---
title: 'Metering Bypass (node)'
description: Single-node metering-bypass suspicion score (0-100) with patterns, formulas, evidence confidence, legal readiness and a field-visit checklist.
section: AI Analytics
weight: 7
related:
  - ai-analytics/fleet-reports/suspicious-nodes
  - ai-analytics/node-reports/consumption-analytics
  - ai-analytics/fleet-reports/metering-bypass-fleet
---

import Alert from '@/components/docs/Alert.astro';
import Image from '@/components/docs/Image.astro';

The **Metering Bypass** report performs a formalised analysis of **a single metering node** over a selected period, with the goal of detecting signs of possible under-metering, substitution of the measuring channel, incorrect sensor behaviour or other events that require attention from the metering service. It relies on the same standards that govern gas metering: ISO 5167 (orifice plates), ISO 6976 (calorific value), EN 12405-1 (electronic gas-volume conversion), OIML R 137 (gas meters), OIML R 140 (measuring systems for gaseous fuel) and EN 1359 (diaphragm meters).

## Report purpose

<Image src="/images/ai-analytics/metering-bypass/01_hero_block.svg" alt="Report header" />

*Report header.* The first thing the reader sees: the node identifier, the device identifier, the corrector type, the covered period, the generation time, the final suspicion score and its textual severity. The score on its own proves nothing — it is a composite indicator that must always be read together with the six neighbouring indicators (see the investigation summary below).

The report **is not a formal statement** of violation. It does not establish the fact of theft, does not replace a field inspection and is not a legal opinion. Its job is to describe suspicious patterns mathematically and metrologically, show the confidence of the sources, set the inspection priority and give the field crew a clear list of what to check on site.

The report answers the following questions:

- are there `Q≈0` periods in the hourly archive that look atypical;
- was the pressure channel `P` stuck at a substitution or near-constant value;
- did the temperature `T` change while the pressure stayed still;
- was there a sharp recovery of `Q` and `P` after a zero period;
- are there matches with the abnormal-events archive;
- are there direct device signals: physical access, parameter change, reset, clock change;
- how complete are the data sources;
- can the suspicion be considered confirmed;
- is a field visit needed and at what priority;
- what potential scale of unmetered volume requires verification;
- which alternative hypotheses must be ruled out before any conclusion about tampering.

<Alert type="warning">
The report shows **a suspicion score**, not proof of tampering. A high score means a mathematical or event-based pattern has been found that requires verification. A legal conclusion is possible only when the evidence base is sufficient: device logs, passport, field inspection, photo documentation, seal check and a formal act.
</Alert>

## Target audience

| Role | What they get from the report |
|---|---|
| Head of the metering service | overall suspicion level, evidence confidence, legal readiness, field-visit priority |
| Metrologist | check of the `Q/P/T` channels, the `P_const` regime, applicability of the physical model, passport gaps |
| Telemetry engineer | link with the sessions archive, completeness of sources, suspicious gaps |
| Field crew | top windows for inspection and the inspection checklist |
| Compliance service | list of suspicious patterns, device events and alternative hypotheses |
| Billing analyst | indicative exposure volume as the scale of the potential blind spot |
| Utility-company lawyer | base for preparing a formal act once hard evidence is confirmed |

## What the report must NOT do

The report must not:

- automatically accuse a consumer of metering bypass;
- call the computed exposure a confirmed loss;
- treat zero flow as a violation without checking the operating regime;
- treat a stuck sensor as proof of tampering;
- apply Gay-Lussac's law without checking its physical applicability;
- treat `P=100 kPa` as illegal without the passport and the `P_const` regime;
- raise legal readiness based on an AI comment alone;
- form a conclusion about tampering when the hourly archive is missing;
- replace a field act with an automatic score.

## Key terms

| Term | Meaning |
|---|---|
| `Q` | hourly gas flow, m³/h |
| `P` | pressure, kPa |
| `T` | gas temperature, °C |
| `Q≈0` | flow below the near-zero threshold |
| `P_default` | pressure close to a substitution value: e.g. 100, 101.325, 103, 105 or 0 kPa |
| `P_stuck` | pressure barely changes during the period |
| `zero-flow run` | a continuous period where flow is near zero |
| `recovery` | sharp return of flow and/or pressure after a zero period |
| `event` | a detected window of a suspicious pattern |
| `severity` | strength of the indicator: `low` / `medium` / `high` / `high_plus` |
| `pattern score` | mathematical suspicion score based on archive patterns (0..100) |
| `event score` | score based on direct or classified device events (0..100) |
| `final score` | overall suspicion score, `max(pattern, event)` |
| `evidence confidence` | completeness of the evidence base |
| `legal readiness` | readiness for a legally meaningful conclusion |
| `field priority` | field-visit priority `P0..P3` |
| `exposure` | estimated potentially unmetered volume, not a proven loss |
| `hard evidence` | direct proof: housing breach, parameter change, archive reset, confirmed device event, formal act |

## Overall report logic

The overall logic of the report is built in several layers:

```text
Hourly archive Q/P/T
→ search for zero-flow periods
→ pressure channel P check
→ temperature T check
→ recovery check after a zero window
→ check of additional patterns
→ matching against the device log
→ pattern score computation
→ event score computation
→ severity cap limitation
→ evidence confidence evaluation
→ legal readiness
→ field priority
→ exposure estimate
→ root cause matrix
→ field-visit checklist
```

It is essential that the report separates:

1. **statistical pattern** in the hourly archive;
2. **device event** in the corrector log;
3. **source confidence**;
4. **legal readiness**;
5. **field inspection**.

