Short demo · 5 minutes · Technical tour · about 28 minutes

Experience ZenFactory step by step

This page has two entry points: a short decision story for the first impression and the full technical tour for the review afterwards. Data path, Policy Gate, human approval, trial run and evidence stay visible throughout.

Short demo Five minutes to the result
for first contact, management and procurement
  1. 01 Understand the situation 1 min 1,000 parts by 5 pm, tool wear at ST020 and a 70 kW limit. The demo starts with the trade-off, not a diagram. open →
  2. 02 Choose an option 1 min Reduce feed, shift part of the order, or change nothing: each option shows delivery, energy, tool life and risk side by side. open →
  3. 03 Who is in control 1 min Policy Gate and human approval stand in front of every write path. The software makes proposals, not covert machine commands. open →
  4. 04 Measure the effect 1 min Canary, watchdog and expected-vs-actual show whether the predicted effect is larger than the metric's noise. open →
  5. 05 Take the evidence 1 min The compact outcome report summarises goal, decision, effect, rollback and sources so it can be shared internally. open →
The short demo shows a reproducible scenario. The plant runs sped up; the protocols, database, asset administration shell, policy check and evidence chain are the vitrine's real system paths.

Technical tour

0/9

Progress stays local in this browser. The demo does not write anything to plants because of it.

Show now · step 01

The factory is running

Plant overview: five plants, two sites, all KPIs live.

2 min

What to say?

Five plant types under one model — a chained production line, a cell with five parallel machines, a filling line with collection tables, two batch reactors and a band saw from 1998 that only speaks Modbus. Each computes its own physics.

What does it prove?

This is not a backdrop with random numbers. Every number comes from a model that you can question and recompute.

Open this step

Interactive process · Industry 5.0 loop

Don’t read it — play it through

The animated packets show that data flows outward, while every path back through OT runs via Policy Gate, human approval, Canary and Watchdog. Click a phase and the metrics change with it.

OBSERVE
01 OPC UA sample 02 Sparkplug B 03 AAS twin 04 Policy Gate 05 Human approval 06 Canary window

MQTT

CONNECTED

Historian

WRITING

AAS

UPDATED

Policy

ARMED

Watchdog

ACTIVE

Ledger

SIGNED

Active state

ST020 reports tool wear

Vibration, spindle temperature and RUL flow into the semantic twin.

RUL 47 ± 8 min
Vibration +18 %
Power cap 70 kW

Mission Mode · technical challenge

Six tasks that make the demo verifiable

not a toy · a guided audit path

Progress

0/6

The status stays local in this browser. Nothing is written to the plant.

OPEN

Find the bottleneck

Open the plant overview and identify the asset with production impact.

Open
OPEN

Check the data path

Follow one measured value from shopfloor through edge, OT-DMZ and historian.

Open
OPEN

Evaluate an option

Compare reducing feed, moving work and making no change.

Open
OPEN

Read the Policy Gate

Check why Safety, Quality and Energy are evaluated separately.

Open
OPEN

Trigger resilience

Simulate a disturbance and inspect buffering, backfill and data loss.

Open
OPEN

Replay the audit

Reconstruct trigger, approval, execution and measured effect.

Open

Experience Industry 5.0 · Augsburg plant

From event to proven decision

Order: 1000 parts by 17:00. Initial state: OEE 84 %, energy forecast 182 kWh, CO₂ 71 kg, scrap 1.1 %. Then ST020 reports declining remaining tool life and the plant activates a 70 kW power limit.

Event 1

ST020 predicted tool degradation

RUL 47 ± 8 min · confidence 0.87

Event 2

Energy constraint activated

Plant power shall remain below 70 kW

Evidence

vibration RMS +18 % · spindle temp +7 %

classical analytics + policy threshold

Authority

AI creates proposals

Policies and safety logic remain authoritative

Alternatives instead of Approve/Reject

Three action options with trade-offs

Open control loop

Option A

Reduce ST020 feed by 8 %

Throughput -3,1 %

Peak Energy -11,8 %

Tool lifetime +14 %

Scrap risk -0,3 pp

The delivery deadline remains reachable, but the buffer until 17:00 shrinks.

