Why this environment matters
A battery storage site translates commercial dispatch requests into actions constrained by rack condition, temperature, inverter limits and local protection. The risky boundary is where a remote request for energy becomes permission to charge or discharge physical equipment. This proposal keeps market connectivity separate from that permission.
The security challenge
A scheduler may ask for output that was available when the request was created but is no longer appropriate when it arrives. A candidate control broker would evaluate the requested power and duration against current local limits. It would identify the source and age of the request and retain the reason for accepting, reducing or rejecting it.
How the capsule model could help
NØNOS could isolate the market-facing client, site optimiser and equipment adapter. The optimiser would propose a schedule without possessing unrestricted access to rack configuration. Local battery management and independent protection would continue to determine allowable physical operation; their telemetry and fault handling need to remain trustworthy even if the optimiser crashes. A restart must reconcile current charge state and active equipment limits before issuing another dispatch. It should not assume that the last saved schedule is still valid or that a cleared process memory means a thermal condition has cleared. The recovery record would identify both the requested operation and the equipment’s acknowledged state. The evaluation would begin with a simulator and recorded dispatch data. Engineers could compare proposed commands against the site’s actual operating envelope under delayed telemetry, lost connectivity and an unavailable rack. This is more informative than a demonstration in which a healthy system follows a single unrestricted schedule.
Deployment requirements
This concept cannot certify a battery installation or derive safe electrochemical limits. Equipment interfaces, independent protection, fire response and control stability need assessment by the relevant system engineers before operational integration. Evaluation requirements: Send a delayed dispatch after a rack becomes unavailable and verify that the current capacity restriction is applied. Restart the optimiser during an active limit and confirm that the restriction survives reconciliation. Remove external connectivity and demonstrate the documented local operating mode without granting the market client additional authority.
Current public-beta limitations, hardware support and application availability must be assessed before any pilot. Neither this use case nor an industry source establishes NONOS certification or a current customer deployment.
A dispatch request is an input, not a safety override
A scheduler may ask for output that was available when the request was created but is no longer appropriate when it arrives. A candidate control broker would evaluate the requested power and duration against current local limits. It would identify the source and age of the request and retain the reason for accepting, reducing or rejecting it.
NØNOS could isolate the market-facing client, site optimiser and equipment adapter. The optimiser would propose a schedule without possessing unrestricted access to rack configuration. Local battery management and independent protection would continue to determine allowable physical operation; their telemetry and fault handling need to remain trustworthy even if the optimiser crashes.
Restart the optimiser without resetting the plant
A restart must reconcile current charge state and active equipment limits before issuing another dispatch. It should not assume that the last saved schedule is still valid or that a cleared process memory means a thermal condition has cleared. The recovery record would identify both the requested operation and the equipment’s acknowledged state.
The evaluation would begin with a simulator and recorded dispatch data. Engineers could compare proposed commands against the site’s actual operating envelope under delayed telemetry, lost connectivity and an unavailable rack. This is more informative than a demonstration in which a healthy system follows a single unrestricted schedule.
Who could buy or integrate it?
- Storage developers procuring complete battery projects and operating platforms
- BESS integrators choosing energy management and controller software
- Storage operators funding fleet security and maintenance upgrades
Industry examples: Fluence, Tesla. Organisations shown illustrate the industry. No NONOS customer, partner or endorsement relationship is implied.