| Custom functions | Model selects a callable. | Qwen selects typed application functions. | ExactNet composes dynamically supplied typed operators. |
| Intermediate state | Tool results return to model context. | Typed registry objects persist across turns; context uses descriptors and references. | Intermediate program values remain in runtime state. |
| Multi-step work | Model chooses successive tool calls. | One session coordinates Qwen, functions, and built-in ExactNet operations. | One semantic delegation can produce an entire exact program. |
| Final answer | Model may write values into prose. | ExactIR references and formatting materialize exact spans. | The same rendering boundary is retained. |
| Checks | Depend on the application and tools. | References, signatures, result types, execution errors, and provenance. | Add semantic types, behavioral checks, and calibrated execute/defer decisions. |
| New functions | Expose descriptions to the model. | No ExactNet retraining; Qwen owns selection. | Test unseen-function composition by ExactNet without new output classes. |
| Private values | Exposure depends on tool arguments, returned data, and deployment. | Raw PII can stay in a local registry; use opaque IDs and minimal descriptors. | Preserve that boundary through program synthesis and execution. |