The Seveso III event happens at 04:12 — and the notification chain depends on somebody remembering who is on call.
The Seveso III Directive requires a clear notification chain, with evidence of who read what and when. The reality: at 4 in the morning, that chain rests on memory and a paper diary. iLEAN Connect fires the SMS to the on-call manager, starts a countdown and escalates to the night shift if there is no confirmation. The log is signed — the inspection does not have to assume anything.
The notification chain is perfect on paper — and depends on a human being awake at 4 in the morning.
In an upper-tier Seveso III plant, the Internal Emergency Plan defines the chain in detail: calling order, maximum response times, escalation, record keeping. In practice, the chain holds together like this:
- The SCADA or the SIS detect the event and trigger a local alarm. The control room operator phones the on-call manager.
- The on-call manager does not answer. It is night, they are asleep, the phone is on silent. The operator calls the second name. And the third. Each call costs a minute.
- When somebody finally answers, the time, the event and who was notified are written down by hand. If it had to be escalated to the authorities (civil protection, the town council), the chain continues.
- The next day, somebody reconstructs the log for the plant manager. And if the competent authority's inspection arrives, it has to be reconstructed again, with less detail.
The problem is not the plan: it is that executing the plan depends on memory and a diary. And the night the plan fails is the night the inspection discovers the log does not add up.
iLEAN does not write your Emergency Plan — it executes the one you already have, without anyone having to remember it.
The problem is not a lack of protocol: it is that the protocol lives in a PDF on a shared drive, and at 4 in the morning nobody opens it. iLEAN Connect acts as the putty between the event detected by the SCADA/SIS and the human chain, without asking you to change your control system or your emergency plan.
Connect fires the SMS, counts the time, escalates if nobody confirms, and records every signed hop. The plan runs by itself only in the notification part — the person decides in the part that matters.
The iLEAN pieces applied to Seveso III SMS escalation:
- Connect — the outbound voice over SMS. Dual gateway (different carriers) and fallback to an automated voice call. Loaded with the on-call calendar and the notification chain. It is bidirectional: the on-call manager's confirmation (replying OK, clicking the link, picking up the call) enters the system at second zero.
- Agents — the chain with a countdown. The agent classifies the event by Seveso category, locates the active on-call manager according to the calendar, sends the SMS, starts the configurable countdown and, if there is no confirmation, escalates to the next person. It carries the clock and the evidence while the person lives their life — and when the inspection arrives, the log is complete, signed and exportable.
- The three rings. SCADA/SIS events enter ring 3 through a passive mailbox: Connect never opens inbound connections into the OT network. The validation chamber (ring 2) verifies category and threshold. Ring 1 keeps the master record of the chain that was executed. The plant manager can review the log cold without exposing the OT network.
Manual call chains vs. SMS with countdown and a signed log
| Aspect | Manual call chain | With iLEAN Connect + countdown |
|---|---|---|
| Primary notification channel | Manual phone call | SMS with carrier delivery confirmation |
| Time to first contact | Minutes per call, in series | Second zero, in parallel if the chain requires it |
| Escalation if nobody answers | The operator remembers and calls the next name | Automatic, with a configurable countdown |
| Backup if the mobile network fails | «We'll try again» | Dual SMS gateway + automated voice call |
| Log for the inspection | Reconstructed by hand the next day | Every hop timestamped and signed, exportable |
| Who decides and signs | The plant manager the next morning | The person at every hop — Connect does not decide |
Impact estimate for your plant — to be validated with your numbers.
The block below is an estimate to be validated with the specific data of your plant. We put it forward so the committee has an order of magnitude; we refine it during the diagnostic.
- Upper-tier Seveso III chemical plant, 3-5 on-call managers in rotation, proprietary SCADA/SIS, internal emergency plan approved by the authority. Pilot over the 4-6 most frequent event categories — the Pareto principle from the book applied to alerts.
