Skip to main content

AUTO-SYS-014 / VERGE MOBILITY SYSTEMS

The plant and software teams finally shared a boundary

Four plants and nine suppliers aligned physical behavior, software changes, and release authority to one boundary contract.

Verge Mobility Systems

Multiple suppliers delivered technically valid components, but field behavior depended on undocumented timing, configuration, and recovery assumptions across boundaries.

4 plants · 9 strategic suppliers · 2022 · 10 months · 7-person delivery team

The problem beneath the brief

Each team could prove its component. No one could prove the integrated operating state or identify who could accept a boundary change.

4
plants alignedaccepted operating-boundary register
9
strategic suppliers integratedsupplier and interface authority matrix
17
boundary contractsaccepted integration package
11
failure scenarios rehearsedintegrated test evidence

Risk constraints

What could not be traded away.

  • line availability
  • physical safety
  • supplier change control
  • configuration traceability
  • degraded-mode recovery

Findings

What inspection changed.

  • the enterprise retry policy conflicted with controller timing
  • two test stations used different configuration baselines
  • remote support access bypassed the plant's intended approval path

Named team and role pattern

The people attached to this engagement.

  • Adrian Cole · senior delivery lead
  • controls engineer
  • embedded software lead
  • integration architect
  • infrastructure engineer
  • quality lead
  • plant operations owner

Architecture

The operating system we installed.

  1. 01boundary and signal contractsconfiguration attestation
  2. 02configuration authoritysupplier change record
  3. 03plant/enterprise event bridgeremote-access approval
  4. 04release evidence modelintegrated failure tests
  5. 05degraded-mode workflowrelease authority matrix

Delivery sequence

Four phases. Evidence at every gate.

  1. 01

    Frame

    Define the decision, outcome, work products, authority, dependencies, exclusions, and acceptance evidence.

    A named sponsor and principal approve the bounded charter.
  2. 02

    Assemble

    Inspect the operating reality, then assemble named specialists, context, access, controls, and a delivery plan around the actual work.

    The client approves the named team, evidence plan, role boundaries, and stop conditions.
  3. 03

    Govern

    Build and operate the smallest coherent change with versioned decisions, quality evidence, escalation, and acceptance attached.

    The integrated state meets the agreed evidence threshold and every material exception has an owner.
  4. 04

    Transfer

    Rehearse recovery, resolve exceptions, accept the work, remove temporary access, and transfer operating ownership.

    The receiving owner signs the handoff with open limits visible.

Complications

Where the plan had to become more honest.

  • A retry that improved enterprise reliability could saturate a controller during recovery.
  • One supplier could not reproduce the plant configuration without a shared baseline.

Outcomes

What changed—and what the record proves.

  • Plant, supplier, and enterprise teams accepted one boundary contract.
  • Integrated tests reproduced the highest-risk timing and recovery failures.
  • Remote support access moved through a named plant approval and expiry path.

Lessons

What we would carry into the next system.

  • Component acceptance is not system acceptance.
  • Configuration is part of the architecture.
  • Recovery behavior must be designed across physical and software timing.
The contract exposed the timing and recovery assumptions that component testing had never forced us to reconcile.
Vice president, manufacturing systems · Verge Mobility Systems

Handoff

The engagement ended with an operating owner.

  1. 01boundary-contract ownership
  2. 02configuration release process
  3. 03supplier escalation
  4. 04degraded-mode runbook
  5. 05quarterly integrated rehearsal

Start with the decision

Bring the priority. We will help bound the work.

If the decisions or constraints look familiar, start with the operating reality—not a preselected solution.

Start a conversation.