Hashlogics

An unanswered alarm is worse than no alarm

Your ATG raised one last week too. So this time, someone cleared it without reading it, and that's exactly how a real release gets missed.

The short version

5 things that decide this

  1. 01Alarm fatigue is the real failure mode in tank monitoring, not a missing sensor. A system that alarms too often teaches the person watching it to clear alarms unread, and the one that matters gets cleared along with the noise.
  2. 02Release detection has to meet the numeric performance standards written into 40 CFR 280.43 and be certified as a method. Software cannot become the method by claiming to be one; it can only add triage on top of it.
  3. 03Triage means de-duplicating, prioritising and escalating what the certified method already reports, tuned to each site's own normal, never replacing the method itself.
  4. 04The record of who acknowledged an alarm, and when, matters as much as the alarm firing in the first place. An alert with no acknowledgement is indistinguishable from an alert nobody ever saw.
  5. 05We build this triage and record layer in TankAware, our platform for Sutherland Excavating Ltd., on top of whatever certified detection method a site already runs.
Picture the console

Your ATG says there's an alarm. It said that last week too

Picture the console at one of your sites. It's raised an alarm again. Not for the first time this month, and probably not for the first time this week. The operator glances at it, recognises the pattern, and clears it without reading the detail underneath. They're not being careless. They're doing exactly what the system has trained them to do.

That training happens quietly, over weeks, one cleared alarm at a time. Nobody decided to stop reading alarms. It just became the rational response to a system that cried wolf often enough that reading every alert stopped being worth the time it took.

Why this is the dangerous one

A missing sensor is visible. A trained-out operator isn't

Here's the part that makes this worse than having no monitoring at all. If a sensor fails and stops reporting, that's a visible gap. Somebody notices the silence, checks the equipment, and fixes it. An alarm that fires constantly doesn't create a gap you can see. It creates a habit, and the habit hides the one alarm that was actually telling you something.

That's the shape of the real risk in this vertical. Regulated release-detection thresholds are tight on purpose: 40 CFR 280.43 sets a performance bar of detecting a leak rate of 0.2 gallons per hour, or a release of 150 gallons within 30 days, with a probability of detection of 0.95 and a probability of false alarm of 0.05. Even a method meeting that bar produces false alarms sometimes, by design. What happens after the alarm fires is where the real safety margin lives, and it's the part almost nobody engineers deliberately.

From a raw alarm to a person who actsLive
  1. Certified method firesThe ATG's own detection, untouched
  2. De-duplicateOne event, not three retries on a flaky link
  3. Triage against the site's normalA tank in full sun differs from one in a shed
  4. EscalateReaches a person at the threshold you set
  5. AcknowledgeLogged: who, when, what they decided

The certified method and the decision to roll a truck both stay with a person. Triage is the middle three stations.

What triage actually changes

Fewer alerts, each one earned

Good triage doesn't mean fewer sensors watching your tanks. It means the alerts that do reach a person are alerts worth reading. That starts with per-site thresholds instead of one number shared across a fleet. A tank sitting in full sun behaves differently from one in a shed, and a single fleet-wide threshold guarantees noise somewhere in your estate.

It also means separating a drifting sensor from a genuine event, so they reach different people through different paths. A sensor trending slowly away from its own baseline over days is a maintenance conversation, not a 2am phone call. And it means de-duplicating retries. A message that arrives three times over a flaky cellular link because of retransmission should register as one alert, not three, or your operator learns to distrust the count along with everything else.

  • 01Per-site thresholds, tuned across a season, never a single number shared across the fleet.
  • 02Sensor drift separated from a genuine event, routed to different people through different paths.
  • 03De-duplication across retries, so a flaky link doesn't inflate the alert count and erode trust in it.
  • 04Escalation that reaches an actual person, at a threshold your team sets and can revisit.
The part nobody engineers on purpose

The record of who acknowledged what

An alarm that fires and gets seen is only half the job. The other half is proving it was seen. Who looked at it, when, and what they decided to do. Without that record, an acknowledged alarm and an ignored one look identical afterward, and that's exactly the gap an inspector or an auditor will ask about after any incident.

This is the same discipline that runs through the compliance side of this vertical generally. A record only has value if it proves what happened, rather than suggesting something might have. TankAware, our platform for Sutherland Excavating Ltd. in Canada, holds this log alongside the tank telemetry and the inspection record. An operator can show, not merely claim, that an alarm reached a person and that person acted.

Questions, answered
01Can triage software replace our certified release-detection method?+

No. Release detection has to meet the performance standards in 40 CFR 280.43 and be certified as a method. Triage sits on top of that certified method: de-duplication, prioritisation and escalation. It never becomes the method itself.

02Why is a noisy alarm worse than no alarm at all?+

Because a missing sensor creates a visible gap someone will notice and fix. A noisy alarm trains a person to stop reading it, quietly, over weeks, and that habit hides the one alarm that actually mattered along with all the noise.

03Should every site use the same alert thresholds?+

No. A tank in full sun behaves differently from one in a shed, and one fleet-wide threshold guarantees noise somewhere in your estate. Thresholds should be set per site, against that site's own baseline, and tuned across a season.

04What does 'acknowledged' actually need to record?+

Who saw the alert, when, and what they decided to do about it, held in a log that can't be edited after the fact. An alert with no acknowledgement record is indistinguishable from an alert nobody ever saw.

By Abdul Basit, CEO, HashlogicsUpdated
Start

Let’s deploy working AI into your business.

We build AI agents and automation, ship them into the tools you already run, then stay on under an agreed service level. A senior engineer reads every brief, and your call gets scheduled within 24 hours.

What happens next

  1. 01

    You send a brief or book a call

    Two minutes, whichever you prefer.

  2. 02

    A senior engineer replies within 24 hours

    Not a sales rep.

  3. 03

    Honest scoping, in writing

    And if we’re not the right fit, we say so.

Abdul Basit, CEO of Hashlogics

“I started Hashlogics because too many teams ship a demo, get paid, and disappear. We build to a standard we’d run ourselves — and we stay to keep it running.”

Abdul Basit · CEO · a direct line

Not ready to talk? Take the checklist.

12 questions to ask any AI agency before you sign. They separate a demo shop from a team that ships to production.

Get the checklist

Free · no newsletter