The mechanism, including the three ways it fails
Six operational sequences are specified. Three of them are failures, and they are not error branches appended to a happy path β they carry the same depth, because failure is where an invariant is either true or decorative.
The core loop: detection to a human decision
Target: under five minutes from ignition-detection to a human decision. Two gates fire before a person is interrupted at all.
- T-0 Aircraft flies an assigned patrol leg
Route weighted by fire danger, lightning history, and values at risk.
- T+0 On-board scoring β thermal anomaly and smoke morphology
No link required. Inference happens where the photons land, which is what makes the whole loop independent of connectivity.
- A detection claim is created
Coordinate, confidence, sensor modality, model version, observation time.
- Gate: does it match a registered burn?
A permitted burn is not a wildfire. Match β alert suppressed, logged, no human interrupted.
- Gate: does it match a known false source?
A millβs steam plume is not a wildfire. Match β suppressed and logged β but an anomalous reading at a known source still alerts, because a mill can burn down.
- T+1m Autonomous confirming pass
A second angle, closer, both sensors. This is the second source, and the aspect delta is shown to the analyst so independence is visible rather than asserted.
- T+3m Alert transmitted
Coordinate plus thumbnail, sized so the whole notification survives the thinnest link state the programme is authorised to use.
- <5m A human dispositions the claim
Confirm, need more, or reject with a source class. A rejection feeds the false-source registry β the loop closes and the system learns from its own noise.
The two gates are the reason the false-alarm budget is achievable at all. A permitted burn and a known false source are both expected signals, and a system that alerts on them spends its user's attention on things it already knew about.
Three failure paths, specified as carefully as the successes
Lost link Expected several times per sortie
Specified behaviour. A planned state with a declared terminal action, not an emergency. The aircraft knows in advance what it will do and does that.
Why at this depth. In this terrain it is routine. A system that treats the routine as exceptional will cry wolf until nobody listens β and then the alarm that matters arrives into a room that has stopped looking up.
A crewed aircraft enters the airspace Must never go wrong
Specified behaviour. Reflexive yield β descend or land immediately without waiting to confirm. Ambiguity is treated as confirmation. No automatic re-entry.
Why at this depth. A single incursion ends the suppression case for the whole programme. The response is deliberately over-reactive β and the corpus records that this same over-reaction is a cheap, permanent denial of service against the fleet, which is a trade it makes knowingly rather than a flaw it missed.
A false positive Decides adoption
Specified behaviour. Dispositioned, typed against a controlled vocabulary, counted against a declared budget, and fed back into the registry that prevents the next one.
Why at this depth. Trust is spent in units of wasted trips. This is the path that decides whether the system is used at all, which is why the controlled vocabulary is mandatory β free-text rejection would break the only mechanism that closes the loop.
The principle underneath all six: the system degrades toward noise and toward safety, never toward silence or toward capability. An unreachable registry produces more alerts, not fewer. A degraded link produces a smaller picture, not a confident one. Compensating autonomy β the machine quietly doing more because a human has become unreachable β is named as the seductive failure and forbidden outright.
What these flows are not evidence of
Every sequence here is specified and none has run. The gates have never fired, the confirming pass has never flown, and no false positive has ever been dispositioned, because nothing is built. Under this library's own standard β recorded as gap four β a check that has not been observed refusing a disqualified input does not count as present, and by that measure none of this counts yet.
The screens page shows where in the interface each of these refusals is meant to live; the charter lists the invariants they enforce.