Record AR-MRS-001 · Governance Architecture

A strategy tells you what to do.
MARS decides how much of it you may run.

This page is a structural explanation of the Montex AlphaRail System — the governance and analytics layer that sits above signal quality and controls how much capital a framework is permitted to deploy at any moment. It documents the vocabulary, the hierarchy, the measurements and the trade-offs, so that the ideas can be understood, argued with, and applied to a framework you did not buy from anyone.

Status Reference Functionality Level 1 Scope Explanatory Updated 2026-07

What this page is, and is not

MARS exists as a spreadsheet-based governance and analytics framework — a separate product with its own workbooks, calibration tables and reporting cycle. This page explains the system; it does not sell the workbook, and it does not reproduce its calibration. Where a number would be a calibration value, the structure is described instead and the omission is stated in the open.

AR-MRS-001·PL-03 — Monte Carlo is the ruler; expectancy is the grade. The forge is where the two are reconciled. Stylised brand illustration of the laboratory, not a photograph of a physical facility. The charts and figures inside the plate are simulated.

Three words,
three commitments.

The name is not decoration. Each of the three parts names an instrument the system refuses to operate without, and the order they appear in is the order in which they constrain each other.

What the system actually is

Strip away the vocabulary and MARS is a set of workbooks that answer one question on a fixed schedule: given the current capital state and the evidence produced since the last review, how much risk is this account authorised to carry, and which management populations are eligible to carry it?

Everything else — the metrics, the badges, the indexes, the dashboards — exists to make that answer defensible. The system does not generate entries. It does not rate instruments. It has no opinion on whether a chart looks good. It sits one level above all of that and decides the size of the envelope inside which the trader's judgement is allowed to operate.

The reason it is a spreadsheet rather than an application is boring and important: a spreadsheet is auditable by the person using it. Every intermediate value is visible, every formula can be traced, and nothing is hidden behind an interface. A governance layer that cannot be inspected is just another opinion with a nicer font.

Boundaries of the system

It governsAuthorised risk pool, maximum tier, open-exposure capacity, branch eligibility, deployment permission and the review cadence that changes them.
It measuresExpectancy, drawdown state, risk-adjusted quality, efficiency of risk conversion, equity acceleration and adherence between authorised and deployed risk.
It does notProduce signals, select instruments, place orders, predict direction, or promise that a framework with positive expectancy will remain one.
It assumesThat a framework already exists, that its trades are recorded honestly, and that the trader will accept a smaller position than they want during a decline.

The uncomfortable half

The last assumption is the one that fails. A governance layer only works if it is obeyed on the day it is least welcome, which is always the day after a loss.

The ruler, the grader,
and the adjudicator.

Two instruments produce a disagreement. A third decides what may be done about it. That sequence is the whole thesis, and almost every governance failure is a case of the third instrument being skipped.

AR-MRS-001 · DIFFERENCE MATRIX

Reading the difference

A benchmark and a measurement will disagree constantly, and the size of the disagreement tells you nothing on its own. What matters is the pairing: whether the account is ahead or behind expectation, and what the capital state looks like while that is true.

Only one of the four combinations produces an unambiguous instruction. The other three are places where traders reliably invent a permission the system never issued.

Benchmark position on the horizontal, capital state on the vertical. Descriptive, not calibrated.

Five master metrics,
two levels of authority.

The system does not treat its own measurements as equals. Two of them can stop deployment on their own. The other three can only argue about how deployment should be shaped, and an argument is not a veto.

Tier 1 · veto-capable

Expected value and drawdown

These two answer questions that have no acceptable negative answer. If expectancy after friction is not positive there is nothing to govern, and no amount of efficiency makes a losing process worth financing. If drawdown has reached a state the plan defines as unsafe, the quality of the edge is irrelevant until the capital state is repaired. Either measure, on its own, can compress the risk pool or stop deployment entirely.

The asymmetry is deliberate. A veto that requires agreement between measures is not a veto — it is a negotiation, and negotiations are won by whoever wants to trade more.

