Data Intel Credit Loop
TradeOS uses Data Intel Credits, or DTI credits, to connect public market intelligence, human review, and product access without turning feedback into trading authority or unrestricted infrastructure access.
The public value ladder is:
Use TradeOS free.
Earn Data Intel Credits by improving intelligence quality.
Build and earn on public intelligence.
Pay when you need private intelligence, scale, alerts, automation, or data rights.
Inside that ladder, the Data Intel Credit loop is:
Read evidence -> label what is useful or wrong -> review quality -> earn DTI credits -> unlock temporary public depth, Ask, or Review Lab access
Data Intel Credits are scoped account-based product credits. Human DTI unlocks public-page depth, public Ask question packs, or read-only Review Lab tasks. It does not unlock private workspace pages, private Ask context, execution, exchange connectivity, custody, personalized financial advice, bulk exports, webhooks, x402 resources, private APIs, or enterprise data.
Scoped DTI Model
DTI is the common credit unit. Spend scope controls where it applies.
| Credit class | Earned by | Spend scope | What it does not do |
|---|---|---|---|
human_dti | Welcome credits and quality-reviewed human feedback | Public dashboard depth, public Ask packs, read-only Review Lab | Does not convert to API scale or paid data rights |
app_reputation_dti | Attributed builder, agent, or automation feedback with stable target IDs after Feedback Ops disposition | App reputation and quota confidence | Does not become a personal user balance, paid entitlement, or API-scale credit |
grant_dti | Operator-approved quota request | Reviewed public API quota | Does not open paid/private resources |
paid_capacity | x402 payment, paid API key, contract, or entitlement | Scale, alerts, automation, exports, private context, data rights | Separate from feedback-earned credits |
Viewer expectations are intentionally different:
| Viewer | Dashboard or API | What they can see |
|---|---|---|
| Human user | /credits, /review, GET /v1/dashboard/credits, GET /v1/credits/ledger | Personal human DTI status, activity, unlocks, and review tasks. |
| Builder account | /developer/feedback, /developer/api-keys, GET /v1/public-intel/feedback-activity | App-key feedback rows and app reputation DTI effects for keys owned by the account. |
| Agent/app key | GET /v1/public-intel/app-feedback-status | The authenticated app key's own feedback lifecycle and app reputation DTI summary. |
| Admin | /admin/feedback | Feedback Command Center for active queues, autonomous disposition, builder/API ops, and audit history. |
Expected viewer outcomes:
| Viewer | Positive outcome | Negative or boundary outcome |
|---|---|---|
| Human user | Sees personal human_dti balance, pending/spent activity, and dashboard/review unlocks. | App reputation DTI from agents does not appear in the personal human ledger and is not API-convertible. |
| Builder account | Sees lifecycle rows for app keys owned by the signed-in account, including source/agent metadata and app reputation DTI effect. | Unowned app keys are not returned; invalid filters are rejected instead of broadening access. |
| Agent/app key | Valid public-intel app keys can self-check their own accepted, pending, rejected, and suppressed feedback rows. | Missing, invalid, revoked, suspended, or expired keys are rejected and do not receive earned app reputation DTI in the error response. |
Human App Flow
- Open public intelligence. Anonymous visitors can read Market Pulse, Token Radar, Signal Radar, public token dossier previews, watchlist preview, and a small number of public-intelligence questions.
- Create an account. Signed-in users receive starter Ask TradeOS access and welcome Data Intel Credits.
- Verify email ownership. Verification is not a hard wall, but it gives future feedback a stronger provenance tier than anonymous or unverified activity.
- Review specific evidence. Feedback is attached to concrete targets such as market cards, VPIN incidents, evidence cards, forecasts, bias views, fusion signals, EA-quality views, digests, token-risk notes, and thesis review tasks.
- Submit a label. Useful labels include whether something was useful, late, too early, confusing, evidence-thin, a false positive, or a missed move.
- Quality checks run. Duplicate, copied, spammy, or abusive feedback can be suppressed or revoked. Trusted feedback keeps the account verification state that existed at submission time.
