Edge perception
8–24 synchronised line-scan cameras per machine. Sub-100 ms defect classification, sub-250 ms break-risk updates. [ASPIRATIONAL design targets]
Pulpum has three layers: a GPU mill-edge node that sees the web in real time, an orchestrator that plans and arbitrates between agents, and a policy engine that decides what may actually be written to the DCS. The digital twin sits alongside all three, rehearsing every move first.
Live example: Grade change PM4 · 135 gsm kraftliner → 110 gsm testliner, no break, ≤14 min off-spec
Perceive, plan, simulate, act, verify, log, learn. Every Pulpum run walks the same seven stages regardless of which agent owns it.
Line-scan and IR cameras, QCS scans, DCS tags, lab results and web-monitoring signals are ingested at the mill edge and time-aligned to the reel.
The orchestrator turns the declared goal into a typed step graph, assigns each step to an agent, and marks which steps need a human.
Candidate recipes run on the as-run twin — forming, press, dryer, calender — and are ranked on off-spec tonnes, break risk and energy.
Each write passes the policy engine: tag allow-list, rate and magnitude limits, autonomy level, interlock state, operator presence.
The next QCS scan and the vision stream confirm the move landed. If it did not, the step is retried, revised or escalated.
Request, reasoning, limits applied, human decisions and results are appended to a hash-chained audit log the mill owns.
Break events, operator corrections and rejected recommendations become training data for the site-specific model.
Not a dashboard, not an alert — a run. It has a goal, a plan, an owner, a duration, an audit trail and an outcome.
Mill Orchestrator — Pulled the 110 gsm testliner spec, customer tolerances and the standing energy budget from mill MES; locked the target envelope for the run.
Mill Orchestrator — Simulated 48 candidate transition recipes on the as-run paper-machine twin — forming, press, dryer and calender — and ranked them on off-spec tonnes, break risk and steam.
Pulp-and-Stock — Stepped refiner specific edge load 1.9 → 1.4 Ws/m and pushed freeness toward 412 CSF while consistency held at 3.4%.
Wetend-and-Chemistry — Retention aid trimmed to 214 g/t and sizing to 1.1 kg/t against live charge and turbidity; first-pass retention recovered to 78% inside 90 seconds.
Form-and-Press — Re-cut the slice profile across 78 actuators and set jet-to-wire to 0.994 to hold formation index through the basis-weight ramp.
Form-and-Press — Nip load reduced 620 → 540 kN/m to protect the lighter web; post-press dryness landed at 47.1%.
Dry-and-Coat — Re-phased the steam schedule across 6 dryer groups and rebalanced the hood; reel moisture converged to 7.4% ±0.19 2σ at 6.1% less steam than the standing recipe.
Defect-and-Inspect — 18 line-scan cameras streaming; two edge-crack precursors detected at the drive side and cleared by a 40 kN/m nip trim before either propagated.
Mill Orchestrator — Speed ramp 1,180 → 1,245 m/min exceeded the site autonomy threshold. Held for the machine tender; approved by J. Okonkwo at 04:57:12.
Quality-and-Conformance — Reel R-24188 released: full genealogy written (furnish, chemistry, CD profiles, defect map, operator actions) and checked against grade spec.
Every tool invocation, argument and result is written to an immutable, human-readable log — and every reasoning step is expandable. Nothing about a run is hidden from the mill.
Plan → thought → action → observation, exactly as the orchestrator recorded it.
Move PM4 from 135 gsm kraftliner to 110 gsm testliner with zero breaks and under 14 minutes of off-spec production.
Simulate the transition on the twin first. Lead with stock and chemistry so the furnish is right before the basis weight ramps, then trim forming and press, then re-phase drying. Watch the web continuously; hold the speed ramp for a human.
The standing recipe drops basis weight and speed together. On the twin that produces a 3-minute moisture excursion because the dryer section unloads faster than the steam schedule can follow. Sequencing the steam re-phase ahead of the basis-weight ramp removes it.
twin.simulate(candidates=48) → recipe #31 re-phases steam 40 s before the basis-weight ramp and holds nip load until post-press dryness confirms.
Recipe #31 estimates 6.4 t off-spec against 9.8 t for the standing recipe, with break risk 0.07. Two candidates scored lower on steam but raised break risk above the 0.15 site limit and were discarded.
Execute recipe #31 under autonomy level L3: nine setpoint writes permitted, speed ramp routed to the machine tender.
Edge-crack precursor at 1,412 mm drive side at 04:56:41. Nip trim of −40 kN/m in press-2 cleared it in 16 s without a break.
Run complete in 11 m 42 s. 6.2 t off-spec, zero breaks, 6.1% less dryer steam than the standing recipe. Reel R-24188 released with full genealogy.
Paper moves 20 metres a second. Anything that has to make a decision about the web has to make it locally, deterministically, and in under 100 milliseconds.
A twin built from the machine drawing is a marketing asset. A twin continuously corrected against this week's reels is a control tool.
