InfiIoT Labs/What-if 01
Maintenance architecture · 21 minute read

What if a transformer could order its own oil test?

The transformer can assemble condition evidence, request the right laboratory work, and keep the result tied to the asset that raised the concern. Engineers retain diagnosis, spending approval, and maintenance authority.

InfiIoT LabsPublished 16 July 2026Standards reviewed: 10Scope: mineral-oil transformers
Step 1

Signal

A condition changed

Step 2

Evidence

The change is trustworthy

Step 3

Test

A lab method can answer it

Step 4

Decision

An engineer owns the action

The phrase "the transformer orders its own test" is useful only if we are strict about the boundary. The machine can raise a well-formed request. Engineering judgment still decides what the request means and what happens next.

Most transformer monitoring systems stop too early. They draw a gas trend, send an alert, and leave a maintenance engineer to reconstruct the asset history, operating load, sensor quality, last laboratory sample, approved vendor, sample method, and open work orders. The digital system notices the condition; the human does the clerical integration.

A better product closes that gap. It turns a condition signal into a traceable maintenance case, proposes a laboratory panel that answers the actual uncertainty, and follows the physical sample back into the twin. Opening an SAP notification or emailing a laboratory is easy. The engineering work is proving that the request is justified, unique, correctly scoped, and attached to the right transformer.

The autonomy boundary
machine authority = detect + qualify + assemble + request + track
human authority = approve + interpret + operate + maintain

Protective relays remain responsible for immediate protection. This workflow lives in the slower condition-maintenance layer.

01 · Open a condition case

DGA belongs inside an engineering decision

Electrical and thermal stress decompose oil and cellulosic insulation into gases. ASTM D3612 defines gas-chromatography procedures for extracting and measuring gases including hydrogen, methane, ethane, ethylene, acetylene, carbon monoxide, and carbon dioxide. It also states that gas composition, concentration, rate of generation, and change over time can indicate the type and degree of an abnormality.[3]

Interpretation is deliberately broader than a threshold table. IEEE C57.104 covers gas generation, DGA quality verification, limitations, norms, fault identification, and suggested operating procedures.[1] IEC 60599 describes how dissolved or free gases may be used to diagnose oil-filled equipment and suggest future action, then makes the critical qualification: the indications are guidance and the resulting action requires proper engineering judgment.[2]

The workflow should therefore create a condition case. It must avoid writing "internal arcing" into the permanent record as a confirmed fact. A case contains the observed change, the diagnostic method, the quality of the evidence, competing explanations, and the next measurement that can reduce the uncertainty. Sometimes that measurement is a laboratory DGA. Sometimes it is moisture, dielectric breakdown, acidity, interfacial tension, or furan analysis. Sometimes the correct answer is to inspect the online monitor before sampling the transformer.

Single spike
DesignCheck sensor quality, persistence, load change, and recent maintenance before opening a case.
FailureA transient value creates an urgent laboratory order and duplicate site work.
Rising gas rate
DesignPreserve the calculation window, baseline, uncertainty, and operating regime.
FailureThe system stores only the latest ppm value and loses the evidence that triggered it.
Diagnostic pattern
DesignRecord the method and version used to classify the gas relationship.
FailureThe interface presents a fault label without the ratios, inputs, or limitations.
Open work
DesignAttach new evidence to the active case when it concerns the same condition.
FailureEvery threshold crossing creates another notification for the same developing fault.
Kill test

The synthetic acetylene spike

Inject one high acetylene reading into an otherwise stable history. Mark the online monitor with degraded quality and add a load-tap-changer operation at the same time. The system should preserve the event, explain why it did or did not qualify, and avoid silently converting one questionable point into a confirmed main-tank fault.

02 · Build the evidence packet

The request should survive without the dashboard

A laboratory request is a record that can travel through a CMMS, procurement system, field team, courier, and external laboratory. It cannot depend on a coloured chart that only the IoT product can render. The evidence packet needs a durable summary with links back to raw data.

