At War with Luck
Source: Mark Spitznagel, *Safe Haven: Investing for Financial Storms*, Chapter 1, “At War with Luck”; original teaching treatment with recalculated examples.
The enterprise problem and today’s slice
People often call an asset “safe” after it survives one crisis, then discover in the next crisis that its protection was accidental, expensive, or absent. The consequence is worse than a bad label: a false haven encourages exposure precisely when capital needs to remain available.
Enterprise problem: an investor, founder, or operator must distinguish repeatable protection from a lucky outcome before the next bad contingency arrives.
Whole-course context: this seven-day course moves from first principles about compounding and one-path survival to a taxonomy and empirical tests of candidate safe havens.
Today’s slice: Chapter 1 defines risk by consequential loss, treats a safe haven as a payoff rather than a named asset, and turns “protection” into a falsifiable portfolio claim.
End-of-day evidence: you will produce a stated ruin boundary, a worked exposed-versus-protected payoff comparison, a repeatable lab record that separates one result from many controlled trials, and a page-audited inventory showing that Chapter 1 contains no graph, table, or data visual to reproduce.
Still unsolved: today does not determine which safe-haven payoff is best or how much to allocate; later chapters supply geometric accounting, path distributions, taxonomy, and comparative tests.
Key terms for a war with luck
Risk language becomes evasive when every fluctuation, forecast error, and permanent loss shares one word. These terms keep the chapter tied to economic consequences rather than a convenient statistic.
| Term | Plain meaning |
|---|---|
| Bad contingency | A possible event that causes a material loss if it occurs |
| Systematic risk | Loss that strikes many assets or activities together and is difficult to diversify away |
| Safe haven | A payoff that mitigates a portfolio's consequential bad contingencies |
| Risk mitigation | Changing exposure or payoffs so damaging outcomes hurt the whole less |
| Arithmetic return | A simple average of separate period returns |
| Compound annual growth rate | The constant annual rate that connects starting wealth to ending wealth through multiplication |
| Net portfolio effect | The change in the whole portfolio after both the cost and protective effect are included |
| Falsifiable claim | A statement that names an observation capable of showing it is wrong |
A safe haven is functional. Gold, cash, an option, spare capacity, a supplier contract, or an emergency fund is not inherently a haven; it earns that description only in relation to an exposure, a bad contingency, a horizon, and a price.
The chapter’s argument
The central problem is not merely that risk exists. It is that both taking too much risk and avoiding too much risk can destroy long-run wealth, creating what Spitznagel calls the great dilemma of risk.
Too much exposure makes a severe loss unrecoverable. Too little exposure can leave a pension, company, or household unable to grow assets faster than its obligations. A supposed compromise can combine weak growth with protection that disappears under stress. The task is therefore not “minimize risk” in isolation. It is to lower the cost of consequential losses without imposing an even larger cost on the compound growth of the whole.
This framing rejects prediction as the main defense. A perfect forecast would help, but a method that requires one is fragile because the forecast is precisely what is unavailable before a surprise. The controllable variables are payoff shape, exposure size, price paid for protection, liquidity, and the rule for continuing after loss.
The chapter advances three first principles:
- Investing unfolds sequentially through time. Each period begins with what survived the previous one.
- The practical objective is realized wealth over time, not a favorable score on a detached risk metric.
- If mitigation is genuinely cost-effective, adding it should raise the portfolio's compound growth across a broad, declared set of outcomes.
The third principle is intentionally demanding. A hedge can reduce volatility while lowering ending wealth; it can make money for reasons unrelated to protection; it can shine in a cherry-picked crisis and fail across repeated costs. None of those observations is sufficient to establish cost-effective risk mitigation.
The chapter begins from practice rather than from a named market model. Its autobiographical opening matters because it explains the research posture: losses threaten the capital base that makes later opportunities possible, so protection is not a decorative reduction in a statistic. At the same time, a practitioner’s record cannot prove the universal claim. A profitable history is one path, produced by a particular portfolio, policy, market sequence, and implementation. It motivates a conjecture; it does not exempt the conjecture from testing.
That distinction prevents an authority error. A learner should neither accept the method because an experienced manager reports success nor reject it because the examples are simplified. The proper response is to isolate the mechanism, derive an observable consequence, and ask where it fails. Chapter 1 supplies that epistemic discipline—how a claim can be challenged—before later chapters supply geometric accounting, resampling, classifications, and historical candidates.
