{
  "id": "elastic",
  "name": "Elastic (Elasticsearch + Agent Builder + Security + Observability)",
  "subtitle": "Mapped to the 4+1 Layer AI Infrastructure Model",
  "version": "v1.0 - 4+1 v2: Authority Split",
  "date": "September 4, 2026",
  "source": "Elastic 9.3 (February 3, 2026), 9.4 (May 5, 2026), and 9.5 (August 4, 2026) release posts; Agent Builder GA release (January 22, 2026) and product docs (agents, tools, custom tools, models, permissions, MCP server, A2A API reference, connectors library); Elastic Inference Service docs and supported-models table; Cloud Connect release (February 2, 2026); Workflows GA post (9.4) and docs; LLM and agentic-AI observability docs; EDOT reference; Managed OTLP Endpoint docs and GA post (March 19, 2026); ES|QL Data Federation docs; deployment, autoscaling, project-settings, and Serverless differences docs; Elastic Cloud Enterprise and ECK docs; GPU vector indexing docs and support matrix; licensing FAQ and GitHub LICENSE files (Elasticsearch, Logstash, Elastic Agent); Attack Discovery, Security AI Assistant, Automatic Import, and Automatic Migration docs; Alert Zero release (July 31, 2026); Elastic and OpenAI collaboration (July 30, 2026); MCP Apps release (April 21, 2026); Q1 FY27 results (August 27, 2026); NVIDIA cuVS and Enterprise AI Factory posts; Jina model cards and Jina commercial-licensing page. Peer-reviewed cell by cell through the labs claims ledger (elastic-1a through elastic-3, ChatGPT gpt-5.5 reviewer, September 4, 2026): 33 claims, 30 upheld, 3 rejected; every upheld claim folded into the cell it named.",
  "status": "complete",
  "summary": {
    "title": "Summary Finding",
    "paragraphs": [
      "Elastic is a retrieval and observability company that shipped an agent runtime on top, and the row reads that way: strong where the buyer's data is searched (Layer 1B) and where the buyer's day is run (Layer 3, Security and Observability), moderate across the data foundation, the pipeline fleet, orchestration, the runtime, and the reasoning plane, and a gap at Layer 0 by design. Authority is two vendors in one row. The free-tier core of Elasticsearch and Kibana, self-run under the GNU Affero General Public License v3 (AGPLv3) option, is the enterprise's to keep: Retained at 1A, 1B, 1C, and Layer 3 on the open-source path, with OpenSearch as the fork. Everything AI-shaped on top is Elastic License or proprietary and Ceded: the Elastic Learned Sparse EncodeR (ELSER) and the Jina models, the ranking pipeline, the tiering engine and its snapshot format, Fleet, Agent Builder, Workflows, the Model Context Protocol (MCP) catalog, Security, and Observability.",
      "The capture is decoupled and mostly visible, with one quiet exception. The data stays in an open store the enterprise can run itself, and that's true, which is what makes the rest easy to underprice: the value accumulates in the vectors, the retriever trees, the agents, the workflows, and the detection rules, and each is captive to a model or a dialect only Elastic serves. The quiet one is the archive: frozen-tier searchable snapshots are written in a format the fork can't restore, so years of cold data are readable only by Elastic, and on Serverless there's no snapshot exit at all, which is coupled capture wearing the open-store label. Decision authority follows the code, not the license: the enterprise's own pipelines and access policies decide at 1C and 2C, the model decides inside the agent loop with the workflow approval gate as the enterprise's last word at 2B, Elastic's engine decides placement and ranking on policy the enterprise writes at 1A and 1B, and Elastic alone decides how its platform is orchestrated and what its applications surface at 2A and Layer 3.",
      "The buyer gets the most complete hybrid retrieval engine on the map with per-user permissions enforced in the index, a generally available (GA) agent runtime over that data with a deterministic action layer, the widest telemetry intake in the enterprise, and the security and observability applications a platform team runs its day on. In exchange: no catalog, no model serving, no graphics processing unit (GPU) plane, no agent identity, no gateway, and an archive and an AI layer that never leave. What moves this row: a catalog or lineage surface at 1A, a serving or fine-tuning product or an evaluation surface at 2B, an agent principal and a request-time gateway at 2C."
    ]
  },
  "layers": [
    {
      "id": "layer0",
      "label": "Layer 0",
      "shortName": "Compute",
      "title": "Compute & Network Fabric",
      "purpose": "Raw compute, networking, and acceleration fabric",
      "status": "gap",
      "statusLabel": "Not Elastic's Layer (By Design)",
      "authority": {
        "decides": "absent",
        "visible": null,
        "overridable": null,
        "boundary": "vendor",
        "direction": "Absent"
      },
      "nvidia": [
        {
          "component": "GPU-Accelerated Vector Indexing (NVIDIA cuVS)",
          "detail": "The one place Elastic's software touches silicon the customer buys: GA in 9.4 on self-managed Enterprise nodes with an NVIDIA GPU. A Layer 1B fact, logged here as dependency context."
        },
        {
          "component": "NVIDIA Enterprise AI Factory Validated Design",
          "detail": "Elasticsearch is a recommended vector database in the design. A go-to-market fact, not a substrate."
        }
      ],
      "gap": "Elastic sells no silicon, fabric, or arrays, and that's the offer. Elastic Cloud Serverless runs in 33 regions across Amazon Web Services (AWS), Azure, and Google Cloud with PrivateLink on AWS and Azure; Elastic Cloud Hosted runs on the three clouds with the customer choosing provider and region; self-managed, Elastic Cloud Enterprise, and Elastic Cloud on Kubernetes run on whatever the enterprise owns. The buyer never thinks about Layer 0 with Elastic on either path, and Elastic Cloud was 49% of revenue in the quarter ended July 31, 2026, so half of them take the path where the substrate is a hyperscaler's, chosen through Elastic.\n\nTwo invisible substrates deserve naming, neither scored here. The Elastic Inference Service is an Elastic-operated NVIDIA GPU fleet the customer never sees or administers, and Cloud Connect (GA 9.3) extends it to self-managed clusters by shipping text off-premises for embedding and returning vectors; the Elastic Managed large language model (LLM) service logs request metadata to AWS CloudWatch, which is the only public hint of where that fleet lives. GPU-accelerated vector indexing (GA 9.4) is the one place Elastic's software touches a specific piece of silicon the customer provisions.\n\nCalibration: Snowflake, Databricks, and Qlik read gap by design; Kamiwaza and Articul8 read gap as enterprise responsibility. Elastic is both shapes at once and reads gap with nothing to grade.",
      "borrowedJudgment": "None to borrow on the self-managed half: the enterprise supplies the hardware and keeps the substrate judgment. On the Elastic Cloud half the substrate is a hyperscaler's, inherited through Elastic and invisible, the Ceded-invisible reading the SaaS-only rows carry. The cell reads Absent because that's what Elastic offers; the cloud path is named so the buyer who takes it knows which reading applies.",
      "notes": "Public evidence that moves the cell: an Elastic doc naming the cloud and region model behind the Elastic Inference Service fleet would sharpen the 2B data-residency narration, not this cell. Instrument note: IBM's Layer 0 reads Ceded-vendor for the same bring-your-own-OEM shape that Kamiwaza and Articul8 read Absent; logged as a reconciliation item.",
      "components": []
    },
    {
      "id": "layer1a",
      "label": "Layer 1A",
      "shortName": "Storage",
      "title": "Data Storage & Governance",
      "purpose": "Durable, governed data foundation — the Governance Catalog that Layer 2C queries",
      "status": "moderate",
      "statusLabel": "Tiered Index Store + Access-Control Governance, No Catalog",
      "authority": {
        "decides": "vendor",
        "visible": true,
        "overridable": true,
        "boundary": "vendor",
        "direction": "Delegated"
      },
      "nvidia": [
        {
          "component": "No NVIDIA Layer 1A Dependency",
          "detail": "Nothing in the data foundation depends on NVIDIA. GPU-accelerated vector indexing is a Layer 1B fact and is logged there."