Asset identityTransformer ID, serial number, site, tank or LTC compartment, voltage class, fluid type.
Observed conditionGas values, rate-of-change windows, temperatures, load, alarms, and event time.
Data qualityMonitor state, calibration date, missing intervals, substituted values, and communication gaps.
MethodRule identifier, diagnostic method, threshold source, software version, and baseline version.
ContextRecent oil work, degassing, maintenance, load changes, tap operations, and previous laboratory results.
Requested answerThe uncertainty the test panel must resolve, urgency, completion window, and accountable reviewer.

Qualification uses explicit gates

A machine-learning probability can support prioritisation. Basic data requirements remain binary. Before a case can request physical work, the asset identity must be complete, the signal must be valid enough for the policy, the persistence condition must be met, and the workflow must confirm that an equivalent case is not already open.

eligible = asset_known AND signal_valid AND persistence_met
AND context_available AND no_equivalent_open_case
priority = policy(condition, rate, criticality, redundancy, consequence)

This structure is less fashionable than a single health score and far easier to audit. When a request is rejected, the system can say which gate failed. When policy changes, the old case still records the rule version that created it.

Bench test

The missing-history replay

Remove four days of load and temperature context before a gas increase. Backfill those values after the case opens. The workflow should show that the original decision used incomplete context, re-evaluate under the new evidence, and retain both decisions in the audit trail.

03 · Order the right test panel

Oil test is too vague to automate

The test request should name the method and the question. DGA by ASTM D3612 addresses gases associated with thermal and electrical stress. Water by coulometric Karl Fischer titration is relevant because excessive water can degrade dielectric properties; ASTM D1533 is commonly used below saturation and is sensitive at low water levels.[6]Dielectric breakdown by ASTM D1816 indicates the liquid's ability to withstand electrical stress and is sensitive to contaminants such as water, dirt, fibres, or conductive particles.[7]

Furanic compounds answer a different question. ASTM D5837 notes that furans are generated by degradation of cellulosic insulation, migrate into the liquid, and can complement DGA when unusual increases suggest paper ageing or an incipient fault.[8] Oil condition work may also call for acidity, interfacial tension, dissipation factor, inhibitor content, or other methods listed in ASTM D117 and IEC 60422.[9][10] Ordering every available test wastes sample, money, and attention. Ordering only the familiar DGA can miss the question that triggered the work.

DGA · ASTM D3612Did the gas pattern or generation rate change in a way that supports the online indication?Electrical or thermal fault concern
Water · ASTM D1533Has moisture changed enough to affect oil condition or dielectric performance?Moisture ingress, thermal history, wet insulation concern
Breakdown · ASTM D1816Can the liquid withstand the specified electrical stress under the method?Contamination or dielectric-strength concern
Furans · ASTM D5837Is there oil-soluble evidence of cellulose degradation?Paper ageing or thermal degradation concern
Oil quality panelAre oxidation, contamination, or inhibitor conditions affecting serviceability?Long-term oil maintenance decision

The sample is part of the measurement system

A perfect laboratory cannot repair a bad sample. IEC 60475 applies to sampling insulating liquids from transformers, reactors, bushings, switchgear, and load tap changers.[4]IEC 60567 covers free-gas sampling and the extraction and analysis of dissolved gases, including calibration considerations and field transport conditions.[5] The work request must identify the compartment, sampling point, container, flushing procedure, sample temperature, timestamp, sealing requirement, transport conditions, and chain of custody.

Asset identity deserves special suspicion. Main-tank oil and load-tap-changer oil can have very different gas behaviour. A sample from the correct substation and wrong compartment is still the wrong sample. Barcode or QR capture should bind the container to the approved request at the sampling point while the asset identity is physically verifiable.

Chain-of-custody test

The swapped syringe

Exchange two labelled sample containers between transformers before laboratory receipt. The workflow should reject or quarantine the result when the scanned identity, compartment, collection time, or custody trail conflicts with the request. A plausible gas result still needs identity proof.

04 · The work-order state machine

A maintenance process needs more states than an alert

The case needs explicit states because physical work stretches across people and systems. A notification can be accepted while the laboratory request remains unapproved. A sample can be collected but never received. A result can arrive for a case that was closed after an instrument fault. Flattening these states into open and closed destroys the evidence needed to improve the workflow.

