Product · Orcher

One control plane between your agents and your systems of record.

Orcher is not a model and not an agent framework. It is the enforced layer those things run through: authority bound before execution, the action verified against the record, the data boundary held, the cost ceiling respected, and the evidence written where nobody can quietly edit it.

Seven components · two layers · metered in Verified Execution Cycles

Orcher — seven components, two layers

Fig. ORC-02

Layer 1 · Accountability

C0

Directive Interface

Where intent enters, attributed.

C1

Role Identity Fabric

Authority bound to a person.

C2

Logic Scrubber

Pre-commit verification.

C3

Immutable Audit Ledger

Hash-chained evidence.

Layer 2 · Operations

C4

Data Control Gateway

Data boundary and redaction.

C5

Cost Governance

Routing and spend ceilings.

C6

Observability

Cross-provider execution telemetry.

Model-agnosticDeploys beside existing agentsNo re-platforming

Dipp AI Research · September 6, 2026

Models advance. Enterprise control must endure.

Our September commentary examines GPT-6 Astra, Claude Fable 5.1, Claude Mythos 5.1 and Muse Spark 1.3 through one enterprise question: can advanced reasoning be trusted with real work—verifiable, cost-disciplined, and in control of the enterprise’s own data?

Choice without surrendering control

Frontier APIs, open-weight families such as Llama, Qwen, DeepSeek, Mistral and Gemma, and enterprise-tuned models belong behind the same authority and evidence requirements.

A neutral plane across compute

AWS, Microsoft Azure and Google Cloud; neoclouds such as CoreWeave, Lambda and Crusoe; private infrastructure. The destination may change. The enterprise’s boundary and budget must not.

Seven controls. Compounding intelligence.

Cost Governance chooses the sufficient route. The Data Control Gateway governs egress. Observability traces the run. Human-in-the-Role binds authority, while verified execution compounds into Dipp Intelligence.

Named release examples follow the September commentary. Model families and compute providers are ecosystem examples, not a claim of certified integrations or universal availability.

Read Frontier Autonomy Needs a Control Plane →

What Orcher does

Four outcomes your agents cannot deliver on their own.#

Every one of these is enforced in the request path, not reviewed afterwards. The components that do the work are named underneath each one.

01

Every action carries a name, before it happens.

Authority is bound to a directive at the start, not asked for in an approval queue at the end. When an action is challenged a year later, the person who authorised it and the scope they held are part of the record.

  • A directive is captured in plain language and frozen before any model is called.
  • It is bound to a named person, their role and the limits that role carries — time-bound and task-bound.
  • Revoking a role revokes the authority instantly, with no agent redeployment.

02

Nothing reaches your systems of record unverified.

The proposed write is re-derived against the policy, the balance, the eligibility or the contract it depends on — in a process the agent does not control. If it does not reconcile, it stops. Nothing partial is written.

  • Verification runs outside the agent's process boundary, so a compromised agent cannot skip it.
  • A refusal returns the reconciliation that failed, not a generic error.
  • The halt is recorded as carefully as the commit.

03

Your data stays inside the boundary you set.

Training exclusion and egress rules are checked on every call, against the destination's current posture — not against a contract signed last year. A provider that no longer satisfies the policy does not get the payload.

  • Payloads are classified and routed per provider and per jurisdiction.
  • A provider whose posture changes is blocked or re-routed automatically.
  • The data decision is written into the same record as the action.

04

Spend follows the stakes, not the habit.

Each step goes to the model that satisfies its cost, latency and assurance requirement. High-volume work runs cheap; anything consequential is escalated. Runaway loops are terminated rather than invoiced.

  • Model tier is chosen from the consequence of the action, not the developer default.
  • Budget ceilings are enforced per role, department and directive class.
  • One timeline shows cost, latency and verification outcome across every provider.

Under all four outcomes sit the same seven components — four gates that run in order before anything commits, and three controls that never stop.

Use cases

Where an enforced control plane changes the outcome.#

Every one of these is a workflow where the question after the fact is not 'what did the model say?' but 'who authorised this, and can you prove it?'

Claims and case adjudication

An agent drafts the determination, the Logic Scrubber checks it against the policy record, and the adjudicator's own authority is what commits it.

