Brain Hints Are Not Authority
A pipeline row may carry one advisory default-brain hint and a boolean review default because launch ergonomics matter. Some tools are better suited to long code sessions, while others have no supported native dispatcher. The row can remember a likely author choice and whether review is normally on, but it does not choose the reviewer.
A hint must not become a hidden gate. If the preferred brain is unavailable, the workshop should expose capabilities and allow an explicit compatible choice. It should not silently substitute and then record the hinted identity, nor should it block a qualified session merely because preference and reality differ.
Launch tickets are convenience with provenance. They package the delegation identity and requested brain for a supported dispatcher, expire, and are consumed once. They do not grant broader task authority; the resulting session still needs the claim and must present its own identity on later writes.
Review policy is separate again. The row's boolean default says whether independent review is normally required; the delegation chooses a review brain when it is created. The main author cannot self-certify just because its model family is powerful. The selected CLI and logged verdict provide authority, not the brand name.
Capability Before Preference
Build a capability map that answers whether a brain can launch, review by CLI, and hold a live session. Resolve preference only inside the compatible set and show the fallback to the operator.
Then record requested brain, actual session brain, and reviewer separately. Collapsing them into one field makes substitution invisible and independent review impossible to audit.