Composed missions
Bring the hardware you have. Reach the rest through the cloud.
A mission rarely needs an entire bench from one place. You may already own the on-board computer and need someone else's power supply — or a specific attitude-control table, for two weeks in March. A composed mission runs across both at once: your hardware and theirs, through one interface.
YOUR APPLICATION
One Client SDK. One device model. One evidence trail.
TWINLINK
↕ ONE CONTROL PATHDiscovery, leases, authorization, command routing, telemetry, audit
YOUR SITE
Hardware you already own
For example: your OBC
- Your Bridge — software you run, dialling out
- Your Connector — your protocol, mapped once
- Your local safety — yours, and final
You contribute it. You keep it. You can withdraw it at any time.
VENDOR OR LABORATORY SITE
Hardware someone else owns
For example: their EPS
- Their Bridge — software they run, dialling out
- Their Connector — their protocol, mapped once
- Their local safety — theirs, and final
They expose a capability subset to you under an explicit grant: scoped, time-limited, and revocable at any moment.
- 01Two leases, not one
- A session lease is scoped to a single resource. A composed mission holds one lease per resource, each with its own command allowlist and its own expiry. Nothing about one lease is implied by the other.
- 02Two safety boundaries, both final
- Local safety is per site and independent. Cloud policy can be stricter than an owner's limit; it can never be weaker. Neither owner's hard limits can be relaxed by the platform, by the other owner, or by you.
- 03Two owners, two independent revokes
- Either side can withdraw unilaterally, without negotiation. The mission fails closed on that resource — and only on that resource. The rest of the composed bench keeps running.
- 04One interface
- The same SDK, the same device model, the same command paths, the same evidence — regardless of who owns which resource or which country it sits in. Your application does not need to know the difference.
OBC and EPS name the real-world shape of this use case, not shipped device classes — the TwinLink device model covers the resource classes it covers today, and this website is pinned to contracts 0.3.0. The cross-organization grant you can exercise in the product experience is an experience-layer capability, not a TwinLink 0.3.0 API.
How a composed mission works →