Forward-looking regime-transition probability modeling and macro-forecasting tools for scenario planning and exposure management.
March 16, 2026 Site

Site Launch — Cross-Asset Regime Model

ATLAS Portal is live. The initial release introduces the core cross-asset regime classification model — a system for detecting structural regime shifts, systemic stress, and instability across global financial markets.

  • Cross-asset regime classification and confidence scoring
  • Multi-signal macro stress monitoring
  • Regime flip-risk estimation and transition probability modeling
  • Portfolio exposure alignment diagnostics
  • Audit logging and governance tooling built toward an institutional standard

Technical Specification

Formal model objects, governance, and admissible decision rules


1. System Objective

ATLAS is a measurement and decision-governance system for portfolio exposure under uncertainty. It does not maximize a point-estimate return. Its objective is to manage exposure when structural macro conditions and tactical classification certainty are unstable.

A decision at time \(t\) is a function of structural state, tactical instability, confidence, disagreement, portfolio constraints, and governance state:

\[ \text{Decision}_t \;\in\; \mathcal{D}\! \left( S_t,\; T_t,\; C_t,\; D_t,\; \mathcal{K}_t,\; G_t \right) \]

where \(S_t\) is structural regime, \(T_t\) is tactical instability, \(C_t\) is confidence, \(D_t\) is disagreement, \(\mathcal{K}_t\) is the set of portfolio and sleeve constraints, and \(G_t\) is governance state.

The admissible decision space is

\[ \{\,\text{allocate},\; \text{reduce},\; \text{hedge},\; \text{hold},\; \text{abstain}\,\} \]

In the current implementation the live posture set is \(\{\mathrm{Allocate},\; \mathrm{Reduce},\; \mathrm{Abstain}\}\). Hold is the absence of a target change; hedge is implemented through the optionality-protection workflow. Abstention is a first-class governed result, not an error condition.

ATLAS manages exposure to uncertainty. It does not assert that any analytical output is a profitable trade.

2. Structural Regime and Tactical Instability

2.1 Structural regime

The structural regime is a slow, persistent classification of the macro-financial environment. In the live implementation the score axes are growth, inflation, risk appetite, and liquidity. Conceptually:

\[ S_t \;=\; f_S\!\left(Z_{1:t},\; \Theta_S,\; G_t\right) \qquad Z_t \;=\; \left(z_{\text{growth},t},\; z_{\text{inflation},t},\; z_{\text{risk},t},\; z_{\text{liquidity},t}\right) \]

\(\Theta_S\) denotes governed structural parameters, including the transition matrix \(P\) with \(P_{ij} = \mathbb{P}(S_{t+1}=j \mid S_t=i)\). The regime is estimated on a declared calibration window and is held out from out-of-sample evaluation. Persistence is enforced by construction: the structural layer is not redefined by short-run tactical motion.

2.2 Tactical instability

Tactical instability is a fast, reversible overlay on the structural regime. It measures whether classification certainty is stable, deteriorating, or unobservable. The live implementation classifies each day as Stable, Transitional, or Unstable from:

\[ T_t \;=\; f_T\!\left(F_t,\; \Delta^2 F_t,\; C_t,\; \Delta C_t,\; D_t^{\,\text{score}},\; N_t,\; G_t\right) \]

where \(F_t\) is flip risk, \(\Delta^2 F_t\) is flip-risk acceleration, \(C_t\) is confidence, \(\Delta C_t\) is confidence change, \(D_t^{\,\text{score}}\) is score disagreement, and \(N_t\) is an NA-driven indicator. NA-driven or inadmissible inputs fail closed: they cannot resolve to Stable.

Layer separation. Tactical instability may restrict or override exposure, but it does not redefine the structural regime. The map \(f_S\) does not take \(T_t\) as an argument.

