Skip to content

Control Plane Architecture

This standard defines the architecture and communication boundaries for all client projections and human interfaces interacting with the platform.


1. Architectural Planes & Product Boundaries

All client interfaces built for the platform—including Drupal / AMCS / ContextControl.ai, Canvas, mobile, and CLI tools—function as projections of shared platform contracts. Projections are prohibited from executing direct backend orchestration or directly mutating operational databases.

       ┌─────────────────────────────────────────────────────────────┐
       │             HUMAN & CUSTOMER INTERFACE PLANE                │
       │   Drupal AMCS │ ContextControl.ai │ Canvas │ Web / Mobile   │
       └──────────────────────────────┬──────────────────────────────┘
                                      │
                                      ▼ HTTP / SSE Connected-Client API
       ┌─────────────────────────────────────────────────────────────┐
       │                    PLATFORM CONTROL PLANE                   │
       │   Identity Plane              │  Model & Capability Plane   │
       │   (Keycloak SSO & Cedar)      │  (Model Routing & MCP)      │
       │   Knowledge Plane             │  Operator Plane (Gas City)  │
       │   (Vector / BM25 Gateway)     │  (Session & Work Routing)   │
       └──────────────────────────────┬──────────────────────────────┘
                                      │
                                      ▼
       ┌─────────────────────────────────────────────────────────────┐
       │                        RUNTIME PLANE                        │
       │   Execution Orchestration │ Beads Work Graph │ Rigs & CI    │
       └─────────────────────────────────────────────────────────────┘
  1. Identity Plane: Handles federated identity, token verification, and Cedar policy evaluation.
  2. Model Plane: Hosts the model registry, routing client model calls to stable semantic aliases.
  3. Knowledge Plane: Coordinates document queries, chunking, embeddings, and vector index lookups.
  4. Capability Plane: Serves as a central registry mapping tool specifications to network-based MCP endpoints.
  5. Operator Plane (Gas City): Orchestrates agent sessions, formulas, orders, and event loops.
  6. Runtime Plane: Manages ephemeral execution worktrees, Beads/Dolt state, and CI/CD pipelines.

2. Ingestion & Retrieval (The Knowledge Plane)

Information is retrieved by client projections using one of four distinct classes of data:

  • Knowledge (Vectorized): Static documentation, standards, and schemas stored on persistent shares and indexed.
  • Operational (Live Queries — Never Vectorized): Running session IDs, telemetry stats, and active beads pulled dynamically from the Runtime Plane.
  • Enterprise (Workspace Adapters): Version control history, issues, and CRM records accessed via API connectors.
  • Personal Context (State): Memory, user preferences, recent conversations, and working sets.

3. Compliance Rules for Projections

Projections must be configuration-only. They are prohibited from: * Directly connecting to Qdrant, MongoDB, Redis, or SQL databases. * Storing API credentials or executing custom local model-routing logic. * Bundling or running embedded execution runtimes (Drupal connects to Gas City via HTTP/SSE API; it does not embed agent runtimes).


4. Governed Control-Plane Ownership Model

To ensure a clear separation of concerns, the following ownership boundaries are strictly enforced across the control plane:

  • AGENT DEFINITION: OSSA
  • AGENT PROFILE: agentictools/agents
  • DISCOVERY: DUADP
  • CAPABILITY IMPLEMENTATION: skills / plugins / Agent Protocol
  • OPERATIONAL CONTEXT: ContextControl
  • AUTHORITY / OWNERSHIP: ContractPlane
  • POLICY EVALUATION: Compliance Engine
  • POLICY SOURCE: cedar-policies
  • WORK AUTHORITY: Gas City / Beads
  • EXECUTION: Gas City agents / rigs
  • SOURCE / RELEASE: GitLab
  • PROVENANCE / CURRENT CONTEXT: ContextControl
  • CREDENTIAL DELIVERY: 1Password + target service identity