Library / Systems Engineering Principles Framework
Jump to passage
In this reading

Link to current text

Published source confirmed at last check

Source changed 2026-10-03 05:29:54 UTC · snapshot created 2026-10-03 05:30:57 UTC · last check 2026-10-03 06:30:20 UTC

SYSE.7:5 - Worked Case: Controller Architecture Description Ensemble

The project is preparing evidence for a controller-architecture decision: whether plant configuration HP-2 should use direct compressor modulation alone or modulation coordinated with thermal storage over the next three heating seasons. The plant, use, configuration, and decision focus are the same across the selected inputs. Outside-use, functional, and bearer descriptions already exist, but the decision-changing claims remain distributed across several descriptions. The engineering team constructs this bounded account:

EntrySubject and useMaterial interpretation or relation
use and operating-scenario epistemeThe intended heat-pump plant in occupied-building use; supplies temperature, noise, maintenance, power-price, and grid-response situations.Scenarios are possible use descriptions, not performed operation or test evidence.
functional-organization epistemeCandidate control organization: demand estimation, compressor modulation, storage dispatch, limit protection, and fault handling.Treat the listed elements as functions until separate bearer and realization relations assign them to controller modules or software processes.
bearer-and-interface accountCandidate controller hardware, plant sensors, actuator connections, storage valve, communication interfaces, and allocations.Names candidate Systems, physical interface specifications, and many-to-many function allocations for the decision.
equation-based plant modelThermal plant and storage behavior under selected boundary conditions.Modelica equations describe one selected physical abstraction; solver output is not observed plant behavior.
controller state and timing descriptionControl states, transitions, sampling assumptions, fallback conditions, and actuator commands.The description concerns intended controller behavior and must correspond to the hardware timing and sensor claims.
component and wiring recordsSensor variants, controller I/O, update rates, error bounds, cable and connector configurations.Catalogue claims apply only to component variants and conditions.
bench and commissioning resultsObservations from controller-in-the-loop Work and later installed-plant trials.Engineers use SYSE.10 to qualify which engineering claims those results support and SYSE.13 to keep tested configurations explicit.

A collision check finds that the plant simulation and controller description assume a two-hertz supply-water temperature update with an error bound of plus or minus 0.1 kelvin. The currently selected procurement variant is specified only for a half-hertz update and plus or minus 0.3 kelvin under the installed cable length and filtering arrangement. Matching the token SupplyTemperatureSensor across three tools had hidden the difference.

The engineers recover the sensor variant and interface configuration instead of merely synchronizing names. They update the model-use assumptions, evaluate another component and estimator option, and perform a controller-in-the-loop trial. The resulting evidence revises the architecture comparison: direct modulation remains acceptable for one building profile, while the storage branch remains unselected until it has either the faster sensing configuration or a different estimator and the corresponding assurance result. This evidence informs the current decision; it does not approve a later storage increment.

The account records the usable description editions, the unresolved estimator claim, the tested configuration, and a reconsideration condition tied to component substitution or a changed grid-response requirement. Controller, procurement, integration, configuration, and assurance Work use different publication forms over recoverable source epistemes while the decision-changing relations remain explicit. The result stays bounded to this decision.

An AI System also produces a proposed cross-description summary and candidate correspondence list. Those outputs are new epistemes produced by performed Work. They are checked against source editions and accepted only where the relation and participants are recoverable. The generated confidence score supplies neither an evidence relation nor authority to alter the architecture decision.