Point One Zero Platform architecturev11 · generated viewSign in to edit
Platform Layers › L6 Data & Documents

L6 Data & Documents

Where this layer sits on the architecture; the client plane band to its right shows the values it reads.

P1Z Platform ArchitectureOne reusable platform, one customization plane, equal partners: the platform is what P1Z builds once; the plane is what makes it a client's own · v2.5P1Z REUSABLE PLATFORMbuilt once, every client runs these same seven layers, unchangedCLIENT CUSTOMIZATION PLANEthe only per-client build, values, never codeLifecycle: PLAN (EA assessment fills the binding) → RUN (operate)1. ExperienceAMBIENT · CONVERSATIONAL · CROSS-CHANNELChatWeb AppDesktopMobile AppVoicePhone / Call CenterEmbedded in ToolsMCP HostsClaude, CopilotOutput & Format Rendererstructures from Knowledge · templates from the PlaneShared UI Coreone core behind every P1Z shell · cross-channelcontinuityChannel Mix & Notificationschannels on/off per client · proactive rulesFeedback Captureedits & rejections → eval storeC1. ExperienceVALUES, NEVER CODEChannel Mixon/off per audienceHouse Templatesbranding & layoutsOutput FormatsTone & LanguageNotification RulesEmbedded Surface Selectionwhich work toolsNORTH-FACING PLATFORM MCP GATEWAY, the whole platform exposed as an MCP SERVER to any host above: agents, use cases and UI resources as tools; allcode and business logic stays server-hosted.Per-tenant endpoint · tenant auth · host allow-list2. SolutionCLIENT-BLIND CODE · CLIENT-AWARE EXECUTIONOrchestratordeterministic, routes, gates, never authorsBusiness Agentsjudgment under guardrails; face the gatesWorkflowsdeterministic multi-stepCopilotshuman-driven assistSkillsone per use case, on demandDomain Rule Libraryimplements what Knowledge declares, computed once, cited everywhereSubagent Workersinternal; bounded summary contractsDetermination rule: any task with a testable right answer is deterministic code. Agents get judgment only, the last resort, not the firstdraft.C2. SolutionVALUES, NEVER CODEUse-Case Activationwhich agents are onOrchestration Modeserial vs parallel per use caseHITL Placementwhere humans reviewCustom Workflow Compositionreusable agents, never new codeOverride & Exception RoutingOverlay Selection3. KnowledgeCLIENT-BLIND · VERSIONED RELEASES ONLYIndustry OntologiesPE today, healthcare next, stable IDsFunctional Ontologiescross-industry: finance ops, legal, reportingP1Z Benchmarkseval outcomes, gate metrics, cycle-time normsPromotion Gateanonymize → aggregate → rights check → human review → versioned releaseCurated Consulting Benchmarksage-old priors as versioned dataC3. KnowledgeVALUES, NEVER CODEOntology Version Pinthe exact release this client readsOverlay Selectione.g., growth equityStage & Gate Name Mappingthe client's languageBenchmark Scope & Data-Rights Clausewhat telemetry may be promoted4. Intelligence (the AI layer)VENDOR-AGNOSTIC · SWAPPABLEModel Routerthe portability boundaryFoundation LLMsSmall Language ModelsEmbeddingsRerankersThis thin layer absorbs model progress, models upgrade, nothing above changes. AGI-readiness is a one-layer swap, not a rebuild.C4. IntelligenceVALUES, NEVER CODEModel Tier PreferenceCost Ceilingsthe router enforces themLatency TargetsApproved-Vendor ListData Sensitivity Boundarywhich classes reach which tier5. IntegrationAGENT TOOL CALLS & API CALLS ENTER HERESouth-Facing MCP Tool Serversplatform acts as MCP CLIENT here, one server per source; permissions onceAPI Gatewayoutbound external API calls; rate limits, retriesConnector Librarypre-built: Egnyte, SharePoint, Airtable, APIsSync EngineSource Catalogsources · access rulesETL, Batch & Streaming TemplatesSchema-Mapping ToolkitDead-letter HandlingMiddleware between everything above and the data below. A missing connector is BUILT into the library and SELECTED on the plane.C5. IntegrationVALUES, NEVER CODESource System SelectionCredentials & OAuth GrantsData ContractsField Mappingsclient schema → taxonomySync Schedules & ModesCustom Connector Selectionfrom the library6. Data & DocumentsPER-TENANT ISOLATION · DATA ENGINEERINGVector DB ServiceDocument Store ServiceData Warehouse ServiceRetrieval APIsIndexing & Taxonomystructures from KnowledgeSystems of RecordERP, CRM, fund adminDocument SourcesVDR, SharePoint, emailUnstructured Datanotes, transcripts, recordingsExternal Data Providersmarket & benchmark feedsTenant stores are reusable templates; dashed boxes are the SOURCE ESTATE they front, reached only through Integration (L5).C6. Data & DocumentsVALUES, NEVER CODETenant Store Instancesthe client's actual dataSource Estate Inventorytheir SoRs, VDRs, warehouses, feedsDocument Taxonomy Mappingtheir docs → the taxonomyData Residency & RegionsRetention & Legal Hold7. Environment (the Harness)BUSINESS-BLIND · SELF-OPTIMIZINGAgent Loop & Run Contractsend state + token budget; over-budget = killGuardrail Mechanics4 locks: instructions < hooks < scopes < gatesSession & Memory Machinerycontext packs, compaction, memory storesObservability & Eval Infracontent-blind traces; eval runners; A/BIdentity & Tenancyservice identities; isolation tests in CICI/CD, ADLC & SSRA Skeletonrepo templates: constitutions, skills, agent defs; sandbox →eval gate → promotion → registry deploySecrets & KMSper-tenant keysSRE & Incident Opsrunbooks, DR, on-callFuture-proofed and model-agnostic by construction. Self-optimizing via the operational loop, every tuning is a versioned config change throughCI; silent drift is a defect.C7. EnvironmentVALUES, NEVER CODETenancy & Account MappingIdentity ProviderEntra / Cognito / OktaToken Budgetsper use caseGate Approver RolesAlerts & Escalation TimersNo code in the plane, values only. Custom logic is a Solution-layeroverlay, SELECTED here.slotsandvaluesKNOWLEDGE LOOP, telemetry & evals, gatedOPERATIONALLOOPlearns how to run -versioned, never silentDeferred and open items are not drawn and never lost: they live on the Decision Register page, with activation triggers.How to read this diagram• Left column: what P1Z builds once and every client reuses. Right column: the values one client fills in. The double-headed connectors between them are that exchange. Samestructure on both sides, only the contents differ.• Two MCP boundaries. The north gateway (between layers 1 and 2) is where hosts like Claude or Copilot connect; all code stays on the server. The south tool servers (layer5) are where agents reach data. Tenant identity is checked at the north, source permissions at the south.• Read top to bottom to follow a request. Build bottom to top; setup starts at layer 7. The knowledge loop promotes gated telemetry into benchmarks. The operational looptunes the harness. The two loops never mix.• Agents live in layer 2 and are reused unchanged; the plane only switches them on and arranges them. No code ever enters the client column.Point One Zero · generated view, scripts/generators/build_p1z_arch.py · v2.4 · seven layers + client plane

