EARLY ACCESS Muster is being validated by pilot departments. Schedule a walk-through →

User guide

Complete reference for using Muster during an incident. If you're just getting started, read the quick-start guide first — it walks you through your first incident in 15 minutes. This guide is the deep reference: every role, every screen, every action.

Testing Muster before your department goes live? Start with tester_onboarding.md instead — it covers the invite / install / License Key flow and points at the current beta feature list.


Table of contents

  1. The seven roles
  2. Starting an incident
  3. Check-in and roster management
  4. Divisions, groups, and branches
  5. Personnel Accountability Reports (PAR)
  6. Mayday
  7. Safety Officer authority
  8. Evacuations
  9. Rehab and vitals
  10. Exposure tracking
  11. Command transfer
  12. The Map view (Q2 GPS)
  13. The whiteboard
  14. Mutual aid and Unified Command
  15. Terminating and finalizing
  16. After the incident
  17. Settings
  18. Troubleshooting

The seven roles

Muster is one binary with role-adaptive screens. Each device picks a role at role-selection time; the role controls what the device can do.

Incident Commander (IC)

Device: tablet or laptop only. Phone devices redirect to "use a tablet."

The IC has overall command authority. Only the command-holding device can issue high-authority events: assign units, change strategy, terminate the incident.

What the IC sees: the full command board — every unit, every division, every timer, every benchmark, every safety event, every rehab cycle. Left side is the roster and unit list; center is the board itself (or the whiteboard when tapped); right side is the timeline and communication log.

Safety Officer (ISO)

Device: tablet preferred, phone works.

The ISO monitors overall scene safety. Distinct authority from IC: can order evacuation in imminent danger without IC approval (rule 22).

What the ISO sees: an ISO-specific board with active hazards, risk status (strategy, weather, structure type, collapse zones), per-unit time-on-task fatigue monitor, and three big buttons — Flag Hazard, Emergency Traffic, Evacuate.

ISO authority is unconditional — even if the license is expired, even if the device is a guest at another department's incident.

Division Supervisor

Device: tablet or phone.

Directs operations in one division. Sees only their division's units, assignments, and safety concerns. Can request PARs of their own units.

Accountability Officer

Device: phone (or tablet at the command post).

Runs PAR cadence for the whole incident when the IC delegates. The Division Supervisor runs PAR for their division; the AO runs PAR for the incident. Big Request PAR button; recent-PAR history card; unread + stale-PAR indicators.

Check-in Officer

Device: phone-first.

Manages intake of arriving units and personnel. High-throughput UI with big buttons and minimal typing. Scan a QR from a guest department's device, or type in unit name + headcount for units without Muster.

Rehab Officer

Device: phone-first.

Manages rehab cycles. Records vitals, watches for medical hold thresholds, clears firefighters back to duty, documents exposures observed during rehab.

Arriving Unit

Device: phone-first.

Three-screen self check-in for a unit that just pulled up. Pick your unit from a recents list or department roster, confirm crew size and roles, report your status. After submission, the role auto-transitions to Crew Member.

Observer

Device: any.

Read-only situational awareness. No write actions. Used by visiting officials, trainees on scene, media coordinators.

Crew Member

Device: phone-first.

The minimal view for individual firefighters. Shows your unit, your assignment, your division. Has the press-and-hold-2-seconds Mayday button, the PAR acknowledgment, and the self-report exposure action.

Crew Member does not see other crew members' vitals or exposure details — this is a privacy rule enforced in the software.

Switching roles mid-incident

Every device has a role switcher at the top of the AppBar. Tap your current role to open the picker; select a new role. The device instantly transitions.

Common transitions:

  • Arriving Unit → Crew Member (automatic on check-in).
  • Crew Member → Division Supervisor (after being assigned supervision).
  • Observer → Safety Officer (if you're qualified and being assigned).

