Security & guardrails

An agent that can move a furnace needs more than a good model.

Every capability is scoped, every write is policy-checked, every action is logged to storage the plant owns, and failure returns control to the systems already on the floor.

Defence in depth

Six layers between a model and a setpoint

A model's opinion never reaches a furnace directly. It passes through every one of these.

01

Typed tool registry

An agent can only call tools that exist in the registry, with declared tags, units and direction.

02

Tag allow-list

Each tool writes only to allow-listed tags, inside per-tag rate and magnitude limits.

03

Policy engine

Autonomy level, shift, product, interlock state and operator presence evaluated before every write.

04

Twin verification

Moves verified on Glastwin before they are proposed; discarded if stress or seed risk exceed site limits.

05

Human approval

Anything above the site threshold waits for a named glass technologist and their decision is logged.

06

Hard fallback

Loss of the edge node, the network or the model returns control to the existing furnace, forming and lehr systems.

Tool calls · scenario

Every call, on the record

Every tool invocation, argument and result is written to an immutable, human-readable log, and every reasoning step is expandable. Nothing about a run is hidden from the plant.

tool-call stream · scenario_fl2_01
  1. 02:14:03mes.read_orders({ line: "FL-2", next: "CLR-4MM" })
  2. 02:14:03ok spec locked · 4.0 mm · optical grade · stress limit set
  3. 02:14:04twin.simulate({ candidates: 36, horizon: "22 min" })
  4. 02:14:45ok best recipe #19 · seed risk low · stress inside spec
  5. 02:14:46policy.evaluate({ recipe: 19, autonomy: "L3" })
  6. 02:14:46ok 11 writes permitted · 1 write requires human approval
  7. 02:14:47scada.write_setpoint({ tag: "F1.PULL_SP", step: 1 })
  8. 02:21:07ok pull step 1 settled · fining stable · chemistry in window
  9. 02:21:08float.write_ribbon({ speed: "+", rollers: "re-angle" })
  10. 02:25:13ok thickness converging to 4.0 mm · flatness in tolerance
  11. 02:25:14lehr.write_curve({ zones: 12, profile: "4mm-fast" })
  12. 02:28:26ok residual stress inside spec at new belt speed
  13. 02:28:27vision.stream({ stations: 8, model: "seedscan-v3" })
  14. 02:28:41seed cluster · ribbon edge · attributed to pull transient
  15. 02:28:42cuopt.sequence({ objective: "cullet+energy" })
  16. 02:28:44ok transition ribbon routed to cullet · good ribbon to order
  17. 02:28:45approval.request({ action: "pull_step_2" })
  18. 02:29:33ok approved by the technologist on shift · logged
  19. 02:31:02isaac.plan_path({ stack: "A3", thickness: "4.0 mm" })
  20. 02:32:12ok paths validated in Isaac Sim · flagged plates diverted
  21. 02:33:15mes.log_lot({ lot: "FL2-4MM", genealogy: "full" })
  22. 02:34:17ok scenario run complete · stress in spec · 0 escaped seeds

Reasoning trace

Plan, thought, action, observation, exactly as the orchestrator would record it.

GoalMove FL-2 from 6 mm to 4 mm clear float with residual stress i…

Move FL-2 from 6 mm to 4 mm clear float with residual stress inside spec and zero escaped seeds.

PlanSimulate the transition on the twin first. Lead with furnace p…

Simulate the transition on the twin first. Lead with furnace pull so the ribbon mass flow is right before the forming change, then thin the ribbon, then re-shape the lehr curve. Watch the ribbon continuously; hold the second pull step for a human.

ThoughtThe standing recipe changes pull and ribbon speed together. On…

The standing recipe changes pull and ribbon speed together. On the twin that produces a fining transient that seeds the ribbon edge. Sequencing the pull step ahead of the forming change and holding fining removes most of it.

