Bounded action space
Each agent has an explicit tag allow-list. A tag not on the list cannot be written, regardless of what any model outputs.
Pulpum writes to production equipment on machines that run at 1,200 metres a minute. Security here is not only about data — it is about what the software is permitted to do, under what conditions, with whose approval, and what happens when something fails.
Live example: Grade change PM4 · 135 gsm kraftliner → 110 gsm testliner, no break, ≤14 min off-spec
A recommendation has to survive all six before it reaches the DCS.
Each agent has an explicit tag allow-list. A tag not on the list cannot be written, regardless of what any model outputs.
Every tool declares magnitude and rate limits in engineering units. A 0.15 bar per 30 s limit is enforced at call time, not reviewed later.
Moves are simulated before execution. A move that raises modelled break risk above the site limit is discarded.
Autonomy level, grade, shift, interlock state and operator presence are all evaluated before the write is released.
Anything above the site risk threshold waits for a named approver, with the request and reasoning shown in mill units.
Every write is logged with its full context and can be reverted to the prior known-good value in one action.
This is the actual log format: timestamp, tool, arguments, result. Copyable, exportable, hash-chained.
Plan → thought → action → observation, exactly as the orchestrator recorded it.
Move PM4 from 135 gsm kraftliner to 110 gsm testliner with zero breaks and under 14 minutes of off-spec production.
Simulate the transition on the twin first. Lead with stock and chemistry so the furnish is right before the basis weight ramps, then trim forming and press, then re-phase drying. Watch the web continuously; hold the speed ramp for a human.
The standing recipe drops basis weight and speed together. On the twin that produces a 3-minute moisture excursion because the dryer section unloads faster than the steam schedule can follow. Sequencing the steam re-phase ahead of the basis-weight ramp removes it.
twin.simulate(candidates=48) → recipe #31 re-phases steam 40 s before the basis-weight ramp and holds nip load until post-press dryness confirms.
Recipe #31 estimates 6.4 t off-spec against 9.8 t for the standing recipe, with break risk 0.07. Two candidates scored lower on steam but raised break risk above the 0.15 site limit and were discarded.
Execute recipe #31 under autonomy level L3: nine setpoint writes permitted, speed ramp routed to the machine tender.
Edge-crack precursor at 1,412 mm drive side at 04:56:41. Nip trim of −40 kN/m in press-2 cleared it in 16 s without a break.
Run complete in 11 m 42 s. 6.2 t off-spec, zero breaks, 6.1% less dryer steam than the standing recipe. Reel R-24188 released with full genealogy.
Pulpum writes to production equipment. Every capability is scoped, every write is policy-checked, and every action is written to an append-only audit log the mill owns.
| Standard | Scope | Status |
|---|---|---|
| SOC 2 Type II | Cloud control plane | RUNNING In progress [ASPIRATIONAL] |
| ISO 27001 | Company-wide ISMS | QUEUED Planned [ASPIRATIONAL] |
| IEC 62443 | Mill-edge OT security | RUNNING Design-aligned |
| GDPR | Operator data | SUCCEEDED Compliant |
| ISO 9001 / FSC | Quality + chain of custody records | SUCCEEDED Supported |
A mill does not go from manual to unattended in one step. Pulpum makes the level explicit, auditable and reversible at any time.
| Level | What the agent does | What the human does | Typical time to reach |
|---|---|---|---|
| L1 · Advisory | Recommends setpoints and explains why | Enters every change manually | Week 1 |
| L2 · Supervised | Proposes a write; it executes on approval | Approves each write in the HMI | Week 3–6 |
| L3 · Bounded | Writes inside tag, rate and magnitude limits | Approves ramps and grade releases | Month 2–4 |
| L4 · Unattended | Runs the envelope without prompting | Sets the envelope; reviews the shift record | Month 6+ [ASPIRATIONAL] |
We publish status honestly, including what is not done yet.
| Framework | Scope | Status | Evidence |
|---|---|---|---|
| SOC 2 Type II | Cloud control plane | In progress [ASPIRATIONAL] | Report on request at completion |
| ISO 27001 | Company ISMS | Planned [ASPIRATIONAL] | — |
| IEC 62443 | Mill-edge OT security | Design-aligned | Architecture review pack |
| GDPR | Operator personal data | Compliant | DPA + records of processing |
| ISO 9001 support | Quality records | Supported | Reel genealogy export |
| FSC chain of custody | Fibre traceability | Supported | Genealogy fields mapped |
The correct behaviour for a supervisory agent that loses confidence is to stop writing and hand back — quietly, immediately, and with a log entry.
The default is that very little does. You choose the rest explicitly.
Raw camera frames, full-rate DCS telemetry, operator identities and interlock state remain on the mill-edge node.
Frames of interest, labelled break events and aggregated run summaries — used for site-specific model training.
Furnish recipes, grade models, defect libraries and any derived weights are isolated per customer, contractually and technically.
Run records, audit log, reel genealogy and model metadata export in JSON and CSV at any time, including on exit.
Tenant deletion removes models, telemetry and derived artefacts within the contractual window, with written confirmation.
For sensitive producers, the mill edge runs disconnected with offline, signed model updates.
Two agents will want the same actuator. The orchestrator arbitrates on the run goal, not on who asked first — and the handoff is logged like any other step.
Form-and-Press wants to hold nip load to protect post-press dryness.
Defect-and-Inspect wants to reduce nip load to clear an edge-crack precursor.
Break risk 0.62 outranks a 0.4-point dryness loss under the run goal "zero breaks". Defect-and-Inspect wins the actuator for 120 s.
Actuator returned; Form-and-Press recovers dryness with vacuum instead. Post-press dryness lands at 47.1%.
One policy model, one audit trail, one benchmark across every machine in every mill — with the grade and furnish models kept private to each site.
The questions mill managers and process engineers actually ask in the first meeting.
External penetration testing of the control plane and the mill-edge appliance is scheduled as part of the SOC 2 Type II programme [ASPIRATIONAL]. Results are shared with customers under NDA.
Tags are allow-listed per tool at configuration time and validated again at call time against the machine's tag database. There is no free-form write API; a tag outside the list returns a policy error and is logged.
Yes. Manual action at the HMI or DCS immediately supersedes the agent, and the agent records the override as a training signal rather than fighting it.
Entries are hash-chained, so any modification breaks the chain and is detectable. The log is written to storage the mill controls.
No. Site data trains site models. Shared components are physics-based or trained on synthetic and public data.
Severity-1 incidents affecting control behaviour trigger immediate degradation to advisory mode, customer notification within the contractual window, and a written post-incident review including the audit-log excerpt.
Architecture diagrams, the OT threat model, the data-flow map and the policy-engine specification — sent under NDA.
↑↓ navigate↵ openesc close