Skip to content
How IOC Works: From Request to Governed Physical Result | IOC
How IOC Works

The smart building can be commanded. The participating building can answer.

IOC gives each physical responsibility enough identity, authority, local truth, continuity, restoration, and proof to participate safely.

A building is not one load. Lighting, irrigation, ventilation, charging, pumps, access, and recovery paths serve different purposes and carry different limits. IOC places a common operating grammar at those physical boundaries so each responsibility can answer according to what it is, what it serves, and what is lawful now.

Connection is not coherenceA message can arrive without carrying physical meaning.

Reachability alone does not establish served purpose, authority, safe limits, or restoration.

Control is not governanceA command can execute without being locally lawful.

The receiving boundary still needs to evaluate present truth and decide what participation is permitted.

Action is not completionThe event is unfinished until continuity, restoration, and proof are closed.

IOC carries the return path inside the operating relationship rather than treating it as an afterthought.

The canonical public sequence

Five movements carry a physical responsibility from identity to proof.

The public sequence is simple enough to follow and deep enough to preserve the architecture. Each movement contains more detailed rules, but the operating path remains the same across lighting, irrigation, ventilation, charging, pumps, recovery, and other physical responsibilities.

1

Identify

Know which physical responsibility exists, where it belongs, what it serves, and which history follows it.

Persistent boundary identity, served purpose, place, and continuity.
2

Govern

Place authority, present condition, dynamic criticality, safe limits, timing, and restoration obligations.

The wider condition is heard without automatically becoming physical permission.
3

Answer

Act, reduce, delay, partially participate, monitor, recover, offer an alternative, or refuse with cause.

The answer returns truthful capability instead of blind obedience.
4

Continue + Restore

Preserve lawful local behavior through communication loss and carry the ordered return path inside the event.

Offline continuity and restoration are part of the architecture, not emergency patches.
5

Prove

Record what happened, why, for how long, what restored, and what physical or operational value followed.

Evidence closes the event and earns the next boundary.
IOC gives ordinary building demand a way to answer—not only be commanded.
One governed operating event

One condition reaches the building. Each responsibility answers according to local truth.

The higher layer expresses the objective. The participating building translates it into differentiated physical answers without erasing purpose, protection, refusal, continuity, or restoration.

01 · ConditionA bounded objective reaches the building.
02 · EvaluationEach boundary checks identity, authority, condition, and limits.
03 · AnswerResponsibilities act, limit, delay, recover, monitor, or refuse.
04 · ClosureLocal continuity, ordered restoration, and proof complete the event.
The condition

The portfolio approaches an afternoon demand target.

The higher layer can express the objective, timing, requested magnitude, fallback, and proof requirement. It does not need to become the minute-by-minute source of physical continuity.

Bounded requestReduce eligible demand for 45 minutes, then restore in order.
Garage lightingParticipates

Stages down within a protected visibility floor and reports the resulting state.

VentilationAnswers conditionally

Offers bounded capability only while contaminant, equipment, and local safety conditions remain inside the approved envelope.

EV chargingDelays and recovers

Pauses eligible sessions, preserves deadlines, and returns through a sequenced recovery plan.

Access controlRefuses

Remains protected because security and continuity make the requested reduction ineligible.

IrrigationHolds its own time

Retains its local schedule and any temporary rain or owner hold rather than inheriting an unrelated electrical command.

Building memoryProves completion

Records action, limitation, refusal, duration, ordered restoration, and the evidence available from each boundary.

Composite operating illustration. It demonstrates how one grammar can govern unlike responsibilities; it does not assert that every embodiment shown has already been deployed together at one site.

Same IOC grammar · different physical interfaces

IOC changes form to meet the responsibility—not the other way around.

A lighting circuit, a frozen gateway, and a six-zone irrigation controller do not need the same terminals or enclosure. They do need the same coherent operating relationship: identity, authority, local evaluation, continuity, restoration, and proof.

The node is the local carrier of one governed responsibility.

The physical interface changes with the circuit, plug load, controller, valve group, sensor, or support device. The common grammar keeps unlike forms coherent inside one building and portfolio record.

