User guide
Complete reference for using Muster during an incident. If you're just getting started, read the quick-start guide first — it walks you through your first incident in 15 minutes. This guide is the deep reference: every role, every screen, every action.
Testing Muster before your department goes live? Start with tester_onboarding.md instead — it covers the invite / install / License Key flow and points at the current beta feature list.
Table of contents
- The seven roles
- Starting an incident
- Check-in and roster management
- Divisions, groups, and branches
- Personnel Accountability Reports (PAR)
- Mayday
- Safety Officer authority
- Evacuations
- Rehab and vitals
- Exposure tracking
- Command transfer
- The Map view (Q2 GPS)
- The whiteboard
- Mutual aid and Unified Command
- Terminating and finalizing
- After the incident
- Settings
- Troubleshooting
The seven roles
Muster is one binary with role-adaptive screens. Each device picks a role at role-selection time; the role controls what the device can do.
Incident Commander (IC)
Device: tablet or laptop only. Phone devices redirect to "use a tablet."
The IC has overall command authority. Only the command-holding device can issue high-authority events: assign units, change strategy, terminate the incident.
What the IC sees: the full command board — every unit, every division, every timer, every benchmark, every safety event, every rehab cycle. Left side is the roster and unit list; center is the board itself (or the whiteboard when tapped); right side is the timeline and communication log.
Safety Officer (ISO)
Device: tablet preferred, phone works.
The ISO monitors overall scene safety. Distinct authority from IC: can order evacuation in imminent danger without IC approval (rule 22).
What the ISO sees: an ISO-specific board with active hazards, risk status (strategy, weather, structure type, collapse zones), per-unit time-on-task fatigue monitor, and three big buttons — Flag Hazard, Emergency Traffic, Evacuate.
ISO authority is unconditional — even if the license is expired, even if the device is a guest at another department's incident.
Division Supervisor
Device: tablet or phone.
Directs operations in one division. Sees only their division's units, assignments, and safety concerns. Can request PARs of their own units.
Accountability Officer
Device: phone (or tablet at the command post).
Runs PAR cadence for the whole incident when the IC delegates. The Division Supervisor runs PAR for their division; the AO runs PAR for the incident. Big Request PAR button; recent-PAR history card; unread + stale-PAR indicators.
Check-in Officer
Device: phone-first.
Manages intake of arriving units and personnel. High-throughput UI with big buttons and minimal typing. Scan a QR from a guest department's device, or type in unit name + headcount for units without Muster.
Rehab Officer
Device: phone-first.
Manages rehab cycles. Records vitals, watches for medical hold thresholds, clears firefighters back to duty, documents exposures observed during rehab.
Arriving Unit
Device: phone-first.
Three-screen self check-in for a unit that just pulled up. Pick your unit from a recents list or department roster, confirm crew size and roles, report your status. After submission, the role auto-transitions to Crew Member.
Observer
Device: any.
Read-only situational awareness. No write actions. Used by visiting officials, trainees on scene, media coordinators.
Crew Member
Device: phone-first.
The minimal view for individual firefighters. Shows your unit, your assignment, your division. Has the press-and-hold-2-seconds Mayday button, the PAR acknowledgment, and the self-report exposure action.
Crew Member does not see other crew members' vitals or exposure details — this is a privacy rule enforced in the software.
Switching roles mid-incident
Every device has a role switcher at the top of the AppBar. Tap your current role to open the picker; select a new role. The device instantly transitions.
Common transitions:
- Arriving Unit → Crew Member (automatic on check-in).
- Crew Member → Division Supervisor (after being assigned supervision).
- Observer → Safety Officer (if you're qualified and being assigned).
Qualification warnings on real-mode incidents
On a real-mode incident, selecting Incident Commander or Safety Officer from the picker surfaces a red compliance- warning subtitle citing the applicable NFPA standard (NFPA 1550 Chapter 5 for IC, NFPA 1521 for ISO). The warning is advisory only — the picker never hard-blocks your selection (rules 5 and 22 preserve the operator's authority to make command and safety decisions unconditionally). It's there so an operator picking one of these roles is prompted to confirm they hold the required qualification.