Each of the five layers is evaluated independently. A high score on one of them does not raise the readiness for action on another. For example, score=100 with no device events and no field visit may stay `partial` on legal readiness and `P1` on field priority.

## Input data

### Mandatory data

| Source | Purpose |
|---|---|
| Hourly archive `Q/P/T` | main source for pattern search |
| Analysis period | window bounds |
| Node and device identifiers | linking the result to a specific object |

Without the hourly archive the report can only show absence of data, and must not build a full suspicion conclusion.

### Desirable data

| Source | Purpose |
|---|---|
| Communication-sessions archive | check whether the node was online during events |
| Abnormal-events archive | search for hard evidence: housing breach, reset, parameter_change |
| Corrector passport | check legality of `P_const`, Qmin/Qmax, pulse weight |
| Field inspection | confirmation of seals, pipework layout, actual regime |
| Corrector display photo | record of `Q/P/T/V`, date, time, regime |
| External-meter readings | reconciliation of the accumulated volume |

### Minimum reliable period

A period shorter than 30 days automatically downgrades the evidence-base confidence by one level: `high → medium`, `medium → low`. A reasonable minimum is 90 days; the recommended period is 366 days (one year gives seasonality for all patterns).

## Evidence map

<Image src="/images/ai-analytics/metering-bypass/12_evidence_map.svg" alt="Evidence map" />

*Evidence map.* Which data sources were used for scoring and how complete they are. The more green "OK" marks, the higher the confidence in the evidence. Each source has a weight in the evidence-confidence formula, and a `partial` or `missing` status lowers the resulting percentage.

| Source | Status | Weight in evidence |
|---|---|---:|
| Hourly archive Q/P/T | ok / partial / missing | 3 |
| Communication-sessions archive | ok / partial / missing | 2 |
| Abnormal-events archive | ok / partial / missing | 3 |
| Corrector passport | ok / partial / missing | 1 |
| Field inspection | ok / partial / missing | 3 |

### Source confidence formula

Let:

- `w_i` — weight of the source;
- `s_i` — source status coefficient.

Statuses:

$$
s_i =
\begin{cases}
1, & status_i = ok \\
0.5, & status_i = partial \\
0, & status_i = missing
\end{cases}
$$

Then the overall source-confidence percentage is:

$$
EvidenceSourcePct =
\frac{\sum (w_i \times s_i)}{\sum w_i} \times 100\%
$$

### Evidence confidence interpretation

| EvidenceSourcePct | Evidence confidence |
|---:|---|
| ≥ 70% | high |
| 35–70% | medium |
| < 35% | low |

<Alert type="warning">
Even `high evidence confidence` does not mean automatic confirmation of tampering. It only means that the sources are sufficient for a more confident investigation.
</Alert>

## Zero-flow period

Most signs in the report start with the search for periods where the flow is near zero.

### Near-zero threshold

Baseline threshold:

$$
Q_{nearzero} = 0.5 \; m³/h
$$

An hour is considered zero if:

$$
Q_h \le Q_{nearzero}
$$

### Minimum duration

A zero period becomes a candidate for analysis if it lasts at least:

$$
H_{zero\_run} \ge 6 \; hours
$$

That is:

```text
Q≈0 continuously for 6 hours or more
```

### Why exactly 6 hours

The 6-hour threshold avoids reacting to short operational pauses, random idle periods or single zero points. For a bypass or substitution pattern, what matters is not isolated zeros but a steady window in which the flow is absent while the other channels behave suspiciously.

Empirically, 6 hours covers most real "night shutdown → morning restart with substitution" patterns without false positives on lunch breaks or short planned stops at industrial sites.

## Substitution pressure P_default

One of the key indicators is pressure close to typical substitution values.

### Substitution values

| Group | Values |
|---|---|
| Atmospheric / contractual | 100.0, 101.325, 103.0, 105.0 kPa |
| Zero / disconnected sensor | 0.0 kPa |

### Tolerance

For atmospheric and contractual values:

$$
Tolerance_{atm} = 0.5 \; kPa
$$

For the zero value:

$$
Tolerance_{zero} = 0.3 \; kPa
$$

### Closeness formula

Pressure is considered close to the substitution value if:

$$
|P_{mean} - P_{default}| \le Tolerance
$$

where:

- `P_mean` — average pressure inside the zero window;
- `P_default` — one of the substitution values.

### Important limitation

`P_default` **is not proof of violation on its own**. It may be:

- a legal `P_const` regime;
- a device setting used when the sensor is absent;
- an emergency fallback value;
- a consequence of sensor disconnection;
- a particular feature of the corrector model.

