STD-DRUPAL-AI-001: Drupal AI Initiative Architecture & Net-Negative Ownership Policy¶
Status: Approved Governing Standard
Owner: Bluefly Engineering / DrupalWorks
Beads: bc-6m1b, bc-qysf, bc-5o48
1. Prime Directive¶
Bluefly owns composition and consumption — not unnecessary custom code.
We follow a strict net-negative ownership policy: 1. Core → Contrib → Recipes → Canvas/SDC → ECA/FlowDrop → Drupal AI → Tool API/MCP → only then custom code as a last resort. 2. If an upstream project, module, or recipe already provides a capability (agent execution, tool bridging, RAG search, recipe validation, security audit), Bluefly projects MUST configure or contribute to the upstream project. 3. Custom PHP scripts, hand-crafted bash parser formulas, and custom agent runtimes are forbidden when an upstream Contrib module exists.
2. Upstream 6-Stage Outside AI Roadmap Alignment¶
All Bluefly agentic Drupal operations follow the upstream Drupal AI Initiative roadmap (git.drupalcode.org/project/ai_initiative, work item 3576908):
Stage 1: Supported Drupal Baseline (drupal_cms_ai recipe)
↓
Stage 2: Scoped Attributable Authority (simple_oauth + mcp_server_oauth)
↓
Stage 3: Machine-Readable Site Discovery (Tool API / OpenAPI)
↓
Stage 4: Governed Operations (Tool API + Tool Belt + mcp_server)
↓
Stage 5: Verification & Observability (WITNESS + Drupal AI Observability)
↓
Stage 6: Drupal-Native Recipes & Handoff (drush recipe)
Stage 4 Execution Law (Governed Interfaces)¶
- Tool API (
drupal/tool) & Tool Belt (drupal/tool_belt) are the sole governed execution surfaces for Drupal capabilities. - MCP Server (
drupal/mcp_server) is the mandatory external transport bridge for STDIO and HTTP MCP agents (Claude Code, Cursor, external LLM agents). - No synthetic users or role mutation: Actions run as the authenticated person or bounded service identity.
3. Canonical 10-Layer Package Baseline¶
All Bluefly Drupal projects inherit this composition stack:
| Layer | Upstream Capability Owner | Package(s) |
|---|---|---|
| 1. Baseline | Drupal CMS AI Recipe | drupal/drupal_cms_ai |
| 2. Drupal AI | Drupal AI Core & Agents | drupal/ai, drupal/ai_agents, drupal/ai_agents_debugger, drupal/ai_agents_ossa, drupal/ai_context, drupal/ai_dashboard, drupal/ai_integration_eca, drupal/ai_policy_gateway |
| 3. Providers | LLM Provider Modules | drupal/ai_provider_openai, drupal/ai_provider_anthropic, drupal/ai_provider_ollama |
| 4. Tool API | Executable Capability Engine | drupal/tool, drupal/tool_belt |
| 5. MCP Transport | External Agent Transport | drupal/mcp_server, drupal/mcp_tools |
| 6. Canvas / UI | Modern Component Builder | drupal/canvas, drupal/canvas_builder, drupal/canvas_ai_seo, drupal/ai_playwright |
| 7. Workflow | Event Automation & Modeler | drupal/eca, drupal/ai_integration_eca, drupal/modeler_api, drupal/modeler, drupal/bpmn_io, drupal/flowdrop, drupal/flowdrop_ai_search, drupal/orchestration |
| 8. Search / RAG | Semantic Search API | drupal/search_api, drupal/ai_search, drupal/ai_search_block, drupal/ai_vdb_provider_qdrant |
| 9. Infrastructure | Key & Metadata | drupal/key, drupal/metatag, drupal/simple_sitemap |
| 10. Performance | SDC Critical CSS | drupal/sdc_critical_css, drupal/non_critical_css |
Explicit Exclusions¶
drupal/ai_loggingis EXCLUDED. Use Drupal AI's native AI Observability submodule for PSR-3/OpenTelemetry integration.- Legacy
drupal/mcpis DEPRECATED. Migrate todrupal/mcp_server.
4. Package Resolution Discipline¶
{
"minimum-stability": "alpha",
"prefer-stable": true
}