Seven specialist systems. One portfolio brain. Two exclusive brokerage boundaries.
Research → falsification → assurance → policy → allocation → routing → reconciliation → learning.
DumbMoney is the public-source composition root for a local-first, multi-agent market research and portfolio orchestration system. It binds forecasting, technical analysis, experimental research, constitutional governance, cyber-assurance, portfolio allocation, and venue-specific brokerage cells into one replayable operating loop.
It is designed around a simple premise:
Intelligence may propose. Evidence may qualify. Policy may permit. Only the assigned venue owner may act.
DumbMoney is not an eighth peer agent. It is the organism around the agents: the scheduler, memory spine, portfolio allocator, router, reconciler, recovery system, and observability plane.
| Question | Current answer |
|---|---|
| What is it? | A public-source reference architecture and executable local harness for an autonomous, evidence-gated multi-agent fund. |
| What is integrated? | Seven exact, content-addressed ObtuseAI component snapshots plus the DumbMoney orchestration runtime. |
| What runs today? | Deterministic provider-free replay, read-only forward evidence collection, model-budget allocation, technical analysis, evidence courts, assurance gates, routing simulation, reconciliation, and dashboards. |
| What does not happen by cloning? | Live orders, broker authentication, capital activation, automatic strategy promotion, or profitability claims. |
| Who owns Robinhood? | Dopey, exclusively. |
| Who owns Kalshi? | Dummy, exclusively. |
| Can DumbMoney call a broker? | No. It produces venue-owned intents; it never owns broker API authority. |
| Can research promote itself? | No. Doofus can recommend a challenger but cannot self-promote or trade. |
| Is the system profitable? | Not established. Synthetic replay and operational health are not profitability evidence. |
| Runtime posture | Public source, private local state, ignored credentials, loopback status surfaces, explicit activation. |
flowchart LR
subgraph SENSE["SENSE"]
DIMWIT["Dimwit<br/>chart + technical intelligence"]
WATERBOY["Waterboy<br/>sports forecasting"]
VENUEOBS["Dummy + Dopey<br/>venue observations"]
end
subgraph THINK["THINK"]
DOOFUS["Doofus<br/>research + evidence court"]
NIMROD["Nimrod<br/>provenance + cyber assurance"]
end
subgraph GOVERN["GOVERN"]
BLUNDER["Blunder<br/>constitutional policy"]
DUMBMONEY["DumbMoney<br/>portfolio brain"]
end
subgraph ACT["ROUTE + ACT"]
DUMMY["Dummy<br/>Kalshi owner"]
DOPEY["Dopey<br/>Robinhood owner"]
end
LEDGER["Content-addressed evidence<br/>reconciliation + memory"]
DIMWIT --> DOOFUS
WATERBOY --> DOOFUS
VENUEOBS --> DOOFUS
DOOFUS --> NIMROD
NIMROD --> BLUNDER
BLUNDER --> DUMBMONEY
DUMBMONEY -->|"Kalshi intent only"| DUMMY
DUMBMONEY -->|"Robinhood intent only"| DOPEY
DUMMY --> LEDGER
DOPEY --> LEDGER
LEDGER --> DUMBMONEY
LEDGER --> DOOFUS
This separation is structural, not just descriptive. The machine-readable
topology in configs/architecture.v5.json
binds every cell to its assignment, authority ceiling, input/output contract,
and venue route. Runtime validation fails if those assignments drift.
