MakwaIT
SAWEM
South African Wholesale Electricity Market
E-Trading Platform
MakwaIT · a South African IT company
Notes on building for an emerging wholesale electricity market

One system, from first bid to final settlement.

A wholesale electricity market is, underneath, a settlement problem wearing a market’s clothes — get the arithmetic wrong and nothing else about it matters. Day-ahead, intraday, balancing and settlement grew up as four separate systems — an accident of sequence, not a design. We built them as one, because a market that reconciles itself after the fact is already behind.

Status today
Working proof of concept · synthetic data
Where it runs
Built, hosted and run in South Africa
What it is not
Not a licensed exchange · no approval claimed
What we understand about this market

The volumes outgrow the process before anyone notices.

A wholesale market this size will not run on spreadsheets and month-end reconciliation for long. That is a systems problem before it is a policy one, and it arrives quietly: nothing breaks on the day the volume doubles, it just stops being possible to answer a question about last Tuesday.

And in a market this new, nobody yet has years of institutional memory for what a bad evening peak is supposed to look like. The baseline has to be built rather than remembered — which is why the arithmetic and the sequence matter more here than they would in a market with forty years of precedent behind it. The infrastructure a market runs on for the next twenty years is usually decided in the first two.

When most of the new capacity is wind and sun, the market’s core input is itself a forecast. Every imbalance charge in the system begins as a forecast that moved. There are only two ways to spend less on that: make the correction cheap and fast, or make the forecast better.

The platform is the first of those — the trading day this document is about. The second is a separate arm of our group: weather, climate and hydrology. That makes high-resolution wind and solar forecasting an input this platform can take rather than a feature it would have to grow. It is not part of the proof of concept, and we do not count it among the seven.

We are not describing an idea for a platform. We built a working one, and this is what we learned building it.

Inside a trading day

A mid-day offer revision, and what it was worth.

Late afternoon. The wind forecast is revised down, and 280 MW of an 840 MW day-ahead position is suddenly uncovered. That gap has to be closed by somebody, at some price. The question is only whether the seller closes it now, on their own terms, or has it closed for them at delivery. Closing it themselves means re-bidding — which, for a seller who is suddenly short, is a buy-back: a cover trade, not a fresh offer.

Intraday market screen at 17:30. A wind forecast revision leaves a 280 MW shortfall against an 840 MW day-ahead position. Two costed choices sit side by side: re-bid now at R3 400 for R952 000, or do nothing and take the balancing price of R4 100 for R1 148 000. A price ladder alongside reads day-ahead R2 850, intraday R3 400, balancing R4 100.
Both ways out, costed the moment the gap appears — re-bid into the intraday at R3 400, or carry it to balancing at R4 100 — on the same record as everything before and after it. The price ladder alongside is the whole argument for an intraday stage in one column: each later correction is dearer, so the design rewards honest early correction. A buyer whose demand runs ahead of forecast meets the same arithmetic in reverse. This is a capture of our SAWEM shadow market, running — not a rendering of one.
What the platform does

Seven capabilities, in the order they matter.

Everything below either runs today or is named as proposed production scope. We have tried hard not to blur the two, because the blurring is the thing that makes a document like this worthless.

01

One system across the full trading day

Day-ahead, intraday, balancing and settlement on one scrubbable, replayable 24-hour timeline. The merit-order stack, the marginal unit that sets the System Marginal Price, and the settlement statement that follows are all the same record — one source of truth, rather than four systems reconciled after the fact. This is the product claim; everything else is a consequence of taking it seriously.

02

Clearing anyone can independently re-verify

A separate command-line verifier imports the same clearing module the server runs, recomputes the System Marginal Price byte-for-byte from a receipt’s inputs, checks it against the SHA-256 output hash the receipt recorded, and exits non-zero on any mismatch. Determinism is enforced as a build gate: the build mechanically rejects wall-clock reads and random numbers inside clearing, settlement and anomaly code. Money is integer cents, energy is integer MW-minutes, ties break on a strict total order. A price that only one system can produce is a price only that system can defend — a counterparty, an operator or a participant can each re-run the number and get the same answer.