- Data Intel Credits unlock dashboard depth or review work. Approved credits can unlock temporary public depth such as more history, deeper evidence cards, Token Radar detail, Signal Radar detail, extra public-intelligence question packs, or read-only Review Lab task families.
Free public market intelligence stays open when an unlock expires.
Credit Ladder
The default GUI credit loop is intentionally concrete:
| Step | User action | Credit or access effect | Expiry |
|---|---|---|---|
| Start anonymous | Open the public dashboard | Read public market state and ask 3 public-intelligence questions | Session or anonymous quota boundary |
| Create account | Sign in to TradeOS | 6 welcome Data Intel Credits and 10 signed-in starter Ask questions | Ask starter lasts 7 days |
| Give useful feedback | Label a unique evidence target after enough dwell time and normal confidence | 3 DTI credits after quality checks | Credits remain in the ledger until spent or revoked |
| Redeem 3 DTI credits | Choose a light dashboard unlock | Faster refresh, more public symbols, longer history, deeper Market Pulse/sector/VPIN evidence, Token Discovery detail, or Fusion Lite detail | 7 days by default |
| Redeem 6 DTI credits | Choose a review or Ask unlock | Forecast Lab, Bias/Fusion Review, EA Entry Quality, Symbol Story, Token Cycle, Digest/Thesis Review, or +5 public Ask questions | 7 days by default |
| Unlock expires | Do nothing or stop contributing | Falls back to free public limits | Immediate after expiry |
Feedback must be attached to a stable target such as a market card, evidence card, forecast, bias view, fusion signal, digest item, token note, thesis task, or bot answer. Duplicate, copied, spammy, low-confidence, or too-fast labels can earn 0 DTI credits or be suppressed.
Free, starter, and feedback-earned access is best-effort promotional access. It has no SLA, no cash value, and may be rate-limited, changed, paused, degraded, or revoked to protect TradeOS infrastructure. Paid/x402/contract access is the path for reliable production scale.
What Users See
| Area | What it shows |
|---|---|
| Market dashboard | Free read-only market state, sector breadth, live transition, VPIN evidence history, feedback prompts, and credit entry points. |
| Token Radar | Public token candidates with identity, risk, confidence, freshness, and dossier links. |
| Fusion Signals | Public direction, confidence, freshness, why-fired context, invalidation, and feedback intake without execution fields. |
| Token dossier preview | Public token-level evidence first, with private evidence depth clearly separated behind paid/private access. |
| Watchlist Intelligence | Public preview plus signed-in account-owned watchlists for tracking token risk, thesis changes, and signal-quality changes. |
| Data Intel Credits | Welcome DTI credits, pending DTI credits, spent DTI credits, active unlocks, available unlocks, and recent activity. |
| Review Lab | Feedback tasks that ask for validation on forecasts, bias, fusion, EA entry quality, token-cycle, digest, and thesis surfaces. |
| Builder/App Feedback | Signed-in builder portal for app-key feedback lifecycle, agent feedback status, and app reputation DTI. |
| Ask TradeOS | Public-intelligence questions with separate starter quotas for anonymous and signed-in users. |
| Email verification banner | A prompt for signed-in unverified users to verify their email for trusted feedback provenance. |
What Unlocks Where Today
DTI credits are enforced by the dashboard-access and review-task APIs. Some unlocks change public page limits directly; others only unlock matching Review Lab tasks.
