All Products performance+

bazefield operations+

Designed for customers who need remote command & control of their assets. operations+ adds overlay SCADA write-access, control schedules, workflow automation, and ROC tooling to the Bazefield portal. For customers with strict cyber-security requirements, an optional second OT portal can be deployed on the OT network, physically segregated from IT. Data replicates from OT to IT so both environments stay in sync — most customers keep critical control tags in OT and full telemetry in IT, though some mirror everything in both.

Request a Demo See the Architecture
Core Operations vs operations+
Every Bazefield customer gets core operations management — event workflows, case tracking, and availability planning. operations+ adds an enterprise-grade overlay control architecture with remote and local command execution.

Core Operations

Included in all Bazefield bundles
  • Dedicated set of applications for real-time operational intelligence in Bazefield-hosted or self-hosted IT environment
  • Event & asset-driven workflows, escalations, and notifications
  • Event triaging and alarm investigation
  • Audible, email, and pop-up alerts
  • Incident tracking, assignment, and resolution workflows
  • Root cause analysis tracking
  • Schedule and track planned and unplanned outages
  • Configurable alerts and subscriptions on events, allocations, and real-time telemetry
  • BI dashboards and reporting
  • CMMS Integrator for field service management (SAP PM, Maximo, IFS)

operations+

Everything in Core Operations, plus…
  • Optional dedicated OT portal for segregated overlay command & control, with write-access to first-level SCADA
  • Stop, start, reset commands on any controllable asset
  • Specialized ROC-state map — compact asset operations view built for remote operating centres
  • Flexible control schedules for curtailments and shutdowns
  • Local site buffer for scheduled controls when communication is lost
  • Multi-step Flow-driven workflow controls with verification
  • Single Line Diagram Creator for live HMI visualisation
  • Command notifications and execution statistics
  • Hot ROC failover — backup remote operating centre for business continuity
  • Data engine high availability — clustered failover with write fencing and command dedup
  • IEC 62443 zone architecture — defence-in-depth cyber security by design
  • NERC CIP compliant for North American medium and high impact installations
Full capability comparison
Detailed breakdown of what ships in Core Operations versus what operations+ unlocks. Blue checks are included in every Bazefield bundle. Green checks require the operations+ bundle.
Capability Core operations+
Event & Alarm Management
Event-driven workflows and escalations
Enhanced
Alarm investigation and triaging
Enhanced
Audible, email, and pop-up notifications
Notification Hub — configurable subscriptions
Case Management
Incident tracking, assignment, and resolution
Root cause analysis tracking
Command execution statistics in event operations
Availability & Outage Planning
Availability planner (planned/unplanned outages)
Control schedules for known curtailments and shutdowns
Automated curtailment rules and scheduling
Asset Control & Commands
Stop / start / reset commands on controllable assets
Overlay write-access to first-level SCADA systems
Command verification and acknowledgement
Notifications on failed or successful commands
Control logs and audit trail
Workflow Automation
Multi-step Flow-driven controls (change mode → verify → stop)
Deterministic event-driven workflow automations
Automated escalation and case creation
Network & Resilience
Optional dedicated OT-network portal (full Bazefield portal, cyber-security separated)
Hot ROC failover (backup remote operating centre)
Data engine clustering (automatic HA failover)
Write fencing & command deduplication (no duplicate SCADA commands)
OPC UA redundant server connections
Localized control service (site-level IT/OT relay)
Local site buffer for scheduled controls on communication loss
Localized control interface (on-site web UI) Roadmap
Cyber Security
IEC 62443 zone and conduit architecture
Mutual TLS with certificate pinning on IT/OT relay
Command-level RBAC and authorisation
Full audit trail on all control actions
One-way data flow (OT → IT, no inbound to OT control plane)
NERC CIP compliant for North American medium and high impact installations
Visualisation
BI dashboards and reporting
Single Line Diagram Creator (per-site HMI)
ROC-state map — compact asset operations view for remote operating centres
Live balance-of-plant heads-up display
Integrations
CMMS Integrator for field service management (SAP PM, Maximo, IFS)
IT/OT overlay control architecture
operations+ adds overlay SCADA write-access to the Bazefield portal. For customers with strict cyber-security requirements, an optional second OT portal can be deployed on the OT network, physically segregated from IT. When deployed, the OT portal is supervisory across all controllable assets, with its own data engine writing directly to first-level SCADA systems. Data replicates from OT to IT so that asset managers, performance engineers, and executives see the same telemetry without touching the control plane. Most customers keep only critical control tags in OT and route full asset telemetry to IT; some mirror everything in both environments.