Option B

Move part of the order to ST030

Throughput +1,8 %

Peak Energy +0,8 %

Tool lifetime ST020 +18 %

ST030 utilization +9 %

Better delivery performance, but higher utilization and more energy in the secondary path.

Option C

No change

Delivery risk +14 %

Peak Energy unchanged

Tool failure probability +22 %

Operator workload +1

No intervention, but rising risk of an unplanned tool change.

Policy Gate

Safetyonly approved setpoint limits PASS
Qualityscrap risk decreases in the canary window PASS
Energy70 kW limit is maintained PASS
Human approvalapproval required because production is affected WAITING

Controlled Execution

  1. 1Human Approval
  2. 2Canary
  3. 3Watchdog
  4. 4Execute
  5. 5Measure
  6. 6Validate
  7. 7Audit Ledger

Expected vs Actual · Decision verified

MetricExpectedActual
Peak Energy−18,0 %−16,9 %
Scrap−0.40 pp−0.35 pp
OEE−1,2 %−1,4 %
Deliveryon timeon time

Audit Event DEC-2026-000381: Trigger Tool degradation, Policy PASS, Human APPROVED, Execution SUCCESS, Rollback READY. In the showcase this is a reproducible scenario; in a real plant the same controlled write path remains in place.

Outcome Report

One decision, ready to share internally

DEC-2026-000381 · signed

Goal

1,000 parts by 5 pm, under 70 kW, no loss of quality

Decision

ST020 feed −8%, human approval, canary rather than immediate adoption

Result

Peak energy −16.9%, scrap −0.35 pp, delivery on time

Uncertainty

OEE −1.4%, within the expected band; small effects remain flagged as noise

Control

Watchdog active, rollback ready, no direct AI write access

Sources

AAS snapshot, historian window, Policy Gate, audit ledger

Audit Replay · reconstruct decision

Decision ID

DEC-2026-000381

Trigger

Tool degradation ST020 + energy constraint

Observations

vibration RMS +18 % · spindle temp +7 % · RUL 47 ± 8 min

Proposal

feed −8 %, partial move to ST030, tool change window 14:45

Policy evaluation

Safety PASS · Quality PASS · Energy PASS

Human decision

APPROVED

Execution

Canary → Watchdog → Execute → Measure → Validate

Actual result

Peak Energy −16.9 % · Scrap −0.35 pp · delivery on time

Rollback state

READY

OT Security Architect Review

Architecture review instead of just an architecture diagram

Direct IT → OT access

DENIED

no IT access to controllers

Broker / historian-facing

OT-DMZ

separated from the control network

AI direct write

NO

AI creates proposals, not commands

Policy before write-back

YES

deterministic before Human Approval

Canary / Watchdog

READY

controlled trial run with abort

Audit chain

INTACT

Hash-chained and reconstructable

open proposals 0 For step 6, a proposal must be open. The loop creates one itself as soon as the situation warrants it.
  1. 01

    The factory is running

    2 min Go there

    Show

    Plant overview: five plants, two sites, all KPIs live.

    Say

    Five plant types under one model — a chained production line, a cell with five parallel machines, a filling line with collection tables, two batch reactors and a band saw from 1998 that only speaks Modbus. Each computes its own physics.

    Proves

    This is not a backdrop with random numbers. Every number comes from a model that you can question and recompute.

  2. 02

    One number, its whole journey

    3 min Go there

    Show

    Plant page, hall view, then click a station.

    Say

    This station’s cycle time comes from the simulation, is offered over OPC UA, published by the edge gateway as Sparkplug B, written into TimescaleDB and kept in the digital twin under a standardised path. Five stations, no step skipped.

    Proves

    The chain is complete and carries real protocols — not a REST interface pretending to.

  3. 03

    The machine that cannot do OPC UA

    3 min Go there

    Show

    Cutting: the same plant page as before, the same KPIs — and below it the note that here things are only read.

    Say

    This band saw is from 1998. It speaks no OPC UA and never will; it has ten holding registers and an indicator lamp. What you see is calculated by a connector at its side from four counters and an operating mode — availability, performance, quality, OEE. In the AAS tree, in the historian and in this interface it is indistinguishable from the other four plants.

