DRAFT — NOT AUTHORITATIVE This document is directionally accepted but not yet promotion-ready. Every concrete implementation claim must be classified VERIFIED_CURRENT, TARGET, CANDIDATE, or NOT_ESTABLISHED before this becomes
status: active. Do not implement the recommendations in §12 until PROMOTION_READY=YES. Authority: Thomas Scola directive 2026-09-30.
STD-CC-001: ContextControl Factory Control Plane Architecture & Governance¶
1. Authority Boundaries (Accepted)¶
The central boundary is accepted. Each system is the canonical authority for its domain. ContextControl governs — it does not duplicate or replace.
GAS_CITY = ORCHESTRATION + EXECUTION + SESSION_STATE
BEADS / DOLT = DURABLE_WORK_AUTHORITY + DEPENDENCY_GRAPH
GITLAB = SOURCE + CI + DELIVERY + RELEASE_PROVENANCE
CONTEXTCONTROL = HUMAN_GOVERNANCE + PRODUCT_STATE + GOVERNED_UI
CEDAR = POLICY_DECISION_POINT (evaluation technology)
CONTRACTPLANE = CANDIDATE — see §6 for required boundary clarification
WITNESS = INDEPENDENT_VERIFICATION_ROLE — see §7
DRUPAL = HUMAN_CONTROL_PLANE + GOVERNANCE_UI + ENTITY_LIFECYCLE + LOCAL_ECA_REACTIONS
Canonical ownership by artifact type:
| Artifact | Canonical Owner | ContextControl Role |
|---|---|---|
| Work items, dependency graph | Beads / Dolt | Projects only — does not copy |
| Runtime / session state | Gas City | Reads events / state — does not duplicate |
| Source-controlled capability | GitLab | Reads provenance — does not re-store |
| Governed product state, timelines | ContextControl | Authoritative |
| Policy source / bindings | Governed source + ContextControl | Authoritative |
| Policy evaluation | Cedar / proven PDP | Delegate — does not re-implement |
| Evidence originals | Originating systems | ContextControl may project — not copy |
ContextControl may PROJECT external authority. Projection ≠ ownership.
Drupal MUST NOT become: - another work graph - another scheduler or agent runtime - another durable orchestration engine - another Beads database
2. The Six Authority Domains¶
ContextControl is the governance authority for six domains. It is not the physical storage system for all six.
- Execution & Delivery Substrate — Gas City executes; Beads tracks; GitLab delivers. ContextControl reads and projects, does not own runtime or work state.
- Control Plane & Agent Coordination — BLU coordinates.
BLU_ROUTES=YES, BLU_EXECUTES=NO. ContextControl surfaces agent registry and approval surfaces. - Discovery & Machine Contracts — DUADP provides federated discovery. OSSA defines portable agent schemas. ContextControl queries DUADP — does not duplicate discovery.
- Context & Knowledge Governance — Governed context (see §9 for custom surface classification). Vector storage via standard provider plugins rather than ad-hoc services.
- Tenancy, Authority & Assurance —
drupal/groupenforces entity-level multi-tenancy. Cedar evaluates policy. ContractPlane boundary per §6. - Human Governance & Presentation — Drupal Canvas + SDC render UI. Drupal is the human control plane. Drupal is not the orchestration engine.
3. Tenancy & Access Boundary¶
- Tenancy access MUST be enforced at the entity access handler layer (
hook_entity_access/EntityAccessControlHandler). - Views-only filtering, frontend query constraints, and hidden links are NOT valid access boundaries.
- Customer A must never retrieve Customer B context, operations, or receipts.
- Global or unscoped context is accessible only to authorized operators.
Multi-tenancy model: Organization (Group) → Workspace (Subgroup) → Project (Subgroup) → Team (Group role collection) via drupal/group + ggroup.
Classification: VERIFIED_CURRENT — group model confirmed as active implementation direction.
4. Integration with Factory Work Authority¶
Every Factory operation that touches ContextControl MUST trace to a canonical Bead. ContextControl projects Bead state — it does not store work items independently.
Receipt fields on ai_context_item for operations emitted to ContextControl:
field_record_kind: signal | operation | run | approval | decision |
finding | evidence | receipt | fact | constraint |
adr | lesson
field_model_cost: decimal(12,4) USD
field_infra_cost: decimal(12,4) USD
field_human_time: decimal(12,4) minutes
field_manual_time_avoided: decimal(12,4) minutes
field_reusable_capability: string
field_measurement_state: measured | partial | model_cost_not_measurable |
not_measurable
Classification of field schema: CANDIDATE — field names require verification against current ai_context module schema before canonizing.
Beads are durable, auditable work authority. Their current state evolves. Their history and evidence must remain attributable and auditable. Beads are NOT immutable.
The Dolt deployment address (127.0.0.1:3308/hq) is current Oracle topology, not product architecture. Do not encode deployment topology into this standard.
5. Non-Duplication Law (Binding)¶
- ContextControl MUST NOT implement its own agent scheduler or task queue that competes with Gas City Orders and Formulas.
