GDS Technology — Built, Wired and Secured podcast banner
Watch on YouTube →
Episodes Built
Episode 84

Who Gets the Power? Prioritizing Critical Loads in Building Outages

July 20, 2026
Key takeaways
  • A power prioritization policy should be short, signed, and testable so teams can execute it under pressure.
  • Undocumented feeders and hidden cross-connections create dangerous single points of failure during outages.
  • Life safety, essential communications, and documented tenant-critical loads should be prioritized before comfort loads.
  • Staged startup sequencing helps prevent generator overload from inrush current when power is restored.
  • Quarterly transfer tests, annual full-load testing, and current drawings turn paper policy into real operational resilience.

Show Notes

Why power prioritization fails when it matters most

This episode of Built, Wired & Secured starts with a familiar but costly scenario: the generator starts during an overnight outage, basic emergency systems come online, and everyone assumes the building is covered. Then the calls start. Tenant servers never return to power. Elevators are on recall. HVAC begins short cycling. No one can quickly identify which panel feeds the systems that matter most. The result is not just downtime. It is lost trust, operational confusion, and days of avoidable disruption.

The conversation makes a direct point: if a building’s power prioritization policy is not short, signed, and testable, it will fail under pressure. In other words, the problem is rarely just generator capacity. More often, it is unclear ownership, undocumented dependencies, hidden cross-connections, and policies that sound reasonable in a meeting but cannot be executed by a night technician in a real outage.

Start with one question: what breaks if this goes down?

One of the strongest ideas in the episode is the discipline of forcing every critical load decision through a single question: what breaks if this goes down? If that cannot be answered in one sentence, the speakers argue that the organization does not actually have a prioritization plan. It has improvisation.

That framing matters because outages create stress, and stress exposes ambiguity. If facilities, IT, property management, and tenants all carry different assumptions about who is responsible for what, the building does not have a resilience strategy. It has a collection of guesses.

  • Property teams may assume tenants protect their own critical equipment.
  • IT may assume facilities has mapped emergency power correctly.
  • Facilities may assume their responsibility ends at life safety.
  • Tenants may assume their essential loads are covered when they are not.

Those gaps become dangerous when undocumented feeders or improvised patches create single points of failure no one sees until the outage happens.

Hidden dependencies are the real outage multiplier

The episode highlights how often the biggest failures are upstream and invisible. A communications closet on non-emergency power. A basement UPS feeding unexpected equipment. An access control system tied into a circuit no drawing reflects. These are the kinds of cross-connections that make buildings appear more resilient than they really are.

The speakers describe these undocumented dependencies as silent killers in an outage. That phrase fits because the systems may work for years without incident, giving teams false confidence. Then a real event occurs and no one can trace what depends on what.

The operational takeaway is clear: mapping and documentation are not optional administrative tasks. They are core resilience work. If feeders, dependencies, and emergency capacity are not visible, the policy is just paper.

A defensible prioritization framework

When resources are constrained, arguments about which loads matter most can become emotional quickly. The episode recommends using a short, objective matrix that is binding before the outage happens.

The order discussed in the conversation is practical and easy to follow:

  • Life safety first, including fire suppression, egress lighting, and emergency communications.
  • Essential communications and monitoring next, such as building alarms and the core network needed for incident response.
  • Business-critical tenant loads after that, but only when they are documented and tied to clear service expectations.
  • Comfort loads like full HVAC later, unless a business process would be damaged without them.

Just as important, the team should document maximum emergency capacity by feeder in kilowatts. This prevents decision-makers from promising more than the generator can reliably supply. The example given is useful: a 500 kW generator might allocate 350 kW to life safety and communications, leaving 150 kW for other supported loads. That kind of specificity turns a vague commitment into an operational rule.

Priority alone is not enough. Sequencing matters.

A major point in the episode is that it is not enough to decide what matters most. Teams also need to decide how loads come back online. Bringing everything online at once can create inrush current that trips the generator and collapses the recovery effort.

The speakers recommend staged startup rules so operators do not have to improvise.

  • Bring up life safety first.
  • Then restore communications.
  • Then energize tenant circuits in stages.
  • Use delays between major feeder transitions.

The timing guidance is especially practical. A range of 30 to 90 seconds between major feeder brings, or a 2-minute confirmation hold for large inrush loads, gives operators a workable standard. That is the kind of detail that makes a procedure executable in the field instead of theoretical on paper.

What an outage-ready rule looks like

One of the best operational insights in the discussion is the standard for a usable rule: one page maximum. That page should include a switch list showing what to keep energized and what to shed, any manual bypass steps, and three contact names with phone numbers available both in a physical binder and on a tablet.

The logic is simple. If a policy requires interpretation, committee discussion, or institutional memory during an emergency, it is not a real emergency policy.

A workable document should answer the immediate questions:

  • Which feeders stay on?
  • Which feeders get shed?
  • What order should startup follow?
  • What manual steps are required?
  • Who needs to be called if something does not behave as expected?

