Product context for builders
The operating loop has eight steps, from ingest to proposed learning, each owned by a layer. L4 owns the immutable card proposal and L5 the mutable live card with its 11 closure states. Pilot 1 is a machine confirmed idle with extra loads still on, sent to the ops head with autonomy off. A table lists each repo layer's job, contracts and must-nots, and another separates what Stamped is from what it is not. The master document still wins on identity and hard stops.
Carried over from the previous architecture page (3 October 2026) where the master document does not already say it. The master document wins on identity, outcomes, ways and hard stops.
17.1 Operating loop#
| Step | Name | What happens | Layer |
|---|---|---|---|
| 1 | Ingest | Meters, machine state, quality and production records, maintenance context, calendars, structured human input | ② Context (L1, L2) |
| 2 | Normalise | Join enough to name one condition (condition key) | ② Context (L2) |
| 3 | Detect | Methods, models and rules produce evidence with a verification plan (as built: Finding 1.2.0; direction: Evidence, section 5.2) | ③ Analytics (L3) |
| 4 | Recommend or answer | Investigate across line, batch, shift and state; emit, supersede, withhold or abstain; or answer a question from the same context | ④ Decision (L4) |
| 5 | Assign | Resolve the role to a person on shift | ⑤ Action (L5) |
| 6 | Record | Accept, edit, reject or defer, with a reason | ⑤ Action (L5) |
| 7 | Verify | Named evidence and an honest closure state (section 5.9) | ⑥ Value (L5) |
| 8 | Propose learning | Short learning fact into plant memory; a named owner accepts any production rule or threshold change | ⑥ Value, governance plane |
17.2 Proposal and live card#
| Object | Owner | Nature |
|---|---|---|
| Card proposal | L4 | Immutable. One primary outcome, one way and optional effect tags; one recommended action and at most two alternatives (hold is always one); proposed owner role; required autonomy level; uncertainty; verification plan; operation emit or supersede; decision trace id. As built it sits beside prescription.json 1.0.0 and L5 dual-reads both; direction is the Prescription contract (section 5.3). Field list: l4/18-contract-deltas.md. |
| Live card | L5 | Mutable. Person, history and one of the 11 ClosureState values (section 5.9); records whether a person or an enabled policy acted. An open proposal can be marked superseded before acceptance; that is not a closure state. |
Closed is not the same as successful: closed_no_change and rejected are honest outcomes and feed learning. The 8-state list in older docs is retired.
17.3 Pilot 1 and the admission rule#
Pilot 1 (as-built energy-and-waste entry): a machine confirmed idle with extra loads still on. The operational task goes to the ops head; the primary outcome is energy and waste, with machine-minutes as a time effect if any. Autonomy stays off. Verification follows IPMVP retrofit isolation on the named auxiliary circuit: Option B (load and idle interval measured) may close as verified; Option A keeps estimated parameters modeled; the whole-facility meter is the wrong boundary. Detail: 16-pilot-and-hard-stops.md.
Admission rule for the next families (alarm dwell, quality correction, near-term sequence): a named owner role, a verification source already in L2, a reviewed constraint and a reusable template. Which outcome is proved first on a live plant stays open in the master document. What not to build: 17-do-not-build.md.
