Sectors / Telecommunications

One topology behind the NOC, the plan and the field team.

A network operations centre rarely suffers from missing data. It suffers from forty-six alarms that are one fault, a capacity plan built on last quarter's topology, and a field team dispatched to the symptom rather than the cause. All three are the same problem: OSS, BSS, and network telemetry describe the network differently, so nobody is planning against the same truth.

Alarm volume is not the problem — topology is

Every operator has tried alarm suppression, and most have found its limits. Thresholds tuned to reduce noise hide real events; thresholds tuned to catch real events restore the flood. The reason suppression cannot solve it is that noise is a symptom of missing structure: forty-six alarms from cells, transport links, and monitoring probes are only reducible to one fibre fault if the system knows how those elements connect.

Correlation is a graph problem before it is a machine-learning problem. Once the topology is modelled — which cells ride which transport path, which sites share which power feed, which edge node serves which segment — collapsing an alarm storm into a single diagnosis with an affected-service list becomes tractable, and the residual alarms that do not fit the diagnosis become interesting rather than lost.

The network ontology

NeuroCluster resolves OSS inventory, BSS records, RF and performance telemetry, alarms, and trouble tickets into governed objects: Site, Cell, Fibre Link, Edge Node, Alarm, Ticket, and Capacity — each with stable identity and version history, so a site is the same object across the inventory system, the ticket queue, and the capacity model.

  • Topology and dependency edges from the inventory of record, kept current rather than annually audited.
  • Alarms and tickets bound to the network element they concern, not to a free-text location string.
  • Capacity and utilisation modelled per element and per service, so a plan and an incident reference the same object.
  • History retained, so a recurring fault on one link is visible as a pattern instead of six unconnected tickets.

From correlation to a dispatch someone signed

The representative output is concrete: consolidate forty-six alarms into one fibre fault and dispatch a single field team. That reaches the network operations manager with the diagnosis, the affected services, and the supporting evidence attached.

The manager authorises it, and the dispatch is created in the field service system with that diagnosis and evidence carried through — so the technician arrives with the reasoning rather than a ticket title. Mean time to repair and avoided truck rolls are then measured against those dispatches, which is the only honest way to know whether the correlation is working.

Field dispatch optimisation runs on the same model: which team, which skills, which parts, and which of today's other jobs sit near enough to combine.

Capacity, spectrum and energy per bit

The same modelled topology supports the planning side: capacity forecasting per cell and per transport segment, RF and spectrum planning, and energy-per-bit analysis across the radio estate — increasingly a board-level number as energy costs and reporting obligations both rise.

Because planning and operations read the same objects, a capacity decision inherits the incident history of the elements it affects, and an incident inherits the plan that was supposed to prevent it.

Why subscriber data changes the deployment question

Telecom operators hold two categories that make casual AI adoption difficult: subscriber and traffic data under GDPR and the ePrivacy regime, and network topology that is itself sensitive national infrastructure information. Sending either through a third-party model API is a hard conversation with regulators and security teams.

Providers of public electronic communications networks and services also sit in scope under NIS2 as digital infrastructure, which puts incident handling, reporting timelines, and supply-chain security on the same footing as the operational work.

NeuroCluster runs on a dedicated European tenant, in the operator's own data centre, or air-gapped, with model routing kept inside that boundary. Sovereign network operations is not a positioning line here — it is the condition under which this data can be used at all.

Frequently asked questions

Does this replace our OSS or existing AIOps tooling?

No. It reads from the OSS as the inventory of record and writes dispatches and decisions back into the systems you already run. Where it differs from generic AIOps correlation is the modelled topology and the governed action path: correlation is grounded in network structure rather than statistical co-occurrence, and every resulting dispatch carries a named human approval and its evidence.

What happens to subscriber and traffic data?

It stays inside your deployment boundary. Models, retrieval, and the agent runtime run on your dedicated European tenant or your own infrastructure, so subscriber and traffic data is never sent to a third-party model provider. Access is governed by classification-aware policies, and every access is logged.

Is telecom in scope for NIS2?

Providers of public electronic communications networks and publicly available electronic communications services are covered under the directive's digital infrastructure sectors, which brings Article 21 risk-management measures and the Article 23 reporting timeline — 24-hour early warning, 72-hour notification, one-month final report. Confirm your specific classification with your national competent authority.

How long before correlation is trustworthy?

The gating factor is topology quality, not model training. Where the inventory of record is accurate, correlation is useful almost immediately because it is reasoning over structure. Where the inventory has drifted, the first phase of work is reconciling it — which has independent value, since a stale inventory is already degrading planning and dispatch.

How do we start?

One fault domain and one measurable number, usually mean time to repair or truck rolls. We model that slice of topology, replay historical alarm storms through it to show what correlation would have produced, and only then wire the approval and dispatch path.

Keep evaluating

Bring us one operational problem.

You do not need a finished brief. Bring the problem — we will work out the next step together.

Or book a call with the team