Status
direction
Conceptual layer
⑤ Action messaging
Repo layer
L5 closure-verification, Plant Box relay
Source
architecture section 5.6 AutonomyPolicy, section 6 · ADR 036 (supersedes fatigue row of ADR-015) · D16, D7 · Index: README.

1. Four message classes#

ClassWhat it isBudget per person
AlertAnomaly or quality riskOutside budgets; alarm rules in 03
ActionA decision with a value attached6–8 a day (plant setting, default 6)
SignalShort timing cue inside an accepted standing procedureAt most 2 an hour; ends when its tag is written
DigestDaily or per-campaign summary1 a day per role, plus the end-of-shift summary

2. Delivery rules#

  • Ranked by expected value. Over budget, the top actions go out and the rest go into the end-of-shift summary. Nothing is dropped without a record.
  • Merged into one thread per episode.
  • On shift only, as L5 already checks; escalations reach the on-shift supervisor.
  • One-tap replies (Done, Can't now, Not relevant, stop reason codes); replies don't count.
  • Local language and English templates per person; allow about a week for WhatsApp template approval; templates are parameterised.
  • Freshness: signals expire after 30 s and alerts after 5 min; nothing is sent about replayed backlog.
  • No phones at the machine: signals go to a screen or stack light on the Plant BoxPlant-side computer for the fast loop (direction; D4) (D7), or wait for the write.

3. Who drafts the procedure card#

Every fast behaviour belongs to a standing procedure. Procedures are a hand-written catalog in the sector pack, with plant limits in the site packVersioned, owner-reviewed plant configuration including topology: reviewed line by line, versioned, linked to hazard rows, and run directly by the twin. L4 explains procedures, adapts wording and proposes new candidates, which the Stamped team turns into catalog entries. The runner never executes LLM output.

4. Acceptance card and the L5 change#

  1. The card (trigger, what the person is asked to do, which tag it may write later, limits, recipients) is shown on L6 and sent to the production head.
  2. A named person accepts it; L5 records the acceptance with the procedure version (AutonomyPolicy direction).
  3. The shift in-charge switches it on per shift.
  4. Any change to version, limits or recipients needs a new acceptance.
  5. Writes need their own stage gate on top (02) (AL2Autonomy levels (direction; fast-loop stages 1–3 = AL1–AL3) then AL3).

L5 adds message_class to the notification log and to suppression: alerts skip the push budget but follow alarm rules; actions use the plant's daily budget (default 6, maximum 8); signals use an hourly cap of 2; digests are one per role per day. P1 alerts keep the 5-minute delivery target; signals target under 5 s and go out from the Plant Box through the L5 relay.

5. Follow-through detection#

For each action type the twin decides from machine data whether the action happened within a window: power dropped on a hold, setpoint moved in the asked direction or the level came back into band, push interval matched the press, heater started on Ready, ageing charged in time, furnace phase changed. Where the machine shows nothing (an inspection), the reply and later register matching decide. Outcomes: taken, not taken, late, not applicable, unknown. Unknown is never counted as not taken.

6. The missed-savings ledger#

When an action is sent, the twin records the expected loss if not taken (low, median, high; in kWh, kg of material or money at the plant's own rates; basis = model_estimate). Follow-through sets the outcome, and where possible the observed consequence is recorded.

  • Labelled model estimate everywhere.
  • Shown per procedure and per shift, never per named person, never summed into one headline figure.
  • Used to find procedures that don't fit the floor, which are reviewed with the plant, not pushed harder.
  • Stored in the L2 ledger schema, next to the L4 opportunity ledgerStore of every blocked candidate with gate id and later outcome if known of ADR-025, which tracks blocked candidates rather than sent actions.

7. Message load and how writes replace signals#

The busiest role (a heater operator in forging) can get dozens of cues a shift if every one is sent. AL1 merges, ranks and caps them (at most 2 signals an hour). Each tag that reaches AL2 or AL3 turns a stream of signals into one confirmation or none. Targets per role are measured by the replay before AL1; when a role is over budget, thresholds rise or the stream waits for its write. Budgets are not raised to fit.

8. Control today#

Following master document section 7, messages do not instruct a hold, release, acceptance or rejection, an interlock, trip, lockout or sort-limit bypass, or a change to customer priority, promise dates, routing or the dispatch sequence; those stay with the plant. A near-term sequence suggestion is an action a named person accepts before anything happens. Templates are checked in CI.

Delivery from the Plant Box goes through the L5 relay, and every card or action that reaches a person counts against one L5 budget for that person (07).

Page history: last 3 changes
  1. 2026-10-07 docs(technical): rewrite fast-loop/; all architecture diagrams in house style 7330f47
  2. 2026-10-03 docs(fast-loop): interfaces and ownership; one topic registry; control-today wording; amend ADR-033 and ADR-036 df796e9
  3. 2026-10-03 docs(decisions): add ADR-033..038 (twin runtime, fast read path, plant-side writer, message classes, alerts and quality-to-lot link, part-keyed parameters), fast-loop technical set, rebuilt index with renumbering map; fix bare-number link text and ranges 22e2872

Diagram

100%

Search the architecture