Skip to content

Part 5 of 7 · Cold chain monitor series ~5 min read

Who decides what happens to the stock

At the end of a breach somebody has to decide whether the stock is usable, and that is the one thing in this entire system that must not be automated, for reasons that are as much about accountability as about safety.

Key takeaways

  • The system presents the evidence; a named person decides and signs.
  • The decision record includes the chart, the duration, the product and the reasoning.
  • Record disposals and releases with equal care. A release is also a decision.
  • The inspection export is a document, not a dashboard login.
  • Count breaches by unit over time; the repeat offender is usually one appliance.

What the system hands over

The evidence pack for one breach

  • The chart: twelve hours either side, at full resolution, on sensor time.
  • The numbers: peak temperature, time out of range, time above each of the relevant thresholds.
  • What was in it: the stock in that unit at that time, if the system knows.
  • The alarm history: when it fired, when it was acknowledged, by whom.
  • Sensor status: last calibration, battery, whether a second sensor agreed.
  • No recommendation. Not even a colour-coded one.

The last line is deliberate and is the point of the post. A system that displays a green tick saying stock is fine has made a food safety judgement, and when that judgement is wrong there is nobody who made it. Presenting the same evidence with no verdict puts the decision where the responsibility already is.

The release is a decision too

Deciding that stock is fine after a breach is exactly as consequential as deciding to throw it away, and it is usually recorded far less carefully because nothing visible happens. That asymmetry is where problems hide.

So both outcomes produce the same record: who decided, when, on what evidence, and why. “Peak minus nine for eighteen minutes, product is a sealed frozen good with a documented tolerance, released” is a defensible sentence. Nothing at all is not.

The decision record

How a decision about stock after a temperature breach is recordedA vertical chain of five steps entered by a box labelled A breach has ended, evidence assembled. Step one identifies who is deciding, a named person. Step two shows them the pack with the chart, numbers and stock. Step three records the decision: dispose, release, or test; an unsure answer exits to Send for testing, described as a real third option. Step four records the reason in their words. Step five signs and closes it, append-only like everything else. A note says the third option exists because forcing a binary choice produces bad releases.AWS ACCOUNTA breach has endedevidence assembledWho is deciding?a named personThey see the packchart, numbers, stockDecisiondispose, release, or testSend for testinga real third optionunsureReason recordedin their wordsSigned and closedappend-only, like everythingThe third option exists because forcing a binary choice produces bad releases.
Fig 1. How a breach is closed out. Offering testing as an explicit third option removes the pressure that produces optimistic releases.
  • App integration
  • Security & identity
  • Analytics
  • People

In their words

The reason is free text and it should be, because the reasoning is specific to the product and the situation and a dropdown cannot hold it. It is also the part that is genuinely useful a year later, when the same question arises and somebody wants to know how it was handled last time.

The inspection export

What a cold chain inspection export containsA horizontal row of five boxes. An inspector asks for a date range. One document, not a login. Every reading, and every gap. Every breach, and its decision. Calibration records attached. A note says a dashboard is not a record, and a document with everything in it is.WHAT AN INSPECTION ACTUALLY NEEDSAn inspector asksfor a date rangeOne documentnot a loginEvery readingand every gapEvery breachand its decisionCalibration recordsattachedA dashboard is not a record. A document with everything in it is.
Fig 2. The export. Producing it as a single self-contained document rather than access to a system is what makes an inspection short.
  • Database
  • Machine learning
  • Security & identity
  • People

The gaps matter here more than anywhere else. An export showing continuous readings with silent holes in it invites the question of what was happening during them; one that shows explicit gap records with their duration answers the question before it is asked.

The repeat offender

Counting breaches per unit over a year almost always produces the same finding: one appliance accounts for a large share of them. It is old, or it is in a warm corner, or its door seal has been marginal for two years.

That is a maintenance or replacement decision with a number attached, and it is invisible when breaches are handled individually. “This unit has breached fourteen times this year and the others have breached three times between them” is the sentence that gets a replacement approved.

What this system does not do

It does not judge stock, it does not silence its own alarms, it does not edit its records, and it does not stop escalating because it is late. Each of those absences is a feature somebody will eventually ask for, and each of them would convert a record that can be relied on into one that cannot.

Next: what all of this costs to run.

All posts