GDS Technology — Built, Wired and Secured podcast banner
Watch on YouTube →
Episodes Built
Episode 1

Power Decisions: Two Floors, One Outage - Choosing Resilience Without Overpaying

February 22, 2026
Key takeaways
  • Define critical loads before selecting UPS, battery, or generator capacity.
  • Match redundancy to the downtime tolerance agreed for each critical service.
  • Document tenant and building ownership boundaries to prevent confusion during recovery.
  • Use testable handover scripts, named owners, acceptance criteria, and recurring tests.
  • Choose centralized or distributed backup based on shared-service needs, tenant churn, and staffing model.

Show Notes

Two Floors, One Grid Glitch, Very Different Outcomes

What turns the same upstream power event into either a four-hour tenant crisis or a recovery measured in minutes? This episode follows an anonymized micro-case involving two neighboring tenant floors in the same building. Both experienced an upstream breaker trip at 2 a.m. Floor 1 lost phones, access systems, HVAC schedules, several server racks, and more for approximately four hours. The result was tenant disruption, frustrated facilities staff, and a difficult incident report.

Floor 2 faced the same outage but restored most critical services in under 30 minutes. The difference was not an oversized, one-size-fits-all backup plan. It came from modest early decisions: defining critical loads, selecting appropriately sized UPS coverage, assigning ownership in writing, and running a documented test every quarter.

The Three-Item Power Resilience Checklist

The episode begins with three practical rules for design meetings, owner discussions, and operational reviews:

  • Define and agree on critical loads.
  • Match redundancy to downtime tolerance.
  • Require testable handover documentation.

These rules help teams move beyond vague discussions about “backup power” and focus on the services that must remain available, the amount of downtime the organization can accept, and the people responsible for keeping the plan functional.

Why Floor 1 Took Four Hours to Recover

Floor 1 relied on basic strip UPS units under desks and a small tenant-supplied generator plan that had never been validated. Sparse metering meant the building team did not know how much load the tenant actually drew. The environment also had mixed tenant equipment on building panels, making it difficult to isolate critical circuits.

The biggest operational problem was ambiguous ownership. Tenant IT believed facilities owned the UPS, while facilities assumed the tenant was responsible. When the outage occurred, the team faced confusion, manual switching, and a long recovery process. The episode identifies three recurring root causes:

  • Undermetering that hides actual demand.
  • Mixed tenant loads that complicate critical-circuit isolation.
  • Unclear ownership that allows maintenance and testing to fall through the cracks.

Why Floor 2 Recovered in Under 30 Minutes

Floor 2 had modestly sized UPS capacity for defined critical loads, explicit written ownership for every relevant piece of equipment, and a simple test procedure performed quarterly. The outage still occurred, but staff had the time and clarity needed to restore services quickly. The power design supported the operating model instead of relying on assumptions during an emergency.

Choosing the Right Backup Strategy

The episode compares common backup approaches without endorsing products or vendors. The right choice depends on load ownership, equipment variability, downtime tolerance, budget, staffing, and the need for coordinated building-wide response.

  • Tenant UPS: A tenant-managed UPS can make sense when loads are exclusively tenant-owned and equipment changes frequently. The tenant controls upgrades and manages its own redundancy.
  • Building UPS: Building-level UPS or centralized battery capacity is often better for shared services such as access control, elevators, and shared Wi-Fi. The key is documenting the ownership boundary and transfer point.
  • Generator capacity: Rather than automatically sizing for every load forever, start with realistic critical loads, growth margin, and a defined runtime target. Determine whether the generator must support an extended utility outage or bridge a shorter event while UPS capacity and selective load shedding support recovery.
  • Centralized batteries: Centralized systems can simplify monitoring, maintenance, and coordinated control for shared building systems.
  • Distributed UPS modules: Distributed systems at tenant cabinets may cost less initially and provide stronger tenant-level isolation, particularly where tenant churn is expected.

