ENERGY COMPLIANCE, INC. Rigorous Compliance. Defensible Programs. HomeWhitepapers › EC-WP-1107

Monitoring Truth & Fleet Reconciliation Series · EC-WP-1107

The Reconciliation Layer

RenewOps — what it does, what it refuses to do, and what it does not claim.

A capability reference for RenewOps, the fleet reconciliation platform Energy Compliance builds. What the product does, marked shipped, in remediation or deferred against a stated observation date; the refusal catalogue, which is the chapter that defines it; and the boundary — item by item — of what it does not claim, including the integrity controls that are specified and not yet enforced.

Contents

  1. Not a monitoring platform
  2. Five rules, and what each one costs
  3. The measurement floor
  4. The alarm layer
  5. The operator layer
  6. NORA — rules, prompts and procedures
  7. The contract layer
  8. The evidence layer
  9. The refusal catalogue
  10. What RenewOps does not claim
  11. How it is deployed, and where to start

Read offline

The complete reference is on this page. The PDF is for circulation inside your organization.

Download the PDF

Chapter one

Not a monitoring platform

The most common first reaction to RenewOps is that it sounds like a monitoring platform with better validation. It is worth being precise about why it is not, because the distinction determines what it can be held responsible for.

What a monitoring platform is built to do

A monitoring platform acquires signals, stores them, and displays them. It is built for fidelity to the source: what the plant sent is what the screen shows. That is the correct design goal, and the good ones achieve it. A monitoring platform that silently altered readings to make them look sensible would be a much worse product.

The consequence is structural rather than a defect. A platform built for fidelity to the source has no independent reference to check the source against. It validates three things well — that data arrived, that the link is up, and that the value parses as the right type. It rarely validates the fourth: that the value is physically possible for this asset. That check requires a per-asset reference the platform was never given. A 200 MW reading is unremarkable on a 300 MW plant and impossible on a 20 MW one, and a generic range check cannot tell the difference.

What the reconciliation layer adds

ReferenceWhat it makes checkable
Asset ratingsNameplate, voltage class, expected operating band. Turns "the value arrived" into "the value is possible."
Executed agreementsThe availability construct, its denominator, its exclusions and its clock. Turns "we computed 99.2%" into "we computed the number this agreement defines, or we could not, and here is why."
The document of recordThe issued voltage schedule, the operating practice, the controlled procedure. Turns a displayed band into a citable one, or refuses.
The obligation calendarWhat is due, when, and on what evidence. Turns a signal into evidence, or states that it is not evidence.
The system's own historyAge, sample counts, unanswered polls, refusal ledgers. Turns a screen into something that can describe its own health.

The practical division. The monitoring platform stays. RenewOps reads from it. Where the two disagree, RenewOps does not overwrite the monitoring platform and does not assert that it is wrong — it publishes both figures with the gap labelled and names which question each one answers. On one site on one day the platform's own availability figure, the upstream contractual figure and the upstream technical figure read 66.0 per cent, 84.76 per cent and 51.45 per cent. None of the three is wrong at its own source.

Where responsibility sits

This matters for what can fairly be asked of the layer. RenewOps does not fix a dead pyranometer, restore a link, or improve a plant's production. It cannot make an uncomputable contract computable — where an agreement left a coefficient blank, no software resolves that; a person negotiates it.

What it changes is that all of the above become visible, dated, attributable and countable instead of being absorbed into a number that looks fine. The exposure existed before the layer was installed. The layer is what makes it surface on your schedule rather than on somebody else's.

Chapter two

Five rules, and what each one costs

The whole product reduces to five rules. Each is easy to state, and each carries a cost that explains why platforms generally do not follow them.

1 · Missing renders as unknown, never zero

The cost: a dash in a tile looks like a broken product and a zero looks like a working one. Every commercial pressure in software pushes toward the zero.

As implemented: three populations of false zeros converted to unknown on 25 August 2026 — a maximum-possible-power column carrying 3,758 zero rows, the measured-insolation column feeding performance ratio, and a telemetry voltage column. A curtailment determination that was never made is set to unknown rather than false, because a false all-clear during a real curtailment is worse than no reading. An infinite insulation-resistance value now renders blank, because infinity there is the absence of a fault path and it had been rendering as an unusually healthy reading.

2 · Every tile carries its own denominator

The cost: denominators are ugly, they take space, and they invite the question the tile was built to avoid.

As implemented: site availability publishes as an unweighted mean, named as unweighted, with the per-asset minimum and the count below threshold beside it. No rollup weighting was invented, because whether an agreement averages by asset count or weights by nameplate is a contract term. Every DC-loss row states how many paired hours it rests on; a day whose coverage swings more than twenty per cent labels itself UNEVEN COVERAGE. Alarm parent rows carry the full child count and the priority mix.

In remediation. An authoritative fleet definition exists, carrying a separate flag for each thing a tile might really be counting. As of 26 August 2026 no tile cites it, and screens still state fleet counts that differ from one another. This is the largest open item against rule two.

3 · Every number shows its provenance and its age

The cost: age is the field that makes a product look bad. A tile that says "as of eleven days ago" is telling the truth about a situation nobody wants to see.