That is why the passport is required for any conclusion:

```text
Check: is P_const allowed, what value of P_const is set, why it was applied.
```

## Stuck pressure channel P_stuck

### Standard deviation of pressure

Within the zero window, the standard deviation of pressure is computed:

$$
\sigma_P =
\sqrt{
\frac{1}{n-1}
\sum_{i=1}^{n} (P_i - \overline{P})^2
}
$$

The pressure channel is considered stuck if:

$$
\sigma_P < 0.1 \; kPa
$$

### Temperature change

For the physical check, the temperature in the window must change noticeably:

$$
\Delta T = max(T_i) - min(T_i)
$$

Condition:

$$
\Delta T \ge 1^\circ C
$$

If the temperature barely changed, it is impossible to say with confidence whether `P` should have changed.

## Gay-Lussac law check

### Physical formula

For a closed volume of gas with a constant amount of substance:

$$
\frac{P}{T_K} = const
$$

where:

$$
T_K = T_C + 273.15
$$

Given initial values:

$$
P_{expected,i} = P_1 \times \frac{T_{K,i}}{T_{K,1}}
$$

Expected pressure change:

$$
\Delta P_{expected} =
max(P_{expected,i}) - min(P_{expected,i})
$$

### Comparison with the actual change

Actual pressure variability is assessed via the standard deviation or the range:

$$
P_{std} = \sigma_P
$$

or:

$$
\Delta P_{actual} = max(P_i) - min(P_i)
$$

If:

$$
\Delta P_{expected} \gg \Delta P_{actual}
$$

and at the same time:

$$
\sigma_P < 0.1 \; kPa
$$

then the pressure channel is treated as suspiciously stuck.

### Divergence coefficient

For the report explanation the following ratio can be used:

$$
K_{GL} =
\frac{\Delta P_{expected}}{max(\sigma_P, \varepsilon)}
$$

where `ε` is a small constant to guard against division by zero.

If `K_GL` is large, the report states that the expected pressure change is many times greater than the actual variability.

### Important physical limitation

Gay-Lussac's law is applicable only to a **closed volume of gas**.

It is not applicable or only partly applicable if:

- the node is connected to the grid;
- the pressure is maintained by a regulator;
- the upstream/downstream is open;
- the pressure is gauge, not absolute;
- the passport specifies a `P_const` regime;
- the volume is not isolated;
- the pressure sensor rounds or filters values.

<Alert type="warning">
A violation of the Gay-Lussac model is not standalone proof of tampering. It is a physical heuristic whose applicability must be verified.
</Alert>

## Catalogue of detected patterns

<Image src="/images/ai-analytics/metering-bypass/03_methodology_table.svg" alt="Methodology table" />

*Methodology table.* All nine indicators the report can search for, with their formal condition, severity level (low / medium / high / very_high) and a clickable "triggered in this report" mark. The table immediately shows which indicators triggered on the given node, and lets you jump straight to the event card.

### Substitution of P with a default value

Formal condition:

$$
Q \approx 0 \; for \; H \ge 6h
$$

and:

$$
\sigma_P < 0.1 \; kPa
$$

and:

$$
P_{mean} \in P_{default}
$$

and:

$$
\Delta T \ge 1^\circ C
$$

Meaning: pressure sits at a typical substitution value during a long zero-flow period. This may indicate substitution of the pressure channel, but may also be a legal `P_const` regime.

### Stuck pressure channel P (Gay-Lussac violation)

Formal condition:

$$
Q \approx 0 \; for \; H \ge 6h
$$

$$
\sigma_P < 0.1 \; kPa
$$

$$
\Delta T \ge 1^\circ C
$$

and the Gay-Lussac model shows that the expected pressure change should be noticeable.

Meaning: temperature changes but pressure is almost still. This may indicate a stuck pressure channel, the `P_const` regime, a grid regulator or substitution of the measuring channel.

### Synchronous Q+P jump after a zero period

Formal condition:

There is a zero period:

$$
Q \approx 0 \; for \; H \ge 6h
$$

and after it ends, within a window of:

$$
\pm 2 \; hours
$$

the following is recorded:

$$
Q_{recovery} \ge 10 \; m³/h
$$

and:

$$
\Delta P_{recovery} \ge 20 \; kPa
$$

Meaning: after a long zero, both flow and pressure are restored simultaneously. This may indicate that metering has resumed after a regime switch, but may also be a normal technological start-up.

### Gap in the archive with successful communication sessions

Formal condition:

There is a gap in the hourly archive:

$$
H_{gap} \ge 24h
$$

and in the same window there were successful communication sessions:

$$
FailRatio < 30\%
$$

Meaning: the node was online, but the hourly archive was not delivered or recorded. This looks more like a delivery, export, parsing or integration issue than a physical bypass of metering.

### Too-flat Q and P (plateau)

Formal condition:

The period lasts:

$$
H \ge 24h
$$

flow is non-zero:

$$
\overline{Q} > 1 \; m³/h
$$

flow is too flat:

$$
\frac{\sigma_Q}{\overline{Q}} < 0.02
$$

pressure is almost stuck:

$$
\sigma_P < 1 \; kPa
$$

Meaning: a very flat curve can be normal for some technological processes, but it can also indicate a synthetic or substituted profile.