Qualification warnings on real-mode incidents

On a real-mode incident, selecting Incident Commander or Safety Officer from the picker surfaces a red compliance- warning subtitle citing the applicable NFPA standard (NFPA 1550 Chapter 5 for IC, NFPA 1521 for ISO). The warning is advisory only — the picker never hard-blocks your selection (rules 5 and 22 preserve the operator's authority to make command and safety decisions unconditionally). It's there so an operator picking one of these roles is prompted to confirm they hold the required qualification.

Training-mode incidents suppress the warning. Training drills exist specifically to build up to qualification, so the picker doesn't second-guess your selection there.

The underlying iso_qualified / ic_qualified flags on each personnel record are granted/revoked by your chief via the admin console's Qualifications card — see for_admins.md.

Starting an incident

From the home screen with no active incident, tap Start Incident. Choose mode:

  • 🚨 REAL INCIDENT — starts a real incident. All events go to your real event store; the archive is authoritative.
  • 🎓 TRAINING / DRILL — hold-to-confirm 3 seconds to enter training mode. Training incidents are segregated at every level — see the training guide for detail.

For a real incident, fill in:

  • Incident type. Structure fire, MVA, MCI, hazmat, wildland, TIM (traffic incident management), and others. Controls the default whiteboard template.
  • Address. Where the incident is. Muster reverse-geocodes to a lat/lon if available.
  • Description. Free text — dispatch narrative or your own.
  • Number. Optional; auto-generates as <year>-<four-digit-sequence> if omitted.

The device that creates the incident is the initial commanding device. Command can be transferred later — see Command transfer.

Check-in and roster management

Every unit on scene must be checked in for accountability to work. Three intake paths:

Path 1 — self-check-in (Arriving Unit role). Fastest for volunteer departments. Every firefighter uses their own phone.

Path 2 — check-in by the IC or a Check-in Officer. From the command board, tap Check In. Options:

  • Pick from the department roster (home unit).
  • Scan the QR code from a guest department's device.
  • Type in a guest unit's designation and headcount.

Path 3 — pre-populated from CAD. Design-stage. The CAD connector interface is scaffolded (Tier 2+ feature) but no vendor-specific implementation ships today. Vendor-specific adapters are Phase 7 connector work, prioritized as customer demand surfaces.

Guest units

Guest units are units from another department (mutual aid). They have a guest badge on the unit chip. Guest units use headcount only — you don't need their department's roster.

The employing department of guest personnel retains authoritative ownership of that personnel's exposure records and rehab records per rule 25 (per-department data ownership).

Releasing a unit

Tap the unit chip → Release. Confirm. The unit leaves the incident; any active assignment ends automatically; any active rehab cycle exits. If the unit was assigned to a division that now has no units, the division stays but shows as empty.

Divisions, groups, and branches

Divisions are geographic sub-areas of the incident (Division A, B, C, D on a structure fire; sectors on a wildland). Groups are functional (Search Group, Ventilation Group). Branches aggregate multiple divisions or groups under one commander.

Creating a division

Add Division on the command board:

  • Name. "A", "B", "Roof", "Staging", "Rehab", etc.
  • Kind. Division, group, branch, staging, rehab, RIC, decon, triage, transport, treatment.
  • Supervisor. Personnel from your roster. Optional but strongly recommended.
  • Span of control limit. Default 5 (per NFPA 1550 Chapter 21.2). If a supervisor's span exceeds this, Muster warns you.

Assigning units

Drag a unit chip onto a division. Muster asks you to confirm the tactical purpose ("fire attack", "primary search", "ventilation") — free text but usually 2-3 words.

Assignments end explicitly (tap the assignment → End) or implicitly (unit released, incident terminated).

Personnel Accountability Reports (PAR)

PAR is your explicit check that every unit is accounted for.

Requesting a PAR

Tap Request PAR (IC board, Accountability Officer board, or Division Supervisor board — the DS's PAR scopes to their division only).

Every unit's device shows a prompt: "IC is asking for PAR. Confirm your crew count." The supervisor taps to confirm; the IC board fills in green.

PAR triggers

Per NFPA 1550, mandatory PARs on:

  • Strategy change (offensive to defensive, etc.).
  • Mayday declaration.
  • Every 20 minutes (department-configurable).
  • Before, during, and after evacuation.