Training-mode incidents suppress the warning. Training drills exist specifically to build up to qualification, so the picker doesn't second-guess your selection there.
The underlying iso_qualified / ic_qualified flags on
each personnel record are granted/revoked by your chief via
the admin console's Qualifications card — see
for_admins.md.
Starting an incident
From the home screen with no active incident, tap Start Incident. Choose mode:
- 🚨 REAL INCIDENT — starts a real incident. All events go to your real event store; the archive is authoritative.
- 🎓 TRAINING / DRILL — hold-to-confirm 3 seconds to enter training mode. Training incidents are segregated at every level — see the training guide for detail.
For a real incident, fill in:
- Incident type. Structure fire, MVA, MCI, hazmat, wildland, TIM (traffic incident management), and others. Controls the default whiteboard template.
- Address. Where the incident is. Muster reverse-geocodes to a lat/lon if available.
- Description. Free text — dispatch narrative or your own.
- Number. Optional; auto-generates as
<year>-<four-digit-sequence>if omitted.
The device that creates the incident is the initial commanding device. Command can be transferred later — see Command transfer.
Check-in and roster management
Every unit on scene must be checked in for accountability to work. Three intake paths:
Path 1 — self-check-in (Arriving Unit role). Fastest for volunteer departments. Every firefighter uses their own phone.
Path 2 — check-in by the IC or a Check-in Officer. From the command board, tap Check In. Options:
- Pick from the department roster (home unit).
- Scan the QR code from a guest department's device.
- Type in a guest unit's designation and headcount.
Path 3 — pre-populated from CAD. Design-stage. The CAD connector interface is scaffolded (Tier 2+ feature) but no vendor-specific implementation ships today. Vendor-specific adapters are Phase 7 connector work, prioritized as customer demand surfaces.
Guest units
Guest units are units from another department (mutual aid). They have a guest badge on the unit chip. Guest units use headcount only — you don't need their department's roster.
The employing department of guest personnel retains authoritative ownership of that personnel's exposure records and rehab records per rule 25 (per-department data ownership).
Releasing a unit
Tap the unit chip → Release. Confirm. The unit leaves the incident; any active assignment ends automatically; any active rehab cycle exits. If the unit was assigned to a division that now has no units, the division stays but shows as empty.
Divisions, groups, and branches
Divisions are geographic sub-areas of the incident (Division A, B, C, D on a structure fire; sectors on a wildland). Groups are functional (Search Group, Ventilation Group). Branches aggregate multiple divisions or groups under one commander.
Creating a division
Add Division on the command board:
- Name. "A", "B", "Roof", "Staging", "Rehab", etc.
- Kind. Division, group, branch, staging, rehab, RIC, decon, triage, transport, treatment.
- Supervisor. Personnel from your roster. Optional but strongly recommended.
- Span of control limit. Default 5 (per NFPA 1550 Chapter 21.2). If a supervisor's span exceeds this, Muster warns you.
Assigning units
Drag a unit chip onto a division. Muster asks you to confirm the tactical purpose ("fire attack", "primary search", "ventilation") — free text but usually 2-3 words.
Assignments end explicitly (tap the assignment → End) or implicitly (unit released, incident terminated).
Personnel Accountability Reports (PAR)
PAR is your explicit check that every unit is accounted for.
Requesting a PAR
Tap Request PAR (IC board, Accountability Officer board, or Division Supervisor board — the DS's PAR scopes to their division only).
Every unit's device shows a prompt: "IC is asking for PAR. Confirm your crew count." The supervisor taps to confirm; the IC board fills in green.
PAR triggers
Per NFPA 1550, mandatory PARs on:
- Strategy change (offensive to defensive, etc.).
- Mayday declaration.
- Every 20 minutes (department-configurable).
- Before, during, and after evacuation.
Muster auto-prompts these; the IC can dismiss the prompt or proceed.