### Night Q=0 at warm temperature

Formal condition:

In night hours:

$$
02:00 \le hour \le 05:00
$$

flow equals zero:

$$
Q \approx 0
$$

temperature is above the threshold:

$$
T > 15^\circ C
$$

and this happens on at least 5 nights.

Meaning: weak indicator. For schools, offices, seasonal sites and residential buildings, zero night-time flow can be the norm.

### Pressure jumps without flow

Formal condition:

At least 3 occurrences:

$$
|\Delta P_h| \ge 30 \; kPa
$$

with:

$$
Q_h < 5 \; m³/h
$$

Meaning: strong pressure jumps with no matching flow may point to a sensor fault, a telemetry artefact or a manual channel edit.

### Long run of identical Q values

Formal condition:

The flow stays identical for:

$$
H \ge 48h
$$

within:

$$
|Q_i - Q_{run}| \le 0.001 \; m³/h
$$

Meaning: natural flow normally has noise and variability. Long-running identity may indicate a constant, a transmission error or a disconnected flow sensor.

### Recoveries only during business hours

Formal condition:

There are at least 3 recovery events, and the share of recoveries during business hours is:

$$
Share_{business} \ge 70\%
$$

Business hours:

$$
09:00 \le hour < 17:00
$$

and the day of the week is a weekday.

Meaning: if metering recovery often happens only during business hours, this may indicate manual maintenance, operator visits or regime actions. But it is not proof of tampering.

## Data-quality pre-filters

Before interpreting tampering patterns, the report must rule out obvious artefacts.

### Physically impossible pressure

If:

$$
P > 500 \; kPa
$$

for a low- or medium-pressure node, this may be a telemetry artefact.

Such points must not inflate suspicion.

### Flow spike

A flow spike can be treated as an artefact if:

$$
Q_h > 20 \times median(Q)
$$

and at the same time:

$$
Q_h > 1000 \; m³/h
$$

Such a point may be a totalizer dump, a transmission error or an archive reset.

### Broken P sensor

If the pressure channel is stuck for:

$$
H_{Pstuck} \ge 168h
$$

then P-dependent tampering detectors must be turned off or marked as non-evidential.

This means:

```text
Issue: metrological reliability of the P sensor.
Not a conclusion: proof of bypass.
```

### Network node where Gay-Lussac is not applicable

If:

$$
median(P) < 10 \; kPa
$$

and:

$$
\sigma_P < 2 \; kPa
$$

and the sensor is not deemed broken, the node may be a low-pressure grid object where pressure is held by a regulator.

In that case GL-dependent indicators must be downgraded or excluded from scoring.

## Severity levels and probability weights

Every triggered indicator is assigned a strength level.

| Severity | Probability weight `p_i` |
|---|---:|
| info | 0.00 |
| low | 0.10 |
| medium | 0.30 |
| high | 0.50 |
| high_plus | 0.65 |

These values **are not the probability of a legal violation**. They are internal weights for combining independent indicators.

## Composite suspicion score

### Why not a simple sum

If we simply summed all indicators, a node with many weak events would receive an excessively high score. Therefore a multiplicative logic of independent signals is used.

### Formula

For each event the weight `p_i` is taken according to its severity.

Probability that none of the indicators points to suspicion:

$$
P_{none} =
\prod_{i=1}^{n}(1 - p_i)
$$

Then the combined estimate is:

$$
P_{combined} =
1 - \prod_{i=1}^{n}(1 - p_i)
$$

Score:

$$
SuspicionScore =
100 \times P_{combined}
$$

or, expanded:

$$
SuspicionScore =
100 \times \left(1 - \prod_{i=1}^{n}(1 - p_i)\right)
$$

### Example

Suppose there are two events:

- medium: `p=0.30`;
- low: `p=0.10`.

Then:

$$
P_{combined} = 1 - (1-0.30)(1-0.10)
$$

$$
P_{combined} = 1 - 0.70 \times 0.90 = 0.37
$$

$$
SuspicionScore = 37
$$

### Events excluded from the score

Some events may appear in the report but not participate in the score:

- informational events;
- events with non-applicable physics;
- events suppressed by a quality gate;
- grid GL events;
- events explained by a broken sensor.

## Severity cap

Even if the score comes out high, the final textual level must not be inflated when all the events are weak.

### Cap matrix

| Composition of events | Maximum level |
|---|---|
| has `high_plus` | very_high |
| has `high` | high |
| has 2 or more `medium` | high |
| has 1 `medium` | medium |
| only `low` | medium |
| only `info` | low / no suspicion |

### Why the cap is needed

The cap protects the report from a situation in which many weak events produce a very high mathematical score while the evidential value of each event remains low.

Example:

```text
Score = 100
But there are no high/high_plus events.
Final level: medium.
```

## Event score — device events

The report takes into account not only the Q/P/T statistics but also the device events.

