The signal that took a month to become visible
A wellhead on an ageing platform is corroding at a joint below the choke. The rate is roughly 0.3 millimetres a year — slow, survivable, well inside the inspection interval, provided nothing changes. Something changes: a slug of produced water with a different chemistry moves through, and the local corrosion rate jumps by a factor of eight for six hours before settling back. The telemetry recorded it. Pressure and vibration sensors sampled every few seconds; the excursion is sitting in the raw stream. But the system responsible for turning telemetry into an integrity judgement runs on a monthly aggregation cycle, because that is the cadence the reporting schedule was built around and the cadence the integrity engineer's dashboard was built to display. The six-hour event is averaged into a month of otherwise calm readings and vanishes. The engineer signs off the monthly report. The joint fails four months later.
This is not a sensor failure. The sensor worked. It is a failure of the relationship between what arrived and what was held — an architecture that has consolidation but no live channel feeding it fast enough to matter, paired with no mechanism for the consolidated report to be revised the moment a faster signal contradicts it. That is precisely the gap the working-memory and long-term-memory distinction in cognition names, and it maps onto the three generations without strain.
What arrives
Four streams, running on four different clocks. Wellhead telemetry — pressure, temperature, flow rate, vibration — arriving at sub-second to minute resolution from hundreds of points across a field. Seismic surveys, run over a reservoir every one to three years, revealing subsurface structure and, on reprocessing, subsidence or fault reactivation that bears on well integrity from below rather than within the pipe. Pipeline pressure and flow data, continuous, cheap to sample, expensive to make sense of, because a pressure drop can mean a closed valve, a leak, or nothing. And regulatory notices — inspection deadlines, incident bulletins from other operators' failures, amended threshold limits — arriving irregularly, in text, from outside the operational system entirely.
No single one of these is the picture. The picture is what an integrity engineer builds by holding several of them against each other at once.
What is held live
At any moment the engineer's working attention can hold perhaps four or five things: which wells are currently trending toward an alarm threshold, which pipeline segment has an open pressure anomaly, what the last seismic reprocessing said about a specific fault, whether a regulatory deadline falls this quarter. This is the maintained buffer — small, continuously refreshed from the fastest stream, and useless the moment the shift ends unless it is written down. It behaves exactly as the cognitive literature predicts: interference-prone, capacity-limited, gone within minutes if not rehearsed. An engineer called away mid-shift to a different platform loses the picture and has to rebuild it from whatever the system retained, not from what they were holding in their head.
What a live buffer alone cannot do — and this is where a system limited to scene-maintenance fails even when it is technically real-time — is remember that the pressure anomaly on segment 14 looked identical to one three years ago that preceded a rupture. That comparison requires retrieval from something durable, not just attention to something current.
What triggers revision
The monthly aggregate is a long-term-memory operation: telemetry is compressed into a corrosion-rate estimate and written to the asset integrity register, with a provenance stamp — which sensor, which calibration date, which model produced the estimate. That register is the durable store. The failure in the platform case was not that the register existed; it was that nothing in the loop compared the register's belief against the live stream fast enough to catch the six-hour excursion before it was averaged away.
A working intake loop needs a trigger for revision that sits between the two timescales: a rule that says a live signal deviating from the retained belief by more than a stated margin forces an immediate write, not a wait for the next monthly cycle. That write is reconsolidation. It does not throw away the old belief; it timestamps it, records what contradicted it, and produces a new belief with its own provenance. The corrosion-rate estimate for that joint becomes something with a history — 0.3 mm/yr, revised upward following an excursion on the fourteenth, revised back down after two weeks of stable readings confirmed the joint was not still degrading. A regulatory notice tightening the threshold for that class of joint does the same thing from a completely different stream: it does not add a data point, it changes the rule by which existing data points are judged, and every held belief measured against that rule needs re-evaluation, not silent carry-forward.
What the integrity engineer sees
Under the monthly-aggregate system, the engineer sees one of two things: a firehose of raw telemetry too dense to interpret unaided, or a static report that is already weeks stale by the time it is read. Neither is the picture. Under an intake architecture built on the maintenance-retention pair, what the engineer should see is a belief, not a reading: corrosion rate at joint 14, currently estimated at 0.4 mm/yr, last revised 11 minutes ago from telemetry, confidence downgraded because the seismic reprocessing covering that structure is 40 days overdue and subsidence in the area was flagged as a slow variable worth rechecking. That single line carries a value, a timestamp, a source, and a decay note. It tells the engineer not just what is believed but how much to trust it right now, which is the information a monthly PDF cannot carry no matter how often it is regenerated.
| monthly-aggregate system | continuous-belief system | |
|---|---|---|
| Fast excursion | averaged out, invisible | triggers immediate revision |
| Stale input (overdue survey) | not flagged | decays visibly, confidence marked down |
| Cross-stream contradiction | resolved by whoever notices, if anyone | forces reconsolidation with recorded cause |
| What the engineer reads | a snapshot report | a belief with provenance and an age |
What it costs, and where the objections land
None of this is free, and the two hardest objections to the idea both bite here.
A system permitted continuous total intake inherits catastrophic interference. You cannot retain everything a wellhead has ever reported and expect retrieval to stay fast or trustworthy — the interference literature is unambiguous about that.
This is largely correct and should not be argued away. An integrity register that retains every raw sample from every sensor since installation, without a decay or summarisation policy, will drown its own retrieval — exactly the failure mode Shereshevsky's unbounded memory illustrates in a different register. The distinction that survives is between permission and obligation. The intake axis says the system may observe every running stream; it does not say it must retain every sample forever. Good design forgets aggressively — most raw telemetry is discarded within days, kept only as a compressed trend — and provenance is precisely what makes that forgetting safe rather than arbitrary. A dropped raw reading can be reconstructed in kind, at need, because the belief derived from it still carries the record of where it came from and when it was last checked against reality. The corrosion-rate belief does not need the four million pressure samples that built it; it needs to know which of them, if any, were anomalous, and that only requires keeping the anomalies.
The second objection concerns whether working memory is a separate thing at all worth building a generation around.
If maintenance is just the activated portion of long-term memory, as Cowan's account suggests, then treating the live buffer and the asset register as architecturally distinct operations reifies a difference psychology no longer insists on.
Probably true of the underlying substrate, and the engineering should not pretend otherwise. But the operational contrast holds regardless of how the activation account settles the neuroscience. A pressure sensor's raw feed is not "an activated part of" the asset register; it is a completely different channel, arriving before any register entry exists to activate. What matters for the platform is not whether maintenance and retention share a substrate but that the live stream and the durable belief behave differently under load — one decays in minutes if unrefreshed, the other persists until deliberately revised — and that an integrity system ignoring that difference is exactly the one that averages a six-hour excursion into invisibility. The functional gap the platform failure exposes is real whether or not the two systems turn out, at the neural or architectural level, to be one continuum wearing two names.
What is left, once both concessions are made, is not a bigger dashboard. It is a discipline: hold the fast signal live, write the slow judgement down with its sources attached, and force the two to argue with each other on a schedule shorter than the thing they are meant to be watching for.