Tier 2 · optimisation

RAPF, RAER and acceleration

These three shape deployment inside whatever envelope tier 1 has already allowed. They decide where risk is best spent, which branch is converting risk efficiently, whether profit quality is structural or concentrated, and whether compounding is improving or quietly decaying.

A strong tier-2 reading never raises a tier-1 ceiling. An excellent efficiency ratio during a deep decline is a description of how well you are losing, not an argument for losing more.

The distinction is easy to lose and expensive to lose. R is a unit of intent: it is what you decided to risk, so measurements expressed in R are comparable across instruments, account sizes and years. Percentage of equity is a unit of consequence: it describes what actually happened to the capital.

Forcing every measure into one dimension would be tidier and wrong. An execution-quality measure has to be indifferent to account size. A capital-state measure must not be.

Seven layers,
in one direction only.

Authority descends. Each layer constrains everything below it and can never be widened by anything below it. Select a layer to see what it controls and what it refuses to be overruled by.

Authority stack

Decorative scene. Plates light from the top down to the selected layer; everything the scene depicts is stated in the text beside it.

PROPERTY 01

Descending only

A lower layer may decline to use the room it is given. It may never take more. Rank six can refuse a signal; it cannot fund one past a rank-three cap.

PROPERTY 02

Different clocks

The upper layers change slowly — the plan almost never, the gate on review boundaries. The lower layers change trade by trade. Mixing those cadences is how a weekly decision gets overturned by a five-minute feeling.

PROPERTY 03

Discretion is inside, not above

Rank seven exists and is not an insult. Judgement about whether to take a permitted trade is valuable. Judgement about whether a cap applies today is not judgement, it is an override, and overrides are logged.

The gate is the brake,
and it steps down early.

Capital state is read as decline from the running equity peak, not from the starting balance, so accumulated gains are defended rather than treated as house money. Each state carries a named brake posture that describes what the account is trying to achieve while it is there.

Why the numbers are withheld

Two reasons, and only one of them is commercial.

The commercial reason. The boundaries and the pool percentages are the calibrated core of the MARS workbook. They are the part that took the work: the part that was tuned against distributions, stress-tested, and revised when it produced behaviour nobody wanted. Publishing them would give away the product while leaving out everything that makes them coherent.

The honest reason. A published boundary becomes a target. Traders trade to the number: they hold a losing position because closing it would cross a threshold, or take an extra position because they are two-tenths of a percent from a better tier. A calibration detached from the workbook that produced it is not a gift to the reader — it is a set of arbitrary thresholds with the authority of something that was never explained.

What is genuinely useful is public and stated above: the gate is a function of drawdown from the peak, it is reviewed on cycle boundaries, it compresses in steps, and it steps down before the situation is critical rather than after.

Review cadence

Gate state is evaluated on cycle boundaries rather than after every trade. Continuous re-evaluation would make the brake chatter: one winning trade lifts the account across a boundary, the next loss drops it back, and position size oscillates for reasons unrelated to the market.

Asymmetric movement

Descending a gate is immediate at the next review; ascending requires the recovery to hold. The asymmetry is intentional. A single good cycle is evidence of a good cycle, not of a repaired capital state.

The lock is a stop, not a failure

System Lock withdraws deployment permission entirely and hands the account to an investigation rather than to a recovery plan. The question it forces is which of the seventeen framework components stopped behaving, not how quickly the balance can be rebuilt.

Seven tiers.
The same tier is not the same size.

A tier names a posture, not a quantity. The quantity it authorises depends on the gate that is active when it is issued — which is the single most persistently misread property of the system.

Select a capital state

Tier availability under the selected state

Illustrative scale

Illustrative relative scale — not the MARS calibration

About the numbers in this demonstration

The authority index above is an arbitrary demonstration scale invented for this page, where 100 represents the full envelope of the healthiest state. It exists only to show that the same tier resolves to a different quantity in a different gate. It is not the MARS pool table, it is not derived from one, and it should not be used to size anything.

Why a ceiling and not a target

A trader given a ceiling of T5 will trade T5. That is what ceilings do to people. The tier is issued as the maximum posture the evidence supports, and the expected behaviour is to sit below it most of the time — using the top of the range for the small number of situations that actually earn it. An account that occupies its ceiling continuously has not been granted more authority; it has removed the ceiling and kept the paperwork.

