Decision D15 · 15 of 21
Predictive safety filter ownership
One filter in the L5 autonomy package, run as edge and cloud copies
RECOMMENDED
- Status
- RECOMMENDED — awaiting Vinayak
- Options
- L3 engine; L5 gate extension; plant-box runtime service; duplicated cloud+edge with same contract
- Trade-offs
- Single owner vs latency
- Recommendation
- One filter implementation, reading the operating envelope inside AutonomyPolicy, owned by the L5 autonomy package. The Plant Box runs the edge copy for writes; the cloud runs the same code for advisory messages. The filter never lives in L3 or KR, which propose.
- Why
- The filter must sit outside every proposer. L5 already owns the autonomy gate, so policy and filter share one owner and one test suite.
- Evidence
- C46; E05 (external staged-verification pattern, not a Stamped outcome); L5
autonomy/gate.py. - Reversible
- Yes. The contract hides the owner.
- Blocks
- Any experiment or write; AL1 messages that imply action.
Page history: last 2 changes
- docs(research): retire stale research to archive/research-2026-10 with a register
ab84821 - docs(technical): split decision board into DECISIONS.md
b4db9d4