System boundaries
What runs in Cloud, Development Studio, Site Runtime and operator clients.
Cloud control plane
The Cloud stores project drafts, revisions, organization membership, subscription state, deployment targets and audit records. It prepares bounded contexts for built-in agents and MCP clients.
Development Studio
Studio is the authoring environment. Connected Desktop loads the complete web Studio and adds a local connector for approved VPN/LAN workflows. Studio is not deployed into the building Runtime.
Site Runtime
Site Runtime owns the active and rollback bundle slots, protocol execution, schedules, block/script programs, local historian, alarm state and site-local credentials. Its management API is authenticated and not exposed to ordinary operator clients.
Operator boundary
Web Station and Client View receive only assigned visualizations, alarms and commands. A Graphic command is resolved server-side against the active bundle and must end at exactly one writable physical Point.
Hardware boundary
Site Server, Edge Controller and Field Controller are distinct roles. Some deployments can temporarily place more than one role on a single industrial computer, but the project model keeps the responsibilities separate.