In short

The customer sees Stamped through experience-integration (L6): one action queue, cards, close, constraints and Ask. Its home screen is the next action rather than a monitoring dashboard. A Next.js front end talks to a Fastify backend-for-frontend that composes L2, L4 and L5 over HTTP, so the browser never holds upstream service keys. L6 renders cards but does not send them, because L5 is the one sender, and it never shows a summed rupee headline.

Status
as-built (experience-integration, Forge web + BFF) · contract (BFF composes L2 / L4 / L5 HTTP) · direction (fast-loop surfaces, richer export / webhook evidence)
Conceptual layer
presentation of ⑤ Action and ⑥ Value
Repo layer
L6 experience-integration
Source
architecture section 3.5, section 3.6.5 · ADRs 016, ADR-023 (withdrawn; was ADR-W023 in archive — analyst context now section 8)

L6 is the customer control room: one action queue, cards, close, constraints, Ask. The browser never holds upstream service keys. Home is the next action, not a monitoring dashboard product.

LabelMeaning
as-builtexperience-integration (Forge web + BFF)
contractBFF composes L2 / L4 / L5 HTTP
directionRicher export / webhook evidence surfaces

Repo#

RepoJobMust not
experience-integrationNext.js Forge + Fastify BFF; session auth; Live / Preview honestyHold L2_DATABASE_URL or bank keys in the browser; five inboxes; summed ₹ headline; OT write

Typical local: web :3000 → BFF :3001.


Surfaces#

SurfaceJob
Now / prescriptions / alarmsOne owner-facing queue; hide hard-gate withhold from customer (staff-only status)
Card / closeAccept / edit / reject / defer; honest ClosureState values (section 5.9)
Live plant / equipmentL2 overlay when gates allow; otherwise Preview
AskConversational view over L4 — does not emit cards
Autonomy / constraintsSettings UI; L2 stores constraints; autonomy default off
EvidenceLive vs Preview badges must stay honest

Dual claim labels: ops-confirmed ≠ bill-verified (ops_confirmed code value is ops clearance, not DISCOM bill-verified).

L6 BFF surfaces

experience-integration BFF

Upstream APIs

L2 query

L4 Ask and runtime

L5 cards and close

Browser Forge UI

session cookies stk_ keys

compose L2 L4 L5 HTTP

service keys server-side only

Owner queue and close in L6

How to read it.

  1. The browser talks only to the BFF; upstream tokens (L2_SERVICE_KEY, L5_AUTH_TOKEN, L4_AUTH_TOKEN) stay server-side.
  2. Fixture Auto vs live gates (USE_FIXTURES, L2_LIVE, L5_LIVE, L4_LIVE) control demos without lying about Live.
  3. Customer surfaces show ⑤ cards and honest closure; staff-only withhold stays off the owner queue.

Build now: BFF boundary per ADR-016. Later: fast-loop procedure and write-history surfaces (direction below).

View Mermaid source
flowchart TB
    %% house-style: l6-bff-surfaces
    browser["Browser Forge UI"]
    subgraph bff["experience-integration BFF"]
        direction LR
        sess["session cookies stk_ keys"]
        compose["compose L2 L4 L5 HTTP"]
    end
    subgraph upstream["Upstream APIs"]
        direction LR
        l2["L2 query"]
        l4["L4 Ask and runtime"]
        l5["L5 cards and close"]
    end
    keys{{"service keys server-side only"}}
    owner(["Owner queue and close in L6"])
    browser --> sess --> compose --> keys --> upstream
    upstream --> owner

    classDef govc fill:#fff4d6,stroke:#c99a2e,color:#000
    classDef agentc fill:#e8f0ff,stroke:#5b7bd5,color:#000
    classDef loopc fill:#eef7ee,stroke:#4f9a4f,color:#000
    class keys govc
    class owner agentc

Fast-loop surfaces (direction)#

Not as-built. Design: ../fast-loop/03 · ../fast-loop/04 · ownership: ../fast-loop/07 section 1 · Plant BoxPlant-side computer for the fast loop (direction; D4) display: D7.

SurfaceJob
Procedure acceptance cardA named plant person accepts a standing procedure once, with its version, recipients, limits shown in plain words; a new version needs a new acceptance
Shift switchPer procedure, per shift. Message-only procedures can be switched on from L6. Anyone may switch off from anywhere. Switching writes on takes a person at the plant (machine switch plus in-charge enable on a plant-local screen); L6 never switches writes on
Alert with lot viewEach alert names the time bins, parts or heat-treatment baskets it affects; per-basket record with the strength results linked
Missed-savings viewModel-estimated loss of actions and signals not taken, per procedure and per shift. Never per person, never summed into one headline
Write historyRead-only view of ledger.write_log rows (request, result, refusal, read-back)

BFF boundary (ADR-016)#

Browser → BFF (cookies / stk_ keys) → L2 / L4 / L5 HTTP. See diagram under Surfaces.


  • Handoff: ../../handoff/l6/stamped-l6-architecture-handoff.md
  • UI charter: ../../handoff/l6/stamped-l6-ui-ux-charter.md
  • L5 closure: L5-closure.md
Page history: last 4 changes
  1. 2026-10-07 docs(technical): rewrite layers/ and L1-L2-DATA-PLANE.md to the architecture 322bf46
  2. 2026-10-03 docs(layers): L1 fast read, writer and sync; L2 tables; L5 relay and budgets; L6 surfaces; data-plane topics 5127af9
  3. 2026-10-03 docs(decisions): renumber live ADRs 001-032 in order, mark withdrawn refs ADR-W###, repoint withdrawn links to archive, note partial supersessions 36c944e
  4. 2026-09-27 docs(architecture): add L5 and L6 architecture ffb4814

Diagram

100%

Search the architecture