Deployment Envelope
Nishad

Deployment Envelope View

Which capabilities are proven in which deployment envelope. "Best available model" is always best within the install's envelope — an air-gapped install's best is the best Lab-rated local model, evidence not assertion. A capability with only cloud evidence does not count for an air-gapped install until a local candidate earns it.

📦 Deployment Envelope = where this install is allowed to run models — fully cloud (vendor models, external calls OK), on-prem-connected (in-network models, external calls per policy), or air-gapped (local models only, no external calls). It decides what's even eligible before cost or score is considered.

☁️ Cloud

6 of 6 capabilities available · vendor models · external calls allowed

🏢 On-prem-connected

4 of 6 available · in-network models · external calls per policy

🔒 Air-gapped

2 of 6 proven · local Gemma-4 class only · no external calls

Capability Cloud vendor models On-prem-connected in-network Air-gapped local node · Thor
reason(cross-service-debug)to rubric≥4
productionclaude-opus-4-8
productionclaude-opus-4-8
eval · 0.58gemma-4-27b · below bar
extract(kb_entities)to schema-valid
productionclaude-opus-4-8
eval · 0.81gemma-4-27b
eval · 0.62gemma-4-27b · below bar
draft(hubspot_contact)via hubspot-connector
productioncodex-1
eval · 0.79sonnet-1
not availableconnector needs external call
synthesize(quorum-panel)to rubric≥4
productionopus-1
eval · 0.77sonnet-1
not availableno local candidate at bar
grounded-inference-with-attributionvia kb-graph, cited
productionsonnet-1
eval · 0.71sonnet-1
eval · 0.66gemma-4-27b · KB-only
transcribe(inbound_call)to WER≤8%
eval · 0.83voice-runtime
not availableno in-network model
not availableno local model
production clean track record eval Lab-proven at bar eval · below tested, under 95% gate not available no evidenced match

The resolver reads this matrix envelope-first, then cost. A match must run in the install's envelope to count — so an air-gapped install only sees the two proven local capabilities, and Cortex says so honestly for the rest rather than borrowing cloud evidence that will not run.

What's on this screen

Built from: the same Lab test results behind the Capability Ledger, cross-tabbed by where each proven model or agent is allowed to run.

On screenWhere it comes fromWhat it means to you
Deployment Envelope definition bannera plain explanation of the three ways this install is allowed to run modelshelps you understand the constraint before you look at any score
Envelope summary cards (cloud / on-prem-connected / air-gapped counts)how many capabilities have a proven holder in each settingshows at a glance which setting is capability-rich and which is thin
Matrix cell (tier + subject, per capability × envelope)the best-proven model or agent for that skill, in that specific settingtells you whether that skill can actually run under your install's rules, and how well-proven it is if so
Legend (production / eval / eval-low / not available)what each cell's icon and color meanlets you read the matrix without guessing what a symbol implies
Footer note ("resolver reads envelope-first")the rule Cortex follows when picking who does a jobexplains why a fully offline install won't get a cloud-only capability even if it's the strongest option elsewhere