Missed PARs
If a unit doesn't respond within your PAR window, that unit turns yellow (approaching threshold) then red (missed the threshold). Red is a signal — investigate the unit's location before continuing operations. Missed PARs during a Mayday are particularly serious.
Mayday
The Mayday button is on every screen, every role, at all times. Muster's approach: fire fast, resolve deliberately.
Declaring a Mayday
On a phone (Crew Member view): press and hold the Mayday button for 2 seconds. The 2-second hold prevents accidental presses.
On a tablet (IC / ISO / DS): the Mayday control opens a confirmation dialog. Enter the affected personnel or unit, last known location, and initial report.
The moment Mayday fires:
- All mesh devices sound a non-silenceable audible alert for 10 seconds.
- The IC board's Mayday panel opens automatically.
- Every device shows the Mayday banner at the top of the screen.
- Muster requests an immediate PAR of every unit.
- Termination of the incident is blocked until the Mayday resolves.
Working the Mayday
Follow your department's SOP. Muster records:
MaydayAcknowledged— the IC or RIC has confirmed and is responding.MaydayLocated— the affected firefighter has been located.MaydayResolvedSafe/MaydayResolvedSerious/MaydayFalseAlarm— final status with a required note.
Every status change fires an event; the archive preserves the full sequence.
Push notifications for Mayday
On iOS, Mayday and evacuation alerts use Critical Alerts — they bypass Do Not Disturb, silent mode, and Focus. Apple requires an entitlement for this; Muster's entitlement was granted in May 2026.
Push notifications also fire for backgrounded incidents — if you're actively looking at Incident A and a Mayday fires on Incident B, you're alerted.
Safety Officer authority
The ISO has specific authorities distinct from the IC per NFPA 1550 Chapter 21.13. All available in the ISO panel:
- Flag Hazard. Type (structural, atmospheric, environmental, chemical, electrical, biological, traffic, other), severity (low / moderate / high / imminent), location, description, affected divisions. Hazards appear on the whiteboard and on affected division cards.
- Raise Safety Concern. Targeted at a specific division or unit (fatigue, tactic, PPE, procedure). Notifies the division supervisor, who acknowledges and responds.
- Emergency Traffic. Halts non-safety radio communications. Non-silenceable audible alert on all devices.
- Recommend Evacuation. IC confirms in normal danger cases.
- Order Evacuation (imminent danger). ISO's unconditional authority — IC is notified but does not need to approve.
- Rotation Recommended. Signals that a specific unit should cycle to rehab.
Vitals access
Per Chapter 21.13, the ISO has access to vitals during the current incident. Access is audit-logged.
Fatigue monitor
ISO's board includes a per-unit fatigue monitor. Default thresholds:
- Green: under 20 minutes on active task.
- Yellow: 20-30 minutes. Rotation recommended.
- Red: 30+ minutes. Rotation required. Also the NFPA 1580 Chapter 22.7.1.1 rehab trigger.
Thresholds are hardcoded to the NFPA 1580 Chapter 22 defaults today. Department-configurable thresholds via the admin console are Phase 5d work; the setting appears in Settings → Rehab policies on the admin console but the write path is pending.
Evacuations
Evacuations are the second-most-serious event after Mayday. Muster tracks them explicitly.
Recommended evacuation (IC confirms)
- Someone (typically ISO) taps Recommend Evacuation.
- IC gets a prominent alert on their board with the recommender and reason.
- IC either:
- Approves and orders →
EvacuationOrderedevent. - Modifies scope and orders → scope-changed
EvacuationOrdered. - Declines with reason →
EvacuationDeclined, evacuation doesn't happen.
- Approves and orders →
Imminent-danger evacuation (ISO orders directly)
When the ISO identifies imminent danger (roof collapse imminent, flashover signs, backdraft indicators), the ISO can order evacuation directly with a required reason (minimum 10 characters).
EvacuationOrderedByIso event fires; the IC is notified but does
not need to approve. This is unconditional (rule 22 — ISO
imminent-danger authority never gates on anything).
