Skip to content

Acquia Source × Bluefly: 6-Week Pilot Proposal

Updated: 2026-04-25 | Status: Active | Owner: Thomas Scola

Production Requirement: An OSSA-compliant system MUST trace every action, attribute every cost, enforce every constraint, and expose every capability via contract.

Invariant: An agent that cannot be traced, cost-attributed, and constrained MUST NOT be deployed.


Terms

Engagement Fixed-price services pilot
Investment $75,000 USD
Duration 6 weeks (30 business days)
Post-pilot $14K/mo Control Plane + DUADP subscription (optional)
Risk $0 license fee. If pilot doesn't deliver measurable value, no obligation.

Governance Guarantees

This pilot enforces:

  • Per-agent cost ceilings — every agent has a maxCostPerDay constraint; cost attributed per execution via trace spans
  • Full audit traceability — every action traced with GAID provenance, Cedar policy decision logged, exportable as compliance evidence
  • Role-based agent separation — worker (Component Factory), validator (Content QA), orchestrator (Release Orchestrator) — no role conflation
  • Compliance tagging — SOC2, HIPAA, FedRAMP, NIST AI RMF evidence generated automatically per Cedar policy decision
  • Bounded autonomy — all agents operate under maxRuntimeSeconds, maxSteps, abort-on-timeout constraints
  • Fail-closed verification — Dragonfly validates every output before delivery; unreachable = blocked

Without OSSA

  • No traceability — no per-agent audit trail, no provenance
  • No cost attribution — no ceiling enforcement, no per-execution metering
  • No safe deployment model — unbounded agents running unverified output into production
  • No compliance evidence — manual documentation, no exportable artifacts

What Gets Delivered

Three Agents, Fully Governed

Agent What It Does Source Surfaces Used Kind
Component Factory Scaffolds React/JSX Canvas components from design specs. Generates tests, docs, accessibility report. Pushes via Canvas CLI. Canvas CLI, JSON:API Agent (bounded autonomy, LLM-backed)
Content QA + A11y Gate Intercepts content publish. Runs WCAG checks (axe-core). Enforces brand compliance. Blocks non-compliant content. JSON:API, Webhooks Agent (bounded autonomy, LLM-backed)
Release Orchestrator Webhook-driven deploy pipeline. Triggers GitLab CI. Validates OSSA manifests. Gates production push on Cedar policy. Webhooks, Canvas CLI, OAuth Workflow (orchestration only, no LLM)

Each agent gets: - OSSA manifest with identity (service_name, service_namespace, service_version, service_instance_id) - GAID (DID identity) registered in DUADP - Cedar policies (deny-by-default) - Execution constraints (maxRuntimeSeconds: 300, maxSteps: 50, timeoutStrategy: abort) - Cost tracking (maxCostPerDay ceiling, per-execution metering) - Observability (tracing: enabled, metrics: enabled — REQUIRED) - Failure model (retryable: timeout, rate_limited; fatal: policy_deny, identity_invalid, cost_ceiling_exceeded) - Dragonfly behavioral tests (fail-closed) - Idempotent commands (default) - ContractPlane A2H approval workflow for regulated content

ContextControl.ai Integration

  • Shared memory layer operational across pilot sites
  • Agents store and retrieve context via Cedar-gated API
  • Cross-site context federation demonstrated
  • Permission model configured (per-site, per-account, per-agent)
  • Every context read/write traced with GAID provenance and cost attribution

Canvas Migration Proof

  • At least one URL migrated to Source as Canvas components
  • Component mapping documented
  • Cedar policy validation on every migrated component
  • Full audit trail: scrape → map → policy → push → provenance

Infrastructure

Component Where What
Private DUADP node Customer cloud (K8s, 3-node HA) DNS TXT + WebFinger + DID + Cedar + federation
Control Plane dashboard Oracle (Bluefly-hosted) OSSA registry, fleet dashboard, policy management
ContextControl.ai Oracle (Bluefly-hosted) Fastify + Postgres + pgvector
Cedar PDP Per-domain on Oracle Policy evaluation (deny-by-default)
Dragonfly Oracle Fail-closed output verification
GitLab CI GitLab.com SaaS Manifest validation, policy gates, canvas push
ContractPlane Oracle A2H approval workflows, audit evidence

Compliance Artifacts

  • Immutable audit trail (append-only, cryptographically signed)
  • Evidence collection for FedRAMP, HIPAA, SOX, NIST AI RMF, ISO 42001
  • Compliance report templates
  • GAID provenance on every agent action
  • Per-agent cost attribution reports

Week-by-Week

Weeks 1-2: Foundation

Week 1: Discovery session (2hr). DUADP node deployment (K8s). Control Plane setup (Keycloak SSO). Source OAuth clients created. Webhook receivers configured. Architecture docs delivered.

Week 2: Cedar policy framework (4 trust tiers: Public/Internal/Restricted/Confidential). DID issuance for 3 agents. Audit + compliance infrastructure. Dragonfly integration. Security hardening (TLS 1.3, network policies, secret management). Security audit.

Exit criteria: DUADP node DNS-resolvable. Control Plane accessible. 3 agents registered with DIDs and unique service_instance_id. Cedar policies enforcing trust tiers. Audit logging capturing all policy decisions. Observability (tracing + metrics) operational for all agents.

