Status
contract + as-built (runtime) + direction (jobs 6–7, Prescription)
Conceptual layer
④ Decision
Repo layer
L4 knowledge-reasoning
Source
architecture section 3.3b, section 3.6.4, section 5.3, section 8
Normative rules
00-kernel.md
ADRs
020 · 021 · 022

What L4 does#

  1. Accepts EvidenceLayer contract for detector output (direction; as built: Finding finding.json 1.2.0) from L3 (as built: FindingAs-built L3 detector output admitted to L4 (finding.json 1.2.0) finding.json 1.2.0), or a discovery candidate from L4 scanners / patterns / (opt-in) hypothesis lane — including on a shift sweepOnce-per-shift whole-plant discovery pass when nothing anomalous fired.
  2. Builds a DecisionCaseOne run unit: intake + snapshot + obligations + candidates + terminal with a condition keyStable id for “this plant condition”; one open card per key and a frozen PSMPlant Situation Model snapshot (as-known-at).
  3. Runs a code-owned stage graph: candidates → constraints → portfolio → card minimizer → kernel re-check → terminal.
  4. Ends in emit | supersede | withhold | abstain, always with a DecisionTraceAlways-on record: observed, context, action, policy, approval, outcome (and seam decisions).
  5. Records every gate block in the opportunity ledgerStore of every blocked candidate with gate id and later outcome if known so refusals teach the system.

Humans decide and execute. L5 owns the live card after emit. L4 never writes equipment or schedules.

Whole-plant claim: The L3 Evidence (Finding) path is reactive. Discovery + shift sweep are how L4 still looks across the plant on a quiet shift — same kernel, same portfolio, same owner card. Cadence: 08-discovery.md.


End-to-end picture#

L4 end to end

Outputs

L4 DecisionRuntime

Inputs

pass

block

emit / supersede

hold

block

emit / supersede

withhold / abstain

L3 Evidence
(as built: Finding 1.2.0)

Deterministic scanners

L3 system / what-if methods

LLM hypotheses

Plant Situation Model

DecisionCase + ledger

Dual-family candidates

Constraint evaluator

Portfolio

Kernel re-check

Opportunity ledger

Prescription to L5
(as built: card proposal)

L4 hold store

DecisionTrace

How to read it.

  1. Intake is L3 Evidence or discovery; every path builds a DecisionCase against a PSM snapshot.
  2. Constraints and portfolio run before the kernel re-check; blocks land in the opportunity ledger.
  3. emit and supersede ship a Prescription (section 5.3); hold stays L4-internal.

Build now: Finding path + discovery + portfolio. Later: full Prescription contract fields beyond prescription.json 1.0.0.

View Mermaid source
flowchart TB
    %% house-style: l4-end-to-end
    subgraph src["Inputs"]
        direction LR
        l3["L3 Evidence<br/>(as built: Finding 1.2.0)"]
        sc["Deterministic scanners"]
        meth["L3 system / what-if methods"]
        hyp["LLM hypotheses"]
    end
    subgraph l4["L4 DecisionRuntime"]
        direction LR
        psm["Plant Situation Model"]
        dc["DecisionCase + ledger"]
        fam["Dual-family candidates"]
        ce["Constraint evaluator"]
        pf["Portfolio"]
        kr{{"Kernel re-check"}}
        ol["Opportunity ledger"]
    end
    subgraph out["Outputs"]
        direction LR
        l5["Prescription to L5<br/>(as built: card proposal)"]
        hold["L4 hold store"]
        tr["DecisionTrace"]
    end
    l3 --> dc
    sc --> dc
    meth --> dc
    hyp --> dc
    psm --> dc
    dc --> fam --> ce
    ce -->|"pass"| pf
    ce -->|"block"| ol
    pf -->|"emit / supersede"| kr
    pf -->|"hold"| hold
    pf -->|"block"| ol
    kr -->|"emit / supersede"| l5
    kr -->|"withhold / abstain"| tr
    kr --> tr
    hold --> tr
    ol --> tr

    classDef govc fill:#fff4d6,stroke:#c99a2e,color:#000
    classDef agentc fill:#e8f0ff,stroke:#5b7bd5,color:#000
    classDef loopc fill:#eef7ee,stroke:#4f9a4f,color:#000
    class kr govc

Two intake paths, one floor#

PathOriginDoc
Evidence (Finding)L3 detector (detector_id / detector_version)07-finding-runtime.md
DiscoveryScanners, certified patterns, grounded-hypothesis lane08-discovery.md

Both meet the same proof floorMinimum evidence/structure required before emit (asset bound, verification path, L3 condition test for discoveries), constraint evaluator, and portfolio. Uncertified detector versions and ungrounded LLM ideas stay in shadow (traced, never sent).


