Watch the readings against the limits your plan already sets, raise an excursion with the sensor's own health attached, and hold the lot for the qualified person who dispositions it.
4Controls appliedReading checks against the plan's own limits, sensor-health checks, hold-by-default and confidence threshold
No human action required
Stages 1 to 4 run unaided, and nothing is released at any of them — the lot is held, and the qualified person's lane opens at the confidence gate.
5DecisionBranches at the confidence threshold
High confidence
Goes to the qualified person to disposition.
Low confidence
Adds a sensor-integrity read first.
Qualified-person disposition
The lot is held with its readings, the sensor's health and the confidence.
Disposition · Hold · Send to quality review
Dispositioned — the lot may move▼
6Quality and warehouse systems updatedOnly where write access and approval policy allow it
7Outcome evaluatedDisposition outcomes, false excursions, sensor faults found and findings raised after delivery
Dispositions
Every disposition a person made is counted in the evaluation.
What should not run autonomously
Human approval stays in control
Outside the boundary — human approval required8 items
Releasing a lot that is being held for review.
Declaring that a food is or is not adulterated.
Closing an excursion without a qualified person.
Deciding whether the affected product may be sold.
Automation boundaryAgent acts unaided
✓Watch the readings against the limits the plan already sets for the named owner.
✓Raise an excursion and default the affected lot to hold.
✓Assemble the readings, the gaps and the sensor's own health.
✓Carry the whole file to the named person who decides it.
Any write happens inside the boundaries agreed at implementation, and never to a controller.
Writing a setpoint to a refrigeration controller.
Specifying the operating temperature for a load.
Assessing at the dock whether abuse was significant.
Changes to limits, hold rules or release authority.
Example output
One excursion, annotated
Everything the agent raises is attached to the readings it was drawn from.
Excursion output · single lotIllustrative example
Lot
What was observed
Time above limit
Limit on the plan
Confidence
Sensor health
Chilled lane, one pallet
Trailer air ran above the plan's limit during a multi-stop drop
42 minutes
Set by the customer's plan
89%
Probe last calibrated, in range
As receivedTaken from the trailer telemetry and the customer's own limits — nothing on this side is written by the agent.
Source records usedTrailer telemetryProbe calibrationShipper's written spec
Why it stops hereThe reading is a fact; whether the food is adulterated is a conclusion the law.
ActionDispositionHoldSend to quality review
What the score decidesBelow the configured threshold the lot picks up a sensor-integrity read first.
Value
Where AI adds value
The same four claims, placed at the point in the workflow where each one applies.
Where the value landsValue 01 – 04
Every readingFrom the lane's own sensors
03Monitoring
Watch against the plan
Draw on the readings, the customer's own limits and the probe's calibration history — monitoring indicates a condition, and the refrigeration is what maintains it.
01Approved path
An excursion is not a verdict
Routine lanes run watched, logged and evidenced without anyone reading a chart.
02Human review
Send the qualified person to the holds
If a lot moved and a problem surfaced after delivery, the trail shows the readings, the sensor's health, and who released it on what basis.
04Build an evidence trail
The excursion, the readings behind it and the qualified person who dispositioned it stay with the lot.
Integrations
Typical integrations
Five system groups connect to the same agent. Which of them are in scope is decided in discovery.
Sensor and logger platformsSensitech · Emerson Controlant · Tive
Transport and telematicsSamsara · Motive Reefer telematics · logger exports
Warehouse and inventoryManhattan · Blue Yonder WMS · lot and hold status
Agent
Cold-chain monitoring
Reads the sensors Raises the excursion Holds for disposition
Documents and recordsSensor feeds · logger exports Lot records · disposition logs
Integration availability depends on the client's existing systems and API access.
Agent controls
Six layers between the model and the lot
Every control encloses the next. What survives the set is named in the map below.
