01Device interfaces, identity, provisioning, and retirement
Provide a sensor, actuator or gateway with exact hardware and firmware revisions, a manufacturing or field bootstrap path, unique identity, multiple trust states, constrained storage, key rotation, ownership transfer, factory reset, lost-device response and retirement. Ask what each component can prove and who may change it.
Confirm: The person starts from schematics, datasheets, firmware interfaces, physical failure modes and named safety owners; separates hardware identity, device identity, user identity and workload identity; avoids shared fleet credentials; defines bootstrap trust, unique credential issuance, attestation only where evidence and threat justify it, scoped authorization, secure storage, expiry, rotation, revocation and recovery; binds registry records to hardware and firmware identity without treating names as proof; limits debug and manufacturing authority; records ownership and lifecycle states; and makes reset, transfer, quarantine, data erasure, key destruction and retirement testable without exposing production secrets.
02Constrained connectivity, protocol semantics, and trustworthy data
Provide intermittent links, roaming or changing gateways, limited power and bandwidth, MQTT or CoAP semantics, delayed reordered duplicated and lost messages, retained state, session expiry, backpressure, clock drift, malformed payloads, schema evolution, calibration changes and one unavailable dependency. Ask what the receiver can safely conclude.
Confirm: The person chooses transport, session and application behavior from measured constraints rather than brand preference; states what MQTT QoS, sessions, retained messages, wills or CoAP request and observe behavior do and do not guarantee; adds application identifiers, deduplication and idempotency where business effects require them; bounds retry, reconnect, buffering and expiry; authenticates and authorizes clients and resources; validates topic or resource paths, payload size, type, unit, range, schema version and device entitlement; separates device event time, gateway receipt time and server processing time; preserves quality, calibration, uncertainty and missing-data signals; handles clock loss and wrap; and prevents a late or duplicate measurement from silently becoming current truth.
03Backend state, command safety, data lifecycle, and tenancy
Provide physical, local, reported, desired and application state; an operator command with eligibility, authorization, expiry and safety constraints; device disconnects during execution; retries from two clients; delayed acknowledgements; tenant boundaries; sensitive telemetry; retention and deletion duties. Ask which state is authoritative at every step.
Confirm: The person models state explicitly instead of collapsing a digital twin into physical truth; records version, provenance, freshness and uncertainty; keeps desired state as intent and reported state as a device claim; makes commands distinct from configuration and telemetry; validates actor, tenant, target, current eligibility, policy, preconditions, expiry, nonce or correlation, idempotency and rate limits before dispatch; requires device-side safety checks and interpretable acknowledgement states without moving physical safety into the cloud; reconciles unknown outcomes after disconnect; applies least privilege to brokers APIs stores jobs and indexes; separates tenants in identity policy queries telemetry and support tooling; encrypts appropriate paths while treating key custody separately; and implements minimization, purpose, access, retention, deletion, export and audit requirements from named authorities.
04Fleet inventory, signed updates, observability, and recovery
Provide mixed hardware and firmware revisions, one vulnerable component, a signed update manifest, partial downloads, low power, interrupted install, bad rollout, unreachable devices, lost credentials, stale inventory, a field incident and a receiving team. Ask how the exact target set is known, limited, observed, stopped and restored.
Confirm: The person preserves hardware software configuration identity and ownership inventory with known freshness; links source, toolchain, component record, manifest, signature, image hash, compatibility and rollout policy; separates author and operator authority; checks model revision dependencies version sequence and rollback policy before install; supports authenticated download, resume, protected staging, atomic transition where the device permits it, boot confirmation and independent recovery; targets cohorts and canaries, sets health gates, rate limits and abort criteria, and treats a job record as intent until device evidence confirms the result; correlates device gateway broker service data and operator events through traces metrics logs and bounded identifiers; handles offline and permanently unreachable units explicitly; rehearses revocation quarantine rollback re-provisioning replacement and retirement; and leaves runbooks and access boundaries another owner can execute.