Skip to main content

Decision support

Two reasoning engines on one picture, joined by rules, with the operator holding the authority.

DomeCommand reasons about a fight in two different ways at once, and keeps them separate on purpose.

ONE PICTUREDETERMINISTICSolverOptimises over assets and threats.Weighs leakage, cost and coverage.Same inputs, same plan, every time.You can prove it.LANGUAGE MODELCognitionClassifies and assesses intent.Narrates what changed and why.Drafts scenarios and rules.You can question it.RULES · THE LINEWhat may be proposed, and what may actually run.Operator decides
A solver and a language model work on the same fused picture. Rules and the autonomy line decide what may be proposed and what runs on its own. The operator decides the rest.

Two brains​

The solver is deterministic. It optimises over your assets and the threats, weighing predicted leakage, cost and coverage. Given the same picture and the same weights it produces the same plan every time, and every number in that plan can be traced. You can prove it.

Cognition is a language model. It classifies, assesses intent, narrates what changed and why, and drafts scenarios and rules on request. It handles the things arithmetic cannot: what this pattern of movement probably means, and how to say it to a commander in a sentence. You can question it.

Neither replaces the other, and neither is allowed to act.

SolverCognition
Good atAssignment, cost exchange, coverage, doing it in parallelMeaning, intent, explanation, authoring
RepeatableYes, exactlyNo
Can be auditedEvery term in the objectiveThe words, against the facts beside them
May commit an actionNoNo

Autonomous decision support​

The two are joined by rules, and bounded by the autonomy line. That joint is what makes the system autonomous without being unaccountable:

  • Rules decide what may even be proposed. They read facts about a track and can designate, deny, prioritise or emit.
  • The autonomy line decides what runs on its own. Every action sits at one level on a fixed ladder, and what the line releases, the engine releases.
  • The operator decides the rest, and holds the authority for anything consequential.

A proposal from either brain travels the same path and meets the same gate. Nothing is released because the solver ranked it first, and nothing is released because the model sounded confident.

One ladder, two numbers​

Every action the system can take sits at one level on a ladder that never changes. The level belongs to the action, not to the situation: intercept is a 5 on a quiet afternoon and a 5 under a raid.

levelwhat it meansactions
0 OBSERVEnothing in the world changesalert, cue a sensor, assign a search sector
1 MANOEUVREour own aircraft move, and touch nobody elsearm, take off, land, hold, move to, follow a route, return to base
2 WATCHan asset holds a placesurveil
3 SHADOWan asset follows a contact, and the contact may noticefollow, warn, designate suspect, roster enrolment
4 DENYstops the target flying its missionjam, spoof
5 DESTROYirreversibleintercept, designate hostile, payload release near people

Two numbers sit on that ladder, and they are the whole permission model.

The ceiling is what exists at this deployment at all. A civil envelope stops at SHADOW. A military envelope is the whole ladder. The envelope is part of the deployment's configuration and not an operator setting: an action above the ceiling has no card, no button and no draft. It is not refused, it is absent.

The line is what the machine does without asking. Everything at or below the line runs. Everything above it waits for a person. The line is moved from one control, AUTONOMY in the top bar, per shift, and moving it is logged like any other act. MANUAL is the line at the bottom, not a separate mode: at MANUAL the only thing that still runs on its own is observation, because reading a sensor changes nothing in the world.

The line can never sit above the ceiling. The slider draws the ceiling as its hard stop, and the bar reads the setting back one way: MANUAL, or AUTO to WATCH, or AUTO to SHADOW, stop within 5 s.

The levels page, every action against its level
The levels page, every action against its level
Every action with its level and what the level means. The line moves from AUTONOMY in the top bar, and the ceiling is the deployment's envelope: at DESTROY the rungs above it do not exist here.

The gate answers three ways​

One function, in the engine, at the one place commands pass through, answers one question about every action. Three answers and no others:

  • RUNS. It happens now, and the act is logged. With a stop window set the action runs, the console announces it, and the operator has that many seconds to take it back.
  • ASKS. It happens when a person says so.
  • NOT PERMITTED. It is above the ceiling and does not exist here.

The same answer is stamped on the capability list each asset advertises, so the button the console shows and the gate the engine enforces are one computation rather than two opinions. A refusal names its rung: DESTROY is above the line, or DESTROY is above this deployment's ceiling. The two read similarly and mean different remedies: one is a hand on the slider, the other is a conversation with whoever set the envelope.

What asking looks like​

What waits for a person collects in one DECISIONS queue. A card names the act, says what happens if nobody answers, and carries the case for it.

A machine designation is not one of the questions. When the evidence reaches hostile, the call is made and recorded, and it arrives in the queue as an advisory carrying OVERRIDE, ACKNOWLEDGE and CERTIFY. The queue carries the overrides, not a re-request for a decision the doctrine already made.

Designation only climbs​

A machine designation moves one way: unknown to suspect to hostile. It comes down for two reasons only: an operator says so, or the track is positively identified as a friend. Kinematics alone never reaches hostile, and kinematics alone cannot walk it back either. The ceiling that enforces this is doctrine in the engine rather than a threshold somebody can raise under pressure. Sensor fusion carries the evidence rules.

Rules hold the line, and never move it​

A rule narrows. Forbid intercept and jam inside a keep-out zone, and that holds against every plan the solver authors and every release the line would allow. No rule widens: a rule cannot raise the line, release an act above it, or authorise anything the ceiling excludes. The line is moved by a person, at the AUTONOMY control, and the move is logged.

Exactly one shipped rule is locked, not editable and not deletable: an asset under attack may defend itself.

Where to go next​