    Proves

    The most common objection is “my machines can’t do that”. They don’t have to. What they have to be able to do is count — and any machine can. What it cannot do is stated there too: this plant has no intervention button, because there is no write path.

  4. 04

    Trigger a fault

    3 min Go there

    Show

    The button here triggers a tool breakage at ST020. Then switch to the plant page. In the public showcase this is visible as a recorded state.

    Say

    The call goes through the OPC UA method InjectFault — the same way a third-party control system would have to go. Watch the buffer in front fill up and the stations behind starve.

    Proves

    The layers really are separate. And: buffers decouple — output collapses later than the station does, and that is exactly why the OEE of a line is not a simple multiplication.

  5. 05

    What the control loop makes of it

    4 min Go there

    Show

    Control-loop page, go through all four tabs.

    Say

    Four plants, one control loop. What differs is the domain knowledge: here the bottleneck, there the queue, there the back-pressure, there the exotherm. Every proposal states its reason, its assumption and the expected effect in numbers.

    Proves

    The expected effect is fixed beforehand. Without it, it could not be checked afterwards whether the proposal was good — you would have automation without learning.

  6. 06

    Approve a proposal

    4 min Go there

    Show

    Approve an open proposal and watch the trial run.

    Say

    Approved does not mean adopted. The value is run for a limited time, and afterwards the measured effect decides. The watchdog runs alongside the whole time and aborts without waiting for the end.

    Proves

    The difficult part is not the intervention but the proof that the forecasts are right. And that takes time: a trial run lasts two to six hours of plant time so that the effect stands out from the noise. At 20× time-lapse that is six to eighteen minutes — start it here and come back to it at step 9.

  7. 07

    The evidence

    3 min Go there

    Show

    Chain of evidence at the bottom of the page, plus the check at the top right.

    Say

    Every step is listed here: who, what, why, through which gate, with whose approval. Hash-chained and signed. The database rejects UPDATE, DELETE and TRUNCATE — whoever changes an entry breaks the chain from that point on, and the check names the number.

    Proves

    That is the argument a dashboard cannot make. And the precondition for an operator ever giving the software more freedom.

  8. 08

    Looking back

    2 min Go there

    Show

    Time travel: query the state at any point in time.

    Say

    No value is ever overwritten. The twin from two hours ago can be queried just like the one from now — and with it the situation on which a decision was based.

    Proves

    A decision can be reconstructed against exactly the state on which it was made. Without that, an evidence ledger is just a claim with a timestamp.

  9. 09

    Why the optimum is not at the limit

    4 min Go there

    Show

    Control-loop page and Industry 5.0 scenario: options, trade-offs and measured effect.

    Say

    In the reactor, the number of batches keeps rising up to 92 degrees. The number of saleable batches peaks at 88 and then collapses. Same runs, two answers. Then comes the part almost nobody shows: Policy Gate, canary run and Expected vs Actual show which effect can actually be proven.

    Proves

    Whoever optimises the wrong KPI drives into an emergency shutdown — which is why an optimiser without domain knowledge of the plant is dangerous. And whoever claims an effect smaller than the noise of their KPI claims nothing at all. The loop then says “indistinguishable” instead of “confirmed”.

What to expect

  • “Does it really run?” — Yes. The plant runs at 20× speed so that a shift can be shown in a quarter of an hour. Everything else is real: protocols, database, twin, evidence.
  • “Why is the loop proposing nothing right now?” — Because the situation does not warrant it. A loop that adjusts something at every opportunity is not one. The control-loop page gives the reason in plain language.
  • “And if the AI talks nonsense?” — It may do nothing without approval. After that it runs for a limited time, is measured, and goes back if the effect fails to appear. Autonomy is off, and the policy states what would have to happen for it to be up for debate.
  • “Why does it say for the cell that nothing is measurable?” — Because it is true. There the manipulated variable acts on one of five parallel machines, and the effect stays below the natural fluctuation. Writing that down openly is the difference between a measurement and a claim — and the most convincing argument of this demo.