One platform. Four deliverables. A failure boundary between them.
Guardian runs a site and keeps it alive on its own. Command Centre governs an estate. Control Room and Mobile are how people see and act. The boundary between the tiers isn't organisational, it's a failure boundary, drawn so that nothing above a site can stop an alarm inside it.
What you actually get
WillowCreek Guardian
The platform running at a single operating site, and the only hard isolation boundary in the system. Guardian owns ingest, positioning consumption, supervision, rules, incidents, escalation and notification for its site. Everything a duress needs is held locally.
Guardian is built to stand on its own: its uplink to the provider plane is outbound-only and optional. Cut it, and the site still raises, routes, escalates and records.
How Guardian is engineered →Everything a duress needs lives inside the site boundary.
WillowCreek Control Room
The staffed live-operations workspace inside Guardian, role-scoped by login: a ranked live alarm queue, incident detail drawer and live zone map in three-way sync, pushed over server-sent events and never polled. History and replay sit alongside, so the last hour is as recoverable as the last second.
Dark theme by default. Control rooms and clinical night shifts run in low light, and a bright interface there is a physical hazard, not a style choice.
Inside the operator surfaces →Queue, drawer and map select together. Push, not polling.
WillowCreek Command Centre
The console your organisation logs into to run its own estate of sites, self-service, up to licensed capacity. Sites, policy, standards, users and roll-up reporting in one place. You create and configure your own sites. Nobody builds them for you, and nobody needs to.
Estate administration is kept separate from site operations: governance lives here, but a duress never depends on it.
Estate administration →- Sites and standards. Stand up a site, apply estate policy, see it reported back.
- Users and roles. Role-based access extended by context: on-shift, own-ward permits; out-of-hours denies.
- Licences that follow you. Tags are licensed at the organisation, not the site. Move them freely, no provider involvement.
- Roll-up reporting. Estate-wide visibility without estate-wide coupling.
WillowCreek Mobile
The native iOS and Android staff app. Raise duress on the move, respond to incidents, and carry your own position with you, so responders are part of the operational picture rather than outside it. Enrolment is by code against your own site, and the app works with dedicated handsets, including hardware duress buttons.
The handset story →- Raise and respond. A duress from the handset is priority one at origination, like every other duress.
- Staged escalation. Prime on entering a risky situation, then trigger with one action. There's no time limit between the two.
- The responder is on the map. Dispatch decisions see responder positions, not just the event.
And behind the scenes: WillowCreek Pulse. Our provider console watches fleet health, licensing and tenancy across every deployment, and controls nothing operational. Pulse is never in the alarm path: its link to your sites is outbound-only from your side, and losing it cannot stop an alarm. You don't buy Pulse. You benefit from the fact that we can see a failing component before you have to call about it.
Loss of the management plane cannot stop an alarm
The platform separates the data plane (events, alarms and escalation, at the site), the control plane (configuration and policy) and the management plane (licensing and fleet health, above the site). Escalation and notification live in the data plane at the site. Licensing and fleet health live in the management plane above it. That is why the layers above a site can fail, disconnect or be decommissioned without an alarm losing its path to a human.
Data plane
Duress ingest, classification, escalation, notification and audit. It all runs at the site, on the site's own database, behind the site boundary.
Control plane
Configuration, policy and standards, drafted, confirmed and applied on a tamper-evident trail. It can never gate a life-safety route.
Management plane
Licensing, entitlement and fleet health sit above the sites, forgiving by design, and structurally incapable of stopping an alarm.
Nine principles the architecture is built on
These are design properties, not promises. Each one is visible in how the platform behaves.
Life-safety first
Life-safety is never gated by any commercial, licensing, subscription, privacy or administrative state. A licence check on a life-safety route is a startup failure, not a runtime warning.
One platform, one code image
Every deployment runs the same image. There is no "lite" build whose gaps you discover during an incident.
Adapter-first, vendor-agnostic
Every external system attaches through a replaceable adapter. Consolidation must not recreate lock-in.
The site is the isolation boundary
Isolation is enforced by database row-level policy on every request, not by application convention.
Thin edges, thick core
Edge components stay simple and replaceable; the intelligence concentrates where it can be supervised and audited.
Survive the link, not just the node
Site equipment connects locally, so a WAN problem never sits between an alarm and the people responding.
Honest state over plausible state
A source that cannot be read returns unavailable, never a plausible zero. Dashboards state their own limits.
Tested resilience, not assumed resilience
Failover is proven by drill. Backups are scheduled and encrypted, and the restore path has been exercised end to end rather than assumed. A life-safety assurance suite gates every release.
Graceful degradation, fixed shedding order
Under pressure the platform sheds analytics before operations. Duress ingest and fan-out are never shed.
See the four deliverables working as one
An hour with your floor plan is worth more than a hundred pages. We'll show you the boundary doing its job.