| System | Role | Core skills and tools | Produces | Authority ceiling |
|---|---|---|---|---|
| DumbMoney | Fund harness and portfolio brain | Scheduling, durable memory, budget auctions, allocation, routing, reconciliation, recovery, telemetry, API/dashboard | Portfolio envelopes, venue-owned broker intents, ledger events, health reports | No broker credentials, no broker API calls, no self-promotion |
| Blunder | Constitutional control plane | Permissions, policy evaluation, capital limits, quorum, stop/kill state, release gates | Policy decisions and bounded authority envelopes | Governs; does not place venue orders |
| Dimwit | Market perception and technical analysis | Chart perception contracts, OHLCV validation, SMA, EMA, MACD, RSI, ATR, Bollinger bands, support/resistance | Content-addressed technical observations | Research input only; no probability invention, credentials, or orders |
| Waterboy | Sports intelligence | Point-in-time sports data, projections, calibration, schedule and result normalization | Sports forecasts and evidence packets | Research input only; never routes directly to Kalshi |
| Doofus | Research laboratory and evidence court | Hypothesis generation, adversarial falsification, held-out evaluation, embargoes, leakage checks, calibration, champion/challenger experiments | Evidence verdicts, retest plans, challenger recommendations | Cannot trade or automatically promote its own work |
| Nimrod | Constitutional cyber-defense assurance | Provenance, integrity, replay, Witness records, cross-implementation checks, read-only observation | Security-assurance verdicts and exact blocked states | No target mutation, containment, trading, or self-authorization |
| Dummy | Exclusive Kalshi brokerage cell | Prediction-market research, market normalization, probability forecasts, Kalshi execution contracts, settlement and calibration | Kalshi receipts, fills, abstentions, outcomes | Only Kalshi; live action still requires explicit external authority |
| Dopey | Exclusive Robinhood brokerage cell | Equities, options, crypto research, broker/account reconciliation, defined-risk execution contracts | Robinhood receipts, fills, abstentions, account evidence | Only Robinhood; live action still requires explicit external authority |
The component names are intentionally memorable. Their contracts are not casual: every crossing between cells is typed, content-addressed, replayable, and authority-bounded.
Dimwit receives chronological, timezone-aware OHLCV and produces deterministic descriptive indicators:
- SMA20;
- EMA12 and EMA26;
- MACD;
- RSI14;
- ATR14;
- Bollinger bounds;
- rolling support and resistance;
- alignment state and source digest.
It does not convert an indicator into a probability or expected return.
Without a point-in-time, embargoed, leakage-cleared, cost-stressed mapping to
outcomes, Doofus returns BLOCKED_RESEARCH_INPUT_ONLY.
flowchart LR
OHLCV["OHLCV / chart evidence"] --> DIMWIT["Dimwit analysis"]
DIMWIT --> INPUT["Research input only"]
INPUT --> COURT["Doofus held-out court"]
COURT -->|"insufficient evidence"| BLOCK["Blocked + experiment request"]
COURT -->|"qualified"| CHALLENGER["Shadow challenger recommendation"]
CHALLENGER -. "never auto-promotes" .-> PORTFOLIO["DumbMoney portfolio"]
Waterboy owns sports forecasting. Dummy owns Kalshi. They are deliberately not the same role.
Waterboy forecasts flow through Doofus falsification, Nimrod assurance, Blunder policy, and DumbMoney allocation before a Kalshi intent can reach Dummy. Waterboy never receives Kalshi credentials.
flowchart LR
DATA["Sports data"] --> WATERBOY["Waterboy forecast"]
WATERBOY --> DOOFUS["Doofus evidence court"]
DOOFUS --> NIMROD["Nimrod assurance"]
NIMROD --> BLUNDER["Blunder policy"]
BLUNDER --> FUND["DumbMoney allocation"]
FUND -->|"Kalshi route"| DUMMY["Dummy"]
A thesis may create different candidates for prediction markets and securities, but the system does not pretend those instruments are interchangeable.
Each venue receives:
- its own market snapshot;
- its own cost model;
- its own liquidity and risk estimate;
- its own evidence verdict;
- its own allocation;
- its own reconciliation record.
The shared thesis is learned across venues only after outcomes are frozen and settled. This supports cross-domain learning without cross-venue authority leakage.
DumbMoney converts qualified candidates into a portfolio, not a list of independent bets. Allocation accounts for evidence strength, uncertainty, cost, risk, correlation tags, capital ceilings, and constitutional policy.
