Show Notes
Why Manual Mode Still Matters
In this episode of Built, Wired, and Secured, Alex Morgan sits down with Michael Harrington and James Rogers to talk about a problem that building operators, property managers, facilities teams, and IT leaders all recognize: modern systems are convenient right up until the moment they are unavailable. When badge readers stop working, reception loses check-in tools, elevator panels throw errors, or a cloud-connected access platform goes down, the issue is rarely just one outage. It becomes a chain reaction that affects tenants, deliveries, staff, and daily operations.
The conversation stays grounded in practical operations. Instead of pushing complicated contingency plans, the episode focuses on simple, testable, low-friction manual procedures that help teams keep a property usable during BAS, access control, power, and communications issues. The goal is not to replace automation. The goal is to keep people safe, preserve accountability, and reduce business disruption while the root problem is being fixed.
What Cascading Failure Looks Like in a Real Building
The episode opens with a realistic Monday morning scenario: badge readers stop, reception cannot check people in, a delivery is stuck outside, and elevator panels are flashing errors. One technician restores a measure of order by following a short manual procedure: locally override the gate, sign people in on an auditable log, and notify tenants using a pre-written SMS. That small set of actions keeps the office functioning while the outage is being worked.
That example leads to one of the episode's key insights: major failures may be rare, but small cascades can stop operations almost immediately. A power event, network outage, or even a cloud outage can disable centralized systems across multiple properties at once. Once that happens, the right planning question is simple: what breaks if this system goes down? If teams can answer that in plain language, they can usually write a one-line or three-line manual step that keeps the building usable.
How to Keep Procedures Simple Without Making Them Unsafe
James Rogers explains that effective manual mode planning should not ask people to improvise technical fixes under pressure. His HVAC example is a strong model: if the BAS loses remote connectivity, do not ask a technician to rewrite control logic. Instead, move to local mode, apply a safe pre-authorized set point, and record who made the change. Those steps maintain occupant comfort while reducing the risk that someone creates a bigger problem through guesswork.
Michael Harrington adds an important operational and governance layer. Simplicity is useful only when scope is controlled. Pre-authorized set points should not be treated as blanket permission to do anything convenient during an outage. They should be documented in a one-page approval with safety review, so the team knows what is allowed, who approved it, and what boundaries apply. That makes the procedure executable and defensible.
Who Should Perform Manual Actions
One of the most useful sections of the episode is the discussion of role-based authority. Not every manual step belongs to every employee. Frontline reception and security staff should have very small, safe tasks they can execute consistently, such as maintaining manual entry logs, unlocking a specific gate, or deploying a battery-powered communications device. Certified technicians can handle intermediate actions like local overrides. Anything that changes control logic belongs with engineers or vendors.
The common thread is clear authority. Teams should document who can do what, who approves escalation, and when control returns to automatic operation. Without that structure, manual mode turns into informal workarounds, which creates operational drift and long-term risk.
Why Procedure Language Matters
The episode emphasizes that procedures must be written for real-world pressure, not for planning binders that nobody uses. James gives a concise example of good procedure language: switch panel to local override, set gate to manual open, record time, name, and reason in the incident log. That style matters because verbs are easier to follow during an incident. The best procedures are short, direct, auditable, and easy to execute even when staff are dealing with stress, tenant questions, and competing demands.
Logging, Retention, and Returning to Automatic
Logging is treated as more than an administrative detail. Michael recommends keeping incident logs for the life cycle of the contract plus one year at a minimum, while aligning retention with the broader records management policy. At a minimum, teams should capture the time, who acted, why they acted, and when the system was returned to automatic.
That last point is especially important. Temporary manual fixes can quietly become normal operating conditions if nobody records the return to standard operation. Once that happens, organizations lose visibility, create safety gaps, and weaken the very systems they depend on.
Training That Does Not Become Theater
The episode also gives a realistic cadence for keeping procedures current. The recommendation is not to run large, disruptive exercises every week. Instead, do a 15-minute walkthrough monthly and run a realistic drill quarterly. In the quarterly drill, reception uses the manual log, HVAC runs on local set points, and the team measures how long it takes to return systems to automatic. Lessons are recorded and assigned for follow-up.
This is a strong operational model because it turns manual mode into a maintained capability instead of a forgotten document. The team also recommends versioning procedures, storing a printed copy in the operations binder, and maintaining an electronic versioned master so staff turnover does not erase institutional knowledge.