Testing and Documentation Make Resilience Real

Power resilience is not complete at handover. A binder placed in a drawer is not an operational plan. The episode recommends testable handover documentation that includes a simple test script, defined acceptance criteria, a named owner, and evidence that the test was performed. Quarterly or semiannual testing is presented as a reasonable baseline for critical loads in many commercial settings.

Automated monitoring and alerting also help teams identify capacity dips or generator self-test failures before tenants experience an outage. Smaller, more frequent tests are more valuable than an annual exercise everyone forgets.

Questions to Use in Your Next Design Review

  • Which circuits are legally owned by the tenant, and which are building-provided?
  • What are the defined critical loads, and what is the agreed downtime tolerance for each?
  • How will handover be tested, who runs the script, how often, and where do results live?
  • Who monitors UPS and generator health, and what alert thresholds apply?
  • If batteries are centralized, how will tenant churn and energy-capacity billing be handled?

Take the Next Step

A modest UPS for communications closets and access control can sometimes be more cost-effective and easier to operate than upsizing a generator to support whole-floor HVAC. In other cases, a tenant with a lab or compute cluster may need tenant-funded redundancy under its own management. There is no universal design; there is only the design that fits the site’s risk tolerance, budget, and staffing model.

Download the episode checklist and one-page tenant/building handoff and test-script templates from the Built, Wired & Secured resource hub at gdec.com/bws-resources. Adapt them to your site, put testing on the calendar with facilities and tenant representatives, and consult licensed electricians and local code officials before implementing technical work.

Deeper dive

Power Resilience Starts With Decisions Made Before the Outage

Backup power discussions can quickly become conversations about equipment: UPS units, batteries, generators, capacities, and costs. Those are important subjects, but they can obscure the questions that actually determine whether a commercial building or tenant floor recovers smoothly when utility power fails.

Consider two neighboring tenant floors in the same building. At 2 a.m., an upstream breaker trips. Both floors experience the same grid-related event. One remains down for about four hours. Phones, access systems, HVAC schedules, server racks, and other services go offline. Tenants are disrupted, facilities staff scramble, and the eventual incident report documents a frustrating recovery.

The other floor experiences the same event yet restores most critical services in under 30 minutes. The difference is not necessarily a much larger capital investment. It is the result of a few clear choices made early: identifying critical loads, matching backup capacity to acceptable downtime, documenting ownership, and testing the handover process on a schedule.

Start by Defining Critical Loads

“Keep the floor running” is not a usable power-resilience requirement. Critical services must be identified specifically and agreed upon by the people who own, operate, and depend on them. For one environment, that may mean communications closets and access control. For another, it may include a small lab or compute cluster. Shared systems can introduce an entirely different set of priorities.

Without a defined list, teams tend to make expensive assumptions. A generator may be sized around an undefined ambition to support everything indefinitely. Or a small UPS may be deployed without knowing whether it covers the circuits that matter most. Neither approach creates a reliable operating plan.

A better starting point is to ask what must remain available, how long it must remain available, and who has authority over each load. This creates the foundation for the rest of the design and prevents a power event from becoming an argument about expectations.

Match Redundancy to Downtime Tolerance

Not every load needs the same redundancy. The episode’s core principle is simple: match redundancy to downtime tolerance. A critical system that must recover quickly requires a different plan than a service that can remain offline while the facility stabilizes.

This is why a modest UPS covering defined critical loads can be more practical than expanding generator capacity to support an entire floor’s HVAC. The objective is not automatically to power everything. The objective is to support the services that the organization has determined are essential, for the amount of time the organization has agreed is necessary.

Generator planning benefits from the same discipline. Oversizing to cover every possible load forever can create unnecessary capital cost, fuel cost, and maintenance complexity. Instead, teams should determine realistic critical loads, include an appropriate growth margin, and establish runtime targets. Is the generator intended to operate until utility service is restored? Or is it meant to bridge a shorter outage while UPS systems protect critical services and selective load shedding supports recovery? The answer should guide the design.

Ownership Boundaries Are an Operational Control

The four-hour recovery in the micro-case was not caused by a single equipment failure. It was undermined by sparse metering, mixed tenant loads, and unclear ownership. Tenant IT believed facilities owned the UPS. Facilities believed the tenant was responsible. During an outage, that uncertainty turns into delayed decisions, manual switching, and lost time.

