5 sources, 1 model
30-day go-live plan
~1 month discovery to production
Live in production

Carbon Canisters

Skyello - 2026

A system, not another person

Scroll
Looking for a design leader who turns ambiguous, high-stakes problems into shipped products? Let's talk →

Recruiter TL;DR -30 seconds15 min read

  • The business problem -a refinery's carbon canister program, the vapor control that keeps benzene out of the air, ran on a hand-kept spreadsheet. The cost was on record: a quarter of the fleet destroyed by uneven rotation, and fresh inventory down to 7 against the 10-canister floor that forces a production cut
  • My role -led it end to end as product and design lead: discovery with the customer, the offer and rollout strategy, research, the domain model and product rules, the specification, and the product through to production
  • Strategy -shaped a Phase 1 the customer could say yes to without a new procurement cycle: a service with no capital purchase, an existing contract vehicle, 30 days from order to live, and acceptance criteria they could hold us to
  • Synthesis -reconciled five sources that disagreed, down to the size of the fleet, into one model where a canister's status comes from where it is, not from someone typing it
  • Judgment -turned seven ambiguous questions into auditable rules, killed my own first concept when the hardware made its core assumption impossible, and held scope when asked to add a second asset type
  • Delivery -specified every story with Given/When/Then acceptance criteria and built ahead of the purchase order with engineering and an AI build partner, so the 30-day promise carried no build risk
  • Outcome -about a month from discovery call to production. Live, with a trial mode for the parallel run and a Phase 2 path to roughly 260 more canisters

Role

Product and design lead: discovery, strategy, systems, UX, specification

Team

Me, Skyello's CTO and engineering, an AI build partner, the customer's site lead, a contractor partner

Timeline

August to September 2026, about a month from discovery to production

Scope

0-to-1. Phase 1: 35 canisters at one site. Phase 2: about 260 across the refinery

A compliance program running on one person's typing

Refineries catch benzene and other vapors in carbon canisters: steel vessels of activated carbon, run in pairs so the second catches what gets past the first. A fleet of them moves through a loop. Staged fresh, put into service, pulled when the carbon is spent, trucked to a supplier to be regenerated, and returned.

The rules come from an environmental compliance order, with penalties that accrue per canister, per day. Pull the oldest fresh canister first. Check canisters in service on a schedule. Replace at breakthrough. Keep enough fresh supply on hand. At this site, all of it was tracked in a spreadsheet, fed by inspections three times a week.

The customer's site lead brought the problem to us directly. The spreadsheet wasn't failing quietly. It had already cost real money.

8of 32

Canisters destroyed

Pull order was a judgment call, so drivers pulled from the front rows. About half the fleet took all the wear until a quarter of it was run to destruction.

7vs 10

A production threshold breached

Below 10 fresh canisters, the refinery has to cut production. It fell to 7, and people found out late, not a system early.

0

Record of supplier condition

Canisters arrived from the supplier damaged, one leaking at hookup, with nothing on file to hold the supplier to.

1

Person holding it together

The one person who kept the sheet might not return to the role, leaving supervision to absorb the work by default.

"A system, not another person."

What the customer asked for on the discovery call

The canister loop

  1. Fresh stagingAvailableQueued oldest-first, counted against the floor
  2. In serviceIn serviceHooked up in a lead/lag pair, checked on a schedule
  3. Spent holdingAwaiting pickupCarbon spent, waiting for the truck
  4. On the roadOutboundTrucked to the supplier
  5. At the supplierRegeneratingTurnaround clock running
  6. ReturningInboundBack to the yard, not usable yet

Back in staging it counts as available only once a receipt check passes: seals, shell, labels, tag, and the regeneration certificate recorded.

The problem to solve

How might we keep a FIFO carbon program honest and provable, protect the production floor, and take the tracking off people entirely?

Designing the path to yes, not just the product

Oil and gas buys slowly. A great product that needs a year of procurement helps nobody this year. So before designing screens, I designed the decision the customer would have to make, and made it small, reversible, and provable.

A service, not a capital purchase

Trackers are provided, owned and maintained by us. The customer never buys, owns or manages a device, which removes the capital approval and the IT and maintenance objections in one move.

Trade-off: we carry hardware risk, so device choice, battery life and mounting became our design problem, not theirs.

