Architectures/Live fleet · operator · driver · tracker
Public reference architecture

Fleet Control & Execution

An exception-led operating picture with accountable state and proof-gated closure.

Qualify every live asset, deduplicate operational evidence, preserve privacy and keep canonical cases separate from offline operator or driver intent.

Know which component owns the state—and what it must never infer.

Every layer exposes an authoritative responsibility and an explicit non-authority boundary.

01
Tracker / TCU / partner feeds

Asset evidence

OwnsSource position, event and device health

Must not inferStale is never shown as live or compliant

02
SAAS-02

Fleet projection

OwnsQualified current state, trips, exceptions and metrics

Must not inferDuplicate events do not create duplicate cases

03
Workflow service

Case authority

OwnsRevisioned assignment, transition and closure state

Must not inferPending client intent is not canonical state

04
APP-05 / APP-06

Operator and field apps

OwnsIntent, acknowledgement and locally queued evidence

Must not inferNo physical contact, dispatch or closure is inferred

State advances through evidence—not optimistic UI.

Each transition names both the action and the identity or version evidence that makes it reproducible.

  1. 01

    Qualify

    Resolve source, freshness, consent, duty state and device health.

    asset/source/time/quality · policy revision
  2. 02

    Detect

    Derive an exception from versioned rules and preserve trigger lineage.

    rule · threshold · source event IDs
  3. 03

    Prioritize

    Rank by impact, SLA, confidence and effective operator role.

    priority basis · definition · gaps
  4. 04

    Act

    Queue revision-bound acknowledge/assign/resolve intent online or offline.

    event/idempotency · actor · base revision
  5. 05

    Close

    Require configured proof references and source reconciliation before terminal state.

    reason · proof refs · reviewer/source receipt

Interfaces that a production program must own.

01

Fleet state

Assets, trips, freshness, duty/privacy and health.

02

Exceptions

Rule, trigger lineage, priority, SLA and deduplication.

03

Case workflow

Revisioned transitions, actor, reason, proof and reconciliation.

04

Analytics

Definition, denominator, population, gaps and versioned evidence.

Failure states stay truthful and useful.

Asset stale/offline

Separate device, carrier and vehicle failure domains; do not show current route compliance.

Duplicate/conflicting sources

Retain both authorities, deduplicate case creation and escalate unresolved conflict.

Operator/driver offline

Project pending intent locally but advance canonical state only after acknowledgement.

Proof or source reconciliation absent

Keep resolved-pending-verification; block verified closure.

Privilege follows the narrowest useful boundary.

  • Role, fleet, shift and purpose-limited asset access
  • Off-duty precision and media policy enforced server-side
  • Revision/idempotency on every case transition
  • Proof references stored without uncontrolled evidence bytes
  • Independent device endpoints and regulated interfaces remain isolated

A green demo is not a production acceptance case.

  • 01Staleness, duplication, conflict and privacy fixtures
  • 02Offline queue/replay and stale-revision tests
  • 03Proof-gated closure and source-reconciliation tests
  • 04Device/carrier/cloud failure isolation
  • 05Operational metric definition/denominator validation

Compose the system without collapsing product ownership.

Each product can be bought and operated independently while sharing identity, context and lifecycle contracts.

OEM program workshop

Turn the Fleet Control & Execution reference into your program architecture.

Confirm target products, vehicle and cloud boundaries, source systems, contract versions, deployment, validation and lifecycle ownership.