The short answer
Start with the events that can interrupt this particular site: fire, utility loss, heating or cooling failure, water interruption, storm damage, flooding, chemical release, disease restriction, loss of access, communications failure and absence of a critical operator. For each event, write the trigger, first safe action, person with authority, notification route, services that may continue, services that must stop, evacuation or shelter decision, crop protection priority, outside help, recovery owner and reopening evidence. Keep emergency response and business recovery connected but separate. The first protects people and controls the incident. The second restores minimum production, customer commitments and records after the site is safe. A short plan that the night operator can use is better than a long manual no one has tested.
Greenhouses have unusual dependencies. A short power loss can stop vents, fans, irrigation pumps, heating controls, thermal-screen drives, alarms and inflated-film blowers at the same time. The crop consequence changes with weather, crop stage and occupied area. The safety consequence changes with fuel systems, wet floors, chemical storage, damaged glazing and the number of people on site. One generic response cannot cover every combination.
Write the plan around decisions, not departments. If an alarm arrives at 02:00, the receiver must know whether to call emergency services, isolate an area, send a qualified technician, notify the grower, move stock, or simply monitor. The plan also needs a substitute when the named person cannot be reached. Test the contact path and the physical actions under controlled conditions before relying on them.
This guide is an operating-control framework. The approved design, crop plan, product labels, manufacturer instructions, site safety procedures, local law and directions from competent local professionals govern the actual work.
What the buyer should control

| Control point | Required record or action | Release evidence |
|---|---|---|
| Life safety and authority | Name the incident lead, evacuation or shelter authority, alternates, assembly points, head-count method, visitor control and emergency-service contact route. | Current site map, role list, call tree and signed acknowledgement from trained staff. |
| Scenario and trigger | Define observable triggers for fire, power, heat, cooling, water, storm, flood, chemical, biosecurity and access events without inventing one universal threshold. | Scenario sheet linked to alarms, weather warnings, equipment status and approved local instructions. |
| Essential crop services | Rank heating, ventilation, cooling, irrigation, controls, alarms, film inflation, lighting, drainage, security and communications by season and crop condition. | Approved seasonal service-priority table with required runtime, dependencies and responsible owner. |
| Safe shutdown and isolation | State which systems may be stopped remotely, which need staged shutdown, and which electrical, gas, pressure or chemical isolations require qualified personnel. | Equipment-specific shutdown cards, isolation points, permits and current manufacturer instructions. |
| People and communications | Keep staff, contractor, utility, emergency, supplier, insurer, grower and customer contacts available when the network or office is unavailable. | Printed and offline contact copy, tested notification cascade and language or accessibility provisions. |
| Minimum operating mode | Define the smallest safe production footprint, acceptable manual work, temporary monitoring, available water and power, staff coverage, and time limit for degraded operation. | Written minimum-mode approval with start time, risks, controls, review interval and stop condition. |
| Recovery and reopening | Inspect affected structures and utilities, preserve evidence, control contaminated material, reconcile crop status, verify alarms and record deviations before release. | Area-by-area reopening certificate signed by the competent people responsible for each hazard. |
Every open item needs an owner, due date, status and effect on safety, production, cost and recovery time. A note that something was discussed or is being handled does not prove closure.
A practical workflow
1. Map the site and its dependencies
Walk the site with operations, growing, maintenance and safety staff. Mark utilities, fuel, chemical storage, exits, shutoffs, drainage, emergency equipment, critical controllers, network points and areas that can become inaccessible. Follow each essential service upstream. A vent motor may depend on a controller, panel, weather station, communications link and backup supply.
2. Choose realistic planning scenarios
Use local weather history, failure records, supplier lead times, utility reliability, insurer findings and staff experience. Combine events where that is credible, such as a winter power loss with blocked roads or a storm with communications failure. Do not plan only for equipment faults that occur during staffed hours.
3. Write the first thirty minutes
For every scenario, state how the event is recognized, who receives it, how the receiver verifies it without entering danger, who has command, and which calls happen first. Include a clear instruction that life safety and official evacuation orders override crop-saving work.
4. Define the minimum viable operation
Identify which crop zones and services can be supported with available people, backup utilities and monitoring. State what must be suspended. Include a time-limited approval because a safe two-hour workaround may become unsafe or biologically unacceptable after a longer interruption.
