Portfolio margin evaluates a defined account as a set of interacting exposures. A useful implementation connects scenario losses, usable collateral, executable liquidity and enforceable settlement rights. This guide explains how to design those connections, calculate an illustrative requirement and validate the transaction paths that can change risk. The architecture and numbers are illustrative, not specifications of a deployed FT system.
Start with the risk perimeter
A portfolio margin engine answers a precise question: how much eligible equity should an account retain to support a particular combination of positions through an adverse market move and an orderly closeout? It can recognize offsets between exposures, but an offset is useful only when the corresponding assets, obligations and settlement rights remain available during stress.
For an onchain prime brokerage architecture, the difficult work starts before choosing a risk formula. Define which contracts can debit the account, which balances are pledged, which positions can be closed together and which entity controls the settlement path. Two economically opposing positions held in unrelated accounts are not automatically one collateralized portfolio. A profitable hedge on another venue may be inaccessible when the losing position needs payment.
Document this perimeter as an account graph. Each edge should identify an enforceable movement of value, its latency, its permissions and its failure condition. A bridge message, a custodian instruction and an atomic contract call have different settlement properties. Treating them as equivalent silently imports credit and operational assumptions into the margin model.
Flying Tulip Inc engineers software for these workflows. This resource describes design choices for institutions building their own products; it does not describe FT Inc providing brokerage, custody or credit.
Separate portfolio margin, cross-collateral and account equity
Portfolio margin is a method for calculating risk across positions. Cross-collateral is a policy for accepting multiple assets as support for obligations. The two can operate together, but neither implies the other. A cash-only account can use portfolio margin. An account with several collateral assets can still apply independent position requirements.
Keep three quantities explicit. Market equity is marked assets plus unrealized profit and loss, less debt, accrued funding and fees. Eligible equity adjusts that amount for collateral rules, encumbrances and any restrictions on recognizing gains. Required margin is the amount the risk model demands for the remaining portfolio. Available capacity follows from comparing eligible equity with the relevant requirement, after reservations.
Initial margin governs entry into additional exposure and withdrawals. Maintenance margin defines the boundary at which the closeout process becomes eligible to act. The difference gives the system room to respond; it does not guarantee that a gap, outage or failed auction cannot cross both thresholds at once.
As one public reference, Deribit's portfolio margin documentation describes testing combined positions under market scenarios. Its worst tested scenario is not a mathematical limit on possible losses. A design review should preserve that distinction rather than presenting the model's output as a maximum loss guarantee.
Build one canonical account state
The calculation should begin from a reproducible snapshot: collateral balances, debt principal and accrual indexes, positions and contract multipliers, pending orders, pending settlements, price observations and the active parameter version. Every quantity needs a unit. A token balance in base units, a dollar price with eight decimals and a perpetual position denominated in contracts cannot safely share an untyped arithmetic path.
Specify how realized and unrealized profit enter the ledger. If a settlement transfers derivative profit into collateral, remove the corresponding unsettled receivable in the same transition. Otherwise the account can receive credit twice. Apply the same discipline to borrowed assets, reserved withdrawals and collateral temporarily committed to an auction.
Use the account ledger as the source of ownership and obligations. An indexer can assemble views and run simulations, but its view may lag a confirmed transaction or include a reorganized block. A transaction that releases value must validate against the authoritative execution state.
A practical interface returns the evaluated account version, price timestamps, model version, eligible equity, initial requirement, maintenance requirement and rejection reasons. This gives a client application enough information to explain a failed withdrawal without reimplementing the model in JavaScript. Persisting this evidence also makes a disputed risk decision reproducible.
Use scenarios that represent the actual portfolio
For each scenario, revalue the portfolio under a joint change in risk factors. Linear positions need price and basis changes; options add volatility, time and nonlinear payoff behavior. Collateral can lose value in the same scenario that makes the trading book unprofitable. A stablecoin liability can become more expensive to repay when the collateral falls against that currency.
