Skip to content

Acquia Source × Bluefly: Demo Script & Events

Updated: 2026-04-25 | Status: Active | Owner: Thomas Scola

Production Requirement: An OSSA-compliant system MUST trace every action, attribute every cost, enforce every constraint, and expose every capability via contract.

Invariant: An agent that cannot be traced, cost-attributed, and constrained MUST NOT be deployed.


What the Demo Proves

Every demo across every event must prove these system properties — not features:

  1. Agents are independently addressable runtime services — each has a GAID, trace spans, cost attribution
  2. Capability binding is dynamically discovered via MCP — not preconfigured tool catalogs
  3. OAuth scopes map directly to capability binding — no ambient authority
  4. No central registry duplication exists — DUADP is the single discovery surface
  5. Every action is traced, every cost attributed, every constraint enforced — observable in real time

Demo constraint: The demo MUST NOT rely on preconfigured tool catalogs. Discovery is live via MCP + WebFinger.


The 24-Hour Demo (Acquia Pitch)

Two things to show. Nothing else.

Demo 1: ContextControl.ai — Shared Memory for Source Agents

Setup: Two Source sites in the same account. A chat agent running on Site A. A deployed agent running on Site B.

Script:

  1. On Site A — user chats with Source's AI assistant about their brand guidelines (colors, tone, audience). The agent stores this context via ContextControl.ai API.

    POST api.contextcontrol.ai/context
    {
      "scope": "account",
      "type": "brand_guidelines",
      "content": { "primary_color": "#1B3A5C", "tone": "professional", ... },
      "agent_gaid": "did:bluefly:agent:source-chat-a",
      "site_id": "site-a-uuid",
      "account_id": "acquia-account-uuid"
    }
    → Cedar evaluates: account scope, agent has write permission → ALLOW
    → Stored in Postgres + pgvector with GAID provenance
    → Cost attributed to agent source-chat-a
    → Trace span emitted: context_write, duration, policy_decision
    

  2. On Site B — a deployed content agent needs to generate a landing page. It queries ContextControl.ai for brand context.

    GET api.contextcontrol.ai/context?scope=account&type=brand_guidelines
    → Cedar evaluates: same account, agent has read permission → ALLOW
    → Returns brand guidelines created by Site A's chat agent
    → Trace span: context_read, cross-site, latency
    

  3. The punchline: "Your agents already work. They just can't remember anything or talk to each other. We give them a brain that works across your entire fleet — with permissions you control. Every read and write is traced, cost-attributed, and Cedar-gated."

Demo 2: Canvas Page Migration

Setup: A random public URL (government site, university page, competitor's landing page). A Source site with Bluefly's component library installed.

Script:

  1. Input the URL → Playwright scrapes the page, extracts content structure
  2. Component mapping → Content blocks mapped to Bluefly Canvas components (hero, nav, content sections, footer)
  3. Cedar policy check → Accessibility scan (WCAG), brand compliance, content governance
  4. Push to Source → canvas push deploys mapped components to the Source site
  5. Result → The random URL's content is now live in Source as governed Canvas components
  6. Trace output → Full trace: scrape → map → policy → push → provenance. Cost attributed. Every step auditable.

The punchline: "Every customer migration starts with 'take what I have and put it in Source.' We automate that. Governed. Accessible. One command. Full audit trail."


Denver Advisory Council

Audience: Dries Buytaert & Acquia Executive Leadership Objective: Prove Bluefly fills the governance gap for regulated Source customers

Core Message

"Source already ships AI agents. Those agents have no memory, no cross-site awareness, and no content migration path. Bluefly fills both gaps without touching Source internals — through your sanctioned surfaces only. Every agent action is traced, cost-attributed, and constrained."

Demo Script (3 Steps)

Step 1: Webhook → Constrained Reasoning Services via ECA - Simulate a content publish event in Source - Show ECA flow turning the event into orchestration (no custom webhook controller) - Show Component Factory agent + Content QA agent operating under bounded autonomy — execution limits, cost ceilings, Cedar constraints - Show trace spans for every decision cycle in real time

Step 2: MCP Server via WebFinger - Connect Claude Desktop to .well-known/webfinger for discovery - Ask Claude: "Scaffold a new Hero Component for Acquia Source" - Show that Source doesn't have an MCP server natively — Bluefly provides one - Capability binding is discovered dynamically — no preconfigured tool catalog - LLM discovers capabilities via standard MCP stack, generates Source-formatted code

Step 3: Cryptographic Deployment Proof - Let the constrained agent authorize deployment to local DDEV instance (Source-equivalent) - Show SHA3-256 hash output from HederaConsensusBridge - Show full trace: identity → policy → execution → cost → proof - "This is how we sell Source to DoD. Mathematical proof the AI didn't hallucinate a security flaw."

