Unattended operation & degraded modes
Software that runs while nobody is watching has to be designed around the periods when it could not see, could not compute, or could not reach anyone. On a shared ward those gaps are covered by people. In a bedroom at four in the morning they are covered by the interface or by nothing.
Overview
Triage worklist establishes that a list must prove it is live. This is the same instinct one level down, applied to a signal: a continuous stream that stops produces a screen showing the last value it received, and nothing about that screen says the stream stopped.
The clinical consequence is specific and severe. A glucose reading of 6.2 mmol/L is reassuring. A glucose reading of 6.2 mmol/L from forty minutes ago is not information about the present at all — and the two are indistinguishable unless the interface makes them different.
A gap is drawn as a gap. Never interpolated, never held at the last known value, never rendered as a blank that reads as normality. And the age of the newest reading is at least as prominent as the reading itself — because on an unattended device, age is the property that decides whether the value means anything.
Absence is a state
Not monitoring, no alarm, and nothing wrong are three different facts and never share a rendering.
Age before value
How old the reading is decides what it is worth. It is displayed with the number, not beneath it.
Degrade loudly
Reduced capability is announced. A device quietly doing less is the most dangerous state it has.
Anatomy
Glucose
Glucose
The right-hand card still shows the last value, because hiding it would be its own kind of lie. What it does not do is present it as the current one.
| Part | Rule |
|---|---|
| Age | Always present, in the header, in words a tired person can parse. "2 min ago", not a timestamp requiring subtraction. |
| Value | Shown while it is current. Once stale, replaced by the state, with the last value demoted to context and explicitly disowned. |
| Direction | Where the stream supports it — rising, steady, falling. On a continuous signal the trend is often more actionable than the value. |
| Cause | What is wrong, in physical terms the person can fix: sensor detached, out of range, phone offline. |
| Consumables | Sensor life, battery, supply. These run out unattended and are the most common cause of a gap. |
| Capability | What the device can and cannot do right now — see below. |
Four kinds of nothing
Key–value pair distinguishes three kinds of absence in a record. A continuous stream adds a fourth, and it is the dangerous one.
| State | What it means | Rendering |
|---|---|---|
| Measured, normal | Looked, found nothing wrong | The value, with its age. |
| Measured, no alarm | Looked, value outside range but not alarming yet | The value with its state. Silence is not the same as normality. |
| Not measured | The sensor is not reporting | "Not monitoring", with the cause and the fix. |
| Measured, could not reach you | An alarm fired and was not delivered | The most severe of the four. Shown at the next opportunity with the time it happened, and escalated at the time — see below. |
- Never interpolate across a gap. A smooth line through missing data is a drawing of something nobody measured — see Data visualisation.
- Never hold the last value. A frozen number is indistinguishable from a stable patient, which is exactly the wrong inference.
- Never a blank. On a device whose normal state is quiet, blankness reads as "all is well".
- Gaps are counted and shown on the trend, because "how much of last night was actually monitored" is a clinical question.
- Alarm state during a gap is stated: no alarms fired and none could have.
Nobody is awake
A device operating overnight must assume its primary user is asleep, that the phone is face down and silenced, and that the person may be unrousable for physiological reasons rather than merely sleeping deeply. Escalation to a second person is not a premium feature; it is the alarm's only remaining path.
The morning summary is not optional. An event the user slept through is an event they otherwise never learn about, and it is the one most worth knowing.
- High-priority alarms override silent mode and do-not-disturb, within what the platform permits — and where the platform does not permit it, the device says so during setup rather than failing silently at 3 a.m.
- Alarms latch. They do not stop because time passed; they stop because somebody responded. Same rule as Acknowledge & escalate.
- Escalation is time-based and goes to a person, not to a louder version of the same unheard sound.
- Overnight events are summarised in the morning, whether or not they resolved. Resolution is not the same as being informed.
- Undelivered alarms are recorded and surfaced. "We could not reach you" is a clinical state, and it is the one users most need to know is possible.
- No alarm on the absence of a problem. An overnight device that alarms loosely gets silenced, and a silenced device is an unmonitored patient.
Degraded modes
A home device loses capability constantly and unremarkably: the phone is offline, the battery is low, the app was backgrounded, the sensor is warming up. Each removes something, and the person needs to know which.
| Condition | What is lost | What the interface says |
|---|---|---|
| Sensor warming up | Readings | Time remaining, and that no alarms can fire until it finishes. |
| Sensor detached or expired | Readings and all alarms | "Not monitoring", the physical fix, and how to check manually meanwhile. |
| Phone offline | Carer alerting; possibly nothing else | Exactly which functions are affected. Local alarms usually still work, and saying so prevents unnecessary alarm. |
| Battery low | Everything, shortly | Warned early enough to act, and repeated. This is a foreseeable loss of the entire device. |
| App backgrounded or killed | Potentially all alarms | Detected and stated on next open, with the period that was unmonitored. |
| Supply exhausted | Therapy | Projected time to exhaustion, well before it happens. |
- Name the capability, not the fault. "Carer alerts are not working" is usable; "network error 502" is not.
