14–15 September 2026 · Sequential design record

A little ghost.
A clearer picture.

From early explorations to a working Cattle preview. Each pass records its question, what changed and what we kept. Generated concepts and browser captures are labeled separately.

Try the current preview
01

The starting point

Familiar principles. Cattle’s own character.

The brief: build a framework-free landing page and app around a cutesy ghostly cow, using the imagegen design guide and the existing Eiko, Gyro, Odette and Meryl work as references.

Keep: clear main actions, readable position summaries, optional explanations and large touch targets. Explore: a soft mint-and-lilac identity with a helpful ghost cow. The references guide the presentation; Cattle’s own source defines the product.
02

Three hypotheses · generated concepts

Which first step makes sense?

These initial concepts used a tentative ThetaCow “price and date” brief while the product question was pending. The user then clarified Cattle’s long/short scope. Their visual ideas remain useful; their product framing is superseded.

Superseded concept A: a lavender guided asset, price and date wizard with a ghost cow.
Superseded product briefA · The gentle guideHypothesis: one decision at a time helps a newcomer. Keep the friendly companion. Reject the asset-swap framing and the forced wizard for Cattle’s first screen.
Superseded concept B: a mint one-page price-and-date ticket with a readable summary.
Visual direction carried forwardB · The open ticketHypothesis: a form and summary together make the choice easier to inspect. Adopt mint, white and lilac. Replace Buy/Sell with Cattle’s two option strategies.
Superseded concept C: a dark moonlit positions workspace with a separate creation form.
Revisited in step 08C · Moonlit pastureHypothesis: lead with positions for returning users. Keep an honest empty state. Reject the large scene, duplicate creation actions and invented wallet control.
Semantic review: B invents “ETH, ETH, or a mix” and implies a conventional limit-order fill. C adds Connect wallet to a preview. None of this raster copy was accepted as a product specification.
03

User correction → source review → revised concept

Strategy, collateral and borrowing.

The user clarified that ThetaCow is specific to the short side, while ThetaCattle handles capital-efficient long and short exposure. Source review in thetaAaveCattle/ established the three parts that the interface must keep distinct.

Corrected Cattle concept: long-call and covered-short choices, two collateral inputs, explicit strike units, and a separate optional-borrowing group.
D · One strategy, three moving partsGenerated proposal. Adopted as the first implementation direction. The user approved the preview and requested wallet integration; see step 07.
ObservationDecisionReason
Long and short are option strategiesAdopt explicit names and behaviorLong call buys into strength. Covered short sells into strength. A covered short is not a bearish leveraged short.
Collateral has two assetsShow both underlying amountsBoth are supplied to Aave. A live starting mix must be quoted and validated.
Strike is quote per baseShow USDC per WETHA dollar sign alone silently changes the product’s units.
Borrowing is optionalSeparate it from creationDebt adds interest, liquidation exposure and possible trade restrictions.
Short uses a pink down arrowReject the arrow shorthandIt suggests a price-down bet. The native UI uses the trading behavior instead.
Generated borrow buttons look liveAdapt into a labeled learning exampleNo live quote, reserve checks or transaction integration is available.
Several nested summaries repeatSimplify in codeOne receipt and one borrowing explanation are enough.
04

Built-in imagegen · project assets

A companion with a job to do.

Two transparent raster illustrations give the landing, summary and empty state a consistent identity. Controls, units and diagrams remain native HTML/CSS. No incoming coin stream or safety shield implies a guaranteed result.

White ghost cow with lilac spots floating over a sage cushion.
The curious companionimg/assets/hero-mascot.png
Used in the landing hero. Original generated artwork; not an Aave or CoW logo.
Helpful ghost cow holding an abstract receipt.
A little clarityimg/assets/guide-mascot.png
Used in the strategy summary and empty local-example view.
Generation method and full prompts

All four UI proposals and both final assets used the built-in imagegen tool. Prompts, exact source references, scope decisions and the illustration prompts are preserved in DESIGN-NOTES.md. The alpha channels are preserved in the project PNGs.

