Reliable AI systems for critical decisions and workflows.

Orcher is the agentic control plane for critical work. It unifies governance, cost-disciplined intelligent routing, strict enterprise data boundaries, elastic compute, and role-scoped authority — enforcing every directive end to end and compounding Dipp Intelligence with each verified execution, towards enterprise superintelligence.

Orcher across your systems of record

— / 8

Fig. A

SOR.01EHR & clinicalSOR.02Claims & billingSOR.03ERP & financeSOR.04CRM & servicingSOR.05HRIS & IAMSOR.06Data warehouseSOR.07Policy & GRCSOR.08ITSM & opsCONTROL PLANEOrcherRole-bound · verifiedRecorded · governedAny model provider or agentImmutable audit ledger

Guided walkthrough

How Orcher connects to your systems of record

Select any node to read how it participates. Orcher is the control plane that makes enterprise autonomy governable: scope, identity, policy, evidence, enterprise data boundaries, cost and observability are enforced together, so agents can act at machine speed inside boundaries the enterprise sets — and nothing reaches a system of record until every one of those controls clears.

Source: Vol. I, p. 13 — How Orcher delivers HITR
Every read, check and write between an agent and a system of record passes through the control plane — bound to a role, verified before commit, and hashed into evidence.
Vol. I · p.4Deployment has outrun provability: enterprises are running agents far faster than they can trace, contain or evidence what those agents do.

One Verified Execution Cycle

Fig. VEC-01

Input

IN.A

Directive

Intent issued by a named professional, not an anonymous prompt.

IN.B

Context

Systems of record, policy, and entitlements resolved at request time.

Control plane · Orcher

C1

Role Identity Fabric

Binds the directive to the role and its cryptographic authority.

C2

Logic Scrubber

Verifies the proposed action against records before commit.

C3

Data Control Gateway

Data boundary, redaction, and egress rules enforced in path.

No model executes until the role, the logic, and the data boundary all clear.

Output

OUT.A

The action

Executed under a named human's authority, at machine speed.

OUT.B

Dipp Intelligence

The verified execution path, retained by the enterprise.

Immutable Audit Ledger hashes every transitionProvider-neutralMetered in VECs

What we do

Compliance

Policy stops being a document and becomes an executable gate. Each proposed action is checked against your systems of record — eligibility, licensure, limits, jurisdiction — and the cycle halts before anything partial is written. What commits is hashed into an immutable audit record.

Explore Compliance

Data control

A hard perimeter around enterprise data: the enterprise data boundary enforced per directive, sensitive fields masked before they reach a model, and contractual no-training guarantees on every provider path — so using frontier models never means donating your data to one.

Explore Data control

Cost and control

Economic ceilings bound autonomy before spend runs away, and one observability view covers every model, framework and agent in flight. Scope, identity and entitlements are enforced at execution rather than requested at review.

Explore Cost and control

Orcher · seven components

One control plane. Seven jobs it never delegates.#

Four sequential gates decide whether an action may commit. Three continuous controls hold data, cost and visibility while it runs. Each is a separate component with its own contract and its own evidence.

The strategy

Dynamic model routing.#

Binding a platform to one heavy frontier model wastes tokens and leaks proprietary data. Dipp AI's strategy — and the reason Orcher's seven components exist — is intelligent routing: decouple orchestration from any single provider, match each task to the cheapest model that can carry it, and keep prompts and data inside the enterprise's own tenant boundary.

ENTERPRISE TENANT BOUNDARY — in-region, no training on your dataDirectiveStated intent, boundto a human roleCost GovernanceClassifies by stakes,not by developer habit4,500× price spreadIn-house / smallRoutine classification, extraction, lookup~60%Open-weight / mid-tierSummaries, drafting, structured reasoning~30%FrontierGenuinely complex, high-reasoning, novel~10%DIPP AI TECHNOLOGIES · ORCHER
Dynamic model routing across In-house small model, Open-weight mid model, Commercial mid-tier, Frontier model classes. Price spread across 400+ models and 70+ providers: 4,500× (Vol. I, p.25).
01

Decoupled orchestration

Switch providers in a week, not a quarter.

An orchestration layer sits in front of every AI task rather than inside one vendor's SDK. Directives, roles, policy and evidence live in Orcher, so a provider change is a routing-table change — a week of work rather than a quarter of re-platforming — and no model vendor becomes the system of record for how the enterprise operates.

The protocol stack
02

Task-to-model matching

Roughly 90% of workloads never need the frontier.

Cost Governance routes by the stakes of the action rather than the habits of the developer. Standard, routine queries — roughly nine in ten workloads — go to cheaper open-weight or small in-house models; expensive frontier models are reserved for genuinely complex, high-reasoning tasks. Across 400-plus models and 70-plus providers the price spread is 4,500× (Vol. I, p.25), so the routing decision is the economics.

