What the Money Actually Does: The ELCI Spending Engine
ELCI simulates a thousand possible retirements, and the spending engine is where each one gets lived: month by month, it plays out how a real household would spend, adapt, pay its taxes and care bills, and sometimes run out. This paper explains what the engine models, why each piece is there, how we check it, and where it is honestly limited.
A measurement instrument, not an optimizer
Most retirement calculators answer a question like "what is the largest safe withdrawal rate?" The ELCI spending engine answers a different one: given the plan you actually stated, what happens? It takes one simulated health trajectory for each spouse, one simulated market future shared by the household, and the plan as entered (spending priorities, income, insurance, accounts, behavioral style), and it steps through the retirement one month at a time, recording what was spent, what it cost in taxes and premiums, and how comfortable each month was against the household's own declared standards. It does not search for a best plan. It shows what a plan produces, so that you can change one thing and compare.
That comparison discipline is structural, not cosmetic. The engine itself is a single fixed monthly step function. Every scenario (claim Social Security later, drop the inflation rider, buy long-term care insurance, tighten the belt faster in a crash) is expressed purely as a difference in the plan's configuration. The engine is never special-cased to answer a what-if, which means two scenarios differ only in the thing you changed, and the thousand simulated futures behind them can be replayed identically on both sides. When we report that a change moved an outcome, the same simulated lives were lived twice, once each way.
One accounting rule runs through everything: the engine works in today's dollars. Inflation from the simulated market enters only where the real world is genuinely nominal: a pension without a cost-of-living adjustment visibly erodes, a long-term care policy's dollar caps and benefit pool grow only as fast as its rider, and tax brackets and the fixed Social Security taxation thresholds produce bracket creep and the growing "tax torpedo." Those are not modeling conveniences. They are three of the quietest ways real retirements lose ground, and the engine carries them so that they can be seen.
One month, in order
Each simulated month runs a fixed pipeline. The market return lands first, across every account. Then the health systems are priced: pre-Medicare insurance, Medicare costs, long-term care, and any paid care the month's health states require. Then income is computed, including the Social Security claiming logic described below. Then the month's share of the year's estimated tax joins the bills. Only then does spending happen, in strict priority: essentials are funded first and may draw the portfolio all the way to zero, because a real household pays the nursing bill before it books a trip.
Discretionary spending comes second and is gated by design: under the adaptive policies it is throttled before the money is gone rather than after. When discretionary funds are constrained, every category receives the same fraction of its own demand, so a squeeze is shared in exactly the proportions the user chose rather than by a hidden priority list. Surplus income that is not spent stays in the portfolio, and the engine routes it into accounts tax-intelligently.
Finally the withdrawal itself is sourced: split across taxable, tax-deferred, and Roth accounts in a defensible order, split between spouses' retirement accounts with early-withdrawal penalties priced when they apply, and recorded into the running tax year. The month closes by scoring comfort. None of this ordering is arbitrary; several subtle behaviors (for example, an emergency Social Security claim that fires when income no longer covers essentials and the runway is short) only work correctly because the essentials figure exists before the claiming decision is made.
Income is harder than it looks
Income in the engine is a uniform list of streams: Social Security, pensions, annuities, wages, installment sales, one-time inheritances. Each stream knows its owner, its start and end triggers, whether it is inflation-adjusted, how it is taxed, and what happens to it when its owner dies. Survivor treatment matters enormously and is modeled per stream: most income continues to a survivor at a stated fraction, but Social Security follows the actual rule, where the survivor keeps the larger benefit and loses the smaller one. A couple that looks comfortably funded on joint income can be structurally underfunded for the survivor, and the engine makes that visible rather than averaging it away.
Social Security claiming is dynamic, not a fixed birthday. Each spouse has a planned claim age, but the engine also claims early under sustained financial stress, on serious health decline, or in a genuine emergency when the portfolio is nearly exhausted, because that is what real households do. Once claimed, the age locks and the statutory early-reduction or delayed-credit adjustment applies for life. For a claimant still earning wages before full retirement age, the earnings test withholds benefits, and the engine also models the part almost everyone forgets: those withheld months are repaid later through the statutory recomputation at full retirement age. The test defers benefits; it does not confiscate them, and a model that skips the repayment quietly punishes working.