Testing is what turns paper policy into real reliability

The episode does not treat testing as a compliance exercise. It treats testing as the only way to prove the policy works in the dark.

The recommended cadence is straightforward:

  • Quarterly short transfer tests, typically around 10 minutes, to validate generator start and stage-one loads.
  • Annual full-load testing for 2 to 4 hours during a low-occupancy window.
  • Checklist-driven transfers with defined breaker actions, confirmation points, rollback steps, and verification owners.
  • Thermographic checks and labeling audits to catch overloaded or mislabeled feeders before an outage reveals them.

This emphasis on preventive maintenance reinforces one of the recurring messages in the episode: reliability starts with disciplined maintenance and clarity, not just equipment ownership.

Two real-world examples that make the case

The first example involves a small downtown office retrofit. The owner wanted comfort-grade HVAC on generator power, but the available generator capacity was limited. After mapping the circuits, the team found critical communications on non-emergency power and chose to reallocate a dedicated tenant breaker to a UPS-backed circuit instead of the generator. The result was no generator upsizing, but tenant servers stayed online for several hours. Just as important, the trade-offs were documented and signed by tenants, making the decision defensible later.

The second example comes from a campus environment where laboratories needed HVAC restored within 30 minutes to avoid sample loss. There, sequencing became the key issue. The campus was segmented, staged transfer switches were tied into a central controller, and manual override steps were retained. An early test exposed a startup sequence that overloaded the generator. After adding a time delay and an operator confirmation step, a 2-minute hold prevented repeat overloads.

Three actions to take this week

The episode ends with a practical checklist leaders can act on immediately:

  • Map and sign: create a one-page prioritization matrix and get facilities, IT, and property management to approve it.
  • Publish emergency capacity per feeder in kilowatts so everyone understands the limits.
  • Put a one-page switch list in the emergency binder and on the tablet for rapid use during an outage.

The final message is simple and useful: short rules, staged sequencing, current drawings, clear labels, and regular testing are what keep a building operational when power is scarce. In a real outage, the goal is not just to have backup power. It is to have decisions that are clear, defensible, and executable.

Deeper dive

Who gets the power when the lights go out?

When a building loses utility power, the emergency generator can create a false sense of security. The lights return in the corridor. Stairwell lighting comes on. A few critical systems wake back up. On the surface, it looks like the building is protected.

But as this episode of Built, Wired & Secured makes clear, the real question starts after the generator engages: who gets the power next?

That question is not academic. It determines whether a commercial building keeps operating or slips into confusion, downtime, and tenant frustration. If the wrong systems are prioritized, or if the right systems are brought back in the wrong order, an outage can trigger business interruption even when backup power technically exists.

The conversation focuses on a practical truth many facilities and IT leaders learn the hard way: power prioritization only works if it is short, signed, and testable. If it takes interpretation in the middle of a nighttime outage, it is not a resilience plan. It is an improvisation plan.

Why outage decisions break down

The episode opens with a scenario that feels painfully realistic. A building experiences a power event in the early morning hours. The generator starts. Then problems begin surfacing. Tenant servers do not come back online. Elevators are stuck on recall. HVAC starts cycling unpredictably. No one is confident which panel feeds what.

That kind of failure is usually not caused by one dramatic mechanical problem. It is caused by a chain of smaller organizational failures that have been tolerated for too long.

The speakers identify three recurring sources of breakdown:

  • People: ownership boundaries are unclear, and each group assumes another group is covering a given risk.
  • Documents: drawings, labels, and feeder documentation are incomplete or outdated.
  • Systems: hidden dependencies and undocumented cross-connections undermine the intended design.

That mix is especially dangerous in commercial buildings where facilities teams, IT teams, property management, and tenants all have overlapping interests but different assumptions. A property team may assume tenants have protected their own critical loads with UPS systems. Tenants may assume the building’s emergency infrastructure covers their most important circuits. Facilities may focus narrowly on life safety. IT may not have accurate visibility into how emergency power is actually distributed.

Those assumptions can coexist quietly for years. Then one outage exposes all of them at once.

The hidden dependency problem

One of the strongest sections of the episode deals with undocumented feeders and improvised cross-connections. These are the kinds of issues that rarely show up in glossy project closeout documents but routinely shape outage outcomes.

A communications closet may be tied to non-emergency power. A UPS may have been patched years ago to support lab equipment or access control. A critical device may be fed from a panel no one would expect. If the current drawings do not reflect those changes, teams can make the wrong decisions with total confidence.

That is what makes hidden dependencies so dangerous. They create single points of failure that are invisible until the exact moment the building is under stress.

The business impact is larger than equipment downtime. When power restoration is chaotic, tenant trust erodes. Response teams waste time debating facts that should already be documented. Leadership is forced into reactive decisions that are hard to defend later. In many cases, the outage itself is not what damages the relationship. The confusion is.

A simple framework for prioritizing critical loads

The episode argues against overcomplicated policy documents and in favor of a short objective matrix. The idea is to establish a binding order before pressure is high and emotions are involved.

