Operational mechanisms

Follow the flow through failure, recovery, and proof.

See who owns each decision, what happens after a duplicate or disconnect, whether a machine acknowledged work, how money reconciles, and how your data can leave.

Operational continuity

Keep control when the flow crosses a boundary.

The mechanisms below reduce reconciliation work, preserve failure ownership, and keep evidence portable.

LESS RECONCILIATION

One current execution context

People do not have to rebuild order, inventory, machine, shipment, and cost state from separate exports after the fact.

SAFER RECOVERY

Failure remains visible and owned

Duplicate, disconnected, rejected, timed-out, and physically contradictory states identify the affected work and authorized recovery path.

BETTER EXIT CONTROL

Evidence survives the vendor boundary

Audit, connector scope, transaction proof, and tenant export make important limits and ownership testable before contract signature.

Delivery layers

Product capability, environment configuration, and measured results.

Product mechanisms are implemented once; equipment, credentials, topology, operating policy, and measured outcomes are established for each deployment.

PRODUCT

Platform mechanism

The state, authorization guard, workflow, evidence, and automated validation ship with the platform.

DEPLOYMENT-SPECIFIC

Environment binding

Equipment dialect, credentials, topology, carrier account, and operating policy must be configured and qualified.

OPERATING RESULTS

Measured deployment

Throughput, uptime, implementation duration, and operating outcomes are recorded from the deployed environment.

Trace 01 / merchant shipment

One commercial and physical evidence chain.

The useful difference is not another dashboard. It is keeping client identity, warehouse execution, carrier purchase, and money movement correlated without exposing internal buy cost or warehouse controls.

Merchant intent → stock truth → label evidence → settlement

01 / IDENTITYCanonical product

Merchant SKU and barcode aliases bind to packaging, lot, serial, and expiry rules.

02 / INBOUNDVersioned plan

Cartons, labels, booking, documents, amendments, and discrepancy responses retain versions.

03 / INVENTORYWarehouse truth

Receipt, quality, ownership, location, holds, reservations, and availability govern promise.

04 / QUOTEImmutable sell price

Carrier, service, parcels, expiry, price lines, total, and signature are snapshotted for the client.

05 / PURCHASEDurable orchestration

One idempotency key joins funding reserve, carrier request, capture, receipt, and transition history.

06 / EVIDENCELabel to ledger

Tracking, download, reprint, void, provider refund, reconciliation credit, and ledger remain explicit.

What the merchant actually sees

Exact sell price and funding readiness before purchase.

The client sees carrier service, surcharge and tax lines, total, quote expiry, proof reference, wallet coverage, and allowed funding choices. Carrier buy cost and operator margin stay outside the client-owned quote.

  • Repeated submission resolves to one client purchase.
  • Card action can resume the durable purchase instead of creating another.
  • Void does not silently erase the original charge or evidence.
XMS Cloud merchant shipment quote with exact price, price lines, proof reference, wallet coverage, and label purchase
Implemented client surface using deterministic, non-customer fixture data.

Trace 02 / human or robot

One task can choose an executor without creating two owners.

The arbiter can compare eligible human and robot candidates. A typed resource reservation is handed to the canonical operator queue or robot mission, then released from terminal state.

Business demand → reserved capacity → acknowledged execution

01 / DEMANDWork task

Domain task, priority, warehouse, source, destination, capability, and business context.

02 / CANDIDATESScore resources

Role, robot capability, queue state, availability, location, safety, and operating policy.

03 / RESERVELease one resource

Typed resource, holder, priority, TTL, state, source, and decision correlation.

04 / HANDOFFUse canonical executor

Human queue assignment or AGV mission is created or recovered idempotently.

05 / OBSERVERead acknowledgement

Mission reports or semantic command ack/complete tags advance observed state under a watchdog.

06 / RECONCILEClose or diverge

Terminal work releases the hold; occupancy mismatch raises a de-duplicated alert until clean.

Machine authority

Mission is not motion. Unknown is not safe.