Actiontwin.simulate(candidates=36) returned recipe #19: pull in two …

twin.simulate(candidates=36) returned recipe #19: pull in two steps, forming change after fining settles, lehr curve re-shaped before belt speed rises.

ObservationRecipe #19 scored lowest on seed risk with stress inside spec.…

Recipe #19 scored lowest on seed risk with stress inside spec. Two candidates scored lower on energy but pushed residual stress over the site limit and were discarded.

ActionExecute recipe #19 under autonomy level L3: eleven setpoint wr…

Execute recipe #19 under autonomy level L3: eleven setpoint writes permitted, the second pull step routed to the glass technologist.

ObservationSeed cluster at the ribbon edge at 02:28:41, attributed to the…

Seed cluster at the ribbon edge at 02:28:41, attributed to the pull transient. cuOpt routed that ribbon to cullet recovery; no flagged plate reached a customer stack.

OutcomeScenario run complete. Thickness at 4.0 mm, residual stress in…

Scenario run complete. Thickness at 4.0 mm, residual stress inside spec, one approval gate, full genealogy written to the lot record.

Guardrails

An agent that can move a furnace needs a leash

Glasent writes to production equipment. Every capability is scoped, every write is policy-checked, and every action is written to an append-only audit log the plant owns.

  • Bounded action space. Each agent can only write to an explicit tag allow-list, inside per-tag rate and magnitude limits.
  • Policy engine before every write. Autonomy level, shift, product, interlock state and operator presence are all evaluated before a setpoint moves.
  • Human-in-the-loop gates. Anything above the site threshold, pull steps, grade releases, safety-adjacent moves, waits for a named approver.
  • Immutable audit log. Append-only, hash-chained, exportable, and retained on the plant's own storage.
  • Hard fallback. Loss of the edge node, the network or the model returns control to the furnace, forming and lehr systems' last known-good state.
  • Tenant and IP isolation. Compositions, forming recipes and defect libraries never cross a customer boundary. On-prem deployment available.

Compliance posture

Compliance and certification status
StandardScopeStatus
SOC 2 Type ICloud control plane RUNNING Planned in the first six months
SOC 2 Type IICloud control plane QUEUED Planned in months six to twelve
IEC 62443Plant-edge OT security RUNNING Design-aligned
ISO 9001 / IATF 16949Quality and genealogy records SUCCEEDED Record formats supported
Container and safety-glass standardsStress and defect conformance records SUCCEEDED Record formats supported

Read the security overview

Autonomy

Four levels, set per agent and per tag

A plant does not go from manual to unattended in one step. Glasent makes the level explicit, auditable and reversible at any time, and the first release plan is shadow, then assist, then graduated autonomy.

Autonomy levels and the human role at each
LevelWhat the agent doesWhat the person doesWhen
L1 · Shadow and advisoryObserves, predicts and recommends setpoints with its reasoningEnters every change manually; a baseline is measuredPilot weeks 1 to 3
L2 · AssistProposes a write; it executes on approvalApproves each write in the review consolePilot weeks 4 to 8
L3 · BoundedWrites inside tag, rate and magnitude limits on low-risk loopsApproves pull steps, grade releases and anything above thresholdPilot week 9 onward
L4 · UnattendedRuns the approved envelope without promptingSets the envelope; reviews the shift recordPlanned, after graduated autonomy proves out
Compliance

Certification status

Stated as it is: planned where planned, aligned where aligned, supported where the record format already exists.

Compliance and certification status
StandardScopeStatus
SOC 2 Type ICloud control plane RUNNING Planned in the first six months
SOC 2 Type IICloud control plane QUEUED Planned in months six to twelve
IEC 62443Plant-edge OT security RUNNING Design-aligned
ISO 9001 / IATF 16949Quality and genealogy records SUCCEEDED Record formats supported
Container and safety-glass standardsStress and defect conformance records SUCCEEDED Record formats supported
OT safety

Failing safe is a design requirement

Glasent is a supervisory layer on top of the plant's existing control systems, never a replacement for them.

