Your water
Enter it once — every answer below uses it.What are you treating?
Picks the chemistry that matters and highlights the right tools.Will this water scale?
How far it can concentrate before something drops out.
Enter or pick a water to see the limit.
What should I do?
The lever that lets it run — and what to check.
Segment chemistry
Sour, acid-drainage or oxygenated water carries scales the standard read doesn't cover.
Go deeper
Four tools, in the order you'd use them. Highlighted for your segment.Every number carries its assumption. Simple hides the working; Expert shows it. Need the full console? Open the advanced console →
ca,mg,alk,... with a value row) or a two-column field,value export. Aliases like “Calcium”, “Alkalinity”, “Conductivity” are recognised. Imported data is tagged caller-supplied and validated — an impossible value is rejected, never guessed.adsorption proxy · uncalibrated
Ca-binding proxy · uncalibrated
Segment species — sour / acid-drainage / boiler (optional; leave blank for cooling & RO)
Cycle limitiThe limiting salt sets the ceiling. Bisects to the highest cycles of concentration at which every phase stays under its practical limit. Run it with and without an antiscalant — the gap between the two is what the chemical actually buys you. Kinetically inhibited phases (dolomite, talc) are excluded: they are supersaturated almost everywhere and never form, so left in they would limit every answer.
How high can this water cycle before something drops out?
SensitivityiWhere to spend lab budget. Each input is perturbed and we watch the limiting phase move. Most analyses have one number doing all the work and several that could be badly wrong without changing the decision. This tells you which is which.
Which measurement is deciding that answer — and is it the one you trust least?
Thermal performance · approach-efficiency & fouling factoriWhat fouling has cost you in cooling capacity — from the temperatures you already log. Two textbook, deterministic reads. Tower effectiveness: range = hot-in − cold-out, approach = cold-out − wet-bulb, effectiveness = range/(range+approach) — a tower cannot cool below the wet bulb. Heat-exchanger fouling resistance: Rf = 1/Uservice − 1/Uclean, the added thermal resistance from deposits (Uservice entered, or derived from duty÷(area×LMTD)). The honesty seam: every quantity is closed-form heat-transfer arithmetic — no fitted model, no fabricated coefficient. The commissioning design approach and the clean-design U are ENTERED from your datasheet, never from memory; without a baseline the current metric still computes but the degradation / fouling-resistance piece is INCOMPLETE, never a fabricated default. Impossible readings (cold water below the wet bulb, a service U above the clean U) are flagged with a reason, never computed into a plausible-wrong number. Cooling only.
Turn your operating temperatures into a thermal-condition read — the tower's approach-efficiency and the exchanger's fouling resistance. Baselines are yours; nothing is assumed.
SDI / pretreatment screeningiIs this water fit to feed the membranes? The Silt Density Index — the standard RO feedwater fouling-potential screen, computed exactly from ASTM D4189: %P = (1 − ti/tf)×100, SDIT = %P/T. The honesty seam: the SDI is exact ASTM arithmetic — no fitted model, no fabricated coefficient. The ASTM validity is enforced: above 75% plugging the result is unreliable and flagged (repeat with a shorter T), never reported as a plausible-wrong SDI. The acceptability band uses the spiral-wound guideline (SDI15 warranty ≈5, preferred ≈3) as a LABELLED default, overridable by your membrane's own warranty limit — never dressed up as calibrated to a plant. The pretreatment recommendation is a class from published selection practice; the SDI a pretreatment will ACHIEVE is never predicted — that needs a pilot. RO-only (the test is defined for pressure-driven membrane feedwater).
Run the bench test into a fouling-potential band — and, where the water isn't fit, the class of pretreatment to consider. Limits are the guideline default or yours; nothing is assumed.
NORSOK M-506 · CO₂ corrosion rateiA second published CO₂-corrosion band, beside the de Waard–Milliams estimate. NORSOK M-506's semi-empirical rate for carbon steel: CR (mm/yr) = Kt·fCO₂0.62·(S/19)0.146+0.0324·log fCO₂·f(pH). The honesty seam is the point of this tool: the method is assembled deterministically here — CO₂ partial pressure by Dalton (x·P), fugacity, the shear term, the product — but the two most error-prone, strongly-tabulated NORSOK constants are NEVER supplied from memory: Kt (the 9-point temperature table) and f(pH) (the pH polynomials) are ENTERED from your copy of the standard. They are standardized values in the same class as ASME limits — reproducing a safety-relevant published polynomial from memory, subtly wrong, would be worse than requiring it. Without Kt the rate is INCOMPLETE. The stable method exponents (0.62, 0.146/0.0324) are LABELLED NORSOK defaults, overridable — verify against the standard. The fugacity coefficient and f(pH) default to a conservative 1.0 (LABELLED); enter the real values. This is a published-model ESTIMATE, not calibrated to your field, and it can diverge from de Waard–Milliams; localized/pitting attack, H₂S/sour cracking and inhibitor availability are not covered. Sour (O&G) only.
Assemble the NORSOK M-506 rate deterministically — you supply the standard's Kt and pH factor; nothing is invented. A second band beside de Waard–Milliams.
Cycles balanceiThe only thing here that measures a RATE. Chloride and conductivity concentrate but never precipitate; calcium does. So cycles measured on calcium reads LOW when calcium is leaving the water, and the gap is the deposition rate. If calcium and alkalinity fall by the same fraction, that is CaCO₃ stoichiometry — the pattern names the scale, not just its presence.
Steps 01 and 02 are theory. This is what your tower is actually doing.
Program costiThe operator’s question is economic. Acid, antiscalant, or fewer cycles — priced per day. Water and acid are arithmetic. The antiscalant line assumes a 5 ppm dose, which this product cannot justify — thermodynamics does not set a dose. Its ranking is indicative until dose-response data exists.
So what do you do — and what does each option cost per day?
Correlation · identify the depositiThree instruments, one tower, and they share no inputs. Thermodynamics ranks the phases by driving force — it says what could form. The ion ledger from step 03 says which ions are leaving, from your logbook. The phosphorus ledger says whether phosphorus is involved and whether your oxidiser is the reason. Joined, they identify the deposit stoichiometrically: calcium and alkalinity leaving 1:1 is a carbonate; calcium and phosphate at 5:3 is apatite; magnesium and silica at 4:6 is sepiolite. The ratios are the mineral formulae — nothing is fitted. Today you identify a deposit by sending a scraping to a lab and waiting weeks for XRD.
What is the scale actually made of — and do two independent methods agree?
Binding constraint · what actually limits cyclesiThe cycle ceiling is rarely the scale you watch. Step 01 finds the chemistry ceiling. But as the tower concentrates, three kinds of limit tighten at once: scale saturation, biocide holding time (residence time — a microbiological risk factor for your assessment, not a Legionella prediction), and your discharge consent (blowdown concentration against your permit). The first to bind sets the real ceiling — and it is often the discharge consent, or apatite created by your own corrosion inhibitor, not carbonate. This couples treatment to environmental compliance in one envelope; scale-prediction tools model these separately, so the true ceiling stays hidden. Discharge consents are entered by you from your permit — never supplied from memory.
Five constraints tighten as you concentrate. Which one stops you first?
Segment chemistryiFor sour, acid-drainage and oxygenated waters. When the water carries dissolved sulfide (O&G sour), low-pH metals (mining acid drainage), or dissolved oxygen (boilers), the engine runs the WATEQ4F thermodynamic database to evaluate the phases those segments care about — barite and iron-sulfide scaling, aluminium-hydroxide and jarosite, and oxygen redox. Phases that are thermodynamically favoured but kinetically too slow to form now are flagged as watch-indicators, never as present risk. The saturation thermodynamics are validated against the database; per-site dose calibration is not yet earned.
