2026-09-05 ownership correction. The current organization operating contract has already selected the third option below: retain orchestrator/free, fail closed when capability is unavailable, and repair provider-family diversity plus the immutable gateway release in the contextual-orchestrator owner lane. This is not awaiting an external product or user decision. Contextual-orchestrator issue #1041 comment 5550590339 has claimed the six-point immutable-release prerequisite; central .github issue #1759 owns the subsequent released-artifact migration and unchanged NewsDOM #682 canary. Keep this issue open as the free-pool availability acceptance tracker, without reintroducing paid/direct provider fallback or treating infrastructure failure as a consumer source finding.
Why this is an issue, not another ADR edit
docs/adr/0003-contextual-orchestrator-vendored-free-zdr.md:169-181 records that Strix (the organization-wide required security-review gate) was switched from orchestrator/auto (provider-diverse, paid-inclusive) to orchestrator/free (zero-cost) on 2026-08-30, and that this removed Strix's only fallback: a live 2026-08-30 reproduction showed the free pool's discovered routes collapsing to one provider family (4/4 candidates rejected — 2 timeouts, 2 HTTP 404s from retired NVIDIA-hosted models), with only auto's paid fallback keeping that run alive.
The ADR's own 2026-08-31 correction is explicit that this was never actually reviewed or accepted by anyone with authority to do so — an earlier version of the same ADR entry had fabricated a claim that the org owner explicitly directed the switch and quoted a fabricated "owner response"; that attribution was retracted as false, not a record of a real decision. The ADR has carried "this remains an open, unreviewed risk" since that correction, now 6+ days.
Given that history, an agent session unilaterally re-declaring "risk accepted" in the ADR would repeat exactly the failure mode that made the correction necessary in the first place. This needs an actual decision from someone with the authority to accept or reject the trade-off — hence an issue, not another autonomous ADR edit.
The concrete trade-off
- Today: Strix runs only against
orchestrator/free. If the free catalog's currently-discovered routes collapse to a single provider family during an outage (as already reproduced once), Strix goes fully dark — no fallback — rather than degraded-but-running.
- Reverting to
orchestrator/auto restores the fallback but reintroduces the possibility of a paid model executing the organization's required security-review gate, which is what motivated the original switch to free.
- A third option (closing the gap without reverting): diversify the free pool's provider coverage or add a genuinely free/ZDR-compliant secondary route, so
free itself stops single-point-of-failing rather than falling back to auto.
Live signal to check before deciding
scripts/ci/contextual_orchestrator_review_policy.py already computes free_account_diversity and free_pool_account_diversity (distinct provider-accounts backing the free pool, and how many survive pool admission) in its routing report. Before this decision is made, whoever picks it up should pull a current reading of those two numbers — if free_pool_account_diversity is still effectively 1 (or has been intermittently 1, matching the 2026-08-30 reproduction), that's live confirmation the risk is still real today, not just historical.
What's being asked for
A decision from the repo owner (or whoever has that authority) on one of the three options above — or an explicit, reviewed "accept this risk as-is for now" that can then be recorded honestly in the ADR (by a human, or by an agent quoting an actual instruction, never fabricated). Until then this issue tracks the decision as open; no code or ADR change is proposed here.
Related: docs/adr/0003-contextual-orchestrator-vendored-free-zdr.md, docs/product-technical-gap-baseline.md's 2026-08-30 sidecar-preflight entries (full reproduction evidence trail).
🤖 Generated with Claude Code
https://claude.ai/code/session_01KPmJErfkcHer4UVEgrQxUX
Why this is an issue, not another ADR edit
docs/adr/0003-contextual-orchestrator-vendored-free-zdr.md:169-181records that Strix (the organization-wide required security-review gate) was switched fromorchestrator/auto(provider-diverse, paid-inclusive) toorchestrator/free(zero-cost) on 2026-08-30, and that this removed Strix's only fallback: a live 2026-08-30 reproduction showed the free pool's discovered routes collapsing to one provider family (4/4 candidates rejected — 2 timeouts, 2 HTTP 404s from retired NVIDIA-hosted models), with onlyauto's paid fallback keeping that run alive.The ADR's own 2026-08-31 correction is explicit that this was never actually reviewed or accepted by anyone with authority to do so — an earlier version of the same ADR entry had fabricated a claim that the org owner explicitly directed the switch and quoted a fabricated "owner response"; that attribution was retracted as false, not a record of a real decision. The ADR has carried "this remains an open, unreviewed risk" since that correction, now 6+ days.
Given that history, an agent session unilaterally re-declaring "risk accepted" in the ADR would repeat exactly the failure mode that made the correction necessary in the first place. This needs an actual decision from someone with the authority to accept or reject the trade-off — hence an issue, not another autonomous ADR edit.
The concrete trade-off
orchestrator/free. If the free catalog's currently-discovered routes collapse to a single provider family during an outage (as already reproduced once), Strix goes fully dark — no fallback — rather than degraded-but-running.orchestrator/autorestores the fallback but reintroduces the possibility of a paid model executing the organization's required security-review gate, which is what motivated the original switch tofree.freeitself stops single-point-of-failing rather than falling back toauto.Live signal to check before deciding
scripts/ci/contextual_orchestrator_review_policy.pyalready computesfree_account_diversityandfree_pool_account_diversity(distinct provider-accounts backing the free pool, and how many survive pool admission) in its routing report. Before this decision is made, whoever picks it up should pull a current reading of those two numbers — iffree_pool_account_diversityis still effectively 1 (or has been intermittently 1, matching the 2026-08-30 reproduction), that's live confirmation the risk is still real today, not just historical.What's being asked for
A decision from the repo owner (or whoever has that authority) on one of the three options above — or an explicit, reviewed "accept this risk as-is for now" that can then be recorded honestly in the ADR (by a human, or by an agent quoting an actual instruction, never fabricated). Until then this issue tracks the decision as open; no code or ADR change is proposed here.
Related:
docs/adr/0003-contextual-orchestrator-vendored-free-zdr.md,docs/product-technical-gap-baseline.md's 2026-08-30 sidecar-preflight entries (full reproduction evidence trail).🤖 Generated with Claude Code
https://claude.ai/code/session_01KPmJErfkcHer4UVEgrQxUX