Local Mini, Cloud Full
auto is the default. On a local leg it resolves to the compiled mini protocol. On a cloud-class leg it resolves to full: the six-layer read-only load order — identity, shared instructions, shared core, soul instructions, soul core, soul index. Paths and declared template variables live in operator config. Firebrand substitutes only those declared names and records the rendered hash. It does not invent a second Pippa and it does not write the vault.
A /model flip across the class boundary re-resolves. Identity mode, source hashes, and the rendered hash become a recorded identity_change. Resume folds the latest state. It does not trust the birth line of session_start after a later transition has spoken.
Override Is Recorded, Not Hidden
--identity and /identity override auto. The override is a fact on the record, not a side conversation. A later reader must be able to say which dial was in force when the model answered.