Status
audit (historical) + reconciliation
Conceptual layer
④ Decision
Repo layer
L4 knowledge-reasoning
Source
architecture section 2.2, section 2.3, section 5
ADR
027

Date: 2026-09-25. Must-have / should-have production items are specified in docs 25–29 and ADR-027. Already closed earlier: OE literature RAG (23-oe-knowledge-corpus.md).


Reconciliation (architecture section 2 and section 5)#

Table: 18 rows by gap id
Gap idFact (unchanged)ArchitectureStatus
GAP-01Work queue / concurrencyL4 doc 25; KR runtime queue/ (section 2.2 KR runtime/)Resolved in L4 contract; open in product until always-on worker + shared L4_DATABASE_URL (30-as-built.md)
GAP-02DecisionCase lifecycle26; lifecycle/ packageResolved in docs; implementation partial (SQL cases; ledger/hold in memory)
GAP-03Port failures / idempotency / breakers27; section 13 degraded modesResolved in docs
GAP-04Token-budget required proof26 section token budget; hard-adjacent gate_id=token_budget_required_proofResolved in docs
GAP-05Commissioning / safe-start28; emit_enabled=false defaultResolved in docs; aligns section 10 scope cut shadow-first
GAP-06Kill switch / control plane28; Plant Box may switch writes off (section 7)Resolved in L4 plant flags; fast-loop relay is open (D7, D16)
GAP-07OE corpus ops + offline privacy28 + 23Resolved in docs
GAP-08Observability SLOs / store durability / CI suites29 · 16-operations.mdResolved in docs; KR CI workflow still open (section 2.2 KR CI)
GAP-09OE literature RAG23-oe-knowledge-corpus.mdClosed
GAP-10KR runtime missing lot and part keyssection 2.2 KR runtime/ Missing; section 5.7Open — contract direction; L4 PSM/topology docs assume site pack
GAP-11KR runtime missing AutonomyPolicysection 2.2 KR runtime/; section 5.6; L5 autonomy/gate.py seedOpen — policy objects live in L5 direction; L4 sets required_autonomy_level on Prescription (section 5.3)
GAP-12Four plant graph shapes (L2, L3, KR)section 2.3 Plant graph → one context contract D1Resolved in architecture; open in code until KR graphs are read-only views
GAP-13Two scheduling solvers (flowline/cpsat.py vs pack solver)section 2.3 Scheduling — repair vs near-term sequence, human accept before write-backResolved in architecture; L4 owns CP-SAT repair role
GAP-14Energy-centric Finding 1.2.0section 2.3 Finding → Evidence section 5.2Resolved in architecture; as-built still finding.json 1.2.0
GAP-15Prescription contract beyond prescription.json 1.0.0section 5.3 (options, required_autonomy_level, …)Open — dual-read with card-proposal until ten contracts D2
GAP-16Ask missing evidence-ID citations enforced by contractsection 2.2 KR ask/; section 8 validator rulesOpen
GAP-17Ledger concept duplicated (L2, L5, KR opportunity ledger)section 2.2 KR runtime/; opportunity ledger is L4; ValueRecord section 5.5 D2Open migration; roles now named
GAP-188 vs 11 closure states in docssection 2.3 Closure states → ClosureState section 5.9Resolved in architecture; L4 emits Prescription, L5 owns ClosureState

Nothing in this table loosens hard stops or claims verified savings; verified savings are ₹0.


Closure map (docs 25–29)#

Former gapNow specified in
Work queue / concurrency25-work-queue-and-concurrency.md
DecisionCase lifecycle26-decision-case-lifecycle.md
Port failures / idempotency / breakers27-ports-and-reliability.md
Token-budget required proof26 section token budget
Commissioning / safe-start28-commissioning-and-controls.md
Kill switch / control plane28
OE corpus ops + offline privacy28
Observability SLOs / store durability / CI suites29-software-quality-and-release.md · 16-operations.md

Still later (conscious deferrals — not silent holes)#

  • Cross-plant priors
  • OE Tier B/C (licensed books, plant SOPs) under license
  • Ask Adaptive Router / heavy GraphRAG on Ask
  • Multi-region HA / chaos topology
  • Automated error-budget auto-block of pins
  • Area-scoped emit_enabled

Not missing (do not reopen)#

Kernel integrity, dual-family seams, PSMPlant Situation Model, discovery/shift sweepOnce-per-shift whole-plant discovery pass, opportunity ledgerStore of every blocked candidate with gate id and later outcome if known, HITL, money/write bans, OE advisory corpus — see README eight ideas.


Implementer rule#

Before first production emit_enabled=true, stamped-l4 must implement kernel + 25–29, not kernel alone. ADR-027 is the lock.

Page history: last 3 changes
  1. 2026-10-07 docs(technical): rewrite l4 21-30, glossary and README; reconcile architecture gaps e7fead7
  2. 2026-10-03 docs(decisions): renumber live ADRs 001-032 in order, mark withdrawn refs ADR-W###, repoint withdrawn links to archive, note partial supersessions 36c944e
  3. 2026-09-25 docs(l4): agentic decision architecture, ADRs, and production hardness 8275e7c

Diagram

100%

Search the architecture