### Device-event classes

| Class | Meaning |
|---|---|
| `physical` | physical access, housing breach, clock change, access events |
| `substitution` | indications of substitution or change of the measuring regime |
| `metrology` | metrological deviations |
| `system_error` | system errors of the device |
| `comm` | communication events |
| `other` | other events |

### Why the event score can dominate

Device events can be more reliable than statistical heuristics. For example:

- housing breach;
- parameter change;
- reset;
- archive reset;
- date/time change;
- password/default access;
- parameter_change.

If such events exist, the final score may be driven by them even when the statistical score is lower.

### Important limitation

Not every device event is direct proof of tampering.

For example:

- metrological deviations may be regular;
- abnormal-event summaries require decoding;
- repeated RAISE/CLEAR must be grouped;
- "flow = 0" may be normal operation.

## Final score and Root Cause Matrix

<Image src="/images/ai-analytics/metering-bypass/11_device_events_matrix.svg" alt="Final score and hypothesis matrix" />

*Final score and hypothesis matrix.* The block shows which of the two layers (statistical pattern or event score) drove the final score, and immediately offers a root-cause matrix with alternative hypotheses. All hypotheses except "bypass" are checked on site. The final root cause is set only after the field visit and decoding of the abnormal-events log.

The final score must take both layers into account:

```text
statistical pattern score
device event score
```

One of the principles:

$$
FinalScore = max(PatternScore, EventScore)
$$

If `EventScore` is higher, the report must explain:

```text
The final score is driven by direct or classified device events.
The statistical detector gave a lower score.
```

If `PatternScore` is higher, the report must explain:

```text
The final score is driven by a repeated Q/P/T pattern.
Direct device signals are insufficient.
```

## Evidence confidence

Evidence confidence reflects not the strength of suspicion but **the completeness of the evidence base**.

### Formula

The source map is used:

| Source | Weight |
|---|---:|
| Hourly archive | 3 |
| Sessions | 2 |
| Device events | 3 |
| Passport | 1 |
| Field visit | 3 |

Source status:

$$
s_i =
\begin{cases}
1, & ok \\
0.5, & partial \\
0, & missing
\end{cases}
$$

Overall percentage:

$$
EvidenceConfidencePct =
\frac{\sum w_i s_i}{\sum w_i} \times 100\%
$$

### Levels

| Percentage | Level |
|---:|---|
| ≥ 70% | high |
| 35–70% | medium |
| < 35% | low |

### Important interpretation

- `Suspicion score` answers: **how strong the pattern is**.
- `Evidence confidence` answers: **whether sources are sufficient for a confident conclusion**.
- `Legal readiness` answers: **whether a legally meaningful conclusion can be made**.

These are three different scales, and one cannot be derived from another.

## Investigation summary: seven scales

<Image src="/images/ai-analytics/metering-bypass/02_investigation_summary.svg" alt="Investigation summary" />

*Investigation summary.* Right under the report header — seven indicators that **are read together**, not separately. For example, Pattern Score = 100 with Evidence Confidence = 58% and Confirmed Tampering = "—" means: mathematically the node looks very suspicious, but there is not yet enough evidence for a formal act — a field visit is needed.

Each of the seven scales has its own meaning, formula and sources:

| Scale | What it shows | Source |
|---|---|---|
| Pattern Suspicion | strength of the mathematical indicators | hourly archive |
| Evidence Confidence | completeness of the evidence base | source map |
| Confirmed Tampering | fact of tampering (juridical) | field act + hard events |
| Legal Readiness | readiness for legal action | confidence + hard events |
| Field Priority | visit urgency | score + confidence + recency |
| Metrology Reliability | reliability of physical assumptions | passport + sensors |
| Data Integrity Risk | integrity of sources | archives + sessions |

## Legal readiness

Legal readiness is the assessment of whether the conclusion is ready for a legally meaningful action.

### Possible statuses

| Status | Meaning |
|---|---|
| `not_ready` | not enough evidence |
| `partial` | strong indicators exist, but confirmation is needed |
| `ready` | enough evidence for a formal act or formal action |

### Conditions for `not_ready`

```text
statistical patterns only
and no field visit
and no hard device evidence
and the passport is incomplete
```

### Conditions for `partial`

```text
there are substitution events
or evidence confidence is high
or there is a field visit but some sources are missing
```

### Conditions for `ready`

`ready` is possible only if the evidence base is sufficient. Examples:

- a hard physical event in the device log;
- confirmed housing breach;
- confirmed parameter change;
- field visit + device events;
- formal photo documentation;
- proven illegal `P_const` / `parameter_change`.

<Alert type="warning">
Legal readiness must not become `ready` solely because of a high pattern score. With no hard evidence and no field visit, the status must stay `not_ready` or at most `partial`.
</Alert>

## Field priority

Field priority defines the urgency of the visit.

