When an agent harness hands a step to another model, a switch — a proxy, a gateway, whatever an operator has put in front of the models — watches the call go by, and writes down both what it did and what the response told it. These are working notes on that seam: what a delegation record has to contain, and what it structurally cannot show. They are for someone deciding what to demand of one before relying on it, not someone deciding whether to buy the thing that writes it.
Why a step is routed to another provider's model at all: the saving, and why the evidence for a saving is the pair of facts a request path receives rather than knows.
Paper 002A tool handler calling another provider leaves no model call in the path; a gateway base URL passes a switch and is documented as unsupported for this purpose.
Paper 003What each route gives a record, and MCP sampling: the one protocol that wrote the seam down, returned the model name from the chooser, and is retiring it.
Paper 004Why, absent an attestation from the party that ran it, a component reading plaintext cannot establish which model answered; where that stops; and the capture that would test it.
Paper 005SLSA, RATS, SCITT and NISTIR 8112 each separate first-hand knowledge from a copied claim. None settles what a cross-provider route does to that split.
Paper 006A record shape split into attested and received fields, and the two traps in proving a saving: counts in different units, and cumulative stream usage.
Paper 007The affirmative: a switch can attest its own routing decision. Not that the decision was carried out as addressed, and not that it was sound.
Paper 008No measurement, no failing input, no conclusion about permission, no escape from self-attestation, and the open items, each with what would settle it.
Ordinary code can reach another vendor's model, putting no model call in the path. The one route a switch can watch — a base URL pointed at a gateway — is one Anthropic's documentation says it does not support for routing Claude Code to non-Claude models (code.claude.com/docs/en/llm-gateway, read 12 September 2026). The record instead carries the name asked for and the name returned as two fields. Which model answered is not among them: that needs an attestation from the party that ran it, which nothing read here settles.
Gateward, a Digital One product, is why this subject is here. Its repository is not public and the hosted service proprietary, so these papers rest on neither: every external quotation is from a published page with the date it was read, and their one internal citation is a sibling paper in this record. They print no figure — an earlier pass lost its artefacts — and call a hypothesis one. Deliberately absent: prices, plans and tiers, availability, deployment internals, and whether any of this is permitted, which Paper 008 leaves open: silence in an instrument shows only that it does not address the act. Instruments are context: they are not legal analysis, they are not advice, and where a legal question is genuinely unsettled the papers say so rather than resolving it in passing.
These notes are contributed under CC BY 4.0: quote, reproduce and build on them with attribution, a link to the licence, and adaptations marked as such. The Foundation is an entity in formation; no public-benefit (ANBI) status is claimed at this time.