Draft for agreement 21 September 2026 v0.5 · bot live, first checks logged Published with the bot once both parties agree

Method · Checkpoint · the Robinhood Chain check-bot

What Checkpoint checks, how often, and what it says when a check fails.

Checkpoint is a read-only Telegram bot, shared by Lisa on Sable and the Sable Observatory. Paste a token address and it answers, in one message, what the chain, the market and the holder data say, followed by a three-sentence reading written inside an attested Sable enclave, with the receipt that proves it. This page is written so that nobody has to take either party on trust.

Reading engine, every signed readingLisa on SableAG Ultra Magnus · lisaonsable.com
Registry, ledger, bot, hostingSable ObservatoryPrimeCircle · sable.primecircle.cloud

What it is

Someone pastes a token address in a group or a direct message. The bot answers with what can be read from public sources, each figure with its source and its time, and closes with Lisa's reading and the signed receipt behind it.

It does not score, rank, recommend or predict. It never links to a wallet, never sends the first message, never asks for anything. A checkpoint reads papers and stamps them; it never says pass or fail. The moment a checker starts ranking things, it stops being a checker.

What it checks, and where each figure comes from

Nine blocks. Three come from the Observatory's own reads of Robinhood Chain (chain 4663), six from Lisa on Sable's token and verdict functions. Every figure carries the name of its source and the time it was read.

BlockFiguresSourceRefresh
Observatory
Official or not
In the registry, seen by the counterfeit watch, or not in the registry. Registry under the Two Sources rule: an address is official only when two official channels carry it. Plus the hourly counterfeit watch on chain 4663. Registry on announcement, watch hourly.
Observatory
Owner controls
Can the owner mint, pause transfers, freeze a wallet, swap the code. Who owns it. Controls read from rpc.mainnet.chain.robinhood.com: owner(), paused(), the three EIP-1967 slots, the bytecode selector scan. Hourly, with a diff ledger.
Observatory
Holders since launch
Holders above the dust line, arrivals last hour and 24 h, top 10 and top 50 share, deployer, burn address. Transfer ledger: every Transfer since the mint, block 63053050 (14 Sep 2026 19:24:04 UTC). Balances summed and checked against total supply. An address counts from 0.001 SABLE. Hourly.
Lisa on Sable
Holders, indexed
Holder count with the indexer's own timestamp, distribution by rank, developer holding, sell test. On Solana the mint and freeze authority. GeckoTerminal, through the token function. Snapshot at most every 15 min, cached 30 s.
Lisa on Sable
Contract
Name, symbol, decimals, total supply, burned (balance of the dead address, EVM only). The public node of the detected chain: rpc.mainnet.chain.robinhood.com for 4663, api.mainnet-beta.solana.com for Solana, public nodes of Ethereum, BNB Chain, Base and Arbitrum. With the snapshot.
Lisa on Sable
Market
Price, market cap, liquidity, pool reserves, 24 h volume, buys and sells, pair age, exchange, number of pairs. Liquidity over market cap is computed by Lisa on Sable from those two figures. DexScreener. With the snapshot.
Lisa on Sable
Namesakes
Tokens carrying the same symbol, ranked by liquidity. DexScreener symbol search, deduplicated per chain and address. With the snapshot.
Lisa on Sable
Delta
What moved since the previous snapshot. Lisa on Sable's own snapshots in Supabase, one per token every 15 min at most. With the snapshot.
Lisa on Sable
Lisa's reading
Three sentences from the figures above and nothing else. Receipt: engine, tier, attestation, logging, tokens, cost, request id. Sable's confidential tier inside a TDX enclave. The engine is the one the receipt names. Cached 60 s.

Addresses on other chains (Solana, Ethereum, BNB Chain, Base and Arbitrum are detected by the token function) get the contract, market, indexed holders, namesakes and reading blocks. The bot says that the registry, controls and ledger blocks cover chain 4663 alone.

