"A missing binding is an explicit unavailable error. Bellows never substitutes a convenient wrong voice."
The Fork Where Tools Go Wrong
You ask for a profile, and the active account has no binding for it. Two paths open. The convenient one: find the nearest available voice, or quietly reach into the other account, and return something so the request succeeds. The honest one: stop, and say exactly what's unavailable. Bellows always takes the honest path. A missing account binding is an explicit unavailable error — never a silent substitution, never a silent cross-account fallback.
Why Wrong-But-Successful Is the Worst Outcome
A loud failure is annoying; a quiet wrong answer is dangerous. If a private message goes out in the wrong voice because the engine "helpfully" picked a substitute, nothing warned anyone, and the mistake is already in the room. Success that betrays the request is worse than a clean error, because it hides. The selected account must hold the exact logical binding — or the request stops, by name.
Fallback by Design, Not by Accident
This isn't hostility to fallbacks — it's insisting they be deliberate. There are real, designed fallback paths elsewhere in the family (native vision plus a text path, OAuth plus an API-key insurance). Those are chosen, tested, and visible at the switch. What Bellows refuses is the accidental fallback — the one that quietly degrades a specific promise ("speak as pippa") into a vaguer one ("speak in some voice"). Hard-fail is the default; any softening is a deliberate exception, never a convenience.