In short

The decision layer lives in knowledge-reasoning. Its DecisionRuntime takes evidence into a plant work queue, builds a decision case against the Plant Situation Model, and produces at most one owned Prescription draft per condition. As built, that draft is the card proposal, and L4 can also withhold or abstain, always with a trace. L4 runs scheduling repair and Ask, where agents use typed read-only tools. It never assigns the final person, sends messages or writes equipment or master data. Thirty-one deep docs cover the runtime, from the kernel to the as-built map.

Status
contract + as-built (runtime) + direction
Conceptual layer
④ Decision
Repo layer
L4 knowledge-reasoning
Source
architecture section 1, section 3.6.4, section 5.3, section 8
As-built map
30-as-built.md
Normative kernel
00-kernel.md
Product
Stamped_Master_Document.md · ADR-018 amended

L4 turns plant conditions into at most one owned PrescriptionWhat to do, why, who, check plan (direction; as built: prescription.json 1.0.0 / card-proposal) draft (as built: card proposal) — or withholds / abstains with a full trace. Humans decide and execute. L5 owns the live card (ClosureStateEleven code states on the live card (direction; as built: stamped_l5_domain/cards/states.py)). L3 owns detection methods and money calculation. L2 owns plant source-of-truth records. L4 owns DecisionRuntime, the derived Plant Situation Model, and the opportunity ledgerStore of every blocked candidate with gate id and later outcome if known.

The live compile path is DecisionRuntime (stamped_l4.runtime + worker/decision_runner.py). Legacy LangGraph prescription-compiler graphs may remain in the consumer tree; they are not the EvidenceLayer contract for detector output (direction; as built: Finding finding.json 1.2.0) → card compile path. See 30-as-built.md.

L4 README runtime

DecisionRuntime

emit / supersede

withhold / abstain / hold

Intake

L3 Evidence
(as built: Finding)

Discovery / shift sweep

Plant work queue

DecisionCase + PSM

Stage graph + portfolio

Kernel re-check

CardSink → L5 Prescription

↩ DecisionTrace + opportunity ledger

How to read it.

  1. Evidence or discovery enters the per-plant queue and becomes a DecisionCase with a frozen PSM snapshot.
  2. The registry stage graph runs constraints and portfolio before the kernel re-check.
  3. Only emit / supersede call CardSink; everything else is traced and soft blocks feed the opportunity ledger.

Build now: shadow DecisionRuntime + Ask read path. Later: full Prescription contract fields and Plant Box fast-loop coupling (../fast-loop/).

View Mermaid source
flowchart TB
    %% house-style: l4-readme-runtime
    subgraph in["Intake"]
        direction LR
        ev["L3 Evidence<br/>(as built: Finding)"]
        disc["Discovery / shift sweep"]
    end
    subgraph rt["DecisionRuntime"]
        direction LR
        q["Plant work queue"]
        dc["DecisionCase + PSM"]
        st["Stage graph + portfolio"]
    end
    gate{{"Kernel re-check"}}
    l5["CardSink → L5 Prescription"]
    tr(["↩ DecisionTrace + opportunity ledger"])
    in --> q --> dc --> st --> gate
    gate -->|"emit / supersede"| l5
    gate -->|"withhold / abstain / hold"| tr

    classDef govc fill:#fff4d6,stroke:#c99a2e,color:#000
    classDef agentc fill:#e8f0ff,stroke:#5b7bd5,color:#000
    classDef loopc fill:#eef7ee,stroke:#4f9a4f,color:#000
    class gate govc
    class tr loopc

Eight ideas this set leads with#

  1. A small kernel of rules; everything else is replaceable. Code owns terminals, hard stops, money references, constraint checks, and the one-card rule. Models, prompts, and registries live inside and swap by release (D9).
  2. See the whole plant, decide about one thing. The Plant Situation Model holds structure, history, and state. Each run gets a focused, provenance-tagged slice.
  3. Constraints are code, not prose. Typed predicates return satisfied, violated, or unknown. A model may explain; it never evaluates a gate.
  4. Evidence before words. Every claim cites a ledger row. Uncited claims are dropped. Models never assign an evidence tierContract tier on claims: measured / confirmed / modeled / unknown; quantity labels per D13 or a rupee (D13).
  5. Two ways in, one way out. Evidence (FindingAs-built L3 detector output admitted to L4 (finding.json 1.2.0)) and discoveries meet the same floor, the same constraint check, and the same portfolio.
  6. The plant is a portfolio. Cards carry footprints; overlapping footprints conflict; owners have a per-shift budget (exceptions exempt via registry).
  7. Built to change, including at the core. Domains, families, workflows, stages, analyses, patterns, constraint kinds, tools, prompts, memory missions, and model pins are versioned registry entries under one release lockfile. The kernel never names a specific domain.
  8. Nothing is silently lost, and every block teaches. Soft-gate blocks reach the opportunity ledger and the owner's backlog. Exploration measures whether blocked items would have helped. Soft gates then move on evidence.

