
The controls basis publishes a twenty-five-field point dictionary [TARGET]. The machine-authoritative register that is supposed to implement it has 233 rows and 18 columns, and none of the 18 is quality, command feedback, command timeout or command failure [TARGET]. Four of those twenty-five fields are named as necessary on this project rather than as good practice. A reviewer reading the 233 rows cannot ask what a point shows when the link drops, or what proves a command was executed, because no field exists in which either answer could be written.
The 18-Column Register Cannot Carry the 25-Field Dictionary
The four required columns are quality, independent command feedback, command timeout and command failure branch. The basis grounds them on two named project risks: a supervisory communication-loss branch, and a valve-position finding that forgetting to reopen a manually closed valve is the highest-frequency human failure. Without those four columns a point list is not a reviewable deliverable on this project.
The 233-row file is a port-candidate index. The same controls basis forbids publishing any single point count at this stage, because cabinet count, generator and uninterruptible-supply count, and heat-rejection route each multiply the total independently. Treating 233 as a purchase quantity is the error the formula exists to prevent.
Quality Must Express Stale; Feedback Must Be Independent
The quality column is enumerated as good, uncertain, bad, stale or substituted [TARGET]. It is paired with a clock rule: loss of the time source may not change any control behaviour and may only degrade data quality. A point list that cannot express staleness cannot tell a healthy zero from an absent reading. The five enumerated values have no column able to carry any of them in the delivered file.
Its companion column is bounded by a rule of the same kind. For any point that is not read-only, the feedback reference must target a source register different from the one the command was written to. Command echo proves the write was accepted. It does not prove the valve moved. The basis gives two physical instances: valve position sampled back as a state, and bus voltage and frequency recovery used as the staging criterion. The worked row in the same chapter shows the pair in use, with the charge-inhibit command marked remote-write prohibited and its feedback column pointing at a measured current.
The Revision Differentiated Alarms but Left the Four Columns Out
Alarm priority is what the file does carry, across six classes, from 18 life-safety and 8 asset-protection rows down to 131 advisory [TARGET], with delays of zero, two, five, ten or thirty seconds, retention at two, five or seven years [TARGET], and a design-status column reading the same value on all 233 rows: point defined, not natively connected. Two hundred rows record their protocol as an unobtained hard-wired signal and 14 as an unobtained vendor protocol [TARGET]. The 233 points sit on 208 distinct objects across 23 system identifiers and terminate on five supervisory endpoints [TARGET], and 206 of the rows still carry their direction as bidirectional or to be confirmed [TARGET]. That is a second way of saying command semantics have not been settled anywhere in the file.
The revision that produced the register was written to remove uniform template values. On the columns it covers it succeeded:
- alarm priority, delay and retention are genuinely differentiated;
- every row carries its own hold identifier with a named responsible body, 233 distinct identifiers [TARGET];
- the four review columns are absent;
- the connection state is uniform and negative.
The publishing package states its own limit in the same direction. It claims internal data structure and state discipline only. It disclaims any proof that native connections exist. Native-created connections in that package stand at zero [TARGET].
The Interlock File Already Carries Feedback, Timeout, and Reset
Add the four columns and the same 233 rows become reviewable with no engineering decision changing. That is what identifies this as a defect in the table and not in the control intent. The eight interlocks published beside the point file already carry feedback, timeout, failure action and reset proof as their own columns [TARGET]. The shape of the fix exists on this project and has not been applied to the point register.
No field in the delivered register can hold either of the two answers today. A supplier's assurance that a behaviour is supported cannot be tested against anything in it.
Limits and open items
The 233-row, 18-column register, the six alarm classes, the delay and retention sets, the 200 and 14 protocol rows, the 206 unsettled directions, the 208 objects, 23 systems and five endpoints, the 233 hold identifiers, and the zero native connections remain delivered-file counts [TARGET]. The twenty-five-field dictionary and the five quality values are basis enumerations [TARGET].
Open: supplier written behaviour on loss of communication; whether each vendor can expose an independent feedback register; population of the four columns once they exist. Adding columns does not populate them. Nothing here has been sealed. The register is not a purchase quantity. [HOLD]
Ask Whether the Header Has the Four Review Columns
The useful test of the next point-list revision is not whether it still has 233 rows. It is whether a reviewer can point at one header cell for quality, one for independent command feedback, one for timeout and one for the failure branch. If those four cells are still missing, the file has not become reviewable.
© 2026 K&K Data Service Inc. All rights reserved. Reproduction or republication is permitted only with clear attribution to K&K Data Service Inc. and a working hyperlink to the canonical URL of this article. Excerpts must preserve the technical context, maturity labels, assumptions, and limitations. No excerpt may imply project approval, field validation, certification, or endorsement that the original article does not state.
Source: K&K Data Service Inc., “A BMS Point List Without Quality and Command Feedback Is Not Reviewable,” https://www.kkdatasvc.com/lab/controls-epms-bms-and-dcim/a-point-list-without-qual-and-cmd-fb-is-not-reviewable/.
Discuss This Constraint. If your project record shows a different result, or the same failure domain under another name, we want to see it. Email inquiry@kkdatasvc.com or use the contact page.