01ObserveOnline DGA, temperatures, load, oil condition, alarms, and maintenance context remain in the twin.
02SuspectA versioned rule identifies a persistent change and records why it matters.
03QualifySignal quality, operating context, duplicate cases, and recent maintenance are checked.
04ReviewA transformer engineer accepts, changes, or rejects the proposed laboratory panel.
05SampleThe approved request includes method, container, location, timing, and chain of custody.
06ReconcileLaboratory values return to the same asset timeline with method and sample metadata.
07ActThe engineer decides whether to monitor, resample, inspect, derate, repair, or escalate.

Every transition needs an actor, timestamp, reason, and idempotent identifier. If the CMMS API times out after creating an order, the retry must find the original order rather than creating a second field visit. If a reviewer changes the proposed panel, the system records the change and keeps the original recommendation. If urgency increases while the sample is in transit, the case carries the new risk without rewriting its history.

Case ID

Stable across the twin, CMMS notification, sample labels, courier record, and laboratory result.

Request version

Changes to test panel, urgency, or sampling instruction create a new version.

Transition owner

Person or service account responsible for each state change.

SLA clocks

Approval, collection, laboratory receipt, result, and engineering review are measured separately.

Duplicate key

Asset, compartment, condition family, and open time window prevent duplicate work.

Cancellation reason

Instrument fault, duplicate case, recent maintenance, or engineering rejection remains searchable.

Bench test

The timeout after create

Let the CMMS create the laboratory work order, then drop the API response. Retry the request five times from two workers. The platform should resolve one external order, record the uncertain interval, and reconcile the returned identifier. Duplicate suppression that relies on a button being clicked once will fail in production.

05 · Reconcile the laboratory result

The result must answer the case that requested it

A PDF attached to a work order is a record, but it is weak machine-readable evidence. The platform should ingest the measured values, units, method, laboratory, sample timestamp, receipt timestamp, result timestamp, uncertainty or quality notes, and report identifier. The original document remains attached. Structured values join the transformer timeline.

Reconciliation compares the laboratory result with the online monitor over the correct time window. Some difference is expected because sampling time, extraction method, monitor response, oil circulation, temperature, and measurement uncertainty all matter. A larger mismatch can indicate a monitor problem, sample problem, compartment error, or a real change between online observation and collection.

Lab confirms trend
DesignEngineer reviews severity, rate, asset criticality, redundancy, and operating options.
FailureConfirmation automatically creates a repair prescription beyond the evidence.
Lab conflicts with trend
DesignInvestigate monitor calibration, sampling identity, timing, and method before closing.
FailureThe case is marked false positive with no explanation and the model learns the wrong lesson.
Sample rejected
DesignRecord the laboratory reason and create a controlled resample if still justified.
FailureA missing result looks like a healthy transformer.
Condition worsens
DesignRe-prioritise the existing case and notify the accountable engineer immediately.
FailureThe workflow waits for the original SLA while the physical condition changes.

Label outcomes for future rules

Closed cases should record why the request was useful or unnecessary: confirmed developing condition, online-monitor issue, bad sample, recent maintenance effect, policy too sensitive, duplicate event, or insufficient evidence. These labels are better training material than a binary alarm acknowledgement. They also show whether the organisation is reducing uncertainty or merely generating laboratory volume.

06 · Governance and safety

Automate the clerical work. Keep authority visible

The workflow touches asset condition, field safety, procurement, and maintenance planning. Role boundaries should be explicit. The condition service can propose. A transformer engineer can approve or change the technical panel. An authorised maintenance planner can schedule field work. Procurement can select an approved laboratory under commercial policy. Field staff can confirm safe access and collect the sample. The laboratory can submit results but cannot alter the original case evidence.

Immediate protection remains outside this loop. A Buchholz relay, differential protection, or other protection function does not wait for an IoT platform, a laboratory, or a human approval. The condition workflow may increase urgency when protection operates, but it must not present a maintenance case as a substitute for protection engineering.

Rule changesVersion, reviewer, effective date, affected asset classes, and back-test evidence.
Spend authorityApproval limit, cost centre, laboratory contract, and exception route.
Field safetySampling procedure, access permit, PPE, isolation requirements, and site contact.
Data accessLeast-privilege service identities for twin, CMMS, procurement, and laboratory interfaces.
AuditImmutable transition history with original evidence and later corrections kept separately.
Manual overrideNamed person, reason, expiry, and review for suppression or urgent escalation.