05

Native implementation · interactive preview

From a picture to a usable page.

The builder supports both strategies, validates both amounts and a future expiry, explains strike units, and reviews a frozen copy of the inputs. Examples can be saved and removed locally. The guide and borrowing lesson are optional native dialogs.

Landing · actual browser captures

Live /dev/cattle/ preview · 1440 × 1050 desktop and 390 × 844 phone viewports · full-page captures · no wallet · default Long call comparison.

Implemented desktop landing with ghost cow, three product parts and native strategy comparison.
Desktop landingMint, lilac and a clear introduction to strategy, collateral and borrowing.
Actual 390-pixel landing page retaining both strategy choices and optional borrowing.
Phone landingThe same product meanings in a stacked layout.

Builder · first implementation → refined

Base WETH/USDC example · Long call · 0.25 WETH + 600 USDC · strike 2,400 USDC/WETH · expiry 28 September 2026, 00:00 UTC. CSS v2; the later JS v3 change adds focus cycling without changing the captured layout.

Refined desktop builder with two strategy choices, dual collateral and separate borrowing explanation.
Refined desktopOne form, one summary and an optional borrowing lesson.
Actual phone builder with both strategy explanations, deposit units and expiry.
Refined phoneLarger help targets, shorter heading and quieter mascot.
Pass 2, from the actual browser: make help actions at least 44px; stack the phone examples action; remove the crowded handwritten aside; explain the liquidation threshold; keep Tab and Shift+Tab inside dialogs. First desktop capture · First phone capture.

Review, save and understand borrowing

Actual covered-short review with 0.5 WETH, 1200 USDC and a 3000 USDC per WETH strike.
Review the exact inputsCovered short · 0.5 WETH + 1,200 USDC · 3,000 USDC/WETH · 28 September 2026. Local-example acknowledgement required.
Actual saved example, explicitly labeled as unfunded, on a 390-pixel phone.
Ideas that survive a reloadSaved inputs persist. Removing the example restores the empty state.
Actual borrowing lesson: current HF 1.07, post-outflow HF 0.85, blocked hedge.
A healthy account can still stallSeparate teaching fixture. The dialog scrolls to assumptions and its final action.
Scope: this is a design preview, not a release of transaction functionality. No wallet, quote or execution state is fabricated. Live creation remains a separate integration task.
06

Behavior and understanding

Test what the page teaches.

Browser behavior can be checked now. Whether an unfamiliar user understands the product still needs user testing.

CheckResultEvidence scope
Input/model tests12 / 12 passExact decimals, both deposit legs, invalid dates, malformed/denied storage, preserved past examples and independent borrowing anchors.
App interactionsPassLong/short switching, edits, frozen review, acknowledgement, save, reload and remove.
Negative amount / past dateReview remains closedField error appears and focus moves to the invalid input.
Borrowing lessonExpected health valuesNo debt: no finite HF. Moderate debt: 2.00 → 1.90. Large hedge: 1.07 → 0.85, labeled blocked.
Keyboard dialogsPass after refinementTab/Shift+Tab cycle inside Guide; Escape returns focus to Guide.
Responsive geometryNo horizontal page overflowApp at 320, 390, 768, 1440 CSS px. Landing at 320, 390, 1440 CSS px. Main review button: 55px high.
Console and artworkNo observed app errors or broken app imagesLive /dev/cattle/ checks. Generated PNG alpha preserved.
Live finance and comprehensionNot testedNo wallet/contract integration or newcomer study in this preview.

Phone evidence uses measured viewport emulation. Window resizing alone did not change the viewport. A background-page capture stalled; checking resumed after selecting the target tab.

Questions for a newcomer

  1. Does “covered short” mean you profit whenever price falls?
  2. What goes into the position: an option premium or both collateral assets?
  3. Is borrowing automatic? What additional risk does it introduce?
  4. Why might a position’s next hedge be blocked while its current health factor is above one?

