The complete platform on one drawing: the reusable platform beside the Client Customization Plane, both MCP boundaries, and the two sealed loops. Use the controls to zoom, or maximize for a distraction-free full-screen view. The guided walkthroughs live on the next page.
Diagram size − 100% + Reset ⤢ Maximize
P1Z Platform Architecture One reusable platform, one customization plane, equal partners: the platform is what P1Z builds once; the plane is what makes it a client's own · v2.5 P1Z REUSABLE PLATFORM built once, every client runs these same seven layers, unchanged CLIENT CUSTOMIZATION PLANE the only per-client build, values, never code Lifecycle: PLAN (EA assessment fills the binding) → RUN (operate) 1. Experience AMBIENT · CONVERSATIONAL · CROSS-CHANNEL Chat Web App Desktop Mobile App Voice Phone / Call Center Embedded in Tools MCP Hosts Claude, Copilot Output & Format Renderer structures from Knowledge · templates from the Plane Shared UI Core one core behind every P1Z shell · cross-channel continuity Channel Mix & Notifications channels on/off per client · proactive rules Feedback Capture edits & rejections → eval store C1. Experience VALUES, NEVER CODE Channel Mix on/off per audience House Templates branding & layouts Output Formats Tone & Language Notification Rules Embedded Surface Selection which work tools NORTH-FACING PLATFORM MCP GATEWAY, the whole platform exposed as an MCP SERVER to any host above: agents, use cases and UI resources as tools; all code and business logic stays server-hosted. Per-tenant endpoint · tenant auth · host allow-list 2. Solution CLIENT-BLIND CODE · CLIENT-AWARE EXECUTION Orchestrator deterministic, routes, gates, never authors Business Agents judgment under guardrails; face the gates Workflows deterministic multi-step Copilots human-driven assist Skills one per use case, on demand Domain Rule Library implements what Knowledge declares, computed once, cited everywhere Subagent Workers internal; bounded summary contracts Determination rule: any task with a testable right answer is deterministic code. Agents get judgment only, the last resort, not the first draft. C2. Solution VALUES, NEVER CODE Use-Case Activation which agents are on Orchestration Mode serial vs parallel per use case HITL Placement where humans review Custom Workflow Composition reusable agents, never new code Override & Exception Routing Overlay Selection 3. Knowledge CLIENT-BLIND · VERSIONED RELEASES ONLY Industry Ontologies PE today, healthcare next, stable IDs Functional Ontologies cross-industry: finance ops, legal, reporting P1Z Benchmarks eval outcomes, gate metrics, cycle-time norms Promotion Gate anonymize → aggregate → rights check → human review → versioned release Curated Consulting Benchmarks age-old priors as versioned data C3. Knowledge VALUES, NEVER CODE Ontology Version Pin the exact release this client reads Overlay Selection e.g., growth equity Stage & Gate Name Mapping the client's language Benchmark Scope & Data-Rights Clause what telemetry may be promoted 4. Intelligence (the AI layer) VENDOR-AGNOSTIC · SWAPPABLE Model Router the portability boundary Foundation LLMs Small Language Models Embeddings Rerankers This thin layer absorbs model progress, models upgrade, nothing above changes. AGI-readiness is a one-layer swap, not a rebuild. C4. Intelligence VALUES, NEVER CODE Model Tier Preference Cost Ceilings the router enforces them Latency Targets Approved-Vendor List Data Sensitivity Boundary which classes reach which tier 5. Integration AGENT TOOL CALLS & API CALLS ENTER HERE South-Facing MCP Tool Servers platform acts as MCP CLIENT here, one server per source; permissions once API Gateway outbound external API calls; rate limits, retries Connector Library pre-built: Egnyte, SharePoint, Airtable, APIs Sync Engine Source Catalog sources · access rules ETL, Batch & Streaming Templates Schema-Mapping Toolkit Dead-letter Handling Middleware between everything above and the data below. A missing connector is BUILT into the library and SELECTED on the plane. C5. Integration VALUES, NEVER CODE Source System Selection Credentials & OAuth Grants Data Contracts Field Mappings client schema → taxonomy Sync Schedules & Modes Custom Connector Selection from the library 6. Data & Documents PER-TENANT ISOLATION · DATA ENGINEERING Vector DB Service Document Store Service Data Warehouse Service Retrieval APIs Indexing & Taxonomy structures from Knowledge Systems of Record ERP, CRM, fund admin Document Sources VDR, SharePoint, email Unstructured Data notes, transcripts, recordings External Data Providers market & benchmark feeds Tenant stores are reusable templates; dashed boxes are the SOURCE ESTATE they front, reached only through Integration (L5). C6. Data & Documents VALUES, NEVER CODE Tenant Store Instances the client's actual data Source Estate Inventory their SoRs, VDRs, warehouses, feeds Document Taxonomy Mapping their docs → the taxonomy Data Residency & Regions Retention & Legal Hold 7. Environment (the Harness) BUSINESS-BLIND · SELF-OPTIMIZING Agent Loop & Run Contracts end state + token budget; over-budget = kill Guardrail Mechanics 4 locks: instructions < hooks < scopes < gates Session & Memory Machinery context packs, compaction, memory stores Observability & Eval Infra content-blind traces; eval runners; A/B Identity & Tenancy service identities; isolation tests in CI CI/CD, ADLC & SSRA Skeleton repo templates: constitutions, skills, agent defs; sandbox → eval gate → promotion → registry deploy Secrets & KMS per-tenant keys SRE & Incident Ops runbooks, DR, on-call Future-proofed and model-agnostic by construction. Self-optimizing via the operational loop, every tuning is a versioned config change through CI; silent drift is a defect. C7. Environment VALUES, NEVER CODE Tenancy & Account Mapping Identity Provider Entra / Cognito / Okta Token Budgets per use case Gate Approver Roles Alerts & Escalation Timers No code in the plane, values only. Custom logic is a Solution-layer overlay, SELECTED here. slots and values KNOWLEDGE LOOP, telemetry & evals, gated OPERATIONAL LOOP learns how to run - versioned, never silent Deferred and open items are not drawn and never lost: they live on the Decision Register page, with activation triggers. How to read this diagram • Left column: what P1Z builds once and every client reuses. Right column: the values one client fills in. The double-headed connectors between them are that exchange. Same structure on both sides, only the contents differ. • Two MCP boundaries. The north gateway (between layers 1 and 2) is where hosts like Claude or Copilot connect; all code stays on the server. The south tool servers (layer 5) are where agents reach data. Tenant identity is checked at the north, source permissions at the south. • Read top to bottom to follow a request. Build bottom to top; setup starts at layer 7. The knowledge loop promotes gated telemetry into benchmarks. The operational loop tunes the harness. The two loops never mix. • Agents live in layer 2 and are reused unchanged; the plane only switches them on and arranges them. No code ever enters the client column. Point One Zero · generated view, scripts/generators/build_p1z_arch.py · v2.4 · seven layers + client plane