Status
direction
Conceptual layer
③ learning and governance
Repo layer
L3 tuning job, L5 staff console
Source
architecture section 3.6.8 · ADR 038 · promotion ADR-011 · D9 · Index: README.

1. One twin, parameters per context#

Context key: line; part (raw SCADA part name through a part-alias table); alloy; billet supplier or lot; die; heat-treatment recipe. Missing fields fall back through inheritance: part → part family → alloy → default prior, each with its uncertainty.

GroupExamplesTuned by Stamped?
HeaterCoil efficiency, heat loss, billet mass and heat capacity, pyrometer offset, lagYes
Flow and pressNormal transfer time, cooling in transfer, force median and spread, first-parts countYes
Part-risk thresholdsCold-edge band, slow transfer, force deviation, run sizeYes, always reviewed by the Stamped team
Heat treatmentLoad response, quench heat-transfer curve, tank cooling, ageing constantsYes, with strength results
Plant limitsTemperature windows, sort limits, written heat-treatment limitsNo. The plant's own values

Rows are versioned in L2 (baselines.param_row) with source, date, data volume and confidence, signed and cached on the Plant BoxPlant-side computer for the fast loop (direction; D4), loaded at every part change, and stamped on every record.

2. Context lifecycle#

Param context lifecycle

Context states

Learning

Candidate

Approved

Known

Revalidate

Retired

Confidence gate and replay

Probation passed

How to read it.

  1. Unknown part or context enters Learning; Candidate waits for Stamped approval while the switch is on.
  2. Known rows re-validate on plant change or drift; Retired parts skip alerts until they return.
  3. Writes stay off in Learning and Revalidate until refit passes.

Build now: Learning and Known with manual promotion. Later: auto-promote when require_internal_approval_new_part is off.

View Mermaid source
flowchart TB
    %% house-style: param-context-lifecycle
    subgraph states["Context states"]
        direction LR
        learn["Learning"] --> cand["Candidate"]
        cand --> appr["Approved"]
        cand --> learn
        appr --> known["Known"]
        known --> rev["Revalidate"]
        appr --> rev
        rev --> known
        rev --> learn
        known --> ret["Retired"]
        ret --> rev
    end
    gate{{"Confidence gate and replay"}}
    learn --> gate --> cand
    appr --> gate2{{"Probation passed"}} --> known

    classDef govc fill:#fff4d6,stroke:#c99a2e,color:#000
    classDef agentc fill:#e8f0ff,stroke:#5b7bd5,color:#000
    classDef loopc fill:#eef7ee,stroke:#4f9a4f,color:#000
    class gate,gate2 govc
StateAlertsActions and signalsWrites
LearningPart-independent onlyLine-level stop and start signals onlyNone
CandidatePart-independent; part-specific in shadowPart-specific in shadow, for the approval reviewNone
Approved (probation)AllAll, within stage gatesConfirmed writes only
KnownAllAllAs the tag's stage allows
Re-validatePart-independent; part-specific marked lower confidenceFrom the last approved row, marked lower confidenceNone until refit passes
Retired———

3. New-part flow#

  1. Detect an unknown part name or a part without a row; enter Learning.
  2. Show it on the L5 staff console and message the Stamped admin.
  3. Learn online from the family or alloy prior with wide uncertainty; moving-horizon fit over the first runs.
  4. Confidence gate (starting values, confirmed by replay): minimum pushes over several runs; 90% interval coverage of 85–95% on a held-out run; error no worse than the family prior (D14 DECIDED).
  5. Propose the candidate row with its evidence and shadow recommendations.
  6. While require_internal_approval_new_part = true (default), a named Stamped team member approves; the approval is a promotion record.
  7. Promote; recommendations start under probation.

Turning the switch off is a recorded decision; candidates passing the gate and replay then promote automatically, still with a record and probation.

4. Continuous tuning#

  • Nightly refit for every context that ran recently.
  • Replay tests in intelligence-evals on recent and long history: not worse on error, coverage within band, no role pushed over its message budget.
  • Bounded change per parameter: inside bounds and passing replay promotes automatically; outside goes to the Stamped team.
  • Always reviewed: part-risk thresholds and any row for an AL3Autonomy levels (direction; fast-loop stages 1–3 = AL1–AL3) tag.
  • Every change is a promotion record with one-step rollback.
  • Weekly drift report per context.

Model code goes through normal CI with reference tests; parameter rows go through this pipeline. Neither bypasses the other.

5. Feedback that tunes#

Follow-through outcomes (procedure fit, ranking), register-matched rejects (part-risk thresholds), strength results (quench and ageing calibration), operator replies (procedure fit, stop reasons), contact-probe checks (pyrometer offset).

6. Plant change catalog#

ChangeDetected byResponse
New partName not in alias table or no rowLearning; console notice and admin message
Alloy, supplier or lot changeJob card if digital; heating response shiftRe-validate affected parts; ask the plant to confirm
Die changeJob card; force level stepWiden first-parts flag; re-learn force; no press writes until settled
Heater maintenance or coil changeMaintenance record, long stop, efficiency stepRe-validate heater; setpoint writes off until refit passes
Pyrometer replaced or recalibratedStep at constant powerReset offset; Re-validate; ask for a contact-probe check
Heater controller retuneChanged step responseRe-validate; writer re-checks limits on site
Recipe or written limits changedRecipe tag or new limit entered by the plantUpdate plant-owned limits; Re-validate heat-treatment rows
SCADA tags renamed or addedTag mapping validationReadings missing; state uncertain; admin maps tags; writes off for those tags
PLC program changedChecksum or tag map changeWriter off; repeat site checks
Seasonal ambient or mains driftSlow parameter driftNightly refit within bounds
New crew or shift patternRoster changeWatch follow-through and load per shift; re-accept procedures if the in-charge changes
Holidays and maintenance daysPlant calendar; no countersTwin idle; excluded from refits and baselines
Mixed parts in one basketJob card or several parts in the windowRecord lists all parts; predictions use the most at-risk part
Partial data daysCompleteness checksExcluded from refits and acceptance measures; never counted as missed actions

7. Admin controls on the L5 staff console#

Pages for new parts (map aliases, assign families), candidates (approve or reject while the switch is on), drift (start a refit), settings (the switch and the bounds, changed with a reason) and history (promotion records, rollback). Every action records the person and the reason.

Page history: last 2 changes
  1. 2026-10-07 docs(technical): rewrite fast-loop/; all architecture diagrams in house style 7330f47
  2. 2026-10-03 docs(decisions): add ADR-033..038 (twin runtime, fast read path, plant-side writer, message classes, alerts and quality-to-lot link, part-keyed parameters), fast-loop technical set, rebuilt index with renumbering map; fix bare-number link text and ranges 22e2872

Diagram

100%

Search the architecture