Record wrong turns and hesitation before changing the UI again. This journal does not claim measured comprehension or conversion gains.

07

Approved preview → external wallet and live positions

A real pasture, with room to explore.

The user approved the initial direction and requested wallet integration using Gyro, Eiko and Odette as references. Cattle may hold a large position, so the chosen pattern uses an external wallet. The app now opens on positions; the example builder remains one tab away.

NeedDecisionBehavior
Connect a chosen walletCattle-owned copy of Gyro’s bridgeInjected wallets, WalletConnect and Coinbase. No temporary wallet or private-key storage.
Explore without fundsThree explicit view choicesMy wallet, sample data and live address preview. A fresh preview never reconnects a remembered wallet.
Debug the backend trialOne-click thetadeployer addressShows the verified short D and long E positions, current collateral, debt, health and trade previews.
Prevent stale identityClear and reload on source/account changesSuperseded requests cannot publish data under another address. Disconnect removes listeners and reconnect preference.
Show account state accuratelySeparate collateral, debt and healthFailed reads stay unavailable. Collateral less debt excludes exit fees. Post-transfer health excludes incoming proceeds.
Actual Cattle address preview with thetadeployer’s verified short and long positions on Base.
Live address preview · desktopActual browser capture, 1440 × 1050 viewport. The block and time printed in the page identify this snapshot.
Actual phone view of Cattle’s live account values and distinct read-only address identity.
The same account · phone390 × 844 viewport. A separate refresh may produce a later block.
Verified: external picker, account changes, wrong-chain retention, explicit Base switching and silent reconnect with an injected test provider. Fresh sample mode makes no wallet or RPC requests. WalletConnect’s modal opens, but physical-wallet pairing and transaction signing were not tested. This stage enables connection and account reads; the builder still saves local examples.
08

User observations · queued for the next visual/copy pass

More intent. A little moonlight.

The user noted that “long” and “covered short” do not explain why someone would choose either strategy. Long is generally bullish. Short commonly expresses range-bound or yield intent, with a delta-hedging spread intended to cover option premiums. That spread target does not apply to long. Neither is an exact replica of a conventional option payoff.

Language direction: explore the perpetuals-versus-dated-futures analogy without implying that these dated positions are perpetual. Keep the target spread distinct from a promised return. The current behavior descriptions are a starting point, not a finished explanation of user intent.
Visual direction: the user found Moonlit pasture appealing for a ghost cow and suggested a cute night-mode toggle. Revisit concept C as an optional theme. Its initial rejection applied to the crowded layout and invented controls; the night palette remains a useful direction. Queued at the user’s “no rush” priority while wallet and discovery work is completed.
09

Latency → discovery index plus current chain reads

The index gets us started. Base fills the gap.

The user requested an indexer and clarified that cron always lags. Cattle now uses a dedicated Cloudflare D1 discovery index. The browser checks its block hash, reads every later block through the current snapshot, and reads balances and the lens directly at that snapshot.

ConditionResult
Valid indexReuse verified deployment history; scan from indexed block + 1 and refresh all account values directly.
Warming, stale, unavailable or mismatched indexFull chain discovery from the configured factory deployment. A failed read never means zero.
Lagging RPC or provider disagreementDo not certify the interval. Each log provider must match the shared block hash before and after returning events.
Reorg or overlapping cron runsLease and atomic SQL fences protect the cursor. A reorg clears the prefix and rebuilds it.
DebuggingUse index=0 for direct discovery. Source and checkpoint details stay in the debug state and engineering notes.
Review evidence: 60 tests pass. Independent review found and verified fixes for a reorg mixing two branches, D1 trigger-inclusive change counts, and lagging log witnesses. Scenario tests confirm exact cron-gap coverage, current-block account reads, atomic rollback, recovery and full-scan fallback. Indexer operations and design ↗

Live verification: the app used checkpoint 51,290,649, filled the next 23 blocks directly, and read both accounts at block 51,290,672. A separate indexed/full-scan comparison at 51,290,704 returned identical position data. One observed run took 7.6 seconds versus 8.5 seconds; no broad latency claim is inferred. Actual indexed phone capture ↗

10

Four independent wording reviews → one synthesis

Start with the view. Then explain the trade.

