Capital allocation
The most capital an agent may commit, in total and per market.
Cortex intelligence
Cortex is the policy-bound AI trading and intelligence layer of ORBITRA ONE™. Its agents observe markets and portfolios, reason over approved data and propose actions — then act only within permissions you grant, explain every decision and stop on a single command.
The governed loop
No agent reaches the market directly. Every intent is simulated and authorized before it can execute.
A governed loop in six steps: Observe (market and portfolio), Reason (a model ensemble), Propose (a trade intent), Simulate (Aegis risk), Authorize (the policy engine) and Execute (ApexMatch). Eight policy gates surround the loop — capital, loss, leverage, markets, time, action, data and kill. A proposal reaches execution only after clearing every gate that applies to it, and the kill control can stop the loop at any step.
Two modes of intelligence
Thinking and acting are separate paths in Cortex. An agent may explore any idea; turning one into an order takes authority you have granted.
Scope
Inputs
Output
Authority
Evidence
Policy controls
Policies are set per agent, versioned and enforced at the authorization step — outside the agent’s own code, so an agent cannot rewrite its limits.
The most capital an agent may commit, in total and per market.
Hard stops on loss per day and across the agent’s life. At either limit, trading stops.
A cap per instrument, set at or below what your account allows.
The instruments an agent may trade, and those it must never touch.
Trading windows, plus an end date after which authority lapses.
Which actions wait for your approval before they are sent.
Only approved feeds and datasets can inform an executable intent. Other sources stay in research.
A single command halts the agent and withdraws every permission it holds.
Explainable actions
A Cortex proposal is never a bare instruction. It states why the agent wants to act, what Aegis expects the action to do to your portfolio and which data informed it — so you judge the reasoning, not only the outcome.
Every action, including one the policy rejects, produces a verifiable action receipt: a signed record of which agent acted, under which policy version, on what simulated risk and authorization, and with which orders and fills. A receipt can be checked without trusting the agent that produced it.
AEGIS
Unified risk graph
Select a risk dimension
Collateral · Volatility · Liquidity · Concentration · Correlation · Counterparty
Human confirmation
Confirmation modes are set per agent and can differ by market and action type. Institutions can require four-eyes approval for any policy change.
The agent prepares a complete intent with its reason, risk and sources. Nothing is sent until you place it yourself.
Every intent waits for your approval on a signed-in device, and expires if its window closes first.
Small in-policy actions proceed. Anything above the size, leverage or loss impact you set waits for you.
The agent acts without prompts inside its full policy. Every action still leaves a receipt for review.
Kill and revocation
One command stops the agent and revokes its authority.
The kill path does not depend on the agent’s cooperation. It halts new actions, withdraws the agent’s resting orders and revokes its permissions at the identity layer, so its signatures are no longer accepted for your account. Existing positions stay under your control and your Aegis protection policies.
Connected layers
Automation, including AI-assisted automation, can fail or behave unexpectedly, and you remain responsible for the permissions you grant. Cortex access depends on jurisdiction and eligibility.