harvey
← Back to Projects

2026-09-25

Robinhood Agentic Trading: Letting an Agent Run an Account

A live Robinhood account run by an agent on a three-beat daily pipeline, with a deterministic risk gate and bull/bear research that argues before a verdict

  • MCP
  • Claude Agent SDK
  • Risk Engine

NAV and positions are live data from this account, synced weekly.

Generation one is Algorithm Trading Framework, built in 2023: fixed signal, fixed sizing rules, mediocre returns, mediocre risk control. Generation two isn't trying to out-discipline it. It hands a real Robinhood account to an agent (codename Hermes) and lets it open, patrol, and close the book every single day on its own. Harvey's job most days is just one verb: approve.

Three beats a day, and the agent clocks in itself

The account moves on its own at three fixed times: 9:45 ET to open, 15:30 ET to patrol stops, 16:15 ET to close and file. These aren't cron jobs firing a script — each one is Hermes opening a session, pulling live positions and quotes over the Robinhood trading MCP, then deciding what to do.

9:45 is the important beat: run the rotation signal, get a target weight per symbol, draft a batch of candidate orders. 15:30 is narrower — anything that's breached its stop gets sold first, regardless of what the signal says that day. 16:15 closes the books: NAV gets written back to the ledger, a daily report goes out.

A hard risk gate: orders get blocked, not talked out of it

Candidate orders don't go straight to the market. They pass through a deterministic, code-only gate that rules each one AUTO (fires on its own), CONFIRM (waits on Harvey), or BLOCKED (no). Every threshold in that gate — stop-loss distance, daily circuit breaker, max position size — lives in a config file the agent can't touch. Changing a number means a human process with a paper trail.

The gate is currently doing real work: the backtest from late September came back FAIL — the strategy hasn't proven it beats SPY on a risk-adjusted basis over the long run, only one year out of several cleared that bar. So the gate downgraded every new buy from AUTO to CONFIRM, and only lets sells and stop-losses fire automatically. The agent can close positions on its own; opening new ones needs a signature. That's not a decorative clause — it's actively in effect right now.

Research in stereo: making two agents argue

Daily rotation manages what's already in the account. A separate research line hunts for mispriced names nobody's watching. Candidates have to clear four funnels at once — undervaluation, momentum, insider cluster buying, superinvestor accumulation — then a financial-quality floor. Not many make it through.

Whatever survives gets sent to two agents that can't see each other's drafts: one builds the bull case only, one builds the bear case only, each reading filings and news independently. A third agent — reading only those two memos, never the raw data — renders the verdict: BUY / WATCH / PASS.

This is the most interesting part of the whole setup. Instead of one model arguing both sides and quietly convincing itself, you force two sides to fight it out first and let a judge weigh the arguments. Both new names this week came back WATCH, not BUY — the gate is actually filtering, not just going through the motions.

Options: the agent never touches the trigger

Stocks at least get a gray zone — sells auto, buys need a signature. Options run on an entirely different permission model: the agent is limited to research and expiration reminders; opening a position is something only Harvey does by hand. The one live options trade on the books so far was opened manually and sits at -53% — kept on record as a reminder that options discipline has to be tighter than stocks, not something to hand to an agent.

Costs and boundaries

The code stays private this round — it's a live account, and publishing the exact strategy wouldn't help anyone. The NAV curve above only covers a handful of trading days; it's beaten SPY over that stretch, but the sample is too small to call it a track record — at best it's "the gate hasn't misfired yet." The real test comes the moment the next backtest passes and buy permissions open back up.