The great dilemma as a constrained decision
Choosing between maximum exposure and maximum caution creates a false binary, and the consequence is a search for a vague middle that may inherit the costs of both extremes. The great dilemma is better written as a constrained decision: pursue compound growth while keeping specified losses inside a survivable boundary.
Let W_t be the capital or capability available at the start of period t, and let R_{t+1} be the whole-system return during the next period. The sequential update is:
W_{t+1} = W_t × (1 + R_{t+1})
This elementary multiplication carries the chapter’s first principle. A 50% loss changes the base on which every later opportunity operates. A later 50% gain does not restore the start: 1.00 × 0.50 × 1.50 = 0.75. Recovery from 0.50 to 1.00 requires a 100% gain. The asymmetry is arithmetic, not a psychological preference.
A decision record therefore needs two thresholds rather than one forecast:
| Threshold | Operational question | Example evidence |
|---|---|---|
| Continuation boundary | Below what wealth, runway, capacity, or health state can the next useful action no longer be taken? | Minimum funded ratio, months of runway, restored transactions per minute, cash needed for housing |
| Carry boundary | How much ordinary-state cost can protection impose before it prevents the objective it was meant to preserve? | Premium budget, forgone growth, duplicate capacity cost, time spent maintaining contingency plans |
The continuation boundary rejects protection that arrives too late. The carry boundary rejects protection so expensive that it quietly consumes the base in ordinary states. A cost-effective haven must work between them. It should reduce the consequential loss enough to preserve continuation while charging less than the compound value it saves across the declared experiment.
This is not the same as minimizing volatility. Volatility is dispersion around a return measure; it can be high while every relevant obligation remains funded, or low while a slow shortfall becomes irreversible. Nor is it the same as maximizing expected wealth in one period. The decision is path-aware because the next period’s choices depend on what survives this one.
The practical output is a bounded policy, not a universal asset ranking. Name the protected base, loss state, continuation boundary, carrying-cost ceiling, horizon, and review rule. If any field is missing, “safe” remains a mood rather than a testable property.
Why payoff comes before asset name
Asset labels create category errors because the same object can protect one portfolio and endanger another. The consequence is that investors compare reputations rather than conditional payoffs.
Suppose a manufacturer holds dollars but owes euros in three months. Dollar cash may be stable in its own units while leaving the euro obligation exposed. A currency forward that looks risky alone may stabilize the firm's actual liability. Likewise, spare server capacity looks idle on a normal day but becomes valuable when demand surges; a second supplier is useful only if it does not share the first supplier's failure mode.
Define a candidate haven with four questions:
| Question | Evidence required |
|---|---|
| What is being protected? | Named portfolio, obligation, capital base, or operating capability |
| From which contingency? | Explicit loss event or state, not “uncertainty” in general |
| What does the payoff do then? | Conditional cash flow, preserved capacity, or reduced loss |
| What does that protection cost elsewhere? | Premium, carry, opportunity cost, complexity, or counterparty exposure |
Only the combined payoff can answer whether the shelter works. Standalone performance is incomplete evidence because a deliberately losing hedge may still improve the whole, while a profitable “defensive” asset may simply add another source of risk.
Worked example: an attractive average that fails to compound
Averages can reward a payoff that quietly consumes its capital base. A six-state teaching game makes the distinction inspectable without relying on market history.
The exposed strategy has one -40% outcome and five +10% outcomes, all equally likely. Its arithmetic average return is:
(-40% + 5 × 10%) / 6 = +1.67%
Now add protection that costs 2 percentage points in the five ordinary states and pays 8 percentage points in the bad state. The protected portfolio therefore has one -32% outcome and five +8% outcomes. The protection by itself has a negative arithmetic expectation:
(8% - 5 × 2%) / 6 = -0.33%
The combined portfolio's arithmetic average falls to:
(-32% + 5 × 8%) / 6 = +1.33%
On an arithmetic scoreboard, protection looks like a drag. But one cycle containing each state changes the comparison:
| Strategy | Six-period wealth multiplier | Geometric return per period |
|---|---|---|
| Exposed | 0.60 × 1.10^5 = 0.9663 | about -0.57% |
| Protected | 0.68 × 1.08^5 = 0.9991 | about -0.02% |
The protection loses money as a standalone component and lowers the arithmetic average, yet it nearly removes the compound loss of the whole. This does not prove the protection is good in reality: the states, equal probabilities, fixed cost, and fixed payoff were stipulated. It does demonstrate the mechanism a valid test must look for.