The Four-Step Checklist to Start Now
For listeners who want an immediate starting point, the episode closes with a short checklist:
- Assign clear ownership for who can enact manual mode and who approves it.
- Define minimal safe steps using short, verb-first actions.
- Test procedures monthly and drill them quarterly.
- Log every manual action and control procedures through versioning.
The conversation adds one more essential guardrail: include safety sign-off for any manual action that could introduce risk. Manual procedures should have explicit safety controls and a clearly documented return-to-automatic step.
Why This Matters for Building Operations
The final takeaway is simple and practical. When teams plan for the human step, they reduce outage impact and speed tenant recovery. Clear authority, short procedures, disciplined maintenance, and an audit trail make it possible to keep buildings running even when automation is unavailable. This episode is a useful reminder that resilience does not always come from adding more technology. Sometimes it comes from defining the right manual steps before the next outage begins.
When Building Automation Fails, Operations Still Have to Work
Modern commercial buildings depend on connected systems to control access, manage HVAC, support communications, and coordinate daily operations. When those systems are working, they remove friction from nearly everything a tenant experiences. Badge readers open doors, reception processes visitors, BAS platforms maintain comfort, and building teams can manage issues from centralized dashboards. The problem, as this episode of Built, Wired, and Secured makes clear, is that many properties assume those systems will always be available.
That assumption breaks down fast during a real outage. In this conversation, Alex Morgan speaks with Michael Harrington and James Rogers about the need for simple, safe manual mode procedures that keep buildings operational when automated systems are unavailable. The discussion stays practical throughout. Rather than proposing major redesigns or expensive overhauls, the episode focuses on the small human-driven steps that reduce outage impact, protect occupants, and help teams recover faster.
The Real Risk Is Often the Cascade, Not the First Failure
The episode opens with a scenario that feels familiar because it is so plausible. On a Monday morning, badge readers stop working. Reception cannot check people in. A key delivery is stuck outside. Elevator panels are flashing errors. The headline system failure is bad enough, but the real operational pain comes from the chain of secondary problems it creates.
One technician restores order with a short manual process: locally override the gate, sign people in using an auditable log, and send tenants a pre-written SMS update. Those actions do not solve the underlying outage, but they keep the office functioning while the team works the problem. That is the heart of manual mode planning. The point is not to duplicate every feature of an automated system. The point is to maintain usable operations until normal service returns.
Michael Harrington highlights why this matters so much in commercial environments. Large catastrophic failures are not the only concern. Smaller cascading issues often have the biggest immediate effect on tenants. A power event or network issue can quickly affect access, communications, comfort, and service delivery. In some cases, even a cloud outage can disable a centralized access platform across multiple properties. Once that happens, the right operational question becomes very direct: what breaks if this goes down?
That question is powerful because it forces teams to think in plain language. If the answer is that people cannot enter the building, visitors cannot be checked in, or tenants will not know what is happening, then the next step is to define the smallest possible manual action that addresses each problem safely.
Simple Procedures Are Better Than Heroics
One of the strongest themes in the episode is that manual mode procedures should reduce improvisation, not encourage it. During an outage, teams are already under pressure. They are juggling tenant expectations, safety concerns, vendor coordination, and time-sensitive decisions. That is the worst possible moment to ask someone to invent a workaround on the spot.
James Rogers gives a useful HVAC example. If a BAS loses remote connectivity, the answer is not to ask a technician to rewrite control logic under stress. Instead, the procedure should focus on three straightforward actions: switch to local mode, apply a safe pre-authorized set point, and record who made the change. Those steps maintain comfort while keeping the response inside defined boundaries.
This matters because resilience depends on repeatability. A short procedure that people can execute correctly is far more valuable than a technically impressive plan nobody can apply during a live incident. Good manual mode design is not about complexity. It is about clarity, constraints, and controlled execution.
Safety and Scope Have to Be Defined Up Front
The episode does not romanticize manual workarounds. Michael raises a valid concern that some owners will hesitate to approve pre-authorized manual actions without legal and safety review. That friction is real, and it is often where planning conversations stall.
The answer offered in the discussion is practical: make the approval process narrow, documented, and specific. A pre-authorized set point or local override should be covered by a one-page signoff with safety officer approval. That approach keeps procedures actionable without turning them into open-ended permission for risky changes.
This is an important lesson for building operators and property teams. Manual mode is not a loophole around governance. It is a disciplined extension of governance into outage conditions. If a manual action could affect safety, occupancy, or system integrity, then the acceptable range, required approvers, and return-to-automatic conditions should be defined before the outage ever happens.
