A multi-account emergency risk monitor and reactive kill switch for NinjaTrader 8.
Fusion Risk Engine monitors configured NinjaTrader accounts and reacts when a configured account-level rule is breached. When a breach occurs, it locks the account, cancels working orders, flattens open positions, and retries cleanup until the account is clean.
Fusion Risk Engine is a reactive software kill switch. It is not guaranteed loss protection.
Loss limits are trigger rules, not promises that losses will stop at the configured amount. Losses can exceed the rule you set because of slippage, gaps, fast markets, partial fills, rejected or canceled orders, position size, stale or delayed PnL data, broker or platform outages, internet failure, machine failure, or NinjaTrader not running.
Never rely on Fusion Risk Engine alone. Use broker-side or prop-firm risk controls, conservative position sizing, direct account monitoring, and exchange or broker protections where available.
Fusion Risk Engine monitors up to 8 NinjaTrader accounts at the same time. Each account has its own rule settings and its own lockout state.
For each monitored account, you can configure:
When a rule fires for one account, Fusion Risk Engine acts on that account only. Other monitored accounts continue to use their own settings and state.
The engine runs independently of any chart, strategy, or indicator window. Closing a chart does not disable the engine. Disabling a strategy does not disable the engine. If NinjaTrader is closed or disconnected, however, the engine cannot monitor or react.
Fusion Risk Engine is account-level, not Fusion-strategy-only.
It monitors the NinjaTrader account you add to the dashboard. If that account’s PnL, positions, or working orders are affected by any of these, they are part of the same account-level risk picture:
When a rule fires, Fusion Risk Engine does not ask which strategy created the exposure. It acts on the monitored account. It cancels working orders and flattens open positions on every instrument where that account has residual working orders or open positions.
This is intentional. Fusion Risk Engine is a kill switch, not a Fusion-only overlay.
Important consequences:
Fusion Risk Engine does not:
NinjaTrader does not provide a public pre-trade order-blocking API for this use case. Fusion Risk Engine is reactive: it responds after account data shows that a configured rule has been crossed.
The first time you open the dashboard in a NinjaTrader session, you must acknowledge the usage and risk warning. This acknowledgement opens the dashboard. It does not turn the engine on or off.
Shows the engine-level state: OFF, STARTING, MONITORING, DEGRADED, or STOPPED.
Appears when one or more accounts resumed in locked-out state from a prior NinjaTrader session. Acknowledging the banner dismisses the message only. It does not clear the lockout.
Each monitored account has a tile showing:
Click a tile to edit that account’s rules and view detail.
The right-side detail panel shows the selected account’s rule editor, current status, lockout controls, and extended messages.
The footer contains the reset time and timezone controls. These settings define the daily session boundary for all monitored accounts.
The global Engine toggle and the per-account monitoring checkbox both matter. The engine must be ON, and the individual account must be enabled, before rules enforce for that account.
Fires when session realized plus unrealized PnL reaches the configured loss amount.
Example: If Max Daily Loss is $500, the rule fires when the account’s current session PnL reaches -$500 or worse.
Fires when session realized plus unrealized PnL reaches the configured profit amount.
Use this when you want the account flattened and locked after a target day is reached.
Tracks the highest session PnL reached so far, then fires when the account draws down from that peak by the configured amount.
The threshold can be dollars or percent.
Example: If the account reaches a session peak of +$1,000 and Drawdown from Peak is $300, the rule fires if session PnL falls to +$700.
Daily Watermark is a two-step rule.
The drawback can be dollars or percent.
Example: Watermark Arm Level is $500 and Drawdown from Armed Peak is $150. The rule arms at +$500. If the day later reaches +$850, the rule fires if PnL falls to +$700.
| State | Meaning |
|---|---|
| OFF | Engine toggle is off, or no accounts are configured. No monitoring. |
| STARTING | Service is starting. This should be brief. |
| MONITORING | At least one account is actively watched. |
| DEGRADED | One or more accounts has stale events, API trouble, or disconnection symptoms. |
| STOPPED | Service stopped, usually because NinjaTrader is shutting down. |
| State | Meaning |
|---|---|
| NOT CONFIGURED | Account is added but has no active rules. |
| STANDBY | Rules exist, but the engine is OFF or account monitoring is disabled. |
| WATCHING | Engine is ON, account monitoring is enabled, and rules are being evaluated. |
| DEGRADED | The account has exposure but account events have been stale for 30 seconds or more, or the account API is temporarily unreliable. |
| DISCONNECTED | No account events for 60 seconds or more, or NinjaTrader reports the account as disconnected. |
| LOCKED OUT | A rule fired. The account remains locked until reset rules are satisfied or you manually reset it. |
These states describe monitoring status. They are not guarantees of protection.
When a configured rule fires for an account, Fusion Risk Engine:
The lockout persists across NinjaTrader restarts. Turning the engine OFF does not erase active lockouts.
At the configured reset time, Fusion Risk Engine can clear an expired lockout if the account is verified clean:
If exposure remains, the lockout stays active and cleanup retries continue.
Use Reset Lockout only after you have verified the account is flat and you understand why the lockout fired.
Manual reset clears the account’s lockout state. It does not guarantee the same condition will not fire again if the account is still near or beyond a configured threshold.
