USER MANUAL · COMPANION eBOOK

SOVEREIGN GLIDEPATH

A practical guide to a Guyton-Klinger guardrail retirement dashboard

Version 1.0.133 · Edition XXIII

Foreword

This book is two things at once. It is a user manual for the Sovereign Glidepath, a single-page retirement dashboard that lives in your browser. It is also a short companion eBook explaining why the dashboard is built the way it is — the history of the ideas behind it, the mathematics that drive the directives on screen, and the everyday discipline of using it well.

Retirement planning has a peculiar problem. The numbers are simple enough that anyone can sketch them on a napkin, but the consequences of getting them wrong are not recoverable. You do not get a second retirement. The desk does not try to predict the future; it tries to give you a calm, repeatable response to whatever the future delivers.

Read Part I if you want the story. Skip to Part III if you only want to use the tool. Return to Part IV when you want to know why a particular number on the screen is the colour it is.

Part I — Why this desk exists

1. The retirement income problem

When you are saving for retirement the goal is straightforward: own more next year than you did this year. When you are spending in retirement, the goal becomes paradoxical. You want to draw enough to live well, but not so much that a poor decade of returns leaves you destitute in your eighties. Worse, the markets do not deliver their long-run average smoothly. They lurch. The order in which good and bad years arrive matters enormously — this is the famous sequence-of-returns risk.

Two retirees with identical average returns over thirty years can finish with wildly different outcomes if one of them happened to retire on the eve of a crash. A static spending plan is, in effect, a bet that the first few years of your retirement will be kind. The Sovereign Glidepath is built on the opposite assumption: spending must respond to conditions, calmly and according to pre-agreed rules.

2. From the 4% Rule to Guyton-Klinger guardrails

In 1994 the American financial planner William Bengen published a study that became known as the 4% Rule. Using historical US data back to 1926, he showed that a retiree who withdrew 4% of their starting portfolio in year one, and then increased that pound figure for inflation each subsequent year, would have survived every 30-year rolling period in the dataset. It was a brilliant piece of work and an enormous step forward.

But the 4% Rule has two well-known weaknesses. First, it is backward-looking and inflexible: it ignores what your portfolio actually does after you retire. If markets crash in year two you keep drawing the same inflation-adjusted pound figure, accelerating your ruin. Second, it is conservative to the point of waste: in most historical paths the retiree died with more money than they started with — money that could have funded a richer life.

In 2006 Jonathan Guyton and William Klinger published a paper in the Journal of Financial Planning titled “Decision Rules and Maximum Initial Withdrawal Rates”. Their insight was elegant: do not fix the pound figure, fix the rules. They proposed a set of guardrails that adjust spending up or down whenever the current withdrawal rate drifts too far from its target.

The two rules the desk applies are the Capital Preservation Rule and the Prosperity Rule. If your realised withdrawal rate climbs 20% above the target — typically because the portfolio fell — you cut spending by 10%. If it falls 20% below the target — typically because the portfolio rose — you may increase spending by 10%. Over a full retirement these small, rule-based nudges have been shown in subsequent research to support starting withdrawal rates of roughly 5.0–5.5% with the same historical success rate as a rigid 4% draw.

3. Why two buckets beat three

The bucket approach to retirement income is older than guardrails. The classical formulation, popularised by Harold Evensky in the 1980s and expanded by Ray Lucia in the 2000s, uses three buckets: cash for the next 1–2 years, bonds for years 3–10, and equities for everything beyond. The intuition is that you should never have to sell shares during a slump because the middle bucket bridges you across.

It is a tidy story but it has problems. First, the middle bucket adds operational complexity for relatively little benefit. You now have to decide when to refill bonds from equities, when to spend bonds instead of cash, and how to handle rising-rate environments where bonds and equities fall together (as in 2022). Second, the bond bucket can drag long-run returns by ten or twenty basis points a year for a thirty-year retirement. Third, and most importantly, the bond bucket encourages the fiction that bonds are safe. They are not always safe; they are different.

The Sovereign Glidepath uses a deliberately simpler two-bucket model: a Cash Shield sized to fund the next 12–36 months of spending, and a Global Equity bucket for everything else. The guardrails decide which bucket to draw from this quarter. When markets are calm you sell equities; when they are in drawdown you spend from cash; when they are recovering you sell equities to refill the cash. Three rules, two pots, one ritual.

Part II — The toolkit at a glance

4. Anatomy of the dashboard

The desk is divided into seven numbered panes arranged top-to-bottom, plus two hidden panes reached by double-click shortcuts, plus a set of standalone Companion Apps (the Accumulation Simulator, the Risk Simulator, and the Comparison Builder) that open in their own tab or window, launched from Pane 2. Everything you ever do happens in pane 1; everything else is the machine reasoning about what you typed.

1. Parameters. Your inputs. Target Horizon Age, current Modeling Age, the two pot balances, Assumed Real Growth Rate, Cash Real Return, Inflation / CPI Assumption (independent of the Risk Simulator's own inflation slider), Cash Buffer Target, Legacy / Inheritance Target, Currency, Reporting Period label and a real Period End Date, Initial Annual Withdrawal — Frozen Baseline, and the Withdrawal Recorded split (Equities / Cash, plus an optional Rebalance Move). While editing an existing row you get three buttons — Update Entry, Discard Changes, and Exit Edit / New Entry — instead of the usual Commit / Cancel pair.

2. Intelligence Diagnostics. The engine's reading of your inputs: total capital, peak drawdown vs ATH, the Fun Bucket surplus, Shield Target in £ and months (chapter 46), Guyton-Klinger target vs realised withdrawal rate, current guardrail state, actual cash shield runway, actuarial amortisation matrix, and market momentum vector. The Scenario Stress Test slider lives at the bottom of this pane — see chapter 9 for what it now shows. Below that sits the Companion Apps section, from which the Accumulation Simulator, Risk Simulator, and Comparison Builder all launch. The Risk Simulator and Comparison Builder both open pre-filled with a live snapshot of your Pane 1 figures; the Accumulation Simulator deliberately opens with its own small, standalone starting defaults instead (chapter 43) — it's built to model someone decades from retirement, so your own real pot figures wouldn't be a useful starting point there. Double-clicking this pane's header (Pane 2 title) opens the hidden State Test Presets pane — eight one-click buttons that populate Pane 1 with a canonical recipe for each directive state, for testing and verification without touching your real ledger. Closing it (double-click again) automatically reverts Pane 1 back to your real committed values.

3. Actionable Brokerage Desk Directives. A plain-English instruction, refreshed every keystroke, telling you which bucket to draw from this quarter and whether a guardrail adjustment is in force. A Defensive-Draw Mode selector (Strict / Standard / Aggressive) shows all three modes' bucket recommendations side by side; where a locking narrative state overrides a mode's own default, that mode's text renders struck through with an "(overridden — see narrative)" flag, so you can see at a glance when the narrative — not your selected mode — is deciding the bucket. See chapter 8 for the full directive-state table.

4. Historical Trend Visualizer Matrix. A chart of every committed ledger entry over time: total capital, stored ATH baseline, and money-market balance, with period labels on the X axis.

5. Can I Afford This? A hypothetical, non-committing "Instant Impact Calculator" for a one-off expense, plus a Commit as Special-Event Withdrawal flow when the spend is real (chapter 29).

6. Extraordinary Inflow. Logs a one-off lump sum landing in your accounts — a property sale, an inheritance, a windfall — adding it to the chosen pot and re-anchoring the Stored ATH Baseline upward (chapter 40).

7. Historical Timeline Ledger. Every committed snapshot. You can re-open any row to edit it, and the Target Horizon Age, growth rate and shield runway you used at the time are restored alongside the balances. The ledger is laid out in six columns: Timeline (period, age, phase badge); Asset Pools (Equities and Cash); Portfolio Total (Total and ATH); Drawdown from ATH (peak-to-trough decline — 0% means a new ATH — colour-coded by magnitude: green < 5%, muted 5–10%, amber 10–20%, red > 20%); Withdrawal Recorded (Equities/Cash split and realised WR %); and Status & Controls (execution rule with Edit / Del beneath).

5. Glossary

Money Market (MM) fund. An open-ended fund holding very short-dated, high-quality debt (bank deposits, T-bills, commercial paper). It aims to keep a stable unit price and pays interest close to the central-bank rate. It is the closest thing to cash that still earns a yield.

Tracker / index fund. A passively managed fund that buys every constituent of a published index (e.g. FTSE All-World, S&P 500) in proportion. No stock picking, no manager view. Total fees are typically 0.07–0.25% per year.

SIPP. Self-Invested Personal Pension. A UK pension wrapper that lets you hold a wide range of investments and draw flexibly from age 55 (rising to 57 in 2028).

Drawdown (pot). Money already moved out of accumulation and available for income.

Drawdown (market). The peak-to-trough fall of an asset, expressed as a percentage.

All-Time High (ATH). The highest total capital your ledger has ever recorded. The desk uses it as the denominator for the Peak Drawdown reading. The desk maintains the ATH automatically: when you commit a ledger entry whose Total Capital exceeds the stored ATH, the ATH is raised to match. You never need to raise it by hand. The only time you should touch the ATH manually is to lower it after an extraordinary withdrawal (see chapter 7).

Sequence-of-returns risk. The risk that a poor run of returns in the first decade of retirement permanently damages portfolio longevity, even if the long-run average is fine.