Sour, acid-drainage, or oxygenated water? The segment-specific scales appear here.
Net acidity · does this water self-neutralise?iThe entry point for acid mine drainage. Net acidity — not pH — decides whether a water self-neutralises or needs added alkalinity, because a circumneutral water can carry high dissolved metal (latent acidity) that appears as the metals hydrolyse. This is the deterministic Kirby-Cravotta / Hedin calculated acidity: proton acidity from pH plus the metal load (Fe, Mn, Al by charge), minus your measured alkalinity. Net acidic → will not self-neutralise, treat; net alkaline → self-neutralises. If you give total iron it is treated as ferrous — a labelled default; split it into Fe(II)/Fe(III) for the exact value (ferric carries more acidity). The lime figure is the stoichiometric CaO demand; real plant demand is higher by a plant-specific factor that is not fabricated here. Recovery, sludge and purity are not computed — this sizes the chemistry, not the plant.
For acid-drainage water. Enter the metal analysis; net acidity decides treat-or-not.
Operating setpoints · from this water, not a tableiFixed universal setpoint tables are wrong. The safe pH ceiling is not a constant — it is set by this water's scaling limit at your operating cycles. A generic “pH up to 8.8” will scale a hard, alkaline water and needlessly restrict a soft one. Here the pH ceiling is bisected against the real engine, the conductivity ceiling is the cycle limit naming the limiting salt, and the ORP target is residual-driven (it moves with pH). Where a value genuinely is a metallurgy default — the corrosion-side pH floor — it is labelled a default, not dressed up as computed. Every setpoint says how it was derived.
The setpoints this water can actually hold — each with its basis.
Phosphate-pH control · coordinated / congruentiThe daily control decision for a drum boiler on phosphate treatment. The Na:PO₄ molar ratio sets the pH the phosphate produces and the corrosion risk: above 3.0 there is free caustic (gouging risk); 2.2–2.8 is the congruent in-control band; below 2.2 is acid-phosphate (corrosion / maricite). This is the coordinated-phosphate diagram computed, not read off a chart — the deterministic phosphate acid-base equilibria (pK₁/pK₂/pK₃ at 25 °C, labelled). It backs out your effective ratio from measured phosphate and pH, and gives the target pH to sit at the congruent centre. The pressure-specific phosphate band is NOT supplied from memory — those limits come from your plant's chemistry program / current EPRI guidance; only the ratio, regime, target pH and the hideout principle are computed. Give a second load reading and it flags the hideout signature (phosphate down + pH up at load).
For boiler water. Enter phosphate, pH and drum pressure; the Na:PO₄ ratio names the regime.
Boiler cycle twin · blowdown & limitsiThe boiler analogue of the cooling dynamic twin. A drum boiler concentrates dissolved solids just like a tower — feedwater in, steam out nearly pure, blowdown the only path out — so this reuses the cooling twin's validated implicit-Euler integrator, but watches boiler chemistry: silica, TDS/conductivity and alkalinity against the unit's boiler-water limits. Deterministic (ships): maximum cycles of concentration = min(limit÷feedwater) over those species (a ratio), and the boiler-water transient — cut blowdown to save energy and see how fast each species climbs to its limit and when it crosses. COC is an OUTPUT (feedwater÷blowdown), never assumed. Gated (honest gap): the phosphate-hideout, deposition and embrittlement RATES are not predicted — the hideout signature is routed to the validated boiler phosphate read, and silica carryover into steam is emitted only against an entered distribution ratio. Limits are entered (your ASME/EPRI/OEM spec for the pressure); the defaults are illustrative and loudly labelled.
For boilers. Enter the feedwater and flows to see the cycle limit and blowdown transient; the hideout and deposition rates stay gated.
Boiler control regime · mode, deadband & failsafeiThe boiler analogue of the cooling control-regime tool. A boiler HAS real closed-loop control — so this recommends the control mode, deadband floor and failsafe for each chemical-feed loop: blowdown (conductivity/cycles), oxygen scavenger (residual O₂), and phosphate/pH. It reuses the same mode-selection kernel as the cooling tool (dead-time÷lag rule + actuator binding + deadband floor). The blowdown gain d(cycles)÷d(blowdown) is computed from the same mass balance as the cycle twin; the phosphate target is routed through the validated phosphate read. Failsafes are reasoned per loop: blowdown fails open (protect the turbine from carryover), scavenger and phosphate fail last-good (protect the metal / don't chase hideout). The scavenger dose target stays uncalibrated (mode only, never a dose number), and every limit is entered. Hard boundary: the SIL-rated life-safety interlocks (drum level, over-pressure) are NOT modelled — this is chemistry control, not the safety system. Boiler-only.
For boilers. Recommends the control mode, deadband and failsafe for the blowdown, scavenger and phosphate loops; the SIL interlocks are out of scope.
Oxygen-scavenger dose · feedwater deaeration chemistryiThe chemical dose that removes residual dissolved oxygen from boiler feedwater. Dissolved O₂ pits and corrodes; a scavenger reacts it away. The dose is set by reaction stoichiometry with O₂ — exact published chemistry: sulfite 7.88 ppm/ppm O₂ (2 Na₂SO₃+O₂), hydrazine 1.00 (N₂H₄+O₂), carbohydrazide 1.41; DEHA is a labelled published ~1.24 (its oxidation is not a clean 1:1). Any target residual and excess are yours and are added to the stoichiometric demand — the specific residual band by pressure comes from your plant's program, not from memory. It does not pick a scavenger — that is a program call; it doses the one you choose and states the trade-offs. Hydrazine is flagged as a suspected carcinogen / controlled substance every time.
For boiler feedwater. Enter the dissolved O₂ and pick a scavenger; the dose follows the stoichiometry.
Condensate amine / AVTiThe carbonic-acid corrosion of the condensate return, and the neutralizing-amine demand. CO₂ carried over with the steam dissolves in the condensate as carbonic acid, drops its pH and corrodes the carbon-steel return. Deterministic (ships): the acidified condensate pH from the carbonic-acid equilibrium ([H⁺] = (−Ka₁+√(Ka₁²+4·Ka₁·C))/2), and the neutralizing base demand to a target condensate pH = [HCO₃⁻]+2[CO₃=]+[OH⁻]−[H⁺] — closed-form carbonate arithmetic, ~1 eq of base per mol free CO₂ to the bicarbonate endpoint. The honesty seam: the carbonate constants are the standard 25 °C reference values, LABELLED; the CO₂ carryover from feedwater alkalinity uses the published 0.79 factor as a LABELLED theoretical upper bound (actual carryover entered); the amine equivalent weight is a labelled library value; and the amine distribution ratio is ENTERED, never from memory — without it the condensate amine still computes but the feedwater dose is INCOMPLETE, never fabricated. The tool does not choose the amine, model the condensation profile, or claim a corrosion rate. Boiler-only.
Compute the condensate acid load and the neutralizing base demand deterministically — the amine and its distribution ratio are yours, and the feedwater dose is honestly gated without them.
RO array balance · recovery, concentrate & fluxiThe system-level design read for a reverse-osmosis array. From the feed, the target recovery and the membrane area, the system mass balance is exact: concentration factor CF = (1−R(1−r))/(1−R), concentrate and permeate TDS, permeate/concentrate flow, and average flux. At 75% recovery CF ≈ 4 — the rule of thumb, computed. The per-stage split is a labelled uniform-flux approximation. The element-by-element profile (lead-element over-flux, per-element dP) is NOT computed — that needs the full element-hydraulic model (the Wave-3 build) and is returned as an honest gap. Salt rejection, element area and β are labelled defaults. It reports the concentrate concentration, not whether it scales — run the concentrate through Scale & Corrosion for that. A CIP regime follows deterministically from the foulant; the specific doses/temps are membrane-specific and deferred.