- ContextControl MUST NOT store work items in a private database disconnected from Beads.
- ContextControl MUST NOT duplicate discovery; it queries DUADP.
- ContextControl MUST NOT author authorization logic in PHP; it evaluates Cedar policies.
- Drupal ECA MUST NOT own Convoys, durable multi-agent workflows, Factory reconciliation, agent scheduling, retry orchestration, or canonical work state.
Permitted Drupal ECA scope: - React to Drupal entity lifecycle events - Manage entity access and approval requirements - Invoke governed external capabilities (via Gas City, not direct agent calls) - Update local ContextControl projections - Notify humans - Enqueue Drupal-local processing
Required ECA pattern for cross-system work:
Drupal ECA event
→ governed invocation (Gas City API / Order trigger)
→ Beads (canonical work authority)
→ agent execution
→ event / evidence emitted
→ ContextControl projection updated
advancedqueue.enqueue_job may enqueue Drupal-local processing. Convoy reconciliation and durable multi-agent orchestration belong to Gas City / Beads, not Advanced Queue.
6. Cedar / ContractPlane Boundary (Requires Clarification)¶
Required before promotion:
CEDAR_ROLE= policy evaluation technology (ABAC / OPA-style)
CONTRACTPLANE_UNIQUE_ROLE= NOT_ESTABLISHED — must prove behavior beyond Cedar integration
POLICY_SOURCE_AUTHORITY= governed source + ContextControl (CANDIDATE)
POLICY_DECISION_POINT= Cedar (TARGET — not yet operational per v2 doc §0)
POLICY_ENFORCEMENT_POINT= hook_entity_access / EntityAccessControlHandler (VERIFIED_CURRENT)
ASSURANCE_ROLE= NOT_ESTABLISHED
ContractPlane exists as a Drupal module providing lightweight governance integration (policy evaluation, audit trail). Whether ContractPlane has unique architectural behavior beyond being a Cedar adapter is NOT_ESTABLISHED.
Rule: Do not preserve ContractPlane as a separate architectural box if it provides no proven unique behavior beyond Cedar integration. If it is only a Cedar adapter, it is an adapter — not a separate authority domain.
AUTHENTICATION ≠ AUTHORIZATION ≠ ASSURANCE
7. WITNESS Model (Corrected)¶
WITNESS is the independent verification role and process, not a product.
Visual testing (Dragonfly or other) provides evidence. It does not equal WITNESS.
deterministic tests
visual proof (Dragonfly, screenshot diff, etc.)
CI pipeline evidence
runtime behavioral evidence
policy evaluation evidence
↓
WITNESS
(independent verification)
↓
VERIFIED / FAILED / NOT_ESTABLISHED
WITNESS acceptance criteria must be typed to the work class. Not every Bead produces a GitLab MR. Research, governance, incident classification, and documentation Beads have different completion shapes. Completion criteria MUST include:
REQUESTED_EFFECT=
EVIDENCE=
INDEPENDENT_VERIFICATION= (where required by work class)
DEPENDENCY_STATE=
DELIVERY_STATE= (where applicable — code Beads only)
RECEIPT=
8. PLAUD / Voice Extraction Governance¶
Voice-extracted commitments are candidate work, not automatically canonical Beads.
A detected commitment may become a Bead only after:
CANONICAL_AUTHORITY=YES
DEDUP_COMPLETE=YES
ROUTING_CONTEXT_RESOLVED=YES
TRANSCRIPT_PROVENANCE=YES
Otherwise the output is: CANDIDATE_WORK pending review.
Mac-local / non-canonical Bead creation is NOT a fallback for PLAUD output.
9. Custom Code Surface (Under Convergence — Not Canonized)¶
The following custom components are the current surface. They are classified by convergence status, not assumed permanent.
Section title: Current Custom Surface Under Convergence — not "What and Only What Is Custom."
| Component | Current Purpose | Upstream/Contrib Equivalent | Disposition | Classification |
|---|---|---|---|---|
kb_cache |
Context memory API, semantic search bootstrap | ai_search + ai_context (contrib) |
REDUCE / CANDIDATE for replacement | CANDIDATE |
ai_context |
Governed context item storage | Contrib ai_context module |
VERIFY parity | CANDIDATE |
contextcontrol_theme / bluefly_theme |
SDC components, design tokens | Canvas + Drupal SDC (contrib-first) | KEEP_THIN_ADAPTER | CANDIDATE |
api_normalization |
OpenAPI → managed Drupal entities | No direct upstream equiv; ECK risk | KEEP_THIN_ADAPTER with ECK constraint | CANDIDATE |
ai_agents_ossa |
OSSA manifest support | OSSA spec (upstream contract) | KEEP — core pillar | VERIFIED_CURRENT |
duadp |
Agent discovery/registry | DUADP spec (upstream) | KEEP — core pillar | VERIFIED_CURRENT |
contractplane (Drupal module) |
Policy evaluation integration | Cedar (policy technology) | CANDIDATE per §6 | CANDIDATE |
Required per component before promotion:
CURRENT_PURPOSE=
CURRENT_CONSUMERS=
UPSTREAM_EQUIVALENT=
CONTRIB_EQUIVALENT=
CONFIG_EQUIVALENT=
PARITY=
UNIQUE_REQUIRED_BEHAVIOR=
DISPOSITION= KEEP_THIN_ADAPTER | REDUCE | REPLACE_WITH_UPSTREAM |
MOVE_TO_CONFIG | MOVE_TO_RECIPE | CONTRIBUTE_UPSTREAM |
DELETE | NOT_ESTABLISHED
CUSTOM ≠ REQUIRED.
