Hashlogics
Answers

What should a tank monitoring system alert on?

Fewer things than most systems send, and each one weighed against that site's own normal, not a number shared across the fleet.

Answered in short

5 things that decide this

  1. 01A tank monitoring system should alert on run-out risk, a delivery that does not match its BOL, a sensor that has drifted rather than failed, a lapsed inspection duty, and a de-duplicated alarm from your certified release-detection method.
  2. 02It should never claim to be the release-detection method itself. 40 CFR 280.43 sets numeric performance standards for a certified method, and software layered on top has to triage, de-duplicate and escalate what that method reports, not replace it.
  3. 03Alarm fatigue is the real failure mode: an alarm that fires every week trains an operator to clear it unread, which is exactly how a real release gets missed.
  4. 04Every alert needs an owner and an acknowledgement, logged with who saw it and when, or the alert is noise with an audit trail attached.
  5. 05We build this triage layer on top of the ATG or telemetry vendor you already run. What each console exposes, and how much of this it can already do on its own, is something we confirm during the audit rather than assume from the datasheet.
Why the obvious answer is wrong

More alerts is not more safety

The instinct is to alert on everything a sensor can measure, because more visibility sounds like more safety. In practice it is the opposite. An ATG that raises the same alarm every week teaches the person watching it to clear alarms without reading them, and that habit is exactly how a genuine release gets missed among the noise.

The fix is not fewer sensors. It is triage: separating a real event from a drifting sensor, a routine reading from a threshold breach, and one alarm from its own duplicate arriving twice on a flaky link. That triage sits on top of the certified detection method your site already runs. It never replaces it.

What earns an alert

Five things worth interrupting someone for

Each of these fails a different way if it goes unwatched, and each one is a real operational cost, not a hypothetical.

  • 01Run-out risk: a level and consumption forecast crossing a threshold that gives dispatch time to schedule a delivery before the tank empties.
  • 02A delivery that does not match its bill of lading: the volume the driver logged against the level change the tank actually shows.
  • 03Sensor drift: a reading trending away from a site's own baseline over days, which is different from a sensor that has simply failed and stopped reporting.
  • 04A lapsed inspection duty: the 30-day walkthrough or the release-detection equipment test that is coming due or already missed.
  • 05A de-duplicated, prioritised alarm from your certified release-detection method, escalated to a person and logged with who acknowledged it.
From a raw reading to a person who actsLive
  1. Certified method firesThe ATG's own detection, untouched
  2. De-duplicateOne event, not three retries on a flaky link
  3. TriageWeighed against that site's own normal
  4. EscalateReaches a person at the threshold you set
  5. AcknowledgeLogged: who, when, what they did

The certified method and the decision to roll a truck both stay with a person. We add the middle three stations.

Questions, answered
01Can a tank monitoring system replace our certified release-detection method?+

No. Release detection has to meet the performance standards in 40 CFR 280.43 and be certified as a method. A monitoring system can triage, de-duplicate and escalate what that method reports, and log who acknowledged it, but it is never the method itself.

02Why does alarm fatigue matter more than missing a sensor?+

Because a sensor that fails stops reporting, which is visible as a gap. An alarm that fires too often trains a person to stop reading it, so the one alarm that matters gets cleared along with the noise. That is the harder failure to catch.

03Should every site share the same alert thresholds?+

No. A tank in full sun behaves differently from one in a shed, and a single fleet-wide number guarantees noise somewhere. Thresholds should be set per site against that site's own baseline and tuned across a season.

04What does 'acknowledged' actually need to record?+

Who saw the alert, when, and what they decided to do about it, held in a log that cannot be edited after the fact. An alert with no acknowledgement record is indistinguishable from an alert nobody ever saw.

05Does this apply to aboveground tanks, or only underground ones?+

The triage principle applies to any tank with a certified detection method behind it. 40 CFR 280 governs underground storage tanks specifically. Aboveground tanks are more often covered by SPCC and API inspection standards instead, which is a separate compliance question we confirm during the audit.

By Abdul Basit, CEO, HashlogicsUpdated
Start

Let’s deploy working AI into your business.

We build AI agents and automation, ship them into the tools you already run, then stay on under an agreed service level. A senior engineer reads every brief, and your call gets scheduled within 24 hours.

What happens next

  1. 01

    You send a brief or book a call

    Two minutes, whichever you prefer.

  2. 02

    A senior engineer replies within 24 hours

    Not a sales rep.

  3. 03

    Honest scoping, in writing

    And if we’re not the right fit, we say so.

Abdul Basit, CEO of Hashlogics

“I started Hashlogics because too many teams ship a demo, get paid, and disappear. We build to a standard we’d run ourselves — and we stay to keep it running.”

Abdul Basit · CEO · a direct line

Not ready to talk? Take the checklist.

12 questions to ask any AI agency before you sign. They separate a demo shop from a team that ships to production.

Get the checklist

Free · no newsletter