L4 system overview
- Status
- contract + as-built (runtime) + direction (jobs 6–7, Prescription)
- Conceptual layer
- ④ Decision
- Repo layer
- L4
knowledge-reasoning - Source
- architecture section 3.3b, section 3.6.4, section 5.3, section 8
- Normative rules
00-kernel.md- ADRs
- 020 · 021 · 022
What L4 does#
- Accepts EvidenceLayer contract for detector output (direction; as built: Finding finding.json 1.2.0) from L3 (as built: FindingAs-built L3 detector output admitted to L4 (finding.json 1.2.0)
finding.json1.2.0), or a discovery candidate from L4 scanners / patterns / (opt-in) hypothesis lane — including on a shift sweepOnce-per-shift whole-plant discovery pass when nothing anomalous fired. - Builds a DecisionCaseOne run unit: intake + snapshot + obligations + candidates + terminal with a condition keyStable id for “this plant condition”; one open card per key and a frozen PSMPlant Situation Model snapshot (as-known-at).
- Runs a code-owned stage graph: candidates → constraints → portfolio → card minimizer → kernel re-check → terminal.
- Ends in
emit|supersede|withhold|abstain, always with a DecisionTraceAlways-on record: observed, context, action, policy, approval, outcome (and seam decisions). - Records every gate block in the opportunity ledgerStore of every blocked candidate with gate id and later outcome if known so refusals teach the system.
Humans decide and execute. L5 owns the live card after emit. L4 never writes equipment or schedules.
Whole-plant claim: The L3 Evidence (Finding) path is reactive. Discovery + shift sweep are how L4 still looks across the plant on a quiet shift — same kernel, same portfolio, same owner card. Cadence: 08-discovery.md.
End-to-end picture#
How to read it.
- Intake is L3 Evidence or discovery; every path builds a DecisionCase against a PSM snapshot.
- Constraints and portfolio run before the kernel re-check; blocks land in the opportunity ledger.
emitandsupersedeship a Prescription (section 5.3); hold stays L4-internal.
Build now: Finding path + discovery + portfolio. Later: full Prescription contract fields beyond prescription.json 1.0.0.
View Mermaid source
flowchart TB
%% house-style: l4-end-to-end
subgraph src["Inputs"]
direction LR
l3["L3 Evidence<br/>(as built: Finding 1.2.0)"]
sc["Deterministic scanners"]
meth["L3 system / what-if methods"]
hyp["LLM hypotheses"]
end
subgraph l4["L4 DecisionRuntime"]
direction LR
psm["Plant Situation Model"]
dc["DecisionCase + ledger"]
fam["Dual-family candidates"]
ce["Constraint evaluator"]
pf["Portfolio"]
kr{{"Kernel re-check"}}
ol["Opportunity ledger"]
end
subgraph out["Outputs"]
direction LR
l5["Prescription to L5<br/>(as built: card proposal)"]
hold["L4 hold store"]
tr["DecisionTrace"]
end
l3 --> dc
sc --> dc
meth --> dc
hyp --> dc
psm --> dc
dc --> fam --> ce
ce -->|"pass"| pf
ce -->|"block"| ol
pf -->|"emit / supersede"| kr
pf -->|"hold"| hold
pf -->|"block"| ol
kr -->|"emit / supersede"| l5
kr -->|"withhold / abstain"| tr
kr --> tr
hold --> tr
ol --> tr
classDef govc fill:#fff4d6,stroke:#c99a2e,color:#000
classDef agentc fill:#e8f0ff,stroke:#5b7bd5,color:#000
classDef loopc fill:#eef7ee,stroke:#4f9a4f,color:#000
class kr govc
Two intake paths, one floor#
| Path | Origin | Doc |
|---|---|---|
| Evidence (Finding) | L3 detector (detector_id / detector_version) | 07-finding-runtime.md |
| Discovery | Scanners, certified patterns, grounded-hypothesis lane | 08-discovery.md |
Both meet the same proof floorMinimum evidence/structure required before emit (asset bound, verification path, L3 condition test for discoveries), constraint evaluator, and portfolio. Uncertified detector versions and ungrounded LLM ideas stay in shadow (traced, never sent).
