> Current deployment: September 21 perpetual generation, source e4c87fc. See [current integration evidence](reviews/2026-09-21-deployment/REVIEW.md). Earlier fee and dated-only assumptions below are historical.

> Status: the minimum live version is implemented and enabled on the Base trial. See [review synthesis](reviews/2026-09-15-live/SYNTHESIS.md) and [validation](reviews/2026-09-15-live/VALIDATION.md). The original checklist below is historical; no agent real-wallet run was performed.

# Live position creation — gap assessment, 15 September 2026

**Implementation update:** the fresh sanity check rejected the proposed persistent
operation records and duplicate preflight machinery. The reduced
[implementation brief](reviews/2026-09-15-live/subtraction-brief.md) governs the
implementation; this assessment remains the record of identified product gaps.

The current interface can be the basis for the live flow. The remaining work is
transaction execution, configuration and lifecycle recovery. No signing or
transaction capability was enabled during this assessment.

## Already present

External-wallet connection with account/network invalidation; verified Base
position discovery; index plus direct-chain tail and fallback; historical wallet
cache; live collateral/debt/order reads; HF scenarios; tutorial funding/borrowing;
position-specific Borrow, Repay and Roll reviews; CoW history links.

The backend's FRONTEND_CHECKLIST still contains old “no client” entries. Those
are not a current assessment of this workspace. The gaps below were checked
against the actual frontend and current contract source.

## Required for first live deposits

| Gap | Current evidence | Work before enabling |
|---|---|---|
| Release and complete creation inputs | `config.js` names a Base trial deployment; the builder has example amounts/strike/date only | Pin the intended factory/implementation/ABI and initial asset pairs. Define IV, short grid, slippage cap, minimum trade value, annual fee and recipient. Show immutable terms in review. |
| Live sizing and preflight | `model.js` validates local examples, with a manually entered market price and illustrative risk weights | Read wallet balances/allowances, actual reserve eligibility/caps, oracle/sequencer state and gas. Validate the exact factory limits. Calculate notional, starting inventory, first hedge and useful trade size from live inputs. |
| Per-position CoW appData | The factory tuple contains a hash; no frontend builder/uploader exists | Predict the pair, build/hash/register its appData with the `syncCollateral()` post-hook before funding, and verify the registered pre-image. An arbitrary hash can leave funded positions unable to publish orders. |
| Transaction controller and recovery | WalletSession manages reads; PublicRpc explicitly rejects sending; action dialogs only review | Add real ABI bindings, selected-wallet signing, per-step simulation and buffered gas estimates, approvals, receipts, replacement/cancellation handling and chain-derived funding recovery. Keep public read RPC separate from wallet sending. |
| Getting funds back | No actionable close/withdraw flow exists | Ship debt-free `closePosition()` with accrued-fee/received-asset review and actual balance reconciliation. If borrowing is enabled, repayment must also work before close. `closed()` alone does not mean empty. |
| Acceptance with actual contracts | Existing tests exercise models/readers/cache/UI and read-only providers | Test a pinned Base fork through create, approve, fund, collateral sync, order registration and close. Cover failure recovery and real ABI encoding. Then verify a small explicitly authorized live lifecycle, including posting/filling and withdrawal. |

Creation is not one atomic wallet transaction in the current design:

```text
choose immutable terms and salt
→ predict owner-scoped pair address
→ build/register the pair's CoW appData
→ simulate and create
→ verify receipt, DeploymentResolved and predicted address
→ approve underlying tokens to that pair, where needed
→ recheck reserve state, simulate and fund
→ read actual notional, balances, quantum, collateral flags and orders
```

A successful create followed by rejected/failed funding must resume at the
existing unfunded pair. A refresh or lost receipt must not create a duplicate.
Freeze chain, owner, salt and configuration before signing; recheck context
before each send. Once a transaction is submitted, retain its hash and source
context even if the wallet changes. A changed wallet must not trigger follow-on
transactions or turn “submitted” into “nothing sent.”

