Electronic Markets from First Principles
Market structure, microstructure, execution, and realistic simulation.
An electronic market is simultaneously a rule system, a distributed event stream, an economic mechanism, and an environment in which participants act with incomplete information.
This book develops those layers in that order. It begins with the concrete mechanics of orders and trades, then explains liquidity and order flow, execution and market making, empirical evidence, simulation, risk, and finally the mathematical models that compress those observations.
Every chapter should answer five questions:
- What observable market phenomenon are we trying to explain?
- Which exchange rules and participant constraints produce it?
- What data would distinguish competing explanations?
- Which assumptions does the model make?
- What would make a simulation or conclusion misleading?
This is not primarily a low-latency programming book. Its companion, Computer Science from First Principles, covers data structures, machine behavior, operating systems, concurrency, networking, and performance engineering. This book uses that machinery only when implementation details change market meaning or experimental validity.
Start with why markets exist, inspect the full curriculum, or use the source map to connect chapters with external books and laboratories.
Curriculum
The path is deliberately causal:
rules and participants
↓
observable order-book behavior
↓
execution and market-making decisions
↓
data, estimation, and simulation
↓
risk controls and mathematical models
Mechanics
Learn what orders mean, how venues organize trading, how matching rules determine outcomes, and which direct costs accompany a trade.
Market microstructure
Explain spreads, depth, liquidity, order flow, queue position, adverse selection, price discovery, and impact from participant incentives and market rules.
Execution
Turn a desired position change into an explicit execution objective, cost benchmark, schedule, order policy, and routing decision.
Market making
Study quoting as a coupled inventory, adverse-selection, fill-probability, and control problem—not as a guaranteed spread-capture strategy.
Data and empirical work
Establish event-time semantics, reconstruct trustworthy state, measure stylized facts, estimate parameters, and separate statistical evidence from artifacts.
Simulation and backtesting
Build event-driven experiments with honest information boundaries, queue and fill models, latency, transaction costs, and sensitivity analysis.
Risk and operations
Track positions and exposure, enforce limits, reconcile external state, handle uncertainty, and define safe behavior during failures or regime changes.
Mathematical models
Introduce probability, point processes, stochastic processes, optimization, and control only after the market mechanisms and observables they model are understood.
The first six parts form the main learning path. Risk accompanies every experiment. Mathematical chapters are optional on a first pass and become essential for deeper research.
Source Map
No single reference is the authority for every layer of electronic markets. The book should use primary venue specifications and empirical papers where exact rules or claims matter, while relying on broader texts for durable models.
Market mechanics
Larry Harris’s Trading and Exchanges supplies the institutional vocabulary: participants, orders, market structures, liquidity, dealers, and trading problems. It belongs near the beginning because later models assume this language.
The working edition is Larry Harris, Trading and Exchanges: Market Microstructure for Practitioners, Oxford University Press, ISBN 978-0-19-514470-3. See the Harris reading map for the chapters assigned to each part of this book and the historical details that require newer primary sources.
Thierry Foucault, Marco Pagano, and Ailsa Röell’s Market Liquidity: Theory, Evidence, and Policy supplies the complementary theoretical and empirical treatment of liquidity, price discovery, order flow, trade size, limit order books, fragmentation, and transparency. See the Foucault–Pagano–Röell reading map.
Graduate microstructure models
The MTH9879 Market Microstructure Models materials provide exercises and models for order flow, spreads, inventory-based market making, impact, execution, latency, and routing. They are best treated as advanced laboratories after the mechanics are clear.
Realistic replay
hftbacktest is a practical laboratory for queue position, latency, L2/L3 books, fill assumptions, imbalance signals, and tick replay. Its results are conditional on its market, latency, queue, and impact models; those assumptions must remain visible.
Mathematical depth
Cartea, Jaimungal, and Penalva’s Algorithmic and High-Frequency Trading supports the later treatment of market making, optimal execution, stochastic models, and control.
Systems companions
CPU-performance, modern-hardware-algorithm, and Rust-performance references belong primarily to Computer Science from First Principles. They should be cited here only where implementation changes timestamps, queue position, experiment validity, or operational behavior.
Source rule
A repository is a laboratory, not proof that a market rule is universal or a model is realistic. Every experiment should identify:
- The venue and period represented by the data.
- The matching and priority rules assumed.
- The observable information available to the strategy.
- The latency, fill, fee, and impact models.
- The claim the experiment can and cannot support.
Edition rule
The working Foucault–Pagano–Röell file is the 2013 first edition, not the expanded 2023 second edition. Its foundational models remain useful, but claims about modern algorithms, venue structure, regulation, and empirical conditions require newer sources.
Harris Reading Map
Larry Harris, Trading and Exchanges: Market Microstructure for Practitioners. Oxford University Press. ISBN 978-0-19-514470-3.
Harris provides the institutional vocabulary for the first half of this book. Its greatest strengths are the distinctions among participant motives, order properties, market structures, liquidity demand and supply, spreads, trading costs, and market quality.
It should guide our explanations without dictating our organization. Our book will begin with smaller interactive mechanisms, incorporate later empirical work, and distinguish contemporary electronic-market rules from durable principles.
Primary reading path
| Our part | Harris chapters | Purpose |
|---|---|---|
| Market Mechanics | 3–9 | Trading industry, orders, market structures, order-driven markets, brokers, motives, and good markets |
| Market Microstructure | 10–14, 19–20 | Information, anticipation, manipulation, dealers, spreads, liquidity, and volatility |
| Execution | 4, 7, 18, 21–22 | Order properties, agency, buy-side trading, transaction costs, and performance evaluation |
| Market Making | 10, 13–14, 19–20 | Informed trading, dealer behavior, spread components, liquidity, and volatility |
| Data and Empirical Work | 20–22 | Volatility, liquidity measurement, transaction costs, and evaluation |
| Risk and Operations | 7, 22, 28–29 | Agency, evaluation, circuit breakers, and information boundaries |
The mathematical-model and simulation parts require later sources. Harris supplies motivations and definitions for those chapters, but not a modern event-driven backtesting or stochastic-control treatment.
Chapter-level assignments
Mechanics
- Chapter 3, The Trading Industry → participants, intermediaries, venues, and industry roles.
- Chapter 4, Orders and Order Properties → order instructions, tradeoffs, and order choice.
- Chapter 5, Market Structures → dealer, auction, brokered, and crossing mechanisms.
- Chapter 6, Order-driven Markets → books, priority, and order interaction.
- Chapter 7, Brokers → agency, routing, conflicts, and execution responsibility.
- Chapter 8, Why People Trade → participant objectives and gains from trade.
- Chapter 9, Good Markets → liquidity, price discovery, fairness, and market quality.
Microstructure and liquidity supply
- Chapter 10, Informed Traders and Market Efficiency → information, prices, and adverse selection.
- Chapter 11, Order Anticipators → prediction of other participants’ demand.
- Chapter 12, Bluffers and Market Manipulation → strategic signaling and deceptive order flow.
- Chapter 13, Dealers → liquidity supply, inventory, and dealer economics.
