A governed agent that synthesizes STEM, market, and competitive research — home-routed to a self-hosted reasoning model, cleared to escalate to frontier, with every chain-of-thought and memory written under enforcement.
Synthesis work reaches for the strongest model, pulls in the widest context, and writes the most durable memory. That is exactly where ungoverned agents leak spend, mix tenants, and produce reasoning no one can audit.
Every query defaults to the most expensive model. Chain-of-thought is discarded or dumped to shared storage. No signed record of what was reasoned over, or on whose authority.
The research lead homes to a self-hosted model, escalates only on cause, and writes CoT + memory into an RLS-isolated tenant behind a deny-by-default enforcement plane that signs every call.
The research lead is one tenant inside a live zero-trust workforce — not a sandbox. Every agent is registered, policy-scoped, and enrolled to the same enforcement plane.
The 7 showcase agents run a 14-edge topological hand-off DAG. The research lead receives escalated context from the security track and produces the synthesis that data analysis and editorial build on. It feeds the research council.
The research lead never talks to a model or a database directly. It mints a capability token; the enforcement plane decides; only on allow does the call reach its own isolated memory tenant.
The research lead homes to ollama_deep — deepseek-v4-pro on Ollama Cloud — and is cleared to escalate to frontier paid tiers when the work demands it. Routing favors free/self-hosted; the ceiling is available, not default.
| Tier | Model · provider | Role | $ / call | Relative cost |
|---|---|---|---|---|
| Home | deepseek-v4-pro · Ollama Cloud | default synthesis | $0.002 | |
| Escalate | sonnet-4.5 · OpenRouter | hard reasoning | $0.03 | |
| Ceiling | opus-4.8 · OpenRouter | frontier only | $0.19 |
This is what a single governed research job actually does — the same shape every fleet agent runs, roughly one to two times a day.
Home/ceiling/floor tiers are per-agent. Escalation is not the agent's whim — it fires on cause. And when the model call fails, the agent degrades safely rather than stalling.
Keyword triggers — +incident +breach +critical — lift routing from the deepseek-v4-pro home toward the frontier ceiling for that job only.
On LLMError the agent falls back to floor. Free-homed agents floor to ollama_oss (gpt-oss:120b) for a reliable degrade — never an unmetered frontier retry.
A research lead is only as good as what it remembers — and in an enterprise, only as safe as how that memory is walled off. Both are enforced at the data plane, not left to the agent.
Nothing about the research lead's autonomy weakens the control surface. Every call is authorized, signed into an immutable chain, and monitored for behavioral drift with automatic containment.
On allow, the PEP forwards verbatim to the tenant backend and signs the call into its SoulKey Ed25519 chain shipped to the control plane. SoulWatch turns behavioral drift into auto-quarantine against the shared postgres store.
Because the research lead homes to a self-hosted reasoning model and escalates only on cause, its steady-state cost sits at the bottom of the roster. The ROI board makes the gap explicit.
| Model | Placement for research lead | $ / call | vs. frontier ceiling |
|---|---|---|---|
| opus-4.8 | ceiling · frontier only | $0.19 | |
| sonnet-4.5 | escalate | $0.03 | |
| deepseek-v4-pro | home | $0.002 | |
| gpt-oss:120b | floor · reliable degrade | $0.0015 | |
| gemma-4-31b:free | free tier | $0.00 |
Home-routed for cost, cleared to escalate on cause, isolated at the row level, and signed on every call. It feeds the research council with synthesis that carries a provable record behind it.