Prove Fire-Protection Cause-and-Effect Boundaries Before Integrated Acceptance
Before integrated acceptance, prove every consequential fire or suppression input produces the required effects—and only the required effects—across power, HVAC, controls, and adjacent zones.
Before integrated acceptance, show for each consequential fire or suppression input exactly what must happen, exactly what must not happen, and prove both sides of that boundary in the as-built system with objective test evidence.
Issue a controlled cause-and-effect matrix or equivalent sequence basis that identifies each consequential initiating input, zone, required downstream effect, required non-effect, timing or delay where applicable, reset condition, and responsible system interface
Reconcile the matrix to the current approved design, fire-alarm programming, suppression logic, electrical shutdown interfaces, HVAC and smoke-control sequences, BMS/controls logic, access-control interfaces, adjacent-zone boundaries, and field point identities
Define representative test scenarios that exercise both intended effects and credible unintended cross-boundary paths, including adjacent-zone inputs where a shared or interfaced system could affect critical operations
Confirm all prerequisite individual-system tests required by the project are complete before relying on integrated results, and identify any impaired, bypassed, temporary, overridden, or not-yet-final conditions
Execute the project-approved L4/L5 tests and record actual outputs, statuses, timing, alarms, shutdowns, releases, inhibitions, resets, and downstream system states against the controlled matrix
For every consequential input, explicitly verify required non-effects as well as required effects; do not infer non-effect from absence of an observed incident outside the tested scenario
Stop on any unexpected cross-zone or cross-system response, missing required effect, contradictory indication, unexplained timing, or undocumented interface and route it through the existing commissioning deficiency and design-governance process
Re-test the affected causal path and any materially coupled scenarios after program, wiring, sequence, zoning, bypass, equipment, or interface changes, then retain an accepted as-left cause-and-effect record
NASA/JPL Lessons Learned Information System Lesson 6776 records that on August 26, 2011, a sprinkler head in office space at JPL Building 600 leaked and then failed. The office space shared a fire alarm system with an adjacent data center supporting Mars Science Laboratory Assembly, Test, and Launch Operations. No water was released in the data center, but activation of the shared alarm caused an immediate electrical shutdown and data-center power outage. Personnel had believed a ten-minute countermand period existed; subsequent investigation found the shutdown was immediate. JPL later installed a separate double-interlock preaction system for the data center so an office-space alarm would not trigger the data-center electrical shutdown. The public lesson does not publish the complete cause-and-effect matrix, wiring, code analysis, or all downstream system states.
Evidence to confirm
Controlled as-built cause-and-effect matrix
authority having jurisdiction · Before the relevant work begins
Every consequential input identifies the approved zone, required effects, required non-effects, timing or delay where applicable, reset state, downstream interfaces, and current revision.
Fire-to-building-system interface reconciliation
authority having jurisdiction · Before the relevant work begins
Fire-alarm/suppression points and programming are reconciled to electrical, HVAC, smoke-control, BMS, security, adjacent-zone, and field identities included in the test boundary.
Approved integrated test scenario set
authority having jurisdiction · Before the relevant work begins
Scenarios cover the consequential intended causal paths and credible cross-boundary paths proportionate to the approved design, including required non-effects.
Effect and non-effect test record
authority having jurisdiction · Before the relevant work begins
For each tested input, actual downstream outputs, statuses, timing, shutdowns, releases, inhibitions, alarms, and non-effects are recorded against acceptance criteria with no unresolved contradiction.
Deficiency resolution and repeat-test evidence
authority having jurisdiction · Before the relevant work begins
Every failed, unexpected, or undocumented response is dispositioned through existing governance and the affected causal path is re-tested successfully after correction.
Reset and return-to-normal proof
authority having jurisdiction · Before the relevant work begins
The facility demonstrates the project-defined reset, restoration, and normal operating state after the tested scenarios without hidden overrides or residual unintended states.
Accepted as-left sequence and change record
authority having jurisdiction · Before the relevant work begins
Conditions to resolve before proceeding
The controlled cause-and-effect basis does not identify both required effects and required non-effects for a consequential interface
The field/programmed configuration cannot be reconciled to the approved sequence or point identity
Prerequisite system acceptance required by the project is incomplete or a consequential bypass, impairment, override, or temporary state is unresolved
A test produces an unexpected shutdown, release, inhibit, cross-zone response, missing effect, contradictory indication, or unexplained timing
A required reset or return-to-normal state cannot be demonstrated
A material interface or sequence change occurs after the verified test without bounded re-evaluation and re-test
Where the lesson comes from
Sources
Use the original material to understand the evidence, scope, and context behind this Pearl. Suggested project actions are Build Pearls’ interpretation.
NFPA 4, Standard for Integrated Fire Protection and Life Safety System Testing — 2023 Motions Committee Report
National Fire Protection Association · Source date: 2023-05-09 · NFPA 4 2023 Motions Committee Report, annex material associated with scope; NFPA 4 2023 Motions Committee Report, proposed Chapter 1 scope; NFPA 4 2023 Motions Committee Report, proposed Section 1.2 · Accessed: 2026-09-04
Triggering an Office Fire Alarm Shut Down an Adjacent Data Center
NASA Lessons Learned Information System / Jet Propulsion Laboratory · Source date: 2012-09-25 · NASA LLIS Lesson 6776, Driving Event; NASA LLIS Lesson 6776, Driving Event and Evidence of Recurrence Control Effectiveness; NASA LLIS Lesson 6776, Recommendation 2 · Accessed: 2026-09-04
The retained authority accepts the final tested sequence, program/configuration revision, outstanding exceptions, and any post-test changes requiring re-verification.
NIST provides general fire-alarm/building-automation integration context and does not prescribe modern data-center cause-and-effect criteria.
The NASA lesson establishes the event, the shared fire-alarm relationship, the immediate electrical shutdown, and JPL's corrective action, but it does not publish the complete fire-alarm cause-and-effect matrix, wiring, control logic, or code analysis.
The NIST publication is general integration guidance from 2001 and is not a current project code requirement.
The historical event occurred in 2011 at a leased JPL facility and cannot establish the current code-required sequence for another data center.
The historical event occurred in 2011 at a specific leased JPL facility; the exact current code basis, authority-having-jurisdiction requirements, and modern data-center design are project-specific.
The lesson does not establish that every data center should isolate every fire alarm input from power, HVAC, controls, or other life-safety effects.
This is official NFPA standards-development material, not a project-specific code determination and not proof of which NFPA 4 edition, if any, is adopted for a particular facility.
The project has an approved design basis, cause-and-effect matrix, sequence, or equivalent source from which required effects and non-effects can be defined
Qualified project authorities can approve safe representative test methods without relying on this Pearl to set life-safety requirements
Fire alarm, suppression, electrical, mechanical, controls, security, and operations teams can participate in integrated testing where their systems are in scope
Existing commissioning, design, deficiency, change, AHJ, and turnover governance can retain the required closure evidence