Go-Go / Go-Slow / No-Go. Michael Stein's three retirement phases (1998). Go-Go: ages up to ~75, high spending, travel. Go-Slow: 76–85, spending tapers. No-Go: 86+, care costs dominate, discretionary spend collapses.

Guyton-Klinger guardrails. Decision rules that adjust withdrawals upward when the realised rate drifts well below target (Prosperity) and downward when it drifts well above (Preservation).

Part III — Operating the desk

6. First-time setup, step by step

Set aside thirty minutes. Have a recent statement from each of your investment accounts to hand, plus a rough idea of what you want to spend in the coming year.

Step 1. Open the file and accept the legal notice. Tick the acknowledgement box and click Accept & Enter Dashboard. If you trust this device, also tick Don't show this again.

Step 2. Set your Target Horizon Age. This is the age to which you want the plan to fund you. The default is 95. See chapter 10 for why you might revise it later.

Step 3. Set your Modeling Age slider to your current age. The phase badge (Go-Go / Go-Slow / No-Go) updates automatically.

Step 4. Set your Assumed Growth Rate. This is a real (above-inflation) expected return for your equity bucket. The default 2.5% is deliberately conservative. Many long-term studies of global equities support 4–5% real, but a planning model should never use the optimistic end.

Step 5. Set your Cash Buffer Target in months. The number of months of spending you want held in cash when markets are calm. The author uses 30 months. The default is 36.

Step 6. Type in your Global Equities balance and your Cash Pot balance. Use today's value. The desk will mask these as £ amounts when the field loses focus.

Step 7. Type in your Target Yearly Withdrawal. Your desired gross annual spend from the portfolio.

Step 8. Seed your Stored All-Time High Baseline (first entry only). For your very first ledger entry, set the ATH equal to your current Total Capital. After that, leave the field alone: when you commit an entry whose Total Capital is a new high, the desk raises the stored ATH for you automatically. The only manual change you should ever make to the ATH is a downward one, and only after an extraordinary withdrawal (see chapter 7).

Step 9. Give the entry a label (e.g. Q1 2026) and click Commit Entry to Ledger. Your first ledger row is now stored. You should see the chart in pane 4 acquire its first datapoint.

7. The quarterly ritual

Set a recurring calendar appointment, ideally on the first business day of each quarter. Allow fifteen minutes. The procedure never changes:

• Open the desk. Confirm the most recent ledger entry is loaded.

• Update Modeling Age if a birthday has passed.

• Type in today's Global Equities balance and today's Cash Pot balance.

Do not touch the ATH field. The desk will lift the stored ATH automatically when you commit, if your new Total Capital is a fresh high. This is by design — see the box below for the one exception.

• Re-enter your Target Yearly Withdrawal if your spending plan has changed (otherwise leave it).

• Read pane 3. Place the trades it tells you to place.

• Label the entry with the period and click Commit Entry to Ledger.

• Export a backup (the floppy-disk icon, top right) and store it somewhere safe.

8. Reading the directives

Pane 3 displays exactly one of the ten canonical directive states defined in the engine's state registry. Seven of them lock the withdrawal source through the narrative itself; three are non-locking and defer to your selected Defensive-Draw Mode. The Guyton-Klinger Preservation / Prosperity banners are overlays on top of whichever state is active — they adjust the amount by ±10%, they are not states in their own right. The coloured left border tells you the urgency:

Border State (as named in the app) Source Meaning
Green Normal Draw Non-locking Markets are calm, cash is at target. Fund spending from your selected mode's bucket.
Green Comfortable Amortization Non-locking Drawdown against a stale ATH, but 3+ years of surplus beyond lifetime needs and legacy. Guardrail cuts are suspended; draw normally.
Purple No-Go Amortization Non-locking Age above ~85 and no deficit. Guardrails off; draw the target amount and run the plan down.
Blue Peak Refill Equities ATH territory with the shield below target. Sell equities and sweep into cash to top the shield up.
Blue Recovery Wave Refill Equities Equities rising after a fall. Sell a little extra to refill cash.
Blue Refilling Shield (banner headline: "Normal Draw — Shield Below Target") Equities Markets calm but the shield is below target and momentum is not ascending. Draw from equities, refill on the next up-move.
Blue Reverse-Shielding Cash Markets down but cash is well above target. Spend cash and buy equities with the surplus.
Amber Preservation (banner headline: "Freeze Equities — Draw from Cash") Cash Meaningful drawdown. Stop selling equities; spend cash.
Red Shield Deficit Equities Cash exhausted mid-drawdown. Empty the pot and sell the remainder from equities.
Red Exhaustion (banner headline: "Shield Deficit / Exhaustion") Equities Both buckets empty. The plan cannot fund the withdrawal.

9. The stress slider

Tucked into pane 2, the Scenario Stress Test slider lets you ask “what would my directive look like if global equities fell another X% tomorrow?”. Drag it from 0 to 50%. A dashed HYPOTHETICAL — X% equities drop preview box appears, showing the stressed Equities balance, stressed Total Capital, stressed drawdown vs ATH, and — critically — what your Fun Bucket Balance and Directive State would become under the hypothetical drop, always shown alongside the real figures so you can see the before/after at a glance. If the hypothetical narrative state differs from your real one (e.g. a slide from Normal Draw into Preservation), a highlighted "Directive would change: X → Y" pane appears beneath it.

Nothing here writes back to your real state — Pane 1's actual values, Pane 3's live directive, and every committed calculation continue to use your real, unstressed figures throughout. To stress-test a hypothetical position properly, open the Risk Simulator from the Companion Apps section at the foot of Pane 2 — it opens with its own live snapshot of your real plan, and its Equities/Cash fields can be edited independently there without touching this slider or your real figures.

It is the cheapest, fastest financial education available. Drag to 30% and watch the guardrail flip from Prosperity to Preservation. Drag to 50% and watch the shield runway shorten as the realised withdrawal rate balloons.

Use it once a quarter as part of the ritual. If the directive at 30% stress is something you could live with, you are well calibrated. If it terrifies you, you may be carrying too much equity for your temperament.

10. Adjusting Target Horizon Age

The Target Horizon Age is the single most powerful lever in the desk. Every figure in the Fun Bucket — and ultimately every Prosperity bonus the guardrails will award you — is computed against the present value of withdrawals from now until that age.

When you are healthy and 65, 95 is a reasonable default. It buys you longevity insurance: if you do live to 95, the plan funded you. The cost is that in your seventies you may have more money than your lifestyle uses.

When circumstances change, the horizon should change. If at 80 your doctor gives you a five-year prognosis, holding the horizon at 95 is actively harmful: it locks money away that could fund care, comfort, or a final round of generosity to family. Drop the horizon to 86 or 87 and the desk will immediately permit a much larger sustainable draw. This is not the model failing; it is the model behaving exactly as designed when given honest inputs.

Part IV — The mathematics under the hood

11. Drawdown, target rate, realised rate

Let E be your equity balance, C your cash balance, T = E + C total capital, A the stored ATH baseline, and W the target yearly withdrawal. The desk computes:

  Peak Drawdown = (A − T) / A × 100
  Target WR = W / A × 100
  Realised WR = W / T × 100

The target rate is calibrated against your high-water mark; the realised rate against your current position. When they diverge, the guardrail rules engage. Because A is a high-water mark, it only ever moves upward on its own — and only at commit time, never mid-edit. The single legitimate downward move is the manual extraordinary-withdrawal adjustment described in chapter 7.

12. The Guyton-Klinger trigger logic

In the Go-Go and Go-Slow phases the desk applies:

  If Realised WR ≥ 1.20 × Target WR  →  Preservation: multiply this quarter's draw by 0.90.
  If Realised WR ≤ 0.80 × Target WR  →  Prosperity: multiply this quarter's draw by 1.10.
  Otherwise  →  Normal: draw unchanged.

In the No-Go phase the guardrails are disabled and the desk shifts to an amortisation directive: spend down the surplus deliberately.

13. The Fun Bucket

The Fun Bucket is the present value of all future annual withdrawals you have planned, discounted at a blended real growth rate. It is computed as an annuity-due (beginning-of-period) factor, reflecting that withdrawals are taken at the start of each period rather than the end:

  Baseline Need = W × (1 − (1 + g)−n) / g × (1 + g)
  Fun Bucket = max(0, T − Baseline Need)

where n = Target Horizon Age − Modeling Age, and g is a blended real rate — not a single growth figure, but your Equities and Cash balances weighted by their own real returns: g = (Equities × Assumed Real Growth Rate + Cash × Cash Real Return) / Total Capital. This is the same blending approach used elsewhere in the app (e.g. Pane 2's Amortization Matrix). One consequence worth knowing: because g depends on the actual Equities/Cash split, the surplus shown can shift slightly for reasons other than the raw pound amount involved — see the note at the end of chapter 29 for a worked example. Anything above the baseline is, by construction, surplus to your stated plan. The desk colours it purple as a quiet invitation to either spend it or formally re-plan it. Remember: if you act on that invitation and withdraw more than your ordinary quarterly wage, lower the stored ATH by the extraordinary amount before committing the next entry (chapter 7).

14. Cash shield runway and phase modulation

The desk silently trims your Cash Buffer Target by age phase:

  Go-Go: full desired runway (default 36 months).
  Go-Slow: capped at 24 months.
  No-Go: capped at 12 months.

