--- status: accepted --- # Runtime owns device alarm state The runtime monitoring system is the authority for a device's alarm state: it sets the device to alarming while any effective alarm cause remains and clears it only after all causes recover through monitoring data, an upstream recovery event, or an authorized manual confirmation. Work order completion may trigger a fresh evaluation but must never clear the device unconditionally, and an alarm record's handled state does not determine the device's current alarm state.