← Research

2026-09-26 · Engineering notes · Immediacy

Making a small model earn its keep

Running a small local model is the easy part. Knowing when to believe it is the hard part, and that’s what immediacy-ctx is built around.


§ Trusting a weak model, carefully

The local decision model is small, sees only tiny snippets, and tends to be over-confident. immediacy-ctx is built around those weaknesses. It runs in “shadow mode,” deciding but not acting, while deterministic rules do the real work; its confidence is re-calibrated before anything goes live; and it never sees more than it can handle. It has to earn trust from real outcomes before it is allowed to matter.

§ Keeping it on a diet

Code flows in one direction: parse the structure, store it in the graph, then build a tiny “card” for each decision. The small model only ever sees those compact cards, never raw code. There are two deliberate exceptions. The frontier coding agent does get real code, because it can read it, and freshness checks read the actual files on disk, so a stale index never misleads anyone.

§ A gate that only decides

Before an agent runs a risky command, it can ask the gate: run, refuse, or escalate. The gate only decides. It never contacts a human itself; the client does that. Truly destructive things (rm -rf, force-push, dropping a table) always escalate, even at high confidence, as a permanent human-in-the-loop floor.

§ Going live is a data milestone

Flipping the model from shadow to live is not a config switch. The system replays the real decisions it has logged and refuses the flip until it has seen enough of them (about 1,000) with zero unsafe auto-approvals. The whole improvement loop closes at the edges: log every decision, export the labels, fine-tune offline (the one bit of Python in the system), then hot-swap the new model in with no restart.

A small model is only allowed to matter once it has shown, on real logged outcomes, that it won’t do damage. See also Four engines, one backpack and the benchmarks.