In short

Functions that need an answer within a second, or must survive an internet outage, run on the Plant Box: fast reads, data-quality gates, state estimation, the safety filter, standing-policy decisions and the writer. Analytics, scheduling, the value ledger and model training run in the cloud. Write-back is an additive channel in the NAMUR Open Architecture sense, with changes sent as requests in the NE 178 Verification of Request pattern. The Plant Box opens every connection, pulls signed bundles every 60 seconds and blocks writes when its clock drifts more than 2 seconds.

7.1 Placement#

FunctionLatency needRuns where (default)WhyOPEN?
Fast read, buffering≤1 sPlant BoxInternet outages; sub-second eventsNo
Data quality gates and evidence labels on fast signals≤1 sPlant BoxMust precede estimation and writesNo
State estimation (twin runtime)Per cycle or unit (seconds), model step 1 sPlant BoxWrites depend on it; heartbeat under 2 sD3 (Python vs compiled)
Predictive safety filter≤1 s for write pathPlant Box (fast); cloud copy for advisoryOuter shell before any write or action-implying messageD15
Writer≤1 s, read-back ≤1 sPlant Box onlySafety; the only component that issues change requests toward plant set pointsNo
Standing-policy decisionsSecondsPlant BoxSame loop as writerNo
Operator messagesSeconds to minutesCloud, with local fallback displayWhatsApp needs internetD7
Analytics (MSPC, causal, forecasts)Minutes to hoursCloudCompute, cross-plant priorsNo
SchedulingMinutesCloudSolver compute; ERP linksNo
Value ledgerDaysCloudNeeds full history and signoffNo
Model training and evalsHoursCloudComputeNo
Parameter and policy distributionMinutesCloud → pulled by Plant BoxOutbound-only connections (IEC 62443 conduit, E26)No

7.2 Write path: NAMUR Open Architecture and NE 178#

Stamped's write-back is designed as an additive monitoring-and-optimisation (M+O) channel, not as a replacement for core process control (CPC) or safety instrumented functions. NAMUR Open Architecture (NOA, NE 175) describes how plant data can leave CPC for plant-specific and central M+O without disturbing the automation pyramid; NE 178 (Verification of Request, published March 2025) describes how change requests travel back from M+O into CPC through authenticate → authorise → verify → map → accept → map-verify, with status feedback that does not disclose plant internals.

For Stamped this means, in pattern form (adoption depth OPEN D17):

  • Reads and analytics live on the M+O side (cloud slow loop and Plant BoxPlant-side computer for the fast loop (direction; D4) fast loop).
  • Any set-point or mode change is a request subject to AutonomyPolicySigned grants, envelopes, expiry (direction; L5 owns engine), predictive safety filter (C46), envelope and rate limits, operator primacy and read-back — the VoR idea, implemented with Stamped's writer and audit trail rather than a claim of full NE 178 compliance on day one.
  • SIS (IEC 61511, E25) and existing interlocks stay outside the allow-list; IEC 62443 zones and conduits (E26) still govern the Plant Box.
  • First write envelopes stay low-risk (utility set points, per-head trims) until the pattern earns trust in the ledger.

Plant Box remains the runtime host for fast-loop copies of estimation, safety filter and write policy — not a parallel brain that invents authority the cloud or the plant did not grant.

7.3 Edge–cloud sync protocol#

The Plant Box opens every connection; nothing in the cloud can open a connection into the plant (IEC 62443 conduit, E26).

Upstream (plant to cloud).

  • Streams: readings, twin_state, write_log, Action, outcomes. Each batch travels in the Envelope (section 5.10) with a per-stream source_seq.
  • The cloud acknowledges the highest contiguous sequence number per stream. The Plant Box deletes nothing before acknowledgement and its retention window (30 days, section 11).
  • Ingest is idempotent on (plant_id, stream, source_seq); a resend after reconnect is harmless.
  • Back-pressure: ingest answers with retry-after; the Plant Box resends oldest first in this priority: write_log and Action, outcomes, slow readings, fast readings. If the backlog passes 24 hours, fast readings are downsampled before sync and marked so.
  • Late data: continuous aggregates refresh a 7-day window; anything older triggers a recompute job for the affected plant and day.

Downstream (cloud to plant), pulled only.

  • The Plant Box polls every 60 seconds for a signed bundle: policy grants, parameter sets, model versions. It checks the signature and version before applying.
  • The cloud can revoke and can let grants expire; it cannot switch writes on. Switching on needs a person at the plant (section 6).
  • Every standing grant carries expires_at. A WAN outage never extends a grant, so the safe state arrives by itself.

Clocks. The Plant Box clock is disciplined by NTP. Every reading keeps source_ts and received_at. An offset above 2 seconds flags readings and blocks writes until the clock is back in band.

Page history: last 5 changes
  1. 2026-10-07 docs(research): retire stale research to archive/research-2026-10 with a register ab84821
  2. 2026-10-07 docs(technical): rewrite fast-loop/; all architecture diagrams in house style 7330f47
  3. 2026-10-07 docs(technical): archive archify; add SYSTEM_VIEWS.md house diagrams; check_docs --min 1e190b6
  4. 2026-10-07 docs(technical): carry product sections; rewrite README and pointers ee1e818
  5. 2026-10-07 docs(technical): split decision board into DECISIONS.md b4db9d4

Diagram

100%

Search the architecture