Rewrite OSAvailable

Bounded, attested autonomy for your Ignition gateway.

Rewrite OS is the substrate that governs the moment an AI agent moves from advising your operators to acting inside your physical control loop. It installs into your existing Ignition gateway, runs on-premise, and enforces a hard operating band: every action bounded, every action attested, every action reversible.

Runs On
Ignition 8.1.x · 8.3.x
Format
.modl gateway module
Deployment
On-premise, in-gateway
Operating Band
L1 to L2 · L3+ excluded
The crossing

The permission, not the deciding.

AI already advises manufacturing operations. It does not yet act inside them. The next industrial discontinuity is not a technology. It is the moment a machine intelligence is first allowed to act on physical reality, and how that permission is governed determines whether the crossing is safe.

What it looks like

See it run. Inside your gateway.

Interactive simulation. Walk through the full plant experience: login, platform install, discovery, the OS shell, operator view, tools, value, and the road to 5.5.

Option B · the modules OS · Assist calls capabilities as tools
Rewrite
Sign in to your plant's intelligence layer.
read-onlySOC 2pilot · free
The autonomy ladder

Where Rewrite operates. And where it will not.

The ladder is adapted from SAE J3016. L0 is advisory only and stays a permanent, legitimate level. The operating band is L1 to L2. L3 and above are excluded as a matter of principle, not just capability.

L0Advisory

AI advises. A person acts. Permanent, legitimate level for decisions never granted action authority.

L1Bounded ActionOperating band

AI acts inside the physical control loop, within hard bounds, every action attested. The crossing.

L2Bounded CoordinationOperating band

AI coordinates across agents and sites within the operating band. Upper edge of the band.

L3+ExcludedExcluded

Autonomous action without bounds. Excluded as a matter of principle, not just capability.

The doctrine

Three pillars. On a governance spine.

Trust

Every action signed, chained, and tamper-evident. The State Integrity Guarantee: the agent cannot alter the record of what it did.

Open Coordination

Five open specifications, donated to a neutral foundation. No proprietary lock-in on the substrate that connects plants.

People

The Provable Promise: attested records restore the path from shop floor to front office by making skill legible on paper.

The Govern Spine

The spine that holds the three pillars together. Runtime assurance: bounds enforced before action, attestation chained after action, halt authority distributed to every admin. The spine is what makes the operating band trustworthy enough to enter.

The substrate

Five open specifications. Donated, not owned.

Four protocols and one profile of the Model Context Protocol. Intended for donation to a neutral foundation so no single vendor, including Rewrite, can own the crossing.

1
Action Protocol

How an agent proposes, executes, and attests a bounded physical action.

2
Attestation Protocol

How every action is hashed, signed, and chained into a tamper-evident ledger.

3
Bound Protocol

How hard limits are declared, enforced at runtime, and verified post-action.

4
Coordination Protocol

How agents and sites share patterns without merging data or ceding control.

5
MCP Profile

A profile of the Model Context Protocol for industrial context, grounding AI in the live historian.

Getting started

From request to running. In four steps.

1
Request access

Tell us which modules you want and which gateway they'll run on. We confirm your Ignition version and licensing.

2
Receive your module files

We send you the signed .modl files for the modules you're licensed for, along with a license key tied to your gateway.

3
Install from the gateway Config page

Open your Ignition Gateway, go to Config, Modules, Install or Upgrade a Module, and select the file. No separate installer, no separate server.

4
Restart and launch

Restart the gateway when prompted. The new modules appear in your Perspective project, ready to add to any screen your operators already use.

Deployment

On-premise by default. Air-gap friendly.

Rewrite OS is designed for plants that cannot send process data off-site. Every module runs entirely inside your gateway. If your site is fully air-gapped, everything still works, the only thing you lose is the optional AI-bridge feature, which needs outbound access and is off unless you turn it on.

No new server

The gateway you already run is the only infrastructure required.

No forced egress

Nothing leaves the plant network unless a module is explicitly configured to reach out.

Standard Ignition security

Access follows your existing Ignition user sources and roles. No separate login system.

Updates

Updates like Ignition. Rollback like Ignition.

Rewrite OS follows the same update model you already trust for every other Ignition module. You choose when to update, and a bad update never has to become a production incident.

Two release tracks

A stable track for production plants and an early-access track for teams that want new capability first. You choose which one your gateway follows.

Update at your own pace

New versions arrive as a new .modl file, installed the same way as the first install. Nothing updates automatically without your action.

Roll back at any time

Each module keeps its previous version on the gateway. If an update causes a problem, revert it at the next restart with no impact on your other modules or your Ignition project.

Requirements

What you need. Nothing exotic.

A running Ignition Gateway, version 8.1.x or 8.3.x.
Gateway admin access to install modules from the Config page.
Standard Ignition licensing for the modules and tags in your project.
Optional: outbound network access, only if you choose to enable the AI-bridge feature.
Common questions

Before you install.

Ready to install

Get Rewrite OS running on your gateway.

Request access

info@rewriteautomation.com

Rewrite Automation Inc. · Southfield, MI 48075