Skip to content
Menu

Operations

How ME intends to run things that must not stop.

Philosophy, not a schedule. ME operates nothing around the clock today. This page holds no staffing data, no rota, no incident record and no live system state, and it never will.

Running continuously

Round the clock, eventually

Critical functions are meant to be staffed continuously once they exist. Systems that matter do not stop mattering at six in the evening.

Eight hour shifts with overlap

Eight hours by default, with a deliberate overlap at each boundary so a handoff is a conversation rather than a note left behind.

A named incident commander

One person holds command of an incident at a time. Everyone can name who that is.

On call specialists

Depth is on call rather than on shift. A specialist is reached when their specialism is needed.

Independent safety and red teams

The people checking a system do not report to the people running it. A safety function that can be overruled by delivery pressure is decoration.

Human override that does not depend on the agent

Override paths work with Carl unavailable, wrong, or suspected compromised.

Fatigue rules and two person rules

Hours are bounded, and critical actions need two people. Tiredness and single points of judgement cause the same kind of accident.

Drills and post incident reviews

Emergencies are practised on ordinary days, and every significant incident is reviewed afterwards.

Breaks

Breaks are paid, scheduled and mandatory.

  • Two paid fifteen minute breaks and one paid thirty minute meal break in a typical eight hour critical shift
  • Mandatory, not offered. A break nobody takes is a policy nobody has
  • Carl proposes staggered break schedules so coverage never drops, and a human shift supervisor can change them
  • Coverage is handed off before anyone steps away from a critical post

Why

Tired people miss things. Treating rest as optional is how an organisation converts goodwill into incidents.

Incident handling

A short, boring process, followed every time.

  1. 01

    Written handoff

    Shift changes carry a structured written handoff, covering active incidents, unfinished tasks, unusual behaviour, decisions, risks and follow up owners.

  2. 02

    Overlap, extended when needed

    Fifteen to thirty minutes of overlap by default, longer when the situation warrants it. The clock does not decide when a handoff is finished.

  3. 03

    Joint command during transitions

    An active incident is held jointly across a shift change, and the incoming lead explicitly accepts command. Command is transferred, never assumed.

  4. 04

    Closing needs agreement

    An incident closes when the incident commander and the relevant technical lead both agree it is closed.

  5. 05

    Review, then tracked follow up

    Significant incidents get a post incident review, and its follow up actions become tracked tasks rather than good intentions.

  6. 06

    Overdue safety work escalates

    Safety and security follow ups that go overdue escalate automatically. Nothing important should depend on someone remembering.

What a written handoff contains

A handoff is a document, not a conversation someone remembers. The incoming shift should be able to read it and know what they have inherited.

  • Active incidents, and who currently holds command of each
  • Unfinished tasks, with where they were left
  • Unusual system behaviour, including things that looked odd and were not chased
  • Decisions made during the shift, and why
  • Risks and watch items for the next shift
  • Follow up owners, by name, for anything that outlives the shift

Cameras and machine safety

Design intent. No camera system is installed, and nothing is watching anything.

  • Broad camera coverage in operationally relevant areas: production floors, labs, plant, loading, and other places where machines and people share space
  • No cameras in private spaces. Bathrooms and changing areas are not covered, and no exception makes them covered
  • The primary purpose is safety, not surveillance of people's work
  • Carl may eventually stop an affected machine or cell when it detects a clear hazard, because a machine that keeps running through a hazard is the problem
  • Restarting takes two things: Carl verifying the hazard is gone, and a person authorising the restart. Neither alone is enough

Alerts go to the people who can act

Design notes only. No alert system has been built.

  • Not everyone by default. Broadcasting to all is a deliberate choice for specific incidents, never the normal path
  • Every alert says why this person was alerted and what action is expected
  • Three answers: accept, need backup, unable
  • Escalation is a chain, not a retry: primary, backup, shift lead, incident commander
  • Public and shared displays show safe public instructions only, never incident detail
  • Each site can raise, route and resolve a local alert with central systems unreachable
  • The long term local controller has an offline manual panel that does not depend on Carl