
100ms Mirroring: Role Based Access Trading for Tradovate Prop Desks
TradeDupe
10 min read
Playbook for Tradovate prop desks: role based access trading with OAuth mapping, CME/NFA controls, and 100ms mirroring by TradeDupe.
Role based access trading for Tradovate copy systems is a permission model that assigns owner, manager, trader, and follower duties, maps leader-to-follower accountId relationships through OAuth, and enforces layered pre-trade limits before copying ever goes live. Operators should verify role assignments, confirm account mapping against Tradovate's API, and run a controlled test before trusting any account to mirror live fills, a sequence we follow in TradeDupe.
*
> TL;DR: > > - Role based access separates account connection, leader assignment, follower toggling, and risk limits, preventing a single compromised login from causing widespread issues. > - Using delegated OAuth ensures that account credentials remain with Tradovate and can be revoked instantly if needed, enhancing operational security. > - Enforcing numeric pre-trade limits, such as maximum order size and exposure caps, offers safer control than relying solely on trust between desk members. > - A thorough onboarding process requires verifying permissions, mapping accounts, configuring limits, and conducting controlled tests before enabling live copying. > - Tradovate's account-side enforcement of daily loss limits and profit targets safeguards traders even if connection issues or software failures occur.
*
Table of Contents
- Operational Roles and Permission Model for Copy Desks
- Account Mapping and Authentication: OAuth, AccountId, and Order Mechanics
- Layered Risk Controls: Limits, Allow/Deny, and Exposure Caps
- Onboarding and Safe Test Sequence Before Production Copying
- Failure Paths, Monitoring, and the Audit Trail
- How TradeDupe Maps These Controls Into a Working Copy Workflow
- Where Busy Operators Should Start This Week
- TradeDupe: A Ready Implementation for Tradovate Prop Desks
- FAQ
- Sources
Operational Roles and Permission Model for Copy Desks
A prop desk running copy trading on Tradovate needs four distinct roles, each with a narrow set of privileges. Blurring these boundaries is how a single compromised login turns into an account-wide incident.
- Owner: connects and unlinks Tradovate accounts, assigns managers, and holds final authority over risk limits.
- Manager: designates leader accounts, enables or disables followers, and sets per-account risk parameters within owner-approved bounds.
- Trader: executes manually on an assigned account but cannot alter copy relationships or limits.
- Follower: receives mirrored orders only and has no execution authority of their own.
These platform roles sit above a separate layer that Tradovate itself controls: account trading permissions. According to Tradovate's permissions endpoint, each account carries a status such as Accepted, Approved, Declined, Requested, or Revoked, along with an approver ID and an update timestamp. A copier dashboard role never overrides that status, it only governs who gets to request or react to a change in it.
Every role change deserves a paper trail: approver ID, timestamp, and a one-line reason for the change.
Pro Tip: Store role and permission changes in the same audit log, not two separate systems, so a reviewer can reconstruct who approved what without cross-referencing tools.
Account Mapping and Authentication: OAuth, AccountId, and Order Mechanics
Delegated OAuth access means a trader authorizes a copier to act on their Tradovate account without ever handing over a password, since the credential stays with Tradovate's own authentication flow rather than sitting in a third-party database. That distinction matters operationally: a copier that stores passwords is a liability a desk cannot audit, while delegated access can be revoked instantly from the broker side.
Leader-to-follower mapping is not optional bookkeeping. Because Tradovate's place-order endpoint requires an explicit accountId on every submission, a copier has to treat each follower as an independent execution target, scaling quantity per account rather than assuming a single order object fans out automatically.
That same endpoint returns specific failure reasons operators should surface in their monitoring UI rather than bury in logs:
- Unauthorized: the account's trading permission is not in an active state.
- TradingLocked: the account is restricted from new orders entirely.
- MaxOrderQtyLimitReached: the order exceeds a per-order quantity cap.
- MaxTotalPosLimitReached: the resulting position would exceed an exposure limit.
One accountId per order is the operating assumption built into Tradovate's API, which is why a copier that treats followers as a single group instead of individual execution targets will eventually misfire during a partial rejection.
Layered Risk Controls: Limits, Allow/Deny, and Exposure Caps
CME Group's pre-trade risk guidance recommends product allow/deny lists, order blocking, cancellation of working orders, and real-time monitoring as the backbone of pre-trade defense. Numeric limits and explicit allow/deny settings beat informal trust because they fail safely: a limit either stops an order or it does not, while trust between desk members has no enforcement mechanism at all.
A workable control stack, layered from broad to specific:
- Account authorization: confirm the account's trading permission status before any order routes through it.
- Product allow/deny: restrict which instruments a follower account can receive, matching CME's recommended permissioning approach.
- Per-account max quantity: cap the size of any single order regardless of what the leader sent.
- Exposure and credit limits: bound total position size across all open orders on that account.
- Kill switch: give managers a one-click disable that halts copying for one account or the whole desk.
Pro Tip: Pair every numeric limit with an alert at 80% utilization, not just a hard stop at 100%, so a manager sees a problem forming before an order gets rejected.
Monitoring should flag repeated rejections on the same account, utilization approaching a configured threshold, and any divergence between what a leader filled and what a follower actually received.

