Skip to content
Bahman Shadmehr Independent AI Systems & Automation Engineer
On this pattern

System Pattern 10 / Decisions, Agents & Authority

Use the smallest model that knows when to stop.

Risk- and Novelty-Aware Model Cascades

Route work through the least expensive eligible model, then escalate novelty, uncertainty and consequence without allowing a cheaper route to bypass mandatory controls.

Maturity
Reference design / Specified
Critical uncertainty
No model may downgrade a policy-required human review or gain additional authority because it produces a confident answer.
Human boundary
Approve, correct, reject, or defer within delegated authority
Applications
Code review · Marketplace moderation · Support triage · Financial document handling
Code review, marketplace, support, and finance tasks pass through nine eligibility and risk layers toward a low-cost route, deep-review route, or human review.

Problem shape

The problem beneath them

Apply deterministic eligibility and authority floors first, use the least costly qualified model for routine work, and escalate novelty, uncertainty, or consequence through controlled routes.

Sending every task to the strongest available model wastes latency and compute, but optimizing only for cost creates a more serious error: the cheap route can become an authority bypass. Model confidence is not calibrated uniformly across task types, distributions, versions, or consequences. A routine-looking input can contain a novel edge case; a stronger model can still be wrong; and neither should override mandatory review.

The pattern separates routing from decision authority. Deterministic controls decide whether automation is eligible at all. A risk floor establishes the minimum route. Task and novelty signals select among eligible models. Output checks decide whether the selected route can stop. Human authority remains a distinct gate for consequential actions.

A cascade must also be evaluated as a policy, not a collection of model scores. Route choice changes which errors are observed, and human outcomes can be delayed or selective. Capturing input strata, route reasons, overrides, and final dispositions is necessary to detect systematic under-escalation.

No model may downgrade a policy-required human review or gain additional authority because it produces a confident answer.

This pattern allocates inference and review effort. It does not prove that a small route is accurate enough, define organizational risk appetite, or make a larger model an oracle. Those require task-specific evidence and accountable policy.

Different problems, same shape

The surface changes. The decision structure persists.

01 / Code review

Does a typo need the same model as a database migration?

Change complexity and blast radius vary substantially.

02 / Marketplace

Is this known policy language or a novel evasion?

Routine violations resemble history while adversarial behavior shifts.

03 / Support

Can the routine route answer this, or does the evidence conflict?

A familiar request contains incompatible sources or unusual consequence.

04 / Finance

Is this ordinary extraction or a high-risk exception?

The same document task can feed either clerical review or a consequential action.

All four questions converge into Risk- and Novelty-Aware Model Cascades.

Exploded pattern

Open the mechanism at every decision boundary.

  1. 01

    Deterministic eligibility

    Question
    Is model automation permitted for this task and data at all?
    Responsibility
    Enforce consent, data class, jurisdiction, feature availability, task allowlists, and required prerequisites.
    Input
    Request, actor, data classification, policy, and system health.
    Output
    Eligible route set or immediate non-model disposition.
    Stops when
    Prohibited work is rejected, deferred, or sent to an authorized human path.
  2. 02

    Non-negotiable risk floor

    Question
    What minimum scrutiny and authority does policy require?
    Responsibility
    Encode actions and consequences that mandate stronger analysis, specialist review, or human approval.
    Input
    Proposed action, affected subject, permissions, reversibility, and regulatory or internal policy.
    Output
    Minimum route and mandatory gates.
    Stops when
    No later component can select a route below the floor.
  3. 03

    Task and consequence classification

    Question
    What kind of work is this, and what happens if it is wrong?
    Responsibility
    Classify task family, complexity signals, blast radius, and error asymmetry using bounded features.
    Input
    Eligible request, metadata, artifacts, and intended downstream use.
    Output
    Task class, consequence class, and routing features.
    Stops when
    Unknown or conflicting classification is itself routed safely.
  4. 04

    Novelty detection

    Question
    Is this input represented by cases the routine route is known to handle?
    Responsibility
    Compare to evaluated distributions, detect unfamiliar patterns and conflicts, and avoid equating distance with certainty.
    Input
    Task features, reference data, policy signatures, and historical route strata.
    Output
    Known, novel, or indeterminate novelty disposition with reasons.
    Stops when
    Novelty is bounded enough to select or escalate a route.
  5. 05

    Small-model route

    Question
    Can the least costly eligible model produce a checkable answer?
    Responsibility
    Handle well-scoped routine tasks under strict output, tool, evidence, and action limits.
    Input
    Bounded task, permitted context, route contract, and required output schema.
    Output
    Candidate result, confidence signals, evidence, and stop/escalate recommendation.
    Stops when
    Validation passes within authority or any escalation trigger fires.
  6. 06

