Building the business case
How to model off-spec reduction, break avoidance and steam margin against a measured 90-day baseline instead of a vendor claim.
Evaluating a supervisory autonomy layer means answering finance, operations, IT and safety in the same week. These are the documents that answer each of them.
Live example: Grade change PM4 · 135 gsm kraftliner → 110 gsm testliner, no break, ≤14 min off-spec
Written for a specific reader, not for a persona.
How to model off-spec reduction, break avoidance and steam margin against a measured 90-day baseline instead of a vendor claim.
A walkthrough of each agent's scope, the tags it may touch and the verification it runs before writing.
Network segmentation, tag allow-lists, scan alignment, fallback behaviour and what happens when the edge node dies.
Where data lives, what leaves the mill, how identity works and how the audit log is protected.
How reel-level records map to ISO, TAPPI and FEFCO methods and what an auditor sees.
A short, plain-language guide to recommendations, approvals, overrides and how to make the system stop.
Short artefacts you can actually finish in a meeting.
Enter machine speed, trim, grade mix and change frequency to estimate current off-spec tonnage and a target range.
Translate break frequency and duration into annual lost tonnes and steam, per machine.
Estimate the energy value of tightening moisture 2σ before moving the mean.
The twenty things that have to be true before a mill-edge install is worth scheduling.
How to define a defensible 90-day baseline both sides will accept at reconciliation.
Pre-filled answers to the standard OT security questions, ready for your IT reviewer.
Every guide refers back to this run so the numbers stay comparable.
Mill Orchestrator — Pulled the 110 gsm testliner spec, customer tolerances and the standing energy budget from mill MES; locked the target envelope for the run.
Mill Orchestrator — Simulated 48 candidate transition recipes on the as-run paper-machine twin — forming, press, dryer and calender — and ranked them on off-spec tonnes, break risk and steam.
Pulp-and-Stock — Stepped refiner specific edge load 1.9 → 1.4 Ws/m and pushed freeness toward 412 CSF while consistency held at 3.4%.
Wetend-and-Chemistry — Retention aid trimmed to 214 g/t and sizing to 1.1 kg/t against live charge and turbidity; first-pass retention recovered to 78% inside 90 seconds.
Form-and-Press — Re-cut the slice profile across 78 actuators and set jet-to-wire to 0.994 to hold formation index through the basis-weight ramp.
Form-and-Press — Nip load reduced 620 → 540 kN/m to protect the lighter web; post-press dryness landed at 47.1%.
Dry-and-Coat — Re-phased the steam schedule across 6 dryer groups and rebalanced the hood; reel moisture converged to 7.4% ±0.19 2σ at 6.1% less steam than the standing recipe.
Defect-and-Inspect — 18 line-scan cameras streaming; two edge-crack precursors detected at the drive side and cleared by a 40 kN/m nip trim before either propagated.
Mill Orchestrator — Speed ramp 1,180 → 1,245 m/min exceeded the site autonomy threshold. Held for the machine tender; approved by J. Okonkwo at 04:57:12.
Quality-and-Conformance — Reel R-24188 released: full genealogy written (furnish, chemistry, CD profiles, defect map, operator actions) and checked against grade spec.
Every tool invocation, argument and result is written to an immutable, human-readable log — and every reasoning step is expandable. Nothing about a run is hidden from the mill.
Plan → thought → action → observation, exactly as the orchestrator recorded it.
Move PM4 from 135 gsm kraftliner to 110 gsm testliner with zero breaks and under 14 minutes of off-spec production.
Simulate the transition on the twin first. Lead with stock and chemistry so the furnish is right before the basis weight ramps, then trim forming and press, then re-phase drying. Watch the web continuously; hold the speed ramp for a human.
The standing recipe drops basis weight and speed together. On the twin that produces a 3-minute moisture excursion because the dryer section unloads faster than the steam schedule can follow. Sequencing the steam re-phase ahead of the basis-weight ramp removes it.
twin.simulate(candidates=48) → recipe #31 re-phases steam 40 s before the basis-weight ramp and holds nip load until post-press dryness confirms.
Recipe #31 estimates 6.4 t off-spec against 9.8 t for the standing recipe, with break risk 0.07. Two candidates scored lower on steam but raised break risk above the 0.15 site limit and were discarded.
Execute recipe #31 under autonomy level L3: nine setpoint writes permitted, speed ramp routed to the machine tender.
Edge-crack precursor at 1,412 mm drive side at 04:56:41. Nip trim of −40 kN/m in press-2 cleared it in 16 s without a break.
Run complete in 11 m 42 s. 6.2 t off-spec, zero breaks, 6.1% less dryer steam than the standing recipe. Reel R-24188 released with full genealogy.
Design targets, marked as such [ASPIRATIONAL].
Figures are design targets and pilot-scoped results [ASPIRATIONAL]. Every number is reproduced from the mill's own reel genealogy, not our telemetry.
Where our thinking comes from, outside our own writing.
Furnish preparation, refining, retention, formation, pressing and drying — the physics the twin encodes.
The measurement methods a genealogy record has to map onto for conformance to mean anything.
The zone and conduit model our network architecture is designed against.