        }
      ],
      "gap": "Elasticsearch is the durable store for the highest-volume data most enterprises hold: logs, security telemetry, and the content indexes behind search. On Elastic Cloud Hosted and self-managed deployments, index lifecycle management moves data across hot, warm, cold, and frozen tiers, and the frozen tier lives as searchable snapshots on Amazon S3 (Simple Storage Service), Google Cloud Storage (GCS), or Azure Blob; Serverless replaces that with an automatic data stream lifecycle and no tiers the enterprise steers. LogsDB and time-series index modes cut the footprint, pattern_text compression (GA 9.3) cuts it again, and cross-cluster replication and snapshot lifecycle handle durability across sites on Hosted and self-managed. Governance is the finest-grained access control on the map: role-based access, document-level and field-level security, audit logging, single sign-on, and Federal Information Processing Standard (FIPS) 140-3 (GA 9.4). Document-level security is what makes permission-aware retrieval at Layer 1B real rather than a slogan. The buyer gets petabyte durability and per-document access control without a separate governance product.\n\nWhat the buyer doesn't get is the catalog the purpose line names. Governance here is access control and audit, not a governance catalog: no lineage, no data classification, no data products, no metadata a reasoning plane could query about what a dataset is and who owns it. Elasticsearch is the index beside the system of record, not the system of record. And the tiering that makes the frozen tier cheap is a captive engine: searchable snapshots are written in Elastic's format, and the OpenSearch fork can restore nothing later than 7.10, so the archive a buyer accumulates over years is readable only by Elastic. Serverless has no snapshot application programming interface (API) at all; the exit is reindex-from-remote or an emergency restore through Support.\n\nCalibration: Snowflake and Databricks read strong on a governed lakehouse plus a catalog (Horizon, Unity Catalog). NetApp reads strong on a data-management operating system plus classification and a metadata engine. VAST reads strong on DataStore plus VAST Catalog. Nutanix reads moderate: platform storage plus compliance governance, 'not the AI-metadata catalog a reasoning plane would query.' Qlik reads moderate on an open lakehouse with a captive trust layer. Elastic sits in the Nutanix cohort by the same logic. The durable store is real and enterprise-scale; the catalog leg is absent. Grading strong on the storage half alone would reopen Nutanix.",
      "borrowedJudgment": "Split by deployment path. The free-tier core of Elasticsearch, self-run under the AGPLv3 option, is open-source software the enterprise operates with OpenSearch as a real fork: Retained. Elastic Cloud Hosted runs the same open substrate as a managed service with a documented snapshot exit to self-managed: Delegated. Serverless runs a different surface with no customer-driven exit: Ceded. Everything Elastic charges for at this layer is proprietary and Ceded: the tiering engine and its snapshot format, the security model with its query-scoped roles, and cross-cluster replication. The enterprise authors the lifecycle and allocation policy and Elastic's engine executes it, visible through the allocation and lifecycle APIs and overridable by policy on Hosted and self-managed: vendor decides, visible, overridable, Delegated, the Snowflake and Databricks reading. Serverless alone would read Ceded-invisible.",
      "notes": "Watch-list, notes only: the Elasticsearch Query Language (ES|QL) Data Federation (experimental in 9.5, Enterprise tier, unavailable on Serverless) lets FROM target Parquet, NDJSON, CSV, and TSV on connected object storage without ingesting; the first sign Elastic wants to read the lakehouse rather than be it. Columnar Mode (technical preview, 9.5) stores each field once in a column store. Public evidence that moves the cell: a shipped catalog, lineage, or classification surface over Elasticsearch data; Data Federation GA as a governed system-of-record path.",
      "components": [
        {
          "component": "Elasticsearch Core, Self-Run (Free-Tier Source Under the AGPLv3 Option)",
          "detail": "The engine the enterprise operates on its own tin or Kubernetes: index and query domain-specific language (DSL), ingest pipelines, data streams, and basic lifecycle management, in the free portions of the source that carry the AGPLv3 option (8.16 and later). OpenSearch is a real fork, and mappings, templates, and queries port with drift; ES|QL, semantic_text, and the 8.x and 9.x surfaces don't. Paid features sit in their own chips.",
          "dapm": "Retained"
        },
        {
          "component": "Elastic Cloud Hosted (Managed Store)",
          "detail": "Elastic operates the same engine on AWS, Azure, or Google Cloud in the customer's chosen region, with lifecycle management, tiers, replication, and user-managed snapshot and restore. A managed run of the open substrate the enterprise can self-run, with a documented snapshot exit to self-managed Elasticsearch: Delegated.",
          "dapm": "Delegated"
        },
        {
          "component": "Elastic Cloud Serverless (Managed Store)",
          "detail": "Elastic operates a search-and-indexing-separated store in 33 regions with automatic backups. Data stream lifecycle only, no data tiers, no _snapshot APIs, cross-cluster replication planned, restore by contacting Support; reindex-from-remote is the one customer-driven data exit. No path to the substrate the enterprise could run: Ceded.",
          "dapm": "Ceded"
        },
        {
          "component": "Data Tiers + Searchable Snapshots on Object Storage (Enterprise; Hosted and Self-Managed)",
          "detail": "Hot, warm, cold, and frozen tiers under index lifecycle management, with cold and frozen served from searchable snapshots on S3, GCS, or Azure Blob. The litmus's named case: a captive tiering engine layered beyond the standard object interface. Snapshot format is Elastic's; the fork can't restore it.",
          "dapm": "Ceded"
        },
        {
          "component": "RBAC + Document-Level and Field-Level Security + Audit + FIPS 140-3 (Paid Tier)",
          "detail": "Role definitions with query-scoped document-level and field-level security, audit logging, single sign-on (SSO), and FIPS 140-3 (GA 9.4). The role model is Elastic's; OpenSearch's security plugin uses a different one, so the policies are rebuilt on exit.",
          "dapm": "Ceded"
        },
        {
          "component": "Cross-Cluster Replication + Snapshot Lifecycle (Paid Tier; Hosted and Self-Managed)",
          "detail": "Active-passive replication across clusters and sites, and scheduled snapshot policies. Proprietary replication with no second implementer; not available on Serverless.",
          "dapm": "Ceded"
        }
      ]
    },
    {
      "id": "layer1b",
      "label": "Layer 1B",
      "shortName": "Retrieval",
      "title": "Context Management & Retrieval",
      "purpose": "Low-latency retrieval for RAG — vector/hybrid search, context windows",
      "status": "strong",
      "statusLabel": "Native Hybrid Retrieval: Sparse + Dense + Rerank, Permission-Aware",
      "authority": {
        "decides": "vendor",
        "visible": true,
        "overridable": true,
        "boundary": "vendor",
        "direction": "Delegated"
      },
      "nvidia": [
        {
          "component": "GPU-Accelerated Vector Indexing (NVIDIA cuVS)",
          "detail": "GA in 9.4 for self-managed Enterprise clusters only (unavailable on Serverless): the cuVS plugin on a node with an NVIDIA GPU of compute capability 8.0 or later and at least 8 GB of GPU memory builds int8_hnsw and hnsw indexes up to 12x faster; the support matrix names CUDA 12.9 and 13 with cuVS 2025.12 for 9.3 and 9.4. The default bbq_hnsw path is CPU. Elastic's only direct NVIDIA dependency, and it's optional."
        },
        {
          "component": "NVIDIA Enterprise AI Factory Validated Design",
          "detail": "Elasticsearch is a recommended and validated vector database in the design. A go-to-market fact, not a runtime dependency."