    Stronger-model or specialist route

    Question
    Does additional capability or specialization resolve the identified difficulty?
    Responsibility
    Reassess novel, complex, or conflicting inputs without relaxing policy controls.
    Input
    Original task, lower-route trace, escalation reason, and expanded permitted context.
    Output
    Deeper candidate result or human-review requirement.
    Stops when
    Checks pass within route authority or uncertainty remains material.
  7. 07

    Confidence calibration

    Question
    Do route signals predict acceptable performance for this task stratum?
    Responsibility
    Apply versioned calibration and output validation; treat unsupported confidence as untrusted.
    Input
    Candidate result, model/version, task stratum, evidence, and evaluation contract.
    Output
    Acceptable-to-stop, escalate, or invalid result.
    Stops when
    The route satisfies the stopping contract or cannot do so.
  8. 08

    Human authority gate

    Question
    Which conclusion or action requires accountable human judgment?
    Responsibility
    Present evidence, route history, uncertainty, and permitted decisions to an authorized reviewer.
    Input
    Candidate output, policy floor, consequence, evidence, and unresolved issues.
    Output
    Approved, corrected, rejected, deferred, or escalated disposition.
    Stops when
    An authorized decision is recorded or the case remains explicitly owned.
  9. 09

    Outcome capture and route evaluation

    Question
    Is the cascade sending the right cases to the right routes over time?
    Responsibility
    Record route reasons, versions, outputs, overrides, delayed outcomes, and evaluable cohorts.
    Input
    Full route trace, human disposition, downstream feedback, and policy version.
    Output
    Auditable decision record and data for controlled route evaluation.
    Stops when
    Outcome status and limitations are recorded without inventing ground truth.

Decision forks

Every branch states why it exists and when it escalates.

Signals, decisions, reasons, and escalation conditions
Signal Decision Reason Escalates when
Policy prohibits model processing Use approved non-model or human path Cost cannot override eligibility Policy applicability is unclear
Mandatory human gate applies Preserve gate for every model route Authority is fixed before inference Reviewer specialization is required
Known low-consequence task with valid inputs Try small-model route Routine work may not need deeper capacity Output or evidence validation fails
Novel or out-of-distribution input Use stronger or specialist route Routine-route evidence does not cover novelty Stronger route also lacks support
Conflicting evidence Escalate depth or human review Confidence cannot settle source conflict Conflict changes a consequential action
High confidence but invalid schema/citation Reject route output Confidence cannot waive contract failure A corrected rerun still fails
Route service unavailable Defer or use approved equal/higher route Availability must not lower controls Capacity deadline creates human-operational risk

Operating paths

Clear, ambiguous, and failed work all reach explicit states.

Clear path

Pass eligibility and risk floor, classify as known and low consequence, run small model, validate, and record.

Final state
Low-cost route.
Owner
Routing system under an approved policy; downstream actor owns any permitted action.
Evidence
Eligibility result, risk floor, task stratum, model/version, validation, route reason, and final output.
Recovery
Re-route from preserved inputs if evaluation, policy, or model version invalidates the disposition.
Ambiguous path

Escalate novelty or conflict to stronger/specialist analysis, then preserve a human gate where uncertainty or authority requires it.

Final state
Deep-review route or Human review.
Owner
Specialist model service until handoff; authorized reviewer for final judgment.
Evidence
Lower-route trace, escalation trigger, additional evidence, validations, and reviewer disposition.
Recovery
Request evidence, narrow the action, correct the output, or defer explicitly.
Failure path

Stop on unavailable models, invalid outputs, broken calibration, or routing-policy mismatch without dropping below the risk floor.

Final state
Human review.
Owner
Platform owner for restoration and operations owner for queued work.
Evidence
Failure class, route availability, model and policy versions, affected strata, and fallback decision.
Recovery
Restore an eligible route, validate it, and replay queued tasks or process them manually.

Authority map

Capability does not grant authority.

