Personnel accountability and custody on an air-gapped network.
A defence systems integrator needed accountability and controlled-item custody with no internet dependency.
Case studies and programme figures on this page are composite worked examples — patterns from comparable deployments, not attributed results for a named client. Named references are available under NDA when you engage.
What they were up against.
Manual accountability
Mustering and personnel accountability were manual and slow.
Custody had no audit trail
Controlled-item custody lacked a sealed, defensible audit trail.
No internet allowed
The solution had to run fully air-gapped on sovereign infrastructure.
Composite worked example — figures are ranges from comparable programmes, not attributed named-client results. Named references available under NDA. We model your own numbers when you engage.
Vendor-neutral, tied to a named KPI.
We delivered personnel accountability, controlled-item chain-of-custody and automated mustering on an air-gapped RF network, designed to IEC 62443 with full audit logging.
What we delivered.
- Personnel accountability and automated mustering
- Controlled-item chain-of-custody, store to field
- Air-gapped, on-premise deployment
The typical range for a programme of this shape.
The stack behind it
Baseline, method, period — and what we excluded.
These pages are composite worked examples, not named-client scorecards. Figures are ranges from comparable RTLS/RFID programmes and published industry sources where noted.
- Baseline: Personnel and kit accountability by radio net and paper musters.
- Method: Geofenced accountability with muster time-to-verified; custody events on controlled items; air-gap where mandated.
- Period: Exercise cycle on a secure compound.
- Excluded: Commercial office badge analogies.
Programme pattern for this vertical
Defence accountability programmes emphasise rapid audit of controlled items across secure zones with strict access roles and often on-prem platforms.
Export control and classification overlays shape architecture more than radio choice.
Outcomes to expect — and how they are earned
Outcomes: audit time collapse, high inventory accuracy, fewer write-offs.
Lessons from comparable programmes
Lessons: no commercial office badge analogies; segment networks; document chain of custody for classified adjacent items.
Deeper problem framing
Controlled-item audits consume days. Commercial badge analogies under-specify security.
Approach
On-prem options; strict roles; secure zones; rapid audit queries; export-control awareness.
Outcomes and measurement
Audit hours, inventory accuracy, write-off trends.
Governance, risk and what we refuse to claim
Composite example only. Your payback depends on adoption, integration quality and exception labour — not tag unit cost. Named references under NDA on engagement.
We challenge any vendor who asks you to accept demo-day averages as production truth.
Implementation sequence and change management
Classify data; choose on-prem/sovereign; role matrices; secure zone RF; rapid audit query design. No commercial badge shortcuts.
KPIs: audit hours, accuracy, write-offs.
Buyer checklist, vendor challenges and engagement shape
For defence accountability, resolve on-prem/sovereign and role matrices before any commercial SaaS assumption.
Buyer checklist before you sign: (1) written system of record for events; (2) acceptance tests with 95th-percentile performance under real interference; (3) integration owner named in IT/OT; (4) privacy or labour consultation path if people are tagged; (5) cybersecurity zoning sketch; (6) five-year TCO including batteries, spares, recalibration and SLA escalations; (7) exit/export terms so you are not hostage to a cloud tenant; (8) a pilot that can fail without political punishment.
Vendor claims to challenge in this pattern: brochure accuracy without production load; 'compliance included' without artefacts; ROI that assumes perfect adoption in 30 days; references that cannot be called under NDA; install partners who have never worked your vertical's overlays; shared support accounts; and any design that dumps locating onto a flat plant or clinical VLAN.
How TRACIO typically engages: stage-1 architecture and measurement design; vendor-neutral shortlist and RFP language; pilot acceptance criteria; then optional implementation oversight or programme rescue if a prior pilot stalled. We stay independent of hardware margin. Composite pages like this one exist so you can prepare the workshop — your numbers replace every planning band when we model payback.
Risk register themes that recur: mute fatigue on alerts; shadow spreadsheets reappearing beside the platform; battery logistics understaffed; master data too weak to support identity; works-council or IG review starting too late; and success declared on demo day before night-shift reality.
