> ## Documentation Index
> Fetch the complete documentation index at: https://docs.bijection.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Support desk with a hosted model

> Verify a customer, answer with scoped facts, and request a refund through reviewed business operations.

Part of [Customer support with bounded agent authority](/use-cases/support-desk/index).

## Complete stack

| System | Custody | Role | Owner | State | Version source | Failure contract |
| - | - | - | - | - | - | - |
| bijection | run | Customer facts, access policy, operations and agent sessions | Application owner | Operational state in PostgreSQL | CLI/backend digests and application source digest | Identity and operation checks are enforced at each entry. |
| host | run | Caller verification, session tools and request journal | Customer application backend | Private verification mailbox and durable call journal | host/desk.mjs and host/chat.mjs | Retries keep the same call identity; verification does not enumerate customers. |
| postgres | run | Operational persistence | Qualification resource owner | Disposable local cluster | Installed PostgreSQL executable recorded at execution | Cleanup stops only the exact owned cluster. |
| model | external | Propose tool calls and customer-facing responses | External model provider | Provider inference; never authoritative customer state | Explicit model binding and captured usage receipts | Provider failure does not grant authority or confirm an operation. |

## Connections

* **host → bijection:** Session-scoped read and operation tools. Identity: Store credential followed by verified customer session.
* **bijection → postgres:** Transactional operational persistence. Identity: Backend database credential.
* **host → model:** Bounded inference and proposed tool calls. Identity: Provider key retained only by the host.

## Deployment inputs

* `backend` (file, required): Native Bijection backend executable.
* `cli` (file, required): Bijection CLI executable.
* `sdk` (directory, required): Built Bijection SDK directory.
* `provider-env` (credential-file, required): Private file defining the hosted model API key.
* `model` (value, required): Explicit model name.
* `cost-estimate` (value, required): Reviewed maximum provider spend estimate for this bounded run.

## Bounds and cleanup

One loopback backend and one disposable PostgreSQL cluster; bounded fixture; no cloud runtime.

Maximum duration: 7200 seconds. Maximum captured log: 4194304 bytes.

Estimated cost: Usage is bounded to 40 calls per store, each with at most 1,500 output tokens. Supply a reviewed provider cost estimate before execution; input-token usage is recorded separately.

Cleanup: The qualification owner stops its exact child processes, removes credentials and stops its owned PostgreSQL cluster. A run passes only after cleanup is observed.

The executable runbook is maintained at `examples/support-desk/recipes/hosted-model/runbook.md`. A declared journey is verified only when every named check appears in a successful execution report and cleanup has been observed.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.