Each of these is answerable at any well-run terminal today. Each currently costs days. What they have in common is that the answer lives across a boundary no one system spans.
"Walk me through what happened that night."
Why it is hard. The HSSE register holds the event. It does not hold what else was true at the time: which work orders were open on the affected asset, what the tank was doing in the hours around it, what the previous shift handed over, whether a related deviation had been raised before. Assembling that means four systems and a person who remembers where to look.
What changes. The event and its surroundings sit in one governed timeline, so a reconstruction is a filter rather than a research project, and the source records travel with it as evidence. Under NIS2's 24-hour early-warning deadline this stops being a convenience and becomes a statutory constraint.
"Which contracts are inside their notice window, and what does each one actually depend on?"
Why it is hard. A contract register gives you dates. It does not tell you which tanks serve that counterparty, what condition those assets are in, or how concentrated your revenue is across a handful of names. The exposure is the combination, and nothing holds the combination.
What changes. Expiries surface against the volume and the assets they depend on, early enough to act rather than at renewal. Counterparty concentration becomes a number somebody can be asked about in a board meeting.
"Show me the corrective actions from last year's findings, and prove they closed."
Why it is hard. Findings are raised in one place and executed in another. Closure evidence rarely travels back to the finding it answers. The records exist; what is missing is the thread between them, and the thread is what the auditor is testing.
What changes. Evidence assembly becomes a filter and an export with the underlying records attached, rather than a week of assembly during which the auditor is forming a view about your record-keeping.
"Which deferred work is capping throughput on a tank we have committed?"
Why it is hard. Maintenance knows the work order. It does not know the contract. So deferral looks like an open ticket rather than what it usually is: a decision with a revenue consequence nobody has priced.
What changes. Recurring work-order patterns read against capacity and against commitment, so the cost of deferring shows up as throughput rather than as backlog. Over a multi-year history the recurring failures also become visible as patterns rather than as individual events.
"Why does this site run differently from that one?"
Why it is hard. Two sites rarely name things the same way. One calls it a work order, another a job card. Gauging vendors disagree about what a level, an observed volume and a net standard volume are. Until those become one vocabulary, cross-site comparison is guesswork presented confidently.
What changes. Vendor terms map to one model at ingestion, so utilisation, incident rates and maintenance load are genuinely comparable. For a group operating several terminals this is usually the first question the board asks and the last one the systems can answer.
"Does what we invoiced match what the tanks actually did?"
Why it is hard. The commercial system and the gauging system were never designed to agree, and reconciling them is manual, monthly and late. By the time a discrepancy surfaces the period is closed.
What changes. Movements reconcile continuously against what the tank measurements imply, and the discrepancy is surfaced rather than silently resolved. The gap is the finding: it points at measurement error, unrecorded movement, or revenue quietly leaking.
All six are the same problem wearing different clothes. Each system answers questions inside its own boundary well. Nobody owns the questions that cross a boundary, and those are the ones an auditor, an insurer or a board actually asks.
Pick whichever of the six is worst at your operation. The Shadow Pilot answers it against your own historical exports in thirty days, without touching production.