The drill every operator dreads and every regulator requires: the system is black. Watch a joint restoration exercise (ISO, generator, and two transmission operators in one simulated room) as a hydro unit self-starts, the cranking path energizes bus by bus, a drill-master trips a unit mid-restoration, and the island re-sequences, recovers, and synchronizes back to the interconnection against the clock. The kind of drill that takes a year to schedule, run on demand, with every action scored. Nobody else can show this one.
| Without | With GridCORTEX | Δ |
|---|
| Without | With GridCORTEX | Δ |
|---|
A blackstart is restarting the grid from a total blackout. Federal reliability rules require utilities to practice it, but a joint drill needs several companies in one room, so it usually happens once a year. This demo is that drill, run entirely on synthetic data, meaning realistic but invented numbers. Three parties share one simulated eight-substation grid: the regional organization that operates the grid, the fictional power producer PELICAN GENERATION, and two companies that own the high-voltage lines. At the start, every light is off. The goal is to reconnect to the neighboring grid at the LAKELINE tie point in under 100 minutes. Three power plants matter. PELICAN HYDRO is a 45 megawatt hydroelectric unit that can start itself with no outside power; one megawatt is roughly enough power for several hundred homes. BAYSIDE CC is a 180 megawatt gas plant that needs outside power before it can start. EASTPORT CT-3 is an 85 megawatt backup gas turbine.
Two minutes in, the first decision arrives. The software has already tested the restart route inside a digital twin, a working computer model of the grid used to try decisions safely before making them. The route is called a cranking path: the exact order in which lines and substations get power again. The model flags one trap in advance: powering one long line before any customer demand is attached would push its voltage 14 percent above normal and trip the automatic protection. The drill room approves the route, and human operators, not the software, close every switch. The hydro unit starts itself at minute 4 and creates a small live island of grid running at exactly 60 hertz, the frequency the grid must hold; think of it as the system's heartbeat. Substations come alive at minutes 8, 13, and 19. Customer demand returns in careful 5 megawatt blocks. By minute 26 the island carries 25 megawatts with a steady heartbeat of 59.98. Then at minute 33 the drill master springs a planned surprise: the big gas plant fails mid-start. That leaves 25 megawatts of demand hanging on the one 45 megawatt hydro unit, and the frequency falls to 59.31. Below about 59.5, the island is minutes from collapsing back into blackout.
The second decision is the heart of the demo. In seconds, the software computes a recovery plan: deliberately disconnect two blocks of customer demand worth 10 megawatts to stop the fall, keep the gas plant's startup alive rather than abandoning it, bring the backup turbine EASTPORT CT-3 online instead, and reconnect customers only after the frequency holds 59.9 for two full minutes. The room approves. The disconnection is done in 90 seconds; the frequency bottoms out at 59.24 and recovers. The backup turbine is running by minute 53, adding 85 megawatts of capability. The big gas plant joins at minute 61, adding 180 more. By minute 70, all 8 substations are live and the island carries 110 megawatts. At minute 78 the island is matched to the neighboring grid, and the LAKELINE tie closes at 82 minutes, well inside the 100-minute goal. The drill ends with 140 megawatts of customer demand restored, all 9 scored objectives met, and the evidence file required by federal reliability rule EOP-005 assembled automatically by minute 83.
The old way starts with a paper binder. The room argues over two candidate routes for 22 minutes, then picks one that powers a long line before any customer demand is attached. Voltage on that empty line spikes 18 percent above normal, a known physics effect, and the automatic protection trips the line. Restarting from scratch costs 30 more minutes. When the surprise plant failure hits, the improvised answer is to disconnect everyone and abandon the plant startup. The island survives, but it serves nobody, and the second startup attempt runs out the clock. The drill is suspended at minute 84 with 4 of 9 objectives met, only 4 of 8 substations live, and zero customer demand restored, followed by two weeks of after-action paperwork. The core failure is improvising under time pressure, with no way to test a route before throwing the switch.
The software does three things. First, it tests every candidate route in the computer model before the room even asks, checking protection settings and the voltage spikes that empty lines produce, so the 22-minute debate and the trip never happen (use case 2.7). Second, when the surprise failure hits, it computes a recovery sequence in seconds instead of leaving the room to guess (use case 1.8). Third, it lets three companies drill together in one shared simulation, with automatic surprises, live scoring, and a compliance evidence file that builds itself during the run (use case 20.7). Every recommendation is an approval gate: the software suggests, the drill room decides, and human operators act. The winning numbers: tie closed at 82 minutes, 140 megawatts restored, 8 of 8 substations live, 9 of 9 objectives met.
