Show Notes
When Tenant Expectations and Building Systems Do Not Match
Tenants may ask for “100% uptime” or fast, reliable internet, but those expectations do not automatically translate into an effective building infrastructure plan. A property owner can invest heavily in redundancy, separate backups, new fiber, and private generation, yet still experience a serious outage if an overlooked riser cable, shared pathway, or misconfigured handoff remains a single point of failure.
This episode examines the gap between tenant SLAs and the physical and operational services a building actually delivers. That gap often exists because lease language, vendor contracts, tenant IT requirements, and building operations are written and managed separately. During an outage, ambiguity quickly becomes a dispute: Who owns backup internet? Who is responsible for testing failover? Which systems receive priority power? What evidence proves that redundancy is truly independent?
The central message is simple: turn tenant expectations into a map of critical services, infrastructure dependencies, business impact, and accountable owners. That creates a defensible way to prioritize investments, reduce operational risk, and avoid spending heavily on resilience that does not address the real failure point.
Start With the Service, Not the Equipment
The practical starting question is: what breaks if this goes down? A tenant’s stated requirement is not enough on its own. Building teams need to identify the specific services the tenant relies on, then trace every dependency required to keep those services available.
Examples of tenant-critical services discussed in the episode include:
- Receptionist Wi-Fi
- VoIP communications
- Point-of-sale systems
- Critical clinical devices
- Electronic medical record access
- Access control
- Emergency monitoring
Once services are identified, map each one to the components and responsibilities that support it. That can include power feeds, riser pathways, carrier handoffs, edge equipment, telecom providers, building vendors, and tenant IT teams. Without this mapping, teams cannot see what deserves priority, where a dependency is shared, or who is expected to respond when something fails.
A Repeatable Tenant-Critical Service Inventory
The episode outlines a straightforward process that building teams can repeat across tenants, floors, or property types.
- Interview tenants. Capture the services they depend on, ranging from everyday connectivity to safety and emergency functions.
- Assign a business-impact score. Use a short scale, such as one through five, to assess downtime cost, safety risk, and tenant-satisfaction impact.
- Map each service to its infrastructure. Connect the service to power, pathways, carrier handoffs, equipment, and responsible vendors.
- Evaluate likelihood and impact. Use those factors to prioritize issues based on money and risk rather than broad promises.
This process exposes hidden single points of failure. Two carriers can appear diverse while entering through the same rooftop pathway. Two power circuits can look independent while ultimately depending on the same transformer or upstream node. Redundancy is only meaningful when the underlying path is actually separate.
Use Business Impact to Avoid Overbuilding
Not every service requires the same resilience investment. Property owners must balance limited capital against different tenant needs, maintenance obligations, and the operational complexity that redundancy creates. The episode recommends three practical levers: zoning, diversification, and targeted redundancy.
- Zoning: Segment power and network infrastructure so a failure affects a limited part of the building rather than every tenant.
- Carrier diversity: Verify physical separation through distinct trenches or pathways. A second carrier does not provide true diversity if both services share the same route.
- Targeted redundancy: Apply stronger resilience measures to the highest-impact services instead of duplicating everything buildingwide.
Backup communications should be evaluated by recovery-time objective and cost. A second carrier with real path diversity may be appropriate for the most critical operations. For other needs, cellular or SD-WAN failover can provide practical resilience in minutes to hours without the expense of full duplication.
A Medical-Tenant Example
One example involved a medical tenant that rated EMR access as completely critical. The initial plan was expensive: separate generators and redundant UPS lines throughout the building. But after the services and dependencies were mapped, the real issue became clear. The EMR servers and the telecom handoff both depended on one utility path outside the building.
The more cost-effective response was to harden that actual path, negotiate a scheduled proof test involving the carrier and tenant IT, and provide simple local failover for the most critical sessions. The result addressed the true single point of failure without committing to broader generator redundancy that would not solve the core dependency.
Account for Operations and Maintenance
Capital cost is only part of the decision. Owners should include expected operations and maintenance costs in the same scoring model so decisions reflect total cost of ownership. Redundancy introduces more systems, testing requirements, vendor coordination, and maintenance responsibility. If a team cannot staff and maintain the added complexity, the investment can create more failure opportunities instead of reducing risk.
