The short answer
Test one scenario from alarm to accepted action. Start with a realistic signal, such as loss of heating, high-temperature risk, water interruption, fire alarm, storm damage or access failure. The first recipient should identify the site and zone, state what is known and unknown, distinguish life-safety information from crop information, confirm who has command and request a read-back of the required action. If the person does not acknowledge within the approved time, the test should move through named alternates and another communication channel. Continue until the responsible person accepts the task and reports back. Record delivery, acknowledgement, message errors, unreachable contacts, authority gaps and the final correction. Never trigger public emergency services or a live evacuation alarm during a test without prior coordination and authorization.
Greenhouse alarms often travel through several layers: sensor, controller, local panel, network, cloud service, mobile provider and a person's phone settings. The message can arrive but still fail operationally because it lacks a zone, uses an unclear label, reaches someone without authority or arrives while the recipient is driving or asleep. A call tree test should examine the human decision chain as well as the technology.
The communication plan also needs a mode for internet, mobile or power failure. Printed contacts, radios, local annunciation, alternate networks and in-person checks may each have a place, but their coverage and limitations must be tested at the site. Keep personal data controlled and current. Give contractors only the access and hazard information needed for their role, and make sure a site representative remains responsible for the decision.
This guide is an operating-control framework. The approved design, crop plan, product labels, manufacturer instructions, site safety procedures, local law and directions from competent local professionals govern the actual work.
What the buyer should control

| Control point | Required record or action | Release evidence |
|---|---|---|
| Scenario and objective | State the initiating event, systems included, people being tested and the one capability the exercise must prove. | Approved exercise brief with no-confusion controls. |
| Initial message | Include site, zone, time, observed condition, immediate safety status, action requested, callback and information still unknown. | Message template and recording or observer notes where lawful. |
| Primary recipient | Verify duty schedule, contact channel, acknowledgement method, decision authority and expected callback. | Time-stamped delivery and read-back record. |
| Alternate path | Test alternates for absence, no acknowledgement, network loss, language need and overloaded communications. | Completed escalation path with each attempt recorded. |
| External contacts | Check utility, contractor, emergency, insurer, regulator and key supplier routes without making unauthorized test calls. | Current verified numbers, service hours and approved test evidence. |
| Offline access | Prove that contacts, maps, alarm labels and shutdown guidance remain available without the office network or cloud service. | Controlled printed or offline copy with revision date and owner. |
| Closure | Record who accepted command, actions assigned, staff accounted for, communications restored and failed test items retested. | Signed exercise log and closed corrective-action list. |
Every open item needs an owner, due date, status and effect on safety, production, cost and recovery time. A note that something was discussed or is being handled does not prove closure.
A practical workflow
1. Choose one operationally credible scenario
Set the time, crop condition, staffing and one communication impairment. Keep the exercise safe and clearly controlled. Tell required controllers and outside parties in advance, while preserving enough realism to test the duty team.
2. Define the message standard
Write the minimum content the receiver needs: exact site and zone, observation, safety status, trend, requested action, decision deadline and callback. Use equipment names that match the site labels. Avoid codes that temporary or new staff cannot understand.
3. Start from the real first receiver
Use the actual alarm route or a controlled simulation. Do not begin with senior management if the night operator or monitoring service is normally first. Observe whether the recipient can find instructions, verify the signal and choose the correct escalation.
4. Require acknowledgement and read-back
A sent message is not a received responsibility. The recipient should repeat the site, problem and assigned action, then state whether they accept command or are passing it to another person. Record the time and any altered detail.
5. Break one normal channel
Simulate an unanswered phone, internet loss or unavailable manager. Use the approved alternate channel and offline contacts. Check radio coverage or local alarm audibility where applicable, without disrupting operations or emergency services.
6. Follow the decision to closure
Continue beyond the first successful call. Confirm who contacts the grower, technician, utility or emergency service, how staff receive updates, who logs decisions and how the all-clear or shift handover is communicated.
7. Correct and retest the failed step
Update the contact, alarm label, roster, message template or authority rule. Then repeat the exact failed portion. Closing an action because a document changed is weaker than proving that the new path works.
Preserve the event sequence and earlier versions of records. The team should be able to reconstruct what was observed, which condition applied, who decided, what changed, how the result was tested and which limitation remained.
Who owns each decision
Exercise controller
Sets boundaries, prevents confusion with a real emergency, pauses the test if needed and protects any personal or recorded data.
Duty recipient
Verifies the message safely, acknowledges it, accepts or escalates authority, starts the correct procedure and reports back.
Incident or continuity lead
Makes site-level decisions, coordinates external calls and ensures that life safety overrides crop-protection activity.
Observer and records lead
Captures exact times, message changes, missed contacts, decisions and corrective actions without coaching the participants.
Release evidence before the next step
Call the communication path ready only when the intended first recipient, alternate and decision owner have each demonstrated their role, the message stayed accurate, acknowledgement was explicit, offline information was accessible and failed items were corrected and retested. A mass message with no acknowledgement does not prove readiness.
Common failure modes
| Failure | Buyer response |
|---|---|
| The test is announced to every participant | Keep safety controls and exercise authorization, but test the real duty path rather than a rehearsed sequence of waiting people. |
| Success means the phone rang | Require read-back, accepted authority, correct action and a callback that closes the assignment. |
| Contacts have job titles but no alternates | Name duty-based primary and alternate roles for leave, travel, illness and night coverage. |
| Alarm labels do not match the site | Use a stable zone and equipment naming system across controls, drawings, procedures and messages. |
| The cloud list is the only copy | Maintain a controlled offline method and test it during a simulated network loss. |
| A test reaches emergency services unexpectedly | Coordinate and authorize external participation. Clearly mark simulations and use approved channels. |
Buyer decision questions
Who receives each critical alarm first at 02:00? What exact message do they see? Can they identify the site and zone without logging into another system? How do they acknowledge responsibility? When does the call move to an alternate? Which channel works during a network or mobile outage? Who may call emergency services, stop production, authorize spending and issue the all-clear?
Keep these decisions connected to the alarm priority and escalation matrix, the business continuity plan, the operator competency checklist. The emergency plan, equipment evidence and crop plan should describe the same operating reality.
Frequently asked questions
Should every employee be in the same call tree?
No. Separate life-safety notification, worker accounting, technical escalation, crop decisions and business communications while keeping their interfaces clear.
Can messaging apps replace phone calls?
They can be one channel if approved, secure and available, but the plan still needs acknowledgement, alternates and a route that works when data service fails.
How should response time be set?
Base it on the site's hazard and crop consequence, local requirements and the action expected. Do not copy one universal time into every alarm.
Should contractors receive direct control-system alarms?
Only where responsibilities, access, privacy, authority and response expectations are written. The site must still own the operational decision.
What if the test finds an unreachable manager?
Use the approved alternate, record the gap, correct the roster or coverage rule and retest. Do not leave a critical decision dependent on one person.
Turn the requirement into a controlled deliverable
Provide the alarm list, duty roster, site naming convention, escalation matrix and current communication channels. Chengfei Greenhouse can help clarify alarm and control-system information for supplied equipment while the owner completes emergency authority and local notification requirements.
Contact Chengfei Greenhouse
