by LockedIn Labs

01 The tour

ARC1 by LockedIn Labs. Control for the autonomous enterprise.

The system of record for AI spending decisions, in twelve chapters: the next forced model change, the record each decision keeps, and what has run so far.

Scroll, or use ← → and J K to move between chapters.

The ARC1 console’s organization overview: machine tokens over 30 days, tokens over time by provider, the current burn rate and spend by model, with departments listed below.
Overview · the whole organizationSynthetic health plan · synthetic data

02 The answer

The system of record for AI spending decisions.

From the options priced to what the month actually cost.

Your gateways enforce. Your evaluation tools test. Your ledger holds the money. ARC1 joins them, one decision at a time, inside your own tenant.

It starts from the AI spend you already have, read as metadata from the systems that hold it.

The same overview scoped to one engineering team inside the claims department: its tokens, providers, models and the people who use them.
Team · Claims Intake EngineeringSynthetic health plan · synthetic data

Spend, by the teams that own it.

Provider bills, gateway readings and agents’ own reports stay separate sources, mapped to departments, teams and workflows. What no source explains stays in view as a remainder.

One workflow, claims auto-adjudication: its workload tokens over 30 days, tokens over time, the model it runs on and the agent that reports it.
Workflow · Claims auto-adjudicationSynthetic health plan · synthetic data

Down to the workflow a decision changes.

A model change is decided on one workflow: the work it does, the model it runs on and what it costs. In ARC1 a decision starts there, with a candidate reviewed against the current model and its limits.

Today ARC1 handles model-change decisions. What has run and what is built: chapter 9.

17

model versions, 14 Oct 2026 to 9 Feb 2027

  1. gpt-4.1-nano1
  2. codex-mini, claude-haiku-4-52
  3. o1, o1-pro, o3, o3-pro, o3-deep-research → gpt-5.6-sol; o3-mini, o4-mini → gpt-5.6-terra7
  4. claude-opus-4-51
  5. claude-sonnet-4-5 → claude-sonnet-5-51
  6. gpt-4o (2024-05-13) → gpt-5.6-sol1
  7. claude-opus-4-61
  8. gpt-5, gpt-5-mini, gpt-5-nano · no replacement listed3
Non-preview text and reasoning models: Azure OpenAI, and Anthropic models in FoundrySourced · Microsoft Learn

03 The trigger

17 model versions retire by 9 February 2027.

Seven of them retire on one day: 19 November 2026.

Standard, Global Standard and Data Zone deployments move to Microsoft’s named replacement unless you opted out. Provisioned deployments don’t move; they must be migrated first. The dates can’t be extended.

For regulated workloads, Microsoft’s own migration guide names the review as the bottleneck. Its advice is to “evaluate available models using your application and data, comparing quality, latency, and cost.” The same guide says teams rarely record what they changed, or why.

Microsoft Learn, Foundry model retirement schedule, Appendix B (page dated 21 Sep 2026, read 7 Oct 2026). Non-preview Azure OpenAI and Anthropic text and reasoning models retiring 14 Oct 2026 to 9 Feb 2027 inclusive; 18 table rows, Haiku 4.5 hosting variants counted once, give 17; count by LockedIn Labs. Whether a workload moves depends on its deployment type and upgrade setting.

Microsoft Learn: model migration guide (updated 26 Aug 2026); models lifecycle policy (updated 24 Jul 2026). Microsoft’s schedule

A decision review for the claims auto-adjudication workflow: evidence incomplete, three visible stages absent and the gap it opens with, spend not reconciled, and the control that downloads the decision packet.
Decision review · evidence incomplete, three stages absentSynthetic health plan · synthetic data

04 One decision, one record

Every decision keeps one record.

What is missing stays visibly missing, never filled in.

Each decision becomes one record: what triggered it, what was compared, who approved it, where it landed and what it cost.

The record view downloads it as a decision packet.

  • Trigger
  • Options, priced on the workflow’s own token mix
  • Limits, registered before results
  • Approval by a second person
  • Published to your gateways, read back
  • Follow-up
  • The month’s spend against the forecast
The same decision’s evaluation: three registered comparisons of 200 paired requests each, two within their registered limits and one outside them on quality, errors and latency.
Decision review · three registered comparisonsSynthetic health plan · synthetic data

The evidence keeps its limits.

On this decision, three comparisons of 200 paired requests each were registered with their limits. Two stayed within them; one missed on quality, errors and latency, and the record says so in words.

