StopWarden is not open yet. Nothing here can be downloaded or bought today; these pages describe how StopWarden is planned to work when it opens. Get one email when it opens.
Safety: exactly what StopWarden will do to your account
This page lists every automatic action StopWarden can take, when it takes it, and what it will never do. Read it before you use StopWarden on a real or prop account.
"The account" below means the one account in targets[0].account. "The log" means NinjaTrader's own trace log (<Documents>\NinjaTrader 8\log\). StopWarden reads positions, orders, connections and strategy starts/stops from it.
You remain responsible for your account. StopWarden detects problems, alerts you, and in Protect mode attempts the actions below and confirms them from the log. It does not guarantee that any action succeeds in time.
Watch is the default. Protect is opt-in.
Every install starts in Watch mode ("mode": "watch"). In Watch, StopWarden reads NinjaTrader's log and alerts you. It does not launch or sign in to NinjaTrader, enable or re-enable your strategy, disable it at end of day, flatten positions, or cancel orders, and the order-guard AddOn is switched off. In Watch, StopWarden never sends an order on its own. It alerts. Its alerts say what Protect would have done.
In Watch, nothing acts on your account unless you type a command. The first is the kill switch, autopilot stop (or the STOP file), and it does nothing else. It disables the strategy: no cancel, no flatten, no enable. If a position is open, autopilot stop refuses unless you add --flatten or --leave-open (section 6), because disabling cancels the strategy's stop. That consent is the same every time a disable is asked for with a position open.
Two more commands act on your account, and they are your own commands too: you type them, StopWarden never runs them for you and never runs them in Watch by itself.
autopilot disabledisables the strategy. With a position open it asks for the same consent asautopilot stop: add--flattento close the configured account's position as well, or--leave-opento say you will manage it by hand. With neither it refuses, clicks nothing in NinjaTrader and sends no order.autopilot flatten --yescloses the configured account's position (account scope). Without--yesit only prints what it would close.
autopilot stop --flatten and autopilot disable --flatten close the configured account's position and cancel the working orders StopWarden has seen on that account (account scope, section 6). They send NinjaTrader's global cancel-all only if you set cancel_scope to "global" and Protect's gate is open (see "How cancelling works" under Known limits).
Protect is opt-in, and it acts only when all of these hold (the "Protect gate"):
"mode": "protect"inautopilot.json;- an active paid licence (
autopilot license activate); - an accepted Learn report for the configured strategy and account (see "The Learn report" below). The engine refuses to save
mode: "protect"without one; - the account is an algo account (
protection.account_modeis not"manual-allowed"), and the report does not show two instruments held at once on it; - the watchdog is switched on (
watchdog.enabledis not false). With the watchdog off nothing reads that file, so the gate reads as closed andstate\tier.jsonsays so. With the gate closed the supervisor only alerts: it does not enable, re-enable, recover, flatten or cancel.
The supervisor checks this gate before every action it takes: enabling and re-enabling, the end-of-day flatten and cancel, the kill-switch flatten, recovery, and switching the order guard on. It writes the answer to state\tier.json every ~15 seconds, and the watchdog flattens only when that file says yes, is less than 15 minutes old, the supervisor is still running and no STOP file is set. So a file edited by hand to "protect" without an accepted report stays alert-only, and so does a watchdog you start on its own (autopilot watchdog without the supervisor). While the gate is closed, Protect alerts after the wait with no working stop and never flattens; autopilot doctor shows why on its Protect gate line.
Sections 1 to 7 below describe what Protect does. Try Protect on Sim101 before any real or prop account.
The Learn report (in Watch)
Protect cannot act for a strategy until StopWarden has measured how that strategy handles its stops. autopilot learn reads NinjaTrader's log for the last 30 days (read-only) and reports, for the configured strategy and account: how long its stop normally takes to be in place after a position opens or changes, how often it moves the stop, how far the stop sits from the entry, whether it looks like an ATM strategy or uses stops NinjaTrader simulates on your PC, and how many times Protect would have acted with its wait. The wait is fixed, so Protect turns on only for a strategy whose stop is normally working well inside the wait. The report also adds up how long the stop was missing within any one minute of normal trading, counted the way the watchdog counts it, and that total must stay well inside the wait too (a strategy that cancels and re-places its stop many times a minute can fail this check with every single gap short). A strategy whose stops sit in Trigger pending (NinjaTrader holds them on your PC) is counted as protected only while the connection named in nt8.connections is seen up in the log. If the report counted such stops but that name never appears in NinjaTrader's log, StopWarden would treat those stops as no stop at all: the report says so and Protect stays closed until nt8.connections matches the name NinjaTrader writes. A slower strategy is classified SLOW. That way Protect does not close a trade your strategy was about to protect.