IT Portal — Asset Management

  • Full Bazefield portal for monitoring, analytics, and reporting
  • All asset telemetry, KPIs, dashboards, and BI apps
  • Event Operations, case management, and availability planning
  • Receives replicated data from OT portal
  • No SCADA write-access — read-only view of the fleet
  • Hot ROC failover — backup ROC takes over seamlessly if primary goes down
  • Accessible to all stakeholders (performance engineers, asset managers, executives)
Secure
IT/OT
Relay
Data replication
OT → IT

OT Portal — Command & Control

  • Full Bazefield portal on the OT network — supervisory across all sites
  • Data engine with SCADA write-access for overlay control commands
  • Data engine clustering — automatic failover with write fencing (no duplicate commands)
  • Stop, start, reset, setpoint, mode change, curtailment
  • Control schedules with local buffer for communication-loss resilience
  • Workflow automation engine (Flow runtime)
  • Critical control tags — or full telemetry mirror, customer’s choice
  • Restricted access — ROC operators and authorised control staff only
Not just one-shot commands
operations+ supports multi-step, Flow-driven control sequences with verification at every stage. Change mode, verify the state change, then proceed — with automatic rollback if a step fails. No more manual, one-command-at-a-time operations.
1

Initiate control plan

Operator selects a control schedule or triggers a manual command from the ROC portal. The plan can target a single asset or a group — e.g. curtail all turbines in sector B.

2

Change mode & verify

The workflow automation engine sends the mode change command to the local data engine, which writes to the SCADA system. The engine polls the asset state and verifies the mode change was acknowledged before proceeding.

3

Execute command sequence

Once mode is verified, the next command fires — stop, curtail, reset, or set a new power setpoint. Each step waits for SCADA confirmation. If verification fails, the workflow can retry, escalate, or roll back.

4

Notify & log

Success or failure notifications fire to the configured channels. The full command chain is logged in Event Operations with timestamps, user, asset, and outcome — feeding long-term control statistics and audit compliance.

What operations+ delivers
Deep-dive into the capabilities that make operations+ an enterprise-grade remote operations platform.

Overlay Control

Write-access overlay on any asset whose first-level SCADA supports command execution from the local data engine. Stop, start, reset, curtail — without replacing your existing SCADA infrastructure.

Control Schedules

Plan curtailments, shutdowns, and maintenance windows well in advance. Flexible scheduling with recurring patterns, one-time events, and group-level targets across any asset class.

Local Site Buffer

When communication from the centralised ROC is lost, the on-site data engine continues executing scheduled controls autonomously. Commands are buffered locally and synced when connectivity returns.

Workflow Automation

Multi-step, Flow-driven control sequences. Change mode → verify → stop machine. Not one-shot commands — deterministic workflows with branching, retry logic, and automatic escalation.

Command Notifications

Real-time notifications on command success or failure. Configurable channels — email, pop-up, webhook. Failed commands trigger escalation workflows automatically.

Execution Statistics

Every command is tracked through Event Operations. View execution rates, failure counts, average response times, and command history per asset — feeding long-term reliability analysis.

Single Line Diagrams

Visual editor for building per-site single-line diagrams. Drag-and-drop electrical symbols — breakers, transformers, feeders, busbars. Bound to real-time SCADA points for a live HMI heads-up display on all balance-of-plant assets.

OT Portal Separation

A full Bazefield portal deployed on the OT network, physically or logically separated from the IT portal. The OT portal is supervisory across all controllable assets — not just a site-level service. Data replicates from OT to IT so both portals stay in sync. Meets IEC 62443 zone separation requirements.