| Feature family | DTI unlock | Where users see it | Feedback capture |
|---|---|---|---|
| Market Pulse, VPIN, and evidence depth | 3 DTI public-depth unlocks | /market/signals reads refresh_interval_seconds, symbol_limit, history_days, and evidence_depth from /v1/dashboard/access; /market remains the Intelligence Layer overview | Market, VPIN, and evidence cards render contextual feedback prompts on stable targets |
| Token Discovery detail | Token Discovery detail (3 DTI) | /discover reads token_discovery_limit, token_discovery_depth, and token_discovery_history_days | Token-cycle validation opens through the matching Review Lab pass |
| Fusion Signal Cockpit detail | 3 DTI public Fusion detail | /fusion reads fusion_signal_limit, fusion_signal_depth, and fusion_signal_history_days | Public feedback labels direction quality, overconfidence, stale reads, missing context, and understated risk; deeper bias/fusion validation opens through the matching Review Lab pass |
| Forecast, EA, Symbol Story, Token Cycle, Digest/Thesis | 6 DTI Review Lab passes | /review calls /v1/review/tasks; tasks with requires_unlock_type become open only when the user has that active unlock | Open tasks render the same artifact feedback prompt and write to the DTI ledger |
| Ask TradeOS public questions | 6 DTI AskTradeOS question pack | /ask consumes the public Ask quota and bonus question grants | Completed answers render an answer-quality feedback prompt |
| Private workspace, private Ask, paid delivery, exports, alerts, automation, x402/API scale, custody, execution | Not DTI | /private-access or paid/builder entitlement paths | DTI cannot open these surfaces |
Current Ask TradeOS starter limits are deliberately small:
| User state | Starter access | Expiry |
|---|---|---|
| Anonymous visitor | 3 public-intelligence questions | Session or anonymous quota boundary |
| Signed-in starter user | 10 public-intelligence questions | 7 days from first quota activation |
| Feedback question pack | 5 extra public-intelligence questions | Earned with DTI credits |
Credit Policy
| Credit source | Treatment |
|---|---|
| Welcome signup credit | Starting Data Intel Credits for signed-in users. |
| Linked verified human feedback | Eligible for normal Data Intel Credit after quality checks. |
| Linked unverified human feedback | Recorded and may help product quality, but not treated as Reppo-ready trusted human validation. |
| Human-assisted feedback | Eligible after validation and sampling, usually with conservative weight. |
| Agent feedback | Useful for QA, disagreement, app reputation, and quota confidence; no personal user credit by default. |
| Automation feedback | Useful telemetry and app-quality signal; no personal user credit by default. |
| Spam, duplicate, or copied labels | Suppressed, ignored, or revoked. |
Operational Credit State Machine
GUI and API feedback use different ledgers today because they carry different credit semantics.
| Source ID | Source ledger | Typical actor | Credit treatment |
|---|---|---|---|
fb_... | feedback_events | Signed-in GUI user | Can create pending human DTI when the feedback is eligible and non-duplicate |
pifb_... | public_intel_feedback_ledger | App key, builder, agent, automation, public-intel client | App reputation or quota-confidence signal; no personal DTI by default |
ifb_... | Normalized intelligence-feedback projection | Inbox, email, GUI, API adapter, Feedback Ops | Not a credit source by itself; points back to fb_... or pifb_... when source-backed |
For GUI/contextual feedback, the user-visible state is:
| Event | Ledger state | User credit state | Notes |
|---|---|---|---|
| Eligible feedback submitted | feedback_events.quality_status = pending; positive credit_ledger grant with reason contextual_feedback_pending | Pending DTI, visible but not spendable | Eligibility requires a signed-in account, stable target, normal confidence, no duplicate target grant, and no abuse/rate-limit flag |
| Duplicate, too-fast, low-confidence, spam, or copied feedback | Duplicate/ineligible/rejected/suppressed state | 0 new DTI | The feedback may still be useful operationally, but it does not add spendable credit |
| Outcome recompute or shadow scoring | scored_shadow | Still not spendable | Shadow scoring can inform review, but explicit disposition is required before human DTI becomes spendable |
Admin open_review_task | pending | Stays pending | Used when more human review, replay, or evidence audit is needed |
Admin mark_reviewed | accepted | Pending DTI becomes spendable | Used when feedback is useful but does not require a product/code fix |
Admin mark_fixed | accepted | Pending DTI becomes spendable | Used after a verified product, data, copy, or model fix/deploy |
Admin ignore | rejected | Pending DTI does not become spendable | Already spendable abusive credit can be revoked separately through admin credit controls |
Admin reopen | pending | Moves back to pending | Used when a prior disposition needs another review |
Backfilled GUI source rows follow the same policy, but reconciliation does not
release spendable credit automatically. If a historical projection was missing
its fb_... source row, backfill may recreate the source row and pending grant;
an admin still has to mark the feedback reviewed or fixed before DTI becomes
spendable.