The report is complete after protection.learn.min_trades round trips over min_sessions sessions (20 and 5 by default). autopilot learn --accept records it. It refuses an incomplete report, and a strategy the report classifies as STOPLESS (exits without a resting stop), UNSTABLE (its slowest 1% of stop placements take longer than the wait), ATM, SLOW (strategies whose own stop is not reliably working well inside the wait, or is missing for too long in total within a minute), or one that held two instruments at once on the account: those stay Watch-only in this version. A later report that shows one of those takes the acceptance back.
The wait is fixed. It is not a setting you can raise. An older config file with a higher watchdog.naked_seconds is read as the fixed wait, with one warning in the log, and StopWarden still starts. A lower value is refused.
Summary
All rows are Protect mode with the Protect gate open (see above). In Watch mode, or while the gate is closed, only the kill switch runs, and it only disables (see above).
| Action | When | What it sends to NinjaTrader | Affects |
|---|---|---|---|
| Launch + sign in | launch_at to disable_at on trading days, when NinjaTrader is closed or at the login screen | Starts NinjaTrader.exe, types or clicks your login | NinjaTrader |
| Connect / reconnect | Same window, when a configured connection isn't connected (or the optional heartbeat goes stale) | Clicks the connection in the Connections menu | NinjaTrader |
| Enable | enable_at to disable_at, when the strategy is off | Clicks the enable box on your one Strategies-tab row | The account |
| Watchdog flatten | Any time the supervisor is running, when a position is uncovered for longer than the wait (see section 3) | CLOSEPOSITION for the account + instrument; screen-click fallback | The account only |
| Orphan-order cancel (AddOn) | Any time NinjaTrader is running with the AddOn compiled and the supervisor has switched it on | Cancels working orders, except a protective stop on a position the account still holds | The account only |
| End of day | Once, at disable_at | Disable click; then (if flatten_on_disable) CLOSEPOSITION + one CANCEL per working order seen on the account | The account only (default cancel_scope: "account") |
| Kill switch | When STOP appears (autopilot stop or the file) | Disable click; then (if flatten_on_disable, or with --flatten) CLOSEPOSITION + one CANCEL per working order seen on the account | The account only (default cancel_scope: "account") |
| Balance floor | Every 5 min in the trading window, if enabled | Sets STOP, disables, and always sends CLOSEPOSITION + one CANCEL per working order seen on the account (whatever flatten_on_disable says) | The account only (default cancel_scope: "account") |
CANCELALLORDERS (NinjaTrader's global cancel-all, which hits every account) is sent only if you set cancel_scope: "global", never in Watch mode, and never while another account has been seen with working orders. See "How cancelling works" under Known limits.
1. Enable
StopWarden enables your strategy only when all of these are true:
- It is a trading day (in
schedule.days, not inschedule.holidays) and the time is betweenenable_atanddisable_at. - There is no kill switch (
STOPfile). This is checked twice: before starting, and again right before the click. The click script checks it a third time. - The account is flat according to the log. If it isn't, StopWarden alerts once (
... is OFF and <account> holds a position ... NOT enabling until flat) and waits. - No configured connection name contains a rejected feed type (
Simulated,Playbackby default). - The watchdog is running and wrote its heartbeat in the last 30 seconds (unless
watchdog.enabledis false). - Today isn't blocked (a configuration problem was found) or capped (too many recovery attempts).
- The Windows desktop is unlocked, NinjaTrader is signed in, and every configured connection shows
Connected. - NinjaTrader's
Config.xmlhas Cancel entry orders and Cancel exit orders when a strategy is disabled both on. Otherwise the result isHYGIENE_OFF. - Exactly one Strategies-tab row has a cell equal to the account and a strategy cell equal to the strategy name. Otherwise the result is
NOTFOUNDorAMBIGUOUS.
Then it clicks the row's enable box and OKs NinjaTrader's "Order Confirmation" box if one appears. It checks that the box reads ON, waits 75 seconds, and reports ENABLED only if the log shows the strategy starting after the click, with no later "Disabling" line, and the box is still ON. Otherwise the result is DIED_AT_STARTUP.
