What should a tank monitoring system alert on?
Fewer things than most systems send, and each one weighed against that site's own normal, not a number shared across the fleet.
Answered in short
5 things that decide this
- 01A tank monitoring system should alert on run-out risk, a delivery that does not match its BOL, a sensor that has drifted rather than failed, a lapsed inspection duty, and a de-duplicated alarm from your certified release-detection method.
- 02It should never claim to be the release-detection method itself. 40 CFR 280.43 sets numeric performance standards for a certified method, and software layered on top has to triage, de-duplicate and escalate what that method reports, not replace it.
- 03Alarm fatigue is the real failure mode: an alarm that fires every week trains an operator to clear it unread, which is exactly how a real release gets missed.
- 04Every alert needs an owner and an acknowledgement, logged with who saw it and when, or the alert is noise with an audit trail attached.
- 05We build this triage layer on top of the ATG or telemetry vendor you already run. What each console exposes, and how much of this it can already do on its own, is something we confirm during the audit rather than assume from the datasheet.
More alerts is not more safety
The instinct is to alert on everything a sensor can measure, because more visibility sounds like more safety. In practice it is the opposite. An ATG that raises the same alarm every week teaches the person watching it to clear alarms without reading them, and that habit is exactly how a genuine release gets missed among the noise.
The fix is not fewer sensors. It is triage: separating a real event from a drifting sensor, a routine reading from a threshold breach, and one alarm from its own duplicate arriving twice on a flaky link. That triage sits on top of the certified detection method your site already runs. It never replaces it.
Five things worth interrupting someone for
Each of these fails a different way if it goes unwatched, and each one is a real operational cost, not a hypothetical.
- 01Run-out risk: a level and consumption forecast crossing a threshold that gives dispatch time to schedule a delivery before the tank empties.
- 02A delivery that does not match its bill of lading: the volume the driver logged against the level change the tank actually shows.
- 03Sensor drift: a reading trending away from a site's own baseline over days, which is different from a sensor that has simply failed and stopped reporting.
- 04A lapsed inspection duty: the 30-day walkthrough or the release-detection equipment test that is coming due or already missed.
- 05A de-duplicated, prioritised alarm from your certified release-detection method, escalated to a person and logged with who acknowledged it.
- Certified method firesThe ATG's own detection, untouched
- De-duplicateOne event, not three retries on a flaky link
- TriageWeighed against that site's own normal
- EscalateReaches a person at the threshold you set
- AcknowledgeLogged: who, when, what they did
The certified method and the decision to roll a truck both stay with a person. We add the middle three stations.
Some of the systems we have shipped
Related questions
01Can a tank monitoring system replace our certified release-detection method?+
No. Release detection has to meet the performance standards in 40 CFR 280.43 and be certified as a method. A monitoring system can triage, de-duplicate and escalate what that method reports, and log who acknowledged it, but it is never the method itself.
02Why does alarm fatigue matter more than missing a sensor?+
Because a sensor that fails stops reporting, which is visible as a gap. An alarm that fires too often trains a person to stop reading it, so the one alarm that matters gets cleared along with the noise. That is the harder failure to catch.
03Should every site share the same alert thresholds?+
No. A tank in full sun behaves differently from one in a shed, and a single fleet-wide number guarantees noise somewhere. Thresholds should be set per site against that site's own baseline and tuned across a season.
04What does 'acknowledged' actually need to record?+
Who saw the alert, when, and what they decided to do about it, held in a log that cannot be edited after the fact. An alert with no acknowledgement record is indistinguishable from an alert nobody ever saw.
05Does this apply to aboveground tanks, or only underground ones?+
The triage principle applies to any tank with a certified detection method behind it. 40 CFR 280 governs underground storage tanks specifically. Aboveground tanks are more often covered by SPCC and API inspection standards instead, which is a separate compliance question we confirm during the audit.
Related
- Site monitoring for fuel and oilfield →The full build: telemetry, alarm triage and the inspection engine.
- How to prove a fuel site inspection happened →The other half of the compliance record.
- Packaged tank monitoring vs a custom site platform →When the vendor portal is enough, and when it isn't.
- An unanswered alarm is worse than no alarm →Why alarm fatigue is the more expensive failure mode.
- Oil and gas →The hub: all eight areas, and which page owns each one.