Cost Governance
03

Private tenant boundaries

Providers never learn from your interaction data.

The Data Control Gateway forces data and prompt histories to stay inside the company's own cloud environment — a private tenant, in-region — and verifies training exclusion and the data boundary on every call before a token leaves. Using frontier capability never means donating enterprise interaction data to the firm that sells it back.

Data Control Gateway

Runtime workflow

Authority per directive.#

Routing is not a developer preference resolved in a config file. For every directive, Orcher resolves who is accountable, selects the cheapest model class that authority permits, carries the data boundary along the chosen route, and hashes the whole decision into one evidence chain that reads the same across every provider.

  1. 01

    Authority is resolved before a model is chosen

    Who is accountable, and what may they authorize?

    The directive arrives with a named issuer. The Role Identity Fabric resolves that professional's current entitlements and binds them to this cycle, so the routing decision is made against a known authority rather than a service account. Anything outside the role halts here — before a single token is spent.

    Enforced by

    Emits
    A role-bound authorization token scoped to this directive.

  2. 02

    The routing decision is a policy decision

    What is the cheapest model class this directive's stakes permit?

    Cost Governance classifies the workload by stakes, sensitivity and reasoning depth, then selects the cheapest sufficient model class within the ceiling in force for that role. Roughly nine in ten workloads clear on routine classes; frontier capacity is reserved for complex work. The chosen class, the alternatives considered and the ceiling applied are all recorded as part of the decision.

    Enforced by

    Emits
    A signed routing decision: class chosen, ceiling applied, rationale.

  3. 03

    The data boundary travels with the route

    May this payload reach that provider, in that region?

    The Data Control Gateway applies data-boundary, redaction and training-exclusion rules to the route that was chosen, not to a default path. If a class is otherwise optimal but its provider cannot satisfy the boundary, the route is refused and the next sufficient class is selected. Consistency across providers is enforced by the gateway, not negotiated per vendor SDK.

    Enforced by

    Emits
    A per-call boundary attestation: region, redactions, no-training terms.

  4. 04

    Every decision lands in one evidence chain

    Can this be replayed and defended months later?

    The Immutable Audit Ledger hashes the directive, the authority, the routing decision, the boundary attestation and the committed action into a single tamper-evident chain. Observability streams the same run across whichever providers were involved, so one query answers what was asked, who authorized it, where it ran and what it cost — regardless of vendor.

    Enforced by

    Emits
    A replayable, hashed execution record with cross-provider cost and latency.

Interactive · routing simulator

Enter a workload. See where it routes.#

Each workload type carries a different level of stakes, sensitivity and reasoning depth. Select one to see which Orcher component owns the decision, which model class it routes to, which gates run, and what that does to tokens and cost against a frontier-default baseline.

Workload type

Routing decision

Document classification and routing

High-volume intake: label the document, extract identifiers, route it to a queue. No irreversible write, no judgement call.

Decided by

Cost Governance

Routed to

In-house small model

Runs inside the tenant. No egress, lowest unit cost, deterministic latency.

Token reduction

42%

1,800 → 1,044 tokens

Cost per directive

$0.00013

baseline $0.0432 on frontier model

Cost saving

100%

2360ms faster median

Gates that run before commit

  1. Role scope check
  2. Cheapest-sufficient class
  3. In-tenant execution
  4. Hashed record

Stays inside the tenant entirely — the payload never reaches an external provider.

Indicative class prices per 1M tokens: In-house small model $0.12 · Open-weight mid model $0.60 · Commercial mid-tier $4.50 · Frontier model $24.00. Illustrative only; the 4,500× spread across 400+ models and 70+ providers is from The Enterprise Superintelligence Report, Vol. I, p.25.

Interactive · economics

What routing does to the bill.#

A frontier-default estate pays the top price band for every workload, including the nine in ten that never needed it. Move the inputs to your own volumes and see the token waste removed and the cost impact of the routine-versus-frontier split.

Your estate

250,000

One directive is one verified execution cycle.

5,000

Prompt plus completion, before scoping and redaction.

90%

Dipp AI's routing model puts this at roughly 90%; the remainder is frontier-only.

32%

Directive scoping, field redaction and cache reuse before a model is called.

$24

Your blended frontier rate.

$0.60

In-house or open-weight class hosted in your tenant.

Estimated impact

Monthly cost, frontier default

$30.0K

1.25B tokens at the top band

Monthly cost with routing

$2.5K

$459 routine · $2.0K frontier

Token waste removed

400.0M

32% of 1.25B never reaches a model

Cost reduction

92%

$27.5K per month

Annualised

$330.0K

Retained by routing 90% of directives to a routine class and reserving the frontier for the 10% that genuinely needs it — with every routing decision hashed into the same audit chain as the action it paid for.

