Every suppressed alarm should be visible as its own operating state, with a reason and an expiry
Aliases: visible and reviewable alarm suppression · shelving register
What it is
Visible suppression means every rule currently kept out of the live alarm channel — the object it applies to, the reason it was suppressed, and its expected expiry — is shown to operators as a first-class operating state, not buried in a configuration menu. This leaf is about the overall visibility and review mechanism: how the team knows what has been removed and whether it should come back. That is a different layer from the other two leaves in this group, which cover when suppression should happen automatically and how manual shelving should carry an expiry and rationale — without this layer, neither of those matters, because no one will ever look.
Why it happens
Once an alarm is suppressed, it changes the effective monitoring coverage of the whole system, and that change must enter shared team awareness the same way any other situational fact does, especially at shift handover — otherwise the incoming crew is operating a system with reduced coverage without knowing it. Review is a separate matter: periodically checking whether the operating mode, rationale, and compensating protection that justified the original suppression still hold. If suppression information lives only on a secondary settings page, anyone without configuration access, who never visits that page, has no way to judge how much risk the system is currently carrying.
Where it stops holding
Simply laying the full suppression list out on the main display creates a different problem — once the list grows, keeping it persistently prominent competes with genuine active alarms for attention and becomes a new source of noise. The workable approach is layered: totals and the highest-risk items stay in the overview, with detail available on demand; suppression entries tied to safety interlocks or access-sensitive information can be scoped by role, but that layering must never reach the point where the person who actually owns the residual risk cannot see it.
Applying it
Design "no suppressions currently active" and "suppression list failed to load" as two distinct, clearly labeled states — never let the second one degrade on screen into something that looks like the first, which would make the system appear cleaner than it is. Keep the overview permanently showing the total suppressed, the single highest-risk item, the next item due to expire, and any unusual pattern of repeated renewal. Detail views should record who approved it, when, on what rationale, and what compensating measures apply. Check the critical suppressions at every shift handover, and separately audit for overdue expiries, repeated renewals, and unresolved root causes as three distinct failure patterns.