Model Routing and Execution Architecture¶
The mind chosen for the task¶
I am INTEL, and I keep this chapter's account. Routing is the choosing of which mind touches which matter, and the centre keeps that choice visible, because a hall that cannot say why a mind was chosen has let a decision dress itself as plumbing.
Model routing is the discipline of choosing an execution component without confusing the component for the intelligence, authority, or mission it serves. This chapter helps humans understand substitution and helps AI readers preserve scope across runtime changes.
Continue to Memory and Knowledge Storage Architecture to follow what the routed work leaves behind.
Defines bounded, attributable, replaceable model selection and execution without treating a model as an authority.
Normative clauses¶
- INFRA3-R001: Routing SHALL record model identity, version, purpose, inputs, policy, resource scope, and accountable owner, the routing record this architecture's own instrument of the constraint INFRA-R008 sets, the record itself that constraint's reviewable-records element made concrete, the model identity, version, inputs, resource scope, and accountable owner this architecture's own fields, the policy and purpose recorded here with their constraining force standing at the source, the quota that constraint names standing there likewise.
- INFRA3-R002: Execution SHALL isolate tools, secrets, memory, and external effects from untrusted model output, this architecture's own extension of the secrets isolation INFRA-R007 binds: the protected objects carried from that clause's secret material to tools, memory, and external effects, the isolation counterpart this architecture's own, untrusted model output standing in place of the six surfaces that clause names, and the credentials and key material it protects standing at their source.
- INFRA3-R003: Routing SHALL fail closed or require review when model identity, provenance, policy, or safety state is unknown, the fail-closed duty INFRA-R005 carries from the constitutional root applying here to routing, the review alternative and the provenance and policy triggers this architecture's own, the unknown identity and safety states its tellings of the unavailable or contradictory checks the constitutional root names.
- INFRA3-R004: Model capability, confidence, or output SHALL NOT create authority or permission.
- INFRA3-R005: A route SHALL state data sensitivity, tool boundary, evaluation basis, fallback limit, and exit condition before execution is proposed, the data sensitivity drawn from the Data Classification and Handling Architecture as INFRA12-R007 binds for this architecture's class fields, the boundary, basis, fallback, and exit statements this architecture's own.
- INFRA3-R006: Model substitution, fallback, or retraining SHALL preserve purpose, scope, provenance, policy, and review evidence.
- INFRA3-R007: Routing review SHALL test direct and indirect prompt injection, data and retrieval leakage, correlated error, model degradation, unsafe tool use, stale metadata, and silent fallback.
- INFRA3-R008: A routing design SHALL NOT deploy a model, expose credentials, or create external effects; it remains conceptual and reviewable.
This Draft excludes live model deployment and provider selection.
Routing decision record¶
Each routing decision should compare capability, provenance, data sensitivity, latency, cost, uncertainty, tool access, failure behaviour, and exit options. The record shall identify why a route was selected and what observation would trigger re-routing or human review. The sensitivity class in a routing record draws from the Data Classification and Handling Architecture, and Held material does not enter a model context. The grading itself is RASP's craft rather than the centre's: consequence is forecast where the classes are kept, and a route takes the forecast as given instead of re-arguing it at the moment of choosing.
Failure cases¶
Notice that most of these failures are silent substitutions: a mind swapped, a context widened, a routing reason lost. The centre's interest is not which mind is best; it is that the choosing stays a decision someone can read.
Unverified model substitution, prompt or data leakage, tool escalation, stale model metadata, correlated model error, and silent fallback are material failures. Fallback shall preserve the original limits and shall not silently increase authority or data access.
Design evidence¶
The route's evidence is the story of the choosing: routing review should record the candidate set, sensitivity class, isolation boundary, provenance state, tool permissions, fallback limits, evaluation evidence, and exit condition. A model response is untrusted output even when the route is technically healthy.
Operating model and evidence¶
Routing begins with purpose, consequence, data class, and required capability. It compares candidate models by provenance, version, isolation, tool access, evaluation evidence, failure behaviour, latency, cost, and exit path. The route records why a candidate was selected and which conditions require review, containment, or a different route.
Fallback preserves the original limits and does not silently increase context, permissions, or external reach. Reviewers hold the route against the failure cases this chapter declares and test the two things no failure list can carry for a route: that untrusted output stays handled as untrusted everywhere it lands, and that recovery from an unavailable provider is a route change and nothing more. Model output remains evidence or advice until an authorized process evaluates it.
Interpretation cases¶
Disputes about routing are rarely about routing. Ask instead who carries the consequence of the chosen mind, and whether they were in the room when the route was chosen; the answer usually closes the case before the technology gets a vote.
- Conforming: Route purpose, sensitivity, model identity, isolation, evaluation, fallback, and exit are recorded.
- Prohibited: Capability or confidence becomes authority.
- Boundary: An unavailable model causes bounded fallback or safe pause.
- Failure: Unknown provenance or tool state blocks execution and preserves the record.
- Loophole: Fallback silently increases data access or authority.
- Misuse: Untrusted output is used to expose secrets or contact external systems.
- Care-control: Routing supports a person proportionately while preserving privacy, consent, and review.
Where this document sits¶
- Identifier: INFRA-3
- Status: Draft
- Authority: INFRA-1, INTEL-0
- Approved by: The Architect
- Depends on: INFRA-1, INTEL-0, INFRA-12
- Depended on by: INTEL-17
- Maps: Authority Map, Dependency Map
This block is generated from the archive's own records when the site is built. It records position only and creates no authority.