Skip to content
GridNinja

AI Data Center Virtual Capacity Control Plane

How much virtual capacity is safe, for how long, and under which evidence?

GridNinja turns constrained infrastructure into safe, usable, auditable capacity by rendering a signed dispatch envelope: the requested MW, the accepted MW, the binding constraints, and the proof trail behind every allow / repair / reject / no-proof decision.

Read-only visual: the browser renders a signed decision record preview; runtime assurance remains the authority boundary.

Dispatch Envelope

The runtime-assured capacity aperture, not a dashboard claim

The dispatch envelope shows what an AI data center can safely use, sell, defer, or refuse inside declared electrical, storage, cooling, bridge-power, workload, telemetry, and policy limits. It is designed for Shadow Mode first, then bounded autonomy only after proof accumulates.

Authority boundary

Read-only proof before autonomy

A production DispatchEnvelopeDTO is produced by telemetry, topology, policy, deterministic solver / verification, runtime assurance, and a signed proof record. The frontend never infers accepted capacity, downgrades no-proof, or becomes an approval path.

Requested envelope

4.0 MWSynthetic illustrative scenario—not a customer or production result.

The operator or workload plan asks for a timed capacity maneuver.

Accepted envelope

2.8 MWSynthetic illustrative scenario—not a customer or production result.

Runtime assurance repairs the request into the safe, usable envelope.

Binding source

UPS / BESSSynthetic illustrative scenario—not a customer or production result.

The evidence trail identifies the limiting domain instead of hiding it.

Dispatch Envelope

Constraint Aperture

REPAIR
4.0 MW->2.8 MW-1.2 MW repaired

Hold

18 min

Ramp

0.70 MW/min

Recovery

12 min

UPS reserve floor clipped the request from 4.0 MW to 2.8 MW and 18 minutes; cooling margin delayed start by one minute.

Proof eligible
policy operator-policy-v14topology sha256:746f706f6c6f67793a383363342e2e2e39316600000000000000000000000000proof sha256:70726f6f663a38663463326431362e2e2e393161370000000000000000000000
Requested
4.0 MW
Accepted
2.8 MW
Repair delta
−1.2 MW
Proof
Eligible

Scenario

Illustrative data

Grid stress: REPAIR

MW over time

Requested vs. accepted envelope

RequestedAcceptedRepair delta
Grid stress: REPAIR dispatch envelopeRequested 4.0 MW and accepted 2.8 MW. UPS reserve floor clipped the request from 4.0 MW to 2.8 MW and 18 minutes; cooling margin delayed start by one minute.CONSTRAINT APERTURE

T+0.0; requested 0.0 MW; accepted 0.0 MW; binding domain None; proof eligible; not pinned.

illustrative scenario

Envelope dimension audit

What changed beyond MW?

requested -> accepted -> binding source

MW

4.0 MW->2.8 MW

Binding source: UPS_RESERVE_FLOOR

Hold

20 min->18 min

Binding source: UPS_RESERVE_FLOOR

Ramp-up

1.00 MW/min->0.70 MW/min

Binding source: UPS_RESERVE_FLOOR

Start

T+0->T+1

Binding source: COOLING_SAFE_START

Recovery

6 min->12 min

Binding source: UPS_RESERVE_FLOOR

Rebound

1.0 MW->0.8 MW

Binding source: UPS_RESERVE_FLOOR

Decision-to-proof trace

Decision evidence writes once, then settles

Illustrative sample · evidence chain complete

The trace links the RTA result to ledger, dispatch envelope, and proof root artifacts for read-only inspection.

proof_root: sha256:70726f6f663a38663463326431362e2e2e393161370000000000000000000000

Proof Artifacts

Every accepted MW should point to replayable evidence

The visual exposes proof roots, policy versions, topology hashes, freshness, confidence, and artifact names so operators can inspect why a capacity claim was allowed, repaired, rejected, or withheld as no-proof.

Static fallback

Scenario summary

ScenarioDecisionRequestedAcceptedBinding evidence

Grid stress

Reserve-limited

REPAIR4.0 MW2.8 MWStorage: reserve_floor_report.csv; Cooling: cooling_water_envelope.json

Normal operation

All limits clear

ALLOW3.0 MW3.0 MWNo binding constraint in the illustrative request.

Cooling contingency

Hard thermal block

REJECT4.5 MWwithheldCooling: cooling_contingency_report.json

Telemetry loss

BESS evidence stale

NO-PROOF2.2 MWwithheldTrust: telemetry_manifest.json; Storage: no_proof_gap_register.json

Bridge power

Fuel-window limited

REPAIR5.0 MW3.4 MWBridge: bridge_power_fuel_window.json

Production path

From Shadow Mode to bounded autonomy, only after evidence

The page is a public-facing preview of the operator discipline: use Shadow Mode to watch dispatch proposals, publish proof artifacts, identify proof gaps, and only then expand authority inside strict dispatch envelopes.

01

telemetry + topology + policy

02

deterministic solver / verification

03

runtime assurance gate

04

signed DispatchEnvelopeDTO

05

read-only visual

06

audit-ready proof pack

Capacity Audit

Turn site constraints into a Capacity Audit

Use Shadow Mode to quantify safe sellable MW, binding constraints, proof gaps, and the decision path before autonomy or capacity commitments expand.