Financial close and reconciliation

High-volume matching runs on cheap models; anything that moves a balance is routed up and bound to the controller who signs the close.

Clinical operations and prior authorisation

Patient data never crosses a boundary the Data Control Gateway has not verified, and training exclusion is enforced before routing, not promised after.

Contract and obligation review

Every clause finding carries a hashed evidence entry naming the model, the role, and the record it was checked against.

Supply and procurement execution

Concurrency and recursion ceilings stop a runaway loop from issuing a thousand purchase actions while a human is asleep.

Regulatory evidence and audit response

Export the ledger for a regime-specific window instead of reconstructing what happened from application logs.

Pricing

Metered in Verified Execution Cycles, not tokens.#

One cycle is one directive: role bound, action verified, boundary checked, cost recorded, evidence hashed. You pay for governed work that completed, not for text a model generated.

Pilot

One workflow, one role, one system of record.

  • A single directive class instrumented end to end
  • All seven components engaged
  • Evidence package exported at the end of the pilot
  • Founding-team engineering contact

Department

A function's worth of directives under one role model.

  • Role-scoped authority mapped to your delegation model
  • Budget ceilings per role and directive class
  • Cross-provider observability and cost attribution
  • Quarterly evidence review

Enterprise

Control-plane deployment across regulated operations.

  • Multi-jurisdiction boundary and training-exclusion enforcement
  • Regime-specific evidence export
  • Dipp Intelligence retained in your own estate
  • Named accountability model reviewed with your risk function

1

directive per Verified Execution Cycle

7

components engaged on every cycle, including in Pilot

0

tenant records released for third-party model training

100%

of verified actions written to the immutable ledger

Talk to the founder

Tell us the workflow, the role that answers for it, and the system of record it touches. We reply with how Orcher would govern it — or tell you plainly if it is not a fit yet.

Request a deployment briefing

One workflow is enough to start. Describe it and we take it from there.

Saved on this device as you type.

Follow the research

New Orcher articles, field notes and control-plane research, sent as they publish.

Orcher article updates

No product marketing — research and release notes only.

We use your address only to send research updates, and every email can unsubscribe you. We keep what you send for as long as we need it to answer you — correspondence and briefing requests for up to 36 months, research access records for up to 24 months, newsletter details until you unsubscribe, and job applications for up to 12 months after a decision. We never sell your details or add you to a marketing sequence without asking. Read the privacy notice or request deletion of your data. Consent statement version 2026-01-v1, recorded with your submission.

Questions

What people ask first.#

What is Orcher?

Orcher is an agentic control plane: a layer between your AI agents and your systems of record that binds each directive to a named human role, verifies the proposed action before it commits, enforces your data boundary, routes work by stakes under a cost ceiling, and writes a hashed evidence entry for every verified action.

How is Orcher priced?

Orcher is metered in Verified Execution Cycles — one directive, role-bound, verified, and permanently recorded — across Pilot, Department and Enterprise deployments rather than by token volume.

Does Orcher replace our model provider?

No. Orcher is provider-neutral. It routes each task to the model that matches its stakes and records which provider executed it, so you can change providers without losing the evidence trail.

Is enterprise data used to train third-party models?

No. The Data Control Gateway verifies training exclusion and the enterprise data boundary before a task is routed, and refuses the route when a provider cannot satisfy it.

Orcher early access · invitation only

Deploy Orcher on one workflow with the founder beside you.

Applications are read by the founding team. We take workflows where an autonomous action touches a system of record and someone has to answer for it — claims, care decisions, credit, filings, dispatch, procurement. Approved organisations get an invitation, a workspace, and a briefing with the people who built the control plane.

For enterprises closing the AI trust gap · one workflow to start

  1. 01

    Apply with one workflow

    One class of directive, the system of record it touches, and the obligation behind it.

  2. 02

    The founding team reads it

    A decision against the current cohort, normally inside one business day.

  3. 03

    Invitation opens the account

    Accounts only open for invited work addresses. Nothing self-provisions.

  4. 04

    Workspace tracks the deployment

    Status, briefings, invitations and the research library in one place.

Autonomy at machine speed, with someone still accountable for it.

Press and analyst enquiries reach the desk at comms@dippai.com. Everything else starts with a briefing request.