Stock Steward
Product guideOpen workspace
STOCK STEWARD / TECHNICAL GUIDE

A reason behind
every decision.

This guide describes the product as it exists today, the rules in its decision engine, and the wallet evidence available today, and the work required before spending is enabled.

Read-only integrations No live ordersUpdated 30 September 2026
CHAPTER 01

The model

Set boundaries, review a strategy, then practice how the agent acts or holds.

Observe

Read simulated prices in Practice or public wallet evidence on Robinhood Chain.

Check

Compare a proposal with the confirmed strategy and saved limits.

Authorize

Practice has its own fake-funds permission. Live spending remains unavailable.

Record

Keep the purchase or hold and its explanation.

CHAPTER 02

What is live today

The hosted workspace stores owner records in D1. Read-only integrations are configured; autonomous spending remains inactive.

Reviewed strategies and practiceAvailable · saved simulation

Nine Practice strategy types cover scheduled and price-based buys, price-based sales including loss limits, two-sided price ranges, and one- or multi-stock rebalancing. Review, exact approval or automatic practice, separate permission, pause/revoke, live or fixture prices, simulated clock and downloadable receipts are available. Server-side AI suggests drafts that require review. Fake balances and receipts are saved per signed-in owner, with optional background checks and safeguard scenarios. Live execution remains inactive.

Wallet code and settlement ledgerAvailable · read only

Inspect canonical wallet code and any delegation indicator. Route receipts combine observed USDG balance with owner-bound pending reservations. External spending, complete USD prices and full portfolio valuation remain unverified. Scheduled recovery verifies recorded direct-router or narrow Roles/Safe outcomes but never sends transactions.

Direct-router simulationAvailable · read only

Route inspection attempts an exact one-pool router call at the recorded block, records its fingerprints and any revert, and checks canonicality. It does not verify delegated wallet authority or submit transactions. Integer accounting and durable attempt recovery are internal tested foundations; live accounting and execution adapters remain unwired.

Autonomy readiness and budget guardsAvailable · execution inactive

Manually check documented mainnet infrastructure and save a blocked readiness receipt. Atomic reservation accounting and complete-fee budget checks are implemented and tested but not connected to a live executor. Read-only scheduling requires a verified runner. Live direct-pool quoter evidence and optional ownership messages are available. No session key or automatic spending is enabled.

Robinhood Chain wallet observationsAvailable · read only

Connect a browser wallet or inspect a public address on mainnet 4663. Balances use official contracts and one block. Indicative prices apply official multipliers. Saved observations and comparisons are available, with partial purchase previews using saved mandates. Optional historical ownership verification and read-only monitoring are available. No mobile wallet transport or spending.

Save a versioned mandateAvailable

Saved under the signed-in workspace owner in the workspace database.

Request workspace-data deletionAvailable locally

A signed-in owner can record a deletion request from Account. Review and erasure are handled manually; submitting a request does not delete data immediately.

Choose an action preferenceAvailable locally

Approval is the default. Automatic is saved as an inactive future preference; it does not grant trading authority.

Decline a proposalAvailable for receipts

The account owner can decline a checks-passed proposal once. The choice is stored in the trail and sends no order.

Sign-in identifies your workspace. Practice saves confirmed rules, simulated funds and receipts. Wallet observation reads public evidence without granting authority. Live spending is not enabled.

CHAPTER 02A

Robinhood Chain wallet evidence

Read and save real holdings without granting spending permission.

Overview accepts an EVM browser wallet or a watch-only public address. The reader verifies mainnet 4663 and matches stock tokens by their official contract addresses. Balances share one block; ETH, DeFi and other tokens are excluded from the stock subtotal. Failed reads never imply zero holdings.

Indicative valuation uses the midpoint of a matched official USD bid/ask, multiplied by the official shares-per-token multiplier and exact raw token quantity. Halted, mismatched, pending-multiplier or quotes older than two minutes are excluded. A stock subtotal is not the full wallet value or an executable swap quote. At most 20 held tokens are priced per read.

