Detection requirements library

The eight screens, and what each one refuses to do

An interface is where a requirement becomes true or quietly stops being true. These eight surfaces are specified in the corpus as layouts with a reads / enforces / deliberately-absent block each. The second column is the one worth your time.

The rest of this library describes behaviour in prose. Prose is where a safety argument goes to become unfalsifiable, so the screens are published here at the same weight as the rules that produced them.

Nothing on this page has been built. The corpus specifies these screens as ASCII layouts, and that ASCII is the specification — there is no software, no rendering, and no running system behind any of it. Every image region below is a generated gradient labelled synthetic on its own face. An unlabelled placeholder inside a document arguing for honesty would be the single dishonest thing in it.

Read the right-hand column. Interface documentation almost always describes capability, because capability is what a vendor is selling. A system’s safety posture lives in the opposite place — in what it will not let a tired person do at three in the morning in the eleventh hour of a shift. Those refusals only hold if they are in the interface rather than in a policy binder, and that is what the deliberately absent column records.

Where these screens sit relative to the corpus

These eight screens were authored as design and adopted into the specification, not extracted from a pre-existing one. Each exists in the corpus as a layout with a reads / enforces / deliberately-absent block, and each enforcement below cites the rule or standard it serves. That direction of travel matters when you are judging how much independent authority the screens carry: they are a design decision the corpus now holds, not a separate confirmation of it. Two of the absences on screen 5 were added after a role journey exposed a case the original layout would have mishandled — a target well inside the envelope on ground the agency may not attack — and that provenance is recorded in the corpus rather than smoothed into the original design.

About the numbers on this page

The library withholds tuned numeric thresholds, named counterparties and jurisdictions as a publication decision, and says so where a number has been removed rather than letting the page read as though no number exists. That policy applies here.

Every field rendered as [bracketed] is a real value in the corpus, withheld: coordinates and sensor accuracy, the registered-burn search radius, suppressant volume, drop and turn timings, the sustained sortie rate, the sortie cap, the triage span-of-control cap, ground-position distances, and the fire-size figure. Clock times, elapsed times, the queue’s confidence values and the two position ages are arbitrary scenario values chosen for these renderings — they are not specified thresholds and should not be read as any. Where a number is shown at all, it is shown because its presence is the thing being specified: a position age is on screen because staleness must be visible, not because 40 seconds is a standard.

1 One decision every two minutes, with no scrolling

Detection triage

The analyst dispositions roughly thirty claims an hour. Any layout that requires navigation collapses at that rate, so everything needed to decide sits on one surface.

Triage queue7 pending ordered by riskAnalyst: J. Ruiz
0.81 15:07
0.62 15:05
0.44 15:02
0.41 14:58
0.38 14:56
span 7/[cap]
median 34s
CLAIM 4471 observed 15:07:12 · 3m 41s ago
IR 15:07:12
SYNTHETIC
EO 15:07:12
SYNTHETIC
Confirming pass · aspect Δ 68°
SYNTHETIC
Terrain — ridge, S-facing, 14%
[coordinate] ±[accuracy] laser · model [ver]
REGISTERED BURN: none within [radius]
PRIOR REJECTIONS HERE: none
JURISDICTION: District 7 (invented)
ConfirmNeed more Reject — source class required
Specification rendering. Imagery is generated, not captured. Bracketed fields are numbers withheld under the library’s publication policy; clock times, elapsed times and the queue’s confidence values are arbitrary scenario values, not specified thresholds.
What it enforces
  • Observation time leads; elapsed time sits beside it. Never receipt time — the fire started when it started, not when the packet arrived.
  • Both sensors, both passes, terrain, registry status and rejection history visible without scrolling.
  • The aspect delta of the confirming pass is shown, so source independence is visible rather than asserted.
  • Confidence and model version always travel with the claim.
  • Span of control — 7 of 30 — is permanently on screen.
Deliberately absent
  • No auto-confirm at high confidence. A threshold that bypasses the human is the first step back toward unfiltered output.
  • No dispatch control. Triage establishes that a fire exists; deciding what to do about it belongs to a different role with different authority.
  • No free-text-only rejection. The controlled vocabulary is the only reason the false-positive loop works at all.

Traces to Enforcements 1 and 4, and the refusal of auto-confirm, all serve RULE-004 — a detection claim carries its confidence and provenance: confidence is a property of a claim, never a licence to skip the human. The absent dispatch control serves the rule that the agency of jurisdiction owns the order. The controlled-vocabulary requirement serves the false-positive control decision.