3. Regime Topology and State Evolution

ATLAS measures not only the current regime level but also movement through score space. Where supported by diagnostic artifacts, the score vector \(\tilde{Z}_t\) in a three-dimensional embedding is tracked over time:

\[ \tilde{Z}_t \;=\; \left(z_{1,t},\; z_{2,t},\; z_{3,t}\right) \]

Finite-difference kinematics are computed on this embedding:

\[ V_t \;=\; \Delta \tilde{Z}_t, \qquad A_t \;=\; \Delta^2 \tilde{Z}_t \]

The following geometric quantities are produced by diagnostic producers. They are descriptive, not decision-authoritative, unless explicitly noted:

QuantityProducerStatusDecision authority
position \(\tilde{Z}_t\)score pipelineLIVElive input to regime and confidence
velocity \(\|\Delta \tilde{Z}_t\|\)regime_geometry_diagnostics_dailyDIAGNOSTICnone
acceleration \(\|\Delta^2 \tilde{Z}_t\|\)regime_geometry_diagnostics_dailyDIAGNOSTICnone
curvature proxyregime_geometry_diagnostics_dailyDIAGNOSTICnone
directional stabilityregime_geometry_map_dailyDIAGNOSTICnone
distance to boundaryregime_geometry_map_dailyDIAGNOSTICnone (geometric confidence is shadow)
distance to centroidregime_geometry_map_dailyDIAGNOSTICnone
tortuosity ratioregime_geometry_map_dailyDIAGNOSTICnone
persistence bandregime_geometry_map_dailyDIAGNOSTICnone
transition entropyregime_geometry_map_dailyDIAGNOSTICnone

The live confidence and flip-risk objects use the margin form on the structural-score axes (Section 4 and 5), not the geometric distance form above. Geometry is an interpretability layer; it does not gate allocations.

4. Confidence and Transition Risk

Confidence is proximity to a decision boundary, adjusted for measurement uncertainty, persistence, disagreement, and data validity. The live implementation uses a score-margin form:

\[ C_t \;=\; \min_{s \neq s'}\, \big|\, M_s(Z_t) - M_{s'}(Z_t) \,\big| \]

where \(M_s(Z_t)\) is the margin assigned to structural state \(s\). A geometric distance to the decision boundary \(\Gamma\),

\[ d(Z_t, \Gamma) \;=\; \inf_{g \in \Gamma} \|Z_t - g\| \]

is computed as a SHADOW research diagnostic and is not wired into the admissibility map. In both formulations \(C_t \downarrow 0\) as \(Z_t \to \Gamma\).

Confidence is decomposed conceptually as

\[ C_t \;=\; f\!\left(d_t,\; U_t,\; P_t,\; D_t,\; Q_t\right) \]

where \(d_t\) is boundary distance, \(U_t\) is measurement uncertainty, \(P_t\) is state persistence, \(D_t\) is model or score disagreement, and \(Q_t\) is data quality/freshness. The live code does not collapse these into one scalar; each contributes separately to abstention admissibility.

5. Flip Risk and Transition Pressure

Flip risk is a decomposed transition-risk measure. It is high when the score vector is near a regime boundary and moving quickly. The live series is computed as

\[ F_t \;=\; \phi\!\left(C_t,\; \Delta Z_t,\; \Delta^2 Z_t,\; G_t\right) \]

with the properties that \(F_t\) is non-increasing in confidence and non-decreasing in score velocity. Flip-risk acceleration \(\Delta^2 F_t\) is one of the three live abstention triggers.

Flip risk is therefore not a directional forecast. It is a pressure indicator: the combination of boundary proximity and motion raises the chance that the structural assessment may need to change. Static threshold crossings alone are insufficient; change and acceleration matter more than level.

6. Disagreement

Score disagreement is the range across the structural-score axes used in the live admissibility map:

\[ D_t^{\,\text{score}} \;=\; \max_{i} Z_{i,t} \;-\; \min_{i} Z_{i,t} \]

A large spread means the macro signals are sending inconsistent messages, which reduces confidence in any single structural label. \(D_t^{\,\text{score}}\) is a live input to abstention.

Surface disagreement, the indicator that two classification surfaces assign different structural labels, is measured but not wired into the live admissibility map. It remains a research track (WS7).

7. Abstention Mathematics

7.1 Abstention triggers

The live abstention engine evaluates three primary triggers:

  • Confidence shock. A large absolute or percentage drop in \(C_t\) below configured thresholds.
  • Flip-risk acceleration. A large second difference \(\Delta^2 F_t\) indicating rising transition pressure.
  • Score disagreement. \(D_t^{\,\text{score}}\) exceeding a configured spread threshold.