### Possible levels

| Priority | Meaning |
|---|---|
| `P0` | urgent, today / 24–48 hours |
| `P1` | visit within a week |
| `P2` | planned check |
| `P3` | monitoring |

### Matrix

| Condition | Priority |
|---|---|
| physical event in the last 7 days | P0 |
| physical event older than 7 days | P1 |
| score ≥ 70 and confidence medium/high | P0 |
| score ≥ 70 and confidence low | P1 |
| score 50–70 | P1 |
| score 30–50 | P2 |
| score < 30 | P3 |

### Why score 100 can be P1

If the score is high but:

- few events;
- no `high` / `high_plus`;
- confidence is medium;
- no field visit;
- the passport is incomplete;
- there is no hard evidence;

then the visit may be `P1`, not `P0`.

## Metrology reliability

Metrology reliability shows how correct the physical and metrological assumptions are.

### What reduces reliability

- passport not confirmed;
- `P_const` unknown;
- pulse weight unknown;
- `Qmin/Qmax` unknown;
- `P≈100 kPa` repeats without explanation;
- the P channel is stuck;
- the T channel is stuck;
- pressure type unknown: absolute or gauge;
- Gay-Lussac is applied to a non-closed grid node.

### Levels

| Level | Meaning |
|---|---|
| high | passport and channels confirmed, no substantial metrological limitations |
| medium | there are passport gaps or isolated anomalies |
| low | the physical model is not applicable or the sensors are clearly degraded |

## Data integrity risk

Data integrity risk shows how complete the investigation data is.

### What raises the risk

- partial sessions archive;
- missing device-events log;
- incomplete hourly archive;
- gaps with successful sessions;
- contradictions between sources;
- timestamp from the future;
- incomplete event decoding;
- raw logs unavailable.

### Levels

| Level | Condition |
|---|---|
| low | sources complete and consistent |
| medium | some sources partial/missing |
| high | there are data-integrity events or serious contradictions |

## Root Cause Matrix — typical hypotheses

The Root Cause Matrix exists so that **the report does not collapse into a single accusation**.

### Typical hypotheses

| Hypothesis | What may support it | What may refute it |
|---|---|---|
| Legal `P_const` | P near default, passport allows the regime | passport does not confirm `P_const` |
| P sensor stuck | low `std(P)`, repeatability | P changes normally outside the window |
| Metering bypass | Q=0 + P default + recovery + hard evidence | no field proof, no device evidence |
| Planned downtime | Q=0 in line with the site's regime | `P_default` / recovery atypical |
| Archive / parser error | gaps, repeated patterns, sessions mismatch | raw device logs confirm reality |
| Downstream valve closed | Q=0 with operating P | no confirmation of valve position |
| Grid regulator | P stable at low pressure | the site is not a grid node |
| Seasonal shutdown | site profile allows downtime | consumption was due under contract |

### Hypothesis statuses

| Status | Meaning |
|---|---|
| `not_checked` | not checked |
| `possible` | possible |
| `unlikely` | unlikely |
| `likely` | likely |
| `confirmed` | confirmed |

The final root cause is set only after a field visit and decoding of the abnormal-events log.

## Potential exposure-volume estimate

<Image src="/images/ai-analytics/metering-bypass/06_exposure_estimate.svg" alt="Potential exposure-volume estimate" />

*Potential exposure-volume estimate.* Not a theft volume, but a scale estimate for prioritising the check. The three numbers (low / expected / high) form a ±30% range around the expected value. The baseline is computed as the median of non-zero flows for the same hour of week outside events. Without a field inspection, all numbers remain a heuristic.

Exposure is a computation of the scale of potentially unmetered consumption in suspicious windows.

<Alert type="warning">
Exposure is not a theft volume. It is a scale estimate for prioritising the check.
</Alert>

### Baseline

For each hour a baseline is built from historical non-event data.

The median of non-zero flows is used for the same combination:

```text
hour of day + day of week
```

Formula:

$$
Baseline_{h,d} =
median(Q \; | \; hour=h,\; weekday=d,\; Q>0,\; outside\; events)
$$

### Hour exposure

For each hour of a suspicious window:

$$
Exposure_t =
max(0, Baseline_t - Q_t)
$$

### Upper cap

To avoid overestimation, the hourly exposure is capped at the historical P95:

$$
Exposure_t =
min(Exposure_t, Q_{P95})
$$

If `Qmax` is known, the cap can be tightened:

$$
Exposure_t =
min(Exposure_t, Q_{P95}, Q_{max})
$$

### Deduplication

If suspicious windows overlap, the same hour is counted only once:

$$
SuspiciousHours =
unique(hours \; inside \; all \; suspicious \; windows)
$$

### Total expected exposure

$$
Exposure_{expected} =
\sum_{t \in SuspiciousHours} Exposure_t
$$

### Uncertainty range

For the indicative range, ±30% is used:

$$
Exposure_{low} = 0.7 \times Exposure_{expected}
$$

$$
Exposure_{high} = 1.3 \times Exposure_{expected}
$$

### Exposure evidence weight

Exposure has low or medium evidence weight until there is:

- a field visit;
- external-meter readings;
- confirmation of the site's regime;
- confirmation that Q should indeed have been >0;
- verification of the passport parameters.