Two holder counts, on purpose

The ledger and the indexer will not match in public, and neither is wrong. The ledger counts every address above 0.001 SABLE from every Transfer since the mint, at the top of the hour, and its balances sum exactly to the supply. The indexer counts at its own moment, with its own rules for dust and contracts.

On 18 September 2026 the ledger said 495 holders at 22:03 UTC while GeckoTerminal said more than 600. The bot prints both lines, each with its source and time, and one sentence that says why they differ. What it cannot do is print one number as if it were the only truth.

Before publication both parties compare the two lists for the same hour and write the exact difference into this page.

The deployer's moves

The same ledger folds every transfer of 100,000 SABLE or more that leaves or reaches the deployer or the launch factory, and every burn of that size, each with its block, its hash read once from the node, and the block's own time. An hour in which the deployer sent more than 0.1% of supply is flagged; smaller moves stay in the list without a flag, so the mark never appears at anyone's discretion.

The words are neutral and the same on both sites: "Deployer transfer: 15.02M SABLE (1.50% of supply) to 3 wallets, 2026-09-20 22:18 to 22:23 UTC". A transfer to the Uniswap v4 pool manager is named as such. The log cannot tell a swap from a liquidity change, so neither site says "swap", "sold" or "dump".

Second order. The wallets that received a flagged deployer transfer are watched for their own moves of 100,000 SABLE or more, under the same hourly rule. That is what tells an airdrop, many small outflows to many wallets, from anything else, without a verdict. The first such flag came on 21 September 2026: one of the three recipients of 20 September sent its whole 1.11M SABLE to the pool manager between 14:44 and 14:47 UTC, in three transfers, each with its hash.

Agreed with AG on 21 September 2026. lisaonsable.com applies the same threshold and wording to its own reading of the deployer balance. Two independent systems, one vocabulary.

What "launch" means

Three moments, three block numbers. The bot names the one it uses.

1 · Contract creation
The creation transaction
The block in which the contract came into existence.
Block to be read from AG's logs and confirmed against the chain.
2 · The mint
The first Transfer
The ledger's anchor. "Since launch" in the bot means since the mint, and the answer says so.
block 63053050 · 14 Sep 2026 19:24:04 UTC
3 · Pair creation
SABLE/WETH on Uniswap v4
The first moment the token could trade.
14 Sep 2026 19:31 UTC per the Observatory chart
Block to be added.

How often, and what it costs

Per user, per address
60 s
Inside the window the bot returns the cached answer and says how old it is.
Bot-wide
< 20 / min
The market data upstream allows about 30 a minute. Beyond the budget, requests queue for one minute, then the bot says it is busy.
Per signed reading
90 to 106 µ$
Measured by AG on real calls, 20 Sep 2026. The receipt carries the exact figure and the bot prints it.
Hard cap
1 $ / day
About 10,000 readings. Beyond it: "no reading, daily cap reached", and the facts still go out.

The readings run on the Lisa on Sable account and AG carries that cost. Without the cap the full budget would be about 2.90 dollars a day; the cap exists so nobody discovers a number at the end of a month. Snapshots on his side are written at most every 15 minutes per token, so polling faster adds nothing.

What it says when a check fails

Each block reports on its own. A failed source is written as "not read" with the reason. It is never dropped and never quietly replaced by an older figure. A validated failure carries the same weight as a validated success.

  • Registry not readable. "Cannot confirm", never "official".
  • Controls or ledger not readable. That block says so. The other blocks still go out.
  • Token function not answering. The Observatory blocks still go out. The market, contract and indexed holder blocks say "not read".
  • Enclave not answering within 15 seconds. The facts go out. The reading says "no reading, the engine did not answer".
  • Daily cap reached. The facts go out. The reading says "no reading, daily cap reached".
  • Every figure carries its own time, so a cached figure is visibly cached.

The record

Every check of a chain 4663 address is posted as a letter to the Observatory's Agent Post inbox: address, verdict, figures, receipt id, time. Never who asked. The board shows the letters with their receipts, so anyone can read what the bot said and when, and check the reading against Sable's own records.