XMS can issue governed mission or semantic command intent. Vendor controllers and safety PLCs retain device motion and interlocks. A missing permissive, poor tag quality, timeout, or unclassified fault blocks blind progression.

  • Named command allowlist and bound tags.
  • Configured permissives checked before write.
  • Issued, acknowledged, completed, rejected, or timed-out handshake.
  • Unknown faults require classification and manual safe-state confirmation.
XMS Cloud AGV control showing live robot health, missions, dispatch, and position
Fleet state and mission supervision; vendor and safety controllers remain authoritative.

Nine operating mechanisms

How the platform maintains control across boundaries.

Each mechanism exposes its state, edge conditions, recovery path, and resulting operational artifact.

DIF-001

A shared reservation view that does not fight existing owners.

Inventory, bins, lanes, docks, lift cells, traffic zones, work items, robots, and operators share a typed hold shape. Existing silo leases are projected read-only; native arbiter claims use priority, TTL, lifecycle, and correlation.

ImplementedWES / MAO
Test it

Contend one human and one robot for eligible work. Inspect the winning decision, one hold, canonical handoff, crash recovery, and release.

DIF-002

System intent is checked against physical occupancy.

Occupied-without-reservation, reserved-without-occupancy, and over-capacity observations create one evolving alert. A clean rescan resolves it automatically rather than hiding drift behind a green mission state.

ImplementedPhysical reconciliation
Test it

Occupy a lane without a hold, scan twice, clear it, and verify one alert is updated then resolved.

DIF-003

OT commands are allowlisted handshakes, not raw writes.

A named command checks configured permissives and tag quality before issue. A watchdog then records acknowledgement, completion, rejection, or timeout. PLC and safety logic remain final authority.

ImplementedEquipment binding required
Test it

Remove a permissive, degrade a tag, and withhold acknowledgement. Verify no blind write and an observable timeout.

DIF-004

The digital twin has a governed route into live layout.

Warehouse designs retain immutable revisions, lineage, checksums, row versions, review, and separate approval. Materialization previews structural adds, updates, deletes, coordinate change, and excluded operational state before apply or rollback.

ImplementedFour-eyes apply
Test it

Branch a published design, edit a rack, attempt self-approval, preview the diff, apply as a second user, then roll back.

DIF-005

Offline authority is allowlisted instead of pretending every write is safe.

Devices queue ordered events. Replay verifies registered device, operator, warehouse, source type, session, sequence, age, payload bounds, and idempotency. Unsupported mutations require reconnection.

ImplementedWorkflow allowlist
Test it

Disconnect during supported work, retry an event, skip a sequence, attempt a blocked action, reconnect, and inspect each result.

DIF-006

Connector readiness records uncovered scope.

Catalog entries bind to adapter class, protocol, version range, owner, lifecycle, limitations, and build. Validation reports Passed, Failed, or ScopeLimited with skipped scenarios, uncovered capability, artifacts, and version drift.

ImplementedProduction qualification separate
Validation scenario

Run contract and emulator validation for the proposed build, then inspect covered, skipped, and unsupported scope.

DIF-007

Tenant exit produces a versioned, verifiable archive.

The takeout manifest identifies datasets and entities with schema versions, row counts, sizes, SHA-256 hashes, product version, and an audited download path.

ImplementedContracted dataset review
Test it

Request an export, reconcile counts and hashes, then import selected files into an independent data store.

DIF-008

Label buying is an immutable commerce state machine.

The client sell quote is snapshotted and signed. Purchase retains one idempotency key, funding and carrier states, transition history, receipt, evidence, void reason, and explicit provider-refund reconciliation.

Merchant releaseCarrier and Stripe accounts
Test it

Submit twice, interrupt after reserve, resume card action, reprint, void, and post a confirmed carrier refund. Demand one trace.

DIF-009

Printers and scanners connect to warehouse devices—not the backend.

The backend authorizes business jobs and artifacts. The bound workstation or handheld owns local scanner, camera, BLE/GATT, or printer transport, checks payload compatibility, and returns acknowledgement as evidence.