Perception, simulation and control on accelerated hardware, and why mill servers cannot carry the workload.
Prior art on graded autonomy and human supervisory control, which our four levels borrow from.
Steam, hood balance and the industrial energy case for variance reduction before mean shifting.
What a good six-month evaluation looks like from the mill's side.
Choose a machine with frequent grade changes and a known off-spec problem. Do not start with the flagship.
Ninety days of historian data, agreed before anything is installed, using the mill's own definitions.
Three to four weeks to rack, connect and validate, then shadow mode until the crew agrees the readings are right.
Recommendations in the HMI. Acceptance and rejection rates are the real metric here, not accuracy claims.
A narrow tag allow-list with per-write approval. Expand only when the crew asks to.
A signed comparison against the baseline. If the numbers are not there, the mill should say so and we should accept it.
A mill does not go from manual to unattended in one step. Pulpum makes the level explicit, auditable and reversible at any time.
| Level | What the agent does | What the human does | Typical time to reach |
|---|---|---|---|
| L1 · Advisory | Recommends setpoints and explains why | Enters every change manually | Week 1 |
| L2 · Supervised | Proposes a write; it executes on approval | Approves each write in the HMI | Week 3–6 |
| L3 · Bounded | Writes inside tag, rate and magnitude limits | Approves ramps and grade releases | Month 2–4 |
| L4 · Unattended | Runs the envelope without prompting | Sets the envelope; reviews the shift record | Month 6+ [ASPIRATIONAL] |
Pulpum writes to production equipment. Every capability is scoped, every write is policy-checked, and every action is written to an append-only audit log the mill owns.
| Standard | Scope | Status |
|---|---|---|
| SOC 2 Type II | Cloud control plane | RUNNING In progress [ASPIRATIONAL] |
| ISO 27001 | Company-wide ISMS | QUEUED Planned [ASPIRATIONAL] |
| IEC 62443 | Mill-edge OT security | RUNNING Design-aligned |
| GDPR | Operator data | SUCCEEDED Compliant |
| ISO 9001 / FSC | Quality + chain of custody records | SUCCEEDED Supported |
Pulpum reads and writes through the systems already on the floor. No rip-and-replace, no parallel historian, no new HMI to learn.
Valmet IQ, ABB 800xA QCS, Honeywell Experion MX
Profiles, scans, lab results
ABB 800xA, Valmet DNA, Honeywell Experion, Siemens PCS 7
Setpoint reads and guarded writes
WIS/WMS line-scan, IR and transmission cameras
Frames, defect maps, break replays
SAP PP/QM, ABB cpmPlus, custom historians
Orders, grades, reel genealogy
OSIsoft PI, Aspen IP.21, InfluxDB
Time-series backfill and replay
NVIDIA Isaac, winder and wrapper PLCs
Reel, roll and clamp-truck motion
Azure AD, Okta, on-prem LDAP
SSO, RBAC, named approvers
NVIDIA Jetson Orin, IGX, on-prem GPU
Sub-100 ms inference at the machine
Autonomy earns trust one shift at a time. These are design-partner quotes from pilot deployments [ASPIRATIONAL].
"The first thing that convinced the crew wasn't the control — it was the log. You can scroll back and see exactly why it dropped the nip. Nobody argues with a timestamp."
Machine tender · PM4 · Nordkraft Mills
"We had two people who could do a clean 135-to-110 transition. One retired in March. The twin now does the sequencing and the second one supervises it."
Production manager · Aurora Board
"Break prediction was the wedge. Ninety seconds of warning is the difference between a nip trim and four hours of threading."
Process engineer · Ternvik Paper
The questions mill managers and process engineers actually ask in the first meeting.
Yes, but only within an explicit tag allow-list with per-tag rate and magnitude limits, and only at the autonomy level your site has set. Level 1 is advisory-only: Pulpum recommends and a human enters everything. Most mills spend their first weeks there before enabling supervised writes.
Control returns to the DCS last known-good state within one scan cycle. Pulpum is designed as a supervisory layer on top of your existing control system, never as a replacement for it, so a Pulpum outage degrades the mill to its current way of running — not to a stop.
Break prediction and defect classification typically need 8 to 12 weeks of QCS, DCS and inspection history per grade family, plus labelled break events. Advisory recommendations start in week one from the physics-based twin, and improve as mill-specific history accumulates.
Only if you choose cloud training. Recipes, grade models and defect libraries are tenant-isolated and never used to train another customer's models. A fully on-prem deployment with an air-gapped mill edge is available for sensitive producers.
You are, the same as with any control strategy — which is why every write is policy-checked, bounded, logged and reversible, and why anything above your risk threshold waits for a named approver. The audit log records the request, the reasoning, the limits applied and the human decision.
A 90 to 120 day mill-edge deployment on one paper machine, scoped to a single workflow with a pre-agreed baseline [ASPIRATIONAL]. Weeks 1–3 are connection and shadow-mode observation; weeks 4–8 advisory; weeks 9+ supervised or bounded writes if the mill is satisfied with the recommendations.
Tell us which reader you have to convince and we will send the right document, without a form wall.
↑↓ navigate↵ openesc close