The user requested Claude Fable, Gemini via agy, Zai and a fresh Codex Astra. All four reviewed a frozen copy of the site. Their shared finding: the short’s intent was missing, while “replicate” and “stays available to borrow against” could promise too much.

Adopt: bullish versus range-bound intent; target holdings versus completed trades; conditional borrowing; current supplied assets; clear strike and expiry language. Keep: Long call and Covered short as the strategy names. Reject: wording that turns the target spread into earned premium, labels a preview as posted, or invents a conventional option payoff.

The shared short description now explains the premium target and that no separate option premium is paid or received at entry. Mode banners follow the actual route. These model reviews do not establish measured newcomer comprehension.

11

Moonlit pasture → a working night theme

The same pasture, after sundown.

A smiling sun/moon toggle switches the landing, app and journal. Deep navy-green panels, lilac accents and quiet meadow silhouettes carry the original night concept into the actual interface. Numbers and controls keep clear contrast.

Generated night ghost cow floating over lilac meadow flowers with two fireflies.
The moonlit companionimg/assets/hero-night.png
Regenerated hero artwork. Native CSS blends its opaque night backdrop into the page.
Generated moonlit guide cow holding a small unlettered paper.
The night guideimg/assets/guide-night.png
Used in summaries and empty states. img/assets/mark-night.png ↗
Generation correction: the first hero and guide outputs painted checkerboards instead of producing transparency. Those outputs were rejected. The final assets use intentional opaque night backgrounds and native edge blending. Day artwork remains available. Full built-in imagegen prompts ↗
Actual desktop Cattle landing in night mode with the regenerated meadow cow.
Night landing · actual browser1440 × 1050 viewport, with the revised wording.
Actual Cattle night landing on a 390-pixel phone.
A smaller night pasture390 × 844 viewport. The theme follows system preference until the visitor makes a choice.
12

User correction → three generated order layouts

Short waits at limits. Long rebalances toward a target.

The user clarified that short should show a buy limit below and a sell limit above, while long uses a market rebalance after a sufficient target gap. Source review confirmed two short grid sides and one bounded market order for long. The option strike is not a fabricated long trigger.

Generated concept A compares a short price ladder with one long market-rebalance state.
ExploreA · Price ladderClear ordering, but tall in a position card. Reject the generated “provides upside” claim and its assumption that the oracle price always lies between the short limits.
Generated concept B uses paired short limit tickets and a single long market-rebalance panel.
Adapted in codeB · Order ticketsCompact buy/sell limits fit the cards. Keep one long status. Remove the repeated market message and any suggestion that limits keep the position safely in range.
Generated concept C uses a shared price map for opposite short and long responses.
Teaching directionC · Shared price mapUseful for comparing responses. Reject “provide liquidity within a range” and language implying that combining the positions keeps the user safe.
Implemented: two labelled short limit slots, one long market state, actual quote-per-base units, explicit unavailable legs and optional limit amounts. No long trade-preview list. Source review also identified the short’s final-hour strike sweep and terminal rebalance; those phases receive their own labels. Posting and fills are not inferred from the contract snapshot.
13

Position identity + HF across prices + debt scenarios

What you hold. How its health can change.

Cards now lead with strategy notional, such as “1 × wstETH,” followed by the strategy, strike and expiry. Current supplied assets remain separate. The user chose a rebalancing-only HF estimate, with liquidation and the borrowing limit marked.

