Typed tool registry
An agent can only call tools that exist in the registry, with declared tags, units and direction.
Every capability is scoped, every write is policy-checked, every action is logged to storage the plant owns, and failure returns control to the systems already on the floor.
A model's opinion never reaches a furnace directly. It passes through every one of these.
An agent can only call tools that exist in the registry, with declared tags, units and direction.
Each tool writes only to allow-listed tags, inside per-tag rate and magnitude limits.
Autonomy level, shift, product, interlock state and operator presence evaluated before every write.
Moves verified on Glastwin before they are proposed; discarded if stress or seed risk exceed site limits.
Anything above the site threshold waits for a named glass technologist and their decision is logged.
Loss of the edge node, the network or the model returns control to the existing furnace, forming and lehr systems.
Every tool invocation, argument and result is written to an immutable, human-readable log, and every reasoning step is expandable. Nothing about a run is hidden from the plant.
Plan, thought, action, observation, exactly as the orchestrator would record it.
Move FL-2 from 6 mm to 4 mm clear float with residual stress inside spec and zero escaped seeds.
Simulate the transition on the twin first. Lead with furnace pull so the ribbon mass flow is right before the forming change, then thin the ribbon, then re-shape the lehr curve. Watch the ribbon continuously; hold the second pull step for a human.
The standing recipe changes pull and ribbon speed together. On the twin that produces a fining transient that seeds the ribbon edge. Sequencing the pull step ahead of the forming change and holding fining removes most of it.
twin.simulate(candidates=36) returned recipe #19: pull in two steps, forming change after fining settles, lehr curve re-shaped before belt speed rises.
Recipe #19 scored lowest on seed risk with stress inside spec. Two candidates scored lower on energy but pushed residual stress over the site limit and were discarded.
Execute recipe #19 under autonomy level L3: eleven setpoint writes permitted, the second pull step routed to the glass technologist.
Seed cluster at the ribbon edge at 02:28:41, attributed to the pull transient. cuOpt routed that ribbon to cullet recovery; no flagged plate reached a customer stack.
Scenario run complete. Thickness at 4.0 mm, residual stress inside spec, one approval gate, full genealogy written to the lot record.
Glasent writes to production equipment. Every capability is scoped, every write is policy-checked, and every action is written to an append-only audit log the plant owns.
| Standard | Scope | Status |
|---|---|---|
| SOC 2 Type I | Cloud control plane | RUNNING Planned in the first six months |
| SOC 2 Type II | Cloud control plane | QUEUED Planned in months six to twelve |
| IEC 62443 | Plant-edge OT security | RUNNING Design-aligned |
| ISO 9001 / IATF 16949 | Quality and genealogy records | SUCCEEDED Record formats supported |
| Container and safety-glass standards | Stress and defect conformance records | SUCCEEDED Record formats supported |
A plant does not go from manual to unattended in one step. Glasent makes the level explicit, auditable and reversible at any time, and the first release plan is shadow, then assist, then graduated autonomy.
| Level | What the agent does | What the person does | When |
|---|---|---|---|
| L1 · Shadow and advisory | Observes, predicts and recommends setpoints with its reasoning | Enters every change manually; a baseline is measured | Pilot weeks 1 to 3 |
| L2 · Assist | Proposes a write; it executes on approval | Approves each write in the review console | Pilot weeks 4 to 8 |
| L3 · Bounded | Writes inside tag, rate and magnitude limits on low-risk loops | Approves pull steps, grade releases and anything above threshold | Pilot week 9 onward |
| L4 · Unattended | Runs the approved envelope without prompting | Sets the envelope; reviews the shift record | Planned, after graduated autonomy proves out |
Stated as it is: planned where planned, aligned where aligned, supported where the record format already exists.
| Standard | Scope | Status |
|---|---|---|
| SOC 2 Type I | Cloud control plane | RUNNING Planned in the first six months |
| SOC 2 Type II | Cloud control plane | QUEUED Planned in months six to twelve |
| IEC 62443 | Plant-edge OT security | RUNNING Design-aligned |
| ISO 9001 / IATF 16949 | Quality and genealogy records | SUCCEEDED Record formats supported |
| Container and safety-glass standards | Stress and defect conformance records | SUCCEEDED Record formats supported |
Glasent is a supervisory layer on top of the plant's existing control systems, never a replacement for them.
Writes are scoped, rate-limited and reversible. The policy engine does not know how to exceed a limit; the limit is enforced in the tool definition, not in the prompt. Every write names the model version, the policy version and the approver, so a bad move can be traced and the policy corrected.
Robot cells follow the same rule: Panebot paths are validated in Isaac Sim before deployment and executed only inside the cell's safety envelope, with the robot's own safety controller untouched.
Tenant isolation and IP protection are defaults. Cloud training is a choice.
| Data | On-prem / air-gapped | VPC | Cloud training |
|---|---|---|---|
| Process telemetry | Stays on site | Your VPC | Tenant-scoped, encrypted |
| Compositions and recipes | Stays on site | Your VPC | Never used across tenants |
| Defect imagery | Stays on site | Your VPC | Tenant-scoped training only |
| Audit log and genealogy | Plant storage | Plant storage + VPC copy | Plant storage + tenant copy |
| Model weights | Delivered to site | Delivered to VPC | Trained per tenant |
| Cross-site learning | None | None | Federated and privacy-preserving, planned |
Federated fleet learning across similar glass families is planned, not built, and would share model improvements without exposing recipes or plant IP.
Two agents will want the same actuator. The orchestrator arbitrates on the run goal, not on who asked first, and the handoff is logged like any other step.
Formeon wants pull held while the ribbon thins, to protect thickness convergence.
Meltrix wants the second pull step now, to settle fining before the seed rate climbs.
Seed risk outranks a short thickness excursion under the run goal "zero escaped seeds". Meltrix wins the actuator, and because the step is above threshold it goes to the technologist.
Actuator returned; Formeon recovers thickness with roller angle instead. Both requests, the score and the reason are in the run record.
One policy model, one audit trail, one benchmark across every line in every plant, with the composition and forming models kept private to each site.
The questions plant directors and glass technologists ask in the first meeting.
Yes, but only within an explicit tag allow-list with per-tag rate and magnitude limits, and only at the autonomy level your site has set. Every pilot starts in shadow mode, where Glasent predicts and recommends and a person enters everything. Writes come later, after the recommendations have earned it.
Control returns to your existing furnace, forming and lehr systems at their last known-good state. Glasent is a supervisory layer on top of the control system you already run, never a replacement for it, so an outage degrades the plant to its current way of running, not to a stop.
Shadow mode starts on the first day from existing SCADA, forming, lehr and inspection data. Defect and stress prediction improve as site history and labelled outcomes accumulate; the pilot plan sets a baseline period before any recommendation is scored.
Only if you choose cloud training. Compositions, forming recipes and defect libraries are tenant-isolated and never used to train another customer's models. On-prem training and an air-gapped plant edge are available for IP-sensitive producers.
You are, the same as with any control strategy, which is why every write is policy-checked, bounded, logged and reversible, and why anything above your risk threshold waits for a named approver. The audit log records the request, the reasoning, the limits applied and the human decision.
A 90 to 120 day line pilot in three stages: shadow mode to measure the baseline, assist mode where a technologist approves each recommendation, then bounded write-back on low-risk forming, annealing or inspection loops if the plant is satisfied with the results.
Architecture, data flows, the tag allow-list model and the audit log schema, for your IT, OT and quality reviewers.
↑↓ navigate↵ openesc close