| Measure | Without GridCORTEX | With GridCORTEX | Delta |
|---|---|---|---|
| Cranking path selectionhow long the room spent choosing the restart route before anyone could act | 22 min of debate | validated in advance | 22 minutes saved |
| Ferranti overvoltage tripa voltage spike on a long line powered with nothing at the far end; it trips protection and forces a restart | yes: restart, −30 min | prevented by sequencing | no restart needed |
| Unit-trip inject responsewhat the room did when the drill master failed the big gas plant mid-start | shed all + abort crank | computed re-sequence, 90 s | the island survived |
| Interconnection tie restoredthe minute the island reconnected to the neighboring grid; the goal was under 100 minutes | not reached | T+82 | objective met |
| Load restored at drill endmegawatts of customer demand back on power when the drill ended | 0 MW | 140 MW | 140 megawatts of customers back |
| Buses energizedsubstations brought back to life along the restart route | 4 of 8 | 8 of 8 | every substation live |
| Drill objectivesthe scored goals the exercise was designed to test | 4 of 9 | 9 of 9 | 5 more objectives met |
| Joint drill frequencyhow often three organizations can practice a restart together | annual (scheduling limit) | monthly, on demand | 12 times as often |
| Drill-master inject prepthe work of preparing surprise events and scoring the response to them | weeks, hand-built | generated + scored live | on demand |
| EOP-005 evidence packagethe proof file that federal reliability rule EOP-005 requires after every blackstart drill | 2 weeks after-action | assembled during the drill | finished at minute 83 |
| Multi-party participationhow many organizations can join, and how hard the drill is to schedule | 3 orgs, 1 painful date | 3 orgs, any date | coordination solved |
| Operator reps per year (blackstart)how many full restart rehearsals each operator gets in a year | 1 | 12+ | practice adds up |
| Findings into plan revisionshow quickly lessons from a drill get written into the official restoration plan | annual cycle | every drill | lessons land immediately |
| Real EMS/SCADA touchedthe live control systems that run the actual grid; the drill never connects to them | never | never | simulation only |
This is the one use case in this set with a real, traceable safety mechanism, and it is still system level rather than personal. Restoration is the most dangerous procedure the grid runs: crews perform switching on a system with unfamiliar configuration and uncertain energization status, and a desk that sequences a cranking path wrong sends field crews to the wrong place under the worst conditions. Practicing quarterly and unscripted, against real restoration physics, is how a mis switch during a real restoration becomes less likely and how restoration finishes sooner, which shortens the period customers are without power.
Counted in units you already track:
Scenario construction, facilitation, travel, and evidence assembly hours come back to the training organization and to every participating member, and the training director spends the time on after action coaching instead of on logistics.
The numbers we need from you to run that formula:
| Cost driver | How it is calculated, from a rate you supply |
|---|---|
| Training and facilitation labor | scenario construction, facilitation, and after action writing hours avoided x your loaded instructor and operator rate |
| Travel and logistics | participant travel hours and trips avoided x your loaded operator rate plus your actual travel and per diem cost per trip |
| Compliance evidence labor | evidence assembly hours avoided x your loaded compliance analyst rate, across the ISO and each participating member |
| Restoration duration | your own estimated cost per hour of a regional restoration, including value of lost load, x the hours you believe better practiced sequencing removes, a share you set from your own drill scores |
| Member coordination effort | hours each member spends today preparing for and reconciling after a joint drill x their loaded rates x number of participating members |
You pay for the scoped engagement that builds and runs this and the simulation compute, for building the restoration physics model on your actual network model and keeping it current as the system changes, for integration into your training and compliance document systems, and for the operator hours spent in the simulator, which are real hours from a staffing plan that is already tight. Member participation is a negotiation, not a purchase, and getting transmission and generator owner desks to commit quarterly is the part that takes the longest.
Payback on labor and travel alone is straightforward to compute and usually modest. The case is really made on restoration duration, so decide up front what an hour of regional restoration is worth to you and to your regulator, and let the drill scores tell you whether that hour is moving.
The safety mechanism here is indirect but specific. A restoration sequence built on a stale configuration does not fail on paper, it fails in the field, mid-restoration, with crews already deployed and the system in an abnormal state. Discovering a mis-assumption during a validation run rather than during a real restoration is what keeps crews from executing steps against equipment that is not where the plan says it is.
Counted in units you already track:
Plan maintenance and drill preparation hours come back to the operations engineers who own the restoration plan.
The numbers we need from you to run that formula:
| Cost driver | How it is calculated, from a rate you supply |
|---|---|
| Engineering labor | plan maintenance and reconciliation hours avoided x your loaded operations engineer rate |
| Drill preparation | preparation hours avoided per drill x drills per year x your loaded rate for the staff involved |
| Consultant studies | outsourced restoration study hours displaced x your contracted consultant rate, where you use one |
| Restoration duration | hours of wide area restoration shortened x your own cost per hour of unserved load, a figure you supply and defend, not one we give you |
| Documentation | hours spent assembling drill and plan evidence x your loaded rate for the compliance analyst who does it today |
You pay for the scoped engagement that builds and runs this, for integration to your energy management system model and your outage scheduling system, and for engineer time to validate generated sequences, which is heavy in the first year and never goes to zero. Nothing here is sent to the energy management system and nothing operates equipment, so the licensed operator review stays in place permanently by design. Treat that review as a permanent line item, not a pilot cost.
