Scope cut
Every component is cut three ways. Build now is what the first three plants need: one ingest path, one store, one registry, one sender, ten 0.x contracts, the slow loop at AL1 and the fast loop in shadow. Later names the trigger that justifies each piece of work, such as AL2 going live once the ledger shows same-condition wins, or MPC once an identified model passes calibration. Not planned records decisions not to build, including AL4 and AL5, a second plant store and bill-verified savings as a product claim. Plant 1 gets the slow loop first.
Every component in section 2.2 and every choice in the layer model, cut three ways. Build now is what the first three plants need for the target state in section 1.2. Later names the trigger that justifies the work. Not planned is a decision not to build, revisited only through DECISIONS.md. Inside Build now, plant 1 gets the slow loop first; fast-loop items run in shadow and never hold up plant 1's slow-loop cards.
Table: 29 rows by component
| Component | Build now (first 3 plants) | Later (trigger) | Not planned |
|---|---|---|---|
EDGE edge-agent | Slow polling, buffer, drift watcher; sub-second sampling for the fast-loop tags | Native S7 and EtherNet/IP drivers (first plant that needs them) | Python stamped-l1 as a second agent (retire) |
EDGE tag-mapping-api/ui | Units and ranges as fields | — | — |
EDGE plant-sim | One utilities archetype for fast-loop tests | More archetypes (each new archetype sold) | — |
| EDGE site adapter | — | — | Product use (stays out of the product path) |
| CLOUD ingest | One ingest path (HTTPS batches) with sequence numbers, dedupe, replay | — | Second ingest router in L2 (merge) |
| Edge–cloud sync | Outbound-only; per-source sequence numbers and idempotent batches; plant-bound changes (policy grants, parameters, model versions) are pulled by the Plant Box and signed; every reading keeps source and receive timestamps; Plant Box clock disciplined by NTP, skew over 2 s flags readings and blocks writes | PTP time where a plant already runs it | Cloud push into the plant |
| L2 TimescaleDB | Lots, parts, genealogy, events, twin_state, write_log tables; ValueRecord enum | Tiger Cloud HA (D20 trigger) | Second plant store |
L3 engines/ | Re-keyed findings, MSPC, soft sensors | State estimation in the cloud beyond the twin (per C14 benchmark) | — |
L3 challenger/ | TabPFN pin; LightGBM baseline | Real TimesFM and Chronos nightly runs (second plant of one archetype); promotion (held-out win, D8) | — |
L3 agentic/ | Keep existing split conformal and BOCPD code; add coverage tracking | Adaptive conformal (after coverage tracking runs a month) | In-memory graph (fold into D1 views) |
| L3 registry, gates, certification | Single registry (D9), coverage gate | Per-plant champion (second plant of one archetype) | — |
| RP rulepacks | Keep | — | — |
| EV evals | Library writing into L3 registry | — | Separate promotion path |
KR runtime/ | Lot and part keys; reads AutonomyPolicy | — | — |
KR flowline/ | Repair role named | Whole-plant model (customer with ERP link) | LLM-to-constraint without human confirm |
KR analytics/ | Move to L3 (D6) | — | — |
KR plant_context/ and graph modules | Views over L2 | AGE path queries (D1 trigger) | Separate graph store |
KR ask/ | Evidence-ID citations enforced; LLM gateway (D21) | — | — |
| KR CI | Add CI first | — | — |
| L5 cards and closure | ClosureState contract, override capture, single sender, budgets (D16) | HMI tile channel (cheap vendor integration) | — |
| L5 verification packs | Multi-KPI ValueRecord, switchback and adjusted baseline (D5) | Synthetic control, DiD (enough untreated lines) | Bill-verified savings as a product claim |
L5 autonomy/gate.py | AutonomyPolicy with operating envelope, safety filter (D15) at AL0–AL1; AL2 in shadow | AL2 live, AL3 (ledger shows same-condition wins) | AL4, AL5 |
| L6 UI | Live data path, one renderer per channel | — | Second WhatsApp sender |
| SE contracts | Ten contracts as 0.x (D2) | 1.0.0 per contract (first production use) | — |
| Client analysis repos | Test oracles | — | Product code |
| Layer model: control ladder | Rule → advice → BO/EVOP | MPC (identified model passes C44) | Shielded RL in the next 12 months |
| Context options | A plus C | E (AGE) | B, D, F as stores |
| Security and tenancy | RLS per tenant (migration 006), secrets in a cloud secret store, Plant Box OT/IT zone split with outbound-only conduit (E26), OPC UA certificates per plant (D10), agent tools read-only and tenant-scoped, LLM provider allow-list (D21) | SSO for customer users (first customer that asks) | Inbound connections to the Plant Box |
| Cost model | stamped_running_cost.py plus STAMPED_RUNNING_COST_ESTIMATE.md (section 16) | Reserved-instance or savings-plan pricing (after 6 months of stable usage) | — |
Page history: last 5 changes
- docs(research): retire stale research to archive/research-2026-10 with a register
ab84821 - docs(technical): rewrite fast-loop/; all architecture diagrams in house style
7330f47 - docs(technical): archive archify; add SYSTEM_VIEWS.md house diagrams; check_docs --min
1e190b6 - docs(technical): carry product sections; rewrite README and pointers
ee1e818 - docs(technical): split decision board into DECISIONS.md
b4db9d4