A pilot is a practical way to validate assumptions. Start with one floor or tenant class, confirm the testing cadence and operational ownership, then refine the approach before applying it more broadly. The agreed resilience level should be reflected in vendor statements of work and ongoing operations and maintenance budgets.
Operationalize the Commitment
Infrastructure only helps during a crisis when responsibility is clear and the system has been tested. The episode recommends formalizing operational ownership through runbooks that identify the building owner, vendors, and tenant IT roles associated with each critical service.
Teams should schedule and document recurring tests, including carrier failover, generator startup, and application-continuity testing. Vendors should provide proof of path diversity and participate in joint testing. Statements of work and lease appendices should include service-acceptance criteria. Finally, keep a living diagram and a change log. An outdated diagram is not useful during an outage, while documented proof that a process worked recently reduces uncertainty and finger-pointing.
Episode Checklist
- Inventory tenant-critical services and map them to specific infrastructure components.
- Score business impact and likelihood to prioritize spending.
- Verify true physical diversity for carriers and power; do not assume it exists.
- Use targeted redundancy where business impact justifies the cost.
- Use cost-effective fallbacks for lower-priority needs.
- Formalize responsibilities through runbooks, vendor statements of work, and regular test plans.
The episode also directs listeners to the Built, Wired & Secured website for a one-page SLA-to-infrastructure worksheet that can support a tenant discussion or pilot-floor assessment.
Translate Tenant SLAs Into Building Priorities Before an Outage Does It for You
Property owners and facilities teams often hear a familiar set of requests from tenants: “We need 100% uptime.” “Internet cannot go down.” “Our systems are business-critical.” Those requests are understandable, but they are not yet an infrastructure plan.
The risk appears when the tenant’s service expectations live in lease language or vendor contracts while the building’s physical and operational capabilities live somewhere else. A building may have new fiber, backup equipment, separate systems, and significant capital invested in redundancy, yet a single misrouted riser cable or misconfigured handoff can still stop a tenant’s operation. The outcome is not just technical downtime. It can mean lost productivity, weakened trust, and difficult questions about where the assumptions failed.
The better approach is to translate tenant expectations into specific services, dependencies, business impact, resilience choices, and operational ownership. This gives owners a practical way to prioritize limited budgets and make infrastructure decisions that support real tenant continuity.
The SLA Gap Is Usually an Ownership Gap
A tenant SLA describes a promised level of service. Building service levels describe what the physical and operational environment can actually support. Those concepts may sound aligned, but they often sit in different contracts, with different vendors, and under different teams.
That separation creates ambiguity. Who provides backup internet? Who tests carrier failover? Does the building control the priority-power design, or is the tenant expected to maintain its own protection? Who confirms whether two carriers truly use separate paths? When these questions remain unanswered, the building may appear resilient on paper while critical tenant services remain exposed.
Every assessment should begin with a more useful operational question: what breaks if this goes down? That question shifts the conversation away from generic promises and toward the actual business services a tenant relies on.
Identify the Services That Matter Most
Do not begin by choosing equipment. Begin by identifying tenant-critical services. Depending on the tenant, that could include receptionist Wi-Fi, VoIP, point-of-sale systems, critical clinical devices, EMR access, access control, or emergency monitoring.
Each service should then be tied to the systems, vendors, and facilities components that make it work. A useful dependency map can include:
- Power feeds and power zones
- Riser pathways and physical cabling routes
- Carrier handoffs and provider responsibilities
- Network edge equipment
- Telecom, infrastructure, and managed-service vendors
- Building operations responsibilities
- Tenant IT responsibilities
This is where hidden risk becomes visible. A tenant may have contracts with two carriers, but if both circuits enter through the same rooftop route, that is not meaningful path diversity. Likewise, two power circuits may look independent until tracing shows they depend on one transformer or upstream node. The building does not have true redundancy simply because it has more than one service contract or more than one piece of equipment.
Score Risk in Business Terms
Once critical services and dependencies are identified, assign a business-impact score. The episode recommends using a short scale, such as one through five, based on downtime cost, safety risk, and tenant-satisfaction impact. Combine that with the likelihood of failure to create a prioritized list tied to money and risk.
This matters because owners are constantly balancing competing investment requests. A scoring model provides a common language for those decisions. Instead of treating every request for uptime as equally urgent, teams can identify where a failure would have the greatest operational consequence and where a modest investment can reduce a serious exposure.
