IT & Security

New product program

Enterprise RMS / SCADA Analytics

A multi-tenant remote monitoring platform for electrical cabinets, power plants, telecom energy sites, and other industrial realities.

Loading tracker...
Program evidence 22%
Across all fourteen workstreams
Current gateGate AField truth and enterprise trust
Workstreams140 blocked
References reviewed5621 FireShot + 31 screenshots + 4 field images
Live field sites0Demo and simulator only
Control postureSandboxZero field command paths
Safety boundary

The deployed console is an admin-gated demo and simulator, not a live SCADA/EMS deployment. It does not issue commands to PLCs, relays, breakers, generators, batteries, or other field equipment. The Simulation-only Control Sandbox now exercises bounded commands, interlocks, select-before-operate, independent approval and feedback verification; field control remains locked behind formal hazard analysis, hardware-in-the-loop tests, FAT/SAT, production identity/audit controls, and independent OT cybersecurity approval.

Live tracker

Delivery workstreams

Owners, targets, status, and completion are saved centrally for authorized IT administrators.

Release gates

Phased roadmap

  1. A
    Field truth + trustOne read-only pilot, historian, SSO/MFA/RBAC, immutable audit and versioned API.
  2. B
    OperationsAlarm-to-work, preventive maintenance, offline evidence and CMMS integration.
  3. C
    CommercialContracts, meters, availability, loss attribution and settlement evidence.
  4. D
    PredictionAsset models, data confidence, RUL, warranty and automated findings.
  5. E
    OptimisationForecasts and least-cost dispatch in shadow mode with constraints and backtests.
  6. F
    Controlled operationHIL validation, safety approval and only then a limited command pilot.
Karim review · 18 August 2026Procurement-gap delivery plan6 gaps · none closed
Capability truth

The previously shown delivery percentage mainly represented interface and simulation work. It must not be interpreted as operational readiness. Prime RMS has zero live field sites and zero field command paths today.

WorkstreamCurrent truthNext deliverableEvidence to exit
01 · Supervisory controlP0 safety architectureSimulation-only command lifecycle, interlocks, independent approval and feedback verification implemented; no field adapter.HIL fault/timeout/rollback cases, production authority matrix and immutable server audit; then scheduled dispatch.Hardware-in-the-loop FAT/SAT and independent safety approval before any field write path.
02 · OptimisationP1 decision engineSeven-day condition risk, not forecasting or dispatch optimisation.Load/solar/price/fuel forecasts, tariff engine, least-cost dispatch and what-if scenarios in shadow mode.Reproducible backtests that respect reserve, warranty, emissions and reliability constraints.
03 · Commercial analyticsP1 buyer requirementAvailability and avoided cost are illustrative; no contract settlement.Contract, SLA/LD, outage-cause, revenue-meter, lost-production and O&M cost models.Auditable monthly statement reconciled to revenue-grade meter evidence.
04 · Asset intelligenceP2 predictive modelsHealth scores and thresholds are descriptive prototypes.Battery RUL/warranty, transformer condition, genset drift/fuel anomaly and PV soiling models with confidence.Historical backtests, false-positive limits, model cards and engineer sign-off.
05 · O&M executionP1 field workflowRepresentative Kanban; no maintenance engine, inventory or offline field evidence.Alarm-to-work lifecycle, PM calendars, crew/skills, checklists/photos, spares and CMMS connectors.One work order completes offline-to-online with auditable evidence and inventory/CMMS reconciliation.
06 · Enterprise trustP0 procurement blockerTarget controls are documented but not proven in the RMS product.SSO/MFA/RBAC/SoD, immutable audit, retention/residency, HA/DR, security evidence, REST/streaming API and webhooks.Published tenant, permission, audit, recovery, failover and API contract test evidence.
Current systemReference UI and capability audit56 references reviewed

The 52 screens reviewed in the private FireShot folder, together with 4 supporting field images, were treated as a product inventory. References are not copied into production. The source product combines fleet operations with deep single-site energy telemetry, but it also shows duplicated old/new navigation, dense screens, inconsistent hierarchy, and many empty states that do not explain data quality or remediation.

Fleet and network

Search, map, online/offline state, location/weather/time, network availability, grid outages, fuel, solar, performance analysis, network pulse, insights, anomaly detection, predictive views, and AI assistance.

Single-site operations

Snapshot, configurations, parameters, BMS, ESON, impact meter, planning, prediction, site pulse, site onboarding, integration status, activity logs, and a 3D site view.

Assets and energy

Transformer, generator, battery, rectifier, solar, infrastructure health, sizing, age, brand, rating, technology, duty cycle, energy mix, utilization, power flow, and data quality.

Work and reporting

Active/historical alarms, task table and Kanban, report templates, custom reports, exports, performance comparisons, impact savings, emissions, and tabular drill-down.

RetainReworkAdd
Hierarchy filters and map-to-site drill-downOne shared navigation and design systemAlarm consequence, cause, action, ownership, and SLA
Asset-specific diagnostics and report exportProgressive disclosure for dense telemetrySource provenance, quality, freshness, and lineage
Active/history alarms and operational tasksActionable empty, offline, and unavailable statesTenant, country, language, currency, zone, and unit configuration
Energy, fuel, solar, BMS, and impact analyticsConsistent terminology, units, accessibility, and mobile layoutsEnterprise security, audit, retention, and integration governance
Target platformArchitecture and information modelEdge to enterprise
FieldMeters · IEDs · relays · PLCs · BMS
→
EdgeRedundant gateways · buffering · normalization
→
OT DMZBrokers · allow-listed transfer · certificates
→
PlatformIngestion · historian · alarms · analytics
→
ExperienceWeb · mobile · API · notifications

Protocol and ingestion strategy

  • OPC UA as the preferred normalized northbound interface.
  • IEC 61850, Modbus TCP/RTU, IEC 60870-5-104, DNP3, SNMP, and vendor drivers at the edge.
  • MQTT Sparkplug B for stateful telemetry distribution; Kafka or Redpanda for durable event streaming.
  • Store source timestamp, receive timestamp, quality, source identity, engineering unit, and sequence for every value.
  • Local store-and-forward preserves telemetry through WAN outages and reconciles without duplicates.