Autonomy onboarding offers an explicit picker for detected browser wallets or a watch-only address. The picker uses EIP-6963 discovery with a browser-default fallback. Extension-supplied wallet labels are not independently verified. Ownership signing uses the wallet you selected, checking its exposed account and Robinhood Chain network before and after signing. Connection shares an address; the separate ownership signature grants no spending permission. Wallet creation inside Stock Steward is planned, not implemented. You may create a wallet in your own wallet app, then connect it. Account or network changes clear the selected onboarding address. Readiness receipts can be downloaded as JSON with their recorded checks, route evidence, and intent digest when present. Exports contain public wallet addresses and recorded financial evidence; review before sharing. The remaining-check checklist is historical and must be refreshed after changes. A separate switch button asks your wallet to add or select Robinhood Chain; it does not send a transaction. Ownership messages show an expiry countdown and cannot be signed after expiry. Stock Steward has no private-key or recovery-phrase input.

Route inspection also records existing USDG allowance to Permit2 and Permit2 allowance to the documented router at the same canonical block. It binds the recipient, exact input, minimum output, pool, deadline and mandate version into an inspectable intent digest. Unknown allowance evidence stays pending. A passing allowance check grants no agent authority. The router’s poolManager getter is checked against the canonical manager at the same block. Unsupported getters remain pending, while mismatches fail. The internal execution guard requires simulation and any exact approval to match the same complete intent digest; changing the amount, output, pool, deadline or mandate invalidates earlier evidence. Router bytecode is fingerprinted, but its deployed interface and enforcement still require verification before executable calldata or full wallet simulation is enabled. USDG token units cannot substitute for verified dollar-limit accounting.

Observe & save stores the evidence under your site login. Wallet ownership remains unverified. Load saved observations to compare quantities, multipliers, available prices and mandate versions. Purchase previews check saved symbol and single-buy limits; daily exposure, full-wallet concentration, funding and execution eligibility remain pending. No preview approves an order.

Automatic spending remains disabled. Alchemy documents Robinhood wallet APIs and scoped session keys, but read-only Alchemy connectivity is verified but total setup cost is not measured. Gas sponsorship does not establish free gas. Before activation, permissions, revocation, execution routes and a user-selected setup budget must be verified. Supported networks · Official data semantics

CHAPTER 02B

Autonomy, with inspectable authority

The intended agent acts within granted limits. Today, readiness checks show precisely why it cannot spend yet.

The workspace can check Robinhood mainnet identity and bytecode at the documented Uniswap Universal Router 2.1.2, Permit2 and Alchemy SMA-7702 delegate addresses. Checks use one observed block. This establishes infrastructure presence, not available liquidity, audited behavior, investor eligibility or a usable stock-token swap.

Each manually requested check stores a historical readiness receipt under your site identity. It identifies your saved mandate version, pending ownership and delegation checks, missing route and fee evidence, and remaining prerequisites. A public address and an automatic preference grant no authority. Optional read-only schedules store observations after runner activation. Pause discards in-flight results, and three consecutive failed observations pause the schedule. Wake-ups may be delayed; actual run times are shown. Transaction watches report chain evidence, not investment completion. No session signer is running.

Spending permissions

Activation requires an owner-approved wallet delegation, a bounded session, approved settlement and output tokens, constrained recipients and calldata, expiry, and proven revocation. A router allowlist alone can allow unwanted commands. Steward must test the complete permission path before requesting live authority. Root permissions are not acceptable.

Accounting before execution

The reservation core is implemented and tested, but is not wired to an executor. It atomically reserves purchase amounts, rejects duplicate intents, and counts unresolved reservations across midnight. Unknown transaction outcomes retain their budget until reconciled. Confirmed purchases count toward their execution-day cap. Reconciliation must establish a terminal outcome before releasing a reservation.

Fees before funding

The fee guard requires fresh estimates for delegation, permission installation and revocation, including execution, data and provider fees. It adds 50% headroom and rounds upwards against a selected cap no higher than $20. It cannot return a complete quote from gas price alone. Funding or bridge fees and investment principal remain separate. Real setup estimates are still pending.

Infrastructure references: Uniswap deployments and Alchemy permissions. Robinhood stock-token restrictions still apply; blockchain accessibility does not establish eligibility.

CHAPTER 02C

A quote, not a trade

Inspect a real direct pool without approving tokens or submitting an order.

The route inspector uses canonical USDG and a stock token matched from the official registry. It verifies mainnet identity, contract presence and the quoter/state-view manager reference, then pins every call to one block. Four zero-hook pool keys are checked: fees 100, 500, 3000 and 10000 with tick spacing 1, 10, 60 and 200.

Pool initialization, active liquidity and exact-input quoter output are separate evidence. An unavailable RPC result is not proof of an empty pool. A failed direct search does not rule out other fee/spacing keys, hooked pools, multihop paths or RFQ venues. The best output means best among those four inspected keys only.

