Description:
Dark-pool oversight is not solved by another dashboard. A proprietary trading firm needs an interactive control application that connects customers, traders, line managers, compliance, surveillance, operations, risk, and technology without exposing every user to the same data or authority. In Asia, the design must handle fragmented venues, local market rules, multiple legal entities, cross-border data restrictions, multilingual users, non-overlapping trading sessions, and different definitions of suspicious or abnormal activity.
This session presents a reference architecture using Databricks Apps to convert governed lakehouse data, analytics, and AI models into an operational dark-pool control application. The application runs as a containerized service on the Databricks serverless platform and connects to Databricks SQL, Unity Catalog data, model-serving endpoints, vector retrieval, jobs, and approved external services. Developers can use Streamlit, Gradio, Dash, Flask, FastAPI, or supported JavaScript frameworks according to the required interaction model.
The architecture avoids unnecessary data exports into a separately governed web stack. Orders, indications of interest, executions, venue events, reference prices, client classifications, trader mandates, surveillance alerts, positions, limits, and investigation records remain in governed platform resources. The app queries authorized data through its configured identity and writes approved workflow records back to controlled tables. This reduces duplicated copies and infrastructure, but it does not imply zero latency. Performance still depends on SQL warehouses, model endpoints, query design, network paths, concurrency, and application compute size.
The solution separates five user experiences. Customers receive permitted execution-quality summaries and case status without seeing proprietary venue logic or other clients. Traders view their own orders, fills, exceptions, and permitted liquidity analytics. Line managers see desk-level concentration, abnormal order size, price deviation, limit usage, cancellations, and unresolved alerts. Compliance and surveillance review potential information leakage, wash activity, layering, spoofing, restricted-list issues, and unusual interaction patterns. Operations and technology monitor booking breaks, app health, data freshness, failed jobs, and service dependencies.
Unity Catalog provides table, view, function, model, and resource permissions. App authorization uses a service principal for controlled resource access, while user authorization can preserve the identity of the signed-in user for fine-grained decisions. Row filters and column masks protect client identity, account information, trader-sensitive fields, and jurisdiction-restricted records. Separate catalogs or schemas can isolate production, investigation, and model-development data. Every write-back action records the user, timestamp, source record, reason, prior value, new value, approval status, and downstream trigger.
The analytical layer calculates execution shortfall, venue fill rate, mark-outs, spread capture, order-to-trade ratio, cancellation intensity, price impact, information leakage, concentration, and deviations from approved behavior. A conversational interface can retrieve policies, venue manuals, prior cases, and model documentation through approved vector search and Mosaic AI services. Responses must cite governed sources, distinguish fact from model inference, and avoid making autonomous enforcement decisions.
A scenario engine allows authorized users to adjust volume, participation rate, spread, volatility, urgency, venue availability, and liquidity assumptions. The application calls approved models to estimate fill probability, expected impact, implementation shortfall, capital usage, and stress outcomes. Line managers can compare continue, reduce, reroute, pause, or cancel scenarios. Material actions remain subject to authority matrices, dual control, and venue-certified mechanisms.
The write-back pattern supports data correction and labeling. An authorized analyst can flag an incorrect venue mapping, classify a false-positive alert, add an investigation outcome, or label a training example. Transactions are written to controlled Delta tables or approved operational services, then trigger data-quality checks, model-evaluation workflows, or retraining pipelines. Direct editing of authoritative trade records is prohibited; corrections use append-only adjustment, approval, and reconciliation patterns.
Production controls include CI/CD, dependency pinning, secrets management, private connectivity, audit logs, application telemetry, rate limits, input validation, prompt-injection testing, model monitoring, resilience testing, and disaster recovery. The application can scale its compute configuration, but capacity, concurrency, cost, and startup behavior must be tested against Asian market-open peaks. The result is a governed control surface, not a replacement for exchange controls, order-management systems, independent surveillance, or human accountability.
The line manager operates as both coach and braking system. Coaching challenges the trader's thesis, sizing, liquidity assumptions, and exit plan. Braking enforces stop-losses, prevents unauthorized averaging down, suspends abnormal automation, and requires risk reduction when capital is threatened. The application supports progression from coaching to warning, hard stop, and emergency action. Follow-the-sun handovers carry severity, owner, next action, source freshness, and deadline between Asian offices. Market-open checks validate feeds, limits, models, and venue dependencies, while after-action reviews capture residual exposure, client impact, operational breaks, and lessons learned. Preservation of principal always takes precedence over maximizing short-term return.