Skip to content

Skydesk is the console for agentic finance

Why a fund's AI stops at research, and how Skydesk, built on Sherwood Protocol, lets agents act on capital inside a mandate the fund controls.

By Skydesk

A software engineer can hand a task to an agent, go to a meeting, and come back to a finished pull request. The agent has read the code, made the change, run the tests and left the work for the engineer to review and merge. The engineer does not have to trust the agent blindly, because the review step is part of how the work lands.

A portfolio manager who hands a task to an agent gets research back: a summary, a screen or a set of signals. The work stops where it would touch capital, because nobody will hand an agent the book.

We are building Skydesk so a fund can go further than research without giving up control, with Sherwood Protocol as the guardrail.

Why the agent stops at research

A fund raises three objections, and each one is fair.

The first is keys: no operations team will accept an agent with signing power over capital. The second is oversight. A person approving every trade defeats the point of an agent, and no person at all is unacceptable to anyone who answers for the fund. The third is compliance, since nothing records what an agent did in a form a CCO or a fund administrator can work with.

So when an LP asks how the fund uses AI, the honest answer is research. The engineer's agent has a review step and a merge button. The fund's agent has neither, so it never gets past the research note.

Sherwood Protocol is the guardrail

Agentic finance needs a capital coordination layer, one that lets agents become fund managers. It gives an agent a vault to run and a set of rules it cannot step around. That is why we built Sherwood Protocol as the missing layer onchain.

The capital sits in a non-custodial vault, and the agent can neither hold it nor withdraw it. What the agent can do is propose a strategy. A proposal commits the agent to the exact calls it wants to make, up front, before anything runs.

From there every strategy follows the same lifecycle, in order.

  • Proposed, with the exact calls attached.
  • Checked, by simulating those calls against the market as it stands and testing them against the fund's mandate.
  • Approved, by the fund wherever the mandate requires a person to sign off.
  • Executed. Only the approved calls can run.
  • Settled, with the outcome landing onchain.
  • Recorded at every step, rejected proposals included.

On the open protocol, a vault's depositors vote on each proposal and independent reviewers replay the calls before capital moves. Skydesk points the same machinery at a single fund, where the fund's signer and its mandate take the place of open voting.

That answers the keys objection. The fund's signer owns the vault, agents get trade authority and nothing more, and nobody at Skydesk can move the capital. An agent cannot act outside its limits either, because a proposal that breaks the mandate fails before it executes. Sherwood Protocol's contracts enforce the mandate, so the limit holds whether or not anyone is watching.

What Skydesk adds

A fund cannot operate a guardrail by itself. Someone has to set the rules, watch what the agents do and answer for it afterwards, and that is the part we are building.

Skydesk, powered by Sherwood, is the console where a hedge fund runs and sees its agentic strategies, plus an MCP server so the fund's harness can keep a workflow going. That harness can be Claude, Grok, ChatGPT or Muse. The agents stay where the fund runs them and reach the vault through Skydesk. We see their proposals, never their prompts, models or keys.

The fund writes its mandate in the console: venues, position caps, the asset list, a drawdown guard, which proposals need sign-off, and a kill switch that revokes any agent. Approvals happen there too. A PM sees the queue of proposals waiting on the fund, each with its mandate check beside it, and makes the call.

Reporting and compliance come out of the record. Every proposal leaves a trail of what was proposed, how it was checked, who approved it and what executed, along with the attempts that failed. Proposal text and rationale are encrypted before storage, so the fund's reasoning stays private. Executed transactions settle onchain and are public, as they are for any onchain fund. The record exports by period, in a format we will settle with design partners.

Skydesk also adds the venues a strategy needs, and it is designed to work with custodian wallets as the signer behind the vault. The fund's people keep working in the tools they already use, and the agent's work reaches them as something to approve, reject or report on.

Where this goes

The engineer can merge an agent's pull request because a review sits between the agent and the main branch, and version control keeps every change. Skydesk puts that same structure between an agent and a fund's capital.

A fund does not have to move its book to begin. It can put one agent on one sleeve, under a mandate it writes, and read the record that agent leaves behind. That record shows what an agent did with real capital under real rules, which a backtest cannot.

Funds that want to help shape Skydesk can apply to become a design partner.