Digital One Foundation The Delegation Record
Paper 004 · Limits

What a switch reading plaintext cannot settle.

A switch in the request path forwards a response and takes delivery of the model name inside it. This paper sets out what that position can and cannot settle: four reasons, where the sentence stops, and the capture that would turn the reasoning into evidence.

Absent an attestation from the party that ran the model, no component reading plaintext in the request path can establish which model produced a response. The model name inside the bytes such a component forwarded and received is a string the upstream chose to send. Four reasons hold the sentence up, and each shows the scope doing work rather than hedging.

On the call it is forwarding, a component in the request path chooses none of its inputs. It forwards a tenant's prompts; it does not select them. Whatever could be established by selecting inputs is unavailable to a component that selects none of its inputs.

It cannot re-execute the work of a model whose weights it does not hold. Where it does hold them, a second run under different serving conditions settles nothing about the first.

An attestation made at the far end does not reach this component in the bytes it handles. Whatever the party that ran the model established about the machine it ran on, a component reading plaintext takes delivery of a response, not of that party's evidence about its own platform; these notes checked no attestation specification and make no claim about what one covers. A construction that does attest which model answered binds the workload as well, which is why it is a different construction rather than a counterexample.

The one cryptographic object in the response is verifiable only by its issuer. Anthropic documents that "full thinking content is encrypted and returned in the signature field on each thinking block", that "the API uses the signature to verify that thinking blocks were generated by Claude when you pass them back", and that "the signature field is opaque: don't interpret or parse it".[1] A value verifiable by its issuer is evidence for that issuer, not for an intermediary holding it.

Where this sentence stops

The limit above is a statement about a position — plaintext, in the request path — and not a statement about what is knowable in general. Moving the question to a party that can attest the execution itself changes the answer, and that is a different construction from the one these notes describe. A record built on the unqualified form of that sentence is built on something false.

Open problem · identified while assembling this paper, 12 September 2026

No capture made on this workstation distinguishes a substitution from an honest answer

Everything above is reasoning over published documentation. What would turn it into evidence is a capture: a request path exercised end to end with a recorded substitution in it, and the bytes each component saw, saved and hashed before one of them is quoted. No such capture was produced for these notes. The shape that would produce a real one is narrow — a local logging proxy in front of a stub upstream, driven until the upstream rejects a configuration it cannot serve, which yields a real status line and real bytes rather than a described one.

Two questions would then be answerable that this paper leaves open: what a harness writes down when the returned name differs from the requested one, and whether a diagnostic emitted at request time reaches any durable artefact on the operator's side. Both are hypotheses until a capture exists, and are named here as hypotheses.

On the provenance of this material

The question these notes work on came out of building a routing switch inside Gateward, a Digital One product. It supplies no evidence here: every quotation above is from a published page a reader can fetch, cited with the date it was read, and the Gateward repository is not public, so nothing in it is a claim a reader can check today. Deliberately absent: prices, plans and tiers, availability, and deployment internals.

References

  1. Anthropic, Extended thinking, Claude Developer Platform documentation, on thinking-block signatures and on passing thinking blocks between models, platform.claude.com/docs/en/build-with-claude/thinking, read 12 September 2026.