Hot ROC Failover

Backup remote operating centre for business continuity. If the primary ROC goes down, a hot standby takes over with zero downtime — operators switch seamlessly to the backup environment with full command authority, live telemetry, and active control schedule state intact.

Data Engine High Availability

Clustered data engine with automatic failover. Two-node heartbeat mode fails over in ~6 seconds; three-node Raft consensus in ~300 milliseconds — with zero external dependencies. Write fencing ensures only the elected leader writes to SCADA, and four-layer command deduplication guarantees no duplicate control commands reach physical equipment. OPC UA redundant connections provide automatic failover between redundant SCADA server endpoints.

Localized Control Roadmap

Site-local web UI for on-site operators to execute control actions without centralised ROC access. Runs on the Localized Control Service within the site OT network.

Defence-in-depth for critical infrastructure
operations+ is built for environments where cyber security is non-negotiable. Every layer of the architecture is designed to meet or exceed the requirements of IEC 62443, IEC 61850, and national critical infrastructure protection frameworks.

IEC 62443 zone and conduit architecture

The IT and OT portals run on physically or logically separated network segments. No direct network path exists between the internet and the OT control plane. Communication between zones passes through a secure relay conduit — fully aligned with IEC 62443 zone and conduit requirements for industrial automation and control systems.

Mutual TLS with certificate pinning

The IT/OT relay authenticates both endpoints with mutual TLS and pins certificates to prevent man-in-the-middle attacks. Certificates are rotated on schedule. No self-signed certificates — no trust-on-first-use shortcuts.

Command-level authorisation and RBAC

Every control command passes through role-based access control with per-command authorisation. Operators are granted explicit permissions for specific command types on specific assets. Privilege escalation requires multi-step approval. The IT portal has no SCADA write-access — a compromised IT environment cannot inject commands into the OT control plane.

Full audit trail

Every command — manual, scheduled, or automated — is recorded with timestamp, issuing user, target asset, command type, and outcome. Audit logs are immutable, tamper-evident, and available for regulatory review. No control action executes without a trace.

One-way data flow

Data replicates from OT to IT — never the reverse. The IT portal receives telemetry, alarms, and execution logs for monitoring and reporting. Control commands originate from authenticated ROC sessions on the OT portal and are validated at the relay boundary before reaching the control plane.

Hot ROC failover

Backup remote operating centre provides instant failover if the primary ROC is compromised, loses connectivity, or requires maintenance. Control authority transfers seamlessly to the standby environment — no manual reconfiguration, no gap in supervisory coverage, no loss of scheduled control state.

Flexible deployment for every infrastructure
operations+ adapts to your network topology. The IT portal can run in the cloud or on-premise. The OT portal runs on the OT network — on-site or in a dedicated OT segment — with data replicating back to IT.

Bazefield-Hosted (Azure) Recommended

IT portal hosted in Microsoft Azure. OT portal deployed on your OT network with data replication back to IT.

  • Zero-ops IT portal — we manage hosting, updates, and monitoring
  • OT portal with full SCADA write-access on OT network
  • Secure relay replicates data OT → IT

Customer Cloud

IT portal in your own Azure, AWS, or GCP tenant. OT portal on your OT network as always.

  • Full control over IT infrastructure and data residency
  • Same OT portal architecture as hosted
  • Your team manages patching and scaling for both portals

On-Premise (IT) Requires Data Platform+

Full Bazefield stack on your corporate IT network. OT control layer on site network.

  • Air-gapped or restricted-internet deployments
  • Full data sovereignty
  • IT/OT relay over internal WAN

On-Premise (OT)

When deployed, the optional second OT portal runs on the OT network. Control commands execute within the OT-segregated environment for safety and compliance. Not all customers require this — operations+ works as a single portal where security requirements allow.

