WASH Research & Development Centre · University of KwaZulu-Natal

A Standardised De-Risking Protocol for Water Efficient Sanitation Systems (WESS/NSS)

The reference model, the decision-tree activity set, the field diagnostics with their thresholds and decisions, the laboratory interpretation, the mitigation catalogue, and the live financial rating — a companion volume to The Water Efficient Sanitation Systems (WESS/NSS) Industry

Consolidates Protocol v5 (June 2026) · the v4 field corrections · the Decision Protocol (Apr 2026) + v6 live-rating direction (July 2026) Compiled 2026-07-19 · Rev. 2026-07-21 — Part IX: first soft-sensor correlation results, current deployment status · · Rev. 2026-08-16 — WRC review (V. Naidoo) worked in: stage-setting, skills ladder, social de-risking tiers, sampling guide, differentiated reuse quality, valorisation pathways, finance approach & portfolio bankability, report template · WRC special publication — manuscript for design

A site is de-risked when

its configuration is declared against the WESS reference model, its risks are recorded in a live HAZOP register, its low-cost soft sensors stream data to a central platform, that stream shows the unit operating within its expected norms, and the staff who run it have been trained to keep it there. Version 6 adds the remaining step: the stream no longer produces a dated certificate but a continuously-computed rating that a lender holds as a covenant.

A solar-powered 620-household WESS community system under monitoring
The 620-household community system at Portion 80 Nooitgedacht — entirely solar-powered, recirculating treated water to head tanks at the top of a sloped settlement. The same protocol that de-risks a single household unit holds here, because both are configurations of one reference model.

Timeframe & acknowledgement

This protocol was built and corrected over roughly 18 months of field work — the site visits, the diagnostics, the laboratory rounds and the reports that turned a design-time method into a field-tested one. It exists because the WESS technology providers — Enviroloo, Prana Aquonic, WEC and Lilliput — opened their installations to independent assessment and acted on the findings visit after visit. The evidence in this document is theirs as much as ours; the Centre's role was to measure, structure and de-risk what they built.

Part I · setting the stage

The WESS industry and the de-risking problem

Water Efficient Sanitation Systems treat waste at or near the point it is generated and recover the treated water for flushing or reuse — a workable way to extend sanitation into the peri-urban and rural settings that waterborne sewerage cannot reach at the required pace.

The state of sanitation, and where WESS stands

South Africa carries a sanitation backlog that conventional waterborne sewerage cannot close at the required pace: millions of households in dense peri-urban settlements and dispersed rural communities sit beyond the practical reach of trunk sewers and centralised treatment works, and the water those works would demand is itself under stress. Non-sewered sanitation is therefore not a stop-gap but a permanent category of infrastructure, and WESS — the sub-category that treats on site and recovers the water — is the form of it that answers the water constraint as well as the sewerage one.

The regulatory and standards ground has been prepared. ISO 30500 was revised in 2025 and sets the effluent and pathogen performance a non-sewered system must meet; ISO 31800 governs the treatment of the faecal-sludge stream; SANS 241 bounds any water that could reach human contact; and a draft framework for model by-laws now defines WESS as a category of non-sewered sanitation that may treat and reuse water on site without a water-use licence. On the piloting side, the engineering field-testing guidelines developed at UKZN and published with the International Water Association set out how a novel sanitation technology is taken through structured field trials. This protocol picks up where those guidelines end: piloting establishes that a technology can work; what follows here is the standardised troubleshooting and optimisation of technologies operating in the field — the stage of the innovation value chain between a successful pilot and a bankable, scaled deployment.

The work reported here was done to improve the industry and to build it towards providing high-quality technologies. The protocol serves the technology developers directly: every diagnostic that locates a failure mode is also a design input, and the providers assessed in this programme have acted on the findings visit after visit, so the assessment loop is simultaneously a product-improvement loop.

Standardising the skills as well as the tests

A protocol standardises more than measurements — it standardises the people. The sector is converging, in a discussion now running internationally, on a tiered skills ladder for non-sewered sanitation: the janitor, who keeps the facility clean and reports what a user sees; the operator, who runs the daily checks and the routine interventions; the technician, who executes the diagnostics in this document and acts on their decisions; and the advanced technician, who reads the laboratory results, maintains the HAZOP register and manages the mitigations. Each part of this protocol is written so that it converts directly into training material at the appropriate tier, under any of the three operating and maintenance arrangements a municipality may choose: O&M carried in-house by the municipality, O&M outsourced to sanitation service providers, or maintenance carried by the technology suppliers on their own installed base. The same tests, thresholds and decisions hold in all three; only the badge on the overalls changes.

The de-risking problem

The technology has been developed and deployed. Adoption has nonetheless been limited, and the limiting factor is the shortage of independent, site-level evidence that an installed unit performs to specification under real operating conditions.

The shortage has a technical side, a financial side, and a social side. Technically, a unit that meets its design criteria on commissioning day drifts from them over the following weeks as loading, temperature, power supply and maintenance vary; without structured monitoring the drift goes undetected until the recirculated water at the toilet interface has discoloured or begun to smell — at which point the user, not the engineer, discovers the failure. Financially, a provider seeking loan finance to deploy at scale meets a lender who has no independent operating record to price against, and who therefore prices the risk conservatively into the spread. Socially, the influent itself is a behavioural variable: what a household flushes, cleans with and diverts into the system drives the variability of the blackwater and greywater the unit must treat, so the de-risking of a site is inseparable from the overall operating and maintenance arrangement — the user practices, the cleaning-agent inputs and the demand pattern are part of the load case, not background noise.

De-risking, in the sense used here, is the conversion of a site from that state of uncertainty to a state of documented, monitored and managed risk — and, in v6, the maintenance of that state as a live, financeable signal.

The field programme and its reach

The team has assessed eight sites operated by four technology providers in KwaZulu-Natal and Gauteng, and issued six formal site reports — five baseline assessments and one mid-point review — with three further sites onboarded for first visits in Q3 2026. Across those assessments the team opened twenty-four HAZOP entries and raised forty-nine engineering recommendations, each traceable to a field measurement.

SiteProviderVisits issuedHAZOPsRecs
Pholani EnvirolooEnvirolooBaseline + Mid-point617
Ekuthuleni ShellcrossPrana AquonicBaseline46
OakfordPrana AquonicBaseline24
Portion 80 NooitgedachtPrana AquonicBaseline711
Upper Malacca (NEWgen)WECBaseline + greywater511
Catoridge · Inchanga · Lilliput HQLilliputScheduled Q3 2026——

The same eight diagnostics, seven completion criteria and HAZOP procedure held from a single household unit to the 620-household community system. The next parts explain why, and exactly how the assessment is carried out.

Part II · the organising principle

The WESS reference model — the gold standard

A WESS unit is not a fixed product. The same treatment functions recur in different combinations and at different capacities. The protocol treats them as one object by defining a single comprehensive reference model — the gold standard — and expressing every real unit as a configuration against it.

The model is a graph. Its nodes are the complete set of treatment functions a WESS unit can perform. An implementation — a technology case, or a specific installed site — is a subgraph: the nodes it instantiates, the edges that route flow between them, and the capacity weights those nodes and edges carry (design flow, working volume, population-equivalent). Two units with the same topology but different capacities are different weighted subgraphs; a unit that omits a whole treatment line simply drops those nodes.

De-risking begins by placing the site on this model. Once the site's subgraph is declared, everything downstream attaches to it: the diagnostics interrogate node types, the criteria roll up defined nodes, each HAZOP entry maps to a model node, and each criterion's live rating attaches to the nodes that produce its evidence.

Blackwater line Greywater line Tertiary · disinfection & reuse Residuals & recovery Q·bw Q·gw yield Blackwater inlet Primary settling/ septic Anaerobic bio Aerobic bio Secondaryclarifier Greywater inlet Buffer /coagulation Ultrafiltration Ion exchange / GAC DisinfectionCl₂·UV·O₃·Electro Recirculation /head tank Reuse (flush) Discharge Sludge handling/ desludging Valorisationbiochar / compost Nutrientrecovery an implementation (subgraph) SenseArray-observed node residual / recovery return
The WESS reference model. A real unit is the highlighted subgraph — the nodes it contains, the edges routing its flow, and the capacities that weight them. The disinfection node names a function; the technology filling it (chlorination, UV, ozonation or electro-disinfection) is a choice the implementation declares.

Nodes carry options; capacities carry load

A node names a function; the technology that fills it is a choice the implementation declares. The disinfection node may be filled by chlorination, UV, ozonation or electro-disinfection — a chemical-free option that generates oxidants (hydroxyl radicals, ozone, hydrogen peroxide and chlorine species) in situ from electrical energy, and suits a decentralised, real-time-monitored unit because it needs no dosing supply chain and is electrically observable. The capacity weights are load-bearing: the weight on the greywater product edge is the design-versus-delivered yield criterion C7 measures — the field found a unit meeting quality at a tenth of design flow, on the graph a product edge whose weight had collapsed while upstream node statuses stayed green.

Cohort implementationConfiguration (nodes present)Capacity weight
Household unit (Enviroloo)Blackwater line → disinfection → recirculation; no greywater linesingle household
Portion 80 community systemFull blackwater line → disinfection → recirculation to head tanks; solar620 households
Upper Malacca (NEWgen)Blackwater line and full greywater line (UF / ion-exchange) → disinfectionsite-scale, two lines
Estimated dissolved-oxygen profile across the blackwater, greywater and septic treatment lines at Upper Malacca
The subgraph made visible in data: the estimated dissolved-oxygen profile at Upper Malacca reads its blackwater line (chambers D15–D21), its greywater line (D22–D27) and its septic/sludge node (D28) as three distinct paths.

Because a diagnostic interrogates a node type rather than a product, the palette that assesses a household settling node assesses a community settling node; only the capacity weight differs. That is why the protocol held across scales — and why a new technology is onboarded by declaring its subgraph, not by writing a new protocol.

Green fibreglass conservancy and treatment tanks with valved manifold
The same nodes in the field: conservancy and treatment tanks with a valved manifold — a real unit's blackwater line.
Circular biological reactor filled with white MBBR bio-media carriers and aeration piping
A biological node up close — MBBR bio-media carriers and aeration in a circular reactor.
Part III · the core method

The decision model & the de-risking decision tree

Underneath the diagnostics, the criteria, the HAZOP register and the financial case sits a single decision model, and it is the organising thread of the whole protocol rather than one component among many.

The model has four steps, repeated across every compartment and every failure mode of a unit. A diagnostic produces a small set of measured signals. The signals combine into a functional index for the compartment they describe. The index is classified on a green / amber / red traffic-light. And each band carries a defined corrective intervention:

BandMeaningThe move
GreenWithin normsContinue and monitor
AmberDrifting; early warningAn action taken before performance is lost
RedOut of specificationA confirmatory test and an operational intervention

Because every part of the engagement resolves to the same green/amber/red statement, the parts compose rather than sit side by side: each field diagnostic expresses the model through its own functional index; the seven criteria are the roll-up of those compartment classifications to the level of the unit; the HAZOP register is the same model viewed from the risk side (a deviation scored on the 5×5 matrix, the score setting the action's priority exactly as a traffic-light band does); and the v6 live rating is this same model made continuous. The design is drawn most directly from the microbial Functional Microbial Health Index, where six functional signals combine into one traffic-light for a compartment — v4 generalised that to the whole palette. Stating it explicitly is what lets a field assessment end in a decision and a next step at each compartment, not a table of numbers requiring expert interpretation after the visit.

Two kinds of number in this document. A limit tagged ISO 30500 is authoritative — the value the standard fixes for compliance (Part VII). A threshold tagged illustrative is an operational trigger the team is still calibrating — the SVI and DSVI bands, DO and ORP ranges, sludge-blanket percentages, TDS drift rates, the electro-disinfection set-points, and every parameter in the rating mathematics. Illustrative values encode the right direction of a decision and are placeholders for the numbers the field data and the surrogate-validation work will fix; they must not be read as validated limits. The decision structure is stable; the exact cut-points are not yet.

The activity set — seven phases, seventeen steps

The engagement is executed as a structured diagnostic algorithm: seventeen steps across seven phases, each step specifying the test to perform, the criteria to evaluate, the branch to follow on the result, and the HAZOP entry it generates. The structure is branching, not linear — results at each step decide whether the assessment proceeds, branches to a root-cause investigation, or triggers a corrective action. This is the answer to "do we even enter this area?": a healthy upstream result closes the deeper branch and moves on; a failing one opens it. The algorithm is run at every visit and feeds directly into the HAZOP register in InfraTrack.

PhaseStepsProtocolFocus
1 · Settling1–4Protocol 1Compartment functionality, SVI/DSVI, root cause
2 · Hydraulics5Protocol 2Residence time, dead volume, mixing
3 · Sludge management6Protocol 3Blanket depth, accumulation rate, desludging
4 · Biological7–10Protocol 4DO distribution, colour gradient, microbial health
5 · Water quality11–12Protocol 5TDS, turbidity, colour, reboot assessment
6 · Disinfection13–15Protocol 6Colour, odour, chlorine, E. coli
7 · Site readiness16–17Cross-cuttingConsumables, sensors, power, HAZOP compilation

The master decision tree below shows the gating between phases: the main spine is the pass path; a tripped gate branches right to a root-cause or mitigation action before the assessment continues.