Proposal: Checkpoint gets its own Sable passport and Agent Post handle, checkpoint, allowlisted by both sites, so the letters carry the bot's own name.

A heartbeat letter goes out once a day. If it stops, the Observatory's external uptime monitor alerts. Checks of other chains are not posted, so the board stays about Sable. Agreed.

What it never does

  • Score or rank.
  • Say buy, sell, hold, or where a price goes.
  • Say "passed" or "cleared".
  • Link to a wallet, a claim, a bridge or a "verify your wallet" flow.
  • Send the first message.
  • Store who asked. Telegram user ids live in memory for the 60-second cooldown and are not logged.
  • Answer a private message about funds.

Who runs what

Sable Observatory

  • The bot, its code and its hosting
  • The registry of official addresses
  • The counterfeit watch
  • The controls read and the transfer ledger
  • The letters, the heartbeat, the uptime monitor
  • Maintenance of the bot

Lisa on Sable

  • The token function
  • The verdict function and Lisa's attested reading
  • Every signed reading and its cost
  • The uptime probe of the gateway
  • Not the bot's code

Both are credited in every answer and on this page. Both hold $SABLE. The bot's /about carries the dated disclosure line of each.

Ownership

Different contributions, equal ownership. Agreed 21 September 2026.

  • The name Checkpoint is shared. Neither party uses it alone.
  • Both parties are credited in every answer and on this page.
  • The Observatory builds and hosts. Lisa on Sable provides the reading engine and pays for every signed reading.
  • One Telegram owner, two key holders. Telegram knows one owner account per bot, so the bot is created from PrimeCircle's account, the party that hosts it, with two-step verification on. The bot token lives on the host and is shared with AG through a secure channel, never through chat. Ownership transfers to the other party on request; BotFather supports that.
  • If one party steps back, the other keeps the bot running, the name stays shared, and the one who steps back keeps the credit for what he built.
  • If it ever turns commercial in any form (sponsor, subscription, takeover), both parties talk first and split. The terms live in a private note both hold, not on this page.

Message shape

One message. The facts land within about two seconds. The same message is edited when the reading arrives, six to nine seconds later, so one question never gets two messages.

  1. Header: official, lookalike, or not in the registry, with source and time.
  2. The blocks, each with its source and time. Holders as two lines.
  3. Lisa's three sentences, receipt id, cost, verify link.
  4. Footer: the no-advice line, then Checkpoint · Lisa on Sable · Sable Observatory · built by PrimeCircle.
🟢 Official $SABLE
registry, two sources · since 14 Sep 19:30 UTC
0xf7894d31D569e6330592D346ecfeFdf4257F3EC1
🔐 Owner controlsnode, read 23:05 UTC
mint no · pause no · freeze no · code swap no · owner none
4 selectors unnamed in any signature database
📒 Holders since the mintledger, 23:05 UTC
558 above 0.001 SABLE · top 10 46.97% · top 50 84.43% · deployer 6.04% · burn 6.50%
+5 in the last hour · +1,237 arrived, -1,203 left in 24 h
📊 Holders, indexedgeckoterminal, 23:01 UTC
624 · top 10 50.21% · developer 8.06%
trade restriction none detected
differs from the ledger: counted at its own moment, with its own dust rule
💧 Marketdexscreener, live figure
price · market cap · liquidity (share of market cap)
volume 24 h · buys · sells · 24 h change
uniswap · 2 pairs · since 14 Sep 2026 · pool
🗣 Lisa reads itenclave, 23:18 UTC
Three sentences from the enclave appear here as a quote, written from the figures above and nothing else, shown whole or withheld whole.
🧾 receipt ca5682cb · $0.000096 · phala/gemma-4-26b-a4b-uncensored · confidential · TDX UpToDate · logging metadata-only
Reads public data and shows it. Says nothing about what to do with it. Not advice.
Checkpoint · Lisa on Sable · Sable Observatory · built by PrimeCircle

The real answer of 21 September 2026, 23:18 UTC, as the founder received it, market figures left out because they move by the minute. The namesakes, delta and "cannot be read" blocks sit between market and reading.