The sequence presented in the conversation is clear:

  • Life safety first, including fire suppression, egress lighting, and emergency communications.
  • Essential communications and monitoring next, such as alarms and the core network needed for incident response.
  • Documented business-critical tenant loads after that, especially where service expectations or operational consequences are known in advance.
  • Comfort loads like full HVAC later, unless a specific process will be damaged without environmental control.

This matters because every building can make itself sound critical in a meeting. A formal matrix forces the team to separate what is required for safety, what is required for response, and what is important for continuity but not immediately essential.

The discussion also adds a crucial realism check: document emergency capacity by feeder in kilowatts. If the generator can only support a defined amount of load, that limit must be published clearly. A building team cannot promise continuity to everyone at once if the generator cannot physically carry that obligation.

This is where resilience planning becomes defensible. A 500 kW generator supporting 350 kW of life safety and communications leaves only 150 kW for other loads. That number changes the conversation from opinion to operational fact.

Restoration order can be as important as the priority list

Another major lesson from the episode is that prioritization without sequencing is incomplete. Even if the right systems are identified, bringing them online all at once can overload the generator due to inrush current.

That is a design and operations issue, not just a maintenance issue.

The speakers recommend staged startup logic that restores systems in deliberate phases. Life safety comes first. Communications follow. Tenant circuits are introduced in stages. Major feeder transitions are separated by timed delays. For larger inrush loads, a 2-minute confirmation hold can help prevent repeated overloads.

This is the kind of detail that often gets overlooked because it feels technical. But it has direct business consequences. If startup sequencing is wrong, the building can turn a recoverable outage into a cascading failure. If sequencing is documented and tested, the response becomes predictable and repeatable.

What field-ready documentation actually looks like

One of the most practical recommendations in the conversation is that the outage playbook should fit on one page. Not a thick binder. Not a policy memo. One page.

That page should include:

  • A switch list identifying which feeders stay on and which are shed.
  • Any manual bypass steps required.
  • The startup sequence.
  • Rollback steps if a transfer fails.
  • Three contact names and phone numbers.
  • Availability in both the emergency binder and on a tablet.

This recommendation reflects a deeper operating principle: if a policy depends on interpretation in the middle of an outage, it will not hold. The technician on the night shift should not have to decode executive intent. The instructions should be clear enough to execute under pressure.

Testing is the difference between policy and performance

The episode also reinforces that reliability is built through maintenance discipline. The speakers recommend quarterly short transfer tests of around 10 minutes to validate generator start and first-stage loads. They also recommend annual full-load testing lasting 2 to 4 hours during low-occupancy periods.

Just as important, they call for checklists covering breaker operations, confirmation points, rollback steps, and ownership of each verification task. Thermographic inspections and labeling audits round out the process by identifying overloaded or mislabeled feeders before a real event exposes them.

This is a useful reminder for both facilities and IT leaders: testing is not just a compliance box. It is how organizations prove that documentation, equipment behavior, and operator expectations still align.

Examples that show the trade-offs in practice

The small retrofit example in the episode is especially instructive. An owner wanted comfort-grade HVAC supported by generator power, but capacity was limited. Once the circuits were mapped, the team identified critical communications on non-emergency power and chose to reallocate a dedicated tenant breaker to a UPS-backed circuit instead of expanding generator scope. That choice preserved server uptime for a few hours without upsizing the generator. The real win, though, was that the trade-off was documented and signed by tenants ahead of time.

The campus example highlights a different issue: not what to power, but how to restore it. Laboratories needed HVAC within 30 minutes to avoid damage to samples. The site used segmented staging, transfer switches tied to a central controller, and manual override steps. An early test revealed that the original startup order overloaded the generator. Adding a time delay and operator confirmation step corrected the problem before a real outage forced the lesson under pressure.

What leaders should do next

If there is one consistent message in this episode, it is that clear, testable rules reduce both technical risk and organizational friction. Facilities leaders, IT teams, and property managers do not need a perfect model of every scenario. They need a shared, signed understanding of what matters most, what the infrastructure can support, and how operators should act when the event happens.

The most actionable next steps are straightforward:

  • Create a one-page prioritization matrix and get it signed by facilities, IT, and property management.
  • Publish emergency capacity by feeder in kilowatts.
  • Build a one-page switch list with staged startup rules and contact information.
  • Schedule quarterly transfer tests and annual full-load tests.
  • Keep labels and drawings current so response teams are not guessing in the dark.

For organizations managing commercial buildings, this is where strategic technology and facility planning come together. Outage resilience is not just about owning a generator. It is about knowing what that generator should protect, in what order, under what constraints, and with what proof.

If you want a stronger starting point for those conversations, this episode offers a practical framework you can apply during design reviews, outage planning, and capital discussions. It is a reminder that the most effective resilience policies are usually the simplest ones: clear priorities, documented dependencies, staged restoration, and disciplined testing. That is the kind of operational clarity worth building before the next outage arrives. If this topic is relevant to your buildings or tenant environments, listen to the full episode and use it to pressure-test your own assumptions.