SENTINEL EAC-1 — Evidence-Gated Energy Assurance Controller
An emerging IYABOKO energy-assurance technology designed to transform BESS and distributed-energy telemetry into qualified evidence, independent risk assessment, uncertainty-aware runtime assurance and governed operator decision support.
Energy systems can have extensive data without having enough trustworthy evidence to justify the next action.
A BMS, EMS or SCADA system may provide measurements, alarms and predictive indicators. EAC-1 investigates an additional assurance question: should operational authority depend not only on estimated physical risk, but also on the integrity, sufficiency and agreement of the evidence supporting that assessment?
Sensor evidence can degrade.
Measurements can become stale, implausible, inconsistent, unavailable or poorly contextualised. A risk estimate should not automatically be trusted when its supporting evidence has degraded.
Predictive systems can disagree.
An anomaly detector may indicate elevated risk while deterministic engineering rules remain normal, or the opposite. EAC-1 preserves that disagreement rather than hiding it.
Risk does not equal authority.
Knowing that something may be wrong is different from establishing which operational response is presently justified, especially in high-consequence energy systems.
Separate the estimated physical state from the authority to respond.
The present research architecture treats physical-risk assessment and action authority as related but distinct system states.
Candidate technical hypothesis
The level of operational action authority justified by a system may change in response to evidence integrity, predictive uncertainty, context or analytical disagreement even when the estimated physical-risk state does not materially change.
From telemetry to a governed assurance record.
The current Alpha/P4 architecture maintains independent evidence, engineering, predictive and authority stages before an operator-facing recommendation is recorded.
Keep deterministic protection available even if intelligent analytics fail.
The longer-term hardware architecture separates deterministic safety logic from more computationally intensive predictive and evidence-processing functions.
Deterministic Safety Controller
Intended functions include signal acquisition, watchdogs, deterministic constraints, sensor plausibility, communications supervision, authority enforcement and fail-safe state management.
- Independent watchdog behaviour
- Deterministic engineering constraints
- Sensor plausibility and health
- Communication supervision
- Authority enforcement
- Fail-safe handling
Intelligent Edge Assurance
Intended functions include anomaly analysis, time-series processing, predictive risk, uncertainty, evidence management, dashboards and fleet integration.
- Predictive / anomaly models
- Digital-twin analysis
- Evidence sufficiency
- Uncertainty calculation
- Operator console
- Fleet / enterprise interface
Use EAC-prefixed authority classes to avoid confusion with organisational governance authority.
IYABOKO governance authority uses G-A0…G-A4. EAC-1 physical/runtime authority uses a separate EAC namespace. The two should never be inferred from one another.
The candidate architecture has been implemented as executable software.
The current Alpha includes simulation, evidence qualification, deterministic assessment, predictive assessment, concordance, runtime authority, command gating and a hash-linked evidence ledger.
Evidence Processor
Converts telemetry into qualified evidence with sufficiency and integrity information.
Dual Risk Analysis
Deterministic and predictive states remain separately observable.
Authority Gate
Requested actions are evaluated against the current runtime authority envelope.
Hash-Linked Ledger
Assurance records connect evidence, risk states, authority and gate outcome.
Thirteen controlled scenarios test the current Alpha behaviour.
These are internal software-verification scenarios. They do not constitute field validation or certification.
| Scenario | Condition | Deterministic | Predictive | Evidence | Authority | Gate result |
|---|---|---|---|---|---|---|
| SIM-001 | Normal operation | NORMAL | NORMAL | 1.000 | EAC-A0 | PERMITTED |
| SIM-002 | Thermal rise | WATCH | WATCH | 1.000 | EAC-A2 | PERMITTED |
| SIM-003 | Hard limit | CRITICAL | WARNING | Qualified | EAC-A3 | Protective request permitted in simulation |
| SIM-004 | Predictive false positive | NORMAL | WARNING | Qualified | EAC-A2 | Protective shutdown blocked |
| SIM-005 | Faulty temperature sensor | WATCH | WATCH | 0.475 | EAC-AH | Automatic reduction blocked |
| SIM-006 | Corroborated abnormal temperature | WARNING | WARNING | 1.000 | EAC-A2 | Permitted |
| SIM-007 | Cloud loss | WATCH | WATCH | 1.000 | EAC-A2 | Local assurance remains available |
| SIM-008 | Predictor unavailable | WATCH | UNKNOWN | 1.000 | EAC-A1 | Automatic reduction blocked |
| SIM-009 | Analytical disagreement | WARNING | NORMAL | 1.000 | EAC-A1 | Protective shutdown blocked |
| SIM-010 | Stale telemetry | WATCH | WATCH | 0.450 | EAC-AH | Automatic request blocked |
| SIM-011 | Command outside authority | WATCH | WATCH | 1.000 | EAC-A2 | OPEN_MAIN_CONTACTOR blocked |
| SIM-012A | Same risk · high evidence | WATCH | WATCH | 1.000 | EAC-A2 | REDUCE_POWER permitted |
| SIM-012B | Same risk · degraded evidence | WATCH | WATCH | 0.475 | EAC-AH | REDUCE_POWER blocked |
SIM-012 asks the central EAC-1 question.
