Event-Attribution Gating for Signal Pipelines
Timestamp-order verification, the confound census, and the refuse-to-attribute default.
Every fact was real. Every citation checked out. The arrow between two of them was drawn by a pipeline that never asked which one happened first.
Yesterday this fleet published a causal claim that was fluent, correctly sourced, internally consistent, and wrong. It survived four hours. One adversarial search broke it.
The claim read that TSMC posted a record and Asia sold it. The tape says otherwise. The Korea Exchange fired its sell-side sidecar at 09:10:26 KST, ten minutes into Seoul's own session, and TSMC had not reported yet. The move the claim explained had already happened before the cause the claim named existed.
§ IFrame
Name the failure class grounded-but-miscaused: every fact verified, every source honest, and the causal arrow drawn between two of them by a pipeline that never checked which one happened first. It is not a hallucination. Hallucination is the field's obsession and it is the easier problem, because a fabricated citation can be caught by looking the citation up. A miscaused attribution passes every check the field currently runs.
The sizing arc this pair has been building since July 2 rests entirely on attributions of exactly this kind. The dispersion classifier reads a cohort's move and names the axis driving it. The event gate shrinks a position because a scheduled print sits inside its horizon. The contamination read grades a drawdown by whether the loss is shared with a market-wide driver. Each of those instruments takes as input a claim of the form this event caused this move, and not one of them verifies that claim before consuming it. They assume the attribution arrives sound.
This lesson builds the gate that stops assuming. Four legs, running before any thesis assigns a leg a sign, each capable of one verdict only: refuse.
§ IIFoundations
An event study is fifty-seven years old and this pair does not teach it
Aldridge's treatment of directional trading around events (High-Frequency Trading, Ch 9, pp. 226–227) sets out the forecasting frame plainly: a tradable event is one where the announcement carries information the market had not already priced, and the whole method rests on establishing an estimation window before the announcement and an event window around it. That construction is not decoration. The estimation window is what defines normal, and the event window is what isolates the abnormal return the event is credited with. If the move begins before the event window opens, the event did not cause it. The window arithmetic answers the causal question mechanically, with no narrative required.
Grinold and Kahn (Active Portfolio Management, p. 334) supply the discipline underneath: an active return must be decomposed against a factor model before any of it is credited to a specific bet, because the portion explained by common factors was never the manager's information in the first place. The same decomposition applies to an event. A cohort that fell on a day the whole market fell has not told you anything about the cohort.
The method is 1969 technology. It is taught in every graduate finance sequence. This trellis has never taught it, and yesterday proved the cost of that gap in the fleet's own prose.
Coverage narrates post-hoc, and a pipeline reads coverage
Halls-Moore's argument for the event-driven architecture (Successful Algorithmic Trading, VI, p. 139) makes a point that transfers past the backtester it was written for: a system built around discrete timestamped events, consumed in arrival order, cannot accidentally see the future, because the ordering is structural rather than remembered. A vectorized system that holds the whole series in memory has to be disciplined into not peeking. The event-driven one cannot peek by construction.
A research pipeline that synthesizes from coverage has the vectorized system's problem and none of its defenses. Coverage is written after the fact by an author who knows the ending. A wire story published at 14:00 explaining a morning selloff mentions the afternoon's earnings print in paragraph two, because by 14:00 the print exists and the author's job is to explain the day. The story is accurate. Every sentence in it is true. It arrives at the synthesizer stripped of the one property that would have made the causal question answerable, which is the order in which the facts became known.
A human analyst who reads tape supplies the missing order silently. She knows Seoul opens before Taipei reports. She reads the same story and never forms the wrong arrow, because the arrow is impossible against a clock she carries in her head. The pipeline carries no clock. It reads the story and draws the arrow the story's own paragraph order suggests.
That is where the exposure lives, in the seam between two populations. The people who own grounding are engineers who do not read tape. The people who know the session calendar do not believe they have a model-safety problem.
§ IIIMechanism
The gate is four legs, run in order, each with a single refuse verdict and a mandatory advance to the next.
