Roadmap

Every phase has a way to die, printed next to it

A roadmap without kill criteria is a wish list. Each phase below states the gate to proceed and the condition under which the correct decision is to stop, and the kill criteria are set in the same typeface, at the same size, as the gates.

The ordering is deliberate and contrarian: the cheapest, most falsifiable things happen first. Any plan that builds the brokerage before testing whether anyone will fill in a falsifier field has the risk ordering backwards.

Six phases

Gates and kill criteria

PhaseGate to proceedKill criterionStatus
−1
Offline validation
0–2mo
Engine beats naive and market out-of-sample on ≥2 public corpora It doesn't. The engine is the product. Here
0
Forecasting only
0–9mo
5,000 forecasters · ≥30% commit 10+ priors in 60 days · 3 design partners Composer completion <15% Not started
1
Resolution & records
9–18mo
500+ at Established · top decile skill >0 vs market, out-of-sample No cohort beats the market reference Not started
2
First revenue
15–24mo
$1.5M ARR from ≥10 institutions <$300k ARR after 9 months selling Not started
3
Brokerage
24–36mo
BD registration · execution at or better than PFOF venues Can't hit competitive execution without rebates, stay a signal business Not started
4
Token
36mo+
Profitable without it · counsel in every jurisdiction No compliant structure, ship without the token Not started

The next task, specifically

Replay the existing harness against Metaculus question histories, Good Judgment Open, and historical prediction-market prints. sim/validate.js already accepts that input shape, it needs a loader and a real dataset. This is the actual Phase −1 gate, and it de-risks everything downstream. It is also the cheapest thing on this page.

Distributing control

Resolution first, governance last

The protocol's entire value rests on one property: a record nobody can edit. If a single entity controls resolution, it controls every score, and that property is false no matter how many token holders vote on parameters. Governance-first distribution of control is theatre.

StageWhat movesGate to proceed
0. Verifiable
now
Nothing distributed yet, everything auditable. Roots anchored, reveals verifiable, code open Anyone can independently recompute every score from public data
1. Resolution k-of-n bonded independent resolvers; disputes ≥7 operators · none >20% of claims · 30 days no unresolved disputes
2. Adapter registry Open proposal, bonded authorship, fee share to author ≥50 adapters · ≥20 distinct authors · <2% disputed
3. Parameters n₀, half-life, extremization bounds, thresholds Changes demonstrably improve out-of-sample Brier
4. Treasury & upgrades Spending, upgrades, fee levels Stages 1–3 stable for 12 months

Adapter lifecycle

propose → bond → shadow (90 days resolving in public, nothing depending on it) → ratify → live → earn

Bonded, slashable on proven misresolution, and forkable, anyone may propose a competing adapter, operators choose, and the better spec wins on disagreement rate. This is closer to open-source package maintenance than to governance.

Capture risks

  • One operator resolves most claims → hard cap on share; fee share declines above threshold
  • Adapter author biases their own adapter → bonded, slashable; redundant operators run the same spec
  • Committee capture → seats sampled per-dispute, weighted by claim-class skill; soulbound records make accumulation slow and unsellable
  • Token-weighted governance buys parameters → parameters gated on measurable out-of-sample improvement, not votes alone
  • Sybil forecasters farm the boardnot solved. See below.

Risks

The five ways this dies

01 · High

Friction kills adoption

The composer asks for a claim, a probability, a horizon and a falsifier. Robinhood asks for a tap. If honest conversion is 10:1 rather than 2:1, there is no consumer product at any level of elegance.

Detection: a forecasting-only phase measuring composer completion. If <30% of registered users commit 10+ priors in 60 days, the thesis is wrong, and no money has been spent.

02 · Certain

Sybil attacks on calibration

The unsolved one, and the most likely technical cause of death. Currently rests on proof-of-uniqueness, which is not solved in general.

Shrinkage (n₀ = 100) and market-relative scoring raise the cost but do not eliminate the shotgun attack: register many identities, forecast randomly, surface the lucky one. The question is whether defences hold, not whether it is attempted.

03 · Medium-high

The corpus is real and nobody buys it

Funds are slow and suspicious of retail-sourced anything. The entire revenue model assumes institutional buyers who may simply never sign.

Mitigation: design partners signed before the corpus exists, with the claim taxonomy built to their spec rather than ours.

04 · Medium

An incumbent copies the feature

They can ship the composer in a sprint. What they cannot ship is an honest scoreboard that tells users to stop trading, or hand back half of signal revenue, or abandon $776M a quarter of transaction revenue.

We are not better at the feature, we are differently paid. That is the moat, and it is a business-model moat, not a technical one.

05 · Low but existential

Calibration may not convert into returns

Returns depend on sizing, timing, costs and tails, not only directional accuracy. Calibration is necessary and not sufficient.

Hence Kelly sizing in the composer, and positioning the signal as an input to a process rather than as a trade recommendation.

Which two actually decide it

Failure modes 1 and 3. Both are testable in a forecasting-only phase, for a fraction of the cost of building a brokerage.

That is the entire argument for the phase ordering on this page. Everything expensive is deliberately downstream of everything falsifiable.

Regulatory posture

Honest, not reassuring

ExposureSeverityTrigger
Investment adviser statusHighPublishing scored, personalised forecasts users act on
Token as securityHighStaking with fee-linked returns
Broker-dealer obligationsMediumStandard, expensive, not novel
Data rights over user priorsMediumLicensing user-generated content that is also personal data

Adviser status

The publisher's exclusion narrows sharply once content is personalised. Mitigations: the platform never states a probability, users and registered agents do; no personalisation in the institutional feed; and register as an RIA if the honest reading requires it. That is the likely answer. Budget for it.

What we explicitly rejected

Launching anonymously from a jurisdiction with no framework. It forecloses every institutional buyer, and institutional buyers are the revenue model. No fund compliance desk subscribes to a signal feed from an anonymous team.

The compliant path is not the cautious option here, it is the only one where the business exists.