Standard operating procedures Keedian executes across the customer estate. Filter by name, domain, source, type, tier, severity or client; click any column header to sort. Click any SOP with a detail link to open its full page (trigger, action plan, escalation, prevention).
| SOP | Domain | Recommended tier | Severity | Source | Type | AI executes | Related metric | Value drivers | Client | Description |
|---|---|---|---|---|---|---|---|---|---|---|
| Excessive runtime | essential | medium | optimization_metric | Standard | hybrid | runtime |
— | RTU runs more hours per day than the expected range for the site profile. | ||
| No runtime when expected | essential | high | optimization_metric | Standard | hybrid | runtime |
— | RTU is silent during its scheduled operating hours with communications confirmed healthy — indicating an equipment-side problem (power loss, control disable, mechanical failure). A communications-failure alarm is a separate event at the platform layer. | ||
| Off-schedule operation | optimized | low | optimization_metric | Standard | yes | runtime |
— | RTU is running outside its agreed operating window — override, schedule drift, or manual operation. | ||
| Low DeltaT | essential | high | optimization_metric | Standard | hybrid | cooling_delta_t |
— | DeltaT below the floor during active cooling — refrigerant-side / capacity family (refrigerant loss, compressor degradation, coil fouling). | ||
| High DeltaT | essential | medium | optimization_metric | Standard | hybrid | cooling_delta_t |
— | DeltaT above the ceiling during active cooling — airflow-side (clogged filter, blower failure, closed dampers, ducting obstruction). | ||
| Setpoint out of corporate range | essential | medium | optimization_metric | Standard | yes | setpoint_compliance |
— | Current setpoint is outside the tolerance range around the corporate setpoint policy for the zone and time of day. A single alarm covers any out-of-range condition; the tolerance range defines how much deviation is acceptable before firing. | ||
| Severe temperature deviation | essential | urgent | optimization_metric | Standard | hybrid | temp_compliance |
— | Space temperature is far outside the expected band — an active comfort failure is in progress. | ||
| Sustained temperature out-of-range | optimized | high | optimization_metric | Standard | hybrid | temp_compliance |
— | Space temperature has been outside the expected band for longer than the noise / startup tolerance window — a real condition, not a transient. | ||
| Sequence fault — Chiller → CHW (CP) pump | essential | urgent | optimization_metric | Standard | hybrid | chiller_plant_operational_compliance |
— | A chiller is proven ON but no chilled-water (CP / primary) pump is proven running — the chiller is producing cooling with no chilled-water flow through its evaporator. The most safety-critical of the plant interlocks: sustained, it risks a low-flow trip or a frozen, physically damaged evaporator. | ||
| Sequence fault — Chiller → CW (CC) pump | essential | urgent | optimization_metric | Standard | hybrid | chiller_plant_operational_compliance |
— | A chiller is proven ON but no condenser-water (CC) pump is proven running — no condenser flow to carry heat from the condenser out to the tower. Sustained, condensing pressure and temperature climb, the chiller loses efficiency, and it eventually trips on high-pressure protection or shuts down. | ||
| Sequence fault — Chiller → cooling tower | essential | urgent | optimization_metric | Standard | hybrid | chiller_plant_operational_compliance |
— | A chiller is proven ON but no cooling tower is running — the plant has no path to reject heat to the atmosphere. Sustained, condenser water just recirculates and heats up, driving condensing temperature up and efficiency down until the chiller protects itself. | ||
| Plant efficiency drift (kW/ton above design) | essential | medium | optimization_metric | Standard | hybrid | plant_efficiency_kw_per_ton |
— | The plant's metered kW/ton has drifted above its own design / commissioned figure by a set margin, sustained and with no load or wet-bulb explanation — the plant is drawing more power per ton of cooling than it should. A monitoring alarm, not a safety fault: it is communicated at cadence, not dispatched out of cycle. | ||
| Backup redundancy lost | essential | urgent | optimization_metric | Standard | hybrid | continuity_posture |
— | A critical backup point drops from ready — it loses the designed redundancy it was built to hold (N+1, a dual feed, or a backup unit). The severe end of the same alarm is the point going fully not-ready. Read-only: Keedian surfaces which point lost its margin and refers the correction to the customer's electrical / power vendor. | ||
| Backup autonomy below minimum | managed | high | optimization_metric | Standard | hybrid | backup_autonomy |
