Alerting more than one person, and what happens when nobody answers
By Vimal Bhaya, Founder and Lead Systems Architect · Last reviewed 3 September 2026
This is a continuation of The alerting problem, a 5-part tutorial. You are on part 4 of 5.
An alert that nobody reads is not an alert. It is a log entry that will be read out to you afterwards, by somebody explaining how the loss happened.
A single-recipient system is one holiday, one flat battery or one deep sleep away from being worth nothing. The fix is not a louder alarm. It is a second and third person, reached by a different route, only when the first one does not answer.
TemperatureWise sends email to as many people as you like, then SMS and WhatsApp, then a phone call. The rules are set separately on every sensor, so the freezer holding your stock can wake three people while the dry store sends one email.
The failure mode nobody specifies for
Buyers compare sensor accuracy, battery life and price. Almost nobody asks what happens if the first person does not pick up, and that is the step where the money is actually lost.
The equipment failure is the easy part. It is detectable, and a decent system will catch it. The hard part is the twenty metres between a correct alert and a human being who is awake, sober, on shift and holding a phone that is not on silent.
Here is an operator describing the most-recommended product in this category, on a thread where three separate people had just recommended it:
"Thermoworks is an option. Negatives are: It can only be linked to one phone for notification. If there's a power/WiFi outage, it needs to be relinked."
Operator, r/restaurantowners
We have not tested that ourselves, so treat it as one user's report rather than a spec, and check the current documentation before you buy anything. But the shape of the complaint is what matters, and it is not unique to one brand. Plenty of systems in this price range assume one account, one phone, one person.
That assumption is fine at 2pm on a Tuesday. It is worthless at 3am on a bank holiday.
What Boxing Day looked like
One of our own sites makes the point better than an argument can. A frozen smoothie brand in Mississauga stores production stock in a stationary reefer trailer, holding somewhere between $100,000 and $125,000 of frozen inventory.
Read the gap between the second and third markers. The alert went out at about 4pm, while the trailer was at 10.9°F (-11.7°C) and everything inside it was still fine. The 17.6°F (-8°C) safety line was not crossed until about 9:45pm.
That is five and three quarter hours of runway. Which sounds generous, until you ask who was holding the phone.
It was Boxing Day. Nobody was on site, and nobody was going to be. Five hours of runway is only worth something if it reaches somebody within five hours, and on 26 December the chance of any one specific person picking up is not high.
The detection was never the risky part. The delivery was.
The ladder
Escalation means the alert gets louder and more intrusive only when the earlier, quieter version has been ignored. Three levels, in order.
- Level one, email. Unlimited recipients. This is the wide net, and it costs nobody anything to be on it. Send it to the site lead, the ops manager, the owner and the maintenance contractor if you want.
- Level two, SMS and WhatsApp. Up to three numbers per sensor. This is for people you are willing to interrupt.
- Level three, a phone call. The same three numbers, dialled in order until somebody picks up. A ringing phone is the only channel that reliably beats a sleeping human, which is exactly why it must be last.
The ordering is the whole design. If everything came in as a phone call, the phone calls would stop working within a fortnight, because people mute what wakes them for nothing. The ladder exists so that the loudest channel stays rare enough to still mean something.
Per-sensor rules, and why that matters more than it sounds
The routing is set on each piece of equipment, not once for the whole account. It is the difference between a system people keep and a system people switch off.
| Equipment | What is in it | SMS | Phone call | |
|---|---|---|---|---|
| Walk-in freezer | $150,000 of finished goods | Everyone | Site lead, ops manager | Site lead, ops manager, owner |
| Prep cooler | Two days of production | Kitchen team | Site lead | Off |
| Dry store | Ambient goods | Site lead | Off | Off |
Nobody should be woken at 3am for the dry store. If your system cannot express that, everybody eventually turns their notifications off, and then the walk-in freezer is unmonitored too. Blanket alerting does not produce more vigilance. It produces less.
What the ops manager gets out of it
The argument for escalation is usually made as insurance, which undersells it. The bigger day-to-day benefit is that it takes work off the person at the top.
Without escalation, the only safe policy is to copy the senior person on everything, because they are the backstop. That person then receives every defrost, every door event and every routine notice from every box on every site. Within a month they are filtering the lot to a folder, and the backstop is gone.
With escalation, the senior person only appears on level two and level three. They hear about a freezer when the person closest to it has already had a chance and did not take it. That is a handful of interruptions a year instead of a hundred a month, and each one is real.
It is the same reason an on-call rota exists in any other operation. The point is not that more people are watching. The point is that responsibility is allocated, so most alerts are somebody's job and only a few are everybody's problem.
This only works if the alerts themselves are worth reading, which is a separate problem covered in what a good alert looks like at 3am, and in why temperature alarms cry wolf. Escalating a stream of false alarms just distributes the noise.
Questions worth asking any vendor
These are the ones that separate a real escalation feature from a checkbox on a comparison table. Ask them before you sign, and ask for the answer in writing.
- How many people can receive an alert, by each channel, and is it capped per account or per sensor
- Can the recipient list differ between two pieces of equipment on the same site
- What triggers the escalation to the next level, and how long is the gap
- Can somebody acknowledge an alert to stop the escalation, and can everybody see who did
- If the site loses power or internet, does the system tell anybody, or does it just go quiet
- After an outage, does the hardware reconnect on its own, or does somebody have to re-pair it
That last pair matters more than the rest put together. A monitoring device that goes silent during a power cut, and stays silent until a human notices, has failed at the precise moment it was bought to cover. It is the most common complaint in the threads we track, across every brand.
Our own answer, since it would be poor form to ask and not say: a backup mini-inverter is $125 once, on top of the cellular package. With it the link stays up through an outage, the record has no gap in it, and nothing needs re-pairing by hand afterwards. Without it we go quiet like everybody else. The costs are set out on the TemperatureWise page.