DO / redox informs settling root-cause (Step 4) discolour / odour → trace back (Steps 7–12) washout ↔ settling / sludge passfail Gradient +SVI < 150? DSVI dilution → root cause(over-aeration / surfactant / toxic) → reboot + reseed passfail τ/HRT > 0.7? Dead volume / short-circuit →baffle & sludge-accumulation check passfail Blanket < 40%? 40–50%: schedule desludge ·>50%: desludge now passfail DO zoned,colour, froth OK? Community failure → reboot +reseed; live culture to O&M passfail Colour ≤ 30 Pt-Co,TDS stable? 30–50 Pt-Co: partial reboot ·>50 Pt-Co: full reboot passfail Free Cl₂ 0.2–0.5,E. coli clear? Low Cl₂: refill / clear dosing ·recirc risk: re-sequence loop Phase 1 · SettlingProtocol 1 — SVI / DSVI Phase 2 · HydraulicsProtocol 2 — RTD tracer Phase 3 · SludgeProtocol 3 — blanket profile Phase 4 · BiologicalProtocol 4 — DO / colour / froth Phase 5 · Water qualityProtocol 5 — TDS / colour Phase 6 · DisinfectionProtocol 6 — Cl₂ / E. coli Phase 7 · Site readiness→ HAZOP register (5×5)
The de-risking decision tree. Each phase gate either passes down the spine or branches (red, dashed) to a root-cause investigation and a mitigation. A healthy upstream reading closes the deeper branch — the protocol only goes as deep as the problems it actually finds. It is a network, not a checklist: the teal feedback links (dotted) show where one phase's evidence re-enters another — the biological DO/redox reading resolves a settling root cause, a discoloured interface is traced back through the biological and water-quality phases, and a biomass-washout signal couples settling and sludge. Full step-by-step logic and thresholds are in Part V; the mitigations are catalogued in Part VIII; and each area — microbial (FMHI), electro-disinfection (signal set), and sensor readiness — carries its own decision surface, not just the six-phase spine.

Cross-reference matrix — step, parameters, thresholds, guide words

StepParametersKey thresholdsHAZOP guide words
1Settled solids, clarity gradientProgressive C1→C5No differentiation; partial failure
2SV30, MLSS, SVISVI <120 good · 120–150 mod · >150 poorPoor settleability; settling failure
3Diluted SV30, TSS, DSVIDSVI <120 recoverable · >150 intrinsicHigh solids; biomass dispersal
4DO (all zones), foam, cleaning productsDO <0.5 in anoxic/anaerobicOver-aeration; surfactant; toxic inhibition
5τ, HRT, τ/HRT, N (tanks-in-series)τ/HRT >0.9 adequate · <0.7 severeDead volume; short-circuiting; poor baffling
6Blanket depth, ratio, interface<30% normal · 40–50 warn · >50 criticalElevated blanket; desludging overdue
7DO (aerobic, anoxic, anaerobic)Aerobic 2–4 · anoxic <0.5 · anaerobic ≈0Insufficient aeration; zoning failure
8Mixed-liquor colour by zoneProgressive lighteningNo gradient; treatment ineffective
9Froth (aerobic), gas (anaerobic)Tan 2–5 cm froth; fine bubblesFilamentous; surfactant; inactive community
10Convergence of steps 2/3, 8, 9Multiple negative indicatorsCommunity failure; reboot required
11TDS, EC, turbidity, colour, pHColour ≤30 Pt-Co; TDS trend stableAccumulation; colour non-compliance
12Water level, consumptionLevel stable; TDS within thresholdWater loss; reboot required; demand mgmt
13Colour, odour, clarity at interfaceClear, odourless, slight residualTreatment failure; excessive dosing
14Free chlorine (DPD)0.2–0.5 mg/LInsufficient/excessive Cl₂; recirc risk
15E. coli (lab enumeration)Below threshold with adequate Cl₂Particulate shielding; disinfection failure
16Consumables, sensors, power, structureAll available & operationalSupply / power / structural risk
17Compiled HAZOP register5×5 risk matrix scoredAll guide words from steps 1–16
This algorithm has no equivalent in the municipal literature (Sacramento operator manuals; Jenkins, Richard & Daigger; WEF MOP 11) — those assume a centralised works with dedicated staff and an on-site laboratory. WESS units are small, compartmentalised, recirculating and unstaffed, so the diagnostic strategy is different: treatment failures are immediately visible at the toilet interface, and the assessment must end in a decision a non-specialist can act on. This protocol fills that gap.
Part IV

The three-visit engagement

Each site engagement is one three-visit cycle over twelve to sixteen weeks, the visits spaced to give the provider at least three weeks to act between them. The provider takes part in the assessment and responds to each report before the next visit.

Week 1
Visit 1

Baseline

Declare the site's subgraph, run the observational diagnostics, open the HAZOP register, survey for sensor placement, install the sensors, take the first laboratory round and set the sampling schedule. V1 is a coverage floor, not a complete diagnosis.

Weeks 3–4
Visit 2

Mid-point review

Run the full equipment-intensive diagnostic set — tracer, settling/TSS, disinfection — and the laboratory campaign, and verify the provider's first revisions.

Weeks 5–6
Visit 3

Final assessment

Verify the provider's revisions, commission and validate the sensor stream against the criteria, and bring the site to its de-risked state and its opening rating.

v4 correction (visit-scoped schedule). The field showed only the observational diagnostics execute at a first visit across every site, so the schedule is an explicit diagnostic × visit matrix, and sensor install moved to V1 so two stream windows and at least two laboratory cross-checks exist by V3 — the condition the completion test needs.
Part V

The eight field diagnostics — full detail

Each diagnostic attaches to a node type, resolves its measurements into a functional index and a green/amber/red status, and carries its own branch logic — the test, the thresholds, the decision, and the mitigation. The step numbers refer to the decision tree in Part III. Every numeric cut-point in this part is an operational trigger — illustrative and under calibration against the field data and the surrogate-validation work; they encode the right direction of a decision, not a validated limit. The authoritative compliance numbers are the ISO 30500 values in Part VII. Microbial functional profiling (Protocol 8) is placed second, immediately after settling — it runs as the integrated Protocol 8 but is the diagnostic most directly tied to the unit's public-health purpose, so it leads rather than trails the palette. Open the protocol you need.

Settleability cones across the treatment compartments
Settleability testing across the compartments (Protocol 1).
Froth and colour in a treatment compartment
Colour and froth reading the biological zoning (Protocol 4).

Sampling stations, method and cadence

Every diagnostic in this part rests on the same sampling discipline, stated once here. Where: each compartment is sampled at its outlet (the water leaving it carries the verdict on that compartment's function), with the influent, the recirculation or head tank, and the final product line sampled in the same round, so the train reads as a progression rather than a set of disconnected points; sludge samples are drawn from the compartment floor by sludge sampler at the same stations. How: samples are taken with the unit in normal use, not after a quiet period — a steady-state reading of an unloaded unit de-risks nothing; grab samples are taken mid-depth away from walls and inlets, in containers matched to the analysis (sterile for microbial, acid-washed for metals, zero-headspace for DO-sensitive determinands); field parameters (pH, EC, DO, ORP, temperature, turbidity) are read on site at the moment of sampling, because they do not survive transport; laboratory samples are coded against the chain-of-custody legend (Part VII), cooled, and delivered within the laboratory's holding times. When: the same stations are sampled at every visit, so visit-to-visit trends are like-for-like — the comparison, not the single value, is the diagnostic.

P1Compartment settling testSteps 1–4 · SVI / DSVI

Purpose

Evaluate the primary treatment function. A properly functioning compartment train produces a progressive improvement in supernatant clarity from compartment 1 through 5; deviations locate the failure.

Procedure

Collect 3 samples from each of the 5 compartments (15 total), settle in Imhoff cones for 30 min, and read the gradient. On the primary settler measure SV30 (mL/L at 30 min); with MLSS known, SVI = SV30 / MLSS. Where SV30 saturates the vessel, dilute iteratively until settled volume falls to 150–250 mL/L and compute DSVI = settled volume / TSS of the diluted sample.

Decision — SVI Step 2

ReadingClassificationDecision
SVI < 120 mL/gGood settleability→ Step 5 (hydraulics)
120–150 mL/gModerateMonitor → Step 5
> 150 mL/g / no settlingPoor / failure→ Step 3 (DSVI)

Decision — DSVI Step 3

ReadingClassificationDecision
DSVI < 120Recoverable at lower conc.; high solidsAssess desludging → Step 5
120–150Moderate; investigate→ Step 4 (root cause)
> 150 / undeterminedIntrinsic biological/chemical problem; biomass dispersed→ Step 4 (root cause)

Root cause & mitigation Step 4

  • DO > 2 mg/L in an anoxic/anaerobic zone → over-aeration, process zoning collapsed → reduce aeration rate, check baffle integrity. HAZOP: over-aeration.
  • Foaming present → surfactant interference → identify cleaning products, community education on WESS-compatible products. HAZOP: surfactant loading.
  • No foaming → possible toxic inhibition or very low food-to-biomass ratio → check influent for toxics, assess F:M, increase sludge feed from the primary settler. HAZOP: toxic / substrate imbalance.
  • In all settling-failure cases → recommend a system reboot (partial or full water replacement to flush accumulated inhibitors); assess whether live bacterial culture is available on site to recharge the community after reboot.

Field example

Where the biomass settled poorly, standard SVI saturated (≈1000 mL/L, vessel-filling); the diluted index recovered ≈171 mL/g, corroborated against a measured aerobic SVI of 177. The protocol now carries the DSVI with its defined saturation trigger.

P8Microbial functional profilingWESScheck BioProfile · FMHI

Microbial detection is its own dedicated channel, not an inference from the physical-chemical sensors (pH, EC, ORP do not carry a biological count). It has three tiers, an on-site six-strip functional screen, a set of ratio indices, a joint-pattern decision logic, and a camera-read scoring system. The per-strip chemistry is proprietary and patent-pending through UKZN InQubate; this edition describes what each strip reads and how the results drive decisions, not the enabling formulations.

Three-tier architecture

TierInstrumentRoleStatus
1 · Accredited labISO/IEC 17025 culture / qPCR / metagenomicsGold-standard confirmation; calibrates the tiers belowIn use
2 · WESScheck BioProfileSix-strip lateral-flow functional profiler, camera-chip readoutOn-site field screen; the fingerprint the rating consumes at each visitConcept & methodology done; not yet built
3 · Ramsurran continuous sensingDNA-sequence detection panels; then a solid-state in-unit indicator read by a camera chipMolecular E. coli detection near-term; the online stream medium-termExploratory

The process-based panel already in place

Operational today: the COD Treatment-Train Profile (CTTP), the Oxygen Distribution and Operational Oxygen-Utilisation Profiles (ODP, OOUP), ORP, pH, temperature, TSS/turbidity, ammonia, nitrate/nitrite and gas production — integrated by a Metabolic State Assessment (MSA: ORP+DO+pH) into the green/amber/red Functional Microbial Health Index (FMHI) per compartment. Microscopy and an ATP activity kit are not yet available and are on the timeline.

Blackwater COD profile across chambers
CTTP — substrate removal across the blackwater chambers (Upper Malacca).
TSS and VSS profile across samples
TSS/VSS — the spike at D17 is biomass washing out of a compartment.

The six-strip BioProfile — what each strip reads

StripReadsBearing on the unit
1Viable faecal-indicator activity (E. coli-associated)Public-health / disinfection verdict
2Total viable microbial activity — the denominator all indices normalise toWhether the biology is alive at all
3Gram-negative dominanceEnteric-signature context for the safety read
4Biofilm & fouling riskMembrane and pipework protection
5AMR-enzyme screening signalAntimicrobial-resistance pressure flag
6Nitrogen-removal functionWhether biological nitrogen removal is active

The functional indices (all normalised to the ATP baseline)

IndexCalculationFeeds criterion
ATP Activity Index1 − (test/control), inverse LFATotal viable-activity baseline (denominator)
Faecal Viability (FVI)viability signal, background-subtractedPublic-health / disinfection (safety)
Gram-neg Dominance (GNDI)(GN·LPS / ATP) × 100Enteric-signature context for safety
Biofilm Fouling (BFI)(EPS / ATP) × 100Fouling / membrane-protection risk
AMR Enzyme Pressure (AEPI)(β-lactamase / ATP) × 100AMR sub-indicator (flag)
N-Removal Function (NRFI)nitrate-reducer signal vs nitrate burdenNutrient-removal process criterion

The joint-pattern decision logic

The read is the joint pattern, never a single strip. Each strip scored visually 0–4 (camera image-analysis converts colour/fluorescence intensity to the indices later); the six sum to a Total BioProfile score 0–24, banded Low (0–4), Moderate (5–10), High (11–16), Very high (17–24). The report states "functional bacterial profile detected," never "bacteria identified" — a screening output, not a compliance score; positives trigger laboratory confirmation.

Combined patternInterpretationAction
High ATP + CQD+ + high GNDIViable activity with faecal & Gram-negative signatureElevated public-health risk → confirm by culture/qPCR
High ATP + CQD− + high EPSActivity without faecal signature; high fouling riskInspect filters, pipes, surfaces; clean / adjust operation
High ATP + high β-lactamaseActive biomass with possible AMR pressureConfirm by AMR culture / qPCR / metagenomics
Low ATP + high LPSResidual Gram-negative debris / endotoxin, not live dominanceDo not call live dominance without viability confirmation
High nitrate + low reducer signalNitrogen-removal biology weak/inactiveCheck oxygen, carbon source, retention time, redox
ATP low, all others lowLow microbial-risk profile at time of testContinue routine monitoring; periodic reference check

The camera-chip reader (the "robot")

The kit is read not by eye but by a fixed-geometry camera-chip / smartphone reader: under controlled lighting a consistent region-of-interest is imaged, and image analysis converts colour or fluorescence intensity to a numerical index against a calibration chart — the step that makes the strip semi-quantitative and, later, the same colour-to-signal principle the Ramsurran solid-state in-unit indicator makes continuous and online. So tiers 2 and 3 are one arc: the strip readout made permanent.