The resulting route is exact:
| Destination | Required owner | Other cells |
|---|---|---|
dummy_kalshi |
Dummy | Rejected |
dopey_robinhood |
Dopey | Rejected |
| Direct broker call from DumbMoney | Nobody | Forbidden |
| Direct order from Dimwit, Waterboy, Doofus, Nimrod, or Blunder | Nobody | Forbidden |
Provider-free replay emits SHADOW_SIMULATE_ONLY intents with zero broker
calls and no execution authority.
Every cycle separates generation, evaluation, promotion, and action:
stateDiagram-v2
[*] --> Hypothesis
Hypothesis --> FrozenCandidate
FrozenCandidate --> AdversarialEvaluation
AdversarialEvaluation --> Rejected
AdversarialEvaluation --> ShadowChallenger
ShadowChallenger --> SettledEvidence
SettledEvidence --> Retest
SettledEvidence --> PromotionRecommendation
PromotionRecommendation --> HumanOrConstitutionalReview
HumanOrConstitutionalReview --> ResearchOnly
HumanOrConstitutionalReview --> BoundedDeployment
BoundedDeployment --> SettledEvidence
Doofus can mutate hypotheses and recommend challengers. It cannot edit the rules that judge it, choose its own hidden test, grant itself execution authority, or erase losing evidence.
Nimrod validates the local architecture digest, component health, source lineage, candidate authority, research verdicts, and immutable fixture digest before routing. A mismatch produces an exact blocked state.
DumbMoney adds:
- restart-safe stage checkpoints;
- a hash-linked SQLite event ledger;
- durable stop and kill state;
- content-addressed source snapshots;
- idempotent imports;
- watchdog heartbeats;
- verified backups;
- fail-closed service recovery.
Assurance is evidence supplied to governance. It does not authorize itself.
OpenRouter is an optional bounded reasoning layer, not an unlimited brain.
DumbMoney allocates a hard $10/day budget:
| Lane | Daily ceiling | Purpose |
|---|---|---|
| Research | $6.00 | Hypothesis development and information gathering |
| Evaluation | $2.00 | Critique, falsification, and uncertainty reduction |
| Operations | $2.00 | Summaries, diagnostics, and bounded coordination |
Requests compete on expected value of information and uncertainty reduction. Ambiguous provider outcomes are conservatively charged. Provider permission is opt-in, ZDR is requested, and model output never receives trading authority.
Most agent systems connect a model to tools and call the result autonomy. DumbMoney separates cognition from permission. A persuasive forecast remains untrusted until evidence, assurance, policy, allocation, and venue ownership all agree.
DumbMoney is not another voter competing with its cells. It is the deterministic environment in which specialists operate: shared memory, capital accounting, routing, recovery, and observability live above the individual agents.
Doofus generates and challenges strategies, but promotion evidence must be point-in-time, held out, cost stressed, leakage checked, and preserved. Synthetic success is labeled synthetic and cannot silently become a live claim.
Nimrod is not a perimeter add-on. Provenance and integrity become explicit inputs before capital routing, while Blunder remains the independent constitutional authority.
Dummy and Dopey do not share a generic execution client. Kalshi and Robinhood actions terminate in different cells, with different evidence, reconciliation, and failure semantics.
The system grows by accumulating immutable observations, predictions, settlements, calibration, rejected hypotheses, and retest results. It is built to compound knowledge while preventing a successful demo from becoming its own authorization.
