Module

Management of Change No change that alters the facility's risk happens without one person assessing it and a different person authorizing it — and two years on, anyone can reconstruct who decided what, when, with which information in view and under what authority.

We know who signed. We don't know what they had in front of them when they signed. That is the problem.

Records board: Every change in its state, from draft to close. Moving a card approves nothing: the record advances from its own page, with its signatures.
Six-step request: Identification, change, scope, review and approval, impact and schedule. It starts as a draft and nothing applies until the signature chain authorises it.
History integrity: Every decision is sealed when it is recorded. The check detects whether a record was modified, deleted or reordered.
Demonstration environment

The problem

What happens today at a facility

A change in the deposition rate, the pond level, a TARP threshold or the responsible engineer alters the facility's risk even if not a single cubic metre of earth moves. Without a formal record, those changes happen as catalogue edits: someone changes a value on a screen, nobody assesses the effect, and the next review finds a TARP pointing at an instrument that no longer exists.

And there is a second problem, the one you pay for in the audit: the decision existed, but the context of the decision was never kept. You know who signed. You don't know what they were looking at when they did.

The usual practice today is a paper procedure and a shared folder. The procedure exists; the question is whether the record survives the turnover of the people who ran it. Twin Mining TMS treats every change as a record that can be defended.

What it does

Capabilities, with their nuance.

  1. Impact graph: nothing is inferred from nothing

    When a change is proposed, the system shows which instruments, thresholds, documents and procedures are affected. Every edge corresponds to a real relationship in the data model and declares whether it is stated or derived; none is invented by a language model. The result starts the record — it does not skip it.

    Impact graph for a sample change — decommissioning a piezometer after signal loss — fanning out from the instrument node to the affected nodes, labelled as open record, document, TARP threshold and failure mode, with the button to generate the change workflow in a demonstration environment.
    Every edge in the fan corresponds to a real relationship in the data model; none is invented by a model.
  1. A formal record with thirteen states

    Every change that alters the facility's risk runs through a thirteen-state flow, from draft to closure: regulatory screening, impact assessment, Engineer of Record conformance, approval, authorization, execution, verification. The order of the list is the order of the work.

  2. Segregation of duties, no exceptions

    Whoever requests does not approve; whoever executes does not verify. There is no administrator path around it, and an automated test watches that none appears.

  3. The approval level is computed and justified

    A rules engine computes who has to sign and returns which rule produced it. An automatic escalation can be justified to an auditor by pointing at the row that caused it.

  4. "Not applicable" is a signed assessment

    The impact matrix has eight fixed dimensions. The system distinguishes between deciding something does not apply and nobody having looked at it; in a spreadsheet the two look identical.

  5. A record that cannot be silently tampered with

    Events are hash-chained per facility, not per record, with a verifier that returns a report rather than a boolean. We don't claim the record cannot be altered: we claim that if someone touches it, it shows, and it shows where.

  6. An audit package organized by question

    It exports structured by question rather than by table: what, who, when, with which information in view, under what authority and with what integrity. PDF to sign, JSON to re-verify the hashes, plain text to diff.

"Not applicable" is an engineering decision. "Nobody looked" is not. In a spreadsheet they look the same.

Scope

What it decides and what it does not

What it works out on its own

It decides what can be done now and what is missing. It computes who has to sign — the approval level is a conclusion of a rules engine, not a choice — and makes sure the person approving is not the person who requested.

What it never decides

It does not decide whether a change is a good idea: a person signs that. And an agent never takes part in evaluating transitions: it writes suggestion events, and only the human confirmation — a second event with its own author and date — moves the state.

Honesty

What it does not do yet, on purpose.

We would rather say it before the first meeting.

  • The TARP threshold lock is currently in observe mode: it records the violation, it does not block it. That is deliberate: every existing threshold predates the module, and enforcing it would lock the screen for the whole team. The observation period buys the evidence.
  • Today nobody can sign a change, because role appointments have no person assigned. You can create, advance, execute and cancel; you cannot sign. That is deliberate: a platform role never becomes technical authority.
  • We don't say the record is unalterable. That would be weaker, and also false. We say it is tamper-evident: if someone rewrites it, it shows, and it shows where.
  • Inspections and Maintenance appear in the menu and do not open. They are not part of what is shown.

Who it is for

Who comes in through here

  • RTFE — Responsible Tailings Facility Engineer Something crosses a threshold and they find out late.
  • Engineer of Record Something that compromises their design gets changed without anyone asking them.
  • Dam Owner / Accountable Executive The portfolio: which facility is worst off, and why.
  • Geotechnical engineer A value they know is written down in some report.
  • Independent reviewer / auditor That the trail does not exist.

Frequently asked questions

What people usually ask about this module

Short answers with no overclaiming. If something is not built yet, we say so.

Who signs a change in Twin Mining TMS, and can an administrator sign it?

The person holding the role that matches the approval level signs, and nobody picks that level: a rules engine computes it and returns which rule produced it. Whoever requests does not approve, and whoever executes does not verify. There is no administrator path around that segregation, and an automated test fails if one appears.

Today, moreover, nobody can sign yet: role appointments have no person assigned. A change can be created, advanced, executed and cancelled; it cannot be signed. That is deliberate: a platform role never becomes technical authority. An AI agent does not sign either: it proposes, cites, and signs its proposal with model and prompt version, and a person decides.

Is the impact graph generated by artificial intelligence?

No, and that is exactly the opposite of what makes it reliable. When a change is proposed, the system shows which instruments, thresholds, documents and procedures are affected, and every edge in the graph corresponds to a real relationship in the data model: a foreign key, a join table, an index. None is invented by a language model, and each one declares whether it is stated or derived.

The result starts the management-of-change record; it does not skip it. The button says "generate change workflow", not "apply".

What is a TARP in tailings facility management?

TARP stands for Trigger Action Response Plan. It is the set of threshold bands for an instrument — green, amber, red — together with the response defined for each: which actions are mandatory, who must approve them, and who must be notified.

Explained to someone outside the sector: it is a sensor's traffic light, plus what has to happen when it changes colour.

In Twin Mining TMS the threshold, the response, and the document backing it live on the same screen, and changing a threshold goes through a formal management-of-change record. That last link is what separates a TMS from a monitoring system.

Does Twin Mining's artificial intelligence make decisions on its own?

No. Agents propose and cite; people decide. This is not a stated policy: it is in the data model. An agent suggestion enters a state that blocks until a person confirms it, and that confirmation is a second event with its own author and timestamp.

An agent never takes part in evaluating state transitions, and every verdict is signed with the model and prompt version that produced it, so an external reviewer can reconstruct where it came from.

Nothing is inferred from nothing either: every edge of the impact graph corresponds to a real relationship in the data model and declares whether it is stated or derived. Deterministic computation first, model narration second — inverting that order would let the model invent the pattern with no way to check it.

Request a demonstration

Let's talk about your facility.

Tell us which facility you manage and what keeps you up at night. We will walk you through the demonstration environment with someone from the team, module by module, and tell you frankly what is built and what is not.

  • We reply within 24 business hours
  • Guided demonstration, tailored to your operation
  • No commitment. There is no public price: we talk

We use your details only to reply. No lists, no forwarding.