Plant context (not per-Finding only)#

LayerOwnerDoc
TopologySite pack → L1→L202-plant-structure.md
Derived situationL4 PSM (cache)03-plant-situation-model.md
ConstraintsTyped rows + code evaluator04-constraints.md
MemoryHindsight + case library06-memory.md

Models#

RoleDefaultPath
Plant family ADeepSeek V4.1 Flash (deepseek-flash)Live
Plant family BGPT-5.6 LunaLive
Offline councilOpus 5.5 + GPT-5.6 SolNever on plant request path

See 11-models-and-seams.md. All plant-path LLM calls go through one KR gateway (D21, section 8.1). Seams are LLM-structured today; each has a Jev / classifier replacement row.


Expandability#

Registries under one release lockfile (21-registries-and-stage-graph.md). Adding a domain or stage is registration plus replay — not a kernel rewrite (17-change-guide.md).


Improvement loop#

L4 improvement loop

Offline improvement

L4 stores

Learning inputs

L5 closures

Soft-gate blocks

Case library

Opportunity ledger

Owner backlog

Exploration cards

Offline council

Playbook / prompt / threshold proposals

Replay + shadow

↩ Named owner accept → release lockfile

How to read it.

  1. Closures feed the case library; soft-gate blocks feed the opportunity ledger.
  2. The offline council proposes playbook, prompt, and threshold changes — never self-promotion (00-kernel.md section 10).
  3. Nothing ships without replay and a named owner accept into the release lockfile.

Build now: opportunity ledger + case library. Later: exploration volume under caps (22-missed-opportunities.md).

View Mermaid source
flowchart TB
    %% house-style: l4-improvement-loop
    subgraph learn["Learning inputs"]
        direction LR
        close["L5 closures"]
        soft["Soft-gate blocks"]
    end
    subgraph store["L4 stores"]
        direction LR
        case["Case library"]
        ol["Opportunity ledger"]
    end
    subgraph improve["Offline improvement"]
        direction LR
        back["Owner backlog"]
        exp["Exploration cards"]
        council["Offline council"]
        prop["Playbook / prompt / threshold proposals"]
    end
    gate{{"Replay + shadow"}}
    own(["↩ Named owner accept → release lockfile"])
    close --> case
    soft --> ol
    ol --> back
    ol --> exp
    case --> council
    exp --> council
    council --> prop --> gate --> own

    classDef govc fill:#fff4d6,stroke:#c99a2e,color:#000
    classDef agentc fill:#e8f0ff,stroke:#5b7bd5,color:#000
    classDef loopc fill:#eef7ee,stroke:#4f9a4f,color:#000
    class gate govc
    class own loopc

Detail: 13-improvement.md · 22-missed-opportunities.md.


Layer boundaries (short)#

LayerOwnsDoes not own
L1Collect, topology publishDecisions
L2Plant SoR, series, context recordsCard proposals
L3Detectors, calculators, simulators, verification buildersPortfolio / attention
L4Decision runtime (DecisionRuntime), PSM, opportunity ledger; jobs 6–7 rank prescriptionsLive card, equipment write
L5Live card, notification, verification, policyDetection methods
L6Surfaces / Ask viewSecond memory, second judge

v1 slice vs later#

v1Later
Finding path + certified patterns + opt-in hypothesis laneBroader scanner/method library
Dual-family plant models; offline council off-pathJev/classifier seam replacements as they beat the log
Opportunity ledger + owner backlogExploration volume under caps
Five product domains (ADR-018)Additional domain registry ids without kernel rewrite
Page history: last 4 changes
  1. 2026-10-07 docs(technical): rewrite l4 00-10 to the architecture c52a111
  2. 2026-10-03 docs(decisions): add ADR-033..038 (twin runtime, fast read path, plant-side writer, message classes, alerts and quality-to-lot link, part-keyed parameters), fast-loop technical set, rebuilt index with renumbering map; fix bare-number link text and ranges 22e2872
  3. 2026-10-03 docs(decisions): renumber live ADRs 001-032 in order, mark withdrawn refs ADR-W###, repoint withdrawn links to archive, note partial supersessions 36c944e
  4. 2026-09-25 docs(l4): agentic decision architecture, ADRs, and production hardness 8275e7c

Diagram

100%

Search the architecture