JLT-Lane Blueprint Factory
← Documentation Plane

Canonical Architecture Projection

Governed Factory Workflows

These diagrams are governed visual projections of the Blueprint Factory architecture at:

branch: main
commit: 97e78aca2af295353da3f02f55bed06fd2908841
tree:   f0db9eea53773078cc215efb829c58ebec4c7f97

They explain implemented and contract-defined architecture. They do not activate runtime consumers, issue authority, admit packages, provision infrastructure, deploy platforms, or authorize production promotion.

Legend

Visual roleMeaning
Green componentImplemented reference mechanism
Blue objectNeutral contract, request, manifest, record, or evidence
Yellow object or dashed pathContract-defined but not operationally implemented
Gray object or dashed containerPlanned or explicitly inactive capability
Red object or connectorDenial, rejection, or failed result
Orange object or connectorException or indeterminate outcome
Green result or connectorSuccessful evidence or decided result
Dashed containerOwnership or trust boundary—not automatic permission

REFERENCE, CONTRACT ONLY, INACTIVE, PLANNED, and DENYALL are capability-status labels. A boundary crossing is meaningful only where a source-supported request, evidence object, port, or decision crosses it. A manifest describes architecture; it does not provide executable authority.

1. Catalog and registry ingress

Catalog and registry ingress
Catalog and registry ingress

Source truth: The legacy adapter supplies canonical Blueprint manifests only. Module, Capability, and Component collections enter their independently owned registries separately before the four registries are assembled into FactoryRegistrySet for resolution bootstrap.

2. Versioned registry selection

Versioned registry selection
Versioned registry selection

Source truth: A registry selects an exact requested version or the highest active version and returns explicit failure results. Registry selection does not flow directly to Construction, admission, provisioning, or deployment.

3. Resolution Engine

Resolution Engine workflow
Resolution Engine workflow

Source truth: Resolution bootstraps immutable context from ProvisioningRequest and FactoryRegistrySet, then executes injected resolvers in order. The pipeline owns ordering; each resolver owns its architectural decision. The first succeeded:false result stops the pipeline and returns that resolver's context.

4. Construction Engine

Construction Engine workflow
Construction Engine workflow

Source truth: Successful resolution evidence authorizes Construction consideration only. The reference Construction Engine returns construction evidence and an untrusted candidate, or construction diagnostics. It does not validate itself or call the repository.

See Construction EnginePublic projection pending.

5. Independent package validation

Independent package validation
Independent package validation

Source truth: Unknown input passes independent structural, identity, manifest, asset-closure, provenance, and integrity checks. Acceptance returns the exact validated package plus validation evidence; rejection returns diagnostics. Validation is not admission or deployment.

See Governed Artifact PackagingPublic projection pending.

6. Governed Package Repository

Governed Package Repository
Governed Package Repository

Source truth: Injected authority verification gates admission and retrieval. The in-memory adapter is a REFERENCE custody mechanism, not a durable production store. Admission, retrieval, lifecycle events, and audit records retain separate result semantics.

See Governed Package RepositoryPublic projection pending.

7. Package admission orchestration

Package admission orchestration
Package admission orchestration

Source truth: The coordinator orders Construction, independent validation, and conditional admission without creating or strengthening the supplied authority grant. A repository exception after invocation is admission-indeterminate; no rollback or repository absence is claimed.

See Governed Package Admission OrchestrationPublic projection pending.

8. Package access flow

Package access flow
Package access flow

Source truth: Authentication and authorization are separate boundaries. Authentication integration, an allow implementation, a grant issuer, an external runtime consumer, and a public endpoint are absent. The reference policy is DENYALL; its compatibility adapter supplies authenticatedPrincipalId:null and fails closed.

See Package AuthorizationPublic projection pending.

9. Governed Factory end to end

Governed Factory end-to-end workflow
Governed Factory end-to-end workflow

Source truth: The governed Factory path crosses independently owned Catalog, Resolution, Construction, Validation, Admission Orchestration, Package Authorization Verification, and Repository Custody boundaries. Beyond custody, Release Evidence & Eligibility is CONTRACTED, Deployment Planning has a deterministic provider-neutral REFERENCE implementation, and Execution Authorization is CONTRACTED. The Provider Adapter Boundary, Provisioning Execution, Deployment Execution, Runtime Verification, and Operations & Intelligence remain PLANNED. Release eligibility does not grant execution authority; a deployment plan is not a mutation permit; execution-authorization contracts do not constitute an authority issuer or provider-execution capability.

Authority boundary

These visual projections confer no runtime, authentication, authorization, package-admission, publication, release, provisioning, deployment, provider-execution, operational, or production-promotion authority.