Synthetic health plan · synthetic data. Pricing the vendor’s default as its own option is planned, and so is recording outcome counts with the decision.

Candidate A

82%

accepted · cheapest per attempt · misses quality, error and latency limits

Errors
4.0%
95th-percentile latency
1,800 ms
Per attempt
$0.05
Cost per accepted result
71.0% lower

Misses the limits

Candidate B

49.5%

lower cost per accepted result, Candidate B, at 94% accepted

Errors
0.5%
95th-percentile latency
700 ms
Per attempt
$0.10
Cost per accepted result
$0.106383

Meets the limits

Hypothetical default

+25%

cost per accepted result · same acceptance as today · misses the cost limit

Errors
0.0%
95th-percentile latency
800 ms
Per attempt
$0.25
Cost per accepted result
$0.263158

Misses the limits

Baseline · 190 of 200 accepted (95%) · $0.20 per attempt · $0.210526 per accepted result

Worked example · claims-correspondence summarizationSynthetic health plan · synthetic data

05 The same work, three ways

Same work, priced three ways.

ARC1 imports your evaluation results; it does not run them.

One option meets the limits. The same 200 paired tasks run against each option, judged by limits registered before anyone sees a result.

Quality
no more than 2 points below the baseline
Errors
no more than 1%
Latency
no more than 1,000 ms at the 95th percentile
Cost
at least 10% lower per accepted result

Unknown prices stay unknown. Select an option to see why it passes or misses.

Worked example: claims-correspondence summarization, 200 paired imaginary tasks per option against a 95% baseline. Imaginary rates, not vendor prices.

  1. Proposedby an administrator
  2. Approvedby a second person, never the proposer
  3. Publishedto the gateway, then read back
  4. Month closedby a different person with finance authority
  • Self-approvalRefused
  • Execution before approvalRefused
Diagram · the rule the lab run exercisedLab run · 6 Oct 2026

06 A second person approves

Every change needs a second person.

Whoever proposes a change can never approve it.

An administrator proposes a policy and a second person approves it. A different person with finance authority closes the month.

The approval is a separate, signed step. A change that tries to skip it is refused.

Lab run, 6 Oct 2026: self-approval and execution before approval were both refused. Receipts are signed by the deployment’s key, not by each person.

50 of 50

signed receipts verified in the lab run

  1. Version 2 published and read back
  2. A change made outside the process
  3. Drift shown on the decision
  4. Recovery approved by a second person
  5. Matches approved

Self-approval refused.

The lab run · one Kong OSS 3.9.3 node, two routesLab · 6 Oct 2026

07 Govern once, read it back

Govern once. Read it back.

One approved policy, compiled for each gateway, then read back.

Your gateways enforce. ARC1 stays out of the request path.

Example rules: labeled plan member IDs and MRNs blocked in prompts; secrets blocked in coding-agent prompts; a daily token quota per person at API Management. Where a gateway cannot carry a rule, the decision says so.

The administrator’s Flow view: callers, configured gateways and model APIs on the request path, with the ARC1 hub beside it sending approved configuration out and taking reported usage, policy events and target readback in.
Command Center · Flow: ARC1 beside the request pathSynthetic health plan · synthetic data

Configuration out, evidence in.

One approved policy is compiled for supported gateways and coding-agent hooks, and each target’s reported configuration is compared with the signed version. A match is configuration evidence; enforcement needs its own request records.

Lab run, 6 Oct 2026: one Kong OSS 3.9.3 node, two routes, no inference, not a customer gateway. API Management and coding-agent settings are built, not yet run live.

$190

for the month

$200
the forecast, approved before the month began
−5%
against the forecast
Worked example · the forecast monthSynthetic health plan · synthetic data

08 The month’s spend

The month’s spend, against the forecast.

$190 for the month, against a $200 forecast approved before it began.

ARC1 reads your ledger. It never posts to it.

In ARC1 the forecast is approved before its month begins, and the closed month’s ledger lines are assigned to it.

Synthetic health plan · synthetic data. Worked-example arithmetic: not a saving, not a finance attestation.

Results: a business case’s value ledger, with its August reconciliation from plan to actual, the ledger movement, the share attributed to AI and the amount allocated to the case shown as separate, nested amounts.
Results · a separate business case, August reconciliationSynthetic health plan · synthetic data

Results, held to the ledger.

