Governed Write Path

The return path into OT is intentionally narrow

ZenFactory does not demonstrate an uncontrolled agent on a PLC. An intervention emerges as a justified proposal and is executed only after policy check, human approval and controlled trial run.

End-to-end chain

STEP 1

Measurement

Machines provide states via OPC UA, Modbus and edge components.

STEP 2

Analysis

Historian, AAS, rules, ML and optimization calculate findings and options.

STEP 3

Proposal

The system formulates a proposal with Current State, Proposed State, Impact and Risk.

STEP 4

Policy Gate

Deterministic rules check safety, quality, energy, limits and allowed write points.

STEP 5

Human Approval

For relevant interventions, the human remains the decision maker.

STEP 6

Controlled Execution

Only approved actions run as a controlled trial with Canary and Watchdog.

STEP 7

Validation

Expected vs Actual is measured; rollback is possible if it deviates.

STEP 8

Audit Ledger

Decision, evidence, gate, approval, execution and effect are documented.

Multi-objective decision instead of automation

A proposal evaluates delivery, throughput, quality, OEE, energy, CO₂, tool wear, workload, asset condition and safety together. The UI shows alternatives and trade-offs so an approval remains understandable.

Example: reducing feed saves energy and tool wear, but can cost throughput. Moving work to ST030 relieves ST020, but increases utilization and energy elsewhere.

RoleMayBoundary
AI/LLMInterpretation, explanation, proposal generationNo direct machine approval
Policy GateSafety, quality, energy and write-point checkAuthoritative before execution
OperatorApproval, rejection, overrideDecision for interventions requiring approval
Edge/ExecutionExecution of permitted setpointsCanary, Watchdog, Rollback

One proposal, start to finish

This is how a single proposal moves through the chain — at ST020, the bottleneck of Line A. Limits and timings come from the policy file, the readings are a typical run.

StepWhat happens at ST020
1 · MeasurementST020, the bottleneck of Line A, reports OEE, tool wear and parts/h over an OPC UA subscription (250 ms).
2 · AnalysisThe Line A rule set finds a throughput gap: 81% of possible output at 2.3% scrap and 34% tool wear — confidence 0.90 after 60 minutes of observation, above the minimum threshold of 0.55.
3 · ProposalControlState.FeedOverride from 1.00 to 1.08 — the largest step the policy allows (max. 0.08). Expected: roughly +8% output.
4 · Policy GateST020 is a bottleneck station and counts among the allowed write points, the step stays within 0.88–1.14, 15 minutes of observation and 20 minutes since the last change are met, the value is not locked out.
5 · Human ApprovalThe operator sees Current State, Proposed State and the trade-off — more throughput against slightly more tool wear — and approves.
6 · Controlled ExecutionA 20-minute trial run begins, with a 4-minute grace period. The watchdog aborts immediately if scrap reaches 14.0% or OEE drops by 0.45 points.
7 · ValidationAfter 120 minutes the effect is measured. From 60% of the expected effect onward the new value stays, otherwise it reverts to 1.00.
8 · Audit LedgerDecision, proposal, approval, trial run and measured effect are recorded immutably in the ledger — traceable, which decision rested on which measurement.

The ZS-100 band saw never runs through this chain: it has no setpoint and no rule set, the control layer there can only measure — see Data paths.

View live control loop OT security architecture Resilience Lab