As implemented: every state stamp carries the full date and an explicit age in days, routed through a single formatter so the whole product was corrected at once rather than card by card. The stalest feed on the fleet reads 796 days. Values resolve to the latest non-null reading per signal, each carrying its own as-of. Two battery sites carry a ROLLUP LIVE, UNITS SILENT verdict where the site number refreshes every fifteen minutes while every underlying unit stopped answering days earlier.

4 · When it cannot compute, it says why

The cost: "cannot compute" is an admission, and it is an admission on a screen somebody is paying for.

As implemented: curtailment tiles print a dash with the reason on the face. Twenty availability rows are withheld with the reason on the row and explicitly not estimated. Sixty-five recurring intervals read cannot-compute rather than showing a manufactured date. Four sites are excluded from a DC comparison, each with its own reason. An event fetcher that hits a response cap halves its window recursively and returns an error rather than writing a partial day that looks whole.

5 · Refusals are recorded and visible

The cost: a refusal ledger is a public list of the things your product would not do. It is the single least flattering artifact a platform can publish.

As implemented: 367 refused samples at one site in twenty-four hours, each auditable, with the raw value preserved beside the blank because the record of a bad reading is the evidence the gate is needed. Every rejected tracker wind sample named in an audit view. Two alarm-catalogue promotions held with the reason held as data. A priority override the classifier cannot read refused at the point of writing rather than stored where it would silently do nothing.

Four of these five rules make the product look worse on a demonstration than a competitor that follows none of them. That is not a flaw in the rules. It is the reason the category does not exist yet.

Chapter three

The measurement floor

Everything else in the platform rests on one question: is this value a measurement? The measurement floor is the set of checks that answer it before any screen is allowed to display anything.

The plausibility gate

Three independent tests run on every point-of-interconnection sample:

1. A per-site power ceiling derived from the plant's own rating rather than a generic range.

2. An absolute bulk-system voltage ceiling, plus a per-site band derived from the voltage schedule of record.

3. A shape test rejecting a twenty-four-hour span wider than one and a half times its own centre — which catches an intermittently corrupt channel that individually plausible samples would pass.

On the day it landed the gate refused 367 samples at one site in twenty-four hours, worst raw values around 13,700 MW and 9,280 kV, with zero false positives anywhere else in the fleet. That last figure is the one that makes the gate deployable; a plausibility check that fires on healthy plants gets switched off within a week.

The check that checks itself. Where a site's own voltage schedule is suspect, the platform refuses to use that setpoint as a banding input and surfaces the site in a coverage view. Six sites currently carry no assertable band and are stated as open per-site questions rather than defaulted to a plausible nominal. Banding against a number you do not trust is not a check; it is a check-shaped object.

The raw value is never modified. A refused reading renders blank with the raw value retained beside it, because a maintenance engineer needs to see 9,280 kV to understand that a tag is mapped wrong. Deleting it would remove the only evidence of the defect.

Methods that validate themselves

A derived figure is only as good as the assumption underneath it, so the platform builds the check into the method rather than adding it afterward:

MethodIts own validity test
DC output per MW installedEight of nine sites put DC actual within 0.94 to 1.11 of the revenue meter for the same window. That ratio is what makes the rest usable. A site reading 0.82 is physically impossible — a partial plant measured against a whole-plant meter — and is excluded with that reason stated.
Comparison bucketsBoth sides must carry comparable asset coverage before the comparison runs. A day whose coverage swings more than twenty per cent labels itself uneven.
Voltage scheduleReconciled against the plant controller's own setpoint, band and output side by side. Agreement at all eight sites where both were available.
Availability ingestVerified by two independent pulls reproducing the same six site figures exactly. A figure that cannot be reproduced on demand is not a measurement.

The first reading after a start is not an observation

A rule adopted after it cost a wrong figure: the first poll following a deployment is discarded. A sweep forty-six minutes old caught twenty-seven of forty-one inverters at zero output and drove a loss figure that described the poller's cold start rather than the plant.

Related, and the opposite of what most systems do: inverters reading zero are counted, not filtered out. An inverter at zero against a non-zero expectation is precisely the loss being measured. Three earlier versions of the calculation filtered them, and each produced a reassuring number.

Dead fields inside live rows

A row reads live when any one of its fields is fresh. Behind that, per-field liveness with age and unanswered-poll counts found fields dead between 41 and 293 days sitting behind between 289 and 413 unanswered polls. The schedule-versus-controller comparison now returns CANNOT COMPARE on a dead point rather than agreement, having previously produced a pass on evidence that does not exist.

In remediation as of 27 August 2026. The per-field liveness migration is staged and had not been run at the time of writing. It is described here as staged, not shipped.

Units are provenance too

Power factor was stored in two conventions under one field. A fleet ranking consequently named one site the worst on the system when its value was identical to the best. The convention is now settled per site by derivation from measured real and reactive power, and the fleet readout refuses and names the reason where a site cannot be settled. A unit convention is not a formatting detail; it is a statement about what the number means.

Chapter four

The alarm layer

An alarm system is an information system whose output is human attention. The layer treats it as one, and measures it accordingly.