One illustrative construction is:
scenario loss = current portfolio equity - scenario portfolio equity
base requirement = maximum positive loss across tested scenarios
initial requirement = base requirement + documented additional chargesThe additional charges could cover closeout costs, concentrated exposure or uncertainty outside the scenario representation. Each charge needs a clear purpose. If the scenario already includes a stressed collateral discount and full unwind cost, adding identical haircuts and liquidation allowances can double count the same risk. Conversely, a simple price shock does not automatically include those costs.
Test common moves, divergence between related markets, funding accumulation, peg breaks, delayed redemption and failed settlement. A historical correlation estimate can inform calibration, but it should not grant unconditional credit to a hedge. A basis position can be nearly delta neutral while remaining exposed to divergent venue prices and inaccessible settlement proceeds.
Separate the engine from its calibration. Reviewers should be able to inspect the scenario set and additional charges without reading every contract branch. Historical replay informs parameter choices; it does not prove that future stress fits inside the selected envelope.
A worked example: net delta hides basis risk
Consider an illustrative account holding $200,000 of cash collateral, a long linear perpetual position equivalent to 10 BTC and a short linear perpetual position equivalent to 8 BTC in a different market. Both enter at $50,000 per BTC with zero initial unrealized profit. Gross notional is $900,000; directional net notional is $100,000. Ignore funding and transaction fees within the scenario table so that the arithmetic is transparent.
| Scenario | Long leg | Short leg | Combined |
|---|---|---|---|
| Both markets fall 25% | -$125,000 | +$100,000 | -$25,000 |
| Both markets rise 20% | +$100,000 | -$80,000 | +$20,000 |
| Long market falls 25%; short market falls 15% | -$125,000 | +$60,000 | -$65,000 |
The worst loss in this deliberately small scenario set is $65,000. Suppose the illustrative policy adds $12,000 for closeout cost and $3,000 for operational uncertainty, producing an $80,000 initial requirement. If the cash collateral receives a 2% haircut, eligible equity at entry is $196,000 and initial margin headroom is $116,000.
That headroom is not an unconditional withdrawal allowance. A withdrawal changes the haircut calculation; open orders may reserve additional capacity; other limits may bind. More fundamentally, the offset assumes the short leg's gain can support the long leg's loss within the defined closeout window. If the two markets cannot settle within that perimeter, this calculation overstates usable protection.
The numbers are teaching assumptions, not FT parameters or recommendations for a live market. A deployable model would require a much broader scenario set, independently justified closeout costs and evidence about each settlement dependency.
Value collateral for the liability it must discharge
A collateral mark answers what an asset is worth under a valuation convention. A closeout path answers how much of the debt's settlement asset can actually be obtained. Keep both representations. An accurate reference price does not mean that the full account can be sold at that price before the next funding payment.
Eligibility therefore needs asset limits, concentration limits and a liquidation horizon. A tokenized fund may have a published net asset value while redemption follows a banking calendar. A wrapped token may share price exposure with its underlying while depending on a separate bridge or redemption contract. Those dependencies belong in the model even if recent returns are almost identical.
Distinguish market exposure from operational eligibility. Reducing a concentration cap should prevent new borrowing immediately if that is the defined policy, but it should not silently erase balances from the ledger. Existing exposure needs an explicit transition, notification and closeout rule. Otherwise a routine parameter update can become an unexplained liquidation event.
When collateral and liability share a risk factor, evaluate both together. Holding a volatile asset against debt in that same asset differs from holding it against a dollar obligation. The oracle layer must preserve quote currencies and the applicable time basis so that the model does not accidentally grant credit to an exchange-rate mismatch.
Check the post-transaction state atomically
The important question is whether the account remains valid after the proposed action. Calculate or verify that state within the same execution boundary that commits the balance changes. A price check performed by a client before submitting a transaction is informational: another fill, withdrawal or parameter update can arrive first.
For a trade, apply the proposed fill, fees and funding accrual to a temporary account state; verify the relevant limits; then commit the transition. For a withdrawal, remove the proposed collateral and recompute eligibility, concentration and margin. For a batch, define whether only the final state must satisfy margin and which external calls can observe intermediate balances.
