{
  "context": {
    "schemaVersion": "hyperion-buyer-decision-asset.v1",
    "assetId": "physical-ai-lifecycle-economics-stress-test",
    "title": "AMR lifecycle economics: a reproducible fictional stress test",
    "buyer": "Operations sponsor, product leader and finance partner considering fleet expansion",
    "decision": "Which service, recovery, supply and sensing assumptions could invalidate the fleet's repeatability and value thesis?",
    "gate": "scale",
    "mandateId": "product-leadership-program",
    "lenses": [
      {
        "lensId": "customer-operator-value",
        "question": "How much useful pallet movement remains after degradation, and what human work is still unmeasured?"
      },
      {
        "lensId": "business-model-economics",
        "question": "How do upfront investment, annual operating cost, lifecycle TCO, net value and payback change under the declared stress?"
      },
      {
        "lensId": "ai-data-evaluation-hmi",
        "question": "Which sensing, recovery-policy and operator-intervention assumptions need application-specific evidence?"
      },
      {
        "lensId": "system-architecture",
        "question": "Which fleet configuration and operating envelope make a comparison meaningful?"
      },
      {
        "lensId": "safety-governance-oversight",
        "question": "Which stop and specialist acceptance decisions remain outside this economic illustration?"
      },
      {
        "lensId": "operations-ecosystem",
        "question": "Can commissioning, spares, recovery staffing and support capacity repeat across sites?"
      }
    ],
    "preparedAt": "2026-09-06T00:00:00Z",
    "publicationStatus": "not_published",
    "humanReviewStatus": "not_recorded",
    "customerEvidence": false,
    "canonicalPath": "/resources/physical-ai-lifecycle-economics-stress-test"
  },
  "evidence": {
    "inputClaimClass": "fictional_example",
    "outputClaimClass": "modelled_result",
    "knowledgeState": "assumed"
  },
  "baselineDefinition": "A clone of the AMR preset with all failure switches disabled, stage set to Scale, and descriptive scenario identity changed. This is an unperturbed hypothetical comparator, not observed operations or the original preset's enabled-failure mix.",
  "interpretation": [
    "Severity is a scenario input to versioned consequence formulas, not an empirical probability or measured effect size.",
    "Only the declared failure settings (enabled state and selected severity) differ between comparable runs, apart from descriptive scenario identity. Inputs, results and hashes are included for independent recalculation.",
    "Productive value is an assumed customer benefit; contract revenue is shown separately and is not added to that benefit. Lifecycle net value is not supplier profit, NPV or a forecast.",
    "The existing engine does not discount cash flows or model tax, financing, utilization distributions or correlated real-world failure probabilities.",
    "The illustrative exposure counts in Product System context are held constant; the failure engine does not predict accepted pallet transfers or operator staffing. Do not read the cost-per-declared-success diagnostic as stress-adjusted throughput economics.",
    "A delayed supplier may leave modeled release weeks unchanged when the declared roadmap already contains slack. Read the changed lead-time field rather than claiming every stress must move every output.",
    "Before investment, replace assumptions with scoped site evidence, capture omitted costs and compare alternatives. A favorable modeled signal still recommends experiment_only."
  ],
  "runs": [
    {
      "id": "baseline",
      "label": "Fictional baseline: all failure switches off",
      "scenario": {
        "schemaVersion": "1.0.0",
        "scenarioId": "fictional-amr-baseline",
        "name": "Fictional baseline: all failure switches off",
        "fictional": true,
        "customerProblem": "A distribution operator needs to reduce repetitive pallet movement without making throughput brittle.",
        "buyer": "VP Operations and site general manager",
        "productPromise": "Move priority loads safely within a bounded warehouse envelope while preserving accountable human release authority.",
        "economics": {
          "fleetUnits": 24,
          "deploymentsPerYear": 4,
          "contractYears": 4,
          "revenuePerUnitYear": 18000,
          "productiveValuePerHour": 34,
          "productiveHoursPerUnitYear": 4800,
          "hardwareCostPerUnit": 42000,
          "integrationCostPerUnit": 11000,
          "platformCostPerYear": 95000,
          "dataOpsCostPerYear": 48000,
          "inferenceCostPerUnitMonth": 65,
          "serviceHoursPerUnitYear": 72,
          "serviceLaborRatePerHour": 105,
          "energyCostPerUnitYear": 1600,
          "engineerDayRate": 1250
        },
        "operations": {
          "mtbfHours": 720,
          "mttrHours": 5,
          "commissioningDaysPerUnit": 1.6,
          "supplierLeadTimeWeeks": 14,
          "sparesPercent": 8,
          "replacementPercentPerYear": 4,
          "targetAvailabilityPercent": 97
        },
        "delivery": {
          "availableTeamHoursPerMonth": 520,
          "plannedTeamHoursPerMonth": 330,
          "teamCount": 2,
          "coordinationTeams": 3,
          "roadmapWeeks": 28,
          "deliveryCadenceWeeks": 2
        },
        "investment": {
          "totalBudget": 2400000,
          "productDiscoveryPercent": 12,
          "hardwarePercent": 30,
          "softwarePercent": 20,
          "dataAiPercent": 12,
