Skip to content

Summary

Two Hermes cron jobs on hermes@192.168.0.132 run the round (the host is hermesagent; its address is DHCP-assigned and changed from .104 on 2026-09-20), weekdays, paper-only (TASTYTRADE_READ_ONLY=1, no order tools). options-round-analyst (10:31 PT) runs the regime gate, prices the book and candidates, and writes the report. report-builder (11:00 PT) turns that report into a visual HTML page and delivers a link. The exact text of both prompts is in the repository at ops/cron/, which is kept byte-identical to the live jobs.json. Change a prompt only through the procedure below.

The Round — options-round-analyst

Section What it enforces Code it relies on
REGIME GATE 0 Environment preflight, once: numpy (HAR dependency) and ~/.config/tastytrade.env (broker auth) —
0b Ex-ante regime record appended to 96-journal/regime.jsonl before anything else regime_snapshot.py: exit 0 = labelled; exit 2 = fail-closed — data missing or stale (older than 2 business days)
1 Non-zero exit or data_missing → no new risk; manage exits and rolls only; never hand-roll a label same
2 Mapping v0 decides candidate eligibility by regime. The cooling-off day is quoted from the record, never re-counted — it advances by market close, so a lagging feed freezes it. The VRP axis is sign only, and each premium-selling idea must disclose the day's vrp_size and its own ladder sigma.rn vs sigma.phys (rn ≤ phys contradicts a premium sale and must be answered). transition → no new risk; event window (CPI/FOMC/NFP within 2 trading days) → no new premium selling transition = pending or 5-business-day cooling-off after a confirmed change (implemented 2026-09-17); transition_reason names which
3 Long-vol straddle book: the edge is the exit path; EV_RN ≈ 0 at entry is the validation signature —
4 Mapping and standing kills are risk_version v0; changes are proposed as AMENDMENT-PROPOSAL in team-insights.md, never self-applied amendment process
EV PROTOCOL 1 Live marks for the watchlist and book spreads capture_snapshot.py (hard-fails on an empty capture)
2 One trades file per round, kept at hermes-pilot/trades-<date>.json; ladders from the engine only, never by hand ev_ladder.py
2a Mandatory attestation: re-execute every ladder. A non-zero exit means the ladders are not evidence ladder-binding.py (reproducibility only; applies no EV gate)
3–4 Read the engine's flags before trusting a ladder (rn_warning, UNDEFINED-RISK, a null Kelly fraction) ev_ladder.py
5 Morning news and the machine macro calendar; headlines may flip a regime assumption only with quoted evidence news_call.py; economic calendar via Xoomar (live since 2026-09-17 10:47)
TEAM STATE / BOOK Read team-insights.md in full, then append. Management acts in whole contracts: a 1-lot position cannot be halved. The book is the HOLD and TRADE entries of the newest round-content-*.json by modification time (ls -t … \| head -1; a name sort puts -evening before that day's morning file). HOLD = carried, TRADE = opened today, EXIT = closed today; a position missing from today's JSON is read as closed gen_report_viz.py renders EXIT (verified)
OUTPUT 1 Report round-content-<date>.md: REGIME RECORD first, then LADDER ATTESTATION, tape, each idea with EV and a management plan (no plan = automatic fail), kills with arithmetic —
2c / 2d The ledger is derived from the round JSON, never written by the model; approval cards are emitted for TRADE/DEFER ideas, with no card without a passing attestation and expiry always stated ledger_sync.py · M1
2 / 2b Append to team-insights.md (regime label in the header); write round-content-<date>.json with the exact field types gen_report_viz.py requires report-builder consumes 2b

The Report — report-builder

Runs after the round. It takes the round's content JSON and snapshot, builds HTML with gen_report_viz.py, serves it on loopback, and exposes it through a cloudflared quick-tunnel, delivering the URL. It fails closed: with no content JSON, or if the generator fails, it reports what failed and sends no link.