One definition of the board

Two states, no others: unacknowledged-active and acknowledged. Acknowledging does not archive. An acknowledged alarm that is still asserting carries an ACK'D · STILL ASSERTING badge, because "I have seen this" and "this is over" are different statements and had been recorded as one. The audible feed is scoped to unacknowledged-active only, so an acknowledged alarm goes quiet and stays visible.

Status is not an alarm, and cannot latch again

The board went from 7,839 rows to 1,175, with 48 of 6,965 status and informational rows held deliberately. One daylight status event had appeared on an operator's board 2,092 times. Criticals went from seventeen present and none rendering to thirty-two rendering.

The durable half of that fix is a rule at ingest so those rows never latch again — a new arrival of that class lands archived with an explicit archive reason rather than landing on the board to await the next cleanup.

Priority resolves in the order authority runs

Approved override first; then the reviewed cause catalogue, matched by event name and then by code; then a classifier fallback. A priority posted by a browser can no longer contradict a catalogued code. A vocabulary check reports any priority word outside the known set, so a new upstream value cannot sort quietly to the bottom of every board.

Grouped alarms take the worst priority among their children plus the full child count, and the parent row carries a priority-mix qualifier on its face — an operator reads "High (High, Medium)" and knows the group is not uniform. Nothing is discarded. A proposed deduplication that would have kept three assets at High or eleven at Medium and thrown away the other was withdrawn before it ran: under-reporting count and severity is worse than staleness, because staleness at least announces itself in a timestamp.

Suppression measured against its own window

Suppression rate publishes with the window it was measured over, from the later of twenty-four hours ago and the moment suppression tagging began. That correction moved a reported 14.2 per cent to a measured 80.9 per cent. The behaviour had not changed; the denominator had. At that rate, 1,131 alarms per hour were still reaching the board.

Deferred. Alarm load is computed against a threshold of sixty alarms per operator-hour, configured in this platform. Whether that matches any published alarm-management guidance has not been verified against the source, and it is not stated as a standard anywhere in this series.

The monitor that stops

The platform publishes its own heartbeat, monitor health and scheduled-job health, and labels an unconfirmed alarm rather than clearing it. Two clocks are named separately — minutes since the newest onset, and minutes since the newest confirmation — so a stopped feed cannot hide behind a calm board.

What that surfaced. A close-out sweep had been destroying every alarm the platform raised itself: 548 voltage-band and 246 schedule-deviation alarms raised and deleted, each stamped as though the plant had returned to normal, none ever seen by an operator. The sweep now touches only alarms that originated upstream, identified by origin. On 25 August 2026, for the first time, sixteen voltage alarms stood across nine sites. Twelve were acknowledged within the hour.

A publish that refuses itself

The board refuses to commit unless four assertions pass: children summed across all parents equal the count of unacknowledged-active alarms; duplicate keys read zero; every dependent view rebuilds with its permissions re-asserted; and both layers complete a concurrent refresh. A duplicate-key counter must read zero on every refresh, and a non-zero reading is visible before the board freezes rather than after.

That guard exists because of what it found: one pre-computed layer had failed fifty-seven consecutive refreshes and a second had never once refreshed since it was created, both serving last-good contents behind a page that looked live.

Chapter five

The operator layer

Situational awareness is a property of the record, not of the dashboard. The test is whether an operator arriving cold can reconstruct the plant from the record alone, without asking anybody.

What the record answers

QuestionAnswered byStatus
What is wrong now?Standing conditions by priority, aged on the source clock with any fallback labelled. 2,096 of 2,126 genuinely still asserting when measured; 257 asserting over a week; oldest a critical breaker status at 458 days.Shipped 25 Aug
What has been done?A separate operator action log holding what a human actually did, apart from the alarm row a bulk operation can rewrite. Bulk acknowledgement writes its own record in the same transaction.Shipped 25 Aug
What is outstanding?Acknowledged-but-still-asserting badged on the row. Events whose end time is assumed counted separately from events observed to end.Shipped 26 Aug
What can I trust?Per-feed staleness in one place — assets, answered in three hours, answered in twenty-four, age of newest sample. Twelve of thirty feeds stale on enable, worst 796 days.Shipped 25 Aug
Who did it?Recorded on every controlled write, from a caller-supplied identity.Not verified

Acknowledge what you say you are acknowledging

A bucket acknowledgement acknowledges the whole bucket server-side and returns the count actually changed. It refuses an unattributed call, refuses an unrecognised priority, and never writes an archive stamp. The confirmation dialogue shows the true bucket size. Previously, "Ack all (1,707)" acknowledged the hundred rows the browser had loaded and reported success.

Metrics that decline to rank people

Operator response coverage publishes at one per cent, and time-to-acknowledge is explicitly marked not usable for ranking. The rule the platform works to: a response-time view emits the corroborated event count, the central tendency over that corroborated population only, the coverage percentage, and a usability flag computed from the first three. A median drawn from one per cent of a population is a different measurement taken from a self-selected sample, and a footnote does not travel with a number into whatever chart somebody builds next. A flag does.

The honest version of an operator metric is usually the one that says this cannot be used to rank people. It is harder to publish than the median, and it is the only version that survives being cited.