Muster auto-prompts these; the IC can dismiss the prompt or proceed.

Missed PARs

If a unit doesn't respond within your PAR window, that unit turns yellow (approaching threshold) then red (missed the threshold). Red is a signal — investigate the unit's location before continuing operations. Missed PARs during a Mayday are particularly serious.

Mayday

The Mayday button is on every screen, every role, at all times. Muster's approach: fire fast, resolve deliberately.

Declaring a Mayday

On a phone (Crew Member view): press and hold the Mayday button for 2 seconds. The 2-second hold prevents accidental presses.

On a tablet (IC / ISO / DS): the Mayday control opens a confirmation dialog. Enter the affected personnel or unit, last known location, and initial report.

The moment Mayday fires:

  • All mesh devices sound a non-silenceable audible alert for 10 seconds.
  • The IC board's Mayday panel opens automatically.
  • Every device shows the Mayday banner at the top of the screen.
  • Muster requests an immediate PAR of every unit.
  • Termination of the incident is blocked until the Mayday resolves.

Working the Mayday

Follow your department's SOP. Muster records:

  • MaydayAcknowledged — the IC or RIC has confirmed and is responding.
  • MaydayLocated — the affected firefighter has been located.
  • MaydayResolvedSafe / MaydayResolvedSerious / MaydayFalseAlarm — final status with a required note.

Every status change fires an event; the archive preserves the full sequence.

Push notifications for Mayday

On iOS, Mayday and evacuation alerts use Critical Alerts — they bypass Do Not Disturb, silent mode, and Focus. Apple requires an entitlement for this; Muster's entitlement was granted in May 2026.

Push notifications also fire for backgrounded incidents — if you're actively looking at Incident A and a Mayday fires on Incident B, you're alerted.

Safety Officer authority

The ISO has specific authorities distinct from the IC per NFPA 1550 Chapter 21.13. All available in the ISO panel:

  • Flag Hazard. Type (structural, atmospheric, environmental, chemical, electrical, biological, traffic, other), severity (low / moderate / high / imminent), location, description, affected divisions. Hazards appear on the whiteboard and on affected division cards.
  • Raise Safety Concern. Targeted at a specific division or unit (fatigue, tactic, PPE, procedure). Notifies the division supervisor, who acknowledges and responds.
  • Emergency Traffic. Halts non-safety radio communications. Non-silenceable audible alert on all devices.
  • Recommend Evacuation. IC confirms in normal danger cases.
  • Order Evacuation (imminent danger). ISO's unconditional authority — IC is notified but does not need to approve.
  • Rotation Recommended. Signals that a specific unit should cycle to rehab.

Vitals access

Per Chapter 21.13, the ISO has access to vitals during the current incident. Access is audit-logged.

Fatigue monitor

ISO's board includes a per-unit fatigue monitor. Default thresholds:

  • Green: under 20 minutes on active task.
  • Yellow: 20-30 minutes. Rotation recommended.
  • Red: 30+ minutes. Rotation required. Also the NFPA 1580 Chapter 22.7.1.1 rehab trigger.

Thresholds are hardcoded to the NFPA 1580 Chapter 22 defaults today. Department-configurable thresholds via the admin console are Phase 5d work; the setting appears in Settings → Rehab policies on the admin console but the write path is pending.

Evacuations

Evacuations are the second-most-serious event after Mayday. Muster tracks them explicitly.

  1. Someone (typically ISO) taps Recommend Evacuation.
  2. IC gets a prominent alert on their board with the recommender and reason.
  3. IC either:
    • Approves and ordersEvacuationOrdered event.
    • Modifies scope and orders → scope-changed EvacuationOrdered.
    • Declines with reasonEvacuationDeclined, evacuation doesn't happen.

Imminent-danger evacuation (ISO orders directly)

When the ISO identifies imminent danger (roof collapse imminent, flashover signs, backdraft indicators), the ISO can order evacuation directly with a required reason (minimum 10 characters).

EvacuationOrderedByIso event fires; the IC is notified but does not need to approve. This is unconditional (rule 22 — ISO imminent-danger authority never gates on anything).