Identity + served purposeKnow what physical duty this instance is carrying and where it belongs.
Local authority + evaluationCheck present truth, timing, limits, and permission before physical action.
Continuity + restorationKeep the assigned local behavior and carry the return path through interruption.
Evidence + service historyReturn what acted, refused, recovered, restored, or remained unresolved.
Polished IOC hardwired retrofit node shown beside existing building electrical equipment
Hardwired circuit interface

Lighting and suitable panel-served responsibilities

The circuit-level form is added beside existing infrastructure to observe, schedule, stage, limit, monitor, continue locally, restore, and return evidence.

  • Garage, hallway, parking, pole, and exterior lighting
  • Selected pumps, heaters, chargers, and other approved paths
  • Single-channel or application-specific hardwired forms
Connection method, ratings, protection, enclosure, certification, and qualified trade scope depend on the approved application and site.
IOC plug-load reset and recovery node for supported routers gateways readers intercoms and controllers
Plug-load / recovery interface

Supported equipment that freezes, disappears, or needs a controlled restart

The recovery form sits inline with selected equipment and carries a bounded interruption, cooldown, return, verification, and escalation path instead of treating reset as an unrecorded manual act.

  • Routers, gateways, readers, intercoms, and controllers
  • Remote recovery before another avoidable site visit
  • Reset limits, recovery verification, and repeated-fault evidence
A recovery node does not make every device interruptible. Eligibility, timing, protected state, and restoration behavior remain application-specific.
IOC irrigation architecture with cellular gateway and modular six-zone local scheduling nodes
Controller / multi-zone interface

Irrigation nodes with complete local six-zone schedules

The irrigation form changes the output interface, not the governing logic. Each six-zone node stores and executes its own full schedule locally while the gateway routes updates, visibility, and portfolio coordination.

  • Six independently identified valve or zone responsibilities per node
  • Local schedules continue when internet or gateway communication is unavailable
  • Additional six-zone nodes expand the property without one central scheduler becoming a single point of failure
Rain Action and additional water-intelligence functions remain separately maturity-labeled; the local scheduling and modular node architecture are the foundation.

The boundary is not the box—and IOC is not one box. Hardware forms, manufacturers, communications, and interfaces may change while the responsibility’s identity, purpose, authority, limits, restoration obligations, evidence lineage, and service history continue. This is how unlike systems become coherent without being flattened into identical devices.

When communication disappears

The participating building remains lawful when the network is imperfect.

Connectivity expands coordination and visibility. It should not become the sole source of safe physical behavior. The local boundary keeps the rules required to continue and restore.

A commissioned local copy remains available

Purpose, schedules, protected states, limits, holds, reset rules, and home-state behavior remain available at the operating point where the application requires them.

Out-of-bounds action remains blocked

The node can still recognize that a request falls outside authority, timing, present condition, or the approved operating envelope.

The responsibility continues

Lighting, irrigation, monitoring, recovery, or another local path follows its assigned continuity behavior rather than waiting helplessly for the cloud.

Restoration and records complete later

The boundary returns through the assigned sequence and synchronizes state changes, refusals, anomalies, recovery, and proof when communication resumes.

Proof before expansion

IOC can begin with one recurring physical burden.

Start with the circuit, controller, zone, gateway, pump, plug load, or recovery path already producing waste, repeated labor, loss of visibility, or recurring service friction.

The architecture becomes real through operation: identify the responsibility, install the appropriate node, establish local rules, let the boundary answer, and use evidence to decide whether the next installation is justified.

01
Choose the repeating problemLighting waste, irrigation disorder, reset calls, blind operation, inaccessible equipment, or portfolio friction.
02
Place the responsibilityConfirm what the physical point serves, where it belongs, which authority applies, and what must remain protected.
03
Install and commission the nodeEstablish identity, current state, limits, timing, refusal, continuity, restoration, and expected proof.
04
Operate and verifyLet schedules, bounded actions, recovery, refusal, restoration, and evidence become visible under real conditions.
05
Repeat only where value is provenOne verified boundary can earn the next responsibility, the next property, and eventually a coherent portfolio field.
Conceptual modular IOC deployment showing multiple governed nodes added beside an existing electrical panel
One governed boundary at a time. IOC can begin at one existing physical point and add further nodes only where verified need and demonstrated value justify expansion. Conceptual illustration. Node form, quantity, connection method, maturity, and installation scope vary by application and approved field design.
MeasuredObserved through meter, device, timing, state, or event data.
EstimatedCalculated from stated assumptions, ratings, schedules, or samples.
AvoidedPrevented waste, truck rolls, repeated diagnosis, or disruption.
QualitativeImproved control, visibility, continuity, accountability, or service.
ProjectedFuture potential kept separate until supported by its own evidence.
Technical depth

The simple public sequence sits above the complete operating architecture.

