A station stops reporting. Nothing visible has broken: the doors still hold parcels, the recipients still have their codes, the couriers still have it on their route. The failure is in what the operator can no longer see, and the damage compounds with every hour it stays invisible.
Triage in order of consequence
The first decision is not repair, it is containment. Parcels already inside must remain collectable. New deposits must stop being allocated there before a courier is sent to a station that cannot confirm anything. Only then does the cause matter: power, connectivity, controller or door hardware, each with a different response and a different person to send.
- Freeze new allocations to the station so no courier is dispatched blind.
- Confirm whether recipients holding codes can still collect.
- Classify the fault from the last heartbeat and the pattern before it.
- Raise a field task with what is known, not a generic alert.
A field task carries context or it wastes a visit
A technician sent with nothing but an address arrives, diagnoses from scratch, and often returns for a part. A task carrying the last reported state, the fault classification and the recent event history converts more visits into fixes. That is the difference between a maintenance queue and an operations function.
The cost of an outage is measured in the parcels that never entered the station, not the minutes it was unreachable.
Recovery ends where it began: the station reports in, occupancy is reconciled against what the platform believed, and allocation resumes only once the two agree.


