Reservations and Concurrent Risk
Two orders checked against the same stale capacity can jointly exceed a limit. Reservations turn accepted intent into exposure before final venue outcomes arrive.
Central questions
- When is risk capacity reserved, converted, released, or corrected?
- Which concurrent operation owns each transition?
- How are rejects, partial fills, cancels, and timeouts reconciled?
Planned model
Race several orders for the last available capacity and compare naive check-then-send with atomic reservation and event-driven release.