Additional abstention drivers include stale or incomplete data (\(N_t=1\) or \(G_t=\mathrm{INADMISSIBLE}\)), an unresolved structural transition, and governance restrictions such as operator-imposed holds or unauthorized sleeves.

7.2 Meta-regimes

Two meta-regimes are distinguished conceptually:

Meta-regimeMeaningLive mapping
TRANSITIONALMotion is coherent, but a stable destination is not yet established.T_t = Transitional with measured triggers and severity_observability = COMPUTED
INDETERMINATEEvidence is inconsistent, incomplete, unstable, or insufficiently resolved.T_t = Transitional driven by NA_FAIL_CLOSED, INSUFFICIENT_HORIZON, or EVIDENCE_UNAVAILABLE

The implementation records the evidence basis explicitly so that an indeterminate state cannot masquerade as a measured transitional state.

7.3 Abstention response

When abstention is admissible, the system may respond with one or more of:

  • capital preservation (no new exposure);
  • gross reduction of existing risk (e.g., the graded Reduce posture);
  • optionality retention or hedge ladder review;
  • delayed commitment until persistence conditions are met;
  • constrained allocation within tightened bounds;
  • operator review and explicit override.

7.4 Outcome assessment

After an abstention episode ends, the outcome is classified at a pre-registered horizon:

  • Justified Caution (JC): forward drawdown exceeded tolerance, so abstaining avoided realized loss.
  • False Caution (FC): forward drawdown remained within tolerance, so abstaining was unnecessary.
  • Inconclusive (IN): insufficient forward data or intermediate outcome.

These labels feed the LANTERN shadow confusion matrix and the abstention economics diagnostics. They are measurement, not policy.

8. Allocation and SHELOB

SHELOB is the governed allocation and portfolio-construction layer. The name is an internal identifier; its role is to produce and explain allocation outputs under regime state, uncertainty, constraints, and governance. It is not an autonomous allocator.

8.1 Optimizer families

FamilyStatusRole
TILTLIVE_AND_GOVERNEDCurrent policy baseline produced by portfolio_targets and consumed by operator surfaces.
MVOSHADOW_OR_RESEARCHMean-variance diagnostic; security weights are bucket-proxy approximations.
Black-LittermanSHADOW_OR_RESEARCHDiagnostic counterfactual; not a live instruction.
EQWSHADOW_OR_RESEARCHEqual-weight reference; availability is honest-empty when the comparator artifact is missing.

8.2 Governed optimization problem

The portfolio-target stage solves a constrained allocation problem. A generic formulation that matches the implementation is:

\[ \min_w \quad \frac{1}{2}\, w^{\top} \Sigma w \;-\; \lambda \, \mu^{\top} w \;+\; \mathcal{P}(w) \]

subject to

\[ A w \;\le\; b, \qquad \mathbf{1}^{\top} w \;=\; 1, \qquad w_{\min} \;\le\; w \;\le\; w_{\max} \]

where \(\Sigma\) and \(\mu\) are inputs, \(\mathcal{P}(w)\) captures penalty terms, and the linear constraints \(Aw \le b\) encode sleeve limits, concentration bounds, liquidity-tier scalers, and optionality gates. The default single-position cap is 20%. Cash absorption is used to renormalize after liquidity scaling.

8.3 From optimizer output to operative allocation

The operative allocation is not merely the mathematical optimizer output. It passes through:

  • regime interpretation and tactical-instability gating;
  • uncertainty controls (confidence, flip risk, disagreement);
  • governance constraints and reason codes;
  • data-validity checks and freshness labels;
  • model-change controls and promotion state;
  • operator-authorized overlays, if any.

The ANDURIL allocation overlay attaches to the decision-state response as an explanatory permission and reason stack. It emits no weights, targets, or trade instructions. NORMAL permission is only reached when every lane is positively confirmed clear; missing or unstable data fails closed to NO_ALLOCATION_ADVICE.

