---
title: Order Flow Report Methodology — What It Measures and How to Reproduce It
slug: order-flow-report-methodology
cluster: reports
description: The methodology of our recurring order-flow report — the exact raw streams it is built from, the measurement window, how each flow layer is computed and stamped, and the resolution limits published alongside every figure.
tldr: The recurring order-flow report measures executed aggression and resting-book behaviour on a fixed rolling window from two public streams — the trade tape with its taker side and periodic depth snapshots. Every figure is stamped with the moment it became observable rather than the moment it is drawn and is published with the sampling limits that make it a probabilistic diagnosis rather than a complete ledger.
published: 2026-07-31
updated: 2026-07-31
author: The Confluence Show Research
schema: Article
keywords: [order flow analysis, order flow report, cumulative volume delta, footprint chart, absorption, iceberg orders]
prompts: [How do you analyse order flow?, What data do you need for order flow analysis?, How is cumulative volume delta calculated?]
entities: [order flow, CVD, footprint, absorption, iceberg orders, liquidity, open interest, Confluence Engine]
related: [confluence-engine-methodology, market-regime-index-methodology, order-flow-trading-explained]
faq:
  - q: Why does the report separate consumed liquidity from withdrawn liquidity?
    a: Because they look identical in the resting series and mean opposite things. Size that disappeared because it was executed against is a defender being eaten; size that disappeared without matching trades is a defender leaving before the fight. Treating the second as the first manufactures conclusions out of ordinary book thinning.
  - q: Can order-flow figures be reconstructed for dates before you started recording?
    a: Partly. Aggregated trades are publicly retrievable so trade-derived layers such as delta and footprint can be rebuilt historically. Resting order-book depth is not republished by any venue we use so book-derived layers exist only for the window we recorded ourselves.
  - q: How accurate is iceberg or spoof detection?
    a: It is a probabilistic diagnosis and we label it as one. The book is sampled at limited depth on a periodic cadence so anything resting outside those levels is invisible and anything placed and pulled between two snapshots is never seen. The report states this next to the figure rather than in a footnote.
  - q: Does the report contain positions or price objectives?
    a: No. It reports what was measured on a defined window. The Confluence Show issues no signals and no positions in any surface — broadcast or written.
  - q: What makes an order-flow figure reproducible by someone else?
    a: A named stream a third party can subscribe to, a stated window, a stated bucketing rule and a stated causal stamp. If any of those four is missing the number cannot be checked and should not be trusted.
sources:
  - label: Binance public market-data streams
    url: https://developers.binance.com/docs/binance-spot-api-docs/websocket-api
  - label: Hyperliquid developer documentation
    url: https://hyperliquid.gitbook.io/hyperliquid-docs
draft: false
---

## What will the recurring order-flow report measure?

The report measures two things that candles cannot show: **who was aggressing**, taken from the executed trade tape with its taker side, and **what the resting book did about it**, taken from periodic depth snapshots. Everything else in the report is a derived view of one or both of those.

It is not a market commentary with numbers attached. Each figure is a named computation over a named window, stamped with the moment it became observable. Where a measurement is inferred rather than observed, the report says so in the same sentence as the number.

This page is the methodology only. It contains no market data, because a methodology that has to be revised when the data arrives was not a methodology. Live narration of these same layers is what [NAIRO](/nairo) does on air.

## Which raw streams is the report built from?

Two, both public, and their properties differ in ways that determine what can honestly be published. The trade tape is retrievable after the fact; resting book depth is not, and that asymmetry decides which figures a third party can rebuild.

**The trade tape.** Every execution carries price, size, timestamp and the aggressing side. This is the input to delta, footprint, aggression profiling and large-print detection. Aggregated trade history is publicly retrievable, so trade-derived layers can be rebuilt for past dates by anyone with the same endpoint.

**Depth snapshots.** The order book is sampled periodically at limited depth per side. This is the input to the liquidity heatmap, wall detection, replenishment, queue depletion and the passive ledger. **No venue republishes historical resting depth**, so these layers exist only across the window we actually recorded. Pre-recording periods are shaded on the chart, never interpolated.

Two supporting streams provide context rather than flow: funding rate with open interest, and a periodically polled options chain used for dealer-gamma work. They answer positioning questions, not aggression questions, and they are reported separately for that reason.

## What is the measurement window and why is it fixed?

The report is computed on a fixed rolling window rather than a hand-picked range, because a hand-picked range is where selection bias enters. A fixed window means the same rule produced this edition and the previous one, and a reader can check the figure without knowing which dates we would have preferred.

Within that window the bucketing rules are also fixed and stated. Trades are assigned to their bar by a canonical time-bucketing function shared by every consumer, so delta computed for a footprint cell and delta computed for a cumulative series always agree. Price bucketing inside a bar is a fixed count of bins across that bar's own high-low range. Book measurements bucket by price band and by snapshot interval, not by bar, because the book changes on its own cadence and pretending otherwise would fabricate resolution.