For reverse osmosis. Enter feed, recovery and array size; the concentrate and flux follow the mass balance.
RO element-by-element profile · lead over-flux, tail under-fluxiResolves a pressure vessel SPATIALLY — per-element flux, recovery, TDS and pressure, so the lead-element over-flux and tail-element under-flux become visible instead of averaged away (the lead element is where fouling/scaling start; the tail is where brine peaks). A first-principles solution-diffusion marcher (FilmTec form): Jw = A·NDP, Js = B·ΔC, pf = exp(0.7·Y), ΔP = 0.01·q1.7. A and B are back-calculated from the element's public datasheet (permeate flow, rejection, test conditions) — a clean, new-membrane value, labelled, NOT fitted to a plant and NOT the aged state; the fouling factor is your assumption. Accuracy: ~5–10% vs a manufacturer projection, ~10–20% vs a real aged plant. Validated against the Johnson & Busch (2010) published seven-element case.
For reverse osmosis. One pressure vessel: enter the feed, element count and target recovery, and either A/B or a datasheet spec.
RO fouling twin · CIP-cycle forecastiThe RO analogue of the cooling dynamic twin. It answers when to clean, not how fast the membrane will keep fouling from the feed chemistry — that mechanistic rate is a gap the platform is honest about. Deterministic (ships): each operating point is normalised against the reference by ASTM D4516 (routed through the platform's own normaliser), giving normalised permeate flow (NPF), salt passage (NSP) and pressure drop (NPD); a least-squares trend on each — with an R² noise guard, so noise is never called a decline — is projected to its entered cleaning threshold to give the CIP-due day. The soonest indicator sets the schedule; the moving indicator names the foulant class (the D4516 verdict). Gated (honest gap): the mechanistic fouling rate, remaining membrane life, and whether a clean will recover performance are NOT predicted — they need a membrane autopsy or fleet data, and are never fabricated. A MEMBRANE_DEGRADATION signature is flagged as cleaning will not restore it.
For RO trains. Enter a reference reading and a time series of operating points to project the cleaning schedule; the fouling rate and membrane life stay gated.
RO control regime · mode, deadband & failsafeiThe RO analogue of the cooling / boiler control-regime tool. An RO train HAS real closed-loop control — so this recommends the control mode, deadband floor and failsafe for each loop: antiscalant (flow-paced), acid/pH (LSI), dechlorination (residual oxidant/ORP), and CIP trigger. It reuses the same mode-selection kernel as the cooling tool (dead-time÷lag rule + actuator binding + deadband floor). Dechlorination is the inverted oxidiser: free chlorine destroys the membrane fast and irreversibly, so — unlike the cooling oxidiser (no safe default) — this loop HAS a safe default: keep removing oxidant, protect the membrane. Antiscalant is flow-paced feed-forward with the dose target uncalibrated (mode only). The CIP trigger routes through the RO fouling twin (crosses the entered cleaning threshold); if the signal is lost it falls back to the time-based schedule. Every limit is entered. Hard boundary: the high-pressure safety interlocks are NOT modelled — chemistry control, not the safety system. RO-only.
For RO trains. Recommends the control mode, deadband and failsafe for the antiscalant, acid, dechlor and CIP loops; the high-pressure safety interlocks are out of scope.
Passive AMD treatment sizing · train selection & areasiRecommends a passive treatment TRAIN and SIZES each unit from published design criteria. Selection uses the Hedin/Nairn/Kleinmann (1994) decision tree: net-alkaline → aeration + settling + aerobic wetland; net-acidic with DO/Fe(III)/Al all < 1 mg/L → anoxic limestone drain (ALD); otherwise → RAPS / vertical-flow pond. Sizing from published loading rates: aerobic wetland Fe 10/20, Mn 1/2 g/m²/d; RAPS acidity 25–35 g/m²/d; ALD limestone = the larger of a 15 h retention hold and life-neutralisation; settling 24–48 h. Rates are empirical medians with wide variance — the compliance basis is ~2× conservative. COST is not computed: unit prices are region-specific and uncalibrated by design — it names the cost-driver structure, not prices. It sizes; it does not predict effluent quality.
For acid mine drainage. Enter the flow and net acidity (from Diagnose) plus DO, Fe, Al, Mn; it selects and sizes the train.
Limestone depletion clock · remaining bed lifeiThe dynamic companion to passive sizing. A passive AMD bed has no control loop — it just slowly depletes as the limestone neutralises the acidity load. This tells you when it needs replacement. Deterministic (ships): remaining life = installed limestone ÷ consumption, where consumption = acidity load ÷ (purity × efficiency) via the same neutralisation stoichiometry as the sizing tool (1 g CaCO₃ per 1 g acidity-as-CaCO₃). This is the stoichiometric upper bound — the real life is at or below it. Gated (honest gap): the armoring rate (Fe/Al hydroxide coating shortens the real life) and end-of-life effluent quality are not predicted — supply an entered armoring de-rating factor from field data to shorten the estimate; the tool never fabricates one. Net-alkaline water reports no depletion. AMD-only.
For AMD. Enter the flow, net acidity and the installed limestone mass to see remaining bed life; the armoring rate stays gated.
Sludge generation · dry mass & disposal volumeiHow much sludge the treatment makes — the disposal cost driver. Sludge handling is a major, often-overlooked annual cost, and disposal is billed by volume. Deterministic (ships): the dry-solids mass — each dissolved metal precipitates as its hydroxide by a fixed molar-mass ratio (Fe(OH)₃, Mn(OH)₂, Al(OH)₃), 100% at the design pH endpoint (the AMDTreat convention). Iron is taken as ferric hydroxide Fe(OH)₃ (aerated active-treatment basis, labelled) — a passive/anoxic flag warns this over-states iron. Not fabricated: the wet volume needs the site-specific percent-solids of the thickened sludge (and, optionally, its density) — supply it and the volume is computed; leave it blank and only the dry mass is returned, the volume an honest gap. Gypsum / calcite / excess-lime solids are not estimated (they need the reagent dose and are saturation-dependent) — enter them if you have them. AMD-only.
For AMD. Enter the flow and the dissolved Fe/Mn/Al to see the deterministic dry-solids mass; add the sludge percent-solids to get the disposal volume.
Scale-inhibitor squeeze design · envelope & lifetimeiDesigns a scale-inhibitor squeeze in three layers, each with its own honesty status. (1) Scaling driver — which scale the squeeze protects against, ROUTED through the platform's own saturation + incompatible-mixing engine (supply formation water + seawater). (2) Reservoir geometry — deterministic: radial penetration r = √(rw² + V/(π·h·φ·S)), treated pore volume, inhibitor mass placed. (3) Squeeze lifetime — the frontal-advance model Vlife = 1 + ρ(1−φ)/φ·(k/n)·MIC(1/n−1). This is deterministic ONLY given a lab-measured isotherm (Freundlich k, n) and MIC from a static-adsorption bottle test + coreflood. Those are rock-and-brine-specific and cannot be predicted from water chemistry — without them the tool returns an explicit lab-data-required gap, never a fabricated isotherm or lifetime.
For oilfield produced water. Enter the reservoir geometry and treatment; add a lab isotherm + MIC to get lifetime.
