Carbon Canisters
Skyello - 2026
Recruiter TL;DR -30 seconds15 min read
01 The Problem
Refineries catch benzene and other vapors in carbon canisters: steel vessels of activated carbon, run in pairs so the second catches what gets past the first. A fleet of them moves through a loop. Staged fresh, put into service, pulled when the carbon is spent, trucked to a supplier to be regenerated, and returned.
The rules come from an environmental compliance order, with penalties that accrue per canister, per day. Pull the oldest fresh canister first. Check canisters in service on a schedule. Replace at breakthrough. Keep enough fresh supply on hand. At this site, all of it was tracked in a spreadsheet, fed by inspections three times a week.
The customer's site lead brought the problem to us directly. The spreadsheet wasn't failing quietly. It had already cost real money.
Pull order was a judgment call, so drivers pulled from the front rows. About half the fleet took all the wear until a quarter of it was run to destruction.
Below 10 fresh canisters, the refinery has to cut production. It fell to 7, and people found out late, not a system early.
Canisters arrived from the supplier damaged, one leaking at hookup, with nothing on file to hold the supplier to.
The one person who kept the sheet might not return to the role, leaving supervision to absorb the work by default.
"A system, not another person."
What the customer asked for on the discovery callThe canister loop
Back in staging it counts as available only once a receipt check passes: seals, shell, labels, tag, and the regeneration certificate recorded.
The problem to solve
How might we keep a FIFO carbon program honest and provable, protect the production floor, and take the tracking off people entirely?
02 Strategy
Oil and gas buys slowly. A great product that needs a year of procurement helps nobody this year. So before designing screens, I designed the decision the customer would have to make, and made it small, reversible, and provable.
Trackers are provided, owned and maintained by us. The customer never buys, owns or manages a device, which removes the capital approval and the IT and maintenance objections in one move.
Trade-off: we carry hardware risk, so device choice, battery life and mounting became our design problem, not theirs.
Contracted through a partner agreement already in place, so no new procurement path. The purchase order rides a channel the customer already uses.
Trade-off: a partner in the loop means every artifact had to stand on its own, without us in the room.
One fleet, 35 canisters, at one site. Phase 2, about 260 canisters across the refinery, is scoped only after Phase 1 is accepted, so the second decision is made on evidence, not projection.
Trade-off: when the customer's manager asked to add a second asset type, I kept it out of this round to protect the timeline.
Survey in week one, install by day 21, a parallel run alongside the sheet, acceptance on day 30. We built the product before the purchase order, so the clock only covers work that can't be done in advance.
Trade-off: building ahead of a signature is a bet, sized to what one site proves.
Rollout: purchase order to acceptance
Days 1 to 7
Site survey. Zone map signed off, device and mounting confirmed
Days 8 to 21
Trackers installed; fleet imported from the sheet; alerts configured
Days 22 to 29
Parallel run beside the sheet; thresholds tuned; alerts tested end to end
Day 30
Acceptance review. The sheet retires, and the system is the record
Acceptance criteria, written into the proposal
03 Discovery
There was no spec to start from. The picture had to be assembled from five things, each describing one slice of the problem in its own vocabulary. They didn't even agree on the size of the fleet: 32 canisters in rotation on the call, 38 rows in the workbook, 35 in scope. Reconciling them was the first design problem.
Conversation
The destroyed canisters, the breached floor, the supplier's condition problem, the person who might not return, and a second fleet of about 260.
Spreadsheet
The site's own program: intake, queue, service checks, removal, and a weekly compliance audit.
Map file
Fresh staging, in-use area, spent holding. One point each.
Hardware
I compared six intrinsically safe tracker makers and chose a Zone 0 rated cellular unit, top-mounted, facing up.
Regulation
The compliance order and the federal benzene rules: canisters in pairs, monitoring between primary and secondary, replacement at breakthrough, a sufficient fresh supply.
Time inside a refinery is expensive for everyone. I drafted every zone from aerial imagery before anyone went on site, so the survey became one day of verification: sky view at every canister position, the area classification, a mounting spec that repeats across the fleet, signal at both sites, and container numbers checked against the stencils on the units. The customer's whole commitment was an escort and a 30-minute sign-off.
