What it will not do, and what would stop it
This page owns the boundary and the stop conditions. Two of the risks have no engineering answer at all, and they are the reason the programme is shaped the way it is — which is the subject of the plan, not this page.
Permanent non-goals
These are commitments, not a roadmap of things deferred. A non-goal that quietly becomes a feature is how a safety argument decays — usually with each step defensible and the destination indefensible.
| Not this | Why it is permanent |
|---|---|
| No autonomous suppression decision | The aircraft never decides to drop. A named person authorises every release, the authorisation is non-inheritable, and it expires. |
| Not a fire-behaviour prediction system | It reports what it observes. It does not forecast spread, and it never presents modelled data as measured. |
| No surveillance capability | Observation is purpose-limited by construction, not by policy. Imagery unrelated to a fire is deleted on a short clock — a property of the schema rather than a discipline someone must remember. |
| Not a replacement for crewed aviation | Additive, and it yields. Where a crewed aircraft may be present, the uncrewed fleet descends or lands. |
| Not a communications network for others | The relay platform carries programme traffic. It deliberately refuses to relay the incumbent voice network, because becoming load-bearing infrastructure for an agency creates a dependency nobody agreed to. |
| No jurisdiction of its own | The programme owns no ground and cannot acquire any. It operates inside organisations that hold statutory responsibility, and it can be told to stop. |
The risk register, with its provenance on the face of it
The source names seven risks. This register carries eleven. The four additions are risks created by gaps rather than risks the source failed to notice — each exists because a piece of analysis is missing. They are marked below, and a reader should treat them as this library's assessment rather than the programme's own.
| # | Risk | Impact | Response | Source |
|---|---|---|---|---|
| R1 | Certification timing slips | Operating cost stays high on waiver-by-waiver operation | The plan assumes waiver-based operation regardless. Expensive, not fatal. | programme |
| R2 | Detection quality below the false-positive budget | Programme credibility; possible stop | This is why the detection milestone precedes everything scaled. Fix or stop, on evidence. | programme |
| R3 | No compliant radio in the required form factor | Coverage capped at relay-covered volumes indefinitely | Not fatal — caps ambition at district rather than statewide. Model the case both ways. | programme |
| R4 | Release authority is never granted | Suppression never happens; the programme is a detection company | Detection alone is a viable, smaller business. Sequencing makes this survivable rather than terminal. | programme |
| R5 | Compliant hardware costs exceed the model | Fleet sizing shrinks | Cost the compliant set before integration investment creates lock-in. | programme |
| R6 | An airspace incident involving a programme aircraft | Programme-ending | Reflexive yield, no automatic re-entry, zero-incident as an exit gate. No further engineering answer exists. | programme |
| R7 | The partner agency withdraws | Programme stops | Mitigated only by being genuinely useful. There is no technical mitigation at all. | programme |
| R8 | A deliberate attack on detection or positioning | Unknown — no threat model exists to bound it | None. This risk exists because a piece of analysis is missing. | this library |
| R9 | Fleet readiness has a role and no requirements | Airworthiness state unmanaged as the fleet grows | None specified. Created by a gap. | this library |
| R10 | Reference registries the programme depends on are unspecified | Capabilities gated on data nobody owns | Named as high-value work; unspecified in the corpus. | this library |
| R11 | New operational roles have no qualification or currency standard | Four created roles filled by people with no defined standard | None. Created by a gap. | this library |
The two with no engineering answer
R6 and R7 are listed last because nothing technical addresses them. An airspace incident cannot be engineered away beyond reflexive yield and a zero-incident gate. A partner agency's withdrawal cannot be engineered away at all — the programme operates under someone else's statutory authority or it does not operate.
That is why the programme's shape is a risk response rather than a schedule. Earning trust with detection before asking for suppression authority is not a preference about sequencing; it is the only available mitigation for the two risks that would end the thing. The plan is that argument worked through.
Halt conditions
Seven halt conditions are specified — observations that stop or re-sequence the programme rather than trigger a review. Two properties matter more than the list:
- Each is tied to the goal it falsifies, so a halt is a statement that a specific promise has failed rather than a general loss of confidence.
- Two of them share a configuration-change evasion. A halt condition expressed against a measured quantity can be satisfied by changing what is measured, and the corpus notes this about its own conditions rather than waiting for someone to discover it. Naming a loophole in your own stop condition is unusual and is the reason to trust the rest of the list.
The gaps are published at the same weight as the risks. Suppression design is unwritten. There is no adversarial security analysis at all. Fleet-readiness requirements and training standards do not exist. Those are on the gaps page, worst first — and a gap named is a gap a reviewer can price.