Can the same simulated physical-risk state legitimately produce different action authority because the quality of the supporting evidence is different?
Same physical risk — qualified evidence
Same physical risk — evidence integrity degraded
P4 · SENTINEL EAC-1 Pilot Site 001
IYABOKO is seeking one Australian battery, microgrid, energy laboratory or renewable-energy integration partner for the first controlled real-world validation deployment.
Read-only BESS assurance overlay
The P4 architecture receives authorised live telemetry without creating a control path back into the battery system. The existing certified or site-approved BMS, protection systems and operating procedures remain primary.
Real plant data in. No live control out.
P4 is intentionally non-invasive so the first real-world evidence can be collected without asking a pilot partner to hand operational control to an unvalidated system.
The P4 pilot should answer measurable questions.
The goal is not simply to run EAC-1 beside a battery. The pilot should determine where the architecture succeeds, where it fails and what evidence is required before any higher-authority stage.
Telemetry Availability
Measure data availability, freshness, channel quality and mapping completeness.
Traceability
Can every material advisory state be reconstructed from its supporting telemetry, rules, models and evidence status?
Gate Violations
Target zero execution of prohibited actions within the read-only P4 environment.
Event Performance
Measure relevant detection, false-positive, false-negative, uncertainty and disagreement behaviour.
Failure Behaviour
Observe stale telemetry, model failure, communication loss and analytical disagreement.
Event Reconstruction
Replay selected site events and compare the reproduced assurance state with the original record.
What is demonstrated — and what remains to be established.
IYABOKO deliberately separates internal verification, demonstration evidence, pilot evidence, external review and certification.
Alpha architecture
Executable software for evidence, dual analysis, authority and gating.
Frozen scenarios
13 controlled scenarios including SIM-012A/B.
P4 read-only gateway
Prototype telemetry-processing and control-disabled architecture.
Real BESS field pilot
Not yet completed. Pilot Site 001 is the next commercial milestone.
Independent validation
University, research-laboratory or qualified engineering evaluation remains required.
Product certification
Relevant product, electrical, cybersecurity and functional-safety assessment remains future work.
Autonomous high-energy control
Not enabled in P4 and not presented as a current commercial capability.
Fleet / OEM deployment
Requires successful field evidence, engineering maturation and commercial integration.
Protect the candidate invention without overstating patent status.
The public EAC-1 page should explain the engineering proposition without publishing unnecessary claim detail, evidence-scoring weights or trade-secret implementation logic.
Candidate Claim Architecture
Evidence-dependent action authority, qualified evidence objects, separate risk and authority states, and physical enforcement are candidate areas for professional patent review.
Scoring & Calibration
Detailed evidence weighting, calibration logic, model tuning and operational thresholds should not be unnecessarily published.
Copyright & Versioning
Source code, documentation, simulation assets and evidence records should retain version and ownership controls.
Three partner types can move EAC-1 forward.
Research validation, real-world pilot evidence and commercial integration are distinct relationships. They should not be bundled into one ambiguous partnership.
Independent Validation Partner
University, battery research centre, laboratory or qualified engineering group to challenge methodology, reproduce experiments, test failure behaviour and identify unsupported claims.
Pilot Site 001 Partner
BESS owner, microgrid, energy laboratory or integrator willing to provide a controlled read-only telemetry environment under agreed scope and responsibilities.
Integration / OEM Partner
Future engineering or technology partner for industrialisation, protocol integration, hardware maturation, deployment, manufacturing or licensing after validation.
Increase evidence before increasing control authority.
The commercial pathway deliberately places real-world read-only evidence ahead of live high-energy control.
Become SENTINEL EAC-1 Pilot Site 001 or an independent validation partner.
IYABOKO is seeking one Australian BESS, microgrid, energy laboratory or renewable-energy integration partner for the first controlled real-world P4 deployment, along with an appropriate research or engineering partner for independent technical evaluation.