The link is public and unauthenticated. Anyone holding the trycloudflare.com URL can read the report — book, positions, marks, strategy — while the tunnel runs. The prompt says so, and it appears deliberate for mobile delivery; it is recorded here so it stays a conscious choice. The book is paper.

How the Analyst's Memory Works

Each round is a fresh session. Its only history is the files its prompt names, and the one it reads in full is team-insights.md. It does not read decisions.jsonl or regime.jsonl. So correcting the journal does not correct the analyst: a correction that must reach it goes into team-insights.md as a dated owner-correction entry (precedents 2026-09-16 and 2026-09-17). A dry run changes nothing.

Version History

Reconstructed from the archives in hermes-pilot/cron-prompt-*-applied.txt (one per version, v2 through v2.6), the jobs.json backups, jobs.json timestamps, and decisions.jsonl. Each version from v2 to v2.11 has a governance record (the archives were last inventoried at v2.6). v2.12 and v2.13 were recorded retroactively on 2026-10-09 from their apply: commits; whether their archives were written on hermes was not checked from the repository.

Version Applied Change Governance record
v1 before 2026-09-15 Pilot round: live marks, ev_ladder, news, team state; no regime layer —
v2 2026-09-15 REGIME GATE, mapping v0, straddle-book column, versioned kills, mandatory regime record 2026-09-15:hermes-cron-prompt-v2-apply
v2.1 2026-09-16 11:13 Environment preflight as step 0; snapshot moved to 0b 2026-09-16:cron-env-hardening-v2.1
v2.2 2026-09-16 14:52 OUTPUT 2b: structured round-content-<date>.json for the report builder; the report-builder job was created with it (on hermes, 2026-09-16 19:54) 2026-09-17:cron-prompt-v2.2-apply — retroactive; original approval not evidenced
v2.3 by 2026-09-16 15:12 One line: the 2b contract given exact field types (news 3-tuples, string EVs, kill 2-tuples). Archived retroactively from a backup as cron-prompt-v2.3-reconstructed-applied.txt 2026-09-17:cron-prompt-v2.3-apply — retroactive; original approval not evidenced
host move 2026-09-17 Paths rewritten /home/ysakakibara → /home/hermes (ai-rig → hermesagent) 2026-09-17:migration-to-hermes-host-verification
v2.4 2026-09-17 Trades kept in hermes-pilot/; step 2a ladder attestation; LADDER ATTESTATION in the report 2026-09-17:cron-prompt-ladder-attestation-apply
v2.5 2026-09-17 Book read from the newest round-content JSON (by mtime); HOLD/TRADE/EXIT status semantics; hand-written book prose and round-state.json retired 2026-09-17:cron-prompt-book-source-apply
v2.6 2026-09-17 VRP note: θ = 3.0 no longer cited; VRP axis sign only; per-idea rn vs phys disclosure for premium sales 2026-09-17:cron-prompt-vrp-note-apply
v2.7 / v2.8 — Proposed separately (M1 approval cards; ledger sync) and never applied on their own — both claimed step 2c, so they were merged superseded by v2.9
v2.9 2026-09-23 OUTPUT 2c derives the position ledger from the round JSON (ledger_sync.py, no model writes the book) and 2d emits M1 approval cards for TRADE/DEFER ideas, with the M1 invariant restated at the foot of the prompt 2026-09-23:cron-prompt-m1-cards-and-ledger-apply
v2.10 2026-09-24 transition_reason quoted verbatim, never re-counted (the window counts market closes, so it freezes when the close does not advance); WHOLE CONTRACTS rule — a 1-lot position cannot be halved 2026-09-24:cron-prompt-v210-apply
v2.11 2026-09-30 Long-vol archetype entry conditions RELOCATED to the mapping (regime_config.json long_vol_archetype, decision-function.md) — the prompt reads them and must not widen them; elevated vol AND backwardation split into two conditions that must both hold, with a new line stating that elevated vol WITHOUT backwardation permits no long-vol entry (stressed-flat: 0 of 132 days where realised beat implied) 2026-09-30:analyst-prompt-v211-apply
v2.12 2026-10-04 11:02 PDT Step 1a (shadow IV30) applied to the live job — added to the mirror in 3361e66 on 2026-10-01 but never applied, so the 10-02 round recorded nothing; its REPORT line also gains the same-instant fields from #49. Backup jobs.json.bak-2026-10-04-step1a; live == mirror sha 73e9335ba2e3692b (4553b28) 2026-10-04:analyst-prompt-v212-apply — retroactive; owner approval stated in the apply commit
v2.13 2026-10-05 13:59 PDT Step 2d cards typed by card_kind (entry / exit / rule-waiver) with default_on_expiry; silence never extends risk (#55, owner option b′). Backup jobs.json.bak-2026-10-05-cardkind; live == mirror sha 23df91fb52494efc (7e0203e) 2026-10-05:analyst-prompt-v213-apply — retroactive; owner decision on #55 (comment 2087)