Falsification before persuasion
Protective stories become dangerous when a favorable observation is treated as proof. The scientific discipline in this chapter is to state a consequence that can fail and to search for that failure.
The safe-haven hypothesis can be written in the form called modus tollens, or denying the consequence:
- If a strategy cost-effectively mitigates the portfolio's risk, then adding it raises the portfolio's compound growth across the declared test range.
- Adding it does not raise compound growth across that range.
- Therefore, it did not cost-effectively mitigate risk under that test.
The reverse does not hold automatically. If a strategy raises compound growth, it may have done so by adding ordinary return rather than by mitigating the stated contingency. The claim needs attribution: show the exposed loss, show the conditional offset, include the cost, and preserve out-of-sample observations.
This approach favors transparent dice and synthetic payoffs at the start because their generator is known. A simple model cannot reproduce markets, but it exposes the logic. Historical data enters later, after the proposed mechanism and failure condition have been declared.
A falsification record that can survive hindsight
A protective claim can be rewritten after every surprise unless its test is recorded before the result, and the consequence is a story that never loses. A falsification record makes the hypothesis, observable consequence, comparison, and rejection rule reviewable as separate fields.
| Field | What to write before observing results | Why it matters |
|---|---|---|
| Protected object | Exact portfolio, liability, runway, service, or household capability | Prevents changing the object after a loss |
| Bad contingency | State in which the unprotected object suffers material harm | Prevents calling every profitable state “protection” |
| Proposed mechanism | Contractual or operational reason the payoff should arrive in that state | Separates causal explanation from correlation |
| Whole-system consequence | Measurable improvement after premium, carry, and implementation cost | Keeps the scoreboard on the combined path |
| Test range | Horizon, scenarios, parameter range, and comparison baseline | Prevents cherry-picking one period |
| Rejection rule | Observation that causes downgrade, redesign, or rejection | Gives the claim a way to be wrong |
| Attribution check | Evidence that improvement came from mitigating the named loss | Blocks the fallacy of affirming the consequent |
Consider a proposed backup supplier. The hypothesis is not “supplier B is diversified.” It is: if B cost-effectively mitigates the loss of supplier A, then a declared A-outage test should preserve a minimum production rate after B’s reservation and switching costs. Failure to preserve that rate rejects the claim for that outage mechanism. Passing does not prove universal resilience: B may fail with A during a port closure, lack capacity in a regional power loss, or help only because demand happened to be low.
The same logic applies to a financial hedge. Suppose its addition raises compound growth. That observation is compatible with at least three explanations: it paid in the specified crash state, it carried unrelated positive return, or the sample path happened to favor it. Only the first supports the named mitigation claim. The attribution check compares conditional payoff, cost, and the unprotected loss state rather than treating higher ending wealth as self-explanatory.
Good falsification is also proportionate. One failed observation can refute a precisely universal claim, but a noisy estimate does not justify certainty about a changing system. Record measurement error, missing states, and data revisions. The decision can be “rejected under this test,” “not yet rejected,” or “outside scope”; it need not pretend that a finite experiment produces final truth.
Deductive dice and the transparent generator
Historical patterns invite hidden assumptions about changing probabilities, and the consequence is an argument whose failure can always be blamed on the data. Chapter 1 turns first to dice because the generator—the rule producing outcomes—is visible, letting deduction and observation be separated cleanly.
A fair six-sided die has six declared, equally likely faces. From that generator, the probability of at least one six in four independent rolls is calculated before any rolling:
1 - (5/6)^4 ≈ 51.8%
For a pair of fair dice, a double-six has probability 1/36 on one roll. The probability of at least one double-six in 24 independent rolls is:
1 - (35/36)^24 ≈ 49.1%
The Chevalier de Méré problem discussed in the chapter uses this contrast: wagers that look parallel are on opposite sides of 50%. The table below is a course-authored calculation of the prose example, not a table reproduced from the book.
| Declared experiment | One-trial event probability | Number of trials | Probability of at least one event |
|---|---|---|---|
| At least one six | 1/6 | 4 | about 51.8% |
| At least one double-six | 1/36 | 24 | about 49.1% |
Repeated observations can estimate an unknown frequency, but they answer a different question. Starting with a known fair die and deriving consequences is deductive: if the premises hold, the probability follows. Starting with rolls and estimating the generator is inductive: the conclusion remains provisional because biased dice, dependence, recording errors, or a small sample may fit the observations too.