  • Edge node loss returns control to the plant's own systems at their last known-good state
  • Network loss keeps the edge node running locally; no write depends on the control plane
  • Model loss falls back to the previous validated model version, then to advisory only
  • Interlocks and safety PLCs are read, never written
  • IEC 62443 design alignment for the plant-edge network zone

Writes are scoped, rate-limited and reversible. The policy engine does not know how to exceed a limit; the limit is enforced in the tool definition, not in the prompt. Every write names the model version, the policy version and the approver, so a bad move can be traced and the policy corrected.

Robot cells follow the same rule: Panebot paths are validated in Isaac Sim before deployment and executed only inside the cell's safety envelope, with the robot's own safety controller untouched.

Data

What leaves the plant, and when

Tenant isolation and IP protection are defaults. Cloud training is a choice.

Data flows by deployment option
DataOn-prem / air-gappedVPCCloud training
Process telemetryStays on siteYour VPCTenant-scoped, encrypted
Compositions and recipesStays on siteYour VPCNever used across tenants
Defect imageryStays on siteYour VPCTenant-scoped training only
Audit log and genealogyPlant storagePlant storage + VPC copyPlant storage + tenant copy
Model weightsDelivered to siteDelivered to VPCTrained per tenant
Cross-site learningNoneNoneFederated and privacy-preserving, planned

Federated fleet learning across similar glass families is planned, not built, and would share model improvements without exposing recipes or plant IP.

Multi-agent handoff

Agents negotiate, they do not collide

Two agents will want the same actuator. The orchestrator arbitrates on the run goal, not on who asked first, and the handoff is logged like any other step.

Contested move: furnace pull rate

  1. 01form_shape.request(pull hold) SUCCEEDED0.2 s

    Formeon wants pull held while the ribbon thins, to protect thickness convergence.

  2. 02batch_melt.request(pull step) SUCCEEDED0.2 s

    Meltrix wants the second pull step now, to settle fining before the seed rate climbs.

  3. 03orchestrator.arbitrate SUCCEEDED0.4 s

    Seed risk outranks a short thickness excursion under the run goal "zero escaped seeds". Meltrix wins the actuator, and because the step is above threshold it goes to the technologist.

  4. 04form_shape.handoff(returned) SUCCEEDED90 s

    Actuator returned; Formeon recovers thickness with roller angle instead. Both requests, the score and the reason are in the run record.

Arbitration rules

  • Run goal first. Every request is scored against the declared goal, not the requesting agent's local objective.
  • Safety and escaped defects outrank throughput. A stress fault in the field costs a recall; a thickness excursion costs minutes of ribbon.
  • Time-boxed ownership. An agent holds a contested actuator for a bounded window, then must re-justify.
  • Everything is logged. The losing request, the score and the reason all appear in the run record.
  • Deadlocks escalate to a person rather than resolving by timeout.

See the agent roster

Enterprise

Standardise autonomy across the group

One policy model, one audit trail, one benchmark across every line in every plant, with the composition and forming models kept private to each site.

Talk to us Enterprise details

  • SSO and role-based access down to the tag level
  • Group-wide autonomy policy with per-site override and approval chains
  • Cross-plant benchmarking on cullet, seeds, energy per tonne and first-pass quality
  • VPC, on-prem and air-gapped plant-edge deployment options
  • Custom composition, forming and tolerance models per site
  • Dedicated deployment engineer and quarterly model review per plant
FAQ

Straight answers

The questions plant directors and glass technologists ask in the first meeting.

Yes, but only within an explicit tag allow-list with per-tag rate and magnitude limits, and only at the autonomy level your site has set. Every pilot starts in shadow mode, where Glasent predicts and recommends and a person enters everything. Writes come later, after the recommendations have earned it.

Get started

Get the security pack

Architecture, data flows, the tag allow-list model and the audit log schema, for your IT, OT and quality reviewers.