Known Issues

  1. ~~Unrecorded changes~~ — recorded retroactively 2026-09-17. v2.2 (with the report-builder job) and v2.3 reached production with no governance record, and v2.3 with no archive. Both now have records, dated from file evidence, and v2.3 has a reconstructed archive. The records ratify the changes; they cannot show who applied them or whether anyone approved at the time — that is simply unknown. The change procedure below is what prevents a repeat.
  2. ~~BOOK CONTEXT was hand-written prose, and stale~~ — fixed in v2.5. Its intended source, round-state.json, had itself been orphaned since 2026-09-06, when its writer (the pi orchestrator) stopped, and still listed the early-September book. The book now comes from the analyst's own newest round-content JSON; round-state.json is renamed round-state.RETIRED-2026-09-17.json. Remaining weakness: the ledger is model-written, with no entry fills or dates.
  3. ~~The mapping's VRP note was unsound~~ — fixed in v2.6. It asked for a justification whenever vrp_size < 3.0, a θ the amendment review found behaves as a VIX-level filter — it would have demanded justification on ~80% of calm-regime days. The note now states that the VRP axis is sign only and requires a scale-free, per-idea disclosure instead: the ladder's trade-implied sigma.rn against its physical sigma.phys. On 2026-09-16 data that check separates ideas correctly — every long straddle had rn < phys, and the one premium sale had rn > phys by only 0.6 vol points.
  4. Journal corrections are invisible to the analyst unless mirrored into team-insights.md (see above).
  5. The report link is public (see above).
  6. The mirror can run ahead of the live job. v2.12 and v2.13 were applied without a governance record. Since v2.13, two prompt changes have merged here without being applied: 46e4db9 and 25a8090 (step 2 PRICE VERIFICATION, #41/#85). Until they are applied, ops/cron/options-round-analyst.prompt.txt is not the live text. The change procedure's step 2 (diff against the live jobs.json) is what catches this. The sha a row records is the first 16 hex digits of the prompt's sha256.

Change Procedure

  1. Edit ops/cron/<job>.prompt.txt in the repository and commit it as a proposal.
  2. Diff it against the live jobs.json text, not the repository copy, so unrecorded drift is caught before it is overwritten.
  3. Get owner approval.
  4. Apply on hermes: hold ~/.hermes/cron/.jobs.lock, back up to jobs.json.bak-<date>-<slug>, replace only that job's prompt, write atomically, keep mode 0600, and check that every other field is byte-identical.
  5. Confirm the edit survives a scheduler tick. The scheduler re-reads jobs.json before writing (verified 2026-09-17).
  6. Archive to hermes-pilot/cron-prompt-<version>-applied.txt and file a governance record in decisions.jsonl.

To roll back, restore the backup under the same lock.

Links