Events that never closed

6,696 events stand open and were never closed, banded by age — 230 over a year, 4,389 between ninety days and a year, 1,947 recent. A separate unambiguous flag catches night events stuck open: 1,866 fleet-wide, including 779 low-irradiance-at-night events across seven sites, oldest at 335 days.

The analysis stops there. It would be tidier to conclude that stuck events are what drives the availability figures. The sites do not line up cleanly enough to support that, so the claim is not made.

Chapter six

NORA — rules, prompts and procedures

NORA is the operator response layer. It raises prompts from a guarded vocabulary of signal types, holds the controlled procedure library, drafts switching orders — and keeps score of how often its own output was ignored.

The not-needed rate

Every rule is scored by the share of its prompts an operator answered "not needed." On 25 August 2026 six enabled rules all measured between zero and 1.5 per cent, with answer counts of 66, 21, 13, 12, 7 and 6. Each was reported as earning its place, and a number rather than an opinion is what earned it.

A rule has three legible states, not two: enabled; disabled, with the reason written onto the rule record; and NOT WIRED — existing but with no candidate branch, so it could never fire under any input. That third state is the one that matters most. On 24 August 2026 four of seven rules structurally could not fire while the screen printed quiet — no independent check available, which an operations manager would reasonably read as a clean fleet on four dimensions nothing was checking. Enabled rules went from six to nine the following day, and wiring state now renders separately from firing state.

Two gates on every candidate branch

A rule comparing a partial day's measurement against a full day's model made the whole fleet look faulted every morning and recover every afternoon. Any candidate branch now requires a completed-day gate and a persistence test. Re-enabled on completed days, that rule caught four genuine site-days in seven — sites generating between 1,000 and 1,800 MWh against zero reported sunlight.

The rules it declines to enable

RuleWhy it is off
Availability below guaranteeDeliberately disabled until the capability score is persisted server-side. A rule firing off a number computed in a browser session produces a prompt nobody can audit afterwards.
Alarm floodThe only available count does not mean what the rule needs it to mean. Pointing the rule at it would put a fabricated alarms-per-hour figure in front of an operator, so the signal is left unconsumed.
PlausibilityThe permitted signal vocabulary contains no signal for arrived on time, from a healthy link, and is not physically possible. Widening it governs what NORA may say at all, so it is an owner decision rather than an engineering repair.

The inverted rule is worth recording because the failure is so easy to reproduce. A communications rule counted comms-loss alarms, so it fired on healthy sites and stayed silent on dark ones — a site that has gone dark cannot send an alarm saying it has gone dark. Its replacement asks how long since the feed last said anything, which covers dark sites by construction, and flagged twelve of thirty feeds stale on enable.

The controlled procedure library

121 controlled documents — operating practices, alarm response guides, switching practices — live and retrievable, filed by document type, with post-load reconciliation reporting nothing missing. Three behaviours matter more than the count:

▸ A company procedure is never returned as the standard it implements. The document type says what the document is; the standard linkage is a separate field. All fields are supplied explicitly on ingest, after auto-detection previously misfiled eight documents as standards.

▸ Supersession runs on ingest. A replacement retires its predecessor; a reload retires the entire prior load. There is no state in which two versions are both live.

▸ Ingest re-verifies the operator against a roster on every call and writes an audit row per ingest. An unrostered code was rejected rather than reconciled later.

Audit finding raised against the library itself, ahead of its effective date. 99 of the 121 controlled documents still carry a placeholder document number, and the approver and wet-signature register could not be loaded.

Machine-drafted switching orders

NORA drafts switching orders, and the order number issues from a controlled sequence at submission rather than being typed or minted at drafting. Two integrity controls are enforced today — controlled numbering, and the document provenance discipline above.

Four further requirements are specified and not yet enforced: expected state required on every step; step provenance and disclosure of any inferred step; separation of drafter, approver and executor; and a refusal recorded as a refusal rather than persisted as the order body. The register as measured on 24 August 2026 held twenty records — thirteen cancelled, seven draft, none ever submitted, approved or executed, expected state null on every step of every order, and one cancelled record whose body was a model's refusal to write it.

Stated plainly because it will be checked. An integrity control that has never been exercised is a design, not a control. The first competent question at a demonstration is "show me an order approved by somebody other than the person who drafted it," and on that register there is no approved order at all. Chapter 10 carries this in the does-not-claim list.

Chapter seven

The contract layer

Availability is not a number. It is a construct defined in an executed agreement, and the layer's output is whether that construct can be computed at all.

Computability as the output

StateMeaning
ReadyConstruct fully specified, every input held. The number can be produced.
PartialConstruct specified; one or more inputs missing or unreliable, and named.
BlockedConstruct specified and not computable by anybody, including the counterparty — a term left unpopulated, or the equation absent from the executed text.
UndefinedThe agreement defines no construct: an exhibit referencing an attachment that is not attached, a section that does not exist in the executed copy.

On the fleet measured, eleven of twenty-three sites read blocked. The dominant cause is coefficients left "mutually agreed upon" and never populated. The panel says so. It does not substitute a market convention, and it does not average around the gap.