L6 · Outermost — last line of defenceInward → L1 · closest to the model
L6Rollback / safe modeFall back to raw temperature reporting when evaluation or production signals degrade.Roll back
L5Version monitoringTrack model, prompt, limit-set and lane-config changes.Track
L4Lot trailRecord the readings, the excursion, the sensor's health and the disposition.Record
L3Qualified releaseHold the lot for a named qualified person; the hold governs movement, not whether the food is sound.Gate
L2Hold-by-defaultTest every disposition path against the held-act list; the default is hold, and release is an attributed act by a person with a stated basis.Restrict
L1Confidence thresholdsRoute low-confidence excursions to a sensor-integrity read first.Require review
Model coreExcursion raised — readings, duration, lots affected and confidence
L1 – L2Test whether a lot may move
L3Puts the disposition in a qualified person's hands
L4 – L5Hold the readings the excursion rests on
L6Falls back to raw temperature reporting when signals degrade
How Nestack evaluates it
Evaluate the monitoring workflow — not only the excursion that alarmed.
Coverage runs the whole depth of the workflow, and every layer is cut by slice.
Surface — the excursion quality reads
Depth of coverage ▼
E1Final-output evaluationDid every raised excursion match the readings behind it?
E2Step-level evaluationDid the agent use the right limits, lot and sensor history?
E3Tool evaluationDid it read and write the correct lot and the correct lane?
E4Confidence calibrationDo low-confidence excursions actually attract more sensor faults?
E5Slice evaluationHow does performance change across specific lane types?
E6Business outcomeHow many lots needed a re-disposition, or a finding after delivery?
Floor — the lot the firm answers for
Failure modes
Where each failure originates in the agent
Seven ways an excursion goes wrong, placed by stage.
Agent lifecycleDirection of processing →
01 · Retrieval1 mode
BR-03
Degraded sensor trusted
A drifting probe is read as though it were in calibration.
Stage gathersReadings, limits, lot and lane, and probe calibration
02 · Reasoning2 modes
BR-04
Excursion read as verdict
A reading outside a limit is written up as adulterated product.
BR-06
Duty put on one party
One party is named responsible where the rule splits the duty.
Stage proposesExcursion, readings, lots affected and confidence
03 · Tool / write2 modes
BR-02
Held lot moved
A held lot moves on before a person dispositioned it.
BR-05
Duplicate excursion
One temperature event is raised twice against the same lot.
Stage writesOnly where write access and approval policy allow it
04 · Output1 mode
BR-01
Excursion never raised
A gap in the readings passes as a lane with no event.
Stage returnsThe excursion a qualified person dispositions
05 · Change / Version1 mode
BR-07
Silent threshold drift
A model or limit change widens what the agent will pass.
Stage tracksModel, prompt, limit sets and lane configuration
Sev-1 · a held lot movedSev-2 · an excursion was never raisedSev-3 · sensor degrades, lot routes to review
The under-counted slice is the probe that drifts rather than fails: it never alarms, so its lots never reach the excursion total at all. Nestack reports the re-disposition rate by slice, not only in total.
Slice performance — reported separately, not only in aggregateIllustrative example
Slice
Failure rate
Lift
Lift vs. threshold
Status
Sensors drifting, not failing
9.7%
3.4×
Review
Multi-stop delivery lanes
6.6%
2.3×
Review
Loading and dock transfers
4.6%
1.6×
Watch
Single-leg refrigerated lanes
2.0%
0.7×
Normal
Bar: re-disposition-rate lift vs. single-leg-lane baseline · scale 0–4.0× · tick marks the 2.0× review threshold2 of 4 slices over threshold
Evidence-linked improvement
Every cycle ends in a standing case
The loop closes on a case the next release must pass, not on an explanation. That suite is what the next excursion raised on a lot is measured against.
Improvement cycle · five stagesSwitchback — the path turns at Improve and returns at Learn
01Detect
Re-disposition rate rises in a lane slice.
02Diagnose
Which lane, which asset, which probe? The readings and the excursions raised off them are read until the cause narrows to one.
03Improve
The fix is versioned with the excursions that motivated it.
04Verify
Nothing ships while an affected case is failing.
05Learn
The case is added for good, and the disposition rules change.
Learn → DetectThe return edge. The next excursion meets a suite one case longer.
