Advisory models on the plant floor meet a human control that vendors under-discuss: override. A soft sensor suggests a set-point band. A vision model flags a defect. A scheduler proposes a sequence. The operator hits override, acknowledge, or force—and production continues. That click is not only a safety or throughput decision. It is a labeled event. If you log it poorly, your next training cycle learns the wrong lesson. If you ignore it, you train on a fantasy of compliance that never happened.
Shadow-mode diaries own advice without ownership. MES free-text hygiene owns prompt injection via comments. OT write-path red teams own actuator authority. This brief owns override telemetry as the quiet supervision signal that decides whether plant AI stays honest.
What an override actually is in data terms
In a governed plant, an override should carry:
| Field | Why it matters | | --- | --- | | Who / role | Accountability and skill mix analysis | | What was overridden | Model ID, tag, set-point, or disposition | | Why (coded) | “False positive,” “unsafe recommendation,” “urgent takt,” “sensor doubt” | | Duration | Momentary ack versus hours of forced state | | Outcome | Did quality/safety later prove the human right? |
Without codes, overrides become noise—or worse, silent negatives that teach the model “operators always disagree,” which is how systems learn to be ignored.

Every override is a vote. Count it like one.
Failure modes already in the wild
- Override as mute — Chronic false positives train staff to force-clear without reason codes; the model never sees “wrong,” only missing labels.
- Override as hero culture — Throughput pressure rewards forcing; the dataset learns that recommendations are optional wallpaper.
- Retrain on forced states as normal — If forced set-points are ingested as “operating normal,” the next model endorses the workaround.
- No close-out — Overrides open; nobody records whether scrap or a near-miss followed.

A banner without a reason code is a confession you will not be able to query.
Governance that keeps learning plant-grade
- Require a reason code before an advisory override clears—short list, shift-usable.
- Separate safety interlock bypass (different briefs, different severity) from advisory override.
- Report override rate per model per week beside precision/recall—not instead of them.
- Freeze training recipes so forced intervals are either excluded or explicitly labeled as forced.
- Feed systematic “false positive” overrides into model change control, not into coffee complaints.

If override rate is not a KPI, retraining is superstition.
Adjacent fences
Shadow diaries own unowned advice. Soft-sensor model cards own gate criteria. Vision confusion matrices own class errors. Write-path red teams own commands to actuators. This page owns human override as supervised signal. Do not celebrate a model refresh and discover it was trained on a month of unexplained forces.