Three figures, side by side, gap labelled

The platform's own inverter-count availability publishes beside the upstream contractual figure and the upstream technical figure, with the platform's own carrying a standing disclaimer that it is not the contractual figure. One site on one day: 66.0, 84.76 and 51.45 per cent.

The technical figure is ingested, stored, exposed — and consumed by no calculation anywhere, because its behaviour contradicts its name: 0.00 per cent at night and 11.58 per cent at midday against a contractual 98.47 per cent on the same asset and day. It is held until somebody with authority defines it. Storing a figure and refusing to compute on it is a legitimate state, and a more honest one than finding a use for it.

The denominator, and twenty rows that cannot be repaired

The inverter denominator was corrected fleet-wide by counting only rows carrying an inverter flag — the upstream source holds inverters and their sub-modules in one population, and ten of seventeen sites are mixed. Naming is explicitly rejected as a guide: at one site the rows named as inverters are the inverters; at another it is the rows named as modules that carry the flag. Only the flag is authoritative.

Twenty historical rows were computed against the wrong denominator, which means the online count was taken over the same wrong population. The percentage cannot be corrected. Those rows are withheld, return blank, carry the reason on the row, and are not estimated.

A figure pulled early is not a settled figure

Contractual availability is not final on the day. Where the contractual and technical figures agree to three decimals, no exclusions have yet been applied — so a "yesterday" figure pulled too early is a pre-exclusion number wearing a post-exclusion label. Flagged and under observation. Ingest is idempotent on its natural keys and accepts a date argument for backfill.

The calendar behind the guarantee

Two calendars, one click from the compliance header. Regulatory: 209 obligations — 86 hard dates, 65 recurring intervals, 58 event clocks. Contractual: 490 obligations — 287 hard dates, 203 intervals, carrying four times the regulatory deadline load inside sixty days.

▸ Provisional dates are badged, not hidden. 84 of 287 dated rows rest on an unconfirmed anchor, badged date provisional · anchor not confirmed with the anchor text printed beneath. Nine sites have no usable anchor at all, including two agreements executed with the effective date left blank — a legal finding, not a data problem.

▸ A cadence is not a date. 163 obligations recurring without a fixed day load as recurring windows carrying the decision still owed and a confidence rating, rather than becoming 163 deadlines nobody agreed to.

▸ Applicability gates are carried as open questions, not guessed: 33 unanswered gates gating 70 of the 86 regulatory hard dates.

Chapter eight

The evidence layer

Provenance is what separates a number you can show from a number you can cite. The evidence layer sorts one from the other and refuses to blur them.

Provenance classes

All twenty-five sites are classified against the voltage schedule of record into six states: a complete document from the operating entity; target only with no tolerance band; wrong bus; not in the source of record; source unusable; and no row at all — the state in which two live sites had been hiding, because a per-row grade cannot grade a row that does not exist.

Eight of twenty-five receive a citable in-band percentage, all from complete documented schedules. One site that had been publishing 62.9 per cent against a placeholder band on the wrong bus now publishes nothing and reads WRONG BUS.

What the classification fixed. Compliance exports previously carried no provenance flags at all, publishing in-band percentages for wrong-bus and explicitly disabled sites — including tautological readings of exactly 100.0 per cent, where the band had been derived from the median of the very series being scored against it. A perfect score against yourself is the cleanest available illustration of a number that is arithmetically correct and evidentially worthless.

A band auto-detected from a site's own median is labelled INDICATIVE ONLY wherever it appears. Each schedule row quotes its source inline — file, path, server-modified date, document key — and the source document's own defects are recorded rather than repaired, because silently cleaning a source destroys the evidence that it needed cleaning.

One write door

The schedule of record may only be set through a single controlled path that demands a directive reference, refuses an implausible setpoint, writes history and stamps the source. Two honest notes: as of 25 August 2026 it had no caller, because schedules arrived through document load — the path is correct and unexercised. And a corrupt seeded setpoint at an impossible value was left in place rather than edited, with the plausibility layer refusing to use it. Changing a voltage schedule is a person's decision made against a directive. The platform is built so it cannot become a data-quality cleanup.

The evidence it declined to create. Two live sites have complete documented schedules and deliver no voltage telemetry. No schedule row was written for either, because a band against a dead channel yields either silence or a 100 per cent excursion the moment a tag appears — both fabricated evidence, one reassuring and one alarming.

Obligations that cannot be marked done dishonestly

Recurring intervals compute a next-due date only from a recorded last-performed date. With no baseline, all sixty-five regulatory intervals read cannot compute — last performed not recorded: not a default, not the start of the calendar year, not silently overdue. The prompt to record the baseline is itself raised by the rules engine.

Completion behaves by type. A hard date closes that occurrence only. A recurring obligation records LAST PERFORMED, the field that unblocks next-due. Both refuse an unattributed call and a completion date in the future. Reopening requires a written reason that stays on the record, and a completed view shows who recorded what, when, how many days early or late, and every reopen with its reason.

After the completion function was verified, the test rows were deleted, leaving the performed list deliberately empty. A fabricated performance record on a compliance calendar is worse than no feature, because the fabrication is indistinguishable from evidence and will be produced as evidence by somebody acting in good faith.