2 The system learns from its own noise, within a bounded scope

Recurring-rejection promotion

The same metal roof glints at the same hour every clear afternoon. After the seventh rejection an analyst can teach the system — but only about that spot, that window, and below that confidence.

What it enforces
  • Promotion is one action from the queue. If teaching the system is slower than rejecting again, nobody teaches it.
  • Suppression is bounded on three axes: location, time window, confidence ceiling.
  • The comparison panel exists so the analyst can see when this one is different. Seven rejections plus a markedly larger signature is the case where the eighth is real.
Deliberately absent
  • No district-wide promotion. A source class promoted broadly would suppress real fires everywhere the pattern loosely matched.
  • No permanent entry. Registry entries expire with the season, because roofs are replaced and quarries close.
  • No unconditional suppression. An anomalous reading at a known source still alerts — a mill can burn down.

Traces to The bounded scope and the season expiry serve the false-positive control decision. The refusal to suppress unconditionally serves RULE-004 and the rule that a registered burn is not a detection — both turn on a claim retaining its own uncertainty.

3 What you are not watching is the decision you are actually making

District picture

Uncovered ground is drawn with equal or greater visual weight than covered ground, and labelled rather than left blank. Absence of information is information.

What it enforces
  • Uncovered ground is labelled not watched, never merely left unshaded.
  • Sensor shadow is a third distinct state. Ground under a smoke column is not being watched even though an aircraft is flying over it.
  • Coverage is stated risk-weighted, not by area. Sixty-one per cent of area and sixty-one per cent of risk are different numbers, and only one of them matters.
  • Degraded link state sits on the main screen, permanently.
Deliberately absent
  • No manual flight controls.
  • No “system healthy” indicator. A green light invites a trust that specific state has not earned.

Traces to The three coverage states serve the standard that declared coverage is measured rather than modelled. The absent health indicator serves the same standard: an aggregate green light is a modelled claim about measured state.

4 The hole you are about to create, shown before you commit

Divert

Moving an aircraft to look at something means somewhere else stops being watched. That cost is rendered at the moment of decision rather than discovered in review.

What it enforces
  • Time to first imagery shown before commitment.
  • The coverage hole is rendered at the moment of decision.
  • Rejected aircraft are shown with their reason — including the one that is nearer but slower. This is what makes ranking by time legible instead of mysterious.
Deliberately absent
  • No silent queueing. If nothing can reach it, the screen says so and offers the soonest alternative rather than quietly accepting the request.

Traces to Showing the coverage cost before commitment serves the standard on declared coverage; refusing to queue silently serves the rule that the agency of jurisdiction owns the order, since an unanswerable request is a decision that was never available.

5 Three gates, shown separately, with their evidence

Suppression authorisation

If you read one screen on this page, read this one. A named human authorises every release, the authorisation expires, and no gate can be overridden by anyone.

Authorise suppressionFIRE 4471 [size]INSIDE envelope
Two suppression aircraft · water source [dist] · [volume]
first drop [t] · turn [t] · sustained rate [withheld]
GATE 1AIRSPACE — no restriction · no air supervisor airborne · no transponder contact
GATE 2GROUND SAFETY — engine [dist] NE, reported 40s ago; crew [dist] S, reported 1m 10s ago
GATE 3AUTHORITY — awaiting you
SINGLE RELEASE — this target, expires [time]
CONTINUOUS ATTACK — this target · max [n] sorties · expires [time]
R. Vasquez · District 7 · Duty Officer (both invented) Authorise release
Specification rendering. “District 7” and “R. Vasquez” are invented and correspond to no real unit or person. Bracketed fields are withheld; the two position ages are arbitrary, and are shown because their presence is the thing being specified.
What it enforces
  • Three gates shown separately with their evidence, never collapsed into one status light.
  • Ground positions carry their age — “reported 40 seconds ago”, not “clear”. A stale position is not a safe one, and rendering it as a tick would hide exactly the thing that kills people.
  • Continuous attack must state target, sortie cap and expiry. Authority does not persist by default.
  • The authorising human’s name and role are on the button, not buried in a session.
Deliberately absent
  • No control at all when the target is outside the envelope — absent, not greyed out.
  • No control at all when the governing agreement does not permit suppression on that ground. The screen instead states what is permitted and names the instrument that withheld the rest.
  • No override for a failed gate. A failed gate produces a named reason and a next action, never a bypass.
  • No “authorise all pending.”