Canonical asset hierarchy

Organization › Tenant › Plant › Unit › Switchboard › Cabinet › Feeder › Device › Tag

  • Stable IDs are independent of display names and source tag names.
  • Templates describe equipment classes, expected tags, alarm limits, documents, and maintenance plans.
  • Relationships support electrical topology, redundancy, parent/child assets, and upstream/downstream impact.
  • Every mapped tag retains source-system lineage and transformation history.

Operational views

Fleet overview, geographic map, single-line diagram, cabinet and feeder detail, generator, transformer, UPS/battery, solar, power quality, live trends, and data-quality console.

Analytics

Load profile, demand peaks, energy balance, losses, fuel efficiency, availability, MTBF/MTTR, alarm analytics, anomaly detection, forecasting, and predictive maintenance.

Platform services

Time-series historian, relational configuration store, object storage, rules, reporting, work orders, notification orchestration, APIs, identity, audit, and observability.

Suggested stack

Go/Rust/.NET edge services; MQTT/Sparkplug B; Kafka/Redpanda; TimescaleDB or ClickHouse; PostgreSQL; Redis; .NET/Java/Go services; React/TypeScript with ECharts; Flutter mobile.

OperationsAlarm lifecycle and notificationsISA-18.2 / IEC 62682
Active unacknowledged→Acknowledged→Return to normal→Closed

Alarm quality

  • Priorities based on consequence and response time, not color preference.
  • Cause, consequence, corrective action, owner, deadband, delay, suppression, shelving, and out-of-service state.
  • Deduplication, chattering detection, standing alarm review, flood detection, and maintenance windows.
  • Immutable acknowledgement, comment, assignment, escalation, and state-change audit.

Notification orchestration

  • In-app, mobile push, email, and optional SMS/voice with tenant-specific routing.
  • Schedules, on-call rotations, receipt tracking, acknowledgement timers, and escalation chains.
  • Grouping prevents notification storms while deep links open the exact plant, asset, and alarm context.
  • Delivery health is monitored independently from the alarm engine.
Commercial requirementMulti-country product foundationConfigured, never hard-coded

Currency

ISO 4217 codes; transaction, base, and reporting currencies; rate source/type/effective date; currency-specific precision; locked historical rates; full conversion audit.

Language and locale

Key-based ICU messages, locale fallbacks, plural rules, RTL, localized date/number/unit formats, and translatable asset, alarm, procedure, and report content.

Time zones and shifts

IANA time-zone IDs; timestamps stored in UTC; source/site/user display zones; explicit DST handling; local operating day, holidays, and shift calendars.

Input sources

SCADA protocols, MQTT, REST, webhooks, files, manual entry, IoT, CMMS/ERP, and legacy historians with mapping, validation, deduplication, quality, and provenance.

Units and grid realities

SI and imperial display, configurable 50/60 Hz, voltage levels, phase conventions, fuel and emissions factors, tariff calendars, and country/site electrical standards.

Tenancy and sovereignty

Tenant-scoped identity, assets, rules, branding, retention, encryption keys, and integrations; per-country data residency with cloud, on-prem, and hybrid deployment options.

Minimum normalized observation

{ tenantId, siteId, assetId, tagId, value, unit, sourceTimestamp, receivedAt, quality, sourceId, sequence, attributes }
Enterprise controlsSecurity, acceptance, and governanceIEC 62443 aligned

Security architecture

  • Zones and conduits, industrial DMZ, least privilege, and outbound-only transfer where practical.
  • Mutual TLS, device certificates, rotation, secure boot, signed gateway releases, and encrypted secrets.
  • SSO through OIDC/SAML, MFA, tenant/site/asset RBAC, break-glass controls, and immutable audit.
  • Threat model and controls aligned with IEC 62443 and NIST SP 800-82; country obligations mapped per deployment.

Pilot acceptance gates

  • Approved tag list, units, scaling, quality rules, owners, and alarm rationalization.
  • Measured data completeness, timestamp accuracy, loss/duplicate rate, and WAN recovery.
  • Alarm delivery, acknowledgement, escalation, audit, backup, restore, and disaster-recovery tests.
  • Desktop/mobile usability, accessibility, language/RTL, zone/DST, currency, and tenant-isolation tests.
  • Runbooks, training, support SLA, observability, vulnerability management, and rollback approval.

Initial risk register

HighUnsafe coupling to control systems

Keep phase 1 read-only; isolate OT; require an independent control safety case.

HighUnreliable or semantically inconsistent tags

Enforce canonical mapping, quality, units, lineage, and site acceptance checks.

MediumAlarm overload

Rationalize before enablement; use deadbands, delays, suppression, grouping, and flood metrics.

MediumCountry-specific assumptions

Make tenant, locale, currency, zone, units, frequency, tariffs, and integrations configuration data.

Audit trail

Recent program updates

No progress updates have been published yet.