Paper moves at 1,200 metres a minute. Perception has to be local, deterministic and fast, so Pulpum runs GPU inference at the mill edge and keeps training, simulation and optimisation in the cloud or on-prem.
8–24 synchronised line-scan cameras per machine. Sub-100 ms defect classification, sub-250 ms break-risk updates. [ASPIRATIONAL design targets]
Vision, time-series prognostics, grade embeddings and process reasoning behind one orchestrator, with deterministic rollback by model version.
Defect vision, break precursors, wet-end response and drying models trained on reel genealogy, QCS histories and operator corrections.
GPU-accelerated CFD, drying and web-dynamics simulation of the as-run machine — 10–100 candidate recipes evaluated per grade change.
Rare break, contamination, wrinkle and formation-upset variants generated and always validated against real mill events before promotion.
Grade-change sequencing, dryer energy allocation, machine-speed balancing and maintenance windows under production and energy constraints.
A mill does not go from manual to unattended in one step. Pulpum makes the level explicit, auditable and reversible at any time.
| Level | What the agent does | What the human does | Typical time to reach |
|---|---|---|---|
| L1 · Advisory | Recommends setpoints and explains why | Enters every change manually | Week 1 |
| L2 · Supervised | Proposes a write; it executes on approval | Approves each write in the HMI | Week 3–6 |
| L3 · Bounded | Writes inside tag, rate and magnitude limits | Approves ramps and grade releases | Month 2–4 |
| L4 · Unattended | Runs the envelope without prompting | Sets the envelope; reviews the shift record | Month 6+ [ASPIRATIONAL] |
Two agents will want the same actuator. The orchestrator arbitrates on the run goal, not on who asked first — and the handoff is logged like any other step.
Form-and-Press wants to hold nip load to protect post-press dryness.
Defect-and-Inspect wants to reduce nip load to clear an edge-crack precursor.
Break risk 0.62 outranks a 0.4-point dryness loss under the run goal "zero breaks". Defect-and-Inspect wins the actuator for 120 s.
Actuator returned; Form-and-Press recovers dryness with vacuum instead. Post-press dryness lands at 47.1%.
Each agent owns a section of the mill, a bounded tool set, and a measured outcome. They negotiate for shared actuators through the orchestrator — never directly.
Pulping, refining, screening, stock prep
Holds freeness, fiber length and consistency on target across furnish swings — recovered fiber, virgin kraft, or blends — by closing the loop on refiner load, specific edge load and dilution.
±4 CSF held on 92% of reels
Retention, sizing, charge, additives
Doses retention aid, sizing, starch and defoamer against live charge, turbidity and first-pass retention instead of a fixed recipe — cutting chemistry cost and wet-end upsets.
11% lower additive spend
Headbox, forming, press section
Trims slice profile, jet-to-wire ratio, vacuum and nip load to hit formation and post-press dryness before the web ever reaches the dryer section.
+1.4 pts post-press dryness
Dryer section, coating, calendering
Schedules steam pressure, hood balance, blade load and calender nip to hit moisture, caliper and gloss at the lowest energy per tonne.
7.9% less dryer steam
Web inspection, break precursors
Fuses line-scan vision and web-monitoring to classify holes, wrinkles, spots, streaks and edge cracks in under 100 ms — and flags break precursors before the sheet goes.
68% of breaks predicted >90 s early
Basis weight, moisture, caliper CD profiles
Runs CD profile control across the full actuator set, keeping 2-sigma inside grade spec through speed changes and grade transitions.
2σ moisture 0.31 → 0.19
Yield, broke, energy, grade sequencing
Sequences grade changes, balances machine speed against dryer capacity, and prices every candidate move in tonnes, broke and megajoules.
−22% grade-change waste
Reel, winder and roll handling
Drives reel turn-up, winder set changes, roll wrapping and clamp-truck routing so finishing never starves or blocks the machine.
3.1 h/shift of manual handling removed
Right-first-time, genealogy, traceability
Builds the reel genealogy record — furnish, chemistry, profiles, defects, operator actions — and gates release against grade spec and standards.
99.2% release records complete
Planning, arbitration, human approval
Plans the run, arbitrates between agents competing for the same actuator, enforces autonomy level and routes anything above the risk threshold to a human.
100% of writes policy-checked
Composite pilot results across design-partner machines [ASPIRATIONAL].
Figures are design targets and pilot-scoped results [ASPIRATIONAL]. Every number is reproduced from the mill's own reel genealogy, not our telemetry.
The Pulpum SDK is typed Python. Tools are declared with schemas and limits; the policy engine enforces them at call time — not in a review meeting.