An existing contract vehicle

Contracted through a partner agreement already in place, so no new procurement path. The purchase order rides a channel the customer already uses.

Trade-off: a partner in the loop means every artifact had to stand on its own, without us in the room.

A bounded Phase 1

One fleet, 35 canisters, at one site. Phase 2, about 260 canisters across the refinery, is scoped only after Phase 1 is accepted, so the second decision is made on evidence, not projection.

Trade-off: when the customer's manager asked to add a second asset type, I kept it out of this round to protect the timeline.

A 30-day promise, de-risked

Survey in week one, install by day 21, a parallel run alongside the sheet, acceptance on day 30. We built the product before the purchase order, so the clock only covers work that can't be done in advance.

Trade-off: building ahead of a signature is a bet, sized to what one site proves.

Rollout: purchase order to acceptance

Days 1 to 7

Site survey. Zone map signed off, device and mounting confirmed

Days 8 to 21

Trackers installed; fleet imported from the sheet; alerts configured

Days 22 to 29

Parallel run beside the sheet; thresholds tuned; alerts tested end to end

Day 30

Acceptance review. The sheet retires, and the system is the record

Acceptance criteria, written into the proposal

Five sources. None of them agreed.

There was no spec to start from. The picture had to be assembled from five things, each describing one slice of the problem in its own vocabulary. They didn't even agree on the size of the fleet: 32 canisters in rotation on the call, 38 rows in the workbook, 35 in scope. Reconciling them was the first design problem.

Conversation

The discovery call

The destroyed canisters, the breached floor, the supplier's condition problem, the person who might not return, and a second fleet of about 260.

It told me
What success is worth, and who carries the risk today.
It left open
What "done" looks like for each role.

Spreadsheet

The FIFO workbook

The site's own program: intake, queue, service checks, removal, and a weekly compliance audit.

It told me
The real process, the roles, the vocabulary, the rules.
It left open
Status, condition and place mixed together, and most of the dates the math needed were blank.

Map file

Three pins in a KML

Fresh staging, in-use area, spent holding. One point each.

It told me
Where the areas are.
It left open
A pin has no edge, so nothing could say whether a canister was inside an area.

Hardware

Six trackers, one spec sheet

I compared six intrinsically safe tracker makers and chose a Zone 0 rated cellular unit, top-mounted, facing up.

It told me
The hard physical limits of the data.
It left open
A handful of reports a day, each metres off. No live GPS, and none under pipe racks.

Regulation

The rulebook

The compliance order and the federal benzene rules: canisters in pairs, monitoring between primary and secondary, replacement at breakthrough, a sufficient fresh supply.

It told me
What "compliant" means, and what a record has to prove.
It left open
Nothing in Skyello's existing rules model had a place for a canister.

A site survey designed to confirm, not discover

Time inside a refinery is expensive for everyone. I drafted every zone from aerial imagery before anyone went on site, so the survey became one day of verification: sky view at every canister position, the area classification, a mounting spec that repeats across the fleet, signal at both sites, and container numbers checked against the stencils on the units. The customer's whole commitment was an escort and a 30-minute sign-off.

Draft zone map, drawn before the survey. Surroundings blurred for confidentialitySurvey

The process was sound. The data wasn't there.

The workbook was well designed: nine tabs, 3,925 formulas, a START_HERE page and a daily routine. So I audited it column by column, what the process asked for against what was actually filled in, to find exactly where a sound process broke down.

The workbook: 9 tabs, 3,925 formulas, 38 canisters entered

DashboardSTART_HERESETTINGSINPUT_MANAGERFIFO_QUEUEACTIVE_SERVICEINSPECTION_LOGOUTBOUND_REMOVALAUDIT_LOG
Container IDentered at receiving
38 / 38
Current statustyped by hand
38 / 38
Arrival date onsitethe FIFO rank is computed from it
17 / 38
Storage position10 of these say "In Service"
25 / 38
Service locationthe lead/lag slot
11 / 38
Placed in service datethe whole check schedule keys off it
0 / 38
Updated bywho changed the row
0 / 38
Exception reason and approvalFIFO bypass marked "No" on every row
0 / 38
Inspection log, weekly auditrows recorded
0 rows

A queue without dates

The pull order ranks by arrival date, and 21 of 38 canisters had none. "Pull next" was a guess, which is how the front rows wore out.

