Petroleum theft in the Texas Permian Basin is an access problem before it is a volume problem. Product leaves through a discharge valve, a tank hatch or a loading connection on a site that is unmanned most of the day, and the discrepancy shows up later in reconciliation with no record of who was there. Restricting access at those points, detecting tampering as it happens, and keeping an event history per asset turns an unexplained variance into a reviewable event.
The Permian Basin in West Texas is an operating environment before it is a map. Production is spread across thousands of square miles of Texas oilfield, connected by lease roads, gathering lines and a constant flow of hauling. Most sites see a person for a fraction of the day. That geography is what makes petroleum theft difficult to address with presence alone — you cannot staff what is distributed, and you cannot patrol what is unmanned.
Losses begin at a physical access point
Crude does not leave an asset diffusely. It leaves through a specific opening that someone has to reach and operate: a discharge valve on a tank or trailer, a thief hatch on top of a storage tank, a loading connection at a remote tank battery. Every one of those points is designed to be opened — that is the job it does during normal operations. Which means the question is never whether the point can be opened, but whether opening it was authorized, whether anyone knew at the time, and whether a record exists afterwards.

Reconciliation can tell you product is missing. It cannot tell you who reached the valve.
Why the variance arrives too late to act on
In many operations the first signal of a loss is a number: a ticket that does not match a gauge, a tank level that fell faster than production explains, a month-end variance that a district manager is asked to account for. By then the product is gone, the vehicle involved has left, and there is nothing to review beyond estimates. Investigations stall not because operators lack diligence, but because no evidence was captured at the moment the access happened.
- A discrepancy is a summary, not an event — it has no time, actor or location attached.
- Unmanned sites produce no witnesses and often no camera coverage worth reviewing.
- Hauling adds custody handoffs where responsibility becomes contested.
- Repeat losses at the same access point look like separate accounting problems.
What actually changes the outcome
Treating this as an asset protection problem, rather than a reporting problem, means putting protection where the product leaves and monitoring at the same point. In practice that is three things working together: physical access protection at valves, hatches and loading connections; connected monitoring that detects tampering and unauthorized access and raises it in real time; and operational visibility so every access attempt becomes an event with a timestamp, a site and an asset attached.
- Controlled, auditable access by role instead of a shared key or an open fitting.
- Remote authorization, so a legitimate haul is approved rather than simply permitted.
- Tamper and unauthorized-access detection on distributed, unmanned sites.
- Event history per asset and per access point, retained for investigation and audit.
- Integration with the operational platforms the operation already runs.
Texas and the Permian as an operating environment
The Permian is not a special case so much as a demanding one. It combines the hardest conditions an asset protection architecture can be asked to work in: distance between sites, limited on-site presence, heavy third-party hauling, and assets that must remain operable by crews under time pressure. An approach that survives that environment tends to hold up anywhere product is stored and moved. Nuve is based in Austin and builds for those conditions — distributed sites first, and the hauling that connects them.
SolutionPermian Basin and Texas asset protectionOne protection architecture across distributed oilfield sites and the trucking between them.Read the solution →The practical starting point is narrow: list the access points on a single site, decide who is allowed to open each one, and decide what should happen the moment one of them is opened by anyone else. Everything else — telemetry, alerting, reporting, integration — follows from that list.

