02 · Selected work
7ARCH governed delivery
Multi-agent work stays accountable because authority lanes stay separate from model spend. ADE-F.T names the formalisation — it is not a SaaS binary.
- Problem — AI pilots without decision rights become theatre.
- Built — Delivery OS: authority, pauses, human go-live, visible cost.
- Result — Documented method (ADE-F.T); not a SaaS SKU.
- Your role — Author / operator of the delivery operating system.
“7ARCH is the operating system I run deliveries on — authority lanes separate from model spend. Cat 05 on AAAS is the public protocol listing; the Studio pack is how we actually gate work. ADE-F.T is the name for that formalisation, not a separate SaaS binary in this monorepo.”
Governance IP and operating method. Cat 05 on aaas.ml-nightworx.io is a protocol/spec listing (url: null / empty live URL) — not proof of a live router app from this tree.
The operating system Marco runs deliveries on — not a named enterprise engagement.
Three non-interchangeable routers (Studio authority, InfraDOME models, Marketing GTM); locked roster; HALT / HITL outbox; Reflector ASTROX go-live gates including RAG ≥90%; LiteLLM as ACCESS/economics only. ADE-F.T is the formalisation name — no adeft/ package or SKU row in the evidence tree.
ADE-F.T as a SaaS SKU or product directory. NTWX HQ/Runtime as a named product. adeft.pages.dev. Production OpenRouter spend dashboards. Pair / OSF as production runtime. Nocturne ADE (a visual design system) is a different artefact.
Claimable architecture
Authority routing (Studio): locked roster — ATLAS, PROMETHEUS, SIENNA, CEDAR, ERIS, GENE, plus specialists. No model IDs on the Studio surface. Seat rules are surface-specific; the roster is not an invitation to invent a seventh Archer.
Model / cost routing (InfraDOME): archetype → primary / paid / local models and a cost hierarchy (open-weight first, paid Claude/GPT as fallback only).
ACCESS layer: LiteLLM for economics — key, model, fallbacks, timeout, retries, cache. Live only when APP_ENV=production. LiteLLM does not own offer or jurisdiction logic.
HALT / HITL: outbox stays DRAFT until approve. Commander gates on quotes, secrets, jurisdiction, and a 2+ Red compatibility override. Reflector ASTROX checks RAG ≥90%, white-label, provision dry-run, and sovereignty — then GO-LIVE ALLOWED or BLOCKED.
Layers documented as Harness / Loop / Graph. Surfaces: AAAS Cat 05 protocol, studio.ml-nightworx.io ops glass (static), Agentic Moat FastAPI (mocks unless production). Cloudflare glass convention: Pages / Worker / Cloud Run.
- JSON routers + skills
- Locked Studio roster
- InfraDOME cost matrix
- LiteLLM ACCESS
- HITL outbox
- ASTROX go-live gates
- Cloudflare glass
Design decisions worth copying
- Split authority routing from model/cost routing.
- Locked Studio roster — no invented seats; surface-specific rules.
- HALT over guessing.
- HITL on irreversible commercial actions.
- LiteLLM = ACCESS / economics only.
- Pair is build-time QC, not production runtime.
- Hard Reflector go-live gates, including RAG ≥90%.
- Cat 05 commercial SKU is not the operator SOP pack — protocol versus operating system.
What this tree does not prove
- ADE-F.T as an implemented product directory or SaaS SKU.
- NTWX HQ / Runtime as a named product.
adeft.pages.dev(not in the evidence tree; do not cite from this case).- Production OpenRouter spend dashboards.
- Live Cloud Run after documented HALT states.
- That Pair / OSF agents are production runtime.
This page describes the operating system — not a named enterprise engagement.