The first governed decision

Today

Governed Bit Intervention

The first governed-decision application. Drilling and well construction.

Current status
Reference implementation complete · real-data qualification complete · pilot partners sought.

The decision on the rig

The decision on the rig.

A bit is downhole, telemetry is coming in, and at some point someone on shift decides whether to pull it.

Pull too early and the operation pays for an unnecessary trip. Pull too late and it risks downhole failure and what follows from it. The decision is made under time pressure, with the information available at that moment, by a person who will later be asked why.

That last part matters as much as the first. The decision has to be defensible afterwards, to people who were not on shift and who will be reading whatever record was kept.

Why a prediction is not a decision

Drilling Bit RUL

A forecast is not a decision.

A remaining-useful-life model produces a forecast. On its own, it does not know what else the decision depends on.

It does not know whether the telemetry it is reading is current, whether the operator's policy permits a pull in this section, who holds authority on this shift, whether that person has authorized anything, or how the decision will be explained afterwards.

What a usable recommendation also needs
The prediction
A remaining-life forecast for the bit.
The evidence and its currency
The telemetry the forecast rests on, and how current each source was when it was read.
The operator's policy
Whether a pull is permitted in this section, under the procedure in force.
The person with authority
Who holds authority on this shift for this decision.
Explicit authorization
A distinct authenticated act by that person.
The record
Why the decision was made, kept so it can be read later.

Governed Bit Intervention brings those into one governed recommendation. Judging what the forecast means for this run — what could happen next, and how uncertain that is — is the assessment's work, not the forecast's.

The governed decision

The seven parts, applied to a bit decision.

Every part below is an entry in one record. The seventh is the frame the other six are drawn inside.

The record below is illustrative. It is built to show the shape of a governed decision, not to report one that happened.

A. Recommendation made B. Recommendation withheld

A. Recommendation made

Both issues are printed here. They are two issues of the same record, not a result and an error.

Parts may be read in any order, and closed again. Nothing advances on its own, and nothing here is waiting to be finished.

  1. 1 Situation Evidence Bit run records for this section, surface drilling telemetry and how current it is, and offset records for the same section. Evidence that was legitimately available at the time.

    What this entry rests on

    • R1Bit run records for this sectionavailable
    • R2Surface drilling telemetry for this runavailable
    • R3How current that telemetry was when it was readavailable
    • R4Offset records for the same sectionavailable
    • R5Operational context recorded for this sectionmissing

    A missing reference keeps its row. It is named, not filled in and not left out.

  2. 2 Assessment Evidence Why it matters: the projected remaining life and how uncertain that projection is, weighed against the cost of an unplanned trip and the risk of downhole failure. Why it matters, and what could happen next, including the uncertainty.

    What each reference carried, and what a gap does to this

    R5 is missing, and it stays visible as missing rather than being filled in or left out. A gap affects what the assessment can support, and the assessment states that limit instead of narrowing around what is absent.

    Where a reference is stale rather than missing, the assessment states how far it depended on that reference and does not treat an old reading as a current one. Where evidence the assessment requires is stale, the system may abstain rather than manufacture confidence.

  3. 3 Recommendation AI proposes Plan a bit pull. AI proposes. It cannot authorize.

    This entry cites parts 1 and 2. It is written into the record for a person to read. It is not sent anywhere and it takes no effect of its own.

  4. 4 Governance Policy decides what is permitted Permitted. Struck through: Not permitted. The determination as it was recorded, not the determination being made.

    What the policy read

    • P1The operator's procedure in force for this section
    • P2The operator's authority mapping for this shift

    The policy is the operator's. The policy evaluation is deterministic. It decides whether the proposed action is permitted; it does not authorize the action.

  5. 5 Authorization People authorize This line is blank on purpose. Nothing on this website can fill it.

    Authorization is a distinct authenticated act, made by the person who holds authority, on the operator's own systems. This line stays blank in both issues, at every width, in every state and in print. Nothing on this website can fill it.

  6. the moment of decision

    No hindsight. Nothing below this line is used to judge anything above it.

  7. 6 Action and outcome Outcome Whether the authorized action was carried out on the operator's own systems, and what followed. Carried out on the operator's own systems, not by DataEnergy.

    Where the action happens

    • O1The operator's own systems and procedures — theirs
    • O2Rig-control systems — never written to

Decision Passport

The Passport is the frame drawn around every part above, not a step after them. It keeps the evidence and its versions, the recommendation, the policy evaluation, the authorization and the outcome together, so the decision can still be interpreted later by someone who was not there.

Every decision keeps its evidence

Parts of this copy you have opened

PartOpened
Situation
Assessment
Recommendation
Governance
Authorization
Action and outcome
Decision Passport

This register lists what you opened in this copy, on this page. Closing a part leaves its mark standing, and opening it again changes nothing. The marks belong to this copy: nothing is stored, sent or read back, and reloading gives a fresh copy of both issues.

The operational Decision Passport records governed decisions. It does not record anything about a visit to this website.

B. Recommendation withheld

Both issues are printed here. They are two issues of the same record, not a result and an error.

Parts may be read in any order, and closed again. Nothing advances on its own, and nothing here is waiting to be finished.

  1. 1 Situation Evidence The same sources, with the telemetry marked stale at the time of reading. Evidence that was legitimately available at the time.

    What this entry rests on

    • R1Bit run records for this sectionavailable
    • R2Surface drilling telemetry for this runstale
    • R3How current that telemetry was when it was readstale
    • R4Offset records for the same sectionavailable
    • R5Operational context recorded for this sectionmissing

    A missing reference keeps its row. It is named, not filled in and not left out.

  2. 2 Assessment Evidence The projection cannot be supported while the evidence it rests on is stale, and the assessment says so. Why it matters, and what could happen next, including the uncertainty.

    What each reference carried, and what a gap does to this

    R5 is missing, and it stays visible as missing rather than being filled in or left out. A gap affects what the assessment can support, and the assessment states that limit instead of narrowing around what is absent.

    Where a reference is stale rather than missing, the assessment states how far it depended on that reference and does not treat an old reading as a current one. Where evidence the assessment requires is stale, the system may abstain rather than manufacture confidence.

  3. 3 Recommendation AI proposes Withheld. Telemetry stale. AI proposes. It cannot authorize.

    This entry cites parts 1 and 2. It is written into the record for a person to read. It is not sent anywhere and it takes no effect of its own.

  4. 4 Governance Policy decides what is permitted Not evaluated. There is no proposed action to evaluate. The determination as it was recorded, not the determination being made.

    What the policy read

    • P1The operator's procedure in force for this section
    • P2The operator's authority mapping for this shift

    The policy is the operator's. The policy evaluation is deterministic. It decides whether the proposed action is permitted; it does not authorize the action.

  5. 5 Authorization People authorize This line is blank on purpose. Nothing on this website can fill it.

    Authorization is a distinct authenticated act, made by the person who holds authority, on the operator's own systems. This line stays blank in both issues, at every width, in every state and in print. Nothing on this website can fill it.

  6. the moment of decision

    No hindsight. Nothing below this line is used to judge anything above it.

  7. 6 Action and outcome Outcome No action was proposed, so none was authorized and none was carried out. Carried out on the operator's own systems, not by DataEnergy.

    Where the action happens

    • O1The operator's own systems and procedures — theirs
    • O2Rig-control systems — never written to

Decision Passport

The Passport is the frame drawn around every part above, not a step after them. It keeps the evidence and its versions, the recommendation, the policy evaluation, the authorization and the outcome together, so the decision can still be interpreted later by someone who was not there.

Every decision keeps its evidence

Parts of this copy you have opened

PartOpened
Situation
Assessment
Recommendation
Governance
Authorization
Action and outcome
Decision Passport

This register lists what you opened in this copy, on this page. Closing a part leaves its mark standing, and opening it again changes nothing. The marks belong to this copy: nothing is stored, sent or read back, and reloading gives a fresh copy of both issues.

The operational Decision Passport records governed decisions. It does not record anything about a visit to this website.

What this does, and does not, do

  1. Recommendations cite the evidence they rely on, and identify the evidence that is missing.
  2. The system can abstain when information is stale or the model is outside the domain it was developed for.
  3. Human authorization remains a distinct authenticated act.
  4. DataEnergy does not write to rig-control systems. If DataEnergy is unavailable, the operation continues according to the operator's existing procedures.

DataEnergy does not control the rig. It is not the control system, the protection system or the safety-instrumented system, and it makes no SIL claim.

No hindsight.

A decision is judged by what could legitimately have been known when it was made.

The moment of decision

Information that arrived later sits below the moment of decision, and it is not used to judge anything above it. A pull that was reasonable on the evidence available does not become unreasonable because of what the next shift found, and a pull that was unreasonable does not become defensible because it happened to work out.

That is why the record is cut at the moment of decision, and why the cut is labelled rather than implied.

When the system abstains

Abstention is a result, not a failure.

When information is stale, or the model is outside the domain it was developed for, the system declines to recommend.

Issue B of the record above is that case. It is the same record, with the same six fields, the same blank authorization line, the same parties and the same cut. Recommendation reads Withheld. Telemetry stale. and Governance reads that there was no proposed action to evaluate.

Nothing about issue B is shorter or less complete than issue A, because an abstention is a legitimate operational result and the record of one has to be as readable as any other. The record shows that no recommendation was made, and why.

What the status means

Today

What the current status means.

The status printed at the head of this page says three things, and each is meant literally.

What each phrase means
Reference implementation complete
The governed loop has been built, from evidence through to the Decision Passport.
real-data qualification complete
Qualification on actual drilling records has been completed.
pilot partners sought
DataEnergy is looking for operators willing to run a scoped pilot.

Scope of this status

This status describes implementation and real-data qualification. It does not imply a customer deployment, a completed pilot, certification, or a safety-instrumented function.

A scoped pilot

Today

A scoped pilot.

A scoped pilot has agreed success criteria and a defined end date.

DataEnergy is looking for operators willing to run one. Scope, duration, data access and commercial terms are worked out with each operator, and none of them is published here.

A pilot conversation starts with the decision you are actually trying to make, not with the software.

Discuss a pilot

AI proposes. Policy decides what is permitted. People authorize. Every decision keeps its evidence.

Contact DataEnergy