If the strategy is already on, StopWarden never clicks it (ALREADY_ON).
The same rules apply to autopilot enable. Its --no-watchdog flag skips only rule 5.
2. Recovery (relaunch, sign-in, reconnect, re-enable)
Recovery runs only between launch_at and disable_at on trading days. Outside that window StopWarden never starts NinjaTrader.
| Problem | Action |
|---|---|
| NinjaTrader not running, or sitting at the login screen | Launch and sign in |
A configured connection isn't Connected | Click it in the Connections menu |
| Strategy dropped to OFF during the trading window | Guarded enable (section 1) |
Optional strategy heartbeat older than heartbeat_stale_minutes | Disconnect and reconnect the configured connections. If a position is open, it does not force the disconnect through NinjaTrader's "active orders" warning. |
Caps. The normal morning start is free. After that, every failed step, and every recovery needed after the strategy was already running today, counts as one attempt.
- After
max_consecutive(default 3) failures in a row, it waitsbackoff_minutes(default 30), then tries once per backoff window. - At
max_attempts_per_day(default 6) it is capped. It alerts, stops trying for the rest of the day, and never re-enables. If the strategy is on and flat, it disables it. If a position is open, it leaves the strategy alone (the watchdog keeps covering) and tells you hands are needed. - If the watchdog closed a position with no working stop and the strategy then went off, turning it back on within 10 minutes is not an attempt. This is free at most 3 times a day. The fourth time, the day is capped and the alert says why: a strategy whose positions keep losing their stop needs a look first.
Blocks. Some problems can't be fixed by retrying: a rejected login, no stored login, NinjaTrader not found, an unknown connection name, cancel-on-disable off, the strategy row missing or duplicated, or a rejected feed type. These block for the rest of the day with one CRITICAL alert that says what to fix. A rejected login is also latched: StopWarden will not type the password again until you store it again. This stops a login loop from locking your NinjaTrader account.
A refusal because the account isn't flat, or because of the kill switch, doesn't use up an attempt.
autopilot resume removes the kill switch and resets today's caps, blocks and back-off. A running supervisor picks it up on its next tick (within ~15 s). No restart needed.
3. Watchdog flatten (naked position)
The watchdog runs all the time while StopWarden runs: every day, in and out of your schedule, whether the strategy is on or off. It looks only at the configured account, and judges each instrument on it separately. It can flatten only while the Protect gate is open and the supervisor is running (see the top of this page); otherwise every step below is an alert, not an action.
Rule. A position is covered when stop orders add up to at least the position size. Each stop order must be:
- a
Stop MarketorStop Limitorder (or a name prefix you listed inextra_stop_name_prefixes, each at least two characters; a profit target never becomes cover by its name: aLimitorMarket-if-touchedorder priced at or beyond your average entry price, on the profit side, is a target whatever it is called); - on the closing side: Sell for a long, Buy or Buy to cover for a short;
- on the same instrument;
- in a state that counts as cover (the time limits are in Configuration,
protection):
| Order state | Counts as cover |
|---|---|
Working, Accepted | Yes |
ChangePending, ChangeSubmitted (the stop is being moved) | For up to transition_max_s |
Submitted, Initialized (just sent) | For up to arriving_max_s. If it is then rejected, the credit is taken back. |
TriggerPending (NinjaTrader simulates the stop on your PC) | Only while the configured connection is up, with a warning |
CancelPending, CancelSubmitted | Only while an exit for the whole position is working |
Partially filled | No: it has already gone to market |
The time limits are measured from the start of the state, and a second state does not buy a second credit. A stop just sent counts from the moment it was sent, however many states it passes through before NinjaTrader accepts it. A stop being moved counts from the first change since it was last Working, so a change that stays unconfirmed is not renewed by each new line. A stop that is confirmed Working between changes starts a fresh credit with the next change. The three limits (transition_max_s, arriving_max_s, exit_settle_s) cannot be set above their built-in values: the settings check refuses a larger value, because a longer credit would hold off the close beyond the wait the Learn report was measured against.
A closing Market order for the whole position also counts for up to exit_settle_s: your strategy is exiting. Profit targets never count. Only the unfilled quantity counts. A stop far from the entry (far_factor × the max loss) still counts, and you get a warning with the dollars at risk.