Sour progression twin · scaling onset on breakthroughiThe sour analogue of the dynamic twin — built around the one sour progression that is deterministic: scaling onset as injection water breaks through. As sulfate-rich injection water (seawater) mixes into Ba/Sr-bearing formation water, the blend becomes supersaturated in barite/celestite that neither water forms alone — the classic produced-water problem. Deterministic (ships): the scaling onset is routed through the validated mixing scan (the platform's own saturation engine) — the smallest seawater fraction at which each emergent scale crosses SI > 0, the binding scale named, and (against an entered breakthrough curve) the field-life time it is reached. Gated (honest gap): the souring rate (biogenic H₂S), scale deposition rate and corrosion rate are not predicted (reservoir-/lab-specific) — an entered souring trajectory is walked as-is, never generated. Sour-only.
For sour (produced-water) systems. Enter the formation and injection waters to see when scaling begins as injection water breaks through; the souring and corrosion rates stay gated.
Control regime recommendation · mode, deadband & failsafeiPer cooling-tower loop, recommends a control MODE + deadband + alarm/failsafe. The process gain is engine-computed (the oxidiser gain dHOCl%/dpH from HOCl speciation); the actuator class (relay vs analog) gates which modes are physically possible; the dead-time/lag ratio selects within it (<0.1 on/off, 0.1–0.3 PID, 0.3–1 pseudo-PID/band, >1 band/timer — tight PID oscillates when dead-time-dominated). Dead time, actuator min-on-time and noise are entered; alarm/failsafe limits are the entered, edition-stamped surface — it computes WHERE a variable crosses them, never the limit itself. Failsafe is reasoned per loop: acid & non-ox FAIL-CLOSED, inhibitor FAIL-LAST-GOOD, and the oxidiser has NO safe default (failing off risks Legionella, failing on risks over-oxidation + consent) so it is never auto-set — the human sets it. Recommends; the human commits.
For cooling towers. Pick a loop and actuator, enter dead time / lag / noise; it recommends the mode and failsafe.
Sensor drift & service scheduling · confound breaker & time-to-limitiTells sensor DRIFT from real SERVICE NEED — and never confuses them. A pH probe that ages and reads low looks exactly like rising acid demand; dose acid to “correct” it and you have driven the water acidic on a lying probe. The confound breaker: a real process change moves MULTIPLE correlated streams together (pH and ORP and calcite SI); instrument drift moves ONE. A stream that departs from what its partners predict is a sensor fault — recalibrate, do not act; a stream that moves with them is real — act. Scheduling by time-to-limit, not calendar: time_to_L = (L − now)/rate, where the limit L is entered with its edition, never from memory. The water clock (soonest limit) and instrument clock (soonest recal) merge into one visit. Full multi-point drift series (with the R² noise guard) ingest via the service-visit API; low-confidence readings SHORTEN, never lengthen, the interval.
For cooling towers. Enter the recent per-stream trends to break the confound, and a variable + entered limit to schedule.
Dynamic twin · driving-force forecastiThe honest cooling-tower digital twin. Sim A (ships now) forward-integrates the transport mass balance — implicit backward Euler, unconditionally stable, tested to hit the analytic steady state exactly — with the reaction terms at zero, and recomputes SI / HOCl% / HTI exactly from the engine at each state. It answers when the water crosses into supersaturation if you push cycles, without claiming a deposit mass. COC is an OUTPUT, integrated and reported (it lands below makeup÷blowdown because windage carries concentrate out) — never assumed. Sim B (rate: kg/day) is gated: the scenario emits a reaction rate ONLY where replay has calibrated that coefficient by closing the mass balance on the plant's own history (rate = residual, not a curve fit). Until then the rate slot is UNCALIBRATED, never fabricated — the twin does not hide a guessed rate inside a differential equation. Corrosion is learned from the probe; Legionella is never predicted; a beneficial forecast does not authorise the setpoint that reaches it.
For cooling towers. Enter the water and tower flows to forecast the driving force; the kg/day rate stays gated until replay calibrates it.
Independent audit · the vendor-neutral second opinioniA second opinion that doesn't sell you chemicals. Given your current operating point — the pH and cycles you actually run — this checks where you sit versus the water-specific setpoints and the binding constraint, names any material finding, and (if you supply economics) the lowest-cost route to it. Every finding shows its basis. It never recommends a point-value dose — dose-response is uncalibrated, so it bounds, it doesn't prescribe — and it states plainly what it cannot say without your field data. Carries no chemical supply interest.
Is your current program right? An independent read of your operating point.
Unified twin · one pass, advisory or simulator-autonomousiThe whole pass in one place. Identify → recommend → control → observe, with every output a single Recommendation carrying what, the proposal, why, its provenance, its confidence, and its safety class. Two rules you can see here: an output with no provenance does not render, and a human-only safety item (oxidant / biocide) is never automatable. Autonomous mode is for validating the control logic against a simulator or test rig — on a plant target it is refused and downgraded to advisory. Human-in-the-loop is the default and the only mode that reaches real hardware.
Run the control logic as one traced pass. Autonomous is simulator/test only.
Control decision · what would actuate, and what may notiThe safety gate, made visible. Ask for a mode and a target, and this shows what the platform would actually do — loop by loop, with the safety class on each action. Two rules are structural, not preferences: autonomous is refused on a plant and silently downgraded to advisory, and an action classed human-only-safety (the oxidiser, the biocide) is never actuated no matter what mode you ask for. If you requested autonomous and got advisory, that is the gate working.
Ask for a mode; see what the gate grants and what it refuses.
Closed-loop sandbox · prove the loop before it touches anythingiLoop validation on a simulator, never a plant. Runs the control loop against simplified tower dynamics to show whether it converges toward the setpoints or oscillates. These dynamics are deliberately simplified and are NOT a calibrated plant model — the sandbox proves the loop's logic and stability, not what your tower will do. The oxidiser is structurally absent from the loop: it cannot be actuated here even in simulation.
Does the loop converge, or hunt? Run it on the simulator and watch.
Calibration · how close is this coefficient to trustworthyiThis is where the moat is built, and where it is honestly gated. Feed service-visit points and the learner classifies each interval (steady / drift / step), excludes dose-change steps from the fit and flags them for human confirmation, then fits the coefficient with a confidence interval. The status is the honest part: a coefficient reaches CALIBRATED only on FIELD or LAB provenance with a tight interval. Synthetic data can never calibrate anything — paste synthetic points and the status stays SYNTHETIC no matter how tight the interval gets.
Feed visit data; watch the confidence interval close — and see what still blocks CALIBRATED.
Field-data capture · distance to CALIBRATEDiThe moat motion. The step above fits a coefficient from whatever you paste; this one persists captured service visits and accumulates the posterior across every visit, then shows, per coefficient, how far it is from CALIBRATED. The honesty is in the distance: a coefficient with only synthetic points is not “almost there” — it is BLOCKED on field data, because no quantity of synthetic reaches CALIBRATED. One with field points but a wide interval shows ~N more field points at the current scatter. This capture is untrusted: any point claiming FIELD is clamped to SYNTHETIC — only a trusted field integration fills the moat, never a pasted payload. That is exactly why the demo below stays BLOCKED however many points you add.
Capture visits, then watch each coefficient's distance to CALIBRATED — honest about the kind of data still missing, not just the amount.