Account for open orders. Two independently acceptable orders may become unacceptable if both fill. An architecture can reserve capacity conservatively or compute a bounded set of possible fills, but it must state its assumptions about mutual exclusivity. A cancel request does not release its reservation until cancellation is authoritative.
A reduce-only flag is not proof that portfolio risk falls. Closing the profitable hedge can leave the losing leg exposed. Deribit's margin explanation illustrates this issue for portfolio margin. Test risk reduction on the resulting portfolio rather than only comparing one instrument's absolute position size.
Choose where the model runs and what must be verified
A fully onchain model offers a direct relationship between execution and the risk calculation, but scenario count, portfolio size and valuation complexity consume gas. Bound each dimension before promising support for a broad instrument universe. An account that can accumulate more positions than the liquidation path can process is an availability problem, even when every individual trade was valid.
An offchain service can evaluate richer scenarios and produce an authorization for a specific action. That introduces a trust and availability boundary. Bind the authorization to the account, chain, verifying contract, proposed state change, model version, price snapshot, nonce and expiry. Verify those commitments before releasing value. A correct signature over an obsolete account is still unsafe.
EIP-712 defines typed structured-data signing and domain separation; it does not supply application replay protection. The account contract still needs explicit nonce consumption and transaction-specific validation.
A hybrid design can keep hard exposure caps and asset eligibility onchain while accepting bounded signed results for complex valuations. This trades flexibility for a larger trust model. Write down who can authorize risk, how keys rotate and which recovery actions remain possible if every authorized calculation service is unavailable.
Treat degraded pricing as an operating state
The model should consume price observations with identity, units, timestamps and quality information. Freshness must reflect the asset and action. A value adequate for a daily report may be inadequate for releasing collateral against a fast-moving derivative. A technically fresh message can also carry an old underlying observation, so transport time and observation time should remain distinct.
Define degraded behavior per operation. New leverage and withdrawals that increase exposure may need to stop when a required feed becomes unusable. Repaying a fixed token amount can often remain available because it need not rely on the missing valuation. Depositing collateral might be allowed into the ledger without immediately granting borrowing capacity.
Liquidation needs a separate decision. Continuing at an untrusted price can wrongly seize assets; freezing indefinitely can accumulate losses. Document the acceptable fallback sources, observation windows and emergency authority before the incident. The fallback must match the same asset and economic meaning, not simply be the next contract that returns a number.
Recovery also matters. Re-enabling operations immediately after one valid tick can create oscillating behavior. Specify evidence for returning to normal, invalidate obsolete risk authorizations and reconcile queued actions against the new account state. Monitoring should distinguish market stress, stale inputs and failed infrastructure because the appropriate response differs.
Design liquidation as a sequence of risk transitions
Crossing maintenance margin begins a workflow; it does not itself create liquidity. The engine must identify executable actions, pay their costs and reevaluate the account after each committed step. Liquidation can cancel orders, repay debt, transfer positions or sell collateral. Each action can change the value of portfolio offsets.
One illustrative policy chooses a bounded slice that restores a target margin buffer with the least expected execution cost, subject to available quotes and maximum exposure duration. A more conservative design can close a complete risk group. The choice depends on whether preserving an offset is practical under stress and whether its component positions can settle together.
Do not assume that selling the most liquid asset first always helps. That asset might be the hedge for an illiquid liability or the only immediately usable settlement balance. Simulate the entire resulting portfolio, including incentives paid to the liquidator and any remaining debt.
Separate ordinary liquidation from insolvency resolution. If realized proceeds cannot cover liabilities, the deficit requires an explicit accounting destination and a defined loss allocation. A backstop should have stated capacity, eligible assets and availability assumptions. See liquidation system architecture for repayment arithmetic, auction choices and residual-debt handling.
Our reproducible hedge-unwind study compares three closeout allocations at equal executed notional and shows how a smaller gross position can leave a larger scenario requirement.
Validate arithmetic, economics and transaction ordering
Validation needs more than examples that reproduce the implementation. Build an independent reference calculator using a different arithmetic path, then compare results across generated portfolios and boundary values. Specify rounding direction: a collateral credit should not round upward while a corresponding obligation rounds downward. Check zero balances, extreme decimals, large accrued indexes and values near signed-integer limits.
