Training guide
Muster's training mode is a parallel universe: every feature works identically, but every event goes to a separate training event store and produces a separate training archive. Training data never mixes with production data at any level.
This guide covers running drills without contaminating your real incident data.
Testing Muster as part of the pre-live cohort? Start with tester_onboarding.md. Every incident you create as a tester should be in training mode — this guide is the deep reference for what training mode covers.
Table of contents
- Why training mode exists
- The two directions of error
- Entering training mode
- Visual segregation
- What works identically
- Exiting training mode
- Multi-department drills
- Facilitator features
- Training in a real call
- Training archives
- Common scenarios
- NFPA 1403 (live fire training)
Why training mode exists
Fire departments train constantly. NFPA mandates specific annual training hours. Volunteer departments run drills weekly or more.
Every department I've talked to that uses any accountability software has the same problem: drills and real incidents end up in the same database.
The consequences:
- Training incidents count in "response time" metrics.
- NERIS submissions accidentally made for drills.
- Mutual aid reports showing "Test Engine 7 was dispatched 47 times" when 35 of those were drills.
- Auditors pulling data thinking it's real and finding it contaminated.
Muster segregates rigorously at the data level.
The two directions of error
Two ways this can go wrong:
- "Drill treated as real." Awkward but low-stakes. Delete the record, apologize.
- "Real treated as drill." Catastrophic. No accountability records generated. Mayday marked as training. NERIS never submitted.
Muster is asymmetric about this:
- The default is real-incident mode.
- Entering training requires hold-to-confirm 3 seconds.
- Exiting training is a single tap ("To respond to a real incident, tap here").
If you're stuck in training when a real call comes in, you can leave in one tap. If you're stuck in real mode and want to train, the 3-second hold takes 3 seconds.
Entering training mode
From the home screen, tap Start Incident. Choose:
- 🚨 REAL INCIDENT (single tap).
- 🎓 TRAINING / DRILL (opens the hold-to-confirm dialog).
Tapping the training button opens a confirmation dialog with a fill-bar button:
Training Mode
This incident will not appear in reports, will not be sent to CAD, and will be stored separately from real incidents.
If this is a real fire, tap Cancel.
Training scenario name (optional): [text field]
[ Cancel ]
[ 🎓 Hold to Start Training ]
████████░░░░░░░░(fill bar)
Hold the button for 3 seconds:
- Fill bar animates left-to-right.
- Haptic pulses every ~750ms (reassures you it's registering).
- At the 3-second threshold: firm haptic "tock" different from the pulses; text changes to ✓ Release to Confirm.
- Release: training incident starts.
- Release before 3 seconds: bar empties, nothing happens, retry.
The threshold haptic lets you know you've committed without looking at the screen — useful when you're coordinating with someone else while starting the drill.
Visual segregation
While a training incident is active:
Theme shift
- Primary color: fire-service red (
#E63946) becomes amber (#F4A261). - Mayday red stays red — the Mayday button is never primary-colored, so it stays its own distinct deep red even in training. Preserves "MAYDAY is serious" visual vocabulary even in drills.
- Transition animates over ~200ms on mode entry.
Persistent banner
A non-dismissible amber bar across every screen:
🎓 TRAINING — Monthly Drill / 2nd floor search
The banner also has a small link: "To respond to a real incident, tap here." This is your fast-exit path.
Whiteboard watermark
"TRAINING" tiled diagonally at ~10% opacity across the canvas background. Shows up in exported PDFs too.
App icon badge
On platforms that support it: a small amber dot on the app icon so a glance at the home screen tells you the device is in a drill.
Per-incident treatment when multi-incident
If the device is in both a real incident and a training incident simultaneously (rare but supported), the amber theme applies only when you're viewing the training incident. The incident switcher shows which is which unambiguously.
What works identically
Every Muster feature works identically in training mode:
- Mayday — same 2-second press-and-hold, same audible alert, same PAR trigger. The alert sound is different (see below); everything else is identical.
- Evacuations — same recommendation-and-order flow, same ISO imminent-danger authority.
- PAR — same request-and-report flow, same missed-PAR warnings.
- Accountability Officer role — the dedicated PAR-cadence role works in training mode just like real mode. The AO's "Request PAR" button, recent-PAR history card, and unread indicators all behave identically. Training-mode drills are the recommended way to practice the AO delegation pattern before running it on a real fireground.
- Rehab — same intake, same vitals capture, same clearance workflow, same medical-hold overrides.
- Exposure documentation — captured in the training archive; does NOT count toward personal cross-incident exposure history.
- Whiteboard — full feature set, but with the "TRAINING" watermark.
- Map view (Q2 GPS) — the map layer works the same in training mode. Location fixes are captured in the training event log and rendered on the training incident's Map view. Position reports never cross the training/real boundary (rule 14 enforcement); a device in a training incident never sees a real incident's GPS fixes or vice versa.