From capital state
to a number of fresh trades.

The throttle is the arithmetic that turns a gate into a position size. It runs in a fixed order, and the order matters: exposure already carried is subtracted before anything new is sized, not after.

Active risk is a function of the stop

A crude exposure model counts open positions and multiplies by the risk each was opened with. That model is wrong in both directions at once. It treats a position whose stop now sits above entry as if it still carried a full loss, and it treats four correlated positions as four independent ones.

Stop-state-aware accounting asks a narrower question of every open trade: if this position closed at its current stop, what would it cost? That number, not the original risk, is what is subtracted from the authorised pool.

The consequence is that management activity creates capacity. Moving a stop to break-even does not just protect a trade — it returns roughly a full unit of risk to the pool, which is why the system rewards active management rather than merely permitting it.

Stop states and their treatment in capacity arithmetic
Stop stateActive risk chargedReasoning
At original stopFullNothing has been protected. The position can still cost the whole amount it was opened with, plus whatever the gap risk of the instrument implies.
Stop moved, still below entryReducedThe remaining loss is the distance from entry to the new stop. The difference is released back to the pool at the next capacity read.
Stop at break-even≈ zeroCharged as approximately nothing rather than exactly nothing — slippage and gaps mean break-even is a plan, not a guarantee.
Partial banked, remainder protectedPartialOnly the unprotected remainder carries risk. The banked portion has already become realised evidence and belongs to expectancy, not exposure.
Closed or excludedNoneA closed trade carries no exposure. It is realised evidence and moves to the expectancy record, where it belongs.

Why nominal concurrency overstates capacity

A limit of six concurrent trades sounds like a capacity statement. It is not — it is a count. Six positions at a large size and six at a small one are the same number and entirely different exposures, and neither figure knows anything about correlation. The binding constraint is almost always the authorised risk pool, and a plan that quotes only a concurrency limit will report free capacity that does not exist.

Capacity demonstration

Four open positions with adjustable stop states, against an adjustable authorised pool. The arithmetic is plain addition and subtraction, performed in the page script, using an illustrative pool expressed as a percentage of equity.

Controls

Pool occupancy

Simulated

Interactive demonstration — not a historical backtest

Figure 1 · Three readings of the same free capacity Simulated

Six measures that describe
the governor, not the market.

Throttle telemetry is self-diagnosis. It does not ask whether the strategy is working; it asks whether the governance layer is behaving as designed, being obeyed, and paying for itself.

Figure 2 · Time spent in each capital state Simulated

Two readings that are routinely misread

Compression is correct behaviour

When open exposure reduces the size of the next trade, nothing has gone wrong. That is the mechanism operating exactly as designed. Recording it as a missed opportunity — "the trade I could not take" — inverts the purpose of the measure and turns a working brake into a grievance.

Override stress exists to be embarrassing

Overrides are permitted. They are also counted, sized and reported, so that the pattern becomes visible before it becomes a habit. One override with a written reason is a judgement call. Eleven in a quarter is not a series of judgement calls — it is the real risk policy, operating without documentation.

The remaining four measures — dwell, tier usage, throttle efficiency and compliance — are only meaningful over a full cycle. Read weekly, they describe weather. Read annually, they describe whether the governance layer earned the growth it cost.

Five principles
that settle arguments in advance.

Each of these exists because the opposite behaviour is intuitive, common, and expensive. They are written down so that they are decided before the moment they are inconvenient.

An open position has two properties that a closed one does not: its outcome is unknown, and its current value is the most emotionally persuasive number on the screen. Counting unrealised profit as evidence means expectancy rises fastest exactly when exposure is highest, which is the worst possible time to be told the edge is improving.

The separation is clean. Closed trades feed expectancy and every metric derived from it. Open trades feed exposure and capacity. Nothing crosses until it closes.

A rule that blocks new trades whenever anything is open is simple and quietly destructive: it makes the framework's throughput dependent on holding time rather than on evidence, and it punishes the branches that hold longest — usually the ones carrying the tail.

