Skip to content
Basin Thread

Platform

Grant control without granting a blank cheque.

Seeing a well and commanding it are separate grants. Authority is scoped per device group, every command takes an explicit confirmation, and each one lands in an audit log that cannot be edited afterwards.

Audit entry09:14:01
device
JR14.PMP.SETPOINT
action
setpoint write
prior
38.0 SPM
commanded
42.5 SPM
device ack
accepted 09:14:02
by
J. Reyes · control grant on Juniper Ridge 14

Entries are append-only. Nothing here can be edited or removed after the fact.

Illustrative. Identifiers and volumes are synthetic.

What you can command

Supervisory actions against authorized field devices, from the same interface that shows you their state.

  • Setpoint writes.
  • Equipment start and stop.
  • Remote shutdown.

Authority is scoped, not global

Control is granted per device group. A user who can see a well cannot necessarily command it, and the two permissions are administered separately.

  • Visibility and control authority are distinct grants.
  • Control is bounded by company and asset grant, the same as visibility.
  • An operator can give a contractor visibility across a field and command rights on nothing.

Every command is confirmed

No command is a single click. Each one requires an explicit confirmation that states what is about to change.

  • The prior value and the commanded value are both shown before you commit.
  • The device acknowledgment is recorded, so a command that was sent but not accepted is visible as such.

The audit trail

Every control action is written to an append-only log capturing the full context of the command.

  • Who sent it, and under which grant.
  • What was commanded, on which device, and when.
  • Where it was sent from.
  • The prior value, the commanded value, and the device acknowledgment.
  • Entries cannot be edited or removed after the fact.

Why the audit trail is the product, not the paperwork

Operators are rightly cautious about remote control. The risk is not usually that the software will do something unexpected; it is that a person will, and that afterwards nobody will be able to establish exactly what happened.

An audit trail that captures the prior value, the commanded value and the device’s own acknowledgment turns that from a reconstruction exercise into a lookup. It also changes the conversation about granting control in the first place, because the question stops being do we trust everyone with this and becomes who has authority on which equipment, and can we see what they did.

Both of those are answerable here.

Common questions

Can we roll out control to some sites and not others?

Yes. Authority is granted per device group, so control can be enabled on a subset of assets while the rest stay read-only, without changing what anyone can see.

What is recorded when a command fails?

The same entry, including the device response. A command that was sent and not acknowledged is distinguishable from one that succeeded, which matters when reconstructing what happened during an incident.

Does control work from a phone?

Control follows the same authority and confirmation rules everywhere. Where a user holds control authority, the confirmation step and the audit record are identical regardless of the device they are using.

See it against your own wells.

A demo runs against synthetic data first, then against a read-only connection to your system of record if you want to see real numbers.