For API/public-intel feedback, the state is:
| Event | Ledger state | Credit or quota effect |
|---|---|---|
| App-key/API feedback submitted | public_intel_feedback_ledger.quality_status = pending | Counts as an attributed app/API quality signal when unsuppressed |
| Useful human-assisted or agent feedback | Pending until reviewed | Can improve app reputation or quota confidence under public-intel policy |
Admin mark_reviewed or mark_fixed | accepted | Improves quality signal; does not create personal human DTI |
Admin ignore | rejected | Does not improve reputation; suppressed/bad automation may reduce quota confidence |
| Missing source projection backfilled | Source row restored as pending | Restores provenance only; no personal DTI is minted |
Human DTI and app/API reputation can share the same credit unit vocabulary, but they are not the same spend scope. Human DTI is dashboard/review/public-Ask credit. API feedback earns app trust and quota confidence unless a future ADR explicitly links it to a verified human account and personal DTI.
App-key responses now expose an app_reputation_dti summary so builders and
admins can see the lifecycle without reading raw ledgers:
| Field | Meaning |
|---|---|
earned | Weighted accepted and unsuppressed eligible app-key feedback. Valid app-key agent feedback currently earns app reputation weight, not personal DTI. |
pending | Eligible app-key feedback awaiting Feedback Ops disposition. |
revoked | Eligible app-key feedback rejected or suppressed by Feedback Ops. |
eligible_agent_events | Agent events that can affect app reputation after approval. |
automation_telemetry_events | Raw automation telemetry. It is visible but zero-weight for earned app reputation until policy changes. |
quota_confidence | Current app quota posture such as starter, earned, baseline, limited, or reviewed project. |
The summary is returned from:
GET /v1/public-intel/api-keys
GET /v1/public-intel/app-attribution
GET /v1/public-intel/admin/app-ops
Builders and agents can inspect the per-feedback lifecycle without admin access:
GET /v1/public-intel/feedback-activity
GET /v1/public-intel/app-feedback-status
feedback-activity uses the signed-in builder account and only returns feedback
for app keys owned by that account. app-feedback-status uses a valid
public-intel app key and only returns that app key's feedback rows. Both surfaces
show accepted, pending, rejected, or suppressed lifecycle state, source/agent
metadata, target IDs, and per-row app reputation DTI effects. They do not return
raw feedback payload internals.
Every summary carries the boundary flags:
{
"credit_class": "app_reputation_dti",
"personal_balance": false,
"api_convertible": false,
"paid_capacity_unlocked": false,
"human_dti_created": false
}
Automation and Review Gates
TradeOS automates intake, scoring, clustering, and audit recording. It does not automatically turn feedback into trading actions, paid infrastructure access, or model/prompt/source changes.
| Workflow area | Automation currently in place | Human or policy gate |
|---|---|---|
| GUI feedback intake | Signed-in contextual feedback writes a durable fb_... event, records provenance, checks dwell time and confidence, dedupes repeated target labels, and creates a pending human_dti grant when eligible. | Pending DTI is visible but not spendable until disposition accepts the feedback. |
| GUI abuse control | Duplicate client event IDs, duplicate account/target/label tuples, per-account velocity limits, too-fast dwell, and low confidence can block or zero-credit feedback. | Support/admin can revoke already-spendable abusive credit separately. |
| Normalized feedback projection | GUI and API feedback can also project into ifb_... intelligence-feedback records for inbox and Feedback Ops clustering. | The projection is not a credit source. Credit state follows the durable fb_... or pifb_... source row. |
| Feedback Ops clustering | Feedback Ops groups related feedback by surface, target, symbol, and correction area; assigns severity, confidence, likely files, recommended actions, ADR drafts, and fix-plan drafts. | Cluster recommendations are review artifacts. They do not mutate product behavior by themselves. |
| Feedback Ops disposition | Admin cluster actions can apply open_review_task, mark_reviewed, mark_fixed, ignore, or reopen across linked source rows and write credit-effect audit records. | mark_reviewed and mark_fixed release pending human DTI; ignore rejects it; open_review_task keeps it pending. |
| API feedback classification | Public-intel feedback is classified as human, human-assisted, agent, automation, hybrid, or unspecified, with separate credit policy and app-reputation treatment. | API feedback does not create personal human DTI by default. Human-linked API credit requires an explicit future policy. |
| API app reputation | Recent attributed, unsuppressed public-intel feedback can refresh public app-key quota; abuse, denials, or suppressed feedback can reduce app reputation. | Production scale, alerts, exports, automation, private context, and data rights require paid capacity, x402, grant, or contract entitlement. |