Implemented adaptersDevice profile required
Test it

Remove WAN, retain the local station, reject a mismatched printer payload, and show there is no backend-to-printer socket.

Failure behavior

Six scenarios that exercise recovery.

Each scenario links the trigger to expected system state, operator guidance, and recovery evidence.

Duplicate event

Retry the same mutation.

The same operator event or purchase key must resolve to the existing outcome; a cross-user key collision must be rejected.

WAN interruption

Disconnect mid-work.

Only approved offline actions continue. Pending events retain order, poison events cannot starve the queue, and reconnection reconciles visibly.

Unsafe machine state

Remove a permissive.

The semantic command must stop before write, identify the blocked condition, and never infer that an unknown fault is safe.

Physical divergence

Move without the expected hold.

Reservation and occupancy disagreement must raise a persistent operational alert and clear only after observation or explicit resolution.

Concurrent layout edit

Change the live baseline.

Row-version or checksum drift must invalidate stale approval/materialization rather than silently overwrite the newer design.

Incomplete connector proof

Request unsupported depth.

The run must report ScopeLimited and list what was skipped or not covered—not convert missing evidence into a pass.

Migration continuity

Capabilities from your previous system move into the product; there is no separate legacy mode.

Daily operational workspaces are kept apart from migration-only import, reconciliation, and finalization controls, so migrated and new tenants use the same contracts, permissions, and evidence.

COMMERCE

Marketplace and shop connectors

Back Market, WiziShop, Boostmyshop, Winpharma, Market Invaders, StoreFactory, Magento, Shopify, and relay-point mappings live in Integrations with per-connector readiness status.

PRICING

Carrier accounts and tariff grids

Weight × zone grids, fuel indices, remote-zone fees, insurance, client assignments, and known-carrier sell pricing live in transport network and rating.

MONEY

Transport transactions and billing

Freight audit, carrier invoices, allocation, settlement, invoice runs, detail annexes, credit notes, payments, and GL output use canonical finance workspaces.

CUTOVER ONLY

Import and reconciliation controls

Legacy source-file ingestion, source reconciliation, and bounded draft-transaction finalization remain governed migration controls rather than everyday navigation.

Deployment validation

Run each workflow with evidence you can retain.

Use your data shape and target build, then retain the screen, API response, event, audit, or export produced by each scenario.

One order across domains

Import demand, reserve stock, assign human or robot work, pack, buy a label, dispatch, receive a carrier event, and trace cost and evidence without spreadsheet correlation.

One 15-minute network cut

Run supported mobile work offline, attempt a prohibited mutation, reconnect, and reconcile ordered events without duplicates or hidden loss.

One equipment rejection

Fail a permissive and an acknowledgement. Verify command refusal, watchdog state, operator context, and manual safe restart boundaries.

One tenant-boundary attack

Use a valid client A identity against client B inventory, order, quote, ledger, and export identifiers. Require denial below UI filtering.

One connector upgrade

Change adapter build, show certification drift, run conformance with a failure injection, and inspect covered, skipped, and unsupported capability.

One exit rehearsal

Generate a tenant takeout, validate manifest hashes and row counts, and load representative datasets independently before contract signature.

Deployment results

Measure the platform in your operating environment.

REFERENCE

Comparable operating profile

Compare volume, automation, regions, tenancy, and operating model with relevant deployment references.

PERFORMANCE

Your measured load

Benchmark throughput, latency, recovery, queue depth, and data growth on the proposed deployment architecture.

DELIVERY

Your implementation burden

Bind timeline, custom-code share, integration ownership, data migration, training, and cutover gates to a statement of work.

ASSURANCE

Your contract controls

Validate certifications, residency, SLA, support, incident, retention, export, and deletion terms separately.

Validate a difficult state

Run the workflow through its recovery path.

Choose one merchant shipment, warehouse move, robot mission, integration failure, tenant boundary, or export and define the expected artifact.