How it wires to the rating

Each index becomes a criterion's compliance probability pₖ only through calibration against the accredited lab, so the BioProfile plugs into the same hierarchical, prospective validation as the physicochemical model — its maturity is earned, not assumed. And the physicochemical soft-sensors supply microbial confidence: turbidity, residual chlorine and high salts are known strip interferences, so a high reading lowers the confidence term cₖ for the microbial criterion. One channel carries the signal; the other says whether to trust it.

The microbial decision path (the tree, applied)

The microbial diagnostic ends in a decision the same way every other phase does — its own branching surface:

  • 1 · Gather the compartment signals — CTTP (COD across chambers), ODP/OOUP (DO), ORP, pH, nitrate/nitrite, turbidity/TSS, sludge, foam/gas, and the BioProfile fingerprint where run.
  • 2 · Classify the metabolic state — the MSA combines ORP + DO + pH into the dominant pathway (aerobic / anoxic / anaerobic / strongly reducing).
  • 3 · Read the combined pattern, not the parameter — the integrated diagnostic matrix (Part VII) maps the pattern to a single diagnosis (organic overload, fermentation, denitrification, sulfide risk, washout, bulking, EPS overproduction, inhibition, collapse).
  • 4 · Roll up to the FMHI band — the eight indicators give one green/amber/red per compartment: green → continue monitoring · amber → increase monitoring + corrective action · red → immediate investigation and intervention.
  • 5 · Confirm and escalate — any BioProfile positive or red FMHI triggers accredited-lab confirmation (culture/qPCR) against the ISO 30500 Table 5 pathogen targets; a confirmed red is a HAZOP entry and, in v6, a rating driver.
P2Residence-time distributionStep 5 · lithium tracer

Purpose & procedure

Determine how effectively each compartment's physical volume is used. A lithium-chloride pulse-injection test constructs the RTD curve, closed with a mass-balance verification; short-circuiting and dead volume reduce effective residence time regardless of biological health.

Decision — mean residence time τ against HRT

ReadingClassificationDecision
τ/HRT > 0.9Full volume utilised→ Step 6
0.7–0.910–30% dead volumeInvestigate sludge accumulation, baffle integrity. HAZOP: reduced effective volume.
< 0.7Severe short-circuiting (>30%)Urgent investigation. HAZOP: hydraulic failure.

Mixing — tanks-in-series N

N < 2 near-complete mixing, poor baffling (assess baffle condition/modification) · N = 2–5 moderate, acceptable for most zones · N > 5 good plug-flow approach, effective baffling. Residence-time was the least-executed diagnostic at baseline (0 of 5 sites) — it is scheduled to V2 once equipment is mobilised.

Why it matters beyond the diagnostic

The fitted tank number N is not just a hydraulics score — it is the hydraulic input to the process model. Coupling the RTD to a biokinetic model is what lets the model separate a hydraulic failure (flow deviating from design, so biology never gets contact time) from a biokinetic failure (the microbes genuinely cannot keep up) — two causes a grab sample cannot tell apart. See Process modeling at the end of this part.

P3Sludge profile assessmentStep 6 · sludge judge

Procedure

Deploy a Sludge Judge at each settling compartment, minimum 3 points (inlet, centre, outlet). Record sludge-blanket depth, total depth, interface quality, colour, consistency and gas bubbles. Blanket ratio = blanket depth as a percentage of total liquid depth.

Decision — blanket ratio

ReadingClassificationDecision
< 30%Within design limits→ Step 7
30–40%Approaching limitMonitor trend; HAZOP if trending upward
40–50%WarningSchedule desludging. HAZOP: elevated sludge blanket.
> 50%CriticalDesludge immediately. HAZOP: desludging overdue.

Also record

Interface quality (sharp = normal compaction · diffuse = poor floc compaction, cross-reference Step 2). Spatial variation > 20 cm within a compartment → uneven flow distribution (HAZOP entry). Accumulation rate (V2/V3): if measured rate exceeds 1.5× design, raise a HAZOP entry for accelerated accumulation.

A buried septic/conservancy tank access lid with an inspection cap in grass
The septic / conservancy access point — where the sludge-judge core is taken. Accumulation here is often the first thing a desludge cadence (mitigation M01) has to fix.

From a trend to a predicted threshold

Beyond the ratio bands, accumulation is quantified so a measured trend becomes a predicted threshold-crossing time: the rate is normalised per user (ΔV_sludge / (Δt · N_users)) and fed to a dynamic model — Stokes settling + a flocculation population-balance built for WESS's unstirred tanks + Kynch hindered settling + a tanks-in-series RTD. That model, and the risk-classification and valorisation decisions that follow from it, are set out in Sludge management & valorisation at the end of this part.

P4Biological activity assessmentSteps 7–10 · DO / colour / froth

Decision — DO distribution Step 7

Zone / readingClassificationDecision
Aerobic 2–4 mg/LAdequate aerationContinue
Aerobic < 1 mg/LInsufficient aerationIncrease aeration / check blower-diffuser. HAZOP.
Aerobic > 4 mg/LExcessive aerationReduce rate (floc breakage, energy waste)
Anoxic > 0.5 / anaerobic > 0.5Process zoning failureCross-reference Step 4

Colour gradient Step 8 & froth/gas Step 9

Colour: progressive lightening across zones = active treatment · minimal change = biological treatment ineffective. Aerobic froth: light, tan, easily dispersed (2–5 cm) = healthy · dense, dark, persistent = filamentous organisms or surfactant (cross-ref Step 4) · none = insufficient biomass. Anaerobic gas: steady fine bubbles = active methanogenesis · none = anaerobic community inactive.

Community failure & mitigation Step 10

When negative indicators converge — no colour gradient + no froth + no gas + poor settling (Step 2/3) — the biological community is absent or severely inhibited. Recommend: system reboot followed by reseeding with live bacterial culture. Investigate the die-off: toxic loading (check influent), chlorine recirculation (check disinfection–recirculation sequencing), extreme pH, or an extended power outage halting aeration. Flag: the site requires on-hand live culture for regular recharging — add to the O&M consumables list and procurement schedule.

Heavy brown froth on the surface of an aerated treatment compartment
Brown froth on an aerated compartment — read with DO and colour for the biological status.
A large reactor with a dome of dense white foam
A dense white-foam dome at a community-scale reactor — persistent foam flags surfactant or filamentous upset.

Expectation bands per compartment illustrative · team-defined

The team maps each parameter to a Green (as designed), Amber (flag for next visit) and Red (immediate response) band per compartment type. The dominant ones:

Aerobic (C4)GreenAmberRed → interpretation
DO (mg/L)2.0–4.01–2 or 4–6<1 or >6 — aeration failure / floc break-up
ORP (mV)+50 to +2000–50 or 200–300<0 or >300 — zoning collapsed
pH6.8–8.06.5–6.8 or 8–8.5<6.5 or >8.5 — acidification / ammonia toxicity
NH₄-N out<33–10>10 — nitrification incomplete
SVI (mL/g)80–150150–250 or 50–80>250 or <50 — bulking / pin-point flocs
Anoxic (C5)GreenAmberRed → interpretation
DO (mg/L)<0.50.5–1.5>1.5 — O₂ carryover; denitrification stops
ORP (mV)−50 to −1000 to −50 or −100 to −150>0 or <−150 — zoning collapsed / fermentation
NO₃-N out<55–15>15 — denitrification not delivering

The complete 15-parameter × 10-compartment band matrix is a follow-up workshop deliverable for the engineering and microbial leads; the bands above are the operational subset in current use.

Leading indicator (v4)

The V1 biological-activity DO profile — an anaerobic chamber reading aerobic-like DO — is a pre-registered leading indicator of later non-compliance on C1/C2. In the live rating it enters as a Watch (band B) trigger, not a breach.

P5Water concentration & rebootSteps 11–12 · TDS / colour

Purpose

Recirculating systems accumulate dissolved solids, colour and colloidal material over successive cycles. Measure TDS, turbidity, EC, colour (Pt-Co) and pH at the greywater compartment and recirculation tank; compare to the previous visit (or baseline at V1).

Decision — TDS trend Step 11

ReadingClassificationDecision
Stable / decreasingMass balance managed→ Step 13
< 5% / weekSlow accumulationMonitor → Step 12
5–10% / weekModerateAssess reboot timing. HAZOP.
> 10% / weekRapidReboot required soon. HAZOP.

Colour & turbidity

Colour > 30 Pt-Co exceeds the ISO 30500:2025 limit → HAZOP: colour non-compliance. Turbidity rising while TDS stable = colloidal accumulation, polishing insufficient; both rising = general water-quality degradation.

Turbidity as the simpler field method. Where a Pt-Co colour comparison is not practical in the field, turbidity serves as the simpler routine surrogate: it is read in seconds on a hand-held meter (or by the same camera-under-fixed-lighting principle the protocol uses elsewhere), it trends with the colloidal and colour load in a recirculating system, and it is already a soft-sensor channel — so the operator tracks turbidity visit to visit and the Pt-Co measurement is reserved for confirming a suspected exceedance. The compliance value remains the Pt-Co number; turbidity is the trigger that says when to take it.

Reboot decision & mitigation Step 12

  • Colour 30–50 Pt-Co → partial reboot (replace 30–50% of volume).
  • Colour > 50 Pt-Co, or TDS above site threshold → full reboot (complete replacement).
  • Flag: does the site have fresh water for reboot? If not → HAZOP: water supply for reboot not secured.
  • Flag: excessive water use (continuous flushing)? If yes → HAZOP: water-demand management required.
P6Disinfection performanceSteps 13–15 · Cl₂ / E. coli

Interface sensory check Step 13

Clear, odourless, slight residual = adequate → confirm quantitatively · discoloured = upstream treatment failure (trace back through Steps 7–12) · septic odour = biological compartments underperforming · chemical odour = excessive dosing. The disinfection node's chosen technology (chlorination, UV, ozonation or electro-disinfection) must be placed and sequenced correctly in the recirculation loop; where electro-disinfection fills the node, its in-situ oxidant generation is directly observable in the ORP/residual stream.

Decision — free chlorine (DPD) Step 14

ReadingClassificationDecision
0.2–0.5 mg/LWithin target→ Step 15
< 0.2 mg/LInsufficientTablets exhausted → refill (HAZOP: Cl₂ supply); dosing blocked → clear; high upstream demand → cross-ref Step 11
> 0.5 mg/LExcessive; by-products, odourReduce dosing

Design check: does chlorinated water recirculate through the biological zones? If yes → chlorine is suppressing the treatment bacteria → HAZOP: disinfection–recirculation sequencing (re-sequence the loop).

E. coli logic Step 15

Sample for laboratory enumeration (results at the next visit). Interpreting the returned value: below threshold with adequate Cl₂ = disinfection effective · elevated with adequate Cl₂ = particulate shielding, improve upstream treatment (cross-ref Step 11 turbidity) · elevated with no Cl₂ = complete disinfection failure (HAZOP).

Electro-disinfection — the node's chemical-free option

Where the disinfection node is filled by electro-disinfection, electrical energy generates the oxidants in situ — hydroxyl radicals, ozone, hydrogen peroxide and chlorine species — which attack the cell membranes, enzymes and genetic material of the pathogens that biological and physical treatment leave behind. It needs no dosing supply chain, suits a decentralised unit, and — the property that matters for de-risking — its whole state is electrically observable, so the disinfection node becomes one of the more readily streamed. Oxidant production is quantifiable by Faraday's law, which lets a lender-auditable set-point be derived rather than guessed:

m = (I · t · M) / (n · F) oxidant mass from current I, time t, molar mass M, electrons n, Faraday constant F = 96 485 C/mol

So current and contact time set the oxidant dose, and the reading set that follows is the decision surface — each signal has a healthy target and a stress signature illustrative (set-points to be fixed against the unit and the ISO Table 5 pathogen targets):

SignalHealthyStress signature → action
E. coli / coliformsSignificant reduction / inactivationPersistent presence or rising counts → confirm dose & contact time
ORPIn target oxidising rangeLow / unstable / sudden drops → insufficient oxidant or high organic load
Residual oxidant (free Cl₂ / HOCl)Maintained through contact periodLow / none → poor capacity or excessive demand → raise current / clean electrodes
Current densityStableFluctuating / insufficient → reduced generation → check supply / cell
Voltage / cell potentialWithin design rangeRising → electrode fouling / scaling → clean or replace electrodes
ConductivitySufficient for current flowLow → weak electrochemistry → check salinity / cell
pH~ 6–8 (optimal for oxidant activity)Too high/low → reduced inactivation → correct upstream
Turbidity / TSSLow (oxidant contacts pathogens)High → particulate shielding → improve upstream treatment
Energy consumptionStable with effective removalRising with little gain → fouling / inefficiency
Electrode conditionCleanFouling / scaling / corrosion → maintenance

Four of these signals — ORP, residual, current density and conductivity — are already SenseArray channels, so the electro-disinfection node streams its own health into the live rating and the HAZOP register in the same way the biological nodes do.

