MeridiansMeridians

Where it's controlled

Source path: knowledge-base/knowledge/conventions/ai-models/05-where-it-s-controlled.md

# Where it's controlled

- **Director-only**, fleet-wide (like the Pilot). Gate: `can.manageAiProfiles` (`role === "director"`).
- **AI Profiles editor** — home sidebar → *AI Profiles*. Full editor: pick a profile, read the
  category→tier grid, override per-category. (`src/features/settings/AiProfiles.tsx`)
- **Quick-switch** — a compact profile picker in the domain **TopBar** and the **ConstellationTopBar**.
  (`src/features/settings/AiProfilePicker.tsx`)
- **Persistence** — the choice writes to `record/aux/meta.json` under `aiProfile` (canonical, synced).
  The browser applies it at hydration; the headless daemon (Program, MCP, Pilot, loops) reads it per-op
  in `configureHeadlessAiRuntime`. Absent → the Balanced default.

## Thinking is an exception, not a category default

The fleet reasoning level is an available budget, not permission for every call to spend it. A call passes
`resolveReasoningBudget()` only when deeper deliberation is needed for a durable or consequential result:
building the causal substrate, judging quality, or making a decision whose correctness matters. Routine
editorial synthesis, routing, suggestions, extraction, and latency-sensitive interaction pass
`REASONING_BUDGETS.none` explicitly. This keeps the app responsive and makes the exceptional spend visible
in [Model calls](../../../generated/MODEL_CALLS.md).

Model category and thinking budget are independent levers: a call can use a strong category model without
thinking tokens when the model permits it, and a fleet-thinking call still obeys the Director's selected
level (including `none`, subject to the provider capability below).
The transport defensively treats a missing budget as `none`, so an accidental omission cannot add latency
or spend; the Model calls generator rejects omissions from direct engine calls, so this backstop never
replaces an explicit product decision.

The provider's model capability is the final constraint: when OpenRouter marks a model's reasoning as
mandatory, an explicit `none` request is promoted by the shared model-policy resolver to the configured
`low` budget. Other models still receive reasoning disabled exactly. Both provider request builders use
this policy, preventing reasoning-mandatory fleet rungs from rejecting otherwise valid work.
Open on GitHub

Raw Markdown source