Acquia Source × Bluefly: Demo Script & Events¶
Updated: 2026-04-25 | Status: Active | Owner: Thomas Scola
Production Requirement: An OSSA-compliant system MUST trace every action, attribute every cost, enforce every constraint, and expose every capability via contract.
Invariant: An agent that cannot be traced, cost-attributed, and constrained MUST NOT be deployed.
What the Demo Proves¶
Every demo across every event must prove these system properties — not features:
- Agents are independently addressable runtime services — each has a GAID, trace spans, cost attribution
- Capability binding is dynamically discovered via MCP — not preconfigured tool catalogs
- OAuth scopes map directly to capability binding — no ambient authority
- No central registry duplication exists — DUADP is the single discovery surface
- Every action is traced, every cost attributed, every constraint enforced — observable in real time
Demo constraint: The demo MUST NOT rely on preconfigured tool catalogs. Discovery is live via MCP + WebFinger.
The 24-Hour Demo (Acquia Pitch)¶
Two things to show. Nothing else.
Demo 1: ContextControl.ai — Shared Memory for Source Agents¶
Setup: Two Source sites in the same account. A chat agent running on Site A. A deployed agent running on Site B.
Script:
-
On Site A — user chats with Source's AI assistant about their brand guidelines (colors, tone, audience). The agent stores this context via ContextControl.ai API.
POST api.contextcontrol.ai/context { "scope": "account", "type": "brand_guidelines", "content": { "primary_color": "#1B3A5C", "tone": "professional", ... }, "agent_gaid": "did:bluefly:agent:source-chat-a", "site_id": "site-a-uuid", "account_id": "acquia-account-uuid" } → Cedar evaluates: account scope, agent has write permission → ALLOW → Stored in Postgres + pgvector with GAID provenance → Cost attributed to agent source-chat-a → Trace span emitted: context_write, duration, policy_decision -
On Site B — a deployed content agent needs to generate a landing page. It queries ContextControl.ai for brand context.
GET api.contextcontrol.ai/context?scope=account&type=brand_guidelines → Cedar evaluates: same account, agent has read permission → ALLOW → Returns brand guidelines created by Site A's chat agent → Trace span: context_read, cross-site, latency -
The punchline: "Your agents already work. They just can't remember anything or talk to each other. We give them a brain that works across your entire fleet — with permissions you control. Every read and write is traced, cost-attributed, and Cedar-gated."
Demo 2: Canvas Page Migration¶
Setup: A random public URL (government site, university page, competitor's landing page). A Source site with Bluefly's component library installed.
Script:
- Input the URL → Playwright scrapes the page, extracts content structure
- Component mapping → Content blocks mapped to Bluefly Canvas components (hero, nav, content sections, footer)
- Cedar policy check → Accessibility scan (WCAG), brand compliance, content governance
- Push to Source →
canvas pushdeploys mapped components to the Source site - Result → The random URL's content is now live in Source as governed Canvas components
- Trace output → Full trace: scrape → map → policy → push → provenance. Cost attributed. Every step auditable.
The punchline: "Every customer migration starts with 'take what I have and put it in Source.' We automate that. Governed. Accessible. One command. Full audit trail."
Denver Advisory Council¶
Audience: Dries Buytaert & Acquia Executive Leadership Objective: Prove Bluefly fills the governance gap for regulated Source customers
Core Message¶
"Source already ships AI agents. Those agents have no memory, no cross-site awareness, and no content migration path. Bluefly fills both gaps without touching Source internals — through your sanctioned surfaces only. Every agent action is traced, cost-attributed, and constrained."
Demo Script (3 Steps)¶
Step 1: Webhook → Constrained Reasoning Services via ECA - Simulate a content publish event in Source - Show ECA flow turning the event into orchestration (no custom webhook controller) - Show Component Factory agent + Content QA agent operating under bounded autonomy — execution limits, cost ceilings, Cedar constraints - Show trace spans for every decision cycle in real time
Step 2: MCP Server via WebFinger
- Connect Claude Desktop to .well-known/webfinger for discovery
- Ask Claude: "Scaffold a new Hero Component for Acquia Source"
- Show that Source doesn't have an MCP server natively — Bluefly provides one
- Capability binding is discovered dynamically — no preconfigured tool catalog
- LLM discovers capabilities via standard MCP stack, generates Source-formatted code
Step 3: Cryptographic Deployment Proof
- Let the constrained agent authorize deployment to local DDEV instance (Source-equivalent)
- Show SHA3-256 hash output from HederaConsensusBridge
- Show full trace: identity → policy → execution → cost → proof
- "This is how we sell Source to DoD. Mathematical proof the AI didn't hallucinate a security flaw."