        }
      ],
      "gap": "This is the layer Elastic exists for, and the cell reads it as the frontier. Retrieval is native and composable: BM25, ELSER learned-sparse vectors, dense vectors with Better Binary Quantization, and cross-encoder reranking, fused through the retrievers framework and reciprocal rank fusion in one query. semantic_text (GA 8.18) chunks long documents automatically and carries the embedding choice in the mapping; DiskBBQ keeps billion-scale indexes off the heap. Embeddings come from ELSER, from Jina's models on the Elastic Inference Service (the v5 omni models put text, images, video, and audio in one index, GA 9.4), from any third-party service through the Inference API, or from any open model the enterprise imports to its own machine learning (ML) nodes. Elastic Rerank, the Jina rerankers on the Elastic Inference Service (EIS) (GA 9.3), or a third-party reranker sit on top. ES|QL adds KNN (GA 9.4) and TEXT_EMBEDDING functions for retrieval in the pipeline language. Playground and Agent Builder consume all of it. The buyer gets production hybrid retrieval with model choice and no second system.\n\nThe distinctive property is where permissions are enforced. Document-level and field-level security apply inside k-nearest-neighbor (kNN), semantic, and hybrid queries at query time, as the requesting user. That's the permission-aware retrieval the peer rows claim and mostly qualify: Snowflake's Cortex Search runs with owner's rights and pushes per-user scope to the application; here the index enforces it. The architect's concern is the opposite one: every embedding path except a customer-imported open model is captive. ELSER is Elastic's model; the Jina models Elastic now owns are CC-BY-NC-4.0, so the enterprise can't serve them commercially anywhere else without Elastic's license; third-party embeddings through the Inference API belong to their owners. The vectors in the index are only as portable as the model that made them, and the ranking pipeline (retrievers, fusion, reranking, learning to rank) is Elastic DSL with no second implementer. What lifts out is the free-tier core the enterprise can run itself.\n\nCalibration: Snowflake, Databricks, and VAST read strong on native hybrid retrieval with model choice and an API the enterprise builds on. Elastic matches every leg and adds learned-sparse retrieval, cross-encoder reranking, GPU-accelerated indexing, multimodal embeddings, and query-time per-user permissions that none of the three has in a scored component. Dell's Data Search Engine is this engine on Dell paper and reads moderate on rules 5 and 6 (below the integrated-retrieval frontier, GPU path unconfirmed on Dell paper); whose-paper credits Dell for what Dell ships, and rule 6 pegs strong to the best shipping implementation, which is Elastic's own. Qlik is moderate because retrieval is a closed product feature with no API or model choice; Elastic is the opposite case. No scope gate applies: the capability is general (rule 4), GA across Serverless, Hosted, and self-managed, and deployed at scale.",
      "borrowedJudgment": "Low for the mechanism and split at the model. The retrieval engine, the ranking pipeline, ELSER, Elastic Rerank, and the Jina models are Elastic intellectual property (IP) and Ceded to Elastic. Third-party embeddings through the Inference API are Ceded to their owners through Elastic's paper under the channel-substitution rule. Open models the enterprise imports to its own ML nodes are the exception: the artifact is the enterprise's, the serving surface is Elastic's, and the vectors recompute anywhere, so that chip reads Delegated on the open-source seam. The runtime tradeoff is Elastic's engine executing a retriever tree the enterprise wrote, with every knob exposed and per-user permissions enforced at query time: vendor decides, visible, overridable, the same reading Dell's Elastic-powered 1B carries.",
      "notes": "Watch-list, notes only: VectorDB index mode and auto-calibration for DiskBBQ (technical preview, 9.5) pick quantization depth and oversampling from the vectors themselves; the multimodal semantic field (technical preview, 9.5 and Serverless) collapses the multimodal ingest path into one field; GPU-accelerated indexing on Elastic Cloud Hosted is undocumented and treated as self-managed only. Docs conflict noted: the EIS overview page marks jina-embeddings-v3 and v5-text as Preview while the EIS supported-models table marks them GA at 9.3; the table is taken as governing. Public evidence that moves the cell: nothing upward from strong; a documented owner's-rights or permission bypass in semantic or kNN retrieval would remove the permission-aware claim.",
      "components": [
        {
          "component": "Vector + Lexical Retrieval Core (dense_vector kNN, BM25, BBQ / DiskBBQ)",
          "detail": "The free-tier engine: hierarchical navigable small world (HNSW) dense vectors with int8, int4, and Better Binary Quantization (GA 9.0 and 8.18); BM25; DiskBBQ for billion-scale indexes (improvements GA 9.4); ES|QL KNN (GA 9.4). Optional NVIDIA cuVS GPU indexing on self-managed Enterprise nodes (GA 9.4). Rides the 1A substrate chips: Retained on the self-run AGPL free-tier source, Delegated on Elastic Cloud Hosted, Ceded on Serverless.",
          "dapm": "Retained"
        },
        {
          "component": "Retrieval Pipeline: Retrievers, RRF, Semantic Reranking, Elastic Rerank, Learning to Rank",
          "detail": "The composable query tree (standard, knn, rrf, linear, text_similarity_reranker, rule retrievers), reciprocal rank fusion, the Elastic Rerank cross-encoder through the Inference API, and learning to rank. Paid-tier surfaces in Elastic DSL with no second implementer; the ranking opinions the enterprise accumulates rebuild on exit.",
          "dapm": "Ceded"
        },
        {
          "component": "semantic_text + ELSER (Learned Sparse Retrieval)",
          "detail": "semantic_text (GA 8.18) chunks and embeds at index time with the endpoint named in the mapping; ELSER is Elastic's proprietary learned sparse encoder, on ML nodes or on the Elastic Inference Service (GA 9.1). Embedding carve-out: the sparse vectors are useless without ELSER at query time, and no second vendor serves it.",
          "dapm": "Ceded"
        },
        {
          "component": "Jina Embeddings and Rerankers on the Elastic Inference Service",
          "detail": "jina-embeddings-v3 and v5-text (GA 9.3), the v5 omni multimodal models (text, images, video, audio in one space, GA 9.4), jina-clip-v2 (GA 9.3), and the Jina rerankers (v2-base-multilingual and v3 GA 9.3, v3.5 and m0 GA 9.5), served GPU-accelerated on EIS and reachable from self-managed clusters through Cloud Connect. The weights are CC-BY-NC-4.0 and Elastic sells the commercial license as its own stock-keeping unit (SKU), including Jina On-Prem containers for the customer's own infrastructure: self-deployable isn't Retained. One owner, one channel, Ceded on the Voyage precedent.",
          "dapm": "Ceded"
        },
        {
          "component": "Third-Party Embedding and Rerank Endpoints (Inference API)",
          "detail": "Inference endpoints to OpenAI, Azure OpenAI and AI Studio, Amazon Bedrock, Google Vertex AI, Cohere, Hugging Face, Mistral, Voyage AI, Alibaba Cloud, IBM watsonx, and Jina AI for embeddings and reranking. The vectors belong to the model owner's space: Ceded to the owner through Elastic's paper under the channel-substitution rule. Open-weights models reached through a Hugging Face endpoint are the exception and would read Delegated.",
          "dapm": "Ceded"
        },
        {
          "component": "Customer-Imported Open Models on ML Nodes (Eland: E5, Hugging Face)",
          "detail": "The enterprise imports its own PyTorch embedding, reranking, named entity recognition (NER), or classification model to Elastic ML nodes through Eland; multilingual-e5-small (MIT) ships as a built-in option. The model artifact is the enterprise's and the vectors recompute anywhere the same weights run; the serving surface is Elastic's. Delegated on the open-source seam, matching Snowflake's Arctic embed.",
          "dapm": "Delegated"
        },
        {
          "component": "Permission-Aware Retrieval (Document-Level and Field-Level Security at Query Time)",
          "detail": "Role-based, document-level, and field-level security enforced inside kNN, semantic, and hybrid queries as the requesting user, with no owner's-rights bypass. The differentiator against the lakehouse rows' retrieval services. The policy model is Elastic's and rides the 1A security chip.",
          "dapm": "Ceded"
        }
      ]
    },
    {
      "id": "layer1c",
      "label": "Layer 1C",
      "shortName": "Pipelines",
      "title": "Data Movement & Pipelines",
      "purpose": "Move/transform data — ETL/ELT, lineage, cost-aware movement, KV cache tiering",
      "status": "moderate",
      "statusLabel": "Telemetry and Content Ingest Fleet; No CDC, No Lineage",
      "authority": {
        "decides": "code",
        "visible": true,
        "overridable": true,
        "boundary": "vendor",
        "direction": "Retained"
      },
      "nvidia": [
        {
          "component": "No NVIDIA Layer 1C Dependency",
          "detail": "Nothing in the pipeline fleet depends on NVIDIA. KV-cache tiering, the one 1C capability on the map that does, isn't offered here."