| Source reconciliation | Reconciliation can restore missing historical fb_... or pifb_... source rows from source-backed projections when enough provenance exists. | Backfill restores pending provenance only. It must not release spendable human DTI automatically. |
The scaled operating model uses the Feedback Ops auto-disposition endpoint to reuse the same disposition path instead of minting credits directly:
source ledgers -> Feedback Ops clusters -> policy decision -> disposition action -> existing credit lifecycle
The current policy is conservative:
| Auto decision | When it is appropriate | Effect |
|---|---|---|
ignore | Duplicate, too-fast, low-confidence, copied, spammy, or abusive feedback. | Rejects or keeps 0-credit feedback out of spendable DTI and app reputation. |
mark_reviewed | Low-risk feedback that is clearly useful, non-duplicate, well-provenanced, and does not require a product/data/model fix. | Releases pending human DTI for GUI feedback; records accepted quality for API feedback without personal DTI. |
open_review_task | Feedback about signal correctness, source grounding, identity risk, missed events, timing, or anything needing replay/outcome validation. | Keeps DTI pending and moves the cluster into review. |
mark_fixed remains a human/admin action because it means a product, data,
copy, or model change was actually verified. The automated path records the
policy version, supports dry-run/apply mode, applies a bounded max_apply, and
uses deterministic idempotency. In alpha, apply mode and the metrics-api
autonomous worker default enabled so eligible queue findings can move through
the credit lifecycle immediately; admins can pause or resume apply mode from
the Feedback Command Center or Feedback Ops, and operators can disable the worker with
FEEDBACK_OPS_AUTO_WORKER_ENABLED=false. Recent autonomous runs are visible to
admins through the Feedback Command Center and Feedback Ops run history, including mode, policy version, bounds,
decision counts, and credit effects. Future hardening should add per-account and
per-app approval caps plus random human sampling.
max_apply limits auto action attempts in a run. Already-handled or
human-required clusters remain visible in run history but do not consume that
budget.
Admin queue semantics are explicit. GET /v1/admin/feedback-ops/findings
defaults to queue=active, which means open or action-required work. Terminal
dispositions such as reviewed, fixed, ignored, approved, rejected, or closed
leave the active queue after success but remain available through history/audit
views. This is queue removal, not source-row deletion.
Current operator and API surfaces:
| Surface | Purpose |
|---|---|
POST /v1/feedback/* | GUI feedback intake that can create pending human DTI. |
GET /v1/dashboard/credits | User-visible available, pending, and spent DTI. |
/developer/feedback | Builder/App Feedback portal for app-key lifecycle and app reputation DTI. |
/admin/feedback | Admin Feedback Command Center for active queues, automation, builder/API ops, and audit history. |
POST /v1/admin/feedback/{event_id}/actions | Direct admin disposition for one GUI feedback event. |
GET /v1/admin/feedback-ops/findings | Clustered operational feedback findings. Defaults to queue=active; supports queue=history and queue=all. |
POST /v1/admin/feedback-ops/findings/{cluster_id}/actions | Manual cluster disposition through Feedback Ops. |
GET /v1/admin/feedback-ops/auto-policy | Admin visibility into autonomous policy version, enable state, bounds, and allowed/protected actions. |
PATCH /v1/admin/feedback-ops/auto-policy | Admin enable/disable and bounded policy-control update for autonomous apply mode. |
GET /v1/admin/feedback-ops/auto-runs | Recent autonomous dry-run/apply summaries for admin observability. |
POST /v1/admin/feedback-ops/auto-disposition | Dry-run or apply conservative policy decisions through the same disposition path. |
| Metrics-api auto worker | Periodically invokes the same auto-disposition runner when FEEDBACK_OPS_AUTO_WORKER_ENABLED is true. |
GET /v1/public-intel/feedback-activity | Builder-owned app-key feedback status and app reputation DTI effects. |
GET /v1/public-intel/app-feedback-status | App-key-authenticated self-check for agent/builder feedback lifecycle. |
POST /v1/admin/feedback/recompute-outcomes | Shadow scoring only; it does not release spendable DTI. |
What Data Intel Credits Can Unlock
Data Intel Credits can unlock temporary scoped public access:
| Cost | Unlock family | Examples |
|---|---|---|
| 3 DTI credits | Light dashboard depth | Faster public refresh, more symbols, 30-day public history, deeper Market Pulse/sector/VPIN evidence, Token Discovery detail, Fusion Lite detail |
| 6 DTI credits | Read-only review depth | Forecast Lab, Bias/Fusion Review, EA Entry Quality, Symbol Story Deep Dive, Token Cycle Review, Digest/Thesis Review |
| 6 DTI credits | Ask extension | 5 extra read-only public-intelligence questions |
Data Intel Credits do not unlock:
- personalized financial advice;
- exchange connectivity, custody, or execution;
- raw exports or bulk API access;
- webhooks, alerts, automation, or x402 resources;
- private forecasts or enterprise datasets;
- Reppo packaging or paid data distribution.
