Plan Runner — AI-native enterprise planning

Enterprise architecture

Build the system before the screens.

Plan Runner starts with stable domain IDs, immutable revisions, command and event contracts, bounded platform modules, and cell-level deployment.

Architecture order

Each layer consumes the contracts below it.

The website and product shell demonstrate the platform, but neither is allowed to become the platform model.

  1. 1

    Experience layer

    Marketing, planning, modeling, administration, portals, and add-ins.

  2. 2

    Application framework

    Versioned packages compose semantic models, views, workflows, roles, reports, forecasts, agents, tests, and migrations.

  3. 3

    Platform services

    Bounded modules for modeling, data, workflow, reporting, security, governance, and intelligence.

  4. 4

    Calculation and query plane

    Compiled formulas, block storage, dependency execution, scenarios, aggregation, and governed range writes.

  5. 5

    Regional data foundation

    PostgreSQL, event streaming, workflow orchestration, cache, object storage, Arrow, Parquet, and Iceberg.

Control plane + tenant data planes

Cell-based by design.

Global operations hold only what they need to route and operate the product. Regional tenant cells own planning state and enforce isolation.

Global control plane

  • Tenant and workspace directory
  • Identity broker and global authorization
  • Region placement and capacity
  • Subscriptions, metering, and packages
  • Status and approved support access

US region

Tenant cell

  • API + realtime gateways
  • Model and workflow services
  • Calculation + query runtime
  • Data, events, and object storage
  • Audit + governed AI context

EU region

Tenant cell

  • API + realtime gateways
  • Model and workflow services
  • Calculation + query runtime
  • Data, events, and object storage
  • Audit + governed AI context

APAC region

Tenant cell

  • API + realtime gateways
  • Model and workflow services
  • Calculation + query runtime
  • Data, events, and object storage
  • Audit + governed AI context

Bounded service map

Complete boundaries, incremental extraction.

The specification names the complete capability inventory. Teams begin with bounded modules and extract deployment units only when scale, isolation, or ownership makes it necessary.

Global control plane

Tenant, placement, identity, entitlement, capacity, package, support, and status capabilities.

Planning and modeling

Applications, dimensions, hierarchies, calendars, modules, formulas, scenarios, revisions, allocations, and lineage.

Calculation and query

Block storage, compiled formulas, dependency execution, aggregation, scenarios, range writes, and explain-value.

Data and integrations

Connectors, ingestion, schemas, mapping, quality, pipelines, catalog, lineage, writeback, and residency enforcement.

Workflow and collaboration

Tasks, approvals, delegation, certification, submissions, locks, decisions, presence, and notifications.

Reporting and presentation

Dashboards, reports, narrative, scheduling, distribution, documents, disclosure, add-ins, and embedding.

Security and governance

Authentication, relationship authorization, cell access, audit, keys, DLP, retention, policy, and compliance evidence.

AI and optimization

Governed context, agents, forecasts, anomalies, solvers, recommendations, approval, evaluation, and cost control.

Machine-readable topology

Inspect the contracts and route map.

Open documentation