Point One Zero Platform architecturev11 · generated viewSign in to edit
Platform Layers › L5 Integration

L5 Integration

Where this layer sits on the architecture; the client plane band to its right shows the values it reads.

P1Z Platform ArchitectureOne reusable platform, one customization plane, equal partners: the platform is what P1Z builds once; the plane is what makes it a client's own · v2.5P1Z REUSABLE PLATFORMbuilt once, every client runs these same seven layers, unchangedCLIENT CUSTOMIZATION PLANEthe only per-client build, values, never codeLifecycle: PLAN (EA assessment fills the binding) → RUN (operate)1. ExperienceAMBIENT · CONVERSATIONAL · CROSS-CHANNELChatWeb AppDesktopMobile AppVoicePhone / Call CenterEmbedded in ToolsMCP HostsClaude, CopilotOutput & Format Rendererstructures from Knowledge · templates from the PlaneShared UI Coreone core behind every P1Z shell · cross-channelcontinuityChannel Mix & Notificationschannels on/off per client · proactive rulesFeedback Captureedits & rejections → eval storeC1. ExperienceVALUES, NEVER CODEChannel Mixon/off per audienceHouse Templatesbranding & layoutsOutput FormatsTone & LanguageNotification RulesEmbedded Surface Selectionwhich work toolsNORTH-FACING PLATFORM MCP GATEWAY, the whole platform exposed as an MCP SERVER to any host above: agents, use cases and UI resources as tools; allcode and business logic stays server-hosted.Per-tenant endpoint · tenant auth · host allow-list2. SolutionCLIENT-BLIND CODE · CLIENT-AWARE EXECUTIONOrchestratordeterministic, routes, gates, never authorsBusiness Agentsjudgment under guardrails; face the gatesWorkflowsdeterministic multi-stepCopilotshuman-driven assistSkillsone per use case, on demandDomain Rule Libraryimplements what Knowledge declares, computed once, cited everywhereSubagent Workersinternal; bounded summary contractsDetermination rule: any task with a testable right answer is deterministic code. Agents get judgment only, the last resort, not the firstdraft.C2. SolutionVALUES, NEVER CODEUse-Case Activationwhich agents are onOrchestration Modeserial vs parallel per use caseHITL Placementwhere humans reviewCustom Workflow Compositionreusable agents, never new codeOverride & Exception RoutingOverlay Selection3. KnowledgeCLIENT-BLIND · VERSIONED RELEASES ONLYIndustry OntologiesPE today, healthcare next, stable IDsFunctional Ontologiescross-industry: finance ops, legal, reportingP1Z Benchmarkseval outcomes, gate metrics, cycle-time normsPromotion Gateanonymize → aggregate → rights check → human review → versioned releaseCurated Consulting Benchmarksage-old priors as versioned dataC3. KnowledgeVALUES, NEVER CODEOntology Version Pinthe exact release this client readsOverlay Selectione.g., growth equityStage & Gate Name Mappingthe client's languageBenchmark Scope & Data-Rights Clausewhat telemetry may be promoted4. Intelligence (the AI layer)VENDOR-AGNOSTIC · SWAPPABLEModel Routerthe portability boundaryFoundation LLMsSmall Language ModelsEmbeddingsRerankersThis thin layer absorbs model progress, models upgrade, nothing above changes. AGI-readiness is a one-layer swap, not a rebuild.C4. IntelligenceVALUES, NEVER CODEModel Tier PreferenceCost Ceilingsthe router enforces themLatency TargetsApproved-Vendor ListData Sensitivity Boundarywhich classes reach which tier5. IntegrationAGENT TOOL CALLS & API CALLS ENTER HERESouth-Facing MCP Tool Serversplatform acts as MCP CLIENT here, one server per source; permissions onceAPI Gatewayoutbound external API calls; rate limits, retriesConnector Librarypre-built: Egnyte, SharePoint, Airtable, APIsSync EngineSource Catalogsources · access rulesETL, Batch & Streaming TemplatesSchema-Mapping ToolkitDead-letter HandlingMiddleware between everything above and the data below. A missing connector is BUILT into the library and SELECTED on the plane.C5. IntegrationVALUES, NEVER CODESource System SelectionCredentials & OAuth GrantsData ContractsField Mappingsclient schema → taxonomySync Schedules & ModesCustom Connector Selectionfrom the library6. Data & DocumentsPER-TENANT ISOLATION · DATA ENGINEERINGVector DB ServiceDocument Store ServiceData Warehouse ServiceRetrieval APIsIndexing & Taxonomystructures from KnowledgeSystems of RecordERP, CRM, fund adminDocument SourcesVDR, SharePoint, emailUnstructured Datanotes, transcripts, recordingsExternal Data Providersmarket & benchmark feedsTenant stores are reusable templates; dashed boxes are the SOURCE ESTATE they front, reached only through Integration (L5).C6. Data & DocumentsVALUES, NEVER CODETenant Store Instancesthe client's actual dataSource Estate Inventorytheir SoRs, VDRs, warehouses, feedsDocument Taxonomy Mappingtheir docs → the taxonomyData Residency & RegionsRetention & Legal Hold7. Environment (the Harness)BUSINESS-BLIND · SELF-OPTIMIZINGAgent Loop & Run Contractsend state + token budget; over-budget = killGuardrail Mechanics4 locks: instructions < hooks < scopes < gatesSession & Memory Machinerycontext packs, compaction, memory storesObservability & Eval Infracontent-blind traces; eval runners; A/BIdentity & Tenancyservice identities; isolation tests in CICI/CD, ADLC & SSRA Skeletonrepo templates: constitutions, skills, agent defs; sandbox →eval gate → promotion → registry deploySecrets & KMSper-tenant keysSRE & Incident Opsrunbooks, DR, on-callFuture-proofed and model-agnostic by construction. Self-optimizing via the operational loop, every tuning is a versioned config change throughCI; silent drift is a defect.C7. EnvironmentVALUES, NEVER CODETenancy & Account MappingIdentity ProviderEntra / Cognito / OktaToken Budgetsper use caseGate Approver RolesAlerts & Escalation TimersNo code in the plane, values only. Custom logic is a Solution-layeroverlay, SELECTED here.slotsandvaluesKNOWLEDGE LOOP, telemetry & evals, gatedOPERATIONALLOOPlearns how to run -versioned, never silentDeferred and open items are not drawn and never lost: they live on the Decision Register page, with activation triggers.How to read this diagram• Left column: what P1Z builds once and every client reuses. Right column: the values one client fills in. The double-headed connectors between them are that exchange. Samestructure on both sides, only the contents differ.• Two MCP boundaries. The north gateway (between layers 1 and 2) is where hosts like Claude or Copilot connect; all code stays on the server. The south tool servers (layer5) are where agents reach data. Tenant identity is checked at the north, source permissions at the south.• Read top to bottom to follow a request. Build bottom to top; setup starts at layer 7. The knowledge loop promotes gated telemetry into benchmarks. The operational looptunes the harness. The two loops never mix.• Agents live in layer 2 and are reused unchanged; the plane only switches them on and arranges them. No code ever enters the client column.Point One Zero · generated view, scripts/generators/build_p1z_arch.py · v2.4 · seven layers + client plane