Estimates only, for planning conversations rather than contract terms. The 4,500× price spread across 400+ models and 70+ providers, and the 68% of AI programmes running over budget, are from The Enterprise Superintelligence Report, Vol. I (pp. 25, 9).

Proof points

The strategy, in measurable terms.#

Dynamic model routing is only a strategy if it moves numbers a finance team and an auditor both recognise. These are the outcomes it is accountable to.

Cost

4,500×

price spread across 400+ models and 70+ providers

The spread between the cheapest sufficient model and the frontier default is the entire economic case for routing. A directive sent to the wrong class does not fail — it just costs orders of magnitude more than it had to.

Vol. I, p.25

Token waste

~90%

of workloads never need a frontier model

Routine classification, extraction, summarisation and drafting clear on in-house or open-weight classes. Reserving frontier capacity for genuinely complex work is what turns AI spend from a run-rate into a budget.

Dipp AI routing model · Vol. I, p.25

Budget

68%

of enterprise AI programmes run over budget

Overrun is a control failure, not a forecasting failure. Cost Governance applies a ceiling per role and per directive and halts loops at the step boundary rather than at the invoice.

Vol. I, p.9

Latency

10×

faster on routine classes than a frontier default

Cheaper classes are also materially faster. Routing the routine nine-tenths off the frontier shortens the median directive as a side effect of the economics.

Indicative class latencies, Orcher routing table

Auditability

28%

of enterprises can trace an agent action end to end today

Every routing decision Orcher makes — class chosen, alternatives considered, ceiling applied, boundary attested — is hashed into the same evidence chain as the committed action, so the economics are as auditable as the outcome.

Vol. I, p.6

Portability

1 week

to change providers, not a quarter of re-platforming

Because orchestration is decoupled from any vendor SDK, a provider change is a routing-table change. Directives, roles, policy and evidence stay in Orcher.

Dipp AI protocol stack contract

78%

of enterprises run agents in production

Vol. I, p.2

28%

can trace an agent action end to end

Vol. I, p.6

144:1

non-human to human identities

Vol. I, p.11

54%

have already had an agent-related incident

Vol. I, p.2

Delegated authority held inside the boundary of a single accountable role
A role binds the action to the authority of the professional who owns it.

Pioneered at Dipp AI · 1 of 8

Human-in-the-Role, not Human-in-the-Loop.#

Human-in-the-Role is the first of eight primitives we defined — and it only works because the other seven exist. A loop asks a tired person to approve a plausible action in thirty seconds. A role binds authority, scope, data, spend and evidence to the professional who answers for the outcome, enforced at execution rather than requested at review.

Vol. I · p.11A loop requests oversight at review and degrades under load. A role enforces authority at execution, so out-of-authority work cannot run at all.
Fig. HITR-11Human-in-the-Loop versus Human-in-the-Role execution flow — the loop reviews after the fact, the role constrains before commit.
Orcher's two layers: gating components above, continuous components below
Four sequential gates above. Three continuous controls beneath.

Seven components · one control plane

Eight primitives. Nothing borrowed.#

Dipp AI defined Human-in-the-Role and the seven components that make it enforceable. Four sequential gates decide whether an action may commit at all — directive scope, role-bound authority, pre-commit verification, hashed evidence. Three continuous controls govern enterprise data boundaries, spend and cross-provider visibility for as long as the work runs. Remove one and the guarantee collapses.

Vol. I · p.13Four sequential gates decide whether an action may commit; three continuous controls govern data, cost and visibility for as long as it runs.

Architecture

The directive execution path.#

From plain-language intent to a hashed record and a retained intelligence asset — the full schematic as published in Vol. I.

Fig. ORC-19Orcher Component Schematic v1 — four sequential gates decide whether an action commits; three continuous controls govern data, cost and visibility while it runs.

Solutions

What enterprises deploy Orcher to control.#

A domain workflow chain with verification checkpoints between each station
Every industry, one accountability model.

Industries

Every industry, one enforceable control plane.#

Orcher is built for industry — from highly regulated sectors to every other line of business running critical decisions and workflows.

The brief

Routing, economics and control — answered.#

How Orcher decouples orchestration from any single provider, routes each task to the cheapest sufficient model, keeps prompts and data inside your own tenant, and proves every execution — written for the security, risk, finance and engineering leaders evaluating agentic AI for production.

What is an agentic control plane?

An agentic control plane is the layer that decides whether an AI agent's proposed action may execute at all. Orcher, built by Dipp AI Technologies, implements it as seven components: a Directive Interface that scopes intent, a Role Identity Fabric that binds the task to accountable identity, a Logic Scrubber that verifies the action against systems of record before commit, an Immutable Audit Ledger that hashes the decision path, plus a Data Control Gateway, Cost Governance and Observability that run continuously. Halt is the default outcome — nothing commits unless every gate clears.