- Distinguish partial from total. A person who believes everything has stopped when only carer alerting has will over-react; the reverse will under-react.
- Warn early enough to act, in the units of the person's day — "your sensor expires tomorrow morning", not "96.4% elapsed".
- State how long the device was degraded once it recovers, and cover the gap on the trend.
- Never require the app to be open for a safety function, and where the platform makes that impossible, say so plainly at setup.
States
| State | Rendering |
|---|---|
| Live | Value, direction, age in minutes, sensor life. |
| Stale | Age becomes the headline; the last value is demoted and explicitly disowned. |
| Not monitoring | State, cause, physical fix, and what to do instead. |
| Degraded | Which capabilities are lost, named individually. |
| Alarm undelivered | Recorded at the time, escalated, and surfaced at the next opportunity. |
| Recovered | The gap is stated and remains on the trend. A recovery that erases the gap has erased the evidence. |
Do's and don'ts
The state, the disowned last value, and a physical fix. Nothing here can be mistaken for a current reading.
A forty-minute-old number presented as the current one, with the age in the smallest text on the card. This is the default behaviour of most dashboards.
Carer alerts are not working — your phone is offline. Alarms on this phone still work normally.
Names the lost capability and, just as importantly, the one that survives. The person can calibrate their response.
Connection error · retrying…
The person cannot tell whether they are being monitored. Under uncertainty they will either ignore it or stay awake all night.
You did not respond to a low glucose alarm at 03:22. Your carer was alerted at 03:27.
The event survives the night. Something happened while the person was unconscious of it, and they are told.
Good morning. Your glucose is 6.4 mmol/L.
A three-hour hypoglycaemic episode and a carer phone call, both absent from the summary because everything resolved.
Your sensor expires tomorrow morning. Fit the new one before you go to bed.
A foreseeable loss of the whole device, warned in the units of the person's day, with the action attached.
Sensor life: 4%
A percentage of an interval the person does not know, with no action. They will find out it expired when it stops monitoring them overnight.
Accessibility
- Age is text in the accessible name of the value — "6.2 millimoles per litre, 2 minutes ago". A number announced without its age is the same failure non-visually.
- "Not monitoring" is announced as a state, not conveyed by a greyed number or a faded card.
- Alarms are assertive; degradation notices are polite. Losing carer alerting is important and is not an emergency.
- No reliance on audio alone. This system specifies only the visual half of IEC 60601-1-8 — see Known gaps — and a device whose overnight safety rests on an unspecified sound is under-designed.
- Vibration and visual alerting alongside audio, for users who are deaf or hard of hearing. Overnight escalation to a carer matters most for exactly these users.
- Targets ≥ 44 px on the urgent path, well above the 24 px minimum — see Lay & patient-facing design.
- No timed dismissal (SC 2.2.1). An overnight summary waits until it is read.
- No flashing on alarm (SC 2.3.1), including in a darkened bedroom where a strobing screen is both a seizure risk and unusable.
Outcomes of use
What this contributes to, in the terms of Usability & context of use. These are attributes believed to contribute to an outcome; the outcome itself is settled by observing real use in a specified context, not by this page.
- Effectiveness — the person's belief about whether they are being monitored matches whether they are. Time spent unmonitored without knowing it is the measure, and it is computable from the device's own logs.
- Efficiency — a gap that can be fixed in one action, at the moment it is noticed, rather than discovered the following morning.
- Satisfaction — sleep. The entire value of an overnight monitoring device is that somebody can stop watching, and that depends completely on trusting it to say when it stopped working.
Clinical safety notes
Trace these in your risk file (ISO 14971) and usability engineering file (IEC 62366-1).
- Age displayed with equal prominence to the value. Mitigates: a stale reading acted on as current.
- Last value disowned once stale. Mitigates: a frozen number read as a stable patient.
- Gaps never interpolated or blank. Mitigates: unmeasured periods read as measured and normal.
- "Not monitoring" stated with cause and physical fix. Mitigates: prolonged unmonitored periods the person could have ended in seconds.
- Alarms latch and escalate to a second person. Mitigates: an alarm nobody heard, during impairment or sleep.
- Undelivered alarms recorded and surfaced. Mitigates: a failed notification indistinguishable from an uneventful night.
- Overnight events summarised regardless of resolution. Mitigates: a recurring nocturnal pattern nobody ever learns about.
- Degraded capabilities named individually. Mitigates: over- and under-reaction to partial loss of function.
- Consumable exhaustion warned in the units of the person's day. Mitigates: foreseeable total loss of monitoring overnight.
- Safety functions never require the app to be open. Mitigates: silent loss of alarming when the platform reclaims the process.
Related
- Therapy recommendation — what the device may do with a value, and why it may not act on a stale one.
- Proxy & carer access — the second person escalation reaches, and the delay they are seeing.
- Acknowledge & escalate — latching and escalation, in the setting this pattern adapts them from.
- Lay & patient-facing design — the register and the impaired-user assumption.
- Key–value pair — the kinds of nothing, which this extends by one.
- SteadyLine — the reference application.