Skip to content

Acquia Source × Bluefly: Strategy

Updated: 2026-04-25 | Status: Active | Owner: Thomas Scola

Production Requirement: An OSSA-compliant system MUST trace every action, attribute every cost, enforce every constraint, and expose every capability via contract.

Invariant: An agent that cannot be traced, cost-attributed, and constrained MUST NOT be deployed.


OSSA is a Control Plane, Not a Framework

OSSA does not execute agents.

It defines: identity, observability, cost governance, and communication contracts.

Frameworks (LangGraph, CrewAI, AutoGen) become execution engines beneath OSSA. Agents are observable, governable, addressable runtime services — not conceptual entities.


Why Existing Agent Frameworks Fail in Production

They lack: - Per-agent identity (no GAID, no DID, no verifiable provenance) - Cost attribution (no per-execution metering, no ceiling enforcement) - Auditability (no trace spans, no policy decision logs, no signed evidence) - Enforceable constraints (no Cedar, no execution bounds, no fail-closed verification)

They produce behavior, not systems. OSSA is the layer above them.


The Pitch (24-Hour Version)

Acquia Source is a locked-down SaaS CMS. No custom modules. No server access. Extension only through OAuth 2.0, JSON:API, Webhooks, and Canvas CLI.

Bluefly provides two things Source can't build itself:

  1. ContextControl.ai — Shared Memory for Source Agents. Constrained reasoning services running inside Source (chat, deployed, or external) can store context, retrieve context, and share it across multiple Source sites in the same account or across separate accounts. Permission-controlled via Cedar policies. This is the missing "brain" that makes Source agents useful across a fleet.

  2. Canvas Page Migration. Take any URL, extract its content and structure, and migrate it into a Source site as Canvas components using Bluefly's component library. Automated. Governed. Accessible.

Why this matters for Acquia: Source already ships AI agents (Dec 2025). Those agents have no memory, no cross-site awareness, and no way to migrate content in. Bluefly fills both gaps without touching Source internals.


Hard Constraints (Non-Negotiable)

  1. Zero custom code inside Acquia Source unless explicitly escalated and approved. Default: forbidden.
  2. Only four sanctioned surfaces: OAuth 2.0, JSON:API, Webhooks, Canvas CLI. No fifth category.
  3. ECA + Cedar only for on-platform orchestration on the governed Drupal site. No parallel orchestrators.
  4. Contrib-first: Before any custom PHP, audit ECA, Webhooks, JSON:API Extras, Key, Tool API, and MCP Client. Custom PHP = stop and escalate.
  5. One architecture across all milestones: Demo → Conference → Pilot → Production. If the pilot requires re-architecture from the demo, the plan is wrong.

Bounded Autonomy

Agents operate under: - Cost limits (per-execution and per-day ceilings) - Capability binding (only tools explicitly declared in OSSA manifest) - Execution limits (max runtime, max steps, abort on timeout) - Policy enforcement (Cedar deny-by-default, Dragonfly fail-closed)

Unbounded agents are not production-safe.


Architecture

Acquia Source (SaaS — untouched)
  ├── OAuth 2.0 → scoped tokens per lane (governance / app / CI)
  ├── JSON:API → content CRUD (nodes, media, taxonomy, users, menus)
  ├── Webhooks → publish/update/delete events → Bluefly
  └── Canvas CLI → component push (React/JSX)

Bluefly Governance Plane (external)
  ├── ContextControl.ai → shared memory (Fastify + Postgres + pgvector)
  │   ├── ai_context entities with Cedar-gated access
  │   ├── Cross-site context federation
  │   └── Permission model: per-site, per-account, per-agent
  ├── ContractPlane.ai → Cedar policy evaluation + A2H approval
  ├── DUADP → agent discovery (DNS TXT + WebFinger + DID)
  ├── OSSA CLI → manifest validation + lifecycle
  ├── Dragonfly → output verification (fail-closed)
  └── GitLab CI → validate → build → policy gate → deploy

Canvas Migration Pipeline (new)
  ├── URL → scrape/extract (headless browser)
  ├── Content → map to Canvas component schemas
  ├── Components → Cedar policy check (a11y, brand, compliance)
  └── Validated → canvas push to Source site

Key architectural decision: Source's authorization is scope-driven, not Drupal roles. The "creating components with AI" docs confirm that role permissions for the OAuth author user are ignored. Governance MUST sit above Source scopes (Cedar + DUADP), not rely on Drupal role semantics.


What Acquia Gets

  • Standards-backed agent governance that complements Source without competing
  • Cross-site memory layer their agents currently lack
  • Content migration pipeline (URL → Source) that accelerates customer onboarding
  • Co-sellable regulated-enterprise solution (FedRAMP, HIPAA, NIST AI RMF)
  • Open-standard governance (OSSA/DUADP) — no proprietary lock-in

What Bluefly Gets

  • Reference customer and proof point for the platform
  • Services revenue ($75K+ per pilot)
  • Subscription revenue (Control Plane + DUADP node + ContextControl.ai)
  • Access to 700+ Acquia partners as distribution channel
  • Validation of the OSSA/DUADP/ContextControl stack in production

Competitive Reality

Acquia already ships AI agents inside Source (site building, writing, governance agents — Dec 2025). Drupal ecosystem has ai_agents framework and ai_agents_ossa import module. Bluefly's differentiation is NOT "AI agents for Source" — that's Acquia's territory.

Bluefly's wedge: cross-system governance, vendor-neutral portability, shared memory across sites, compliance evidence, and content migration — things Acquia is structurally unlikely to build for multi-platform ecosystems.

Key Finding: No existing framework provides per-agent identity, enforced observability, or cost governance. They are orchestration libraries, not infrastructure. OSSA is the only model defining agents as infrastructure components.


Document Index

Doc What It Covers
01-STRATEGY.md (this) Position, constraints, architecture, competitive context
02-TECHNICAL-SPEC.md Integration surfaces, built vs needed, compliance matrix
03-DEMO-AND-EVENTS.md 24-hour demo script, Denver, AI Summit, Pivot conference
04-PILOT-PROPOSAL.md 6-week SOW, agents, deliverables, commercial terms
05-RESEARCH-REFERENCE.md All research findings, citations, API details