## Correlation with the abnormal-events archive

<Image src="/images/ai-analytics/metering-bypass/07_events_by_groups.svg" alt="Events by groups" />

*Events by groups.* Each suspicious-pattern window expands into a full card: detailed values, correlation with the abnormal-events log (device events within ±24h), the list of alternative hypotheses and the hourly archive of this window. A strong correlation (parameter_change / reset inside the window) is a hard-evidence candidate.

The correlation shows whether device events sit near a suspicious window.

### Correlation window

For each event the following window is used:

$$
[event\_start - 24h,\; event\_end + 24h]
$$

### What counts as a match

A match is any device event that falls inside the window.

Examples:

- abnormal-events summary;
- a single abnormal event;
- `parameter_change` — change of a device parameter;
- `reset` — reset;
- `cover_open` — housing breach;
- `clock_change` — clock change;
- `archive_reset` — archive reset.

### Interpretation

| Result | Meaning |
|---|---|
| no matches | the device log does not confirm the window |
| only summaries | weak correlation |
| `parameter_change` / `reset` | strong correlation |
| `cover` / `magnet` / `physical` | hard-evidence candidate |
| log is empty | confirmation is impossible |

## AI commentary

<Image src="/images/ai-analytics/metering-bypass/05_ai_commentary.svg" alt="AI commentary" />

*AI commentary.* An auxiliary text for the operator: one block explains the device events, the other formulates a methodology summary. The disclaimer at the top stresses that AI does not participate in scoring and does not replace a field inspection.

AI commentary is **an auxiliary text**.

### What AI can do

- briefly explain the issue;
- list the main risks;
- formulate hypotheses;
- suggest the order of checks;
- produce a clear conclusion for the operator.

### What AI cannot do

AI **cannot**:

- change the score;
- change legal readiness;
- confirm tampering;
- replace the device log;
- replace the passport;
- replace a field visit;
- create evidence.

### Required disclaimer

```text
The AI commentary does not participate in the calculation of Legal Readiness, Evidence Confidence or Pattern Score and is not part of the evidence base.
```

## Field-crew inspection checklist

<Image src="/images/ai-analytics/metering-bypass/04_field_checklist.svg" alt="Field-visit checklist" />

*Field-visit checklist.* The minimum set of photos and measurements needed to draft the act. Printed or opened on a tablet before the visit. Tied to the detected indicators: if the `P_default` pattern triggered — the `P_const` regime item is mandatory; if the archive-gap pattern triggered — the abnormal-events log item is mandatory.

The checklist must be tied to the detected indicators.

### General items

- meter seals;
- corrector seals;
- pulse cable / reed / encoder;
- pressure sensor;
- temperature sensor;
- bypass line;
- valve positions upstream and downstream of the meter;
- `P_const` regime;
- abnormal-events log;
- cumulative volume on the meter and the corrector;
- corrector display photo;
- pipework layout;
- contractual regime of the site.

### Required photos

- corrector display: `Q, P, T, V`;
- corrector date and time;
- `P_const` regime;
- meter serial number;
- corrector serial number;
- seals;
- P sensor;
- T sensor;
- pulse cable;
- bypass and valves;
- overall view of the node.

### What to measure

- actual pressure with a reference manometer;
- actual temperature;
- cumulative volume;
- external-meter readings;
- presence of pulses;
- power-supply status;
- communication parameters;
- `Qmin/Qmax` per passport;
- pulse weight.

## Q/P chart and suspicious windows

<Image src="/images/ai-analytics/metering-bypass/09_qpt_chart.svg" alt="Flow and pressure chart" />

*Q/P chart.* The main visualisation. The blue line is the hourly flow, the orange one is the pressure. Red and yellow hatched zones mark windows of the triggered patterns: on hover, the exact hour values are shown. The double chart lets you see the whole period at once and not miss long-term trends.

<Image src="/images/ai-analytics/metering-bypass/10_qpt_tooltip.svg" alt="Chart tooltip" />

*Chart tooltip.* Hovering over any point shows the exact hourly values of `Q` and `P`. This is needed for hypothesis checks: e.g. to learn the pressure value inside a suspicious window or to compare flow against the baseline.

### What to look for on the chart

- long horizontal segments of P (plateau → `P_stuck`);
- drops of Q to zero (zero-flow periods);
- simultaneous jumps of Q and P (recovery);
- pressure jumps without flow;
- a perfectly flat Q with a non-zero mean (synthetic profile);
- discontinuities in time (gap in the archive).

### What cannot be interpreted alone

- a single zero hour;
- a one-off P spike;
- any anomaly without checking the abnormal-events log and the passport.

## Node summary and hourly distribution

<Image src="/images/ai-analytics/metering-bypass/08_node_summary.svg" alt="Node summary" />

*Node summary.* A single glance at the "raw fabric": how many events, how diverse the indicators, total duration, period coverage. The "when they started" histogram is useful for spotting regime patterns: events only at night or only during business hours are diagnostically important (see the "recoveries only during business hours" pattern).