- Chapter 14, Bid/Ask Spreads → spread components and measurement.
- Chapters 15–18 → block, value, arbitrage, and buy-side trading motives.
- Chapter 19, Liquidity → dimensions, origins, and beneficiaries of liquidity.
- Chapter 20, Volatility → price variation and its relationship to trading.
Measurement and design
- Chapter 21, Liquidity and Transaction Cost Measurement → spread and execution-cost concepts.
- Chapter 22, Performance Evaluation and Prediction → benchmarks, attribution, and the difficulty of evaluating skill.
- Chapters 23–27 → index markets, specialists, internalization, fragmentation, competition, and automated trading.
- Chapter 28, Bubbles, Crashes, and Circuit Breakers → instability and intervention.
- Chapter 29, Insider Trading → information boundaries and market integrity.
Durable concepts versus historical details
Treat these as durable conceptual foundations:
- Participants trade for different reasons and under different constraints.
- Every order type exchanges one risk for another.
- Market structure affects execution, information revelation, and liquidity.
- Liquidity has several dimensions and is costly to supply.
- Spreads compensate for costs and risks rather than representing free profit.
- Trading-cost and performance measurements depend on their benchmark.
Treat these as historical context until verified against current primary sources:
- Named venues, intermediaries, and industry roles.
- Available order types and precedence rules.
- Fee schedules, tick sizes, lot sizes, and trading hours.
- Market-data contents and timestamp semantics.
- Routing, best-execution, disclosure, and market-integrity obligations.
- Claims about the relative importance of floor, dealer, crossing, and automated markets.
For current facts, the eventual chapter should cite the relevant exchange rulebook, technical specification, regulator, or dated empirical study.
Writing rule
Use Harris to establish vocabulary and causal questions. Then ask:
- Can the mechanism be demonstrated with a smaller interactive market?
- Which parts are universal and which depend on a venue rule?
- What observable data would test the explanation?
- What has changed since the book’s publication?
- Which later source supplies the empirical or mathematical extension?
Foucault–Pagano–Röell Reading Map
Thierry Foucault, Marco Pagano, and Ailsa Röell, Market Liquidity: Theory, Evidence, and Policy. Oxford University Press, 2013. ISBN 978-0-19-993624-3. DOI 10.1093/acprof:oso/9780199936243.001.0001.
This source complements Harris. Harris gives us participant motives and institutional vocabulary; Foucault, Pagano, and Röell give us models and evidence for the trading process itself—especially liquidity, price discovery, order flow, trade size, the limit order book, fragmentation, and transparency.
The supplied file is the 2013 first edition. It is suitable for the foundational chapters below. A later revision should consult the 2023 second edition and current venue specifications for algorithmic trading, high-frequency market making, fragmentation, regulation, and recent evidence.
Primary reading path
| Our part | Source chapters | Purpose |
|---|---|---|
| Market Mechanics | Introduction; 1 | Why real trading differs from frictionless exchange; dealer and auction mechanisms; trading rules |
| Market Microstructure | Introduction; 2–4; 6–8 | Liquidity measurement, order flow, depth, limit order books, fragmentation, and transparency |
| Execution | 2; 4; 6–7 | Trading costs, trade size, order choice, venue choice, and execution conditions |
| Market Making | 3–4; 6 | Price dynamics, inventory absorption, depth, and limit-order supply |
| Data and Empirical Work | 2–5 | Liquidity measures, empirical price dynamics, depth, and estimation |
| Mathematical Models | 3–4; 6–9 | Order-flow models, trade-size models, equilibrium liquidity, and asset-pricing implications |
Chapter-level assignments
- Introduction → the gap between frictionless asset-pricing models and real trading; market liquidity; price discovery; the interaction of market, funding, and monetary liquidity.
- Chapter 1, Trading Mechanics and Market Structure → rules of the game, dealer markets, continuous limit order books, call auctions, hybrid structures, and transparency.
- Chapter 2, Measuring Liquidity → spreads, price impact, execution costs, and the limits of any single liquidity statistic.
- Chapter 3, Order Flow, Liquidity, and Securities Price Dynamics → informed and uninformed order flow, price response, and liquidity provision.
- Chapter 4, Trade Size and Market Depth → quantity, depth, and price concessions.
- Chapter 5, Estimating the Determinants of Market Illiquidity → empirical identification and estimation.
- Chapter 6, Limit Order Book Markets → endogenous order choice and liquidity supply in a book.
- Chapter 7, Market Fragmentation → competition, concentration, and venue choice.
- Chapter 8, Market Transparency → displayed information and participant behavior.
- Chapter 9, Liquidity and Asset Prices → liquidity premia and funding-liquidity feedback.
- Chapter 10, Liquidity, Price Discovery, and Corporate Policies → consequences beyond the trading desk.
How we will use it
This book will not copy the source’s chapter order. Each chapter starts with an observable mechanism, then introduces the smallest model needed to explain it. The source provides hypotheses and modeling discipline; current exchange specifications and empirical papers must establish contemporary facts.
For each borrowed model, state:
- Which participants are present.
- What each participant knows and observes.
- What actions the mechanism permits.
- How and when orders meet.
- Which quantity the model predicts.
- What real-world feature the model deliberately leaves out.
First-edition boundary
Treat the first edition as authoritative for durable definitions and foundational mechanisms, not for the current state of electronic markets. The following always need newer verification:
- Venue ownership, market share, and trading protocols.
- Order types, matching rules, and transparency regimes.
- Tick sizes, fees, access, and market-data products.
- The prevalence and effects of high-frequency and algorithmic trading.
- Regulatory requirements and market-design reforms.
- Quantitative claims tied to a particular sample or historical episode.
Market Mechanics
Before modeling a market, learn what its participants can submit, how a venue processes those instructions, and what constitutes an execution.
This part remains descriptive before becoming mathematical. Exact rules vary by venue, instrument, jurisdiction, and time, so concrete claims should eventually cite the relevant specification.
Why Markets Exist
A market is not merely a place where trades happen. It is a mechanism for finding counterparties, forming prices, and deciding who trades, when, and on what terms.
The six participants above want to trade the same asset, one unit each. A buyer’s number is the most they would pay. A seller’s number is the least they would accept. The potential gain from a particular trade is:
gain from trade = buyer's value - seller's cost
If the difference is positive, some price can make both sides willing to trade. The mechanism does not create that gain. It determines whether the two sides find each other, how long they wait, what they learn, and how the gain is divided.
That distinction is the foundation of market microstructure:
The desire to exchange explains why a market can exist. The trading mechanism explains what actually happens.
Exchange begins with disagreement
People trade because the same asset can serve them differently.
A buyer may value an asset because it moves purchasing power into the future, hedges a risk, completes a portfolio, supplies an input, or expresses information about future prices. A seller may want cash now, less exposure, a different asset, or a chance to act on opposing information. Participants can also differ in constraints, inventories, tax positions, funding, and time horizons.