The watchdog acts when the position has been under-covered for the limit without a break, or for that many seconds in total within any 60 seconds (a stop that keeps disappearing and coming back). The limit is the fixed wait (watchdog.naked_seconds). protection.naked_budget_s sets the in-total limit, which cannot be lower than the wait. With the gate closed the watchdog alerts at the same point and does not act. When it acts, the watchdog:
- Writes an ATI
CLOSEPOSITIONfor the account + instrument. According to NinjaTrader, this also cancels that instrument's working orders on the account. - If ATI doesn't pick up the file within 4 seconds, it deletes the file (so it can't fire hours later when ATI is turned on) and uses the screen-click fallback: Positions tab > right-click > Close Position.
- If the position still isn't clear after about 10 seconds, it uses the screen-click fallback.
- It sends a CRITICAL alert either way.
If the position is still naked, it tries again after another wait: 3 attempts in all per episode. Then it alerts hands needed now and stops trying for that episode.
With watchdog.flatten: false it only alerts. It never flattens.
The instrument comes from NinjaTrader's own position line. If NinjaTrader hasn't logged one yet, it uses targets[0].instrument. If neither is known, it skips ATI and goes straight to the screen-click fallback.
4. Orphan-order cancel (the AddOn)
The AddOn runs inside NinjaTrader, every 2 seconds, for every account matching account_regex in C:\ProgramData\StopWarden\orderkill.json. Each time the supervisor starts, it sets that to exactly your configured account (^<account>$). It switches the guard on only while the Protect gate is open; in Watch mode, or with the gate closed, it switches it off.
Rule. If no strategy on the account is running (Configure, DataLoaded, Historical, Transition, Realtime or Active state) and the account has working orders for longer than a short grace period (grace_sec), the AddOn cancels them, except a protective stop on a position the account still holds: a closing-side Stop Market / Stop Limit on that instrument, up to the position size (and any order linked to it by OCO, so cancelling one leg cannot take the stop with it). On a flat account nothing is spared. It doesn't look at order names. It writes a CRITICAL line that StopWarden forwards to your phone. If it can't read the strategy states, the positions or the connection, it does nothing for that sweep.
It stays switched on for your account after StopWarden's end of day and overnight. Stopping StopWarden doesn't turn it off either.
Manual orders will be cancelled. On the configured account, an order you place by hand while no strategy is
running looks exactly like an orphan. It is cancelled after the grace period.
5. End of day
At disable_at, once per day:
- Disable the strategy (screen click). If that fails, it retries on the next two 15-second ticks.
- If
flatten_on_disableis true (the default): sendCLOSEPOSITIONon the configured account if the log still shows a position, then one ATICANCELfor each working order the log still shows on that account (see "How cancelling works" below). - Re-read the log. If every configured account is flat and the disable worked, it sends the INFO end-of-day alert. Otherwise it sends a CRITICAL
END OF DAY PROBLEM.
If the disable still fails after three tries (for example, the desktop is locked), step 2 still runs. The strategy may still be enabled. A CRITICAL alert names the problem. Disable it by hand.
If NinjaTrader isn't running at end of day, StopWarden can't disable, cancel or confirm flat. If anything ran that day, it sends CRITICAL CHECK YOUR BROKER NOW with the last position it saw. See "A dead platform is not a flat account" below.
If StopWarden starts more than 30 minutes after disable_at and nothing was enabled that day, it skips the end of day and leaves whatever you are doing alone.
NinjaTrader stays open after the end of day. StopWarden never closes it.
6. Kill switch
Set it with autopilot stop [--reason "..."], or create an empty file named STOP in C:\ProgramData\StopWarden\state\.
Once, when it appears, StopWarden:
- Disables the strategy (if NinjaTrader is running).
- In Protect mode with the Protect gate open, if
flatten_on_disableis true: closes the configured account's position, then cancels each working order it has seen on that account.autopilot stop --flattenasks for this step even whenflatten_on_disableis false, and also in Watch mode or with the gate closed. Without--flatten, Watch mode (and a closed gate) skips this step: it disables only. - Sends a CRITICAL alert.
NinjaTrader's cancel-on-disable (which StopWarden requires) cancels the strategy's stop the moment the strategy is disabled. So when a stop that would not close the position (Watch, or Protect with flatten_on_disable: false) finds a position open, autopilot stop is refused and changes nothing: it tells you to run autopilot stop --flatten (close it) or autopilot stop --leave-open (you will manage it by hand; you get a CRITICAL alert naming the position). A STOP file you create by hand is never refused (you asked for it), but if it leaves a position without a stop you get UNPROTECTED under STOP: ... at once and again every 5 minutes until the account is flat.
