Skip to content

TECHNICAL PREVIEW · IN ACTIVE DEVELOPMENT

ALL NOTES

DEPLOYMENTS

The line does not stop for the network

A production line runs to a takt, and a stoppage propagates through buffers that were never sized to absorb it. That is why a runtime dependency on a link outside the building is a scheduling risk rather than an IT risk.

· 8 min read

A stopped line is not an outage. It is a missed commitment, and it shows up in the contract before it shows up in an incident report. A line runs to a takt — a fixed interval at which a unit has to leave each station — and that interval is not an internal preference. It is derived from what the plant has committed to produce, and every station, buffer, and staffing decision on the floor has been sized against it.

The sizing is what makes interruption expensive. Buffers between stations absorb ordinary variation: a fastener that binds, a fixture that needs a second attempt, an operator who steps away. They are deliberately small, because material sitting between stations is capital doing nothing, and any plant that has been optimized at all has spent years making them smaller. A buffer scaled to seconds of variation does not absorb minutes of stoppage. It drains, the station downstream starves, the station upstream blocks, and the disturbance walks outward in both directions faster than anyone can intervene.

So a system that introduces a runtime dependency on a link leaving the building is not asking a plant to accept an IT risk. It is asking the plant to accept a scheduling risk with a counterparty it cannot audit, cannot escalate to, and cannot hold to a maintenance window. Those are different conversations, held by different people, and the second is much harder to win.

What a stoppage actually costs

The units not built are the smallest part of it. A line does not resume the moment the cause clears. Work in process may have gone out of tolerance while it sat — adhesives skin over, thermal processes fall out of window, anything mid-cure or mid-cycle when motion stopped may be scrap. Restart is its own procedure, frequently manual, frequently requiring someone to walk the line and confirm state before motion is re-enabled.

Then the consequences leave the building. Downstream commitments are dated. Inbound material arrives on a schedule built around a rate the plant is no longer holding, so time lost on the floor keeps disturbing a receiving dock well after the line is running again. None of this is visible from the perspective of the software that caused it, which observed a link failure and a retry.

The asymmetry is what makes wide-area dependencies so poorly suited here. A link outside the building fails rarely enough that nobody plans for it and often enough that it happens. Rare failures with expensive consequences are the class of risk that industrial engineering exists to design out rather than to monitor. A plant that would not accept a single unbackstopped air compressor is being asked to accept a single unbackstopped connection to somewhere else, and it will notice.

The plant was here first

The second thing that distinguishes a manufacturing floor is that it is not empty. Nearly every plant that would benefit from a fleet of learning machines is a brownfield site with decades of accumulated automation already running, and that automation already holds actuation authority. Programmable logic owns the cells it owns. Interlocks own the safe states they own. Light curtains, two-hand controls, and stop circuits are validated as a system, and that validation is a document with a signature on it.

A new compute plane does not arrive at the top of that hierarchy. It arrives as a subordinate participant, and the honest framing is that it requests while the existing safety system disposes. That is not a limitation to be engineered away later. It is the correct arrangement, because a learned model is the least predictable software on the floor, and the case for letting it near a stop circuit is weak in precisely the way the case against it is strong.

The same history produces a second constraint. Automation on a floor is rarely from one vendor and rarely from one decade. A cell installed years ago speaks its own protocol, exposes its own idea of state, and was commissioned by people who may no longer work there. There is no single abstraction to coordinate through, because no such abstraction was ever agreed on. A coordination layer that assumes it can see and command everything on the floor is describing a plant that does not exist, and a representation that coordinates heterogeneous automation without flattening away what makes each piece useful is unfinished work.

The method is the asset

Process data is sensitive in a way worth separating from the more familiar case of personal data. Privacy-sensitive data is sensitive because of whom it concerns, and the remedies are correspondingly procedural: consent, minimization, redaction, retention limits. Trade-secret process data is sensitive because of what it discloses about how the plant does the work, and there is no procedural remedy, because the disclosure is the content.

Consider what a camera pointed at a line captures. Fixturing and tooling geometry. The order of operations, and the places where that order differs from the obvious one. Where the human interventions are, which is where the process is still hard. Rework, visible in how often a part comes back. A competent engineer from a competitor learns more from that footage in an afternoon than from years of inference from outside the fence. A video of the line is a disclosure of the method.

Yield telemetry is the same problem in numeric form. The value of a mature process concentrates in the gap between what it should achieve and what it does achieve, and that gap is exactly what the data records. This is why the export question is not settled by encryption in transit or by contractual assurances about who may look. The plant's objection is to the copy existing at all, somewhere it does not control, subject to a subpoena, an acquisition, or a change of terms it will not be consulted about.

Radio behind steel

The floor is also a hostile radio environment, which deserves stating plainly because it is usually treated as an implementation detail. A plant is full of steel — machine frames, racking, conveyance, the building itself, and large metal objects that change propagation as they move — while motor drives, welders, and induction equipment put broadband noise next to the machines that most need coverage. Where coverage fails, it tends to fail in the most enclosed cells and aisles, which are often where a machine is doing the most delicate work.

None of this makes wireless useless on a floor. It makes wireless a medium with a variable and partly unobservable error rate: acceptable for telemetry, unacceptable as the path a machine depends on in order to think. A system whose capability degrades with coverage will also be judged by its behavior in the worst cell rather than the average one, because the worst cell is where the plant will test it.

The conversation a new system has to survive

Change management in a plant is not a formality. On a floor that has been running, every change is suspected of causing the next problem, and that suspicion is usually well earned. Anything new enters a process that asks what it does, what it touches, how it fails, and who is accountable when it does, because undocumented modifications are how good processes quietly become bad ones.

Two questions come up early and decide a great deal. The first is whether the plant can inspect the thing. A general-purpose computer on the floor running unspecified software is difficult to answer for, because the honest answer to what is running on it is that nobody entirely knows. The second is whether the vendor needs a path in. A remote support tunnel is an outside party with reach into the production network, and industrial security organizations have spent a decade arguing that arrangement down.

A sealed node answers both narrowly rather than reassuringly. If a node boots from a signed, read-only image carrying one defined workload, the question stops being what might be running and becomes whether this is the image that was approved — which has a cryptographic answer rather than an assurance. If egress is default-deny, with every interface to plant systems declared, checked, and logged, then the answer to what this thing can reach is a list rather than a policy. That is an argument built for the people who actually decide whether the system goes in.

What the plane is for here

Strip away what manufacturing shares with every other environment and what remains is specific. A plant needs coordination and inference that run in local time on its own switches, so that no link outside the building sits in the path of a decision with a takt attached to it. It needs the fleet to get better at this plant's work, which means adaptation on the plant's own data, between shifts, inside the fence. And it needs the process to stay in the building — not by policy, but because the system has nowhere to send it.

E31 Network is being designed against that shape: edge nodes that keep their machines productive when nothing else is reachable, a facility plane holding coordination and heavy inference inside the boundary, and a fleet plane that can prove integrity across sites while remaining blind to what any site makes or how it makes it. The line does not stop for the network, because the network was never in the loop.

DESIGN PARTNER PROGRAM

Build this with us.

We are working with a small number of teams operating real fleets in constrained environments. If the cloud is not an option where your machines work, we want to talk.