The short answer
Build the matrix from consequences, not from every available controller point. For each alarm, identify the protected person, crop, asset or service; the triggering logic and delay; priority; affected zone; useful context; primary recipient; required acknowledgement and response; escalation route; authorized temporary action; restoration test; and record. Separate warnings from urgent actionable alarms. Test the complete path from field condition through controller, communications provider and human response, including power and network loss.
If low temperature, failed heater, open vent and sensor fault all generate repeated messages without hierarchy, the operator may acknowledge symptoms while missing the cause. If every deviation is urgent, staff begin to mute notifications. If remote messages are the only protection, a phone outage or expired account can silently remove the alarm system.
Use operating scenarios to rationalize alarms. Ask what the first responder can do, how long the condition can safely continue, what other signals help confirm it, and when a second person must be called. The matrix should also cover bad-quality or missing data, commands that do not receive feedback, sustained manual overrides and alarms disabled for maintenance.
This guide is an operating-control framework, not a substitute for the approved design, crop protection plan, product labels, manufacturer instructions, employment and safety procedures, local law, or advice from qualified growers, engineers, water-treatment specialists, plant-health advisers, and safety professionals.
What the buyer should control

| Control point | Required record or action | Release evidence |
|---|---|---|
| Alarm identity and consequence | Use a unique name, zone and equipment reference; state the threatened safety, crop, production or asset outcome and the plausible time to harm. | Approved rationale links each alarm to a specific response need. |
| Trigger and quality | Define threshold or condition, persistence delay, hysteresis, voting or confirmation, sensor validity, mode suppression and return-to-normal logic. | Controlled configuration record and test result for both activation and clearing. |
| Priority and presentation | Assign a limited priority set with consistent color, sound and wording; show current value, limit, zone, duration, related equipment and suggested first check. | Operator review confirms the message is understandable without searching several screens. |
| Recipients and timing | Name the on-duty role, delivery channels, acknowledgement time, response expectation, second-level contact and management escalation. | Roster and communications test show the active shift can be reached. |
| Immediate and fallback action | State safe authorized checks, manual or backup mode, crop protection, access needs, limits and conditions requiring shutdown or evacuation. | Current response card or procedure available to the recipient. |
| Maintenance and override control | Record shelving, suppression, disabled alarms, manual overrides, reason, approver, expiry, compensating checks and restoration. | Daily review shows no expired suppression or unexplained override remains. |
| Testing and performance review | Test sensors, logic, annunciation, remote delivery, acknowledgement, escalation, restoration and event history; track floods, repeats, missed alarms and response time. | Periodic test report and rationalization actions based on event data. |
Give every open item an owner, due date, status, related drawing or package, and effect on cost, time, quality, safety, and performance. “Discussed,” “in progress,” or “by others” is not a closure record.
A practical workflow
1. List hazardous and crop-critical scenarios
Start with loss of power, heating, cooling, ventilation, water, fertigation, communications and control. Add equipment protection, access and security scenarios where relevant.
2. Trace cause, symptoms and available confirmation
Choose a primary actionable alarm and use related values as context. Avoid notifying the same person repeatedly for every downstream symptom unless separate action is required.
3. Set priority from consequence and available response time
Consider severity, speed of harm, detectability and backup capacity. Do not copy default controller priorities without review.
4. Design the human response
Use role names rather than one person's phone number, maintain the roster, define acknowledgement, record ownership and escalate when the first recipient is unavailable or the condition persists.
5. Test, observe and tune
Run safe drills and review actual event logs. Correct nuisance triggers, missing context, unreachable contacts and unclear procedures without suppressing evidence of a real equipment or crop problem.
Use one controlled register and preserve superseded records. The team should be able to reconstruct which instruction, setting, role and asset condition applied when an event was observed, adjusted, maintained, tested, restored and accepted.
Roles at the operating interfaces
Owner and operations manager
Set the crop, safety, production and business priorities; assign authority; approve operating limits; and make sure urgent decisions can be made outside normal hours.
Grower and plant-health lead
Define crop-sensitive conditions, hygiene zones, scouting evidence, water-quality needs, permitted treatments, release criteria and the response to suspected pests or disease.
Maintenance and controls team
Keep assets, sensors, software, backups, alarms, isolations, spares and work records usable. Report degraded functions before they turn into crop or safety events.
Suppliers and local specialists
Provide scope-specific instructions, competent service, replacement parts and technical evidence. Local professionals must control regulated electrical, pressure, chemical, fire and environmental work.
Use evidence before releasing the next step
Before people, water, chemicals, crops or equipment enter a released area, confirm that the approved method is current, the responsible person has checked the work, exceptions are controlled, affected teams have been informed, and the record can be retrieved. If a condition is not met, state what may continue, what remains on hold, who owns the action, and when it will be checked again. This is more useful than a general statement that the greenhouse is ready.
Common failure modes
| Failure | Buyer response |
|---|---|
| Every limit deviation sends an urgent message | Operators become desensitized. Use persistence, mode logic and a small consequence-based priority structure. |
| Acknowledgement is treated as correction | Keep the alarm active or the issue open until the condition is physically verified and restored. |
| One mobile phone is the escalation plan | Use maintained role-based coverage, a second route and periodic end-to-end tests. |
| Maintenance disables an alarm without expiry | Require reason, approver, compensating check, visible status and automatic review or expiry. |
Buyer decision questions
What harm is this alarm intended to prevent? How quickly can it occur under the current season and crop stage? Can the recipient take a useful action? What context distinguishes sensor failure from real conditions? Who owns the response on every shift? What happens if power, internet or the messaging service fails? How are suppression and manual overrides reviewed?
Link the answer to the greenhouse automation system guide, the commissioning checklist, the preventive maintenance plan, so operating decisions remain connected across the crop, equipment, maintenance and evidence.
Frequently asked questions
How many alarm priorities should a greenhouse use?
Use the smallest set that produces clearly different operator actions and response times. Too many levels are hard to apply consistently.
Should every alarm send a mobile message?
No. Remote notification should be reserved for conditions requiring timely off-console action. Advisory events can remain in dashboards or shift reviews.
How often should alarms be tested?
Set frequency by consequence, failure history and site policy. Test after relevant software, sensor, network, roster or equipment changes.
Can an alarm be removed because it is noisy?
Investigate why it repeats. Correct the process, sensor, threshold, delay or equipment. Removal is justified only after a documented consequence and response review.
Turn the requirement into a controlled deliverable
Share the zone list, crop limits, controller alarm export, staffing roster, backup systems and recent event history. Chengfei Greenhouse can help rationalize alarms for its supplied controls while the owner approves site-wide priorities and emergency response.
Contact Chengfei Greenhouse
