Blog · Operations

How do you keep an installed fleet measured and protected? Sensor maintenance and site security after commissioning

What changes after the robots are in service: keeping Halo nodes calibrated, keeping the Atlas model current and keeping Sentinel watching the segments that matter.

An installed Sirdar fleet stays trustworthy through three habits. Keep every Halo node inside its ±5 mm calibration tolerance and its clock inside the PTP tolerance, and re-survey when the site changes. Keep the Atlas model current so every plan is traced to a version that matches the floor. Keep Sentinel enrolled on every endpoint and watching every OT segment, with investigations handled by the partner of record. Sentinel raises an alert in a median 1.8 seconds; the rest is discipline.

Soren Avelar · Chief Technology Officer, Sirdar Systems · · 4 min read

Last updated

What maintenance does a Halo node need?

Less than a camera, but not none.

A Halo H30 is IP67, fanless in its enclosure and rated from minus thirty to sixty degrees Celsius, so weather is rarely the problem. What drifts is the reference. The node measures to ±5 mm at 40 m against a survey reference. When the site changes, the reference can move: a crane rail is re-laid, a pole is struck, a wall is rebuilt.

The commissioning checklist is also the maintenance checklist:

  • mount verified against the survey;
  • PoE++ power and link;
  • Sentinel enrolment with a signed device identity;
  • timestamp sync within tolerance;
  • target-board calibration to ±5 mm at 40 m.

Every accepted node keeps a timestamped calibration record. A partner reviews residuals over time and re-calibrates the nodes whose residuals trend toward the tolerance, not the nodes whose turn it happens to be.

Why does clock sync matter as much as calibration?

Because a measurement with the wrong timestamp is a wrong measurement.

Halo nodes sync to a PTP grandmaster disciplined by GNSS. At the Port of Halvard the tolerance is 500 nanoseconds; a correction of 84 nanoseconds on an Edge Node is logged and resolved without anyone being paged. A node outside tolerance fails the commissioning check until sync is restored. Timestamp sync within tolerance is a step on the checklist for that reason.

How does the Atlas model stay current?

By treating every physical change as a new version.

Nordvik Steel's Atlas model moved from v40 to v41 when a coil-storage aisle was added and a crane rail was re-surveyed. The diff is explicit: what was added, what changed, what was removed, and which Kinetic safety zones were verified unchanged. The sources are named too, down to how many Halo and Kinetic observations trained the version.

Training events are authorized by the customer and metered within an agreed scope. A partner who reviews the diff with the customer after each version keeps the safety case honest without re-writing it.

What does site security look like after commissioning?

It looks like a console the partner's security desk actually watches.

Sentinel protects every Kinetic unit, FC-1 controller and Halo node from the factory, and every operator workstation and gateway the partner enrolls. The overview ranks sites by health and open investigations. The median detection-to-alert time is 1.8 seconds. Sentinel understands Modbus TCP, OPC UA, EtherNet/IP, PROFINET and DNP3 natively, so the crane and reefer segments are visible without a second tool.

When something happens, the timeline is the product. A recent investigation at Berth 3 began when a gateway opened 14 Modbus TCP sessions to controllers it had never addressed in 90 days. Sentinel matched a write attempt against the crane PLCs on that segment, denied the writes under the site's OT allow-list, kept the reads for evidence and raised a high-severity alert. The partner of record's security desk claimed the investigation. Sentinel proposed containment: isolate the gateway, quarantine the east segment, pause the two Kinetic units on it, snapshot the gateway memory. Two of six units paused. The cranes kept working under manual control. The action was reversible.

Who runs security day to day?

The partner of record, or Sentinel Managed Detection where the customer prefers it.

Sentinel Professional adds investigation timelines and response handoffs for teams that run their own queue. Sentinel Enterprise adds multi-site fleet policy and staged upgrade cohorts with rollback ownership, which is how a 38-site network like Meridian Freight upgrades without a bad day. Both tiers are eligible for Managed Detection.

What about the network edge?

Thin networks get an EN-200. The Sentinel Edge Node is a 1U, fanless appliance drawing 12 W typical, with two 10GbE SFP+ and four 1GbE ports, rated from minus ten to fifty-five degrees Celsius. It secures and buffers site telemetry where the link is unreliable. Telemetry availability is the figure to watch: Caledon Grid reports 99.8% across 45 monitored sites. It is hardware only; every protected endpoint still needs a current Sentinel subscription.

What should an operations lead review each quarter?

  • Halo calibration residuals per node, and the re-survey list.
  • Atlas version diffs since the last review, and the safety zones verified.
  • Sentinel investigations opened, contained and closed, with their approvers.
  • Firmware cohorts: Halo firmware 5.2 and Sentinel 3.8 are current; Sentinel 4.0 is a preview and not yet for production.

A partner who brings those four lists to the quarterly review is doing the job.

Last updated 2026-09-30.

Questions and answers

How often does a Halo node need re-calibration?
When its residuals trend toward the ±5 mm tolerance or when the site reference changes, such as a re-laid crane rail. Partners review calibration records over time rather than on a fixed schedule.
What happens if a Halo node loses clock sync?
It fails the commissioning check until sync to the PTP grandmaster is restored within tolerance. Timestamp sync is a checklist step because a measurement with the wrong timestamp is a wrong measurement.
Who investigates a Sentinel alert?
The partner of record's security desk, or Sentinel Managed Detection where the customer has chosen it. The investigation timeline records detection, correlation, the response handoff and the containment decision with its approver.
Is Sentinel 4.0 ready for production?
No. Sentinel 4.0 is a preview and not a sellable entitlement. Sentinel 3.8 is the current release.
Does the EN-200 replace Sentinel subscriptions?
No. The Edge Node is collection hardware for thin networks. Every protected endpoint still needs a current Sentinel subscription.

#Halo #Sentinel #Maintenance #Site security #Atlas