After that, it never enables anything and does no recovery, on any day, until you run autopilot resume. While the kill switch is set, the watchdog only alerts: it never flattens under a STOP, so a naked position left after the kill switch is yours to close (step 2, or autopilot stop --flatten, does it for you). The order-guard AddOn keeps cancelling orphan orders on the account if it was switched on.
autopilot disable follows the same rule: a disable cancels the strategy's stop too. With a position open and nothing that would close it, it is refused the same way (--flatten or --leave-open), sends nothing and clicks nothing in NinjaTrader. With --leave-open you get the same CRITICAL alert naming the position, and the position is left open, even in Protect with the gate open (if you give --flatten as well, --flatten wins). In Protect mode with the gate open and flatten_on_disable true, autopilot disable closes the position as autopilot stop does, unless you gave --leave-open. If a close is sent but the position is still there afterwards, autopilot disable exits 1 and sends a CRITICAL alert. autopilot flatten --yes is a separate command you type to close the position now; it needs no consent beyond --yes.
A STOP file you create by hand takes effect on the next supervisor tick (within about 15 seconds). autopilot stop acts at once, and the supervisor may run the same disable/cancel/flatten again on its next tick. That is harmless, but you may get two alerts.
7. Balance floor (optional, off by default)
With balance_floor.enabled: true, every 5 minutes during the trading window StopWarden reads the account's Net liquidation (or Cash value) from the Control Center's Accounts grid. If it is below floor, StopWarden:
- Writes the
STOPkill switch. - Disables the strategy.
- Always closes the configured account's position and cancels each working order it has seen on that account. This is the emergency path, so it ignores
flatten_on_disable. - Sends a CRITICAL alert.
Limits: it only checks every 5 minutes. It only runs between launch_at and disable_at, with the desktop unlocked and NinjaTrader connected. It reads the screen, not the broker, so it isn't a trailing-drawdown model. Set the floor a little above your firm's liquidation level.
What StopWarden will never do
- Open a position or place an entry order. Its only order instructions close positions or cancel orders.
- Enable a strategy while the account holds a position, while
STOPexists, or after today's cap or block. - Clear the kill switch by itself. Only
autopilot resumedoes that. - Look at, flatten, or guard any account other than the one in your config. The one exception is NinjaTrader's global
CANCELALLORDERS, which is sent only if you setcancel_scope: "global"(see below). - Cancel or flatten anything in Watch mode, or in Protect mode before a Learn report for your strategy and account is accepted, unless you run
autopilot stop --flatten(account scope only). - Create, edit or re-parameterise strategies, or enable a row other than the one matching your strategy and account.
- Change NinjaTrader options. It only reads
Config.xml. - Close NinjaTrader.
- Write, print or send your passwords or tokens anywhere. They are read from Windows Credential Manager only when needed.
Invariants (built into the code)
- Never enable while the account is not flat per the log.
- Never enable while
STOPexists. - Watchdog flatten fires only on under-coverage that lasts (the limit without a break, or the same total within 60 s), only on configured accounts, and only while the Protect gate is open and the supervisor is running.
- A stop counts as protection only on the closing side, by its unfilled quantity, and only in the states listed in section 3 (states in flight count for a few seconds at most).
- Nothing acts in Watch mode, or in Protect mode before a Learn report for this strategy and account is accepted.
- Recovery is capped per day. When the cap is hit: alert, stop trying, leave the strategy off.
- Every screen-automation step has a hard timeout (
recovery.ui_timeout_seconds, default 240 s) and is killed on overrun, so the supervisor never hangs. - Credentials come only from Windows Credential Manager and are never logged.
Known limits
How cancelling works
End of day, the kill switch, the balance floor and the enable-undo (when an enable is undone because a setting was wrong) all use the same steps. With the default cancel_scope: "account":
CLOSEPOSITIONfor the configured account's instrument, if the log shows a position. According to NinjaTrader, this also cancels that instrument's working orders on that account.- One ATI
CANCELfor each working order the log still shows on the configured account, by NinjaTrader's order id. The close goes first, so a protective stop is not cancelled ahead of the position it protects. - Each cancel is read back from the log. If NinjaTrader rejects one or doesn't pick it up, you get a CRITICAL alert naming the order. Check the Orders tab yourself.
