SYSE.6:5 - Worked Case: Architecture Decision for the Heat-Pump Plant Controller
Engineers using SYSE.5 have produced two viable alternatives for an occupied-building heat-pump plant. In
alternative A, local unit controllers carry protection and normal regulation while a supervisor sends bounded
set-points. In alternative B, thermal storage and a tariff scheduler carry most time-shifting while local
controllers retain protection and regulation. Both can satisfy the current use concept; their structures and unresolved evidence
differ.
The project must choose the controller architecture for plant configuration HP-2 for the next three heating
seasons. Its architecture board is the decision subject; a separate project relation gives the board authority
to make this decision. The board’s assignment and the decision record do not create that authority. The resulting
ArchitectureDecisionRelation@Project selects these project-shaping structures:
- local protection remains within each unit boundary and does not depend on supervisor or utility communication;
- the supervisor can coordinate set-points only inside declared unit operating envelopes;
- plant-state and command interfaces carry units, timestamps, quality, validity, fallback, configuration, and effectivity conditions;
- a later storage branch can enter only through the declared thermal, control, configuration, and assurance interfaces.
The architecture board compares protection independence, room-comfort response, grid-flexibility response, integration burden, energy and cycling consequences, maintenance access, and continuing change. Each criterion names its bearer and conditions. Current evidence supports alternative A. Alternative B remains a future option because storage-cycling, plant-space, supply, and economic claims are not yet sufficient for the current commitment.
The accepted loss is less global optimization than the most centralized candidate predicts. The decision protects local fail-safe behavior and records the operating evidence that can reopen the balance. Algorithm choice, hardware supplier, detailed state estimator, and user-interface design remain open refinements provided they preserve the fixed structures and guardrails.
The controller and integration teams use the fixed structures while shaping controller, bench, installation,
and integration Work with SYSE.3. Configuration and interface-version Work uses SYSE.13; utility-signal
authority and service conditions are handled with SYSE.18. Model and trial results are assessed through
SYSE.10, and the assurance question is handled through SYSE.4. The Agents performing these neighboring
Work occurrences apply their respective Methods, and each Work occurrence produces its own result for its named
receiving use. The architecture decision only supplies relevant constraints and questions.
The architecture board reconsiders the decision if communication-loss trials violate local protection,
room-comfort or cycling observations cross their guardrails, the utility changes signal semantics, storage enters
current project scope, or the installed structure diverges materially from the selected option. A new decision
then names the changed configuration, remaining horizon, unresolved evidence gaps, and operating envelope. It may
supersede the earlier decision.
The architecture decision does not make the plant configuration obtain. After integration, observations of the actual installed Systems and relations are compared with the decision content. A different wiring, fallback, or control allocation is an implementation divergence even if the architecture record was left unchanged.