Traces to Gate 1 serves the crewed-aircraft right-of-way rule. Gate 2 serves the rule forbidding a drop over unverified ground personnel — which is why position age is rendered rather than a tick. Gate 3, the expiry, and the absence of any override serve the rule that no suppression release occurs without human authorisation. The two absences that remove the control entirely serve the initial-attack envelope standard and the rule that the agency of jurisdiction owns the order.

6 Built for someone standing up, in direct sun, wearing gloves

Crew view

Oriented to the user’s heading rather than north-up, because a person walking a line does not re-project a map in their head.

What it enforces
  • The staleness banner is unmissable, not a subtle timestamp. Fires grow while a picture ages.
  • Works with no link. Last picture retained, position still recording.
  • The value control is as prominent as the safety control. The device is carried for “request a look”, and the safety veto only works if the device is carried at all.
Deliberately absent
  • No drop authorisation on this device. Ever.
  • No crew tasking. The system shows the fire; the incident commander directs people.
  • No settings, no configuration, no menus.

Traces to The staleness banner serves the imagery-delivery requirement; working without a link serves the rule that lost link is a planned state. The permanent absence of drop authorisation on this device serves the rule that no release occurs without human authorisation at an authorised surface.

7 The veto that outranks everyone, held by the person closest to the ground

No-drop hold

Any crew member can stop a release over their own position instantly. No approver sits in the path.

⛔ NO-DROP HOLD ACTIVE
set by you · 16:20 · 4 min ago
◉ youHOLD RADIUS

Aircraft will not release inside this area until you clear it.

No approval was required.

CLEAR HOLD
Specification rendering.
What it enforces
  • The hold takes effect immediately, with nobody in the approval path.
  • The screen states plainly that no approval was required. The crew must know the veto is theirs, or they will not reach for it when it matters.
  • Only the person who set it can clear it.
Deliberately absent
  • No override path visible to anyone, including the duty officer. A duty officer’s authorisation loses to this hold, and there is no screen anywhere in the system that resolves it the other way.
  • No timeout. Holds do not expire on their own.

Traces to The whole screen serves the rule forbidding a drop over unverified ground personnel, and the corpus’s decision-rights table is what makes the veto unappealable — the absence of an override path is the interface honouring a decision right, not a UI choice.

8 It finds you; you do not go looking for it

Duty officer notification

Push, never pull — and small enough to survive the thinnest link the programme is authorised to use.

What it enforces
  • Arrives without any surface being open.
  • Both supporting sources are named on the notification — the two-source rule is visible, not implied somewhere behind it.
  • Unacknowledged notifications escalate to a declared alternate. Delivered is not received; received is not read.
  • The thumbnail is sized so the whole notification survives the thinnest link state.
Deliberately absent
  • No suppression authorisation from this screen. “Suppress” opens the full three-gate panel elsewhere — a release cannot be authorised from a lock-screen notification.
  • No dismiss-without-acknowledge.

Traces to Naming both sources serves the two-source confirmation rule. Observation time and elapsed time serve RULE-004. Refusing authorisation from the notification serves the rule that no release occurs without human authorisation, which the corpus binds to a surface that can show all three gates.

Why the absences are the interesting half

Taken together the right-hand columns describe a system that has been designed to be less capable than it could be, on purpose, in specific places. It will not confirm a fire for you even when it is confident. It will not let you authorise a release from a notification. It will not show you an authorise button when the ground is not yours to attack — not greyed out, absent, so that no attention is spent on a decision that was never available. It gives the person standing closest to the fire a veto that the person with the most authority cannot override, and then tells that person, on the screen, that nobody approved it.

Those are the properties I would want a regulator to test, and they are testable: each one is a thing you can look for and fail to find. That is a different kind of claim from “the system is safe”, and it is the only kind I can make about something that has not flown.

What this page is not evidence of

None of these screens has been implemented, so none of these refusals has ever actually refused anything. Under this library’s own standard — recorded on the gaps page as gap four — a check that has not been observed refusing a disqualified input does not count as present. Every absence on this page is a specified absence. It is a design commitment and a testable one, and it is not a result.

If a screen here would fail you in the field, that is the most useful thing anyone could send back. The people who would know are duty officers, engine bosses and air tactical supervisors, and none of them has seen these. The contact page reaches the author directly, and no request form stands in front of it.