  • Full Bazefield portal with SCADA write-access
  • Supervisory across all controllable assets
  • Local command buffer and scheduling
  • IEC 62443 zone compliant
Common questions about operations+
What SCADA systems can operations+ control?
Any asset whose first-level SCADA system provides write-access through the Bazefield data engine. This includes OPC UA, OPC DA, Modbus TCP, IEC 61850, IEC 60870-5-104, and vendor-proprietary APIs. The data engine acts as the translation layer — operations+ doesn’t need to speak every protocol directly.
What happens if the connection between the ROC and site drops?
The local site buffer on the data engine continues executing any scheduled control plans autonomously. When connectivity returns, execution logs sync back to the central portal. Manual ad-hoc commands cannot be sent during an outage, but pre-scheduled actions (curtailments, shutdowns, automated workflows) run uninterrupted.
How are multi-step controls different from one-shot commands?
One-shot commands fire a single instruction (e.g. “stop turbine”) with no verification. Multi-step Flow controls chain multiple commands with state checks between each step — for example: set mode to maintenance → verify mode change acknowledged → ramp down power → verify ramp complete → stop machine. If any step fails, the workflow can retry, escalate to an operator, or execute a rollback sequence.
Is the OT portal on a separate network from the IT portal?
Yes. The OT portal is a full Bazefield portal deployed on the OT network, supervisory across all controllable assets. The IT portal handles asset management, analytics, and reporting. Data replicates from OT to IT through a secure relay with mutual TLS and certificate pinning — no direct network path exists between the internet and the OT control plane. Most customers keep critical control tags in OT and full telemetry in IT, but the architecture supports mirroring everything in both environments. This follows IEC 62443 zone and conduit architecture.
Can I schedule curtailments weeks in advance?
Yes. Control schedules support one-time events, recurring patterns, and time-windowed rules. You can plan grid-mandated curtailments, seasonal shutdowns, or maintenance windows as far ahead as needed. Schedules are pushed to the local site buffer so they execute regardless of central connectivity.
What is the Single Line Diagram Creator?
A visual editor for building per-site single-line diagrams (SLDs) that serve as live HMI screens. Drag and drop electrical symbols — breakers, transformers, feeders, busbars — and bind them to real-time SCADA data points. The result is a heads-up display showing the live state of all balance-of-plant assets, updated in real time, accessible from the ROC portal.
How are command outcomes tracked?
Every command — whether manual, scheduled, or Flow-driven — is logged in Event Operations with full metadata: timestamp, issuing user, target asset, command type, outcome (success/failure/timeout), and execution duration. Notifications fire on both success and failure. Aggregate statistics are available in BI dashboards for long-term reliability analysis.
What happens if the primary ROC goes down?
operations+ supports hot ROC failover. A backup remote operating centre runs as a warm standby with synchronised state. If the primary ROC loses connectivity or is taken offline for maintenance, control authority transfers seamlessly to the backup — no manual reconfiguration, no gap in supervisory coverage. Active control schedules, pending commands, and operator sessions continue uninterrupted on the failover environment.
What happens if a data engine node fails?
The data engine supports clustered high availability with automatic failover. In a two-node deployment, a heartbeat monitor detects failure and promotes the standby within ~6 seconds. In a three-or-more-node deployment, embedded Raft consensus elects a new leader in ~300 milliseconds with no external infrastructure required. Write fencing ensures only the elected leader can issue commands to SCADA — preventing duplicate or conflicting control actions during failover. Additionally, OPC UA redundant connections automatically cycle through backup SCADA server endpoints if the primary OPC UA server goes offline.
What cyber security standards does operations+ align with?
operations+ is designed around IEC 62443 (industrial automation and control system security) zone and conduit architecture. The IT/OT separation, mutual TLS relay, command-level RBAC, one-way data flow, and full audit trail are all aligned with IEC 62443 security levels. The architecture also supports compliance with national critical infrastructure protection frameworks (NIS2, NERC CIP, BSI IT-Grundschutz) depending on jurisdiction and deployment model.
Do I need operations+ to use case management?
No. Case management, event workflows, availability planning, and the notification hub are all part of Core Operations — included in every Bazefield bundle. operations+ adds the control architecture, workflow automation engine, SLD creator, and OT portal separation on top of the core.