Acquia Source × Bluefly: 6-Week Pilot Proposal¶
Updated: 2026-04-25 | Status: Active | Owner: Thomas Scola
Production Requirement: An OSSA-compliant system MUST trace every action, attribute every cost, enforce every constraint, and expose every capability via contract.
Invariant: An agent that cannot be traced, cost-attributed, and constrained MUST NOT be deployed.
Terms¶
| Engagement | Fixed-price services pilot |
| Investment | $75,000 USD |
| Duration | 6 weeks (30 business days) |
| Post-pilot | $14K/mo Control Plane + DUADP subscription (optional) |
| Risk | $0 license fee. If pilot doesn't deliver measurable value, no obligation. |
Governance Guarantees¶
This pilot enforces:
- Per-agent cost ceilings — every agent has a
maxCostPerDayconstraint; cost attributed per execution via trace spans - Full audit traceability — every action traced with GAID provenance, Cedar policy decision logged, exportable as compliance evidence
- Role-based agent separation — worker (Component Factory), validator (Content QA), orchestrator (Release Orchestrator) — no role conflation
- Compliance tagging — SOC2, HIPAA, FedRAMP, NIST AI RMF evidence generated automatically per Cedar policy decision
- Bounded autonomy — all agents operate under
maxRuntimeSeconds,maxSteps, abort-on-timeout constraints - Fail-closed verification — Dragonfly validates every output before delivery; unreachable = blocked
Without OSSA¶
- No traceability — no per-agent audit trail, no provenance
- No cost attribution — no ceiling enforcement, no per-execution metering
- No safe deployment model — unbounded agents running unverified output into production
- No compliance evidence — manual documentation, no exportable artifacts
What Gets Delivered¶
Three Agents, Fully Governed¶
| Agent | What It Does | Source Surfaces Used | Kind |
|---|---|---|---|
| Component Factory | Scaffolds React/JSX Canvas components from design specs. Generates tests, docs, accessibility report. Pushes via Canvas CLI. | Canvas CLI, JSON:API | Agent (bounded autonomy, LLM-backed) |
| Content QA + A11y Gate | Intercepts content publish. Runs WCAG checks (axe-core). Enforces brand compliance. Blocks non-compliant content. | JSON:API, Webhooks | Agent (bounded autonomy, LLM-backed) |
| Release Orchestrator | Webhook-driven deploy pipeline. Triggers GitLab CI. Validates OSSA manifests. Gates production push on Cedar policy. | Webhooks, Canvas CLI, OAuth | Workflow (orchestration only, no LLM) |
Each agent gets:
- OSSA manifest with identity (service_name, service_namespace, service_version, service_instance_id)
- GAID (DID identity) registered in DUADP
- Cedar policies (deny-by-default)
- Execution constraints (maxRuntimeSeconds: 300, maxSteps: 50, timeoutStrategy: abort)
- Cost tracking (maxCostPerDay ceiling, per-execution metering)
- Observability (tracing: enabled, metrics: enabled — REQUIRED)
- Failure model (retryable: timeout, rate_limited; fatal: policy_deny, identity_invalid, cost_ceiling_exceeded)
- Dragonfly behavioral tests (fail-closed)
- Idempotent commands (default)
- ContractPlane A2H approval workflow for regulated content
ContextControl.ai Integration¶
- Shared memory layer operational across pilot sites
- Agents store and retrieve context via Cedar-gated API
- Cross-site context federation demonstrated
- Permission model configured (per-site, per-account, per-agent)
- Every context read/write traced with GAID provenance and cost attribution
Canvas Migration Proof¶
- At least one URL migrated to Source as Canvas components
- Component mapping documented
- Cedar policy validation on every migrated component
- Full audit trail: scrape → map → policy → push → provenance
Infrastructure¶
| Component | Where | What |
|---|---|---|
| Private DUADP node | Customer cloud (K8s, 3-node HA) | DNS TXT + WebFinger + DID + Cedar + federation |
| Control Plane dashboard | Oracle (Bluefly-hosted) | OSSA registry, fleet dashboard, policy management |
| ContextControl.ai | Oracle (Bluefly-hosted) | Fastify + Postgres + pgvector |
| Cedar PDP | Per-domain on Oracle | Policy evaluation (deny-by-default) |
| Dragonfly | Oracle | Fail-closed output verification |
| GitLab CI | GitLab.com SaaS | Manifest validation, policy gates, canvas push |
| ContractPlane | Oracle | A2H approval workflows, audit evidence |
Compliance Artifacts¶
- Immutable audit trail (append-only, cryptographically signed)
- Evidence collection for FedRAMP, HIPAA, SOX, NIST AI RMF, ISO 42001
- Compliance report templates
- GAID provenance on every agent action
- Per-agent cost attribution reports
Week-by-Week¶
Weeks 1-2: Foundation¶
Week 1: Discovery session (2hr). DUADP node deployment (K8s). Control Plane setup (Keycloak SSO). Source OAuth clients created. Webhook receivers configured. Architecture docs delivered.
Week 2: Cedar policy framework (4 trust tiers: Public/Internal/Restricted/Confidential). DID issuance for 3 agents. Audit + compliance infrastructure. Dragonfly integration. Security hardening (TLS 1.3, network policies, secret management). Security audit.
Exit criteria: DUADP node DNS-resolvable. Control Plane accessible. 3 agents registered with DIDs and unique service_instance_id. Cedar policies enforcing trust tiers. Audit logging capturing all policy decisions. Observability (tracing + metrics) operational for all agents.