If NinjaTrader restarts while an account is locked out, Fusion Risk Engine reloads the lockout and shows a recovery banner. Dismiss the banner after reading it, then use the account tile to inspect and reset the lockout when appropriate.
Fusion Risk Engine saves:
These settings are stored under NinjaTrader’s user data folder and reload when NinjaTrader starts.
If the engine was ON before shutdown, monitoring resumes only after NinjaTrader has loaded the engine, the account is available, and account data can be read.
If the engine was OFF before shutdown, it stays OFF until you turn it back on.
When Fusion Risk Engine calls NinjaTrader’s account flatten action, NinjaTrader disables active NinjaScript strategies on the affected account and instrument. This can include Fusion Strategy and non-Fusion NinjaScript strategies. This is expected NinjaTrader behavior.
After the session reset and after you verify the account is clean, manually re-enable any strategies you intend to run again.
Rules apply to the whole monitored account. They do not apply only to one chart, one strategy, one instrument, or one Fusion product.
If ES, NQ, and CL all have exposure on the same monitored account, a lockout cleanup can cancel and flatten across those instruments.
Because pre-trade blocking is not available, a new order may briefly fill before Fusion Risk Engine can cancel or flatten. This is especially important in fast markets and with large position size.
Fusion Risk Engine polls account PnL and also listens for account events. If an account has open exposure and events go stale, the account tile can show DEGRADED or DISCONNECTED. When that happens, check NinjaTrader’s Connections panel and broker connection status.
Different brokers and data adapters report account values differently. If a tile reports API trouble or stale data, treat that account as needing manual attention until NinjaTrader account data is stable again.
Fusion Risk Engine deliberately uses warning dialogs for money-path actions.
The first time you open the dashboard in a NinjaTrader session, you acknowledge that:
When you turn Engine ON, the confirmation warns that configured rules on monitored accounts start enforcing immediately and that loss limits are not guaranteed.
When you turn Engine OFF, the confirmation warns that monitoring pauses on all accounts, active lockouts remain, and rules do not enforce again until the engine is re-enabled.
Save validation can block rules that are already breached by current account state. Examples:
Save validation can also warn before saving:
If warnings appear, read them carefully. Saving anyway means you accept that rule interaction.
Manual reset warns that it clears an active lockout. Use it only after verifying the account is flat and understanding why the lockout fired.
Remove Account asks whether to delete persisted lockout and session-state files.
Before trading:
After a lockout:
Confirm NinjaTrader has loaded accounts in Control Center and that you are connected to the broker or simulator. Accounts already being monitored do not appear again in the Add Account list.
Check both toggles:
Also confirm the account has at least one active rule.
Fusion Risk Engine is not receiving fresh enough account events, or the account API is not returning reliable data. Open NinjaTrader’s Connections panel and verify the broker connection. Do not assume the engine can react normally while the tile is degraded or disconnected.
The value you entered is invalid or would already be breached based on the current account/session state. Read the full validation message, adjust the rule, and save again.
Fusion Risk Engine only clears an expired lockout after the account is clean. Check for open positions and working orders.
Expected NinjaTrader behavior. Account flatten disables affected Fusion and non-Fusion NinjaScript strategies. Re-enable them manually only after the account is flat and the lockout situation is resolved.
The banner appears when an account is still locked out. Acknowledging the banner hides the banner. It does not clear the account lockout. Use the account tile’s Reset Lockout only after verifying the account is flat.
Q: Is Fusion Risk Engine guaranteed to protect my account?
A: No. It is a reactive software tool running inside NinjaTrader. It can only act when NinjaTrader is running, connected, and receiving usable account data.
Q: Can it stop orders before they reach the broker?
A: No. NinjaTrader does not provide the needed public pre-trade blocking API. Fusion Risk Engine cancels and flattens reactively after rules are breached.
Q: Is Fusion Risk Engine only for Fusion Strategy?
A: No. It is account-level. It monitors configured NinjaTrader accounts, so it can react to manual trades, Fusion Strategy trades, and non-Fusion NinjaScript strategy trades on the same monitored account.
Q: What happens to non-Fusion strategies if a rule fires?
A: Fusion Risk Engine cancels and flattens at the account level. NinjaTrader may disable active strategies on the affected account/instrument when account flatten is called. This can include non-Fusion strategies.
Q: Does it monitor manual trades too?
A: Yes, if the trade affects a monitored account inside NinjaTrader. The rules are account-level, not strategy-only.
Q: Can one strategy trip a rule that affects another strategy?
A: Yes, if both trade the same monitored account. The rules evaluate account-level PnL and exposure, not per-strategy PnL. Use separate accounts if you need separate risk boundaries.
Q: Does closing the dashboard turn the engine off?
A: No. The engine state is separate from the dashboard window. Use the Engine ON/OFF toggle to change monitoring state.
Q: Can different accounts have different rules?
A: Yes. Each monitored account has its own rule values and monitoring checkbox.
Q: What is the maximum number of accounts in V1.0?
A: V1.0 supports up to 8 monitored accounts.
Q: Should I still use broker-side risk controls?
A: Yes. Treat Fusion Risk Engine as one layer, not the authoritative layer.