L4 · deep doc 25 of 31
L4 architecture gap audit — agentic stack + industrial hardness
- Status
- audit (historical) + reconciliation
- Conceptual layer
- ④ Decision
- Repo layer
- L4
knowledge-reasoning - Source
- architecture section 2.2, section 2.3, section 5
- ADR
- 027
Date: 2026-09-25. Must-have / should-have production items are specified in docs 25–29 and ADR-027. Already closed earlier: OE literature RAG (23-oe-knowledge-corpus.md).
Reconciliation (architecture section 2 and section 5)#
Table: 18 rows by gap id
| Gap id | Fact (unchanged) | Architecture | Status |
|---|---|---|---|
| GAP-01 | Work queue / concurrency | L4 doc 25; KR runtime queue/ (section 2.2 KR runtime/) | Resolved in L4 contract; open in product until always-on worker + shared L4_DATABASE_URL (30-as-built.md) |
| GAP-02 | DecisionCase lifecycle | 26; lifecycle/ package | Resolved in docs; implementation partial (SQL cases; ledger/hold in memory) |
| GAP-03 | Port failures / idempotency / breakers | 27; section 13 degraded modes | Resolved in docs |
| GAP-04 | Token-budget required proof | 26 section token budget; hard-adjacent gate_id=token_budget_required_proof | Resolved in docs |
| GAP-05 | Commissioning / safe-start | 28; emit_enabled=false default | Resolved in docs; aligns section 10 scope cut shadow-first |
| GAP-06 | Kill switch / control plane | 28; Plant Box may switch writes off (section 7) | Resolved in L4 plant flags; fast-loop relay is open (D7, D16) |
| GAP-07 | OE corpus ops + offline privacy | 28 + 23 | Resolved in docs |
| GAP-08 | Observability SLOs / store durability / CI suites | 29 · 16-operations.md | Resolved in docs; KR CI workflow still open (section 2.2 KR CI) |
| GAP-09 | OE literature RAG | 23-oe-knowledge-corpus.md | Closed |
| GAP-10 | KR runtime missing lot and part keys | section 2.2 KR runtime/ Missing; section 5.7 | Open — contract direction; L4 PSM/topology docs assume site pack |
| GAP-11 | KR runtime missing AutonomyPolicy | section 2.2 KR runtime/; section 5.6; L5 autonomy/gate.py seed | Open — policy objects live in L5 direction; L4 sets required_autonomy_level on Prescription (section 5.3) |
| GAP-12 | Four plant graph shapes (L2, L3, KR) | section 2.3 Plant graph → one context contract D1 | Resolved in architecture; open in code until KR graphs are read-only views |
| GAP-13 | Two scheduling solvers (flowline/cpsat.py vs pack solver) | section 2.3 Scheduling — repair vs near-term sequence, human accept before write-back | Resolved in architecture; L4 owns CP-SAT repair role |
| GAP-14 | Energy-centric Finding 1.2.0 | section 2.3 Finding → Evidence section 5.2 | Resolved in architecture; as-built still finding.json 1.2.0 |
| GAP-15 | Prescription contract beyond prescription.json 1.0.0 | section 5.3 (options, required_autonomy_level, …) | Open — dual-read with card-proposal until ten contracts D2 |
| GAP-16 | Ask missing evidence-ID citations enforced by contract | section 2.2 KR ask/; section 8 validator rules | Open |
| GAP-17 | Ledger concept duplicated (L2, L5, KR opportunity ledger) | section 2.2 KR runtime/; opportunity ledger is L4; ValueRecord section 5.5 D2 | Open migration; roles now named |
| GAP-18 | 8 vs 11 closure states in docs | section 2.3 Closure states → ClosureState section 5.9 | Resolved in architecture; L4 emits Prescription, L5 owns ClosureState |
Nothing in this table loosens hard stops or claims verified savings; verified savings are ₹0.
Closure map (docs 25–29)#
| Former gap | Now specified in |
|---|---|
| Work queue / concurrency | 25-work-queue-and-concurrency.md |
| DecisionCase lifecycle | 26-decision-case-lifecycle.md |
| Port failures / idempotency / breakers | 27-ports-and-reliability.md |
| Token-budget required proof | 26 section token budget |
| Commissioning / safe-start | 28-commissioning-and-controls.md |
| Kill switch / control plane | 28 |
| OE corpus ops + offline privacy | 28 |
| Observability SLOs / store durability / CI suites | 29-software-quality-and-release.md · 16-operations.md |
Still later (conscious deferrals — not silent holes)#
- Cross-plant priors
- OE Tier B/C (licensed books, plant SOPs) under license
- Ask Adaptive Router / heavy GraphRAG on Ask
- Multi-region HA / chaos topology
- Automated error-budget auto-block of pins
- Area-scoped
emit_enabled
Not missing (do not reopen)#
Kernel integrity, dual-family seams, PSMPlant Situation Model, discovery/shift sweepOnce-per-shift whole-plant discovery pass, opportunity ledgerStore of every blocked candidate with gate id and later outcome if known, HITL, money/write bans, OE advisory corpus — see README eight ideas.
Implementer rule#
Before first production emit_enabled=true, stamped-l4 must implement kernel + 25–29, not kernel alone. ADR-027 is the lock.
Page history: last 3 changes
- docs(technical): rewrite l4 21-30, glossary and README; reconcile architecture gaps
e7fead7 - docs(decisions): renumber live ADRs 001-032 in order, mark withdrawn refs ADR-W###, repoint withdrawn links to archive, note partial supersessions
36c944e - docs(l4): agentic decision architecture, ADRs, and production hardness
8275e7c