WCM One

Find your pillar. Here is what runs under it.

Ten pillars is how a plant is run and how an assessment is scored, so it is how this page is written. The product is built the same way underneath: every pillar is a row with its own step progress, its own versioned audit checklist and its own evidence pack, and the blue room reads all ten from one query.

10

One spine, so the numbers agree across all of them.

Every fact carries the same three dimensions — where on the org tree, when in the cost-deployment year, which pillar owns it. A rollup is always the sum of its children, and one pillar’s loss is priced in the same ledger and the same currency as every other pillar’s.

PM

Professional Maintenance

The machine ledger is the system of record — components, their maintenance lines, the standard sheet those lines read out as, and the fifty-two week board they land on.

  • The standard sheet and the 52-week plan board: TBM, CBM, hour-based, AM and quality check points per component, generated idempotently so a plan slot can never be re-planned over a recorded outcome.
  • Adherence with two fences, both of them your own data. No figure leaves without the era that produced it, so a number measuring a migrated backfill can never appear under a caption naming your plant. And a machine nobody enrolled is not accused of missing a plan — it publishes no percentage and no missed cells, and enrolling it today mints zero missed weeks behind it.
  • One definition of adherence, so the argument stops: the plant total is the sum of the machine numbers a planner can open, re-derived from summed integers rather than averaged from percentages.
  • A line stop is raised from a phone in two taps; closing it prices the loss and raises the EWO under the same number. Stage gates refuse a stage the record cannot justify — no root cause, a countermeasure still open, a mandated action linked to nothing, and work the EWO itself mandated still running.
  • Condition-based maintenance the whole way: a tag register, one shared threshold evaluator, an alert that mints a tagging order and stamps the order reference back, and an adoption register that ranks which machines should stop being time-based in the order the money says.
PD

People Development

A skill matrix where “not assessed” is a first-class state, and a training loop that closes on evidence rather than on a calendar.

  • Person, topic and level on a fixed one-to-five scale with a required level and a required-by date. The eligibility engine keeps “not assessed” and “below required” apart and names which one it matched.
  • A session has its people before it happens: one write creates the session and its whole roster, and every roster row carries why that person is on it — an eligibility rule frozen into the row, a manual add, a breakdown obligation, a statutory requirement, or a no-show carried over.
  • On-the-job observation freezes the standard’s steps, its gates and its version at the moment of observation, and grants a practical level on a dated row naming the observer.
  • When a breakdown is root-caused to human capability the product demands the person be named — and then refuses to stop there. It asks what prevented correct execution, from a fixed list it will not let you extend, and any answer but “not trained” demands a system-fix countermeasure — so a plant that discovers the operator lacked the tool, the time, the standard or the access cannot send him on a course instead. The named person has a right of reply the closure gate respects.
  • The trainer register opens on an attribution ledger whose three buckets always sum to the total. Delivering a session does not by itself make somebody a trainer, nobody rates their own delivery, and one response publishes no average.
CD

Cost Deployment

A loss becomes money the moment the line stops, priced from a rate master your own finance seat filed and the database will not let anybody edit.

  • Every ledger row is the exact sum of its four named cost terms, and a journey asserts the sum. A loss the rate master cannot price stores nothing rather than zero, so no total silently swallows a figure that means “never measured”.
  • The rate master is effective-dated and append-only in the database, not in application code: a rate can only be superseded, a note is mandatory, and filing one tells you how many loss events it affects instead of quietly restating them.
  • A C-matrix crossing loss type against area, every cell drillable to exactly its own ledger rows and its own sum — and an area with no money this period draws a genuine zero rather than dropping the row, which is the defect a reviewer never spots.
  • Savings are claimed month by month and banked only after verification. A forecast cannot be banked, and every banked month names its signatory and the role they held at signature.
  • The loss taxonomy is pillar-coded across the whole plant, so every pillar’s losses land in one ledger, in one currency, priced the same way.
FI

Focused Improvement

The analysis toolkit is a set of gates rather than a form — and a learning that stops at one machine has not been deployed.

