The strongest objection first
Take the case against continuous monitoring at its best. An integrity engineer on a North Sea platform, or a pipeline operations centre in the Permian, does not want more data streaming in. They want fewer, better-trusted numbers, checked on a cadence a human can actually review. Wellhead telemetry alone can throw off thousands of readings a second across pressure, temperature, flow and vibration. Add seismic surveys, pipeline SCADA feeds, corrosion coupon results and the drip of regulatory notices from a pipeline safety authority, and the honest response is not "watch everything continuously." It's "aggregate sensibly, or drown."
There is a real engineering case for this. Monthly aggregation of an integrity signal — say, a rolling average of internal corrosion rate derived from ultrasonic thickness readings — is not laziness. It exists because raw signals are noisy, because false alarms have a cost measured in shutdown-hours, and because the people who act on the number need it stable enough to trust. A number that jitters hourly invites either alarm fatigue or constant recalibration, both of which degrade judgement faster than a slow-moving average does. The objection, stated in its strongest form: continuous intake does not solve Goodhart's law in this domain, it just moves the noise problem somewhere else, and it costs more compute, more storage and more human attention doing it.
This deserves to be taken seriously before it is answered, because the failure mode it is trying to prevent — instrument-induced false alarms shutting down production — is a genuine and recurring cost in this industry. The case against continuous intake is not stupid. It is the case for stability against a background of noisy telemetry. What it misses is what happens when the thing being measured moves faster than the aggregation window, which is exactly the failure this domain produces on a schedule.
Where the monthly number quietly detaches
Here is the mechanism, stated the way Goodhart stated it for money supply targets in 1975: a statistical regularity relied upon for control tends to break down once you rely on it. In integrity management the regularity is this — historically, a slow monthly trend in wall-thickness loss or pressure anomaly correlates well with the risk of a leak or rupture. That correlation was built from a population of failure modes dominated by steady, gradual corrosion. Optimising the monitoring system around that correlation — reporting monthly, alarming on monthly trend breaks, briefing management on a monthly integrity dashboard — works exactly as long as the failure population stays gradual.
It does not stay gradual. A stress corrosion crack under insulation can propagate from undetectable to through-wall in under a day once conditions align — moisture ingress, cyclic loading, the wrong metallurgy at the wrong weld. A pigging run finds nothing amiss at the start of the month; a hydrogen-induced crack initiates mid-month; the line fails in hours, days before the next scheduled reading would have caught the trend. The monthly aggregate was never wrong about the population it was built on. It detached from the specific well or segment the moment that segment's failure mode stopped being the gradual kind the aggregate assumed.
This is not the engineer being negligent. It is Goodhart's law in its structural form, not its incentive form: the measuring system sampled a frozen slice of behaviour — a month's worth of thickness readings, aggregated for stability — while the measured system, the pipe wall under real stress, kept evolving on its own clock. The correlation between "monthly trend looks fine" and "pipe is fine" was contingent on a distribution of failure modes. Nothing in the aggregation step notices when that distribution shifts under a specific asset. The proxy survives on the dashboard. The goal — knowing whether this segment will hold — quietly stops being served by it.
What continuous intake actually buys, and what it costs
Compare cadences directly.
| monthly aggregate | continuous stream with provenance | |
|---|---|---|
| Sampling rate vs. failure rate | Slower than fast-onset failure modes | Matched to sensor Nyquist limits, not to a reporting calendar |
| What decays | The correlation between proxy and risk, silently | The correlation still decays, but the decay is visible in the stream |
| Response to a detaching signal | None until next reporting cycle | Belief flagged and re-weighted as soon as supporting readings stop arriving |
| Cost | Cheap to compute, expensive when it misses | Expensive to sustain, cheap when it catches |
This is the honest trade the first objection identifies. Continuous intake does not remove noise; it converts a monthly average, quiet by construction, into a stream that has to be triaged in real time. That triage is a genuine cost — more compute, more storage, more attention from an integrity engineer who is already stretched across dozens of assets. Where the objection goes wrong is in treating that cost as pure waste. What it buys is the one thing the monthly aggregate structurally cannot produce: a record of which specific readings a "segment is healthy" belief currently rests on, so that when a stress corrosion crack starts producing anomalous acoustic emissions at 3 a.m. on day 17, the system can flag that the belief's supporting evidence has just gone stale, rather than waiting until day 30 to recompute an average that already lied for two weeks.
The manipulation objection, and why frozen data isn't the safe alternative
A second, sharper objection: continuous monitoring opens a live channel. If sensor placement, alarm thresholds and reporting logic are known — and in a regulated industry with public safety filings, much of this is discoverable — then a continuous system can, in principle, be probed and gamed in real time, the way link-selling schemes learned to game PageRank within a few years of its launch. A monthly aggregate, updated on a fixed and auditable schedule, is at least a known, stable target that cannot be shaped minute by minute.
The manipulation risk is real, and worth conceding fully: any live feedback loop is a channel an adversarial actor, or simply a badly incentivised contractor, can learn to work. A pigging contractor paid per clean run has an incentive to schedule runs when conditions are favourable; a real-time system that reacts to their reports faster gives that incentive more leverage, not less.
But the frozen alternative is not safe, only slower to fail and harder to fix. A monthly aggregate built on a bad calibration — a corrosion model tuned to the wrong metallurgy, a threshold set before a change in produced-fluid chemistry — degrades invisibly for as long as it takes someone to notice the dashboard has stopped meaning anything. That noticing, historically, happens after a rupture, not before. The distinction that matters is not speed, it's remediability. A continuous system with provenance can localise a bad belief to the readings that produced it and withdraw it the day those readings are shown to be unreliable. A monthly system has no mechanism for localising anything; it just reports a new number and hopes the old one wasn't load-bearing. Continuous intake makes gaming faster and, crucially, detectable in the stream itself — an unusual pattern of favourable readings is itself a signal. Frozen intake makes gaming slower and structurally invisible until the pipe fails.
The narrower claim
None of this rescues continuous monitoring from Goodhart's law. It cannot. Any proxy — acoustic emission count, ultrasonic thickness delta, pressure decay rate — will still detach from the risk it was meant to track, the moment enough weight is put on it, whether that weight comes from a cost-cutting decision to skip a pigging run or from a contractor learning which readings avoid triggering a shutdown. Nothing in this argument makes that stop happening. What changes is whether the detachment is observed while it is still cheap to correct, or discovered afterward in an incident report.
That is the claim actually being made here, and it is narrower than it might first sound. A Large Universe Model, on this domain's evidence, is not a promise that integrity failures stop happening. It's the structural position of sampling wellhead telemetry, seismic surveys, pipeline pressure and regulatory notices on the same running clock the pipe itself is operating on, with enough provenance attached that a belief like "segment 14 is healthy" can be traced to the specific readings holding it up and withdrawn the hour those readings stop arriving or start looking manufactured. The monthly aggregate will always be cheaper. It will also always be wrong for exactly as long as nobody is watching it detach.