8.4 Infeasibility and audit trace

If constraints are mutually inconsistent, the target generator reports infeasibility through reason codes rather than emitting an ungoverned allocation. Every SHELOB surface is descriptive-only: it explains weights, availability, and readiness. Audit trace includes model family, artifact version, constraint set, and the governance state at the time of generation.

9. Pipeline and Artifact-First Architecture

ATLAS is built as an artifact-first pipeline. Derived analytics are pre-computed, schema-validated, and written as versioned artifacts before any UI or API consumer reads them. The logical sequence is:

source data → validated ingest → governed features → analytical producers → versioned artifacts → decision-state assembly → API contracts → UI rendering

Key consequences of this architecture:

  • Downstream consumers read governed artifacts; they do not recompute analytics.
  • Schema validation occurs at ingest and at artifact boundaries.
  • Keys must be unique; dates use consistent classes; missing columns fail fast.
  • Latest-available data is distinguished from incomplete current-day data.
  • Stale data remains visibly stale.
  • Production and research artifacts are stored in separate paths (derived_governance vs. derived_shadow).
  • Pipeline manifests identify exactly what ran.

Each pipeline run produces a run manifest (schema version 2) with, where available:

run_id, as_of_date, artifact_version, schema_version, producer_version, source_git_sha, source_image_digest, stage_definition_version, source_lineage, freshness_state, validation_state, environment, tenant

The run manifest is observational and non-blocking: a manifest failure does not abort the pipeline, but it is recorded honestly. Artifact content hashes (SHA256) are written to pipeline_artifact_hashes_daily.parquet for later provenance queries.

10. Model-Change Auditing

Model changes are treated as governed events rather than ordinary code edits. A candidate model is evaluated against a baseline:

\[ \Delta M \;=\; M_{\text{candidate}} \;-\; M_{\text{baseline}} \]

Across dimensions that include:

  • output differences and regime-state changes;
  • confidence changes and flip-risk changes;
  • allocation changes and abstention changes;
  • constraint breaches and missing-data behavior;
  • historical replay and null/placebo tests;
  • staleness behavior and computational reproducibility.

10.1 Change classification

Changes are classified by scope. The repository uses a version scheme of {generation}.{revision}.{calibration} and a changelog in config/model_changelog.yml. Conceptually:

ClassMeaning
NO_SEMANTIC_CHANGENo effect on analytical outputs.
DISPLAY_ONLYUI rendering change; no artifact change.
SCHEMA_CHANGEColumn, type, or contract change.
FEATURE_CHANGENew or removed derived feature.
PARAMETER_CHANGEThreshold, window, or scalar change.
MODEL_CHANGEEstimator, regime map, or inference change.
DECISION_POLICY_CHANGEAdmissibility map or posture mapping change.
GOVERNANCE_CHANGEAuth, promotion, or override rule change.

10.2 Change attribution

The system attempts to attribute an observed output change to one of: changed source data, data revision, schema change, code change, model version, parameter change, calibration-window change, operator override, or environment change. The R/helpers_ai_state_model_change.R reader produces daily-lag deltas with direction labels and closed-vocab status (AVAILABLE, MISSING, SCHEMA_INVALID, NOT_EVALUABLE, STALE, DEGRADED, UNKNOWN).

10.3 Promotion states and stop conditions

The promotion committee evaluates candidate changes against required gates. Verdicts include PROMOTE, REJECT, and HOLD. Candidate statuses include SHADOW, CANDIDATE, EVIDENCE_ACCUMULATING, PROMOTION_READY, PROMOTED, ACTIVE, and BLOCKED. A negative, inconclusive, or unstable result is a legitimate endpoint: a model is not promoted merely because it is newer.

There is currently no governed model-change ledger artifact. The model-change reader exists and is tested, but the endpoint that would surface a ledger returns an honest-empty response.