— | Estimated ride-through — the UPS battery bridge plus the generator's run-time on available fuel — falls below the building's agreed minimum at the present load. If the grid fails now, backup does not cover the outage to restoration. Read-only: Keedian surfaces the shortfall and the leg responsible and refers it to the customer and the electrical / power vendor. | ||
| Generator fuel low | managed | high | optimization_metric | Standard | hybrid | backup_autonomy |
— | Usable fuel has been drawn down so the standby generator's run-time falls under the building's required autonomy — the generator leg of the ride-through is short even if the UPS bridge is intact. Read-only: Keedian surfaces the run-time shortfall and refers refuelling to the customer and the electrical / power vendor. | ||
| UPS battery capacity low | essential | high | optimization_metric | Standard | hybrid | ups_battery_readiness |
— | A UPS battery bank's usable capacity has faded below its agreed band — an aging bank whose bridge is thinning, even while the UPS still shows online. Read-only: Keedian surfaces the fade against nominal and refers the battery service to the customer's electrical / power vendor. | ||
| UPS on bypass | essential | urgent | optimization_metric | Standard | hybrid | ups_battery_readiness |
— | A UPS has moved to bypass — the load is running unprotected on raw utility and the battery bridge is gone right now. Read-only: Keedian surfaces the bypass event and refers restoration to the customer's electrical / power vendor; the UPS is not commanded off bypass. | ||
| Generator not in AUTO | essential | urgent | optimization_metric | Standard | hybrid | generator_start_readiness |
— | A standby set is found in MANUAL or OFF — it will not start on a utility failure regardless of its mechanical condition. The classic silent fault left after service. Read-only: Keedian surfaces the mode and refers the return to AUTO to the customer / electrical / power vendor; the set is not commanded. | ||
| HAV Temporary Setpoint Adjustments | managed | low | ad_hoc_client | Ad-hoc | hybrid | — | HAV | Apply temporary, timed HVAC setpoint overrides at HAV sites via the Delinea-protected remote environment, in compliance with standard setpoint limits. | ||
| HVAC HIP Alarm Monitoring and Response — Tractor Supply | essential | urgent | ad_hoc_client | Ad-hoc | hybrid | — | Tractor Supply | Investigate and resolve HVAC Human Illness Prevention (HIP) temperature alarms at Tractor Supply locations within the 30-minute SLA; suppression is not permitted. | ||
| JCPenney — Review Alarms on a Unit in SC/SC+ | managed | medium | ad_hoc_client | Ad-hoc | hybrid | — | JCPenney | Review active equipment alarms inside the SC/SC+ platform and attempt the initial reset; dispatch a Corrigo work order when the alarm fails to clear. | ||
| JCPenney — Building Occupancy Status (BOS) Mode | managed | low | ad_hoc_client | Ad-hoc | hybrid | — | JCPenney | Operate the Building Occupancy Status (BOS) Mode — formerly the Last Man Out switch — so HVAC, lighting, and alarm systems respond consistently to ADT-panel occupancy state. | ||
| JCPenney — Mechanical Variance Request | managed | medium | ad_hoc_client | Ad-hoc | hybrid | — | JCPenney | Review, validate, and execute JCPenney Mechanical Variance setpoint / schedule requests in compliance with the corporate setpoint policy (cooling ≥71°F, heating ≤70°F) and the per-platform override mechanics for SC/SC+, Niagara/Tridium, PMT, Trane/Summit, and iScope. | ||
| PHD — Thermostat Swaps, Setpoints, and Modes | managed | medium | ad_hoc_client | Ad-hoc | hybrid | — | PHD | Troubleshoot PHD thermostats: locate the device, run a swap test for blank screens, adjust setpoints within corporate lockout limits, change operating mode (heat / cool / auto / EHEAT), and escalate via the 10-step hardware checklist when in doubt. | ||
| 7-Eleven — Ticket Handling: Hot/Cold Store Request for Service | managed | high | ad_hoc_client | Ad-hoc | hybrid | — | 7-Eleven | Provide HVAC diagnostics to the Service Provider for 7-Eleven Request-for-Service tickets within a 1-hour SLA; check 7Help for duplicates, attempt remote resolution where possible, and document the diagnostic into both 7Help and the Accruent ticket. | ||
| Tractor Supply — Envoy Exception Schedule (Adding a Special Event) | managed | low | ad_hoc_client | Ad-hoc | hybrid | — | Tractor Supply | Add a Special Event to a Tractor Supply store schedule in Envoy — inventory, early delivery, renovations, or holiday adjustments — using Modify Schedule behavior so the event overlays cleanly on the regular schedule. | ||
| Chedraui — HVAC Change Requests | managed | medium | ad_hoc_client | Ad-hoc | hybrid | — | Chedraui | Handle Chedraui hot/cold complaints — diagnose units in Ultrasite (status, space / supply / outside temps, relay states), distinguish mechanical failures from comfort-only requests, and only apply a temporary setpoint override after explicit Chedraui Operations Center approval. | ||
