Edge and cloud split, and the write path (NAMUR OA / NE 178)
Functions that need an answer within a second, or must survive an internet outage, run on the Plant Box: fast reads, data-quality gates, state estimation, the safety filter, standing-policy decisions and the writer. Analytics, scheduling, the value ledger and model training run in the cloud. Write-back is an additive channel in the NAMUR Open Architecture sense, with changes sent as requests in the NE 178 Verification of Request pattern. The Plant Box opens every connection, pulls signed bundles every 60 seconds and blocks writes when its clock drifts more than 2 seconds.
7.1 Placement#
| Function | Latency need | Runs where (default) | Why | OPEN? |
|---|---|---|---|---|
| Fast read, buffering | ≤1 s | Plant Box | Internet outages; sub-second events | No |
| Data quality gates and evidence labels on fast signals | ≤1 s | Plant Box | Must precede estimation and writes | No |
| State estimation (twin runtime) | Per cycle or unit (seconds), model step 1 s | Plant Box | Writes depend on it; heartbeat under 2 s | D3 (Python vs compiled) |
| Predictive safety filter | ≤1 s for write path | Plant Box (fast); cloud copy for advisory | Outer shell before any write or action-implying message | D15 |
| Writer | ≤1 s, read-back ≤1 s | Plant Box only | Safety; the only component that issues change requests toward plant set points | No |
| Standing-policy decisions | Seconds | Plant Box | Same loop as writer | No |
| Operator messages | Seconds to minutes | Cloud, with local fallback display | WhatsApp needs internet | D7 |
| Analytics (MSPC, causal, forecasts) | Minutes to hours | Cloud | Compute, cross-plant priors | No |
| Scheduling | Minutes | Cloud | Solver compute; ERP links | No |
| Value ledger | Days | Cloud | Needs full history and signoff | No |
| Model training and evals | Hours | Cloud | Compute | No |
| Parameter and policy distribution | Minutes | Cloud → pulled by Plant Box | Outbound-only connections (IEC 62443 conduit, E26) | No |
7.2 Write path: NAMUR Open Architecture and NE 178#
Stamped's write-back is designed as an additive monitoring-and-optimisation (M+O) channel, not as a replacement for core process control (CPC) or safety instrumented functions. NAMUR Open Architecture (NOA, NE 175) describes how plant data can leave CPC for plant-specific and central M+O without disturbing the automation pyramid; NE 178 (Verification of Request, published March 2025) describes how change requests travel back from M+O into CPC through authenticate → authorise → verify → map → accept → map-verify, with status feedback that does not disclose plant internals.
For Stamped this means, in pattern form (adoption depth OPEN D17):
- Reads and analytics live on the M+O side (cloud slow loop and Plant BoxPlant-side computer for the fast loop (direction; D4) fast loop).
- Any set-point or mode change is a request subject to AutonomyPolicySigned grants, envelopes, expiry (direction; L5 owns engine), predictive safety filter (C46), envelope and rate limits, operator primacy and read-back — the VoR idea, implemented with Stamped's writer and audit trail rather than a claim of full NE 178 compliance on day one.
- SIS (IEC 61511, E25) and existing interlocks stay outside the allow-list; IEC 62443 zones and conduits (E26) still govern the Plant Box.
- First write envelopes stay low-risk (utility set points, per-head trims) until the pattern earns trust in the ledger.
Plant Box remains the runtime host for fast-loop copies of estimation, safety filter and write policy — not a parallel brain that invents authority the cloud or the plant did not grant.
7.3 Edge–cloud sync protocol#
The Plant Box opens every connection; nothing in the cloud can open a connection into the plant (IEC 62443 conduit, E26).
Upstream (plant to cloud).
- Streams: readings, twin_state, write_log, Action, outcomes. Each batch travels in the Envelope (section 5.10) with a per-stream
source_seq. - The cloud acknowledges the highest contiguous sequence number per stream. The Plant Box deletes nothing before acknowledgement and its retention window (30 days, section 11).
- Ingest is idempotent on (
plant_id, stream,source_seq); a resend after reconnect is harmless. - Back-pressure: ingest answers with retry-after; the Plant Box resends oldest first in this priority: write_log and Action, outcomes, slow readings, fast readings. If the backlog passes 24 hours, fast readings are downsampled before sync and marked so.
- Late data: continuous aggregates refresh a 7-day window; anything older triggers a recompute job for the affected plant and day.
Downstream (cloud to plant), pulled only.
- The Plant Box polls every 60 seconds for a signed bundle: policy grants, parameter sets, model versions. It checks the signature and version before applying.
- The cloud can revoke and can let grants expire; it cannot switch writes on. Switching on needs a person at the plant (section 6).
- Every standing grant carries
expires_at. A WAN outage never extends a grant, so the safe state arrives by itself.
Clocks. The Plant Box clock is disciplined by NTP. Every reading keeps source_ts and received_at. An offset above 2 seconds flags readings and blocks writes until the clock is back in band.
Page history: last 5 changes
- docs(research): retire stale research to archive/research-2026-10 with a register
ab84821 - docs(technical): rewrite fast-loop/; all architecture diagrams in house style
7330f47 - docs(technical): archive archify; add SYSTEM_VIEWS.md house diagrams; check_docs --min
1e190b6 - docs(technical): carry product sections; rewrite README and pointers
ee1e818 - docs(technical): split decision board into DECISIONS.md
b4db9d4