After the evacuation

Muster automatically:

  • Moves affected units to staging.
  • Requires a PAR before any re-entry.
  • Blocks termination until re-entry or explicit abandonment.

If accountability fails after evacuation (personnel missing), declare a Mayday.

Rehab and vitals

Rehab cycles track a firefighter through the rest → monitoring → clearing flow. Runs per NFPA 1580 Chapter 22 (formerly NFPA 1584).

Entering rehab

Rehab Officer taps Intake on the rehab station board:

  1. Select the firefighter (from your roster) or unit (headcount only for guests).
  2. Confirm the trigger — SCBA bottle count, time-on-task, IC direction, self-report.
  3. Firefighter enters rehab.

Recording vitals

Every reading is optional — a department with just a BP cuff and pulse oximeter can still use rehab tracking:

  • Heart rate, blood pressure systolic + diastolic, SpO2, temperature, respiratory rate, perceived exertion (Borg 1-10), notes.
  • Muster evaluates against NFPA 1580 Chapter 22 thresholds (or department-configured thresholds on Tier 2+).

Clearance and medical hold

  • Cleared — vitals in range across two readings 5+ minutes apart. Firefighter returns to staging; IC can reassign.
  • Held for medical — thresholds exceeded; requires medical evaluation. Locks the firefighter out of operational assignment until the hold is cleared.
  • Medical hold override — IC can override with a required reason (creates a paper-trail event). Not silent — the override is prominent in the archive and the after-action PDF.

Crew Member view of own vitals

You never see another crew member's vitals — that's a hard privacy rule enforced at the use-case layer.

Cross-incident personal vitals history is design-stage — Muster's default retention is incident_only, meaning vitals records live in the archive with the incident, not in a per-firefighter history. Opt-in cross-incident aggregation and firefighter-portal display of your own history are Phase 5d work. Exposure records (separate from vitals) already flow to the firefighter portal per OSHA 1910.1020.

Exposure tracking

Exposure to smoke, chemicals, asbestos, bloodborne pathogens, carcinogens, and other contaminants is documented in Muster per NFPA 1550 Chapter 16.7-8 and OSHA 1910.1020.

Recording an exposure

Any of these can record an exposure:

  • IC, ISO, Rehab Officer, or Division Supervisor via the affected personnel's card.
  • Crew member self-reporting via their phone.
  • Post-incident within the review window.

Fields captured:

  • Exposure type (smoke, chemical, asbestos, bloodborne, biological, carcinogen, radiological, PFAS, diesel exhaust, heat, cold, noise, other) and specific agent.
  • Route (inhalation, dermal, ingestion, injection, mixed).
  • Start/end time or duration.
  • Location on scene.
  • Intensity estimate.
  • PPE worn (checkboxes).
  • PPE failures noted.
  • Decon performed (gross, technical, mass).
  • Symptoms.
  • Medical evaluation recommended, transport recommended.

Long-term retention

Exposure records are retained for 30+ years post-separation per OSHA 1910.1020 (Tier 2+). Admin cannot configure retention shorter — this is a hard architectural rule.

Long-term records live in the admin console (admin.safesignals.io) and the firefighter portal (firefighter.safesignals.io).

Cancer presumption support

Muster produces state-specific cancer presumption documentation export packages for California, Florida, New York, New Jersey, Massachusetts, Pennsylvania, Texas, and Illinois. See the admin console → Exposures → Generate Presumption Documentation.

Command transfer

Command transfers are explicit and never automatic (rule 5).

The happy path

Current IC taps Transfer Command → picks the receiving device from the peer list → the receiving device sees a prompt to accept.

Accept → CommandTransferred event, new IC has full authority. The old IC continues to participate but does not command.

The IC-unresponsive path

If the IC device goes silent (no heartbeat for 30 seconds), any other peer sees an Assume Command? prompt.

Assuming command requires a required reason (minimum 10 characters) explaining why — e.g., "IC device battery died", "Chief sent to rehab". The reason lands in CommandAssumed and shows in the archive.