Other accounts in the same NinjaTrader are not touched. Limits you should know:
- Only orders StopWarden has seen in the log. An order placed before StopWarden started (or before the log lines it reads) may not be known to it, and the account-scoped path won't cancel it. In particular, orders NinjaTrader restored from the broker before its log started are not visible to this sweep. The order-guard AddOn (section 4) is the backstop for those: it cancels working orders on the account when no strategy is running. Check the Orders tab after any CRITICAL.
- Cancelling depends on NinjaTrader accepting it. Every account-scoped cancel above sends ATI
CANCELwith an order id, including for an order StopWarden didn't place itself. If NinjaTrader refuses it, the cancel is reported as a CRITICAL and the order-guard AddOn is the backstop.
cancel_scope: "global" also sends NinjaTrader's ATI CANCELALLORDERS first, which cancels working orders on every account connected in NinjaTrader, not only yours. StopWarden refuses to send it (WARN alert, then account scope as above) whenever it has seen working orders on another account, and never sends it in Watch mode. Leave the default unless you have a reason; if you keep other accounts in the same NinjaTrader, the default is the safe choice.
The watchdog and autopilot flatten use CLOSEPOSITION for the configured account and instrument only, whatever cancel_scope says.
The log doesn't say which account a strategy started on
NinjaTrader logs "Enabling NinjaScript strategy 'Name/…'" with no account. StopWarden's log view knows only whether a strategy with that name is running. If the same strategy runs on two accounts in one NinjaTrader, StopWarden can think yours is on when it isn't, or the other way round. Every 5 minutes it checks your exact row on screen, which limits the damage. Don't run the same strategy name on another account while StopWarden manages one.
One instrument per account
The watchdog judges each instrument on the account separately and alerts on any naked one. Protect, though, stays off for an account where the Learn report saw two instruments held at once (a Watch-only case in this version). Trade one instrument on the configured account.
Screen automation needs a real, unlocked desktop
Sign-in, connect, enable, disable, the balance read and the flatten fallback all click NinjaTrader's windows. They don't work when:
- the screen is locked;
- the PC is asleep;
- a Remote Desktop session is disconnected (sign-in refuses to type into one);
- StopWarden runs as a service (session 0).
While the desktop is locked, StopWarden sends one WARN alert and pauses those actions. In Protect mode the watchdog still flattens through ATI, which doesn't need the screen. The end-of-day disable can't click (see section 5).
Google sign-in and VPS
login.method: google clicks a saved Google account. Google often blocks sign-ins from data-center/VPS IP addresses. On a VPS, use credential or none.
A dead platform is not a flat account
If NinjaTrader is closed or has crashed, orders already at the broker keep working and can fill with no strategy attached. The watchdog reads NinjaTrader's log, and ATI runs inside NinjaTrader, so neither can act while NinjaTrader is down. During the trading window, StopWarden relaunches NinjaTrader. At end of day it warns you loudly. Outside the window it doesn't relaunch. Your broker's own tools are the only check that works when the platform is down.
Other limits
- Schedules are one daytime window per day. Overnight and 24-hour sessions aren't supported in v1.
- Holidays and early closes aren't automatic. Add holidays to
schedule.holidays. There is onedisable_atfor all days. - The balance floor checks every 5 minutes and reads the screen, so a fast move can go past the floor before it acts.
- If the PC, Windows, the internet or power fails, StopWarden fails with it.
Belt and braces (recommended)
StopWarden is a backstop. Keep these layers too:
- Your strategy's own stop loss on every entry. The watchdog waits a short while before it acts. Your strategy's stop protects you from the first tick.
- Broker-side or firm-side daily loss limits, where your broker or prop firm offers them. They work even when your PC, NinjaTrader and StopWarden are all down.
- Alerts on your phone, with notifications on. Test them with
autopilot test-alert. - Use a strategy that replaces its stop well inside the wait, so your strategy gets the first chance to replace a stop. The Learn report checks this: a strategy whose stop is not reliably working well inside the wait, or is missing for too long in total within a minute, stays Watch-only.
- Don't trade the configured account by hand while StopWarden runs (sections 3 and 4).
- Test every change on Sim101 first: new strategy version, new NinjaTrader version, new StopWarden version, new PC.