Technology consulting lead for a Gulf capital's unified Digital Out-of-Home programme, advising two government authorities simultaneously. I authored the technology specification, the platform requirements catalogue and the operator integration standard for an estate of 2,127 assets, then audited the installed digital base against them, device by device.
The city's outdoor advertising estate, roughly 2,127 permitted assets across two municipalities, sat under long-running concessions held by four private operators. Only 51 assets were digital, and every one ran on a proprietary vendor cloud. The government could see permits and contracts. It could not see what was playing, prove a booked campaign had actually run, enforce a content decision across multiple approving authorities, or push a public-safety message onto a single screen.
The mandate: one sovereign platform with a dual operating mandate. A guaranteed emergency and public-warning layer that can override every connected screen, and a governed commercial marketplace underneath it. Full source code, IP and data transferred to government, no vendor lock-in, architecture designed to scale past 1,000 connected assets.
My role was client-side: I wrote the standard the market had to meet, then tested the installed base against it. The specification reached v5.5, the requirements catalogue v2.3 across ten domains, each requirement bound to acceptance criteria, KPIs and SLAs, and together they became the programme's procurement baseline.
The platform doubles as a national public-warning surface, integrated with the national emergency management authority over the Common Alerting Protocol. Emergency content bypasses the entire commercial approval pipeline and is pushed straight to edge controllers in five languages, Arabic first. Delivery SLAs: two minutes zone-targeted, five minutes for the whole emirate. A five-tier override doctrine is enforced server-side and cannot be bypassed: Emergency over Public Safety over Civic over Regulatory over Paid Commercial. A separate three-scope kill switch runs from single-asset with MFA step-up to emirate-wide under dual control by two named supervisors.
The sharpest deliverable was the compliance assessment of the 35 in-service digital assets against the connection standard. The verdict: none could connect as configured. The core finding was conceptual: LED media players are not edge controllers. The estate ran commercial signage playback hardware managed from vendor clouds; the platform requires a hardened Linux computer running government-signed containers on a hardware root of trust.
But the assessment did not stop at "replace everything." Separating hardware capability from software configuration showed that 33 of the 35 assets were industrial x86 machines that already carried TPM 2.0 and could be recovered by reimaging to hardened Linux rather than replaced. That distinction changed the remediation cost of the programme. The audit also surfaced the details that only device-by-device work catches: a consumer-grade home router on public infrastructure, thermal ratings short of the environmental requirement, and a duplicate serial number that turned out to be an operator data-entry error.
A specification only has teeth if it can say no. Declaring three requirements non-negotiable is what turned the audit from advisory into decisive. And the most valuable consulting finding was not a failure grade, it was the distinction inside the failure: the difference between "replace 33 controllers" and "reimage 33 controllers" is most of a remediation budget, and you only find it by opening every box.