Split-brain

Rare but possible: two devices claim command after a network partition heals. Muster's HLC-based resolution:

  • Whichever device's CommandTransferred / CommandAssumed event has the higher HLC timestamp wins.
  • The other device's post-partition events are flagged as "issued while not holding command" in the archive.
  • All peers get a prominent notice explaining what happened.

The Map view (Q2 GPS)

Distinct from the whiteboard: a real-world map layer showing where each unit's device physically is per its GPS. Access from the Map button on the IC board's AppBar.

How it works. Every device attached to a unit reports its position via UnitLocationReported events (proto field 1100) at 30-second cadence, rate-limited to fixes with accuracy ≤100 m (both values are department-configurable in Settings → Peer Mesh). The Map view renders each unit's last-known position as a pin against OpenStreetMap tiles.

Permission is required. On first entry into the Map view, Muster surfaces a pre-flight rationale dialog explaining what/why/when/what-if-declined before the OS prompt fires. Grant location "While Using the App"; the Map view starts populating within one fix cycle. Declining is fine — Mayday, evacuation, PAR, and every other safety feature continue to work regardless of whether you granted location (rule 6). The Map view will show a persistent red banner when permission is denied, with a shortcut to Settings → Location so you can re-grant later.

Which units appear. Only units whose crew members have selected the Crew Member role AND picked their unit AND granted location permission. Chiefs and ISOs on tablets without an attached unit don't appear as pins by design.

Whiteboard pin vs Map pin. The whiteboard's unit chips are TACTICAL — the IC drags them onto templates and division regions to represent operational placement. The Map view's pins are REAL-WORLD GPS coordinates. A truck's whiteboard chip could be pinned to "side C" (a tactical description) while the same truck's Map pin shows the actual curb address. Both are useful; they're different layers.

Privacy. GPS position is more sensitive than operational data. Crew Member view does NOT display other members' GPS positions — the Map view is available to IC, ISO, and Division Supervisor roles. Long-term GPS history is not kept unless explicitly opted into by the firefighter (this opt-in is on the roadmap for a future release).

The whiteboard

The whiteboard is the IC's spatial command surface. Tablet-first, though phone works for reference.

Layers

Three composed layers:

  1. Context layer — freehand ink, dropped images, notes.
  2. Template layer — ICS-201, structure fire, TIM (traffic incident), wildland, MCI grid. Auto-fills based on incident type.
  3. Live accountability layer — unit chips pinned to logical coordinates. Chip state reflects real unit state (headcount, PAR status, Mayday, rehab, exposure recent).

Tools

Toolbar at the top:

  • Pan (default).
  • Draw — stroke color + width picker.
  • Erase.
  • Text — annotation with size and color.
  • Region — draw a polygon for a division; auto-suggests assignment when a unit is dropped into it.
  • Hazard pin — with type, severity, and description.
  • Hydrant — tap-to-add on a Structure Fire template's footprint.

Keyboard shortcuts: Space/D/E/S/R/T for tools, 1-5 for colors, Cmd/Ctrl+Z undo, Cmd/Ctrl+S snapshot, Esc cancels pending state.

Building generator

For structure fires, the building generator produces a plan-view and side-elevation from a few parameters:

  • Occupancy type (residential / commercial / industrial / mixed).
  • Stories.
  • Footprint dimensions.
  • Construction type.
  • Roof type.
  • Basement.
  • Attached structures.

Generated buildings live with the incident today. Save-as- pre-plan and a cross-incident pre-plan library will land in the admin console in a later release.

Command Post

Placed as a pinned element with the NAPSG standard CP symbol. IC can move it as the CP relocates; every move is preserved in the archive per Chapter 21.4.

Snapshot

Manual snapshots (or automatic at termination) capture the whiteboard as PNG for the after-action PDF.

Mutual aid and Unified Command

When another department's units arrive, Muster handles them as guests without ceremony (for pre-registered partners) or with a one-time QR scan (for spontaneous mutual aid).