The reasoning is asymmetric: a 90-year-old does not need a three-year equity-market buffer because they no longer have a three-decade horizon to protect. Holding excess cash that late simply guarantees underperformance.

Part V — Case studies

15. A bear market (2008-style)

Imagine you retired in late 2007 with £1,000,000: £900,000 in global equities and £100,000 in cash, planning to spend £45,000 a year (target WR 4.5%). By March 2009 your equities have fallen 45%. Your balances are now roughly £495,000 equity and, having drawn from cash for six quarters, £77,500 cash. Total capital £572,500. ATH still £1,000,000 (you did nothing to it; market falls never lower the ATH). Peak drawdown 42.75%. Realised WR is 45,000 / 572,500 = 7.86%, against a Target WR of 4.5%.

7.86% / 4.5% = 1.75 — comfortably above the 1.20 Preservation threshold. The desk does three things at once. It posts an amber Preservation banner cutting next quarter's draw by 10% to £10,125. It freezes equity sales and tells you to source the £10,125 from cash. And, because your shield runway is now near the bottom of its range, it stops sweeping anything into cash on the equity side.

What you have not done is sell £45,000 of equities at the bottom of the worst crash in eighty years. That single behavioural discipline — enforced by a rule rather than your willpower — is the core value the desk delivers.

16. A bull market (2017-style)

Same retiree, ten years later. Equities have compounded handsomely. Your balances are £1,300,000 equity and £150,000 cash; total £1,450,000. Each time Total Capital printed a new high over the last few quarters, the desk lifted the stored ATH automatically at commit — so the ATH now reads £1,450,000 as well. Realised WR is 45,000 / 1,450,000 = 3.10%, against a Target WR of 3.10% (target uses ATH as the denominator). The guardrail is Normal — but next quarter, if equities rise another 5%, the ATH will rise with them and your realised rate will drift below 0.80 × target.

Prosperity triggers. The desk posts a purple banner offering you £12,375 this quarter (a 10% bonus on £11,250) and tells you to source it from equities. Over a multi-decade bull run those 10% bumps compound into a materially richer retirement than any static-draw method would have permitted.

17. A sideways decade

Markets do not always crash or boom. A flat, choppy decade is, for a guardrail system, the easiest environment: realised WR drifts slowly around target, the guardrails rarely trigger, and the cash shield is topped up gradually from ordinary equity sales. The desk simply tells you to draw your target amount from equities, quarter after quarter, and to refill cash whenever Total Capital prints a new high (which is also when the ATH ticks up).

Part VI — Reference

18. Frequently asked questions

Is my data stored anywhere?
No. The desk runs entirely in your browser. The ledger is held in your browser's local storage and, optionally, in the backup files you export. Nothing is sent to any server.

Why does the desk use the floor of 2.5% for growth?
It is the default, not a recommendation. Choose a real (above inflation) figure you genuinely believe your equity tracker can earn over the next twenty years. Lower numbers produce more conservative directives.

Do I ever need to raise the ATH myself?
No. The desk does it for you, at commit time, whenever Total Capital is a fresh high. Leave the field alone during your quarterly ritual.

When do I need to lower the ATH myself?
Only when you take a withdrawal beyond your normal quarterly wage — for example, the Fun Bucket shows a £60,000 surplus and you actually pull £40,000 out for a car or £30,000 as a gift. Lower the ATH by the extraordinary amount before committing. If you skip this step, the desk will read the next quarter's lower Total Capital as a market crash and likely fire a Preservation guardrail, telling you to cut spending you did not need to cut.

Why does my Target WR change when the ATH moves?
Target WR uses ATH as its denominator. A new high makes the same spending look like a smaller share of wealth, which is the correct intuition: when you are wealthier than ever, you have more headroom. When you legitimately lower the ATH after an extraordinary withdrawal, the denominator shrinks and Target WR rises — also correct, because you genuinely have less working capital.

What if I miss a quarter?
Nothing breaks. Commit a fresh entry whenever you next sit down. Long gaps mean the guardrails react to bigger moves at each visit, which is operationally noisier but mathematically identical.

Can I run the desk on more than one portfolio?
Yes, but use a separate browser profile or a separate backup file for each, so the ledgers do not mix.

Why two buckets, not three?
See chapter 3. A bond bucket adds complexity without adding robustness in the regimes that matter (sharp equity falls, rising-rate environments).

What if I want to spend a one-off lump sum?
Reduce your Cash Pot balance by the lump sum and reduce the Stored ATH by the same amount, then commit. Next quarter the desk will likely instruct you to refill the shield from equities at the next opportunity, and the guardrails will not mistake your spending for a market fall.

Should I trust the Prosperity bonuses?
Yes, with discipline. The bonuses are temporary; if markets fall again the desk will withdraw them. Spend them on time-bounded joys (travel, gifts, experiences) rather than baking them into fixed monthly outgoings. If you turn a bonus into a lump-sum purchase rather than ordinary spending, treat it as an extraordinary withdrawal and lower the ATH accordingly.

What happens if both buckets are empty?
The desk shows a red System Exhaustion banner. There is no more capital. This is the outcome the rules are designed to avoid; if you ever see it, the time to have acted was years earlier.

Is this regulated financial advice?
No. It is a personal planning tool. Take professional advice before acting on its output, particularly around tax, pension rules, and estate planning.

19. The author's own setup

Offered for illustration only — your circumstances, tax position and risk tolerance will differ.

Cash Shield. Royal London Short Term Money Market Fund, sized for a 30-month runway. Held inside the SIPP so withdrawals can be staged tax-efficiently.

Global Equities. HSBC FTSE All-World Index Fund. A single global tracker covering developed and emerging markets, ongoing charge well under 0.25%. One fund, one decision, no rebalancing between regions.

Wrapper / broker. Self-Invested Personal Pension (SIPP) hosted at Interactive Investor. Flat-fee platform suits a buy-and-hold portfolio of this size.

Ritual. Quarterly review on the first business day of each quarter. Backup file copied to encrypted local storage and to a USB key kept in a drawer.

20. Legal notice (summary)

The Sovereign Glidepath is an information and modelling tool. It is not financial, investment, tax, legal or pension advice. No warranty is given as to accuracy, fitness for purpose, or future outcomes. Past performance is not a guide to future performance. You are solely responsible for your investment decisions and for any loss — actual or perceived — that may arise from acting on the desk's output. The full legal notice and limitation of liability is displayed when the application loads; you must read and accept it before use.

— End of manual —

Part VII — The Risk Simulator

Licensing & the 30-day evaluation

Sovereign Glidepath ships as an offline-only application with a 30-day evaluation window. On first launch the app stamps an installation date in localStorage. During the trial all features are fully unlocked and a dismissible amber banner at the top of the dashboard shows days remaining.

After day 30 the app continues to function but the Historical Timeline Ledger is capped at 5 committed entries. Attempting to commit a 6th entry opens a lockout dialog directing you to the License screen. Existing entries above the cap remain visible and editable; the cap only blocks new commits.

To activate, click 🔑 License in the top-right toolbar. Enter the registered name or email supplied with your key and paste the license key. Verification runs entirely in your browser via the Web Crypto API — no network call. On success the banner switches to Licensed to: … and the key is stored only on this device.

If you re-install or clear browser storage you will need to re-enter the same name/email and key. Keep both somewhere safe.

Transferring to another machine. Re-open the License dialog on the licensed machine and click Deactivate License (left of the Cancel button). This clears the saved key from this browser and restores the trial banner and 5-entry cap, freeing you to enter the same name and key on the new machine. While a license is loaded the primary button reads Re-activate instead of Activate, so you can swap in a different registered name / key without first deactivating.

21. What Monte Carlo actually does

The rest of the desk gives you one answer: at your assumed growth rate, here is the single straight line your capital will trace through time. The Risk Simulator gives you 10,000 answers. It re-runs your retirement 10,000 times, each time rolling fresh annual returns, and shows the spread of outcomes as a coloured fan. The point is not to predict the future. The point is to make the shape of uncertainty visible — to show that the single straight line is the median of a wide cloud, and that you live in exactly one of the 10,000 possible futures.

This matters because of sequence-of-returns risk. Two retirees with the same long-run average return can finish in completely different places depending on when the bad years arrive. A single deterministic projection hides this entirely. A fan chart cannot.

22. Historical vs Parametric mode

Historical mode draws each simulated year at random from MSCI World (Net Total Return, GBP) annual returns 1970–2024 — a global-tracker proxy more appropriate for a UK investor than a single-country index. This preserves the fat tails — the 1974, 2002, 2008, 2022 drawdowns and the 1985, 1995, 1999, 2019 melt-ups. If a sequence-of-returns disaster is going to happen to you, it will look a lot more like one of these than like a tidy bell curve. Build 128 replaced this series with the genuine real data — an earlier version had several pre-2000 years off by a wide margin (1971 modelled at +31% against the real +12.43%, for instance) despite this chapter's own description always having said "real returns." See Chapter 46 for the full story.

Parametric mode manufactures returns from a normal distribution with a mean and standard deviation you control. The defaults (μ 11.85%, σ 17.8%, updated at Build 128 to the real MSCI World full-period 1970–2024 arithmetic mean/stdev) are reasonable proxies for a global equity portfolio. Parametric is useful for "what-if" experiments: lower the mean to model a more cautious balanced fund, or raise the volatility to see what a more concentrated portfolio does to the fan.