5. Drill, observe and correct
Run desktop exercises and controlled functional tests. Use nights, weekends and handover periods in the scenarios. Record missed calls, inaccessible instructions, unclear authority, slow starts, depleted supplies and unsafe assumptions. Assign corrections and repeat the failed part of the drill.
6. Control the recovery
Separate emergency control from reopening. Inspect structure, power, fuel, water, controls and crop health through the appropriate competent people. Photograph damage, preserve logs and create a release list. Restart one defined area or service at a time so new faults are visible.
Preserve the event sequence and earlier versions of records. The team should be able to reconstruct what was observed, which condition applied, who decided, what changed, how the result was tested and which limitation remained.
Who owns each decision
Incident lead
Protects people, calls emergency services, chooses evacuation or shelter actions, controls access and records major decisions. The alternate must have the same authority when the lead is unavailable.
Grower continuity lead
Ranks crops and zones, defines acceptable short-term conditions, decides which production work stops, and documents crop disposition. This role does not overrule a safety exclusion.
Technical recovery lead
Coordinates qualified inspection and staged restoration of utilities, controls and equipment. This person keeps temporary workarounds visible and prevents unauthorized reconnection.
Communications and records lead
Maintains the call tree, head count, event timeline, customer and insurer notices, photographs, costs, purchase approvals and the final record package.
Release evidence before the next step
Reopen an area only after the incident lead has removed the access restriction and each relevant technical owner has accepted the condition. A single 'all clear' message is not enough when structure, electrical supply, gas, water quality, controls and crops need different checks. Record temporary limitations, inspection dates and the next review. If evidence is missing, label the area or service as unavailable rather than assuming normal operation.
Common failure modes
| Failure | Buyer response |
|---|---|
| The plan is a telephone list | Add triggers, authority, safe actions, service priorities, alternatives, stop conditions and reopening evidence. |
| Every system is called critical | Rank by life safety first, then crop consequence, seasonal need, available backup and restart difficulty. A priority list that contains everything guides nothing. |
| The owner is the only decision maker | Appoint trained alternates with written limits of authority for nights, travel and communications failure. |
| A successful generator start ends the drill | Continue through load acceptance, alarms, communication, staff response, degraded-operation controls and return to normal supply. |
| Recovery starts before hazards are assessed | Keep people out of damaged or contaminated areas until the appropriate authority or competent professional has released them. |
Buyer decision questions
Which event could harm a person before anyone notices the crop problem? Who can order evacuation, shutdown, temporary spending and customer notification at night? Which services share one electrical panel, water source, controller or communications link? What can run safely on backup power, and for how long? Which crops or propagation batches lose value first? Which instruction remains available when the internet is down? What evidence proves that a damaged area can reopen? When was each part of the plan last tested by the person expected to use it?
Keep these decisions connected to the greenhouse alarm escalation matrix, the operator training checklist, the greenhouse commissioning checklist. The emergency plan, equipment evidence and crop plan should describe the same operating reality.
Frequently asked questions
Should one plan cover every greenhouse site?
Use a common company framework, but each site needs its own hazards, maps, utilities, contacts, escape routes, crop priorities and local emergency requirements.
How often should the plan be exercised?
Set a documented schedule based on risk and local requirements. Repeat exercises after staff, crop, layout, utility, control-system or emergency-contact changes, and after any real event exposes a gap.
Can crop-protection staff remain during an evacuation?
Only a site-specific emergency plan and the responsible safety authority can define essential operations and the conditions for trained staff to remain. No crop task justifies ignoring an evacuation order.
What should be stored offline?
Keep current maps, call lists, shutdown instructions, asset priorities, insurance details, key supplier contacts, essential recipes, backups and blank event forms in protected offline and printed copies.
What should happen after a near miss?
Preserve the timeline, alarms and decisions. Ask what made the event possible, which protection caught it, which protection failed, and whether another site has the same exposure. Track the correction to verified closure.
Turn the requirement into a controlled deliverable
Share the site layout, crop calendar, utility single-line information, equipment list, alarm routes, staff coverage, local hazards and existing emergency procedures. Chengfei Greenhouse can help identify dependencies in its supplied systems while the owner and qualified local professionals complete the safety and continuity plan.
Contact Chengfei Greenhouse
