How Owner and Agent Permissions Differ in Trading Automation
A concise guide explaining the separate roles of owner and agent permissions, the limits each enforces, and best practices for secure delegation in automated
Produced with automation, then checked by deterministic quality rules and an independent source-grounded review before publication.
- 01Owner permission is tied to a private key that can sign withdrawals and policy updates.
- 02Agent permission is granted through a scoped key that can only place, modify, or cancel orders within owner‑defined limits.
- 03Withdrawals always require a separate owner‑signed instruction and cannot be executed by an agent key.
- 04Owner‑defined limits such as order size, daily notional, loss caps, and expiry can be changed or revoked at any time.
- 05An emergency stop revokes the agent key instantly but does not automatically close existing positions.
Owner permission defines who can move funds and set system policies, while agent permission defines which trading actions a delegated program may perform. The owner retains ultimate control through a private key that signs withdrawals and policy updates. Agents operate only within the numeric and temporal limits the owner configures.
What does owner permission control?
The owner holds the private key that authorizes any balance movement, policy amendment, or emergency stop. Owner‑signed limits can restrict order size, daily notional exposure, loss caps, and expiry dates. These limits are stored in the system’s policy fields and can be changed or revoked at any moment. Because the owner key also signs withdrawal intents, no trade‑scoped key can bypass this final human checkpoint.
How is agent permission scoped?
Agent permission is granted via a signed key that carries explicit scopes such as order placement, modification, cancellation, and read‑only market data access. The agent cannot exceed the numeric or temporal bounds set by the owner, and it cannot initiate withdrawals without a distinct owner‑signed instruction. Any request that falls outside the defined scope is rejected with a clear error response, preserving system integrity.
Typical agent scopes
- Place, modify, or cancel orders within defined size and notional limits.
- Access market data that includes source, timestamp, and freshness metadata.
- Log decisions and execution outcomes for auditability.
Why can’t an agent hold the withdrawal key?
Withdrawal is the highest‑risk operation and requires a separate owner‑signed intent to ensure a final human review. Allowing an agent to hold that key would bypass critical safety checks and increase exposure to software bugs or malicious behavior. Keeping withdrawal authority exclusive to the owner preserves a vital security checkpoint and aligns with the system’s design that trade‑scoped keys are never withdrawal paths.
An agent key is trade‑scoped; a withdrawal key is owner‑only authority.
What happens during an emergency stop?
An emergency stop revokes the calling agent key, preventing further actions from that agent. It does not automatically close open positions or cancel token allowances that were previously granted; those require separate owner‑signed commands. The owner must review existing positions manually and decide whether to unwind them or adjust limits.
How can owners monitor and adjust agent activity?
Owners should regularly review the decision log, order history, and policy compliance reports. If an agent approaches a limit, the owner can tighten the policy or revoke the key entirely. Durable mutation identity and explicit error states must be reconciled because timeouts do not guarantee that an order failed. Continuous monitoring helps maintain alignment with risk parameters.
For deeper context see the related guides: Understanding Owner and Agent Authority for Trading Agents, Owner Authority vs Agent Authority: Understanding the Core Differences, and How to run an AI trading agent with real‑money controls.
Frequently asked questions
No. Owner permission must always define explicit limits such as order size, daily notional, or expiry; unlimited power defeats the purpose of scoped agent keys.
No. Withdrawals require a separate owner‑signed intent; the agent key only authorizes order‑related actions.
Agents must treat missing or unverified data as unavailable and refrain from trading until reliable data with source and timestamp is received.
The owner can issue an emergency stop or update the policy to remove the agent’s scopes; revocation takes effect immediately for new requests, while existing positions remain until the owner takes further action.
Regular audits, at least weekly for active agents, help ensure compliance with limits and provide early detection of unexpected behavior.
Sources and verification
Product claims in this article were checked against these first-party references. Runtime status remains authoritative for current availability.
- Felix documentationfirst party
- Felix machine referencefirst party
Build with Felix now.
Felix infrastructure is live through MCP and the API. The Felix V1 retail quant-desk private beta is planned for September 22.
AI agents act as disciplined overseers for a suite of trading models, handling order routing, risk limits, data verification and emergency stops. This guide explains the core functions, required controls and practical steps for safe deployment.
A solid quantitative trading platform delivers reliable data, enforceable risk limits, transparent order handling, separated key permissions and a safe emergency stop mechanism. This guide explains each core function in depth.