Trading bot: 9 things to know before you commission one
The most important thing to know before commissioning a trading bot is this: a bot is not a strategy, it is a tool that applies a strategy with discipline. An unprofitable strategy does not become profitable once it is turned into a bot — it simply produces the same result faster and more consistently. In this article we set out nine points on strategy, testing, risk limits, security and monitoring that should be settled before you begin.
This article is a technical guide, not investment advice. Trading in any financial market — cryptocurrencies and leveraged products above all — carries the risk of losing part or all of your capital.
Strategy: what will the bot actually apply?
1. A bot does not produce profit; it applies a rule
A trading bot is software that buys and sells in the market according to set rules. Its strengths come from three things: it does not tire, it does not act on emotion, and it applies the rule the same way every time.
None of these strengths guarantees beating the market. An approach that does not work when you apply it by hand will not work as a bot either. Worse, a bot can apply a faulty rule far faster, and far more often, than a person ever could. So the first question should not be “how much will the bot make?” but “which rule will it apply, and why should that rule work?“
2. Your strategy must be possible to write down
A strategy a bot can apply has to be clear enough for a machine to follow. “I buy when the market looks good” is not a rule. This is:
- Entry condition: Which data is watched, and which threshold opens a position?
- Position size: How much of the capital goes into each trade?
- Exit condition: Under what conditions do you take profit, and cut a loss?
- The unexpected: What happens if the data feed drops, the exchange stops responding or the price jumps in an instant?
On our projects, the first job is to write the strategy down with the client at this level of detail. Along the way, the vague parts of the strategy tend to surface by themselves. That written strategy is the most valuable output that comes before any code.
Testing: what historical data can and cannot tell you
3. A backtest is a filter, not proof
A backtest simulates how the strategy would have performed on historical market data. It is necessary — but it is often misread.
What we watch for in a backtest:
- Overfitting. The more tightly parameters are tuned to past data, the less likely they are to work in future. A strategy that looks perfect on history is usually a suspicious one.
- Unseen data. The strategy is tuned on one period and tested on another it has never seen.
- Realistic costs. Leave out trading fees, slippage and, for futures, funding costs, and the results look better than they are.
- Seeing the future. The most insidious mistake is a simulation accidentally using data that would not yet have been known at that moment.
A strategy that fails the backtest is dropped. One that passes has only earned the right to move on to the next stage.
4. Markets change character
A strategy can work well in a trending market and lose steadily in a flat, compressed one. An approach that works in calm conditions can collapse in a sudden burst of volatility. We call this a change of market regime.
Our own autonomous trading system, CAI, started from exactly this problem. Classic single-strategy bots weaken when the regime shifts. In CAI, instead of a single strategy, ten specialist agents continuously read the market regime and consult one another before each decision. We describe that architecture in detail in our article on multi-agent AI systems.
Not every bot needs to be that elaborate. But every bot should at least have an answer to the question: “Under what conditions should I not be running?”
Risk and security: the first line of the architecture
5. Risk limits are written before the code
A bot is judged by what it does when things go wrong. So we do not treat risk limits as a feature to bolt on later; we treat them as the first line of the architecture:
| Limit | What it does |
|---|---|
| Risk per trade | The most of the capital a single trade may put at risk |
| Daily loss limit | Once a set loss is reached in a day, the bot opens no new trades |
| Total position limit | The total size that may be open at any one time |
| Leverage limit | The highest leverage that may be used |
| Consecutive loss rule | After a set number of losses in a row, stop and ask a person |
The values of these limits are your decision. Our job is to make sure the bot obeys them under every condition.
6. The kill switch comes before everything
A kill switch takes the bot out of service in a single move: cancelling open orders, closing positions if needed and blocking any new trades.
It needs three properties:
- Always reachable. From your phone, with one tap.
- Always in charge. A manual stop can never be overridden by any automatic decision of the bot.
- Able to fire by itself. When risk limits are breached, the data feed drops or an unexpected error occurs, the bot stops itself.
In CAI, manual override always wins, in one click. Building that in from the start was the precondition for having the confidence to run the system with real capital.
7. The API key gets the least privilege possible
The bot connects to your exchange account with an API key. That key is a door into your account.
- Never grant withdrawal rights. The bot may trade; it can never move money out of the account.
- IP restriction. If the exchange supports it, the key works only from the address of the server the bot runs on.
- Store the key safely. It is never written into the code, and is kept where unauthorised people cannot reach it.
- A separate account. Where possible, open a sub-account for the bot, so the risk stays confined to it.
Monitoring and going live
8. Without monitoring and logs, you are flying blind
The bot works around the clock; you do not. You need to see what it is doing and hear about anything important.
- Live panel. Open positions, the day’s result, how close you are to each risk limit.
- Notifications. Messages to your phone when a trade opens, when a limit is near, when the bot stops.
- Decision log. Under which condition, and on which data, each trade was opened. When something goes wrong the first question is “why?” — and without a log there is no answer.
- Technical health. Is data arriving, is the exchange connection open, is latency normal?
9. Going live happens in stages
Jumping straight from a backtest to full capital is the most common mistake. The order we recommend:
- Historical testing. The strategy and the code are verified.
- Paper trading. The bot runs on real-time data but sends no real orders. This is where the gaps between simulation and reality show up.
- Live with a small budget. Real orders, with an amount you can afford to lose. Slippage, latency and the exchange’s quirks only fully appear here.
- Gradual scaling. If the results and behaviour match expectations, capital is increased step by step.
The work does not end once the bot is live. Exchanges change their APIs, and market conditions change. That is why we offer monthly maintenance for trading bots.
Frequently asked questions
Does a trading bot guarantee profit?
No. No bot can guarantee profit. A bot only applies your strategy with discipline; it does not remove market risk. We build the technical tool and give no investment advice.
Does the bot run on my own account?
Yes. It connects to your account with the permissions you set. It is never given withdrawal rights, and the kill switch is always in your hands.
I don’t have a strategy — can the bot find one for me?
Finding strategies and making investment decisions is not our work. We turn the rules you set into a system that is safe, tested and easy to monitor. While the strategy is being clarified, we help you put its vague parts into writing.
Can you make my existing bot safer?
Yes. We review the existing bot’s risk limits, kill switch, API permissions and monitoring. The gaps are then dealt with in order of importance.
If you would like to talk about turning your own strategy into a rule-based system you can monitor, have a look at our bot development page or write to us. We reply within two business days.