Harris groups these motives into broad families: investment and borrowing, asset exchange, hedging and risk sharing, speculation, dealing, and other non-investment motives. One participant can have several motives at once. The important lesson is not the taxonomy itself; it is that order flow is heterogeneous. A buy order does not tell you, by itself, why the buyer wants to trade. [Harris, ch. 8]
This heterogeneity creates gains from trade. Suppose a buyer values one unit at 106 and a seller values keeping it at 94. Any price between them can make both better off:
buyer surplus = 106 - price
seller surplus = price - 94
total surplus = 106 - 94 = 12
The price divides the surplus. It does not determine the total surplus for that buyer–seller pair.
Why bilateral search is not enough
Two people can trade without an exchange, dealer, or order book. They must still solve several problems:
- Discovery: Who is willing to take the other side?
- Comparison: Is this the best available counterparty and price?
- Negotiation: What price and quantity are acceptable?
- Timing: Will the counterparty still be available when needed?
- Credibility: Can each side trust the other’s instructions and ability to settle?
- Information: Does the other side know something important?
Bilateral search can be appropriate for unusual, large, or highly negotiable transactions. It becomes expensive when many participants repeatedly trade a standardized instrument. Every trader would otherwise have to rediscover counterparties and terms.
An organized market reduces these coordination costs. It standardizes messages and contracts, concentrates or connects trading interest, publishes some information, defines how orders receive priority, and supplies procedures for execution and settlement.
What a trading mechanism decides
Foucault, Pagano, and Röell describe a mechanism as the market’s rules of the game. At minimum, those rules determine:
- Permitted actions: which orders and cancellations participants may submit.
- Observable state: which quotes, orders, identities, and trades participants can see.
- Matching protocol: which compatible orders trade, at what price, and in what sequence.
- Trading frequency: whether orders meet continuously or at scheduled calls.
- Intermediation: whether customers meet directly or trade through dealers.
These choices affect more than implementation. They affect execution probability, waiting time, trading costs, information leakage, dealer inventory, and the distribution of surplus. [Foucault, Pagano, and Röell, introduction and ch. 1]
Four ways to organize the same trading interest
The interactive model deliberately holds participants constant. Only the mechanism changes.
Bilateral search
Buyers and sellers locate and negotiate with one another. Terms can reflect the particular pair, but finding and comparing counterparties consumes time. Trading interest is dispersed, so a participant cannot automatically know whether a better price exists elsewhere.
This structure is useful when trades require customization or relationship-specific judgment. It is weak when fast, repeated comparison is important.
Dealer market
A dealer posts prices at which the dealer will buy and sell. Customers gain immediacy: they can trade against the dealer instead of waiting for another customer. The dealer earns a spread but assumes inventory and information risk.
The dealer is not a magical source of liquidity. The dealer uses capital, manages inventory, updates quotes, and may later trade with another customer or dealer. If that service becomes risky or costly, quoted size can fall and the spread can widen.
Call auction
Orders accumulate and are matched together at a scheduled time, normally at one clearing price. Concentrating interest can increase the chance of finding the other side and reduce the influence of a momentary arrival imbalance. The cost is delay: a participant cannot necessarily trade immediately.
Calls are therefore natural when trading interest is sparse or when a market wants to concentrate liquidity at an open, close, or reopening.
Continuous limit order book
Participants submit priced orders to a shared book. A compatible incoming order executes against resting interest; otherwise it waits. Price priority usually ranks better prices first, with a secondary rule such as time priority for equal prices.
Continuous trading offers immediacy when compatible orders are already present. It also makes arrival order consequential. A patient trader may earn a better price by supplying a limit order, but assumes non-execution and adverse-selection risk.
| Mechanism | Counterparty discovery | Price formation | Main service | Main cost or risk |
|---|---|---|---|---|
| Bilateral search | Trader searches | Pairwise negotiation | Custom terms | Search, delay, weak comparison |
| Dealer | Dealer stands between customers | Dealer bid and ask | Immediacy | Spread, inventory risk, information risk |
| Call auction | Venue pools orders | One clearing price | Concentrated liquidity | Must wait for the call |
| Continuous book | Venue matches incoming and resting orders | Sequence of book executions | Continuous access | Timing, queue, non-execution, leakage |
No row is universally best. The appropriate design depends on the instrument, participation, urgency, trade size, information environment, and objectives of the market.
Liquidity is a service, not a synonym for volume
In this book, market liquidity means the ability to trade promptly, in useful size, without a large price concession relative to the market’s prevailing assessment of value.
That definition has several dimensions:
- Tightness: how far execution prices are from a useful reference price.
- Depth: how much can trade before prices move substantially.
- Immediacy: how quickly a desired trade can be completed.
- Resilience: how quickly liquidity and prices recover after an imbalance.
The quoted bid–ask spread measures one part of tightness. It does not, by itself, describe the cost of a large order, the likelihood of execution, or recovery after a shock. A market can show a narrow top-of-book spread and still be shallow or fragile.
Liquidity matters because transaction costs can prevent otherwise beneficial exchanges. It also matters before anyone trades: the option to sell later can make an asset more useful to hold today. Harris emphasizes that liquid exchange and hedging markets can improve specialization, risk sharing, and capital allocation. [Harris, ch. 9]
Price discovery is the other central service
Participants do not arrive with identical information. Some orders respond to public news, some reflect private analysis, and others arise from funding needs or risk reduction. A market combines these actions into observable quotes and transaction prices.
Price discovery is the process by which prices incorporate available information. It is not an instantaneous revelation of a known, objective number. The relevant value is uncertain, participants disagree, and order flow mixes information with non-informational demand.
Liquidity and price discovery can reinforce one another: low trading costs encourage participation and information production. They can also conflict. When liquidity suppliers suspect that incoming orders contain superior information, they may protect themselves by widening prices, reducing size, or withdrawing.
This tension explains why market quality cannot be reduced to “more trading” or “a smaller spread.”
What makes a market good?
A market design is only “good” relative to stated objectives. Possible objectives include:
- Enabling useful trades at low total cost.
- Producing prices that incorporate information accurately and promptly.
- Supporting meaningful size without excessive price impact.
- Remaining reliable during imbalances and operational stress.
- Applying rules predictably and limiting avoidable advantages.
- Making risks and responsibilities clear enough for participants to act.
These objectives can conflict. More transparency can aid comparison while exposing intentions. Continuous matching can provide immediacy while rewarding speed. Dealer commitment can provide execution while requiring compensation for risk. Batch trading can reduce the value of tiny timing advantages while making everyone wait.
Good analysis therefore separates:
- Positive questions: What behavior and outcomes will this rule produce?
- Normative questions: Which outcomes should the market prioritize?
Changing a matching rule is not merely a technical refactor. It changes economic incentives and redistributes costs, risks, and opportunities.
What the model leaves out
The visualization is a teaching model, not a market simulator. Its reservation values are fixed, participants submit one unit, all trades settle, and nobody behaves strategically. Real markets add:
- Multiple price levels and quantities.
- Arrival, cancellation, and communication latency.
- Hidden or conditional orders.
- Fees, rebates, tick sizes, and minimum quantities.
- Inventory, funding, margin, and position limits.
- Private information and strategic order placement.
- Multiple venues and routing.
- Clearing, settlement, and counterparty risk.