For example, a failure that disrupts a high-impact clinical application may deserve a different response than a temporary loss of convenience Wi-Fi. Both matter, but the right resilience level, recovery objective, and budget may not be the same.
Target the Actual Single Point of Failure
A medical-tenant example illustrates why dependency mapping is more valuable than broad redundancy. EMR access was rated as a five: completely critical. The owner initially considered a costly plan involving separate generators and redundant UPS lines across the building.
After mapping the service, the team found the more important issue. The EMR servers and the telecom handoff shared a single utility path outside the building. Buildingwide generator redundancy would have added cost, but it would not have resolved that external shared dependency.
The more focused solution was to harden the utility path, establish a scheduled proof test with the carrier and tenant IT team, and deploy a simple local failover for the most critical sessions. That approach was less expensive and more effective because it addressed the true point of failure.
The lesson is not that redundancy is unnecessary. It is that resilience investments must follow the service map. If a building protects the wrong layer, it can spend heavily while leaving the tenant’s most important dependency unaddressed.
Use Zoning, Diversity, and Targeted Redundancy
Three practical levers can help property teams match resilience spending to business impact: zoning, diversification, and targeted redundancy.
Zoning limits the blast radius of a failure. Segmenting power and network systems can keep an issue from affecting all tenants or an entire building at once. The goal is to contain disruption rather than allow one incident to become a full-property event.
Carrier diversity requires verification of physical separation. Separate pathways or trenches matter. A second carrier using the same route is an illusion of diversity, not a meaningful resilience measure.
Targeted redundancy focuses stronger measures on the services with the highest impact scores. Rather than mirroring every system for every tenant, owners can apply the most robust design where it is justified and use pragmatic alternatives elsewhere.
For backup communications, recovery-time objective and cost should guide the decision. A second carrier with true path diversity may be the right choice for a highly critical tenant. For less critical needs, cellular or SD-WAN failover may deliver minutes-to-hours resilience at a lower cost. The important point is to make those decisions deliberately and visibly, based on the tenant’s business requirements.
Include Ongoing Maintenance in the Decision
Capital expenditures are only one part of the resilience equation. Owners also need to consider operations and maintenance. Redundant systems require testing, documentation, vendor coordination, monitoring, and people who understand how the components work together.
Expected operations and maintenance costs should be included in the scoring model so decision-makers see total cost of ownership. Adding redundancy without maintaining it can create additional complexity and more ways for systems to fail. Reliability is not achieved at installation; it is demonstrated through operation.
A practical method is to start with a pilot. Test the approach on one floor or with one tenant class. Validate assumptions, responsibilities, and testing cadence. Then use what the pilot reveals to improve the design and budget before wider deployment.
Make the SLA Operational
Clear ownership is essential in a crisis. A tenant-critical service should have a documented runbook that identifies the relevant owner, vendor, and tenant IT roles. It should also define what happens when the service fails, who is contacted, and what evidence confirms recovery.
Regular testing should include carrier failover, generator startup, and application-continuity scenarios. Vendors should provide proof of path diversity and participate in joint tests when their systems are part of the dependency chain. Service-acceptance criteria should be written into statements of work and lease appendices, not left as verbal assumptions.
Teams also need a living diagram and change log. Building systems and vendor arrangements change quickly. During an outage, an outdated drawing is not a reliable source of truth. Current documentation and recent test results make it easier to respond, establish accountability, and reduce finger-pointing.
A Practical Checklist for Building Teams
- Inventory tenant-critical services.
- Map every critical service to physical infrastructure, providers, equipment, and responsible parties.
- Score business impact and failure likelihood.
- Verify physical diversity for power and carrier services.
- Apply targeted redundancy where the impact justifies the cost.
- Use lower-cost fallback options where appropriate.
- Include operations and maintenance in the cost model.
- Document responsibilities in runbooks, vendor statements of work, and test plans.
- Maintain diagrams and change logs as living operational documents.
Tenant continuity is not created by a broad promise of uptime. It is created when critical services are understood, dependencies are traced, resilience is matched to business impact, and every participant knows how the plan is tested and maintained. For a practical worksheet to guide that conversation, listen to this episode of Built, Wired & Secured and use the SLA-to-infrastructure framework discussed in the episode.