After the evacuation
Muster automatically:
- Moves affected units to staging.
- Requires a PAR before any re-entry.
- Blocks termination until re-entry or explicit abandonment.
If accountability fails after evacuation (personnel missing), declare a Mayday.
Rehab and vitals
Rehab cycles track a firefighter through the rest → monitoring → clearing flow. Runs per NFPA 1580 Chapter 22 (formerly NFPA 1584).
Entering rehab
Rehab Officer taps Intake on the rehab station board:
- Select the firefighter (from your roster) or unit (headcount only for guests).
- Confirm the trigger — SCBA bottle count, time-on-task, IC direction, self-report.
- Firefighter enters rehab.
Recording vitals
Every reading is optional — a department with just a BP cuff and pulse oximeter can still use rehab tracking:
- Heart rate, blood pressure systolic + diastolic, SpO2, temperature, respiratory rate, perceived exertion (Borg 1-10), notes.
- Muster evaluates against NFPA 1580 Chapter 22 thresholds (or department-configured thresholds on Tier 2+).
Clearance and medical hold
- Cleared — vitals in range across two readings 5+ minutes apart. Firefighter returns to staging; IC can reassign.
- Held for medical — thresholds exceeded; requires medical evaluation. Locks the firefighter out of operational assignment until the hold is cleared.
- Medical hold override — IC can override with a required reason (creates a paper-trail event). Not silent — the override is prominent in the archive and the after-action PDF.
Crew Member view of own vitals
You never see another crew member's vitals — that's a hard privacy rule enforced at the use-case layer.
Cross-incident personal vitals history is design-stage —
Muster's default retention is incident_only, meaning vitals
records live in the archive with the incident, not in a
per-firefighter history. Opt-in cross-incident aggregation and
firefighter-portal display of your own history are Phase 5d
work. Exposure records (separate from vitals) already flow to
the firefighter portal per OSHA 1910.1020.
Exposure tracking
Exposure to smoke, chemicals, asbestos, bloodborne pathogens, carcinogens, and other contaminants is documented in Muster per NFPA 1550 Chapter 16.7-8 and OSHA 1910.1020.
Recording an exposure
Any of these can record an exposure:
- IC, ISO, Rehab Officer, or Division Supervisor via the affected personnel's card.
- Crew member self-reporting via their phone.
- Post-incident within the review window.
Fields captured:
- Exposure type (smoke, chemical, asbestos, bloodborne, biological, carcinogen, radiological, PFAS, diesel exhaust, heat, cold, noise, other) and specific agent.
- Route (inhalation, dermal, ingestion, injection, mixed).
- Start/end time or duration.
- Location on scene.
- Intensity estimate.
- PPE worn (checkboxes).
- PPE failures noted.
- Decon performed (gross, technical, mass).
- Symptoms.
- Medical evaluation recommended, transport recommended.
Long-term retention
Exposure records are retained for 30+ years post-separation per OSHA 1910.1020 (Tier 2+). Admin cannot configure retention shorter — this is a hard architectural rule.
Long-term records live in the admin console (admin.safesignals.io) and the firefighter portal (firefighter.safesignals.io).
Cancer presumption support
Muster produces state-specific cancer presumption documentation export packages for California, Florida, New York, New Jersey, Massachusetts, Pennsylvania, Texas, and Illinois. See the admin console → Exposures → Generate Presumption Documentation.
Command transfer
Command transfers are explicit and never automatic (rule 5).
The happy path
Current IC taps Transfer Command → picks the receiving device from the peer list → the receiving device sees a prompt to accept.
Accept → CommandTransferred event, new IC has full authority.
The old IC continues to participate but does not command.
The IC-unresponsive path
If the IC device goes silent (no heartbeat for 30 seconds), any other peer sees an Assume Command? prompt.
Assuming command requires a required reason (minimum 10
characters) explaining why — e.g., "IC device battery died",
"Chief sent to rehab". The reason lands in
CommandAssumed and shows in the archive.
