Architecture 29 — Facility, Power Quality & Environmental Monitoring Fabric

Reference Architecture Diagram + Narrative (BMS/EPMS + PQ analytics + remediation loops)

                          ┌──────────────────────────────────────────────┐
                          │        FACILITY EQUIPMENT & SENSORS          │
  Utility mains │ UPS/STS/Generators │ PDUs/RPDU │ Panels/Breakers │ HVAC │
  PQ analyzers (THD/TDD, sags/swells, flicker, transients) │ Temp/RH │ Leak │ Vibration
                          └───────────────┬───────────────┬───────────────┘
                                          │               │
                                          ▼               ▼
                ┌─────────────────────────────────────────────────────────┐
                │     FIELD GATEWAYS / EPMS-BMS EDGE (OT side)           │
                │  • Proto: Modbus/TCP, BACnet/IP, SNMP, IEC 61850       │
                │  • Local rules: rate-limit, unit normalize, sign data  │
                │  • Store-and-forward cache (checksum, ordering)        │
                └──────────────┬──────────────────────────┬──────────────┘
                               │                          │
                 Private LAN (OT) / SegGW                 │  LP/Out-of-band (dial-out DR)
                               ▼                          ▼
          ┌────────────────────────────────────────────────────────────────┐
          │         TRANSPORT / SECURITY FABRIC (northbound)               │
          │  SD-WAN to DC/Colo/Cloud  ║  SASE/SSE POP (ZTNA/SWG/CASB/FWaaS)│
          │  VLAN/VRF: OT │ IT │ Vendors  •  PAM/JIT windows for service   │
          └───────────────┬───────────────────────────┬────────────────────┘
                          │                           │
                          ▼                           ▼
   ┌────────────────────────────────────┐     ┌─────────────────────────────────────┐
   │   EPMS / BMS CORES (DC/Colo)       │     │  CLOUD ANALYTICS & DATA LAKE        │
   │ • PQ DB (5/10/60-cycle windows)    │     │ • PQ models (harmonics, flicker)    │
   │ • Events: sag/swell, transients    │     │ • Forecasts, anomaly, battery SOC   │
   │ • Dashboards: load, PUE, capacity  │     │ • FinOps/Carbon overlays            │
   └──────────────┬─────────────────────┘     └───────────────┬────────────────────┘
                  │                                           │
                  ▼                                           ▼
   ┌────────────────────────────────────┐       ┌───────────────────────────────────┐
   │  REMEDIATION / CONTROL LOOPS       │       │  ALERTING, EVIDENCE & REPORTING   │
   │ • PQ filters/active harmonics      │       │ • ITSM tickets • GRC/WORM packs   │
   │ • Load rebalancing (phase/feeder)  │       │ • Compliance (NERC/OSHA/ISO)      │
   │ • UPS setpoints / genset tests     │       │ • Energy/Carbon reports (PUE, kWh)│
   └────────────────────────────────────┘       └───────────────────────────────────┘

  Telemetry & Ops ──► AIOps (THD drift, hot-spots) • SIEM/SOAR (OT events) • ITSM/CMDB • Digital-twin views

Narrative (how facilities speak clearly to IT, finance, and safety)

1) Purpose & posture

  • Objective: Make power, cooling, and environment measurable, predictable, and correctable—from mains to rack—so IT uptime, safety, and cost/carbon targets are met.
  • Posture: OT/IT segmentation, identity-gated vendor access (PAM/JIT), signed telemetry, and evidence-ready reporting.

2) Edge & protocols (syntax at the plant floor)

  • Gateways ingest Modbus/TCP, BACnet/IP, SNMP, IEC-61850 from PQ meters, UPS/STS, gensets, PDUs, CRAC/CRAH, sensors (temp/RH/leak/vibration).
  • Normalize units (kW/kVA/A/V/Hz), timestamp to utility-grade resolution, rate-limit and sign payloads; buffer with store-and-forward during outages.

3) Secure transport (semantics preserved to core/cloud)

  • SD-WAN uplinks into SASE/SSE: ZTNA per role (facility ops, vendor), FWaaS/DLP on IT flows; vendor access only via PAM/JIT, recorded.
  • VRFs/VLANs keep OT isolated from IT and guest networks; northbound traffic pinned to approved regions.

4) Processing layers (where meaning aggregates)

  • EPMS/BMS cores compute PQ windows (5/10/60-cycle), detect sags/swells, flicker, transients, imbalance, neutral current, and track PUE, load, capacity.
  • Cloud analytics/lake runs harmonic decomposition, trend and forecast (batteries, fuel, filter life), and correlates with IT loads and work orders.

5) Closed-loop remediation (grammar in action)

  • Active harmonic filters / tuned reactorsengaged automatically or via approval when THD/TDD exceeds thresholds.
  • Feeder/phase rebalancingrecommendations (and change tickets).
  • UPS/gensettest orchestration; cooling setpoint optimization tied to rack inlet telemetry.

6) Operations, compliance & evidence (pragmatics)

  • AIOpshighlights drift (rising THD, transformer heat), hot-aisle risks, and fuel/battery health; opens ITSM tickets with runbooks.
  • SIEM/SOARwatches OT events (unexpected breaker ops, tamper); playbooks isolate vendor session, lock gateway, notify HSE.
  • GRC/WORMstores PQ incidents, maintenance, test proofs, and regulatory packs (NERC, OSHA, ISO 50001).

7) Reference KPIs (facility-grade)

  • THD (voltage/current)≤5% / ≤15% (site policy)
  • Sags/swells0 critical events impacting IT (class per IEEE 1159)
  • PUEtrend ↓; Hot-spot response time: <15 min
  • Vendor session coverage (recorded)100%
  • Evidence retrieval<5 min (incident/test report)

8) Minimal BOM (aligned to the fabric)

PQ meters/analyzers; Gateways (Modbus/BACnet/61850/SNMP); Sensors (temp/RH/leak/vibration); SD-WAN/Segmentation; SASE/SSE (ZTNA/FWaaS); PAM/JIT; EPMS/BMS; Cloud analytics/lake; AIOps; SIEM/SOAR; ITSM/CMDB; Active harmonic filters/Reactors; UPS/STS/genset integration; WORM/GRC reporting.


Key terms in plain language

Open a term for a concise explanation of language used on this page.

SD-WAN

Software-defined wide area networking. It manages multiple connections and chooses paths based on application needs, performance, and policy to improve resilience and control.

SASE

Secure Access Service Edge combines networking and security capabilities in a cloud-delivered architecture so users and locations can receive consistent policy wherever they connect.

Cloud Computing

Computing resources—such as applications, servers, storage, or databases—delivered from remote infrastructure and scaled as requirements change.

Infrastructure as a Service (IaaS)

Cloud-based servers, storage, and networking that customers configure and manage without owning the underlying data-center hardware.

Software as a Service (SaaS)

Software accessed as an online service instead of being installed and maintained entirely on the customer’s own computers or servers.

Disaster Recovery (DRaaS)

A plan and service for restoring applications, data, and operations after an outage or disruption. DRaaS provides recovery infrastructure through a managed cloud service.