Verification before anyone else sees it

The expected answer per case is written down before the run. The run happens in a private group and its results are attached to this page.

  • Test set. The official $SABLE address. Every address in the counterfeit ledger (26 on 20 September 2026). A non-token address. A Solana address. An address on Base. A malformed string.
  • Failure drill one. Token function unreachable. The Observatory blocks must still go out.
  • Failure drill two. Enclave unreachable. The facts must still go out, the reading must say so.
  • Failure drill three. Daily cap reached. Same behaviour, different sentence.
  • Gate. Only after all three drills pass does the bot enter a public group.

Decisions

1
Name: Checkpoint, handle @CheckpointOnChainBot locked 21 Sep 2026
Name proposed by AG Ultra Magnus. "On chain" says where the numbers come from and reads in one second to someone who has never heard of us. Rejected: a "CA" handle, because outside crypto it reads as a place or a profession, and inside crypto "here is the CA" is the scammers' own sentence. The display name on every message is "Checkpoint". "Two Sources", AG's other candidate, becomes the name of the registry rule.
2
Trigger agreed
/check <address>, and replying to a message that holds an address. Passive scanning of every pasted address is off, because a busy group would spend the 20-a-minute budget on noise. Can be switched on per group later.
3
Languages agreed
English by default. The reading follows the asker when they add a language, /check <address> fr, one of en, fr, it, es, zh.
4
First group default
Whichever community group invites it. The official Sable group only when the team asks.

Verification log

21 September 2026, night, before any public group. The bot runs on the Observatory's server as @CheckpointOnChainBot. Composer runs asked for no readings, so no cost fell on AG beyond the three live checks the founder made himself.

  • Unit tests. 28, all green: composer, header rule, source labels, reading gate, budget, letters, formatting, Telegram rendering.
  • Live checks in Telegram. The official address, one lookalike, one non-token. All three answered as this page says. Two defects found and fixed the same night: the word rule had masked a descriptive "sell" inside Lisa's sentence, so the rule changed (quoted readings are shown whole or withheld whole, never edited, because a receipt stands behind them); and a contract that could not be read printed question marks instead of "not read".
  • The test set through the composer against live sources. 33 cases: the official address, every address in the counterfeit ledger (28, one of which is the official contract itself, which the watch lists too), a non-token, a Solana address, an address on Base, a malformed string. No composer error, every answer under the length limit, every verdict as expected.
  • Drill one, token function unreachable. Registry, controls and ledger went out; the token blocks said "not read".
  • Drill two, enclave unreachable. The facts went out; the reading said "no reading".
  • Drill three, daily cap. Not run live, it needs AG to trip it. The composer path is covered by a unit test with the cap response.
  • Also changed after the first checks. No reading is asked for when the token function returns no figures at all. A delta of zeros prints "nothing moved". A namesake without indexed liquidity prints "unranked". The header says since when an address is official, and for a lookalike when the counterfeit ledger last changed.

Open before publication

Before any public group

  • The contract creation block and the pair creation block, so the three launch moments carry numbers.
  • The holder reconciliation for one shared hour, ledger against GeckoTerminal, and the sentence that explains the difference.
  • The engine name is settled: the receipt prints phala/gemma-4-26b-a4b-uncensored, confidential tier, TDX.
  • The private ownership note, one page, both parties keep a copy.
  • The same test set through Telegram in a private group, and the letters once the bot has a passport key and a place on the allowlist.
  • Done 21 September: both dated disclosure lines are in /about and in the footer of this page.
  • The uptime monitor on the health URL, green for 24 hours.

After that: the spec with the exact message format, then the test set, then the Telegram layer.