Guest departments

  • Guest units check in like any other unit, with a guest badge.
  • Guest ICs, ISOs, and Rehab Officers use their normal roles — safety features work at full authority regardless of department.
  • Guest department retains authoritative ownership of their own personnel's exposure records, rehab records, and Mayday records (rule 25).

Unified Command

For incidents where multiple agencies share command (fire + law enforcement at a hostage situation; multiple fire departments crossing jurisdictional boundaries), Unified Command is a first-class concept per NFPA 1550 Chapter 18.5.

Activating:

  1. Current IC taps Propose Unified Command → picks the receiving IC.
  2. Receiving IC sees a prompt to accept.
  3. Both devices switch to Unified Command mode: top bar shows "Unified Command" instead of a single IC name.

Joint decisions. Strategy changes, full-scene evacuation, and termination require consensus of participating ICs. Each IC's device shows a proposal dialog with accept/reject.

Agency-scoped authority. Each IC retains full authority for their own agency's personnel — assignments, resources, agency- scoped evacuation. ISO imminent-danger authority remains unconditional for any ISO from any participating agency.

Area Command

For multiple related incidents that share resources but each have their own operational command (wildland complex, MCI with distributed care sites), Area Command coordinates without commanding — the Area Commander sees the whole picture and directs resources across incidents, but each incident's IC keeps operational command of their scene.

Terminating and finalizing

Termination is the ten-step flow from operational close to the archived record.

Hard blocks

Muster refuses to terminate if:

  • Any Mayday is unresolved (any non-resolved status).
  • Any evacuation is active without re-entry or explicit abandonment.

Resolve these first; there is no override.

Warn-but-allow

Muster shows warnings and lets the IC acknowledge and continue:

  • Open PARs → recorded as "PAR incomplete at termination."
  • Active assignments → auto-released (AssignmentEnded events).
  • Active rehab cycles → auto-exited.
  • Active hazards not marked mitigated → noted "active at termination."
  • Open safety concerns not acknowledged → "closed-unresolved."
  • Unacknowledged exposures → noted, preserved for firefighter acknowledgment later.
  • Emergency Traffic still active → auto-released.

The ten steps

  1. IC taps Terminate.
  2. Muster validates: hard blocks stop; warnings prompt.
  3. IC acknowledges warnings.
  4. TerminationInitiated event fires.
  5. Open items cascade (auto-release / exit / note).
  6. Incident enters pending_review state.
  7. IC writes a narrative.
  8. IC reviews the timeline and adds corrections (additive events, original never modified).
  9. IC finalizes (or auto-finalize after 72 hours by default).
  10. .muster archive is generated, signed, and stored.

Corrections

Any timeline event can be corrected. Corrections are additive — they add a CorrectionNoted event that references the original. The projection produces the canonical corrected state, but the original is preserved. The after-action PDF has a corrections appendix.

After the incident

The .muster archive

The signed ZIP containing:

  • Full event log (Protobuf binary).
  • All media (photos, whiteboard strokes).
  • Templates and pre-plans applied.
  • Roster snapshot.
  • Department settings snapshot.
  • Ed25519 signatures from participating devices.

The archive is the authoritative record. PDFs and other exports are renderings of the archive.

The after-action PDF

Comprehensive PDF with:

  • Cover page with signature field.
  • Timeline (editorial filter of significant events).
  • Personnel summary.
  • PAR log.
  • Benchmarks.
  • Rehab summary.
  • Safety events (hazards, concerns, evacuations, emergency traffic).
  • Exposures (per visibility settings).
  • Medical incidents.
  • Corrections appendix.

Cloud archive (Tier 2+)

Archives sync to the admin console automatically on finalization. Chief and admin can:

  • Browse and search archives.
  • Regenerate the PDF.
  • Access investigation mode (audit-logged) for full Mayday detail.
  • Generate NERIS-shape projections for their RMS integrator.
  • Generate cancer presumption documentation packages.