Payback is driven by engineering plan maintenance and drill preparation hours, which are countable from this year's timesheets and drill schedule. The value of a shorter wide area restoration is the real reason to do it and is far too uncertain to anchor a business case on.
The direct exposure removed is small and the indirect one is large. During an actual blackstart, operators and field crews perform a long sequence of switching operations under extreme pressure, and a step that cannot succeed on today's topology turns into improvised switching and unplanned field trips. Validating the path before the event is how you keep the restoration on the written sequence instead of on somebody's judgment at three in the morning.
Counted in units you already track:
Restoration planning and drill preparation hours come back to transmission operations engineering, and the plan owner reviews only the steps the twin flagged.
The numbers we need from you to run that formula:
| Cost driver | How it is calculated, from a rate you supply |
|---|---|
| Restoration planning labor | engineer hours avoided x your loaded transmission operations engineering rate |
| Drill preparation and facilitation | preparation hours avoided x your loaded rate for the staff who run the drill, plus operator hours pulled off desk x their loaded rate |
| Generation staff time | hours your plant staff spend confirming cranking unit capability x their loaded rate |
| Restoration duration | your own value of customer minutes not served during a widespread restoration x the minutes you believe a validated path saves, a share you set, not us |
| Consulting support | your current cost per commissioned restoration study x the studies you would no longer commission |
You pay for the GridCORTEX simulation service, for integration into your topology model, your outage scheduling system, and your blackstart unit test records, and for engineering and operator time to compare the twin's result against a drill you have already run. The integration into outage scheduling is usually the larger and slower line item, because equipment status has to arrive automatically or the whole benefit evaporates.
Payback is driven by engineering and drill preparation labor, because those hours are on a timesheet you can pull. Avoided restoration time is the bigger number and the one your finance team will trust least, so carry it as upside.
What is this, exactly? It is AI software: intelligent agents and models built and delivered by SoftServe, running on NVIDIA accelerated computing. It is not a hardware appliance and it does not replace the systems you run today. It deploys in your own cloud or on your premises, connects read-only to your existing systems, and recommends; your people approve every action, starting in shadow mode until it earns trust.
A multi-party restoration simulator for the ISO/RTO and its member operators. Each desk runs its own procedures against live restoration physics on the real network model, with an AI adversary injecting unscripted failures; output is scored drills and NERC EOP-005/006 evidence every run. The demo above uses synthetic data; everything below describes what the real deployment needs from your organization.
| Your system | Typical products | How we connect |
|---|---|---|
| Energy Management System (EMS) / transmission SCADA | AspenTech OSI monarch, GE e-terra | scheduled file export (CSV or CIM XML) |
| Document and knowledge stores | blackstart plans, restoration procedures, prior drill records | document upload |
| SCADA historian | AVEVA PI System, GE Proficy | historian mirror (one-way feed) |
| Plant control (DCS) for generation | blackstart unit capability and test records | document upload |
| Planning and study tools | PSS/E, PowerWorld, TARA | scheduled file export (CSV or CIM XML) |
| Asset / work management (EAM/CMMS) | IBM Maximo, SAP PM, Hitachi Asset Suite | database replica refreshed nightly |
Blackstart plans are highly sensitive, so this runs fully isolated with no internet connection, on-premises or in a dedicated enclave, with member desks connecting through the ISO's secured channels. It is simulation only, with no connection to production control systems.
The Approve button you just clicked in the demo above is the real workflow. This is what it looks like on the screen of the ISO director of operations training in the GridCORTEX console:
Approve schedules the drill in the simulator and notifies member training contacts, who confirm participation in their own processes. The simulator is fully separate from the production EMS; evidence files to the compliance document store as drafts for the training director.
Drills are console-driven: the director picks participants, date, and inject count. Network model updates flow automatically from the ISO's model export.
Each run loads the latest approved network model export, not live SCADA; every drill report shows the model vintage it ran on.
Lives in the GridCORTEX console, with evidence filed in the compliance document store; a scored drill report emails each participant's training lead. The console runs in a browser beside your existing screens on day one; embedding into your own systems is a roadmap step once the read-only phase has earned trust. Approve, Modify, and Decline are all captured in an audit trail your compliance team can pull, and GridCORTEX never blocks or overrides anything in the systems you run today.
The fair question from any ISO or TO: "We have a dispatcher training simulator, a restoration plan, and we run the NERC-required drills, what's new here?" Here's the honest answer.
When someone asks "what did it actually calculate?", this is the list. In the simulation these factors drive the storyline; in a pilot they are computed from your restoration plan, network model, relay settings, and unit data.
Presenter's one-liner: "Three control rooms, one black grid. The agent validated the cranking path, sized every load pickup, survived a drill-master's unit trip by re-sequencing in seconds, and synchronized back to the interconnection, while writing its own NERC evidence package. A drill that takes a year to schedule, on demand. That's what you just watched."