Document baseline windows explicitly: what you measured, for how long, which shifts, and what you excluded. Investment committees and auditors both punish fuzzy before/after stories. If your baseline is weak, spend two to four weeks fixing measurement before ordering anchors or portals. That discipline is cheaper than a stranded deployment and is the difference between a locating programme and a technology souvenir.
Training and communications plan: who explains purpose to operators, how often refreshers run, how contractors are inducted, and how successes are fed back without turning safety systems into league tables. Budget a champion network on each shift. Platforms do not adopt themselves. Where unions or works councils exist, share the purpose statement and retention rules early — surprise monitoring is how programmes die. Finally, schedule a formal gate review against the written criteria; celebrate a no-go if evidence is weak. Expanding failure is not delivery.
Governance, risk and what we refuse to claim
Composite example only. Your payback depends on adoption, integration quality and exception labour — not tag unit cost. Named references under NDA on engagement.
We challenge any vendor who asks you to accept demo-day averages as production truth.
Buyer checklist, vendor challenges and engagement shape
For defence accountability, resolve on-prem/sovereign and role matrices before any commercial SaaS assumption.
Buyer checklist before you sign: (1) written system of record for events; (2) acceptance tests with 95th-percentile performance under real interference; (3) integration owner named in IT/OT; (4) privacy or labour consultation path if people are tagged; (5) cybersecurity zoning sketch; (6) five-year TCO including batteries, spares, recalibration and SLA escalations; (7) exit/export terms so you are not hostage to a cloud tenant; (8) a pilot that can fail without political punishment.
Vendor claims to challenge in this pattern: brochure accuracy without production load; 'compliance included' without artefacts; ROI that assumes perfect adoption in 30 days; references that cannot be called under NDA; install partners who have never worked your vertical's overlays; shared support accounts; and any design that dumps locating onto a flat plant or clinical VLAN.
How TRACIO typically engages: stage-1 architecture and measurement design; vendor-neutral shortlist and RFP language; pilot acceptance criteria; then optional implementation oversight or programme rescue if a prior pilot stalled. We stay independent of hardware margin. Composite pages like this one exist so you can prepare the workshop — your numbers replace every planning band when we model payback.
Risk register themes that recur: mute fatigue on alerts; shadow spreadsheets reappearing beside the platform; battery logistics understaffed; master data too weak to support identity; works-council or IG review starting too late; and success declared on demo day before night-shift reality.
Document baseline windows explicitly: what you measured, for how long, which shifts, and what you excluded. Investment committees and auditors both punish fuzzy before/after stories. If your baseline is weak, spend two to four weeks fixing measurement before ordering anchors or portals. That discipline is cheaper than a stranded deployment and is the difference between a locating programme and a technology souvenir.
Training and communications plan: who explains purpose to operators, how often refreshers run, how contractors are inducted, and how successes are fed back without turning safety systems into league tables. Budget a champion network on each shift. Platforms do not adopt themselves. Where unions or works councils exist, share the purpose statement and retention rules early — surprise monitoring is how programmes die. Finally, schedule a formal gate review against the written criteria; celebrate a no-go if evidence is weak. Expanding failure is not delivery.
Last updated:
Mission constraints first
Independent advisory means the radio is chosen last — after the job, the constraints and the system of record are clear.
Air-gap and clearance are requirements
Discovery treats network, accreditation and custody as hard gates, not afterthoughts.
No reseller bias under pressure
When timelines compress, independence is what stops the default vendor winning by default.
Evidence the board and auditor can read
Measurement method agreed up front so readiness claims survive scrutiny.
Measurement
Baseline: accountability drill times, serialized-part audit gaps, and “unable to locate” tickets. Pilot: one unit/area with identity + location reconciled to the approved system of record. Steady-state: muster/accountability completion, custody exceptions, and audit findings. Only programme-type ranges are published; classified detail stays offline.