        }
      ],
      "gap": "Elastic moves more bytes than most rows on this map, and does it with the widest intake on the instrument. Elastic Agent under Fleet management ships logs, metrics, traces, security events, and cloud telemetry through hundreds of prebuilt integrations, with outputs to Elasticsearch, Logstash, or Kafka (GA). Logstash is the general-purpose pipeline: any input, scriptable filters, any output, including Kafka, S3, Hypertext Transfer Protocol (HTTP), and a competitor's index. The Elastic Distributions of OpenTelemetry make the intake standards-based end to end: seven GA language software development kits (SDKs), and since 9.5 the Elastic Distributions of OpenTelemetry (EDOT) Collector built into Elastic Agent. The Managed OpenTelemetry Protocol (OTLP) Endpoint (GA on Serverless and, since March 19, 2026, on Elastic Cloud Hosted) takes OTLP from any software development kit (SDK) or collector, buffers it through Kafka, and lands the OpenTelemetry data model without translation. Inside the cluster, ingest pipelines run grok, dissect, enrich, script, and inference processors, so embedding and entity extraction happen at ingest; transforms and downsampling summarize continuously. Self-managed content connectors and the Open Web Crawler pull documents from SharePoint, Confluence, object stores, databases, and the web. Automatic Import (GA) has a model write the integration for a source Elastic never shipped one for, reviewed by a human before it runs. Cost-aware movement is index lifecycle management tiering data to object storage by age, scored at Layer 1A. The buyer gets one agent, one collector standard, and a pipeline that already handles the highest-volume data the enterprise has.\n\nWhat it isn't is the enterprise's data-engineering platform. There's no change data capture from operational databases, no lineage, no lakehouse-bound extract, load, transform (ELT): Logstash can write files to S3, but nothing writes Iceberg or Delta, and ES|QL Data Federation (experimental) only reads. KV-cache tiering doesn't exist. Applying rule 4's decidable test: for event, log, trace, and document workloads the pipeline runs whatever the enterprise never anticipated, with insertable stages and choosable destinations, so the capability is general in kind. Apply the day-two corollary to tabular data and it fails: the second requirement, replicating an Oracle schema into the lakehouse, brings another tool, and the layer's responsibility never transferred. That's a slice of the function, well engineered on its slice. On the portability side the concern is quieter than at 1B: the open paths (Logstash, Beats, the EDOT SDKs, the free-tier ingest pipelines) lift out, the standards-based ones (the Collector, the managed endpoint) swap by changing an exporter, and the captive ones (Fleet policies, integration packages, connectors, Automatic Import) are configuration the enterprise rebuilds rather than opinions it loses.\n\nCalibration: the strong cohort at 1C (Snowflake Openflow, Databricks Lakeflow, Qlik change data capture (CDC) plus Talend, VAST DataEngine) covers batch, streaming, CDC, declarative transformation, and lakehouse-bound movement generally. NetApp reads moderate with best-in-class movement and a fixed-function AI-ingest pipeline; Dell reads moderate on Dataloop, general in kind but maturity-gated. Elastic is the NetApp shape inverted: the pipeline is general and mature, the scope is telemetry and content rather than the enterprise's tables. Rule 6 pegs strong to the best shipping implementation of the layer's whole function, and Elastic doesn't stand with Lakeflow or Openflow on the tabular half. Moderate is that trade stated honestly; on its slice, Elastic is the frontier, and the cell says so.",
      "borrowedJudgment": "Low, and split by path. Logstash, Beats, and the EDOT SDKs are open-source software the enterprise operates with real alternatives, Retained; the EDOT Collector packaged in Elastic Agent and the Managed OTLP Endpoint are proprietary implementations behind the OpenTelemetry standard interface, Delegated; the free-tier ingest pipelines ride the 1A core chips. Elastic Agent and Fleet, the integration packages, the content connectors, the crawler, and Automatic Import are Elastic License 2.0 or proprietary and Ceded, though the accumulated opinions are configuration rather than captive logic. The runtime is deterministic execution of pipelines the enterprise wrote and, on Logstash and the SDKs, also runs; the model in Automatic Import writes a pipeline at design time behind a human review and never runs it. If the customer writes or controls the code, the customer decides: code decides, visible, overridable, Retained.",
      "notes": "Watch-list, notes only: Wired Streams (Preview on Serverless, Preview since 9.2 on Elastic Stack) route documents into child streams by partitioning rules with inherited mappings, processors, and retention, and AI-partition and parse raw logs; Elastic-managed content connectors (Preview on Serverless Security, Preview since 9.1 on Elastic Stack); the AWS managed integration (technical preview 9.5); ES|QL Data Federation (experimental 9.5, Enterprise) reads Parquet, NDJSON, CSV, and TSV from object storage without ingesting; the EDOT Browser SDK (technical preview). Public evidence that moves the cell: a shipped CDC source, a lineage surface, or a lakehouse writer would put the day-two test back in play and reopen strong. Instrument follow-up: Databricks, Snowflake, Qlik, and VAST read vendor / Ceded at 1C on enterprise-authored pipelines; this cell reads code / Retained on the derivation's own words, and the difference is logged for /reconcile.",
      "components": [
        {
          "component": "Elastic Agent + Fleet + Integrations",
          "detail": "One agent for logs, metrics, traces, endpoint security, and cloud telemetry, centrally managed through Fleet policies, with hundreds of prebuilt integrations and outputs to Elasticsearch, Logstash, or Kafka (GA). Elastic License 2.0; policies and integration packages are Elastic-specific and rebuild on exit.",
          "dapm": "Ceded"
        },
        {
          "component": "Logstash + Beats (Apache 2.0 Core)",
          "detail": "The general-purpose pipeline: any input, scriptable filters, any output including Kafka, S3, HTTP, and non-Elastic indexes. Core source and -oss binaries are Apache License 2.0; the x-pack folder (centralized pipeline management) is Elastic License. Open-source software the enterprise operates, with Fluentd, Vector, and the OpenTelemetry Collector as real alternatives.",
          "dapm": "Retained"
        },
        {
          "component": "EDOT Language SDKs (OpenTelemetry, Apache 2.0)",
          "detail": "GA distributions for Java, .NET, Node.js, PHP, Python, iOS, and Android (Browser in technical preview). OpenTelemetry is a multi-vendor standard interface; instrumentation lifts to any OTel distribution and any OTLP backend.",
          "dapm": "Retained"
        },
        {
          "component": "EDOT Collector (Built Into Elastic Agent Since 9.5)",
          "detail": "The OpenTelemetry collector capability, formerly a standalone distribution and from 9.5 packaged inside Elastic Agent (Elastic License 2.0). Collector configurations are OTel-standard and lift to any distribution; the binary is Elastic's. A proprietary implementation behind a multi-vendor standard interface: Delegated.",
          "dapm": "Delegated"
        },
        {
          "component": "Elastic Cloud Managed OTLP Endpoint",
          "detail": "GA on Serverless and on Elastic Cloud Hosted (March 19, 2026); unavailable for self-managed, Elastic Cloud Enterprise (ECE), and ECK. Accepts OTLP from any SDK or collector, buffers through Kafka to absorb bursts and decouple ingestion from indexing, stores the OpenTelemetry data model natively. A managed service behind a standard interface: switch the exporter endpoint and leave.",
          "dapm": "Delegated"
        },
        {
          "component": "In-Cluster Transformation (Ingest Pipelines, Inference and Enrich Processors, Transforms, Downsampling, Data Stream Lifecycle)",
          "detail": "Ingest pipelines with grok, dissect, enrich, script, and inference processors run embedding and entity extraction at index time; continuous pivot and latest transforms and time-series downsampling summarize in place. Free-tier core, riding the 1A substrate chips: Retained on the self-run source, Delegated on Hosted, Ceded on Serverless.",
          "dapm": "Retained"
        },
        {
          "component": "Content Connectors + Open Web Crawler",
