# Model gateway, routing and evaluation

Hard constraints come first, then quality, cost and latency are compared: rule out the models that are not allowed, then choose among those that are. With no permitted candidate, the work pauses or goes to a person.

> Document ID: MYRILUM-DOC-ARCH-017
> Document type: concept
> Product: NOT_APPLICABLE
> Version: 0.1.0
> Region: GLOBAL
> Visibility: PUBLIC
> Publication: PUBLISHED_GLOBAL
> Content maturity: DRAFTED
> Governance: APPROVED
> Capability state: IN_DEVELOPMENT
> Availability: NOT_AVAILABLE
> Authorization: PUBLIC_INFORMATION
> Freshness: CURRENT
> Safety class: INFORMATIONAL
> Owner: Web3Capital Documentation Steward
> Approvers (assignment only; not approval evidence): Stephen
> Canonical authority: SRC-ARCHITECTURE-ATLAS-V2-2
> Source commit: 6b41cce4496de03c67a501aa94cd41ec6ac0e85a
> Content digest: 8f04e9869c316e244f99f7959a9a8e7b839a2a818ddf1241e753d912eda4ff7f
> Effective: NOT_SET
> Expires: NOT_SET
> Last verified: 2026-09-23
> Review due: 2026-10-23
> Command authority: NONE
> Canonical URL: /en/architecture/model-gateway-and-routing

<a id="overview"></a>

## What this map shows

![Model gateway, routing and evaluation diagram (A17)](/figures/atlas-v2-2/A17.png)

*MYRILUM architecture map v2.2 · A17 (public edition). Labels are in Chinese; every element is listed in English below. Select the diagram to open it at full size.*

This is MYRILUM's target architecture. It does not mean everything on the map is live; whether a capability can be used today is stated in “Current availability”.

Hard constraints first, then quality, cost and latency are compared; with no permitted candidate, the work pauses or goes to a person.

First rule out the models that are not allowed, then choose a suitable one among those that are.

<a id="part-1"></a>

## Registration and request standardization

| Field | Value |
|---|---|
| Model catalog | Provider, actual model identifier, version, capabilities and limits |
| Policies and evaluation | Benchmarks per task type, data policies and price snapshots |
| Standard request | Task, context references, budget and output contract |
| Provider adapter | Interface, authentication, parameters, errors and response structure |

> **A routing model is a hypothesis** — Quality scores and weights need real evaluation; an uncalibrated combined score is never called the optimal strategy.

<a id="part-2"></a>

## How routing chooses

| Field | Value |
|---|---|
| Hard-constraint filter | Capability, data permission, region, authorization, health and budget |
| Ranking permitted candidates | Weighs calibrated quality, cost, latency and reliability |
| Budget reservation | Safe under concurrency; records price and limits |
| Execution and receipt | Actual version, request identifier, usage and result |

> **Not every task needs a large model** — Exact calculation, data validation and clear rules prefer deterministic programs; the task decides how much a model is involved.

<a id="part-3"></a>

## Results and exceptions

| Field | Value |
|---|---|
| Output checks | Structure, factual support, refusals, errors and limits |
| Limited retries | Retries may cost money and never exceed the total budget |
| Fallback within authorization | A replacement model never changes the approved data-flow boundary |
| No permitted candidate | Pause, wait for the provider to recover, or ask a person to decide |

> **Privacy before fallback** — A provider outage is never a reason to send customer material to an unapproved region, model or recipient.

<a id="part-4"></a>

## Continuous evaluation and provider governance

| Field | Value |
|---|---|
| Task-level evaluation | Representative samples, baselines, failure modes and uncertainty |
| Cost and latency | Actual usage, queueing and the cost of each effective delivery |
| Version and alias changes | Records the version actually resolved; re-evaluates when needed |
| Replacement and exit | Limits dependence and keeps the ability to migrate data and contracts |

> **No fixed vendor list** — The map defines replaceable capabilities; it claims no contract with any model vendor and promises no completed integration.

<a id="source"></a>

## Source

This page follows A17 of the MYRILUM architecture map v2.2 (public edition: restricted products and internal open items are left out). Related: “AI execution architecture”; “Agent runtime and failure recovery”; “Observability, quality, cost and operations”.

---

This document is read-only, grants no command authority, and does not authorize deployment, payment, provider modification, or any other real-world action.