Ownership must be written down. Teams should be able to identify what the tenant owns, what the building maintains, and what occurs at the transfer point between them. This matters for procurement and billing, but it matters even more for maintenance, monitoring, testing, and emergency response.

The ownership model should influence the architecture. If a load is exclusively tenant-owned and the tenant expects frequent changes in equipment, a tenant-managed UPS may be appropriate because the tenant can control upgrades. If the load supports shared services such as access control, elevators, or shared Wi-Fi, building-level UPS capacity or centralized batteries may reduce operational surprises. The decision is not simply who pays; it is who can reliably manage the responsibility over time.

Centralized and Distributed Backup Have Different Strengths

Centralized batteries can make building-level control easier. They may be more efficient to monitor and maintain, and they provide a coordinated approach for shared systems. For a building that needs consistent blackout tolerance across shared services and wants a single point of monitoring, centralization can simplify coordination.

Distributed UPS modules at tenant cabinets can offer another advantage: isolation of responsibility. They may be less expensive upfront and may fit buildings with high tenant churn, where tenants need distinct control over their own environments.

Neither model is universally correct. A resilient design aligns the architecture with operational responsibility and the staffing model. A technically sound system that nobody has the time, authority, or process to manage will not deliver the expected result when it is needed.

Metering and Load Isolation Cannot Be Afterthoughts

Undermetering hides true demand. When the building team does not know how much a tenant actually draws, it cannot confidently validate capacity or determine what will happen during a transfer event. Mixed tenant equipment on building panels creates another complication: critical circuits become difficult to identify and isolate.

These issues do not need to wait until an incident exposes them. They belong in design reviews, handover reviews, and periodic operational checks. Clear circuit ownership, defined critical loads, and visible demand information give facilities and tenant teams a shared basis for decisions.

Testable Documentation Is What Separates Theory From Reality

A handover binder and a brief walkthrough do not prove that a backup-power strategy will work. Documentation needs to be usable during an actual event. That means a simple test script, defined acceptance criteria, a named owner, and a record that the test occurred.

Quarterly or semiannual testing for critical loads is a reasonable baseline in many commercial settings. Smaller, more frequent tests are more effective than a single annual test that is forgotten. Automated monitoring and alerting further reduce surprises by identifying UPS capacity dips or generator self-test failures before tenants report an outage.

The goal is to create breathing room. In the successful floor example, the UPS and the documented handover steps gave staff the time needed to restore services in under 30 minutes. That is the business value of operational readiness: fewer tenant disruptions, less confusion during an incident, and a recovery process that does not rely on memory or assumptions.

Five Questions for a Better Design Review

  1. Which circuits are legally owned by the tenant, and which are building-provided?
  2. What critical loads have been defined, and what downtime tolerance applies to each?
  3. How will the handover be tested, who runs the script, how often, and where are results retained?
  4. Who monitors UPS and generator health, and what alert thresholds are in place?
  5. If batteries are centralized, how will tenant churn and energy-capacity billing be addressed?

These questions cut through broad resilience claims and focus the conversation on ownership, expectations, and operations. They also help reveal where a modest investment may prevent a much more expensive disruption.

Build a Plan That Can Be Operated

There is no one-size-fits-all power strategy. A tenant with a small lab or compute cluster may need tenant-funded redundancy that it manages itself. Another site may benefit most from a modest UPS for communications closets and access control rather than whole-floor backup capacity. The right answer depends on risk tolerance, budget, staffing, and clear operational ownership.

The practical takeaway is straightforward: document critical loads, choose redundancy based on downtime tolerance and responsibility, and require testable handover documentation. Those decisions can be the difference between a short recovery and a four-hour outage.

For the episode checklist and one-page templates for tenant/building handoffs and test scripts, listen to this episode of Built, Wired & Secured and visit the resource hub at gdec.com/bws-resources. Before implementing technical work, consult licensed electricians and local code officials for design and compliance validation.