### Summary metrics

| Metric | What it shows |
|---|---|
| Total events | total number of detected patterns |
| Unique types | how many distinct detectors triggered |
| Duration | total duration of all windows (with deduplication) |
| Coverage | share of the period covered by suspicious windows |
| Levels | breakdown by `low`/`medium`/`high`/`high_plus` |
| Most severe | name and severity of the strongest indicator |

### Hourly distribution

The "when they started" histogram uses colour coding:

- **night** (00–05) — blue;
- **morning** (06–08) — light blue;
- **day** (09–17) — orange;
- **evening** (18–23) — violet.

Concentration in one colour is a strong diagnostic signal (e.g. all events during business hours → manual maintenance).

## Top-5 windows for field inspection

<Image src="/images/ai-analytics/metering-bypass/13_top5_field_visit.svg" alt="Top-5 windows for the crew" />

*Top-5 windows for the crew.* If the crew is time-limited — start with these 5 windows. The full list is below in the "all events by groups" section. The "what to check" column is assembled automatically from the triggered indicators: for `zero_flow_p_default` it is the `P_const` regime, for `gap_with_clean_sessions` it is the abnormal-events log and an archive-parser check.

### Top-5 selection algorithm

```text
1. filter events with severity >= medium
2. sort by weight (high_plus > high > medium > low)
3. within each weight — by time descending
4. keep the first 5
5. assemble the checklist union from the triggered indicators
```

### "What to check" column

| Triggered indicator | Mandatory items |
|---|---|
| `zero_flow_p_default` | seals, passport `P_const`, abnormal-events log |
| `zero_flow_p_stuck` | P sensor, passport, display photo |
| `zero_flow_recovery` | valve positions, abnormal events, recovery time |
| `gap_with_clean_sessions` | sessions archive, parser, raw logs |
| `plateau_q_p` | pulse cable, encoder, passport `Qmin/Qmax` |

## How to read the upper block

### Pattern suspicion

Answers the question:

> How strong are the mathematical indicators of suspicion?

Does not answer the question:

> Is tampering proven?

### Evidence confidence

Answers the question:

> How complete is the evidence base?

Is not equal to `suspicion score`.

### Confirmed tampering

Must stay `NOT CONFIRMED` if there is no hard evidence or field act.

### Legal readiness

Shows whether one can proceed to a legally meaningful action.

### Field priority

Shows how urgently a field visit is needed.

### Metrology reliability

Shows whether the physical and metrological assumptions can be trusted.

### Data integrity risk

Shows how complete and consistent the data sources are.

## Common interpretation mistakes

### Mistake: score 100 = proof

Wrong. A score of 100 may be the result of a strong statistical pattern or event score. Proof requires sources.

### Mistake: P=100 kPa = illegal substitution

Wrong. It may be a `P_const` or default value allowed by the passport.

### Mistake: Gay-Lussac violated = tampering

Wrong. The model applies only to a closed volume.

### Mistake: Q=0 with P>0 = bypass

Wrong. It may be downtime, a closed valve or a technological regime.

### Mistake: exposure = loss

Wrong. Exposure is a scale estimate for the check.

### Mistake: AI wrote "suspicion" = proven

Wrong. The AI commentary is only an explanation.

### Mistake: "not triggered" = "no problem"

Wrong. An indicator may have been suppressed by a quality gate, disabled because of a stuck sensor or simply not applicable to the node type. Read the limitations section carefully.

## Minimum criteria for a complete report

The report is considered methodologically complete if it contains:

- analysis period;
- node card;
- pattern suspicion score;
- evidence confidence;
- confirmed tampering status;
- legal readiness;
- field priority;
- data-source map;
- list of detected patterns;
- formal condition for each pattern;
- severity and cap logic;
- event score or an explanation of its absence;
- root cause matrix;
- exposure estimate;
- correlation with device events;
- AI disclaimer;
- field-visit checklist;
- methodology with formulas and thresholds;
- statement of limitations and alternative hypotheses.

## Recommended final-verdict wording

A correct final verdict must be neutral:

```text
The node shows indicators that require verification: long Q≈0 periods,
a stuck pressure channel and/or matches with device events.
This is not standalone proof of tampering.
For the final verdict, the P_const passport, the abnormal-events log,
seals, the pulse cable, the corrector readings and the actual node layout must be checked.
```

If evidence confidence is high:

```text
The presence of direct device events raises the evidence weight, but the final qualification
must take into account the decoding of the codes, passport parameters and the results of the field inspection.
```

If evidence confidence is low:

```text
The detected indicators are heuristic in nature and are used only for planning the check.
```

## Related reports

- **[Metering Bypass (fleet)](/en/platform/v3/ai-analytics/fleet-reports/metering-bypass-fleet)** — the same assessment across the whole fleet at once, without the proceedings blocks.
- **[Suspicious Nodes](/en/platform/v3/ai-analytics/fleet-reports/suspicious-nodes)** — the main fleet-level tool for detecting bypass.
- **[Consumption Analytics](/en/platform/v3/ai-analytics/node-reports/consumption-analytics)** — a general node breakdown with the event log; recommended to run before or together with this report.
- **[Passport Audit](/en/platform/v3/ai-analytics/fleet-reports/passport-audit)** — a check of passport completeness, without which legal readiness cannot be `ready`.