Reading order#

Table: 32 rows by order
OrderDocRole
000-kernel.mdNormative frozen surface
101-system-overview.mdEnd-to-end picture + Mermaid
202-plant-structure.mdSite-pack topology
303-plant-situation-model.mdPSM
404-constraints.mdTyped constraints
505-context-engineering.mdLedgers and zoom
606-memory.mdHindsight, case library
707-finding-runtime.mdFinding → terminal
808-discovery.mdScanners, patterns, hypothesis lane
909-portfolio.mdDedupe, conflict, attention
1010-domain-analyses.mdDomain plug-ins
1111-models-and-seams.mdDual family, Jev seams
1212-trace-and-eval.mdTrace and pass^k
1313-improvement.mdOffline council
1414-ask.mdAsk over L4
1515-l3-l4-interface.mdContract with L3
1616-operations.mdDeploy and monitor
1717-change-guide.mdHow to expand
1818-contract-deltas.mdCross-layer deltas
1919-failure-modes.mdNamed failure modes
2020-benchmark.mdHow we know it works
2121-registries-and-stage-graph.mdRegistries
2222-missed-opportunities.mdOpportunity ledger
2323-oe-knowledge-corpus.mdOE literature RAG (advisory)
2424-architecture-gaps.mdGap audit (historical + pointers)
2525-work-queue-and-concurrency.mdPlant work queue
2626-decision-case-lifecycle.mdCase states, leases, resume
2727-ports-and-reliability.mdTimeouts, retries, breakers, idempotency
2828-commissioning-and-controls.mdSafe-start, kill switch
2929-software-quality-and-release.mdTests, CI, SLOs, durability
3030-as-built.mdShipped package map + compile path
—glossary.mdTerms

Fast loop (direction): plant-side twin, writer and message budgets live outside L4; L4's touch points are 15 section 13 and 22 (missed-savings vs opportunity ledger). Design: ../fast-loop/.

ADRs#

ADRTitle
020Decision runtime
021PSM and memory
022Discovery
023Dual-family models
024Site-pack topology
025Soft gates / opportunity ledger
027Production hardness

Research#

  • Peers and literature: ../../research/plant-efficiency-exploration-2026-09/19-l4-agent-peer-systems.md
  • Vision wins on conflict: ../../research/plant-efficiency-exploration-2026-09/09-stamped-founder-vision.md

What this is not#

Not code. Not a schedule optimizer. Not equipment write. Not a second plant UI. Not a graph product in L2.


v1 slice vs later#

v1 (docs + as-built runtime)Later
Architecture docs 00–29 + as-built Finding runtime / PSM / seams / ledger / queue / controls (30-as-built.md)Harden SQL-backed case/trace loop; expand discovery certification
Four outcomes (master document); registry ids may expandAdditional outcomes / families by registration
Cross-plant memory / priorsNot in v1 (designed seam only)
OE corpus Tier A public ingestBroader Tier B/C under license / owner packs