Weeks 3-4: Integration & Agents

Week 3: Source ↔ Bluefly integration (Canvas CLI plugin, GitLab CI pipeline, webhook triggers). Agent 1 (Component Factory) built, tested, deployed with bounded autonomy constraints. ContextControl.ai integration for Agent 1.

Week 4: Agent 2 (Content QA + A11y Gate) built and deployed. Agent 3 (Release Orchestrator) built as Workflow kind (no LLM, orchestration only). Cross-agent workflows tested. Canvas migration proof completed.

Exit criteria: 3 agents operational through Source extension surfaces. Kind enforcement validated (Agent vs Workflow). Canvas component created and pushed via governed pipeline. Content blocked by Cedar policy for non-compliance. ContextControl.ai storing and retrieving cross-agent context. One URL migrated to Source as Canvas components. All agents emitting trace spans and cost metrics.

Weeks 5-6: Hardening & Handoff

Week 5: Load testing (100 concurrent agent operations). Failure mode testing (Dragonfly fail-closed, Cedar deny cascades, cost ceiling exceeded, timeout abort). Compliance evidence generation. Performance tuning.

Week 6: Production readiness review. Documentation package (architecture, runbooks, troubleshooting, training). Knowledge transfer (2 sessions). Executive demo. Transition planning to production.

Exit criteria: All success metrics met. Documentation complete. Team trained. Executive demo delivered. Production transition plan agreed. Compliance evidence package exported.


Success Metrics

Metric Target
Time to validate + publish OSSA manifest to DUADP < 15 minutes
High-risk actions requiring Cedar approval 100%
Denied publishes producing verifiable audit logs 100% (exportable JSON)
Source modifications visible in Control Plane 100%
CISO can export compliance evidence package Yes
ContextControl.ai cross-site context retrieval Working across 2+ sites
Canvas page migration from URL At least 1 complete migration
Per-agent cost attribution Metered and reportable
Trace spans emitted per decision cycle 100%
Execution bounds enforced (timeout, max steps) Verified via failure mode testing

Commercial Products (Post-Pilot)

Product Price Target Buyer
Source AgentOps Accelerator $75K–$200K one-time + retainer VP Digital / WebOps
Managed DUADP Node $4K–$12K/mo + setup CISO / Platform Eng
Control Plane SaaS $1.8K–$15K/mo (tiered) Platform Eng / Security
Agent Blu SourceOps Pack $2K–$8K/mo add-on Marketing Ops / WebOps
ContextControl.ai Included with Control Plane or standalone Platform Eng

Template Factory Revenue

Offering Price Range
Template creation $30K–$80K project
Template maintenance $3K–$8K/mo retainer
Component library license Per-component or enterprise
Migration to Source $50K–$150K
Multi-brand deployment $5K–$15K/site
Compliance packages (FedRAMP/508) $20K–$40K

Vertical Templates Available

  • gov-starter: FedRAMP-ready, 508-compliant, USWDS tokens, mega nav, alert banners
  • higher-ed: University template, branded sections, program finder
  • healthcare: HIPAA-aware components, patient portal hooks
  • enterprise: Multi-brand support, generic enterprise layout

All Canvas React/JSX + Tailwind + Vite + GitLab CI. Validate → Build → Policy Gate → Push pipeline.


Resource Requirements

Bluefly Team

Role Allocation Responsibility
Platform Architect (Thomas) 50% Architecture, Cedar policies, OSSA manifests, executive comms
Senior Developer 100% Source connector, agents, CI pipelines, ContextControl.ai
DevOps Engineer 50% DUADP deployment, K8s, monitoring, security
QA Engineer 25% Dragonfly tests, compliance validation

Customer Team

Role Allocation Responsibility
Source Product Owner 10% Requirements, acceptance, demos
Source Developer 20% API access, webhook configuration, Canvas testing
Security/Compliance 5% Cedar policy review, audit validation
Executive Sponsor 2% Steering meetings, go/no-go decisions

Risk Mitigation

Risk Mitigation
Source API limitations All integrations validated against live Source subscription (UUID 8ddc1cee, expires Oct 2026)
Cedar policy complexity Start with 4 trust tiers, expand based on customer needs
Dragonfly instability P0 fix before pilot starts; fail-open fallback documented
Customer engagement Daily standups, weekly steering, executive sponsor required
Scope creep Fixed-price SOW, change orders for out-of-scope work
Unbounded agent behavior Execution constraints enforced: maxRuntimeSeconds, maxSteps, cost ceilings

Why Acquia Should Co-Sell This

  • Higher-margin regulated accounts stay on Source instead of choosing competitors
  • Partner-led delivery — Acquia doesn't build or maintain governance
  • Customer gets portable manifests, verifiable identity, policy enforcement, CI-driven delivery
  • Source becomes the governed platform of choice for FedRAMP, HIPAA, DoD
  • Open-standard approach (OSSA/DUADP) — no proprietary lock-in for Acquia or customers
  • 700+ Acquia partners as potential distribution channel
  • Every agent is observable, governable, addressable — the production standard Acquia's built-in agents don't meet