Stop and resume
Pause an asset
Pause an asset
- Risk pauses it:
POST /v1/instruments/{instrumentId}:pausewith a rationale. One call holds the asset, at once. - The asset reads
pausedonGET /v1/instruments/{instrumentId}, andinstrument.pausedgoes to the feed and the webhooks. - To resume, release the hold: risk asks, two approvers sign.
Release a hold
Release a hold
A hold stops an asset’s distributions, redemptions and new issuance. A newer, agreeing statement clears the finding behind it, never the hold.
- Read the latest run,
GET /v1/reconciliation-runs/latest, and confirm the finding is answered. - Risk asks for the release:
POST /v1/holds/{holdId}:release. - Two approvers, neither the maker nor an auditor, approve it (
POST /v1/approvals/{actionKey}:approve).hold.releasedgoes to the feed and the webhooks.
A reserve short of its cover
A reserve short of its cover
- Reconciliation finds the cover below the minimum, holds the backed instrument and announces
reserve.cover-low. New mints are refused; redemptions go on. - The issuer restores the cover: the reserve’s holder tops a par reserve up with assets of its own, or the price source publishes a fresh point where a stale price caused it.
- The next run finds the cover met. Risk asks for the hold’s release, and two approvers sign it.
Revoke a standing approval
Revoke a standing approval
POST /v1/standing-approvals/{standingApprovalId}:revoke, by the operator, risk or approver role, alone. It takes effect at once, and standing-approval.revoked is announced.Findings
A mint the registrar made to itself
A mint the registrar made to itself
- Reconciliation finds the mint and holds the asset, naming the run (
GET /v1/reconciliation-runs/{reconciliationRunId}). - The registrar burns the units back, naming that run as the burn’s reference.
- The next run explains the burn by the finding it named, and is clean.
- Release the hold: risk asks, two approvers sign.
Units moved between two holders outside NodeAsset
Units moved between two holders outside NodeAsset
On an asset that rebases, a transfer between two custodians moves units away from their income, so the finding holds the asset. A registered succession explains a holder’s move to its successor; anything else is investigated, then the hold released under two approvers. On a par or accumulating asset the transfer is reported only.
Orders
An order that cannot settle
An order that cannot settle
A subscription or a redemption whose investor allocated, but which can no longer settle (the order was closed, or its deadline passed), would leave the investor’s cash or units set aside until that deadline.
- Release it:
POST /v1/subscriptions/{subscriptionId}:releaseorPOST /v1/redemptions/{redemptionId}:release. The venue, as the settlement’s executor, cancels the investor’s allocations and withdraws its request in one transaction. - Withdraw the order, or ask the investor again.
A node has not vetted the package
A node has not vetted the package
An act refused 409
package-not-vetted names the package and the party whose node has not vetted it. That node’s owner vets the release’s package; the same request then goes through.A dealing cycle refused
A dealing cycle refused
One leg refused on either registry refuses the whole cycle, and nothing moves. Release the cycle,
POST /v1/dealing-cycles/{dealingCycleId}:release, and open a new one without the order at fault.The engine and its connections
The ledger is out of reach
The ledger is out of reach
Health answers
connected: false. A write’s operation fails with the problem ledger-unavailable, and a call that waits on the ledger answers 503 with a Retry-After. Once health answers connected again, read the resource to see whether the write took effect, then send it again under a new Idempotency-Key.The identity provider is out of reach
The identity provider is out of reach
Calls answer 503
idp-unavailable with a Retry-After: the engine cannot fetch the provider’s keys, and the caller’s token may be fine. Restore the engine’s reach to the provider’s key set; nothing else changes.After a restart
After a restart
When the engine is ready, it resolves every operation the previous process left queued or running. A settlement whose start was recorded carries on from the ledger. A distribution caught mid-way fails with its resume call,
POST /v1/distributions/{distributionId}:resume, which finishes it under the approval it already has. Anything else fails interrupted, with what to check before repeating it: read GET /v1/operations?state=failed.The engine's database is lost
The engine's database is lost
Restore it from a backup, or start a fresh one at the right reconciliation offset. See Backup and recovery.

