Methods

Is your method covered — and to what depth?

Seven methods are operational today, each described below with its actual depth and its known limits. Seven more are specified in the architecture and not yet built — they sit in their own section, in the future tense, and never in a list with the operational set.

Operational — demonstrable on the live instance Specified — architecture only, no implementing code

Functional Hazard Assessment

FHA

Aircraft- and system-level failure conditions with project-configurable classification schemes and probability objectives, flight phases, effects, crew response and compensating provisions. Conditions link to their source functions; existing registers arrive through a spreadsheet import wizard with row-level validation.

KNOWN LIMITS

Functions are hand-entered or spreadsheet-imported today. SysML model import is in build — and ships only together with the completeness checks that catch never-assessed imported functions.

Fault Tree Analysis

FTA

Interactive tree editor over a computation engine with two independent cut-set solvers — MOCUS and a from-scratch ROBDD — auto-selected by tree size and required to agree. Unavailability models for fixed, exponential, repairable and dormant events with periodic-test intervals, five importance measures, beta-factor CCF. Exports a DOCX report with tree diagrams and an XLSX workbook carrying cut sets, importance rankings and the audit log as its own sheet.

KNOWN LIMITS

CCF is beta factor only — MGL and alpha-factor are rejected outright, not approximated. Long solves run as isolated, cancellable background jobs; the synchronous compute route still solves in-process.

Dependence Diagrams

DD

Reliability logic as dependence diagrams per failure condition — the notation many programmes file alongside or instead of fault trees — quantified and synchronised with the FHA so the failure condition and its diagram cannot drift apart.

KNOWN LIMITS

DD link changes update traceability rows directly without writing their own audit event yet — the underlying entity mutations are what carry the audit record.

Failure Mode & Effects Analysis

FMEA

Worksheet FMEA in the 23-column format working analysts actually use — failure modes with rates and sources, local and end effects, detection, compensating provisions — with each mode linkable to the fault-tree basic event it feeds.

KNOWN LIMITS

Links to basic events are explicit, per row. Nothing is inferred from name matching — a link exists because an engineer made it.

Systems-Theoretic Process Analysis

STPA

Losses, hazards and constraints per the STPA Handbook, an interactive control-structure editor, unsafe control actions across the four UCA types, and loss scenarios that derive design requirements — with hazards linked back to FHA failure conditions.

KNOWN LIMITS

The control structure is drawn in SPARC. Deriving it from SysML part and connection usages is explicitly excluded from the model-import scope.

Common Cause Analysis

CCA · CMA / ZSA / PRA

Common mode, zonal and particular-risk analysis per ARP4761A, recorded as structured checklist items in the standard's own taxonomy and linked to the failure conditions and analyses they qualify.

KNOWN LIMITS

CMA, ZSA and PRA are checklist-driven records of an engineer's inspection — no candidate is derived from the cut sets, and there is no geometric zonal model behind them.

Goal Structuring Notation

GSN

The safety argument as a first-class artefact: goals, strategies, context, assumptions, justifications and solutions on an editable canvas, with solution nodes citing analysis results directly. This is where the platform's one distinctive property becomes visible — the argument knows the state of its own evidence.

KNOWN LIMITS

Evidence freshness — CURRENT, STALE, MISSING — is recomputed on every read against the baseline each citation captured. There is no stored status column, so there is nothing to hand-set.

Roadmap

Seven more are specified but not built.

These have a place in the data model and the plan, and zero implementing code today. No dates — each joins the operational set above when it can be demonstrated on the live instance.

Preliminary Hazard Analysis PHA / PHL
Early-programme hazard list that will feed the FHA.
Roadmap
Hazard & Operability Study HAZOP
Guide-word deviation study over flows and states.
Roadmap
Bow-Tie / Barrier Analysis BOW-TIE
Barrier view joining causes, top event and consequences.
Roadmap
Event Tree Analysis ETA
Event sequences from an initiating event to outcomes.
Roadmap
Markov Analysis MARKOV
State-transition models for repairable and degraded systems.
Roadmap
Reliability Block Diagrams RBD
Success-path reliability view alongside the fault trees.
Roadmap
ALARP & Cost-Benefit ALARP
Risk tolerability and cost-benefit argumentation.
Roadmap

Around the seven operational methods sit assumption management, safety requirements with verification status, the compliance matrix, report generation and the traceability backbone — described on the evidence page.