Split-brain
Rare but possible: two devices claim command after a network partition heals. Muster's HLC-based resolution:
- Whichever device's
CommandTransferred/CommandAssumedevent has the higher HLC timestamp wins. - The other device's post-partition events are flagged as "issued while not holding command" in the archive.
- All peers get a prominent notice explaining what happened.
The Map view (Q2 GPS)
Distinct from the whiteboard: a real-world map layer showing where each unit's device physically is per its GPS. Access from the Map button on the IC board's AppBar.
How it works. Every device attached to a unit reports
its position via UnitLocationReported events (proto field
1100) at 30-second cadence, rate-limited to fixes with
accuracy ≤100 m (both values are department-configurable
in Settings → Peer Mesh). The Map view renders each
unit's last-known position as a pin against
OpenStreetMap tiles.
Permission is required. On first entry into the Map view, Muster surfaces a pre-flight rationale dialog explaining what/why/when/what-if-declined before the OS prompt fires. Grant location "While Using the App"; the Map view starts populating within one fix cycle. Declining is fine — Mayday, evacuation, PAR, and every other safety feature continue to work regardless of whether you granted location (rule 6). The Map view will show a persistent red banner when permission is denied, with a shortcut to Settings → Location so you can re-grant later.
Which units appear. Only units whose crew members have selected the Crew Member role AND picked their unit AND granted location permission. Chiefs and ISOs on tablets without an attached unit don't appear as pins by design.
Whiteboard pin vs Map pin. The whiteboard's unit chips are TACTICAL — the IC drags them onto templates and division regions to represent operational placement. The Map view's pins are REAL-WORLD GPS coordinates. A truck's whiteboard chip could be pinned to "side C" (a tactical description) while the same truck's Map pin shows the actual curb address. Both are useful; they're different layers.
Privacy. GPS position is more sensitive than operational data. Crew Member view does NOT display other members' GPS positions — the Map view is available to IC, ISO, and Division Supervisor roles. Long-term GPS history is not kept unless explicitly opted into by the firefighter (this opt-in is on the roadmap for a future release).
The whiteboard
The whiteboard is the IC's spatial command surface. Tablet-first, though phone works for reference.
Layers
Three composed layers:
- Context layer — freehand ink, dropped images, notes.
- Template layer — ICS-201, structure fire, TIM (traffic incident), wildland, MCI grid. Auto-fills based on incident type.
- Live accountability layer — unit chips pinned to logical coordinates. Chip state reflects real unit state (headcount, PAR status, Mayday, rehab, exposure recent).
Tools
Toolbar at the top:
- Pan (default).
- Draw — stroke color + width picker.
- Erase.
- Text — annotation with size and color.
- Region — draw a polygon for a division; auto-suggests assignment when a unit is dropped into it.
- Hazard pin — with type, severity, and description.
- Hydrant — tap-to-add on a Structure Fire template's footprint.
Keyboard shortcuts: Space/D/E/S/R/T for tools, 1-5 for colors, Cmd/Ctrl+Z undo, Cmd/Ctrl+S snapshot, Esc cancels pending state.
Building generator
For structure fires, the building generator produces a plan-view and side-elevation from a few parameters:
- Occupancy type (residential / commercial / industrial / mixed).
- Stories.
- Footprint dimensions.
- Construction type.
- Roof type.
- Basement.
- Attached structures.
Generated buildings live with the incident today. Save-as- pre-plan and a cross-incident pre-plan library will land in the admin console in a later release.
Command Post
Placed as a pinned element with the NAPSG standard CP symbol. IC can move it as the CP relocates; every move is preserved in the archive per Chapter 21.4.
Snapshot
Manual snapshots (or automatic at termination) capture the whiteboard as PNG for the after-action PDF.
Mutual aid and Unified Command
When another department's units arrive, Muster handles them as guests without ceremony (for pre-registered partners) or with a one-time QR scan (for spontaneous mutual aid).
Guest departments
- Guest units check in like any other unit, with a guest badge.
- Guest ICs, ISOs, and Rehab Officers use their normal roles — safety features work at full authority regardless of department.
