What success would look like, and what would prove it wrong
Six goals for the programme itself. Each carries a measure, and each carries the observation that would falsify it — a goal without a falsifier is a slogan. None has a baseline, and the reason is on every row rather than in a footnote.
These are the goals of the programme being specified. They are not the goals of the requirements practice that produced the specification — those are on the practice goals page, and conflating the two is easy enough that both pages say which they are.
The source corpus does not state a set of programme goals. It states non-goals, requirements, rules, standards and a plan — and the goals below were read out of those artifacts by this library rather than lifted from a list the programme wrote. Under this library's own grading that makes them derived, not attested.
That matters for how much weight they carry. The measures and falsifiers are real commitments traceable to specific standards; the framing of them as six numbered goals is an editorial act. If the programme later writes its own goals and they differ from these, the programme's are correct and this page is wrong — which is the right way round and is stated here so nobody has to guess.
This is the same class of error the charter records: a claim read out of a mapping is derived, and grading it attested is what removes the prompt to re-check it.
G-1 A detection reaches the responsible human fast enough to change the outcome, with its uncertainty still attached.
- Measured by
- Detection-to-notification latency, and whether confidence and provenance survive to every surface including exports.
- Falsified by
- A measured latency that lands outside the window in which a fire is still small — or a surface, anywhere, that displays a claim stripped of its confidence.
The second half is the harder one. Latency is easy to measure and easy to argue about; a confidence value quietly dropped in an export is how a probabilistic claim becomes an institutional fact.
G-2 The programme keeps its licence to operate: it never becomes a hazard to crewed aircraft or to people on the ground.
- Measured by
- Airspace incidents, and drops with a ground position older than the freshness limit.
- Falsified by
- One incursion. The target is zero and it is an exit condition rather than an aspiration.
A single incursion ends the suppression case for the whole programme, which is why the specified response is deliberately over-reactive — and why the corpus also records that the same over-reaction is a cheap denial of service against the fleet.
G-3 The system is trusted enough to be used: alarm load stays inside a human’s tolerance, and every refusal is legible in operational language.
- Measured by
- False positives per duty officer per shift against a declared budget; refusals typed and machine-countable.
- Falsified by
- Sustained load above the budget — or, more quietly, a refusal an operator cannot act on because it names a system state rather than an operational one.
Trust is spent in units of wasted trips. This is the goal that decides whether the system is used at all, which is why the false-positive path is specified as carefully as the successes.
G-4 One supervisor safely oversees many aircraft — which is where the programme’s economics live.
- Measured by
- Achieved supervision ratio under real workload, not modelled.
- Falsified by
- A measured ratio materially below the assumed band — or an operational rule that caps it administratively, which would falsify it without any human-factors finding at all.
The second falsifier is the one nobody plans for: the ratio can be capped by regulation rather than by human capability, and the business case does not care which.
G-5 Initial attack happens inside the window in which a small fire is still small.
- Measured by
- Time from detection to first drop, and measured effect on rate of spread.
- Falsified by
- Trial outcomes in which the effect on rate of spread is indistinguishable from no action at the sortie interval the turn cycle can actually sustain.
This is the goal that rests on the programme-ending efficacy assumption. It cannot be settled from a desk, and the plan tests it at the last milestone before any suppression build spend.
G-6 The operating organisation can investigate, audit and extend the system without the supplier.
- Measured by
- Whether an incident can be reconstructed end to end — including the interface state each human was shown — with no vendor assistance.
- Falsified by
- A reconstruction attempt that stalls on data the system did not capture, or that requires the supplier to interpret.
Treated as a precondition of the programme existing rather than a feature. It cannot be retrofitted after an incident, because the uncaptured data is not recoverable.
Every one of these is unmeasured
Not one of the six has a baseline, because nothing is built and no season has been operated. The measures are specified — instrument, collector, frequency, falsifier — and have never been run.
Where a number appears anywhere in this library it is a design target or a declared placeholder, never a result. The initial-attack envelope figure in particular is explicitly a placeholder awaiting an evidence-based revision, and is recorded that way in the source rather than presented as a finding.
Two of these goals rest on assumptions the programme names as programme-ending if wrong — G-2 on the airspace safety case, G-5 on initial-attack efficacy. The plan exists to test those two in the order that spends least on being wrong, and the halt conditions say what happens when one of them fails.