P7Greywater-stream performanceNEW in v4 · yield ≠ quality

Added in v4 after the paired two-site greywater evaluation, which established that a mechanical greywater train (coagulation → ultrafiltration → ion-exchange/GAC → disinfection) can meet its quality target while delivering only about a tenth of design yield. The protocol separates the axes:

  • Product-water yield against design — measured on a flow meter on the product line, now a protocol fixture (it is the capacity weight on the greywater product edge).
  • UF integrity / membrane protection — a pressure-hold test with a trans-membrane-pressure log, since the recurring failure is the UF membrane fouled by upstream solids.
  • Quality vs yield recorded separately — feeding the new completion criterion C7. A unit that treats correctly but delivers little recovered water is not de-risked on the recovery function.
A greywater treatment skid with blue piping, valves and an isolator switch
A mechanical greywater skid — coagulation → ultrafiltration → ion-exchange → disinfection. The UF membrane, fouled by upstream solids, is the recurring failure the yield and pressure-hold tests catch.

Selecting the train — the greywater decision-support tool (Khanyinda)

The paragraph above de-risks a train that is already deployed. The prior question is which train to deploy, and no single technology is universally sufficient: physical steps remove solids but not dissolved organics; biological steps cut COD/BOD but suffer shock loading and surfactant inhibition; natural steps (constructed wetlands, soil filtration) polish but do not reliably hit microbial targets; chemical disinfection is the final barrier but its effectiveness depends on upstream turbidity and organic demand. The answer is a multi-barrier train — physical pre-treatment (screen + grease trap) → biological (biofiltration / MBBR) → natural polishing (constructed wetland / soil filtration) → chemical disinfection — with the specific units chosen from the influent characterisation.

The governing rule — BOD/COD ratio

Biodegradability decides whether biological treatment will even be efficient: BOD/COD = BOD₅ ÷ COD.

BOD/COD ratioInterpretationTreatment implication
> 0.5Highly biodegradableBiological treatment (NBS or engineered) will be efficient
0.3–0.5Moderately biodegradableHybrid treatment system recommended
< 0.3Poor biodegradabilityChemical / advanced-oxidation pre-treatment

Influent thresholds → pathway illustrative · team-defined

Each characterisation parameter is banded NBS-suitable / needs-attention / action-required — the same green/amber/red move the rest of the protocol uses, applied to greywater selection:

ParameterNBS suitableNeeds attentionAction required
Turbidity (NTU)< 5050–150> 150 → bio-treatment / pre-screening
TSS (mg/L)< 100100–250> 250 → settling required
pH6.5–8.55–6.5 / 8.5–10< 5 or > 10 → neutralisation
COD (mg/L)< 150150–500> 500 → engineered bio-treatment
BOD₅ (mg/L)< 100100–300> 300 → engineered bio-treatment
BOD/COD ratio> 0.50.3–0.5< 0.3 → chemical pre-treatment
Total nitrogen (mg/L)< 1515–40> 40 → nutrient removal
Total phosphorus (mg/L)< 55–20> 20 → nutrient removal
Oils & grease (mg/L)< 2020–50> 50 → grease trap required
Surfactants — MBAS (mg/L)< 1515–40> 40 → inhibits biological treatment
Electrical conductivity (mS/m)< 7070–200> 200 → dilution / desalination
E. coli (CFU/100 mL)< 1010–100> 100 → UV / chlorination disinfection

Pathway logic

PathwayTrigger conditionsRepresentative systems
Nature-Based Solution (NBS)COD < 300, TSS < 150, E. coli < 100, BOD/COD > 0.5Constructed wetlands, soil biofilters, green walls
Engineered bio-treatmentCOD > 500, or BOD > 300, or turbidity > 200Membrane bioreactor (MBR), activated sludge, trickling filters
Hybrid systemIntermediate-strength; not meeting NBS criteriaCombination of physical, biological and disinfection units
The tool's output is a starting hypothesis, not a final answer: the experimental programme tests whether the indicated pathway actually achieves the required removals and reuse-quality targets at bench/pilot scale, across the range of sites and influent variability. Parameters, thresholds and pathways are illustrative pending that validation.

The reuse destination sets the target quality — differentiated, not uniform

The thresholds above characterise the influent; the treatment target is set by the destination, and one uniform quality for all reuse is the wrong specification — it over-treats some routes and under-protects others. The protocol therefore reads reuse against a differentiated ladder:

DestinationGoverning concernQuality logic illustrative
Toilet flushing (closed loop)User contact is incidental; aesthetics drive rejectionThe ISO 30500 recirculated-water values govern — colour ≤ 30 Pt-Co, the pathogen log-reductions, and odour; the E. coli band above is set for incidental contact and aerosol exposure at the pan, which is why it is this strict for a water no one drinks
Fertigation (subsurface / drip to crops)Pathogens and salts, not nutrientsNitrogen and phosphorus are the benefit, not the contaminant — the TN/TP action bands invert, and the nutrient load is credited against fertiliser demand; the governing limits become the pathogen values (WHO reuse guidance; ISO 30500 Category B), EC/sodium for soil health, and boron/chloride for crop sensitivity
Surface irrigation & landscapeContact and runoffPathogen limits tighten with public access; salinity and sodium-adsorption ratio govern long-term soil structure
Soakaway / managed infiltrationThe receiving ground, not the waterAcceptability is a geotechnical and hydrogeological question — percolation, water-table depth, and whether the setting is water-sensitive; where the geotechnical analysis clears the site and water-sensitivity is not an issue, the water-quality bar is the lowest on the ladder

Each site's reuse destination is declared at baseline, the applicable column of limits attaches to criterion C1, and a site that changes its destination (extending flush-water reuse to a garden, say) re-enters the ladder at the stricter row.

De-risking the greywater train — critical-indicators diagnostic

Once a pathway is selected and built, it is de-risked the same way as the rest of the unit — a staged verification (baseline → mid-point after each barrier → final log-reducible pathogen removal) reading the pattern across physical, organic, nutrient and microbial indicators, not one number:

Observed conditionLikely diagnosisRecommended check
High turbidity + high TSSExcessive particulate / solids loadingInspect pre-screening and settling capacity
Low BOD/COD (< 0.3)Poor biodegradabilityChemical / advanced-oxidation pre-treatment
High COD/BOD, normal TSSDissolved organic load beyond biological capacityAssess engineered bio-treatment (MBR, activated sludge)
High TN or TPNutrient loading from detergents / food wasteAdd a nutrient-removal stage to the hybrid train
High surfactants (MBAS)Detergent-driven inhibition of biologyReview household detergent use; consider pre-treatment
High ECSalinity risk from softeners / certain detergentsEvaluate dilution or desalination needs
High E. coli despite good COD/TSS removalDisinfection barrier failure or bypassVerify UV/chlorination dosing and contact time
pH outside 5–10Household chemical contaminationAdd neutralisation pre-treatment

This greywater treatment-selection and de-risking work is led by Gloseje Khanyinda (greywater characterisation and treatment sequencing), and its experimental programme will turn these illustrative thresholds into validated ones across the cohort's sites.

Process modeling — the biokinetic model, coupled to RTD (Khan)

The diagnostics measure what a unit is doing now; a mechanistic process model predicts what it will do under conditions not yet seen — a load shock, an aeration failure, a new site's influent. WESS units resist prediction from design assumptions because they run under variable loading, intermittent flow and non-ideal hydraulics.

The model's central job in de-risking is to separate two failure modes a grab sample cannot distinguish: a biokinetic failure — the microbial community cannot degrade the load fast enough — and a hydraulic failure — the reactor's actual flow deviates from the ideal, so nominally adequate biology never gets adequate contact time. Coupling a biokinetic model to the residence-time distribution resolves the ambiguity, and is the core modeling contribution of this work.

The biokinetic model

Two mechanistic frameworks: ASM2d (19 state components — carbon oxidation, nitrification, denitrification and biological phosphorus removal) coupled with UCTADM1 (13 state variables, 10 reactions — anaerobic degradation of organic matter and methane production). State variables are linked by a stoichiometric Petersen matrix, each process rate a Monod, Contois or first-order expression. The general mass balance for a reactor element of volume V receiving flow Q:

dCᵢ/dt = (Q/V)·(Cᵢ,ᵢₙ − Cᵢ) + Σⱼ νᵢⱼ·ρⱼ ρ(aerobic growth, H) = μmax · SS/(KS+SS) · SO2/(KO2+SO2) · XH (a Monod switching rate)

Oxygen enters the aerobic switch through a transfer term kLa·(SO2,SAT − SO2), carried in the code as a dissolved-oxygen-saturation boundary so the switch responds to a realistic, time-varying oxygen field rather than a fixed input. The aeration coefficient kLa — not the saturation constant — is the physically meaningful lever the de-risking work fits. The balance above is written for the liquid phase only: the gas-phase transfer of CH₄/CO₂/H₂S that governs alkalinity, pH and methane on the anaerobic side is a required extension, not yet in the liquid-only form.

What runs today, and what is planned

This distinction is needed to read the indicator table below honestly. Implemented now: a reduced three-process matrix — hydrolysis, aerobic growth and lysis — that closes the full mass balance of COD, alkalinity and suspended solids and returns the carbon-and-solids state (SS, XS, XH). It is assembled from five core components — initial conditions, influent characterisation, oxygenation, stoichiometry and process kinetics — integrated through the reactor mass balance and solved sequentially in each TIS compartment, so transport, biological reaction and oxygen transfer resolve together. It does not yet resolve nitrogen, phosphorus or the anaerobic/methane pathway. Planned: the full ASM2d (nitrification, denitrification, biological-P) and UCTADM1 (anaerobic digestion, methane) that add the nitrogen, phosphorus, methane and VFA state. The indicator table further down is therefore the full-model target set; only its carbon-and-solids rows are live in the current reduced model, and the rest are marked planned.

The hydraulic coupling — Tanks-in-Series

The reactor is discretised into N ideally-mixed tanks in series (with a toggle to a single CSTR). The TIS residence-time distribution has a closed form:

E(t) = t^(n−1) / [ (n−1)! · τᵢⁿ ] · e^(−t/τᵢ)

As n → ∞ it sharpens toward ideal plug flow; at n = 1 it recovers the single-CSTR exponential decay. Fitting n from the tracer data (the P2 diagnostic) is a direct, physically interpretable measure of how far a reactor deviates from its design intent — and the hydraulic input the biokinetic model needs. Assuming ideal CSTR hydraulics would neglect that deviation and bias the biological prediction. The tracer is what makes the separation identifiable at all: from an effluent value alone the two failure modes are degenerate — a unit with capable biology but short-circuiting hydraulics, and one with adequate hydraulics but struggling biology, can return the same number — so pinning n independently from the tracer curve leaves the biokinetics as the only remaining unknown to fit.

De-risking the model — three stages

A calibrated model is trustworthy only once it has been shown to predict, not merely fit. So the model is de-risked with the same rigour as the physical unit, in three stages that mirror the three-visit engagement:

Critical indicators — read together, never alone

Mass-balance closure error, effluent COD/N/P prediction error, biomass trends, sludge retention time, the tank number N fitted from tracer, and the agreement of the coupled model against the measured tracer curves. The interpretation is joint: a good biokinetic fit with a poor hydraulic fit (or vice versa) means the two sub-models are compensating for each other, not that both are correct. The full-model target set follows — only the carbon-and-solids rows are live in the current reduced model (see above); the rest are marked planned:

Model predictionHealthyStress signature
Readily biodegradable COD (SS)Rapidly consumed by heterotrophsElevated → overloading or low biomass activity
Particulate organics (XS)Gradual hydrolysis to substrateAccumulation → hydrolysis rate-limiting / low solids retention
Heterotrophic biomass (XH)Stable — supports COD removal & denitrificationDecay / washout → poor, unstable COD removal
Autotrophic biomass (XA) plannedStable nitrifier populationReduced → incomplete nitrification, high ammonia
Ammonium (NH₄⁺-N) plannedFalls through nitrificationPersistent → O₂ limitation, inhibition or overload
Nitrate/nitrite (NOₓ-N) plannedProduced then reducedAccumulation → poor denitrification; low → nitrification failure
Orthophosphate (PO₄³⁻-P) plannedReduced by biological P removalElevated → poor uptake or stressed PAO
Dissolved oxygen (DO)Within target rangeLow limits nitrification; high suppresses denitrification & wastes energy
AlkalinityConsumed gradually, pH heldExcessive depletion → pH decline, inhibits nitrification
Methane (CH₄) plannedStable generation → efficient digestion & COD conversionReduced → microbial inhibition, overload or poor digestion
Volatile fatty acids (VFAs) plannedFormed and consumed in balanceAccumulation → acid-vs-methanogen imbalance, digester instability
Biogas production plannedStable yield → healthy anaerobic degradationDeclining → reduced microbial activity or inhibition
Anaerobic biomass plannedStable → sustains hydrolysis, acidogenesis, acetogenesis, methanogenesisLoss/inactivity → lower digestion efficiency & methane
COD removal efficiencyHigh (combined aerobic + anaerobic)Reduced → overloading, inhibition or short retention
Sludge productionStable → balanced microbial growth and decayExcess or reduced biomass → process imbalance or washout
Effluent qualityLow COD, ammonia, nitrate, phosphateElevated → one or more biological processes deteriorating

This process-modeling work is led by Muhammad Ameen Khan (process modelling and residence-time analysis), building the WESS process and population-balance models that the field diagnostics calibrate.