ROI / eROI value ledgeriThe business case, without fabricating a number. Turns a physical operating improvement into water / energy / carbon / labour / dollar terms for a plant manager. The physical quantities it derives are textbook, deterministic water balances — the cooling water balance from a cycles change (blowdown = evaporation÷(cycles−1)), RO intake water from a recovery change (feed = permeate÷recovery) and boiler makeup water from a cycles change; every other quantity is entered and flagged. The honesty seam: every price and carbon/energy factor is ENTERED and source-stamped, never supplied from memory (treated like a regulated limit) — a missing price makes its line INCOMPLETE, never a fabricated default. Each line is quantity × price, shown. Physical and monetary confidence are reported apart: a deterministic water quantity does not make its dollar value validated — the money is HEURISTIC, riding on your entered prices. Prices may be entered as bands. Payback / ROI% appear only if a capital cost is entered. All segments.
Translate a physical improvement into the numbers a plant manager buys on. Enter a cooling cycles change (derived water saving) and/or your own physical deltas, plus your source-stamped prices.
Compliance reportiThe audit artifact, honest by construction. Builds an audit-ready value-vs-limit record — ASHRAE 188 register, NPDES discharge, ASME/EPRI cycle-chemistry, or mine-discharge. The honesty seam: every limit is ENTERED and edition-stamped, never supplied from memory (the platform's standing position on discharge consents and ASME limits). A parameter with an entered limit is assessed transparently (value vs limit) → PASS/FAIL; a parameter without a limit is reported but NOT assessed — never a fabricated pass, and excluded from the overall verdict. Every value carries its provenance (engine / measured / entered). The report must name its standard and edition or it is incomplete. For ASHRAE 188 no Legionella CFU is predicted — the register documents the water-management program. It is a factual record, not a legal certification. All segments.
Assemble an audit-ready compliance record from your parameter values and your entered, edition-stamped limits. Nothing is assessed against a limit the tool invented.
AMD lifecycle cost / NPViThe one segment with only free government tools. An AMDTreat-style whole-of-life cost for an acid-drainage treatment system — capital + annual O&M + recapitalization (media replacement), discounted to NPV. The honesty seam: physical quantities are routed from the validated AMD reads (net-acidity → reagent demand, passive sizing → limestone mass, sludge → disposal tonnes/volume, depletion clock → replacement interval) or entered, each tagged with its provenance — never fabricated. Unit costs are ENTERED and UNCALIBRATED (the platform has never calibrated an AMD cost coefficient and never supplies one from memory); a line with no unit cost is INCOMPLETE — listed, excluded from the total, never a fabricated default. The NPV is deterministic arithmetic given your entered discount rate and horizon. Physical vs monetary confidence are kept apart: the dollar total is a HEURISTIC planning estimate, not a bid. Give two scenarios for a passive-vs-active comparison. AMD only.
Build a whole-of-life cost for an AMD system from routed physical quantities and your entered, uncalibrated unit costs. Nothing is costed against a coefficient the tool invented.
ESG / water-stewardship disclosureiPhysics-grounded disclosure, not a typed-in guess. Assembles a framework-structured water disclosure for CDP Water, GRI 303, or ESRS E3. The honesty seam: the record names its framework + edition or it is INCOMPLETE; a datapoint the framework asks for that has no value is NOT reported — listed as a gap, excluded, never a fabricated value or zero; the withdrawal / discharge / consumption volumes (GRI 303-3/4/5) are DERIVED deterministically from the platform's own water balance (blowdown = evaporation/(cycles-1); withdrawal = consumption + discharge) and tagged engine — RO consumption is left an honest gap (it depends on downstream use); the water-stress classification is ENTERED and sourced, never derived from memory (it needs external basin data like WRI Aqueduct); any monetary valuation uses an entered, uncalibrated internal water price and is planning-only. It is a disclosure-PREPARATION record, not an assured disclosure (CSRD requires third-party assurance). Neutral — all segments.
Prepare a CDP / GRI 303 / ESRS E3 water disclosure whose water balance comes from the engine, whose gaps are shown as gaps, and whose water-stress and water price are yours and sourced — never invented.
RO cost of foulingiThe running cost fouling actually adds. Free membrane-design tools (WAVE, IMSDesign) stop at design; this is the operational OPEX cost of RO fouling, across four categories: accelerated element replacement, the energy penalty from the fouling pressure rise, extra CIP (cleaning), and downtime. The honesty seam: every category is the INCREMENTAL cost vs clean operation (the difference from a baseline), not a gross cost. The physical drivers (flux/flow decline, pressure-drop rise, CIP interval, membrane life) are routed from the D4516 fouling twin or entered, tagged with provenance — never fabricated. Unit costs are ENTERED and UNCALIBRATED (never from memory); a category with no unit cost, or no clean baseline, is INCOMPLETE — listed, excluded, never a fabricated default. Physical drivers and dollars are kept apart: the total is a planning estimate, not a bid. RO only.
Cost the OPEX that fouling adds — from the twin's drivers and your entered, uncalibrated costs. Each line is the increment over clean operation; nothing is costed against an invented baseline.
Boiler fuel savingsiThe classic boiler energy case, done honestly. Boiler blowdown carries hot treated water out of the drum, so cycling up (reducing blowdown) saves fuel. The physics that is routed: blowdown = steam/(cycles-1), so the reduction from cycling up is deterministic — the same balance the boiler cycle twin uses — and is routed from the twin or entered, never fabricated. The one value that is entered, not fabricated: the blowdown heat content above makeup (kJ/kg) is ENTERED from steam tables for your drum pressure — there is no steam-table read here, and it is never supplied from memory. Boiler efficiency and fuel heating value are entered physical values; the fuel price is ENTERED and UNCALIBRATED, so the dollar figure is planning-only. The saving is INCREMENTAL (baseline → improved cycles); a line short a required value is INCOMPLETE — excluded, never fabricated (the physical fuel saving stands without a price). Physical and monetary confidence are kept apart: the total is a planning estimate, not a bid. Boiler only.
Turn the twin's blowdown reduction into fuel and dollars — deterministic where the physics allows, entered where it must be, and never a fabricated steam-table number.
Production at riskiA dollar figure on a deferral — without pretending to predict it. In sour (O&G) service a souring or corrosion condition can force a choke-back or shut-in to stay inside a facility H2S-handling, metallurgy or HSE limit; the consequence is the production value at risk. The honesty seam — and it matters most here: this tool does NOT forecast the risk. The souring/corrosion rates that would predict whether or when a constraint binds are UNCALIBRATED in this platform, so the affected rate, at-risk fraction (choke-back or shut-in) and duration are ENTERED, never a fabricated trajectory. Any constraint check is a deterministic comparison of your entered indicator against your ENTERED limit (source-stamped, never from memory) — it flags whether the premise holds, not a souring prediction. Price is ENTERED and UNCALIBRATED (planning only); a missing quantity or price is INCOMPLETE — excluded, never fabricated (the physical volume at risk stands without a price). Physical and monetary confidence are kept apart: the value is a planning estimate, not a bid or a forecast. Sour only.
Quantify the production a sour condition puts at risk — from your entered scenario, not a souring forecast. No unit conversion is done; enter a rate and a price in matching units.
Halogen speciationiOnly the undissociated acid is a strong biocide — HOCl is roughly 80× more active than the hypochlorite ion. So the active fraction is an acid-base equilibrium, and at tower pH it decides the whole programme. HOCl pKa is temperature-corrected from Morris (1966); HOBr uses 8.70 at 25 °C with no temperature correction, because its T-dependence is not as well established and inventing one would be worse than saying so.
How much of your halogen is actually the active acid?
Holding time indexiHow long a slug survives, by dilution alone. Standard cooling-water practice and pure arithmetic from numbers Engine 1 already carries: blowdown = evaporation/(cycles−1) − windage. This is a CEILING on contact time, never the contact time — an oxidiser is also consumed by demand, sunlight and your own inhibitors, and dies faster. A non-oxidiser is not consumed by demand, so dilution is close to its whole loss path and HTI is close to real for it.
