Platform · capability group
Data Plane
Where an answer's inputs come from, under which licence, and what the record of that is.
EN This publication is published in English only. Site navigation is available in 18 languages.
The Data Plane is the layer the architecture freeze identified as missing rather than wrong [A]. Everything else in the reconciliation refined something that already existed. This did not exist.
It is a capability grouping, not a ninth plane. The plane model has eight and that number is fixed. The Data Plane's parts answer to the Knowledge plane for retrieval and to the Policy and Authority planes for entitlement
[D](data-plane, S4).
That sentence is load-bearing and it is the reason this page exists at all: a layer that was missing attracts scope, and the fastest way to turn a correct addition into an architectural defect is to let website copy promote it to a plane.
Status. Specified, not implemented. No source is integrated, no contract is signed, and no figure on this page has been measured [D] (data-plane, S4).
The four parts
| Part | Owns | Status |
|---|---|---|
| Source Registry | What sources exist, what they cover, how they are reached, and — separately — what this tenant's contract permits | S4 |
| Provenance Passport | The per-datum record of origin, entitlement and expiry, attached at ingestion, propagated through derivation, enforced at use | S4 |
| Data Router | Which source answers this question, under authority, freshness, coverage, cost, latency, licence, jurisdiction and permission | S4 |
| Source Intelligence | How each source has actually performed, and what the system does when two of them disagree | S5 TARGET |
The moat is explicitly not the connectors
A connector catalogue is a list of integrations somebody else can also write. Anyone can integrate a market-data vendor; roughly two hundred companies have [A]. What is not purchasable is a per-datum record of which source answered which question, under which entitlement, and whether it turned out to be right — because that record cannot be bought, cannot be scraped, and cannot be reconstructed after the fact [A].
This is why the Provenance Passport is specified as P0 and non-waivable while the rest of the plane may move [D] (data-plane.provenance-passport, S4). Everything else in the plane can be added later. The Passport cannot: a datum ingested without one is a datum whose rights are permanently unknown, and UNKNOWN is enforced as deny.
Boundaries, stated as refusals
The Data Plane:
- Refuses to return a datum without a Provenance Passport. No permissive path, no development flag, no log and continue branch
[D](data-plane.provenance-passport, S4). - Refuses to treat API access as evidence of any right beyond reading. Being able to
GETa resource says nothing about whether it may be cached, retained, derived from, embedded, redistributed or trained on[A]. - Refuses to resolve a contradiction by choosing. Two sources that disagree produce a contradiction and a re-route to a more authoritative primary source, or a contested claim carrying both values. Never a silent winner
[D](data-plane.source-intelligence, S5). - Refuses to select a source the tenant's entitlement does not cover for the declared purpose. Admissibility runs before scoring, so an inadmissible source is never scored and can therefore never win on quality. That ordering is a security property, not a performance one
[A]. - Refuses to escalate to a paid rung without a budget grant. On evidence-intensive work, premium data routinely costs more than the inference performed over it
[A]. - Refuses to own storage. It writes into the stores that already exist. It does not introduce a fourth store
[D](data-plane, S4).
What it does not own
| Not owned | Owner |
|---|---|
| The evidence store itself | Knowledge Graph |
| The Source Intelligence store | Execution Store — Source Intelligence is a view, not a store |
| The stopping rule | Compute Governor |
| Retrieval strategy — dense, sparse, hybrid, graph | Retrieval Router |
| Identity resolution across sources | Knowledge Graph |
| Tenant permissions and residency policy | Policy and Authority |
| Connector execution and credentials | Tools and Connectors |
The two routers are not one router
The Data Router selects a source. The Capability Router selects an executor. They are different decisions over different catalogues, and the corpus refuses the unqualified word Router for exactly this reason: once a capability, a source and a verifier are all being selected, an unqualified name makes three things ambiguous [A].
Open, and named rather than absorbed
The ownership of one boundary — where the Passport is written versus where it is believed — is recorded as unresolved and escalated rather than settled in copy [O].