The contract accepts a nonzero deposit of either or both assets; the tutorial
currently requires both. Decide the initial supported funding mode explicitly.
Do not mistake that tutorial rule for a contract requirement. Nonzero borrowing
delegation requires both strategy aToken balances to be present. A suggested
starting mix should also account for the first hedge rather than just accepting
two arbitrary positive amounts. Native ETH wrapping is a separate capability;
the current inputs are ERC-20 WETH or wstETH, not native ETH.

## Required before enabling borrowing

`position-flow-model.js` currently compares debt with weighted collateral and
the collateral-based LTV limit. That is appropriate for an action preview, but
it does not reserve collateral for the pending hedge's outgoing transfer.

The backend records a real first-hedge stall on long pair E after borrowing.
Calculate headroom from Aave availability, the chosen HF target, and each pending
trade's post-outflow requirement. Use the actual debt asset and prices. Convert
total-debt ceilings into additional borrowing by subtracting existing debt;
do not mix a total-debt `gateBound` with an additional-debt allowance. Respect
the configured minimum order size and the contract's two-atom outflow pad.

Ordinary borrowing is:

```text
pair.approveCreditDelegation(asset, boundedAmount)
→ Aave Pool.borrow(asset, amount, variableRate, referralCode, pair)
```

The connected owner receives the borrowed tokens; the pair holds the debt.
Repayment goes through Aave on behalf of the pair, with the owner's token
approval where required. Implement accrued interest, finite “repay all” sizing
for repayment on another account, allowance changes and debt readback. Keep the
tutorial's hypothetical 75%/80% parameters out of all live transaction limits.

## Required before enabling rolling

The current Roll dialog performs initial destination checks. It still needs
accrued-fee and transferred-asset estimates, all debt assets, destination debt/
collateral review, delegation preparation, transaction simulation and recovery.
Use `primeFor(source)` only for an authenticated source/destination relationship.
After `rollTo(destination)`, reconcile what arrived and separately activate with
`fundFromHoldings(maxNotional)`. A stopped source can still roll remaining assets.
Priming, rolling and activation are distinct chain states; subsequent actions must
not repeat a completed transfer. See [ROLL-PLAN.md](ROLL-PLAN.md).

## Liveness and initial rollout

The UI should distinguish funded holdings, a valid contract preview, a posted
CoW order and a confirmed fill. The recent hourly-retry investigation shows why
funding must not immediately be labelled “actively hedging.” Verify current
ComposableCoW registration and collateral flags after the first fill; provide
the manual collateral-sync recovery path because CoW hooks are best-effort.

Suggested implementation order: pin the Base deployment/defaults; wire
create/fund/resume and debt-free close; then bounded borrow/repay; then debt rolls
and destination activation. Broader chains and shared solver/fill monitoring can
follow the Base lifecycle proof. This does not call for another visual redesign.

## Source references

- Local contract source: `thetaAaveCattle/src/ThetaCattleFactory.sol` `_resolve`,
  `create`, `predict`; `ThetaCattlePair.sol` `deposit`, `_size`, `_register`,
  `approveCreditDelegation`, `_postTransferHealthy`, `closePosition`, `rollTo`.
- Local design evidence: `docs/DESIGN_NOTES.md` §1.1, §3, §9, §10.11;
  `docs/FRONTEND_NOTES.md` first-hedge and delegation bounds; Base trial report.
- [Aave Pool interface](https://raw.githubusercontent.com/aave/aave-v3-origin/main/src/contracts/interfaces/IPool.sol)
  documents borrowing/repayment and `onBehalfOf`; use the deployed Base behavior
  for final simulation and acceptance.
- [Current CoW appData package](https://github.com/cowprotocol/cow-sdk/tree/main/packages/app-data)
  contains the maintained schema tooling; the older standalone repository is archived.

Outstanding release decisions are the exact deployed generation, initial asset
pairs and immutable parameter defaults. These can be made concrete in the live
review form before any real funding is enabled.