Subtracting active risk instead keeps the constraint where it belongs, on capital rather than on count. A framework holding three well-protected runners has real capacity for a fourth position. A framework holding three positions at full original stop does not.

A logged override leaves a record that can be examined: what was authorised, what was deployed, why, and what happened next. Over a year that record is one of the most informative datasets the trader owns, because it isolates the moments when discretion overruled structure.

An unlogged override leaves nothing. The system's reports then describe a policy that was not followed, which is worse than having no reports at all — the numbers are precise and the conclusions are false.

A Monte Carlo benchmark is a description of what the modelled distribution would produce. Running below it is information: the sample may be short, the regime may be unfavourable, or the model may be wrong. None of those readings is an instruction to deploy more capital.

The instinct to size up in order to "catch up" is the single most reliable route from a disappointing year to a terminal one, because it raises exposure precisely when the evidence for the edge is at its weakest.

A promising result is a hypothesis with good manners. Between it and live capital sits a promotion step: a written statement of what was tested, on what data, with what expected behaviour, and what observation would cause the change to be withdrawn.

Without that step, "we are testing a variation" becomes indistinguishable from "we changed the system", and the account has no idea which framework it is actually running. The next section describes the boundary in full.

Alpha has to survive
the questions that follow it.

The word is used as a synonym for outperformance, which is why it is nearly meaningless in retail contexts. In this system it carries four qualifications, and a result that fails any of them is called something else.

Above a benchmarkNot above zero, and not above last year. Above what the modelled distribution said this framework should produce over a comparable sample.
Net of riskCompared at equivalent exposure. Doubling position size and beating the benchmark is arithmetic, not skill, and it is fully reversible on the way down.
Net of drawdownAchieved without a deeper decline. A higher return bought with a worse capital path has not improved anything a trader can actually live with.
Net of execution qualityPresent after friction, slippage and giveback are charged. Outperformance that exists only in theoretical fills is a reporting artefact.
Repeatable in principleRobust to resequencing. If the same outcomes in a different order remove the advantage, what was measured was ordering, not edge.

Experiments do not become
authority by accumulating.

The most common way a governed framework stops being governed is not rebellion. It is drift: a sequence of small, individually reasonable adjustments, none of which was ever promoted, and none of which can be reversed because nobody recorded when it started.

STATE 01
Research
A question with a proposed test. No capital, no authority, no presence in any live report. Failures at this stage are cheap and are kept.
No capital
STATE 02
Candidate
The result survived its own validation conditions. It now has a written specification, an expected behaviour and a stated failure signature.
No capital
STATE 03
Shadow
Run alongside production and recorded, but not deployed. This is where the difference between a modelled behaviour and an observed one becomes visible at no cost.
Recorded only
STATE 04
Promoted
An explicit, dated decision with a named reason. The prior configuration is archived rather than overwritten, so the change can be reversed as one action.
Explicit step
STATE 05
Production authority
Part of the live framework, subject to the same gates, tiers and telemetry as everything else. It now has to keep performing, not merely have performed once.
Live

What the promotion step actually buys

A date. That is most of the value. With a dated promotion the account can be partitioned into before and after, and the question "did that change help?" becomes answerable. Without one, every performance comparison silently mixes two different systems and produces a number that describes neither.

The second thing it buys is a reversal path. A change made deliberately can be withdrawn deliberately. A change that accumulated cannot be withdrawn at all, because nobody can say what the previous state was.

The drift signature

Drift is recognisable in the telemetry before it is recognisable in the returns: compliance falls while override stress rises, and tier usage begins to cluster at the ceiling. The framework has not been replaced. It has been renegotiated, one exception at a time.

Applies to the governance layer too

Changing a gate boundary, a pool percentage or a tier ceiling is itself a promotion event and is subject to the same steps. A governor that can be adjusted mid-drawdown without a record is not a governor.

Governance is not free,
and the bill arrives in good years.

A layer that compresses risk during declines necessarily compresses it during the recoveries that follow declines. That is not a defect to be tuned away — it is the price, and it should be quoted before the benefit.

The preview engine on this site models the same shape: an ungoverned configuration deploys a constant fraction of equity; a governed one compresses that fraction as decline from the peak deepens, and stops entirely past a lock boundary.

