Skip to content
Trading Systems

Nasdaq Put MCP Inside Calypso: Designing Trade-Lifecycle Agents For A Capital-Markets Platform, From Read-Only Assistants To Exception Workers, In Code

On 29 September Nasdaq launched an agentic AI operating environment inside Nasdaq Calypso, its capital-markets and treasury platform: Nasdaq-hosted agents on Amazon Bedrock, an integration layer built on the Model Context Protocol so clients can connect their own agents to Calypso workflows, data and controls, strict sandboxing with no external data retention, live oversight to keep agents inside an institution's policies and data perimeter, and a first natural-language assistant over trading, risk and collateral data. The same week Trading Technologies closed its TRAFiX acquisition to complete a multi-asset OEMS, and Cboe announced KPI-linked binary contracts for October with Robinhood as first retail partner. The message for trading-technology teams: the systems of record are becoming agent platforms, and MCP is the socket. This is how to design the agents that plug in - the tool surface, the data perimeter, the exception worker pattern and the audit trail - with code.

AlchmAI Engineering16 min read

29 Sept

Nasdaq launched an agentic AI operating environment within Nasdaq Calypso, hosted on Amazon Bedrock with an MCP integration layer

0

External data retention in the environment's sandboxing, with live oversight to keep agents inside an institution's policies and data perimeter

30 Sept

Trading Technologies closed its TRAFiX acquisition, adding global equities and equity-options OEMS to a cloud multi-asset platform

Oct 2026

Target launch of Cboe's KPI-linked binary contracts on its US securities exchange, pending approval, with Robinhood as first retail partner

Nasdaq's announcement is the clearest statement yet of where capital-markets software is going. Calypso - the system of record for trading, risk, collateral and treasury at a large number of banks and asset managers - now ships with an agentic operating environment. Agents are hosted by Nasdaq and run in Calypso's cloud environment on Amazon Bedrock; clients can use Nasdaq's agents or connect their own proprietary AI infrastructure through an integrated layer built on the Model Context Protocol; the environment enforces operational boundaries, live oversight and strict sandboxing with no external data retention; and the first capability is a natural-language assistant that answers questions over trading, risk and collateral data and documentation. Magnus Haglind, Nasdaq's head of capital markets technology, described it as evolving Calypso 'from a system of record into an intelligent platform', letting clients 'connect agents from many different sources to real workflows, data, and controls', with further agentic workers to automate manual processes across the trade lifecycle to follow.

It did not arrive alone. Trading Technologies closed its acquisition of TRAFiX on 30 September, adding global equities and equity-options order and execution management and FIX connectivity to a cloud platform that already spans futures, FX, fixed income and digital assets - a single multi-asset OEMS with surveillance, margin analytics and regulatory reporting. And Cboe announced KPI-linked binary contracts - pay-outs tied to companies' key performance indicators and corporate events - for an October launch on its US securities exchange, pending approval, with Robinhood as the first retail broker and a temporary Covered Clearing Agency registration for Cboe Clear US. New platforms, new products, and an agent socket on the system of record: the trade lifecycle is being re-plumbed for software that acts.

The Tool Surface: Three Tiers

  1. 01Tier 0 - read and explain. Positions, trades, cashflows, collateral calls, limits, documentation. This is Nasdaq's first assistant and where most value sits with almost no risk. Tools are read-only, results are scoped to the caller's entitlements, and output is structured.
  2. 02Tier 1 - propose. Draft a resolution for a settlement exception, a collateral substitution, a limit-breach explanation, a corporate-action election. The agent produces a proposal object; a human or a deterministic rule engine accepts it.
  3. 03Tier 2 - act within bounds. Auto-apply proposals that fall inside a narrow, versioned policy: for example, matching a break where the difference is under a threshold and both legs reference the same trade ID. Everything else escalates.
typescriptmcp/lifecycle-server.ts
import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";
import { z } from "zod";

// Tier 0: read tools scoped to the caller's entitlements. The perimeter is
// applied server-side from the authenticated identity - never from prompt text.
export function registerReadTools(server: McpServer, platform: Platform) {
  server.registerTool("get_settlement_exceptions", {
    description: "Open settlement exceptions for the caller's books, optionally filtered by value date and currency. Read-only.",
    inputSchema: { valueDate: z.string().date().optional(), currency: z.string().length(3).optional(), limit: z.number().int().max(200).default(50) },
    annotations: { readOnlyHint: true },
  }, async (args, ctx) => {
    const books = await entitlements.booksFor(ctx.identity);          // perimeter
    const rows = await platform.exceptions.query({ ...args, books });
    audit.log(ctx.identity, "get_settlement_exceptions", args, rows.length);
    return { content: [{ type: "text", text: JSON.stringify(rows) }] };
  });

  server.registerTool("get_collateral_position", {
    description: "Collateral held and posted for a counterparty agreement, with eligibility and haircuts. Read-only.",
    inputSchema: { agreementId: z.string() },
    annotations: { readOnlyHint: true },
  }, async ({ agreementId }, ctx) => {
    await entitlements.assertAgreement(ctx.identity, agreementId);
    const pos = await platform.collateral.position(agreementId);
    return { content: [{ type: "text", text: JSON.stringify(pos) }] };
  });
}

