Site monitoring for fuel and oilfield operators: the tank level without the drive, the alarm triaged, the inspection you can prove
You keep your ATGs, your fuel ERP and your certified detection method. We build the layer around them: level telemetry where a site has power and signal, offline capture on a phone where it doesn't, alarm triage that de-duplicates and escalates instead of adding to the noise, and an inspection record that's timestamped, photo-backed and immutable.
What changes at your sites
3 things that decide this
- 01You stop driving out to read a number. Level telemetry runs where the site has power and a path for the data, offline capture covers the sites that don't, and the run-out forecast is regression on usage and weather, which is what we call it rather than dressing it up as AI.
- 02Alarms get triaged before they reach anyone. We de-duplicate, prioritise and escalate on top of your certified detection method, and we log who acknowledged what, so the alarm that says that every week stops training your operators to clear the one that matters.
- 03The record becomes something you can hand over. Inspections are scheduled per asset and per site, captured with photos and the time the work happened, held immutable with a gap shown as a gap, and every deficiency becomes a work order a contractor closes with evidence.
From a tank reading to a closed deficiency, and where the machine takes over
Three stations of a site operator's month. Pick the system you'd want written to; your fuel ERP, P2, WellView and the rest follow the same pattern to the depth their access model allows.
Station 01 · The tank level nobody knows
- Today
- Someone drives out and sticks your tank. A run-out stops your customer's farm, fleet or generator, and the emergency delivery breaks your day's route.
- What we automate
- Level telemetry where the site has power and signal, offline capture on a phone where it doesn't, a consumption forecast on usage and weather, run-out alerts, and a delivery trigger written into your dispatch.
- What stays human
- Your dispatcher decides what to do with the trigger. A forecast is a forecast, and it tells you so.
Writes to Enverus OpenInvoiceNot an OpenInvoice station.
Station 02 · The alarm that says that every week
- Today
- Your ATG raises an alarm. It raised one last week too. Your operators clear it without reading it, which is exactly how a real release gets missed.
- What we automate
- Alarm triage, de-duplication and prioritisation on top of your certified detection method, escalation that rings a person at the threshold you set, and a log of who acknowledged what and when.
- What stays human
- Release detection stays with your certified method; we never claim to be it. Your people decide whether to roll a truck.
Writes to Enverus OpenInvoiceNothing.
Station 03 · The 30-day inspection record
- Today
- Your walkthrough happens, mostly, and your record is a binder with gaps. When an inspector asks you for twelve months, the gaps are the violation.
- What we automate
- Inspections scheduled per asset and per site, dynamic checklists on a phone, photos and timestamps, an immutable record with a gap shown as a gap, deficiencies escalated to a work order, and audit and compliance reports exported on demand.
- What stays human
- Your inspector still walks the site and signs. We make the record survive, searchable and honest.
Writes to Enverus OpenInvoiceNothing.
The certified detection method and the inspector's signature stay with a person at every station. We add the triage and the record.
Four things we build into a site monitoring platform
Four pieces, in the order a site meets them. Each one is running in TankAware today.
Telemetry, offline capture and a forecast that admits what it is
A level sensor plus a forecast replaces the truck you send to read a number. We keep raw readings apart from derived values so a recalibration reinterprets your history instead of rewriting it, we store the tank chart with the tank and version it, and we compare every predicted level against what the truck actually dropped. Where a site has no signal, your people capture on a phone and it syncs later with the original time intact.
Alarm triage on top of your certified detection method
Thresholds belong to the site, not the fleet: a tank in full sun moves differently from one in a shed, and one global number guarantees noise somewhere. We model each site's normal first, separate a drifting sensor from a real event so they reach different people, escalate to someone who can act, and track how often each alert type gets acted on so we can retire the ones nobody answers.
The inspection engine, and proving the negative
Most systems show you that a check happened. Very few show you that one didn't, and that's the question an auditor actually asks. So we model the duty itself, recurring per asset and per site, and it raises its own hand when it lapses. Each area checked gets its own result rather than one verdict for a whole site, the checklist freezes as it stood that day, and an amendment is a new version rather than an overwrite.
Deficiency to work order to contractor close-out
You find a deficiency, you call a contractor, and three weeks later nobody knows if it's fixed. The lifecycle crosses a company boundary, so we give contractors their own access, an assigned work order with a due date, evidence of completion, and integrated payments where you want them. TankAware runs exactly this loop.
Buy the packaged monitor first. Here's the point where operators outgrow it.
ATG vendors' portals and packaged tank monitors do one job well: levels and alarms, per site, from their own hardware. If you run a handful of tanks from one vendor and you need a level and a text message, buy one of those and don't call us. We'll tell you the same thing on the audit call.
What we hear from operators who've outgrown them is narrower than "we need a platform". It's three things. Triage has to work across sites and across vendors, because an estate of any age carries several console generations and each one publishes its data differently. The inspection record has to sit in the same system as the alarm, or your compliance evidence lives in a binder while your telemetry lives in a portal. And every party has to see only theirs, because your contractor gets access to his sites and to nobody else's, which is a breach question rather than a bug.
That's the layer we build. Your gauges stay your gauges, your certified method stays your certified method, and what we add is the part that spans them.
- 01One tank vendor, one site, a level and a text: buy the packaged monitor.
- 02Several console generations, several sites, and an inspection record that has to survive an audit: that's a build.
- 03Contractors and clients in the same system as your own staff: multi-tenant separation, not a shared login.
Software on top of a certified detection method, never instead of it. We write that down first.
Fuel and oilfield operations sit under rules that don't bend for software: release detection has to meet the performance standards in 40 CFR 280 and be certified as a method, the 30-day walkthrough record is the compliance artefact whether or not the inspection happened, and a field ticket is a billing document an operator will audit. So every build starts with a one-page map of what the software records, what it only proposes, and where a person signs.