What is Orcher and what problem does it solve?

Orcher is Dipp AI's agentic control plane for enterprise AI. It closes the trust gap between deployment and provability: 78% of enterprises run agents in production, only 28% can trace an agent action end to end, and 54% have already had an agent-related incident. Orcher makes policy executable rather than documentary, enforces enterprise data boundaries and no-training guarantees on every provider path, caps spend before autonomy runs away, and produces a hashed, replayable record of every committed action.

What are the seven components of Orcher?

Layer 1 — Accountability (sequential gates): 1) Directive Interface, which turns plain-language intent into a bounded task; 2) Role Identity Fabric, which binds the task to a role's cryptographic authority and entitlements; 3) Logic Scrubber, which verifies the proposed action against policy and systems of record before commit; 4) Immutable Audit Ledger, which hashes the full decision path into tamper-evident evidence. Layer 2 — Control (continuous): 5) Data Control Gateway for data boundary, redaction and egress; 6) Cost Governance for economic ceilings on autonomy; 7) Observability for one view across every model, framework and agent.

What is Human-in-the-Role and how does it differ from Human-in-the-Loop?

Human-in-the-Loop asks a person to approve a plausible action inside a short review window; under volume it degrades into automation bias, ignored alerts and timeout auto-proceed, and the only artefact is a click. Human-in-the-Role, the model Orcher enforces, binds the action to the scope and authority of the professional accountable for it before any model runs, halts anything outside that authority, and writes hashed evidence of the path. Control moves from review-time attention to execution-time enforcement.

How does Orcher handle enterprise data privacy and model training?

The Data Control Gateway sits in the execution path: the data boundary is enforced per directive, sensitive fields are masked before a prompt reaches any model, egress rules are applied continuously, and contractual no-training guarantees are held on every provider route. Orcher is provider-neutral, so using frontier models does not mean donating enterprise data to one.

How is Orcher priced?

Orcher is metered in Verified Execution Cycles — one directive carried through the full control plane — rather than per seat. Orcher is invite-only during the current deployment phase, and scope follows a technical briefing with the founding team rather than a published rate card.

Which industries and regulations does Orcher support?

Orcher is deployed across every industry, including healthcare, insurance, banking and financial services, government and public sector, military and defense, life sciences and pharma, legal services, energy and utilities, manufacturing, telecommunications, logistics, retail, automotive, education, and real estate and construction. Its evidence model is designed against obligations such as EU AI Act Article 14 human oversight, the NIST AI Risk Management Framework, and FDA clinical decision support guidance.

What is Dipp AI's strategy for model cost and provider choice?

Dynamic model routing. First, decoupled orchestration: Orcher sits in front of AI tasks so an enterprise can switch providers within a week rather than a quarter, because directives, roles, policy and evidence live in the control plane rather than in one vendor's SDK. Second, task-to-model matching: routine standard queries — roughly 90% of workloads — are routed to cheaper open-weight or small in-house models, while expensive frontier models are reserved for complex, high-reasoning tasks; the price spread across 400-plus models and 70-plus providers is 4,500× (Vol. I, p.25). Third, private tenant boundaries: data and prompt histories are forced to stay inside the company's own cloud environment, with training exclusion and data boundaries verified on every call, so model providers cannot learn from enterprise interaction data.

Who founded Dipp AI Technologies?

Dipp AI Technologies, Inc. was founded by Odero Otieno, its CEO and CTO, previously Managing Director of Engineering for Cloud, Data, and AI Platforms at Humana — where he architected infrastructure supporting more than $130 billion in annual revenue and 20 million-plus customers across healthcare, insurance, and finance — and Principal Director of Software Engineering for Enterprise Platforms at Microsoft, where he led platform engineering for the company's top 100 enterprise customers. He pioneered Human-in-the-Role and authored The Enterprise Superintelligence Report, whose Vol. I (August 2026) documents the trust gap between enterprises deploying agentic AI and those able to prove what those agents did, sets out Human-in-the-Role as the replacement for Human-in-the-Loop review, and specifies Orcher's seven-component control plane covering authority, policy enforcement, audit evidence, enterprise data boundaries and no-training guarantees, cost ceilings on autonomy, and cross-framework observability.

Output B · Dipp Intelligence

Every verified cycle leaves an asset behind.

OUT.B of the Verified Execution Cycle is Dipp Intelligence — the verified execution path, retained by the enterprise rather than absorbed by a model provider.

Path

The exact sequence that produced a verified outcome.

Role

The authority under which the action was permitted.

Cost

The model tier that actually proved sufficient.

Proof

The hashed evidence a regulator will accept.

Put one real workflow under verifiable control.

Book a briefing