| # Guarded Executor Contract | |
| The aggregator does not place orders. | |
| Any future executor must satisfy this contract: | |
| ## Required checks | |
| - dry-run/live posture | |
| - HALT_TRADING env var | |
| - `.membra_halt` file | |
| - position guard | |
| - max notional | |
| - max contracts | |
| - max inventory per symbol | |
| - max total exposure | |
| - recovery protocol state | |
| - audit receipt before and after attempt | |
| ## Forbidden | |
| - raw exchange client calls from strategy modules | |
| - live mode default | |
| - credential logging | |
| - background daemon without visible PID/receipt | |
| - auto-reopen behavior without explicit policy and cap | |