Notifications compose into an outbox and hold as held-without-recipient until an address is configured. Composed, readable, and never reported as sent.

Can the evidence survive the platform?

On 28 August 2026 a restore was proven onto a clean, empty database from the exported files alone: 136 tables, 202 views, 95 functions, 18 materialized views, 255 indexes, 163 policies. Zero schema errors, zero function errors, all 220 relations executing.

Two findings came with it. The export was not self-sufficient and did not say so — it granted to roles it never created, so it failed on its first statement against an empty database. Anyone attempting a restore before that date would have concluded the export was broken. It was not broken; it was incomplete in a way nothing recorded. And the materialized views must refresh in dependency order: refreshed alphabetically, four of eighteen fail, breaking ten ordinary views — and nothing on screen says the numbers are stale. The screens simply report nothing.

Deferred, stated precisely. What was proven is a schema and objects restore from a schema-only export. A data restore has not been demonstrated, and this reference does not describe the result as a proven backup of the evidence.

Chapter nine

The refusal catalogue

If you read one chapter of this reference, read this one. A platform is defined more precisely by what it declines to produce than by what it displays, because anything can be displayed.

Every entry below is a place where RenewOps has a value available, or could readily compute one, and does not. Each was observed on a live production instance between 24 and 28 August 2026.

Refusals of measurement

What is refusedWhat appears instead
Implausible telemetryBlank, with the raw value retained beside it as evidence the gate is needed. 367 samples in twenty-four hours at one site, zero false positives elsewhere.
A setpoint the platform does not trustDeclines to use it as a banding input; the site surfaces in a coverage view. Six sites carry no assertable band, stated as open questions rather than defaulted.
Tracker wind outside a physical bandRejected, with every rejected sample named in an audit view. 162 controllers at one site reported roughly Mach 2.2, and wind stow is decided off that signal.
An infinite insulation readingBlank. Infinity is the absence of a fault path, not a perfect reading.
A comparison across uneven coverageThe day labels itself UNEVEN COVERAGE and the bucket does not compare.
A site whose derived total is physically impossible against its meterExcluded from the comparison with the reason stated — partial plant measured against a whole-plant meter.
The first poll after a deploymentDiscarded. A cold start is not an observation of a plant.
A comparison against a dead pointCANNOT COMPARE, rather than agreement. It had been producing a pass on evidence that does not exist.
A power factor whose convention cannot be settledRefused, with the reason named, rather than ranked against values in a different convention.

Refusals of computation

What is refusedWhat appears instead
A curtailment figure with no directed history-- and the reason on the face of the tile.
A determination that was never madeUnknown, never false. A false all-clear is worse than no reading.
Twenty availability rows on a wrong denominatorBlank with the reason on the row. Not estimated, not interpolated, not dropped from the series to keep a chart continuous.
A site availability rollup weightingAn unweighted mean, named as unweighted, with the minimum and the count below threshold. The weighting is a contract term, not a display choice.
A next-due date with no recorded baselineCannot compute — last performed not recorded. Sixty-five of sixty-five.
A cadence with no fixed dayA recurring window carrying the decision still owed, not a manufactured deadline. 163 of them.
A partial day written as a whole oneThe fetcher halves its window recursively and returns an error.
A figure whose meaning contradicts its nameStored, exposed, and used in nothing until an owner defines it.

Refusals of evidence

What is refusedWhat appears instead
An in-band percentage against a seeded bandNothing. Seventeen of twenty-five sites publish no figure. A band the operating entity never issued is not evidence of conformance to one it did.
A schedule row for a site with no telemetryNot written. A band against a dead channel yields silence or a 100 per cent excursion the moment a tag appears — both fabricated.
Editing a corrupt schedule to make it sensibleLeft in place; the plausibility layer refuses to use it. Changing a schedule is a person's decision against a directive.
Repairing a garbled source documentThe defect is recorded on the row. Cleaning a source destroys the evidence that it needed cleaning.
Test rows on a compliance calendarDeleted after verification, leaving the performed list deliberately empty.
A notification with no configured recipientHeld-without-recipient. Composed, readable, never reported as sent.
A completion dated in the future, or unattributedRefused at the point of writing.

Refusals of configuration

What is refusedWhat appears instead
A priority override the classifier cannot readRejected on write. An override that cannot take effect is worse than one never made, because somebody will later cite it.
A rule evaluation interval that would make it uselessRefused outright.
A rule pointed at a signal that does not mean what it needsLeft unconsumed rather than approximated. It would have put a fabricated alarms-per-hour figure in front of an operator.
Two catalogue promotionsHeld, with the reason held as data rather than in a ticket. One would have moved an isolated main transformer off Critical; one would have buried thirty-two Criticals under a night-time flood.
A board publish that does not reconcileRefused unless four assertions pass — child counts reconcile, duplicate keys read zero, dependent views rebuild with permissions re-asserted, both layers refresh.
Widening the rules engine's signal vocabularyNot done by engineering. It governs what the engine may say, so it is an owner decision.
Write operations on the upstream integrationDenied by default. Verified externally on 27 August 2026: insert, delete and point-create all refused.