Not Everyone Should Do Everything
Another practical insight from the episode is the need to match tasks to roles. Frontline reception or security staff should handle only very small, safe, repeatable actions. That may include manual entry logs, unlocking a designated gate, or deploying a battery-powered communications device. Certified technicians can manage intermediate actions such as local overrides. Engineers or vendors should be the only people handling anything that changes control logic.
That division of responsibility matters for two reasons. First, it protects safety by keeping specialized actions with qualified personnel. Second, it keeps procedures usable. A receptionist should not need technical training to perform the manual task that belongs at the front desk. In the same way, a technician should not be left guessing whether a manual override is authorized. Clear authority keeps the response fast and controlled.
The team stresses that authority should be documented explicitly. Who can enact manual mode? Who approves escalation? Who decides when systems return to automatic? If those answers are vague, the procedure is not ready for real-world use.
Write Procedures for Pressure, Not for Paper
The language used in procedures gets special attention in the episode, and for good reason. A manual runbook should not read like a policy memo. It should read like something a real person can follow while phones are ringing and tenants are asking questions.
James offers a model example: switch panel to local override, set gate to manual open, record time, name, and reason in the incident log. This style works because it is direct, sequential, and action-oriented. It tells the operator exactly what to do and exactly what to document.
That kind of writing improves more than usability. It improves accountability. Small verb-first actions make it easier to verify whether the procedure was followed, which matters during incident review, tenant communication, and future updates.
Audit Trails Prevent Temporary Fixes from Becoming Permanent Drift
Logging is a core part of the resilience model described in this episode. Michael recommends retaining manual mode incident logs for the life cycle of the contract plus one year as a minimum, with retention aligned to the broader records management policy. The required details are straightforward: record the time, who acted, why they acted, and when the system was returned to automatic.
That last step may be the most important one. In many environments, temporary workarounds become normalized simply because nobody closes the loop. A system stays in local mode longer than intended. A manual exception becomes standard practice. Over time, that drift creates risk, erodes control, and weakens confidence in the operating environment.
An audit trail is not just for compliance. It is how teams preserve operational discipline when they have to leave the normal path.
Testing Has to Be Regular, but It Also Has to Be Realistic
The episode also gives listeners a practical training cadence. Monthly, teams should do a short 15-minute walkthrough of the manual steps. Quarterly, they should run a realistic drill that simulates a two-hour partial outage. In that drill, reception uses the manual log, HVAC runs on local set points, and the team measures how long it takes to restore automatic operation.
This approach is useful because it avoids two common failures. The first is neglect, where procedures are written once and never revisited. The second is performative training, where teams hold exercises that are too abstract to build real skill. A short monthly review and a quarterly operational drill create muscle memory without overwhelming the staff responsible for daily building performance.
The team also recommends version control for procedures, a printed copy in the operations binder, and an electronic versioned master. That protects institutional knowledge, especially when staff roles change or turnover occurs.
A Four-Step Starting Point for Facilities and IT Teams
For organizations that want to act quickly, the episode closes with a concise checklist. First, assign clear ownership for who can enact manual mode and who approves it. Second, define minimal safe steps using short, verb-first actions. Third, test those procedures monthly and drill them quarterly. Fourth, log every manual action and control procedures through versioning.
There is also one additional safeguard worth emphasizing: involve a safety officer or operations lead in approving any manual action that could create risk. If a fallback procedure is going to be used under pressure, it needs explicit safety controls and a documented return-to-automatic step.
Operational Resilience Is a Human Process Too
The broader lesson from this episode is that resilient buildings are not defined only by the sophistication of their automation. They are defined by how well people can keep operations moving when that automation is unavailable. Clear authority, short procedures, routine drills, and disciplined logging create a human layer of resilience that protects tenants and supports recovery.
For commercial real estate teams, facilities leaders, and IT partners, that is a practical advantage. Better manual mode planning can reduce outage impact, limit confusion, preserve auditability, and shorten the path back to normal operations. It can also help teams avoid the much higher cost of improvised responses that create safety or service problems during an already difficult incident.
If your building depends on connected systems, this episode offers a useful reminder: manual mode should not be treated as an afterthought. It should be designed, approved, practiced, and maintained like any other operational control. That is how teams keep buildings usable, occupants supported, and recovery on track when the automated path disappears.
If this topic is relevant to your property, portfolio, or facility operations, listen to the full episode and use it as a prompt to review where your current systems need a simple, safe human fallback.