Disability is modeled too. When simulated health ends a working spouse's earned income, Social Security Disability Insurance pays after the statutory waiting period, at the full unreduced benefit, converts to the retirement benefit at full retirement age, and triggers Medicare eligibility before 65 on the timeline the law sets. This matters because the scenario it covers (a worker's income disappearing years before the plan expected) is the kind of compounding setback a retirement model exists to stress-test, and leaving it out makes early health shocks look artificially catastrophic.
Households adapt, so the model does
The engine's adaptive machinery models a household that notices. Discretionary spending rides a comfort level between two numbers the user declares per category: a floor below which cuts genuinely hurt, and a target above which extra is just saved. Being well funded lifts the level toward the target; a market drawdown pulls it toward the floor. The adjustment is asymmetric, expanding faster than it contracts, because lifestyle ratchets are real. It is smoothed on a timescale of months, so spending responds to market cycles rather than jerking with every tick. And the drawdown signal tracks the market itself, not the account balance, so a planned spend-down before Social Security starts does not masquerade as a crisis, while a genuine crash engages the full defense.
That dial is the first of three policies the product offers, under the name Behavioral. The second, the annual checkup, is the default, and it is the adaptive idea made human-executable: once a year, a single funded-rate number maps onto a quantized ladder of spending levels, with a ratchet that limits how fast comfort is cut, an off-cycle review that fires when a serious health event persists, and a deep-crash trigger for severe markets. The third, spend the target with no adjustments, is the honest baseline: running a plan through it shows what refusing to adapt costs. (Rigid textbook rules, fixed-percentage and fixed-dollar withdrawals, live only in our internal research tooling, where they belong: they are the premise of the academic safe-withdrawal-rate literature, and we use them to reproduce those results, but they assume a retiree who never reacts, which is why the product does not offer them.)
The funded rate behind the annual checkup is the engine's most deliberate piece of judgment. It is not a naive balance-divided-by-spending snapshot. It is a forward solvency projection: the engine walks the plan ahead through every scheduled transition (income starting or ending, Medicare handoffs, a mortgage ending) and asks what the steady state looks like on the far side. A household two years from a large pension should not panic-cut today, and a household whose comfortable present depends on a stream that ends in three years should not coast. A spot ratio gets both of those wrong; the projection gets both right.
Health care, in three eras
Before Medicare, early retirees face the insurance bridge, and the engine models it with the machinery that actually determines what people pay: marketplace premiums by age and household, premium tax credits computed from the household's modeled taxable income against the federal poverty guidelines, the subsidy cliff under current law, cost-sharing reductions for lower-income households, and a year-end reconciliation where the advance credit is settled against actual income. The engine follows this coupling in both directions: withdrawal decisions change taxable income, which changes the subsidy, which changes the bills, which changes the withdrawal.
From 65 (or earlier via disability), each spouse pays a modeled Medicare bundle: premiums by age band, expected out-of-pocket costs scaled by simulated health state, and the income-related surcharge, which the engine computes the way the government does, from household income two years earlier. That two-year lag is a classic planning trap (a large withdrawal today raises premiums two years from now), and modeling it is one of the reasons the tax and health calculations are linked.
Late-life care is the deep end. The engine infers the care setting from each spouse's simulated function and cognition (home care, assisted living, nursing care, or paid supervision for cognitive impairment in the community, with costs shared sensibly when one household's services cover two impaired spouses). It models what Medicare's post-acute benefit really does: short, improving episodes resolve at little or no cost, while episodes that turn chronic lose coverage and bill a realistic catch-up. Long-term care insurance is modeled as an actual contract, per covered person: the tax-qualified benefit trigger, the elimination period, nominal monthly caps and a benefit pool grown by the inflation rider, premium waiver while on claim, and a pool that can run out. Whether such a policy is worth buying is the kind of question people bring to this tool, and it cannot be answered with a stylized care model.
Taxes are always on
There is no tax-free mode. Every plan runs an annual tax overlay on the monthly spending: at each year's open, a solver sizes the gross withdrawal that nets the intended spending after accounting for the household's other income, Social Security's provisional-income taxation, capital-gains stacking, required minimum distributions, wage payroll taxes, and state tax. One twelfth of the estimate accrues monthly alongside essentials, so the plan is always paying its taxes as it goes rather than discovering them at the end.