| David's Bridal — Controller Offline (XL10 Controller Failure) | managed | high | ad_hoc_client | Ad-hoc | hybrid | — | David's Bridal | Identify suspected XL10 controller failures at David's Bridal locations, verify with ohmmeter continuity checks at the EMS panel terminal strip, and install a Drop Stat (Temporary Construction Stat) so the HVAC unit remains operational until the controller is replaced. | ||
| Off-hours consumption above floor | essential | medium | optimization_metric | Standard | hybrid | energy_consumption |
— | Closed/unoccupied-hours consumption sits above the store's expected overnight floor — energy burned while the site should be idle. | ||
| Consumption step-change | essential | medium | optimization_metric | Standard | hybrid | energy_consumption |
— | Daily or monthly consumption steps up against the site's own trailing baseline with no known operational change. | ||
| Consumption above defined threshold | essential | medium | optimization_metric | Standard | hybrid | energy_consumption |
— | Period or interval consumption exceeds a client-defined absolute ceiling (a budgeted or contracted kWh cap), independent of the site's own baseline drift — the customer's own line in the sand for 'too much energy'. | ||
| Demand peak approaching threshold | essential | medium | optimization_metric | Standard | hybrid | peak_demand |
— | Rolling demand approaches the billed/ratchet peak or a demand-charge threshold, especially inside the utility on-peak window. | ||
| Per-circuit consumption step-change | optimized | high | optimization_metric | Standard | hybrid | per_circuit_load |
— | A sub-metered circuit's consumption or run-fraction steps change with no merchandising or load change. | ||
| Short-cycling | optimized | urgent | optimization_metric | Standard | hybrid | cycling_frequency |
— | A compressor or motor short-cycles — starts per hour exceed the equipment-class threshold — the most destructive and most fixable reliability failure. | ||
| Sustained undervoltage | optimized | high | optimization_metric | Standard | hybrid | service_voltage |
— | Service voltage sits below the lower band for several intervals — chronic undervoltage overheats motors and shortens their life. | ||
| Sustained overvoltage | optimized | medium | optimization_metric | Standard | hybrid | service_voltage |
— | Service voltage sits above the upper band for an extended window — overvoltage shortens the life of LED drivers and electronics. | ||
| Low power factor | optimized | medium | optimization_metric | Standard | hybrid | power_factor |
— | Power factor falls below the tariff penalty threshold where the utility bills it — a reactive-power surcharge on the invoice. | ||
| Off-schedule lighting | essential | medium | optimization_metric | Standard | yes | schedule_compliance |
— | A lighting circuit's on/off state is against its agreed schedule — exterior or parking lights on at mid-day, sales lighting on after close, or a zone dark during operating hours. | ||
| Utilization out of band | essential | medium | optimization_metric | Standard | hybrid | utilization |
— | A lighting circuit's on-fraction falls outside the expected band for its space — too high for a sensor-controlled area, or too low for a space that should be lit. | ||
| Lamp life threshold approaching | essential | low | optimization_metric | Standard | hybrid | burn_hours |
— | Cumulative burn hours on a circuit approach the lamps' rated life — failures will start to cluster, and the burn-hour record is the evidence for an efficiency rebate. | ||
| Out of service / stoppage | essential | high | optimization_metric | Standard | hybrid | vertical_transport_availability |
— | An elevator or escalator reports an out-of-service state or a stoppage from its controller. The headline signal of the add-on: the building operator learns of the stoppage from the system the moment it happens, not from a tenant complaint at the front desk. | ||
| Controller fault code | essential | medium | optimization_metric | Standard | hybrid | vertical_transport_availability |
— | A unit's controller raises a fault code without necessarily taking the unit fully out of service — a drive fault, a safety-circuit fault, a leveling or brake fault. Captured, severity-classified against the agreed fault map, and routed to the maintenance provider before it becomes a stoppage. | ||
| Car emergency / entrapment call | essential | urgent | optimization_metric | Standard | hybrid | vertical_transport_availability |
— | A car's emergency alarm or in-car call button is activated — a possible passenger entrapment. Keedian surfaces this at the highest priority and notifies the building operator immediately, but never in place of the certified in-car emergency line and its monitoring, which handle the actual response. | ||
