Data center HVAC operations

Run data-center cooling as an operation, not an alarm feed.

A supply-air sensor crosses its limit at 03:14. Four minutes later a qualified technician is moving, with the unit history, the procedure and the live readings already attached — because the system did the part in the middle.

Cooling operationsATL-04 · 11 open · Live
Triage4
CW-2184
CRAH-07 supply air above limit
CriticalDH-2
CW-2179
CDU-2E differential pressure low
CriticalDH-1
CW-2176
Humidity swing, row R9
WatchDH-2
CW-2171
Filter ΔP high — AHU-2
PlannedPlant
Dispatched2
CW-2168
Chiller 2 approach temperature rising
CriticalPlant
CW-2165
Leak detection cable fault, R21
UrgentDH-3
On site2
CW-2160
Rear-door HX flow low, R22
UrgentDH-3
CW-2158
VFD fault CRAH-11
CriticalDH-1
Verifying3
CW-2151
Valve actuator replaced — CRAH-04
2 of 4 conditions
CW-2147
Coolant top-up CDU-1
Baseline held 46 min
CW-2143
Belt replacement AHU-1
Closing
Alert · ALR-884203:14:02
CRAH-07 supply air above limit
ATL-04 · Hall DH-2 · Row R14 · Loop CHW-B
29.4°C
Supply air · now
Limit27.0 °C
Baseline21.8 °C
Sustained5 min 12 s
Rule Cooling — supply air critical held for 5 min. Redundancy fell to N.
Created automatically03:14:04
CW
CW-2184
CRAH-07 supply air above limit
CriticalDispatch proposed
MO
M. Okonkwo
Mechanical · OEM-authorised · 14 min out
Qualified
Auto-dispatch in 2 min
01The trigger

A limit breaks at 03:14. Nobody is awake.

Design-partner scope

Supply air on CRAH-07 crosses 27 °C and stays there. In most halls that becomes an amber row on a graphics page, then a phone call, then a decision made by whoever picked up.

Here it is a rule with a scope and a consequence, written once in the language the shift already uses: which point, which limit, for how long, in which hall — and what happens when it holds.

Automations9 active
Cooling — supply air critical12 runs · 7d
Loop ΔP loss — CDU3 runs · 7d
Chiller approach temperature5 runs · 7d
Condensate / leak detection1 run · 7d
Filter ΔP — planned change9 runs · 7d
Fan speed held at maximum4 runs · 7d
Rear-door HX flow low2 runs · 7d
Humidity outside ASHRAE class0 runs · 7d
Redundancy below N+1 for 30 min6 runs · 7d
+ New automation
Cooling — supply air criticalLive
When
Point reading receivedUnit → Supply air temp
If
Valueis above27.0 °C
Sustained forat least5 min
Hallis any ofDH-1, DH-2, DH-3
Redundancyis at or belowN+1
All conditions
Then
  1. Create work orderType: Cooling — critical · Priority from thermal margin
  2. Fold in related signalsSame loop, same 10 min window → one incident
  3. Attach live pointsSupply air, return air, valve, loop ΔP · last 60 min
  4. Require qualificationMechanical · OEM-authorised for CRAH-07 class
  5. NotifyOn-call mechanical, hall lead
02The work order

The work order writes itself, with the equipment already on it.

Design-partner scope

Two seconds after the rule holds, a work order exists. Not a ticket with an alarm string pasted into the description — a record carrying the unit, the hall, the loop it feeds, the redundancy it just consumed, and the procedure that applies.

The dispatcher stops asking what this is. The question becomes whether it is right, and that is a question a person can answer in seconds.

CW

CRAH-07 supply air above limit

CW-2184CriticalDispatchedOpened 03:14:04
OverviewEquipmentTelemetryProcedureActivity
THERMAL MARGIN
11min
falling
ABOVE LIMIT
2.4K
since 03:14:02
RACKS DOWNSTREAM
18
row R14
REDUNDANCY
N
CRAH-08 carrying
Equipment
UnitCRAH-07 · CRAH, 120 kW
HallDH-2 · Row R14
LoopCHW-B · chilled water
Fed fromChiller 2 · primary
Last serviceCoil clean · 2026-06-11
ProcedureMOP-114 · 2 of 5
  • Confirm redundancy state at panel
  • Isolate per LOTO — CHW-B branch
  • Inspect valve actuator travel
  • Verify supply air returns below 24 °C
  • Restore N+1 and record final state
Assigned
MO
M. OkonkwoAccepted 03:15:41
MechanicalOEM · CRAHSite induction
Live pointsstreaming
Supply air29.4 °C
Return air34.1 °C
Valve100 %
Loop ΔP41 kPa
Closure conditionsset at open
Baseline21.8 °C
Recovery below24.0 °C
Hold for45 min
No recurrence24 h
Raised by
ALR-8842Rule: supply air critical · 03:14:02
03Live equipment

Open the work order. The equipment is still live inside it.

Design-partner scope

A work order carrying a screenshot of an alarm is out of date before it is assigned. This one carries the points themselves — supply air, return air, valve position, loop differential pressure — still moving while the technician drives.

It is the same view the technician opens at the unit, and the same series the system reads back after the work is called complete.

