In short

The operating loop has eight steps, from ingest to proposed learning, each owned by a layer. L4 owns the immutable card proposal and L5 the mutable live card with its 11 closure states. Pilot 1 is a machine confirmed idle with extra loads still on, sent to the ops head with autonomy off. A table lists each repo layer's job, contracts and must-nots, and another separates what Stamped is from what it is not. The master document still wins on identity and hard stops.

Carried over from the previous architecture page (3 October 2026) where the master document does not already say it. The master document wins on identity, outcomes, ways and hard stops.

17.1 Operating loop#

StepNameWhat happensLayer
1IngestMeters, machine state, quality and production records, maintenance context, calendars, structured human input② Context (L1, L2)
2NormaliseJoin enough to name one condition (condition key)② Context (L2)
3DetectMethods, models and rules produce evidence with a verification plan (as built: Finding 1.2.0; direction: Evidence, section 5.2)③ Analytics (L3)
4Recommend or answerInvestigate across line, batch, shift and state; emit, supersede, withhold or abstain; or answer a question from the same context④ Decision (L4)
5AssignResolve the role to a person on shift⑤ Action (L5)
6RecordAccept, edit, reject or defer, with a reason⑤ Action (L5)
7VerifyNamed evidence and an honest closure state (section 5.9)⑥ Value (L5)
8Propose learningShort learning fact into plant memory; a named owner accepts any production rule or threshold change⑥ Value, governance plane

17.2 Proposal and live card#

ObjectOwnerNature
Card proposalL4Immutable. One primary outcome, one way and optional effect tags; one recommended action and at most two alternatives (hold is always one); proposed owner role; required autonomy level; uncertainty; verification plan; operation emit or supersede; decision trace id. As built it sits beside prescription.json 1.0.0 and L5 dual-reads both; direction is the Prescription contract (section 5.3). Field list: l4/18-contract-deltas.md.
Live cardL5Mutable. Person, history and one of the 11 ClosureState values (section 5.9); records whether a person or an enabled policy acted. An open proposal can be marked superseded before acceptance; that is not a closure state.

Closed is not the same as successful: closed_no_change and rejected are honest outcomes and feed learning. The 8-state list in older docs is retired.

17.3 Pilot 1 and the admission rule#

Pilot 1 (as-built energy-and-waste entry): a machine confirmed idle with extra loads still on. The operational task goes to the ops head; the primary outcome is energy and waste, with machine-minutes as a time effect if any. Autonomy stays off. Verification follows IPMVP retrofit isolation on the named auxiliary circuit: Option B (load and idle interval measured) may close as verified; Option A keeps estimated parameters modeled; the whole-facility meter is the wrong boundary. Detail: 16-pilot-and-hard-stops.md.

Admission rule for the next families (alarm dwell, quality correction, near-term sequence): a named owner role, a verification source already in L2, a reviewed constraint and a reusable template. Which outcome is proved first on a live plant stays open in the master document. What not to build: 17-do-not-build.md.

17.4 Repo layers: jobs, contracts and must-nots#

Repo layerRepos (as built)JobPrimary contractsMust notDeep doc
L1connectors-edge, connectors-cloud, connectors-docRead plant and document signals into envelopes; Plant Box fast read and writer (direction)stamped-record-envelope, measurement, event, bill_line; Envelope (section 5.10)Write to OT outside the Plant Box writer and a WriteRequest (section 5.8)layers/L1-connect.md, L1-L2-DATA-PLANE.md
L2universal-repositaryStore of record: readings, assets, topology, context records, lots and genealogy (direction)envelope ingest, query API, Lot and genealogy (section 5.7)Hand L3–L6 a database URL; become a second plant graphlayers/L2-universal-repository.md
L3intelligence-core, intelligence-rulepacks, intelligence-evalsSeven-job chain jobs 1–5, router with abstain, the one model registry (D9), twin runtime (direction)Finding 1.2.0 as built; Evidence and PlantState (section 5.1, section 5.2)Open L2 SQL; promote Lab output; invent rupeesl3/
L4knowledge-reasoningJobs 6–7: ranked prescriptions, scheduling repair, Ask; agents through typed read-only toolscard proposal, decision trace, Prescription (section 5.3)Assign the final person; send messages; write equipment or master datal4/, l4/30-as-built.md
L5closure-verificationCard machine, one sender and budgets (D16), verification packs, AutonomyPolicy and the safety filter (D15), ValueRecordClosureState, Action, ValueRecord, AutonomyPolicy (sections 5.4–5.6, section 5.9)Draft options; invent recommendations; override a withholdlayers/L5-closure.md
L6experience-integrationDecision queue, live picture, value register, AskBFF over L2, L4 and L5 HTTP (ADR-016)Hold keys in the browser; a second sender; a summed rupee headlinelayers/L6-experience.md

Repos talk only through versioned contracts in this pack (ADR-006). Only L2 opens TimescaleDB for plant truth; L4 may hold derived operational data (situation model, traces, case libraryEpisodic store of traces joined with L5 outcomes; authority when it disagrees with Hindsight, opportunity ledgerStore of every blocked candidate with gate id and later outcome if known) but not a second plant record (ADR-021).

17.5 Anti-confusion#

ConcernStamped isStamped is not
Energy and wasteOne outcome and a practical entryAn energy-only product, an EMS, or verified DISCOM-bill identity
Quality and yieldAn outcome with a person-accepted correctionA QMS replacement; silent hold release
Uptime and throughputThe next action from plant proceduresA CMMS or lockout authorisation
Dynamic schedulingA near-term sequence a person acceptsAn APS, a plant OS, or a silent dispatch publish
MES, ERP, APS, QMS, CMMSContext Stamped readsSystems Stamped replaces
L4The decision layer: decide and answer from plant contextThe company; silent plant control; a chat-only product
L3Analytics: methods and models feeding L4A frozen energy-only detector list
AutonomyEarned per action class and asset in an AutonomyPolicy, plant-approved, revocable, every action recorded; default AL1Silent or unapproved control
Plant Box writerWriteRequest only, OPC UA only, inside a signed operating envelopeA second brain that invents authority
AgentsRead-only tools that proposeHolders of an AutonomyPolicy

17.6 Reading map#

PriorityDocFor
0Stamped_Master_Document.mdCompany identity and hard stops
1This fileThe architecture
2DECISIONS.mdWhat is still to be decided
3layers/One page per repo layer
4L1-L2-DATA-PLANE.md, l3/, l4/, fast-loop/Depth per layer and the plant-side fast loop
5SYSTEM_VIEWS.mdSystem and repo views as house diagrams
6../handoff/README.md, ../contracts/, ../decisions/README.mdBuild handoffs, schemas, ADRs
7../research/stamped-tech-revamp-2026-10/Learning guide, appendix, cost estimate, capability map and evidence ledger behind this file
Page history: last 5 changes
  1. 2026-10-07 docs(research): retire stale research to archive/research-2026-10 with a register ab84821
  2. 2026-10-07 docs(technical): rewrite fast-loop/; all architecture diagrams in house style 7330f47
  3. 2026-10-07 docs(technical): archive archify; add SYSTEM_VIEWS.md house diagrams; check_docs --min 1e190b6
  4. 2026-10-07 docs(technical): carry product sections; rewrite README and pointers ee1e818
  5. 2026-10-07 docs(technical): split decision board into DECISIONS.md b4db9d4

Diagram

100%

Search the architecture