Stamped technical decisions
What is still to be decided. The architecture follows each recommendation until Vinayak decides, and every entry says how to reverse it.
| ID | Topic | Status | Position in one line |
|---|---|---|---|
| D1 | Plant context store | RECOMMENDED | Relational plus event tables in L2, link method and confidence on every edge |
| D2 | Contracts | RECOMMENDED | Draft all ten in SE now as 0.x, experimental, bump on first plant use |
| D3 | Twin runtime | RECOMMENDED | Python on the Plant Box behind a heartbeat gate; compiled core only if the gate fails |
| D4 | Plant Box | RECOMMENDED | Fanless industrial PC on Linux; customer VM as fallback |
| D5 | Value method | RECOMMENDED | Switchback where actions alternate, adjusted baseline otherwise, power analysis first |
| D6 | MSPC and soft sensors | RECOMMENDED | L3, KR analytics moved alongside |
| D7 | Fast-loop channel | RECOMMENDED | WhatsApp plus a local Plant Box display |
| D8 | Time-series foundation models | RECOMMENDED | Shadow-only until a held-out win |
| D9 | Model registry | RECOMMENDED | L3 registry is the single owner; EV becomes a library |
| D10 | Writer protocol | RECOMMENDED | OPC UA write only |
| D11 | TabPFN pin | RECOMMENDED | Pin to a release whose default weights are v2 |
| D12 | Client numbers | RECOMMENDED | Script-and-commit rule |
| D13 | Evidence labels | DECIDED | Evidence and PlantState, cascading |
| D14 | Calibration thresholds | DECIDED | Per model class |
| D15 | Safety filter owner | RECOMMENDED | One filter in the L5 autonomy package, run as edge and cloud copies |
| D16 | Message budgets | RECOMMENDED | Extend L5 |
| D17 | NE 178 depth | RECOMMENDED | Pattern-level Verification of Request |
| D18 | Probabilistic stack | DEFERRED | Choose with the first C15 template |
| D19 | MHE solver | DECIDED | Offline benchmark first |
| D20 | L2 hosting | RECOMMENDED | Self-managed Postgres + Timescale on EC2 until 10 plants, then Tiger Cloud |
| D21 | LLM provider and data residency | RECOMMENDED | One gateway, low-cost default model, no plant data to a provider the customer has not approved |
The decision board for the technical architecture. Moved out of architecture section 9 on 7 October 2026 so the architecture states what is built and planned, and this file holds what is still to be decided. Internal. Nothing here claims a result at a plant; verified savings are ₹0. The master document hard stops bind every option below.
Waiting on Vinayak#
Each of these is RECOMMENDED — awaiting Vinayak. The architecture follows the recommendation until Vinayak decides; every entry below says how to reverse it.
- D1 — Plant context store. Relational plus event tables in L2, link method and confidence on every edge.
- D2 — Contracts. Draft all ten in SE now as 0.x, experimental, bump on first plant use.
- D3 — Twin runtime. Python on the Plant Box behind a heartbeat gate; compiled core only if the gate fails.
- D4 — Plant Box. Fanless industrial PC on Linux; customer VM as fallback.
- D5 — Value method. Switchback where actions alternate, adjusted baseline otherwise, power analysis first.
- D6 — MSPC and soft sensors. L3, KR analytics moved alongside.
- D7 — Fast-loop channel. WhatsApp plus a local Plant Box display.
- D8 — Time-series foundation models. Shadow-only until a held-out win.
- D9 — Model registry. L3 registry is the single owner; EV becomes a library.
- D10 — Writer protocol. OPC UA write only.
- D11 — TabPFN pin. Pin to a release whose default weights are v2.
- D12 — Client numbers. Script-and-commit rule.
- D15 — Safety filter owner. One filter in the L5 autonomy package, run as edge and cloud copies.
- D16 — Message budgets. Extend L5.
- D17 — NE 178 depth. Pattern-level Verification of Request.
- D20 — L2 hosting. Self-managed Postgres + Timescale on EC2 until 10 plants, then Tiger Cloud.
- D21 — LLM provider and data residency. One gateway, low-cost default model, no plant data to a provider the customer has not approved.
Deferred: D18 (probabilistic stack): choose PyMC, NumPyro or Stan with the first C15 template.
Decided by Vinayak (7 Oct 2026): D13 (Evidence labels), D14 (Calibration thresholds), D19 (MHE solver). The architecture states these as facts.
How to read an entry#
Each decision has a status, the recommendation, the options and trade-offs considered, the evidence, how to reverse it, and what it blocks. D13, D14 and D19 are DECIDED by Vinayak (7 Oct 2026) and D18 is DEFERRED; every other entry is RECOMMENDED and waits for Vinayak. D1–D5 block the most downstream work; D3, D4, D10, D15 and D17 sit on the closed-loop critical path. D20 and D21 were added while finalising: D20 because Amazon RDS does not offer the TimescaleDB extension L2 needs, D21 because data residency decides which LLM a customer will accept.
Section marks (section ) in the entries refer to the architecture. C-numbers are capabilities and E- and I-numbers are evidence, defined in the capability map and the evidence ledger.
The decision board lives in DECISIONS.md: every open choice with its status, recommendation, evidence, how to reverse it and what it blocks. D13, D14 and D19 are DECIDED and stated as facts in this document (section 3.3b, section 5.2); D18 is DEFERRED; every other decision (D1–D12, D15–D17, D20, D21) is RECOMMENDED — awaiting Vinayak, and this document follows the recommendation until he decides. A (Dn) mark anywhere here links to that entry.