- Dual SMS gateway + SCADA integration through a passive mailbox + on-call calendar loaded into Connect. First value expected within a few weeks: the first Seveso event with an automatic chain, countdown and signed log.
- Indicative payback between 4 and 9 months. Hard levers: control room operator hours given back (no more chaining phone calls), reduced regulatory risk at inspection (a defensible log is worth more than a reconstructed PDF), and reduced reaction time to a real event — the hard money is here, even if it is difficult to put in a table.
- Expected reduction in time-to-notify the on-call manager of ≥30% in the first quarter, conservatively — the ceiling is set by the on-call calendar and the mobile network.
And the plant manager's reasonable doubt
«What if the AI escalates wrongly and wakes up the person who wasn't on call?» — the escalation is not decided by the AI, it is decided by the on-call calendar loaded into Connect and by the notification chain in the Internal Emergency Plan. The AI executes what your plan says. Even so, the critical part is never decided alone: every SMS has a fast cancellation route for the plant manager, and SCADA false positives are filtered in the validation chamber (ring 2) before the SMS is fired. Reliability on anchored tasks (classifying an event by threshold, locating the contact on the calendar) is high — the best models brought the error below 1.5% on this type of task [1].
[1] OpenAI paper «Why Language Models Hallucinate», 2025 — on the reliability of AI in anchored tasks.
What people ask about Seveso III SMS escalation to the on-call shift
What does the Seveso III Directive require regarding alerts and on-call duty?
The Seveso III Directive (2012/18/EU) requires establishments handling dangerous substances above the Annex I thresholds to have an Internal Emergency Plan with a defined notification chain: who receives the alert, in what order, within what time, and what evidence remains of each step. The competent authority can ask you at any inspection for the log of the last activation: who received the alert, when they read it and what they did. The 24/7 chain of command outside working hours is the classic weak point.
Why SMS and not a messaging app or a proprietary app?
Because SMS is the channel with the smallest failure surface you have in the plant: it does not depend on mobile data, it does not depend on the app being installed, it does not depend on the phone's operating system being up to date, it does not depend on the Wi-Fi battery at the on-call manager's home. When the event is Seveso III you do not want a push notification that can get lost in a tab — you want the SMS that vibrates on the on-duty phone and that carries carrier delivery confirmation. Connect uses SMS as the minimum safety layer, and adds messaging app and voice call as redundancy.
How does the countdown and the escalation to the night shift work?
Connect sends the SMS to the active on-call manager according to the loaded shift calendar. It starts a configurable countdown (typically 3-5 minutes). If it receives no read confirmation (a STOP/OK reply by SMS or a click on the link), it escalates to the next person: night shift supervisor, substitute, plant manager. Every hop is timestamped and archived. The chain is defined by the Internal Emergency Plan; Connect executes it without anyone having to remember at 4 in the morning whose turn it was to be called.
What if the mobile network fails right when there is an event?
Connect has a dual SMS gateway (different carriers) and, if both fail, it falls back to an automated voice call with the same message. If all of that failed, Seveso III events stay queued in the system and are retried with backoff until confirmation or direct human intervention. The log keeps everything: who the system tried to reach, over which channel, with what result. The inspection wants to see that, not to assume that «the SMS never arrived because the carrier failed».
How does it integrate with the plant's SCADA / SIS events?
Connect reads SCADA or SIS events through whichever route the customer prefers: a shared log file, OPC UA, MQTT, or a webhook if the system allows it. It never opens inbound connections into the OT network — it reads from a passive mailbox. The agent classifies the event (Seveso tier and category), locates the active on-call manager in the calendar, sends the SMS and starts the countdown. Every step is signed for audit: it is exactly the three-ring pattern applied to the notification chain.
Tell us about your case and within 48h we'll send you the estimated ROI of SMS escalation for your Seveso III plant.
We work on your plant's real data, not on ours. Diagnostic with no commitment.
Request estimated ROI in 48h See iLEAN Connect