Model: use the hedge curve to derive target holdings and a self-financing asset path. Reprice the actual borrowed assets, apply each reserve’s LT/LTV, and hold time and volatility fixed. The initial implementation stopped when the ideal target needed more funds; step 15 corrects that cutoff. The curve at today’s price is after model rebalancing; the actual account HF remains above it. Equations, inputs and validation ↗
Actual live Cattle positions with notional-led headings, rebalancing HF charts, liquidation markers and distinct order types.
Live positions · actual browserThe displayed Base block identifies the account snapshot. Additional reserve reads use that same block.
Actual phone view of fictional long and short HF scenarios with borrowing and repayment controls.
Sample scenarios · actual phoneThe fictional long has mixed debt and a U-shaped curve. Shape comes from the inputs; it is not forced onto the live long.
Borrow / repay: change a hypothetical debt asset and amount to see HF and liquidation levels move. Each scenario starts from current debt. Borrowed proceeds remain outside the position; repayment uses external funds. Actual account figures and wallet identity do not change.

Independent review caught and verified a fix for two liquidation crossings hidden around a shallow U-shaped minimum. The implementation finds extrema before crossing searches. Current configuration has no separate Call/Put subtype; debt changes net exposure without changing the encoded strategy name.

14

Lifecycle study · roll integration queued

Funding is a start. Borrowing is another decision.

The guide now separates deploy/fund, review of the first rebalance, optional borrowing, and repayment or rolling. Borrowing is not bundled into creation. The HF planner gives the independent debt decision a place in the current read-only app.

Proposed roll flow: review the destination and owner; verify assets, debt, fees and eligibility; prepare the authenticated source if debt must move; roll; verify what arrived; activate the destination; then review any additional borrowing. The actual API is primeFor → rollTo → fundFromHoldings. Full source-checked roll study ↗

Roll transaction controls remain queued. This study does not enable delegation, borrowing, repayment, rolling or activation sends. The initial pass had 75 passing tests; browser checks cover live charts, hypothetical borrowing and full repayment, 320/390px layouts, system theme changes, denied storage and the night wallet picker.

15

User correction → a continuous HF estimate

Buying can stop. Collateral still has value.

The user challenged the message “This target needs additional funding. No HF is plotted here.” With wstETH collateral and USDC debt, HF can keep rising as wstETH rises. Running out of quote assets limits further buying; it does not make the account’s health undefined.

Correction: follow the hedge curve while trades can be funded. When quote assets run out, retain the acquired base balance and continue valuing it against the actual debt. If today’s full target is already unaffordable, buy only what the supplied assets can fund and resume hedging where the target becomes affordable. No extra borrowing is assumed.
Show the assumption: the chart follows a one-way price move from today. Selected-price readouts now show estimated supplied assets and identify when further buying stops. Liquidation and borrowing-limit searches include each funding transition. Updated model and validation ↗

The correction is checked against independently executed small trades for long and short in both price directions, including initially unaffordable targets. All 79 tests pass. Live charts were checked at Base block 51,294,774: the long’s +60% price point retains 0.97752 wstETH and zero USDC supplied, with HF 2.280 and debt unchanged. An independent unequal-LT cusp case also finds both liquidation and borrowing-limit crossings between ordinary plot samples. Astra verification ↗ · Repayment scenario capture ↗

16

User correction → both directions for long

Sell on a fall. Buy on a rise.

A single current order did not explain both responses. Long positions now have paired Sell market and Buy market tiles with estimated trigger prices. The current contract preview stays separate, with its actual minimum or maximum execution-price bound.

Price meaning: solve when the current inventory gap reaches the configured minimum trade value, using the hedge curve and the current model epoch. A sell also has a lower price cutoff where its value becomes too small; the details show that range. These are trigger estimates, not fill prices. Atomic order rounding and settlement checks remain distinct.

Independent reference: one base token of notional, 0.5 held, strike 3,100, 52% IV, seven days and a 30-quote minimum gives sell near 3,086.552, buy near 3,097.384, and a lower sell cutoff at 60. Review caught a tiny-CDF discontinuity at the minimum quote atom; the regression now prevents a false far-away trigger. Final-hour pause, missing inputs and fully held targets have explicit states.