Builder Flow With The Distribution Kit
Builders can use the TradeOS distribution kit to package public intelligence into bots, dashboards, digests, widgets, and research workflows. The public repository mirrors the builder-facing setup, SDK, CLI, MCP, app-key, feedback-provenance, and paid-boundary docs: agenticsrclab/tradeos-public-intel-kit.
Builder feedback should preserve provenance:
{
"target_type": "digest",
"target_id": "digest_123",
"label": "useful",
"client_app": "market-briefing-bot",
"client_version": "0.1.0",
"feedback_source": "human",
"automation_level": "none",
"idempotency_key": "tradeos_public_intel_..."
}
Recommended builder steps:
- Use the public API, SDK, CLI, or MCP server from the distribution kit.
- Preserve stable target IDs for every digest, thesis, evidence card, alert, bot answer, or dashboard widget.
- Submit feedback with
feedback_source,automation_level, client metadata, and an idempotency key. - Use a verified TradeOS account when creating public-intelligence app keys.
- Keep human feedback, human-assisted feedback, agent feedback, and automation feedback distinct.
Agentic and automated feedback can be valuable, but it should not be credited as personal human judgment unless TradeOS validates the source and policy.
Builder API Quota Loop
Builder API quota is related to feedback quality, but it is not the same spend scope as human Data Intel Credits. The unit is common; the API reward is app reputation and quota confidence, not a personal GUI balance. Anonymous public-intel API preview stays small; verified app keys receive the larger starter quota immediately and can refresh it with useful attributed feedback.
| Builder state | Public API treatment | What changes it |
|---|---|---|
| Anonymous preview | Small keyless read/write limits | Create a verified TradeOS account and app key |
| Verified starter key | 7-day starter public quota | Time expires or app reputation changes |
| Baseline key | Conservative public quota | Submit useful attributed feedback, request review, or pay for scale |
| Earned key | Starter-level quota refreshed by recent useful feedback | Keep sending useful, non-suppressed feedback |
| Reviewed project | Higher public quota after manual approval | Submit /v1/public-intel/quota-requests with project and feedback plan |
| Paid/entitled project | Private intelligence products, scale, alerts, automation, exports, or data rights | x402 payment, paid API key, contract, or entitlement |
Agent and automation feedback can improve app reputation when it is honest, targeted, and useful. It does not become personal user credit by default. Bad, copied, spammy, or suppressed automation can reduce app reputation and quota.
The API response exposes the active profile in
access_control.rate_limit_status.quota_profile and the refresh path in
access_control.quota_policy.
Why This Matters
Data Intel Credits let TradeOS learn which evidence is useful, late, thin, confusing, or wrong while giving users a transparent reason to participate. The credit ledger also gives Label Ops a defensible way to separate verified human validation from unverified activity, agent-generated labels, and raw automation.
That distinction is what makes future human-validation datasets more valuable: each label keeps its target, timestamp, source class, account verification state, and quality-review status.