A schedule with no start

The 7- to 42-day check dates come from a service date that was blank for every canister, so no check could ever come due.

Three ideas in one field

"In Service" typed as a storage position, "Hold" as both a status and a condition, and damage written into free-text notes.

Counts are aggregate. No client values, names or identifiers appear on this page.

The product couldn't be a better spreadsheet. It had to observe the facts people were being asked to type.

Every typed field became an observed fact

I took every column the sheet asked a person to fill and worked out where the system could learn it instead: a tracker report, a zone boundary, a scan, a reading, or a rule. Where nothing could observe it, it stayed a person's job, but a small and specific one: approving an exception, recording a receipt check.

The biggest structural call was to separate status from condition. Where a canister is in the loop comes from place. Whether it's fresh, damaged or spent is its own field. The sheet had fused them, and that fusion is why a damaged canister could quietly sit in the queue.

From the workbook's columns to the product's model

They typedFilledNow it comes from
Current statusby handThe zone the tracker reports from: staging, in service, spent holding, the supplier, or the road
Arrival date onsite17 / 38The trip record, when the canister reports back on site
Storage position25 / 38A scanned bay first, then the assigned bay, then the nearest free one
FIFO rankformulaOldest verified arrival first. Only canisters whose receipt check passed are queued
Placed in service date0 / 38Entry into an in-service zone
7 to 42 day checks0 loggedReadings between primary and secondary on the site's interval. At or over the instrument's limit is breakthrough
Removed, outbound, pickup dates4, 4, 1 / 38Leaving service, reaching spent holding, leaving site; supplier turnaround measured per trip
FIFO bypass, reason, approval0 / 38Detected when a canister goes in out of order; only a supervisor can close it, with a reason, recorded as the approval
Condition and damage notesfree textCondition as its own field. A damaged receipt puts the canister on hold and builds the supplier's evidence
Weekly FIFO audit0 rowsContinuous: an append-only, tamper-evident history of every move, reading and exception

Pins had to become fences

To decide status from place, each area needed an edge, and an edge needs a margin, because GPS near a fence flickers in and out. Zones became polygons with a buffer band, drawn and signed off by the site.

What the site had, and what the product needed

Fresh staging In use Spent holding Inside? Unknowable.
Three pinsA point per area, no boundaries.
In the buffer: wait for a second report
Zones with a buffer bandAn edge, a margin, and a rule for the grey area.

Seven ambiguities, turned into policy

Each of these had more than one reasonable answer, and each answer changes what a supervisor can defend to an auditor. I wrote every one down as an explicit rule, so the system behaves the same way everywhere and can explain itself.

01

Where is it, exactly?

Why it's hard
Fixes are metres off, canisters stand about three metres apart, and there are only a few reports a day.
Rule
Grade every position: scan, high, medium, low. Seat canisters on their bays by default, keep raw GPS one click away, and never draw two units stacked.

02

Has it really moved?

Why it's hard
A fix by the fence flips a canister in and out of a zone, and every flip would be a false status change.
Rule
A buffer band around each zone. A clear fix deep inside counts at once; a borderline one waits for a second report. Cell-tower fixes never move a canister between zones.

03

Is it usable yet?

Why it's hard
A canister back from the supplier is fresh on paper, and some have arrived damaged.
Rule
It counts as available only once its receipt check passes, or shows as unverified after a grace period. A damaged receipt puts it on hold and into the supplier's evidence packet.

04

When is it spent?

Why it's hard
Different instruments, different limits, and checks that sometimes can't be taken.
Rule
A reading at or over that instrument's limit is breakthrough, whatever box was ticked. A check with no reading needs a reason. Leaving service always marks a canister spent.

05

What if the queue is skipped?

Why it's hard
Real yards need exceptions, and an audit needs every exception explained.
Rule
Allow it, detect it, and require a reason. Only a supervisor can close a FIFO bypass, and their name is recorded as the approval.

06

What if a tracker goes quiet?

Why it's hard
Batteries, dead zones and a unit behind a steel wall all look the same: silence.
Rule
Show the last known position with its age. After three missed reports, alert with the fix: scan the tag on the next round. Off site, allow 48 hours.

07

Which canister is it?

