L3 — Intelligence core (detection)
L3 turns L2 telemetry into findings for L4. As built that is Finding 1.2.0; the direction is the Evidence contract. Engines run on a schedule, and only findings with status emitted and delivery l4 leave L3; lab output never promotes itself. L3 runs jobs 1 to 5 of the seven-job chain with a method router that may abstain, and it owns the one model registry. Money cites a tariff or a tagged fallback. The plant-side twin runtime on the Plant Box is direction.
- Status
- as-built (runtime, engines, contract emit) · direction (twin, packs, twin-record engines)
- Conceptual layer
- ③ Analytics (seven-job chain jobs 1–5)
- Repo layer
- L3
intelligence-core,intelligence-rulepacks,intelligence-evals - Source
- architecture section 3.3b, section 3.6.3, section 5.2, section 2.2 L3 cards · ADRs 010, 012 · direction: 033, 038
L3 turns L2 telemetry into contract EvidenceLayer contract for detector output (direction; as built: Finding finding.json 1.2.0) (direction; as built: FindingAs-built L3 detector output admitted to L4 (finding.json 1.2.0) 1.2.0) objects. Only dual-lane status=emitted ∧ delivery=l4 leave for L4. Lab never promotes. Money cites tariff or tagged fallback. No L2_DATABASE_URL. Model governance lives in the governance plane: one registry in L3 (D9, RECOMMENDED).
| Label | Meaning |
|---|---|
| as-built | intelligence-core · intelligence-rulepacks · intelligence-evals |
| contract | Finding 1.2.0 · RunArtifact 1.1.0 (direction contract: finding-2.0.0.json) |
| direction | Seven-job chain jobs 1–5 (section 3.3b); plant-side twin stamped-l3-twin on the Plant Box (D3, ADR-033; 05) |
How to read it.
- Scheduled L3 reads L2 only over HTTP or fixtures; engines emit Finding 1.2.0 through the outbox when dual-lane rules pass.
- Everything else stays in Lab; there is no promote-Lab-to-L4 path.
- The L3 registry is the single promotion owner; EV evals feed scorecards into it (D9).
- The twin writes state and records to L2; scheduled engines may read those records and emit Findings — the twin never holds an outbox.
Build now: slow-loop detection and dual-lane. Later: Evidence 2.0.0, PlantState from the twin (section 5.1).
View Mermaid source
flowchart TB
%% house-style: l3-folder-overview
l2["② L2 HTTP / fixtures"]
subgraph sched["Scheduled L3 as-built"]
direction LR
eng["Engines + PathScheduler"]
lane{{"Dual-lane: emitted ∧ delivery=l4"}}
out["TransactionalOutbox"]
end
lab["LabLog / RunArtifact 1.1.0"]
l4["④ L4 inbox"]
subgraph gov["Governance plane"]
direction LR
reg{{"L3 registry, gates, certification (D9)"}}
end
subgraph twin["Twin direction on Plant Box"]
direction LR
tr["stamped-l3-twin"]
rec["Records → L2"]
end
l2 --> eng --> lane
lane --> out --> l4
lane -.-> lab
reg -.-> eng
tr --> rec --> l2
classDef govc fill:#fff4d6,stroke:#c99a2e,color:#000
classDef agentc fill:#e8f0ff,stroke:#5b7bd5,color:#000
classDef loopc fill:#eef7ee,stroke:#4f9a4f,color:#000
class lane,reg govc
Repos#
| Repo | Job |
|---|---|
intelligence-core | Runtime: scheduler, engines, outbox, Lab HTTP, registry/ · direction: second deployable stamped-l3-twin (stamped_l3_core/twin/) on the Plant Box |
intelligence-rulepacks | YAML thresholds, tariffs, vertical priors (RULEPACK_PATH) |
intelligence-evals | Offline eval CLI + Lab UI; library under D9 |
Reading order#
| Order | Doc | Role |
|---|---|---|
| 1 | 01-runtime.md | Pipeline, dual-lane, schedules, money |
| 2 | 02-engines.md | Engine catalog and enable flags |
| 3 | 03-rulepacks-and-evals.md | Rulepacks vs math; offline evals |
| 4 | 04-finding-contract.md | Finding 1.2.0 → L4 intake |
| 5 | 05-twin-and-fast-loop.md | Twin runtime, twin-record engines, packs, replay (direction) |
Hard rules#
| Rule | Owner |
|---|---|
| No L2 SQL | Core clients are HTTP / fixtures only |
| Lab never promotes | Dual-lane invariant |
| Never invent ₹ | Tariff resolve + outbox forged-INR guard |
| Shipping a module ≠ shipping a Finding | Many engines need ENABLE_* or PROOF_RUN=1 |
| Twin never holds an outbox (direction) | Card path = scheduled engine → Finding → outbox (ADR-033) |
| Procedure runner never executes LLM output (direction) | Runner executes accepted, versioned procedure YAML only |
L4 intake contract detail: ../l4/15-l3-l4-interface.md.
Deep docs in L3
- L3 — Detection runtimePathScheduler ensures cold never blocks hot.
- L3 — Engine catalogShipping a module ≠ shipping a Finding. Many detectors stay dark until an enable flag or PROOF_RUN=1 plus required tags on L2.
- L3 — Rulepacks and evalsFilesystem catalog of versioned YAML rulepacks, vertical priors, and DISCOM HT tables.
- L3 — Finding contract and L4 intakeContract: contracts/schemas/intelligence/finding.json · const 1.2.0Forward schema (direction): finding-2.0.0.json — not what core emits today
- L3 — Twin runtime and the fast loopL3 view of the fast loop: what L3 adds, what stays in scheduled L3, and where the boundary sits.
Page history: last 4 changes
- docs(technical): rewrite l3/ to the architecture
4a28bbd - docs(l3): twin runtime, twin-record engines, packs and replay as direction
28255e9 - docs(decisions): renumber live ADRs 001-032 in order, mark withdrawn refs ADR-W###, repoint withdrawn links to archive, note partial supersessions
36c944e - docs(l3): document detection runtime and engines
0a02a37