- Outages, halts, and exceptional market states.
Later chapters add these complications one at a time. Keeping the first model small makes it possible to see exactly which conclusion changes when an assumption changes.
What you should internalize
- People trade because assets, cash flows, and risks have different values to different participants.
- A positive gain from trade can exist before any market mechanism is chosen.
- Markets reduce the cost of discovering counterparties, comparing terms, coordinating time, and completing exchange.
- A trading mechanism defines permitted actions, visible information, matching, pricing, and timing.
- Dealers sell immediacy while assuming inventory and information risk.
- Call auctions concentrate interest; continuous books make arrival sequence and queue position matter.
- Liquidity is multidimensional. A spread is useful but incomplete.
- Price discovery emerges from heterogeneous order flow; it can both support and threaten liquidity.
- There is no universally best market structure. Evaluate a design against explicit objectives and constraints.
Retrieval drill
Using the six values in the visualization:
- Identify every buyer–seller pair with a positive gain from trade.
- Choose one pair and show how three different transaction prices divide the same total surplus.
- Explain why a dealer’s bid and ask are not pure profit.
- Explain one reason a call auction may outperform continuous trading for a thin instrument.
- Name one market-quality improvement that could make another objective worse.
Sources
- Larry Harris, Trading and Exchanges: Market Microstructure for Practitioners, Oxford University Press, 2002, chapters 8–9.
- Thierry Foucault, Marco Pagano, and Ailsa Röell, Market Liquidity: Theory, Evidence, and Policy, first edition, Oxford University Press, 2013, introduction and chapter 1.
An Order Book Is a State Machine
A matching engine consumes an ordered command stream and produces a deterministic sequence of state changes and trades.
The visualization processes one input at a time. Notice that an incoming order is not automatically inserted into the book. It first trades against compatible resting orders. Only an unfilled remainder becomes resting state.
That leads to the chapter’s central model:
previous state + one valid input
→ next state + ordered outputs
If the same initial state and the same ordered inputs can produce different results, the matching engine is not deterministic.
The book is state, not a picture
A displayed order book is usually drawn as bids on one side and asks on the other. That picture is only a projection of deeper state:
- Live orders and their remaining quantities.
- Price levels and their aggregate quantities.
- Queue order within each price level.
- Stable order identities.
- The sequence in which commands became authoritative.
- Instrument state such as open, halted, or auctioning.
For a basic continuous limit order book:
- Bids are ranked from highest price to lowest.
- Asks are ranked from lowest price to highest.
- The highest bid is the best bid.
- The lowest ask is the best ask.
- At one price, an earlier accepted order precedes a later order under time priority.
These are not merely display conventions. They determine who trades.
Commands and events are different
A participant sends a command:
Add order B1: buy 5 at 100
Cancel order B1
Replace order B1
The venue decides whether that command is valid, applies it to canonical state, and emits events:
Order accepted
Trade: 5 at 100
Order partially filled
Order rested
Order canceled
Command rejected
Keeping commands separate from events prevents a common systems mistake: treating a client’s intention as though it were already authoritative venue state.
An add command might produce:
- A rejection and no state change.
- One trade and no resting order.
- Several trades across price levels.
- Several trades followed by a resting residual.
- No trade and one new resting order.
The input is singular. The output can be a sequence.
The smallest useful state
A clear reference model can use standard structures:
#![allow(unused)]
fn main() {
use std::cmp::Reverse;
use std::collections::{BTreeMap, HashMap, VecDeque};
type Price = i64; // integer ticks, never floating point
type Quantity = u64;
type OrderId = u64;
struct Order {
id: OrderId,
price: Price,
remaining: Quantity,
accepted_sequence: u64,
}
struct Book {
bids: BTreeMap<Reverse<Price>, VecDeque<OrderId>>,
asks: BTreeMap<Price, VecDeque<OrderId>>,
orders: HashMap<OrderId, Order>,
}
}
This representation makes the semantics visible:
- The tree orders price levels.
- The deque expresses FIFO priority at one price.
- The hash map resolves an identity to live order state.
- Prices use integer ticks, avoiding ambiguous floating-point equality.
It is a good specification model. It is not automatically the fastest production representation.
Processing an add
Consider an incoming buy limit order with limit price P and remaining quantity Q.
It can trade while both conditions hold:
Q > 0
best ask exists
best ask price <= P
At each step:
- Select the best ask.
- Select the first order at that price.
- Execute the smaller of taker remaining quantity and maker remaining quantity.
- Decrement both quantities.
- Remove a fully filled maker.
- Remove an empty price level.
- Continue until the taker is filled or no compatible ask remains.
- If quantity remains, append the residual to its bid-price queue.
The sell path is symmetric.
incoming buy crosses when limit >= best ask
incoming sell crosses when limit <= best bid
In the model above, each trade occurs at the resting order’s price. That is a common continuous-book convention, but an actual venue’s rulebook is authoritative.
Price priority before time priority
Suppose the ask book contains:
101: S1(4), S2(3)
102: S3(8)
An incoming buy for five units with a limit of 102:
- Trades four with
S1at101. - Trades one with
S2at101. - Never reaches
S3.
Price priority selects the 101 level before 102. Time priority selects S1 before S2.
The taker’s limit is a constraint, not a request to pay exactly that price.
Partial fills create residual state
If a buy for ten units finds only six compatible units, two things happen:
executed quantity = 6
remaining quantity = 4
If its order instructions allow the residual to rest, four units join the bid queue at the order’s limit price. If the instruction is immediate-or-cancel, those four units are canceled instead. The matching algorithm therefore cannot be separated completely from order instructions.
A production event stream must make the distinction explicit. “Order accepted” does not imply “order fully executed,” and “trade occurred” does not imply “order is terminal.”
Canceling by identity is the first representation trap
The hash map can find order B2 in expected constant time. That does not mean the order can be removed from the middle of a VecDeque in constant time.
HashMap lookup expected O(1)
find/remove inside VecDeque O(n) in that price-level queue
A strict constant-time cancel path needs a stronger representation, such as:
- Stable nodes in a slab or arena.
- Intrusive previous/next links within each price queue.
- A map from order ID to stable node handle.
- Lazy tombstones with bounded cleanup.
This is the same structural issue encountered in strict LRU caches. A lookup table provides identity resolution; it does not automatically provide constant-time structural mutation.
The reference model should stay simple until profiling shows that cancel behavior matters. The optimized model must preserve exactly the same externally visible transitions.
Core invariants
An implementation should check invariants after every command in tests and debug builds.
Ordered price levels
bids: strictly descending price
asks: strictly ascending price
Positive live quantities
Every order stored in a price queue has remaining quantity greater than zero. Empty price levels do not exist.
No crossed resting book
After one command has been completely processed:
best_bid < best_ask
If the two sides are compatible, matching work remains. A locked or crossed book may appear in feeds for venue-specific reasons, but it should not appear accidentally in this simple matching model.
FIFO within one price
The accepted sequence numbers in a price queue are increasing. Canceling an order does not change the relative order of its surviving neighbors.