03

A participant model built on this market’s structure

Generator, large customer at 1 MVA and above, distributor, aggregator, cross-border and municipality — the last participating indirectly rather than as a direct counterparty. Traders are excluded from cleared auctions in this phase, and the API returns that reason explicitly rather than failing quietly. These are not generic market roles with local names painted on them.

04

Intraday value capture — the re-bid loop

A forecast slips and a position goes uncovered. The platform prices both ways out while there is still liquidity to act on, instead of presenting the outcome as a line on a settlement statement three days later. Bid validation and gate-closure handling are proposed, not built, and they are what makes this loop safe at production volumes.

05

Settlement on the record that cleared

Not a downstream reconciliation: the settlement statement reads the same appended events the clearing wrote. Every event lands on a SHA-256 hash-chained append-only log with its own chain verifier, so every trade has a receipt either counterparty can verify independently. The chain is tamper-evident: alteration is detectable rather than impossible, and that is the honest word for it.

06

Market data as a product, not a by-product

A market this size needs a shared, privacy-safe public price signal. Published aggregates carry differential-privacy noise and a k-anonymity floor of five, so the market can be read without revealing any single participant’s book, and a low-bandwidth text-only view is included, so the public price signal stays usable on a slow or metered connection.

07

Market monitoring — and what the hour should have cost

Four detectors run against the book: capacity withholding signalled by Residual Supply Index, wash trading by matched offset, price spikes against a 30-day band and collusion or layering by order-book pattern. Each flag is a screening signal, not a verdict. What makes it useful is the counterfactual re-clear behind it, which says what the hour should have cost rather than only that something looked odd: in the worked case, R1 150/MWh against the R2 850 it actually cleared at. It runs inside the market’s own core, alongside matching and settlement — the operator’s own instrument on its own book.

Past trends screen: price, demand and renewable share plotted across a trading day, with 1D, 1M, YTD, 1Y and MAX range selection.
The same trading day, read back afterwards on the same system — price, demand and renewable share out of one record, not four reconciled into one after the fact. A market with a memory is a market you can learn from.
Market-integrity screen. A banner reads: Residual Supply Index 0.96, a supplier is pivotal, price should have been R1 150 not R2 850. Four detectors are listed down the left, two flagged, one on watch, one clear. A panel compares 3 200 MW declared available against 2 600 MW actually offered, leaving 600 MW withheld, beside a control to re-clear the hour without the withheld capacity.
Capability seven, at the size it deserves. The withholding flag opens with what was declared, what was actually offered, and the arithmetic that makes the supplier pivotal — then offers to re-clear the hour without the withheld capacity. The flag is a screening signal, not a verdict; a person decides whether it goes further.

Also built, and deliberately not on this list: vesting contracts, a ramp-cap gauge, an infra-marginal “did my offer clear?” panel and a greeting layer across the eleven official spoken languages, with South African Sign Language noted as the twelfth. Ancillary services, capacity markets, financial transmission rights and full metering reconciliation are real, necessary and not here.

The architecture

How a bid becomes a settled trade.

The spine down the left is the point of the design. Every layer writes to it, nothing bypasses it, and what it holds can be checked by someone who does not trust us.

PROVENANCE SPINE every step is sequenced, chained and independently checkable 01 PARTICIPANTS Generators Buyers & municipalities Regulator 02 GATEWAY Participant API · identity Market data & dashboards orders, offers, nominations 03 MARKET CORE SOVEREIGN CORE — SOUTH AFRICA Matching engine Settlement engine Market monitoring single sequenced writer · integer maths · no clocks, no randomness 04 SYSTEM OF RECORD Hash-chained event ledger append-only · every order, clearing, settlement and flag, in sequence measured volumes in 05 VERIFICATION & INTERFACES Independent re-verifier Grid & metering systems Banking & settlement rails Public projections privacy-preserved read path · routed around the core

Everything drawn here runs today except the replicated commit log, hardware-backed signing, and the grid and banking integrations. Gate closure, prudential handling and a second South African site are proposed and not drawn.