- CloudActiveIncidents — training-mode incidents appear in the "Available on cloud" list of the incident switcher on other training-mode-only devices. The switcher visually distinguishes training from real; cross-mode auto-join is refused per rule 14.
- Peer sync — training devices discover only other training devices at the discovery layer's mode-visibility check.
- Command transfer — same explicit-only flow.
- Termination — same ten-step flow, same hard blocks on unresolved Mayday and active evacuation.
- Archive generation — produces a
.musterarchive stored in the training path.
Differences from real mode
- Push notifications for training Mayday use a different sound and clearly indicate "TRAINING MAYDAY" in the text.
- iOS Critical Alerts NOT used for training notifications. Apple would likely revoke the entitlement; more importantly, training Maydays shouldn't bypass Do Not Disturb.
- Radio alert tones (Phase 7a radio connector) are suppressed — don't want to ruin the real dispatch channel with a training air horn.
- NFPA 1580 medical investigation workflow NOT triggered — training Maydays are teaching events, not post-incident investigations.
- Exposure events are recorded in the training archive but do NOT count toward personal cross-incident exposure history (even though they're captured — useful for training decon procedures and exposure recognition).
- Role-picker qualification warnings are SUPPRESSED. On a real-mode incident, selecting Incident Commander or Safety Officer surfaces a red compliance-warning subtitle citing the applicable NFPA standard (Chapter 5 for IC, NFPA 1521 for ISO). In training mode the warning is suppressed by design — drills exist specifically to build up to qualification, so the picker doesn't second-guess your selection. Chiefs running training-mode drills should still document which personnel need which qualifications; the admin console's Qualifications card is the record of truth.
Exiting training mode
Two distinct exit paths:
1. Terminate training normally
Same ten-step flow as terminating a real incident. Hard blocks still apply (unresolved training Mayday blocks termination). Training archive is generated and stored.
2. Abandon training for a real call
Single tap on the "To respond to a real incident" link in the banner. No hold-to-confirm — leaving training mode to respond to a real call is always fast.
The training incident is not terminated — it's left in an
abandoned state with a note. You can come back to it later,
or leave it. If you don't come back within your department's
auto-finalize window (default 72 hours), it auto-finalizes as
"abandoned during training" with the note preserved.
Principle: entering training is costly (3-second hold); leaving is cheap (one tap). The dangerous error direction is "stuck in training during a real call" — Muster is built to prevent it.
Multi-department drills
A county-wide multi-department drill is a real and valuable
scenario. Muster handles it identically to real mutual aid,
except every incident is mode: training:
- One department creates a training incident as host.
- Other departments' devices discover and join.
- Discovery filters on mode — training devices only see training incidents in the "Available on Wi-Fi" list.
- All peer sync, guest units, PAR, Mayday features work identically.
- Each department generates their own training archive.
Cross-mode discovery works at the mDNS layer with a mode flag in the TXT record: an iPad with no active incident sees a training peer and offers "Switch & join" — but auto-dial is refused at the segregation-enforcement layers (EventStore tables, Hello mode-match, QR pairing mode-match, BLE payload mode bit).
You can never accidentally join a training incident from real mode without an explicit "Switch mode" step.
Facilitator features
Muster's core training-mode capability is data segregation — every drill's events, archive, and after-action PDF live in the training path, never mixing with real data. That baseline works today at every tier.
The dedicated facilitator tooling below (scenario injection, pre-scripted timelines, instructor views, cross- department scenario marketplace) is planned for a future release. Instructors run drills today by manually issuing the same actions they'd issue during a real incident, from whichever role they've picked.
Available today (all tiers)
- Full segregation. Training incidents run through every Muster feature identically to real incidents; they just live in the training event store, training archive path, and produce watermarked PDFs.
- Training archives library. The admin console's Training Archives tab is the debrief surface — browse, filter, and download past drill archives + PDFs.
- Training cadence CSV report (Tier 2+) — the Reports tab's Training cadence report totals training hours by member for NFPA 1550 Chapter 11-15 personnel-training documentation.
Design-stage (not shipped today)
- Scenario injection — instructor manually injects events (declare a Mayday, generate a PAR request, mark a benchmark) from an instructor tablet.
- Training templates — save a scenario setup (building, units, divisions) as a reusable template.
- Basic instructor view — device flagged as instructor's tablet; grid of all peer devices' current screens (read-only).
- After-action review scrubber — replay the archive with a timeline scrubber for debrief.
- Fast-forward — advance the scenario clock past waiting periods.
- Pre-scripted scenarios — timeline of automated injections.
- Instructor notes on the drill PDF.
- Cross-department scenario marketplace — regional coordinators publish scenarios to multiple departments.
- Remote facilitation via cloud sync.
Contact product@safesignals.io if any of the deferred
facilitator features would meaningfully change your training
program — customer signal drives which of them lands first.
Training in a real call
The scariest scenario: department is running a drill at the firehouse, pagers go off for a real structure fire in town.
