Bounded, attested autonomy for your Ignition gateway.
Rewrite OS is the substrate that governs the moment an AI agent moves from advising your operators to acting inside your physical control loop. It installs into your existing Ignition gateway, runs on-premise, and enforces a hard operating band: every action bounded, every action attested, every action reversible.
The permission, not the deciding.
AI already advises manufacturing operations. It does not yet act inside them. The next industrial discontinuity is not a technology. It is the moment a machine intelligence is first allowed to act on physical reality, and how that permission is governed determines whether the crossing is safe.
See it run. Inside your gateway.
Interactive simulation. Walk through the full plant experience: login, platform install, discovery, the OS shell, operator view, tools, value, and the road to 5.5.
Where Rewrite operates. And where it will not.
The ladder is adapted from SAE J3016. L0 is advisory only and stays a permanent, legitimate level. The operating band is L1 to L2. L3 and above are excluded as a matter of principle, not just capability.
AI advises. A person acts. Permanent, legitimate level for decisions never granted action authority.
AI acts inside the physical control loop, within hard bounds, every action attested. The crossing.
AI coordinates across agents and sites within the operating band. Upper edge of the band.
Autonomous action without bounds. Excluded as a matter of principle, not just capability.
Three pillars. On a governance spine.
Every action signed, chained, and tamper-evident. The State Integrity Guarantee: the agent cannot alter the record of what it did.
Five open specifications, donated to a neutral foundation. No proprietary lock-in on the substrate that connects plants.
The Provable Promise: attested records restore the path from shop floor to front office by making skill legible on paper.
The spine that holds the three pillars together. Runtime assurance: bounds enforced before action, attestation chained after action, halt authority distributed to every admin. The spine is what makes the operating band trustworthy enough to enter.
Five open specifications. Donated, not owned.
Four protocols and one profile of the Model Context Protocol. Intended for donation to a neutral foundation so no single vendor, including Rewrite, can own the crossing.
How an agent proposes, executes, and attests a bounded physical action.
How every action is hashed, signed, and chained into a tamper-evident ledger.
How hard limits are declared, enforced at runtime, and verified post-action.
How agents and sites share patterns without merging data or ceding control.
A profile of the Model Context Protocol for industrial context, grounding AI in the live historian.
From request to running. In four steps.
Tell us which modules you want and which gateway they'll run on. We confirm your Ignition version and licensing.
We send you the signed .modl files for the modules you're licensed for, along with a license key tied to your gateway.
Open your Ignition Gateway, go to Config, Modules, Install or Upgrade a Module, and select the file. No separate installer, no separate server.
Restart the gateway when prompted. The new modules appear in your Perspective project, ready to add to any screen your operators already use.
On-premise by default. Air-gap friendly.
Rewrite OS is designed for plants that cannot send process data off-site. Every module runs entirely inside your gateway. If your site is fully air-gapped, everything still works, the only thing you lose is the optional AI-bridge feature, which needs outbound access and is off unless you turn it on.
The gateway you already run is the only infrastructure required.
Nothing leaves the plant network unless a module is explicitly configured to reach out.
Access follows your existing Ignition user sources and roles. No separate login system.
Updates like Ignition. Rollback like Ignition.
Rewrite OS follows the same update model you already trust for every other Ignition module. You choose when to update, and a bad update never has to become a production incident.
A stable track for production plants and an early-access track for teams that want new capability first. You choose which one your gateway follows.
New versions arrive as a new .modl file, installed the same way as the first install. Nothing updates automatically without your action.
Each module keeps its previous version on the gateway. If an update causes a problem, revert it at the next restart with no impact on your other modules or your Ignition project.
What you need. Nothing exotic.
Before you install.
Get Rewrite OS running on your gateway.
Request accessinfo@rewriteautomation.com
Rewrite Automation Inc. · Southfield, MI 48075