          "detail": "Self-managed Python connectors (SharePoint, Confluence, Google Drive, S3, GCS, Jira, Salesforce, ServiceNow, relational databases, and more) and the Open Web Crawler, run on the customer's infrastructure; the Elastic-managed search connectors on Cloud Hosted were discontinued in 9.0, and Elastic-managed content connectors are Preview. Elastic License 2.0 source-available, not open source: the sync configurations rebuild on exit.",
          "dapm": "Ceded"
        },
        {
          "component": "Automatic Import (LLM-Generated Integrations)",
          "detail": "GA on Elastic Stack (Enterprise subscription) and on Serverless (Security Analytics Complete or Observability Complete tier). A model analyzes sample data from a source without a prebuilt integration and generates the ingest pipeline and Elastic Common Schema mapping, reviewed by a human before deployment. Proprietary, and its output is an Elastic integration package.",
          "dapm": "Ceded"
        }
      ]
    },
    {
      "id": "layer2a",
      "label": "Layer 2A",
      "shortName": "Orchestration",
      "title": "Infrastructure Orchestration",
      "purpose": "GPU scheduling, quotas, RBAC, fair-share scheduling, utilization optimization",
      "status": "moderate",
      "statusLabel": "Platform-Scoped Orchestration (ECE, ECK, Autoscaling); No GPU Plane",
      "authority": {
        "decides": "vendor",
        "visible": true,
        "overridable": false,
        "boundary": "vendor",
        "direction": "Ceded"
      },
      "nvidia": [
        {
          "component": "No GPU Plane to Depend On",
          "detail": "Layer 2A is where NVIDIA dependency concentrates for most of the map (Run:ai, GPU Operator, GPU scheduling), and Elastic has no GPU plane to be dependent in. The GPUs behind the Elastic Inference Service are Elastic's to schedule; the GPUs under cuVS vector indexing are the enterprise's, scheduled by whatever runs the node."
        }
      ],
      "gap": "Elastic orchestrates Elastic, on three paths, and the buyer picks how much of it to hold. Elastic Cloud Enterprise is a self-managed orchestrator: the enterprise installs it on its own virtual machines (VMs), premises, or cloud accounts and gets automated provisioning, scaling, and upgrades of many deployments, SSO and role-based access, and an API and user interface (UI) for the fleet. Elastic Cloud on Kubernetes is the operator form of the same thing on the enterprise's Kubernetes (Google Kubernetes Engine (GKE), Azure Kubernetes Service (AKS), Amazon Elastic Kubernetes Service (EKS), OpenShift, or any conformant distribution), managing Elasticsearch, Kibana, Agent, Logstash, and the rest as custom resources, with Elasticsearch autoscaling and the Horizontal Pod Autoscaler for stateless parts. Elastic Cloud Hosted runs the orchestrator for you with autoscaling policies you can see and edit; Serverless removes node, topology, and autoscaling administration and leaves Search Power, the search boost window, and retention as the knobs, scaling on usage, separating search from indexing, and billing by compute units. Cluster autoscaling covers data nodes on storage and machine learning nodes through policies of roles and deciders; trained-model deployments scale separately through adaptive allocations and adaptive resources, always on in Serverless. It's real orchestration, it ships, and enterprises run thousands of nodes under it.\n\nNone of it's the layer's job. The purpose line is GPU scheduling, quotas, fair-share, and utilization for the enterprise's AI compute, and Elastic has no surface for any of that. Machine learning nodes are CPU. The GPU acceleration Elastic sells is the Elastic Inference Service, an Elastic-operated NVIDIA fleet billed per token that the customer never sees, sizes, or schedules: under the exposure test that's Elastic's serving fact at 2B, not a customer-administered compute plane. GPU-accelerated vector indexing runs on a GPU the enterprise provisions on its own node, and Elastic schedules nothing about it. So the architect's concern is the same as at the other software rows: the orchestration is scoped to the vendor's workloads, the enterprise's AI compute is orchestrated one layer down by Kubernetes, Run:ai, or a cloud, and the opinions accumulated in ECE and Elastic Cloud on Kubernetes (ECK) (deployment topologies, autoscaling policies, node sets) are Elastic's API with no second implementer.\n\nCalibration: Qlik, Snowflake, Databricks, and Palantir all read moderate for platform-scoped orchestration the vendor holds, with no customer GPU plane or a pre-GA one, and Qlik's cell names the thin end of the cohort. Elastic sits above the thin end: ECE and ECK are purchasable, customer-administered orchestrators, which is more than any of those four exposes. Kamiwaza reads gap because its Swarm orchestrates only the platform's own services; ECE and ECK orchestrate a fleet of the enterprise's clusters across its own infrastructure, which is the real-dependence guardrail met. IBM reads strong on OpenShift because the orchestrator is general and the GPU plane is real; Elastic's is neither. Present, Elastic-scoped, no GPU plane: moderate.",
      "borrowedJudgment": "Moderate. The orchestration opinions (deployment topology, allocation, autoscaling deciders, upgrade sequencing) are Elastic's and Ceded on every path, including the two the enterprise operates itself; running ECE on your own VMs is operational control, not authority. The capacity underneath is the enterprise's on ECE and ECK and the hyperscaler's on Hosted and Serverless. The runtime tradeoff is Elastic's deciders estimating capacity, exposed through the autoscaling and capacity APIs and bounded by policy on Hosted, ECE, and ECK; bounds aren't a runtime override, and the cohort reads the same shape Ceded. Vendor decides, visible, not overridable, Ceded. The GPU question is wholly delegated one layer down or absorbed by Elastic behind EIS.",
      "notes": "Nothing on the watch-list at this layer. Public evidence that moves the cell: a customer-administered GPU node type or scheduler in any Elastic deployment model; GPU-accelerated indexing on Elastic Cloud Hosted with sizing the customer controls.",
      "components": [
        {
          "component": "Elastic Cloud Enterprise (Self-Managed Orchestrator)",
          "detail": "GA. Installs on the enterprise's VMs, premises, or cloud accounts and orchestrates many Elastic deployments: provisioning, scaling, upgrades, SSO and role-based access control (RBAC), API and UI. A proprietary orchestrator the enterprise runs itself; self-deployable isn't Retained, and the fleet definitions have no second implementer.",
          "dapm": "Ceded"
        },
        {
          "component": "Elastic Cloud on Kubernetes (Operator)",
          "detail": "GA, Elastic License 2.0 with Basic and Enterprise tiers. Manages Elasticsearch, Kibana, Agent, Fleet, Logstash, Beats, application performance monitoring (APM) Server, and the Package Registry as custom resources on GKE, AKS, EKS, OpenShift, or any conformant Kubernetes, with Elasticsearch autoscaling and Horizontal Pod Autoscaler (HPA) for stateless workloads. The consumed interface is Elastic's custom resource API, not the Kubernetes API: the manifests don't lift to another vendor's operator. The Kubernetes substrate is the enterprise's and isn't this component.",
          "dapm": "Ceded"
        },
        {
          "component": "Elastic Cloud Hosted + Serverless Autoscaling",
          "detail": "GA. Hosted exposes cluster autoscaling policies (roles and deciders) for data and machine learning nodes that the enterprise can view and bound, with trained-model deployments scaling separately through adaptive allocations and resources; Serverless autoscales on usage with no enablement, exposing Search Power, the search boost window, and retention while Elastic keeps node, topology, and autoscaling control. Vendor-run capacity management.",
          "dapm": "Ceded"
        }
      ]
    },
    {
      "id": "layer2b",
      "label": "Layer 2B",
      "shortName": "Runtime",
      "title": "Application Runtime & Execution",
      "purpose": "Model serving, agent execution, inference APIs, distributed inference",
      "status": "moderate",
      "statusLabel": "Agent Builder + Workflows Runtime (GA); Brokered LLMs, No LLM Serving",
      "authority": {
        "decides": "model",
        "visible": true,
        "overridable": true,
        "boundary": "model",
        "direction": "Delegated"
      },
      "nvidia": [
        {
          "component": "Elastic Inference Service GPUs (Elastic-Operated)",
          "detail": "The Managed LLMs, embeddings, and rerankers run on NVIDIA GPUs Elastic operates and bills per token. No customer-side NVIDIA dependency exists at this layer: ML nodes are CPU, and nothing Elastic sells serves an LLM on the customer's GPUs."