Actual paired triggers and wallet action links ↗

17

Funding → optional borrowing in one tutorial

Keep the next decision in the same example.

The user asked to include borrowing in the example flow, then keep the example as tutorial mode for the live integration. Borrowing now follows the funding inputs inline. The separate borrowing lesson dialog is removed.

One set of inputs: choose the borrowed asset and amount; value collateral using a separate example market price; see debt, HF and LTV; review and save everything together. The example uses disclosed 75% LTV and 80% liquidation thresholds. The strike never substitutes for the market price. Borrowed proceeds stay outside supplied collateral.
Cattle tutorial showing collateral, terms and an optional 300 USDC borrow in one form.
Same example · after borrowing0.25 WETH plus 600 USDC at an example WETH price of 2,400 gives 1,200 USD collateral. Borrowing 300 USDC gives illustrative HF 3.200 and LTV 25%.
The integrated Cattle tutorial on a phone.
Phone tutorialBorrowing remains a separate decision after funding, within the same flow.
18

My Wallet → cached positions and the next action

Resume with context. Refresh before acting.

My Wallet can show its last saved positions immediately while refreshing Base data. Each fresh position links to its own Borrow, Repay and Roll review flow. The selected position, its assets and its debt carry into the review.

Cache: scoped to wallet, chain and contract configuration; at most five wallets, seven days and one megabyte. Cached cards clearly show historical values. They carry no order previews, risk charts or action controls. A failed refresh retains the saved view; account or network changes clear it immediately. Cache hits always start a fresh chain read.
Action reviews: reread the verified position before reviewing borrowing or repayment. Rolling checks a different, same-owner destination with matching assets and pool that is open, unexpired and unstarted. A stopped source may still roll remaining holdings. Transfer, fees, delegation, activation and final transaction simulation remain separate steps. Wallet signing belongs to the subsequent live integration; these reviews send no transactions.
Cached My Wallet positions displayed while current Base data refreshes.
Saved positions · updatingBrowser test used a read-only test provider for wallet identity and real public Base data. Paused chain reads exposed the cache; forced read failures retained it without renewing its timestamp.
Position-specific borrowing review with live collateral and debt, before and after HF, and transaction steps.
Borrow from this positionThe review preserves supplied balances and shows debt and health before and after the proposed amount. No signature or transaction was requested.

104 tests pass. Browser checks covered inline borrowing, saving and reload, actual long trigger levels, cache hydration, failed refresh, account/network changes and a refused already-funded roll destination. Independent cache and flow review ↗ · Repayment review capture ↗

19

15 September · user review of prices and spacing

Compare the same kind of price.

The user found that the long’s inventory-based triggers were far from the current order’s buy maximum. Short tiles showed execution limits, while long tiles showed activation thresholds. That comparison was misleading.

UI correction: long tiles now show the current oracle-based sell minimum and buy maximum. An actual candidate uses its token-amount ratio; the other direction is marked indicative. The heading is “Market prices.” Remove the extra “Estimated trigger prices” line and the separate current-preview panel. Add a position-specific CoW order-history link to both fresh and cached cards.
Live Cattle short limits and long execution price bounds with oracle prices and CoW history links.
Comparable prices · actual browserShort limits and long slippage bounds retain their different mechanics, with the oracle price visible beside each pair.
Phone layout check showing a 24-pixel gap below the saved-position updating banner.
24px of separationLayout check: the saved-state banner was shown above existing cards to measure the actual gap. Cache data and refresh logic were unchanged.

108 tests pass. Independent review verified price scaling, outward rounding, phase gates and retaining an exact candidate when the separate oracle read fails. Desktop and 390px phone checks found no horizontal overflow; the CoW history link opened the correct account.

20

User follow-up → contract pricing investigation

When to buy is different from the maximum to pay.