RULE

May decide
Set eligibility, risk floors, mandatory gates, and validation contracts
May not decide
Infer novel semantic judgments not encoded in policy
Required evidence
Policy/version, evaluated attributes, and route result

MODEL

May decide
Classify, generate, compare, and recommend within route contract
May not decide
Lower the risk floor, approve itself, or perform unauthorized actions
Required evidence
Model/version, input scope, output, evidence, and uncertainty

SYSTEM

May decide
Enforce routes, validate schemas, preserve traces, and execute permitted handoffs
May not decide
Replace unavailable routes with weaker unauthorized ones
Required evidence
State, route reason, checks, events, and service health

HUMAN

May decide
Approve, correct, reject, or defer within delegated authority
May not decide
Erase model/system evidence or bypass non-negotiable policy
Required evidence
Identity, authority, reviewed evidence, rationale, and disposition

EXCEPTION

May decide
Hold novelty, conflicts, invalid output, or unavailable capacity
May not decide
Become an automatic approval or ownerless backlog
Required evidence
Trigger, risk floor, owner, age, and recovery options

Failure modes and recovery

A failed path remains owned, evidenced, and recoverable.

Failures, detection, containment, recovery, and owners
Failure Detection Containment Recovery Owner
Cheap route receives prohibited case Route audit conflicts with eligibility policy Halt affected policy version and preserve tasks Repair policy, replay, and review prior affected decisions Routing owner
Novel input appears confidently routine Drift, override, or incident review reveals miss Tighten stopping rules for affected stratum Add evaluated examples and revalidate before release Model owner
Larger model bypasses human gate Missing gate event in trace Block downstream action Restore gate and review all affected outputs Authority owner
Calibration no longer matches model version Version change or monitoring check invalidates mapping Disable calibrated auto-stop Re-evaluate and approve new versioned thresholds Evaluation owner
Cascade loops between routes Repeated route state or attempt bound detected Move to exception once Correct route graph and resume with one owner Platform owner
Reviewer sees only final answer Packet completeness validation fails Prevent consequential disposition Provide evidence and route trace; repeat review Operations owner

Invariants and guarantees

Properties the structure is designed to preserve.

  • Deterministic eligibility and policy-required review are evaluated before model routing.
  • No route may select below the non-negotiable risk floor.
  • Novelty, evidence conflict, and invalid output have explicit escalation paths.
  • Stronger models retain the same privacy, evidence, and authority constraints.
  • Every route choice identifies its reasons, policy, model version, and stopping checks.
  • Human review is an authority boundary, not a confidence threshold.
  • Evaluation distinguishes task strata and route selection effects.

What changes between implementations

The constraints determine the final mechanism.

The model set, prices, latency, and deployment boundary change frequently; none belongs in the invariant design. Task classifiers may be deterministic, learned, or hybrid. Novelty can use rule signatures, embedding distance, disagreement, or domain-specific detectors, but each requires evaluation in its own strata. The risk floor follows action consequence, policy, reversibility, and affected population.

Stopping checks vary by output: schema validity, cited evidence, test execution, policy match, or human confirmation. Review capacity influences which eligible low-risk cases automate, but must not weaken mandatory gates. Private environments may have fewer eligible models and need capacity deferral instead of public fallback.

Evidence chain

Follow the pattern into systems and software.

Architecture and controls specified; no production results published.

model-routed-code-review relates to allocating review depth according to change type and risk. small-model-marketplace-review relates to separating familiar policy cases from novel or consequential moderation. These references indicate design composition only; they do not establish that this exact cascade was implemented, tested, or measured.

Evidence-bounded inference constrains what any route may conclude. Durable execution keeps route attempts recoverable. Private inference limits eligible infrastructure and requires no-egress fallback behavior.

The status is REFERENCE DESIGN and maturity is specified. No production results are published. No open-source implementation is linked. No evaluation fixture, test, or benchmark is linked. Because route quality is an empirical question, this design must not be labeled implemented, tested, measured, or cost-saving without corresponding evidence.

Known boundaries

Limitations and non-fit

No universal confidence threshold or novelty detector can establish safe routing across tasks. Cascade complexity can increase operational failure modes and hide errors in route selection. Human outcomes may be sparse, delayed, or biased toward escalated cases, making evaluation difficult. A larger model can add capability but not authority or guaranteed correctness.

For low-volume, uniformly high-consequence work, one specialist route plus mandatory human review may be simpler and safer. For tasks with no defensible evaluation set or stopping contract, automated cascading is premature. It is also non-fit where latency from escalation violates a hard safety requirement; the system should reject or defer rather than silently lower scrutiny.

Related patterns

Continue through the adjacent decision structures.

A useful cascade spends capability according to the problem while holding authority constant. The smallest route earns the right to stop only through policy eligibility, evaluated scope, and checkable evidence. When those conditions fail, escalation is the intended operation—not an embarrassment to hide.

Adapt the pattern

Bring the problem, the boundary, and the consequence of being wrong.

Let's build something real