        }
      ],
      "gap": "Agent Builder (GA on Serverless and since 9.3 on Elastic Stack) is a real agent runtime over the data Elastic already holds. The enterprise defines agents with instructions and tools; tools are ES|QL queries and index searches it writes, Elastic Workflows it authors, and any external MCP server it imports; agents run through a chat surface or the Converse API with the model chosen per agent or overridden per request. Elastic Workflows (GA 9.4 on every deployment type, Enterprise) is the action half: manual, scheduled, and alert triggers, Elasticsearch, HTTP, Kibana, and agent steps, a waitForApproval step that pauses for a human and records who started the run and who approved it, natural-language authoring and versioning with rollback in 9.5. The MCP server (GA 9.3) turns every tool, including Workflows, into something Claude Desktop, Cursor, LangChain, or another vendor's agent can call. Models come brokered: the Elastic Managed LLMs on the Elastic Inference Service are a catalog of named third-party models (Claude Haiku 4.5 through Opus and Sonnet 5, Gemini 3.x, GPT-5.2 through 5.6, GLM 5.2, gpt-oss) with zero retention and per-token billing, reachable from self-managed clusters through Cloud Connect, or the enterprise brings its own OpenAI, Azure OpenAI, Bedrock, Gemini, Anthropic, or OpenAI-compatible local endpoint. The buyer gets agents over governed enterprise data, with a deterministic action layer and human gates, without standing up a serving stack.\n\nWhat the buyer doesn't get is a serving stack. There's no product for serving a large language model on Elastic, on the customer's GPUs or Elastic's; no fine-tuning; no distributed inference. Machine learning nodes serve embedding, reranking, and natural language processing (NLP) models on central processing units (CPUs) (the customer-imported chip scored at 1B), and the Elastic Inference Service serves Elastic's catalog on Elastic's GPUs. The agent runtime is capable but bounded: tools are queries, workflows, and MCP calls, with no GA code-execution or HTTP tool inside Agent Builder itself (the connectors library that would add third-party API calls is preview behind a flag), so an agent that needs to compute rather than retrieve and act goes out through Workflows or an external MCP server. Human-in-the-loop confirmation covers Elastic-built tools and skills, not custom tools; the enterprise's gate is the waitForApproval step in Workflows, which means an agent calling an external MCP tool acts as the user with no Elastic gate in between. Tools run as the calling user with that user's privileges, which is the right default and also the whole identity story (Layer 2C). Agent tracing is technical preview. Rule 4 reads the runtime as general on its slice: an agent Elastic never anticipated runs if its work is search, ES|QL, and actions.\n\nCalibration: the Salesforce and Palantir precedent scores strong on a governed, constructible, any-model agent runtime without general model serving, and the line that separated Palantir (strong) from Qlik (moderate) is constructible governed runtime with swappable model versus configurable agents with a fixed model. Elastic has the Palantir shape on three legs: constructible through custom tools and Workflows as deterministic control flow, swappable model, and deterministic execution with human gates. What holds it at moderate is rule 5's first-release maturity gate: no evaluation surface, tracing in technical preview, no confirmation on custom tools, a runtime seven months GA. Snowflake and Databricks add serving and fine-tuning on top of the same shape; Qlik reads moderate on turnkey agents with no model serving; Kamiwaza reads moderate on a runtime the enterprise deploys. Elastic sits well above Qlik and below the Palantir bar on maturity, not on serving. Moderate, with the legs that move it named.",
      "borrowedJudgment": "Low for the runtime, split at the model. Agent Builder, Workflows, and the MCP server are Elastic IP and Ceded to Elastic: the tools behind the standard protocol are Elastic objects, the Snowflake and VAST reading. Model access is Delegated on both paths: the Managed LLMs are a broker the enterprise can replace with its own connector, and its own connectors consume the standard interfaces the instrument treats as the S3 of inference; prompts, evals, and tool logic lift. The tools the enterprise writes and the workflow gates it configures are Retained on the Snowflake ruling: they are the seam where control passes from instructing the model to executing code outside it. The model decides which tool to call; the enterprise's tools and the persisted waitForApproval gate decide whether the effect happens on the workflow path, and nothing gates the MCP-tool path: model decides, visible, overridable, Delegated.",
      "notes": "Watch-list, notes only: the agent-to-agent (A2A) server (the send-task endpoint is labeled Experimental in the Kibana API reference, added in 9.2, while the overview page says GA; the API reference governs); Agent Builder tracing as OpenTelemetry (technical preview 9.5); the Agent Builder connectors library including webhook-backed HTTP calls (preview behind agentBuilder:experimentalFeatures); the Amazon Bedrock AgentCore integration (technical preview 9.3); the Elastic and OpenAI collaboration (July 30, 2026) plans to bring GPT-5.5 Cyber models into Elastic Security agentic workflows, not shipped. Claude Opus 4.5 and Sonnet 4.5 are Legacy (end of life soon) on EIS. Public evidence that moves the cell: an evaluation surface and GA tracing for Agent Builder, or confirmation on custom tools, would clear the maturity gate; a GA product for serving or fine-tuning a customer's own LLM would widen the layer. Either reopens strong.",
      "components": [
        {
          "component": "Elastic Agent Builder (Agents, Tools, Converse API, Chat)",
          "detail": "GA on Serverless and since 9.3 on Elastic Stack, Enterprise tier. Custom agents with instructions and assigned tools; built-in tools, custom ES|QL and index search tools, workflow tools, and imported MCP tools; the Converse API with per-request model override; skills, attachments, and plugins (9.4). Agent and tool definitions are Elastic objects with no second implementer.",
          "dapm": "Ceded"
        },
        {
          "component": "Customer-Authored Tools + Workflow Approval Gates (ES|QL Tools, Index Search Tools, Workflow Tools, waitForApproval)",
          "detail": "The queries, searches, and workflows the enterprise writes as tools, and the waitForApproval gate it places before consequential actions in Workflows. The customer possesses and controls the logic; the Elastic dialect is a residual rewrite. Retained on the Snowflake customer-tools ruling, and the deterministic gate that makes the authority reading Delegated on the workflow path. Confirmation isn't available for custom tools, external MCP tools run ungated, and external-channel approvals in waitForApproval use public, short-lived links the docs say not to use for destructive workflows.",
          "dapm": "Retained"
        },
        {
          "component": "Elastic Managed LLMs on the Elastic Inference Service",
          "detail": "GA since 9.0 and on Serverless. A catalog of GA third-party models (Anthropic Claude Haiku 4.5, Opus 4.6 through 5, Sonnet 4.6 and 5; Google Gemini 3.0 through 3.8; OpenAI GPT-5.2 through 5.6 variants and gpt-oss 20B and 120B; Z.ai GLM 5.2) served through EIS with zero retention, request metadata logged in AWS CloudWatch, per-token billing, and Cloud Connect for self-managed clusters. A managed broker the enterprise can replace with its own connector: Delegated.",
          "dapm": "Delegated"
        },
        {
          "component": "LLM Connectors (OpenAI, Azure OpenAI, Amazon Bedrock, Google Gemini, Anthropic, OpenAI-Compatible Local)",
          "detail": "Bring-your-own model access through the providers' own APIs, including a self-hosted vLLM or Ollama endpoint behind the OpenAI-compatible interface. Dynamic LLM connectors and Inference Management GA 9.4; fast model routing GA 9.5. The inference-interface ruling: Delegated.",
          "dapm": "Delegated"
        },
        {
          "component": "Elastic Workflows (Automation and Action Engine)",
          "detail": "GA 9.4 on Serverless, Hosted, ECE, ECK, and self-managed, Enterprise tier, execution-based pricing. YAML workflows with manual, scheduled, and alert triggers; Elasticsearch, HTTP, Kibana, and agent steps; waitForApproval; versioning and rollback and natural-language authoring (9.5). An Elastic dialect executed only inside Kibana; the Keep lineage stays open source but the product doesn't lift.",
          "dapm": "Ceded"
        },
        {
          "component": "MCP Server (Tool and Workflow Catalog for External Agents)",