Hall DH-29 units · live
CRAH-0321.4 °C
CRAH-0421.7 °C
CRAH-0521.6 °C
CRAH-0621.9 °C
CRAH-0729.4 °C
CRAH-0823.8 °C
CRAH-0922.0 °C
CDU-118.1 °C
CDU-218.4 °C
CRAH-07 · liveSupply air · 30 min · updating
30272421Baseline 21.8 °CLimit 27.0 °C03:05now
Supply air
29.4°C
+7.6 K over baseline
Return air
34.1°C
+4.2 K
Valve position
100%
open, held 6 min
Loop ΔP
41kPa
−18 % on CHW-B
Downstream
Chiller 2CHW-BCRAH-07Row R1418 racks
N+1 consumedCRAH-08 carrying11 min margin
04The model

A CRAH is not a line item. It gets its own object.

Field service systems model a customer, a job and an invoice. None of those describe a hall, a chilled-water loop, a coolant distribution unit or an N+1 state, so teams push them into notes and custom fields until the model stops carrying weight.

The objects here are the ones the work has: Hall, Loop, Unit, Point, Alert, Work order, Verification. Every record page is assembled from blocks that read those fields — a telemetry block, a redundancy block, a procedure block.

Objects7 · cooling operations
HallSite · rows · ASHRAE class
11 fields
LoopChilled water · condenser · coolant
9 fields
UnitCRAH · CDU · RDHx · AHU
24 fields
PointReading · limit · dwell · trust
8 fields
AlertRule · severity · folded signals
12 fields
Work orderResponse · qualification · MOP
27 fields
VerificationBaseline · window · recurrence
10 fields
Layout · Work orderEditing
Headercooling
title ← Work order · name · status ← stage
KPI rowcooling
thermal margin, above limit, racks, redundancy
Field group
fields ← Unit, Hall, Loop, Fed from
Live telemetrycooling
points ← Unit · monitoring points · window: 60 min
Procedure
checklist ← MOP for work order type
Qualification
candidates ← Team, filtered by certification
Verification
conditions ← Verification · closure rules
+ Add block
05Your systems

Every system you run already holds a true part of this.

Each is authoritative about its own slice and blind to the others. None of them is wrong, and none of them is the missing piece.

What no system owns is the span between them: deciding what a set of physical signals means, who is permitted to act on it, and whether the action worked.

BMS · BAS
Controls and observes the plant. Knows the setpoint and the current state.
DCIM
Holds assets, capacity and environmental history for the hall.
Controls · sensors
Report temperature, pressure, flow and valve position.
CMMS · EAM
Holds asset history and the maintenance record.
Field service
Moves technicians and closes work orders.
06The boundary

The repair is physical. A person still has to make it.

Design-partner scope

Nothing here takes control authority over a cooling plant. Every connection is read-only, and the write scopes that would let it act on equipment are not requested and not available.

It reads, interprets and proposes. Dispatch inside an approved scope happens on its own; anything outside that scope waits for a person. A human puts hands on the unit, which is also the moment the decision gets tested against reality.

Decisionslast 6 h
Dispatch CW-2184 → M. OkonkwoWithin approved scope
Escalate CW-2168 to hall leadApproved by J. Reyes · 02:41
Close CW-2147Approved by J. Reyes · 01:12
Raise CW-2179 as WatchWithin approved scope
Reopen CW-2139 — recurrenceWithin approved scope
Extend window on CW-2151Approved by A. Mensah · 00:36
Hold dispatch CW-2133Declined by J. Reyes · 23:58
ConnectionsRead-only
BMS · Niagara N44,812 pointsRead-only
DCIM · asset + capacity1,140 assetsRead-only
Controls · CDU gateway306 pointsRead-only
CMMS · work historyWork ordersRead · write work
Control authority
Setpoint changesNot requested · not available
Start / stop equipmentNot requested · not available
Valve and damper commandsNot requested · not available
Alarm suppressionNot requested · not available
07Answered

Does it control our cooling equipment?

No. The boundary is read-only. It observes points, builds topology, interprets conditions and raises work, and it makes workflow decisions inside a scope you approve. It never changes a setpoint, commands a valve or starts equipment. Humans keep physical repair and every safety-critical approval.

How is this different from BMS-to-CMMS alarm integration?

Alarm integration transports a signal and opens a ticket, which is a real capability and several products do it well. This is about what sits between those two events: folding many signals into one physical condition, working out what it threatens through the cooling topology, and deciding whether the response is authorised at all.

What actually creates the work order?

A rule you can read. Point, limit, dwell time, hall scope, and the actions that follow — create the work order, attach the live points, require the qualification, notify the on-call. Interpretation runs on top of that rule to fold related signals into one incident, never underneath it as an unexplained decision.

Can we model our own equipment types?

That is the point of the object model. A hall, a chilled-water loop, a coolant distribution unit, a rear-door heat exchanger and a monitoring point are objects with their own fields, not custom fields bolted to a generic job. Record pages are assembled from blocks that read those fields.

What has to agree before an incident closes?

A pre-work baseline, an expected recovery signal, an observation window and a recurrence rule, all defined before the work starts. Telemetry returning to baseline and the technician's findings must agree. Where they disagree the incident stays open — a sensor can be wrong, and a fix can be temporary.