Toggle between the two. If your conclusion changes dramatically between Historical and Parametric, the bell-curve assumption is probably flattering you.

23. Reading the fan chart

The chart shows your capital from year 0 (today) out to your Target Horizon Age.

Light blue band: the 10th to 90th percentile of simulated outcomes. Eighty per cent of the 10,000 paths finished somewhere inside this band.

Darker blue band: the 25th to 75th percentile — the central half of outcomes. This is the bulk of the cloud.

Solid blue line: the median (50th percentile) simulated path.

Dashed line: your deterministic "if returns come in exactly as assumed, every year" reference path. Only the RETURN side is fixed — the flat Assumed Real Growth Rate and Cash Real Return you set in Pane 1, with no randomness at all. The WITHDRAWAL side is fully live: it runs through the exact same engine as every stochastic path in the fan — Guyton-Klinger guardrail adjustments, defensive bucket-sourcing between Equities and Cash, pension netting once your pension is in payment, and No-Go phase gating all apply here exactly as they do everywhere else. So this line answers "what if the only thing that went to plan was the return" — everything else about how the app would actually behave is still in force.

Compare the dashed line to the median. If the dashed line sits below the median, your assumption is more cautious than the average simulated future. If it sits above, your assumption is more optimistic. The further it sits from the median, the more your headline plan is leaning on luck in one direction or the other.

23a. Yearly Withdrawal Increase Rate slider

The slider above the chart (0%–5%) sets the annual rate at which your withdrawal grows year on year — a stand-in for inflation, lifestyle creep, or a planned wage rise. Each simulated year's nominal return is converted to a real return via (1 + nominal) / (1 + inflation) − 1, and the whole chart is plotted in today's pounds. £100k at year 30 on the chart means £100k of today's purchasing power. Set it to 0% to model pure nominal returns with a flat withdrawal.

23b. True two-bucket simulation (cash drag & defensive draw)

The Risk Simulator does not treat your portfolio as a single volatile blob. It tracks two buckets — Equities and Cash — through every year of every one of its 10,000 runs. Equities follow the chosen return model (Historical MSCI World 1970–2024, or a Parametric normal curve you control). Cash earns a deterministic real return set by the Cash real return % slider (default 1%, range 0–3%).

This matters because the previous engine quietly overstated both the median and the floor. By treating the whole pot as equities, it earned the equity return on money that, in reality, is sitting in a money-market fund earning roughly inflation. The cost was a fictitious cash drag-free median. The benefit was an understated buffer: cash was never available to absorb a bad year, so the 5th percentile was harsher than the two-bucket reality.

The defensive draw rule

Each simulated year the engine inspects the equity return and decides which bucket to spend from. Each button click re-runs all 10,000 simulations against the same seeded return paths, so the change you see comes from the draw rule — not from random re-rolling.

Three thresholds are offered:

Equities & Cash Pot overrides

The single "Total Capital" override has been replaced by two: Equities and Cash Pot. Each is seeded from your most recent ledger entry but can be edited freely for what-if experiments. An amber ✎ what-if marker appears when you have overridden a bucket; a "Reset to actual" link snaps it back to the real value. Overrides are never written to local storage — a refresh, or a fresh ledger entry, restores reality.

Allocation bias slider

The allocation bias slider beneath the Equities and Cash inputs lets you tilt the starting split toward one bucket or the other while keeping total capital fixed. It is a quick way to test “what if I carried more cash?” or “what if I stayed more equity-heavy?” without manually editing both fields.

23c. Worked example — a 30-year stress test

This section makes the engine concrete. We follow one randomly-drawn 30-year path through the simulator using a realistic UK setup, year by year, so you can see exactly how the two buckets, the defensive-draw rule, the State Pension, and the inflation drag interact. The simulator runs 10,000 of these paths in parallel and plots the resulting spread as the fan chart — this is one of them.

Starting position

What the engine does, year by year

For each simulated year, in order:

  1. Draw a market return (Historical = one MSCI World year sampled at random; Parametric = a normal draw at your mean/StDev).
  2. Convert to a real return by deflating with inflation. The chart is in today's pounds.
  3. Compute net withdrawal = £42,000 (escalated) − State Pension (if age ≥ 67, escalated at 3%).
  4. Classify the year via the threshold. Good year → spend from Equities, then refill Cash up toward £125k. Bad year → spend from Cash first; only touch Equities if Cash is exhausted; do not refill Cash.
  5. Apply the real return to whatever remains in each bucket.

One path drawn at random (seed 11)

Returns shown are nominal; the engine deflates them internally. Money values are in today's pounds.

Yr Age Nominal Pension Net draw Mode Equities Cash Total
1 60 −12.6% £0 £42,000 DEF → cash £554,338 £83,830 £638,168
2 61 +13.0% £0 £42,000 GOOD → refill £524,697 £125,000 £649,697
3 62 +22.9% £0 £42,000 GOOD → eq £578,859 £126,250 £705,109
4 63 −1.2% £0 £42,000 DEF → cash £557,900 £85,092 £642,992
5 64 −30.0% £0 £42,000 DEF → cash £381,005 £43,523 £424,528
6 65 +6.0% £0 £42,000 DEF → cash £393,834 £1,539 £395,373
7 66 +25.0% £0 £42,000 GOOD → refill £364,706 £65,914 £430,620
8 67 +24.6% £13,000 £31,064 GOOD → refill £347,058 £125,000 £472,058
9 68 −12.5% £13,390 £31,010 DEF → cash £296,425 £94,930 £391,355
10 69 −13.7% £13,792 £30,957 DEF → cash £249,616 £64,613 £314,229
11 70 +18.3% £14,205 £30,903 GOOD → refill £214,554 £103,121 £317,675
12 71 +14.6% £14,632 £30,849 GOOD → refill £184,518 £125,000 £309,518
13 72 +31.5% £15,071 £30,794 GOOD → eq £197,277 £126,250 £323,527
14 73 +22.7% £15,523 £30,740 GOOD → eq £199,389 £127,512 £326,902
15 74 +5.4% £15,988 £30,685 DEF → cash £204,975 £97,796 £302,771
16 75 −20.0% £16,468 £30,629 DEF → cash £159,981 £67,838 £227,819
17 76 +48.1% £16,962 £30,574 GOOD → refill £158,961 £96,569 £255,530
18 77 +2.4% £17,471 £30,518 DEF → cash £158,773 £66,711 £225,484
19 78 −5.6% £17,995 £30,462 DEF → cash £146,290 £36,611 £182,901
20 79 −11.2% £18,535 £30,406 DEF → cash £126,718 £6,267 £132,985
21 80 +22.0% £19,091 £30,349 GOOD → refill £97,497 £23,535 £121,032
22 81 +9.3% £19,664 £30,293 GOOD → refill £60,927 £34,523 £95,450
23 82 +1.5% £20,254 £30,235 DEF → cash £60,322 £4,330 £64,652
24 83 +6.0% £20,861 £30,178 DEF → cash+eq £35,653 £0 £35,653
25 84 +11.4% £21,487 £30,120 GOOD → refill £5,110 £902 £6,012
26–29 85–88 mixed £22k–£24k £30,000 exhausted by age 88 £0 £0 £0

Defensive draws this run: 14 years of 29 (≈48%). The two crashes at ages 64 and 75 both arrived inside the early-sequence danger window; the Cash Pot absorbed them in years 5–6 and again in 9–10, sparing the Equities Pot from being sold at the worst prices.

What this single path tells us

How this differs from the live quarterly app (Panes 1–3)

Aspect Risk Simulator (standalone page) Live app (Panes 1–3)
Step size 1 year 1 quarter
Withdrawal Fixed real £ Guardrail-adjusted ±10% each quarter
Refill rule Automatic in good years Manual, on directive recommendation
Drawdown re-classification None Recomputed every commit
Phase shifts (Go-Go → Go-Slow → No-Go) Not applied Applied automatically at 75 / 85
Taxes, fees, FX Not modelled Not modelled — they live in your inputs

Net effect: in real life with the live app, the same return sequence above should land closer to the p50–p75 band than to the p10, because the guardrails truncate the worst tails the simulator deliberately leaves in.

23d. What-if Current Age and Horizon Age

Two fields on the Risk Simulator's own page — Current Age and Horizon Age — behave differently from every other field there. They seed from your live Pane 1 figures the moment the page opens, exactly like everything else, but they're freely editable afterward with a visible "✎ what-if" badge and a Reset to actual link once changed. Nothing you do to either writes back to your real plan, and reopening the Risk Simulator fresh from Pane 2 always starts from your real figures again.

The two are independent, so both need to be changed together to model a genuinely different retirement shape — moving Current Age alone just shifts when the same horizon starts, while moving Horizon Age alone changes how long the plan needs to fund without touching when it begins.

This is the mechanism the Accumulation Simulator's hand-off window relies on (chapter 43) — when it opens the Risk Simulator with a projected pot, it's setting exactly these two what-if fields, the same way you could by hand.