Refusals of conclusion

The last category is the one that cannot be built into software, and it is the one that most determines whether the rest is worth anything. Three examples from the same six weeks:

▸ A deduplication that would have kept three assets at High or eleven at Medium and discarded the other was withdrawn before it ran.

▸ A ratio returning exactly 101.8 per cent on every unit at two sites was recorded as a constant, not a capacity metric — a negative result written down so nobody repeats the mistake.

▸ The link between stuck events and the availability figures was not claimed. The sites do not line up cleanly enough, and saying it would have been tidier than the evidence.

Refusal is a feature that costs money on every demonstration and earns it back exactly once, in a room where somebody asks where a number came from.

Chapter ten

What RenewOps does not claim

A capability reference that lists only capabilities is a brochure. This chapter is the boundary — stated at the same level of specificity as the rest, and dated the same way.

Controls specified but not enforced

Claim not madePosition as of 28 August 2026
Enforced separation of drafter, approver and executor on switching ordersNo order on the register has reached submitted, approved or executed. The separation has never been exercised and is not demonstrated by an empty register.
Expected state enforced on every stepNull on every step of every order on record. Specified, not enforced at write.
Step provenance and inferred-step disclosureNo order carries either field populated.
Refusal recorded as a refusalOne cancelled record currently holds a model's refusal as its order body.
A capability grade that respects its own denominator gateThe gate is deployed and confirmed present in the running bundle. It does not fire. One site shows a top grade with 50 of 75 inverters reporting.
An auditable capability scoreComputed per browser session, per operator, not persisted. Two operators can hold two numbers with no way to reconcile them.

Attribution

Content is guarded well across every controlled write in the platform. Identity is not. On most paths the actor is a string the caller supplies, so who set a schedule, approved an override, marked an obligation complete or answered a prompt is recorded but not independently verified. Every attribution in the system is therefore a claim rather than a fact. An evidence layer that has solved provenance of values while leaving provenance of actors open has solved half the problem, and this reference will not describe it as more than that.

Open items carried, not closed

▸ Fleet qualifiers are not on the tiles. The authoritative fleet definition exists and no screen cites it. Counts still differ between screens.

▸ Eleven days of historical false zeros remain written as zeros. New false zeros are stopped; the historical remediation decision is open, and those rows feed everything downstream.

▸ 131 of 249 catalogued alarm codes disagree with the priority in use, including a breaker trip-coil monitor sitting below Critical. Documented, not reconciled.

▸ The governed priority override store is empty. The path exists and refuses bad writes; nothing reads it yet, so applying an override today writes an audit trail and changes nothing.

▸ No rule has been retired on the not-needed rate. The lifecycle evidenced runs enabled → disabled-with-reason → not-wired. A ratchet that has never had to release is not yet proven to release.

▸ The per-condition quiet period is owed. One user answering eleven prompts in ninety-nine seconds muted twenty-eight standing protection conditions at once.

▸ 99 of 121 controlled documents carry placeholder numbers, and the approver register could not be loaded.

▸ No contract terms are held as structured data. Computability positions are produced by a person reading an executed exhibit; the platform holds the result, not the reasoning.

▸ The upstream source holds twenty-three site trees; the fleet holds twenty-five. The overlap has not been reconciled, and this is stated before fleet-wide ingest rather than discovered afterwards.

▸ A data restore has not been demonstrated. What was proven on 28 August 2026 is a schema and objects restore from a schema-only export.

What the layer cannot do at all

It does not fix a dead sensor, restore a link, or improve production. It cannot make an uncomputable agreement computable — where a coefficient was left blank, a person negotiates that, not software. It does not tell you whether a citable signal shows compliance: a fully traceable record of an exceedance is exactly as citable as a record of conformance, and rather more likely to be cited. And a clean result from any of its diagnostics is a statement that the record is consistent, sourced and current. It is not a statement that the plant is healthy, and several of the worst findings on the fleet measured sat on top of plants running perfectly well.

Conflating the record with the plant is the most common misreading of this work. It produces false alarm in one direction and false comfort in the other.

Chapter eleven

How it is deployed, and where to start

The layer reads from what you already run. It does not replace a monitoring platform, and a fleet that installs it on the assumption that it will is buying the wrong thing.

The shape of a deployment

1. Read from the existing monitoring stack. The layer acquires signals read-only. The monitoring platform stays, and where the two disagree the layer publishes both with the gap labelled rather than overwriting anything.

2. Establish the references. Asset ratings, the executed agreements, the documents of record, the obligation set. This is the step that makes checking possible and it is the step that takes the time — most of it is a document exercise, not an integration.

3. Resolve signals to roles. What each signal is for, per asset, so a value can be checked against something rather than merely stored.

4. Turn the floor on before the screens. Plausibility, staleness, denominator and provenance first. Screens built on an unchecked floor produce confident numbers, which is the problem being solved.

5. Enable rules on measured branches only. A rule goes live when its candidate branch has been tested against completed data and shown to fire on real conditions and stay quiet on healthy ones.

