Requirements Library · Public Preview
The FirePro Requirements Library
A wildfire detection and initial-attack programme that is designed and unfunded. This is the design — what the system must do, what it must refuse to do, what would prove it working, and what remains unknown.
The accompanying essay argues that a detection system for Oregon sits designed and
waiting on a funding decision rather than on an invention. It also made a promise: that
when the design work was ready it would be shown rather than described secondhand. This
is that showing.
Nothing described here has been built. No hardware exists, no agency has
been approached, and no line of production code has been written. A programme that cannot
yet be built can still be specified to the point where a reviewer can find its faults,
and that is the entire claim being made. A specification is worth reading when it is
falsifiable — when it names the observations that would show it wrong, the
assumptions it proceeded under, and the places it is silent.
Where this library comes from
Two bodies of practice, deliberately hybridised. The first is the BABOK Guide v3,
published by the International Institute of Business Analysis, cited throughout by clause
number and clause name. Every characterization of it here is our own wording, so a reader
with a copy can check our reading against the clause rather than take it on trust. No text
from the guide is reproduced.
The second is an internal specification-driven method developed in-house, referred to as
the House Method. Where the two agree, this library says so once. Where they genuinely
disagree, it says which one the library follows and why. Those disagreements are the most
useful content in the preview, and they are marked rather than blended — a
methodology page that smooths its sources into consensus has hidden the only part a
practitioner could argue with.
One point of provenance, because this library is strict about it elsewhere.
These pages are derived from the programme’s design corpus through a
structured inventory of it, rather than reproduced from the source artifacts directly. The
structure, the goals, the rules and the gap list are faithful to that corpus; the
full-depth material — every artifact at full section depth, with its evidence and
traceability blocks intact — is held privately and released after a conversation. So
a figure quoted here should be read as reported at one remove, not as a quotation from a
signed artifact. The library asks elsewhere that a status claim rest on the primary
artifact rather than on a secondary record’s assertion about it; this preview does not
yet meet its own standard on that point, and says so rather than letting the omission read
as compliance.
What is published, and what is not
The programme
The problem stated narrowly enough to be wrong, the five bounded contexts the design is organised around, and the ten design invariants with the artifact that enforces each. Carries a correction, left visible: an earlier internal claim about which rules the invariant set covers was false and had propagated to nine places.
The programme
Six goals for the programme itself — distinct from the goals of the practice that produced the specification. Each carries a measure and the observation that would falsify it. None has a baseline, and the reason is on every row.
The programme
Six permanent non-goals, seven halt conditions, and eleven risks — seven from the source and four created by gaps in it, marked as such. Two of the risks have no engineering answer at all, and they are why the programme is shaped the way it is.
The programme
Six role journeys and the authority model underneath them. The property worth more than the rest: the roles that can stop an action are not the roles that can command one — a crew member’s no-drop hold beats the duty officer’s authorisation, and no screen resolves it the other way.
The programme
Six specified sequences, three of them failure paths carried at the same depth as the successes — because failure is where an invariant is either true or decorative. Includes the principle underneath all six: degrade toward noise and toward safety, never toward silence or toward capability.
The programme
Why the hardest permission is asked last, why the two programme-ending assumptions are tested at opposite ends, and the rejected alternative presented at full strength. States a defect in itself: the last two milestones name no failing observation.
Published in full
Every operator surface the system specifies, each published with what it enforces beside what is deliberately absent from it. The absences are the point: no auto-confirm at high confidence, no override for a failed safety gate, no authorise control at all when the ground is not the agency’s to attack, and a crew member’s no-drop hold that the duty officer cannot override. Three screens are rendered from the specification; all imagery is generated and labelled as such.
Published in full
What the library recognises as an artifact, where each category comes from in the BABOK Guide and in the in-house method, what each one contains, and the completeness test you can apply to it yourself. Includes the four places the two source methods genuinely disagree and which one this library follows.
Published in full
Six goals for the practice, each with a measure, the instrument that captures it, the collector, the frequency, and the observation that would falsify it. Five of the six have no baseline yet, and the page says which and why rather than presenting a figure it does not have.
One artifact, complete
A single business rule worked end to end through all fourteen sections of the standard template. It is published complete, including an acceptance criterion recorded as currently failing and an evidence section recorded as empty, because a worked example that hides those teaches the wrong thing.
Published in full
Seven gaps the practice found in its own requirements set, including one — the near-total absence of adversarial security analysis — that is the largest and least defensible. Published because a requirements practice that cannot find its own gaps is not working.
Concept draft
The Wildfire Early Detection Partnership Act, drafted in Legislative Counsel form so its gaps sit where a drafter would look for them. Nobody has introduced it, no legislator has seen it, and no sponsor is attached — the bracketed figures are placeholders a drafter would price, not positions anyone has taken. It is here because the programme’s hardest dependencies are statutory rather than technical: who holds the federal airspace authorization, who pays across the years it has prevented nothing measurable, and how insurers and utilities contribute without it becoming a subsidy. Its section 6 is the argument in miniature — the assessment disappears for any owner holding a current defensible space certification, so public money for detection cannot quietly displace private responsibility for fuel.
The rest carries operational specifics — siting, spectrum, platform and vendor
selections, tuned numeric thresholds, named counterparties and jurisdictions. Those are
withheld as a publication decision, not because the corpus lacks them. Where a number has
been removed from a published page, the sentence says so rather than reading as though no
number exists.
Conventions used throughout
-
Identifiers are the library's own, of the form
TYPE-NNN. They are stable
and are never reused, even when an artifact is superseded or deleted. They do not
correspond to any identifier in the source system.
-
A slot marked N/A with a reason is a claim that was examined and can
be checked. A missing heading is a silence that cannot be. Only the first passes
review, and the distinction is enforced mechanically rather than by habit.
-
Time appears in this preview as release ordinals rather than calendar dates. The full
library carries dates.
The library as published
Thirty-nine parts. The status column is the honest answer to what is actually being shown,
and it is printed here rather than discovered after a request.
Three rows are worth noticing before you read anything else. Part V.6 is empty and says so.
The whole of Part VII is not applicable and says so. Appendix E is published in full and is
the longest thing here that reflects badly on the corpus. Those three facts are the
argument for the rest.
Requesting the rest
The parts marked on request are released after a conversation. That is not a
formality and it is not a mailing list: the material carries operational detail about a
system intended to operate in public airspace alongside crewed aircraft, and who holds it
is a decision worth making one person at a time.
A phone number is required because the conversation happens by phone. If you would rather
not provide one, use the contact page instead and say what you are
looking for — that route is open and always will be.