An installation is a city, an airfield, a fuel farm, a network and a high-value target at the same time. Physical, cyber, airspace, contractor and host-nation risk all act on the same perimeter, and each one is watched by a different staff section on a different console.
One evening at a garrison. Every system does exactly what it was bought to do, and every operator follows the procedure correctly.
The SOC opens a ticket and queues it as routine.
Ticket openedThe gate guard enters it in the blotter.
Blotter entryThe counter-UAS console logs the track and clears it.
Track loggedThree sections, three queues, three correct procedures. The badge server, the blotter and the counter-UAS log do not talk to each other, and nothing in the building is responsible for the line that runs through all three. By the morning update the three items are read out separately, if they are read out at all. The pattern was never the problem. Ownership of the pattern was.
The same six domains resolve onto every estate. This is what they are when the estate is an installation.
Installation and mission networks, plus the control systems behind power, water, fuel and environmental plant. A controls alarm and a network alert are the same story more often than either console can tell.
Entry control points, patrol and blotter reporting, alarm and camera systems, and the access control record that says who was where and when.
Detection is now common. The unanswered question is what a track means alongside ground activity and network events in the same window, and who has to act on it.
Who is scheduled on post, what is arriving, and which vendor sits upstream of a system that matters. Access and supply are the same exposure viewed from two directions.
A storm that closes a resupply route and a generator that fails are one event acting on readiness, not two unrelated tickets, and counting them twice is its own failure.
Intelligence reporting, host-nation posture and local unrest change what a perimeter indicator means, particularly at a fixed post outside the wire of a larger force.
The same event matters differently at the gate, in the TOC and at the commander's desk. One object, delivered at each altitude, with the clock that altitude actually runs on.
What changed on the perimeter in the last hour, and what to look for on this shift.
The ranked picture across domains, the converging set behind each item, and the option set with an owner attached.
What is being worked, what posture is recommended and why, and what the recommendation rests on if it is questioned later.
Comparable exposure across installations, ranked by policy that was ratified rather than inferred by a vendor.
Nothing here assumes a complete estate or a rip and replace. Sources are added as adapters against a common contract, and the score states the coverage it was computed on.
Onboarding is four things, in order.
Build the asset model for the post, so a signal has something to attach to. Connect what exists and state what does not. Ratify the policy: the weights, thresholds and windows that decide what outranks what, signed by a named person rather than shipped as a default. Then run it against real traffic and compare the queue to the judgment of the people who already do this work.
Where a feed does not exist, coverage is disclosed on the object instead of the gap being quietly absorbed into a number.
We walk one real convergence case from your post, and we name what is built, what is specified, and what is neither.