Agent architecture
Agents sit downstream of structured intelligence. They reach the context, analytics and decision layers only through typed, read-only tools, and any number they report must cite an evidence ID and tier. A validator checks every proposal for schema, units, limits and evidence IDs, and a valid one becomes a Prescription draft at AL1 for a person to act on. Agents never hold an AutonomyPolicy. All LLM calls go through one gateway in KR with a per-tenant token budget, a low-cost default model and at most eight tool calls per question.
Agents sit downstream of structured intelligence. The design rule from the evidence: the systems with real control results compute decisions with models and optimisers and keep people or deterministic checks in charge (E03 to E05, E08). Agent results in industry today are about engineer time on analysis and search (E07 is a vendor's 70% time saving on root-cause analysis), not plant KPIs.
How to read it.
- The agent reaches the layers only through typed, read-only tools.
- Every proposal passes the validator; an invalid one goes back to the agent.
- A valid proposal becomes a Prescription draft at AL1, for a person to act on.
Build now: Ask with the validator. Later: agent-drafted re-plans, confirmed by a person.
View Mermaid source
flowchart TB
%% house-style: agent-architecture
user["Plant manager or engineer"] --> agent["Agent (LLM)"]
agent -- "typed tool calls" --> tools["Tools: query metric, get PlantState, list Evidence, get Prescription, graph lookup, document search, run what-if"]
subgraph layers["Read-only sources"]
direction LR
l2["Context store"]
l3["Analytical layer"]
l4["Decision layer"]
end
tools --> l2 & l3 & l4
agent -- "proposal" --> val{{"Validator: schema, units, limits, evidence IDs present"}}
val -- "valid" --> rx["Prescription draft (AL1)"]
back(["↩ invalid: back to the agent"])
val --> back --> agent
classDef govc fill:#fff4d6,stroke:#c99a2e,color:#000
classDef agentc fill:#e8f0ff,stroke:#5b7bd5,color:#000
classDef loopc fill:#eef7ee,stroke:#4f9a4f,color:#000
class val govc
class user,agent agentc
class back loopc
Rules that follow from this:
- Read-only tools. Agents have read-only tools. Any number they report comes from a tool result with an evidence ID and an evidence tierContract tier on claims: measured / confirmed / modeled / unknown; quantity labels per D13 (Measured / Estimated / Assumed / Unknown); the validator rejects answers that state numbers without one, and rejects action proposals that cite uncalibrated outputs when a gate requires calibration (C23, C44).
- Method router. Agents call the method-selection router (C45) rather than inventing a method; abstain is a first-class result when evidence or calibration is insufficient.
- Re-planning. For re-planning, the agent translates a plain-language request ("move order 4471 ahead, keep changeovers under two per shift") into solver constraints; CP-SAT solves; a deterministic checker validates the plan against hard constraints; the plan is shown with what changed. Re-plan and tariff sit on calibrated prediction, abstain and the safety filter. LLM formulation accuracy is still modest on industrial problems (OptiMUS-0.3 at 37.0% on IndustryOR, E44), so the human confirms the constraint set before solving.
- No AutonomyPolicySigned grants, envelopes, expiry (direction; L5 owns engine). Agents never hold an AutonomyPolicy. They can draft one for a person to sign. Agent proposals that imply action still pass the predictive safety filter (C46) before becoming a PrescriptionWhat to do, why, who, check plan (direction; as built: prescription.json 1.0.0 / card-proposal) at AL1Autonomy levels (direction; fast-loop stages 1–3 = AL1–AL3) or higher.
8.1 Agent cost and safety controls#
- One gateway (D21). All LLM calls go through one gateway in KR with a per-tenant monthly token budget: a warning at 80% and a hard stop at 100%, after which Ask answers with deterministic tools only.
- Cheap by default. A low-cost model answers by default; a larger model is used only for named tasks, and each use is logged. Prompt caching covers system prompts and tool schemas.
- Bounded loops. At most eight tool calls per question; no agent runs unattended on a schedule except the shift handover summary.
- Measured. Tokens and cost per tenant are a metric (section 14). The running-cost model prices the LLM line per model (section 16): at base usage it is under ₹600 per plant per month with the default model.
Page history: last 5 changes
- docs(research): retire stale research to archive/research-2026-10 with a register
ab84821 - docs(technical): rewrite fast-loop/; all architecture diagrams in house style
7330f47 - docs(technical): archive archify; add SYSTEM_VIEWS.md house diagrams; check_docs --min
1e190b6 - docs(technical): carry product sections; rewrite README and pointers
ee1e818 - docs(technical): split decision board into DECISIONS.md
b4db9d4