The order every distribution operator dreads: "Shed your share. Now." Watch a full EEA-3 firm load shed event, end to end: the ISO calls three times, 10, 20, then 30 MW of obligation, while GridCORTEX computes the sheddable pool (hospitals, water, and pipeline feeders excluded), splits blocks at mid-feeder reclosers for double the rotation depth, dispatches distributed generation and batteries to shrink the shed itself, and rotates outages so no customer sits dark longer than five minutes. Then restoration in ISO-released stages (through a stuck breaker and a fault on pickup) ending with the complete event report, written before the phones stop ringing.
| Order | Received | Obligation | Met At | Response | Status |
|---|
| Element | Issue | Action Taken | Customers | Outage |
|---|
| Without | With GridCORTEX | Δ |
|---|
| Without | With GridCORTEX | Δ |
|---|
It is 14:00 in a fictional utility's control room, and the regional grid is one step from emergency blackouts. The regional grid operator (the ISO), the organization that runs the grid and the electricity market, has declared an alert called EEA-2, level 2 of its Energy Emergency Alert scale: record heat, two power plants tripped offline, and no more power left to import. The dreaded next step is EEA-3, when the operator orders utilities to deliberately cut power to paying customers, called firm load shed, because cutting some customers on purpose is the only way to keep the entire grid from collapsing. GridCORTEX set the board an hour earlier. It computed which customers can safely take turns going dark: 29 rotatable blocks totaling 61 megawatts (MW), built around reclosers, automated switches partway down a power line that let just a section be turned off. It locked 10 critical lines out of the pool entirely: the regional hospital, water treatment, a gas compressor, the 911 center, a dialysis cluster, and more. And it verified 6.8 MW of helper resources ready: batteries, a small local generating plant, and businesses paid by contract to cut their use on request. Then the recorded line rings three times. At 14:04 the grid operator orders 10 MW of firm load shed, with 15 minutes to comply; at 14:28 the obligation doubles to 20 MW; at 14:50 a third order takes it to 30 MW. The clock runs from 14:00 to about 16:20, through the shed, the staged restoration, and the automatically written event report.
Each order is a decision point, and a human shift supervisor approves every response, because deliberately turning customers off is the most serious thing a utility does. The response to Order 1 dispatches the helpers first: the Bayshore battery (2.4 MW) plus the Midtown generating plant (1.8 MW), so 4.2 MW never has to be taken from anyone. The remaining 5.8 MW rotates across the pool, where the mid-line switches split 11 lines into half-blocks, doubling the number of groups that can share the burden, on a schedule that keeps no block dark longer than 5 minutes. Order 2's response adds the third helper, 2.6 MW from businesses under cutback contracts (total offset 6.8 MW), and widens the rotation to about 7 blocks dark at a time; the obligation is met in 4 minutes. Order 3's response rotates the full 23.2 MW that remains after the helpers, and is met in 3 minutes with the 5-minute promise still holding: each block spends 38% of the time dark and rests about 9 minutes between turns, the longest outage is 4 minutes 52 seconds, and the water plant and hospital lines are confirmed live on the control room's monitoring screens throughout.
The fourth decision point arrives with the 15:15 release order, when the grid operator starts letting load come back. Restoration has a trap: after an outage, air conditioners and appliances all restart at once, so each restored block briefly draws about 1.35 times its normal load. The approved plan restores the hardest-hit blocks first, spaces the switch closures 90 seconds apart so no transformer is overloaded, and keeps the helper resources running until the obligation falls below 5 MW. Then come the night's two curveballs. At 15:35 the breaker on line FDR-112 refuses its remote close command, a mechanical alarm, so a crew is dispatched and the rotation re-plans around the stuck block until a manual close ends its 31-minute outage, logged as an exception. At 15:48 line FDR-121 fails under the restart surge; its automated switch isolates only the faulted section, so 61% of that line's customers come back anyway while 420 stay out with a crew on the way.