L6 Data & Documents PER-TENANT ISOLATION · DATA ENGINEERING

The storage half, split from Integration because the technology and the skillset differ (data engineers and architects: schema, indexing, retrieval quality). The stores are reusable templates; the client's instances and data are plane-side.

  • Vector DB, document store, SQL/warehouse services + retrieval APIs, provisioned per tenant from templates
  • Indexing & embedding jobs; taxonomy enforcement (document structures come from Knowledge)
  • Plane-side: tenant store instances (the client's actual data), document-to-taxonomy mapping, residency, retention & legal hold
  • Isolation verified by automated cross-tenant tests in CI
  • Restricted stores stay walled: excluded from every shared index and pipeline; entitlement-checked retrieval only
  • Never the system of record: originals stay in the client's source estate, every store here holds derived, disposable copies

Boundary test: nothing in another layer stores client data; nothing here knows what the data means.

Plane parameters: tenant instances · taxonomy mapping · residency · retention

Client-specific configuration for this layer is specified band by band in Client Delivery, C6 spec: every input with its binding key, generated artifact, and verifying check.

Component reference

Vector DB Service

Per-tenant vector collections powering semantic retrieval.

ImplementationProvisioned from templates at setup; per-engagement case indexes follow the scoped index lifecycle: created at open, destroyed at close.

Document Store Service

The platform's working copies of documents, with lineage attached.

ImplementationDerived, disposable copies only: the originals remain in the client's source estate, which stays the system of record.

Data Warehouse Service

Structured analytical storage per tenant.

ImplementationProvisioned per tenant from templates, or connected to the client's existing warehouse through the Integration layer instead of migrating it.

Retrieval APIs

The only read path agents use into tenant data.

ImplementationEntitlement-checked on every call; restricted stores are reachable only here; responses follow the high-signal, paginated tool standard.

Indexing & Taxonomy Enforcement

Classification and embedding jobs that keep stored content aligned to Knowledge's document taxonomy.

ImplementationStructures come from Knowledge; execution belongs to platform machinery in L7; taxonomy mapping per client is a C6 value.

Systems of Record

The client's ERP, CRM and fund administration systems.

ImplementationNever replaced and never written around: reached through the south servers, with the authority mapping deciding which source wins a disagreement.

Document Sources

VDR-class rooms, SharePoint, network drives: where documents actually live.

ImplementationRestricted stores stay walled: excluded from every shared index and pipeline, entitlement-checked retrieval only.

Unstructured Data

Notes, transcripts, recordings and similar loosely structured material.

ImplementationEnters through the ingestion pattern (P3) with PII screening at the door, before anything is stored or indexed.

External Data Providers

Market and benchmark data feeds.

ImplementationReached through the API gateway; programmatic-access license terms are captured in Discovery section D before any connection is built.