Strategic Context (From DA Partner Meeting)¶
- Christoph Breidert: Dries' top product priority is "AI reviews of content (SEO, fact-checking, legal compliance)" — Bluefly delivers this externally
- Molly Schoenberger: DCPs' #1 priority is "winning new business" — Bluefly enables regulated-market bids
- Key positioning: "You are trying to build AI content reviews. As a Premier Partner, we already built the enterprise-grade implementation for Source."
Drupal AI Summit (New York)¶
Audience: Technical architects, AI developers, broader tech community Objective: Establish Bluefly as the leader in open-source AI governance + MCP engineering
Core Message¶
"We turned Acquia Source into a native MCP server. External LLMs can dynamically talk to Source — proving Drupal isn't just an AI-feature participant, it orchestrates the AI ecosystem. Every agent is an observable, governable, addressable runtime service."
Demo Focus¶
- Universal MCP mesh interoperability (not just Drupal features)
- ContextControl.ai as the cross-platform shared memory standard
- OSSA manifests as the portable agent contract (identity, observability, cost governance, communication)
- DUADP as vendor-neutral agent discovery
- Kind enforcement: Agent vs Task vs Workflow separation live
Drupal Pivot (Cambridge, MA — May 27-28)¶
Audience: Agency CEOs (closed-door un-conference) Objective: Pitch Bluefly as a revenue multiplier for DCPs
Core Message¶
"You are losing enterprise bids because Source can't satisfy DoD/FedRAMP compliance natively. Bluefly's governance plane lets you sell Source into those markets. Every agent is traceable, cost-attributed, and constrained — the evidence package your CISO needs."
What Agencies Get Without OSSA¶
- No traceability — who did what, when, why
- No cost attribution — which agent spent how much
- No safe deployment model — unbounded agents in production
Demo Focus¶
- ContextControl.ai as a co-sellable service (recurring revenue for agencies)
- Canvas migration as a service offering (project revenue)
- Agent governance as the differentiator in RFP responses
- OSSA + DUADP = no vendor lock-in (portable across Acquia, standalone Drupal, any platform)
- Per-agent cost ceilings and audit export for procurement sign-off
Pre-Demo Blockers (Task List)¶
| # | Task | Status | Blocks |
|---|---|---|---|
| 1 | ContextControl.ai API — Fastify service with CRUD + pgvector + Cedar gates + trace spans | Not started | Demo 1 |
| 2 | Canvas page migration — Playwright scraper + component mapper + cost attribution | Not started | Demo 2 |
| 3 | Bluefly Canvas component library — React/JSX components for Source | Partial | Demo 2 |
| 4 | Test data seeding — drupal-recipe-manager with sample components |
Not started | Denver Steps 1-3 |
| 5 | Fix Dragonfly COMPLIANCE_ENGINE_URL → compliance.drupl.ai |
Not started | Denver Step 1 |
| 6 | DDEV local Source-equivalent instance | Partial | Denver Step 3 |
Priority for 24-Hour Window¶
- ContextControl.ai API (Demo 1) — minimum viable: CRUD + scope-based Cedar + one pgvector query + trace spans
- Canvas migration proof (Demo 2) — minimum viable: one URL → component mapping → canvas push + audit record
- Everything else is narrative-only for the 24-hour window
Conference Timeline¶
| Event | Date | Focus | Audience |
|---|---|---|---|
| Acquia pitch | Now (24-hour window) | ContextControl.ai + Canvas migration | Acquia leadership |
| Denver Advisory Council | ~20 days out | Full demo (webhook→agents, MCP, crypto proof) | Dries + Council |
| Drupal AI Summit | TBD (NYC) | Universal MCP mesh, ContextControl.ai | Technical community |
| Drupal Pivot | May 27-28 (Cambridge) | Agency revenue model, co-sell pitch | Agency CEOs |
Same architecture at every event. No re-architecture between milestones. If Denver demo can't evolve directly to pilot without redesign, the plan is wrong.