The Exception Worker Pattern

Nasdaq's roadmap - agentic workers that automate or reduce manual processes - describes the pattern that has always been the best fit for AI in post-trade: the exception queue. Most items are routine and rule-shaped; a minority need judgement; all need an audit trail. The worker below reads an exception, gathers evidence through Tier 0 tools, proposes a resolution through a Tier 1 tool, and lets a policy engine decide whether the proposal is applied automatically or routed to a person. The model never touches the platform's write path directly.

typescriptagents/exception-worker.ts
interface Resolution {
  exceptionId: string;
  action: "match" | "amend_ssi" | "chase_counterparty" | "escalate";
  evidence: string[];          // tool-call ids the agent relied on
  rationale: string;
  confidence: number;          // model-reported; policy treats it as advisory only
}

const AUTO_POLICY = {
  match: (e: Exception, r: Resolution) =>
    e.type === "amount_break" && Math.abs(e.deltaMinor) <= 100 && e.legsShareTradeId,
  chase_counterparty: (e: Exception) => e.ageHours >= 4 && e.type === "unmatched",
};

export async function handleException(e: Exception, agent: Agent, human: Queue) {
  const proposal: Resolution = await agent.propose(e);          // Tier 1 tool call
  const rule = AUTO_POLICY[proposal.action as keyof typeof AUTO_POLICY];
  const autoOk = rule ? rule(e, proposal) : false;
  await audit.append({ exceptionId: e.id, proposal, autoOk });
  if (autoOk) return platform.apply(proposal, { by: "policy:" + proposal.action, evidence: proposal.evidence });
  return human.enqueue({ exception: e, proposal });              // everything else: a person decides
}
  • The policy is code, versioned and reviewed like any control. The agent's confidence score is recorded but never decides anything.
  • Evidence is a list of tool-call IDs, so a reviewer can replay exactly what the agent read before proposing.
  • The apply path is the platform's own, called by the orchestrator under a policy identity - the agent's credentials cannot reach it.

Connecting Your Own Agents To A Platform's MCP Layer

Nasdaq's design lets a firm bring its own agents. When you do, treat the platform's MCP server like any critical upstream: pin the tool list you rely on, validate schemas at start-up, and wrap each tool in your own allow-list so a new tool appearing upstream does not silently become available to your agent.

pythonagents/upstream_guard.py
EXPECTED = {
    "get_settlement_exceptions": {"readOnlyHint": True},
    "get_collateral_position":   {"readOnlyHint": True},
    "propose_resolution":        {"readOnlyHint": False},
}

def guard_tools(listed_tools: list) -> list:
    """Expose to the agent only tools we have reviewed, with the annotations we expect."""
    by_name = {t["name"]: t for t in listed_tools}
    missing = [n for n in EXPECTED if n not in by_name]
    if missing:
        raise RuntimeError("upstream MCP changed: missing " + ", ".join(missing))
    exposed = []
    for name, want in EXPECTED.items():
        t = by_name[name]
        if bool(t.get("annotations", {}).get("readOnlyHint")) != want["readOnlyHint"]:
            raise RuntimeError("annotation drift on " + name)
        exposed.append(t)
    new_tools = set(by_name) - set(EXPECTED)
    if new_tools:
        log.warning("upstream added tools not exposed to agent: " + ", ".join(sorted(new_tools)))
    return exposed

“The system of record is becoming the agent platform. Your job is no longer to get the data out of it; it is to decide, in code, what an agent may do once it is in.”


New Products, Same Discipline

Cboe's KPI-linked binaries and the ever-longer list of event contracts mean trade-lifecycle systems will carry instruments whose pay-offs depend on corporate metrics and events rather than prices. For agents that touch them, the same tiers apply: read and explain the contract terms and positions freely; propose hedges or elections; act only within a policy that understands the settlement source. And with TT's TRAFiX deal completing a multi-asset OEMS, the front office is consolidating onto platforms that will expose their own agent sockets - the tool-surface discipline above is what lets one agent architecture span them.

The Bottom Line

Nasdaq's agentic operating environment inside Calypso - hosted agents on Bedrock, an MCP integration layer for clients' own agents, sandboxing with no external retention and live oversight, starting with a natural-language assistant over trading, risk and collateral data - marks the point where capital-markets systems of record become agent platforms. Designing for that means a three-tier tool surface from read-only to bounded action, an exception-worker pattern where the model proposes and a versioned policy decides, entitlement-scoped perimeters enforced server-side, and a guard on the upstream tool list so nothing new reaches your agent unreviewed. Alongside TT's completed TRAFiX acquisition and Cboe's KPI binaries, it is a week that redrew the trading stack. That is the trading AI architecture we build in London, and MCP has just become the interface it plugs into.

References & Further Reading

Trading AI architectureTrading Workflow architectureAI Automation Trading codeMCPNasdaq Calypsotrading automationpost-trade
Share Email
AI

AlchmAI Engineering

Engineering, London

Written by the AlchmAI engineering team in Mayfair, London. We build trading platforms, real-time charts, market data pipelines and AI features for brokers, prop firms and fintech teams. The Playbook is where we explain how we approach these systems, with code you can run and sources you can check.

Code in this guide is illustrative and supplied without warranty. Review and test it before production use. Nothing here is investment advice. Important information