What follows is simple to state, and we put it in writing. We triage, de-duplicate and escalate alarms from your certified method; we never claim to be the method. Every inspection record is timestamped, photo-backed and immutable, and a gap stays visible as a gap. Tickets and invoices are approved by a person before they go to an operator's portal. And every automated touch is logged so an inspector or an auditor can read what happened, and when.
- 01Release detection stays with the certified method; we add triage, escalation and the record.
- 02Inspection records immutable and gap-honest; tickets and invoices approved by a person.
- 03Thresholds are set per site and tuned across a season, not shipped as one global number.
“They will treat your vision like their own and build it that way.”
Ron Klabunde · Founder, SmartREI ↗
“TankAware has revolutionized how we manage petroleum sites. The real-time data and automation have exceeded expectations.”
Blake Sutherland · President, Sutherland Excavating Ltd.
Some of the systems we have shipped
- AuditFree. We read a month of your alarms and what happened to each one, look at how inspections are recorded across your sites today, and count the trips your people make just to read a level.
- DiagnoseWe map the path into your ERP, ATG feeds and operator portals, and ride along on a site round or a ticket's journey.
- BuildFixed price from the diagnostic. Tested on your real sites, real tickets and real alarms, offline-first, under NDA.
- RunMonitoring, a named engineer, and the first two months of maintenance free.
Best fit: ten or more sites or trucks, or an oilfield services company with a ticket-to-cash problem, and systems you've outgrown in places. Not a fit yet: a single-site operator who needs a sensor and a text, and we'll say so. You can stop after any stage; the audit note is yours either way.
Before you book
01Can this be our release detection method?+
No. Release detection has to meet the performance standards in 40 CFR 280 and be certified as a method, and anyone who tells you their software is one should show you the certification. Your certified method stays the method. What we add on top is triage, de-duplication, escalation that reaches a person and a record of who acknowledged what, which is the part that stops alarm fatigue hiding a real release.
02What should a tank monitoring system actually alert on?+
Fewer things than most of them do, and each one against that site's normal rather than a fleet-wide number. Level and run-out risk, a delivery that doesn't match the BOL, a sensor whose readings have drifted rather than failed, a lapsed inspection duty, and an alarm from your certified method that survived de-duplication. We track which alert types get acted on and retire the ones that never do.
03Do sensors at our sites need special ratings?+
Inside a hazardous area, yes, and this is the constraint that quietly kills naive projects. Areas around fill points, vents and dispensers may hold flammable vapour, and equipment installed there has to be rated for it. A standard commercial gateway or tablet in one of those areas is a code violation and an ignition risk. We treat area classification as an input before any device is chosen, with your electrical engineer and the authority having jurisdiction involved.
04Half our sites have no signal. What happens there?+
Your capture still works. Inspections, deficiencies and BOLs are captured offline on a phone and sync when the device sees a network, which is how TankAware runs. Level telemetry needs power and a path for the data, so at a site with neither we're honest that you're buying a better inspection record rather than a live level. Readings that do arrive buffer at the edge and reconcile on reconnect, so your history has no hole exactly where the interesting event happened.
05How do you keep offline inspections from looking falsified?+
By recording the time of capture and the time of sync as two separate fields. A check made at nine in the morning and uploaded at five is honest work; keep only the upload time and it reads as a suspect evening entry. Every offline record in an estate has this problem at once, so it's a data-model decision on day one rather than a fix later.
06What does the 30-day walkthrough record have to contain?+
Per 40 CFR 280.36(b), the record lists each area checked, whether each area was acceptable or needed action, and a description of the action taken to correct an issue, and it's retained for one year. Most states run their own EPA-approved programme and are often stricter than the federal floor, so your implementing agency has the final word. We keep intervals and retention in configuration so a second jurisdiction is a settings change.
07Will this connect to our gauge consoles and back office?+
To the depth each exposes, and we confirm that during the audit rather than promising it on a call. ATG vendors publish their own feeds and Veeder-Root, Franklin Fueling and OPW each expose data differently; Quorum, P2 and WellView go to different depths; some fuel ERPs only export. Expect device variance across an estate of any age rather than one integration, and your back office stays the system of record and wins any conflict.
A senior engineer, not a sales rep
Abdul Basit founded Hashlogics in 2017, and the team runs from Lahore with a US LLC. Clients rate the work 5.0 on Clutch, and in 2026 it was named Best AI-Native Software House of the Year at TechNova. TankAware, the AI and IoT petroleum site platform we built for Sutherland Excavating Ltd. in Canada, is live and we can show it to you.
Your audit call is with an engineer who has read inspection logs, ATG alarm histories and field tickets like yours. Bring last month's numbers if you have them, and we'll work from those.
- NDA before the first conversation.
- No pitch on the call. A note you could hand to another firm.
- Fixed price after the diagnostic, so the number isn't a guess.

Go deeper
- Oil and gas →The hub: all eight areas, and which page owns each one.
- Field operations for oilfield services →Field tickets, approvals, dispatch and ticket-to-cash.
- Custom software for oil and gas →Vendor portals, multi-tenant separation and the numbers across sites.
- Fuel distribution software →Run-outs, routes, BOLs and wetstock variance for distributors and bulk plants.
- What should a tank monitoring system alert on? →Triage on top of the certified method, not instead of it.
- How to prove a fuel site inspection happened →What 40 CFR 280.36 asks for, and what the record has to survive.
- Packaged tank monitoring vs a custom site platform →When to buy the monitor, and when the layer across them is the job.
- TankAware case study →The petroleum site platform, in detail.