L5 Integration AGENT TOOL & API CALLS ENTER HERE

The movement half, the most client-weighted layer of the seven. Left side: the connector library (pre-built Egnyte, SharePoint, Airtable, generic APIs, a P1Z asset that compounds with every engagement), sync engine, schema-mapping toolkit, pipeline templates, dead-letter handling. Right side: everything that makes it this client's.

  • South-facing MCP tool servers (platform as MCP client; 10 logical, ~4 physical) + API gateway; connector library, sync engine, schema-mapping toolkit, built once, reused everywhere
  • Source catalog, the machine-readable registry of what exists, where it lives and what access applies; agents consult it before reaching for data (populated from the plane's source-estate inventory)
  • Plane-side: source selection, credentials & OAuth grants, field mappings (client schema → taxonomy), sync schedules, data contracts
  • A missing connector is BUILT into the library and SELECTED on the plane, never as engagement code; second client needing it proves it belongs (build-twice rule)
  • Different failure modes than storage: a broken sync loses data loudly; monitor accordingly

Boundary test: the machinery never hardcodes a client system; every connection is a plane value.

Plane parameters: sources · credentials · field mappings · schedules · contracts

Client-specific configuration for this layer is specified band by band in Client Delivery, C5 spec: every input with its binding key, generated artifact, and verifying check.

Component reference

South-Facing MCP Tool Servers

The platform acting as MCP client toward data: one logical server per source, permissions defined once per server.

ImplementationRoughly ten logical servers consolidated onto a few physical gateways per the cloud overlay. Tool definitions follow the published design standard; the Smart Pipe antipattern (business logic inside a connector) is the failure mode to review for.

API Gateway

The outbound path for external API calls: authentication, rate limits, retries.

ImplementationFronts market-data and external services; every outbound call is metered and traced like any tool call.

Connector Library

Pre-built source connectors that compound with every engagement.

ImplementationA P1Z asset. A missing connector is built into the library and selected on the plane, never written as engagement code; the second client needing it proves it belongs.

Sync Engine

Scheduled and event-driven data movement between sources and tenant stores.

ImplementationModes and schedules are C5 plane values; every failure dead-letters rather than disappearing.

Source Catalog

The machine-readable registry of sources: what exists, where it lives, what schema and access rules apply.

ImplementationPopulated from the C6 source-estate inventory during discovery; agents consult it before reaching for data, so navigation is configured rather than guessed.

ETL, Batch & Streaming Templates

Reusable pipeline shapes for ingestion and movement.

ImplementationInstantiated with client field mappings; executed by the data-layer machinery in L7; pattern P3 is the reference trace.

Schema-Mapping Toolkit

Translates client schemas into the platform taxonomy.

ImplementationField mappings are C5 values, versioned with the binding; drift is caught by data-contract checks, not discovered in outputs.

Dead-letter Handling

Failed items parked, alerted on, and replayable; nothing silently dropped.

ImplementationAlert routing comes from the plane; a silent drop is the Silent Start antipattern.