Ballast 0.4.4-beta · Windows · invited beta
Ballast 0.4.2-beta — confirmations, consolidation runners and update access
Invited beta release prepared September 18, 2026. Availability follows the beta channel; an installed copy changes only when its user applies the signed patch.
Orders you can trace
Crypto holdings and order details now use account-specific reads for the same account used by the existing submission route. This fixes a case where the broker filled a purchase but older read endpoints returned no order or holdings. Matching account, broker ID, client reference, symbol and side, with finite execution values, are required. Quotes never substitute for fills.
Pending orders appear on the Bot page with status and age. Do not resubmit an unresolved purchase: its coins may already be at the broker even though the local position is missing. Local exit management for that quantity is unconfirmed until settlement completes. Known, verifiable pending orders are checked on normal cycles. Unidentified orders and legacy interrupted settlements still need manual review.
New crypto settlement uses one database transaction for its position, order, realized result, retained core and pending release. Interrupted writes roll back together. Crypto cannot enter the stock/ETF pyramid or equity-order route. Equity and core fills retain broker IDs and confirmed status for later review. Pending crypto buys cannot become protected owner deposits simply by appearing twice. Daily alert deduplication uses the Eastern trading date across UTC midnight.
Optional consolidation-aware crypto runners
Enable after reviewing System → Crypto consolidation runners, separately for paper and live mode. Existing first-sale size, hard stops, reserves and stop cooldowns remain. Already-armed runners keep their existing policy.
The policy needs a position age of at least 48 hours and 12 observed hours within one ATR below target and above average cost in the previous 72 hours. Collection starts after enabling; no older consolidation is presumed. Intervals longer than ten minutes earn no time, missing quotes break continuity, and changed target or cost resets history. A recent observed approach must precede the target crossing.
At that crossing the first sale proceeds as configured. The remaining runner captures a trail of 1× ATR at 12 observed hours, rising linearly to 2× at 48 hours, with a maximum width of 10%. Its floor is 0.5% above average cost. This replaces the classic target-price floor, peak-age tightening and confirmed-top shortcut. The captured stop only rises after arming. A fast move without that history keeps the classic behavior. System shows earned hours and active policy; the Bot rail shows the actual stop used by the engine.
Wider room can give back substantially more profit. A threshold is not a guaranteed execution price or net return; fees and price gaps can produce a loss. This initial policy is not proven more profitable and is not modeled by the daily-bar backtest.
Historical records and protected holdings
Older releases could store estimated prices or pre-rounding quantities. A maintainer can preview corrections using exact broker execution matches and unambiguous local position/leg/result links. Correction requires a verified private backup, rejects stale plans, commits atomically and retains original records. Installation does not automatically rewrite history. Ambiguous records, incomplete broker history or unknown ownership need review; do not delete holds or lower reserves to hide them. Broker statements remain the source for official execution and tax records.
Privacy, research and email improvements
Community insights require opt-in plus Share now for each snapshot. Update checks and preference changes do not share it. Best-of cards preserve the original research date; unknown dates stay unknown. Exception percentages use the entire retained collection, not its first ten-card preview.
Branded beta notices remind each recipient of their valid download code and link to the versioned download page. Messages remain individual, with an owner copy and unsubscribe/support information. Revoked or expired codes are not revived.
Updating and remaining limits
Use the update prompt or System's update action. Signed file patches preserve credentials, preferences, trading state and STOP, with rollback copies. Local trading checks pause while the service restarts. Review the short patch lessons for orders, runners, community sharing and research dates.
The signed reviewer-evidence companion remains tied to the exact app ZIP. It is evidence of stated checks, not a safety certification. Windows publisher signing, independent review, clean-device acceptance and wider public-launch obligations remain separate readiness work. Local exits require the app/computer to run and usable broker access. Other testers must apply their own update; publishing does not install software remotely.