Why it's hard
A container serial, a tracker ID and a printed tag are three identifiers for one thing, and trackers get swapped.
Rule
One record per canister. Tracker bindings are time-ranged so history follows the canister through a swap, and search finds it by any of the three.

+

And the sheet people already trust?

Why it's hard
Nobody switches off a working spreadsheet on day one, and they shouldn't.
Rule
Import the workbook as it is, with its own headers and its own position naming, then run a trial mode beside the sheet until the two agree.

I killed my own first concept. The hardware told me to.

My first concept treated this as asset tracking: sites down the side, battery health, geofence exits, a fleet list, and pings every 15 minutes. It answered "where are my containers?"

Two inputs killed it. The workbook showed the question the site actually asks: what do we pull next, and will we stay above the floor? And the tracker spec sheet showed the 15-minute ping was never real. The battery budget tops out at twelve reports a day.

Concept
First concept: asset tracking, sample dataKilled
  • A map of the site with the fleet beside it
  • Geofences as the unit of place
  • Pings every 15 minutes, which the hardware can't sustain
  • Battery health as a headline instead of an exception
  • No pull order, no floor, no breakthrough, no supplier loop
Shipped
Shipped: the business questions, answered firstLive
  • Fresh canisters against the production floor, with a 14-day projection
  • The next canister to pull, and the three after it
  • Rotation balance: proof the wear problem is fixed
  • Tracker health only when a tracker needs attention

The battery budget that reset the design: reports per day vs. tracker battery life

1 per day
8 to 10 yrs
2 per day
5 to 8 yrs
4 per day
2.5 to 4.5 yrs
6 per day
2 to 3 yrs
12 per day
1.5 to 2 yrs
96 per day (concept)
Not offered
0246810 years

From the tracker manufacturer's published spec sheet (preliminary figures). Because we own the hardware, battery life is our cost. The product is built around about five reports a day, and everything that assumed "live" was redesigned around "last known".

A spec engineering could build from, and QA could test against

I wrote the product spec as the single source of truth: problem, goals, users, zones, status model, rules, alerts, hardware, data boundaries, rollout, and open questions. Every story became a user story with Given/When/Then acceptance criteria, and the milestones mirrored the rollout, starting with "build complete" before the purchase order.

The spec, by epic

Platform and rules

  • Data model and the canister record5 stories
  • Tracker ingestion and device health6 stories
  • Geofence and status engine3 stories
  • Inventory, FIFO rotation, supplier turnaround4 stories
  • Inspections and canister condition3 stories
  • Alerts and notifications2 stories
  • Security, configuration, reports and export6 stories

Experience and rollout

  • Web app: overview, map, fleet, alerts8 stories
  • Field app: register trackers, scan canisters3 stories
  • Settings: site, zones, thresholds, roles8 stories
  • Reports1 story
  • Field deployment4 stories
  • QA, parallel run, acceptance3 stories
Given
a canister in fresh staging
When
a report puts it just inside spent holding, within the buffer band
Then
its status holds until a second report, at least ten minutes later, confirms the move

The buffer-band rule, written the way the spec writes every rule.

What the rules look like on screen

01

Show the yard as it's run, not as GPS guesses

Raw GPS scatters a packed yard: units overlap, rows break up, and some land outside the zone entirely. The default view seats every canister on its bay, staging in pull order, with PULL NEXT on number one. That's the answer to the front-row wear problem, made visible.

The raw view is one click away, and even there units are pushed apart instead of stacked. The map should never show a yard that doesn't exist.

GPS
As the trackers report it

Metres of error: units overlap, and one lands well outside the fence.

FIFO
As the yard is run

Each canister on its bay, in pull order. Same data, one click apart.

02

3D, and honest about what it knows

Canisters are modelled at their real footprint. They're white in the yard, so the body stays white and status rides on a band around the roof edge, readable from any angle.

Every unit says how sure the system is: scanned, tracked, a GPS accuracy ring, or last known when a tracker goes quiet. A silent unit doesn't vanish. It becomes a question with an owner.

Fresh staging: queue positions, last-known units, painted bay IDsMap

03

Alerts that protect the floor, each with a next step

Inventory warns at 14 and escalates at 12, sized to fire a full resupply cycle before the production floor of 10, on holiday weekends the same as a Tuesday morning. Twenty alert kinds in all; condition alerts close themselves when the condition goes away, and event alerts wait for a person to own them.

