Skip to content
Terranoux

Physical AI

Engineering that tests its own assumptions.

Some uncertainties only a physical experiment can settle: friction on a real surface, the strength of a printed part, a film's resistance after annealing. This part of Terranoux turns those questions into bounded, measured, auditable runs, and sends the evidence back into the design.

Design stageFormats and examples on this page are drafts and will change.

Overview

Hypothesis, experiment, measurement, design update.

The engineering model decides what it needs to know. Authority comes from LucidRail. Everything between, Terranoux handles with the care physical actions need.

  1. 01

    Experiment specification

    objective · variables · controls · measurements · budget · stop

    Engineering model
  2. 02

    Environment adapter

    capabilities · envelope · channels · calibration · cost model

    Terranoux
  3. 03

    Simulation and validation

    predicted outcome · resource use · envelope violations

    Terranoux
  4. 04

    Authority

    identity · policy · budget · approvals · scoped grant

    LucidRail
  5. 05

    Physical execution

    configure · interlocks · stopping conditions · deviations

    Terranoux
  6. 06

    Raw evidence and provenance

    observations · calibration · actions · custody

    Terranoux → model
TerranouxOutside Terranoux

01

Experiment specification

A contract written before anything moves. If a field is missing, the experiment is not ready.

experiment_contract.yamlExample · illustrative

01 / 09

Objective

What is being tested?

One measurable aim. If it cannot be measured, it is not ready to run.

Example value

sheet resistance of film batch A after annealing

Checked by

Engineering model

experiment_contract.yamlDraft · example
# Draft experiment contract. Field names are not final.
experiment:
  id: exp_example_0142
  objective: "sheet resistance of film batch A after annealing"
  question_ref: q_example_0142           # the uncertainty this resolves
  variables:
    anneal_temp: { values: [120, 160, 200], unit: degC }
  controls:
    duration: { value: 30, unit: min }
    atmosphere: N2
    substrate: batch_A
  interventions:
    - anneal(sample, anneal_temp, duration)
    - measure(sample, sheet_resistance)
  measurements:
    sheet_resistance: { unit: ohm_per_sq, replicates: 3 }
    chamber_temp:     { unit: degC, rate_hz: 1 }
  stopping_conditions:
    - chamber_temp > 225 degC
    - interlock.open
    - samples_complete == 9
  budget:  { samples: 9, instrument_hours: 4, cost_usd: 180 }
  risk_class: R2
  authority: required                    # filled only by LucidRail

02

Environment adapters

Terranoux should not need to own the lab. An adapter describes an existing instrument in a common model and translates to whatever interface it already speaks.

Each adapter declares capabilities, its risk envelope, measurement channels, calibration source, cost model and stop mechanisms. The experiment model only ever talks to that declaration. Native protocols stay behind it: vendor SDKs, OPC UA, SiLA 2, ROS 2, Modbus or whatever the equipment exposes.

adapter.yamlIllustrative
# What an adapter declares about one instrument (illustrative)
adapter: furnace_example
capabilities:   [set_temperature, hold, ramp, purge_n2]
envelope:       envelopes/furnace_example.yaml
channels:
  chamber_temp: { sensor: tc_02, unit: degC, max_rate_hz: 10 }
calibration:    { source: tc_02.cal, valid_until: <date> }
cost_model:     { per_hour_usd: 28, consumables: [n2_gas] }
stop:           { software: abort(), hardware: e_stop_relay }
native:         vendor_sdk | opc_ua | sila2 | ros2 | modbus

No adapters exist today. Protocol names are examples of the interfaces an adapter would translate to, not integrations.

03

Risk envelopes

The safe operating range of a physical system, written so a machine can check it before acting.

Operating range
Allowed values for each controllable parameter.
Prohibited states
Combinations that are never allowed, even if each value is.
Hard maxima
Motion, force, pressure, temperature, voltage, concentration.
Materials
Permitted and forbidden material classes.
Space and time
Physical boundary and the window the grant covers.
Stop and approval
Emergency stop, and which approvals each class needs.