  • Five-W-one-H is all seven answers or nothing. Five-Why runs as parallel chains with a three-level cascade and a coherence check across them, and a verdict’s polarity is enforced so “nok” means confirmed rather than failed.
  • The stoppage is stratified into six phases that must sum to it exactly — a plant cannot report a repair that took longer or shorter than the machine was down.
  • Kaizen in four classes whose rules — duration, capex ceiling, team size, approval chain, required tools, minimum benefit-cost ratio — are your own master rows. The same chain opened at two values produces two different ladders, and the signatures the threshold skipped are named alongside the threshold that skipped them.
  • Horizontal deployment is the pillar’s teeth. A frequency change on one machine enumerates comparable machines, gives each a named owner with its own match basis and confidence, publishes a coverage number, and writes the sister machine’s own ledger line — recorded as applied rather than agreed, with a refusal that has to carry a reason.
QC

Quality Control

The QA matrix ranked by a Defect Priority Index the server computes, and an audit arc that will not close on a promise.

  • DPI is recomputed on every write from severity, occurrence and detection stage — never accepted from the caller — and re-derived across every referencing row the moment a defect mode’s severity or detection stage changes.
  • QM conditions are 4M standards per component, minted into Q-points; a NOK check puts a fact on the bus in the same transaction that records it. A containment opens an exposure window and will not close while any suspect unit is unaudited.
  • An audit run is conducted point by point with photo evidence demanded at capture rather than assembled afterwards, refuses completion while points are unanswered, and auto-fails on a critical NOK regardless of percentage.
  • Closure is a gauntlet: a resolution note, critical evidence, a verifier who must differ from the resolver, and an approval instance verified against the approvals service rather than accepted from the caller’s word for it.
  • Quality-critical tightening is its own spine — six tightening technologies with per-technology calibration regimes, station installations carrying the full history of which serial served which joint and when, an overdue-calibration list, and torque-change and tool-swap requests riding versioned approval chains.
SAF

Safety

Anybody on the floor raises a safety tag, and your own threshold decides when it has been open too long.

  • S-tags walk open → actioned → closed, and high-risk tags past the plant’s own threshold get their own overdue list carrying an integer age in days. Overdue means untouched, so opening a record does not reset its age.
  • JSRA and LOTO libraries are versioned: an edit is a new version, at most one version is approved at a time, and the previous one retires in the same transaction. A work order that says LOTO is required will not start until somebody confirms the isolation.
  • SMAT behavioural rounds with a monthly safe-act ratio computed as an exact string, never a float.
  • A safety-flavoured EWO creates its incident automatically and idempotently, and one incident belongs to one safety EWO — so the Heinrich pyramid can never count the same event twice, and it prints null rather than a ratio when the denominator is zero.
AM

Autonomous Activities

Which department owes which routine, at which cadence, against which subject — and whether they are adhering.

  • five routine kinds are first class — CIL, 5S, layered process audit, poka-yoke verification and torque check — each naming the versioned standard it runs against. A CIL routine cannot be activated while its standard is unapproved.
  • When a routine falls due it materialises as a real work order or a scheduled audit run, the artifact reference stamps back onto the occurrence, closing the work closes the adherence ledger, a nightly sweep marks what went past due as missed, and a monthly rollup publishes adherence per routine.
  • The operator and the line incharge see the routines due today on the same screen as their tasks, with every mutation going through the offline outbox.
  • A CIL round closes on the step gate alone: a skip demands a reason, a photo step demands the photo taken at the machine, and closure is refused while the sequence has gaps — with the missing step numbers named and linked rather than left for somebody to find.
EEM

Early Equipment Management

A capex project walks your own seven step-gates, and the handover gate reads the record rather than a tick.

  • Review templates are versioned and a review pins the version it ran against, so a gate passed last year cannot be re-read against this year’s checklist.
  • The first three gates refuse to pass until the design lessons your own breakdowns produced have been consulted, and the reference must name an MP-Info that exists. “Not applicable” is a legitimate disposition — in writing, with the reason.
  • Life-cycle cost compares alternatives on net present value in integer paise with pure-integer discounting, lowest total wins, and the discount rate is stamped on each scenario so a stored NPV stays reproducible.
  • The handover gate is the teeth. It verifies the day-one package from record links rather than manual ticks — a commissioned asset reference, active machine-ledger lines, a standard procedure linked to a component, an approved risk assessment, four weeks of ramp actuals and no open major punch item — and collects every failure into one refusal naming each. It is the one gate that can never be waived.
LOG

Logistics

The maintenance store: an append-only ledger the database itself enforces, a location tree down to the bin, and procurement that walks a real approval chain.

