Walk your newest site and count the things that move freight without hands. Autonomous forklifts. AMRs shuttling between staging and doors. A de-palletizing cell. Your automation roadmap adds more of them every budget cycle, because the business case closed years ago. Now ask the question this journal always asks: when one of those machines moves a pallet, what does the record say?
Every incumbent record you run was designed under an assumption nobody wrote down: the observer is a person. The WMS has user IDs. The event standard has company-grain parties — EPCIS 2.0 defines what, when, where, why and how, with no performer of any kind (§7.2.2; the ten-minute self-check is in Five Dimensions, No Performer). Neither has a place to put a machine that acted. So sites improvise, and the improvisations are the subject of this post — because one of them is a quiet falsification your incident-review process will eventually meet at the worst possible moment.
One pallet move, recorded three ways
The scenario: an autonomous forklift picks a pallet of temperature-sensitive product from staging lane 4 and puts it to outbound door 9. Eleven seconds of routine automation. Record it three ways.
Recording one — anonymous. The status quo. The move appears as a location change: pallet was in lane 4, pallet is at door 9. No observer of any kind. This is the company-grain sentence — the site moved the pallet — and it holds right up until the pallet matters: the product arrives warm, the claim lands, and the review asks who or what carried it, under what parameters, on whose authority. The record's answer is nobody. The review proceeds by pulling robot telemetry from the vendor's portal, camera footage from a second system, and shift logs from a third — the exact archaeology your automation spend was supposed to end, now with a machine in the middle of it.
Recording two — the borrowed badge. The common workaround, and the one to stop shipping: the robot's acts are logged under a supervisor's login, because the WMS demands a user ID and the integration used the credential it was given. Every move the fleet makes is now attributed to a person who did not perform it. Consider what an incident review does with that. Best case, the attribution is recognized as fiction, discarded, and you are back to recording one — minus the record's credibility, because it has now been shown to contain systematic false statements. Worst case, it is not recognized, and a named human carries the paper trail for a machine's fault. A record containing knowingly false performer attributions is not a custody record; it is a liability with timestamps.
Recording three — the robot as attested observer. On this record, the move is an event whose who is the forklift itself — an embodied agent with a resolvable identity — and whose capturedBy is the warrantor account under which the fleet operates at your site: yours, or the automation vendor's, whichever party actually stands behind those captures under your contract. The two fields never collapse, which is what makes the machine case work at all: the observer is a robot, the warrantor is a party that can answer for it. Identity for all three kinds of observer — human, agent, embodied agent — resolves through the same grain at id.org.ai: Agent. Human. Thing.
Replay the warm-pallet claim against recording three. The review reads: this unit, this move, this timestamp, warranted by this account — one query, then straight to the right counterparty with the right evidence. The dispute is now about a fact both sides can verify, not about whose systems to believe. Only the third recording survives contact with an incident review, and it is the only one of the three that was true.
One grain, three kinds of observer
The design point worth carrying into your next architecture conversation is that the robot is not a special case. It is the third value of a dimension your record needed anyway. The person on your dock, the software agent working your exception queue, and the forklift are all observers performing custody-relevant acts, and a record with one who grain for all three — each attested under a warrantor — handles tonight's mixed shift, where a pallet crosses human hands, an agency crew, and an autonomous vehicle inside the same hour. Your human-staffing version of this exact problem is worked in The Dock Runs on Temporary Labor, and the two-grain vocabulary underneath both posts is in who Is Not capturedBy. All of it rides conformantly: a superset of EPCIS 2.0 that stays conformant, projecting down to events that validate against GS1's official pinned schema — so the record your automated site writes is one your customers' auditors can still read as the standard they know.
The procurement horizon
Here is the timing argument, and it is about contract durations, not technology. The automation you commission next year will run for a decade — longer than your WMS contract, longer than most of your client logos, and longer than the record system you are evaluating this quarter. Buy the record for the fleet you will have, not the roster you had: if the system in front of you cannot name a non-human observer today, the gap lands mid-contract, and it lands as recording two — the borrowed badge — because that is what integrators reach for when the schema has no better field. The RFP question that surfaces this in one line: "Show me a custody event whose performer is a machine, and show me who warrants it." Vendors who can, will.
The door here is the get-started interview: your email first, then a short interview that branches on your answers — the 3PL branch asks how you answered the traceability section of your last RFP, how your last disputed handling claim resolved and what you produced, and what share of an average shift is agency or temp. We answer in writing.