Governed Write Path
The return path into OT is intentionally narrow
ZenFactory does not demonstrate an uncontrolled agent on a PLC. An intervention emerges as a justified proposal and is executed only after policy check, human approval and controlled trial run.
End-to-end chain
STEP 1
Measurement
Machines provide states via OPC UA, Modbus and edge components.
STEP 2
Analysis
Historian, AAS, rules, ML and optimization calculate findings and options.
STEP 3
Proposal
The system formulates a proposal with Current State, Proposed State, Impact and Risk.
STEP 4
Policy Gate
Deterministic rules check safety, quality, energy, limits and allowed write points.
STEP 5
Human Approval
For relevant interventions, the human remains the decision maker.
STEP 6
Controlled Execution
Only approved actions run as a controlled trial with Canary and Watchdog.
STEP 7
Validation
Expected vs Actual is measured; rollback is possible if it deviates.
STEP 8
Audit Ledger
Decision, evidence, gate, approval, execution and effect are documented.
Multi-objective decision instead of automation
A proposal evaluates delivery, throughput, quality, OEE, energy, CO₂, tool wear, workload, asset condition and safety together. The UI shows alternatives and trade-offs so an approval remains understandable.
Example: reducing feed saves energy and tool wear, but can cost throughput. Moving work to ST030 relieves ST020, but increases utilization and energy elsewhere.
| Role | May | Boundary |
|---|---|---|
| AI/LLM | Interpretation, explanation, proposal generation | No direct machine approval |
| Policy Gate | Safety, quality, energy and write-point check | Authoritative before execution |
| Operator | Approval, rejection, override | Decision for interventions requiring approval |
| Edge/Execution | Execution of permitted setpoints | Canary, Watchdog, Rollback |
One proposal, start to finish
This is how a single proposal moves through the chain — at ST020, the bottleneck of Line A. Limits and timings come from the policy file, the readings are a typical run.
| Step | What happens at ST020 |
|---|---|
| 1 · Measurement | ST020, the bottleneck of Line A, reports OEE, tool wear and parts/h over an OPC UA subscription (250 ms). |
| 2 · Analysis | The Line A rule set finds a throughput gap: 81% of possible output at 2.3% scrap and 34% tool wear — confidence 0.90 after 60 minutes of observation, above the minimum threshold of 0.55. |
| 3 · Proposal | ControlState.FeedOverride from 1.00 to 1.08 — the largest step the policy allows (max. 0.08). Expected: roughly +8% output. |
| 4 · Policy Gate | ST020 is a bottleneck station and counts among the allowed write points, the step stays within 0.88–1.14, 15 minutes of observation and 20 minutes since the last change are met, the value is not locked out. |
| 5 · Human Approval | The operator sees Current State, Proposed State and the trade-off — more throughput against slightly more tool wear — and approves. |
| 6 · Controlled Execution | A 20-minute trial run begins, with a 4-minute grace period. The watchdog aborts immediately if scrap reaches 14.0% or OEE drops by 0.45 points. |
| 7 · Validation | After 120 minutes the effect is measured. From 60% of the expected effect onward the new value stays, otherwise it reverts to 1.00. |
| 8 · Audit Ledger | Decision, proposal, approval, trial run and measured effect are recorded immutably in the ledger — traceable, which decision rested on which measurement. |
The ZS-100 band saw never runs through this chain: it has no setpoint and no rule set, the control layer there can only measure — see Data paths.