24. "Sims beating your assumption"

The headline readout below the chart is the percentage of the 10,000 simulated futures that ended at or above the dashed-line value your assumed rate produces. It is deliberately framed so that higher is better and the colour matches:

Reading Colour What it means
75%+ Green Conservative — most futures beat your assumption. Your headline plan is on the cautious side; you have margin.
50–74% Amber Reasonable — the majority of futures meet your assumption, but not by a huge margin.
25–49% Amber/Red Optimistic — a minority of futures match what you've assumed. Consider lowering the assumed growth rate or raising the cash shield.
Below 25% Red Aggressive — few simulated futures look like your headline plan. The plan is leaning hard on a good outcome.

"Capital preserved" is the percentage of runs that ended at or above your starting capital. In withdrawal mode this is a tough bar by design — you are spending the pot. A more useful question is whether the 10th-percentile ending value (the bottom of the light blue band at the right-hand edge) is still positive. If it is, even the unlucky 10% of futures did not run out; if it is at zero, you have a real ruin risk to think about.

25. What the simulator is NOT

The Risk Simulator is a stress test, not a forecast. Specifically, it does not model:

Wage growth and CPI shocks. The Yearly Withdrawal Increase Rate slider (0–5%) escalates your withdrawal smoothly each year and the chart is shown in today's pounds. It does not model surprise CPI spikes or step-change tax/benefit shifts.

Taxes. No allowance for income tax on drawdown, dividend withholding, or capital gains.

Fees. Platform and fund charges are not deducted.

Your actual asset mix. Historical mode uses MSCI World (NTR, GBP); parametric uses a single mean/stdev. Neither captures a real bond allocation or your specific fund tilts.

Behavioural reality. The simulator assumes you keep withdrawing the same amount through a 40% crash. Real humans cut spending. The guardrail engine elsewhere in the desk models that; this pane does not.

Future regime change. Historical mode assumes the next century looks statistically like the last one. It might not.

26. FAQ — "Is the maths broken?"

Q. My Expected Return is 7% and my Assumed Growth is 7%. Why does the median path sit visibly below the dashed line — and why does that gap get worse the higher I push volatility?

This is volatility drag, also known as the arithmetic-vs-geometric-mean gap. It is real money lost to variance, not a charting glitch. The figure you type into "Expected Return %" is the arithmetic mean of annual returns. What a portfolio actually compounds at over many years is the geometric mean, which is always lower whenever returns vary. A good approximation is:

geometric ≈ arithmetic − σ² / 2

Plugging in numbers:

• σ = 0% → drag = 0. The median sits exactly on the dashed line.

• σ = 15% → drag ≈ 0.15² / 2 = 1.13 %/yr. The median compounds at ~5.9%, not 7%. Over 20 years that gap accumulates into the visible separation you can see in the chart.

• σ = 25% → drag ≈ 3.1 %/yr. The median pulls dramatically away from the dashed line.

Intuition: a portfolio that gains 20% one year then loses 20% the next ends at 0.96, not 1.00. The bigger the swings, the more ground the next year has to claw back. The dashed line ignores that asymmetry; the median respects it. Higher volatility ⇒ bigger drag ⇒ wider gap. Exactly what you are seeing.

Q. And why is the upper half of the fan so much wider than the lower half — the 90th percentile shoots way up while the 10th sits relatively close to the median?

Because returns compound multiplicatively, the distribution of ending capital is log-normal, which is right-skewed. The downside is bounded (you can lose at most 100% of capital — ending value of zero), but the upside is unbounded — a long string of good years can multiply capital several-fold with no ceiling. So the 90th percentile sits much further above the median than the 10th percentile sits below it. That asymmetric fan shape is the honest visualisation of compounded risk, not a plotting artefact.

Q. So the maths is solid?

Yes. Both effects above — volatility drag pulling the median below the dashed line, and a right-skewed fan with a longer upper tail — are exactly what a correctly-built Monte Carlo of a compounding portfolio must show. A simulator that produced a symmetric fan neatly centred on the dashed line at your stated return would be the broken one: it would either be running at zero volatility or quietly papering over the fact that compounding works in both directions.

Part VIII — Legacy, Special Events & Lifecycle Refinements

These features were added after the original edition of this manual. Each is small on its own; together they close the last three or four "silly answer" corner cases and let the ledger reflect real one-off spending honestly.

27. Legacy / Inheritance Target

Pane 1 now carries a Legacy Target field (in the same row as Cash Buffer and Currency). It is a real-terms amount you want to leave behind at the end of the plan — an inheritance, a charitable bequest, or simply a floor of untouchable capital. The engine subtracts it from the Actuarial Amortization Matrix surplus before computing "years of Fun Bucket left", so every directive respects it automatically. Set it to zero to draw the pot to nothing.

Because it is a real-terms figure, £100,000 today buys £100,000 of today's purchasing power at horizon age — it is inflated internally by the assumed growth rate the same way withdrawals are, so you never have to guess a future nominal figure.

28. Automatic ATH baseline

The Stored All-Time High is now maintained by the app itself. When you commit an entry whose Total Capital exceeds the stored ATH, the field is raised to match automatically. You never need to type it by hand for normal quarters — and doing so is discouraged, because a hand-raised ATH will fire phantom Preservation cuts next quarter.

The only time you should touch the ATH manually is when you take an extraordinary withdrawal from Pane 6's Special-Event flow (see chapter 29) — and even then the app now lowers the ATH by the withdrawal amount for you. In practice you should treat the ATH field as read-only.

29. Special-Event withdrawals (Pane 5)

The "Can I Afford This?" calculator has long modelled a one-off expense hypothetically. It can also commit that expense as a real ledger row. Type the amount, pick the source (Equities / Cash / Cash-first-then-Equities), review the impact, then in the purple pane type a short description (e.g. "New car", "Kitchen refit", "Gift to daughter") and click Commit Special Event.

Three things happen on commit:

30. Commit-confirmation modal

Clicking Commit Entry to Ledger now opens a small review dialog before anything is written. It shows the label, age, phase, both pot balances, the total, the (possibly-raised) ATH, the drawdown vs ATH, the target annual draw and its realised WR, the legacy target, the cash-buffer target, the assumed growth rate, and the current directive. This is a final sanity-check for typos — an extra zero in the Equities field or a forgotten label is easy to spot at this stage and painful to fix later. Cancel returns you to Pane 1 unchanged; Commit to Ledger writes the row.

31. Comfortable Amortization override

The Guyton-Klinger −10% Preservation cut is deliberately a blunt instrument — it fires whenever the current realised withdrawal rate rises 20% above the target rate, which is fine most of the time but becomes counter-productive in one specific situation: the ATH was set many years ago at a genuine peak, the pot has fallen back but is still comfortably ahead of remaining lifetime needs, and the engine wants to cut spending against a stale reference.

The engine detects this: whenever the Actuarial Amortization Matrix shows ≥ 3 years of surplus beyond lifetime needs and the legacy target, the Preservation / Freeze branches are suppressed and the directive box switches to green "Comfortable Amortization — Draw Normally", and the guardrail-status readout in Pane 2 agrees with the directive; they can no longer disagree.

In practice this only fires late in a plan when the surplus is genuinely large. It is not a way to spend more — it is a way to stop the engine hoarding capital against a peak you can no longer reach.

32. Quarterly-tick simulator mode

A companion mode to the Risk Simulator ticks quarterly rather than annually. The toggle sits in the simulator header next to Historical / Parametric.

The original engine (now labelled Yearly tick) runs 10,000 paths one year at a time. Each year gets one nominal return, one defensive-draw decision, and one withdrawal. It is fast, standard, and easy to reason about — but it does not model the fact that the live app looks at your pots every quarter and can adjust ±10% each time. In particular, a bad first quarter and a strong fourth quarter net out to a middling annual number, which the yearly engine treats as a middling year.

The new Quarterly tick mode splits each year's nominal return into four equal geometric quarters and, at every quarter, re-evaluates Guyton-Klinger against a per-path all-time high:

The defensive-draw decision (which bucket to fund from) is still made once per year against the year's nominal return — that matches the annual-return granularity of the underlying historical dataset. What changes is the size of each quarter's withdrawal.

What to expect visually. In runs where a drawdown bites early, the p10 floor lifts slightly under Quarterly tick, because the Preservation cut kicks in earlier and more often than it would under a once-a-year check. The median moves less, because good and bad quarters average out. The gap between the two modes is a direct visualisation of the value of the live app's quarterly discipline. If the gap is small on your plan, the quarterly ritual is buying you comfort more than survival; if it is large, that ritual is doing real work.

Cost. Quarterly tick runs four times the inner iterations of yearly tick — still under a second on a modern browser, and cached the same way. All other simulator controls (defensive threshold, allocation bias, pension, withdrawal escalation) apply identically.

33. Withdrawal Recorded field

This replaces the withdrawal-history bar with an explicit input on Pane 1 titled Withdrawal Recorded. It is auto-populated each quarter from the guardrail-adjusted Request, but is freely editable so you can log the exact £ that actually left the pot — down to the penny. The value is stored on the ledger row and displayed in place of the old "Drawdown Income" figure in the Historical Timeline Ledger (Pane 3). Every quarter now carries a clean, auditable record of what was withdrawn, independent of the Initial Annual Withdrawal — Frozen Baseline.

Use the Reset to Request button next to the field to snap the value back to the current guardrail-adjusted number. Committing a row re-arms the auto-seed so the next quarter starts fresh.