Index agreement
Every live order is reachable through both:
- Its order-ID index.
- Exactly one side and price queue.
No queue entry points to a missing order, and no indexed order is absent from the book.
Quantity conservation
For every accepted order:
original quantity
= executed quantity
+ canceled quantity
+ live remaining quantity
This equation is useful in unit tests, replay validation, and production reconciliation.
Deterministic replay
A deterministic matcher is naturally event-sourced:
snapshot + commands after snapshot → current state
Replay supports:
- Recovery after process failure.
- Reproducing disputed executions.
- Comparing two implementations.
- Testing optimized code against a reference model.
- Building historical books from authoritative events.
The ordering input must itself be authoritative. Wall-clock timestamps alone are insufficient when two messages can share a timestamp or arrive through different paths. A venue normally needs a total sequence, a single serialization point, or rules that produce an equivalent ordering.
For each processed command, record enough information to reproduce:
- The command and participant identity.
- Its authoritative sequence.
- Validation outcome.
- Generated trades in order.
- Resting or terminal outcome.
Why the matching core is usually a single writer
The critical state is small but tightly coupled. Matching one command can touch:
- The best price level.
- Several maker orders.
- Aggregate quantity.
- The ID index.
- The trade sequence.
- The incoming order’s residual.
Allowing several threads to mutate these structures concurrently makes ordering and recovery much harder. A common architecture therefore uses one logical writer per partition:
network receive
→ parsing and validation
→ sequenced command queue
→ single matching-state owner
→ execution and market-data outputs
“Single writer” does not mean “the whole venue uses one CPU.” Instruments can be partitioned, and parsing, persistence, risk, and publication can run elsewhere. The design constraint is that one canonical order stream has one unambiguous mutation order.
This is an architectural starting point, not a universal law. Measure before adding coordination to the matching path.
Correctness before representation
Two implementations can expose the same state machine:
| Concern | Clear reference | Possible optimized form |
|---|---|---|
| Price levels | BTreeMap | Flat ladder, radix structure, custom tree |
| FIFO at price | VecDeque<OrderId> | Intrusive queue over slab nodes |
| Identity | HashMap<OrderId, Order> | Dense handle table or specialized hash table |
| Allocation | Ordinary owned values | Preallocated arena or object pool |
| Outputs | Growable vector | Bounded ring or preallocated batch |
Do not optimize by silently changing semantics. The fast implementation should be tested against the reference implementation using generated command streams.
The companion systems chapters explain the machinery:
This book owns the market semantics. The systems book owns representation, CPU behavior, networking, and measurement.
Failure cases worth testing
A useful test suite includes:
- Duplicate order ID.
- Unknown cancel.
- Zero or overflowing quantity.
- Invalid tick price.
- Add that walks several levels.
- Partial maker and partial taker fills.
- Cancel of the head, middle, and tail of a queue.
- Disconnect after the command becomes authoritative but before acknowledgment.
- Replay containing a duplicate or missing sequence.
- Snapshot taken between output publication steps.
- Instrument halt while commands are queued.
Tests should assert the final book and the exact ordered output events.
What you should internalize
- The book is canonical state; its visual ladder is only a projection.
- Commands express intent. Events describe authoritative outcomes.
- An incoming order matches before any residual rests.
- Price priority chooses the level; time priority chooses within the level.
- Partial execution changes quantity without necessarily terminating an order.
- Fast identity lookup does not guarantee fast removal from a FIFO queue.
- Invariants turn matching rules into executable correctness conditions.
- Deterministic replay requires an authoritative total input order.
- A single logical writer makes mutation order and recovery easier to reason about.
- Optimize the representation only after preserving the reference state machine.
Retrieval drill
Using the event sequence in the visualization:
- Why does
S2trade withB1beforeB2? - Why does two units of
B2remain afterS2finishes? - At what price does
B3trade withS1, and why? - Which invariant would detect a zero-quantity order left in a queue?
- What additional structure would make cancellation from a long price queue constant time?
Sources
- Larry Harris, Trading and Exchanges: Market Microstructure for Practitioners, Oxford University Press, 2002, chapters 4 and 6.
- Thierry Foucault, Marco Pagano, and Ailsa Röell, Market Liquidity: Theory, Evidence, and Policy, first edition, Oxford University Press, 2013, chapter 1.
Exact order types, amendment rules, precedence, and execution prices are venue-specific. Later venue chapters will use current rulebooks and protocol specifications as primary sources.
Orders and Execution Instructions
An order is a conditional instruction, not simply an intention to buy or sell. Price, quantity, duration, visibility, routing, and contingency determine when it may execute.
Central questions
- What protection does a limit provide, and what fill risk remains?
- What does a market order actually guarantee?
- How do time-in-force and special instructions change eligibility?
Planned model
Submit market, limit, immediate-or-cancel, fill-or-kill, post-only, hidden, and pegged instructions into the same book and expose every accepted, rejected, rested, and executed quantity.
The Order Lifecycle
Between decision and terminal state, an order may be pending, accepted, resting, partially filled, canceling, replaced, rejected, expired, or uncertain.
Central questions
- Which event makes each transition authoritative?
- What happens when fills race with cancellation?
- How should duplicate or missing acknowledgements be interpreted?
Planned model
Animate client, gateway, and venue state on one timeline. Inject delay, duplication, rejection, partial execution, cancel races, and disconnects.
Matching and Priority
Matching rules decide which compatible orders trade and which resting order receives an execution first.
Central questions
- How do price-time, pro-rata, size, and allocation rules differ?
- Which order changes retain or lose priority?
- What behavior does each rule encourage?
Planned model
Apply the same arriving orders under price-time and pro-rata priority. Display allocations, queue movement, amendments, and participant incentives.
Market Structures
Dealer markets, order-driven auctions, crossing systems, and hybrid venues assign price formation and immediacy to different mechanisms.
Central questions
- Who supplies executable prices?
- When are orders exposed to one another?
- Which mechanism handles thin liquidity or concentrated information best?
Planned model
Run identical participant arrivals through bilateral search, dealer quotes, call auctions, and continuous limit-order trading, then compare outcomes and information leakage.
Instruments, Venues, and Trading Sessions
An instrument defines contractual exposure; a venue defines where and under what rules it trades; a session defines which rules are active at a given time.
Central questions
- What exactly is delivered, settled, or financially referenced?
- Which venue and session state govern an order?
- How do auctions, halts, expiries, and corporate actions alter continuity?
Planned model
Place one instrument on several venues and step through pre-open, auction, continuous trading, halt, reopen, and close while displaying permitted actions and price formation.
Participants and Objectives
Participants trade for different reasons: investment, hedging, liquidity, arbitrage, dealing, market making, or agency execution. The same action can be rational under one objective and harmful under another.
Central questions
- Who needs immediacy and who can wait?
- Which risks and constraints shape each participant’s orders?
- Why should observable order flow not be assigned one universal motive?
Planned model
Give participants different values, deadlines, inventories, and information. Show how their chosen orders change as those constraints change.
Ticks, Lots, Fees, and Rebates
Price grids, quantity increments, minimum values, fees, and rebates change both valid orders and the economics of apparently identical trades.