Out-of-envelope requests are refused and returned with a reason. Terranoux does not quietly adjust a parameter to make a request fit. Widening an envelope is an authority decision, made outside Terranoux.

Try to leave the envelope

Example instrument

54°C / 20°C – 80°C
0°C120°C
1.2 bar / ≤ 2.5 bar
0.0 bar6.0 bar
45 min / ≤ 90 min
0 min240 min
All parameters inside the envelope. Drag past a boundary to see a refusal.
envelope.yamlplaceholder values
instrument        reactor_07   # exampletemperature       54°C   # range 20–80°Cpressure          1.2 bar   # ≤ 2.5 barduration          45 min   # ≤ 90 minmaterial_classes  [aqueous, non_oxidizing]prohibited_states [dry_heat, sealed_over_2bar]cost_ceiling      $400 / runphysical_boundary vessel_interiortime_boundary     grant window onlyauthority         grant_example_7f3aemergency_stop    enabled

Refusal log

  • no refusals
Illustrative classes

R1 Reversible

Move a calibrated stage within its travel.

Physical change, easily undone.

Required from LucidRail before Terranoux may act

  • Identity of requesting system verified (required)
  • Policy permits this action type (required)
  • Budget reserved before execution (required)
  • Simulation or dry run passed (not required)
  • Named human approver (not required)
  • Second, independent approver (not required)
  • Operator physically present (not required)

04

Simulation first

Simulate, inspect, authorize, execute. Physical runs are for what models cannot answer.

Where a credible model exists, the proposal is simulated before approval is requested. The result carries the model's identity and validity range. Where no credible model exists, that is stated, and the experiment may need a smaller first run or a higher level of approval.

Predicted outcome
A band, not a point. Used later to flag surprises.
Resource use
Materials, instrument time, energy and cost.
Envelope violations
Steps that would cross a limit, removed before review.
Fidelity
Which model, which version, and where it is known to fail.
0255075100120160200240anneal temperature / °Csheet resistance / Ω·sq⁻¹ (normalized)envelope max 220
planned conditionpredicted bandmeasuredExample data

State · Proposed

The engineering model proposes four anneal temperatures. Nothing has been checked yet.

conditions
120 · 160 · 200 · 240 °C
samples
12
envelope check
not run
authority
none

05

Authority boundary

Terranoux proposes. LucidRail decides. Terranoux executes only inside the granted envelope.

The authority boundaryTerranoux sends a request containing the experiment contract, predicted risk and cost to LucidRail. LucidRail returns either a scoped grant or a refusal. Terranoux cannot issue a grant to itself.TERRANOUXValidated contractPredicted risk classEstimated costno signing key for grantscannot widen an envelopecannot extend a budgetBOUNDARYLUCIDRAILIdentityPermissions and policyBudgetRequired approvalsAudit recordrequestscoped grantor refusal, with reasongrant = scope · envelopebudget · expiry
  • Terranoux sends the validated contract, predicted risk class and estimated cost to LucidRail.
  • LucidRail checks identity, permissions, policy, budget and required approvals, and returns a scoped, time-limited grant or a refusal.
  • A grant can be revoked during a run. Revocation is a stopping condition.
  • Terranoux holds no means to issue, widen or extend a grant for itself.

06

Execution

Configure, check, run, watch. The physical system keeps the right to refuse.

  1. 01ConfigureSet up equipment to the contract through its adapter.
  2. 02PreflightConfirm calibration validity, interlock state and the grant window.
  3. 03RunPerform interventions in order, recording each action as performed.
  4. 04WatchMonitor stopping conditions and envelope limits continuously.
  5. 05Deviate or stopRecord every deviation. Stop on any stopping condition, interlock or revocation.

Hardware interlocks and emergency stops sit below software and override it. If an instrument refuses an action, the refusal is recorded as data, not retried around.

07

Measurement

Raw first. Interpretation later, where it can be checked.

