The outcome you are walking toward
A hardware plan for one Domain property you can put in front of the property team: which kit tier fits the building, what goes on the wall and in the plant room, which loops must keep working when the uplink drops, and the order the rollout happens in. One honesty note first: MCV.REALTY is in staged rollout, so every capability below is described as designed to operate — not as shipped production behavior. The kit contents are a reference configuration, finalized per site survey, not a fixed bill of materials.
The building is a Mesh node
The design principle the whole playbook hangs on: the building is a Mesh node. Every critical system is designed to be discoverable, healthy, and observable from the same fabric the rest of the operation runs on. The mandatory core, per major building or logical cluster:
- Primary edge node — with an optional redundant edge for large or critical assets.
- Managed networking with segmentation — building systems never share an unsegmented LAN with tenant traffic.
- Power resilience — UPS backing for critical control and access, so a power event is not an access event.
- The local runtime — local Mesh, local Synapse, local policy, and a critical agent runtime, so the building stays coherent on its own. How that layering maps to the platform is covered in the L0–L4 layer model.
Access, identity, and zone control
Access hardware is where the building meets the tenant record, and it is designed to span every class of door:
- Smart locks and access control panels across units, common areas, amenities, and back-of-house.
- Mobile credential and fob/card readers — the credential follows the person, not a key ring.
- Visitor management hardware for guests, vendors, and deliveries.
- Elevator control integration where the building's systems allow it.
- Intrusion, door-forced, and emergency hardware — the signals that matter most when nobody is watching.
Zone control is the policy half of this hardware: who may open what, when, under which role — and every grant or denial is designed to land in the audit trail & evidence model at the moment it happens.
Environmental sensing
The building is designed to report its own health instead of waiting for a complaint:
- Environmental sensors — temperature, humidity, CO₂, air quality, and leak detection.
- Occupancy and people-flow sensors — amenity usage, crowding, and common-area utilization.
- Building-system gateways — HVAC controllers, lighting control integration, and water, electrical, and energy metering.
- Critical plant equipment sensors — pumps, boilers, chillers, and the rest of the plant room, feeding predictive maintenance signal extraction.
That last item is the point of the layer: maintenance is designed to shift from reactive and calendar-based to predictive and closed-loop, with work orders born from sensor signal rather than from a tenant's phone call.
Privacy-zoned cameras
Camera coverage is scoped to entry points, corridors, elevators, amenities, package rooms, and critical plant rooms — with privacy zones drawn during the site survey, before any camera is mounted. Two rules are non-negotiable: privacy and tenancy boundaries are non-negotiable, and the zones are enforced by policy, not by camera placement alone. Tenant-facing boundaries follow the same discipline as per-brand data isolation: a camera covering a corridor is designed to see the corridor, never the unit beyond the door.
How the physical layer feeds the agents
Hardware exists to feed the agent team. The designed routing, at a glance:
- Access granted, denied, or anomalous — high-to-critical priority; Sentinel and Domain Steward act on security and tenant flow.
- Leak or environmental threshold breach — critical priority; Sentinel and Domain Steward drive immediate response.
- HVAC or plant anomaly — high priority; designed to open a predictive work order before the failure.
- Amenity overcrowding or underuse — an experience and utilization signal for Domain Steward.
- Energy spike or inefficiency pattern — a cost and sustainability signal the Ledger side of the team reads.
Domain Steward — the named primary agent of the realty vertical — lives inside these loops. Maintenance and experience are designed to be live signals, not lagging reports.
Offline behavior: the highest-priority loops
Per the offline contract, access control and safety signaling are the highest priority offline loops for a Domain location. When connectivity is lost, the building is designed to hold this line:
- Access control continues on local credentials and cached policy.
- Critical safety and leak detection still function and alert locally.
- The edge continues to buffer all events with integrity — no critical environmental event is dropped.
- Local overrides remain possible under audited break-glass.
- On reconnect, ordered reconciliation with full evidence — and no access authority is silently lost.
Multi-building portfolios are designed to tolerate partial network partitions without losing local coherence: one building's outage is never the portfolio's outage. The full contract — what must continue, what may degrade, what is forbidden — is in the offline resilience guide.
Kit tiers: one building to a whole portfolio
Standardized, Mesh-native kits are designed to scale from a single asset to an institutional portfolio without custom one-offs:
- Domain Core Kit — edge, access control, essential cameras, and environmental basics; for smaller buildings and low-complexity assets.
- Domain Full Building Kit — Core plus rich vision, HVAC and metering gateways, and amenity hardware; the standard multifamily or commercial fit.
- Domain High-Sensitivity Kit — Full plus advanced leak and environmental coverage, higher camera density, and redundancy; for luxury, life-science, and critical-tenant assets.
- Domain Portfolio Kit — the standardized stack optimized for rapid multi-building rollout across an institutional portfolio.
- Domain Mixed-Use Kit — Full plus retail and commerce interfaces where the asset mixes uses.
Every kit is designed for Domain Steward and supporting-agent activation, and every kit's final contents are set by the site survey — the tiers are the starting shape, not a shopping cart. Kit availability and ordering live on the MCV.STORE.
Deployment sequence
The designed order of operations for one asset:
- Building survey — systems, network, access, privacy zones, plant
- Kit selection and integration points definition
- Physical installation and secure network segmentation
- Mesh join, policy, and privacy pack download
- Building-system gateways and sensor onboarding
- Access control and identity binding
- Agent activation — Domain Steward plus the supporting team
- Pilot with the property team on live work orders and experience loops
- Full production
- Continuous forging of maintenance and experience playbooks
Steps 8 and 9 are decisions, not defaults: the pilot earns production, the same discipline as any institutional deployment.
Adjacent reading
The realty vertical page shows the tenant lifecycle this hardware feeds, the offline resilience guide is the full contract the offline section above summarizes, and the MCV.STORE is where the kits surface when realty availability opens. Until then, treat this page as the spec to hold a site survey against.
