Skip to content

Platform · capability group

Data Plane

Where an answer's inputs come from, under which licence, and what the record of that is.

EN This publication is published in English only. Site navigation is available in 18 languages.

The Data Plane is the layer the architecture freeze identified as missing rather than wrong [A]. Everything else in the reconciliation refined something that already existed. This did not exist.

It is a capability grouping, not a ninth plane. The plane model has eight and that number is fixed. The Data Plane's parts answer to the Knowledge plane for retrieval and to the Policy and Authority planes for entitlement [D] (data-plane, S4).

That sentence is load-bearing and it is the reason this page exists at all: a layer that was missing attracts scope, and the fastest way to turn a correct addition into an architectural defect is to let website copy promote it to a plane.

Status. Specified, not implemented. No source is integrated, no contract is signed, and no figure on this page has been measured [D] (data-plane, S4).

The four parts

PartOwnsStatus
Source RegistryWhat sources exist, what they cover, how they are reached, and — separately — what this tenant's contract permitsS4
Provenance PassportThe per-datum record of origin, entitlement and expiry, attached at ingestion, propagated through derivation, enforced at useS4
Data RouterWhich source answers this question, under authority, freshness, coverage, cost, latency, licence, jurisdiction and permissionS4
Source IntelligenceHow each source has actually performed, and what the system does when two of them disagreeS5 TARGET

The moat is explicitly not the connectors

A connector catalogue is a list of integrations somebody else can also write. Anyone can integrate a market-data vendor; roughly two hundred companies have [A]. What is not purchasable is a per-datum record of which source answered which question, under which entitlement, and whether it turned out to be right — because that record cannot be bought, cannot be scraped, and cannot be reconstructed after the fact [A].

This is why the Provenance Passport is specified as P0 and non-waivable while the rest of the plane may move [D] (data-plane.provenance-passport, S4). Everything else in the plane can be added later. The Passport cannot: a datum ingested without one is a datum whose rights are permanently unknown, and UNKNOWN is enforced as deny.

Boundaries, stated as refusals

The Data Plane:

  • Refuses to return a datum without a Provenance Passport. No permissive path, no development flag, no log and continue branch [D] (data-plane.provenance-passport, S4).
  • Refuses to treat API access as evidence of any right beyond reading. Being able to GET a resource says nothing about whether it may be cached, retained, derived from, embedded, redistributed or trained on [A].
  • Refuses to resolve a contradiction by choosing. Two sources that disagree produce a contradiction and a re-route to a more authoritative primary source, or a contested claim carrying both values. Never a silent winner [D] (data-plane.source-intelligence, S5).
  • Refuses to select a source the tenant's entitlement does not cover for the declared purpose. Admissibility runs before scoring, so an inadmissible source is never scored and can therefore never win on quality. That ordering is a security property, not a performance one [A].
  • Refuses to escalate to a paid rung without a budget grant. On evidence-intensive work, premium data routinely costs more than the inference performed over it [A].
  • Refuses to own storage. It writes into the stores that already exist. It does not introduce a fourth store [D] (data-plane, S4).

What it does not own

Not ownedOwner
The evidence store itselfKnowledge Graph
The Source Intelligence storeExecution Store — Source Intelligence is a view, not a store
The stopping ruleCompute Governor
Retrieval strategy — dense, sparse, hybrid, graphRetrieval Router
Identity resolution across sourcesKnowledge Graph
Tenant permissions and residency policyPolicy and Authority
Connector execution and credentialsTools and Connectors

The two routers are not one router

The Data Router selects a source. The Capability Router selects an executor. They are different decisions over different catalogues, and the corpus refuses the unqualified word Router for exactly this reason: once a capability, a source and a verifier are all being selected, an unqualified name makes three things ambiguous [A].

Open, and named rather than absorbed

The ownership of one boundary — where the Passport is written versus where it is believed — is recorded as unresolved and escalated rather than settled in copy [O].