Your cycles decide how long a slug lasts — and nothing in the biocide programme changed.
Halogen demand & decayiHolding time is dilution only, and on a fouled tower dilution is the slowest loss path by far. With measured constants the half-life can be under two hours against a holding time of a hundred — so a dilution-only curve overstates the residual by orders of magnitude, in the direction that says the biocide is still there when it is gone. Demand and bulk decay come from Standard Methods 2350 (Oxidant Demand/Requirement) — a jar series on this water, an afternoon’s bench work. We refuse to predict without them rather than substitute a plausible default.
What is actually left — once demand, your own inhibitors, and dilution have all taken their share.
Dose for residualiThe inverse of step 03: C₀ = D + C_target · exp(k·t). This is a dose recommendation, and it is defensible for a precise reason — the target is yours, from your water management programme or HSG274, never from us; and demand and decay are measured, not guessed. The forward and inverse models are pinned to round-trip against each other in the test suite. Dose-for-RESIDUAL only. Never dose-for-kill: that needs an efficacy constant, and none exists for biofilm organisms.
What dose holds your documented control limit — and how much of it is wasted on demand?
Bio-dispersant slug windowiA bio-dispersant has no kill claim — it is a penetrant that exposes biofilm so the biocide can reach it, with no concentration-versus-kill relationship. But the dosing is exact arithmetic, and it is the operational instruction nobody computes: blowdown dilutes the slug, so holding a concentration for a contact time means suspending blowdown, and for how long is a number. Evaporation is ignored deliberately — it removes water and would concentrate the slug, so ignoring it errs conservative.
Stop blowdown, dose, wait how long, resume — using the volumes from step 02.
Phosphorus ledgeriThe cycles balance, applied to phosphorus. Phosphorus enters as orthophosphate you dose and as phosphonate you dose; it leaves in blowdown, deposits as apatite, or converts — the oxidiser degrades phosphonate into orthophosphate. Against a chloride tracer: total P short of the tracer means it is depositing; ortho P above what you dosed means your phosphonate is being destroyed; both at once means your oxidiser is manufacturing your scale. Every input is a routine test. Assumes steady dosing and a conservative tracer — heavy bleach reduces to chloride and will inflate it.
Two independent failures, one balance, three routine tests.
Programme couplingsiAn oxidiser does not stay in its lane. It consumes tolyltriazole, so yellow-metal protection falls while the halogen residual still looks fine. It degrades phosphonates into orthophosphate — losing the scale inhibitor AND raising calcium-phosphate supersaturation, which the dispersant then has to absorb. These are directional and disclosed. No rate is put on them: that would need kinetic constants we do not have.
What your biocide does to the rest of the programme.
Biocide classes
Not a taxonomy — the three classes behave differently in ways the model has to respect.
Live-stream diagnosisiClosures, not alarms. A lab analysis is a snapshot; sensors add time, closure and cross-instrument agreement. Each closure is the SAME physical quantity measured two independent ways — when they agree the balance is sound, when they diverge exactly one thing is wrong and which pair diverges names it. A fault fires only when instruments that share no inputs disagree, so it names a cause, not just an alarm. What the numbers mean for asset life is the one fleet-calibrated layer, shown separately and never faked.
Feed the sensor values. The closures, the fault tree and drift detection are all deterministic.
RO performance normalisation · ASTM D4516iThe most-used RO operational calculation — and it separates the three failure modes a single number cannot. It normalises a current reading back to your start-up conditions for temperature and net driving pressure, then reads three trends: NPF (normalised permeate flow) down means fouling or scaling; NSP (normalised salt passage) up means membrane damage or a seal leak; NPD (normalised pressure drop) up means the feed channels are plugging. Read together they name the cause: flow-down with pressure-drop-up is fouling; flow-down with salt-up is degradation; salt-up alone is a leak. The temperature-correction constants and the pressure-drop exponent are polyamide defaults, labelled as defaults — override with your membrane’s value. Osmotic pressure uses the standard brackish TDS approximation, labelled; a rigorous value comes from Scale & Corrosion with a full analysis. This is a deterministic published method, not a fitted or fleet model.
Enter your commissioning (reference) reading and a current reading. Flows in your own consistent units; pressures in psi; TDS in mg/L; temperature in °C.
Corrosion rate · coupon or LPR → mpyiTurns a raw corrosion measurement into a banded rate. A coupon (weight loss over a known exposure, ASTM G1) gives the average rate; an LPR probe (polarisation resistance, Stern-Geary + ASTM G102) gives the instantaneous rate. Both are deterministic published arithmetic. The verdict is metal-aware: the same mpy means different things for carbon steel and a yellow metal, so the band uses the metal's own acceptable range (NACE RP0775 for steel; the tighter cooling target for copper alloys), labelled. The Stern-Geary B is a labelled default (0.026 V, actively-corroding steel) and overridable. Neither method sees a pitting or localised rate — only the uniform average. Corrosion consequence (a rate → remaining asset life) is not computed here.
For cooling, boiler and sour systems. Convert a coupon weight-loss or an LPR reading to a banded rate.
A shareable, Waalgo-branded PDF, and your one working report — it's saved to your account and comes back when you sign in again. Build it by using Pin to report at the top-right of any tool's result, across Diagnose, Prescribe, Operate, Learn and Value. Each pinned result carries its water, segment and input parameters alongside the result, as a snapshot from when you pinned it. If you pin nothing, the report falls back to the default sections for your segment. Reorder or remove pins below, or Start fresh to begin a new report. Every number carries its units and the assumption it rests on.
Choose the water systems you work with. The platform shows only the segments you turn on here — the Home picker, the Scale & Corrosion mode buttons, the “My water” tabs, and every tool follow this list. This is your own view and changes nothing in the engine; a tool that is off is simply hidden, not disabled in the chemistry. At least one stays on.
Choose your preferred unit for each quantity used on the platform — SI or Imperial, per dimension. The default is SI everywhere and USD. Switching converts the values on screen, not just the labels; the engine always computes in SI, so a unit or currency choice never changes a calculated result. Ion concentrations stay mg/L in both systems — the industry convention, so there is no choice to make there.
Two headline counts and the peak-load metric. Live users are distinct people active in the last few minutes — from the pseudonymous activity signal, no PII; registered users is the total number of accounts. The metric below answers the surge question: what binds first, and whether every resource holds 30% headroom above its observed peak. Deeper service liveness, RED metrics, database health and logs live on the System Health tab.
Every figure here is observed — a real sample against a real host or configured ceiling — over the trailing 7 days of capacity samples. Load drivers (active users, API calls, DB lock contention) show a peak but never a made-up ceiling. The binding constraint is whichever resource sat highest against its ceiling at the busiest observed moment. Max concurrent is the one projected figure: a linear extrapolation from that busiest point to the binding ceiling, stamped ESTIMATE with its assumption shown — it is not a load-tested limit, and it reads INSUFFICIENT SIGNAL rather than guess when the peak is too thin. Peaks are only as sharp as the sampling cadence — schedule the sample to catch real surges.
Turn a whole segment on or off for the entire deployment. A segment turned off here is unavailable to every user — it disappears from onboarding, from each person's Settings focus, and from every picker, regardless of their per-user grant. At least one must stay on. Every change is written to the audit log and takes effect on each user's next sign-in.
Create an account and choose how the person receives it. Invite sends a one-time activation token — they set their own password, and no secret is ever transmitted. Temporary password issues a password they must change on first sign-in. Either way, the account is created here; nothing is self-signup.