Onboarding and Safe Test Sequence Before Production Copying
Moving from a fresh connection to live production copying works best as a fixed sequence, not an improvised rollout. Tradovate's API supports each stage below through dedicated account discovery and permission endpoints.
- Connect via OAuth: authenticate the account through Tradovate's own flow, never a stored credential.
- Discover and verify accounts: confirm every linked account appears correctly and belongs to the intended user.
- Confirm trading permissions: check the account's permission status before assigning any role.
- Map leader to follower: set the mirroring relationship and quantity-scaling rule.
- Configure limits: apply product allow/deny, max quantity, and exposure caps.
- Run a controlled test: place small test trades and confirm fills, scaling accuracy, and failure handling on every follower.
- Review logs: check that alerts fired correctly and no silent failures occurred.
- Enable production copying: only after every follower has produced a clean test fill.
Minimum acceptance criteria before flipping the production switch: a successful test fill on each follower, correct quantity scaling, correct handling of at least one simulated rejection, and alerts arriving within a reasonable window of the triggering event.
Failure Paths, Monitoring, and the Audit Trail
NFA's supervisory guidance on electronic order-routing systems calls for pre-execution controls, prompt monitoring, the ability to block subsequent orders, and recordkeeping sufficient to reconstruct a trade after the fact. That standard applies directly to any copier sitting between a leader and a group of follower accounts.
- Unauthorized or TradingLocked: halt further copying to that account and escalate to the manager immediately.
- MaxOrderQtyLimitReached or MaxTotalPosLimitReached: log the rejection, notify the operator, and hold further orders until reviewed.
- Leader/follower divergence: flag any mismatch between expected and actual fills for manual reconciliation.
A usable audit trail records who changed a role or limit, an approver ID, a timestamp, and enough order data to replay the sequence of fills during a review, exactly the kind of recordkeeping NFA guidance points to for trade reconstruction.
How TradeDupe Maps These Controls Into a Working Copy Workflow
We built TradeDupe around the sequence above rather than bolting controls on afterward. Every account connects through Tradovate's own OAuth flow, so we never see or store a password, and every fill on a leader account mirrors to enabled followers over a live WebSocket stream, typically within 100 milliseconds.
- Per-account copy toggles let a manager enable or disable any single follower without touching the rest of the group.
- Rogue-trade detection flags follower-side orders the copier did not originate.
- Execution-mode controls govern how aggressively orders scale across accounts.
- Daily loss limits and profit targets are set directly on Tradovate, so the broker enforces them rather than our dashboard alone.
Our admin dashboard handles account discovery, role assignment, controlled testing, and ongoing analytics in one place, which keeps the onboarding sequence from spanning multiple disconnected tools. Our getting-started guide walks through connecting a first leader and follower pair in a single sitting.
Pro Tip: Run your controlled test during a low-volume session first, since a quiet market makes a scaling error or a missed fill far easier to spot.
Where Busy Operators Should Start This Week
If you manage a multi-account desk, start with three things: confirm every account's trading permission status, set numeric limits before you set roles, and run a controlled test with real but small size before enabling production copying. These priorities come from years spent inside futures order flow and prop firm evaluation processes, where the gap between a documented policy and an enforced limit is where most account blowups happen. When accounts are customer-facing, loop in compliance before copying goes live, not after.
> — Andres
TradeDupe: A Ready Implementation for Tradovate Prop Desks
We built TradeDupe specifically for traders running multiple Tradovate-backed prop accounts, not as a generic multi-broker bridge that treats every platform the same way. Connecting through Tradovate's official OAuth flow means your password never touches our servers, and nothing needs to run on your own PC or VPS around the clock.

Rogue-trade detection catches a follower-side order the copier did not place, and daily loss limits get enforced by Tradovate itself rather than by a dashboard setting that a bad connection could silently ignore. Plans run from $20 a month billed yearly on the Standard tier, up through other plans for desks running more connections, and every plan starts with a 7-day free trial you can cancel with one click. Visit our product overview to see which plan fits your account count, or head straight to the getting-started guide to connect your first leader and follower pair today.
This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.

FAQ
What is role based access in a Tradovate copy trading setup?
It is a permission structure that separates who can connect accounts, assign leaders, toggle followers, and set risk limits, keeping those duties distinct from Tradovate's own account-level trading permission status. The two layers work together: platform roles govern who can act, while Tradovate's permission status governs whether an account can trade at all.
How does OAuth protect accounts in a copy trading system?
Delegated OAuth access lets a copier act on an authorized account without ever storing the account's password, since authentication stays with Tradovate's own flow. This means access can be revoked instantly from the broker side if something looks wrong, without depending on a third-party system to honor the change.
What pre-trade risk controls should a prop desk configure?
CME Group's guidance recommends product allow/deny lists, per-order quantity caps, exposure limits, and the ability to block or cancel orders in real time. These numeric controls are preferable to informal trust because they enforce automatically rather than relying on a team member remembering a rule.
What should an onboarding checklist include before enabling live copying?
A safe sequence covers OAuth connection, account verification, permission confirmation, leader and follower mapping, limit configuration, and a controlled test trade reviewed before production copying begins. Minimum acceptance criteria should include a clean test fill on every follower account and correct handling of at least one simulated rejection.
Does TradeDupe enforce daily loss limits itself?
Daily loss limits and profit targets are set directly on Tradovate accounts, so the broker enforces them rather than our dashboard acting as the sole safeguard. This keeps the limit active even if a connection drops, since enforcement lives at the account level, not inside a third-party session.
Sources
Recommended
- How to Mirror Trades Across Prop Accounts: 2026 Playbook
- Prop Desks: 100ms Tradovate Integration with T0 to T3 Audit Trail
- 34ms Mirroring: Link Tradovate Accounts for Prop Desks
- Server Colocation Trading Guide for Tradovate Prop Desks
For educational purposes only. Not financial advice. Futures trading involves substantial risk of loss and is not suitable for every investor.