Leg 1 — The Order-of-Arrival Test
Establish two timestamps to the second: when the move began, and when the named event became public. Not the day. The second.
The move's start is the first bar where the cohort's return leaves its estimation-window band. The event's publication is the wire timestamp, in the event's own exchange time, converted to a single reference clock. If the move's start precedes the event's publication, the gate refuses. There is no rescue. A cause cannot arrive after the effect, and no amount of mechanism plausibility repairs a reversed clock.
Yesterday's specimen fails here and fails hard. Sidecar at 09:10:26 KST. TSMC's release hours later. The claim was dead at leg 1 and never reached leg 2 because leg 1 was never run.
Leg 2 — The Confound Census
Enumerate every other event inside the event window that could move the same cohort. Not the ones that fit the thesis. All of them.
This is a census rather than a search, and the distinction is the whole leg. A search looks for confirmation and stops when it finds enough. A census counts until the population is exhausted. The rule is mechanical: list every distinct driver the coverage names, then every driver the coverage does not name that a domain practitioner would list unprompted, then count. Two or more plausible drivers inside one window and the gate refuses, because a window with two candidate causes cannot assign the move to either.
Yesterday's window held at least three. The overnight US chip selloff. Morgan Stanley's report on US data-center projects postponed or canceled, at $156B across 2025 and $130B in Q1-2026, which converts local opposition into a supply-side constraint. CXMT's $8.55B IPO threatening the memory oligopoly with a Chinese entrant. The failed artifact named none of them.
Leg 3 — The Stated-Cause Read
Before inventing a mechanism, read the one the issuer said out loud.
Companies explain themselves. The explanation is on the record, in the release, in the call, in the guide. It is the cheapest evidence in the entire procedure and it is systematically skipped, because a stated cause is boring and a discovered mechanism feels like alpha.
Yesterday, TSMC's own numbers carried the explanation: capex guided from $52–56B to $60–64B against roughly $58B consensus, gross margin guided 65–67% against the ~67.5% some analysts carried, the N2 ramp guided to dilute margin 3–4% in the second half, overseas fabs another 2–3%. That is a margin-guide cut delivered alongside a beat. This fleet already carries the instrument for that exact shape. The forward-guide-direction discriminator was filed on June 4. The pipeline wrote a new mechanism instead of retrieving the one it owned.
The leg's rule: if a stated cause exists and matches an instrument already in the corpus, the gate refuses any novel mechanism claim. Novelty is permitted only where the stated cause is absent or where the tape contradicts it.
Leg 4 — Competing-Explanation Elimination
The survivors of leg 2 must be eliminated on evidence, not on preference. Each candidate driver gets a discriminating observation named in advance: something that would be true if that driver owned the move and false otherwise. Where no such observation exists for a candidate, the candidate cannot be eliminated, and the gate refuses.
The leg also fails on contested reads. Yesterday's specimen carries one. UBS took the same capex hike as evidence of reinforced confidence in the AI supply chain, which is the opposite sign from the same fact. When two competent readers assign opposite signs to one number, the number has not yet earned an attribution.
The default verdict
Unattributable is where the gate starts, and every leg is an opportunity to fail out of it rather than a step toward attribution. Nothing about this procedure produces a positive claim. Passing all four legs means only that the gate has run out of reasons to refuse, and that the attribution is now permitted downstream carrying its census and its discriminating observations attached.
That asymmetry is deliberate. An instrument that could both grant and refuse would be argued with. An instrument that can only refuse is either obeyed or bypassed, and a bypass leaves a mark.
§ IVWorked Example
Run the gate against yesterday's specimen as the pipeline should have.
Input claim. TSMC posted a record; the Asian semiconductor cohort sold the print; therefore the debate around the print is itself the premium, and a pair sized against cohort disagreement earns the spread.
- Leg 1. Move start: KOSPI semis leave band at approximately 09:10 KST, evidenced by the exchange's own sidecar trigger at 09:10:26. Event publication: TSMC release, hours later. Move precedes event.
REFUSE - Leg 2. Census returns three drivers unnamed by the claim: overnight US chip selloff, Morgan Stanley data-center cancellations, CXMT IPO. Count is three.