Loading…
An append-only record of account actions — logins, denials, provisioning, activation, password changes, and role/status changes. This is the accountability trail; it is never edited or deleted from here.
Loading…
How the intelligence tools are reporting, by outcome class. This rides the signals the engines already emit — a normal result (ok), a case the tool does not apply to, an unsolvable input, a safety refusal, or an uncalibrated (banded) answer. A rising edge-rate on one tool is a signal to investigate — a bug, or a shift in what users are feeding it. The counts are aggregate; no water chemistry or user input is stored here.
Loading…
Product-usage metrics keyed on a pseudonymous user id — never name or email, and the event stream stores only the action, never water chemistry. First-party and internal only; never sold, shared, or used for advertising.
Loading…
Live health of the seven services, the data stores, and growth trends. Green is healthy, amber needs a look, red needs action. Capacity forecasts are shown only where the data actually supports one — a flat or noisy series says “insufficient signal” rather than guessing. Latency and error spikes and lock errors are shown as current values and thresholds, not forecast. The peak-load & capacity metric and the live/registered user counts are on the Admin console.
Every tab, offer and tool is enabled by default. Disable one here and it is hidden from everyone who is not an admin — the tab button, the offer, or the tool tile simply does not render for them. Admins always see everything (a disabled node is marked off below). Only an admin can change this, and the change is enforced server-side. Scope: this controls UI visibility — a disabled node is hidden from non-admins; hard API-level access control on the underlying endpoints is a separate, disclosed follow-up.
Waalgo answers five questions about one water — Diagnose (what will it do), Prescribe (what to hold and what it costs), Operate (act, safely gated), Learn (feed field data back) and Value (the business case) — across five kinds of system (cooling, reverse osmosis, sour, acid-drainage, boiler), plus a cross-cutting Microbial control suite. Every screen reads the same shared water. Tools that don't fit a given water are greyed out, and a segment never shows another segment's answer.
The one discipline behind every tool. Waalgo computes what physics, chemistry, geometry and balance determine — and where an answer needs a measurement (a halogen demand, a NORSOK Kt constant, a lab isotherm, a limestone armoring rate, a steam-table heat content, a price) or lies outside what the model can certify (Legionella, a ‘kill dose’), it asks for it or says so, rather than inventing a number. When you see “INCOMPLETE”, “not computed” or “enter the source-stamped price”, that is the product working as designed — it is what makes the numbers it does give you defensible.
Browse the hierarchy or search to find a tool, then select it to see a plain-language explanation, a worked example, and everything it’s good for — with an Open button that jumps you straight to it.
— · released —. This is 0.x on purpose. The version number is a claim, and 1.0 would claim the core is validated. It is not: the inhibitor ranking has never been checked against wet-lab dose-response. The thermodynamics being right — PHREEQC, published constants, and the checks below — is not the same thing, and the version must not blur it. 1.0.0 ships the day that calibration exists, not before, however many checks pass. Every release carries a changelog entry recording what changed and what was found to be wrong; a test asserts the entry exists.
Waalgo computes scale, corrosion and microbiological-control conditions across five kinds of water system — cooling towers, reverse osmosis, oil & gas (sour), mining acid drainage and boilers — and pre-screens candidate treatment chemistry against a compliance envelope. It is built so that every number tells you how much it is worth — and so that where a number would be dishonest, you get a stated gap instead. Five screens, one water: Scale & Corrosion computes the saturation state, Microbial control and Intelligence both read from that analysis, Sensors diagnoses the live operating data, and Inhibitor Screening ranks chemistry against it. The segment-specific reads (sour, acid-drainage, boiler) surface only on the water that needs them.
The reason to run them together is that they share knobs and disagree about them. Raising pH from 7.0 to 8.6 improves mild-steel corrosion, drives calcite from +0.41 to +1.86, drives hydroxyapatite from +4.75 to +10.76, and collapses active chlorine from 77.6% to 8.0%. Four outcomes, three vendors, one knob. Each vendor optimises their own and the plant lives with the sum — this console exists to show the sum.
| Output | Basis | Status |
|---|---|---|
| Saturation index | PHREEQC / Davies on published constants. Reproduces published solubilities it was never fitted to — gypsum, barite, celestite and amorphous silica all land inside 0.07 SI (worst case celestite, 0.069). This is the number to trust. | VALIDATED |
| LSI · RSI · PSI | Standard empirical formulae, calibrated for low-TDS water. We have not benchmarked these values against published worked examples — what we test is the guard that suppresses them above ~4000 mg/L TDS, outside which they mislead. Read them as the industry conventions they are, not as our result. The saturation index is the number to trust. | UNBENCHMARKED |
| Stiff & Davis · S&DSI | The high-salinity analogue of LSI (ASTM D4582), reported where LSI is suppressed above 4000 mg/L TDS — brine, seawater, RO concentrate. K is computed from PHREEQC’s activity coefficients, not read off the published chart: the chart was an approximation of exactly that, and digitising a 1952 nomograph would be guessing at a regulated number with no way to test it. The identity pH − pHs ≡ SI(calcite) closes to 0.000, because they are the same quantity — Stiff & Davis is LSI with a better K. So this adds no accuracy over the calcite SI already shown; it adds the form the industry reports in, valid where LSI is not. | VALIDATED |
| Fast engine | Davies reads high versus ion association — conservative, increasingly so as ionic strength rises. The Rigorous engine hands off to Pitzer the moment its Davies-computed I crosses 0.5 (Pitzer then reports a higher I on the same water, typically ~0.75); Davies is never carried above its own 0.5 convention ceiling, so it does not degrade silently into brine. Use Rigorous for brine and seawater. | BENCHMARKED |
| RO wall SI | Concentration polarisation applied (β, default 1.15). Scale forms at the membrane wall, not in the bulk. | MODELLED |
| Corrosion axis | Adsorption-centre proxy (N/S/aromatic). Real, but not fitted to any inhibition data. | UNCALIBRATED |
| Scale axis | Ca-binding density proxy. Also unfitted. It ranks threshold inhibitors only — molecules that poison crystal growth sub-stoichiometrically at 2–10 ppm. Neither axis sets dose. No wet-lab dose-response data exists behind it. | UNCALIBRATED |
| Calcium phosphate · hydroxyapatite | Reported whenever you enter a PO₄ residual. On a real phosphate programme (Ca 300, PO₄ 6 mg/L, pH 7.8) apatite reaches SI +8.2 against calcite’s +1.1 — the mild-steel inhibitor creates the most supersaturated phase in the tower, and the AA/AMPS dispersant is what holds it in suspension. Flagged kinetically slow: it forms through amorphous precursors over days, so a high SI means your dispersant is doing its job, not that scale is forming now. The thermodynamics is PHREEQC; the rate, and therefore the dispersant dose, is not modelled. | THERMO ONLY |
| Passivating inhibitors | Ortho- and pyrophosphate work by forming an iron-phosphate film, not by adsorbing a lone pair — which is all the corrosion axis measures. They therefore carry no score at all. A 0.0 would call the primary mild-steel inhibitor useless: the chelant error inverted. Pyrophosphate additionally hydrolyses back to orthophosphate in service, faster hot, so a pyro programme becomes an ortho programme and the phosphate risk rises with it — that reversion is disclosed, not modelled. | DISCLOSED |
| Halogen speciation | Acid-base equilibrium, exact. HOCl pKa temperature-corrected from Morris (1966) — reproduces 7.54 at 25 °C. HOBr uses 8.70 at 25 °C with no temperature correction: its T-dependence is not as well established, and inventing one would be worse than disclosing the basis. Only the undissociated acid is a strong biocide, which is why at pH 8.3 bromine is ~5.6× more active than chlorine. | VALIDATED |