Sludge management & valorisation — the decision framework (Vundla)

A WESS unit can look healthy on inspection and still carry undetected risk in what settles at the bottom. WESS sludge is more concentrated, more variable and more pathogen-rich than conventional wastewater sludge, and no structured management framework exists for it in the South African context — a gap municipalities cite as a barrier to adopting WESS at all. This work builds the first evidence-based sludge-management decision framework for WESS, grounded in field data from four operational installations.

Preliminary sampling has already confirmed the scale of the problem: significant inter-site variability in solids and organic loading, consistently acidic conditions (pH low enough to point to unmanaged acidogenesis, to be confirmed against VFA), and pathogen loading above acceptable limits. A site anomaly — effluent TSS exceeding influent TSS at one site — is flagged for resampling rather than smoothed over.

Progress to date — an underway programme, not a proposal

The framework is being built on field data and a working model already in hand, not on a plan. What is banked:

ActivityStatusOutput
Site sampling & characterisation (Obj. 1)Complete at 3 of 4 sitesPhysicochemical results across sites — total solids, COD, pH, E. coli
Sludge-blanket height field monitoring (Obj. 2)Ongoing — Week 5 data collectedLive workbook; condensed field report (Rev. 3), Upper & Lower Malacca, three tank types per site
Flocculation kinetics / PBE model (Obj. 2)Kernel rebuilt for unstirred WESS; first run completeWorking Python implementation; documented seven-step procedure with equations
Settling-performance groundwork (Obj. 3)SV30/DSVI batch data availableFirst-pass calibration input identified, not yet applied
Risk classification, techno-economic screening, framework integration (Obj. 4–7)Not yet startedDependent on Tours 2 & 3 and full characterisation

The framework — a pipeline, not a set of sub-projects

Two questions organise the work: how sludge characteristics, accumulation rates and risks can be systematically characterised and classified, and how a techno-economic and risk-based rule set can link those classes to treatment and valorisation pathways. The pipeline: characterise across physical, chemical, biological and thermal properties → quantify how fast sludge accumulates → assess how well it settles → classify into risk classes → screen valorisation options against cost and feasibility → integrate into one decision tool for operators and planners.

Characterisation panel

DomainParametersWhat they inform
PhysicalTS, VS, TSS, VSS, moisture, particle size, density, SVI/DSVISettleability & accumulation behaviour
ChemicalCOD, SCOD, BOD₅, TKN, NH₃-N, TP, alkalinity, pH, conductivity, heavy metalsTreatment demand & valorisation suitability
BiologicalE. coli, total coliforms, helminth ova, floc/filamentous microscopy (Eikelboom)Pathogen risk & settleability failure modes
Thermal pendingProximate + CHNS elemental analysisEnergy-recovery screening

Accumulation — a population-balance model built for unstirred tanks

Blanket depth is measured with a Sludge Judge at three positions per tank across visits and converted to volumetric and volatile-solids accumulation rates (L/user·day, kgVS/user·day). Predicting the time to the desludging threshold needs a settling model, and here the standard approach breaks: WESS tanks are unstirred, so the shear-driven aggregation kernel of conventional settling models does not apply. The model instead tracks the full floc-size distribution n(L,t) through aggregation, breakage and settling loss:

∂n(L,t)/∂t = B_agg − D_agg + B_br − D_br − [v_s(L)/H]·n(L,t) β(L,L′) = α·[ (2k_BT / 3μ)·(L+L′)²/(L·L′) + (π/4)·(L+L′)²·|v_s(L) − v_s(L′)| ]

The kernel is built from Brownian motion and differential settling; at the tens-to-hundreds-of-µm floc sizes of sludge, differential settling dominates and the Brownian term is essentially inactive. The one fitted parameter is the collision efficiency α. Collapsing the distribution into its moments gives two field-measurable outputs from instruments already in the panel, with no floc imaging required: TSS ∝ M₃ (floc volume) and turbidity ∝ M₂ (floc surface area). Because aggregation conserves floc volume but not surface area, the model predicts a clean diagnostic signature — turbidity falls faster than TSS during early aggregation — readable directly from a turbidimeter and a TSS measurement.

A first material-balance run (settling tank as a tanks-in-series reactor, N = 5) yields a predicted desludging-threshold time that is now being reconciled against the multi-week Sludge-Judge blanket series; that model-versus-field check is the validation step, and the accumulation rates it produces are the primary publishable output (Paper 1). Those rates do four jobs at once: they turn a measured blanket trend into a predicted threshold-crossing time for desludging scheduling, put every site on a common quantitative footing for cross-site comparison, feed the risk classification directly, and provide the field series the model is validated against.

Risk classification & valorisation decision rules

Sludge is classified into risk classes on pathogen loading, organic content and handling requirement; techno-economic rules then link measured characteristics to candidate pathways, converting a measured quantity directly into an operational decision:

Risk is scored on likelihood and consequence: high-risk findings require immediate corrective action, medium risks monitoring and optimisation, low risks routine surveillance. A single favourable reading does not offset a disqualifying one — a high heavy-metal load restricts every pathway regardless of the rest.

Valorisation pathways under consideration

PathwayPrincipleBest suited to
Anaerobic digestionBiological breakdown of organic matter under anoxic conditions, producing biogasHigh biodegradable COD, low heavy-metal load
Agricultural reuseLand application after thermophilic pasteurisation to inactivate pathogensSludge within acceptable heavy-metal and pathogen limits post-treatment
Pyrolysis pending thermal dataThermal decomposition in the absence of oxygen, producing biocharHigh organic/carbon content, low moisture
Composting with pasteurisation gateAerobic biological stabilisation to a soil conditioner; thermophilic phase (or a separate pasteurisation step) inactivates pathogens including helminth ovaC:N ratio 20–40; bulking material available; land-application route open
Other thermal routes screening stageDrying-plus-combustion (the LaDePa pattern), gasification, and hydrothermal carbonisation each trade moisture tolerance against energy input and product valueHTC where moisture is high; combustion/gasification where a heat or power sink exists; all gated by the same heavy-metal and emissions screens

The pathway set is deliberately open — composting, biochar and the wider thermal family enter the comparison as their characterisation data arrives, and the techno-economic screening ranks whichever pathways the site's sludge qualifies for; the framework fixes the method of choosing, not a fixed menu.

Settling & accumulation as a diagnostic — read together

Observed patternConditionOperational meaning
Low SVI/DSVI, steady accumulationWell-settling sludgeRoutine monitoring; desludge as predicted
Rising SVI/DSVI, filamentous growthPoor settleability developingInvestigate floc condition; review upstream loading
Accumulation diverging from modelModel–data mismatchRe-examine site-specific settling / flocculation assumptions
High COD with high moistureLow energy densityReduces thermal-conversion suitability; consider AD or composting
E. coli / helminth ova above threshold post-treatmentPathogen risk unresolvedEscalate risk class; reassess valorisation pathway

De-risking the framework — three stages

Objectives 4–7 (risk classification, techno-economic screening, framework integration) are not yet started; they depend on completing the remaining site tours and full characterisation. The framework stays site-conditional — the inter-site variability already observed means no single pathway suits all four sites.

This sludge-management framework is the MSc work of Mxolisi Vundla, supervised by Prof. Randhir Rawatlal and Dr. Samuel Tenaw Getahun, targeting two papers — Paper 1 (accumulation & characterisation; Water SA, target Q4 2026) and Paper 2 (risk-based decision framework; Journal of Environmental Management, target Q2 2027).

Part VI

The seven completion criteria

Each criterion carries a status of Met, On track, At risk or Not yet assessed — the unit-level roll-up of the green/amber/red compartment classifications. They are tracked separately even where they correlate, because the dependence between them is what the diagnostic palette is designed to expose.

CriterionDefinitionEvidence base
C1 Effluent qualityLaboratory parameters within compliance bands for the reuse destinationP6 + lab round; sensors at calibration (ISO 30500; SANS 241)
C2 Process integrityEach compartment delivering its intended treatment functionProtocols 1–4
C3 Infrastructure conditionMechanical and structural fit for purposeP3 + visual inspection + photographs
C4 Operator capabilityTrained, equipped and registered against the HAZOP registerTraining log + HAZOP
C5 Sensor coverageStreaming and calibrated against at least two laboratory roundsSensor package; installed at V1
C6 Social acceptanceUse without rejection, vandalism, misuse or community complaintSocial assessment
C7 Product-water yieldDelivered volume within tolerance of design output, where the unit recovers waterP7 product-line flow metering
C7 is new to v4 (quality and delivered volume are distinct axes). Two further v4 gates sit alongside: an inter-observer reliability check (a sample of ratings carries a second independent rating → Cohen's/Fleiss' κ or ICC); and a chain-of-custody requirement (a sample-code legend mapping every coded lab sample to site/compartment/stream) — see Part VII.

Tiered social framework: acceptance to capability (phase 2)

C6 records whether a community accepts the unit; C4 records whether its operators can run it. Between the two sits the behavioural ground the influent-variability finding (Part I) makes unavoidable, and phase 2 of the de-risking programme structures it as a tiered framework that shifts a site progressively up four rungs: awareness — the users know what the system is, what it recovers, and what must not enter it; education — the janitors and households understand why the rules hold (what a surfactant surge or a diverted greywater line does to the biology they depend on); behavioural nudges — the defaults, signage, dispenser choices and feedback that make the compliant behaviour the easy one, applied before enforcement is ever considered; and training — the formal ladder of Part I (janitor → operator → technician → advanced technician), with competence registered against the HAZOP register exactly as the engineering mitigations are. A site climbs the rungs in order, its position is recorded alongside C4 and C6 at each visit, and the aim is that by the final visit the social state of the site is as documented, monitored and managed as its process state — which is the definition of de-risked applied to people rather than to compartments.

Part VII

Laboratory results & interpretation guide

The sensor stream tracks parameters that correlate with performance but cannot directly measure every regulated indicator, so a structured laboratory schedule provides the definitive measurements. Three sampling events are conducted across the engagement, one per visit, aligned to ISO 30500:2025 and collected by trained engineers in sterile containers under chain-of-custody. This part sets out the compliance framework the results are read against, the decision each value drives, and the integrated diagnostic interpretation that turns a chamber-by-chamber data set into a single microbial diagnosis.

Labelled sample jars and a sample bottle on site concrete during a field visit
Labelled field samples during a visit. Who draws the sample, and whether the code can be traced back to a compartment, is the difference between evidence and an orphaned number — the chain-of-custody discipline below.

The compliance framework — ISO 30500:2025

ISO 30500:2018 was adopted as SANS 30500:2019; the second edition, ISO 30500:2025 (July 2025), updates the performance requirements, and the Centre sits on the SABS standards-writing division adapting it for South African conditions. A unit is first classified — Class 1/4 (backend non-biological) or Class 2/3 (backend includes one or more biological treatment processes), single- or multi-frontend — which sets its test route; this is the same declaration as placing the unit's subgraph on the reference model. The standard then fixes the numbers below. These are authoritative, not illustrative.

Environmental parameters ISO 30500 Table 6 — recirculated water & effluent

ParameterCategory A — unrestricted urban reuseCategory B — restricted reuse / discharge to surface water
COD≤ 50 mg/L≤ 150 mg/L
TSS≤ 10 mg/L≤ 30 mg/L
BOD₅≤ 10 mg/L≤ 30 mg/L

Nutrients Table 7 · pH & colour Table 8

ParameterRequirement (meet either)
Total nitrogen≥ 70% load reduction  OR  ≤ 15 mg/L
Total phosphorus≥ 80% load reduction  OR  ≤ 2 mg/L
pH6.0 to 9.0 (all reuse)
Colour≤ 30 Pt-Co (recirculated water only)

Human-health — max concentration & log-reduction Table 5 (liquid)

Pathogen classSurrogate / indicatorMax in liquidOverall LRV
BacterialE. coli≤ 100 /L≥ 6
ViralMS2 coliphage≤ 10 /L≥ 7
HelminthAscaris suum ova< 1 /L≥ 4
ProtozoaClostridium perfringens spores< 1 /L≥ 6

Noise must not exceed 60 dBA (LEX,24h) and never 85 dBA (LpA,max); odour reported as unpleasant-or-unacceptable must stay ≤ 10% of observations (≤ 2% "unacceptable"). Where recirculated water may be ingested (hand-washing, anal cleansing) the Table 5 pathogen log-removal applies with physical barriers and signage; for reuse (e.g. irrigation) the DWS Revised General Authorisations (2013) also apply. Free chlorine at the interface is held at 0.2–0.5 mg/L illustrative as the operational disinfection set-point.