The distinction explains why the chapter wants both directions. Deduction exposes exactly which assumptions make a proposed haven work. Experiment then compares those consequences with observations. When they disagree, the model, mechanism, measurement, or scope must change. Agreement earns continued testing, not proof.
Dice also clarify aggregation. A person living through one irreplaceable path has a sample size of one for that life-defining decision. A casino can pool many wagers whose dependence is controlled and can approach an ensemble frequency. Insurance and organizational pooling may expand the effective sample, but common shocks shrink it again. One hundred stores sharing one payment processor are not one hundred independent operational trials when that processor fails.
The limits must remain visible. Real markets do not arrive with certified fair generators. Probabilities drift; payoffs depend on liquidity and price; adverse states cluster; participants adapt; and the most damaging state may be absent from the sample. Dice are valuable precisely because they do not pretend to estimate those facts. They are a transparent instrument for checking reasoning before opaque historical evidence is introduced.
Interactive lab: separate protection from a lucky path
One realized path cannot reveal whether a hedge improved the process or merely happened to win. This lab compares the same exposed and protected payoff rules across deterministic batches so the claim can be repeated and challenged.
Provenance: this is an original conceptual teaching reconstruction. Chapter 1 contains no source graph, table, or data visual to transcribe. The lab operationalizes the chapter’s prose claims about sequential compounding, risk mitigation, deduction, and repeatability; its six-state payoff values, controls, simulation design, and chart are course-authored.
The horizontal axis is trial number and the vertical axis is compounded wealth. Distinct line styles identify exposed and protected paths; summary readouts report arithmetic return, compound growth, the worst protected ending, and the share of fixed-seed paths in which protection improved terminal wealth. Bad-event probability changes how often the fixed 40% loss occurs. Protection cost changes the ordinary-state drag while the bad-state offset remains fixed at eight percentage points. The horizon, path count, loss size, protection payoff, and deterministic seeds stay fixed so each slider isolates one declared mechanism.
Use a falsifiable protocol:
- Reset and record every control, the two growth rates, the worst path, and the improvement share.
- Increase bad-event probability one step at a time while holding protection cost fixed. Record where conditional protection begins to improve the compound rate.
- Restore the probability and increase protection cost one step at a time until the protected compound rate no longer exceeds the exposed rate.
- Test the four endpoint combinations of probability and cost. Explain why the same fixed payoff can help in one declared process and hurt in another.
- State a probability-and-cost range before sweeping it. Reject the cost-effective claim if it fails the declared portfolio consequence within that range.
Interpret the lab at the portfolio level. A negative standalone hedge return is not a failure if the combined path compounds better, and a profitable hedge is not proof if it did not offset the named loss. The simulation uses independent synthetic events, constant probabilities, fixed payoffs, frictionless rebalancing, and a finite horizon. It omits regime change, clustered crises, liquidity gaps, taxes, counterparty failure, and estimation error; no setting estimates a real asset or recommends a trade.
Economics application: obligations make risk concrete
Economic policy becomes abstract when risk is reduced to market volatility. The consequence appears later as pensions, insurers, or public budgets failing to meet obligations that were always concrete.
A pension plan should name the liability path it must fund, the loss that would impair that funding, and the horizon over which assets must recover. Holding only low-return assets can enlarge the funding gap; reaching for return can expose the plan to a deep drawdown just before benefits are due. A candidate mitigation belongs in the whole funding model, including fees, collateral needs, and the possibility that supposedly diversified assets fall together.
The useful policy question is not “Did the hedge profit in the last recession?” It is “Across declared adverse funding paths, did the hedge preserve the capital base enough to improve the plan's compound funding trajectory after cost?” That question can be falsified and audited.
At the macroeconomic level, this distinction separates a stabilizer from a subsidy with a defensive label. A lender-of-last-resort facility, deposit guarantee, or automatic fiscal transfer should name the discontinuity it prevents: disorderly liquidation, payment-system collapse, or a temporary income shock becoming permanent unemployment. Its ordinary-state cost includes fees, distorted incentives, political allocation, and correlated claims on the guarantor.