34. Audit Mode (hidden)

Double-click the "Risk Simulator — Monte Carlo Fan Chart" header (inside the standalone Risk Simulator page) to toggle Audit Mode. In this mode the RNG is paused and the simulator runs a single deterministic path with canonical inputs: Age 64 → 85, Equities £610,000, Cash £90,000, Withdrawal £36,000, Pension £12,700 starting at Age 67 with 2.5% real growth, cash real return +2.0%, inflation 2.5%. In Parametric mode the equity return is a flat +7.0% nominal every step; in Historical mode the engine walks the MSCI World sequence chronologically starting from 1973 — the classic sequence-of-returns stress benchmark. A step-by-step ledger table renders beneath the chart to the second decimal place so the math can be reproduced with a pocket calculator. Double-click the header again to exit and restore the full 10,000-run engine.

Part IX — Precision, Auditability & Defensive-Draw Control

This part documents everything added since Chapter 34, none of which existed when the earlier chapters of Part III were originally written. Read this alongside Part III rather than instead of it — the ritual and philosophy described there are unchanged; these are the newer inputs and safeguards layered on top.

35. Currency, Period End Date & the two independent-assumption sliders

Currency selector. Pane 1 carries a £ / € / $ selector. It is cosmetic only — no foreign-exchange conversion is applied — and simply relabels every figure across the app in your chosen symbol.

Period End Date. Alongside the free-text Reporting Period label (e.g. "Q3 2026"), Pane 1 now carries a real date field — Period End Date. The label stays cosmetic; the date is the single source of truth used to sort the ledger chronologically and to calculate elapsed time between entries for the annualised-return figure in Pane 3. Auto-Label refreshes both together. When back-filling an old entry, set this date deliberately rather than leaving it at today's default.

Cash Real Return and Inflation / CPI Assumption are now two independent sliders on Pane 1, sitting beneath Global Equities / Cash Pot and Assumed Real Growth Rate respectively. The Inflation / CPI Assumption slider feeds Pane 3's annualised-real-return calculation specifically; it is deliberately kept separate from the Risk Simulator's own Inflation / Escalation slider, so you can hold a different short-term CPI view for live directives than for long-run Monte Carlo planning. Moving one does not move the other.

36. Rebalance Move & the Withdrawal Recorded split, revisited

The Withdrawal Recorded block on Pane 1 now sits alongside an optional Rebalance Move control — None / Equities → Cash / Cash → Equities, plus an amount field — for recording an intra-bucket transfer that happened this quarter, separate from ordinary spending. Neither field is required; leave Rebalance Move on "None" if nothing was transferred.

While editing an existing ledger row, Pane 1 shows three buttons instead of the usual pair: Update Entry (commit your changes), Discard Changes (revert your typed edits but stay on this row), and Exit Edit / New Entry (abandon editing this row entirely and return to the fresh new-entry state, as if the app had just loaded). All three — together with the ordinary Cancel button used when you are not editing — correctly restore every Pane 1 field, including Cash Real Return, Inflation / CPI Assumption, Legacy Target and Currency, back to the appropriate values.

37. Defensive-Draw Mode overrides, made visible

Chapter 8 explained that seven of the ten directive states lock the withdrawal source regardless of your selected Defensive-Draw Mode. When a locking state's required bucket differs from what your selected mode (Strict / Standard / Aggressive) would otherwise recommend, that mode's text in the three-way comparison line now renders struck through with an amber "(overridden — see narrative)" flag, so the contradiction between "what my mode says" and "what's actually happening" is visible at the point where it would otherwise be easy to miss. The Withdrawal Recorded split fields on Pane 1 auto-seed from the same resolved, post-override bucket that drives this display — not from the mode's raw, un-overridden default — so what you see and what gets recorded always agree.

38. State Test Presets & QA/Audit Mode on Pane 2

Double-clicking Pane 2's header ("2. Intelligence Diagnostics") toggles a hidden pane of eight State Test Presets — one-click buttons, each populating Pane 1 with a canonical recipe designed to trigger one specific directive state (Normal Draw, Peak Refill / Recovery Wave, Reverse-Shielding, Freeze Equities / Cash Draw, G-K Preservation, G-K Prosperity, No-Go Amortization, Shield Deficit / Exhaustion), together with a before/after diff of every field it changes. This is a testing and verification aid only — applying a preset populates Pane 1 for inspection but commits nothing to your real ledger.

The active preset (if any) renders in a brighter purple than the other seven, matching the same purple used elsewhere for Audit Mode's "Active" banner, so you can tell at a glance which recipe is currently loaded. Double-clicking Pane 2's header again exits the pane and automatically reverts Pane 1 back to your real, committed values — you do not need to remember to click Cancel first.

39. The canonical directive-state registry

Every state the engine can emit — the ten listed in Chapter 8's table, their locking bucket, and their on-screen banner headline — is now declared once in a single registry inside the engine, rather than being independently duplicated across Pane 3's banner, its footnote, and the app's documentation. This closed a real discrepancy that existed for some time: three states (Preservation, Refilling Shield, and Exhaustion) had a banner headline that read differently from their canonical name, which made the footnote beneath the banner appear to name a different "current state" than the banner itself. All three now display their canonical name consistently, and a future rename of any state is a one-place edit rather than requiring every display location to be found and updated individually.

Part X — Security & the Companion Apps

40. Extraordinary Inflow — windfalls, property sale, inheritance

Pane 6, Extraordinary Inflow, logs a one-off lump sum landing in your accounts — a property sale, an inheritance, a windfall, a bonus you want to hold apart from the plan's normal quarterly draws. Type the amount, choose a Destination (Equities or Cash), and add a short description (e.g. “House sale proceeds”).

Committing an inflow does three things: it adds the amount to the chosen pot, it re-anchors the Stored ATH Baseline upward so future Guyton-Klinger guardrails treat the new total as a genuine permanent peak rather than a one-off spike to be corrected away, and it writes a purple ★ EVENT row into the Historical Timeline Ledger — the same visual treatment as a Special-Event withdrawal (Chapter 29), just on the inflow side of the ledger rather than the outflow side.

41. App-Lock — encryption at rest

On first launch the desk asks you to set an app-lock passphrase (a minimum of 8 characters). From that point on, your ledger, your saved settings and your licence details are encrypted on this device with AES-256-GCM, and the dashboard will not mount until the correct passphrase is entered — there is no separate "skip for now" path. If you already had data saved before this build, it is migrated from plaintext to encrypted storage automatically the first time you set a passphrase; nothing needs re-entering by hand.

Unlock is required at every app start — there is no lockout period and no "remember me" option, by design. Backups exported after this build are encrypted automatically as part of the export step, with no separate password prompt each time; a backup made before this build, or a legacy XOR-protected backup from an earlier scheme, both still restore correctly.

42. Companion Apps — the Comparison Builder

Pane 2 carries a Companion Apps section, sitting directly beneath the Scenario Stress Test box, which is home to spin-off tools built on the same underlying engine as the main dashboard rather than a separate approximation of it. The first of these is the Comparison Builder, launched with the button marked 📊 Compare vs 4% Rule (Historical).

The Comparison Builder backtests your plan against every real rolling US retirement start-year since 1928, run through the same Guyton-Klinger engine (engine.ts / drawdown.ts) that drives this dashboard, set alongside a faithful replica of the classic, unguarded 4% Rule for direct comparison. Opening it passes your live Pane 1 figures through automatically — equities, cash, age, horizon, gross withdrawal target, and your State Pension age and amount if one is configured, omitted entirely rather than zeroed when no pension is set up — so the comparison reflects your actual plan the moment the tool opens, with nothing to re-type. Opened on its own, with no plan attached, it falls back to its own editable example figures.

43. Companion Apps — the Accumulation Simulator

The third Companion App is the Accumulation Simulator, launched with the button marked 📈 Accumulation Simulator. Where the Risk Simulator stress-tests a pot being drawn down, this is its mirror image — it projects a pot growing, from an early starting age up to a chosen retirement age, across 10,000 possible market paths using the same fan-chart machinery and the same real historical return data as the Risk Simulator.

It's aimed at a different audience than the rest of this app — someone decades from retirement, most often a younger family member the plan-holder wants to make the case to about starting early. For that reason it deliberately does not open pre-filled with your live Pane 1 figures the way the other two Companion Apps do; it starts from its own small, sensible defaults, and every field it does have persists locally between visits since there's no real plan behind it to fall back to.

A "Move this pot to the Risk Simulator" button lets the two tools meet in the middle: it opens a confirmation window asking for a desired retirement income and State Pension details, then hands the projected pot — split 15% cash / 85% equities — over to the Risk Simulator as its starting capital, landing on the same Current Age / Horizon Age what-if fields covered in chapter 23d. Nothing before or after that hand-off writes back to either tool's real state. Full detail, including the historical/parametric modes, the zoom-and-hover chart controls, and exactly how the hand-off figures are calculated, lives in its own dedicated guide, opened from the 📖 User Guide button on the Accumulation Simulator's own page.

Part XI — Realised Inflation Tracking

44. The realised-inflation index, and the actual-CPI field

The live directive has always spoken in real terms (today's money): the withdrawal target stays flat from quarter to quarter, and the model deflates portfolio returns rather than inflating the withdrawal. That is internally consistent — but it means the pound figure printed on screen was never the actual nominal amount to withdraw in cash. The user had to do that translation themselves, silently, with no help from the app. This chapter and the next cover the fix: a genuine record of realised inflation, and a directive that finally shows actual pounds.