With all four approvals, the emergency ends at 15:58. Every rotation block is back except the two logged exceptions, and every restored block lands inside equipment limits with zero repeat trips. By 16:13 the event is closed: 41,000 customers touched, longest routine outage 4 minutes 52 seconds, zero critical facilities interrupted, and the full event report, covering orders, blocks, exceptions, fairness, and helper output, is already assembled from the automatic decision log. The closing screen shows that report, including the 3-for-3 compliance record, next to the binder-and-spreadsheet version of the same night.
The binder plan sheds four whole lines from a 2019 spreadsheet, including FDR-108, which feeds the water treatment plant; the city learns that by phone when the plant goes dark. The plan fails because it does not know what is on each line today, cannot turn off anything smaller than a whole line, and has nothing that shrinks the order itself. Manual rotation runs about 30 minutes behind while operators build switching lists by hand, and the third order means eight whole lines dark on a roughly 40-minute cycle with no helper megawatts.
Restoration without staging trips two lines straight back out under the restart surge; they are shed and restored twice. The night ends with a 47-minute maximum outage, a water plant on backup power for 118 minutes, only 1 of the 3 orders met on time, roughly 1.9 million customer-minutes of outage (one customer dark for one minute is one customer-minute), and the record of it all living in nine operators' memories, to be reconstructed over three weeks for the inevitable inquiry.
The software computes the pool of sheddable customers live, block by block down to the switch level, with critical lines excluded segment by segment. It dispatches the helper resources first, so 6.8 MW of the 30 MW order never sheds anyone. Its rotation engine holds every routine block under 5 minutes dark while spreading the burden fairly across neighborhoods. Every step keeps a person in charge: the shift supervisor approves all four recommendations, and operators execute every switching action through the utility's own control system.
The winning numbers: all 3 orders met within minutes, longest routine outage 4:52, zero critical facilities interrupted, zero repeat trips on restoration, roughly 0.6 million customer-minutes instead of 1.9 million, and a regulator-ready event report generated during the event, finished the same night.
| Measure | Without GridCORTEX | With GridCORTEX | The difference |
|---|---|---|---|
| Longest routine outagethe longest any normally rotated block sat dark, not counting the two logged equipment exceptions | 47 min | 4:52 | the 5-minute promise kept |
| Rotation cadencehow quickly the dark blocks are swapped so nobody sits out long | manual, ~40 min | computed, 5 min | 8× tighter |
| Rotatable blockshow many separate customer groups can take a turn; more blocks means a shorter turn for each | 8 whole feeders | 29 (reclosers split 11) | 3.6× finer control |
| Critical loads interruptedhospitals, water plants, and other facilities that must never be shed | 1; water plant, 118 min | 0 | the headline |
| MW shed at peak orderhow much customer load actually had to be turned off to meet the 30 MW order; DER means distributed energy resources, the batteries, local plant, and contracted cutbacks that covered the rest | 30 (no offset) | 23.2 (DER carried 6.8) | 23% less shed |
| Blocks cycledwhich customer groups took turns going dark, and whether the burden was shared | 8, repeatedly | the full pool, equitably | burden spread |
| Cold-load re-tripslines that fail again under the surge of everything restarting at once after an outage | 2 feeders | 0; staged pickups | engineering |
| Customer-minutes (order-of)the total outage burden: one customer dark for one minute counts as one customer-minute | ~1.9M | ~0.6M | 68% less time dark |
| Customers touchedhow many customers experienced at least one rotation outage, and how long each turn lasted | ~52,000, some 3× | ~41K, max 5 min each | fairness |
| ISO compliance recordwhether each of the grid operator's three orders was met inside its 15-minute deadline | 2 of 3 late | 3 of 3 in minutes | no penalty exposure |
| DER contributionenergy supplied by the batteries, the local plant, and the contracted cutbacks instead of shedding customers; MWh is megawatt-hours, one megawatt sustained for one hour | 0 MWh | ~9 MWh carried | shed avoided |
| Event reportthe full record of orders, actions, and outcomes the regulator will ask for | 3 weeks, from memory | generated during event | same night |
| Regulatory posturehow well the utility can defend every decision after the event | inquiry defense | every action logged as it happened | evidence built in |
| Media storythe headline the public reads the next morning | "water plant dark" | "5-minute rotations held" | reputation |
The safety effect is indirect and worth stating honestly. Managing over generation with dispatch rather than with hardware and switching means fewer manual field actions taken under time pressure on a constrained feeder.