| Recurring door fault | essential | low | optimization_metric | Standard | hybrid | vertical_transport_availability |
— | A unit logs repeated door faults — nudging, reopening, or door-time-out events — inside a rolling window without a full stoppage yet. A degradation signal: the door operator is the most common cause of an eventual out-of-service, so it is referred before it strands the car. | ||
| Panel fault signal | essential | high | optimization_metric | Standard | hybrid | fire_system_readiness |
— | The fire-alarm panel reports a fault condition — either a supervisory signal (a closed or tampered valve, low water / air pressure, low tank level: the suppression side may not perform) or a trouble signal (a device or loop fault, ground fault, loss of AC power, a failing panel battery: the detection side may not perform). Both mean the system may not do its job in a fire, so both are surfaced and referred to the licensed provider. The supervisory / trouble distinction is kept internal; to the customer it reads as one panel fault signal. | ||
| Loss of communication with the panel | essential | urgent | optimization_metric | Standard | hybrid | fire_system_readiness |
— | Keedian loses its read connection to the fire-alarm panel — the panel's heartbeat is no longer received. The system's state can no longer be seen, so a supervisory or trouble condition arising during the outage would go unnoticed. For a life-safety system this is escalated, not assumed normal. | ||
| Inspection / testing (ITM) overdue | essential | medium | optimization_metric | Standard | hybrid | fire_system_readiness |
— | The regulated inspection, testing, and maintenance (ITM) cycle for the fire system (NFPA 25 / local code) is approaching or past due. A compliance gap independent of the panel state — the system may read normal yet be out of certification. | ||
| Water / air pressure drift | essential | medium | optimization_metric | Standard | hybrid | fire_system_readiness |
— | Where the optional read-only pressure transducer is installed, the sprinkler-riser / fire-pump water pressure (or, on a dry system, the supervisory air pressure) is out of band or drifting toward the panel's supervisory threshold — an early sign of a valve creeping shut, supply degradation, a small leak, or jockey-pump short-cycling, caught before the panel's single-threshold switch trips. | ||
| VAV box starved — airflow below floor with damper saturated open | essential | high | optimization_metric | Standard | hybrid | vav_airflow_delivery |
— | A VAV box is holding below its airflow delivery floor while its damper is already saturated open — it is calling for air it cannot get. Confirmed against damper authority (a low ratio with the damper mid-travel is a control or calibration question, not a starvation fault), so a genuine shortfall means a stuck damper, a collapsed flex duct, or the AHU not holding static for that box. Left alone, the zone drifts warm the moment the load rises. | ||
| Minimum ventilation breach — occupied box below its ventilation floor | essential | medium | optimization_metric | Standard | hybrid | vav_airflow_delivery |
— | A VAV box is running below its agreed occupied minimum airflow during scheduled-occupied hours — the ventilation floor the zone needs for indoor air quality even when it is not calling for cooling. Whether from an over-aggressive energy setback that starved ventilation, a damper stuck below minimum, or a minimum set too low at commissioning, the result is a quietly under-ventilated occupied zone — the stuffy, high-CO2 room no temperature reading explains. Read against the confirmed design minimum, never a computed ventilation rate. | ||
| VAV loop hunting — damper and zone temperature oscillating around setpoint | essential | medium | optimization_metric | Standard | hybrid | vav_airflow_delivery |
— | A VAV box's control loop is hunting — the damper command and the space-temperature error oscillating around setpoint during steady load instead of settling on it. It wears the modulating damper actuator with continuous travel, unsettles the zone (temperature drifting up and down, drafts as airflow swings), and pushes needless airflow swings back to the AHU's static and fan control. Caught early, a future failed-actuator no-cooling call becomes a planned retune or a scheduled actuator replacement. | ||
| AHU not holding discharge — supply air above setpoint under a cooling call | essential | high | optimization_metric | Standard | hybrid | ahu_supply_air_temp_compliance |
— | The air handler holds its supply-air (discharge) temperature above the value its sequence commands while it is calling for cooling — it cannot make the air the floor was designed to receive. Because every box on the handler draws that supply air, one out-of-band AHU warms a whole floor at once: a fouled coil, a chilled-water valve losing authority, low coil flow, or a capacity shortfall at peak. | ||