USDG input is a token amount, not a guaranteed dollar valuation. Output is raw stock-token quantity before UI multiplier conversion. Minimum output is rounded down using the selected tolerance. Quote expiry cannot outlive thirty seconds from either its block timestamp or observation. Quoter gas excludes the full router/account transaction, approval, setup, data and provider fees.

Owner control and replay protection

You may request a five-minute ownership message, inspect it, then choose to sign through your wallet. Its origin, address, chain, nonce and expiry are checked against a server-held challenge under your signed-in identity. An EOA signature is recovered, or a deployed contract must return the ERC1271 magic value. A consumed, replaced or expired challenge cannot verify again. Counterfactual undeployed wallets are unsupported. Signatures are not persisted.

Verification proves control at a recorded time. It neither installs a delegation nor proves future control, current balances or eligibility. Forgetting the record removes this workspace evidence; it does not revoke any separate wallet permission.

Execution preflight

The internal guard requires a matching owner, current mandate, fresh quote and block, unpaused state, verified eligibility, complete onchain restrictions, reserved accounting, concentration evidence, account-level simulation and complete fees. Approval mode also requires exact, unexpired approval bound to that route and mandate. Automatic mode still requires verified scoped authority. These checks are tested foundations; no signer or submission adapter is connected.

Router arguments require narrow enforcement. The tested Roles/Safe policy restricts exact commands, output tokens, recipients, quotas and expiry. It has not been installed on your live wallet. A generic contract/function allowlist cannot replace it; Stock Steward requests no broad or root grant. Provider permission reference · Stock-token trading venues

CHAPTER 02D

Test the current release

Start with fake-money practice, then try read-only wallet evidence and an optional ownership signature. No funding is required.

  1. Save boundaries.

    In Mandate, choose allowed symbols and limits. Save, reload, and check the version persists. Automatic is a saved preference and must remain inactive.

  2. Inspect an address.

    In Overview, paste a public address and select Observe & save. Inspect coverage, unavailable prices and the recorded block. A failed read must show an error, not zero balances.

  3. Use your own wallet.

    In Autonomy, choose a detected wallet and connect. Cancel once to check recovery, then reconnect. Switch to Robinhood Chain using the separate button. Account or network changes must clear the onboarding address.

  4. Verify control.

    Request an ownership message. Review its address, origin and expiry, then sign only if they match. This signs a message, not a transaction or spending grant. Expired messages need replacement. Watch-only addresses cannot sign through this flow.

  5. Inspect a route.

    Enter a stock symbol and USDG token amount, then inspect. Quotes may be unavailable; that is a valid result. When a quote exists, inspect the minimum output, pool, block hash, allowances and intent digest. Quoter gas is not a full transaction fee.

  6. Check and export readiness.

    Run a fresh readiness check and download its JSON receipt. Ownership evidence may pass historically, while delegation and execution remain blocked. Reload and inspect saved history. The export includes public address and recorded evidence.

  7. Try monitoring deliberately.

    If you want background read-only observations, start a monitor, refresh status, then pause it. A scheduled run can take longer than the chosen interval because GitHub can delay wakes. Pause must show monitoring paused; it does not revoke wallet permissions.

Stop if a wallet prompt unexpectedly requests a transaction, token approval or delegation during this walkthrough. Those features are not enabled. Report the step and visible error; keep keys, secrets and signatures out of screenshots.
Open workspace
CHAPTER 02E

Execution preparation

Autonomy is the goal. The current preparation builds evidence without spending funds.

Exact router candidate

One exact-input USDG/stock swap fixes the pool, maximum input, minimum output, initiating account and deadline. Local validation rejects changed call bytes, targets and native value. These checks do not enforce permissions onchain.

Read-only call simulation

Inspect a route to see a direct-router call result, expiry, code fingerprint and any revert. The call uses real recorded state with no fabricated balances. A successful direct call is still not a complete delegated-wallet simulation. Its gas estimate excludes data and provider fees.

Complete dollar accounting

The internal accounting core uses integer amounts, verified USD price bounds, pending spend, full inventory and external activity. It rounds upwards and reserves room for loss and fees. The live data adapter remains incomplete; USDG is not assumed to equal one dollar.

Durable attempt recovery

Internal storage reserves budget atomically and allows one attempt claim. Interrupted or uncertain attempts keep their reservation across midnight. An outer transaction success alone cannot establish a fill. No live signer invokes this storage today.