For long, the inventory-neutral price is where the target base amount equals the amount held. An oracle price sufficiently above it creates a buy gap; sufficiently below it creates a sell gap. The resulting market order is protected at the current oracle price plus or minus the slippage cap.

Same-block witness: at Base block 51,314,988, the oracle was 3,212.876394943420456879 USDC per wstETH. The old buy trigger was about 3,162.5673. The contract targeted 0.767881877589088566 wstETH against 0.646977490008352754 held. Its rounded buy of 0.1209 wstETH and maximum 390.378939 USDC payment matched an independent integer calculation exactly. The source feed ratio, delta, epoch and publication preview also agreed.
Timing clue: at 20:00:41 UTC, the rounded trade value was only about 31.2839 USDC, below the 50 USDC minimum. The contract returned PollTryAtEpoch(21:00 UTC, “no order”). By 20:55:23 it could publish a buy. An epoch-delayed retry is therefore a plausible reason for the activation level to lag spot. At 21:00:36 UTC, CoW published the next buy, which filled for 0.09597 wstETH. That supports the retry explanation, though it does not establish the hosted watchtower’s exact polling logs.

No arithmetic or direction bug was found in this witness. Exact inputs and RPC results ↗ · Assessment and scope ↗. No orders, signatures, backend settings or contracts were changed.

21

15 September · user wording refinement

Say what the strategy does.

The user proposed “buys” and “sells” in place of “targets more” and “targets less.” The shared descriptions now use those direct verbs, while keeping the bullish and range-bound intent labels.

Long: Buys more WETH as price rises and sells as it falls.
Short: Buys more WETH as price falls and sells as it rises.

Applied to position cards, tutorial summaries, reviews, saved examples, the guide and landing-page direction labels. Live cards use their actual asset symbol. Execution conditions remain in the order details; this change describes the strategy’s direction.

22

User review → gaps before real funding

The interface is ready for the execution layer.

The user asked what remains before creating and funding real positions. Existing wallet reads, discovery, cache, scenarios and action reviews are in place. The next work is live configuration, transaction execution and recovery.

Before deposits: pin the release and complete immutable settings; read live balances, reserves and prices; register each pair’s CoW appData and collateral-sync hook; simulate create/approval/funding; reconcile receipts; resume an unfunded pair after interruption; provide a working close path.
Before debt: bound borrowing by both Aave limits and the pending hedge’s outgoing collateral. Repayment uses the owner’s funds through Aave. Debt rolls need verified preparation, transfer reconciliation and separate destination activation.

The current read/model tests do not establish live transaction readiness. Prove the full lifecycle on a Base fork, then a small explicitly authorized live run. No runtime capability was enabled by this assessment. Concrete gaps and implementation order ↗

23

15 September · sanity review before implementation

Keep the first live flow small.

A fresh agent read the requested sanity-check persona and critiqued the plan before coding. Its main finding was excess recovery machinery. The user asked for a minimum functioning version and confirmed the trial defaults.

Accepted subtraction: no persistent transaction ledger, nonce locks or duplicate contract-validation layer. The external wallet sends transactions; receipts and existing chain discovery recover completed steps. Account and network changes stop follow-on requests.
Keep the actual product steps: register per-pair CoW settings, create, approve and fund; then optional borrowing. Existing positions expose repayment, withdrawal and roll. Roll activation uses the assets that arrived and remains a separate decision.

Fresh sanity critique ↗ · Reduced implementation brief ↗

24

Minimum live version · external wallet on Base

Create, fund, then choose what comes next.

New position creates a wstETH / USDC long call or covered short. Starting amounts are editable; a suggested mix helps explain strategy size. An unfunded option prepares a roll destination. Funding supplies assets to Aave and starts trading without creating debt.