Counted in units you already track:
Event handling hours come back to the DER operations engineer on shift, and settlement hours come back to the back office analyst who reconciles curtailment.
The numbers we need from you to run that formula:
| Cost driver | How it is calculated, from a rate you supply |
|---|---|
| Avoided curtailment payments | megawatt hours of curtailment avoided x your compensation rate per megawatt hour under the applicable interconnection or program agreement |
| Operations labor | event handling hours avoided x your loaded DER operations engineer rate |
| Settlement labor | reconciliation hours avoided x your loaded settlement analyst rate |
| Deferred reinforcement | your own cost per feeder or transformer upgrade x the upgrades you judge deferrable because flexibility now manages the constraint |
| Make whole exposure | your contractual make whole or lost production payment per megawatt hour x megawatt hours no longer curtailed |
You pay for the scoped engagement that builds and runs this, for the integration into your DERMS, the distributed energy resource management system, and for telemetry quality work on enrolled resources, because an optimizer is only as good as the measurements it dispatches against. Plan on running it in shadow mode through one shoulder season while your operators build trust, and count that operator time as real cost.
Payback is dominated by avoided curtailment payments if you compensate for curtailed energy, and by deferred reinforcement if you do not. Work out which of those two you actually are before you build the case.
Worker exposure is not the main story here and we will not pretend otherwise. The direct safety mechanism is public: life support customers, water pumping, and emergency communications stay energized because the exclusions are enforced by the plan rather than by an operator's recall under extreme pressure, and no block gets held past its planned duration because a timer was missed.
Counted in units you already track:
Plan building and block tracking hours come back to the operators and support staff working the emergency, and reporting hours come back to the regulatory team afterward.
The numbers we need from you to run that formula:
| Cost driver | How it is calculated, from a rate you supply |
|---|---|
| Emergency staffing | activation hours avoided x staff involved x your loaded rate at the overtime and callout premiums that apply during an emergency |
| Regulatory reporting | post-event reporting and data request hours avoided x your loaded regulatory analyst and legal support rate |
| Customer care volume | calls avoided through accurate, block-specific notification x your own fully loaded cost per contact center call |
| Over-shed energy | megawatt hours shed beyond the required amount x your own value of lost load or your own cost per unserved megawatt hour, a figure you set |
| Switching device duty | rotation operations avoided x your maintenance cost per operation, since operation counts drive recloser and breaker inspection intervals |
You pay for the scoped engagement that builds and runs this, for integrations to your ADMS, advanced distribution management system, your customer information system, and your GIS, and for the designation work underneath: somebody on your side has to establish and defend which feeders are critical and which customers are medical baseline, and keep that current. Add drill time, because a tool nobody has practiced with is not going to be trusted during the one hour it matters.
Payback here is awkward and you should hear it straight: capacity emergencies are infrequent, so an hours-per-event case built on frequency will not hold up. Build it on the preparation and the post-event regulatory reporting work, which happens whether or not you shed, and treat the emergency day savings as the reason it exists rather than the reason it pays.
The exposure this removes is mostly public safety rather than worker safety, and it is worth saying so plainly. The mechanism is that a facility with life support, water pressure, or emergency communications does not discover mid-outage that it was downstream of a switching action nobody modelled. There is a smaller worker benefit: fewer switching jobs get executed and then reversed when the impact is discovered late.
Counted in units you already track:
Tracing and phone call hours come back to the planners and the key accounts team, and list building hours come back to the emergency operations center during events.
The numbers we need from you to run that formula:
| Cost driver | How it is calculated, from a rate you supply |
|---|---|
| Planning and notification labor | tracing and calling hours avoided x your loaded planner and key accounts rate |
| Emergency operations staffing | event day hours avoided x staff involved x your loaded rate, at the overtime rate that applies during activations |
| Avoided rework switching | switching jobs reversed or re-scheduled per year x crew size x hours per reversal x your loaded crew rate |
| Emergency generation | standby or emergency generator deployments avoided x your own contracted mobilization and daily rate |
| Reporting and inquiry response | post-event reconstruction and regulatory inquiry hours avoided x your loaded analyst rate |
You pay for the scoped engagement that builds and runs this, for integrations to your GIS, your customer information system, and your OMS, and for the registry work. The registry work is the real cost and it is yours: somebody on your side has to validate which accounts are genuinely critical and confirm backup generation attributes, and no model can invent that. Expect the first pass to be a few months of key accounts effort.