11. Governance Mathematics

Governance determines whether an analytical result is informational, research-only, shadow, restricted, actionable, operator-required, or blocked. Action authority is a function of:

\[ A_t \;=\; \mathcal{G}\!\left(E_t,\; V_t,\; F_t,\; R_t,\; O_t\right) \]

where \(E_t\) is entitlement state, \(V_t\) is data and model validity, \(F_t\) is freshness, \(R_t\) is research or production status, and \(O_t\) is operator authorization. The resulting authority level is drawn from a closed set:

INFORMATIONAL, RESEARCH_ONLY, SHADOW, RESTRICTED, ACTIONABLE, OPERATOR_REQUIRED, BLOCKED

Analytical strength does not automatically create operational authority. A validated model with stale inputs may be restricted; a shadow model with current inputs has no decision authority.

Governance enforcement includes:

  • reason codes for every restriction or override;
  • expiry timestamps on overrides;
  • actor identity and tenant context;
  • approval boundaries and break-glass write gates;
  • append-only audit logs;
  • production versus beta separation;
  • fail-closed behavior and no silent fallbacks.

The governance override write seam is live in non-production environments; production contexts are forbidden by construction.

12. Auditability and Provenance

ATLAS is designed so that any decision can be reconstructed. A reviewer should be able to answer:

  • What data were available?
  • Which versions were used?
  • Which pipeline ran?
  • Which artifacts were produced?
  • Which model produced the result?
  • Which constraints applied?
  • Was the result stale?
  • Was the result research-only or actionable?
  • Was there an override? Who authorized it?
  • What changed from the prior run?

Provenance mechanisms include:

  • append-only run manifests and artifact registries;
  • per-artifact SHA256 content hashes;
  • model identifiers and experiment identifiers;
  • source hashes and actor IDs;
  • reason codes and environment tags;
  • tenant scope and run-id provenance classification;
  • run provenance linkage with reproducibility verdicts (REPRODUCIBLE, PARTIALLY_REPRODUCIBLE, NOT_REPRODUCIBLE, INDETERMINATE).

The provenance API surfaces the artifact hash table. Historical reproducibility is explicitly marked as partial or indeterminate when source commit, image digest, or stage-definition anchors are missing.

13. Machine-Readable AI Briefing Architecture

AI prose in ATLAS is downstream of governed facts. The architecture is:

governed analytical artifacts → briefing catalog → briefing context contract → intent and policy guardrails → machine-readable parser → structured briefing request → generated narrative → traceable response

Key components:

  • Briefing catalog. R/helpers_ai_state_registry.R registers briefing types such as CURRENT_SYSTEM_STATE, PORTFOLIO_OVERLAY_STATE, OPTIONALITY_STATE, with prompt versions, required payload fields, permission scope, and live-call policy.
  • Context contract. R/helpers_ai_state_payload.R builds a governed JSON payload from artifacts including freshness, decision_outcomes_ledger_daily, abstention_now, and regime_overlay_state_daily.
  • Parser/adapter. R/helpers_ai_state_adapter_contract.R and R/helpers_ai_state_briefing_context.R provide a machine-readable adapter and context builder with closed vocabularies and schema versions.
  • Policy guardrails. Forbidden intents are scanned; trade-generation and target-mutation language are blocked; the output is marked descriptive_only = TRUE and allocation_authorized = FALSE.
  • Live-call gate. The operational LLM route is gated by an environment flag and an API key. In the current deployment it fails closed with OPENAI_KEY_UNAVAILABLE.

The governed /v1/ai-briefing route reads a persisted artifact that is not currently materialized, so it returns AI_BRIEFING_SOURCE_MISSING. The legacy Shiny AI Briefing tab remains functional but is explicitly not integrated into the ARAGORN API. The machine-readable catalog and parser capability is implemented and tested; full end-to-end wire integration is still in progress.

The AI layer explains governed system state; it does not create the state and has no independent authority to change allocation.

14. Data Freshness and Validity

Scientific status and data validity are orthogonal. A validated method may be unusable when its inputs are stale. The following matrix is a public abstraction of the internal freshness and artifact-status logic:

Scientific statusData statusOperational interpretation
ValidatedCurrentMay be actionable if authorized
ValidatedStaleRestricted or informational
ValidatedMissingUnobservable / blocked
InconclusiveCurrentResearch-only
ShadowCurrentNo decision authority

Artifact statuses include OK, STALE, DEGRADED, MISSING, and CONTENT_STALE. Downstream artifacts inherit upstream non-OK states rather than masking them. Yesterday's regime state does not appear as current without an explicit freshness annotation.