Each Normal ledger row can now carry an optional Actual CPI since last entry figure, entered in Pane 2's Inflation Tracking panel at commit time. Leave it blank and the desk falls back to the assumed CPI slider (Pane 1) for that gap — correctly pro-rated for the real elapsed time between rows, not assumed to be a full year. A six-month gap only ever applies half a year's assumed inflation, never a full year's.

Chained together across the ledger's history, oldest row first, these per-row rates build a cumulative realised-inflation index — 1.000× at the oldest tracked row, compounding upward from there. Pane 2 shows three things: the current cumulative index, the implied average annual rate across the whole tracked span, and the calendar year the index is anchored to. A “View realised-inflation history” table beneath that lists every tracked row individually — its date, the rate applied, whether that rate was Actual or Assumed, and the running index at that point — so the whole chain is auditable at a glance, not just the current total.

45. One number per instruction — the directive, the Frozen Baseline, and why neither needs manual updating

Before this build, the directive could show two figures for what was really one instruction — “Sell £5,000 from Global Equities” sitting above a separate box saying “Withdraw £5,750.66”. Both were correct, but presenting them side by side read as two competing instructions rather than one, and it left a genuinely reasonable question unanswered: if the pounds actually needed keep rising with inflation, shouldn't the Pane 1 target rise too?

The answer is no, and the redesign makes the reasoning visible on screen rather than requiring the user to hold it in their head. Every action figure in the directive — the main draw, a sweep into the Cash Pot, a deploy into equities, a Guyton-Klinger overlay adjustment — is now converted through the realised index before it reaches the sentence. There is exactly one bold, actionable number per instruction, and it is already the actual pounds to move. The real-terms figure that number was derived from appears only as a small reference footnote beneath the instruction, worded deliberately to close the loop: “Your Year-1 (2026) plan figure is £5,000.00/quarter — this stays fixed and never needs manual updating; the pounds above already account for realised inflation.”

This only changes display figures within whichever directive branch has already been selected — the sweep and deploy amounts are computed after the branch fires. It deliberately does not touch which branch fires in the first place (the Preservation threshold, for instance, still compares the actual cash balance held against a real-terms figure, exactly as it always has). That comparison mixing an actual balance against a real-terms threshold is a pre-existing characteristic of the whole guardrail engine, not something introduced here, and changing it is a materially bigger, separate decision deserving its own dedicated review.

The Pane 1 input itself was renamed for the same reason: “Target Annual Base Withdrawal” is now “Initial Annual Withdrawal — Frozen Baseline”, with a short caption underneath — “Set your desired initial income at plan start — inflation adjusts automatically. Use the slider below to apply a % lifestyle change.” — and a live nominal preview that appears beneath the field as you type, before you commit anything: the annual and quarterly actual-pounds equivalent of whatever you've typed. As of Build 127 the caption points at a dedicated Lifestyle Change slider rather than describing the arithmetic in words — see Chapter 46 for how it works.

Withdrawal Recorded (Pane 1) auto-seeds from the same nominal figure the directive shows, not the real-terms figure underneath it — an inconsistency an earlier pass of this build introduced and a live walkthrough of the actual app, not a code read-through, caught. The Commit-confirmation modal's mismatch warning and its “Initial Annual Withdrawal (Frozen)” review row were updated to match, so what you review before committing is never a stale label for what the row will actually record.

46. The lifestyle-change slider, and Shield Target moves to Pane 2

Chapter 45 covered why the Frozen Baseline field never needs manual inflation-arithmetic, and closed with a worked example: a genuine lifestyle change is just old value × 1.2 for a 20% rise. Build 127 turns that arithmetic into a live control instead of a sentence to work through by hand.

The Lifestyle Change slider sits directly beneath the Frozen Baseline field, running −30% to +30%. The design question it had to answer is what 0% means. It is anchored to your last committed baseline — not wherever the field happens to sit after a previous drag. Dragging to +15% always means 15% above what was actually last committed, regardless of how many times the slider has already moved this session, so repeated drags cannot silently compound into a much larger change than the percentage shown suggests. That baseline is refreshed at every point Pane 1 genuinely reloads or reverts — app boot, entering Edit mode on a ledger row, Cancel / Discard Changes, and the re-seed that happens if you delete the most recent ledger row — never by the slider itself, and never by typing into the field.

Typing directly into the Frozen Baseline field still works exactly as it always has; it simply repositions the slider to match. If you type a figure more than 30% away from baseline, the percentage readout above the slider shows the true, uncapped number (e.g. +60%), but the slider's own thumb visually pins at the end of its track rather than trying to render a position that doesn't exist on a −30/+30 scale. The field is never restricted to ±30% — only the thumb's on-screen position is.

The Request: / Shield Target: line has been removed from Pane 1. It duplicated information already shown in Pane 2's diagnostics, and grew stale-looking once a plan had been running a while. The Shield Target figure itself has not disappeared — it has moved.

Pane 2's diagnostics row (Total Capital / Peak Drawdown / Fun Bucket Balance — chapter 13) now carries two further tiles beneath that row: Shield Target (£) and Shield Target (Months). The £ figure is the same one that used to sit on the removed Pane 1 line; the months figure sits next to it for the first time. Both are drawn from the engine's phase-adjusted target — the same 36 / 24 / 12-month trimming by Go-Go / Go-Slow / No-Go phase described in chapter 14 — so the two tiles always agree with each other and with the Actual Cash Shield Runway comparison beneath them, rather than one showing your raw setting and the other showing what the engine actually enforced this quarter.

47. The real MSCI World data fix, and two Monte Carlo seeding bugs

Chapter 22 describes Historical mode as drawing from real MSCI World (GBP) annual returns 1970–2024. That description was always the intent; it wasn't always true. An earlier version of the underlying series had several pre-2000 years off by a wide margin against the genuine index — 1971 modelled at +31% against the real +12.43%, 1975 (the year after the 1973–74 oil-shock trough) modelled at +36% against the real +52.99%, 1990 modelled at −21% against the real −31.07%, understating that crash by over 10 points. 2000 onward was a close match, evidently rounded from a real series already; the older years weren't. Build 128 replaced the series with the real data, verified index-by-index to within 0.005 percentage points — pure rounding, not approximation. This affects both the Risk Simulator and the Accumulation Simulator: they share one copy of this series (see chapter 43).

Two structural bugs in the Monte Carlo seeding surfaced while independently verifying that fix. First: Historical mode's random seed always included the Parametric tab's mean and standard deviation fields, even though Historical mode never uses them to generate a return — so tweaking the other tab's sliders silently reshuffled which 10,000 paths Historical mode showed, with no visible cause and no way to reproduce a given run except by chance. Historical mode's seed now depends only on your pot size, years, and mode. Parametric mode is unchanged — its own seed still depends on mean/stdev, which is what lets its slider produce a smooth delta in the fan chart rather than a full reshuffle on every small tweak.

Second: the Parametric-mode defaults (μ 7%, σ 15%, referenced in chapter 22 before this build) were closer to the real MSCI World return over 2000–2024 alone (arithmetic mean ~7.95%) than to the real full 1970–2024 record (arithmetic mean 11.85%, stdev 17.80%). Updated to the full-period figures, so a fresh Parametric run and a fresh Historical run are both anchored to the same underlying reality rather than one quietly reflecting a stronger, more recent slice of history than the other.

A smaller, unrelated finding from the same pass: mulberry32 (the seeded random-number generator), gaussian, quantile, and the mean/stdev default constants were each duplicated byte-for-byte between the Risk Simulator and the Accumulation Simulator — exactly the kind of drift risk that produced the data bug above, just running the other direction (two copies, one gets updated and the other forgotten). Consolidated into a single shared module both simulators import from.

48. Editing history: pension and inflation now show what was actually true then

Two related bugs, both with the same shape: a figure that should have reflected a specific historical ledger row was instead always computed from whatever is live right now, regardless of which row you had open.

Inflation. The Live Nominal Preview under the Frozen Baseline field (chapter 45), and the directive amounts it feeds, always used the cumulative inflation index as of your most recently committed ledger row — not the row you actually had open for editing. Opening an old entry from several years back showed it nominalised using inflation accrued all the way to your latest row, effectively "as of right now," rather than as of that entry's own period. Fixed: editing a row now nominalises using that row's own cumulative index. The caption changes to match — "in actual pounds as of this entry's period" while editing history, "in actual pounds today" only for a genuinely new entry.

Pension. A more consequential version of the same bug. Pension (Annual Pension, Pension Start Age, Pension Real Increase %) had always been a single live, global Pane 1 setting — never stored on the ledger row itself, unlike Growth Rate / Cash Real Return / Inflation, which have carried a per-row snapshot since Build 095. So the "Gross lifestyle target / Less pension in payment / Net drawn from pot" breakdown under the Frozen Baseline field always recomputed using today's live pension figures, whichever row you had open. This was caught live: editing a Scenario Test Runner row (chapter 38) showed a pension figure compounded forward from the live plan's real pension — wildly different from the pension that scenario was actually built on. The row's own recorded numbers were always correct; only this explanatory breakdown was reading from the wrong source.

Fixed by giving LedgerEntry its own pensionAmount / pensionStartAge / pensionIncreasePct, stamped onto every row at commit time (and, for Scenario Test Runner rows, onto every row the scenario builds, from that scenario's own meta values — not the live plan's). Editing an old row now loads that row's own pension into Pane 1, and an inline note appears when it differs from your live settings, or when a legacy row (committed before Build 128) has no snapshot recorded at all.

