Skip to content
← Back to Override Doctrine

Operator brief · 261

The panel contains two controls called override, and they do opposite things.

The key idea

The cap

A ceiling the operator may impose, and it is always safe to use.

The manual override cap sits among the decision engine's inputs and behaves as a maximum tier the operator selects. Blank means the top of the ladder — no constraint added — and any selection caps risk lower than the formulas would have produced. It enters the resolution as one more term in a minimum, alongside the gate cap and the raw core recommendation, so it can bind the outcome downward and has no mechanism for lifting it. That single directional property is what makes it structurally different from everything else discussed under the heading of overrides. Using it cannot breach a constraint, cannot stack exposure, and cannot produce a state the rest of the system needs to be warned about. Its worst case is that the account deploys less than the evidence supported, which is a cost the system is explicitly built to prefer.

FigureTwo controls, one word, opposite governance
controldirectioncan breach poollog requirement
Manual override caplowers onlyno — impossiblerecorded, no reason
Full Tier throughputraises exposureyes, by designwritten justification
Compress Risk modeholds countnorecorded as mode
Smart Capacitydefaultnorecorded as mode

The two rows differ on every property that matters. The cap participates in the ordinary resolution as one more minimum; the throughput mode acts after resolution and is the only path in the panel that can produce exposure above the authorised pool.

The mode

A throughput exception that acts after the tier is settled.

The full-tier throughput override operates at a different stage and on a different quantity. The tier has already been resolved by the time it applies; what it overrides is the smart-capacity chain's answer about how much of that tier can be deployed given what is already open. It forces four fresh trades at the full per-trade average regardless of carryover, which is why it can produce total active risk above the authorised pool and why the workbook is required to warn when it does. Its governance reflects that: rare, deliberate, documented, with a written justification in the log. The two controls are therefore not two settings of one dial. They act at different stages, on different quantities, in different directions, under different rules.

Why the confusion is costly

A single word covering both makes the safe one feel transgressive.

The practical damage of collapsing them runs in a direction most operators do not expect. Because override carries a strong connotation of departing from the system, and because the full-tier mode's doctrine is genuinely severe, the word acquires a weight that then attaches to the cap as well. An operator who has internalised that overrides should be rare, deliberate and documented will hesitate before imposing a manual tier ceiling, and hesitating to reduce risk is the precise opposite of what the doctrine intends. The cap is the mechanism by which an operator's judgement enters the system in the only direction the system unreservedly welcomes. Treating it with the caution reserved for the exception layer means the one legitimate discretionary input gets used less than it should.

What the cap is for

It is where knowledge the workbook has no column for gets expressed.

The cap exists because an operator sometimes knows something the inputs cannot represent. A holiday period with thin liquidity, a scheduled event the panel has no field for, a personal circumstance affecting attention, a recent execution error that has not yet reached the diagnostics. None of these appear in the six inputs, and all of them are reasons to deploy less than the evidence would authorise. Without a downward control, that knowledge has only two outlets: overriding the throughput chain, which is the wrong instrument entirely, or simply not following the directive, which puts the account outside the governed system and leaves the log recording a decision that did not happen. The cap gives it a sanctioned route that stays inside the arithmetic and inside the record.

Both still get logged

Recording is universal; justification is what the asymmetry changes.

The distinction is not between a logged control and an unlogged one. The decision log preserves the inputs the engine saw, which includes whichever cap was in force, and it preserves the mode alongside the smart-suggested and effective values. Every use of either control is therefore visible in review. What differs is the burden attached: the throughput override requires a written justification because it produces a state the system otherwise forbids, while the cap requires none because it produces a state the system already permits — a lower tier, which the gate could have produced on its own. The asymmetry in accountability tracks the asymmetry in risk exactly, which is the property that keeps the accountability requirement from being read as a formality.

  • The cap enters as a minimum and can only reduce; it needs no defence.
  • The throughput override acts after resolution and can exceed the pool; it needs one.
  • Both are recorded. Only one requires a written reason, and the difference is directional.

The key idea

Governance should make the safe departure easy and the risky one expensive.

A system with one undifferentiated override channel prices all discretion identically, and since the channel has to be governed tightly enough for its most dangerous use, every use inherits that friction — including the ones that reduce risk. Splitting the channel by direction means the cost of expressing judgement matches the consequence of being wrong. Reducing deployment on a hunch costs a dropdown selection. Increasing it past the pool costs a written justification that will be read again in review. That is the correct relative pricing, and it only exists because the two controls were built as separate objects rather than as one control with a sign.

Connected inside MARS

Every brief documents the same shipped system.

The complete MARS package — eleven workbooks, three TradingView indicators, the full manual library — $497.