          "detail": "GA since 9.3 and on Serverless. Exposes the tool catalog including Workflows to Claude Desktop, Cursor, LangChain, and any MCP host, with API keys everywhere and OAuth 2.1 on Serverless. The protocol is a standard; the catalog behind it's Elastic objects that run nowhere else, the Snowflake and VAST reading: Ceded.",
          "dapm": "Ceded"
        }
      ]
    },
    {
      "id": "layer2c",
      "label": "Layer 2C",
      "shortName": "Reasoning",
      "title": "Agentic Infrastructure — The Reasoning Plane",
      "purpose": "Policy-driven placement and resource coordination — the Autonomy Layer",
      "status": "moderate",
      "statusLabel": "Observability + Workflow Orchestration + Registry; No Agent Identity, No Gateway",
      "authority": {
        "decides": "code",
        "visible": true,
        "overridable": true,
        "boundary": "vendor",
        "direction": "Retained"
      },
      "nvidia": [
        {
          "component": "No NVIDIA Layer 2C Dependency",
          "detail": "No reasoning-plane product exists to carry a dependency, and the governance surfaces that do exist are Kibana and Elasticsearch objects."
        }
      ],
      "gap": "Elastic's reasoning plane is assembled from three products that weren't designed as one. The registry leg is Agent Builder's catalog: agents and tools are managed objects, scoped by Kibana Spaces, governed by the agentBuilder feature privilege, with tools assigned per agent, so which agent may use which tool is an administered fact rather than a prompt. The orchestration leg is Workflows: agents call workflows as tools and workflows call agents as steps, with the waitForApproval gate recording the responder when the approval comes from a signed-in Kibana user, and versioning with rollback since 9.5, so multi-agent sequences are deterministic code with human checkpoints. The observability leg is the part Elastic is actually known for: LLM and agentic-AI observability (GA on every Elastic Cloud deployment type) meters and traces agents running on Amazon Bedrock, Azure OpenAI and AI Foundry, Google Vertex and Gemini Enterprise, OpenAI, and Anthropic through Elastic-built integrations, with Bedrock Guardrails events and Anthropic cost polling; Elastic Security adds LLM audit integrations with standardized fields. The buyer who runs agents on three platforms and wants one place to see what they did already has Elastic in the design.\n\nTwo legs are missing, and they are the two that make governance enforceable at request time. There's no agent identity: agents execute as the calling user with that user's index privileges, MCP OAuth tokens are the user's, and API keys are machine credentials, so nothing in the audit trail says an agent rather than a person acted, and no agent can hold less than its user. Snowflake's SERVICE_AGENT users and agent-typed access history are the calibration point; Elastic has the Lab 019 shape instead, keys and consent user-bound. There's no request-time gateway: Inference Management (GA 9.4) is one place to administer inference endpoints, models, and connectors, and per-user connector authentication (GA 9.4) improves attribution, but no per-agent rate limit, cost cap, or tool-access policy is evaluated per request. Fast model routing (GA 9.5) is single-variable routing, not placement reasoning. Agent Builder's own tracing and the OpenTelemetry LLM instrumentation in the EDOT SDKs are technical preview. Applying the rules: no reasoning mechanism, and a partial Intelligence-2C plane, three legs of five. The live per-inference placement gap and the deterministic outcome-validator gap are universal on the instrument and noted rather than charged.\n\nCalibration: Snowflake reads moderate on identity, registry, and observability; Databricks on governance, gateway, and supervisor; Salesforce on broad governance without a reasoning mechanism. Elastic's three legs are registry, orchestration, and observability, the same count as Snowflake with the identity and observability legs swapped in depth: Elastic's observability is the most complete on the map and its identity is the thinnest. Qlik and VAST read gap because permission inheritance and confirmation prompts are properties of agents scored at 2B, not a plane; Elastic clears that bar on the orchestration and observability products, and the registry leg alone would not. Moderate, at the Snowflake standard, with the two missing legs named.",
      "borrowedJudgment": "Low for what is provided, and the term means dependence on third parties: the catalog, Workflows, and the observability integrations are Elastic IP and Ceded to Elastic; the OpenTelemetry path that would make the telemetry lift is technical preview and unscored. Which agent may act on what is decided by roles and Spaces the enterprise writes, evaluated deterministically by Elasticsearch, and by approval gates the enterprise authors in Workflows: code decides, visible, overridable, Retained, the Salesforce and VMware reading. The model decides inside the agent loop and that reading lives at 2B; here the enterprise's policy is the last word, thin as the policy vocabulary is.",
      "notes": "Watch-list, notes only: Agent Builder agent observability and monitoring (technical preview 9.5; traces in traces-agent_builder.otel-<space-id>, logs in logs-agent_builder.otel-<space-id>, on by default per an Elastic engineering post, preview per the release post); EDOT LLM observability in the Java, Node.js, and Python SDKs (tech preview); the A2A server (experimental API endpoints added in 9.2); the Agent Builder connectors library (preview behind agentBuilder:experimentalFeatures); the Amazon Bedrock AgentCore observability integration (technical preview 9.3); the Elastic and OpenAI collaboration's stated intent to extend governance to the OpenAI platform (July 30, 2026, nothing shipped). External-channel approvals in waitForApproval use public, short-lived resume links and aren't audit-grade; the docs say not to use them for destructive workflows. Public evidence that moves the cell: a documented agent principal distinct from the invoking user; a request-time policy surface over agent tool calls or model calls with per-agent limits; Agent Builder tracing GA. Identity plus gateway at GA would complete the plane.",
      "components": [
        {
          "component": "Agent + Tool Catalog Under Kibana RBAC and Spaces (Registry Leg)",
          "detail": "Agents and tools as managed objects: Space-scoped, governed by the agentBuilder feature privilege, tools assigned per agent, MCP server exposure of the catalog with API keys or user-bound OAuth 2.1. No promotion gates, no agent versioning, no agent principal. Elastic objects with no second implementer.",
          "dapm": "Ceded"
        },
        {
          "component": "Workflows as Cross-Agent Orchestration (Agent Steps, Workflow Tools, waitForApproval, Versioning)",
          "detail": "Deterministic sequencing of agents and actions: agents invoke workflows as tools, workflows invoke agents as steps, waitForApproval records the responder for Kibana-authenticated approvals (external-channel approvals use public short-lived links and aren't audit-grade), versioning and rollback since 9.5. Scored at 2B as the action engine; here as the orchestration leg. An Elastic dialect executed only inside Kibana.",
          "dapm": "Ceded"
        },
        {
          "component": "LLM and Agentic-AI Observability (Elastic Observability + Security LLM Integrations)",
          "detail": "GA on Serverless, Hosted, ECK, and ECE. Metrics, logs, token and cost insight, and guardrail events for agents on Amazon Bedrock, Azure OpenAI and AI Foundry, Google Vertex and Gemini Enterprise, OpenAI, and Anthropic through Elastic-built integrations and Kibana dashboards; Security's LLM integrations add standardized audit fields. The GA surface is Elastic's integrations and dashboards, not a standard interface; the OpenTelemetry tracing path is technical preview and watch-listed. Ceded.",
          "dapm": "Ceded"
        }
      ]
    },
    {
      "id": "layer3",
      "label": "Layer 3 (+1)",
      "shortName": "Applications",
      "title": "AI Application Layer — The Value Plane",
      "purpose": "AI-powered business capabilities — business logic, workflow automation",
      "status": "strong",
      "statusLabel": "First-Party Security, Observability, and Search Applications; Agentic SOC GA",
      "authority": {
        "decides": "vendor",
        "visible": true,
        "overridable": false,
        "boundary": "vendor",
        "direction": "Ceded"
      },
      "nvidia": [
        {
          "component": "No NVIDIA Layer 3 Dependency",
          "detail": "The applications run on Elasticsearch and Kibana; the models behind their AI features are brokered through the Elastic Inference Service or the customer's connectors, with no NVIDIA component in the application layer."
