In short

For the first three plants the targets include a fast-loop step under 1 second at p99, a card within 2 minutes of its prescription and zero acknowledged readings lost. They are design targets, not results, and each names the check that proves it. Security uses row-level tenancy, per-device certificates on the Plant Box and no inbound ports. Every degraded mode has an owner, a detector and a fallback, and writes stop first in all of them. Observability traces a card by episode_id from reading to ValueRecord, and deployment profiles run from one pilot box to managed HA.

11. Non-functional requirements#

Targets for the first three plants. They are design targets, not measured results; each is checked by the test or signal named.

RequirementTargetChecked by
Fast-loop step timep99 under 1 s; heartbeat under 2 s72-hour soak on the Plant Box (D3)
Writer read-backUnder 1 s after the writeWriter test against plant-sim, then shadow logs
Slow-loop freshnessReading in L2 within 5 minutes, p95Source watermark (migration 017)
Card deliveryWithin 2 minutes of the prescription, p95L5 card timeline
Acknowledged readings lostZeroSequence numbers and replay (section 7.3)
Plant Box buffer on WAN loss30 days of readingsLocal store sizing (section 15)
Cloud availability99.5% a month on one box; 99.9% after the D20 move to managed HAUptime check (section 14)
Recovery point and timeRPO 15 minutes (WAL archive), RTO 4 hoursQuarterly restore drill
RetentionRaw readings 90 days hot, 1-minute aggregates 3 years; write log, Action and ValueRecord 7 yearsTimescale retention policies
Tenant isolationNo cross-tenant readRLS tests in L2 CI
Running costInside the ADR-002 ceiling (₹15–25k a month) up to 5 plants; the D20 move to managed Timescale with HA breaks it by design, so the ceiling is revisited when D20 firesstamped_running_cost.py (section 16)

12. Security and tenancy#

AreaBuild nowLater (trigger)
TenancyOne shared database with row-level security by tenant_id (migration 006); RLS tests in L2 CIDedicated deployment per customer (a customer requires it, priced per deal)
PeopleStaff sign in with SSO and MFA; customer users by email one-time code; roles: viewer, owner, plant approverCustomer SSO (first customer that asks)
ServicesShort-lived service tokens; least-privilege database roles per service—
Plant BoxPer-device certificate (mutual TLS) issued at commissioning and revocable; OT and IT network ports with no routing between them; read-only root; signed A/B updates; no inbound portsTPM-backed keys where the hardware has a TPM
WritesOPC UA SignAndEncrypt with a per-plant certificate (D10); writer accepts only WriteRequest (section 5.8) inside the operating envelope; safety systems and interlocks are never on the allow-list—
SecretsCloud secret store; none in gitRotation automation (Growth tier)
AgentsRead-only, tenant-scoped tools; tool output never grants an action; step cap per question; provider allow-list per customer (D21)—
DataEncryption at rest (EBS, S3, managed database defaults) and TLS in transit; personal data limited to the names and phone numbers cards need; retention per section 11—
AuditHash-chained write_log; admin and policy changes logged with who and when—

The master document hard stops must be enforced in code, not only in policy: no AutonomyPolicySigned grants, envelopes, expiry (direction; L5 owns engine) can name a safety or critical-equipment tag, a quality hold, a maintenance authorisation, or a dispatch sequence; those action classes exist only as AL1Autonomy levels (direction; fast-loop stages 1–3 = AL1–AL3) advice that a named person acts on. Build gate: the AutonomyPolicy and WriteRequestPlant Box write path request (direction; closure/action-intent.json retired) 0.x schemas, with these action classes deny-listed and a CI test that fails if a policy names one, ship before any write leaves shadow.

13. Degraded modes#

Every mode has an owner, a detector and a safe fallback. Writes are the first thing to stop in every mode.