| Plane | Implemented capabilities |
|---|---|
| Orchestration | Fifteen-stage restart-safe supervisor, continuous mode, deterministic replay, stage checkpoints |
| Evidence | Content-addressed observations, frozen candidates, outcome separation, settlement, calibration |
| Research | Adversarial verdicts, held-out TA court, champion/challenger recommendations, quarantine and retest |
| Portfolio | Proof-weighted allocation, risk/cost inputs, correlation tags, venue allocation |
| Technical analysis | Deterministic stock/crypto OHLCV indicators and research-only classifications |
| Dopey data plane | Verified 13,112-file catalog, normalized equity history, zero-authority options context, and research-memory provenance |
| Walk-forward research | Rolling train/holdout folds, outcome embargo, round-trip costs, drawdown, Brier calibration, and regime diagnostics |
| Shadow campaign | Content-addressed, deduplicated evidence units and ranked 20-symbol strategy results without promotion authority |
| Sports | Point-in-time sports observations and evidence-routed Kalshi candidates |
| Assurance | Seven-tree integrity checks, architecture invariants, Nimrod read-only verdicts |
| Governance | Blunder policy contracts, durable stop/kill, explicit authority ceilings |
| Routing | Exclusive Dummy/Kalshi and Dopey/Robinhood broker intents |
| Model gateway | Optional OpenRouter, hard daily/lane budgets, conservative accounting, ZDR request |
| Operations | Loopback GET-only API, dashboard, watchdog, Windows persistence plans, verified SQLite backups |
| Portability | Exact component materialization and isolated Python environment per cell |
| Data handoff | Secret-rejecting, content-addressed Dopey data intake without changing frozen source |
The committed provider-free scenario is visibly synthetic and exercises the whole control flow without network, model, or broker calls:
uv sync --frozen
uv run dm architecture-status
uv run dm doctor
uv run dm replayCurrent expected replay:
components healthy 7
Dimwit TA observations 1
TA candidates promoted 0
research inputs blocked 1
Nimrod assurance PASS_READ_ONLY_ASSURANCE
portfolio candidates 4
Dummy / Kalshi intents 2
Dopey / Robinhood intents 2
provider calls 0
broker calls 0
live activation false
profitability evidence false
Replay digest:
28d0813b814d6d99966763a78555041caceef24483ebd3e4153d762333919037
uv run dm bootstrap --plan-only
uv run dm bootstrap
uv run dm doctor --require-environments
uv run dm architecture-status
uv run dm technical-analysis --input C:\path\to\synthetic-ohlcv.json
uv run dm replay
uv run dm shadow --continuous --serve
uv run dm forward --continuous --serve --allow-network
uv run dm forward-status
uv run dm verify-ledger
uv run dm stop
uv run dm kill
uv run dm resumeOpenRouter is contacted only when --allow-provider is supplied and
OPENROUTER_API_KEY exists in the process environment.
The Dopey laptop handoff accepts either the original verified v4 directory bundle or the simple content-addressed v5 ZIP, including SQLite research indexes. See Dopey Data Drop v5.
The imported data can drive the provider-free real-data research loop without changing the frozen Dopey source tree:
uv run dm dopey-data-catalog
uv run dm dopey-research
uv run dm dopey-research-status
uv run dm dopey-campaign-statusDimwit produces technical observations, Doofus runs disjoint cost-stressed
walk-forward holdouts, Nimrod verifies lineage and temporal controls, and
DumbMoney may emit only SHADOW_SIMULATE_ONLY Robinhood intents to Dopey.
Options and trade memory have zero directional authority. See
Dopey Real-Data Research v6. The
campaign ranks all 80 symbol/strategy pairs across the configured 20-symbol
universe. Re-running unchanged market data records duplicate observations but
does not inflate distinct evidence.
Dopey's final laptop-generated public runner configuration is a separate single-file handoff:
uv run dm dopey-runner-config-verify --source C:\path\to\dopey-robinhood-runner.v1.json
uv run dm dopey-runner-config-import --source C:\path\to\dopey-robinhood-runner.v1.json
uv run dm dopey-runner-config-statusThe importer is secret-rejecting, content-addressed, and non-activating. See Dopey single-file runner configuration. The Windows service plan schedules this provider-free research once daily and runs one bounded cycle immediately after installation.