Readers who need the deeper ontology can open the sections below. The detail remains available without becoming the entrance test for every visitor.

The detailed operating sequence beneath the five movements

The five public movements compress the detailed sequence rather than replacing it.

1. IdentifyName the served circuit, controller, zone, device, location, present state, and responsible domain.
2. ClassifyDetermine the current role, authority, and dynamic criticality: protected, flexible, recoverable, event-specific, routine, or monitor-only.
3. BoundDefine floors, ceilings, duration, timing windows, reset limits, restoration rules, and prohibited actions.
4. EvaluateCheck present condition, timing, requester authority, communication state, local rules, and restoration readiness.
5. Refuse or actPerform only the eligible action—or reject, limit, delay, or offer an alternative when the request falls outside the approved conditions.
6. RestoreReturn through the assigned home state, recovery rule, cooldown, or staged restoration sequence.
7. VerifyRecord state, request, response, refusal, duration, restoration, anomalies, and the available physical or operational result.
Semantic state and dynamic criticality

On and off are real electrical states, but they are too small to describe the operating life of a responsibility. IOC can distinguish serving, protected, available, reduced, delayed, partially participating, refusing with cause, offline-continuing, restoring, under service, unavailable, and verifying.

ProtectedParticipation is refused because safety, code, service continuity, comfort, local policy, or present condition makes the boundary unavailable.
FlexibleThe boundary may dim, pause, coast, delay, stage down, or otherwise yield inside its current envelope.
RecoverableRestoration becomes the priority for a gateway, controller, reader, router, charger, or support system.
Monitor-onlyVisibility comes before action while approval, policy, code, commissioning, or installation scope remains incomplete.
Dynamic criticality belongs to the present condition of the served responsibility—not permanently to the product label.
The boundary, node, and orchestration layer
The persistent governed boundaryThe continuing circuit, controller, zone, pump, gateway, plug load, charger-support path, or other served responsibility whose identity, policy, history, and obligations survive hardware replacement.
The replaceable local node instanceThe commissioned mechanism that observes state, applies bounded authority, refuses when required, continues locally, restores, and returns proof. Hardware can change without erasing the governed responsibility.
The orchestration and proof layerBuilding, portfolio, utility, or city systems that express conditions, update policy, issue bounded requests, observe outcomes, and coordinate many governed boundaries.
The governing distinctionHigher systems coordinate. The local boundary preserves truthful physical responsibility and continuity.
From governed boundaries to coherent demand and Liquid Cache

When enough ordinary demand becomes distinguishable, ranked, bounded, locally enforceable, restorable, pathway-relevant, and verifiable, the field can produce event-shaped operating headroom. IOC calls this Liquid Cache.

Liquid Cache is not stored electricity. It is temporary operating room inside governed demand. The resource exists only when eligible boundaries are available in the right place and time, protected boundaries can refuse, restoration is controlled, rebound is addressed, and the response returns credible evidence.

See it inside one building

Book I — The Participating Building

The website explains the public operating path. Book I follows one ordinary composite building through identity, purpose, authority, dynamic criticality, truthful response, refusal, offline continuity, restoration, proof, portfolio expansion, and the feeder-aware edge.

The old building consumed. The smart building could be commanded. The participating building can answer.Book I is the lived building-scale doorway into the architecture.
Specification and placement

Technical White Paper V2 + system comparison

The Technical White Paper V2 carries the governed-boundary architecture, two-level operating map, embodiments, deployment, conformance, and evidence requirements. The comparison page shows where IOC sits beneath useful BMS, EMS, VPP, DERMS, smart-panel, controller, and AI systems.

The first participating boundary

Choose one ordinary physical responsibility. Let real operation decide what comes next.

Start with one repeating building problem. Add the node required at that physical point. Establish identity, authority, present condition, limits, refusal, continuity, restoration, and proof. Repeat only where the value is demonstrated.

IOC does not replace utilities, codes, electricians, professional engineering, generation, storage, BMS/BAS, DERMS, VPPs, OpenADR, smart panels, controllers, or device systems. It gives their requests and actions a trustworthy physical receiving layer governed by identity, authority, local eligibility, continuity, restoration, and proof.