An application presents a key and names its route. Miso looks the caller up in one registry and the model in another, replaces the identifiers the route says to replace, sends the request to a provider with an agreement in force, and writes a record. Internal applications and vendor applications go through the same check.
Each provider is listed with the BAA that covers it, its retention terms, and its region. Each model is pinned to a version the provider documents as fixed. A provider with no agreement on file is outside every route.
Each application, team, and vendor is listed with its agreement, its routes, its budget, and its review date. A request whose key matches no entry is refused and logged. For everything that goes through Miso, this list is the AI inventory.
When Privacy approves Claude Sonnet for discharge summaries, the route records exactly that: which application may call it, what data it may send, which identifiers get replaced first, under which BAA, and what the caller owes afterwards. A route request from a builder comes with the validator's findings attached; approval puts it live.
Allowed or refused, each request adds a row to an append-only table in your Postgres, hash-chained to the row before it. Identifier types and counts are recorded. The values are never stored.
Some obligations Miso enforces itself. Some the provider attests to in its BAA. Some the vendor or team attests to and receives back on every response. The ledger shows all three, and it shows the ones nobody has taken yet.