Each December the year trues up: required minimum distributions are enforced, the year's actual withdrawals and income are taxed against what was accrued, early-withdrawal penalties settle, the marketplace subsidy reconciles, and the year's income is recorded to drive future Medicare surcharges. Filing status follows the household through widowhood with the real rules, including the final joint year. Cost basis in taxable accounts is tracked so that selling appreciated assets is taxed on the gain, not the proceeds.
One assumption deserves plain statement: the engine treats today's tax law as persisting for the life of the plan. Scheduled sunsets are projected as extended, because Congress's historical habit is extension, with one deliberate exception: the Social Security taxation thresholds, which are frozen in actual law, stay frozen in the model, so their real bite grows exactly as it does in the world. You may disagree with the persistence assumption. It is disclosed so that you can.
Scoring comfort, not just survival
Simulators usually report a success probability: did the money last? The engine scores every month of every simulated life against the household's own declared standards. Essentials covered with discretionary spending at its target is full comfort. Spending pushed below a declared floor registers as genuine sacrifice. An essentials shortfall always scores below every discretionary outcome, no matter how the categories are configured; comfortable extras can never paper over an unpaid necessity. The scores also adjust for health, because a household with a spouse in a nursing facility does not want the same travel budget it wanted at 67, and scoring it against that budget would manufacture false misery.
The engine distinguishes two kinds of belt-tightening that a single yellow flag would conflate: a voluntary, temporary cut made to defend the portfolio through a market drawdown, and a persistent cut forced by genuinely insufficient wealth. They have different causes, different durations, and different remedies, and the engine records enough to tell them apart.
Red means something specific and severe: the household's essentials and care can no longer be funded under its own stated rules and resources. The model deliberately stops there. It does not simulate the informal rescues a real family might reach for (adult children, Medicaid spend-down, selling the house), because the intended user is the person planning not to depend on them. Red is the boundary of the plan, not a prediction of destitution, and treating it that way keeps the signal honest.
How we know it works
The most important check is that the engine contains the classic experiment as a special case. Its subsystems switch off cleanly, and with all of them off (fixed real spending, a flat thirty-year horizon, no taxes, premiums, or care costs) it is running the exact world the 4% rule came from, and it reproduces that literature's results there. Everything this paper describes is then added back one mechanism at a time, on the same simulated lives, so each addition's cost is measured as a true departure from a baseline anchored to independent published work.
One further check is unique to the annual checkup policy: it is required to be executable by a human being. A person with a one-page worksheet and the same yearly numbers must reach the same decisions the simulated household reaches, including the off-cycle review a persistent health event triggers. A policy the engine could follow but a person could not would be a simulation artifact, not a plan.
More on the 4% rule, and where the market model underneath lands against the Trinity study and its global successors, can be found in the MarketPath paper.
What this model does not know
The behavioral parameters (how fast a household expands and contracts spending, how sharply comfort responds to a drawdown, how health scales the appetite for travel) are plausible, defended defaults, not estimates fitted to panel data. We state this plainly because it shapes how the tool should be used: single absolute numbers deserve some skepticism, while comparisons are robust, since both sides share whatever error the defaults carry. The tool is built around comparison for this reason.
Several simplifications are disclosed and deliberate. Social Security is modeled per spouse from the benefit figures you enter (whatever each of you actually expects to receive), with real survivor, claiming, earnings-test, and disability logic on top. State tax is a flat-rate placeholder until the per-state model ships. Health cost presets are national medians adjusted for age and health, not an individual claims model. Medicare's post-acute benefit is approximated by a recovery-trajectory rule that leans slightly generous in rare oscillating cases and slightly harsh on short skilled stays; both effects are small and measured. Care prices are also carried at today's levels in real terms; if care costs keep outrunning general inflation, as they have for most of the past few decades, the late-life care tail will be more expensive than modeled.
Two modeling choices will strike some readers as harsh, and both are positions rather than gaps. Self-insured late-life care is modeled without Medicaid, reverse mortgages, or unpaid family labor, because the user this tool serves is planning not to rely on them, and an uninsured care tail is the intended place to watch a plan cross its boundary. And intact households here do not follow the famous declining "retirement spending smile": the panels behind the smile recorded what impaired households spent, which embeds documented unmet need and an enormous unpaid-family-care subsidy. This engine prices purchased, safe independence instead, which costs more. A model that matched the smile would look cheaper and would be quietly assuming your children provide the difference.