Skip to content
DocEE-DOC-102
TitleElastic Sentinel
RevA
Sheet1 / 1
Used onEE-DOC-001

Venture sheet/ R2 · 20%

Sensors on the machine. The work on record.

Rung R2 — the recording every rung below it trains on.

We place instruments on our own service contracts — sensors across the electromagnetic spectrum, WiFi to X-ray — built to record machine state and the engineer's own work as it happens. The record is designed to feed the Service audit trail, and it is the corpus every rung below trains on.

Master planFollow the build

Load

Every fault ever cleared was seen once, by one person, and then it was gone.

A fault is cleared at a customer site, and the machine goes back to work.What the engineer saw before the fix is nowhere.What they did next, and in what order, is typed up from memory the following day.What the machine was doing while they worked was never measured at all.A machine that troubleshoots would need a corpus of troubleshooting, the way language models needed a corpus of language.No such corpus exists, because every observation that belongs in it lived in one engineer's hands and left with them.Nothing was recording.

Corpus of troubleshooting
What was observed, what was done next, and what that changed — recorded in that order, at the machine, while the work is being done.
  1. Half one — the machine

    One sensing discipline, from the router band to the treatment vault.

    The machine tells on itself across the whole spectrum. It talks on the WiFi band. It heats where it is working and where it is failing, and a thermal camera sees both. Its lamps, displays and indicators are visible light. Arcs and discharges show in the ultraviolet. In a treatment vault the beam itself is X-ray, and a detector in it reads what the machine is actually delivering. Today each of those is watched, if at all, by a different instrument from a different vendor on a different clock.

    Sentinel is designed as one discipline — the detection of electromagnetic waves — carried across every band, with every instrument bought off a shelf and wired to one clock. Machine state is what they record: what the machine emitted, radiated, transmitted and displayed, timestamped so that a change in one band can be laid beside a change in another. The sensors are purchased; they are item 003 of the master plan's bill of materials. What they are pointed at is the design.

  2. Half two — the engineer

    The other half of the record has never existed.

    Machine telemetry is the easy half, and it is the half that already gets sold. The half that has never been recorded is the engineer's: what they looked at, what they tried, in what order, and what the machine did after each try. It is not in the service report, which is written afterwards and says what was replaced. It is not in the machine's log, which does not know a person was there. It is the one record a troubleshooting model would have to learn from, and there is no instance of it anywhere.

    Sentinel is built to record the engineer's own work beside the machine's state, on the same clock. Service's wearables already narrate the visit; Sentinel's instruments are designed to fix what that narration was about — the reading, the setting, the part, the moment. An observation paired with the action that followed it is one line of the corpus. Telemetry with no action attached is noise, and an action with no observation is a report from memory.

Mechanism

A record that teaches where to point the next instrument.

The instruments do not know what matters. The corpus does. Every fault recorded beside the action that cleared it says which band moved first, which reading the engineer actually used, and which channels were watching nothing. That is fed back into where the next instrument is placed and what it samples, so the recording sharpens itself. Every pass points the next one better.

Drawn as a causal loop diagram, the design states its own failure modes, and there are two. An engineer on record is an engineer who can withdraw consent, and a Sentinel that erodes that consent records nothing. And an observation nobody pairs with an action is backlog, not corpus; if the backlog grows faster than the pairing, the corpus thins while the disks fill. Both balancing loops are below, and both are what the first article is built to measure.

Fig. 1 — the recording loop, signedCompiled from a signed model and verified on every build: loop polarity is derived from the edge signs rather than asserted, and variables that feed nothing back are rejected. Edit an edge and the figure, the table below, and this page either agree or the build fails.
Table 1 — loop audit. Polarity is the product of each loop's edge signs.
LoopPathSignsPolarityReading
R1contracts → instruments → observations → audit trail → contracts+ + + +reinforcingPlacement. A machine whose every event is on record is a contract that holds, and a contract that holds is a place to put the next instrument.
R2observations → corpus → signal selection → observations+ + +reinforcingThe recording sharpens itself: the corpus says which bands mattered, and the next instrument is pointed there.
B1instruments → engineer on record → consent → observations → audit trail → contracts → instruments+ − + + + +balancingThe honest one. Every instrument records the engineer too; if that erodes consent faster than scope restores it, the recording stops.
B2observations → backlog → corpus → signal selection → observations+ − + +balancingPairing. Observations nobody attaches to an action are backlog, and backlog dilutes the corpus that would have said what to record next.

The diagram is convertible to a stock-and-flow model — the corpus, the unpaired backlog, and the engineer's consent are the stocks. In that reading the design claim is a single inequality: the fraction of observations paired with an action must exceed the drag of the fraction that is not. Stated that way it is testable rather than persuasive, and the source lives in the repository beside the page.

