Skip to content

docs: OpenRouter behind an allowlist, one credential store, a decision adapter measured in a lab, and the runner with a recorded fallback - #657

Closed
REPPL wants to merge 3 commits into
mainfrom
docs/routing-rulings
Closed

REPPL wants to merge 3 commits into
mainfrom
docs/routing-rulings

Conversation

@REPPL

@REPPL REPPL commented Sep 22, 2026

Copy link
Copy Markdown
Collaborator

What

The product thinker's routing interview of 2026-09-22, after two independent research passes and an ideate gauntlet:

  • adr-2609221009491186: a provider adapter serves only the models it lists, under a vendor denylist no listing overrides; everything else runs on the host. adr-2609221017021499: every external credential abcd holds is named in configuration and kept in one store the person chose.
  • Planned and READY: the OpenAI-compatible API adapter with OpenRouter as configuration, the allowlist, the named key, the run record and a one-time ahoy walkthrough (itd-2609081951381895); the credential store with three homes and one reader (itd-2609221017023290); a decision adapter for abcd's typed judgements that runs in shadow as an abcd lab and whose research note is the evidence a ruling turns a judgement type on with (itd-2609221009495079); the command-line runner, with a configured fallback host and every fall back recorded as intel (itd-2609201916056194).
  • Amended: the model tier takes the escalation rule (one tier up on a failed fix round) and the allowlist; itd-22 is widened so "any harness" includes none; itd-17's learned router is superseded.
  • Recorded, not adopted: the control-programme idea went through the ideate gauntlet and came out reframed — an operator console served by the binary over local web, with a product-thinker pane in their own register, sequenced after the runner. Two kill attempts were fatal to the idea as put.

Why

Jev (TypeSafe AI, on OpenRouter) is a typed-decision model, not a router: it fits abcd's closed-option judgements and nothing generative. Reaching it means reaching an aggregator that also serves the frontier models a person already pays for through their host, so the allowlist is the condition of the integration, not a refinement of it. The same walkthrough is the pattern for every credential abcd will hold, which is why the store is its own record rather than the adapter's private habit.

Review

Three independent passes fed this: a state-of-the-art pass on Jev and model routing (filed as a research note with its sources), a primary-source pass on headless harness invocation, and an adversarial review of the console idea by an evaluator that saw the artefact without its provenance. Every record went through the readiness gate; the record, reviews-charter, decisions-append and docs gates and the full preflight pass.

Records

Assisted-by: Claude:claude-opus-5

…gements get a decision adapter measured in a lab

adr-2609221009491186: a provider adapter serves only the models it lists,
under a vendor denylist no listing overrides; everything else runs on the
host. The OpenAI-compatible API adapter (OpenRouter as configuration) is
written and planned with the allowlist, the denylist, the named key, the
run record and a one-time setup at ahoy that offers three homes for the
key and never touches the harness. A decision adapter for the
closed-option judgements is planned: one interface with the host's own
judgement, shadow mode as an abcd lab, a research note as the evidence a
ruling turns a judgement type on with, Jev the first candidate. The model
tier takes the escalation rule (one tier up on a failed fix round) and the
allowlist; itd-17's learned router is superseded. The research pass is
filed as a note.

Assisted-by: Claude:claude-opus-5
…ne for the routing rulings

Assisted-by: Claude:claude-opus-5
…configured fallback recorded as intel, and itd-22 widened to no harness

Assisted-by: Claude:claude-opus-5
@REPPL
REPPL enabled auto-merge September 22, 2026 15:54
@REPPL

REPPL commented Sep 22, 2026

Copy link
Copy Markdown
Collaborator Author

Superseded by #658, which carries the same work rebuilt off main. The secret scan on this branch failed on a false positive: a spec's footprint line read internal/core/oracle, internal/adapter/openaiapi, internal/surface/cli, and the generic-api-key rule read the package name plus the next token as a key and its value. No credential was involved. The scan reads history, so an edit could not clear it and this branch cannot pass; #658 has the two footprint lines reworded and scans clean.

@REPPL REPPL closed this Sep 22, 2026
auto-merge was automatically disabled September 22, 2026 17:19

Pull request was closed

@REPPL
REPPL deleted the docs/routing-rulings branch September 22, 2026 17:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant