Agents.
The operator's spec, for builders who want to integrate early. Everything here is a shape, not a shipment — Phase 1 starts the build.
What it feels like when the operator is on watch. Stakes first; mechanics after.
The budget you can't blow
You hand Vigil a daily cap and a watchlist. Overnight it acts only inside both. Morning brings a ledger — not a story.
The treasury that runs itself
A small DAO points Vigil at its runway: settle in USDG, surface anomalies, stay inside the committee's declared limits.
The inbox that closes
Escalations reach you only when a human is genuinely needed. Everything else is handled — and recorded.
The quiet night
Some nights nothing should happen. The operator holds, the ledger notes the non-action, and nobody invents busywork.
Four objects, one worldview: an operator works inside limits you can read.
Loop
What to watch. A named set of positions, pools and prices — plus the conditions worth waking up for. Phase 1.
Budget
What it may spend. Per-loop limits and stop conditions. Together they form the operator's entire spending authority. Phase 2.
Ledger
What happened. Append-only entries: every check, every settle, every non-action that mattered. Phase 3.
Report
What reaches you. A scheduled brief assembled from the ledger — the morning read. Phase 3.
Shape of the HTTP surface. Base URL is a placeholder — it publishes with Phase 1.
POST /v1/loops create a watch loop Phase 1PUT /v1/loops/:id/budget set limits & stops Phase 2GET /v1/ledger read the record Phase 3GET /v1/reports/latest the morning brief Phase 3Four moves, one loop — each move maps to one object, and nothing moves outside declared conditions.
Point
You name what to watch — positions, pools, prices. That becomes a Loop.
Cap
You hand it limits and stop conditions. That becomes a Budget — and the operator's entire spending authority. Phase 2.
Watch
The loop runs through the night inside those boundaries. Findings land in the log. Phase 1.
Read
Morning brings a Report assembled from the Ledger — a reading, not an interview. Phase 3.
Wallet signature
No accounts, no emails, no API keys floating in screenshots. Sign once per session; scopes follow the wallet.
No key handling
The API never asks for keys. Anything that could move funds passes through budget gates first. Phase 2.
Questions we get — including the ones about what we don't do.
Can Vigil move funds on its own?
Only inside the budget and stop conditions you declared. Outside them it cannot act — by design, not by policy.
Does Vigil hold my assets?
No. Custody is not in the design. Keys stay with you; settlement happens on the rail.
Is this live?
The spec is live; the runtime is not. Phase 1 starts the build — the phases on this site are the schedule.
What happens on a quiet night?
Nothing forced. A quiet night is a valid outcome, and the ledger records the non-action.
The operator spends only from its loop budget. The project spends only from treasury. Fee routing is published as policy (Phase 2) — ~50% treasury · ~30% burn · ~20% incentives. No custody, no pooled funds, no middle account — in either direction.
Engineering honesty: the decisions we haven't made yet.
Report format
Plain text, structured JSON, or both? Leaning both — defaulting to plain.
Escalation channel
Which channel gets the 3 a.m. page: X, email, or the loop's own log?
Stop defaults
What ships as the safe default when a user sets no stop conditions at all?
Ledger anchoring
Hash-only entries, or periodic on-chain anchoring? Cost and auditability both argue.