A completion-cache hit is not a cheap model call
A reused answer needs its own decision and receipt because no provider call occurs and current authority still controls whether it can serve.

A reused answer is a new governed event, not an unusually cheap model call. Its receipt should describe reuse without inventing provider usage or savings.
Our Muniment Cloud architecture contract draws this boundary between completion caching and provider prompt caching. The contract records accepted design, not observed runtime behavior.
Provider prompt caching still calls the model
Provider prompt caching can reuse prompt material inside a model request. The provider still executes that request and can report cache-read tokens.
A completion-cache hit takes another path. It returns a previously completed answer without making a provider call.
Calling both paths a cache hit hides the operational difference. One path contains a model request. The other serves an earlier result under a new decision.
Reuse gets a new receipt
The contract requires four facts for each completion-cache hit:
- The hit gets a new decision identity.
- The provider attempt count is zero.
- The receipt states
provider_call.made = false. - The source receipt belongs to the same organization.
The new decision identity matters because reuse does not revive the earlier request. It creates a current decision with its own evidence.
Zero provider attempts describes the skipped boundary. The explicit provider-call field removes any need to infer that fact from token values.
The source receipt preserves provenance for the completed answer. Its organization boundary prevents a hit from borrowing an answer across organizations.
This event still belongs in the request-level cost record described in Cost receipts belong to the request. The receipt records what this request did, including the external call it skipped.
Current authority decides whether reuse is allowed
An earlier answer carries the earlier actor and grants as provenance. Neither one becomes authority for the new request.
Before a cached answer may serve, the lookup evaluates six current checks again:
- The current actor.
- The current policy.
- The current budget.
- The current capabilities.
- The current retention rules.
- The source receipt’s eligibility.
A prior permission cannot bypass a policy change, revoked capability, exhausted budget, or retention rule. Reuse remains subject to today’s boundary.
Unknown cost stays unavailable
A skipped provider call does not establish that serving cost was zero.
The contract therefore keeps actual serving cost unavailable when the system cannot establish it. It does not manufacture a zero.
Estimated saved spend follows the same rule. Without a lifecycle-governed estimate, saved spend remains unavailable instead of appearing as zero.
The receipt does not manufacture zero token counts to imply that no provider call occurred. Token counts do not stand in for either value.
The contract stops before runtime claims
This architecture contract does not demonstrate runtime correctness or cache-hit quality. It does not demonstrate a latency improvement.
It also does not demonstrate isolation under production load or any cost savings. Implementation, adversarial conformance tests, and measured operation must support those claims.
The evidence comes from our Muniment Cloud note pinned to commit e985055710f7d9522e315.
A reused answer deserves a truthful receipt. The receipt should show a fresh decision, current authority, and the provider call that never happened.