- Guest department retains authoritative ownership of their own personnel's exposure records, rehab records, and Mayday records (rule 25).
Unified Command
For incidents where multiple agencies share command (fire + law enforcement at a hostage situation; multiple fire departments crossing jurisdictional boundaries), Unified Command is a first-class concept per NFPA 1550 Chapter 18.5.
Activating:
- Current IC taps Propose Unified Command → picks the receiving IC.
- Receiving IC sees a prompt to accept.
- Both devices switch to Unified Command mode: top bar shows "Unified Command" instead of a single IC name.
Joint decisions. Strategy changes, full-scene evacuation, and termination require consensus of participating ICs. Each IC's device shows a proposal dialog with accept/reject.
Agency-scoped authority. Each IC retains full authority for their own agency's personnel — assignments, resources, agency- scoped evacuation. ISO imminent-danger authority remains unconditional for any ISO from any participating agency.
Area Command
For multiple related incidents that share resources but each have their own operational command (wildland complex, MCI with distributed care sites), Area Command coordinates without commanding — the Area Commander sees the whole picture and directs resources across incidents, but each incident's IC keeps operational command of their scene.
Terminating and finalizing
Termination is the ten-step flow from operational close to the archived record.
Hard blocks
Muster refuses to terminate if:
- Any Mayday is unresolved (any non-resolved status).
- Any evacuation is active without re-entry or explicit abandonment.
Resolve these first; there is no override.
Warn-but-allow
Muster shows warnings and lets the IC acknowledge and continue:
- Open PARs → recorded as "PAR incomplete at termination."
- Active assignments → auto-released (
AssignmentEndedevents). - Active rehab cycles → auto-exited.
- Active hazards not marked mitigated → noted "active at termination."
- Open safety concerns not acknowledged → "closed-unresolved."
- Unacknowledged exposures → noted, preserved for firefighter acknowledgment later.
- Emergency Traffic still active → auto-released.
The ten steps
- IC taps Terminate.
- Muster validates: hard blocks stop; warnings prompt.
- IC acknowledges warnings.
TerminationInitiatedevent fires.- Open items cascade (auto-release / exit / note).
- Incident enters
pending_reviewstate. - IC writes a narrative.
- IC reviews the timeline and adds corrections (additive events, original never modified).
- IC finalizes (or auto-finalize after 72 hours by default).
.musterarchive is generated, signed, and stored.
Corrections
Any timeline event can be corrected. Corrections are additive —
they add a CorrectionNoted event that references the original.
The projection produces the canonical corrected state, but the
original is preserved. The after-action PDF has a corrections
appendix.
After the incident
The .muster archive
The signed ZIP containing:
- Full event log (Protobuf binary).
- All media (photos, whiteboard strokes).
- Templates and pre-plans applied.
- Roster snapshot.
- Department settings snapshot.
- Ed25519 signatures from participating devices.
The archive is the authoritative record. PDFs and other exports are renderings of the archive.
The after-action PDF
Comprehensive PDF with:
- Cover page with signature field.
- Timeline (editorial filter of significant events).
- Personnel summary.
- PAR log.
- Benchmarks.
- Rehab summary.
- Safety events (hazards, concerns, evacuations, emergency traffic).
- Exposures (per visibility settings).
- Medical incidents.
- Corrections appendix.
Cloud archive (Tier 2+)
Archives sync to the admin console automatically on finalization. Chief and admin can:
- Browse and search archives.
- Regenerate the PDF.
- Access investigation mode (audit-logged) for full Mayday detail.
- Generate NERIS-shape projections for their RMS integrator.
- Generate cancer presumption documentation packages.
Settings
Peer Mesh
-
Cloud relay — live status tile (Off / Connecting… / Connected / Reconnecting) and mode toggle. Two modes:
- Always-on (default) — engages the cloud relay
immediately when the mesh starts, so a device on
cellular or a different network can reach peers via
wss://relay.safesignals.iowithout waiting on local mDNS discovery. - Fallback-only — waits 30 seconds for a local peer to show up on Wi-Fi first; engages the relay only if no local peer appears. Cancels the engagement if a local peer arrives inside the window.