Raw observations
Unprocessed readings, with units and sampling rate.
Instrument identity
Which sensor, which firmware, which channel.
Calibration state
When it was last calibrated and against what.
Uncertainty
Declared resolution and known error where available.
Environmental state
Ambient conditions that could affect the reading.
Timestamps
Monotonic and wall-clock, so ordering survives clock drift.
Environment streamExample run
Raw readings from an example run
tchannelvaluesource
Evidence packagewaiting
  • Experiment specificationsha256 9f1c…e04a
  • Authorizationgrant_example_c41e
  • Equipment identityfurnace · tc_02 · 4pp_01
  • Calibration4pp_01 cal 14 days old
  • Actions performed3 setpoints · 9 placements
  • Deviations1 · run 7 overshoot
  • Raw measurements0 readings, unprocessed
  • Environmental stateN₂ · 21.4 °C ambient
  • Failuresnone
  • Timestampsmonotonic + UTC
  • Costs9 samples · 3.57 h · $158

Verdict: not included. The engineering model decides what the evidence means.

08

Provenance

Every run returns an evidence package: the physical equivalent of a receipt.

The package links the exact specification, the authorization, the equipment and its calibration, the actions actually performed, deviations, failures, raw measurements, environmental state, timestamps and costs. It is signed along its chain of custody. The engineering model then decides what the evidence means for the design.

evidence_package.yamlDraft · example
# Evidence package (draft structure)
evidence:
  experiment: exp_example_0142  sha256: 9f1c…e04a
  grant:      grant_example_c41e  issuer: lucidrail
  equipment:
    - furnace_example   firmware: <version>
    - tc_02             calibration: tc_02.cal (14 d)
    - 4pp_01            calibration: 4pp_01.cal (14 d)
  actions:              # what was actually done, in order
    - t: 00:03:41.870  set_temperature 120 degC
    - …
  deviations:
    - t: 02:20:31.761  chamber_temp +1.8 degC over setpoint
  observations:   raw/  (27 files, unprocessed)
  environment:    { ambient_c: 21.4, atmosphere: N2 }
  failures:       []
  cost:           { samples: 9, instrument_hours: 3.57, usd: 158 }
  custody:        signed by adapter → executor → engineering model
  verdict:        null  # interpreted downstream, where it can be checked

Where experiments could run

Existing equipment, through adapters.

Terranoux does not operate labs or facilities. These are the kinds of environments the adapter model is designed for.

  • Laboratories

    chemistry · biology · materials

    Keeping calibration state and sample lineage attached to every reading.

  • Manufacturing

    processes · inspection · optimization

    Running experiments on a live line without disturbing production outside the envelope.

  • Robotics

    manipulation · mobility · testing

    Expressing spatial and force envelopes precisely enough for a machine to check before moving.

  • Infrastructure

    energy · sensors · environmental systems

    Attributing a measured change to an intervention when the environment never holds still.

  • Field environments

    agriculture · geology · ocean · climate

    Recording environmental state well enough that the experiment means something later.

Principles

Rules for touching reality.

Physical experiments are not cheap and not always reversible. The architecture is held to these.

  1. 1Simulation before execution.No approval request without a simulation result, or an explicit statement that none is credible.
  2. 2Authority is external.Terranoux holds no means to issue, widen or extend its own grants.
  3. 3Every action is bounded.An action with no declared envelope is not available to the experiment model.
  4. 4Raw evidence before interpretation.The execution layer leaves the verdict empty. Interpretation happens in the engineering model.
  5. 5Failures are first-class data.Every stop, deviation and refusal is recorded with a timestamp and cause.
  6. 6Physical systems must be able to refuse.A refusal from equipment ends the step and is reported. It is never retried silently.
  7. 7Reproducible where possible.Contracts and evidence packages are versioned and content-addressed.
  8. 8No silent expansion of the envelope.Out-of-envelope requests are refused with a reason and returned unchanged.

When simulation isn't enough, test reality.