Most of the slow loop exists as code with tests across eleven product repos, but none of it runs at a customer yet, and nothing runs in seconds at the plant. The fast loop is direction: designed in ADRs and deep docs, not built. Every page in this pack says which of the two it describes.

What is built and what is planned

Later, each with a named trigger

AL2 live, then AL3

MPC after an identified model passes calibration

Managed Timescale with HA at about 10 plants

Build now: first three plants

One ingest path, one store, one registry, one sender

Ten contracts as 0.x

Fast loop in shadow on the Plant Box

Exists as code with tests

EDGE edge-agent: read connectors, buffer

L2 TimescaleDB store

L3 engines, registry, gates

KR DecisionRuntime in shadow, Ask, CP-SAT repair

L5 11-state card machine, verification packs

L6 UI on fixtures, WhatsApp

Not planned: AL4 and AL5, shielded RL in the next 12 months, a second plant store, cloud push into the plant

How to read it.

  1. The top box is what the repos contain today. "Exists" means code with tests, not a running customer deployment.
  2. Build now is the target state for the first three plants, from architecture section 1.2 and section 10.
  3. Later items wait for a named trigger. The yellow box lists decisions not to build, which change only through the decisions board.

Build now: the middle box. Later: the bottom box, trigger by trigger.

View Mermaid source
flowchart TB
    %% house-style: tour-built-planned
    subgraph built["Exists as code with tests"]
        direction LR
        edge["EDGE edge-agent: read connectors, buffer"]
        l2["L2 TimescaleDB store"]
        l3["L3 engines, registry, gates"]
        kr["KR DecisionRuntime in shadow, Ask, CP-SAT repair"]
        l5["L5 11-state card machine, verification packs"]
        l6["L6 UI on fixtures, WhatsApp"]
    end
    subgraph now["Build now: first three plants"]
        direction LR
        one["One ingest path, one store, one registry, one sender"]
        ten["Ten contracts as 0.x"]
        shadow["Fast loop in shadow on the Plant Box"]
    end
    subgraph later["Later, each with a named trigger"]
        direction LR
        al2["AL2 live, then AL3"]
        mpc["MPC after an identified model passes calibration"]
        ha["Managed Timescale with HA at about 10 plants"]
    end
    no{{"Not planned: AL4 and AL5, shielded RL in the next 12 months, a second plant store, cloud push into the plant"}}
    built --> now --> later

    classDef govc fill:#fff4d6,stroke:#c99a2e,color:#000
    classDef agentc fill:#e8f0ff,stroke:#5b7bd5,color:#000
    classDef loopc fill:#eef7ee,stroke:#4f9a4f,color:#000
    class no govc

Status labels#

Every deep doc opens with a status line, and the site shows it as tags at the top of the page.

LabelMeans
as-builtCode exists on a named branch. Not a claim about production
contractA schema or topic in the SE pack
simulator-provenProven against lab simulators, not at a named plant
directionDesigned and agreed, not built

When a page mixes them, the status line lists each part separately, so read it before trusting a field name.

What exists today#

The slow loop has every stage in code. The Go edge agent reads plant protocols and buffers. L2 stores readings in TimescaleDB. L3 has 48 engines with challengers in shadow, a registry and gates. KR runs DecisionRuntime in shadow, Ask and CP-SAT repair.

L5 runs the 11-state card machine, verification packs and an autonomy gate, and L6 has the UI on fixtures plus WhatsApp. The fast loop in ADR-033 to ADR-038 exists only on paper and in offline prototype scripts run on one customer's exported data.

The code also carries duplication we have to remove. There are four shapes of the plant graph across L2, L3 and KR, two promotion paths for models, two WhatsApp senders, and closure states that number 8 in older docs and 11 in code. The architecture resolves each one, mostly by naming a single owner: L2 for the plant record (D1), the L3 registry for models (D9), L5 for sending (D16).

The scope cut#

Architecture section 10 cuts every component three ways. Build now is what the first three plants need. Later names the trigger that justifies the work, such as native S7 drivers for the first plant that needs them, or synthetic control once there are enough untreated lines. Not planned records a decision not to build, such as a second plant store or bill-verified savings as a product claim. Inside Build now, plant 1 gets the slow loop first, and fast-loop work never holds up its cards.

Go deeper: current architecture map · scope cut · L4 as-built map

Page history: last 1 change
  1. 2026-10-08 docs(technical): architecture tour and page summaries 79c8ea3

Diagram

100%

Search the architecture