Offline is an operating mode, not an exception
19:05. Evening count unresolved, one unit without eMAR, one urgent release at 20:00. What safe degraded mode actually looks like.
Consider the tabletop. It is 19:05. The network has failed. The evening count is unresolved, Unit C has no electronic medication record, and one urgent release is scheduled for 20:00. Waiting for central systems is the fastest option administratively and the most dangerous one operationally. Letting each unit improvise is flexible and destroys consistency and evidence. The third option is the only defensible one: declare degraded mode.
Declare, control, sign, restore, reconcile, learn
Degraded mode is a named state with a named commander and a defined scope — not a period of silence. Local control continues for the three classes of work that cannot wait: count, medicines and release. Every action is signed with time, actor and source. On restore, services are validated, events reconcile with conflict detection, and the outage is reviewed as an operational event with a chronology and actions — not filed as an IT ticket.
What each protected class requires
- Count — signed unit sheets, with discrepancy resolution before any certification. Out-counts carry their own evidence and reconcile into the same total.
- Medicines — offline administration and omission with reasons, on the facility edge node, with clinical follow-up queued for restore.
- Release — live authority verification by phone protocol plus two-person sign-off. No exceptions, no shortcuts, and no "the system was down" in a custody record.
Reconciliation is where trust is earned
A real example from the reference deployment: an offline count sheet said 118 for Unit C; the RFID replay said 117. Neither was silently corrected. CCTV review confirmed an escorted medical move logged late, and the record was corrected with the evidence attached. Reconciliation that resolves a disagreement by picking the more convenient number is not reconciliation.
The outage is an operational event with chronology, ownership and review — not just an IT ticket.
Drill it, or you do not have it
Continuity that has never been rehearsed is a diagram. Quarterly drills combine tabletop and live failover, including a night scenario with an urgent release, and every finding becomes a versioned change-set with an owner. Staff who have run the drill twice do not need the runbook at 19:05 — which is the point.
Self-service on the wing: autonomy as rehabilitation
Why kiosks reduce adjudications, free officer time and rebuild the agency that release requires.