Every LLM endpoint sits behind a per-provider safety stop with closed, half-open, and open states and exponential backoff. Thresholds are configurable per tenant. When the safety stop opens, the orchestrator routes to the tenant-declared fallback provider and emits a registry event so the audit trail reflects the degraded path.
Backoff
Exponential with jitter
AnthropicOpenAIBedrockAzure OpenAIGoogle