The ISO compliance rule (not a single reading). Environmental thresholds (Tables 6–8) must be met in at least 4 of 5 test events, with no more than 20% variance on any failed parameter, and results are not averaged. Human-health thresholds (Table 5) must be met in each event. In field verification, ≥ 75% of environmental results and 100% of human-health results must pass. This is why the de-risking rating separates a green reading from a confident, repeated green reading — the ISO test is itself non-averaging and event-based, exactly the discipline the live rating enforces continuously.
CategoryParametersSampling pointsDecision driven
DisinfectionE. coli (CFU/100 mL), free chlorine, total coliformsRecirculation line, toilet bowl, greywater outletC1 safety; Step 15 logic (shielding vs failure)
Greywater qualityColour (Pt-Co), COD, BOD, TSS, TDS, nutrients (N, P)Greywater compartment, recirculation tankC1 quality; reboot trigger (Step 11–12)
SludgeTotal solids, volatile solids, SVIPrimary settler, secondary clarifier, sludge holdingC2/C3; desludging trigger (Step 6)

Mapping a returned value to a decision

ParameterMethodDecision value / limitSensor surrogate
E. coliLab (culture / qPCR)≤ 100 /L & LRV ≥ 6 ISO T5— (microbial channel; lab-anchored)
Free chlorineDPD (field)0.2–0.5 mg/L illus.ORP / residual
ColourPt-Co≤ 30 Pt-Co ISO T8Turbidity + optical
CODLab≤ 50 (Cat A) / ≤ 150 (Cat B) ISO T6Soft-sensor MLR
BOD₅Lab≤ 10 (A) / ≤ 30 (B) ISO T6Soft-sensor MLR
TSSGravimetric≤ 10 (A) / ≤ 30 (B) ISO T6Turbidity (well-inferred)
TDSGravimetric / ECSite threshold; trend < 5%/wk illus.Electrical conductivity (direct)
Total N / PLabTN ≥70% or ≤15 · TP ≥80% or ≤2 ISO T7Soft-sensor MLR
SVI / solidsSettling + gravimetricSVI < 120 good; DSVI on saturation illus.Turbidity + settling test

Laboratory results also calibrate the sensor stream: correlating lab TDS with sensor conductivity, for instance, lets the stream serve as a continuous TDS proxy between sampling events, and the site-specific calibration improves with each round. This is the same paired data the v6 surrogate model consumes, and each returned value maps to a green/amber/red band and, in v6, to the compliance probability pₖ for its criterion.

The integrated diagnostic interpretation

The chamber-by-chamber data — COD, DO, ORP, pH, nitrate/nitrite, turbidity/TSS, sludge, foam and gas — is not read parameter by parameter. No individual parameter is interpreted independently; the diagnosis is the combined pattern of evidence. The objective is not to identify species but to decide whether the biological process is stable, stressed, overloaded, inhibited, oxygen-limited, washing out, or at risk of failure. The two surfaced tables below are the load-bearing ones — the integrated diagnostic matrix and the FMHI scorecard; the per-signal interpretation guides sit in the accordion beneath.

The integrated diagnostic matrix — combined pattern → diagnosis

Combined patternLikely diagnosis
COD high + low DO + negative ORPOrganic overload
COD plateau + ORP decreasing + pH fallingFermentation / acidogenesis
Positive ORP + measurable DO + nitrate presentOxidative biological activity (healthy)
Mildly negative ORP + nitrate decreasingDenitrification
Strongly negative ORP + odour presentSulfide-formation risk
Turbidity increasing + COD worseningBiomass washout
Poor settling + diffuse sludge blanketFilamentous bulking
High foam/scum + unstable settlingEPS overproduction
Low DO + low COD removalBiological inhibition
Low biomass indicators + poor performanceBiomass collapse

Functional Microbial Health Index — the traffic-light scorecard

Eight indicators are each classified green / amber / red and rolled up to one FMHI band for the compartment. The eight: COD profile, DO profile, OOUP, ORP profile, pH stability, nitrogen transformation, turbidity/TSS, and biomass structure.

FMHI classificationMeaningRecommended response
GREEN StableMicrobial community healthy and functioning as intendedContinue routine monitoring
AMBER StressedEarly warning signs of stress presentIncrease monitoring and implement corrective action
RED CriticalMicrobial function severely impaired or at risk of collapseImmediate investigation and intervention
iCOD Treatment-Train Profile (CTTP)substrate removal

COD is the surrogate for organic matter available for microbial degradation; a progressive decrease between compartments indicates successful substrate utilisation.

ObservationInterpretation
Progressive COD reductionActive microbial degradation and substrate utilisation
COD plateauReduced activity, insufficient retention or limited biodegradability
COD increase between chambersSolids resuspension, biomass decay, sludge disturbance or sampling variation
High COD throughoutOrganic overload or poor treatment progression
Minimal COD reductionBiological underperformance, inhibition or insufficient biomass
iiOxygen Distribution & Utilisation (ODP / OOUP)aerobic vs anaerobic zoning

The ODP reads DO across sequential compartments (not a single-reactor OUR), giving an operational map of aerobic, oxygen-limited and anaerobic zones. Always read with the CTTP, ORP, pH, nitrogen and biomass.

DO conditionZone
> 2 mg/LAerobic
0.5–2 mg/LOxygen-limited
< 0.5 mg/LAnaerobic likely
ObservationInterpretation
Progressive decline in DOActive oxygen consumption by microorganisms
Stable DO across compartmentsLimited biological oxygen demand or reduced activity
Sudden increase in DOAeration, mixing or polishing stage
Persistently high DO with poor COD removalPossible microbial inhibition or insufficient biomass

OOUP — Operational Oxygen Utilisation Profile (WESS-specific)

Operational Oxygen Utilisation (%) = ((DO_influent − DO_chamber) / DO_influent) × 100

Quantifies the relative DO drawdown between sequential compartments under real operating conditions — a field diagnostic that supports, not replaces, laboratory OUR.

iiiMetabolic State (ORP + DO + pH)dominant pathway
ORP rangeMetabolic state
+100 to +400 mVAerobic
0 to −100 mVAnoxic
−100 to −250 mVAnaerobic
< −250 mVStrongly reducing
Combined evidenceInterpretation
Positive ORP + measurable DO + stable pHAerobic biological activity likely
Mildly negative ORP + nitrate present/decreasingAnoxic conditions and possible denitrification
Negative ORP + low DO + falling pHAnaerobic degradation, fermentation or acidogenesis risk
Strongly negative ORP + odour/gasStrongly reducing; sulfide or methanogenic risk
ivNitrogen transformation & biomass healthN pathway · washout / bulking

Nitrogen transformation (read nitrate/nitrite with ORP + DO)

ObservationInterpretation
Nitrate present + positive ORPOxidised nitrogen conditions
Elevated nitriteIncomplete nitrification or unstable nitrogen transformation
Decreasing nitrate + mildly negative ORPDenitrification
Nitrate present + strongly reducing ORPNitrate present, but active nitrification unlikely under prevailing redox

Biomass health

Observation patternInterpretation
High turbidity + increasing CODBiomass washout
Poor settling + diffuse sludge blanketFilamentous bulking
Excessive foam/scumEPS overproduction or microbial imbalance
Low sludge volumeBiomass loss or poor retention
Dense compact sludgeStable biomass retention
The precondition — chain of custody. Each laboratory sample is labelled with a code, and the record must carry a legend mapping every code to its site, compartment or stream, and visit. The first field application found this the single most consequential documentation gap: results returned under codes that could not be paired back to a compartment leave C1 without an evidence base, because a number that cannot be located is not evidence. The legend is a required deliverable of every sampling round, recorded in InfraTrack, and a de-risked declaration is not issued for a criterion whose supporting samples cannot be traced to their source.
Part VIII

The HAZOP spine & mitigation catalogue

The same field information, read from the risk side, forms a living HAZOP register. Each of the five treatment compartments is a study node, and v4 adds a sixth — the User-and-Community Interface. For each node the standard guide words (NO, MORE, LESS, REVERSE, PART OF, AS WELL AS, OTHER THAN) are applied to the relevant parameters; a deviation is scored on a 5×5 severity × likelihood matrix, and the score sets the priority of the action exactly as a traffic-light band does.

The 5×5 HAZOP severity–likelihood matrix
The 5×5 severity–likelihood matrix on which every register entry is scored.
NodeParametersPrincipal deviationsProtocols
1 · Primary settlingFlow, level, retention, sludge depthNO settling; MORE sludge; LESS retention; AS WELL AS foreign objects1, 3
2 · Biological treatmentDO, pH, temperature, biomass activityNO activity; LESS DO; MORE toxic loading; OTHER THAN expected organisms1, 4
3 · Secondary clarificationTurbidity, SVI, hydraulic loadingMORE solids carryover; LESS settleability; REVERSE (rising sludge)1, 3
4 · Greywater treatmentTDS, turbidity, colour, nutrientsMORE dissolved solids; LESS treatment; AS WELL AS accumulation over cycles1, 5
5 · DisinfectionCl₂ residual, E. coli, colour, odourNO disinfectant; LESS pathogen removal; OTHER THAN expected colour/odour1, 6
6 · User & CommunityInfluent composition, use intensity, stream routing, cleaning inputsOTHER THAN expected influent (surfactants); AS WELL AS cleaning agents; MORE flush intensity; PART OF / REVERSE greywater diverted4, 5

The sixth node is a v4 correction and a load-bearing one: reading the register with explicit behaviour classes showed that 29% of entries are behaviour-class, and every one bears on C2 — the process-integrity criterion the cohort fails at every site. Three behaviour-extension deviation classes are scored on the same matrix: cleaning-product chemistry, user behaviour, community practice, with a stated keyword rule so the share is reproducible.

The mitigation catalogue

Every red or amber band carries a defined intervention. The catalogue below is the decision matrix — deviation, its cause, the mitigation, the step that raises it, and whether it is an operating action (OpEx) or a capital/design change (CapEx), and whether it is provider-controllable or driven by household behaviour.

DeviationMitigationStepType
Over-aeration (zoning collapse)Reduce aeration rate; check baffle integrity between zones4, 7OpEx · controllable
Surfactant / cleaning-product loadingIdentify products; community education on WESS-compatible products4OpEx · behaviour
Toxic / low F:M imbalanceCheck influent for toxics; increase sludge feed from primary settler4OpEx · mixed
Settling / biological community failureSystem reboot (partial/full water replacement) + reseed with live culture4, 10OpEx · controllable
Live culture not on handAdd live bacterial inoculum to O&M consumables & procurement schedule16OpEx · controllable
Elevated sludge blanket40–50%: schedule desludging · >50%: desludge immediately6OpEx · controllable
Dead volume / short-circuitingInvestigate sludge accumulation; assess / modify baffles5CapEx · controllable
Colour / TDS accumulationPartial reboot (30–50 Pt-Co) or full reboot (>50 Pt-Co / TDS over threshold)11–12OpEx · controllable
Insufficient chlorineRefill tablets / clear dosing blockage; trace upstream demand14OpEx · controllable
Excessive chlorineReduce dosing (by-product & odour risk)14OpEx · controllable
Chlorine recirculating through bio zonesRe-sequence the loop so disinfected water does not re-enter treatment14CapEx · controllable
E. coli elevated with adequate Cl₂Particulate shielding → improve upstream treatment / reduce turbidity15OpEx · controllable
Fresh water for reboot not securedSecure a reboot water supply12, 16CapEx / logistics
Excessive flushing / greywater diversionDemand management + community practice; engineer tolerance to the behaviour envelope12Design · behaviour
Power supply unreliableReliable power (solar / battery / grid)16CapEx · controllable
Structural integrity compromisedMaintenance / repair (leaks, tank condition)16CapEx · controllable
The behaviour-class rows carry into the v6 covenant: a margin ratchet that penalises the provider for household practice is unfair. The durable fix is engineering the unit's tolerance to the behaviour envelope — choosing node options and capacities robust to how the unit is actually used — not penalising the provider for the user (Part X §D).

The WESS mitigation library

Every recommendation the protocol raises resolves to an entry in a shared mitigation library, each with a stable ID so the same fix is named the same way across sites and its outcomes can be pooled. This is the canonical list — the diagnostics and the lab review both draw from it.

IDMitigationTypical triggerType
M01Desludge + sludge-judge cadence (desludge at 50% blanket)Blanket > 50%; septic COD/TSS climbingOpEx
M02System reboot ± reseed with live cultureBiological community failure; inhibitor build-upOpEx
M03Increase internal recirculation (anoxic→sedimentation, 3–4× influent)NO₃ accumulating; denitrification carbon-starvedOpEx
M04External carbon dose to anoxic (methanol/acetate, ~3 g COD per g NO₃-N)Internal carbon insufficient for denitrificationOpEx
M05Chemical-P: alum/PAC jar-test then dose at sedimentationPhosphorus removal below reuse specOpEx / CapEx
M06Aeration correction (blower / diffuser)Aerobic DO outside 2–4 mg/L bandOpEx
M07Re-sequence disinfection loop (chlorinated water out of bio zones)Recirculation suppressing treatment bacteriaCapEx
M08GAC polishing stage downstream of disinfectionColour / organics above reuse specCapEx
M09Install minimum sensor suite to InfraTrack (DO+EC aerobic, turbidity at disinfection)Sparse / no continuous monitoringOpEx / CapEx
M10Rebalance hydraulic distribution across plantsLoad imbalance between parallel unitsOpEx
M11Composite sampling + SANAS chain-of-custodyGrab-sample variance; unauditable dataOpEx
M12TDS reboot SOP (partial drain-down at effluent TDS > 1500 mg/L)Salt accumulation in the recirculation loopOpEx
M13Community education on cleaning products / behaviour envelopeSurfactant load; behaviour-class deviationOpEx · social

Priority scoring — which mitigation first

A site can raise a dozen flags; the register is prioritised so the team acts on the right one first. Each candidate mitigation is scored on four axes, each 1–5, and combined:

Priority = (S × C × I) / E range 0.2 – 125
AxisCaptures15
S SeverityImpact of the failure on the seven criteriaCosmetic; criterion still metMultiple criteria failing; public-health pathway open
C ConfidenceHow well the data evidence the diagnosis (tier-weighted)Grab sample only, unconfirmedSANAS lab + corroborating field tiers
I ImpactExpected risk reduction if implementedMarginalBrings multiple criteria to On Track / Met
E EffortCost, time, disruptionOperator action, < 1 day≥ 3 months and/or capital

Priority bands: ≥ 30 Critical (this week / before next visit) · 10–30 High (within 4 weeks) · 3–10 Medium (8–12 weeks) · < 3 Low (document only). A worked, scored register on real lab data is in Part XI, Example 3.