04 Data Audit
The workbook was well designed: nine tabs, 3,925 formulas, a START_HERE page and a daily routine. So I audited it column by column, what the process asked for against what was actually filled in, to find exactly where a sound process broke down.
The workbook: 9 tabs, 3,925 formulas, 38 canisters entered
The pull order ranks by arrival date, and 21 of 38 canisters had none. "Pull next" was a guess, which is how the front rows wore out.
The 7- to 42-day check dates come from a service date that was blank for every canister, so no check could ever come due.
"In Service" typed as a storage position, "Hold" as both a status and a condition, and damage written into free-text notes.
Counts are aggregate. No client values, names or identifiers appear on this page.
The product couldn't be a better spreadsheet. It had to observe the facts people were being asked to type.
05 Synthesis
I took every column the sheet asked a person to fill and worked out where the system could learn it instead: a tracker report, a zone boundary, a scan, a reading, or a rule. Where nothing could observe it, it stayed a person's job, but a small and specific one: approving an exception, recording a receipt check.
The biggest structural call was to separate status from condition. Where a canister is in the loop comes from place. Whether it's fresh, damaged or spent is its own field. The sheet had fused them, and that fusion is why a damaged canister could quietly sit in the queue.
From the workbook's columns to the product's model
| They typed | Filled | Now it comes from |
|---|---|---|
| Current status | by hand | The zone the tracker reports from: staging, in service, spent holding, the supplier, or the road |
| Arrival date onsite | 17 / 38 | The trip record, when the canister reports back on site |
| Storage position | 25 / 38 | A scanned bay first, then the assigned bay, then the nearest free one |
| FIFO rank | formula | Oldest verified arrival first. Only canisters whose receipt check passed are queued |
| Placed in service date | 0 / 38 | Entry into an in-service zone |
| 7 to 42 day checks | 0 logged | Readings between primary and secondary on the site's interval. At or over the instrument's limit is breakthrough |
| Removed, outbound, pickup dates | 4, 4, 1 / 38 | Leaving service, reaching spent holding, leaving site; supplier turnaround measured per trip |
| FIFO bypass, reason, approval | 0 / 38 | Detected when a canister goes in out of order; only a supervisor can close it, with a reason, recorded as the approval |
| Condition and damage notes | free text | Condition as its own field. A damaged receipt puts the canister on hold and builds the supplier's evidence |
| Weekly FIFO audit | 0 rows | Continuous: an append-only, tamper-evident history of every move, reading and exception |
To decide status from place, each area needed an edge, and an edge needs a margin, because GPS near a fence flickers in and out. Zones became polygons with a buffer band, drawn and signed off by the site.
What the site had, and what the product needed
06 Product Rules
Each of these had more than one reasonable answer, and each answer changes what a supervisor can defend to an auditor. I wrote every one down as an explicit rule, so the system behaves the same way everywhere and can explain itself.
01
02
03
04
05
06
07
+
07 First Concept
My first concept treated this as asset tracking: sites down the side, battery health, geofence exits, a fleet list, and pings every 15 minutes. It answered "where are my containers?"
Two inputs killed it. The workbook showed the question the site actually asks: what do we pull next, and will we stay above the floor? And the tracker spec sheet showed the 15-minute ping was never real. The battery budget tops out at twelve reports a day.
The battery budget that reset the design: reports per day vs. tracker battery life
From the tracker manufacturer's published spec sheet (preliminary figures). Because we own the hardware, battery life is our cost. The product is built around about five reports a day, and everything that assumed "live" was redesigned around "last known".
08 Specification
I wrote the product spec as the single source of truth: problem, goals, users, zones, status model, rules, alerts, hardware, data boundaries, rollout, and open questions. Every story became a user story with Given/When/Then acceptance criteria, and the milestones mirrored the rollout, starting with "build complete" before the purchase order.
The spec, by epic
The buffer-band rule, written the way the spec writes every rule.
09 The Product
01
Raw GPS scatters a packed yard: units overlap, rows break up, and some land outside the zone entirely. The default view seats every canister on its bay, staging in pull order, with PULL NEXT on number one. That's the answer to the front-row wear problem, made visible.
