Position

Why Orcher

Frontier models now act, not just answer. Every provider is shipping its own control surface — but control that belongs to a model vendor cannot refuse that vendor. Orcher's neutrality is structural: it has no model to defend, so it can enforce the trust gap once, across all of them.

Why the control layer cannot belong to a vendor

Fig. NEU-04

Converging on the control layer

V1

Model vendors

Have a model to defend.

V2

Cloud platforms

Have consumption to defend.

V3

Observability tools

Watch, but cannot refuse.

Structural neutrality

N1

Orcher

No model, no cloud, no routing incentive — able to refuse any provider.

Refusal is only credible from a layer with nothing to sell underneath it.

Provider-neutral by architecture, not by policy
A quadrant field of vendor markers with one isolated luminous position
Everyone is converging on the control layer. Neutrality is structural, not a posture.

Not a model provider's console

A provider's control surface cannot credibly block that provider's model, nor trace a directive that left its estate three hops ago.

Not an agent registry

A registry records that an agent exists. It does not decide, at runtime, whether this action is within a role's authority.

Not an observability tool

Telemetry describes what happened. Orcher decides whether it may happen, then produces evidence that it was permitted.

Not a policy document

Written policy is not a control. A control refuses, halts, and leaves a hashed record of the refusal.

Guardrails ≠ governance

Eight vendors, ten platforms, one missing primitive.

Agent identity is not directive identity. Registering that an agent exists is not the same as proving that a named human authorized this action, in this role, against this record.

47%

of CISOs saw unauthorized agent behavior

5%

were confident they could contain it

38%

of organizations with a named agent owner (from 7%)

<1%

with full agent governance maturity

Vol. I · p.8Documented incidents mapped one-to-one to the component that would have prevented them

Landscape

Specialists, platforms, and the convergence.

Vol. I maps who is building toward this layer and what each of them structurally cannot do.

Vol. I · p.9Specialist market landscape for agentic governance
Vol. I · p.21Vendor convergence matrix

Neutrality

Who can refuse whom

Microsoft

Names the problem and sells the gateway — but is invested in both OpenAI and Anthropic. Never provider-neutral.

Google · AWS

Gateways and routing at scale, without runtime verification of the human authority behind an action.

Sierra · Glean

Vertical agents bound to one provider harness. Excellent outcomes, single-vendor evidence.

Frontier labs

Own the model and the application layer at once. Structurally conflicted as an arbiter.

Dipp AI · Orcher

Verified authority per directive, enforced across providers. No model to defend.

September 2026 commentary

Why provider-neutral control is now essential.

The frontier releases of GPT-6 Astra, Claude Fable 5.1 / Mythos 5.1, and Muse Spark 1.3 show every lab building its own safeguards. Read why a control surface that belongs to a vendor cannot credibly refuse that vendor.

Runtime workflow

Authority per directive.#

Routing is not a developer preference resolved in a config file. For every directive, Orcher resolves who is accountable, selects the cheapest model class that authority permits, carries the data boundary along the chosen route, and hashes the whole decision into one evidence chain that reads the same across every provider.

  1. 01

    Authority is resolved before a model is chosen

    Who is accountable, and what may they authorize?

    The directive arrives with a named issuer. The Role Identity Fabric resolves that professional's current entitlements and binds them to this cycle, so the routing decision is made against a known authority rather than a service account. Anything outside the role halts here — before a single token is spent.

    Enforced by

    Emits
    A role-bound authorization token scoped to this directive.

  2. 02

    The routing decision is a policy decision

    What is the cheapest model class this directive's stakes permit?

    Cost Governance classifies the workload by stakes, sensitivity and reasoning depth, then selects the cheapest sufficient model class within the ceiling in force for that role. Roughly nine in ten workloads clear on routine classes; frontier capacity is reserved for complex work. The chosen class, the alternatives considered and the ceiling applied are all recorded as part of the decision.

    Enforced by

    Emits
    A signed routing decision: class chosen, ceiling applied, rationale.

  3. 03

    The data boundary travels with the route

    May this payload reach that provider, in that region?

    The Data Control Gateway applies data-boundary, redaction and training-exclusion rules to the route that was chosen, not to a default path. If a class is otherwise optimal but its provider cannot satisfy the boundary, the route is refused and the next sufficient class is selected. Consistency across providers is enforced by the gateway, not negotiated per vendor SDK.

    Enforced by

    Emits
    A per-call boundary attestation: region, redactions, no-training terms.

  4. 04

    Every decision lands in one evidence chain

    Can this be replayed and defended months later?

    The Immutable Audit Ledger hashes the directive, the authority, the routing decision, the boundary attestation and the committed action into a single tamper-evident chain. Observability streams the same run across whichever providers were involved, so one query answers what was asked, who authorized it, where it ran and what it cost — regardless of vendor.

    Enforced by

    Emits
    A replayable, hashed execution record with cross-provider cost and latency.

Proof points

Neutrality you can measure.#

A neutral control plane has to prove itself in numbers rather than positioning. These are the outcomes dynamic model routing is accountable to across every provider in the estate.

Cost

4,500×

price spread across 400+ models and 70+ providers

The spread between the cheapest sufficient model and the frontier default is the entire economic case for routing. A directive sent to the wrong class does not fail — it just costs orders of magnitude more than it had to.

Vol. I, p.25

Token waste

~90%

of workloads never need a frontier model

Routine classification, extraction, summarisation and drafting clear on in-house or open-weight classes. Reserving frontier capacity for genuinely complex work is what turns AI spend from a run-rate into a budget.

Dipp AI routing model · Vol. I, p.25

Budget

68%

of enterprise AI programmes run over budget

Overrun is a control failure, not a forecasting failure. Cost Governance applies a ceiling per role and per directive and halts loops at the step boundary rather than at the invoice.

Vol. I, p.9

Latency

10×

faster on routine classes than a frontier default

Cheaper classes are also materially faster. Routing the routine nine-tenths off the frontier shortens the median directive as a side effect of the economics.

Indicative class latencies, Orcher routing table

Auditability

28%

of enterprises can trace an agent action end to end today

Every routing decision Orcher makes — class chosen, alternatives considered, ceiling applied, boundary attested — is hashed into the same evidence chain as the committed action, so the economics are as auditable as the outcome.

Vol. I, p.6

Portability

1 week

to change providers, not a quarter of re-platforming

Because orchestration is decoupled from any vendor SDK, a provider change is a routing-table change. Directives, roles, policy and evidence stay in Orcher.

Dipp AI protocol stack contract

Output B · Dipp Intelligence

Every verified cycle leaves an asset behind.

OUT.B of the Verified Execution Cycle is Dipp Intelligence — the verified execution path, retained by the enterprise rather than absorbed by a model provider.

Path

The exact sequence that produced a verified outcome.

Role

The authority under which the action was permitted.

Cost

The model tier that actually proved sufficient.

Proof

The hashed evidence a regulator will accept.

Architecture beats models.

Capability is rented quarterly. Accountability is built once and compounds.