---
name: oracle-action-semantics
description: Use for watch, ping, prepare, arm, sign, send, execution-capability, or trade lifecycle status and evidence questions.
---

# Oracle action semantics

Keep these planes distinct:

1. **Public prepare plane**: reads, quotes, simulates, and prepares unsigned artifacts. Signing and broadcast happen through the wallet, `oracle signer`, or a verified execution lane.
2. **Generic Oracle signer**: the documented unattended daemon exposes built-in public surfaces: `evm`, `evm-swap`, `evm-bridge`, `evm-nft`, `evm-order`, `btc`, `sol`, `hl`, `poly`, and `lighter`. Bounded is not generic chain authority: each surface decodes and validates its envelope shape and refuses while allowlists, local keys, RPC URLs, simulation, signed-byte verification, receipt binding, or ledger accounting are missing. Enablement is never authority; every signature still needs one exact owner-confirmed grant.
3. **User-wallet execution**: ordinary preparations can still be signed by the user's wallet instead of the local signer.
4. **Optional extra execution**: a deployment may expose a separate same-host, owner-gated executor such as MAD. Verify its status and policy before saying it is available. Never infer extra `hl`/`poly` authority from the public package or the generic signer.

Do not turn a deployment fact into a universal claim. If no bounded EVM executor is installed or healthy, say the current deployment cannot execute EVM. Do not say Oracle can never execute EVM.

## Binding vocabulary

- `watch`, `watch this`, `ping`, `ping me`, `alert`, and `notify` mean notification only.
- Persist them as `active: true` and `actionMode: alert_only`.
- `arm` means authorization intent for one exact bounded action.
- Persist it as `active: true` and `actionMode: execute` only after the exact action and owner authorization are present.
- Never convert `watch` into execution.
- Never convert `arm` into a watch.
- A status field such as `armed` is not action authority. Current records require explicit `active` and `actionMode` fields.

Before accepting `arm`, require the exact chain, token pair, amount or fraction, trigger, recipient, router, deadline, slippage bound, and approval bound. Require the owner-gated executor to be healthy and disarmed until that exact action is authorized. Refuse global, implied, or reusable authorization.

## Execution states

Report each state separately:

- `executionReady`
- `requiresUserSignature`
- `signingReady`
- `broadcastReady`

A quote is not a preparation. A preparation is not a signature. A signature is not a broadcast. A broadcast is not mined execution. Claim success only after a transaction hash, successful receipt. Report balance delta only when `balanceDeltaVerified` is true.

Lifecycle status is evidence-only. `NONE` means no lifecycle record is evidenced. A request, instruction, or complete set of fields alone remains `NONE`; never infer `INTENT`. `INTENT` requires an explicitly created, recorded `trade_lifecycle` event. Planned next work never advances current state. Report only the highest state backed by an actual event, artifact, external signature, transaction hash, successful receipt, verified balance delta, or verified position.

ERC-20 approval is a separate transaction. Use an exact bounded amount unless the user explicitly authorizes another cap. Never silently create an unlimited approval.
