Section 42 of 83
41. Control Cartridge
Stable section ID: S05-CON-005-SECTION-42 · 30 content blocks
A Control Cartridge receives inputs, applies approved logic, and issues commands to connected equipment, Cartridges, or building systems.
Examples include:
lighting controllers;
valve controllers;
motor controllers;
HVAC zone controllers;
access controllers;
structural-response controllers;
robotic coordination units;
emergency-control modules;
local Building BIOS gateways.
Each Control Cartridge shall declare:
controlled devices or functions;
accepted inputs;
available commands;
operating modes;
authority level;
priority relationships;
timing requirements;
interlocks;
safe state;
override procedure;
failure behavior;
cybersecurity classification.
Control authority shall be explicit. A Cartridge shall not issue commands outside its authorized domain, zone, or operating state.
Where commands may originate from occupants, automation, AI, remote services, maintenance personnel, or emergency systems, the priority and conflict-resolution rules shall be defined.
The Control Cartridge shall verify, where possible, the physical result of a command. A command to close a valve or lock a mechanism shall not be assumed successful without state feedback where the consequence of failure is significant.
Control logic affecting safety shall be deterministic, traceable, version-controlled, and independently verifiable. AI may advise or optimize within authorized boundaries but shall not silently modify safety logic.
Manual override shall indicate that automatic control is suspended or limited. Override status shall remain visible and recorded until formally cleared.
Control-loop classes, response times, deterministic protocol requirements, and authority hierarchy remain TBD.