Skip to content

DRAFT — NOT AUTHORITATIVE This document is directionally accepted but not yet promotion-ready. Every concrete implementation claim must be classified VERIFIED_CURRENT, TARGET, CANDIDATE, or NOT_ESTABLISHED before this becomes status: active. Do not implement the recommendations in §12 until PROMOTION_READY=YES. Authority: Thomas Scola directive 2026-09-30.

STD-CC-001: ContextControl Factory Control Plane Architecture & Governance

1. Authority Boundaries (Accepted)

The central boundary is accepted. Each system is the canonical authority for its domain. ContextControl governs — it does not duplicate or replace.

GAS_CITY          = ORCHESTRATION + EXECUTION + SESSION_STATE
BEADS / DOLT      = DURABLE_WORK_AUTHORITY + DEPENDENCY_GRAPH
GITLAB            = SOURCE + CI + DELIVERY + RELEASE_PROVENANCE
CONTEXTCONTROL    = HUMAN_GOVERNANCE + PRODUCT_STATE + GOVERNED_UI
CEDAR             = POLICY_DECISION_POINT (evaluation technology)
CONTRACTPLANE     = CANDIDATE — see §6 for required boundary clarification
WITNESS           = INDEPENDENT_VERIFICATION_ROLE — see §7
DRUPAL            = HUMAN_CONTROL_PLANE + GOVERNANCE_UI + ENTITY_LIFECYCLE + LOCAL_ECA_REACTIONS

Canonical ownership by artifact type:

Artifact Canonical Owner ContextControl Role
Work items, dependency graph Beads / Dolt Projects only — does not copy
Runtime / session state Gas City Reads events / state — does not duplicate
Source-controlled capability GitLab Reads provenance — does not re-store
Governed product state, timelines ContextControl Authoritative
Policy source / bindings Governed source + ContextControl Authoritative
Policy evaluation Cedar / proven PDP Delegate — does not re-implement
Evidence originals Originating systems ContextControl may project — not copy

ContextControl may PROJECT external authority. Projection ≠ ownership.

Drupal MUST NOT become: - another work graph - another scheduler or agent runtime - another durable orchestration engine - another Beads database


2. The Six Authority Domains

ContextControl is the governance authority for six domains. It is not the physical storage system for all six.

  1. Execution & Delivery Substrate — Gas City executes; Beads tracks; GitLab delivers. ContextControl reads and projects, does not own runtime or work state.
  2. Control Plane & Agent Coordination — BLU coordinates. BLU_ROUTES=YES, BLU_EXECUTES=NO. ContextControl surfaces agent registry and approval surfaces.
  3. Discovery & Machine Contracts — DUADP provides federated discovery. OSSA defines portable agent schemas. ContextControl queries DUADP — does not duplicate discovery.
  4. Context & Knowledge Governance — Governed context (see §9 for custom surface classification). Vector storage via standard provider plugins rather than ad-hoc services.
  5. Tenancy, Authority & Assurance — drupal/group enforces entity-level multi-tenancy. Cedar evaluates policy. ContractPlane boundary per §6.
  6. Human Governance & Presentation — Drupal Canvas + SDC render UI. Drupal is the human control plane. Drupal is not the orchestration engine.

3. Tenancy & Access Boundary

  1. Tenancy access MUST be enforced at the entity access handler layer (hook_entity_access / EntityAccessControlHandler).
  2. Views-only filtering, frontend query constraints, and hidden links are NOT valid access boundaries.
  3. Customer A must never retrieve Customer B context, operations, or receipts.
  4. Global or unscoped context is accessible only to authorized operators.

Multi-tenancy model: Organization (Group) → Workspace (Subgroup) → Project (Subgroup) → Team (Group role collection) via drupal/group + ggroup.

Classification: VERIFIED_CURRENT — group model confirmed as active implementation direction.


4. Integration with Factory Work Authority

Every Factory operation that touches ContextControl MUST trace to a canonical Bead. ContextControl projects Bead state — it does not store work items independently.

Receipt fields on ai_context_item for operations emitted to ContextControl:

field_record_kind:          signal | operation | run | approval | decision |
                            finding | evidence | receipt | fact | constraint |
                            adr | lesson
field_model_cost:           decimal(12,4) USD
field_infra_cost:           decimal(12,4) USD
field_human_time:           decimal(12,4) minutes
field_manual_time_avoided:  decimal(12,4) minutes
field_reusable_capability:  string
field_measurement_state:    measured | partial | model_cost_not_measurable |
                            not_measurable

Classification of field schema: CANDIDATE — field names require verification against current ai_context module schema before canonizing.

Beads are durable, auditable work authority. Their current state evolves. Their history and evidence must remain attributable and auditable. Beads are NOT immutable.

The Dolt deployment address (127.0.0.1:3308/hq) is current Oracle topology, not product architecture. Do not encode deployment topology into this standard.