15. Limitations

The following limitations are stated explicitly to prevent inferential drift:

  • Regime classification is uncertain; historical relationships may change.
  • Model outputs depend on data quality, revisions, and the completeness of cross-asset inputs.
  • Regime topology describes geometry, not causality.
  • Confidence is not certainty; a high-confidence day can still precede a regime change.
  • An optimizer does not eliminate model risk or tail risk.
  • AI briefings summarize governed state but may still require human review.
  • Research and shadow results do not automatically become production controls.
  • No model can remove tail risk.
  • Abstention can be costly as well as protective.
  • The governed AI-briefing artifact is not currently materialized; the operational LLM route is not active.
  • Model-change auditing has a reader but no governed ledger artifact yet.
  • Artifact retention and quarantine policy is descriptive and not enforced by an automated state machine.

16. Public Mathematical Glossary

Symbols introduced in this specification and their live status. Implementation status is one of LIVE, LIVE labeling, SHADOW, DIAGNOSTIC, or RESEARCH.

SymbolDomainInterpretationStatus
\(t\)\(\mathbb{Z}_{\ge 0}\)decision time indexLIVE
\(S_t\)finite \(\mathcal{S}\)structural regimeLIVE
\(T_t\)\(\{\text{Stable},\text{Transitional},\text{Unstable}\}\)tactical instability stateLIVE
\(Z_t\)\(\mathbb{R}^k\)structural-score vectorLIVE
\(C_t\)\(\mathbb{R}_{\ge 0}\)confidence (margin form)LIVE
\(F_t\)\([0, F^{\max}]\)flip-risk / transition pressureLIVE
\(\Delta^2 F_t\)\(\mathbb{R}\)flip-risk accelerationLIVE
\(D_t^{\,\text{score}}\)\(\mathbb{R}_{\ge 0}\)score-axis disagreementLIVE
\(D_t^{\,\text{surface}}\)\(\{0,1\}\)surface-label disagreementRESEARCH
\(N_t\)\(\{0,1\}\)NA-driven indicatorLIVE
\(G_t\)governance stateadmissibility / authorityLIVE
\(\pi_t\)\(\{\text{Allocate},\text{Reduce},\text{Abstain}\}\)policy postureLIVE
\(\mathcal{K}_t\)constraint setsleeve / concentration / liquidity boundsLIVE
\(w\)portfolio weightsallocation decision variableLIVE (TILT); SHADOW (MVO/BL/EQW)
\(\tilde{Z}_t\)\(\mathbb{R}^3\)diagnostic score embeddingDIAGNOSTIC
\(V_t, A_t\)\(\mathbb{R}^3\)diagnostic velocity / accelerationDIAGNOSTIC

References

Ang, A. & Timmermann, A. (2012). Regime changes and financial markets. Annual Review of Financial Economics, 4, 313–337.

Bishop, C. M. (2006). Pattern Recognition and Machine Learning. Springer.

Chow, C. K. (1970). On optimum recognition error and reject tradeoff. IEEE Transactions on Information Theory, 16(1), 41–46.

Diebold, F. X. & Rudebusch, G. D. (1996). Measuring business cycles: A modern perspective. Review of Economics and Statistics, 78(1), 67–77.

El-Yaniv, R. & Wiener, Y. (2010). On the foundations of noise-free selective classification. Journal of Machine Learning Research, 11, 1605–1641.

Hamilton, J. D. (1989). A new approach to the economic analysis of nonstationary time series and the business cycle. Econometrica, 57(2), 357–384.

Harvey, C. R., Liu, Y. & Zhu, H. (2016). … and the cross-section of expected returns. Review of Financial Studies, 29(1), 5–68.

Popper, K. R. (1959). The Logic of Scientific Discovery. Hutchinson.

Taleb, N. N. (2007). The Black Swan: The Impact of the Highly Improbable. Random House.

Tetlock, P. E. & Gardner, D. (2015). Superforecasting: The Art and Science of Prediction. Crown.

Contact

Ask about ATLAS


0 / 2000