Use the falsification record at the institutional level. State the protected function, trigger, payout channel, fiscal or balance-sheet cost, and terminal evidence. Then test a positive path and at least one common-mode failure in which many claims arrive together. A policy is not validated merely because output later recovered; attribution must show that it preserved the named capability rather than coinciding with unrelated recovery.
Startup application: preserve the next experiment
Startups often optimize expected growth while treating runway as a forecast input. The consequence is that one clustered delay in revenue, financing, or product delivery can remove the option to learn.
Define the protected object as months of decision-making capacity. A cash reserve, staged hiring plan, cloud-spend cap, or reversible vendor contract is useful only if it prevents a named runway breach at an acceptable opportunity cost. Keeping all cash idle may itself be ruinous if it prevents a necessary product launch; committing all cash to growth may leave no second attempt.
A founder can test a mitigation with three paths that use the same total sales shortfall: spread evenly, clustered early, and clustered just before a financing milestone. Record cash after every month and the first irreversible commitment. The safer plan is the one that preserves a viable next action, not the one with the calmest spreadsheet.
Make the great dilemma explicit. Holding twelve months of cash may protect against a financing delay while sacrificing the hiring or distribution experiment needed to reach product-market evidence. Holding six weeks may maximize current speed while making one delayed enterprise invoice terminal. The useful variable is not “conservatism”; it is the minimum buffer that preserves a predeclared next experiment across the tested shocks after its opportunity cost.
A startup record should include customer concentration, committed payroll, cancellable and irreversible spending, financing dependencies, and the lead time of each mitigation. The falsifier for a credit line is not that cash fell; it is that the line was unavailable, too small, or covenant-blocked in the named runway breach. The falsifier for a staged hiring plan is that it failed to preserve the milestone capacity the delay required.
Business application: protect the bottleneck, not the label
Business continuity plans fail when they purchase generic “resilience” without locating the bottleneck that stops delivery. The consequence is expensive redundancy that shares the same hidden dependency.
For a product reliant on one manufacturer, a second supplier is not a haven if both depend on the same port, tooling vendor, or power grid. Map the revenue-producing flow, identify the bad contingency, and express protection as a payoff: units delivered, days of capacity preserved, or cash released under disruption. Include minimum-order costs and quality failures in ordinary states.
The falsifier is direct. If the supposed backup cannot preserve the stated throughput during the shared disruption, it is not protection against that contingency, whatever its procurement category says.
Apply the same structure to cyber recovery. A backup is a stored copy; a recovery capability is the tested payoff of restoring authoritative state within a required time. If backup credentials share the compromised identity plane, if restore time exceeds the business interruption boundary, or if the recovered data cannot be reconciled, the “backup” label does not satisfy the contingency.
Measure ordinary-state cost and bad-state effect in the same unit where possible. For a fulfillment operation, cost may be annual reservation spend and effect may be gross margin or customer orders preserved during a declared outage. Where a common unit would be dishonest, keep a constraint table: maximum cost, minimum throughput, recovery-time objective, and prohibited failure. A board can then reject a control without collapsing safety into one synthetic score.
Daily-life application: buy options on your own future
Personal safety can become excessive avoidance when every uncertain activity is rejected. The consequence is a life that is protected from both loss and worthwhile opportunity.
Use the same great-dilemma framing for cash, time, health, and commitments. An emergency fund protects against a short income interruption; an open evening protects recovery and caregiving capacity; insurance transfers losses too large to self-fund; a cancellable booking preserves the option to change. Each has a cost, and each should name the event it covers.
A practical review asks: what must remain possible after a bad week, what buffer preserves it, and when does maintaining the buffer cost more than the flexibility is worth? This is decision structure, not personalized financial or medical advice.
The protected object can be nonfinancial. Sleep, mobility, medication access, caregiving coverage, and trusted relationships are bases from which later choices are made. A spare key is useful against lockout but not eviction; a copied document helps after loss but not if it exposes identity data; an empty evening can absorb a delay but not a long illness. Naming the contingency prevents one small precaution from being mistaken for universal security.
Run a modest household pre-mortem: choose one interruption, state what must remain possible, list the first dependency that would fail, and identify a low-carry response. Then name its shared dependency and expiration condition. The point is not to optimize a person’s life into a portfolio. It is to preserve agency without allowing protection work to consume the life it is supposed to support.
