Y1.08.3Verifiability across shared and workstation displaysdesignresearch

A critical figure on the wall is only trustworthy if a workstation can trace it to its source

Aliases: Verifiability across shared and workstation displays · cross-display verification

What it is

Cross-display verifiability means that a critical state, event, or conclusion shown on the wall can be traced by the responsible operator, at their own workstation, back to its source data, timestamp, and constituent detail. A wall display is a good place to raise a prompt or start coordination; it is a bad place for a conclusion to end, unverified. If a judgment can only be supported by "that's what the wall showed," it carries no real accountability.

Why it happens

A wall display is constrained by viewing distance and information density, so it typically relies on aggregation and simplified coding: several sensor readings collapse into one status light, a stretch of trend data collapses into one arrow. Aggregation itself is not the problem. The problem is what happens after aggregation — whether the raw data behind it can still be found. Without a shared object identifier and a drill-down path between the workstation and the wall, an operator facing a wall-level conclusion has only two options: believe it, or don't. There is no third option.

The condition flip here is that aggregation and unverifiability are not the same thing; the problem only appears once aggregation severs the path back to the raw data. The same aggregation logic, paired with a consistent object identifier and a deep link from wall to workstation, lets an operator drill down to the underlying data within seconds — aggregation then becomes an efficiency gain rather than a liability. Without that path, even flawless aggregation logic leaves an operator unable to distinguish a genuine summary from a false one produced by a missing sensor reading or a communications dropout — two situations that can look identical on the wall, the difference buried in a layer the operator cannot reach.

Studying it

Deliberately seed drills with faulty aggregation or stale data — for example, freezing one sensor's feed while the wall keeps displaying its last value — and measure the time from noticing a wall-level prompt to tracing supporting evidence at the workstation, plus the proportion of operators who accept the wall's conclusion without checking it. Also verify that object identity and time semantics agree between the wall and the workstation; if they don't, the drill-down chain breaks partway even when the interface appears to offer an entry point.

Where it stops holding

A genuine emergency broadcast is allowed to precede full evidence — when a safety system trips an interlock, the wall should show "tripped" immediately rather than waiting until an operator can drill into every detail. But the evidence chain behind that broadcast must catch up quickly; it cannot remain permanently at "the wall said it tripped."

A presentational board aimed at management or visitors, never used by operators as a basis for action, need not carry workstation drill-down — the verifiability requirement only binds the portion of content that actually feeds decisions. But if a board built purely for display gets casually adopted as a decision input, it silently crosses into that requirement, and that shift is easy to miss unless someone actively checks for it rather than assuming a display-only purpose will hold indefinitely.

Even with an identifier and a deep link in place, if the workstation query hits a delayed replica of the historian while the wall runs off the live feed, the two can show real, if brief, discrepancies during fast-moving conditions. That is not a missing drill-down path — it is the two ends of the path drawing from different data sources, and verification needs to rule that out before treating a mismatch as an aggregation error.

Applying it

Give every critical wall-display metric a stable object identifier, a data timestamp, and a deep link into the workstation, where the raw readings behind it and each reading's quality state — normal, missing, communications lost — can be seen.

For conclusions used in incident investigation or audit, retain the raw snapshot from the moment of aggregation as well, not just the aggregated result, or the basis for later reconstruction is lost.

How to check: randomly sample several key conclusions that appeared on the wall during a shift and ask the duty operator to reconstruct, at the workstation on the spot, their source, timestamp, and constituent data. Failure to reconstruct them, or a reconstruction that disagrees with what the wall showed at the time, both count as a fail.

Related

  • Same group: Y1.08.1 Public and personal display roles · Y1.08.2 Cross-display synchronization lag · Y1.08.4 Shared visual reference in control rooms
  • Nearby: Y3.11 Hierarchical displays and navigation · Y3.07 Trend displays and history
  • Search terms: data provenance · drill-down visualization · trust in automation · information verifiability

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/Y1.08.3