How it is built

Keep the part that must be right small.

Proposed production design, written for the person who will be asked whether this is credible.

A small core, kept provably correct
  • Event-sourced append-only ledger as the system of record, on a replicated commit log. The ledger is the truth; every portal, dashboard and report is a view of it.
  • CQRS. A single deterministic writer performs matching and clearing. Read projections — participant portals, the public view, the detectors — scale independently and never touch the clearing path.
  • Deterministic single-writer matching engine, lock-free. Consensus elects only which process is the writer — never what the arithmetic says.
  • Monotonic sequence numbers at a single authoritative ingress settle who bid first. Participant-supplied timestamps are logged for reference and never used to break a tie, because participant clocks cannot be allowed to decide that.
  • Idempotent at-least-once ingestion with exactly-once effect, so a flaky participant connection cannot double-submit a bid.
  • RPO near zero, RTO in tens of seconds on matcher failover. A stalled clearing at gate close is itself a market-integrity incident, so it is designed for as one.
Evidence, identity and the outside world

The honest line runs through the word signing. Clearing receipts and settlement statements would be signed with keys held in an HSM or KMS, laid on top of the tamper-evidence that already exists — what runs today is hashed, not signed, and we keep those two words apart on purpose. Underneath it, archival is write-once with object lock and air-gapped copies, so the record outlives the systems that wrote it.

A record nobody can quietly amend is worth less if anybody can quietly become somebody else, so identity is hardware-rooted at the participant edge and mutual TLS between services, with segregation of duties and maker-checker on every settlement adjustment. Prudential, credit and collateral management — exposure, margining, default handling — is absent from the proof of concept entirely, and the first production workstream we would fund.

Where standards earn their keep we use them rather than invent around them: CIM (IEC 61970/61968) for grid and market data, IEC 62351 for its security, ISO 20022 for settlement messaging, REST and webhooks for the participant API. The stack is containerised and defined as infrastructure-as-code, so it can be moved between hosting providers without redesign.

Where it runs

The market core stays in South Africa.

This runs today, in South Africa, on infrastructure we built and host ourselves — not a slide of a plan. The production design keeps the entire market core in the country. Only the public view is a candidate for distribution beyond it, and only because differential privacy and a k-anonymity floor have already taken everything confidential out of it. For a market this visible, who can see or seize the record tends to get asked before anything about features.

How a system like this gets proven

A sequence, not a schedule.

The infrastructure a market runs on for the next twenty years is usually decided in the first two. This is the order in which a system of this consequence earns the right to be trusted — and each step is passed on technical evidence before the next one begins.

Where it is
Proof of concept

Running now, in-country, on synthetic data, with the clearing path held under a determinism build gate and the ledger under a chain verifier.

Then
Shadow run

The same engine fed real data, clearing and checking in parallel, while nothing it produces moves money or changes dispatch. The point is a track record built before it is needed — a detector validated in advance rather than debugged during its first real dispute.

Then
Production

Authority transfers only once the answers have matched reality long enough to be unremarkable. That is the standard we would want applied to us.

Where that leaves it

One system, from first bid to final settlement.

That is what runs: a full trading day cleared, re-verifiable by anyone who cares to check, and settled on the record that cleared it — every order, clearing and settlement written once, in sequence, never rewritten.

Credit, collateral and margining are next to build — the layer that stands behind a cleared trade and makes sure it settles. Named now, on the roadmap, rather than discovered late.

Status. What runs today is a proof of concept: real code, real determinism, real cryptographic chaining — on synthetic data, at demonstration scale, on a single site. It is not a licensed exchange, not a certified system, and it carries no claim of regulatory approval. Every figure in the captures above is illustrative synthetic data; the code that produces those figures is real, deterministic and re-runnable, which is the whole point. Who built it. MakwaIT is a South African, B-BBEE-recognised IT company; the engineers and the infrastructure are both South African.