17.4 Repo layers: jobs, contracts and must-nots#
| Repo layer | Repos (as built) | Job | Primary contracts | Must not | Deep doc |
|---|---|---|---|---|---|
| L1 | connectors-edge, connectors-cloud, connectors-doc | Read plant and document signals into envelopes; Plant Box fast read and writer (direction) | stamped-record-envelope, measurement, event, bill_line; Envelope (section 5.10) | Write to OT outside the Plant Box writer and a WriteRequest (section 5.8) | layers/L1-connect.md, L1-L2-DATA-PLANE.md |
| L2 | universal-repositary | Store of record: readings, assets, topology, context records, lots and genealogy (direction) | envelope ingest, query API, Lot and genealogy (section 5.7) | Hand L3–L6 a database URL; become a second plant graph | layers/L2-universal-repository.md |
| L3 | intelligence-core, intelligence-rulepacks, intelligence-evals | Seven-job chain jobs 1–5, router with abstain, the one model registry (D9), twin runtime (direction) | Finding 1.2.0 as built; Evidence and PlantState (section 5.1, section 5.2) | Open L2 SQL; promote Lab output; invent rupees | l3/ |
| L4 | knowledge-reasoning | Jobs 6–7: ranked prescriptions, scheduling repair, Ask; agents through typed read-only tools | card proposal, decision trace, Prescription (section 5.3) | Assign the final person; send messages; write equipment or master data | l4/, l4/30-as-built.md |
| L5 | closure-verification | Card machine, one sender and budgets (D16), verification packs, AutonomyPolicy and the safety filter (D15), ValueRecord | ClosureState, Action, ValueRecord, AutonomyPolicy (sections 5.4–5.6, section 5.9) | Draft options; invent recommendations; override a withhold | layers/L5-closure.md |
| L6 | experience-integration | Decision queue, live picture, value register, Ask | BFF over L2, L4 and L5 HTTP (ADR-016) | Hold keys in the browser; a second sender; a summed rupee headline | layers/L6-experience.md |
Repos talk only through versioned contracts in this pack (ADR-006). Only L2 opens TimescaleDB for plant truth; L4 may hold derived operational data (situation model, traces, case libraryEpisodic store of traces joined with L5 outcomes; authority when it disagrees with Hindsight, opportunity ledgerStore of every blocked candidate with gate id and later outcome if known) but not a second plant record (ADR-021).
17.5 Anti-confusion#
| Concern | Stamped is | Stamped is not |
|---|---|---|
| Energy and waste | One outcome and a practical entry | An energy-only product, an EMS, or verified DISCOM-bill identity |
| Quality and yield | An outcome with a person-accepted correction | A QMS replacement; silent hold release |
| Uptime and throughput | The next action from plant procedures | A CMMS or lockout authorisation |
| Dynamic scheduling | A near-term sequence a person accepts | An APS, a plant OS, or a silent dispatch publish |
| MES, ERP, APS, QMS, CMMS | Context Stamped reads | Systems Stamped replaces |
| L4 | The decision layer: decide and answer from plant context | The company; silent plant control; a chat-only product |
| L3 | Analytics: methods and models feeding L4 | A frozen energy-only detector list |
| Autonomy | Earned per action class and asset in an AutonomyPolicy, plant-approved, revocable, every action recorded; default AL1 | Silent or unapproved control |
| Plant Box writer | WriteRequest only, OPC UA only, inside a signed operating envelope | A second brain that invents authority |
| Agents | Read-only tools that propose | Holders of an AutonomyPolicy |
17.6 Reading map#
| Priority | Doc | For |
|---|---|---|
| 0 | Stamped_Master_Document.md | Company identity and hard stops |
| 1 | This file | The architecture |
| 2 | DECISIONS.md | What is still to be decided |
| 3 | layers/ | One page per repo layer |
| 4 | L1-L2-DATA-PLANE.md, l3/, l4/, fast-loop/ | Depth per layer and the plant-side fast loop |
| 5 | SYSTEM_VIEWS.md | System and repo views as house diagrams |
| 6 | ../handoff/README.md, ../contracts/, ../decisions/README.md | Build handoffs, schemas, ADRs |
| 7 | ../research/stamped-tech-revamp-2026-10/ | Learning guide, appendix, cost estimate, capability map and evidence ledger behind this file |
Page history: last 5 changes
- docs(research): retire stale research to archive/research-2026-10 with a register
ab84821 - docs(technical): rewrite fast-loop/; all architecture diagrams in house style
7330f47 - docs(technical): archive archify; add SYSTEM_VIEWS.md house diagrams; check_docs --min
1e190b6 - docs(technical): carry product sections; rewrite README and pointers
ee1e818 - docs(technical): split decision board into DECISIONS.md
b4db9d4