Permission enforcement, full account simulation and fill reconciliation are tested in the isolated contract lab. Mainnet activation still requires your installed policy, current eligibility, verified full-wallet price and activity evidence, measured provider costs, a reviewed signer deployment and a separately approved funded end-to-end test. Funding alone does not complete those gates.

For now, test route inspection and its simulation report with a small token amount. A revert caused by missing funds or allowance is an honest result. No approval, delegation or transaction prompt is expected.
CHAPTER 02F

Wallet evidence and recovery

The workspace distinguishes what the chain proves from the authority and economic evidence still missing.

Inspect wallet code

Read a public address at a canonical block. Empty code, contract code and an EIP-7702 delegation indicator are distinguished. A matching Alchemy target is only an address match: it proves neither ownership nor installed session limits.

Inspect settlement records

A route receipt combines the observed USDG balance with unresolved Steward reservations belonging to your sign-in. Earlier-day reservations still count. Missing raw amounts remain unknown. Local records cannot establish external daily spending, USD prices or the complete portfolio value.

Verify a direct-router outcome

The internal reconciliation adapter checks exact account, target, calldata, router-code fingerprint, canonical inclusion and provider finality. A successful fill also needs matching settlement and stock-token transfers within the intent bounds. Missing or changed logs stay unresolved.

Recover without retrying

The read-only scheduled worker can mark interrupted historical attempts unknown and inspect recorded direct-router outcomes. It has no signer and cannot submit or resend transactions. A missing plan or unsupported user operation keeps its reservation.

Bundled user operations require a separate verified account envelope and event path. The narrow Roles/Safe adapter also checks the exact session/module envelope and installed policy at the transaction block. The isolated lab verifies full account simulation, fixture swap proof, durable attempt settlement and all six lifecycle fee components. Other bundled user operations remain unsupported. The standard session permissions do not establish restrictions inside router arguments; no broad/root grant is installed.

Test readiness and route inspection to see wallet-code and settlement evidence. No trading funds are needed. Your own wallet is necessary only for the separate ownership-message test. Automatic spending remains inactive.

Spending permissions: implemented, inactive

The integration compiles an owner-only Safe wallet setup and a narrow Zodiac Roles 2.1.1 policy. Fixed-size USDG buys share daily and cumulative call quotas across approved outputs. Exact router commands, pool parameters and output floors are pinned; arbitrary recipients, approvals, native transfers and administration calls are excluded.

The isolated contract lab passed 44 scenarios, including wallet creation, rejected unsafe calls, failed-call quota rollback, daily refill, cumulative exhaustion and owner revocation. It uses Robinhood mainnet wallet, permission, Universal Router, Permit2 and PoolManager bytecode with local fixture assets and liquidity. This is contract testing, not a funded mainnet trade.

The installed-state reader checks canonical contract fingerprints, wallet configuration, complete bounded permission history and remaining quotas. A verified state does not enable spending. Your verified owner wallet, current economic evidence, reconciled reservations, full setup fees and a guarded signer are still required.

  1. Connect a wallet you control and verify it with a message.
  2. Review the protected wallet setup, exact policy and complete fees.
  3. Sign installation only after reviewing that cost and authority.
  4. Verify the installed policy before any separately approved funded test.

No spending grant, paid setup or live transaction has been installed by these tests. An example address cannot authorize this setup.

CHAPTER 02G

Strategies and practice

A direction defines when to act. A mandate defines the limits. Confirmation and permission are separate steps.

Supported strategies

Practice supports scheduled buys, price-ceiling buys, target-allocation buys, cautious accumulation, sales above or below a price, a two-sided buy and sell range, single-stock rebalancing, and a two or three-stock portfolio target. Portfolio rules trade one stock per check and leave unallocated weight in fake cash. Selling requires held simulated shares.

Review before activation

In Strategy, describe your direction for an AI-suggested draft or set the fields directly. Review the exact rules and confirm them before Practice can use them. Your direction is sent to the configured AI provider only when you click Interpret. The free quota may run out; direct rule entry remains available. Changing a draft never changes active rules. Confirming replacement rules revokes Practice permission. News triggers, shorting, leverage, unrestricted assets and guaranteed outcomes are unsupported.