  • On-hand is never a stored column — it is the sum of an append-only ledger, enforced by a database trigger rather than an application check. Issue over the counter takes the quantity and the bin in one atomic call, so a shortage leaves no paper behind.
  • Store → rack → bin with transfers, cycle counts and a spare-first find. A reorder breach has consequences rather than a notification: a purchase-request draft and a Store work order, both raised automatically.
  • Procurement walks your own approval chain to a purchase order, then partial goods receipts with putaway, and lead-time actuals are derived from the ledger rather than typed in.
  • Valuation nets its negative bins and names them in their own report, so the headline can never exceed the sum of its own rows. A part booked to an EWO reaches three seats at once — the craftsman’s workbook, the storekeeper’s where-used and the controller’s money — with nobody recomputing anything.
ENE

Environment & Energy

A metering tree that mirrors the plant rather than a spreadsheet, and a residual that is always named.

  • Utility, sub, machine and virtual meters, each anchored to an org unit or a machine by the same reference the rest of the product uses, with parent-child structure and apportionment rules where submetering does not exist.
  • Readings are exact decimals on the wire and in the database. Arithmetic runs on scaled integers and money in integer minor units, so no float ever touches a consumption or a cost, and a duplicate reading on the same meter and timestamp is refused rather than averaged in.
  • The per-vector summary carries consumption, cost and CO₂e over a window — and always reports the unmetered residual. A plant that submeters sixty per cent of its load should see the other forty named, not absorbed.
  • Energy loss tags — leaks, idle running, standby — walk open → actioned → closed like any other abnormality, and energy loss, compressed-air leak and kilowatt-hours saved are priced from the same rate master as everything else in the plant.

The record everything hangs on

The machine ledger is the system of record, not a report you generate.

And it is the sheet your auditor already reads — the standard OMS layout, populated from live records, printable at A2.

When a WCM assessor asks how the plan evolved, the answer is one screen.

The plan comes from it
Fifty-two week cells per component — TBM, CBM, hour-based, AM and quality check points — where marking a week executed or missed, or moving a plan with a reason, happens in the cell itself.
The breakdown lands on it
The stoppage is recorded on the row that owns the component, next to the plan it interrupted.
The frequency change is logged against it
Old → new with its evidence, and the approval spawns the horizontal-deployment task automatically.
The cost sheet is derived from it
Not maintained beside it in a workbook that disagrees by the end of the quarter.
A component linkage is never faked on it
A legacy reference that matches neither the component’s code nor its name nor a station-scoped reference is attributed to no component row rather than guessed into one, and the column stays empty.
It says when it cannot be drawn
On a small phone the sheet does not pretend: it hands back a plain grid and a sentence asking for a larger screen, rather than a broken document an auditor would have to argue with.

Not pillar-shaped

The rest of what a plant is actually buying.

A phone that keeps working in a dead zone, exports that agree with the screen, three languages, many plants on one deployment — and an agent that checks the plan and cannot write to it.

