How we are building SigmaX.
The build roadmap for the governed Capital Action OS — the foundation we have shipped, the surfaces we are building now, what comes next, and the future that legal and governance must open.
This is not a trading roadmap. SigmaX moves no capital. Every phase hardens the layer that decides what is allowed to happen before capital moves.
The Capital Action OS: turn a signal into a mandate-checked, preflighted, human-authorized, audit-recorded capital-action candidate.
Govern, Pulse, Alpha Foundry, and Liquidity share one evidence and proof layer — not shared authority.
No custody, execution, live allocation, or customer-capital routing — by construction, not by default.
Every capability ships read-only and default-off. Any live authority is operator- and legal-gated.
What we are building, and where it stands.
- Phase 01Shipped
Governed action spine
The ActionIntent lifecycle as a system of record: signal to audit trail, recomputed or rejected by the server — never forged by a caller.
What it provesSigmaX can govern a capital-action decision end to end, produce a replayable record, and move no capital doing it.
- Signal, Decision Packet, Capital Mandate, ActionIntent, Preflight + ComplianceCheck, Approval, Route disposition, Impact & Drift
- Workspace-scoped and principal-authenticated; a foreign record is indistinguishable from an absent one
- Append-only audit and impact ledgers with provenance verification and CSV export
- Multi-approver quorum; agents may propose, never approve or execute
- Phase 02Shipped
Embeddable, partner-grade contract
Everything the spine records is reachable through a governed, documented contract — so another platform can embed the decision check without gaining an execution surface.
What it provesThe governed primitive is portable: an API, an SDK, and an approval inbox others can build on.
- ActionIntent create / query / list API, a typed SDK, and an OpenAPI contract
- SSRF-guarded webhook delivery with a signature-verify helper; idempotency keys; keyset pagination
- Embedded approval inbox; deploy-health, disaster-recovery runbook, and authenticated metrics
- Read-only import wall and no-execution guards enforced in CI
- Phase 03Building
The four wings
One intelligence layer, four separately-governed surfaces — so each keeps its own authority posture and none inherits another wing’s trust.
What it provesGovern, Pulse, Alpha Foundry, and Liquidity share evidence and proof, not permissions.
- Govern: mandate monitor, drift radar, decision records, counter-evidence, committee packets
- Pulse: an adaptive money-and-risk MRI; connectors demo-only, no external action
- Alpha Foundry: strategy proof with net-of-fees evidence, capacity limits, and stop rules
- Liquidity: a fail-closed liquidity-truth terminal
- Phase 04Building
Governed autonomy
Read-only evidence and proof loops that feed the pipeline — they surface what deserves attention; humans authorize; nothing runs itself.
What it provesAutonomy that adds evidence, not authority — every loop propose-only and default-off.
- Capital-action operator brief; mandate-registry and compliance-drift audits; ActionIntent candidate queue
- Every loop workspace-fenced, propose-only, and declared in a safety manifest
- No AI auto-approval, no scheduled capital action, no fabricated "active" status
- Legacy trading-era loops repurposed into governed evidence surfaces
- Phase 05Next
Institutional depth and proof
Move the record from inspectable to defensible — the proof a committee, an auditor, or an allocator can rely on.
What it provesOne record, many recipients — the same evidence rendered for the reviewer who needs it.
- Scenario lab, auditor packs, proof records, and a thesis library
- Counter-evidence and mandate-drift detection at depth
- Recipient-adaptive proof packets generated from a single record
- Demo and sample records always visibly separated from real evidence
- Phase 06Legally gated
Legal pathway and capital movement
The only path to any live capital movement — and it stays blocked until a legal structure and a closed execution chokepoint exist.
What it provesThis is not a feature being withheld; it is a boundary that legal and governance must open before it can exist.
- Paper and draft-handoff route dispositions are available now; no order is ever transmitted
- Customer-eligibility is structurally unreachable without an approved legal pathway
- Live execution and allocation require counsel and operator approval plus new evidence
- Capital movement lives in a separately-governed, legally-walled venture — never in the client surface
The roadmap cannot outrun the proof layer.
SigmaX can surface evidence, proof gaps, approval needs, route state, and audit references.
Humans authorize permitted candidates. Atlas and the software do not authorize capital-linked action.
SigmaX does not custody capital, submit orders, route customer capital, or manage client capital.
Any route integration requires a legal pathway, a closed chokepoint, operator approval, and new evidence.