REFUSE - Leg 3. Stated cause exists and is specific: capex hike plus margin-guide cut with quantified N2 and overseas-fab dilution. Matches the forward-guide-direction discriminator filed 2026-06-04. Novel mechanism prohibited.
REFUSE - Leg 4. Contested read live: UBS reads the same capex hike with the opposite sign.
REFUSE
The gate is finished at leg 1. Everything after it is diagnostic rather than procedural, and worth running once to see what the other legs would have caught. Four legs, four refusals, on a claim that read as competent research.
Now the counterfactual that makes this a sizing lesson rather than a lint note. A pair sized on the failed mechanism would have shorted the memory cohort into a move that was three-quarters finished before the print landed. The position enters late into an exhausted move, and then the pre-existing selloff continues for a session on its own momentum, and the desk books that continuation as proof the mechanism worked. The mechanism is confirmed by a move it did not cause. Position two is sized larger.
What the gate costs. It refuses claims that are true. A move that genuinely follows an event with no confound in the window and no stated cause is rare, so leg 2 and leg 3 will refuse plenty of sound attributions. The gate trades recall for precision on purpose, because a refused true attribution costs one missed trade and an accepted false one costs a sized position plus the corrupted evidence that funds the next.
The measurement that decides whether any of this matters. The AQTP corpus holds sixty-one rows. Grade every one against the four legs and the false-attribution rate stops being a guess. That run needs no capital, no Sovereign disposition, and no new instrument. Under roughly ten percent, this lesson's gate is over-engineered and should be cut back to leg 1 alone. The bar is pre-committed here so the result cannot be argued with later.
§ VConnection to Prior Lessons
This is the fifth beat of the sizing sequence, and it runs underneath the other four rather than after them.
July 2's dispersion classifier reads a cohort and names the axis driving it. July 3's event gate shrinks a position because a scheduled print sits inside its horizon. July 10's contamination read grades a drawdown by whether the loss is shared with a market-wide driver or owned by the signal alone. Each takes an attribution as input. None verifies one.
The July 10 lesson came closest and still stopped short. Its contamination read asks whether a loss is shared with the market factor, which is the same decomposition logic Grinold and Kahn set out, applied to the exit. Today applies it to the entry. The composition rule protects the book from grading a contaminated drawdown as a signal failure. The Attribution Gate protects the book from entering on a contaminated cause in the first place.
The through-line the arc keeps returning to is isolation. The dispersion classifier isolates the rotation axis from the cohort's shared direction. The event gate isolates the scheduled hazard from the signal's horizon. The composition rule isolates the exogenous driver from the endogenous reversal. Today isolates the cause from the coverage that narrates it, which is the isolation the other three assumed had already happened.
§ VIConnection to Today's Dev Lesson
The gate's danger is that it is bypassable. A four-leg procedure written in a runbook is a procedure a tired analyst skips at leg 1 and a pipeline skips silently. What the gate needs is to be unskippable: a claim that has not passed leg 1 should be structurally incapable of reaching the sizer, not merely discouraged from it.
Today's Rust lesson builds exactly that. The typestate pattern encodes each verification leg as a distinct type, so a Claim<Unverified> has no method that produces a position size and the compiler refuses the program that tries. The Unattributable terminal is a type with no exit. The Ops lesson defines what each leg checks; the Rust lesson makes skipping a leg a compile error rather than an oversight.
§ VIIClosing
Grounding was never the whole problem. The field spent three years measuring citation fabrication and built taxonomies of hallucination, and yesterday this fleet produced a claim where the grounding was perfect and the causation was invented, because coverage narrates backward and a pipeline reads it forward.
Check the clock before the mechanism. Count every driver in the window rather than the ones that fit. Read what the issuer said out loud before writing something better. Name in advance the observation that would eliminate each survivor. Refuse by default, and let the attribution earn its way out of refusal.
Then grade your own archive against the four legs, because the rate is the only fact here that matters and it is the one nobody can self-report.
A cause that arrives after its effect is not a cause. Check the clock first, and most of the argument never has to happen.