The phone in a dead zone
The technician’s module is built for a phone that loses signal at the machine. Every mutation — a step tick, a reading, a photo, a line stop, a safety tag — is queued in a browser outbox and replayed on reconnect, and the tray shows pending AND failed, so it can never say “synced” while a rejected write sits in the store. Reads are warmed too, and deliberately bounded: the tasklist, each task’s procedure with its step text and safety flags, the machine’s recent EWOs, and the parts issued against them down to store, rack and bin.
Excel that agrees with the screen
thirteen registers export as a real server-side workbook, and the export is handed the same query the screen just fetched with — the search text, the filter chips and the sort travel verbatim, so an export cannot quietly become a second, laxer API. It refuses exactly what the list refuses. The workbook speaks the reader’s own language, headers and filename included. Three documents print: the monthly summary, the machine ledger and the EWO one-pager.
The WCM agent — it checks, and it cannot write
The agent watches your own events and writes findings that appear next to the document they concern. It cannot write a domain record, close a gate or change a number, and a human may dismiss any finding with a reason that lands on an immutable log. Every finding renders the inputs the check read and the threshold it compared them against, so the argument is with the data. five deterministic checks ship, and whether one runs at all is your data: no active row, no evaluation. A judgment layer can additionally read a five-Why chain and say whether it reaches a systemic root cause or restates the symptom — on its own queue, so a model call never sits in front of the deterministic lane.
Many plants on one deployment, isolated for real
A cell is one self-contained regional deployment — one database, one bus, one identity realm, one gateway — and cells share nothing at all, not even a config field in which one could name another. Inside a cell, plants share the database and nothing else: there is no default tenant anywhere, every tenant-stamped table has row-level security FORCED rather than merely enabled, and the application role is created unable to bypass it — the cell refuses to boot if it could. Exactly five named background workers may cross plants, and adding one more takes four deliberate edits in four files that must agree.
Condition monitoring, and a board that earns its colours
Your gateway publishes on your topics in your dialect, and this system invents nothing from that traffic: an unrecognised key is quarantined with the key kept so somebody can map it, units are never converted, a retired tag’s reading is refused, and a replay after an outage is a counted duplicate rather than a second alarm. The health board reads all of it and one thing besides — it is composed from four signals rather than from sensors, because on a real plant almost none of the colour comes from instrumentation. Plant → shop → line → machine, worst first, refreshing itself because a wallboard is not reloaded by hand.
English, Hindi and Marathi
The whole application is translated three ways — 5,438 interface strings in each, held identical by a guard in the pipeline, so a new English string cannot ship without its Hindi and Marathi counterparts. The choice is stored per reader and sets the document language, and it reaches the exports: the workbook a Marathi reader downloads has Marathi headers and a Marathi filename.
Approval chains anything can hang on
One engine, configured by you: versioned chain definitions where an edit is a new version and old versions are never mutated, one approval instance per subject snapshotting the version it opened against, and step decisions that are immutable once taken and carry a server-computed signature. Steps sharing a sequence advance together as a parallel group; any rejection closes the instance. Purchase requests, kaizen gates, torque-parameter changes, tool swaps and quality-observation closures all ride it without the engine knowing their domains.
The controlled-document register
The register an auditor asks for second: what is controlled, at which revision, approved by whom, and what it is attached to. Governance owns the register while the governed content stays with the service that owns it, so a procedure is registered here and lives in the maintenance ledger. The stamps printed on the report library’s cards are read from this register rather than typed, so the library and the printed footer cannot disagree.
A plant’s own facts arrive as workbooks
Org units, machines, people and masters arrive in bulk as workbooks, with a preview before the commit and an honest account of what landed — a bad row fails loudly and the counts reconcile. The set-up screen is a checklist read from the plant’s own data rather than a wizard with a cursor, so it stays truthful long after the first week. The role vocabulary arrives with the plant, which breaks the circle where no role meant no administrator meant no way to create a role.
Escalation and one inbox
Work that ages escalates on your own matrix, configured on a screen rather than in a deployment. The person who raised a line stop is told when the loop closes on it. One inbox address works for everybody and shows each person what is theirs, rather than needing two deep links for two audiences.
Every list honours your filter, or refuses it by name
A register either answers the query you gave it or refuses it and says which parameter it would not take. It never returns the whole register while looking like a filtered view — and the export is held to the same rule, on every journey run, across work, KPI, breakdown, cost, early-equipment and the safety tag register.
What a finding looks likeRendered as the craftsman sees it, on the document it concerns. Illustrative values on a real rule.
Soft gaterule · FREQ-GATE-01

The proposed interval is outside the reliability window.

mtbf 41 dσ 13.9 dσ/mtbf 0.34proposed 14 dmtbf − 2σ 13.2 d

PM pillar, step 4 — time-based maintenance holds while σ/MTBF ≤ 0.2. Beyond that, screen for condition-based work instead of shortening the interval.

A soft gate takes a dismissal with a reason, and the reason becomes its own audit signal.

22 services behind it, walked end to end by 26 journeys that run against a live stack rather than a mock. Counted from the repository at publish time, not typed here — every figure on this site is re-derived before the page is built. Verified against the running application on 11 August 2026.

See it against your plant

Bring one machine and one bad month.

Bring the ledger for a machine you argue about, and the breakdown history behind it — we will walk the EWO loop, the six-phase stoppage split and the frequency logic against your own data, and you can judge whether the method holds.