5. Non-Duplication Law (Binding)

  1. ContextControl MUST NOT implement its own agent scheduler or task queue that competes with Gas City Orders and Formulas.
  2. ContextControl MUST NOT store work items in a private database disconnected from Beads.
  3. ContextControl MUST NOT duplicate discovery; it queries DUADP.
  4. ContextControl MUST NOT author authorization logic in PHP; it evaluates Cedar policies.
  5. Drupal ECA MUST NOT own Convoys, durable multi-agent workflows, Factory reconciliation, agent scheduling, retry orchestration, or canonical work state.

Permitted Drupal ECA scope: - React to Drupal entity lifecycle events - Manage entity access and approval requirements - Invoke governed external capabilities (via Gas City, not direct agent calls) - Update local ContextControl projections - Notify humans - Enqueue Drupal-local processing

Required ECA pattern for cross-system work:

Drupal ECA event
  → governed invocation (Gas City API / Order trigger)
    → Beads (canonical work authority)
      → agent execution
        → event / evidence emitted
          → ContextControl projection updated

advancedqueue.enqueue_job may enqueue Drupal-local processing. Convoy reconciliation and durable multi-agent orchestration belong to Gas City / Beads, not Advanced Queue.


6. Cedar / ContractPlane Boundary (Requires Clarification)

Required before promotion:

CEDAR_ROLE=                 policy evaluation technology (ABAC / OPA-style)
CONTRACTPLANE_UNIQUE_ROLE=  NOT_ESTABLISHED — must prove behavior beyond Cedar integration
POLICY_SOURCE_AUTHORITY=    governed source + ContextControl (CANDIDATE)
POLICY_DECISION_POINT=      Cedar (TARGET — not yet operational per v2 doc §0)
POLICY_ENFORCEMENT_POINT=   hook_entity_access / EntityAccessControlHandler (VERIFIED_CURRENT)
ASSURANCE_ROLE=             NOT_ESTABLISHED

ContractPlane exists as a Drupal module providing lightweight governance integration (policy evaluation, audit trail). Whether ContractPlane has unique architectural behavior beyond being a Cedar adapter is NOT_ESTABLISHED.

Rule: Do not preserve ContractPlane as a separate architectural box if it provides no proven unique behavior beyond Cedar integration. If it is only a Cedar adapter, it is an adapter — not a separate authority domain.

AUTHENTICATION ≠ AUTHORIZATION ≠ ASSURANCE

7. WITNESS Model (Corrected)

WITNESS is the independent verification role and process, not a product.

Visual testing (Dragonfly or other) provides evidence. It does not equal WITNESS.

deterministic tests
visual proof (Dragonfly, screenshot diff, etc.)
CI pipeline evidence
runtime behavioral evidence
policy evaluation evidence
            ↓
         WITNESS
   (independent verification)
            ↓
  VERIFIED / FAILED / NOT_ESTABLISHED

WITNESS acceptance criteria must be typed to the work class. Not every Bead produces a GitLab MR. Research, governance, incident classification, and documentation Beads have different completion shapes. Completion criteria MUST include:

REQUESTED_EFFECT=
EVIDENCE=
INDEPENDENT_VERIFICATION=   (where required by work class)
DEPENDENCY_STATE=
DELIVERY_STATE=             (where applicable — code Beads only)
RECEIPT=

8. PLAUD / Voice Extraction Governance

Voice-extracted commitments are candidate work, not automatically canonical Beads.

A detected commitment may become a Bead only after:

CANONICAL_AUTHORITY=YES
DEDUP_COMPLETE=YES
ROUTING_CONTEXT_RESOLVED=YES
TRANSCRIPT_PROVENANCE=YES

Otherwise the output is: CANDIDATE_WORK pending review.

Mac-local / non-canonical Bead creation is NOT a fallback for PLAUD output.


9. Custom Code Surface (Under Convergence — Not Canonized)

The following custom components are the current surface. They are classified by convergence status, not assumed permanent.

Section title: Current Custom Surface Under Convergence — not "What and Only What Is Custom."

Component Current Purpose Upstream/Contrib Equivalent Disposition Classification
kb_cache Context memory API, semantic search bootstrap ai_search + ai_context (contrib) REDUCE / CANDIDATE for replacement CANDIDATE
ai_context Governed context item storage Contrib ai_context module VERIFY parity CANDIDATE
contextcontrol_theme / bluefly_theme SDC components, design tokens Canvas + Drupal SDC (contrib-first) KEEP_THIN_ADAPTER CANDIDATE
api_normalization OpenAPI → managed Drupal entities No direct upstream equiv; ECK risk KEEP_THIN_ADAPTER with ECK constraint CANDIDATE
ai_agents_ossa OSSA manifest support OSSA spec (upstream contract) KEEP — core pillar VERIFIED_CURRENT
duadp Agent discovery/registry DUADP spec (upstream) KEEP — core pillar VERIFIED_CURRENT
contractplane (Drupal module) Policy evaluation integration Cedar (policy technology) CANDIDATE per §6 CANDIDATE

Required per component before promotion:

CURRENT_PURPOSE=
CURRENT_CONSUMERS=
UPSTREAM_EQUIVALENT=
CONTRIB_EQUIVALENT=
CONFIG_EQUIVALENT=
PARITY=
UNIQUE_REQUIRED_BEHAVIOR=
DISPOSITION=   KEEP_THIN_ADAPTER | REDUCE | REPLACE_WITH_UPSTREAM |
               MOVE_TO_CONFIG | MOVE_TO_RECIPE | CONTRIBUTE_UPSTREAM |
               DELETE | NOT_ESTABLISHED

CUSTOM ≠ REQUIRED.