The forming bar is excluded from every computation. Only closed candles enter, everywhere, without exception.

## How is each order-flow layer computed?

Each layer is a small explicit rule over one or both streams. The table lists what the report carries and what each figure is actually a statement about.

| Layer | Built from | What the figure states | Stamped at |
| --- | --- | --- | --- |
| Cumulative volume delta | Trade tape | Signed aggression accumulated per bar | Bar close |
| Footprint profile | Trade tape | Buy and sell volume by price inside each bar | Bar close |
| Stacked diagonal imbalance | Footprint bins | Runs of bins where one side dominates its diagonal counterpart | Bar close |
| Absorption | Candles plus volume | Volume far above the trailing median with range far below it | Bar close |
| Defended level | Footprint plus candle shape | Aggression concentrated at a bar extreme that was rejected | Bar close |
| Passive ledger | Trades plus depth | Consumed against withdrawn against replenished size per band | Closing snapshot |
| Iceberg replenishment | Trades plus depth | Executed volume far exceeding the largest size ever shown | Closing snapshot |
| Queue depletion | Trades plus depth | Fraction of a level's shown size consumed with replenishment falling | Closing snapshot |
| Wall behaviour | Trades plus depth | A confirmed wall pulled without trades or absorbed while holding | Bin close |
| Large prints | Trade tape | Individual executions above a notional floor | Trade time |

The vocabulary here is defined at length in [cvd explained](/learn/cvd-explained), [footprint charts explained](/learn/footprint-charts-explained), [absorption in order flow](/learn/absorption-in-order-flow) and [order flow imbalance explained](/learn/order-flow-imbalance-explained).

## The distinction the whole report hinges on

Resting size that disappears between two snapshots disappeared for one of two reasons: it was executed against, or it was cancelled. The series looks identical either way. The meanings are opposites.

So the passive ledger splits every interval three ways. The drop in resting size explained by executed volume is *consumed*. The drop not explained by execution is *withdrawn*. Executed volume beyond the drop is *replenished* — size that came back after being hit.

That split is what makes downstream diagnoses defensible. An iceberg is a level replenishing while being consumed. Queue depletion is consumption without replenishment while the level still shows size. A trapped passive requires a level that was genuinely defended — consumed *and* replenished — then finally exhausted, then traded through with acceptance beyond it. Someone who withdrew was never trapped; they left before the fight. Building any of these on raw resting drops instead of the split would manufacture them out of ordinary book thinning.

## What resolution caveats are published with every figure

Three caveats travel with every figure, stated next to the numbers rather than buried in a footnote. They are the depth to which the book is sampled, the cadence at which it is sampled, and the warm-up a layer needs before it returns anything at all. Each one bounds what the number can be used to claim.

**Sampling depth.** The book is observed to a limited number of levels per side. Anything resting outside that band is invisible to every book-derived layer.

**Sampling cadence.** Snapshots arrive periodically. An order placed and pulled between two of them is never seen at all. Consequently every passive diagnosis — iceberg, spoof, depletion, trap — is evidence, never proof, and the report words it that way.

**Warm-up and coverage.** Layers that need trailing history return nothing until they have it. Layers that need recorded depth return nothing outside the recorded window. A blank is published as a blank; it is never filled with a neutral default, because a fabricated neutral reads as a measurement to anyone downstream.

## How the report can be reproduced

Anyone with the same public endpoints can rebuild the trade-derived half exactly. Subscribe to the trade stream for the instrument, bucket executions into bars by open time, sign each by taker side, and the cumulative delta series will match. Bin each bar's trades across its own high-low range and the footprint will match. The diagonal imbalance test and the absorption test are then pure functions of those two objects plus a trailing median.

The book-derived half is reproducible in *method* but not in *data*, and we say that plainly: without your own recording of depth over the same period, you cannot rebuild a heatmap or a passive ledger for a past window, no matter which vendor you use. That is a property of exchange data, not a moat.

Where the report's figures feed decisions on air, they enter the zone machinery described in [confluence engine methodology](/reports/confluence-engine-methodology), and the regime context they are read against is defined in [market regime index methodology](/reports/market-regime-index-methodology).

## What the report will never contain

No positions, no orders, no price objectives, no sizing guidance and no performance claims. No win rate without a sample size, an interval and the timeframe it was measured on. No figure whose window was chosen after seeing the result.

It is educational market analysis produced by a broadcast that keeps score rather than predicting. The same discipline applies across every surface: the [free delayed stream](/watch), the live room, and these written pages. Anything unclear about scope is answered on the [FAQ](/faq), and coverage per instrument is listed under [markets](/markets).
