Skip to content

Tiered confidential-compute escalation contract for model-router #22

Description

@mdheller

From the SourceOS-vs-Apple ModelCarry analysis (spec-intake 2026-08-03), section 5.2 medium-term. Apple's on-device to PCC escalation has a named confidential-compute boundary. SourceOS routing tiers need an equivalent: where does an over-scale request go, and under what attested-compute guarantee?

Acceptance criteria

  • An escalation contract (schema + validator) with: local-by-default posture, an attested confidential-compute escalation target, and the trigger condition (task exceeds local capability).
  • The escalation decision and its confidence are propagated as a first-class provenance record (the Palantir-comparison point made operational at the model layer).
  • No-user-data-for-training and end-to-end-encryption posture declared as invariants of the escalation target.
  • Keep uncertainty-with-provenance as a first-class primitive on the escalation path (do not regress the SourceOS differentiator for delivery convenience).
  • Wired into make validate; valid + negative fixtures.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions