One loop, repeated until the problem is gone
First Mate is a Windows service on your Milestone server with a panel your crew opens in a browser. Everything it does follows the same six steps, and every one of them is visible.
Detection
Checks run continuously against the recording servers, the Milestone services, the cameras, the viewing stations, the disks and the retention you agreed on. A finding has to survive a cooldown before it becomes an issue, so a camera that blinks once does not wake anybody.
Explanation
The panel does not repeat the error message. It states what is wrong, what is probably causing it, what the safe fix is, how long that takes, and what it will not touch. Recording is almost always the thing that must not be affected, so it is named explicitly.
Confirmation
A fixed pattern that never changes: explanation, then the impact in a highlighted block, then a mandatory reason chosen from a list. The button stays disabled until a reason is selected, because free text makes a logbook unsearchable.
Execution
An agent process performs the action from a signed runbook. Runbooks are written and tested by us, they declare their own blast radius, and they are the only thing that can run. Commands are short lived and signed, so a captured instruction cannot be replayed later.
Validation
After the action, First Mate checks whether the problem is actually gone, within a defined window. If it is not, it says so and prepares an escalation. A restart that changed nothing is not reported as success.
Record
Everything lands in the logbook: the finding, the decision, the person, the reason, the result. Append only, hash chained, verifiable, and stored on your server.
The one pattern we will not compromise on
Software that acts on a mission critical system without a person behind it is a liability, however clever it is. So this screen sits in front of every action.
Confirm
Restart the viewing station on Bridge-01?
This closes and reopens the viewing application on that station. It takes about 40 seconds.
Recording is not affected. Live viewing on this station is unavailable while it restarts. Other stations continue as normal.
Afterwards I will check that live viewing returns within 90 seconds.
The impact is stated before the button
Not in a manual, not afterwards. What continues, what stops, and for how long.
A reason is mandatory
Chosen from the runbook's own list. It is what makes the logbook answer questions six months later.
Cancel is on the left, always
The safe choice never moves, so muscle memory at three in the morning stays safe.
Version one has no autonomous mode
Higher autonomy is designed and written down, but it is not shipped. Anything that acts on its own would need your explicit decision, per action and per vessel.
Small on purpose
A panel that is used once a month has to be obvious. There are four screens, and a tab bar on a tablet so a gloved hand can reach them.
Overview
Is my system healthy, and if not, what now. Fixed card order, honest counts, and a maximum of three items asking for attention. Silent when everything is well.
Actions
What may I do, and what may I not do, and why not. Actions you are not entitled to stay visible but greyed out, so you know who to call instead of assuming the system cannot do it.
Access
Who can see this system right now, and who can intervene. Including us. In version one this screen tells the truth and promises nothing: no standing access exists.
Log
People by name, system actions under the name of the software, filters by person, day and type, and one line at the bottom that says the chain verified without gaps.
Designed for the moment the link is gone
Everything described on this page happens on the server in your rack. There is no cloud service in the path, no connector to install, and no account to keep alive.
When there is no link to shore, the panel does not turn red. Losing the connection is the normal condition at sea, not a fault. Escalations queue and go out when a link returns, and the crew keeps working in the meantime.
Status Recording normal
No shore link right now
Everything on board keeps working. Escalations are queued and will be sent when a link returns.
3 items waiting, last link 4 days ago
Ice tint, not amber. Nobody has to do anything.
One engineer day, on the server you already have
What it needs
The existing Milestone server, or the management server in a larger environment. It installs as a Windows service. No separate appliance, no rack space, no second network.
Where the crew opens it
In a browser on any device on board, on a wall tablet in kiosk mode, or inside the Smart Client. On the wall tablet, status is public and action is personal: anyone can look, acting requires identifying yourself.
How long it takes
About three hours to install and configure, and about three hours to verify the environment afterwards. Plus a short briefing for the crew, not a course. Remote where possible, on site where that is better.
Start with a survey of your Milestone system
Half a day of reading your environment: what runs, what keeps breaking, and what your crew should be able to fix without calling anyone. You get the findings whether or not you ever install First Mate.