The operator had every record an auditor could ask for. They were in four systems that had never been introduced to each other, and answering one crossing question took days of spreadsheet archaeology.
A European bulk-liquid terminal operator ran a multi-site business on four systems that each held part of the truth: a CMMS for maintenance, gauging for tank data, spreadsheets and shift logs for HSSE, and a drawer of commercial contracts. Nothing was missing. Nothing was connected. Any question that crossed two systems became a research project measured in days.
This is not a story about bad operators or neglected records. The maintenance history was meticulous: eleven years of it, including 2,442 distinct recurring orders. The HSSE register went back roughly a decade. The contracts were signed, filed and current.
The problem was structural, and it is the same at nearly every terminal we have looked at since. Each system answers questions inside its own boundary very well. It is the questions that cross a boundary that have no owner:
Every one of those was answerable. Each one cost days.
The operator's systems were left exactly where they were. Nothing was replaced, nothing was migrated, and no one on the operations team changed how they work.
The point of joining the records is not the dashboard. It is the class of question that becomes cheap.
An audit or insurance question that previously meant assembling a case from four systems becomes a filter and an export, with the underlying records attached.
Contract expiries and counterparty concentration surfaced against the tanks and volumes they actually depend on, while there is still time to act, rather than at renewal.
Recurring maintenance patterns read against capacity and commitment, so the cost of deferring a job is visible as throughput, not just as an open ticket.
An HSSE event reconstructed alongside the maintenance state and tank activity around it, instead of as an isolated entry in a register.
Being precise about this matters more than the numbers above, and it is where most vendor case studies quietly overstate.
| Dimension | What is true |
|---|---|
| The data | Real. Live operational records from a working multi-site terminal business: maintenance, HSSE, tank and contract data, not a demo set or a simulation. |
| The engagement | A paid pilot and MVP. The platform was developed and validated against real terminal workflows rather than assumptions. |
| The build | Delivered. Commercial intelligence and portfolio analysis were built and handed over, along with the operational and evidence layers. |
| The relationship | Concluded. The commercial collaboration did not continue past the pilot. The platform is now licensed independently, and no client is named here or anywhere else. |
| The claim we do not make | We do not describe this as a multi-year production rollout, and we do not name the operator. Discretion is the arrangement; overstating the deployment would be the easier story and the wrong one. |
The reason to publish it at all is that the alternative, a platform with no demonstrable history, asks a terminal operator to take considerably more on faith.
Terminal operators do not publish their operational patterns, and neither do we. Volumes, incident rates and contract structures describe how a business runs and where it is exposed. That is not marketing material, and treating it as such would tell every future client exactly what to expect from us.
So the counts are here, the operator is not, and the platform itself is shown in private walkthroughs on representative data. How the data is handled →
Ingestion is measured in days, not months, because the layer reads the exports the CMMS already produces rather than requiring an integration project. The longer part is validation: deciding what a malformed eleven-year-old record should become, and confirming the totals reconcile against the source.
No, and you should be sceptical of anyone who suggests it. Your existing systems remain the systems of record throughout. The operational layer reads from them. If it were removed tomorrow, every source system would still be running exactly as it is.
They will be, and that is the normal starting condition. Eleven years of real operational data contains format changes, retired conventions and records entered by people who have since left. Handling that is part of the work rather than a precondition for starting it.
That is what the Shadow Pilot exists for: thirty days, historical exports only, nothing touching production, and you keep the findings whether or not you proceed. How the Shadow Pilot works →
Not a demo of our features: a walkthrough of how your own kind of question looks when the operation can testify for itself.