| AHU overcooling — supply air below setpoint | essential | low | optimization_metric | Standard | hybrid | ahu_supply_air_temp_compliance |
— | The air handler holds its discharge below the temperature its sequence commands — overcooling the supply air it feeds the floor. A chilled-water valve stuck or hunting open, a supply-air reset not applied, or a sequence overriding to a colder setpoint than the load needs; it spends cooling energy the floor did not call for and drives reheat and comfort complaints downstream. | ||
| AHU not holding static — floor losing air with the fan near max | essential | high | optimization_metric | Standard | hybrid | ahu_fan_vfd_performance |
— | The air handler cannot hold the duct static its VAV boxes are calling for — the worst-case box stays pinned open, or several boxes saturate open at once, while the supply fan runs at or near maximum speed. The floor is running out of air even though no single box has failed: a static setpoint or reset capped below demand, a fan at its capacity ceiling, or a system restriction. | ||
| AHU fan drive in bypass or faulted — modulation and reset authority lost | essential | medium | optimization_metric | Standard | hybrid | ahu_fan_vfd_performance |
— | The supply-fan variable-frequency drive is running in bypass or has faulted — the fan runs at full speed regardless of what the static-pressure reset is asking for. Both an energy finding (the reset can no longer save fan energy) and a control-authority finding (the fan can no longer follow the floor's demand): a drive fault, a manual bypass left in place after service, or a tripped protection. | ||
| AHU filter loading high — pressure drop past the change threshold | essential | medium | optimization_metric | Standard | hybrid | ahu_fan_vfd_performance |
— | The pressure drop across the air handler's filter bank has risen past its change threshold — the filters are loaded and the fan is working harder to push the same air through them. Left alone it raises fan energy, erodes the fan's ability to hold static for the floor, and eventually lets the filter bypass; caught in time it is a planned filter change, not an emergency. | ||
| Defrost cycle missed | managed | medium | optimization_metric | Standard | hybrid | refrigeration_defrost_cycle_performance |
— | A case's scheduled defrost cycle does not start when the controller's commissioned schedule expects it. An un-run defrost lets ice build on the coil and pushes the case toward a temperature excursion that is not a hardware fault. | ||
| Defrost duration excessive | managed | medium | optimization_metric | Standard | hybrid | refrigeration_defrost_cycle_performance |
— | A defrost cycle runs materially longer than the case's commissioned duration. A long defrost adds heat to the case and its product and wastes defrost energy, and often signals a termination-sensing or heater problem. | ||
| Defrost termination failure | managed | high | optimization_metric | Standard | hybrid | refrigeration_defrost_cycle_performance |
— | A defrost cycle fails to satisfy the controller's termination condition — it does not end on its temperature or time-out condition as configured. The coil is left iced or the case is held warm past its recovery window, a direct precursor to a temperature excursion. | ||
| Abnormal post-defrost behavior | managed | medium | optimization_metric | Standard | hybrid | refrigeration_defrost_cycle_performance |
— | After a verified defrost and past its configured suppression window, the case does not settle back into its band as expected. Defrost Performance flags the abnormal post-defrost behavior; the recovery curve itself is owned by Temperature Recovery, which this alarm correlates to rather than duplicates. | ||
| High discharge pressure sustained | managed | high | optimization_metric | Standard | hybrid | refrigeration_rack_discharge_pressure |
— | The rack holds discharge (high-side) pressure above its commissioned high-discharge setpoint for longer than its delay. Sustained high-side pressure loses capacity across every case the rack feeds and, unaddressed, walks toward a protection trip. | ||
| Discharge trip approach | managed | high | optimization_metric | Standard | hybrid | refrigeration_rack_discharge_pressure |
— | Rack discharge pressure is approaching the configured trip threshold — the rack is close to a protective shutdown that would take every case it feeds offline at once. A lead-time warning to act before the trip. | ||
| Discharge protection trip | managed | high | optimization_metric | Standard | hybrid | refrigeration_rack_discharge_pressure |