Central questions
- How does tick size constrain spreads and queue competition?
- Which explicit costs differ for adding and removing liquidity?
- When do rebates change behavior without changing gross prices?
Planned model
Adjust tick size, lot size, taker fee, and maker rebate while participants choose prices. Show effective spread, queue length, and net execution cost.
Market Microstructure
Microstructure connects participant incentives and trading rules to spreads, liquidity, order flow, prices, volatility, and impact.
The emphasis is causal reasoning: what is observed, which mechanism might produce it, what alternatives exist, and what evidence distinguishes them.
Quotes, Spreads, and Midpoints
The best bid and ask summarize immediately displayed trading opportunities. Their difference is observable; its interpretation depends on trade direction, size, fees, and subsequent prices.
Central questions
- What do quoted, effective, and realized spreads measure?
- When is the midpoint a useful reference price?
- How do locked, crossed, or empty books alter these definitions?
Planned model
Move quotes and trades through time while computing multiple spread measures and showing the reference price used by each.
Depth, Liquidity, and Resilience
Liquidity has several dimensions: tight prices, available quantity, low impact, immediacy, and recovery after demand consumes the book.
Central questions
- Why is visible depth not identical to executable liquidity?
- How does required trade size change the relevant spread?
- What does resilience measure after a shock?
Planned model
Walk market orders through adjustable depth, then animate cancellations and replenishment. Plot average execution price, impact, and recovery time.
Order Flow and Imbalance
Order flow records additions, removals, and trades. Imbalance compresses selected state or events into a directional statistic whose meaning is horizon- and venue-dependent.
Central questions
- Which events count as buying or selling pressure?
- Does the statistic use displayed depth, trades, or order-flow changes?
- Over what horizon does any predictive relationship persist?
Planned model
Construct several imbalance measures from one event stream and compare their response to additions, cancellations, executions, and spoof-like transient depth.
Queue Position
At a price-time venue, a resting order’s fill opportunity depends on quantity ahead, subsequent removals, incoming contra-side demand, and the venue’s exact priority rules.
Central questions
- Which events reduce quantity ahead?
- Can market-by-price data reveal an individual order’s exact rank?
- How do amendments, hidden size, and packet loss affect inference?
Planned model
Place an order in a visible queue and process trades, cancels, additions, hidden liquidity, and data aggregation while showing true and estimated position.
Adverse Selection and Toxicity
A passive fill is adverse when the counterparty tends to trade before prices move against the resting quote. The fill itself can contain information.
Central questions
- What post-trade horizon defines an adverse outcome?
- How are information, volatility, and mechanical price movement separated?
- Which toxicity measure is observable in real time?
Planned model
Mix informed, liquidity-motivated, and random arrivals. Compare maker P&L at several marking horizons and expose selection bias from conditioning on fills.
Price Discovery
Price discovery is the process through which dispersed information becomes reflected in executable prices across participants and venues.
Central questions
- Which event moved the quote, and was the move informative or temporary?
- How is leadership measured across fragmented venues?
- What benchmark represents an unobserved efficient price?
Planned model
Inject public and private signals into participants trading across two venues. Show quote changes, trades, lag, noise, and competing estimates of the latent value.
Volatility and Market Time
Price variation depends on sampling interval, clock, estimator, trading intensity, and microstructure noise. “Volatility” is incomplete without those choices.
Central questions
- Are observations sampled in wall time, event time, or volume time?
- How do bid-ask bounce and discrete ticks bias estimates?
- Which horizon is relevant to the decision being modeled?
Planned model
Generate one latent price and noisy quotes, then sample it under several clocks and intervals while comparing realized-variance estimates.
Market Impact
Impact describes price changes associated with trading, but observed correlation mixes mechanical consumption, information, selection, and broader market movement.
Central questions
- Is impact temporary, permanent, or measured over a specified horizon?
- What counterfactual price would have occurred without the trade?
- How do size, participation rate, liquidity, and urgency interact?
Planned model
Execute schedules against replenishing depth while separating immediate book walking, subsequent recovery, and an independently moving latent price.
Execution
Execution begins with a target position change and converts it into orders over time and venues while balancing urgency, price risk, explicit costs, impact, and fill uncertainty.
There is no universally best algorithm: the objective, constraints, information set, and benchmark determine what “better” means.
The Execution Problem
Execution transforms a desired position change into market actions before a deadline while prices, liquidity, and information evolve.
Central questions
- What quantity, deadline, and completion requirement define the task?
- Which price and risk objectives compete?
- What information is available when each decision is made?
Planned model
Give the reader a parent order, deadline, evolving book, and risk preference. Compare immediate execution, uniform scheduling, and adaptive participation.
Costs and Implementation Shortfall
Execution cost includes explicit fees and the difference between actual outcomes and a chosen decision-price benchmark, including unexecuted opportunity cost.
Central questions
- Which timestamp establishes the decision price?
- How are spread, impact, delay, fees, and opportunity cost decomposed?
- What treatment keeps partial completion honest?
Planned model
Trace a parent order from decision through child fills and residual quantity, then compute shortfall under several price paths and completion outcomes.
Execution Benchmarks
Arrival price, close, VWAP, TWAP, and other benchmarks encode different questions. Optimizing to a benchmark can change behavior in ways unrelated to economic value.
Central questions
- What decision does the benchmark evaluate?
- Can the trader influence the benchmark itself?
- Which information is known before versus after execution?
Planned model
Apply one set of fills to several benchmarks and expose when identical trading is judged differently solely because the evaluation reference changed.
Scheduling and Participation
An execution schedule distributes quantity through time or observed volume, balancing market exposure, completion risk, signaling, and impact.
Central questions
- Should trading follow time, volume, liquidity, or urgency?
- What happens when realized volume differs from forecast volume?
- How does a participation cap constrain completion?
Planned model
Compare TWAP, VWAP, percentage-of-volume, and adaptive schedules against quiet, bursty, and trending volume profiles.
Choosing Orders
Passive orders trade price improvement for fill uncertainty and adverse selection; aggressive orders trade certainty and speed for spread and impact.
Central questions
- What is the value of waiting relative to the risk of non-completion?
- Which queue position and cancellation policy accompany a passive order?
- When does an order type merely hide a dynamic policy?
Planned model
Choose price, size, and duration while the book evolves. Display expected fill, realized cost, opportunity loss, and information exposed.
Routing and Venue Selection
Routing distributes orders across venues whose prices, fees, queues, latency, fill quality, and rules differ.
Central questions
- Which displayed quantity is reachable before it changes?
- How are fill probability and adverse selection estimated per venue?
- What obligations or protections constrain routing?
Planned model
Route one parent order across venues with different depth, fees, delays, and toxicity. Show expected and realized net outcomes.
Optimal Execution
Optimal execution formalizes a tradeoff among expected cost, price risk, impact, completion, and constraints. The result is optimal only inside its model.
Central questions
- What state, objective, controls, and constraints define the problem?
- Which impact and price dynamics are assumed?
- How sensitive is the policy to parameter error?