ModeDetected byOwnerFallback
WAN loss at the plantPlant Box sync heartbeatEDGE / Plant BoxBuffer locally; local display carries cards (D7); standing policies continue only if their grant has not expired; nothing new is granted
Clock skewNTP offset over 2 sPlant BoxReadings flagged; writes blocked until the clock is back in band
Ingest backlogSequence gap or lag over threshold in CLOUD ingestCLOUD ingestBack-pressure to the edge; replay in order by sequence number; analytics marked stale
Model stale or uncalibratedCoverage or NIS outside D14 band; model age over limitL3 registryRouter abstains; AL2 and above revert to AL1 messages
Coverage drop in dataData-quality gate (C03)L2 and Plant BoxEvidence label falls to Unknown; no action gated on it
Operator stop or touchWriter watchdog, operator inputPlant Box writerStop writes, restore the pre-write value where the policy says so, card to the owner
Cloud write switch offL5 autonomyL5Plant Box drops to AL1; switching back on needs a person at the plant

14. Observability#

Signal groupSignalsAlert (pages someone)
Plant BoxHeartbeat, buffer depth, clock offset, fast-loop step time p99, writer rejections by reasonHeartbeat lost over 5 minutes at a plant with an active grant; rejection spike
PipelineIngest lag per plant, sequence gaps, watermark age (migration 017)Lag over 15 minutes
ModelsCoverage and NIS per model class (D14), PSI drift, router abstain rateCoverage outside band for a model behind an active grant
ProductCards sent, budget suppressions, time to close— (daily digest)
CostLLM tokens per tenant against budget; cloud spend against the section 16 forecastTenant at 100% of budget
BackupsSnapshot and WAL archive success, last restore drillAny failure
  • Services emit structured JSON logs and OpenTelemetry traces keyed by episode_id, so a card can be traced from reading to ValueRecord. The backend is CloudWatch for the first tiers; the instrumentation does not depend on it.
  • An external uptime check measures section 11 availability.
  • Application logs are kept 3 months; write_log, Action and ValueRecord 7 years (section 11).

15. Deployment profiles and capacity#

ProfilePlantsCloudPlant sideTrigger to the next
Pilot1One EC2 t4g.large in ap-south-1 runs Timescale and the services in Docker Compose; Fargate for nightly jobs; S3 for backups and documents; Vercel for the front endPlant Box (D4)Memory above 70%, or a second plant
Early2–10Database and services on separate instances; Timescale still self-managed (D20)Plant Box per plantAny D20 trigger
Growth11+Tiger Cloud (Mumbai) with an HA replica; services on two or more instances behind a load balancerSameLoad
Air-gappedper dealNone; an on-site server runs the slow loop; LLM features off or self-hostedPlant Box plus on-site serverLater: first customer that forbids cloud; priced per deal, not in section 16

Capacity notes (base case, planning numbers, not measurements):

  • Plant BoxPlant-side computer for the fast loop (direction; D4). 40 fast tags at 1 Hz is about 3.5 million readings a day; 30 days fits easily in 256 GB. The twin step and safety filter must pass the D3 soak on the same box.
  • L2. About 5 GB per plant after 12 months with compression, from the sizing in scripts/pricing/stamped_running_cost_assumptions.json.
  • Jobs. Nightly analytics and CP-SAT repairs run as Fargate tasks of 1 vCPU and 2 GB, about 30 minutes per plant per day. The MHE benchmark runs offline (D19).
  • Delivery. CI builds images; the Plant Box pulls signed images (A/B); L2 migrations run through the existing migration runner. Infrastructure as code from the Early tier.
Page history: last 5 changes
  1. 2026-10-07 docs(research): retire stale research to archive/research-2026-10 with a register ab84821
  2. 2026-10-07 docs(technical): rewrite fast-loop/; all architecture diagrams in house style 7330f47
  3. 2026-10-07 docs(technical): archive archify; add SYSTEM_VIEWS.md house diagrams; check_docs --min 1e190b6
  4. 2026-10-07 docs(technical): carry product sections; rewrite README and pointers ee1e818
  5. 2026-10-07 docs(technical): split decision board into DECISIONS.md b4db9d4

Diagram

100%

Search the architecture