Settings

Peer Mesh

  • Cloud relay — live status tile (Off / Connecting… / Connected / Reconnecting) and mode toggle. Two modes:

    • Always-on (default) — engages the cloud relay immediately when the mesh starts, so a device on cellular or a different network can reach peers via wss://relay.safesignals.io without waiting on local mDNS discovery.
    • Fallback-only — waits 30 seconds for a local peer to show up on Wi-Fi first; engages the relay only if no local peer appears. Cancels the engagement if a local peer arrives inside the window.

    Requires the license's cloud_event_sync feature (Tier 2+). Emergency and Tier 1 devices don't engage the relay. Rule 6 preserved — local mesh + Mayday + evacuation continue to work if the relay is unreachable.

  • Show pairing QR — for QR-bootstrap mutual aid on networks where mDNS is blocked or when a guest department needs an explicit invite.

Cloud active incidents

Devices signed into a Tier 2+ department see an "Available on cloud" section in the incident switcher listing every currently-active incident in the department, regardless of which network the host device is on. Tap to join — the joining device seeds the local projection from the mirror doc's initial_event_json (the real IncidentCreated event; if absent, a synthesized minimal seed is used with a note in the join UI).

Missing an incident you expected to see? Two common causes:

  • The host device hasn't refreshed its last_seen_at in over 24 hours (defensive TTL sweep removes stale mirror docs).
  • Your device's license lacks cloud_event_sync (Emergency or Tier 1). Local mesh continues to work; the cloud mirror isn't part of that tier.

Roles and permissions

  • Role assignment — pick your role; changes take effect immediately.
  • ISO qualification tracking (Tier 2+) — chief grants / revokes via checkboxes on the personnel detail page's Qualifications card (iso_qualified, ic_qualified, and training_officer_qualified are stored in the personnel record's certifications set). The role-picker surfaces a compliance warning subtitle when an operator selects IC or ISO on a real-mode incident (NFPA 1550 Chapter 5 for IC, NFPA 1521 for ISO). The warning does not hard-gate (rules 5 + 22 — never automatically block command or ISO authority); training-mode incidents suppress the warning. Per-personnel hard-gating requires tying the device to a specific personnel record + is design-stage.

Notifications

  • Critical Alerts (iOS) — required for Mayday and evacuation bypass of Do Not Disturb. Prompts once at first launch.
  • Push notifications — Muster registers for FCM tokens at license activation.

Symbology

  • Symbol library — NAPSG, ANSI INCITS 415-2006, NFPA 704 (hazmat diamond), NWCG (wildland). Default: NAPSG for tactical, NFPA 704 for hazmat identification.

Symbology attribution

  • Muster uses NAPSG's incident symbology library under CC-BY 4.0. Attribution appears in Settings → Symbology.

Troubleshooting

Peers not discovering each other

  • Both devices on the same Wi-Fi? mDNS requires it.
  • Wi-Fi network blocks multicast? Enable one device as a hotspot and have others join it.
  • QR bootstrap as universal fallback — Settings → Peer Mesh → Show pairing QR on one device; scan from the other.

Cloud relay not connecting

  • License tier? Cloud relay requires Tier 2 or higher.
  • Internet reachable? Check wss://relay.safesignals.io from the device's browser.
  • Firewall blocking WebSocket upgrade? Some corporate firewalls do deep packet inspection that breaks WebSocket handshakes. See For IT & security teams.

License activation fails

  • Internet required for first-time activation. Once activated, Muster works offline for 60 days.
  • Wrong email or code? Check the welcome email; the code is one-time.
  • Expired grace period? Contact your department admin or support@safesignals.io.

Missing personnel from roster

  • Department admin adds personnel via admin console. Once added, they appear on all devices after the next license revalidation (up to 24 hours; force refresh via Settings → License → Revalidate).

PDF rendering slow

  • On older iPads — the pdf package is slower. Wait; the PDF is generated in the background and appears when ready.
  • Emoji rendering — Muster uses icon fonts rather than emoji because the pdf package renders emoji inconsistently.

App is stuck on a screen

  • Never force-quit during an active incident. Muster preserves state on force-quit but you might lose in-progress form data.
  • Force-quit is safe post-termination.

For more help, email support@safesignals.io or use the in-app Support link in Settings.