Strategic Context (From DA Partner Meeting)

  • Christoph Breidert: Dries' top product priority is "AI reviews of content (SEO, fact-checking, legal compliance)" — Bluefly delivers this externally
  • Molly Schoenberger: DCPs' #1 priority is "winning new business" — Bluefly enables regulated-market bids
  • Key positioning: "You are trying to build AI content reviews. As a Premier Partner, we already built the enterprise-grade implementation for Source."

Drupal AI Summit (New York)

Audience: Technical architects, AI developers, broader tech community Objective: Establish Bluefly as the leader in open-source AI governance + MCP engineering

Core Message

"We turned Acquia Source into a native MCP server. External LLMs can dynamically talk to Source — proving Drupal isn't just an AI-feature participant, it orchestrates the AI ecosystem. Every agent is an observable, governable, addressable runtime service."

Demo Focus

  • Universal MCP mesh interoperability (not just Drupal features)
  • ContextControl.ai as the cross-platform shared memory standard
  • OSSA manifests as the portable agent contract (identity, observability, cost governance, communication)
  • DUADP as vendor-neutral agent discovery
  • Kind enforcement: Agent vs Task vs Workflow separation live

Drupal Pivot (Cambridge, MA — May 27-28)

Audience: Agency CEOs (closed-door un-conference) Objective: Pitch Bluefly as a revenue multiplier for DCPs

Core Message

"You are losing enterprise bids because Source can't satisfy DoD/FedRAMP compliance natively. Bluefly's governance plane lets you sell Source into those markets. Every agent is traceable, cost-attributed, and constrained — the evidence package your CISO needs."

What Agencies Get Without OSSA

  • No traceability — who did what, when, why
  • No cost attribution — which agent spent how much
  • No safe deployment model — unbounded agents in production

Demo Focus

  • ContextControl.ai as a co-sellable service (recurring revenue for agencies)
  • Canvas migration as a service offering (project revenue)
  • Agent governance as the differentiator in RFP responses
  • OSSA + DUADP = no vendor lock-in (portable across Acquia, standalone Drupal, any platform)
  • Per-agent cost ceilings and audit export for procurement sign-off

Pre-Demo Blockers (Task List)

# Task Status Blocks
1 ContextControl.ai API — Fastify service with CRUD + pgvector + Cedar gates + trace spans Not started Demo 1
2 Canvas page migration — Playwright scraper + component mapper + cost attribution Not started Demo 2
3 Bluefly Canvas component library — React/JSX components for Source Partial Demo 2
4 Test data seeding — drupal-recipe-manager with sample components Not started Denver Steps 1-3
5 Fix Dragonfly COMPLIANCE_ENGINE_URL → compliance.drupl.ai Not started Denver Step 1
6 DDEV local Source-equivalent instance Partial Denver Step 3

Priority for 24-Hour Window

  1. ContextControl.ai API (Demo 1) — minimum viable: CRUD + scope-based Cedar + one pgvector query + trace spans
  2. Canvas migration proof (Demo 2) — minimum viable: one URL → component mapping → canvas push + audit record
  3. Everything else is narrative-only for the 24-hour window

Conference Timeline

Event Date Focus Audience
Acquia pitch Now (24-hour window) ContextControl.ai + Canvas migration Acquia leadership
Denver Advisory Council ~20 days out Full demo (webhook→agents, MCP, crypto proof) Dries + Council
Drupal AI Summit TBD (NYC) Universal MCP mesh, ContextControl.ai Technical community
Drupal Pivot May 27-28 (Cambridge) Agency revenue model, co-sell pitch Agency CEOs

Same architecture at every event. No re-architecture between milestones. If Denver demo can't evolve directly to pilot without redesign, the plan is wrong.