General-purpose language models know a great deal about finance. They do not know the specific rulebook, exception history, and document set of a single lifecycle. Closing that gap is the core of our model layer research, and it is the piece of the system most people underestimate.
The problem with general capability
A frontier model can explain how ETF creation works. Ask it what to do when an authorized participant's basket delivery is short one constituent after the cutoff, in a discount regime, when the fund's borrow cost has spiked, and the model will produce a plausible answer. Plausible is not the standard. The standard is what the fund's own procedures, the exchange's rules, and the desk's exception log say to do, every time, across five thousand agents making the same class of decision.
We solved this by post-training a language model on the lifecycle itself: its rules, its documents, and its recorded exceptions. Every agent in the swarm reasons on that model. The model is not a generalist that happens to be prompted about ETFs. It is a specialist that has internalized the rulebook.
Exceptions are the training set
The most valuable data in any lifecycle is its exception history. The happy path is documented in a procedures manual. The exceptions are documented in years of reconciliation breaks, email threads, and the memory of the people who resolved them. That is what a human specialist actually knows and what a general model does not.
Our post-training process treats exceptions as first-class training signal. Each historical exception becomes a case: the state of the lifecycle when it occurred, the rule that applied, the action that resolved it, and the counterparty confirmation that closed it. The model learns not just the rules but the mapping from messy real-world states to rule applications.
Bounded tool use
A post-trained model that reasons well is still not permitted to act freely. Every agent reasons on the shared model with bounded tool use. The tools available to a given agent are determined by its gate and its permission scope, not by what the model would like to call. A prediction agent has read access to market data. It does not have a tool that places orders, so it cannot place one no matter what it concludes.
This is where the model layer and the authentication layer meet. The model provides consistent reasoning across the swarm. The permission scope provides consistent limits on what that reasoning can touch.
Why this creates a defensible position
A post-trained model is a moat because the training set is not public. The rules are public. The exception history of a specific lifecycle, resolved and confirmed over time, is not. Every session the swarm runs adds to that history. Every rejected proposal teaches the model something about where the council draws its line. The model gets more specific to the lifecycle the longer it runs it, and that specificity is not something a competitor can download.