Trial defaults retained: 52% IV, 0.5% short grid, 0.5% slippage cap, 50 USDC minimum trade and a 1% annual fee paid to the position owner. Long uses grid zero. The review shows the owner, expiry in UTC, immutable settings, supplied amounts and predicted address.
My Wallet: fund an unstarted position; borrow with room for the current outgoing hedge; repay from the wallet; withdraw after debt is cleared; or roll to a verified destination. Received assets use a separate Start received assets action. Update collateral provides the manual fallback for a missed sync hook.
Review synthesis: Fable caught a receipt-versus-discovery timing gap and approval ordering. Confirmation now waits until the existing head-minus-two reader can see the receipt; funding checks state before approval. Zai verified units, spenders and identity handling. Its proposed fee change was rejected against the deployed source. CoW accepted the new hook document; older trial documents do not have it.
Live position borrowing review with 100 USDC amount and before and after debt and health factor.
Borrow from this positionCurrent assets, debt and room for the next trade feed the review. The final wallet action remains a separate button.
Full position debt repayment review using a finite amount with an interest buffer.
Repay with room for interestApprove a finite amount; Aave takes at most the debt owed at confirmation.

120 frontend tests and two deployed-contract Base fork lifecycle tests pass. Browser checks use a wallet fixture with no key or send support. No agent wallet transaction was broadcast. Fable + Zai findings and decisions ↗ · Validation and limits ↗ · Open Cattle ↗

25

18 September · fee recipient clarification

The annual fee goes to the protocol.

The user clarified that the 1% annual fee belongs to the deployer/protocol. The earlier owner-recipient default and “paid to your wallet” wording were incorrect for new user positions.

Correct creation settings: keep the connected wallet as position owner, and set the fee recipient to the configured thetadeployer address, 0x4a4c7c5549359b9fff0137bb3ec4d48c4aa79cc7. The review shows these as separate rows, using the same configuration encoded into the factory call.
Copy: “1% annual protocol fee, collected when withdrawing or rolling.” Existing contracts retain their immutable recipient; withdrawal and roll reviews continue to use each position’s actual on-chain settings. This correction supersedes the recipient statement in entry 24.
Creation review showing the user wallet as position owner and a separate protocol fee recipient.
Owner and protocol recipientThe displayed addresses come from the configuration encoded into the creation transaction. Browser check used a read-only wallet fixture; no transaction was sent.

121 tests pass. Independent evaluator review and browser checks passed. Validation ↗ · Open corrected app ↗

26

21 September · latest deployed contracts

A weekly cycle, with the same pasture.

The new Base deployment supports perpetual positions. Creation now offers weekly repetition or a dated expiry, with 53% trial IV. The calendar returns to the same strike each week; closing or rolling remains the owner’s choice.

Read the deployed model: use the new factory, implementation and lens from e4c87fc. The model moves to the next weekly cycle one hour before the calendar boundary. Show its live model expiry and the repeating schedule instead of treating the first boundary as a permanent end date.
Fees: the 1% annual protocol fee accrues from funding on the value recorded at the last skim. It can be collected during the position, as well as at withdrawal or roll. Fees leave as Aave receipt tokens; withdrawal returns the remaining underlying assets. The review shows those separately, even when the connected owner is the protocol recipient.
Continuity: keep earlier positions available with their original contract interfaces and fee rules. Both deployment generations share one portfolio snapshot block, each with its own verified index and direct-chain tail. Partial reads cannot replace the wallet cache. Verified rolls can move debt and assets from the old generation into a new perpetual.
The latest Cattle short and long positions showing weekly schedules and live model expiry.
Latest positions · S and LBoth use one wstETH of strategy notional. Earlier dated D/E positions remain visible below.
Withdrawal review separating underlying assets returned from the pending fee paid as Aave receipt tokens.
Different return assetsUnderlying withdrawal and fee receipt tokens are separate amounts, not a combined wallet return.

130 frontend tests and five deployed-contract Base fork tests pass, including old-to-new debt roll and the one-hour-early weekly rollover. Both discovery indices are ready. Browser checks use real chain data and a wallet fixture without signing support. Deployment, review and validation ↗ · Open updated app ↗