— | The rack's discharge protection has tripped after its configured trip setpoint and delay — a protective shutdown that takes the whole rack offline and puts every case it feeds at risk simultaneously. The highest-urgency rack event. | ||
| Repeated discharge resets | managed | high | optimization_metric | Standard | hybrid | refrigeration_rack_discharge_pressure |
— | The rack's discharge protection auto-resets repeatedly, or trips recur after the configured auto-reset — a rack running on the edge of its protection band that masks a developing fault behind automatic recovery. | ||
| High suction pressure sustained | managed | high | optimization_metric | Standard | hybrid | refrigeration_rack_suction_pressure |
— | The rack holds suction (low-side) pressure above its active operating target for longer than its delay. High suction raises evaporating temperature across the rack and starves case temperatures on every circuit it feeds. | ||
| Low suction pressure sustained | managed | medium | optimization_metric | Standard | hybrid | refrigeration_rack_suction_pressure |
— | The rack holds suction (low-side) pressure below its active operating target for longer than its delay. Persistent low suction wastes energy, can flag a starving or valve/charge issue, and stresses compressors over time. | ||
| Suction setpoint deviation | managed | medium | optimization_metric | Standard | hybrid | refrigeration_rack_suction_pressure |
— | Rack suction pressure persistently deviates from the active controller setpoint in either direction, so the rack is not holding the operating target it is commissioned to — a control-health signal distinct from a single high or low excursion. | ||
| Pump-down does not reach setpoint | managed | high | optimization_metric | Standard | hybrid | refrigeration_rack_pump_down_performance |
— | A pump-down request fails to reach its configured Pump Down Setpt within Pump Down Delay. An incomplete pump-down leaves refrigerant where it should not be and risks liquid return and compressor damage on the next start. | ||
| Pump-down aborted or incomplete | managed | high | optimization_metric | Standard | hybrid | refrigeration_rack_pump_down_performance |
— | A pump-down sequence is aborted or left incomplete before it finishes. As with a pump-down that never reaches setpoint, an aborted sequence risks liquid return and compressor damage and points to a controls or valve fault. | ||
| Pump-down repeats abnormally | managed | high | optimization_metric | Standard | hybrid | refrigeration_rack_pump_down_performance |
— | The pump-down sequence repeats more often than the commissioned observation window expects — a short-cycling pattern that stresses compressors and points to a leak-back, valve, or control fault rather than a single failed sequence. | ||
| High temperature excursion | essential | high | optimization_metric | Standard | hybrid | refrigeration_temperature_compliance |
— | A refrigeration asset holds above its configured upper band for longer than its configured persistence window — a product-risk excursion that must be validated, triaged, and, where safety may be affected, met with a product-check recommendation. | ||
| Low temperature excursion | essential | medium | optimization_metric | Standard | hybrid | refrigeration_temperature_compliance |
— | A refrigeration asset holds below its configured lower band for longer than its configured persistence window. The SOP distinguishes excessive cooling or control failure, freezing risk for refrigerated product, normal freezer behavior inside its own band, and invalid or drifting sensor readings. | ||
| Prolonged refrigeration door open | essential | medium | optimization_metric | Standard | hybrid | refrigeration_door_exposure |
— | A door-equipped refrigeration asset's door remains open longer than the configured ceiling for its asset type and operational context. The SOP validates the door sensor, checks the restocking window, correlates temperature, notifies the store, and escalates if the door stays open or temperature risk develops. | ||
| Slow temperature recovery | optimized | medium | optimization_metric | Standard | hybrid | refrigeration_temperature_recovery |
— | An asset's recovery time or recovery slope degrades materially against its approved baseline for repeated events after a recognized disturbance. A leading indicator worked with correlated evidence — not a definitive mechanical diagnosis — to prioritize intervention before degradation becomes product loss. | ||
| Failed temperature recovery | optimized | high | optimization_metric | Standard | hybrid | refrigeration_temperature_recovery |
— | An asset does not return to its configured band within the approved maximum recovery window after a recognized disturbance. Worked with correlated temperature, door, controller, runtime, and peer-asset evidence before recommending dispatch, and treated as a product-risk event when temperature is already out of band. |