Deep docs in L4

  1. 00L4 kernel (normative)Frozen surface — changes only through an ADR, a kernel version bump, and a full replay.5 min
  2. 01L4 system overviewHumans decide and execute. L5 owns the live card after emit.as-builtcontractdirection5 min
  3. 02Plant structure and commissioningCross-asset checks need more than a list of assets.contractdirection8 min
  4. 03Plant Situation Model (PSM)A DecisionCase needs more than the Evidence (Finding) local window.contractdirection4 min
  5. 04Constraints and resources“Code withholds on a known constraint conflict” is only true if code can evaluate the constraint.contract2 min
  6. 05L4 context engineering — ledger, partitions, zoomModels judge options. They do not invent plant facts, money, or evidence tiers.contract8 min
  7. 06MemoryMemory improves the next card without poisoning thresholds, inventing outcomes, or letting Ask chat rewrite plant truth.as-builtcontract3 min
  8. 07Finding runtimeThis doc is the Evidence (as built: Finding finding.json 1.2.0) path from L3 intake to a terminal.as-builtcontractdirection7 min
  9. 08DiscoveryL3 detectors catch registered conditions.as-builtdirection7 min
  10. 09PortfolioThe plant is not one card at a time in isolation.as-builtcontract5 min
  11. 10Domain analysesProduct framing today is five domains (ADR-018).as-builtcontract7 min
  12. 1111. Models and seamsL4 puts models inside named seams. Code owns the stage graph, money references, constraint evaluation, and terminals.contractdirection7 min
  13. 1212. Trace and evaluationEvery L4 run leaves a DecisionTrace. Replay, eval, and improvement all read the same ledger.contract5 min
  14. 1313. Improvement loopL4 gets better from what it sent and from what it held back.contractdirection7 min
  15. 1414. AskAsk is a view over L4, not a second product.as-builtcontractdirection5 min
  16. 1515. L3-L4 interfaceL3 owns methods (detect, price, test, simulate, build verification plans).as-builtcontract7 min
  17. 16OperationsL4 on a live plant is a pinned release, a dual-family model slot, and a short list of rates somebody watches.as-builtcontract7 min
  18. 17Change guideL4 is built to change at the edges and, when needed, at the core — without rewriting the kernel every time.contract7 min
  19. 18Contract deltas (cross-layer)Documentation and schema intents for L4 to run against L1–L6.as-builtcontractdirection5 min
  20. 19Failure modesNamed ways L4 goes wrong on a plant — each with a detection signal and a mitigation that points at the kernel or a sibling doc.contract6 min
  21. 20BenchmarkL4 works when held-out DecisionCases, gates, and human closures say so — not when a vendor claims a model is “best for manufacturing.” Numbers that are not measured on a named suite or plant are illustrative or omitted.contract4 min
  22. 21Registries and stage graphThe kernel stays small. Domains, workflows, soft thresholds, and model pins change weekly in v1.contractdirection4 min
  23. 22Missed opportunities and gate calibrationStrict gates protect the floor. The same strictness can hide real waste.contract7 min
  24. 23OE knowledge corpus (advisory retrieval)Plant memory answers what worked here. Detectors answer what is happening now.contractdirection3 min
  25. 24L4 architecture gap audit — agentic stack + industrial hardnessNothing in this table loosens hard stops or claims verified savings; verified savings are ₹0.3 min
  26. 25Work queue and concurrencyL3 Evidence (as built: Findings), PSM events, shift sweeps, Ask sweeps, and backlog promotes arrive together.contract3 min
  27. 26DecisionCase lifecycleA DecisionCase is a durable unit of work, not a single request.contract4 min
  28. 27Ports and reliabilityL4 is a composition of ports. Production readiness is mostly how those ports fail.contract3 min
  29. 28Commissioning, safe-start, and plant controlsA correct DecisionCase design can still harm a plant if emit is enabled before topology, constraints, and methods are honest.contract3 min
  30. 29Software quality and release gatesDecision integrity (kernel) is necessary but not sufficient.contract2 min
  31. 30L4 — As-built decision runtimeMaps what is implemented today under src/stamped_l4/runtime/.as-built3 min

Terms used across these docs are in the glossary.

Page history: last 5 changes
  1. 2026-10-07 docs(technical): rewrite l4 21-30, glossary and README; reconcile architecture gaps e7fead7
  2. 2026-10-03 docs(handoff,l4): fast-loop architecture handoff, L4 procedure and ledger links, indexes 0f45a47
  3. 2026-10-03 docs(decisions): add ADR-033..038 (twin runtime, fast read path, plant-side writer, message classes, alerts and quality-to-lot link, part-keyed parameters), fast-loop technical set, rebuilt index with renumbering map; fix bare-number link text and ranges 22e2872
  4. 2026-10-03 docs(decisions): renumber live ADRs 001-032 in order, mark withdrawn refs ADR-W###, repoint withdrawn links to archive, note partial supersessions 36c944e
  5. 2026-09-27 docs(architecture): align identity with the four-outcome master document 1663dd2

Diagram

100%

Search the architecture