Additional named dependencies requiring classification before promotion:

ContextualMemory        CANDIDATE
SiteTemplateAMCS        CANDIDATE
recipe_agent_platform   CANDIDATE
Qdrant                  CANDIDATE
Page Manager            REQUIRES_VALIDATION
Advanced Queue          REQUIRES_VALIDATION
orchestration module    CANDIDATE
modeler / modeler_api   CANDIDATE

10. Human Authority Policy

"Thomas Only" is not an architectural authorization primitive.

Standards promotion and high-authority decisions require a governed human-authority policy that can be transferred and is not tied to a personal identity.

Thomas currently holds the human authority role. That fact does not make thomas an architecture keyword.

Replace with:

HUMAN_AUTHORITY_REQUIRED=YES
CURRENT_AUTHORITY_HOLDER=   platform operator (Thomas Scola, 2026)
GOVERNANCE_PATH=            [defined in human authority policy]


11. Economic Law

Replace "zero technical debt" with measurable convergence targets.

For each milestone:

CUSTOM_LOC_BEFORE=
CUSTOM_LOC_AFTER=
CUSTOM_COMPONENTS_REMOVED=
UPSTREAM_COMPONENTS_ADOPTED=
CONFIG_REPLACEMENTS=
DUPLICATE_AUTHORITIES_REMOVED=
NEW_CUSTOM_CODE=
NET_CUSTOM_CODE=
NEXT_RUN_REUSE_GAIN=

Default target: NET_NEW_CUSTOM_CODE <= 0

Exception requires a demonstrated upstream/contrib/config gap — not a convenience preference.


12. Vertical Slice Requirement (Before Promotion)

Before expanding the product surface and before promoting this document, prove one complete vertical slice:

Target operation: Drupal Security & Release

Signal
  → ContextControl operation (entity created)
  → policy evaluation (Cedar / ContractPlane)
  → human approval IF policy requires it
  → canonical Bead (not a ContextControl-local work item)
  → Gas City routing / Order trigger
  → gc hook → atomic Bead claim
  → agent execution
  → GitLab MR + deterministic CI
  → WITNESS (independent verification)
  → merge / release
  → evidence receipt
  → ContextControl operation timeline updated
  → capability candidate recorded

Acceptance for promotion:

NO_DUPLICATE_WORK_AUTHORITY=YES
NO_DRUPAL_ORCHESTRATOR=YES
NO_CUSTOM_SCHEDULER=YES
CANONICAL_BEAD_USED=YES
SESSION_IDENTITY_RESOLVED=YES
POLICY_DECISION_RECORDED=YES
GITLAB_DELIVERY_PROVEN=YES
WITNESS_PROVEN=YES
CONTEXTCONTROL_TIMELINE_PROVEN=YES

13. Promotion Gate

STD_CC_001_STATUS=                    DRAFT
FACT_TARGET_CLASSIFICATION_COMPLETE=  NO — §4 API fields, §6 ContractPlane, §9 components
UPSTREAM_GAS_CITY_VERIFIED=           NO — integration pattern CANDIDATE, not tested
BEADS_INTERFACE_VERIFIED=             NO — projection pattern not yet implemented
CUSTOM_SURFACE_CLASSIFIED=            PARTIAL — components listed, dispositions not proven
DRUPAL_ORCHESTRATION_REMOVED=         NO — §5 rules stated; ECA flows not yet verified
CEDAR_CONTRACTPLANE_BOUNDARY=         NOT_ESTABLISHED
WITNESS_BOUNDARY=                     CORRECTED in §7 — not yet proven in practice
PLAUD_GOVERNANCE_FIXED=               STATED in §8 — implementation not verified
VERTICAL_SLICE_READY=                 NO
NET_NEW_CUSTOM_CODE=                  NOT_ESTABLISHED
WITNESS_RESULT=                       NOT_RUN
PROMOTION_READY=                      NO

Do not implement §12 recommendations. Do not mass-rename Beads based on this draft. Do not create new taxonomy layers.

Update this document (not a new one) as each classification is resolved. Promote to status: active only when PROMOTION_READY=YES.


Ref: Thomas Scola convergence directive 2026-09-30. Bead: bc-3nq9. Source document under convergence: products/ContextControl/ContextControl.ai/contextcontrol-technical-architecture-v2.md