Running both at three risk levels produces the honest picture below. Governance is close to worthless at low risk, clearly useful at moderate risk, and decisive at high risk — while costing growth at every level. The cheapest way to obtain most of its benefit remains risking less per trade in the first place.

Simulated demonstration data

Figure 3 · Modelled maximum drawdown, governed against ungoverned Simulated

Figure 4 · Modelled net growth over the same histories Simulated

How this comparison is produced

Both sides of every pair come from the same evaluation code path and the same outcome ladder. Only the governance flag and the risk-per-trade setting differ; every other parameter sits at the laboratory default, so the comparison isolates the governance layer rather than rewarding a favourable configuration.

For each risk level the engine builds nine seeded histories and reports the median, so the figures describe a central case rather than a lucky or unlucky draw. Drawdown is measured from the running peak of each history. Net growth is the ending return of the median history over a fixed horizon of 320 modelled trades.

The compression schedule inside the preview engine is the site's own illustrative model. It is not the MARS calibration, produces different numbers, and exists to demonstrate the shape of the trade-off rather than to reproduce a workbook.

Read the direction, not the digits

These figures are the output of a model, not a measurement of any account. What is informative is the direction and the relative size of the effect across risk levels. The precise values would move with any change to the underlying assumptions.

The trade the trader is actually making

Given upCompounding speed in favourable sequences, and part of the recovery rate immediately after a decline — the moment when compression is most resented.
ReceivedA shallower worst case, a materially lower probability of reaching a depth from which recovery is unrealistic, and a smaller distribution of outcomes.
UnchangedExpectancy per trade. Governance does not improve the edge; it changes how much capital the edge is allowed to touch.
Worth it whenThe consequence of the deep case is not survivable, or the trader's realistic behaviour under a deep decline is worse than the compression they are complaining about.

What this system
cannot do for you.

Stated plainly, because a governance layer that is oversold becomes the thing traders blame when it works exactly as described.

It cannot create an edge

Governance applied to a framework with negative expectancy after friction produces a slower, more orderly loss. Every metric on this page assumes something worth financing already exists. If it does not, the correct action is not compression — it is stopping.

It cannot prevent a large single loss

Gates respond to realised decline. A gap through a stop, an instrument that reprices between sessions, or a correlated cluster resolving at once will all hit before any review boundary. The gate governs what happens next, not what has already happened.

It cannot compensate for bad data

Every measurement here descends from a trade record. If fees are missing, risk amounts absent or timestamps unreliable, expectancy is overstated and the gate that depends on it is calibrated to fiction. Data quality is upstream of governance, not parallel to it.

It cannot enforce itself

A spreadsheet issues an authorisation. A human places the order. The distance between those two events is where the system succeeds or fails, and no amount of analytical structure closes it. Compliance telemetry measures the gap; it does not remove it.

It is not a guarantee of survival

Compression lowers the probability of reaching an unrecoverable depth. It does not eliminate it, and no configuration described anywhere on this site should be read as promising that an account will persist.

It is optional

MARS is presented as one answer to the capital-authority problem, not the only one. A trader who risks a small fixed fraction, holds few positions and stops after a defined decline has solved much of the same problem with less machinery, and should.

This site

The AlphaRail Foundry Laboratory

A planned web application for building, testing, diagnosing, governing and refining complete trading frameworks. It will model governance behaviour — gates, tiers, throttle and exposure capacity as analytical modules — so that the structure can be studied against a framework of your own. It is not a copy of the workbook and does not carry its calibration.

Source note

Structural descriptions on this page are original AlphaRail material covering the concepts behind the Montex AlphaRail System at an educational level. Calibration tables, thresholds and workbook internals are deliberately excluded. Interactive outputs are produced by the site's own preview engine and are simulated demonstrations, not historical or live results.

Positioning · Two products, two jobs

MARS runs the trading operation.
This laboratory proves what deserves to be deployed.

Why the subscription recurs

A one-time simulator with static outputs would eventually feel like a downloadable product, and would deserve to. These are the six things that keep arriving.

And if you do not own the workbook,
none of this is a prerequisite.

The same concept, under two names