- Accounting invariants: settlement cannot recognize the same gain twice; reserved balances cannot be withdrawn; debt reduction matches the amount actually received.
- State invariants: a committed risk-increasing action satisfies the active limits; stale authorizations fail; model-version changes invalidate incompatible approvals.
- Economic tests: a basis divergence reduces hedge credit; closeout costs rise with stressed size; inaccessible settlement proceeds do not count as immediately available cash.
- Adversarial sequences: fill two orders, withdraw then fill, partially liquidate then update a price, rotate parameters during a pending authorization, and interrupt an external settlement.
- Operational tests: run the largest permitted portfolio through valuation and liquidation under the intended execution limits.
Replay stressed markets with realistic observation delays and unsuccessful executions. A backtest that assumes every quote fills at its displayed price measures a different system. Record model breaches, false liquidation signals, closeout shortfalls and time spent in degraded mode; each reveals a distinct calibration or architecture problem.
Carry funding and settlement through the closeout horizon
A snapshot can understate exposure when it assumes that closeout is immediate. Funding, borrowing costs and settlement obligations continue while an account is being reduced. Estimate the time needed to complete the permitted execution path, then carry those cashflows through the same horizon used for market stress.
For example, suppose an illustrative $1 million position pays funding equivalent to 15 basis points per day for three days before it can be fully transferred. At unchanged notional, that is $4,500 of additional outflow. The assumption is deliberately simple: an actual model would use the applicable funding convention, changing position sizes and a stressed rate path. A hedge that offsets the position's price exposure may not offset its funding payments.
Distinguish an accrued receivable from settled collateral. If a venue owes profit but pays it after the account must meet another obligation, the receivable may improve economic equity without improving immediate payment capacity. Apply a defined recognition policy rather than treating the two as interchangeable.
Expiry adds another transition. Contract settlement can replace an exposure with a cash amount, exercise obligation or underlying asset. Test the account immediately before and after that event, including any fees and required currency conversion. Margin should remain coherent when the instrument changes form.
Version parameters and explain every decision
Risk parameters are executable policy. Store a version and activation rule for scenarios, collateral eligibility, concentration limits and closeout assumptions. A reviewer should be able to reconstruct the exact requirement applied to a past transaction, including the data available at that time.
Before increasing a haircut or tightening a limit, run the proposed configuration against current exposure and representative stress portfolios. Report which accounts would lose capacity or cross maintenance. A planned rollout can give operators a defined transition; an emergency update may need a faster path with narrower authority and a record of the reason.
Dashboards should explain the binding constraint. An account can have positive market equity but no withdrawal capacity because a settlement is pending, concentration is excessive or a feed is unavailable. Returning only an opaque health score leaves both users and operators unable to distinguish these conditions.
An implementation-ready engagement should produce an account and settlement specification, a risk-model document, reference calculations, transaction invariants, a parameter change procedure and an incident playbook. Those artifacts connect the mathematical model to the contracts and operations that must enforce it. They also define what evidence is still needed before any production deployment is considered.
Common engineering questions
What is portfolio margin in crypto?
Portfolio margin calculates a requirement for interacting positions within a defined account. It can recognize offsets under modeled scenarios, while retaining charges for risks such as basis divergence, concentration and closeout cost. The result depends on both the model and the ability to access collateral and hedge proceeds during stress.
Is portfolio margin the same as cross-collateral?
No. Portfolio margin describes how position risk is measured. Cross-collateral describes which assets can secure obligations. A system can use either independently or combine them under one account and settlement policy.
Can a reduce-only trade increase portfolio margin?
Yes. Closing one leg of a hedge can reduce that instrument's position while increasing the remaining portfolio's scenario loss. Risk checks need to evaluate the resulting portfolio, including settlement effects and costs.
Does this describe a live FT Inc margin product?
No. This is an engineering resource with illustrative calculations. FT Inc develops software and architecture; product parameters, counterparties, operational responsibilities and deployment status are defined for each engagement.