Limitations and guardrails
Simple deduction can reveal an invalid inference while still failing to capture the world. The danger is replacing one dogma with a beautifully transparent toy model.
Real bad events are dependent, prices gap, protection can disappear, counterparties fail, and behavior changes after losses. Compound growth is also not the only human value: legal duties, consumption needs, fairness, and survival constraints may override wealth maximization. A hedge that improves a long-horizon median can still impose an unacceptable short-horizon loss.
Use several models, preserve the unprotected baseline, and report lower-tail paths alongside the center. Declare what observation would reject the claim before inspecting the result. The course explains reasoning about safe havens; it does not identify a specific suitable investment.
Chapter 1 also cannot supply empirical calibration. It offers no asset-return series, transaction-cost model, liquidity stress, tax treatment, option surface, or current market price. It cannot establish that a historical relationship will persist, that a counterparty will perform, or that a stated capital objective captures every legal and human obligation. Those omissions are not defects to conceal; they bound what today’s deduction can claim.
Page-by-page source-visual inventory
Inventing a book figure where none exists would turn a source audit into false evidence, and the consequence would be a learner unable to distinguish Spitznagel’s material from course scaffolding. Every physical PDF page in the delegated Chapter 1 range was therefore rendered and visually inspected, not merely searched through extracted text.
| Physical PDF page(s) | Printed page(s) | Visual finding | Course treatment |
|---|---|---|---|
| 21 | 3 | Decorative chapter-opening die above the title; no axes, values, table, or analytical encoding | Excluded from the graph/table/data-visual inventory |
| 22–45 | 4–27 | Prose, inline arithmetic relationships, and bulleted logical syllogisms only; no graph, table, plotted distribution, or data figure | Arguments explained in prose and course-authored worked calculations; no source figure claimed |
| 46 | None shown | Blank transition page | No course artifact |
Exact Chapter 1 inventory: 0 source graphs, 0 source tables, and 0 source data visuals across physical PDF pages 21–46. The decorative die is editorial artwork, not an analytical figure. The existing safe-haven-ch1-luck lab remains the only Day 1 lab and is explicitly labeled an original teaching reconstruction.
This zero count is a positive source result, not missing work. One-to-one visual coverage means reproducing every analytical source visual exactly once and manufacturing none. Chapter 1’s contribution is conceptual: the great dilemma, sequential multiplication, a cost-effectiveness hypothesis, modus tollens, and transparent deductive dice. Later chapters introduce the visual taxonomies, distributions, bootstrap paths, and cost-effectiveness planes.
Source note
The chapter structure and core claims are paraphrased from Chapter 1 of Mark Spitznagel's Safe Haven (Wiley, 2021), printed pages 3–27 and physical PDF pages 21–45: the practitioner’s “war with luck,” the functional definition of a safe haven, the great dilemma of risk, sequential investing, wealth over time as the practical scoreboard, cost-effective mitigation, falsification through modus tollens, and deductive dice as a transparent method. Physical PDF page 46 is blank. The six-state worked example, probability table, falsification record, interactive lab, and cross-domain applications are original teaching constructions built to expose those claims without reproducing the book's prose or pretending to be book figures.
Key takeaways
The first chapter replaces a comforting asset label with a hard portfolio test. Protection has economic meaning only when it changes the consequences of a named bad state after all costs are included.
- Risk is exposure to consequential bad contingencies, not a synonym for volatility.
- A safe haven is a conditional payoff in relation to a portfolio, not an asset class by reputation.
- The objective is cost-effective mitigation: better compound growth of the whole, not merely smaller fluctuations.
- Prediction is optional; payoff structure, exposure, and price are controllable.
- A favorable outcome cannot confirm a protective mechanism, but a failed declared consequence can reject it.
- Transparent models are useful when their assumptions and falsifiers remain visible.
Checklist
Mastery means being able to challenge a protection claim before capital depends on it. Complete each item with a specific exposure rather than a generic statement.
- [ ] I can name the capital base or capability being protected.
- [ ] I can state the bad contingency and the ruin boundary.
- [ ] I can describe the candidate haven as a conditional payoff.
- [ ] I can include premium, carry, opportunity cost, and failure modes.
- [ ] I can calculate arithmetic and compound results for the six-state example.
- [ ] I can state an observation that would falsify the cost-effective claim.
- [ ] I can use the lab protocol without treating one seed as proof.
- [ ] I can explain why the lesson is not an investment recommendation.