A worked register — Site S001, Visit 1

Each entry is scored on the 5×5 matrix as Likelihood × Consequence; the score sets the priority and drives a linked recommendation. This is a real baseline register from the reporting exemplar — five entries opened at a first visit, each traceable to a field reading in the diagnostics above.

EntryNodeGuide wordDeviationRisk
HAZ-001Primary settlingNONo settling after 30 min; SVI not calculable12 (3×4)
HAZ-002Primary settlingMORESludge blanket at 69% of depth; exceeds 50% threshold9 (3×3)
HAZ-003Aerobic polishingMOREPersistent dense foam (5 cm) from surfactant loading6 (3×2)
HAZ-004Aerobic polishingLESSDO ~47% sat., similar to anaerobic zones; insufficient aeration12 (3×4)
HAZ-005DisinfectionLESSFree Cl₂ drops to 0.3 mg/L at the toilet interface (below target)16 (4×4)

The linked recommendations

ActionPriorityOwnerLinks
Investigate aeration in the polishing zone; measure air-flow and confirm diffuser conditionHighProviderHAZ-004
Assess primary settling tank for desludging (blanket 69% > 50%)HighProviderHAZ-002
Review chlorine dosing rate; relocate dosing point closer to toilet blocks to hold residual > 0.5 mg/LHighWESP + ProviderHAZ-005
Develop community awareness material on detergent / cleaning-agent dischargeMediumWESP teamHAZ-003
Calibrate deployed sensors against laboratory results once availableMediumL. Naidoooperational
Conduct the residence-time tracer test on anaerobic chamber 1 at Visit 2MediumM. KhanV2 schedule

The full register is maintained per site and live in InfraTrack; the recommendations carry a responsible party and a timeline (typically "before the next visit"), and a CapEx recommendation is flagged distinctly from an OpEx one. This is how the assessment ends in a decision and a next step, not a table of numbers.

Part IX

The data layer & streaming exit

The data layer has two parts. SenseArray is the time-series capture service: a low-cost package built on commodity probes measuring pH, dissolved oxygen, temperature, turbidity, electrical conductivity, TDS and ORP, integrated on a microcontroller platform with local logging and online transmission, installed at the monitored nodes and streaming through a single ingestion endpoint into a central store.

The low-cost monitoring enclosure with LCD and sensor ports beside labelled sample vessels
The field data-logger: a low-cost microcontroller enclosure with local display and multi-probe ports, developed in-house.
A Gravity pH-meter sensor interface board
A representative probe interface — the package is assembled from commodity sensors to keep per-site cost low.

The value of the package is the soft-sensor models on top: multiple-linear-regression models estimate the more expensive compliance parameters — chemical oxygen demand, total nitrogen and phosphate — from the cheap physical measurements, and with drift correction they let that inexpensive, foulable stream substitute for the laboratory between visits. This is exactly the inference the v6 rating consumes, and each physical channel maps to what it can carry:

Physical channel (measured)Infers / carriesConfidence
TurbidityTSS (physical relationship); COD contributionStrong — should validate to a high maturity
Electrical conductivity, TDSIonic load; the TDS proxy between labsStrong (direct)
ORPRedox / metabolic state; disinfection stateModerate (context)
pH, temperatureProcess stability envelopeDirect
MLR of the aboveCOD, total nitrogen, phosphateUnder validation illus.
— (no physical proxy)E. coli / biological countNone — microbial channel, lab-anchored

Each inference carries a maturity that gates how far it may drive the rating on sensor data alone (the v6 term mk in Part X §B): a strong physical relationship like turbidity→TSS clears the gate early; the MLR estimates of COD, N and P ride between labs only once their prospective validation clears the bar; E. coli never rides the physical stream and stays lab-anchored. The stream is only trusted while it is live and calibrated — a readiness gate checks liveness (expected readings received, in plausible range, tamper-clear), calibration currency (against the last two lab rounds) and drift, and a failure of any drops the node to Provisional rather than passing a stale reading as fresh.

The regression work has reached first results. Models fitted on turbidity, TDS, electrical conductivity and pH return the following Pearson r2 against laboratory analysis, by model degree:

Model degree (includes constant column)CODTotal NP
10.7350.5330.983
2, excluding interaction terms0.8490.7560.998
2, including interaction terms0.9620.9871.000

These are training fits on a limited dataset, not cross-validated results tested for overfitting, and they will change as site data accumulates. The phosphate column in particular is too good to trust at this sample size and should be read as a sign of overfitting rather than of accuracy. The figures are reported here because the direction is informative — COD and total nitrogen respond strongly to the interaction terms — but no MLR estimate rides the rating on sensor data alone until prospective, cross-validated performance clears the maturity gate.

Development status (honest). Sensor selection, power distribution, local data acquisition, the calibration protocol, and the online database and SenseArray dashboard are complete. Field deployment has begun: units are being installed at sites, connected to site power and collecting data, with the first installation completed on 21 July 2026. Waterproof housing, long-term stability and drift compensation, streaming optimisation, and the enlargement of the dataset needed to cross-validate the soft-sensor models are in progress; soft-sensor implementation into the continuous-monitoring path follows validation.

InfraTrack is the platform on which the record is managed and read: a national status map, the alerts and recommendations as they arise, and the live sensor streams, field observations, laboratory results, HAZOP register and compliance status of every site in one view.

InfraTrack dashboard rendering sites as a live status map
InfraTrack consolidates every site's streams, labs, HAZOP register and status.
InfraTrack national site map
The national set of sites as a live status map.

A site is designated de-risked when its subgraph is declared, its HAZOP register is populated, its soft sensors are streaming through SenseArray to InfraTrack showing each monitored node within norms, the laboratory schedule is established, and the O&M staff are trained. From that point the streaming exit makes the v6 live rating possible.

Part X · the v6 direction

The live rating

The De-Risking Certificate is the financeable artefact, and it has a structural weakness the method's own opening argument exposes: a unit drifts from specification, so a certificate that stamps a time-varying risk at a point in time is decaying from the day it is issued.

Version 6 turns the stream into a live rating on a small ordinal scale the sensor stream maintains and a lender holds as a covenant. One principle runs through every layer — an unknown is a penalised state, not a neutral one.

BandStateConditionFinance consequence
ADe-risked (Live)All criteria green, stream current and confident, no open high-severity HAZOP nodeFull spread benefit (~prime − 3.0 pp)
BWatchA criterion amber, a leading indicator tripped, or drift detectedReduced concession; provider notified
CProvisionalSensor stream degraded/offline, or a lab round overdueNo concession — the site is unobserved
DBreachA criterion red, or a high-severity HAZOP node realisedCovenant event; remediation window opens
A unit health dashboard showing per-node status and trend
The rating is the runtime of the diagnostic: each monitored node carries a live status and trend, rolled up to the site band.

A fouled or unplugged sensor drops the site to C, and only a confirmatory laboratory round restores A — never the stream simply reading green again. The rating launches on the robustly inferable criteria first (TSS from turbidity, settleability, process state) and treats E. coli and BOD as lab-confirmed inputs that age. The four technical annexes below make it audit-grade.

§AThe rating mathematicsaudit-grade

Compliance and confidence are kept separate: "probably compliant but barely observed" must rate below "probably compliant and confident."

pₖ = Φ( (L − μ) / σ ) compliance probability from the predictive distribution cₖ(t) = vₖ(t) · φₖ(t) · mₖ confidence (liveness · freshness · model maturity) φₖ = exp( −(t − t_last,k) / τₖ ) freshness decay; τₖ = drift half-life qₖ(t) = cₖ · pₖ + (1 − cₖ) · p_floor,k risk-adjusted compliance — unseen ⇒ pessimistic floor S(t) = Π_k qₖ ^ wₖ ( Σ wₖ = 1 ) non-compensatory geometric mean

Weights wₖ come from HAZOP severity and the node capacity weights now, the actuarial library later, and are published. Band decision, first match wins: D any criterion confidently red (pₖ<p_red AND cₖ≥c_min) or a realised high-severity node; C confidence below threshold on a material criterion (we do not certify what we cannot see); A S≥S_A AND every material cₖ≥c_min AND no open high-severity node; B everything else. The asymmetry is intentional — failing-but-blind → D; fine-looking-but-blind → C. A bad reading at low confidence routes to C plus a priority verification lab round, never a direct covenant D. Transitions require persistence (n consecutive updates or a CUSUM control-limit breach), with asymmetric hysteresis — easy to fall, hard to rise. Every parameter is a stated, auditable number.

§BThe surrogate-model validation planthe load-bearing dependency

The rating rests on the model inferring the compliance parameters from the cheap stream, so maturity mₖ is earned. For each parameter build a calibrated predictive distribution p(y | x, site, t) — a Bayesian hierarchical (partial-pooling) regression with global coefficients and site random effects, censored-lognormal for E. coli/BOD, with drift terms. A pair is a lab result matched to the concurrent sensor vector (the v4 chain-of-custody fix makes pairs constructible), sampled to span the exceedance region, not just steady-state green. Validate by leave-one-site-out (a new site at V1) and prospective forward-in-time (predict the next lab round), scoring interval coverage and Brier/AUC on P(exceed) near the limit — never in-sample R². The published gate: a criterion may drive an A-band on sensor data alone only when its prospective coverage, exceedance discrimination and paired-evidence count are met; below the gate mₖ is capped low and the criterion stays lab-anchored with a short τ. Expected early outcome: TSS/turbidity clears; E. coli and BOD stay lab-anchored.

§CThe microbial channel in the ratingsee Part V · P8 for full detail

The microbial channel (three tiers, six-strip BioProfile, indices and joint-pattern logic) is documented in full in Part V · P8. Its bearing on the rating: the BioProfile fingerprint decomposes across several criteria (FVI → safety, BFI → fouling, NRFI → nutrients, AEPI → AMR flag), each becoming a pₖ only through lab calibration. Today there is no online microbial stream, so liveness is ≈0 between visits and the criterion is carried by lab-and-BioProfile freshness (short τ), with the laboratory cadence set from τ so a site does not sit at Provisional on public health. Medium-term, the Ramsurran solid-state camera-read indicator supplies a genuine online stream and, once validated, raises mₖ so the microbial criterion can finally ride between visits.

§DThe loan covenanthow the band prices a loan

A margin ratchet — the interest margin a function of the band — prices risk continuously rather than at a cliff (the structure of a sustainability-linked loan); the cliff (event of default) is reserved for sustained failure. The rating-math penalty and the covenant penalty become the same lever: a provider who lets the sensor go dark drops to Provisional and loses the concession that month.

BandMarginEffect
A Liveprime − 3.0 ppFull concession
B Watchprime − 1.5 ppReduced, under observation
C Provisionalprime − 0 ppNo concession — site unobserved
D Breachprime + penaltyRemediation clock; penalty margin during cure

Operative clauses: reliance & liability (a stated-basis opinion, not a guarantee); data & access covenants (keep the package powered, unobstructed, untampered — closing the gaming loop); remediation & cure (30–60-day window aligned to the between-visit rhythm; restoration needs a confirmatory lab); a standing-service fee (a subscription, borrower-pays, funding recurring telemetry and bi-annual labs — what decouples value from a single loan); independence (the rating entity contractually separate from the platform vendor and provider); and a forward portfolio hook. Fairness point: behaviour-class deviations are 29% of the register, partly outside provider control, so provider-controllable and exogenous drivers are distinguished in the ratchet, or behaviour-class breaches given a longer cure window.

One mechanism, both scales. Every rating transition is an event in a loss dataset; the fleet-level distribution of ratings is the portfolio loss distribution a guarantee facility or parametric performance-insurance product prices against — the bridge from a per-site spread nudge to WESS as a priced, assessable asset class.
Part XI · redacted

Worked examples

Two field walk-throughs, site identifiers redacted, showing the decision tree end-to-end: real readings resolved into classifications, mitigations, a HAZOP register and an opening rating. Operational thresholds are illustrative; ISO limits are authoritative.

Example 1 — Site α, a household-scale unit at baseline (V1)

A blackwater-line unit (primary settling → anaerobic ×2 → aerobic polishing → disinfection → recirculation). The team runs the observational diagnostics, installs the sensors, and takes the first laboratory round. The readings, by phase:

CompartmentBlanket ratioDO (% sat.)ColourFoam
Primary settling61–69%2.1BlackNone
Anaerobic 136–43%4.5Dark greyLight scum
Anaerobic 224–28%8.2Grey-brownNone
Aerobic polishing10–13%46.8Light brownDense white, 5 cm
Disinfection—38.2Pale yellow-greenNone

Walking the tree:

The register and its linked actions (the same five entries developed in Part VIII):

EntryDeviationRiskAction
HAZ-005Free Cl₂ 0.3 mg/L at interface16Review dosing; relocate dosing point closer to blocks
HAZ-001Primary: no settling / SVI n/a12Resolve via desludge (HAZ-002); re-test
HAZ-004Aerobic polishing DO too low12Investigate aeration; measure air-flow, diffuser
HAZ-002Primary blanket 69% > 50%9Desludge before V2
HAZ-003Dense foam / surfactant6Community awareness on cleaning agents

Opening rating. Process integrity (C2) and effluent quality (C1) are At risk — a red disinfection residual and an under-aerated polishing stage — so on the v6 scale the site would open around B–C: the criteria are not green, and with the sensors only just installed the stream is not yet confident enough to hold A regardless. The three-week action window (desludge, aeration, dosing) is exactly the between-visit remediation the rating's cure logic assumes; a V2 re-test that clears the reds and two confident stream windows are what would carry the site toward A.