Planned model
Adjust risk aversion, horizon, volatility, and impact coefficients in a small discrete-time control problem and compare resulting schedules.
Market Making
Market makers expose prices and quantities while managing inventory, adverse selection, queue position, volatility, fees, and operational risk.
This part treats spread capture as compensation for risks and costs, not free profit obtained merely by posting on both sides.
The Quoting Problem
A market maker chooses bid and ask prices and quantities while fills arrive asynchronously and future value remains uncertain.
Central questions
- What reference value anchors the quotes?
- How should inventory, volatility, queue position, and fees alter them?
- When should one side be reduced or withdrawn?
Planned model
Let the reader move quotes around a latent value while observing fills, inventory, marked P&L, and adverse post-fill movement.
Where the Spread Comes From
The spread can compensate for order-processing costs, inventory exposure, adverse selection, tick constraints, competition, and venue economics.
Central questions
- Which costs are fixed, state-dependent, or informational?
- What changes when tick size binds?
- Why is a realized spread smaller than the quoted spread after adverse price movement?
Planned model
Turn individual cost and risk components on and off and show how break-even quotes and realized maker economics change.
Inventory Risk
Fills create inventory whose value changes with the market. Inventory-aware quoting trades expected spread capture against exposure and liquidation risk.
Central questions
- How should quotes skew as inventory approaches a limit?
- Which horizon and covariance define exposure risk?
- When should inventory be hedged elsewhere rather than through quotes?
Planned model
Accumulate inventory under stochastic fills and prices, then compare symmetric quoting, inventory skew, hard limits, and external hedging.
Stale Quotes and Adverse Selection
A quote becomes stale when new information changes fair value before the quote can be updated or canceled. Faster counterparties may selectively execute it.
Central questions
- Which observation triggers a quote update?
- What delays exist from observation through cancel effectiveness?
- How does latency affect losses conditionally on being filled?
Planned model
Move an external reference price while injecting market-data, decision, gateway, and venue latency. Show the vulnerability window and resulting fills.
Fill Probability
Fill probability depends on price, rank, future order flow, cancellations, hidden liquidity, and venue rules. Historical fill rates are conditional on the quoting policy that generated them.
Central questions
- What state variables make a fill estimate conditional?
- How are cancellations ahead distinguished from behind?
- Does a higher fill probability also imply worse selection?
Planned model
Vary quote price and queue position under several order-flow regimes while plotting fill probability alongside post-fill markout.
Controls and Failure Modes
Quoting must remain bounded when data is stale, connectivity fails, volatility jumps, inventory grows, or acknowledgements become uncertain.
Central questions
- Which conditions withdraw one side or all quotes?
- What state is trustworthy during a disconnect?
- How are message rate, exposure, and loss bounded independently?
Planned model
Inject stale feeds, reject storms, cancel delays, volatility shocks, and position-limit breaches into a quoting state machine and observe its safe-state transitions.
Data and Empirical Work
Market data is not a clean table delivered by nature. It is a sequenced record produced by particular venues, clocks, symbology systems, schemas, and collection paths.
This part establishes when reconstructed state and derived statistics are reliable enough to support a claim.
Market Time and Symbology
An event may have exchange, gateway, capture, and processing timestamps, while an instrument may change or share identifiers across venues and dates.
Central questions
- Which clock and event does each timestamp represent?
- How are offset, drift, precision, and ordering handled?
- Which identifier maps a record to the intended economic instrument?
Planned model
Align one event stream across imperfect clocks and changing symbol mappings, then show how attribution and joins fail when semantics are ignored.
Event Schemas
Market data may describe orders, price levels, trades, quotes, snapshots, corrections, and administrative state. A schema determines what can be reconstructed.
Central questions
- Is the feed market-by-order, market-by-price, or a derived view?
- Which fields distinguish updates, corrections, and deletions?
- What precision and units apply to price, size, and time?
Planned model
Encode the same market events as L1, L2, and L3 data and expose which questions each representation can and cannot answer.
Cleaning and Reconstruction
Cleaning is the preservation of known semantics while handling loss, duplicates, disorder, corrections, session transitions, and invalid records—not making inconvenient observations disappear.
Central questions
- Which invariant detects a corrupt or incomplete state?
- Can a gap be repaired, or must the interval be excluded?
- How are transformations logged and reproduced?
Planned model
Reconstruct a book from a damaged event stream and compare repair, resynchronization, quarantine, and silent-forward-fill policies.
Stylized Facts
Stylized facts are recurring empirical patterns, not universal laws. Their strength depends on instrument, venue, regime, sampling, and cleaning choices.
Central questions
- Which distribution, dependence, or scaling pattern is claimed?
- Under what conditioning and time scale does it appear?
- Could discreteness, spread bounce, or data handling create it?
Planned model
Compare return tails, volatility clustering, duration, volume, and order-sign persistence under several sampling and filtering choices.
Estimation and Calibration
Calibration chooses model parameters from observations; estimation also quantifies uncertainty. A close in-sample fit does not establish identification or predictive value.
Central questions
- Which likelihood, moments, or loss function connect data to parameters?
- Are parameters identifiable from available observations?
- How stable are estimates across time, instruments, and sampling choices?
Planned model
Fit a simple arrival or impact model to generated data while varying sample size, censoring, regime shifts, and misspecification.
Experimental Design
An empirical result is credible when its hypothesis, information boundary, comparison, sampling procedure, uncertainty, and failure conditions are explicit before interpreting performance.
Central questions
- What observation would contradict the hypothesis?
- Which data selected the model and which evaluated it?
- Are dependence, multiple comparisons, and regime changes addressed?
Planned model
Run the same signal through random splits, chronological splits, purged evaluation, and repeated parameter search to expose leakage and selection bias.
Simulation and Backtesting
A backtest asks what might have happened under decisions that were not actually sent to the historical market. That counterfactual requires assumptions about information, latency, queue position, fills, impact, and costs.
The simulator should make every such assumption visible and test sensitivity to it.
Event-Driven Replay
Event-driven replay advances simulated state through a deterministic ordered stream rather than repeatedly sampling snapshots without causal transitions.
Central questions
- Which clock orders events with equal or conflicting timestamps?
- When may a strategy observe an event and when may its response arrive?
- Which random choices must be seeded and recorded?
Planned model
Step exchange events, strategy observations, decisions, outbound messages, and acknowledgements through one priority queue with explicit tie-breaking.
Book Reconstruction
A simulator can only replay the state represented by its data. L1, L2, and L3 inputs support progressively stronger but still venue-specific conclusions.
Central questions
- Which order-book invariants are checked after every event?
- How do snapshots join the incremental stream?
- Which hidden or implied liquidity remains unobserved?
Planned model
Reconstruct the same interval from L1, L2, and L3 feeds and compare executable depth, queue knowledge, and simulated fill claims.
Queue and Fill Models
Historical trades do not prove that a hypothetical order would have filled. A queue model supplies the missing counterfactual allocation assumptions.
Central questions
- How is initial rank estimated from the available feed?
- Which cancellations are assumed to occur ahead?
- Does the simulated order alter subsequent market events?