Alert emails carry a map picture of the canister, so the answer is in the notification, not behind a login.

Alerts: the problem, the next step, who owns itAlerts

04

The supplier loop, on the record

Canisters on the road follow real roads, coloured by live traffic, with an arrival time that moves when the traffic does. Supplier turnaround is measured per trip, and every receipt check lands in the canister's permanent record, so the next damaged delivery is a documented supplier issue, not a disagreement.

Returning: route, traffic, ETAOff site
The permanent record, from the mapRecord

05

The site sets itself up

Zones are drawn or imported from KML and signed off by the site after walking the edges. Last week's reports show as yellow dots, so the survey check is visual: every dot should sit inside the zone the canister was really in. Bays snap into rows and columns as they're placed.

Zone editor: the next bay snapping into lineSetup

Proven against a yard before the yard had trackers

No tracker had reported yet, so there was no real data to design against. We built a simulator instead: a sample site whose 38 canisters mirror the workbook's status mix, with live simulated trackers and a week of backfilled history. Every screen was designed and reviewed against moving data, and the simulator shipped as a feature for demos and training.

A survey check before sign-off

Zones start as drafts. The site signs them off only after walking the edges and seeing last week's reports land inside the right zones.

A parallel run

Trial mode emails alerts but never escalates them, so the product runs beside the sheet until status accuracy clears the 98% bar.

Performance, measured

When the map felt slow to settle, I benchmarked it rather than guessed: the same pan and zoom path, a fresh cache per configuration.

~350 ~100ms

Until the map settles after a pan

~255 ~150ms

Until it settles after a zoom

~400 ~20ms

Going back to a part of the yard you've already seen

Built ahead of the order. Live in about a month.

From the discovery call to production took about a month. Carbon Canisters runs on Skyello's platform with the site's workbook importable as it is and a trial mode for the parallel run, so the 30-day rollout starts the day the order lands, with no build left on the clock.

Success is defined in the customer's terms, and every measure is already instrumented: status accuracy through the parallel run, inventory alerts that fire before the floor, the sheet retired with sign-off, and rotation balance, which flags any canister worked well above the fleet average and is the proof that the wear problem is fixed.

The same pattern scales to Phase 2: about 260 canisters across the refinery, with Bluetooth tags and fixed gateways where pipe racks block the sky.

What shipped

Live yard map

Satellite or dark, 3D canisters, lit for the site's time of day

FIFO pull order

Queue positions, receipt checks, supervised exceptions

Inventory protection

Available against the floor, a 14-day forecast, tiered warnings

Twenty alert kinds

Owners, a next step on every condition alert, email with a map

Supplier accountability

Receipt checks, turnaround per trip, an evidence packet

Five reports

Monthly program, supplier evidence, rotation, history, full export

Setup by the site

Workbook import, zones and bays, tag labels, survey sign-off

Sample sites

A simulated fleet with live trackers, for demos and training

The spreadsheet was the spec. The blank cells were the problem statement.

Design the decision, not just the product. In a slow-buying industry, the offer, the contract path and the acceptance criteria were as much a design problem as the interface, and they decided whether the interface would ever be used.

The customer's own artifacts beat a requirements document. The workbook held the process, the roles, the vocabulary and the rules, and its empty columns showed exactly where the process broke. Reading it closely was the research.

Data you ask people to type is data you won't have. The goal wasn't a better form. It was to stop needing the form, and keep the few things only a person can do small and specific.

Physical constraints are design inputs. A battery chart on a spec sheet reshaped the whole product. I now read the hardware before I sketch the software.

Skills demonstrated in this project

Product Strategy Service Design Customer Discovery Problem Framing Data Audit & Synthesis Domain Modeling Systems Thinking Product Specification Regulated Industries IoT & Hardware Constraints Geospatial & 3D Visualization Design Engineering AI-Accelerated Delivery 0-to-1 Product Leadership

Tabari Seward

Zero-to-one product designer combining product judgment, enterprise systems thinking, AI-native product-development methods, functional prototyping, and measurable business impact.

Next Case Study

Walgreens

Reducing a 10-step pharmacist workflow to two steps across 8,500+ locations