A business case names its owner and locks its baseline at approval. Forecast, provisional value and finance-approved allocation stay separate, and a different person with finance authority closes the month.

Has run

  • Publish, read back, drift, recovery · Kong, our lab
  • Record, follow-up, forecast lock · test databases
  • Offline verification of signed receipts
  • The worked example · illustration, fictional data

Built, not yet run live

  • Azure API Management
  • Entra sign-in and install in your tenant
  • Claude Code and Codex settings
  • Provider and billing readers
As of 7 October 2026Status

09 Stated as it stands

What has run, and what is built.

Customer installations: none yet.

Every product screen in this tour comes from our hosted reference deployment, on a fictional health plan’s synthetic data. No customer has closed a month in ARC1 yet.

As of 7 October 2026. Record, follow-up and forecast paths tested in disposable databases; the worked example is a fictional illustration and writes no records. Lab: one Kong OSS 3.9.3 node, 6 Oct 2026.

  • Kong GatewayCompiles the approved policy, publishes it after a second approval, reads the configuration back and shows drift.Run in our lab
  • Azure API ManagementReads token metrics into Spend; compiles approved policy, including a daily token quota per person, and reads it back.Built, not yet run live
  • Claude Code and CodexManaged settings and hooks compiled from the approved policy; usage reported as metadata.Built, not yet run live
Where approved policy is enforced: your gateways and coding agentsMarks belong to their owners

10 Integrations

It fits what you already run.

Metadata in. Compiled policy and exports out, through your pipeline.

ARC1 sits above your request path and reads what you already run. Your pipeline still ships every change.

Connectors are tested against each vendor’s documented interface; Kong is the one exercised against a running gateway, in our lab. Marks belong to their owners.

  • Azure Cost ManagementReads an existing Cost Management export in the FinOps FOCUS format; it creates no export, role or resource.Built, not yet run live
  • Provider usage APIsReads provider usage and cost reports, kept apart from gateway and machine readings.Built, not yet run live
  • Entra ID and OktaSign people in; SCIM sends people and departments. ARC1 never writes to them.Built, not yet run live
  • GitHubReads the approvals your pipeline already records, beside ARC1’s own.Built, not yet run live
  • ServiceNowPublishes the AI inventory to AI Control Tower after approval, and opens approval tickets.Built, not yet run live
  • Datadog, Splunk and SentinelReceive an approved export from ARC1.Built, not yet run live
What ARC1 reads, and where it sendsMarks belong to their owners

Your tools already produce every number.

Usage, cost, identity and approvals are read where they already live, and an approved export goes to the tools your teams already watch.

Trademarks belong to their owners. API Management and the ServiceNow connector are built, not yet run live.

Your environment

ARC1PostgreSQL
  • Usage and cost metadata
  • Gateway configuration, read back
  • Your directory, through Entra ID or Okta

Your request path · prompts and replies stay here

LockedIn Labs · no connection required

Diagram · where ARC1 runs and what it holdsDiagram

11 Security and the data boundary

Yours to run.

ARC1 runs in your tenant, holds metadata, and stays read-only until you grant more.

Metadata only
Requests never pass through ARC1. The usage reporting contract excludes prompts, responses, source code and local paths.
In your environment
One deployment for one organization, in your environment, signed in through your identity provider.
How it installs
Container image, Helm chart, PostgreSQL; Azure templates for Container Apps. No connection to LockedIn Labs required.
Signed receipts
Every proposal, approval and policy change is kept as an Ed25519-signed receipt, chained to the one before it and verifiable offline.
Two people sign
Every change is proposed by one person and approved by another.

Publishing to a gateway needs a write identity you grant, limited to what ARC1 owns, and a second approval on every change.

30

days, inside your own tenant

Week 1
Install in your subscription; connect one gateway and the billing export.
Week 2
Price the workflow’s options on its own token mix; register limits; import your evaluation results.
Week 3
Approve, compile, ship through your pipeline to a test route; read back.
Day 30
Decide: license it, build with LockedIn Labs, or stop.
One workflow that faces a model changeRead-only

12 The pilot

A read-only pilot on one workflow.

Day 30: license it, build with LockedIn Labs, or stop.

We need a place to run it, an Entra app registration, reader roles on one gateway and the billing export, and two named approvers. The check against your ledger follows when the forecast month closes.

A wider horizon.

See the record on your next model change.

A 30-minute walkthrough on our hosted reference deployment, with synthetic data. If a retirement or another model change is coming, we use it as the example.