Fake-money permission

Save your approved stocks and limits in Mandate first. Practice begins with $1,000 fake cash, test prices and no permission. Authorize Practice separately, then run one check or start the agent. Approval mode waits for your exact approval; automatic mode changes only fake balances after all checks pass. Permission expires after 24 hours and does not grant wallet or broker access.

Price evidence and receipts

Test prices support fast clock, price and safeguard scenarios. Read-only live stock quotes can be selected after a reset: buys use the ask, while simulated sales and valuation use the bid. Missing, stale or halted quotes block trades. All held stocks and portfolio targets need current quotes. Trail records simulated purchases, sales, approvals, holds and declines with the checks behind them; it can export receipts.

Fake balances, rules and recent receipts survive reloads in the signed-in workspace. The agent checks about every eight seconds while open. Cloudflare requests optional background checks every 15 minutes; actual wakes may be delayed; approval mode still waits for you. Pause stops checks. Revoke permission before resetting fake funds. The Practice portfolio view shows cash, holdings, allocations and total fake-value change since reset; it is an estimate, not a real fill.

The Live selector cannot activate execution. Real custody, permissions, economic data, fees, settlement and an authorized execution path remain separate work. Practice authority never transfers to a real wallet.

CHAPTER 03

Your mandate

A mandate is the versioned rule set the decision engine would cite when it evaluates a proposed buy.

Approved symbols

Only stocks you list may be considered. An empty list approves no stock purchases.

Maximum single buy

A proposed order cannot exceed this dollar amount.

Maximum daily buys

Filled buys today and open buy orders count together with the proposed amount.

Maximum position share

The projected stock position cannot exceed this share of portfolio value.

Action preference

Ask for approval is the default. Automatic within limits can be saved as a future preference, but is inactive and grants no trading authority.

The workspace shows a live preview of the draft rule sentence, position ceiling, and action preference as fields change. Reset draft restores the last saved values without creating a new version. Saving increments the mandate version in the signed-in owner’s D1 ledger. The server validates the limits and rejects stale versions from another session. Practice execution choice is reviewed separately in Strategy. Live spending remains inactive. Changing a mandate invalidates practice permission and pending approvals.

CHAPTER 04

Wallet evidence

Read-only observations are separate from simulated practice balances.

Wallet tracking uses official Robinhood Chain stock-token contracts and same-block balances. Indicative prices are not execution quotes. Missing prices or failed reads remain unknown; the stock subtotal excludes ETH and other assets. Ownership verification is a separate message signature and does not authorize spending.

CHAPTER 05

Decision checks

The practice evaluator explains every passed or failed rule.

Checks cover the approved symbol, purchase size, available fake cash, daily budget, concentration, cash reserve, price freshness and strategy trigger. A failed check holds the proposal. Ask-before-buying mode requires approval of the exact practice purchase; automatic practice can act only when all checks pass.

CHAPTER 06

Decision receipts

Each saved practice purchase or hold has an inspectable reason.

Trail displays the latest saved practice receipts with the symbol, amount, timestamp, strategy and mandate versions, rule results and outcome. Simulated fills update fake balances. Holds and pending approvals do not spend funds. Receipts can be downloaded from Trail. Practice does not produce real transaction hashes.

CHAPTER 07

Execution lifecycle

Practice approval and live wallet authority are different permissions.

Confirming rules does not authorize spending. Authorize Practice enables simulated activity only. Pause stops the practice agent; revoke removes its practice permission. Background practice is optional and operates on fake funds. Live execution needs a separate reviewed wallet policy, verified route, complete accounting and fees, and a tested executor before activation.

CHAPTER 08

Before real money

Robinhood Chain live autonomy remains unfinished.

01Wallet authority

Verify your wallet and review bounded spending permissions, expiry and revocation.

02Route and fees

Verify executable liquidity and estimate all setup and execution fees within your cap.

03Live safeguards

Connect fresh funds, valuation, daily accounting and durable execution recovery.

04Funded verification

Test a small approved transaction and verify the limits before unattended execution.

Funding alone does not finish this work. Practice remains available without a funded wallet.

CHAPTER 09

Glossary

A few terms used throughout the workspace and code.

Mandate
Your saved set of allowed symbols and purchase limits.
Proposal
A suggested buy before authorization or submission.
Hold
A proposal blocked by one or more checks; no order is sent.
Receipt
The inspectable record of evidence, rules, reason, and any later outcomes.
Reconciliation
Matching a submitted order to a verified transaction outcome.
End of guide · Reviewed 30 September 2026Go to workspace