Pension is treated deliberately differently from Growth Rate / Cash Real Return / Inflation on exit from Edit, though. Those three are genuine per-quarter assumptions — it's expected that correcting an old row updates your ongoing baseline too. Pension is documented elsewhere in this manual as "your real figures" — a single ongoing truth the Risk Simulator and every new commit read live, not something that should silently drift just because you reviewed or corrected an old row's history. So your live pension setting is restored after every exit from Edit — Discard Changes, Exit Edit, and a successful Commit alike — while a deliberate correction to a row's own historical pension figure still works exactly as typed, since that gets stamped onto the row itself regardless of the restore. A genuine second bug surfaced testing this exact mechanism: Discard Changes was found to jump pension to today's live value instead of keeping the row's own just-reloaded figure, because the reload and the restore were firing back-to-back in the wrong order. Fixed by giving Discard Changes its own legacyTarget/currency-only restore path, separate from the full restore Exit Edit uses.

49. The Scenario Test Runner's bundled scenario picker

Chapter 38 covers the Scenario Test Runner itself. As of this build, it offers a second way to run a scenario alongside uploading your own JSON file: a dropdown of 40 pre-loaded QA scenarios, grouped into Base (each scenario's own historical withdrawal rate) and Aggressive (the same era with a fixed +1.5 percentage-point withdrawal bump), sorted oldest era first within each group. Your own real 1996–2021 lifetime ledger scenario is included in the pool and marked with a ★.

Picking a scenario from the dropdown and clicking Run selected scenario goes through exactly the same path as uploading a file by hand — if a ledger already exists, it's backed up first and you confirm the replacement, identically either way. The 40 files aren't bundled into the app's code; they're separate JSON files the app fetches when you run one, referenced by a small internal list. Adding a 41st scenario later is a one-line addition to that list plus dropping the file in — no other changes needed.

Two rendering issues were caught and fixed before this ever reached a documented release: selecting a new scenario without running it yet used to show two different scenario names on screen at once, and every dropdown in the app (this one, and the Currency picker in Pane 1) had no dark-theme styling on its native options list, so the list rendered pale text on a pale background. Both fixed — see the Build 129 changelog entry for the detail.

50. Exporting the ledger as a styled Excel workbook

Pane 7 has always offered Download Ledger (CSV). As of this build there's a second option beside it, Export as XLSX, producing a two-sheet Excel workbook instead of a plain CSV: a Summary & Assumptions sheet (your live Pane 1 assumptions, plus a short results summary — row count, date range, whether the pot was ever exhausted, final total capital, final cumulative inflation index) and a Full Ledger sheet with the same data CSV export uses, styled with a frozen header row, currency and percentage number formatting, and column widths sized to the content.

The XLSX export uses the same underlying ledger data the CSV export does — not a richer or different data source — so anything the CSV export can show, the XLSX export can too, just formatted. A handful of columns some prior one-off exports have shown (year-by-year assumed market return and inflation figures) are deliberately not included here: those only make sense for a ledger built by the Scenario Test Runner from a specific scenario file, not for your real hand-committed history, where Pane 1's assumptions are a live setting rather than a per-row record of what actually happened that quarter.

51. The "potential underspend" signal (Pane 2)

Every other diagnostic in this app is aimed at one failure mode: running out. The Shield Runway, the Preservation cuts, the Prosperity Bonus — all of it is built around not depleting the pot too fast. Nothing previously said anything about the opposite risk: ending up with far more left over than intended, purely because a strong run was never revisited.

A rolling study across 29 overlapping real historical 26-year windows (built from the same real MSCI World and UK inflation data behind the QA scenario pool — see chapter 52) found a genuinely clean pattern. Scenarios that ended with a large surplus (four times the starting pot or more) almost always shared two things by year 5: their realised withdrawal rate had fallen well below where they started, and the pot had never fallen more than roughly 10% below its starting value at any point. Both conditions held together far more reliably than either alone — a falling withdrawal rate on its own wasn't a clean signal, and neither was "never dipped" on its own, but the combination separated the two outcomes cleanly across the real data tested.

Pane 2 now checks your real live ledger against exactly that pattern, using your plan's own day-one figures as the fixed reference point — not the constantly-moving All-Time High the guardrails already track, since that answers a different question ("is this a good quarter") to the one this is asking ("has the whole plan been running comfortably ahead since it began").

Dismissing the tile ("Reviewed — check again next year") genuinely waits a year before it can reappear, not just a page reload. The two thresholds behind the signal — withdrawal rate falling to 90% of your original rate, and never dipping more than 10% below your starting pot — are editable directly in the tile, not buried constants. They came from a rolling window over one real history, not a large independent sample, so they're offered as a considered starting point, not a precisely calibrated cutoff.

Like every other diagnostic in this app, the signal only ever informs — it never adjusts your Target Yearly Withdrawal or anything else on your behalf.

52. Appendix — the historical market and inflation data behind the QA scenario pool

The 40-file QA scenario pool referenced in chapters 38 and 49 (and the Build 128 changelog entry that first built it) is constructed from two real historical data series: MSCI World GBP annual real returns (1970–2024, the same series both the Risk Simulator's and Accumulation Simulator's Historical mode bootstrap from — see chapter 47), and UK consumer-price inflation (CPI) year by year. The full table below is provided for transparency, so any scenario result in the pool can be traced back to the specific year's actual figures rather than taken on trust.

Data-provenance note, resolved in Build 133: an earlier version of this pool (Builds 128–132) mixed two different UK inflation measures — 38 of the 40 files were built on the Retail Prices Index (RPI), while your own canonical 1996–2021 lifetime ledger scenario used the Consumer Prices Index (CPI). RPI historically runs 0.5–1.5 percentage points hotter than CPI and includes mortgage interest and council tax, which is also why it briefly went negative in 2009 while CPI stayed positive — the clearest tell that two different series were in play. CPI is the Bank of England's current inflation target and the standard a professional financial-planning tool would use, so all 38 pool files have been regenerated on CPI, sourced from the Office for National Statistics' own historical modelled CPI series (1971–2021, annual average of the twelve monthly 12-month rates) plus published ONS annual figures for 2022–2025. All 40 files now agree on inflation for every year they share, within rounding noise of a few hundredths of a percentage point against the canonical scenario — consistent with a minor ONS data revision between when the canonical file was built and this reconciliation, not a methodology difference.

This wasn't just a labelling fix: because the QA pool's engine outputs depend on the actual inflation figures fed in, correcting RPI to CPI changed several scenarios' real computed results, most notably five aggressive- or stagflation-era scenarios that previously showed the pot reaching Exhaustion under RPI but now complete successfully under CPI, since the lower inflation figure keeps real withdrawals smaller. Every file's expected checkpoints were regenerated against the real engine after the correction, and the standing 1996–2021 regression anchor was recomputed once your own canonical scenario was refreshed onto this same freshly-sourced CPI data (see below) — it moved from £2,007,282.02 to £2,006,221.98, a shift of about £1,060 from the underlying data revision, not from any change to the engine itself.

Year MSCI World GBP (real annual return) UK Inflation (annual)
1970 -3.08%
1971 +12.43% 8.53%
1972 +31.97% 6.72%
1973 -14.24% 8.92%
1974 -25.85% 14.65%
1975 +52.99% 21.99%
1976 +36.62% 15.42%
1977 -8.89% 14.73%
1978 +8.80% 7.52%
1979 +0.13% 10.94%
1980 +17.89% 14.81%
1981 +17.36% 11.32%
1982 +29.21% 8.17%
1983 +37.42% 4.86%
1984 +26.59% 4.39%
1985 +15.40% 5.15%
1986 +42.42% 3.70%
1987 -8.58% 3.27%
1988 +23.49% 3.90%
1989 +33.36% 5.22%
1990 -31.07% 6.98%
1991 +24.41% 7.53%
1992 +11.65% 4.29%
1993 +27.41% 2.53%
1994 +0.53% 1.98%
1995 +22.15% 2.65%
1996 +5.06% 2.43%
1997 +16.06% 1.82%
1998 +23.51% 1.57%
1999 +27.82% 1.32%
2000 -5.90% 0.80%
2001 -14.38% 1.23%
2002 -28.03% 1.26%
2003 +19.75% 1.36%
2004 +6.41% 1.35%
2005 +22.87% 2.04%
2006 +5.38% 2.32%
2007 +6.53% 2.34%
2008 -18.55% 3.61%
2009 +17.09% 2.18%
2010 +16.78% 3.31%
2011 -5.34% 4.48%
2012 +10.98% 2.84%
2013 +23.81% 2.57%
2014 +11.36% 1.46%
2015 +4.17% 0.04%
2016 +29.53% 0.67%
2017 +11.48% 2.68%
2018 -3.60% 2.48%
2019 +23.76% 1.79%
2020 +12.12% 0.85%
2021 +23.36% 2.58%
2022 -8.25% 9.10%
2023 +17.08% 7.30%
2024 +20.43% 2.50%
2025 3.40%

UK Inflation figures are annual averages of the twelve monthly CPI 12-month rates (Office for National Statistics, historical modelled CPI for 1971–2021; published annual CPI for 2022–2025). All 40 scenario files in the pool, including your own canonical 1996–2021 lifetime ledger scenario, now share this single series.