Position

Machines are monitored. Engineers are not.

Condition monitoring is a mature market. Vibration, temperature, current draw, log scraping: the asset is watched by the vendor who sold it or by a monitoring firm that bolted a box to it, and the alert goes to a dashboard. All of it stops at the machine's skin. Nobody records what the engineer did when the alert came in, because the monitoring vendor does not employ the engineer and the service vendor does not own the sensors. The pairing falls between two companies, and neither can make it.

Elastic is both companies on its own contracts. The instruments sit beside a working engineer because the engineer is ours and the machine is under our contract to keep up. That is the whole reason Sentinel needs R1 first, and the whole reason nobody else has the corpus. None of it is novel science; the sensors are catalogue parts and the clock is a clock. What is missing is one party on both sides of the machine. We are that party, on our own contracts, first.

§ 01 / Placement rung R2

R2 because the corpus comes before the motion.

Sentinel sits second because it needs exactly one thing that only R1 produces — a service contract, the only place an instrument sits beside a working engineer — and because every rung below it needs what Sentinel produces before it can start. miniFactory executes motion against the corpus in a cell it controls; Robotics trains kinematics and decision models on it; neither has a corpus to train on until this rung has recorded one. It takes the second-largest allocation as a consequence of that position, not as the reason for it. The rule from the master plan holds: Sentinel spends nothing Service has not already earned.

The sensors are purchased. They are item 003 of the master plan's bill of materials (§ 03), bought off a shelf until Sentinel can make its own, and buying them is the point: nothing here waits on an instrument being invented. What is made here is the arrangement and the record. The corpus is not for sale.

Table 1 — The ladder in the order the knowledge has to arrive. Each rung needs the rung above it. Allocation follows that order; see § 05.
RungVentureNeeds firstTeachesAlloc
R1Service— nothing. This is the rung we hold.How engineering knowledge moves in the field, and what actually fails.75%
R2SentinelR1's service contracts — the only place where instruments sit next to a working engineer.A recorded corpus of observation and action: what was seen, what was done, and in what order.20%
R3miniFactoryR2's corpus — motion executed in a cell Elastic controls, before motion anywhere else.Making a part from raw stock, and the process control that makes it repeatable.4%
R4RoboticsR2's corpus to train kinematics and decision models, and R3's factory to build them.Acting on the corpus in the field, where nothing is held still for you.0.8%
R5ThinktankR1 through R4 — practice worth teaching, which cannot be taught before it is had.Transmission: one engineer's judgment, held by many.0.2%
AerospaceEvery rung above it.0%

§ 02 / First article in design

One machine, two bands, one shift, on one clock.

The first article is deliberately small: one machine on one Elastic service contract, two bands — the network the machine talks on and a thermal camera on the cabinet, because both are cheap, both are off a shelf, and neither touches the patient or the beam — one engineer, one shift. The engineer's narration from Service's wearable and the two instruments are written to a single time-stamped log. The output is a replay: what the machine was doing, what the engineer said and did, in order, to the second.

Anyone with the log can check whether the pairing holds — whether a reading and an action line up, or whether they are two files that happen to share a date. It waits on R1's first contract, which is the ladder working as drawn. This is not a deployment. It is a first article, and it is in design.

§ 03 / Falsifiers open questions

Four things would have to be true.

  1. The engineer must consent to being on record, and keep consenting. Loop B1 stated plainly. Scope, retention and who may replay what are design constraints, in a regulated room more than anywhere. An opt-out that is not real makes the corpus coerced and the recording stop. We would rather state that here than discover it at a customer site.
  2. Observation and action must land on one clock. If the instrument log and the engineer's narration cannot be aligned to the second, there is telemetry and there is a report, and no corpus. Loop B2 is this failure in slow motion.
  3. Off-the-shelf sensors must be good enough across the band. A thermal camera is a catalogue part. A detector that reads a treatment beam is not a webcam. If an instrument has to be invented, Sentinel has become a research program, and the master plan says we do not bill for discovery.
  4. The customer must allow instruments on their machine. A contract to keep a machine up is not a licence to instrument it. That is a clause a customer signs, not a feature we ship, and in a clinic it is a clause several people sign.

They are the four ways this design is wrong.

§ 04 / Status no solicitation

Forming — Sunnyvale, California

Elastic Engineering is forming in Sunnyvale, California. Sentinel has no instrument in the field, no contract to place one on, and no corpus. What exists is a design, its place in the ladder, and a plan for the first article. This sheet states an intent; it offers nothing and solicits nothing.

If part of it intersects a problem you own, open a conversation.

sam@elastic-engineering.com

End of sheet · EE-DOC-102 · Rev A · Sentinel is R2 of EE-DOC-001.