| Halogen residual · demand | Predicted from measured demand and bulk decay (Standard Methods 2350) plus exact dilution. Without those constants we refuse and name the test — a default would reproduce the very failure this fixes and look authoritative doing it. The finding: on a fouled tower dilution is ~1% of the halogen loss, so holding time alone overstated the residual by roughly 80×, in the direction that says the biocide is still there when it is gone. This is what separates halogen control from scale dose-response: the constants are an afternoon’s bench work, not a year of field trials. | VALIDATED (CALIBRATED) |
| Dose for residual | Prescriptive, and defensible for a precise reason: the target comes from your own water management programme or HSG274 — never from us — and demand and decay come from a bench test, not a guess. The forward and inverse models are pinned to round-trip against each other. Dose-for-RESIDUAL only. Never dose-for-kill: that needs an efficacy constant which does not exist for biofilm organisms. | VALIDATED |
| Bio-dispersant slug window | How long blowdown must be suspended to hold a slug above its threshold for the contact time — exact dilution arithmetic, and the operational instruction nobody computes. Evaporation is ignored deliberately: it removes water and would concentrate the slug, so ignoring it errs conservative. This is the dosing, not the effect — a bio-dispersant is a penetrant with no concentration-versus-kill relationship, and whether the biofilm lifts is not modelled. | EXACT |
| Phosphorus ledger | The same conservative-tracer balance as the cycles balance, applied to phosphorus. Total P short of the tracer means it is depositing; ortho P above what you dosed means the oxidiser is destroying your phosphonate. Both at once means your oxidiser is manufacturing your scale. Every input is a routine test (Cl, total P, ortho P). Assumes steady dosing and a conservative tracer — heavy bleach dosing reduces to chloride and inflates the tracer, which is disclosed. A 5% band is treated as noise because no noise floor has been established against field data. | UNBENCHMARKED |
| Holding time index | Standard cooling-water arithmetic from the same mass balance the rest of Engine 1 uses: blowdown = evaporation/(cycles−1) − windage. It is a CEILING on contact time, never the contact time — an oxidiser is also lost to demand, sunlight and your own inhibitors, all faster than dilution. A non-oxidiser is not consumed by demand, so dilution is close to its whole loss path and HTI is close to real for it. | EXACT (a ceiling) |
| ASHRAE 188 register | Verification only. ASHRAE 188 separates verification (are we doing what we said?) from validation (is it working?). This register does the first. The bridge that makes it defensible: HSG274 names scale and deposit control AS a Legionella control measure, and that is precisely what Engine 1 computes — so we evaluate a measure the standard names against chemistry we compute exactly. The CFU action levels are deliberately NOT keyed in: guessing at a regulated figure is fabricating it, the same rule that stopped us digitising the Stiff & Davis nomograph. | VERIFICATION ONLY |
| Legionella prediction | Not attempted, and it will not be. Legionella lives in biofilm and inside amoebae, not in the bulk water this product models. Bulk free halogen → CFU has no validated mechanistic model; the literature is epidemiological association. ASHRAE 188, HSG274 and WHO are risk-management frameworks by deliberate choice. The failure is also asymmetric: a wrong saturation index costs money, while a false negative here gives someone a defensible-looking reason not to sample. | REFUSED |
| Mechanism separation | A chelant (citric acid, gluconate) sequesters calcium stoichiometrically — mol‑for‑mol, hundreds of ppm — and is not an antiscalant at antiscalant doses. It binds calcium well and so scores well on binding density, which is why it is ranked on its own axis and never against a threshold inhibitor. Ranked together, citric acid (59.5) outranked polyacrylic acid (47.6), which would be a two-order-of-magnitude dosing error. | ENFORCED |
| Cycle limit · limiting salt | Bisection on the same PHREEQC saturation the rest of Engine 1 uses. The thermodynamics is validated; the practical SI ceilings it bisects against (calcite +2.5 on antiscalant, gypsum 0.0) are industry convention, not measurements — vendor-dependent and unfitted. Kinetically inhibited phases are excluded, or dolomite would limit every water. | MIXED |
| Sensitivity | Each input perturbed, the limiting phase re-solved. Deterministic arithmetic on a validated engine — it inherits the SI's accuracy exactly and adds no assumption of its own. | VALIDATED |
| Cycles balance · deposition rate | Mass balance against a conservative tracer (Cl, EC). The arithmetic is exact and the method is standard practice, but it assumes stable makeup, that nothing else removes the ion, and honest sampling — real towers break all three. No noise floor has been established against field data, so a small shortfall is not yet distinguishable from analytical scatter. The one output here that is a rate, not a tendency. | UNBENCHMARKED |
| Program cost | Water and blowdown are arithmetic; acid is stoichiometric and ignores corrosion risk. The antiscalant line assumes a 5 ppm dose that nothing in this product justifies — thermodynamics does not set a dose. Its ranking is indicative only, and it is labelled LOW in the panel. | PART ILLUSTRATIVE |
- Polymers are scored per repeat unit, using attachment points rather than an arbitrary chain length, so the score no longer moves with how many units you happen to draw. They are now rankable against each other — but the axis is still uncalibrated, and a real antiscalant's performance also depends on molecular weight and distribution, which a repeat unit cannot express. Draw your own polymer with end caps and the old dilution effect returns; use
[*]attachment points. - The practical SI limits are borrowed, not measured. The Intelligence tab’s cycle limit bisects against ceilings that are industry rules of thumb (calcite +2.5 on antiscalant). They are uncalibrated and vendor-dependent. Today this shows: sepiolite currently limits ordinary municipal water at about 3 cycles, while real plants run 5–6 — so either that ceiling is wrong or sepiolite is kinetically slow like dolomite. We do not have the data to say which. Field dose-response data is exactly what replaces these numbers.
- Kinetics are not modelled anywhere. Every index is a tendency. Talc and chrysotile are deliberately not reported even though they are supersaturated in ordinary cooling water — they cannot form at these temperatures, and a permanent alarm on a phase that never appears teaches you to ignore the panel. Dolomite is reported but is famously slow to nucleate; treat it as a long-term indicator, not a today problem.
- A treatment programme is not modelled — only its molecules are. A real cooling programme couples a mild-steel passivator, a yellow-metal azole, a scale inhibitor, a dispersant polymer and two biocides, and the interactions dominate: chlorine degrades tolyltriazole; an oxidiser degrades phosphonates to orthophosphate, which raises the calcium-phosphate risk the dispersant then has to absorb. The couplings are now named on the Microbial control tab, but none of them are given a rate — that would need kinetic constants that do not exist. Biocides are absent entirely and deliberately — nothing in a saturation model speaks to microbiology, and scoring them would invent a third meaningless axis.
- Copolymer composition is inexpressible. An AA/AMPS dispersant is defined by its molecular weight and its sulfonation level, which set its calcium tolerance. We score the AMPS comonomer alone, so neither is expressible — the same limit as the repeat-unit scoring above.
- No dose recommendation. Nothing here tells you how much inhibitor to feed.
- A visible gap is a feature, not a failure. Where PHREEQC will not converge — at absurd concentration, or a charge balance too broken to speciate — the point appears as a gap in the chart, never as a plausible wrong number. The engine refusing to answer is the most important thing it does; a model that always returns a number is the one to distrust.
Questions about Waalgo, the models, or a pilot? Leave a note and it goes straight to the team's inbox.