Muster's answer:
- Responders starting from home create a new real incident from their devices. They're not on the training mesh.
- Devices at the firehouse, once aware of the real call, tap the exit link in the amber banner and leave the training incident. Then create or join the real incident via CAD dispatch, QR, or peer discovery.
- The training incident persists with its events up to that point. It can be terminated later with an abandonment note, or left in limbo until the department comes back to it.
- No device is locked into training when it needs real.
Key principle: training incidents are fully walk-away-able. The confirmation barrier was on entering training, not on exiting.
Assisted awareness (Tier 2 CAD connector — design-stage)
The CAD connector interface is scaffolded but no vendor-specific implementation ships today. Once shipped, a new real dispatch will trigger a modal on every training device:
New incident dispatched: Structure Fire — 123 Main St
[ Continue training ]
[ Respond to real incident ]
Tap "Respond" and the training incident pauses (not terminated — the training scenario is preserved). Your device joins the real incident.
Until CAD integration ships, the awareness path is the same one crews use for real calls without Muster CAD integration: radio + pagers. The banner's "To respond to a real incident, tap here" link is always available.
Training archives
Storage
Training archives:
- Separate on-device directory (
training_archives/). - Separate Firebase Storage path (
training-archives/in Tier 2+ cloud sync). - Never mix with real archive queries.
Retention
Training archives are retained indefinitely by default. Not automatically deleted by any process. Storage is negligible (~100-150 KB per typical drill); a decade of weekly drills is ~40 MB per department.
Why indefinite: training archives become a teaching library over time. "Primary search times improved 40% since 2022" is only possible with retained archives.
If you want to delete specific archives, explicit admin action in the admin console. Never automatic.
PDF watermark
Training PDFs are watermarked "TRAINING — NOT A REAL INCIDENT" across every page. Cannot be disabled.
Visibility
- Training archives are NOT listed in the standard admin console archive view. Separate "Training Archives" tab.
- NERIS submission is disabled for training archives: "This was a training incident. NERIS submission is not available."
- Mayday visibility overridden to full disclosure regardless
of department's
maydayVisibilitysetting. Training is inherently a shared learning experience.
Post-drill review
The admin console's Training Archives tab today lets you browse, filter by date, and download the training archive + PDF for each drill. Tag taxonomy, "learning value" flags, publish-within-department notifications, and cross-referencing between drills are design-stage; see the archive list itself for the currently-shipping filter surface.
Common scenarios
Monthly volunteer drill
Weekly cadence, one crew, ~1 hour drill:
- Chief opens Muster, hold-to-confirms training mode.
- Names the scenario ("Monthly drill — 2nd floor primary search").
- Creates the drill incident.
- Crew members check in via Arriving Unit role on their phones.
- Chief runs the scenario. Injects a Mayday at some point. Crew responds; safety officer trainee reacts.
- Terminate. Add narrative. Review the PDF.
- Publish "Learning value" flag if the drill exposed something worth reviewing.
Live fire drill (acquired structure)
Higher-stakes drill with a real building and real fire:
- Set up as above. Additional scenario tags:
live-fire,nfpa-1403. - All standard safety features work: Mayday, evacuation, rehab. Vitals capture is particularly valuable — heat stress is real even in training.
- On termination, the training archive documents the drill for NFPA 1403 compliance.
Regional multi-department drill
County-wide drill:
- Host department starts the training incident.
- Guest departments' devices discover and join via QR bootstrap (spontaneous) or partner-registered auto-trust (pre- registered mutual aid).
- Each department's crews check in via their own devices.
- Full mutual aid features work identically to a real incident.
- On termination, each department generates their own scoped training archive.
ISO training
Safety Officer qualification drills:
- Start a training incident. Trainee ISO responds to hazards the facilitator flags in real time. (Automated scripted- hazard templates are design-stage — see Facilitator features.)
- The trainee ISO responds to injected hazards.
- Facilitator observes and injects additional hazards.
- Terminate. PDF contains the safety-events section with trainee response times.
- Contributes to the trainee's ISO qualification documentation (per NFPA 1521 / 1550 Chapter 5).
NFPA 1403 (live fire training)
NFPA 1403 governs live fire training evolutions. Muster's training mode supports NFPA 1403 documentation:
- Training archive segregation at every layer (rule 14).
- Watermarking of all outputs.
- Full accountability — every trainee is tracked exactly as in a real incident.
- PAR at required intervals — including the mandatory PAR before live fire ignition.
- Rehab — vitals capture during high-heat evolutions.
- Instructor role — dedicated Safety Officer role is strongly recommended for live fire drills.
- Documentation — the training archive supports NFPA 1403 compliance documentation for AHJ review.
Muster does not replace NFPA 1403 documentation requirements — the department is responsible for its own live fire training policy. Muster is a supporting tool.
Getting help
Training-mode questions to support@safesignals.io.
Tier 3 customers with a named TAM can request custom scenarios and remote facilitation.