Payback is driven by planner and key accounts hours plus avoided rework switching, all of which you can count. The avoided consequence, the outage that would have hit a hospital, is the reason people buy it and the number you should keep out of the base case.
What is this, exactly? It is AI software: intelligent agents and models built and delivered by SoftServe, running on NVIDIA accelerated computing. It is not a hardware appliance and it does not replace the systems you run today. It deploys in your own cloud or on your premises, connects read-only to your existing systems, and recommends; your people approve every action, starting in shadow mode until it earns trust.
An emergency decision-support service that builds and continuously updates a rotating load shed plan: which feeders to rotate, in what order, while protecting critical loads and keeping the rotation fair across customer groups. Operators see a recommended schedule; nothing executes without their action in the existing control system. The demo above uses synthetic data; everything below describes what the real deployment needs from your organization.
| Your system | Typical products | How we connect |
|---|---|---|
| Advanced Distribution Management System (ADMS) | Schneider EcoStruxure ADMS, GE Vernova PowerOn, Oracle NMS | read-only API |
| Customer Information System (CIS) / billing | Oracle CC&B, SAP IS-U | database replica refreshed nightly |
| Geographic Information System (GIS) | Esri ArcGIS Utility Network, GE Smallworld | scheduled file export (CSV or CIM XML) |
| Energy Management System (EMS) / transmission SCADA | AspenTech OSI monarch, GE e-terra | read-only API |
| Metering (AMI head-end and meter data management) | Itron, Landis+Gyr, Aclara | read-only API |
| Outage Management System (OMS) | GE PowerOn, Oracle NMS, ADMS outage module | read-only API |
| Document and knowledge stores | SharePoint, emergency operations plans | document upload |
Because this touches emergency operations and sensitive customer data, it runs in your cloud account or fully on premises, with medical-needs data on need-to-know access. All connections are read-only with no link to control systems; any shed action is taken by an operator in the ADMS, and recommendations are written back only after a person approves, via your existing system's own interface.
The Approve button you just clicked in the demo above is the real workflow. This is what it looks like on the screen of the senior distribution operator during a capacity emergency in the GridCORTEX console:
Approve sends the rotation schedule to your ADMS switching queue as a proposed plan in pending status; your operators execute each block through the ADMS's own controls and confirmations. GridCORTEX never opens a breaker or sheds load itself; it can only update the pending plan.
Declare the load shed event in one click and enter your obligation in MW and the duration; if the instruction also arrives digitally through your EMS or market interface, GridCORTEX picks it up and pre-fills the entry for confirmation.
Rebuilds the rotation continuously from live ADMS and EMS state, telemetry seconds old, AMI load data as received; each schedule update shows its as-of timestamp.
The GridCORTEX console, with the schedule mirrored in the ADMS; mobile and Teams pushes on stage changes and plan updates. The console runs in a browser beside your existing screens on day one; embedding into your own systems is a roadmap step once the read-only phase has earned trust. Approve, Modify, and Decline are all captured in an audit trail your compliance team can pull, and GridCORTEX never blocks or overrides anything in the systems you run today.
The fair question from any operations VP: "We have an ADMS, a load-shed spreadsheet, and operators who've done this, what's new here?" Here's the honest answer, and it's written in the after-action reports of every major shed event of the last decade.
When someone asks "what did it actually calculate?", this is the list. In the simulation these factors drive the storyline; in a pilot they are computed from your GIS, ADMS, customer systems, and DER registry.
Presenter's one-liner: "The ISO called three times and we answered in minutes every time. The reclosers doubled our rotation depth, the batteries shrank the shed itself, no one sat dark longer than five minutes, the water plant never blinked, and when it ended, the report was already written. That's what a load shed looks like when it's computed instead of improvised."