Digital One Foundation The Delegation Record
Paper 008 · Limits

What these notes cannot do, and what would settle it.

The limits of these notes, stated before anyone else states them: no measurement, no failing input, no conclusion about permission, and no escape from self-attestation. Then the four questions it leaves open, and what would close each one.

They carry no measurement. An earlier pass produced figures of the right shape and did not keep its artefacts, and no repository of the switch this work came from exists on the machine these notes were written on — so no per-call cost, no latency claim, no token reconciliation. A number without the artefact it came from is a press release with a decimal point.

They carry no failing input. The route that matters most here — a tool handler calling out of band — produces no model call in the path, so the thing that would need capturing is the thing that is structurally absent. What Paper 004 carries instead is an open problem, the form with no failing input by definition.

They reach no conclusion about permission. Two things are routinely confused: a support-policy sentence in documentation states what a vendor will help with, and silence in an instrument establishes that the instrument does not address the act — never that it permits it.

And they do not escape self-attestation. The operator signs its own record from its own position, which is the epistemic position the model string occupies in Paper 004. The gain is not certainty. It is that a reader can tell, field by field, which sentences their author could have known first-hand, and direct doubt at the right half rather than at the whole document. Labelling each field as attested or received does not lift the record out of that position; it makes the position legible to a reader who was not there. That is worth doing and it is less than a proof, and a paper that let the labelling stand in for the proof would have committed the error Paper 004 spends itself avoiding.

And the open items, each with what would settle it and who decides:

  1. Whether a two-name field pair catches a substitution in practice. Settled by the capture described in Paper 004; two agreeing names neither settle it nor falsify it. Whoever builds the switch decides.
  2. Whether counts from two providers can be put on any common footing. Settled by measurement on a named corpus with both counters and both conventions named; no such figure exists here.
  3. Whether a switch's own decision record is worth anything to a reader who does not trust the operator. Settled by making it checkable against an earlier commitment rather than the operator's word — the subject of the earlier work in this record: a record shows what was done, not that it was right.
  4. Whether anything short of an attestation from the party that ran the model can raise the model name above a received string. Nothing read for these notes on 12 September 2026 does, which is a statement about what was read rather than a proof that nothing does.

Nothing above is decided here: the record shape in Paper 006 is a proposal.

On the provenance of this material

The question these notes work on came out of building a routing switch inside Gateward, a Digital One product, and the direction in Paper 007 was raised by frontierscore.ai, another Digital One property. Neither supplies evidence here: every quotation in these notes is from a published page a reader can fetch, cited with the date it was read. The Gateward repository is not public, so nothing in it is a claim a reader can check today, and the earlier measurement pass that lost its artefacts is why no figure from it is printed. The second property's public pages link no methodology — no test design, no prompt set, no calculation — read 12 September 2026, which is why Paper 007 treats a published method as the condition. Deliberately absent: prices, plans and tiers, availability, and deployment internals.