Additional named dependencies requiring classification before promotion:
ContextualMemory CANDIDATE
SiteTemplateAMCS CANDIDATE
recipe_agent_platform CANDIDATE
Qdrant CANDIDATE
Page Manager REQUIRES_VALIDATION
Advanced Queue REQUIRES_VALIDATION
orchestration module CANDIDATE
modeler / modeler_api CANDIDATE
10. Human Authority Policy¶
"Thomas Only" is not an architectural authorization primitive.
Standards promotion and high-authority decisions require a governed human-authority policy that can be transferred and is not tied to a personal identity.
Thomas currently holds the human authority role. That fact does not make thomas an architecture keyword.
Replace with:
HUMAN_AUTHORITY_REQUIRED=YES
CURRENT_AUTHORITY_HOLDER= platform operator (Thomas Scola, 2026)
GOVERNANCE_PATH= [defined in human authority policy]
11. Economic Law¶
Replace "zero technical debt" with measurable convergence targets.
For each milestone:
CUSTOM_LOC_BEFORE=
CUSTOM_LOC_AFTER=
CUSTOM_COMPONENTS_REMOVED=
UPSTREAM_COMPONENTS_ADOPTED=
CONFIG_REPLACEMENTS=
DUPLICATE_AUTHORITIES_REMOVED=
NEW_CUSTOM_CODE=
NET_CUSTOM_CODE=
NEXT_RUN_REUSE_GAIN=
Default target: NET_NEW_CUSTOM_CODE <= 0
Exception requires a demonstrated upstream/contrib/config gap — not a convenience preference.
12. Vertical Slice Requirement (Before Promotion)¶
Before expanding the product surface and before promoting this document, prove one complete vertical slice:
Target operation: Drupal Security & Release
Signal
→ ContextControl operation (entity created)
→ policy evaluation (Cedar / ContractPlane)
→ human approval IF policy requires it
→ canonical Bead (not a ContextControl-local work item)
→ Gas City routing / Order trigger
→ gc hook → atomic Bead claim
→ agent execution
→ GitLab MR + deterministic CI
→ WITNESS (independent verification)
→ merge / release
→ evidence receipt
→ ContextControl operation timeline updated
→ capability candidate recorded
Acceptance for promotion:
NO_DUPLICATE_WORK_AUTHORITY=YES
NO_DRUPAL_ORCHESTRATOR=YES
NO_CUSTOM_SCHEDULER=YES
CANONICAL_BEAD_USED=YES
SESSION_IDENTITY_RESOLVED=YES
POLICY_DECISION_RECORDED=YES
GITLAB_DELIVERY_PROVEN=YES
WITNESS_PROVEN=YES
CONTEXTCONTROL_TIMELINE_PROVEN=YES
13. Promotion Gate¶
STD_CC_001_STATUS= DRAFT
FACT_TARGET_CLASSIFICATION_COMPLETE= NO — §4 API fields, §6 ContractPlane, §9 components
UPSTREAM_GAS_CITY_VERIFIED= NO — integration pattern CANDIDATE, not tested
BEADS_INTERFACE_VERIFIED= NO — projection pattern not yet implemented
CUSTOM_SURFACE_CLASSIFIED= PARTIAL — components listed, dispositions not proven
DRUPAL_ORCHESTRATION_REMOVED= NO — §5 rules stated; ECA flows not yet verified
CEDAR_CONTRACTPLANE_BOUNDARY= NOT_ESTABLISHED
WITNESS_BOUNDARY= CORRECTED in §7 — not yet proven in practice
PLAUD_GOVERNANCE_FIXED= STATED in §8 — implementation not verified
VERTICAL_SLICE_READY= NO
NET_NEW_CUSTOM_CODE= NOT_ESTABLISHED
WITNESS_RESULT= NOT_RUN
PROMOTION_READY= NO
Do not implement §12 recommendations. Do not mass-rename Beads based on this draft. Do not create new taxonomy layers.
Update this document (not a new one) as each classification is resolved. Promote to status: active only when PROMOTION_READY=YES.
Ref: Thomas Scola convergence directive 2026-09-30. Bead: bc-3nq9.
Source document under convergence: products/ContextControl/ContextControl.ai/contextcontrol-technical-architecture-v2.md