What an assessment produces

Most fleets should not begin with a deployment. They should begin by finding out whether they need one, and the honest way to find out is to look.

EngagementWhat comes back
Fleet Exposure ReadYour availability constructs reconciled against your executed agreements, returning a per-site computability position — ready, partial, blocked or undefined — with the specific blocker named for every site that cannot compute.
Monitoring Truth AssessmentThe full defect battery against your live stack. Every finding returns with a source, a timestamp, and the question that resolves it. Where something cannot be verified it comes back marked deferred with the specific question, not softened into a maybe.
Evidence Provenance ReviewYour compliance-relevant signals traced to source and sorted into citable and not, with the seeded, the derived and the self-referential separated from the issued.

You keep the findings either way. If you never buy anything else, you still walk away knowing which of your numbers you can defend. That is not a concession — it is the point. Nobody buys a reconciliation layer before they know they need one.

Five questions to put to your own fleet first

None of these requires us, and all five are answerable in a week by somebody who already has access:

1. Pick a tile showing a percentage. What is its denominator, and does the tile say? If you have to ask an engineer, an auditor will have to ask one too.

2. Find a value that is currently zero. Can you tell whether it is a measured zero or an absent one? If the screen renders both identically, you have the first failure class somewhere in your fleet.

3. Take the oldest reading on any screen. Does the screen say how old it is? A time of day with no date is the cheapest and most common version of this defect.

4. Take one availability guarantee out of one executed agreement and try to compute it from your monitoring data. Not approximately. Exactly as written, with that denominator, those exclusions and that clock.

5. Pick one compliance-relevant number you would cite at audit and trace it to source. Is the source a document somebody issued to you, or a value your own system derived from itself?

If all five come back clean, you do not need this layer and we will say so. On the fleets assessed so far, none has.

Getting in touch

Thirty minutes against your specific situation, and we will tell you inside the first ten whether we would find anything.

Energy Compliance, Inc.

[email protected] · energycomplianceinc.com · 763.438.4427Bloomington, Minnesota

The firm

About Energy Compliance, Inc.

Energy Compliance, Inc. is an independent regulatory compliance and advisory firm serving the energy sector, with a focus on NERC, FERC, and RTO/ISO compliance and a particular concentration in the ERCOT and Texas PUCT markets. The firm helps registered entities and prospective registrants navigate the full compliance lifecycle — registration, program design, evidence development, RSAW production, mitigation, and audit defense.

The approach is research-analyst-first. Every conclusion is tied to an authoritative source, every narrative is evidence-backed, and every deliverable is built to survive regulator scrutiny. Engagements are led by a single senior practitioner with regulator-side experience. We do not staff for billable hours. We staff for outcomes. Where automation can replace manual work, we build the automation. Where senior judgment is required, the senior is in the room.

That discipline extends to a portfolio of compliance technology, of which RenewOps — the reconciliation layer described throughout this series — is one part.

Rob Smith — Founder & Principal

More than thirty years on every side of the North American Bulk Electric System. Control-room operations as Reliability Coordinator, Transmission Operator and Power System Operator. Senior compliance auditor and subject matter expert for NERC Reliability Standards — auditing grid facilities, evaluating mitigation adequacy, and supporting the development of violation notifications and settlements as part of FERC-directed enforcement actions, from inside the regulator's process. Overseas, a regulatory audit in the Sultanate of Oman conducted against the Sultanate's Sector Law and Grid Code.

MSL, Corporate Compliance — Fordham Law · MS, Energy Management · BAS, Mechanical Engineering (Metallurgy minor), University of Florida · BAS, Energy Management · AAS, Power Plant Technology and Electrical Transmission System Technology, Bismarck State College

Auditing teaches one habit that never leaves: before you believe a number, ask what it would look like if it were wrong.

Where to start

An assessment points our defect battery at your live monitoring stack and hands you the findings — each with a source, a timestamp, and the question that resolves it — whether or not you buy anything afterward. Nobody buys a reconciliation layer before they know they need one, and the only honest way to find out is to look.

Fleet Exposure Read

Your availability constructs reconciled against your executed agreements, returning a per-site computability position — ready, partial, blocked, or undefined — with the specific blocker named for each site that cannot compute.

Monitoring Truth Assessment

The full defect battery against your live monitoring stack. Every finding returns with a source, a timestamp, and the question that resolves it. Where we cannot verify something, it comes back marked deferred with the specific question, not softened into a maybe.

Evidence Provenance Review

Your compliance-relevant signals traced to source and sorted into citable and not, with the seeded, the derived, and the self-referential separated out from the issued.

RenewOps

The reconciliation layer itself, deployed against your fleet: contract terms parsed to structure, signals resolved to roles, every tile carrying its own denominator, its own provenance, and its own age — and refusing to compute, visibly, when it cannot.

Energy Compliance, Inc.

[email protected] · energycomplianceinc.com · 763.438.4427Bloomington, Minnesota

To discuss how any of this applies to a specific fleet, or to request other references from the Energy Compliance library, visit energycomplianceinc.com.

Rigorous Compliance.Defensible Programs.

energycomplianceinc.com

Monitoring Truth & Fleet Reconciliation Series