Typical build scope
Twelve workstreams across six weeks
The build scope read against the delivery timeline. Week structure follows the six-week plan — discovery, sources, monitoring workflow, evaluation, integration, then production validation and handover.
WorkstreamWeek 1Week 2Week 3Week 4Week 5Week 6
01Cold-chain workflow discovery and boundary definition with quality.
02Sensor, telematics and WMS assessment.
03Limit sets, lane mapping and release-authority mapping.
04Reading ingestion and normalisation.
05Excursion logic and lot binding.
06Confidence scoring and hold routing.
07Qualified-person disposition workflow.
08Sensor-platform and WMS integration.
09Hold-default and sensor cases.
10Guardrails and disposition controls.
11Lot-trail instrumentation.
12Deployment, documentation and Agent Care handover.
12 workstreams · 6 weeks · bar shows the weeks a workstream is active — several run in parallelFinal scope and sequence confirmed in discovery
Engagement tiers
What each tier includes
Rows are the capabilities named in each tier's scope. Higher tiers include everything below them.
Capability✓ in scope · — not at this tierPilotOne lane, one siteProductionProduction sensor platformsAdvancedMultiple sites / carriers
Introduced at Pilot
Monitoring to your limits and lots✓✓✓
Qualified-person disposition✓✓✓
Detection-quality baseline✓✓✓
Introduced at Production
Reporting by lane and asset—✓✓
Disposition workflow in your systems—✓✓
Approved write-back—✓✓
Sensor-platform integration—✓✓
Introduced at Advanced
Multi-party transport rules——✓
Multi-stage quality approvals——✓
High lane count——✓
Multi-site cold-chain controls——✓
Build priceFrom $5,000From $8,000Custom quote
Final build priceConfirmed after discovery based on integrations, workflow complexity, lane count, approval controls and deployment requirements.
Separate from buildBuild pricing is separate from recurring Agent Care, which covers managed monitoring, evaluations, incidents and verified improvements after launch.
What we need from you
What you bring, and what we build with it
Each input maps to a piece of build scope and a week in the delivery timeline.
You bringWe build with it
01Your lanes and the sensors already on them→Reading ingestion and lane mappingWeek 1
02Representative excursions you have held→Detection baseline, limit extraction and lot bindingWeek 2
03Your limit sets and who may release a lot→Limit sets, lane mapping and release-authority mappingWeek 1
04Access to relevant APIs, feeds or exports→Sensor, telematics and WMS assessment, then integration setupWeek 2
05Lots you would not want released→Hold cases and the evaluation suiteWeek 4
06What must reach a qualified person before a lot moves→Confidence scoring, hold routing, guardrails and disposition controlsWeek 3
07Named qualified people to disposition lots→Disposition workflow, then pilot and production validationWeeks 5–6
Nothing else is requiredDeployment, documentation and Agent Care handover are ours.
Delivery timeline
Four phases across six weeks
Each phase occupies the weeks it needs, so the fifth week carries two kinds of work.
PhaseW1W2W3W4W5W6
DiscoveryW1
BuildW2 – W3
EvaluateW4 – W5
Pilot & LaunchW5 – W6
Week focusW1Cold-chain discovery, limit mapping and the automation boundaryW2Sensor integration and the detection baselineW3Monitoring workflow, confidence logic and hold controlsW4Hold cases, held-act guardrails and failure-mode testingW5Sensor and WMS integration, pilot lanes and targeted correctionsW6One shipping season monitored under quality, then handover
Reading the bandThe bars follow real work rather than a plan, which is why week 5 carries two kinds rather than padding.
At the end of W6The season closes validation and Agent Care assumes monitoring.
DurationSix-week plan shown · typical delivery 4–6 weeks depending on scope confirmed in discovery.
Next step · Food & Beverage AI agent
Build a cold-chain agent that holds the lot and hands you the file.
Show us a lane, its sensors and your limit sets. Who releases a held lot at two in the morning, and on what basis — the shipper who set the operating temperature, the carrier who must demonstrate it, or the receiver at the dock? We build the boundary around that answer.