Refrigerated logistics · Project

Temperature alerts with a clear responder

A monitoring service checks temperature alerts against site context, routes qualifying events to the duty role and documents the response.

An overnight alert has no identified responder

A chilled room crosses its upper limit during the night. The monitoring platform sends a message within a minute to a shared mailbox and a group chat. Several people can see it, but the message does not name the person expected to act.

By the morning, the temperature has returned to range. Someone may have checked a door, watched a defrost cycle or moved stock. The shift notes contain the temperature and time, but they may not show who acted, what they found or how the site closed the event.

The operator needs to know whether every important overnight alert reached a contactable person and whether the morning team can see what happened.

Decision testCan the operator improve response and accountability without creating an unmanageable alert load or changing the existing safety duties?
Technicians working in a refrigerated distribution centre
Chilled-site operating environment

An alert without an identified responder leaves risk open

The monitoring platform does its core job. Sensors report, thresholds trigger and messages reach the team within a minute. The gap begins after delivery. A shared mailbox cannot tell whether the on-duty person saw the alert, started an inspection or passed the issue to maintenance.

That ambiguity costs staff time each morning. Managers compare shift notes, maintenance updates and staff recollection. They may establish what happened, but the search delays review and makes an older incident hard to reconstruct. A missed alert and a handled alert can leave the same thin account. A refrigeration failure can also force stock removal, add labour and interrupt sales.

Discovery is reviewing one month of alerts from one site. The team is classifying each item as complete, explained by another source, recoverable from staff recollection or unsupported by the available material. It is also counting stale readings, signal gaps, alert volume and cases with no clear action.

The review does not determine whether stock remained safe or whether the current thresholds are correct. A Food Standards Agency observational study of 29 food businesses found that some treated temperatures above the recommended 5°C as normal and failed to act. Imperial research notes that refrigeration accounts for about half of supermarket-store energy use and that major faults can force stock removal, add labour and inhibit sales. These sources establish the stakes and provide no local result.Sources: Food Standards Agency, Chilling food correctly, FDA, HACCP Principles and Application Guidelines, Food Standards Agency, Storing chilled foods at incorrect temperatures, 2023, Imperial College London Grantham Institute, Impact of a warming climate on UK food retail refrigeration systems, 2020

The current gap concerns attention and follow-through, so the first change focuses on those two points.

Management narrowed the pilot to response

Management chose a one-site response pilot before changing refrigeration equipment or expanding overnight cover. The service separates alerts that require site action from faulty or incomplete signals that maintenance must investigate. Site leaders set the rules using temperature, duration, equipment state, product and room context. The person on duty makes the judgement.

The person on duty acknowledges the case, completes the inspection and adds the information needed to close it, such as a follow-up temperature, a photograph or a stock disposition. Site staff continue to decide severity, product action and escalation. The service does not control refrigeration equipment.

Threshold changes need approval. Missing sensor input remains visible. The on-call rota must cover every hour before the operator enables live routing. European medicine-distribution guidance offers a useful comparison through its focus on a contactable responsible person, but that separate regime does not apply to this site.Sources: European Commission, Guidelines on Good Distribution Practice of medicinal products for human use (2013/C 343/01)

The pilot can read monitoring information and cannot control refrigeration equipment. That boundary prevents a response tool from changing machinery. NCSC guidance supports separating monitoring access from operational control.Sources: NCSC, Secure connectivity for operational technology, 2026, NCSC, Operational Technology guidance

The operator has set the test boundaries

The operator has agreed the purpose, one-site scope, identified response role and proposed fifteen-minute acknowledgement target. Discovery has also defined the alert review that will provide the starting point. The team has not completed that review or tested the service with a live shift.

False alarms could overload the rota, while missed excursions or weak product context could hide a serious event. Poor sensor coverage adds another risk. Staff may also fill in a closing field to clear the queue without improving the actual response.

Four weeks of observation will precede any live alert. The service will identify qualifying events and propose the person on duty. Shift managers will compare its output with current practice each morning, and current controls remain unchanged.

The pilot will test both operational usefulness and the burden placed on the shift.

Live routing depends on response quality

Measures include signal availability, faulty-signal detection, important events found only by current practice, false alarms per shift, time to an identified person, oldest untouched case, completion quality and staff time per case. The operator will set acceptable limits before the pilot starts.

Live routing can proceed only if the service does not miss an unacceptable number of important events, the rota can absorb the qualifying volume and the completion information helps managers understand the response. The fifteen-minute target must also prove suitable for the site’s risks and staffing.

A poor result will point to the next business decision. High signal failure means the sensor estate needs attention. Excessive alert volume means the qualifying rules need work. Insufficient overnight capacity means the operator must change scope or staffing before adding live routing.

A technician inspecting refrigeration pipework with a temperature probe
Equipment inspection during a shift

Next steps

  1. Finish the one-month alert review
  2. Agree the alerts that require a response
  3. Run four weeks beside current practice
  4. Use missed-event and response measures to decide live routing
Enquiries

Discuss a business problem.

Start an enquiry