Safe PerimeterBorn Between 2 Generals

Operations

Connection to server failed. Retrying.

Every monitoring programme lives or dies in this room, on an ordinary Tuesday, when a third of the fleet is offline and somebody has to decide which of those outages means anything.

The specification so far describes a system working. This page describes it not working, which is the condition it will spend most of its life in.

Device states an operator will actually see

StateWhat it looks likeWhat it meansResponse
HealthyReporting, strap intact, fix goodNormalNone
Fix lostReporting, no positionIndoors, underground, urban canyon. Extremely common.None automatically. The tier engine already refuses to alert on it.
SilentNo contact for > 15 minNetwork gap, or a device off. Indistinguishable at first.Automatic query. Escalate on duration, not on the fact.
Low powerBattery under thresholdCharge due, or a charging pattern being avoidedSubject notified; repeated instances are a supervision matter, not a device matter.
Power deadOrderly shutdown, then nothingDefined in the conditions as a violationWritten response per the order. Not an emergency call.
Strap breachContinuity broken, device may still reportRemoval. The one hardware event that is unambiguous.Immediate, per the latency budget on the devices page.
Signal denialAll radios lost at once, in a place with prior coverageJamming, a shielded enclosure, or a dead antennaRecorded as an event in its own right; investigated on pattern.
Late batchA burst of buffered events arriving at onceReconnection after an outageEvery event in the batch is labelled with its true age. Presenting buffered events as live is how a monitoring system produces a wrong arrest.

False alerts

There will be a lot of them, and how they are handled is the programme’s reputation.

  • Classify before you count. A false alert is not one thing: a bad fix, a legitimate encounter with an innocent explanation, a device fault, and a data error each need a different fix and each should be counted separately.
  • An overturned alert leaves the pattern count. Repeats feed the ladder. An uncorrected false positive permanently raises a subject’s escalation risk, and the error compounds.
  • Publish the rate. Quarterly, broken down by classification. A programme that will not publish its own false-positive rate has no standing to ask anyone to trust its true ones.
  • Watch for the desensitisation curve. Track the time between an alert arriving and a human acting on it. When that number starts to rise, the ladder is mis-tuned — and rising response time is the leading indicator of the failure that gets programmes cancelled.

The unglamorous list

Charging

Named in the conditions with a specific window and a specific duration. “Keep it charged” is not an enforceable condition and will not survive a violation hearing. The child’s band targets five to seven days precisely so charging never becomes the reason it is not worn.

Fleet health

A daily figure for devices reporting, devices silent over 24 hours, and strap events. Any programme where this number is not on somebody’s desk each morning is already failing and does not know it.

Firmware

Staged rollout, never fleet-wide at once, with the version recorded against every encounter so a defect can be scoped to the events it touched. A silent fleet update that changes classifier behaviour is a change to the evidence.

Key list distribution

The daily pseudonymous key list has to reach every band. A band that has not fetched today’s list is matching against yesterday’s and is quietly less capable, so staleness is a monitored condition — not a silent degradation.

Lost and found bands

A found band carries no identity, so it cannot be returned by looking at it. Revocation must be immediate from the guardian side, and the pairing secret wiped on the next power cycle.

Handover between agencies

Subjects move. Enrolment, tier, term and audit history have to move with them, and the receiving jurisdiction has to be one where the order is enforceable. Where it is not, the programme ends for that subject — and says so, rather than pretending to a coverage it no longer has.

The metric that actually predicts failure

Not uptime, not alert volume, not enrolment. Median time from alert to human action, tracked weekly. It captures dispatcher desensitisation, understaffing, and a mis-tuned ladder in a single number, and it starts moving months before anything visible goes wrong.

Next

All of it, in one document

The full specification collects every requirement on this site into a single printable page.