The status service is loopback-only and rejects POST:
GET /health/live
GET /health/ready
GET /v1/status
GET /v1/cycles
GET /v1/events
GET /v1/ledger/head
GET /v1/budget
GET /v2/forward/status
GET /v2/scorecards
GET /v2/predictions
GET /v2/settlements
GET /v2/snapshots
GET /v2/service
GET /v4/dopey-handoff
GET /v5/architecture
GET /v6/dopey-research
GET /v7/dopey-campaign
The forward dashboard runs at http://127.0.0.1:8791/dashboard when enabled. It presents evidence maturity, calibration, raw and independent sample counts, the ranked Dopey shadow campaign, model budget, runtime health, Dopey handoff state, and the seven-cell architecture.
DumbMoney/
├── configs/ # runtime, model, service, architecture
├── contracts/ # versioned inter-cell contracts
├── docs/ # architecture and evidence specifications
├── fixtures/ # visibly synthetic deterministic scenarios
├── projects/
│ ├── blunder/ # constitutional control plane
│ ├── dimwit/ # chart + technical intelligence
│ ├── doofus/ # research + evidence court
│ ├── waterboy/ # sports intelligence
│ ├── nimrod/ # cyber-defense assurance
│ ├── dopey/ # Robinhood brokerage owner
│ └── dummy/ # Kalshi brokerage owner
├── scripts/ # bootstrap, service, handoff, validation
├── src/dumbmoney/ # composition root and runtime
├── tests/ # integration, replay, API, recovery tests
├── DUMBMONEY_WORKSPACE.json # content-addressed workspace manifest
└── pyproject.toml
Each component keeps its own original README, landing assets, notices, and license. DumbMoney validates each integrated subtree against its recorded Git tree, preventing accidental edits to the embedded source snapshots.
| Component | Upstream | Integrated tree |
|---|---|---|
| Blunder | ObtuseAI/blunder |
398736f9e72e73b86190bae45d2fb526a67fad39 |
| Dummy | ObtuseAI/dummy |
65794d672fa001f2b34489e307ce4883245a7830 |
| Dopey | ObtuseAI/dopey |
d0c581da3c5d8e429490e244ef01a4b2d82eaae7 |
| Doofus | ObtuseAI/doofus |
a48260166f317ebc224506af741a65c88a2ed9d0 |
| Waterboy | ObtuseAI/waterboy |
95bd0fefdd1462c1113a4c845b29f859d164446b |
| Dimwit | ObtuseAI/dimwit |
77eddc59e2a70ce18647f8555b4dcb3f06722200 |
| Nimrod | ObtuseAI/nimrod |
0618ac4a9644f54905476e4e3855ea55e776c078 |
Materialize any component as a standalone local Git repository without a network fetch:
python scripts/materialize_component.py dimwit C:\DumbMoneyRuntime\dimwit
python scripts/materialize_component.py nimrod C:\DumbMoneyRuntime\nimrodpython scripts/validate_workspace.py
python scripts/scan_secrets.py --root .
uv run python -m unittest discover -s tests -v
uv run dm architecture-status
uv run dm replay --assert-digest 28d0813b814d6d99966763a78555041caceef24483ebd3e4153d762333919037
uv run dm verify-ledger
uv buildCI runs the integrated workflow on Windows with Python 3.12 and 3.14.
DumbMoney is public source with private local operation.
The repository intentionally excludes:
- broker credentials and browser sessions;
- account history and private market data;
- model-provider API keys;
- live runtime databases;
- local state, logs, imports, and backups;
- signed operator authority;
- deployment-specific capital limits.
A clone is research-only until the operator separately supplies every required credential, dataset, policy, deployment receipt, and explicit authority. Nothing in this repository is financial advice, an offer to manage capital, a profitability claim, or authorization to place an order.
DumbMoney is source-available under LICENSE. Integrated component
trees retain their own license terms under projects/<component>/LICENSE.
Third-party materials remain governed by their respective terms.
See SECURITY.md for reporting and operational boundaries.
DumbMoney compounds evidence before it compounds capital.