All articles
Options Analysis

How Multi-Leg Execution Works: Verification and Rollback Explained

What happens when you execute a multi-leg structure — order submission, a verification window, position checks, and an automatic rollback when legs fail. Plus how exit validation reads your broker rather than our records.

Arthalab10 min read
Placing a four-leg structure is not one action, it is four orders that can each succeed or fail independently. What happens between pressing execute and holding a position is where most of the real engineering sits, and it is worth understanding because the failure cases are the ones that cost money.

The problem being solved

A multi-leg structure only has the risk profile you designed if every leg is in place. Lose one and you are holding something else entirely.
StructureIf a leg is missingWhat you actually hold
Short straddleOne leg rejectedA naked short option, uncapped on one side
Iron condorProtective legs rejectedA short strangle, uncapped both sides
Bull call spreadBought leg rejectedA naked short call
Bear put spreadBought leg rejectedA naked short put
Each of those is a materially different trade from the one intended, and in three of the four cases the risk is open-ended where it was supposed to be capped.

What execution actually does

Rather than firing four orders and hoping, the execution runs through a defined sequence with a verification step built in.
  1. The legs are submitted. Each order goes to your broker, and the result of each submission is streamed back to you as it happens.
  2. A verification window opens. Rather than trusting the submission acknowledgement, the engine waits a fixed period before checking anything.
  3. Order status and positions are checked. Both — because an order can be acknowledged and still not result in a position.
  4. If legs are missing, a rollback is issued. Orders are sent to close whatever did fill, so you are not left holding a partial structure.
  5. The rollback is itself verified. The same wait-and-check applies, because a rollback order can fail too.

Why the wait exists

Step two is the one that looks like inefficiency and is not. A broker acknowledging an order is not the same as the order filling, and checking immediately would frequently check too early and reach the wrong conclusion.

Why it checks positions and not just orders

An order status can say one thing while your actual position says another — a partial fill, a late rejection, or a modification you did not expect.
Checking the position delta answers the question that matters: did this leg actually result in the exposure it was supposed to? Order status alone can be satisfied while the answer is no.

When the distinction matters

The distinction matters most on exactly the days you least want ambiguity: fast markets, wide spreads, and moments when the broker's own systems are busiest.

Rollback, and its honest limits

Rollback is a genuine safety mechanism and it is not a guarantee. It is worth being precise about what it can and cannot do.
Rollback canRollback cannot
Close legs that did fillUndo the market move between fill and close
Leave you flat rather than partially positionedRecover the spread and charges paid on the round trip
Report exactly what it closedSucceed if the market has become untradeable
Be verified, like the entryGuarantee a price

Watching it happen

The execution streams its progress rather than returning a single result at the end. You see each leg submitted, the verification window counting down, and then the outcome per leg.
This matters more than it sounds. A multi-leg execution takes long enough that a silent interface would leave you wondering whether anything was happening, and the obvious response to that uncertainty — pressing execute again — is the worst available action.

Why the streaming matters

Watching the progress also means that if a rollback is triggered you see it happening rather than discovering it afterwards in a log.

Exiting a position

Exiting has a validation step of its own, and it reads from a specific source.
Exit validation checks your broker's positions, not the platform's own order book. That distinction is deliberate: the platform's records describe what it believes happened, and your broker's positions describe what is actually there.

Why the broker is the source of truth

If those two ever disagree — because of a manual trade you placed yourself, a partial fill, or an action taken elsewhere — the broker is right and the platform is not. Validating against the broker means an exit is built on what you actually hold.
The flow is two-step: validate, then confirm. Validation tells you what it found and what it intends to close; confirmation is a separate action. This prevents an exit from acting on an assumption that has gone stale.

Managing orders after execution

Beyond entry and exit, individual orders can be modified or cancelled, and a single position can be exited on its own rather than closing the whole structure.
That last capability needs care. Exiting one leg of a hedged structure removes the hedge, and the position you are left with has a different risk profile from the one you were managing.

Why you should not re-press execute

The single most damaging action during a multi-leg execution is pressing the button again because nothing appears to be happening.
The verification window is deliberate and takes long enough to feel like something has stalled. During it, orders have already been submitted to your broker and are being checked.

What a second press actually does

A second execution submits a second set of orders. If the first set fills, you now hold double the intended position, and the rollback logic is reasoning about a state nobody designed for.
If you genuinely believe something has hung, the safe action is to check your broker's order book directly. That shows what actually reached them, which is the only authoritative answer.

The logs

Every execution is recorded — what was attempted, what the broker replied, what was verified and whether a rollback ran.
The broker's own message is preserved rather than replaced with a generic one, because the exact wording is what identifies whether a rejection was margin, session, address or order type.
Reading logs properly is the same discipline that applies to automated strategies: start from what was decided, then what was sent, then what the broker said, and only then look at the result.

What this means for how you trade

  • Expect multi-leg execution to take a moment — the wait is verification, not slowness
  • Never press execute twice because nothing seems to be happening
  • Keep margin headroom above the peak requirement during assembly
  • Prefer liquid strikes — a rollback on an illiquid leg is the expensive case
  • After any rollback, check positions yourself rather than assuming it was clean
  • Before exiting one leg, work out what the remaining structure becomes

The short version

  • A multi-leg order is several independent orders, each able to fail
  • Submission is followed by a verification window, then order and position checks
  • Failed legs trigger a rollback, and the rollback is verified too
  • Rollback converts open-ended risk into a known cost — it is not a reset
  • Exit validation reads your broker's positions, never the platform's records
  • Exiting a single leg of a hedged structure removes the hedge

Frequently asked questions

A second set of orders is submitted. If the first set fills you hold double the intended position, and the rollback logic is reasoning about a state it was not designed for.

Read the streamed progress, which shows each leg advancing. If you still believe something has hung, check your broker's order book directly — that is the authoritative record.

It is the difference between checking a result and guessing one. A broker acknowledging an order is not the same as it filling, and checking immediately would frequently reach the wrong conclusion.

Yes, each execution is a separate deliberate action. That is by design — nothing repeats on its own, which is what the strategy builder is for.

The execution verifies which legs actually resulted in positions and issues a rollback to close those that did, so you are not left holding a partial structure. The rollback is itself verified.

There is a deliberate verification window after submission. A broker acknowledging an order is not the same as it filling, so checking immediately would frequently reach the wrong conclusion.

No. The progress is streamed, so you can see each leg's status as it goes. Pressing again risks duplicating orders.

No. It leaves you flat rather than partially positioned, which is the point, but you pay the spread and charges on the round trip and whatever the index did in between. It converts open-ended risk into a small known cost.

Because your broker's positions are what you actually hold. If the platform's records and the broker ever disagree, the broker is right, and an exit should act on reality rather than on a belief about it.

Yes, but work out what remains first. Closing the bought leg of a spread leaves you short and uncapped, which is the same outcome as a rejection — chosen deliberately.

It is verified in the same way as the entry, and the outcome is reported. If a rollback cannot complete, check your positions directly and square off manually.

The execution logs record what was attempted, the broker's own reply verbatim, what was verified and whether a rollback ran.

Automated strategies run through the same broker and face the same rejection causes. The square-off-all-legs rule in the strategy builder serves the equivalent purpose there.

Start with a free 3-day trial

Build a strategy, backtest it and run it on paper — no broker, no IP and no money needed to try it.

Ask us on Telegram
How Multi-Leg Execution Works: Verification and Rollback Explained | Arthalab — Algo Trading India