Single sanctioned OPC UA access point per site — one session per piece of equipment.
- Two namespaces: equipment (raw) + System Platform (processed) — absorbs LmxOpcUa.
- Clustered, co-located on existing System Platform nodes — no new hardware footprint.
- Hybrid driver strategy: proactive core library (8 drivers) + on-demand long-tail.
- OPC UA-native auth: UserName tokens + standard security modes (inherited from LmxOpcUa).
- Data-path ACL model: scope hierarchy + per-node permissions, committed in v2.
- Tiered cutover: ScadaBridge first, Ignition second, System Platform IO last (across Years 1–3).