Plant alarms that reach a person, not an empty room
An escalation app for hospital estates. Alarms from cold storage, generators and medical gas plant are routed to whoever is on duty, and every acknowledgement is recorded.
- Plant systems on one feed
- 4
- Before the duty manager is paged
- 3 hops
- Needed to acknowledge
- 0 bars
The client
A 300-bed private hospital
Named clients are withheld under the confidentiality agreements we work to. Sector, scale and system detail are published with permission.
- Sector
- Healthcare, estates and facilities
- Scale
- Estates team of eleven, four alarm sources, cover around the clock
- Duration
- 9 weeks, plus four weeks running beside the old phone list
- Team
- Mobile engineer, Backend engineer, Integration engineer, Estates liaison, client side, Project manager
What was wrong.
Plant alarms landed on a monitor in the engineering room. When the room was empty, which it was for most of the night, an alarm waited until somebody walked past. The team was finding problems at seven that had started at two.
Escalation was a laminated phone list. It did not know who was on leave, and it did not record whether a call was answered. The hospital wanted the acknowledgement itself to be data, so a missed alarm could be seen the next day rather than reconstructed from memory.
The approach, step by step.
- 01
Read the plant as it is
Chillers, the medical gas plant, the generator panel and the blood-bank refrigerators each spoke a different protocol. We normalised all four into one event type, with severity bands the estates team defined themselves.
- 02
Route by the roster
The app resolves who is on shift at the moment the alarm fires, then pages that person. Nobody is woken because their name sits on a list printed last year.
- 03
Acknowledge, or it escalates
An unacknowledged critical alarm moves to the next person after a set interval, then to the duty manager. Each hop is written to the alarm's history with its timestamp.
- 04
Build for a basement
Signal in plant rooms is poor. The app queues acknowledgements offline and syncs when the phone finds a bar, and a parallel text-message path covers a handset with no data at all.
- 05
Report the misses
A weekly report lists every alarm, how long it took to acknowledge and what escalated. The estates meeting now runs on that report.
The architecture we shipped.
Every layer below exists in the running system. Nothing here is a reference diagram.
- Plant interface
- Modbus and dry-contact inputs from chillers, medical gas, generators and refrigeration, polled by a gateway in the plant room.
- Normalisation
- Every input becomes one event type carrying source, severity, value and a threshold the estates team can edit.
- Roster resolver
- Shift patterns, leave and swaps decide who is on duty at the second the alarm fires.
- Escalation engine
- Timed hops with acknowledgement, each appended to the alarm's history rather than replacing the last state.
- Delivery
- Push notification first and text message as the fallback path, both carrying the same acknowledgement token.
- Mobile app
- An offline queue and one screen per alarm, showing the plant reading and the last three events from that source.
- Reporting
- Time to acknowledge, escalation count and repeat sources by asset, exported weekly.
What it does now.
Read from the system itself. No revenue claims, no multiples.
Plant systems on one feed
Chillers, medical gas, generators and blood-bank refrigeration.
Before the duty manager is paged
Each hop timestamped, so a silent alarm is visible the next morning.
Needed to acknowledge
The app queues in plant rooms with no signal and syncs on the way out.
Weekly, on time to acknowledge
Per asset and per shift, drawn from the same event history.
What it runs on.
- React Native
- Node.js
- Modbus TCP gateway
- MQTT
- PostgreSQL
- Redis
- Firebase Cloud Messaging
- SMS gateway
- Docker
The value is not the notification. It is being able to see the alarm nobody answered, and ask why, with the times in front of us.
Attributed by role and sector only, at the client's request.
What happens next.
Runtime hours read from the same gateway, so servicing is scheduled on use rather than on the calendar.
Services behind this build
Sector
HealthcareEstates team of eleven, four alarm sources, cover around the clock. The pattern transfers; the domain detail is rebuilt for every client.
Have a system that should work like this one?
We will walk your process, tell you what is worth automating, and scope the first version that can be measured.