        }
      ],
      "gap": "This is where Elastic's revenue lives and where the buyer starts. Elastic Security is a security information and event management (SIEM) and endpoint platform with the agentic security operations center (SOC) shipping: Attack Discovery (GA) correlates alerts into attack narratives mapped to the MITRE ATT&CK adversary-technique matrix and, since the July 31, 2026 release, investigates before it flags, hunting raw events and corroborating entity risk so analysts get a short list of validated threats; the Security AI Assistant (GA), the alert-analysis workflow, and Workflows-based response replace a standalone security orchestration, automation, and response (SOAR); the AI SOC Engine packages the AI layer as a Serverless overlay on Splunk, Sentinel, and CrowdStrike estates; Automatic Migration ports Splunk rules. Elastic Observability is a Gartner Leader in 2026: APM, logs, metrics, and traces on an OpenTelemetry-native store, Streams for log investigation, native Prometheus Query Language (PromQL) and Prometheus remote-write (GA 9.5), service level objectives (SLOs) and alerting, with the Observability AI Assistant deprecated since 9.4 in favor of Agent Builder agents and observability Agent Skills. Kibana is the surface for all of it: dashboards, Discover, and ES|QL. For search builders, Playground turns the 1B engine into a testable retrieval experience and Search UI is an Apache-2.0 headless library for shipping it. The buyer gets the applications a security or platform team runs its day on, with the AI features GA rather than promised.\n\nThe architect's concern is that these are IT-operations applications, and the purpose line reads business capabilities. The cell reads security and observability as the business capabilities of the buyer who signs the Elastic contract, the same way the instrument reads analytics as Qlik's value plane; an enterprise looking for AI-powered CRM, ERP, or industry applications finds none here. Nearly everything scored is Elastic's: detection rules, cases, dashboards, SLOs, and playbooks are Kibana objects that rebuild on exit, and the free-tier Kibana core and Search UI are the pieces that lift. The AI-driven pieces put a model in the analyst's chair: Attack Discovery decides what is an attack before a human sees it, and the analyst's override is the control; the application's opinions about what to show, rank, and automate remain Elastic's.\n\nCalibration: Qlik reads strong on the analytics value plane, Snowflake and Databricks on first-party agents and applications, Salesforce and Palantir on first-party business applications. Elastic is the Qlik case in a different department: the vendor's native layer, first-party, with GA agentic features on top of its own runtime. VAST reads moderate on a partner ecosystem because it ships no applications; Elastic ships three. Strong.",
      "borrowedJudgment": "Low. Security, Observability, and Playground are Elastic IP and Ceded to Elastic; the Kibana free-tier core is open-source software the enterprise can run itself and reads Retained on the same path as the Elasticsearch core, with OpenSearch Dashboards as the fork and drift named; Search UI is an Apache-2.0 library with custom backend connectors and reads Retained. The models behind the AI features are brokered and swappable (2B). The application layer's runtime tradeoffs, what to surface, correlate, rank, and automate, are Elastic's: vendor decides, visible, not overridable, Ceded, the reading every first-party value plane on the map carries.",
      "notes": "Watch-list, notes only: Kubernetes agentic investigation workflows and the Observability MCP App (technical preview, April 22, 2026, despite the 9.4 release post calling the workflows GA; the product post governs); MCP Apps for Security, Observability, and Search (public preview, April 21, 2026); Search Applications (beta, not recommended for new 9.x users); AI-powered dashboard creation and Dashboards as Code (technical preview 9.4); SIEM Readiness visibility health (technical preview 9.4); Automatic Migration for QRadar rules and for dashboards (technical preview); the AWS managed integration (technical preview 9.5). Public evidence that moves the cell: nothing upward from strong; the cell narrows if Elastic retires a scored application or the agentic SOC features fall back to preview.",
      "components": [
        {
          "component": "Elastic Security (SIEM, Endpoint, Attack Discovery, Security AI Assistant, AI SOC Engine)",
          "detail": "GA. Detection engine and endpoint protection, Attack Discovery as an autonomous triage agent (July 31, 2026), the Security AI Assistant (Enterprise on Stack, EASE or Security Analytics Complete on Serverless), alert-analysis and response through Workflows, Entity Analytics, Automatic Migration for Splunk rules, and the AI SOC Engine overlay for Splunk, Sentinel, and CrowdStrike estates. Rules, cases, and playbooks are Kibana objects with no second implementer.",
          "dapm": "Ceded"
        },
        {
          "component": "Elastic Observability (APM, Logs, Metrics, Streams, PromQL, SLOs)",
          "detail": "GA. OpenTelemetry-native APM, logs, and metrics; Streams; native PromQL and Prometheus remote-write (9.5); SLOs and alerting; observability Agent Skills; a 2026 Gartner Magic Quadrant Leader. Kubernetes agentic investigations are technical preview and watch-listed. The intake is standards-based and scored at 1C; the application, its dashboards, SLOs, and investigations are Elastic's.",
          "dapm": "Ceded"
        },
        {
          "component": "Kibana Core (Dashboards, Discover, Free-Tier Source Under the AGPLv3 Option)",
          "detail": "The free-tier surface the enterprise can run itself; OpenSearch Dashboards is the fork and saved objects port with export, import, and rework. Rides the 1A substrate chips: Retained on the self-run source, Delegated on Hosted, Ceded on Serverless. The Dashboards and Visualizations API (GA 9.5), ES|QL, and paid Kibana features are Elastic-specific surfaces outside the free core and belong to the solution chips.",
          "dapm": "Retained"
        },
        {
          "component": "Playground (Retrieval Experience Builder)",
          "detail": "GA. Build and test retrieval-augmented experiences over the 1B engine with the configured LLM connectors, then export the query and code. An Elastic-specific application surface. Enterprise Search (App Search and Workplace Search) is discontinued in 9.0 and Search Applications are beta, watch-listed.",
          "dapm": "Ceded"
        },
        {
          "component": "Search UI (Apache-2.0 Headless Library)",
          "detail": "GA. A headless JavaScript search library for React, vanilla JavaScript, and other frameworks, maintained by Elastic under Apache-2.0, with a connector system that works against any backend. Open-source software the enterprise owns in its own application code.",
          "dapm": "Retained"
        }
      ]
    }
  ]
}