Planned model
Run pessimistic, optimistic, probabilistic, and exact-L3 queue models on one stream and compare their fill timing and P&L.
Latency Models
Latency determines which state is observable when a decision occurs and which competing events arrive before an order or cancellation becomes effective.
Central questions
- Which receive, compute, send, network, gateway, and venue delays are modeled?
- Are delay samples independent of load and message type?
- How are timestamp uncertainty and clock error represented?
Planned model
Apply constant, empirical, load-dependent, and correlated latency distributions to identical decisions and reveal changed queue positions and fills.
Impact and Counterfactuals
Once a hypothetical order is large or visible enough to affect other behavior, replaying an unchanged historical future becomes internally inconsistent.
Central questions
- At what size can a strategy plausibly be treated as a price taker?
- Which historical events depend on the market state the simulation changed?
- How is uncertainty in impact represented?
Planned model
Compare no-impact replay, mechanical book consumption, parametric response, and adversarial sensitivity bounds for one execution schedule.
Bias and Evaluation
Look-ahead, survivorship, selection, overfitting, optimistic fills, missing costs, and repeated testing can manufacture attractive historical performance.
Central questions
- Was every input available at the simulated decision time?
- Which choices were made after inspecting evaluation results?
- Does reported uncertainty include parameter and model selection?
Planned model
Introduce common biases one at a time into a strategy with no true edge and show how each changes reported returns, risk, and significance.
Risk and Operations
Trading decisions operate inside position, credit, rate, price, and operational constraints. Correct behavior during uncertainty matters as much as the normal path.
This part treats limits, reservations, reconciliation, kill switches, and recovery as state-machine problems with explicit safe defaults.
Position, P&L, and Exposure
Position and P&L are derived from fills, fees, corrections, marks, currencies, and accounting conventions. Exposure asks what can change value before positions are closed or hedged.
Central questions
- Which events are authoritative and idempotent?
- How are realized, unrealized, gross, net, and factor exposures distinguished?
- Which price and exchange rate mark each position?
Planned model
Apply fills, fees, busts, price moves, and FX moves to a ledger while displaying position, cash, realized P&L, unrealized P&L, and exposure.
Pre-Trade Limits
Pre-trade controls reject or constrain orders using current and outstanding exposure, price, quantity, credit, message rate, and operational state.
Central questions
- Which checks apply per order, instrument, strategy, account, and firm?
- What state must include unacknowledged or resting orders?
- Which unavailable input causes fail-closed behavior?
Planned model
Pass orders through layered limits while changing positions, prices, outstanding quantities, and session state. Show the exact reason and state for every decision.
Reservations and Concurrent Risk
Two orders checked against the same stale capacity can jointly exceed a limit. Reservations turn accepted intent into exposure before final venue outcomes arrive.
Central questions
- When is risk capacity reserved, converted, released, or corrected?
- Which concurrent operation owns each transition?
- How are rejects, partial fills, cancels, and timeouts reconciled?
Planned model
Race several orders for the last available capacity and compare naive check-then-send with atomic reservation and event-driven release.
Kill Switches and Safe States
A kill switch stops or constrains new activity and may attempt cancellation, but it cannot assume cancellation is instantaneous or successful.
Central questions
- What triggers manual or automatic intervention?
- Which actions remain permitted while stopping?
- How is residual live exposure discovered and handled?
Planned model
Trigger strategy, account, venue, and firm-level stops while orders are pending and filling. Display new-order blocking, cancel progress, uncertainty, and recovery authority.
Reconciliation and Recovery
After failure, local intent, durable records, venue state, and downstream positions may disagree. Recovery begins by discovering authoritative external state.
Central questions
- Which records survive each failure boundary?
- Which resend or cancel actions are idempotent?
- When must automated recovery stop for operator judgment?
Planned model
Crash a gateway at several acknowledgement boundaries and reconcile local logs with venue order and trade reports before allowing new activity.
Model and Regime Risk
A model can fail because parameters drift, mechanisms change, inputs break, or its abstraction was never valid at the scale being used.
Central questions
- Which observable conditions define the model’s operating domain?
- What detects drift or structural change soon enough to act?
- Which fallback remains safe when confidence collapses?
Planned model
Shift volatility, order flow, fees, tick size, latency, and participant behavior while comparing static calibration, adaptive estimates, guardrails, and shutdown.
Mathematical Models
Mathematics becomes useful after variables have operational meanings. This part introduces probability, event-arrival models, stochastic prices, optimization, and control as representations of mechanisms already observed earlier.
Every derivation must keep its information set, objective, constraints, calibration method, and failure conditions visible.
Probability for Event Streams
Probability describes uncertain events conditional on an information set. Market applications require careful treatment of dependence, conditioning, stopping, and selection.
Central questions
- What random variable and filtration represent the observation process?
- Which independence assumption is being made?
- How do conditional expectation, variance, and likelihood enter estimation?
Planned model
Build event sequences from Bernoulli, categorical, and dependent processes while showing unconditional and conditional probabilities as information arrives.
Point Processes
Point processes model random event times and types. Their intensities can depend on time, market state, and prior events.
Central questions
- What does a conditional intensity predict?
- When is a Poisson assumption contradicted by clustering or inhibition?
- How are marks such as side, size, or event type included?
Planned model
Generate homogeneous, state-dependent, and self-exciting arrivals and compare durations, clustering, likelihood, and simulated book consequences.
Stochastic Price Models
Price models approximate uncertain evolution at a chosen horizon. A model for latent value, transaction prices, and discrete quotes need not be the same.
Central questions
- Which price process is being modeled?
- Are increments continuous, jumping, mean-reverting, or regime-dependent?
- Which empirical feature and decision require the model?
Planned model
Compare random walk, diffusion, jump, mean-reverting, and regime-switching paths after adding tick rounding and bid-ask bounce.
Optimization and Dynamic Programming
Optimization chooses controls to improve an explicit objective under constraints. Dynamic programming decomposes sequential decisions through state and future value.
Central questions
- What state is sufficient for future decisions?
- Which costs, constraints, and terminal conditions define success?
- When does the state space make exact recursion impractical?
Planned model
Solve a finite-horizon inventory liquidation problem by backward induction and expose each state value, action choice, and sensitivity to assumptions.
Stochastic Control
Stochastic control chooses actions as uncertain state evolves. Market-making and execution models often arise by balancing expected reward against inventory or price risk.
Central questions
- Which process is controlled and which uncertainty remains exogenous?
- What observations are available to the controller?
- Is the derived policy robust to misspecified dynamics?
Planned model
Move from a discrete value function to a small continuous-time quoting or liquidation model while keeping every assumption connected to an earlier observable mechanism.
Model Validation
Validation asks whether a model is adequate for a particular decision, not whether it is universally true. Fit, prediction, calibration, stress behavior, and operational use are distinct tests.
Central questions
- Which observable implications were not used to fit the model?
- How are parameter, sampling, and structural uncertainty reported?
- What decision loss results when the model is wrong?
Planned model
Compare models that fit the same in-sample statistic but disagree on tails, event dependence, fills, and policy outcomes under held-out regimes.