The tier ladder
Only the deterministic rung is on. Tiers 1 to 3 are built and held off by default.
Read Fig. 04 as text
TIER 3 behavioural verifier clears or refutes a change [ ] HELD OFF - opt-in
exercises the changed tool executes the tool
TIER 2 LLM consult judges the ambiguous [ ] HELD OFF - opt-in
an LLM call
TIER 1 cloud corpus lookup judged once, known [ ] HELD OFF - opt-in
everywhere a contract hash leaves
---------------------------------------------------------------------------------
TIER 0 deterministic did this contract change [X] LIVE - runs first
contract-diff versus what you pinned? local - no egress
ChangeKind taxonomy fail-closed
+ marker scan
the default build is tier-0 only. it egresses nothing.
the behavioural tier clears or refutes. it never proves a tool safe.A four-rung ladder. Tier 0, the deterministic contract diff over the ChangeKind taxonomy plus a marker scan, is live, runs first, is local and egresses nothing, and fails closed. Tier 1 cloud corpus lookup, tier 2 LLM consult and tier 3 behavioural verifier are built as in-path seams but each is held off by default and requires explicit opt-in. The default build is tier 0 only. The behavioural tier clears or refutes a change; it never proves a tool safe.
Licensed CC BY 4.0. Use it anywhere, including commercially. Keep the credit.
Paste under the figure. That is the whole licence obligation.
<a href="https://mcpindex.ai/diagrams/tier-ladder">The tier ladder - mcpindex.ai</a> (CC BY 4.0)Standalone image/svg+xml. Vector, editable, no stylesheet needed.
https://mcpindex.ai/diagrams/tier-ladder/svgLast reviewed 2026-07-27 · derived live from well-known:drift_gate.tiers · never hand-typed
mcp trust tiers · mcpindex tier 0 · deterministic contract diff · mcp gate architecture