What's the job?
Today's conditions
Tap what matches. The job card has already picked the likely ones.
How fresh is our data?
Traffic in the window
Sign-off
The decision is yours, under your name. The tool only gave you the evidence.
Hold on — a reason is required
Works permit intake
New assessment — works on or adjacent to the runway
Load a works package preset or fill the MOWP form. Every field either feeds the risk ledger or is echoed in the assessment record.
Evidence pack
Assessment results
AIrport 360 is decision support. It produces supplementary evidence behind the operator's accepted risk assessment methodology — the assessor remains responsible for the decision.
Conditions & mitigations — what-if (scenario copy)
Toggles run a working copy of the submitted permit and show both results side by side. The submitted permit is never altered by a toggle — use “Apply to permit form” to adopt a variation explicitly.
Assessor sign-off
The decision below is the named assessor's own entry. The tool's role ends at evidence.
Gate rule (stated here because it blocks generation): a named, typed rationale is mandatory whenever (i) the computed cell is lower-risk than the hazard-register entry, or (ii) the assessor’s decision is more permissive than the evidence summary (accept / accept-with-conditions against a top-band likelihood or a beyond-validated-range cap regime). No record can be generated with an empty rationale in those cases. Model-driven upgrades pass automatically; downgrades and overrides never silently.
Sign-off gate — named rationale required
Plain-English glossary
- Distribution
- The spread of results across all simulated repetitions of tonight, not a single number.
- Percentile (e.g. 90th)
- The value that 90% of simulated repetitions stay below.
- 90% interval
- The range holding the middle 90% of simulated outcomes — a statement of uncertainty, not a forecast.
- Exceedance
- The chance of at least one event at or above a given severity class.
- Central chain
- The hand-recomputable headline: posterior-mean rate × the median of each active factor.
- MC median
- The middle value of the full Monte Carlo sample — sits below the central chain because rare-event rates are right-skewed.
- RR-propagated 90% interval
- The uncertainty coming from the risk factors (RR = risk ratio, the “×4 wet runway” style multipliers) only, drawn around the central chain — the base rate is held fixed.
- Posterior mean
- The class base rate after your own history has been folded in — the “best single number” for the rate.
- Conjugate update
- The exact arithmetic (no simulation) that folds your history into the base rate: add events to one number, add exposure to the other.
- Estimand
- The precise quantity a number claims to be. Every figure here is labelled with its estimand so a mean is never passed off as a median.
- σ base → eff
- The factor’s uncertainty width from its evidence, and the widened width actually sampled when the driving observations are stale or missing.
- Log-asymmetric (flagged)
- A declared interval that isn’t symmetric around its middle in ratio terms — reported to the methodology owner rather than silently reshaped.
- “≥” on a figure
- A floor, not an estimate: the stacking cap has clipped the upper tail, so the true value can only be higher.
Methodology
How AIrport 360 works
What it is. AIrport 360 is a forms-fed state model: the state of the aerodrome changes when a form is submitted — a works permit, a daily inspection, a METAR — never by magic. From that state it produces supplementary evidence behind your accepted matrix: probability and severity distributions with every assumption on display. It is decision support; the assessor remains responsible for every decision, forever.
The frequency model. Each event chain — runway excursion on landing, and vehicle/pedestrian deviation (the works-driven incursion mode) — starts from a class base rate encoded as a Gamma prior over the event rate. Your own history updates it by exact conjugate arithmetic (Poisson–Gamma). With zero local excursions in 60,000 landings the posterior barely moves: you are your class, and the tool says so — with the credibility weights printed in the ledger. Local learning is precursor-based: the model learns your risk-factor profile (surface state, friction currency, works discipline) — never "your accident rate".
Conditioning. Tonight's state activates multiplicative risk factors, each a lognormal random variable specified by a median and 90% interval, with its source and evidence class (P published / E elicited) printed in the risk ledger. Correlated covariates enter as one coherent set (no wet × low-visibility double-count); the total stacked factor is capped at ×30 with the cap status displayed, never hidden. The headline is the central chain — posterior-mean rate × median factors — recomputable on a calculator from the printed ledger. Uncertainty bands come from a seeded Monte Carlo (documented PRNG, seed and iteration count on every output).
The cap regime (validated range). The ×30 stacking cap is a guard-rail, not physics. When the cap binds materially — the median stack exceeds ×30, or more than 20% of iterations are capped — the combination of factors sits beyond the model’s validated range and the tool stops quoting precise probabilities: affected figures are printed as floors (“≥”), the answer line says so in plain words, and the results list which mitigations would bring the stack back within range. A capped figure is a floor because the true uncapped value can only be higher. This threshold (20%) is fixed and documented here; stale-data widening that is clipped by the cap is flagged next to the interval rather than silently absorbed.
Data coverage. Stale or missing observations widen the sampled intervals mechanically: observation weight decays with a published half-life, and unobserved variables fall back to the class prior at full width — never to a silent "serviceable". The coverage panel shows observed / aged / imputed per variable, with the widening effect stated in plain English.
Severity and the matrix. Severity is a distribution over ICAO Doc 9859 classes A–E, conditioned on your actual RESA and obstacle geometry via a location-curve model; it is never multiplied into frequency to make a single score. The 5×5 view is a projection of the distribution onto the operator's accepted matrix under a fixed, versioned rule (likelihood cell = band of the 90th percentile), with band edges configurable to the operator's SMS manual and cell occupancy always shown, so the matrix can never disagree with the distribution behind it.
Governance. Model-driven cell upgrades may be automatic; any downgrade against the hazard register — and any assessor decision more permissive than the evidence summary — requires a named sign-off with a typed rationale before a record can exist (to see the downgrade gate fire, run the grass mowing preset). The tool never issues a verdict or approval: the results page opens with an evidence summary, written in evidence-voice and labelled as such, for the named assessor to adopt or strike; completion is "assessment record generated", nothing more.
References
- mvp/data/data-notes.md — per-number sources and confidence for every coefficient in the demo dataset (the audit table).
- ACRP Report 50 — fitted excursion frequency/location models; the Phase-1 coefficient source (illustrative magnitudes until transcription).
- FAA RWS / ATADS — incursion counts over movement denominators anchoring the V/PD class prior (parameters illustrative).
- ICAO Doc 9859 (4th ed.) — severity classes A–E; matrix scales are the operator's own.
- UK CAP 760 — precedent for numeric likelihood-band quantification.
- Vose, Risk Analysis: A Quantitative Guide (3rd ed.) — Poisson-Gamma conjugate pattern and lognormal factor parameterisation.
No regulatory authority has assessed or accepted this tool or its outputs.
Band definitions, decay constants and mapping rules are demo defaults, configurable to the operator's
SMS manual at onboarding. Verification: the engine ships with a self-test suite (engineer checklist
T1–T5 + M-checks, 19 tests) — run the self-tests in this browser or
node js/selftest.js.
Verification
Engine self-tests (engineer checklist T1–T5 + M-checks)
Running 19 checks at 20,000 iterations — typically 5–20 seconds on this machine. If nothing appears after that, an error has occurred and will be printed here.