The raw view is one click away, and even there units are pushed apart instead of stacked. The map should never show a yard that doesn't exist.
Metres of error: units overlap, and one lands well outside the fence.
Each canister on its bay, in pull order. Same data, one click apart.
02
Canisters are modelled at their real footprint. They're white in the yard, so the body stays white and status rides on a band around the roof edge, readable from any angle.
Every unit says how sure the system is: scanned, tracked, a GPS accuracy ring, or last known when a tracker goes quiet. A silent unit doesn't vanish. It becomes a question with an owner.
03
Inventory warns at 14 and escalates at 12, sized to fire a full resupply cycle before the production floor of 10, on holiday weekends the same as a Tuesday morning. Twenty alert kinds in all; condition alerts close themselves when the condition goes away, and event alerts wait for a person to own them.
Alert emails carry a map picture of the canister, so the answer is in the notification, not behind a login.
04
Canisters on the road follow real roads, coloured by live traffic, with an arrival time that moves when the traffic does. Supplier turnaround is measured per trip, and every receipt check lands in the canister's permanent record, so the next damaged delivery is a documented supplier issue, not a disagreement.
05
Zones are drawn or imported from KML and signed off by the site after walking the edges. Last week's reports show as yellow dots, so the survey check is visual: every dot should sit inside the zone the canister was really in. Bays snap into rows and columns as they're placed.
10 Validation
No tracker had reported yet, so there was no real data to design against. We built a simulator instead: a sample site whose 38 canisters mirror the workbook's status mix, with live simulated trackers and a week of backfilled history. Every screen was designed and reviewed against moving data, and the simulator shipped as a feature for demos and training.
Zones start as drafts. The site signs them off only after walking the edges and seeing last week's reports land inside the right zones.
Trial mode emails alerts but never escalates them, so the product runs beside the sheet until status accuracy clears the 98% bar.
When the map felt slow to settle, I benchmarked it rather than guessed: the same pan and zoom path, a fresh cache per configuration.
~350 ~100ms
Until the map settles after a pan
~255 ~150ms
Until it settles after a zoom
~400 ~20ms
Going back to a part of the yard you've already seen
11 Outcome
From the discovery call to production took about a month. Carbon Canisters runs on Skyello's platform with the site's workbook importable as it is and a trial mode for the parallel run, so the 30-day rollout starts the day the order lands, with no build left on the clock.
Success is defined in the customer's terms, and every measure is already instrumented: status accuracy through the parallel run, inventory alerts that fire before the floor, the sheet retired with sign-off, and rotation balance, which flags any canister worked well above the fleet average and is the proof that the wear problem is fixed.
The same pattern scales to Phase 2: about 260 canisters across the refinery, with Bluetooth tags and fixed gateways where pipe racks block the sky.
What shipped
Satellite or dark, 3D canisters, lit for the site's time of day
Queue positions, receipt checks, supervised exceptions
Available against the floor, a 14-day forecast, tiered warnings
Owners, a next step on every condition alert, email with a map
Receipt checks, turnaround per trip, an evidence packet
Monthly program, supplier evidence, rotation, history, full export
Workbook import, zones and bays, tag labels, survey sign-off
A simulated fleet with live trackers, for demos and training
12 Reflection
The spreadsheet was the spec. The blank cells were the problem statement.
Design the decision, not just the product. In a slow-buying industry, the offer, the contract path and the acceptance criteria were as much a design problem as the interface, and they decided whether the interface would ever be used.
The customer's own artifacts beat a requirements document. The workbook held the process, the roles, the vocabulary and the rules, and its empty columns showed exactly where the process broke. Reading it closely was the research.
Data you ask people to type is data you won't have. The goal wasn't a better form. It was to stop needing the form, and keep the few things only a person can do small and specific.
Physical constraints are design inputs. A battery chart on a spec sheet reshaped the whole product. I now read the hardware before I sketch the software.
Skills demonstrated in this project
Product Strategy Service Design Customer Discovery Problem Framing Data Audit & Synthesis Domain Modeling Systems Thinking Product Specification Regulated Industries IoT & Hardware Constraints Geospatial & 3D Visualization Design Engineering AI-Accelerated Delivery 0-to-1 Product Leadership