Requires the license's
cloud_event_syncfeature (Tier 2+). Emergency and Tier 1 devices don't engage the relay. Rule 6 preserved — local mesh + Mayday + evacuation continue to work if the relay is unreachable. - Always-on (default) — engages the cloud relay
immediately when the mesh starts, so a device on
cellular or a different network can reach peers via
-
Show pairing QR — for QR-bootstrap mutual aid on networks where mDNS is blocked or when a guest department needs an explicit invite.
Cloud active incidents
Devices signed into a Tier 2+ department see an
"Available on cloud" section in the incident switcher
listing every currently-active incident in the department,
regardless of which network the host device is on. Tap to
join — the joining device seeds the local projection from
the mirror doc's initial_event_json (the real
IncidentCreated event; if absent, a synthesized minimal
seed is used with a note in the join UI).
Missing an incident you expected to see? Two common causes:
- The host device hasn't refreshed its
last_seen_atin over 24 hours (defensive TTL sweep removes stale mirror docs). - Your device's license lacks
cloud_event_sync(Emergency or Tier 1). Local mesh continues to work; the cloud mirror isn't part of that tier.
Roles and permissions
- Role assignment — pick your role; changes take effect immediately.
- ISO qualification tracking (Tier 2+) — chief grants /
revokes via checkboxes on the personnel detail page's
Qualifications card (
iso_qualified,ic_qualified, andtraining_officer_qualifiedare stored in the personnel record'scertificationsset). The role-picker surfaces a compliance warning subtitle when an operator selects IC or ISO on a real-mode incident (NFPA 1550 Chapter 5 for IC, NFPA 1521 for ISO). The warning does not hard-gate (rules 5 + 22 — never automatically block command or ISO authority); training-mode incidents suppress the warning. Per-personnel hard-gating requires tying the device to a specific personnel record + is design-stage.
Notifications
- Critical Alerts (iOS) — required for Mayday and evacuation bypass of Do Not Disturb. Prompts once at first launch.
- Push notifications — Muster registers for FCM tokens at license activation.
Symbology
- Symbol library — NAPSG, ANSI INCITS 415-2006, NFPA 704 (hazmat diamond), NWCG (wildland). Default: NAPSG for tactical, NFPA 704 for hazmat identification.
Symbology attribution
- Muster uses NAPSG's incident symbology library under CC-BY 4.0. Attribution appears in Settings → Symbology.
Troubleshooting
Peers not discovering each other
- Both devices on the same Wi-Fi? mDNS requires it.
- Wi-Fi network blocks multicast? Enable one device as a hotspot and have others join it.
- QR bootstrap as universal fallback — Settings → Peer Mesh → Show pairing QR on one device; scan from the other.
Cloud relay not connecting
- License tier? Cloud relay requires Tier 2 or higher.
- Internet reachable? Check
wss://relay.safesignals.iofrom the device's browser. - Firewall blocking WebSocket upgrade? Some corporate firewalls do deep packet inspection that breaks WebSocket handshakes. See For IT & security teams.
License activation fails
- Internet required for first-time activation. Once activated, Muster works offline for 60 days.
- Wrong email or code? Check the welcome email; the code is one-time.
- Expired grace period? Contact your department admin or
support@safesignals.io.
Missing personnel from roster
- Department admin adds personnel via admin console. Once added, they appear on all devices after the next license revalidation (up to 24 hours; force refresh via Settings → License → Revalidate).
PDF rendering slow
- On older iPads — the
pdfpackage is slower. Wait; the PDF is generated in the background and appears when ready. - Emoji rendering — Muster uses icon fonts rather than emoji
because the
pdfpackage renders emoji inconsistently.
App is stuck on a screen
- Never force-quit during an active incident. Muster preserves state on force-quit but you might lose in-progress form data.
- Force-quit is safe post-termination.
For more help, email support@safesignals.io or use the in-app
Support link in Settings.