L6 — Experience and integration
The customer sees Stamped through experience-integration (L6): one action queue, cards, close, constraints and Ask. Its home screen is the next action rather than a monitoring dashboard. A Next.js front end talks to a Fastify backend-for-frontend that composes L2, L4 and L5 over HTTP, so the browser never holds upstream service keys. L6 renders cards but does not send them, because L5 is the one sender, and it never shows a summed rupee headline.
- Status
- as-built (
experience-integration, Forge web + BFF) · contract (BFF composes L2 / L4 / L5 HTTP) · direction (fast-loop surfaces, richer export / webhook evidence) - Conceptual layer
- presentation of ⑤ Action and ⑥ Value
- Repo layer
- L6
experience-integration - Source
- architecture section 3.5, section 3.6.5 · ADRs 016,
ADR-023(withdrawn; wasADR-W023in archive — analyst context now section 8)
L6 is the customer control room: one action queue, cards, close, constraints, Ask. The browser never holds upstream service keys. Home is the next action, not a monitoring dashboard product.
| Label | Meaning |
|---|---|
| as-built | experience-integration (Forge web + BFF) |
| contract | BFF composes L2 / L4 / L5 HTTP |
| direction | Richer export / webhook evidence surfaces |
Repo#
| Repo | Job | Must not |
|---|---|---|
experience-integration | Next.js Forge + Fastify BFF; session auth; Live / Preview honesty | Hold L2_DATABASE_URL or bank keys in the browser; five inboxes; summed ₹ headline; OT write |
Typical local: web :3000 → BFF :3001.
Surfaces#
| Surface | Job |
|---|---|
| Now / prescriptions / alarms | One owner-facing queue; hide hard-gate withhold from customer (staff-only status) |
| Card / close | Accept / edit / reject / defer; honest ClosureState values (section 5.9) |
| Live plant / equipment | L2 overlay when gates allow; otherwise Preview |
| Ask | Conversational view over L4 — does not emit cards |
| Autonomy / constraints | Settings UI; L2 stores constraints; autonomy default off |
| Evidence | Live vs Preview badges must stay honest |
Dual claim labels: ops-confirmed ≠ bill-verified (ops_confirmed code value is ops clearance, not DISCOM bill-verified).
How to read it.
- The browser talks only to the BFF; upstream tokens (
L2_SERVICE_KEY,L5_AUTH_TOKEN,L4_AUTH_TOKEN) stay server-side. - Fixture Auto vs live gates (
USE_FIXTURES,L2_LIVE,L5_LIVE,L4_LIVE) control demos without lying about Live. - Customer surfaces show ⑤ cards and honest closure; staff-only withhold stays off the owner queue.
Build now: BFF boundary per ADR-016. Later: fast-loop procedure and write-history surfaces (direction below).
View Mermaid source
flowchart TB
%% house-style: l6-bff-surfaces
browser["Browser Forge UI"]
subgraph bff["experience-integration BFF"]
direction LR
sess["session cookies stk_ keys"]
compose["compose L2 L4 L5 HTTP"]
end
subgraph upstream["Upstream APIs"]
direction LR
l2["L2 query"]
l4["L4 Ask and runtime"]
l5["L5 cards and close"]
end
keys{{"service keys server-side only"}}
owner(["Owner queue and close in L6"])
browser --> sess --> compose --> keys --> upstream
upstream --> owner
classDef govc fill:#fff4d6,stroke:#c99a2e,color:#000
classDef agentc fill:#e8f0ff,stroke:#5b7bd5,color:#000
classDef loopc fill:#eef7ee,stroke:#4f9a4f,color:#000
class keys govc
class owner agentc
Fast-loop surfaces (direction)#
Not as-built. Design: ../fast-loop/03 · ../fast-loop/04 · ownership: ../fast-loop/07 section 1 · Plant BoxPlant-side computer for the fast loop (direction; D4) display: D7.
| Surface | Job |
|---|---|
| Procedure acceptance card | A named plant person accepts a standing procedure once, with its version, recipients, limits shown in plain words; a new version needs a new acceptance |
| Shift switch | Per procedure, per shift. Message-only procedures can be switched on from L6. Anyone may switch off from anywhere. Switching writes on takes a person at the plant (machine switch plus in-charge enable on a plant-local screen); L6 never switches writes on |
| Alert with lot view | Each alert names the time bins, parts or heat-treatment baskets it affects; per-basket record with the strength results linked |
| Missed-savings view | Model-estimated loss of actions and signals not taken, per procedure and per shift. Never per person, never summed into one headline |
| Write history | Read-only view of ledger.write_log rows (request, result, refusal, read-back) |
BFF boundary (ADR-016)#
Browser → BFF (cookies / stk_ keys) → L2 / L4 / L5 HTTP. See diagram under Surfaces.
Related#
- Handoff:
../../handoff/l6/stamped-l6-architecture-handoff.md - UI charter:
../../handoff/l6/stamped-l6-ui-ux-charter.md - L5 closure:
L5-closure.md
Page history: last 4 changes
- docs(technical): rewrite layers/ and L1-L2-DATA-PLANE.md to the architecture
322bf46 - docs(layers): L1 fast read, writer and sync; L2 tables; L5 relay and budgets; L6 surfaces; data-plane topics
5127af9 - docs(decisions): renumber live ADRs 001-032 in order, mark withdrawn refs ADR-W###, repoint withdrawn links to archive, note partial supersessions
36c944e - docs(architecture): add L5 and L6 architecture
ffb4814