The agentic stack. Eight layers, one autonomous lifecycle.
OpenEXA separates perception from decision from execution, binds them with authenticated connectivity, and writes every action to a log that cannot be edited. Built once. Deployed per lifecycle.
Perceive. Reason. Act. Govern. Optimize. Orchestrate. Connect. Permit.
Each layer has one job and a hard boundary. That is what lets the system run tens of thousands of narrow agents at once without any of them becoming a black box — and what lets a new lifecycle reuse everything below the agents.
Signal IntelligencePerceive
Proprietary AI and ML models for risk and prediction. In Lifecycle 01 the create-and-redeem signal watches every ETF against its NAV, basket, borrow and venue depth, and captures short-lived discrepancies when execution latency is controlled and risk is properly managed. It never sleeps and never anchors.
- Risk model
- Price model
- Arb model
- Regime detection
- Continuous re-estimation
Model LayerReason
A post-trained LLM tuned on the lifecycle's documents, rules, message formats and exception history — the substrate every domain agent reasons on. Tool use is bounded by the layers beneath it: the model can propose anything and execute nothing on its own.
- Post-trained LLM
- Domain corpus
- Bounded tool use
- Evaluated per release
Domain-Specific AgentsAct
Proprietary, fully automated, domain-specific workflow agents. A one-click workflow creator builds custom execution workflows tailored to specific market conditions and regulatory requirements. Each agent does one narrow job — read a feed, score a gap, size an order, check a limit, match a fill — and the swarm does the rest.
- 5,000 – 50,000 per lifecycle
- One-click workflow creation
- Exception management
- Master–copy replication
Execution CouncilGovern
The gate every proposal passes. The Council arbitrates when agents disagree, enforces policy and mandate limits, and returns approve or reject in milliseconds — or hands the decision to a human when the operating mode says so. Nothing reaches execution that did not pass.
- Approve / reject
- Policy engine
- Conflict arbitration
- Human-in-the-loop optional
Routing LayerOptimize
Continually optimizes execution flow for an efficient lifecycle. Routes each approved action across brokers, OTC desks, dark pools, exchanges and clearing rails on real-time conditions and historical performance — the cheapest, fastest, safest path for that action, right now.
- Smart order routing
- Venue scoring
- Cost of execution
- Latency budget
Execution LayerOrchestrate
Orchestrates the lifecycle end to end with deterministic state — validated, submitted, partial, filled, reconciled — plus retries, idempotency keys and reconciliation against counterparty truth. The execution layer stays algorithmic so that the intelligence above it can be audited against it.
- Order-state machine
- Idempotent submission
- Retries & backoff
- Reconciliation
MCP ServerConnect
A custom Model Context Protocol server and toolset deploy tools to the agents and provide authenticated connectivity to brokers, transfer agents, custodians, execution desks, exchanges and clearing. Deployed as secure, customer-scoped MCP servers — your rails, your context, nothing shared.
- Custom tools
- Secure customer MCP servers
- Broker & custodian adapters
- Real-time data pipe
Authentication LayerPermit
Scoped, revocable permissions for every agent, tool and counterparty — exactly the permissions a workflow needs, and nothing more. Agents act inside limits you set. Custody never moves. Nothing in the system has withdrawal rights.
- Scoped API permissions
- Revocable per agent
- Never withdrawal rights
- Role-based access
Intelligence decides what, when and how much. Execution stays deterministic.
Rules, adapters, order state.
- Deterministic action rules with explicit pre-conditions
- Adapters with retries, backoff and idempotency
- State machine: validated → submitted → filled → reconciled
- Reconciliation against counterparty truth
- Market-hours gates and instrument-level constraints
Models, agents, council.
- Signal selection and parameter tuning per regime
- Risk-adjusted strategy rotation under portfolio-level constraints
- Anomaly detection across signals, venues and counterparties
- Arbitration between agents when their proposals conflict
- Only profitable, policy-compliant actions pass to execution
Thousands of narrow agents beat one wide one.
A lifecycle is decomposed into hundreds of small, verifiable jobs. Each job gets an agent; each agent gets exactly the tools and permissions that job needs; the Council arbitrates. Nothing important depends on a single model's judgement — and every judgement is on the record.
The master–copy agent model. One master agent is proven in production, then copied and specialized — a copy per asset, venue or customer — all reporting to the same Council, all sharing the same ledger.
Watch
Real-time analysis across prices, NAV, baskets, borrow, venue depth — and, in other lifecycles, documents, meters and filings.
Decide
Create or redeem, size and timing — proposed under risk, policy and portfolio constraints, then submitted to the Council.
Act
Route approved actions to clearing, OTC, dark-pool and HFT rails and dealer-brokers through the routing and execution layers.
Prove
Match fills to counterparty truth, raise discrepancies, and close the loop in the hash-chained ledger.
Every action passes three gates. Every gate leaves a record.
Institution-grade controls for autonomous execution — designed so that an operator, an auditor or a regulator can replay any action, at any step, and see exactly why it moved.
- P-01
Validate and risk-check
Proposals pass schema checks, policy rules, position and notional caps, and market-hours gates before they exist as orders at all. The Council signs the result.
schema ✓ · policy ✓ · caps ✓ · council ✓ - P-02
Submit and confirm
Submission tracks fills, partial fills and retries with idempotency keys, so a disrupted connection can never produce a duplicate action.
submitted → partial → filled - P-03
Reconcile and report
Internal records are matched against counterparty truth — positions, cash, NAV, documents — with discrepancy alerts raised to operators and written to the ledger.
internal ≡ counterparty · alerts on Δ
Your rails. Your context. Your permissions.
Every customer runs on a dedicated, secure MCP server: the agents that act for you see only your tools, your data and the permissions you grant — and can lose them in one call.
Dedicated MCP server
A customer-scoped Model Context Protocol server with its own toolset and adapters. No shared context between customers, ever.
Productionized real-time data pipe
Prices, NAVs, baskets, confirmations and reference data delivered to the agents with latency budgets and provenance on every record.
Permissions you can revoke
Scoped API permissions per agent and tool, granted through the authentication layer and revocable instantly. Custody stays at your broker.
As autonomous as your mandate allows.
Each lifecycle runs in one of three modes. Switch modes at any time; the emergency halt is database-backed and works in all of them.
| Mode | Who approves | Latency | Typical mandate |
|---|---|---|---|
| Fully automaticAgents execute within policy | Execution Council | ms | Low-risk single-agent lifecycles |
| Auto-with-approvalAgents propose, humans confirm | Operator or delegate | seconds – minutes | New lifecycles, new strategies, larger tickets |
| ManualAgents recommend only | Operator | discretionary | Evaluation and onboarding |
| Emergency haltAvailable in every mode | Any operator | immediate | Counterparty or API disruption, market events |
Built as a platform others deploy agents on — not a single product.
The same eight layers that run OpenEXA's first lifecycle are designed for third parties to deploy their own agents, lifecycles and controls — once trust and liquidity have been built in production.
Publish agents and lifecycles.
- Workflow creation and instrument-level constraints
- Streamlined approval workflows through the Council
- Governance management and role-based access
- Sophisticated models, real-time feeds and algorithms — only compliant actions pass
Allocate with full visibility.
- Lifecycle and pool selection with strategy-level performance
- Transaction visibility for execution-quality monitoring
- A secure sandbox: agents execute, monitor and enforce risk controls
- Custody stays at your broker throughout
See the stack run on live capital.
Request a walkthrough of Lifecycle 01 — the swarm, the Council, the control plane and the ledger — on real trades.