Measure the workflow with operational metrics: time from qualified signal to approved request, percentage sampled inside the required window, sample rejection rate, laboratory turnaround, duplicate orders prevented, cases confirmed by laboratory evidence, cases traced to monitor or sampling problems, and time from result to engineering disposition. "Alerts generated" is an activity count. It says nothing about maintenance quality.

07 · The hostile workflow test

Break the evidence chain before a real transformer does

A useful acceptance test needs signal faults, software faults, and ordinary human mess. Run it against a test CMMS tenant and a simulated laboratory interface with production identity and permission rules. The workflow should remain understandable after every failure.

SensorSpike one gas, freeze another, degrade quality, and change calibration status after the case opens.
ContextAdd a load step, oil processing event, tap operation, and recent maintenance record out of order.
DuplicateTrigger the same condition from the rule engine, an engineer, and a batch analytics job.
IntegrationTimeout after CMMS create, reject one field, rotate credentials, and replay an old webhook.
SamplingUse the wrong compartment, break custody, delay transport, and let the laboratory reject the sample.
ResultReturn different units, a revised report, an unstructured PDF, and a value that conflicts with the online monitor.
EscalationWorsen the gas trend while approval is pending and while the sample is in transit.
AuditChange the policy after closure and prove the original rule, evidence, approval, and result remain reconstructable.

Release criteria

Evidence
DesignEvery request reconstructs the signal, context, quality, rule, and baseline that created it.
FailureThe case contains a severity label and a screenshot.
Work control
DesignApproval, sampling, laboratory receipt, result, and disposition are separate states.
FailureOpen and closed hide where physical work stopped.
Identity
DesignCase, asset, compartment, sample, result, and external order share a verifiable chain.
FailureStaff match a PDF to a transformer by filename.
Authority
DesignThe product proposes and tracks; accountable people approve and decide.
FailureA health score quietly becomes a maintenance prescription.

Useful autonomy delivers the engineering review with the history, uncertainty, sample request, and audit trail already in order. It leaves the judgment with the engineer who carries the consequence.

Research notes

Standards and original sources

The cited standards define laboratory methods, sampling practice, interpretation guidance, and oil-maintenance context. Utilities must supply the approved action policy for each transformer class, fluid, history, criticality, and operating consequence.

  1. [1]IEEE C57.104-2019: Guide for the Interpretation of Gases Generated in Mineral Oil-Immersed Transformers · IEEE Standards Association
  2. [2]IEC 60599:2022: Guidance on the Interpretation of Dissolved and Free Gases Analysis · International Electrotechnical Commission
  3. [3]ASTM D3612-02(2026): Analysis of Gases Dissolved in Electrical Insulating Oil by Gas Chromatography · ASTM International
  4. [4]IEC 60475:2022: Method of Sampling Insulating Liquids · International Electrotechnical Commission
  5. [5]IEC 60567:2023: Sampling of Free Gases and Analysis of Free and Dissolved Gases · International Electrotechnical Commission
  6. [6]ASTM D1533-20: Water in Insulating Liquids by Coulometric Karl Fischer Titration · ASTM International
  7. [7]ASTM D1816-12(2019): Dielectric Breakdown Voltage of Insulating Liquids Using VDE Electrodes · ASTM International
  8. [8]ASTM D5837-15(2023): Furanic Compounds in Electrical Insulating Liquids by HPLC · ASTM International
  9. [9]IEC 60422:2024: Mineral Insulating Oils in Electrical Equipment, Supervision and Maintenance Guidance · International Electrotechnical Commission
  10. [10]ASTM D117-22: Guide for Sampling, Test Methods, and Specifications for Electrical Insulating Liquids · ASTM International
Next in the lab

Three vibration sensors, one spindle, 30 days

In test

The teardown stays unpublished until all three sensors have run on the same spindle for the full physical test, including mounting, noise floor, drift, edge features, and fault detection.

Return to InfiIoT Labs →
Connected-product assessment

Bring one product. Leave with a clear next step.

Use 30 minutes to test the fit around one product and one blocked decision. If there is a fit, we will outline the two-week Product Blueprint.

30-minute fit callOne productNo prepared deck