Somewhere in your logistics operation, there's an alert queue that nobody trusts anymore.
It didn't start that way. When the monitoring system went in, every alert got investigated. A humidity spike triggered a call to the carrier. A shock reading got escalated, discussed, logged. The team took the data seriously because that was the whole point of buying the system.
Then the pattern set in. The humidity spike turned out to be a warm dock transfer. The shock event was a rough stretch of road. The tilt warning was the container being set down normally. Investigation after investigation closed with the same finding: nothing actually happened.
Ask anyone who has run receiving operations for a few years and they'll tell you what comes next. The instinct shifts from "investigate" to "probably nothing." Alerts get acknowledged without being read. And the monitoring system, which was supposed to be an early warning capability, becomes a compliance artifact that generates records nobody looks at.
It's tempting to call this a discipline problem. It isn't. The team is responding rationally to a system that cried wolf too many times. The failure is in the model itself.
The model was built for a different job
Threshold alerting is simple by design: pick a limit, fire an alert when a sensor crosses it. Shock above 10G, notify. Temperature outside range, notify.
For commodity freight, this works fine. If you're shipping pallets of packaged goods, "something big happened to this pallet" is genuinely useful information, and "nothing crossed a threshold" is a reasonable proxy for "the shipment is fine." The stakes are modest, the payloads are tolerant, and a coarse signal is enough to act on.
The problem starts when the same model gets applied to a completely different class of freight. An EUV system. A lithography module aligned to nanometer tolerances. A satellite instrument. For payloads like these, the relationship between sensor readings and actual risk is nothing like it is for a pallet of consumer goods, and the threshold model breaks in two directions at once.
Failure direction one: the noise
Precision payloads travel in engineered packaging, on air-ride trailers, with careful handling requirements. The transit environment still produces plenty of sensor activity. Roads vibrate. Docks get warm. Containers get set down, tilted onto ramps, moved through humid ports.
Set your thresholds tight enough to protect a sensitive assembly and most of this ordinary activity crosses them. Every crossing generates an alert, every alert demands attention, and almost every investigation finds normal transit conditions. This is the wolf-crying phase, and it does real damage: it trains skilled people to discount the one channel that's supposed to protect the asset.
Failure direction two: the miss
Here's the part that costs money. Loosen the thresholds to quiet the noise and you create the opposite problem, because the events that actually damage precision equipment often don't look dramatic on any single sensor.
Consider a real risk profile: a 5G shock during a transfer, followed by 72 hours of sustained low-level vibration, elevated humidity, and a door-open event at an intermediate handling facility. No single reading in that sequence crosses a sensible threshold. A 5G shock on its own is unremarkable. Vibration within limits. Humidity elevated but not extreme. A door event with no context.
Individually, each one is noise. Together, they describe a shipment that took a hit, spent three days being shaken while exposed to moisture, and was accessed by someone mid-route. For a precision assembly, that combination is a genuine damage risk, and the threshold model is structurally incapable of seeing it. The system stayed quiet not because the shipment was fine, but because no one told it how to add.
So the operation ends up with both failures at once: a team trained to ignore the alerts that fire, and real risks that never fire an alert at all. The damage gets discovered weeks later at uncrating, with no documentation of when it happened or who had custody. Unboxing economics covers what that moment costs; the short version is that the cascade of cleanroom investigation, field-engineer assessment, and slipped installation schedule routinely dwarfs the equipment value itself.
What the alternative looks like
The fix isn't a smarter threshold. It's a model that evaluates what happened across every sensor stream simultaneously and reports what the pattern means, not which line got crossed.
That requires a few things the threshold model never needed.
It requires more than one point of measurement. A single tracker on the outside of a container can tell you the container took a 20G hit. It cannot tell you whether the impact reached the asset inside, separated from the container wall by crating, isolation mounts, and air gaps. Measuring at both the container and the asset, and reading the delta between them, is the difference between "an event occurred" and "the packaging absorbed it" — or didn't. The delta is the whole game.
It requires treating absence as a signal. In a mesh of communicating devices, a node going dark is itself a data point. Correlate that silence with a door-open event, an interior temperature shift, and a stop at a non-designated location, and you're no longer looking at a connectivity glitch. You're looking at a possible asset extraction, classified as such with the evidence attached. Silence is a signal.
And it requires history. Judging whether a reading is anomalous means knowing what normal looks like for that class of asset, on that lane, across many shipments. That baseline can't come from an industry average, and it can't come from disposable trackers that start from zero every trip. It accumulates in reusable hardware over repeated deployments. A reusable model is what makes anomaly detection possible.
Put those together and the output changes character entirely. Instead of a stream of threshold crossings for someone to triage, the system delivers a judgment: this shipment is nominal, or this shipment experienced a specific sequence of events that warrants escalation, with the timestamps, locations, and custody records to support it. By the time the crate arrives, the receiving team already knows which of those two situations they're walking into. The pre-arrival report is the output that makes that possible.
A number versus an answer
The threshold model asks operations teams to do the interpretation themselves, alert by alert, until fatigue wins. That was an acceptable trade for freight where the worst case was a damaged pallet.
For freight where the worst case is a nine-figure tool, a slipped fab schedule, and a liability dispute with no evidence, it isn't. The monitoring layer has to do the interpretive work: fuse the streams, weigh the pattern, and say what it means.
Single-point trackers give you a number. The number was never the hard part. What the operation needs is the answer.
If you're shipping precision freight on a threshold model and wondering which alerts you should actually be worried about, we should talk.