Weeks 3-4: Integration & Agents¶
Week 3: Source ↔ Bluefly integration (Canvas CLI plugin, GitLab CI pipeline, webhook triggers). Agent 1 (Component Factory) built, tested, deployed with bounded autonomy constraints. ContextControl.ai integration for Agent 1.
Week 4: Agent 2 (Content QA + A11y Gate) built and deployed. Agent 3 (Release Orchestrator) built as Workflow kind (no LLM, orchestration only). Cross-agent workflows tested. Canvas migration proof completed.
Exit criteria: 3 agents operational through Source extension surfaces. Kind enforcement validated (Agent vs Workflow). Canvas component created and pushed via governed pipeline. Content blocked by Cedar policy for non-compliance. ContextControl.ai storing and retrieving cross-agent context. One URL migrated to Source as Canvas components. All agents emitting trace spans and cost metrics.
Weeks 5-6: Hardening & Handoff¶
Week 5: Load testing (100 concurrent agent operations). Failure mode testing (Dragonfly fail-closed, Cedar deny cascades, cost ceiling exceeded, timeout abort). Compliance evidence generation. Performance tuning.
Week 6: Production readiness review. Documentation package (architecture, runbooks, troubleshooting, training). Knowledge transfer (2 sessions). Executive demo. Transition planning to production.
Exit criteria: All success metrics met. Documentation complete. Team trained. Executive demo delivered. Production transition plan agreed. Compliance evidence package exported.
Success Metrics¶
| Metric | Target |
|---|---|
| Time to validate + publish OSSA manifest to DUADP | < 15 minutes |
| High-risk actions requiring Cedar approval | 100% |
| Denied publishes producing verifiable audit logs | 100% (exportable JSON) |
| Source modifications visible in Control Plane | 100% |
| CISO can export compliance evidence package | Yes |
| ContextControl.ai cross-site context retrieval | Working across 2+ sites |
| Canvas page migration from URL | At least 1 complete migration |
| Per-agent cost attribution | Metered and reportable |
| Trace spans emitted per decision cycle | 100% |
| Execution bounds enforced (timeout, max steps) | Verified via failure mode testing |
Commercial Products (Post-Pilot)¶
| Product | Price | Target Buyer |
|---|---|---|
| Source AgentOps Accelerator | $75K–$200K one-time + retainer | VP Digital / WebOps |
| Managed DUADP Node | $4K–$12K/mo + setup | CISO / Platform Eng |
| Control Plane SaaS | $1.8K–$15K/mo (tiered) | Platform Eng / Security |
| Agent Blu SourceOps Pack | $2K–$8K/mo add-on | Marketing Ops / WebOps |
| ContextControl.ai | Included with Control Plane or standalone | Platform Eng |
Template Factory Revenue¶
| Offering | Price Range |
|---|---|
| Template creation | $30K–$80K project |
| Template maintenance | $3K–$8K/mo retainer |
| Component library license | Per-component or enterprise |
| Migration to Source | $50K–$150K |
| Multi-brand deployment | $5K–$15K/site |
| Compliance packages (FedRAMP/508) | $20K–$40K |
Vertical Templates Available¶
- gov-starter: FedRAMP-ready, 508-compliant, USWDS tokens, mega nav, alert banners
- higher-ed: University template, branded sections, program finder
- healthcare: HIPAA-aware components, patient portal hooks
- enterprise: Multi-brand support, generic enterprise layout
All Canvas React/JSX + Tailwind + Vite + GitLab CI. Validate → Build → Policy Gate → Push pipeline.
Resource Requirements¶
Bluefly Team¶
| Role | Allocation | Responsibility |
|---|---|---|
| Platform Architect (Thomas) | 50% | Architecture, Cedar policies, OSSA manifests, executive comms |
| Senior Developer | 100% | Source connector, agents, CI pipelines, ContextControl.ai |
| DevOps Engineer | 50% | DUADP deployment, K8s, monitoring, security |
| QA Engineer | 25% | Dragonfly tests, compliance validation |
Customer Team¶
| Role | Allocation | Responsibility |
|---|---|---|
| Source Product Owner | 10% | Requirements, acceptance, demos |
| Source Developer | 20% | API access, webhook configuration, Canvas testing |
| Security/Compliance | 5% | Cedar policy review, audit validation |
| Executive Sponsor | 2% | Steering meetings, go/no-go decisions |
Risk Mitigation¶
| Risk | Mitigation |
|---|---|
| Source API limitations | All integrations validated against live Source subscription (UUID 8ddc1cee, expires Oct 2026) |
| Cedar policy complexity | Start with 4 trust tiers, expand based on customer needs |
| Dragonfly instability | P0 fix before pilot starts; fail-open fallback documented |
| Customer engagement | Daily standups, weekly steering, executive sponsor required |
| Scope creep | Fixed-price SOW, change orders for out-of-scope work |
| Unbounded agent behavior | Execution constraints enforced: maxRuntimeSeconds, maxSteps, cost ceilings |
Why Acquia Should Co-Sell This¶
- Higher-margin regulated accounts stay on Source instead of choosing competitors
- Partner-led delivery — Acquia doesn't build or maintain governance
- Customer gets portable manifests, verifiable identity, policy enforcement, CI-driven delivery
- Source becomes the governed platform of choice for FedRAMP, HIPAA, DoD
- Open-standard approach (OSSA/DUADP) — no proprietary lock-in for Acquia or customers
- 700+ Acquia partners as potential distribution channel
- Every agent is observable, governable, addressable — the production standard Acquia's built-in agents don't meet