Example 2 — Site β, an integrated microbial diagnosis (two lines)

A two-line site (blackwater chambers D15–D21, greywater D22–D27, a septic/sludge node D28). Reading the chamber data through the integrated interpretation (Part VII):

Blackwater COD profile across chambers
CTTP — COD falls progressively down the blackwater line: active substrate utilisation.
TSS/VSS profile across samples
TSS — a sharp spike at D17 against an otherwise declining profile: a localised washout.

Example 3 — Site γ, reading a laboratory report into mitigations

A 63-household site running three parallel biological plants (influent → anaerobic → sedimentation → aerobic → anoxic → 2nd sedimentation → disinfection), treated water reused for flushing only. Five accredited (SANAS) laboratory reports were reviewed. The final-effluent report is read parameter by parameter — each value against expectation, then to a mitigation from the library:

ParameterValueReading & decision
E. coli1 CFU/100 mLDisinfection working — down from 13 000 (≈4-log). Meets the health target.
BOD₅6 mg/L97% removal (from 213). Well within ISO Cat A (≤10).
TSS8.0 mg/L69% removal (from 26). Within Cat A (≤10).
COD66.4 mg/LWithin Cat B (≤150) but close to the ~75 discharge ceiling — thin margin against load shocks.
NO₃-N47.3 mg/LNitrification complete but denitrification is not occurring — the anoxic stage is not delivering. → M03/M04
NO₂-N4.17 mg/LNon-trivial — nitrite-oxidisers lagging ammonia-oxidisers; track visit-to-visit.
Total P9.78 mg/LOnly ~67% removal; no chemical-P stage. Blocks any <5 mg/L reuse spec. → M05
TDS1 234 mg/LHigh and climbing as the reuse loop concentrates salts. Set a reboot rule at >1500. → M12
True colour129 Pt-CoAcceptable for flush; visually noticeable. GAC polishing if reuse extends. → M08
DO5.27 mg/LConfirms the aerobic chamber is functioning.

The septic chamber tells a second story: COD climbed 1 657 → 5 691 and TSS 42 → 2 544 over two months with no desludge cadence — the single highest-severity finding. Consolidating every flag through the priority scoring (S×C×I/E) gives a register that acts on the right thing first:

MitigationSCIEPriority
M01 Desludge septic + sludge-judge cadence5551125 Critical
M11 Composite sampling + SANAS chain-of-custody353145 Critical
M10 Rebalance load across the three plants444232 Critical
M12 TDS reboot SOP (> 1500)243124 High
M09 Minimum sensor suite to InfraTrack354320 High
M03/M04 Recirculation audit + carbon on standby344316 High
M05 Alum/PAC jar-test for phosphorus24338 Medium

The scoring corroborates the engineering judgement — desludge and load-rebalance surface first — and additionally promotes the sampling-protocol fix (M11) that a narrative read under-weights: the January-to-March influent ammonium varied 60× on the same plant, which is more plausibly grab-sample variance than a real influent change, and until the data are auditable every downstream diagnosis inherits that uncertainty.

All three examples show the same move: readings → functional index → green/amber/red → a decision and a next step, ending in a register and a rating — never a table of numbers left for after the visit. The redaction removes only the site names; the readings, the lab values and the decisions are the real thing.
Part XII

Cost & financial de-risking

Before the numbers, the approach. Financial de-risking converts the engineering record this protocol produces into a price: a lender who can see an independent operating record prices the loan against evidence rather than against uncertainty, and the spread falls. The mechanism has three parties. The technology provider sources the finance — it is the provider who borrows, from a commercial bank, to manufacture and deploy units at scale, and the provider who carries the interest cost that de-risking reduces. The de-risking engagement is paid for separately and in advance of the loan: under the WESP De-Risking Fund the per-site cost is co-funded 50/50 between the fund (seeded by the Water Research Commission, financial institutions and corporate social investment) and the provider, keeping the provider's incentive aligned with the outcome. The lender pays nothing, and receives the certificate — in v6, the live rating held as a covenant — as the independent record it otherwise lacks. The municipality or site owner enters not as a financier of the de-risking but as the payer for the sanitation service whose reliability the whole arrangement secures.

Within that structure, a full engagement is of the order of R 175,000 per site.

Cost itemAmount
Engineering personnel — three visits, field and analysisR 78,000
Laboratory analysis — settleability, sludge, microbial, complianceR 40,000
Soft-sensor package, installation and first-year telemetryR 30,000
Travel and site logistics — three visitsR 15,000
Field consumables and test kitsR 7,000
Reporting and certificationR 5,000
Total per siteR 175,000

Under the WESP De-Risking Fund the cost is met 50/50, so the provider carries about R 87,500. Under v6 the telemetry and laboratory lines become recurring — the standing-service fee — rather than one-off.

The bankability case

On an illustrative R 3,000,000 loan over five years, a three-percentage-point reduction in spread saves roughly R 266,000 in interest over the term:

At prime (11.5%)At prime − 3 pp (8.5%)
Monthly repayment (R 3.0m, 5 yr)R 65,978R 61,550
Total interest over the termR 958,669R 692,976
Interest saving—R 265,694
Net benefit to the provider—≈ R 178,000

Net benefit reaches zero at a break-even spread reduction of about one percentage point for this loan, rising as the loan shrinks. The one input the field programme cannot supply — the spread a certificate actually earns — is a stated objective of the commercial-bank engagement, which in v6 widens to fixing the whole ratchet and covenant structure. Each de-risked site is also a reference case for the provider's next application, and the recurring rating fee is a standing revenue line rather than a cost amortised against one facility.

Bankability at portfolio scale: ten sites

The single-site table understates the case, because the lender's real question is about a deployment, not a unit. For an illustrative programme of ten sites, each financed as above:

Portfolio line (10 sites, illustrative)Amount
Loan book (10 × R 3.0m, 5 yr)R 30,000,000
Interest saving at a 3 pp spread reduction, over the term≈ R 2,660,000
De-risking cost (10 × R 175,000, before the 50/50 co-funding)R 1,750,000
Provider's share under the Fund (10 × R 87,500)R 875,000
Net benefit to the provider across the portfolio≈ R 1,785,000

Three things change at this scale that no single site shows. The evidence compounds: ten monitored sites give the lender a distribution, not an anecdote, so the priced risk falls further than the per-site arithmetic suggests. The fixed costs dilute: the engineering team, the laboratory relationship and the data platform are stood up once and amortise across the book, so the marginal site costs less than the first. And the portfolio becomes the covenant: under v6 the lender holds not ten certificates but one live view of a rated fleet, which is the instrument a development financier or a securitising bank can actually work with. Bankability, for a ten-site programme, means the de-risking pays for itself out of the interest saving alone, before any value is placed on the reference cases, the standing-service revenue, or the faster approval of the next ten.

Part XIII

Circular-economy context

The circular-economy framing held up in the field and is carried unchanged from v3 — on the reference model it is the residuals-and-recovery lane. Open it if you need it.

XIIWESS as circular-economy infrastructurerecirculation · nutrients · sludge · energy · policy

Water recirculation. The unit recovers treated water for flushing and reuse, closing the loop at the point of generation.

Nutrient recovery. Nitrogen and phosphorus concentrated by the train can be recovered rather than discharged — the nutrient-recovery node, fed by the nitrogen-removal read.

Sludge valorisation. Solids characterised by the sludge-profile diagnostic can be valorised as biochar or compost, turning a desludging cost into a product.

Energy balance. The community reference site runs entirely on solar power; the protocol assesses the energy balance as part of operational sustainability.

Policy positioning. The method sits within the revised ISO 30500 (2025), SANS 241 and the draft model by-laws defining WESS as a non-sewered sanitation category permitted to treat and reuse water on site.

Part XIV

Team & trajectory

The programme is delivered by a small core team, each member holding one axis, so the eight diagnostics are the field expression of seven specialisms. In the KwaZulu-Natal cluster the team is joined by two eThekwini Municipality trainee engineers.

The framework is exercised and stable; what remains is depth of coverage — the sensor-streaming final visits, the Lilliput trio's first visits in Q3 2026, and the spread a certificate earns confirmed against a real lender. Phase 2 extends the framework to twenty further sites with train-the-trainer coursework for municipal engineers (CPD through the Water Institute of Southern Africa), transferring the capacity to de-risk a site to the Water Services Authorities that will own these installations. The Centre's independence rests on holding no equity and manufacturing no technology; the rating log is portable and third-party auditable.

Across the roughly eighteen months of this work, the programme's evidence base was built visit by visit at real installations. We thank the WESS technology providers — Enviroloo, Prana Aquonic, WEC and Lilliput — for their openness to independent assessment and their willingness to act on the findings; a de-risking method can only be field-tested on units that someone has built and is prepared to have measured.

Appendix A · the record

Record of site visits

The programme is not a desk exercise. This is the field record — every site engaged, when, and what came out of it — kept both as an evidence trail and to show the funders the volume of work behind the method. Site and provider names are replaced by consistent hash codes (the same site always carries the same code); the document links open the underlying reports on the local drive.

Reach to date: 9 sites · 4 technology providers (P-B672 · P-99B4 · P-BEF5 · P-B320) · 2 provinces · 5 formal baseline assessments + 1 mid-point review + 3 onboardings + a 5-report accredited-lab review · 24 HAZOP entries and 49 engineering recommendations, each traceable to a field measurement · field visits Jan–Jul 2026, within the ~18-month programme.

SiteProviderRegionVisit(s) & dateHAZOPsRecsOutcomeReport
S-DC33P-B672KZNBaseline · 2026-02-06 + Mid-point · 2026-03-20617At-risk process status at baseline; sludge overload, under-aeration and low chlorine residual actioned; returned for a mid-point review.V1 report · V2 report · Field report
S-1B42P-BEF5KZNBaseline · 2026-02-2546Baseline assessment; process integrity at risk; recommendations issued.Field report
S-0E31P-BEF5KZNBaseline · 2026-02-0924Baseline assessment; field record and photographs captured.Anonymised report
S-4783P-BEF5GautengBaseline · 2026-02-06711620-household community system — the most HAZOP entries of any site, the community-scale complexity a desk review does not surface.Field report
S-F14EP-B320KZNBaseline + greywater · 2026-04-14511Two-line site (blackwater + greywater); integrated microbial diagnostics and the paired greywater evaluation; microbial review and mitigations issued.Microbial review
S-2D8BP-BEF5—Lab review — 5 accredited reports · 2026-01-14 / 2026-03-12—863-household site (3 Aquonic plants); five SANAS-accredited laboratory reports reviewed — denitrification failure and septic accumulation the critical findings; 8-item scored mitigation register.Lab review & mitigations · Aquatico effluent report
S-2785P-99B4KZNOnboarding · 2026-05-19——Onboarded for first-visit assessment.Onboarding report
S-3792P-99B4KZNOnboarding · 2026-05-19——Onboarded for first-visit assessment.Onboarding report
S-7474P-99B4KZNOnboarding · 2026-05-19——Onboarded; first site report issued.Site report · Onboarding report
On the codes and links. The hash codes anonymise site and provider identities for circulation while staying consistent across the record. The Report links are file:// references to documents on the WASH R&D drive — they open when this page is viewed locally (or from the Word edition on the same machine); a shared web copy cannot open a local file. This appendix is a live index, not the reports themselves.
Appendix B · the template

The site report template

Every visit ends in a report, and every report follows one template, so a provider, a municipality or a lender reading their third report can navigate it as fast as their first. The template below is the structure every site report in the Appendix A record follows; on the monitoring platform the same template is generated directly from the visit data.

SectionContentsSource in this protocol
1 · Site identificationSite and provider (coded where circulated), configuration against the reference model, reuse destination, visit number and date, personnelPart II declaration; Part IV visit plan
2 · Data statusThe single-round caveat where it applies; sample codes against the chain-of-custody legend; any quality flagsPart VII gates
3 · Executive summaryOpens with what the data shows working, then the excursions — each finding stated once, with its measurement, mechanism and action; classifications carry their confidence grade (Confirmed / Provisional / Re-test required)Part V diagnostics; the reporting style guide
4 · Compartment classificationsThe green/amber/red status per compartment with the measured values and the branch taken in the decision treeParts III & V
5 · Laboratory resultsParameter table against the destination's compliance bands; each excursion mapped to a mitigationPart VII interpretation guide
6 · Completion criteria roll-upC1–C7 with status and evidence base; the social-framework rung alongside C4/C6Part VI
7 · HAZOP register updateEntries opened, progressed and closed this visit, with guide words and ownersPart VIII spine
8 · Mitigations & actionsThe priority-scored mitigation list from the library, each with its trigger measurement and its ownerPart VIII catalogue
9 · Next visitWhat will be measured to confirm each provisional finding and each mitigation's effect; sensor and rating status where installedParts IV, IX & X

The template is deliberately symmetrical with the protocol: a reader can put any report section beside the part of this document that produced it and see the method behind the finding — which is what makes the reports auditable, and what makes the protocol trainable.