# Bound the dryer agent to six steam groups on PM4.
from pulpum import Agent, Tool, Limit, Autonomy
steam = Tool(
name="dcs.steam_schedule",
tags=["PM4.DRY.G1..G6.PRESS_SP"],
limits=[Limit(max_step="0.15 bar", per="30s")],
)
dryer = Agent(
id="agent.dry_coat",
goal="reel moisture 7.4% +/-0.5, min steam",
tools=[steam, Tool("qcs.read_moisture", read_only=True)],
# bounded writes; humans still gate ramps
autonomy=Autonomy.L3,
# simulate on the twin before every write
verify="twin",
)
run = dryer.start(machine="PM4", grade="TL-110")
for step in run.stream():
print(step.name, step.status, step.duration)
The same run engine, the same policy checks, the same audit trail — from the terminal, the HMI or the SDK.
$ pulpum run "grade change PM4 to TL-110" --autonomy L3
→ plan composed 10 steps · 1 approval gate
→ twin.simulate 48 candidates · best #31 · risk 0.07
→ policy.evaluate 9 writes permitted · 1 held for human
→ executing stock.refine ... ok 2m10s
→ executing wetend.dose .... ok 1m26s
→ executing form.headbox ... ok 1m05s
→ executing dry.steam ...... ok 3m18s
! approval required speed_ramp 1180 → 1245 m/min
→ approved J. Okonkwo · machine tender · 04:57:12
→ run complete 11m42s · off-spec 6.2 t · breaks 0
$ pulpum runs show run_8f21c4 --format genealogy
Autonomy earns trust one shift at a time. These are design-partner quotes from pilot deployments [ASPIRATIONAL].
"The first thing that convinced the crew wasn't the control — it was the log. You can scroll back and see exactly why it dropped the nip. Nobody argues with a timestamp."
Machine tender · PM4 · Nordkraft Mills
"We had two people who could do a clean 135-to-110 transition. One retired in March. The twin now does the sequencing and the second one supervises it."
Production manager · Aurora Board
"Break prediction was the wedge. Ninety seconds of warning is the difference between a nip trim and four hours of threading."
Process engineer · Ternvik Paper
Pulpum reads and writes through the systems already on the floor. No rip-and-replace, no parallel historian, no new HMI to learn.
Valmet IQ, ABB 800xA QCS, Honeywell Experion MX
Profiles, scans, lab results
ABB 800xA, Valmet DNA, Honeywell Experion, Siemens PCS 7
Setpoint reads and guarded writes
WIS/WMS line-scan, IR and transmission cameras
Frames, defect maps, break replays
SAP PP/QM, ABB cpmPlus, custom historians
Orders, grades, reel genealogy
OSIsoft PI, Aspen IP.21, InfluxDB
Time-series backfill and replay
NVIDIA Isaac, winder and wrapper PLCs
Reel, roll and clamp-truck motion
Azure AD, Okta, on-prem LDAP
SSO, RBAC, named approvers
NVIDIA Jetson Orin, IGX, on-prem GPU
Sub-100 ms inference at the machine
Pulpum writes to production equipment. Every capability is scoped, every write is policy-checked, and every action is written to an append-only audit log the mill owns.
| Standard | Scope | Status |
|---|---|---|
| SOC 2 Type II | Cloud control plane | RUNNING In progress [ASPIRATIONAL] |
| ISO 27001 | Company-wide ISMS | QUEUED Planned [ASPIRATIONAL] |
| IEC 62443 | Mill-edge OT security | RUNNING Design-aligned |
| GDPR | Operator data | SUCCEEDED Compliant |
| ISO 9001 / FSC | Quality + chain of custody records | SUCCEEDED Supported |
One policy model, one audit trail, one benchmark across every machine in every mill — with the grade and furnish models kept private to each site.
The questions mill managers and process engineers actually ask in the first meeting.
Yes, but only within an explicit tag allow-list with per-tag rate and magnitude limits, and only at the autonomy level your site has set. Level 1 is advisory-only: Pulpum recommends and a human enters everything. Most mills spend their first weeks there before enabling supervised writes.
Control returns to the DCS last known-good state within one scan cycle. Pulpum is designed as a supervisory layer on top of your existing control system, never as a replacement for it, so a Pulpum outage degrades the mill to its current way of running — not to a stop.
Break prediction and defect classification typically need 8 to 12 weeks of QCS, DCS and inspection history per grade family, plus labelled break events. Advisory recommendations start in week one from the physics-based twin, and improve as mill-specific history accumulates.
Only if you choose cloud training. Recipes, grade models and defect libraries are tenant-isolated and never used to train another customer's models. A fully on-prem deployment with an air-gapped mill edge is available for sensitive producers.
You are, the same as with any control strategy — which is why every write is policy-checked, bounded, logged and reversible, and why anything above your risk threshold waits for a named approver. The audit log records the request, the reasoning, the limits applied and the human decision.
A 90 to 120 day mill-edge deployment on one paper machine, scoped to a single workflow with a pre-agreed baseline [ASPIRATIONAL]. Weeks 1–3 are connection and shadow-mode observation; weeks 4–8 advisory; weeks 9+ supervised or bounded writes if the mill is satisfied with the recommendations.
Start with one paper machine and one measurable baseline. A 90-day mill-edge pilot on break prediction, drying energy or moisture profile shows the number before you commit further.
↑↓ navigate↵ openesc close