Plant context (not per-Finding only)#
| Layer | Owner | Doc |
|---|---|---|
| Topology | Site pack → L1→L2 | 02-plant-structure.md |
| Derived situation | L4 PSM (cache) | 03-plant-situation-model.md |
| Constraints | Typed rows + code evaluator | 04-constraints.md |
| Memory | Hindsight + case library | 06-memory.md |
Models#
| Role | Default | Path |
|---|---|---|
| Plant family A | DeepSeek V4.1 Flash (deepseek-flash) | Live |
| Plant family B | GPT-5.6 Luna | Live |
| Offline council | Opus 5.5 + GPT-5.6 Sol | Never on plant request path |
See 11-models-and-seams.md. All plant-path LLM calls go through one KR gateway (D21, section 8.1). Seams are LLM-structured today; each has a Jev / classifier replacement row.
Expandability#
Registries under one release lockfile (21-registries-and-stage-graph.md). Adding a domain or stage is registration plus replay — not a kernel rewrite (17-change-guide.md).
Improvement loop#
How to read it.
- Closures feed the case library; soft-gate blocks feed the opportunity ledger.
- The offline council proposes playbook, prompt, and threshold changes — never self-promotion (
00-kernel.mdsection 10). - Nothing ships without replay and a named owner accept into the release lockfile.
Build now: opportunity ledger + case library. Later: exploration volume under caps (22-missed-opportunities.md).
View Mermaid source
flowchart TB
%% house-style: l4-improvement-loop
subgraph learn["Learning inputs"]
direction LR
close["L5 closures"]
soft["Soft-gate blocks"]
end
subgraph store["L4 stores"]
direction LR
case["Case library"]
ol["Opportunity ledger"]
end
subgraph improve["Offline improvement"]
direction LR
back["Owner backlog"]
exp["Exploration cards"]
council["Offline council"]
prop["Playbook / prompt / threshold proposals"]
end
gate{{"Replay + shadow"}}
own(["↩ Named owner accept → release lockfile"])
close --> case
soft --> ol
ol --> back
ol --> exp
case --> council
exp --> council
council --> prop --> gate --> own
classDef govc fill:#fff4d6,stroke:#c99a2e,color:#000
classDef agentc fill:#e8f0ff,stroke:#5b7bd5,color:#000
classDef loopc fill:#eef7ee,stroke:#4f9a4f,color:#000
class gate govc
class own loopc
Detail: 13-improvement.md · 22-missed-opportunities.md.
Layer boundaries (short)#
| Layer | Owns | Does not own |
|---|---|---|
| L1 | Collect, topology publish | Decisions |
| L2 | Plant SoR, series, context records | Card proposals |
| L3 | Detectors, calculators, simulators, verification builders | Portfolio / attention |
| L4 | Decision runtime (DecisionRuntime), PSM, opportunity ledger; jobs 6–7 rank prescriptions | Live card, equipment write |
| L5 | Live card, notification, verification, policy | Detection methods |
| L6 | Surfaces / Ask view | Second memory, second judge |
v1 slice vs later#
| v1 | Later |
|---|---|
| Finding path + certified patterns + opt-in hypothesis lane | Broader scanner/method library |
| Dual-family plant models; offline council off-path | Jev/classifier seam replacements as they beat the log |
| Opportunity ledger + owner backlog | Exploration volume under caps |
| Five product domains (ADR-018) | Additional domain registry ids without kernel rewrite |
Page history: last 4 changes
- docs(technical): rewrite l4 00-10 to the architecture
c52a111 - docs(decisions): add ADR-033..038 (twin runtime, fast read path, plant-side writer, message classes, alerts and quality-to-lot link, part-keyed parameters), fast-loop technical set, rebuilt index with renumbering map; fix bare-number link text and ranges
22e2872 - docs(decisions): renumber live ADRs 001-032 in order, mark withdrawn refs ADR-W###, repoint withdrawn links to archive, note partial supersessions
36c944e - docs(l4): agentic decision architecture, ADRs, and production hardness
8275e7c