Skip to content
Use case 041

Drinking Water Treatment Operator Workstations

A deployment concept for Drinking-water utilities fund operator workstation renewal and approve plant integration.; Control-system suppliers package workstation software into treatment automation contracts.; Water engineering integrators implement upgrades; shift operators use the resulting displays.

Proposed deployment · Compatibility assessment required
Water and Environmental Infrastructure

Why this environment matters

A treatment-plant operator needs to know whether the display represents the live process and whether an adjustment will reach the intended control point. The workstation is therefore both a viewing surface and a privileged route into treatment operations. This concept examines how those roles could be separated without displacing independent plant safeguards.

The security challenge

A proposed workstation would receive telemetry through a read-focused capsule and issue adjustments through a different command broker. An operator action would identify the process point, requested value and authorised operating context. Importing a report, opening a trend or acknowledging a notification would not by itself create permission to alter chemical dosing.

How the capsule model could help

The prototype would also distinguish measured values from calculated or stale values on the display. A compromised visual component might otherwise mislead an authorised operator into approving a harmful action. The command confirmation should show the relevant source and state through a separately assessed path, rather than trusting an arbitrary field in the requesting application. If the workstation fails, the control system and local safety arrangements need a defined response. Reloading a clean interface should first reacquire and reconcile live state, not replay a queue of old adjustments as if they were new requests. Recovery records should make an unconfirmed command distinguishable from one the controller accepted. For an initial evaluation, the proposed broker could observe a recorded control feed and compare its decisions with a simulator. Engineers should establish plant-specific bounds, staffing procedures and fallback visibility before permitting any connection that can write to operating equipment.

Separate address spaces and capability checks can limit cross-process reach. They cannot stop harmful use of legitimate permissions, prove AI decisions correct or substitute for domain-specific safety controls.

Deployment requirements

This is a workstation boundary proposal, not a water-treatment control design. Treatment chemistry, independent protection, hydraulic behavior and local operating procedures require plant engineering evidence. No cited guidance establishes that NØNOS is ready for this duty. Evaluation requirements: Present delayed telemetry and verify that stale data is visible before an operator is asked to confirm an adjustment. Crash the viewer during a pending command and distinguish accepted, rejected and unconfirmed results after recovery. Try a write operation from the report-generation capsule and verify denial at the device interface.

Current public-beta limitations, hardware support and application availability must be assessed before any pilot. Neither this use case nor an industry source establishes NONOS certification or a current customer deployment.

An alarm display should not inherit set-point authority

A proposed workstation would receive telemetry through a read-focused capsule and issue adjustments through a different command broker. An operator action would identify the process point, requested value and authorised operating context. Importing a report, opening a trend or acknowledging a notification would not by itself create permission to alter chemical dosing.

The prototype would also distinguish measured values from calculated or stale values on the display. A compromised visual component might otherwise mislead an authorised operator into approving a harmful action. The command confirmation should show the relevant source and state through a separately assessed path, rather than trusting an arbitrary field in the requesting application.

Recovery must preserve the plant’s actual state

If the workstation fails, the control system and local safety arrangements need a defined response. Reloading a clean interface should first reacquire and reconcile live state, not replay a queue of old adjustments as if they were new requests. Recovery records should make an unconfirmed command distinguishable from one the controller accepted.

For an initial evaluation, the proposed broker could observe a recorded control feed and compare its decisions with a simulator. Engineers should establish plant-specific bounds, staffing procedures and fallback visibility before permitting any connection that can write to operating equipment.

Who could buy or integrate it?

  • Drinking-water utilities fund operator workstation renewal and approve plant integration.
  • Control-system suppliers package workstation software into treatment automation contracts.
  • Water engineering integrators implement upgrades; shift operators use the resulting displays.

Industry examples: Siemens, Schneider Electric. Organisations shown illustrate the industry. No NONOS customer, partner or endorsement relationship is implied.

Market opportunity

Market benchmarks and device scenarios.

Published industry benchmark
US$4.43 billion

Water automation and instrumentation

Global · 2025 · annual market estimate

Automation and instrumentation for water and wastewater; includes physical instruments and control systems beyond workstation software.

Modelled global devices
20K–800K

Candidate OS endpoints

Hypothetical planning range · 2025

Low confidence: planning assumptions. Hardware compatibility, procurement and adoption have not been validated.

Illustrative annual licensing
$2M–$320M

USD / year at full model coverage

Device scenario × assumed US$100–$400 per device / year.

Not a revenue forecast, announced price or measured serviceable market.

Device calculation

Hypothetical global planning range, 2025 scenario: assume 10,000–80,000 municipal and industrial drinking-water treatment facilities × 2–10 candidate OS endpoints per site/asset = 20,000–800,000 endpoints. Counting unit: operator and maintenance workstations. Site and asset counts, and devices per site, are planning assumptions. The installed base has not been measured. Coverage is limited to the defined equipped subset; includes all candidate endpoints within that assumed subset. Hardware eligibility, certification, adoption and achievable NØNOS share are unverified; overlaps other cases.

Water Automation and Instrumentation Market – Size, Companies & Trends ↗

Market context only; separate from device and site population estimates. Original monetary-market scope and geography are preserved in benchmark. This source does not establish the assumed worldwide site count or endpoint density.

How to interpret the figures

Adjacent or broader commercial market benchmark; not the NØNOS OS market, licensable-device count or revenue forecast.

Modelled candidate endpoints multiplied by an assumed annual USD price per endpoint. Pricing is a planning assumption, not a vendor quote. This illustrates the full scenario range, not revenue or total addressable market. It excludes adoption timing, procurement, certification, support costs, channel economics and achievable market share. Use cases can overlap, so their totals do not represent unique devices.

Research from 2026. Publisher estimates have not been independently audited.

Read the full methodology

Explore NONOS

Choose your
NONOS experience.

Discover the platform for your organisation or explore the software.

You can reopen this chooser from the footer at any time.