SpiAlert / Industries / The console is logged in. Is the cleared operator still there?
Critical Infrastructure and OT

The console is logged in. Is the cleared operator still there?

Control rooms run on shared HMI and SCADA consoles that stay logged in across a shift or a handoff. An unattended screen at a plant, substation, or water system looks exactly like the authorized operator to every downstream system. SpiAlert verifies the authorized human continuously, at the console and in the field.

Air-gap and low-connectivity readyVendor and contractor governanceForensic presence records
PRESENCE, VERIFIED PRIVATELY
Control room, HMI-3
PresentSteps awayScreen protectedReturns, revealed instantly
irreversible descriptors only · no image stored · nothing persisted
Illustrative interface
The gap in this environment

A logged-in HMI is not the same as a cleared operator.

Standard access control confirms an operator once at login and then trusts the console for the length of the shift. A control room screen left open during a handoff, or a field technician's tablet left unlocked, looks identical to the authorized user to every system reading that session.

SpiAlert holds the session to a verified human second by second, passively, using the webcams and device cameras you already have. When the authorized person is not present, access is denied and the screen is protected immediately, then revealed automatically when they return.

Safety and operational integrity

Why this matters here

An unsafe action taken from an unattended control console is not a hypothetical, it is a documented cause of industrial incidents. Regulators and insurers increasingly expect provable evidence of who was at the console during a change or an event, not just a login timestamp from hours before. SpiAlert ties every console session to a specific, continuously verified human, with verification that runs locally even at air-gapped or low-connectivity sites.

Where it applies

Use cases for this industry.

Control room console protection

Continuous presence verification at SCADA, ICS, and HMI consoles, so a walked-away or hijacked session is never treated as the authorized operator.

Engineering workstation security

Keep configuration tools, diagrams, and safety-critical settings visible only to a verified, authorized engineer.

Field technician device coverage

On-device verification for tablets and rugged devices used at substations, plants, and remote sites, with no dependency on connectivity.

Vendor and contractor access governance

Confirm the identity of vendors and third parties during privileged remote or on-site sessions, with presence logs for accountability.

What it delivers

What SpiAlert delivers here.

SpiAlert is architected to support your compliance obligations. It provides continuous presence evidence, not a certification.

Presence at the console

Verifies the authorized operator continuously, including at the moment a configuration change or control action is executed.

Forensic-grade presence record

A continuous, per-session presence trail that supports incident review and regulatory audits.

Runs where connectivity doesn't

Verification processes locally, with no dependency on cloud connectivity, and no raw images stored or transmitted.

The bottom line

A control system is only as safe as the person at the console. SpiAlert ensures the only person operating your critical systems is the person you authorized.

Request a demo

See presence verification on a live session.

We will walk through the post-authentication gap in your environment and show how SpiAlert holds presence without adding friction for your people. We are also glad to discuss current pilots and references under NDA.

[email protected]   |   908 770 1552

Thanks. Your email client should open with the details ready to send. If it does not, write to [email protected] and we will follow up within one business day.
Please enter your name.
Please enter a valid work email.
Please enter your organization.

Submitting composes an email to our team. To be wired to your CRM or form endpoint before launch.