          "safetyCompliancePercent": 12,
          "fieldOperationsPercent": 14
        },
        "methodContext": {
          "uncertainty": 4,
          "hardwareSoftwareCoupling": 4,
          "safetyCriticality": 4,
          "regulatoryBurden": 3,
          "coordinationScale": 3,
          "fieldLearningNeed": 5
        },
        "operatingEnvelope": {
          "minTemperatureC": 5,
          "maxTemperatureC": 40,
          "maxPayloadKg": 1000,
          "minimumConnectivityPercent": 85,
          "operatorTrainingHours": 8,
          "evidenceCoveragePercent": 72
        },
        "risk": {
          "baseSafetyLikelihood": 2,
          "baseSafetyImpact": 4
        },
        "productization": {
          "stageId": "scale",
          "decisionDoor": "demo_to_operated_product",
          "lensIds": [
            "customer-operator-value",
            "business-model-economics",
            "ai-data-evaluation-hmi",
            "system-architecture",
            "safety-governance-oversight",
            "operations-ecosystem"
          ],
          "configuration": {
            "baselineId": "fictional-amr-fleet.configuration-v1",
            "status": "conditional",
            "changeSummary": "Fictional AMR chassis, sensors, task policy, map and warehouse workflow; rollback rehearsal is missing.",
            "rollbackStatus": "gap",
            "reopeningTriggers": [
              "Reopen after any policy, model, hardware, data, tooling or site configuration change.",
              "Reopen if sustained duty, intervention demand or recovery exceeds the declared assumptions."
            ]
          },
          "humanBaseline": {
            "status": "gap",
            "statement": "Measure manual pallet-movement throughput, errors, waiting and operator burden; no baseline has been observed."
          },
          "productClaim": {
            "status": "conditional",
            "statement": "Fictional hypothesis: move priority pallets across one mapped warehouse shift with accountable recovery."
          },
          "requirement": {
            "status": "conditional",
            "statement": "Define a successful pallet transfer, obstruction recovery and safe-stop acceptance before testing the fleet."
          },
          "architecture": {
            "modelSystems": [
              "task_specific_policy",
              "physics_simulator",
              "deterministic_controller"
            ],
            "worldModelRoles": [
              "scenario_generator"
            ],
            "policyStatus": "conditional",
            "worldModelStatus": "conditional",
            "dataLearningRightsStatus": "gap",
            "edgeCloudBoundaryStatus": "gap"
          },
          "reliabilityExposure": {
            "exposureUnit": "fictional pallet-transfer attempts per fleet-year",
            "attemptedOutcomesPerYear": 240000,
            "successfulOutcomesPerYear": 228000,
            "interventionsPerYear": 4800,
            "recoveryAttemptsPerYear": 3600,
            "successfulRecoveriesPerYear": 2880,
            "longestContinuousDutyHours": 8,
            "operatorMinutesPerDutyHour": 6,
            "toleratedSevereEventsPerYear": 0,
            "severityTolerancesStatus": "unknown",
            "fallbackStatus": "gap"
          },
          "authority": {
            "evaluatedAuthority": "bounded_actuation",
            "intendedAuthority": "bounded_actuation",
            "evaluatedSupervision": "continuous_operator",
            "intendedSupervision": "monitoring_only",
            "interventionAvailable": true,
            "deterministicStop": true,
            "recoveryOwner": "Illustrative warehouse shift supervisor"
          },
          "learning": {
            "memoryStatus": "conditional",
            "taskProgressStatus": "conditional",
            "deadEndDetectionStatus": "gap",
            "autonomousExperienceStatus": "unknown",
            "humanCorrectionsStatus": "conditional",
            "generalizationStatus": "gap",
            "fleetLearningStatus": "unknown"
          },
          "critic": {
            "present": true,
            "version": "fictional-amr-fleet-critic-v1",
            "independent": false,
            "sharedDependenciesDeclared": false,
            "calibrated": false,
            "deterministicChecks": true,
            "humanEscalation": true
          },
          "technologyCurve": {
            "technology": "Fictional warehouse task policy with deterministic motion limits",
            "plateauRisk": "unknown",
            "requiredProductBarStatus": "conditional",
            "expectedCeilingStatus": "unknown",
            "futureCostStatus": "unknown",
            "migrationPathStatus": "gap",
            "vendorExitStatus": "gap"
          },
          "lifecycleReadiness": {
            "manufacturing": "conditional",
            "supply": "conditional",
            "deployment": "conditional",
            "service": "gap",
            "regulatory": "unknown",
            "cybersecurity": "unknown",
            "commercialCommitment": "gap",
            "rollback": "gap",
            "retirement": "unknown"
          },
          "completeness": [
            {
              "dimension": "capability",
              "status": "conditional",
              "gap": "Fictional capability assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "reliability",
              "status": "gap",
              "gap": "Shift-length obstruction and recovery evidence is missing."
            },
            {
              "dimension": "authority",
              "status": "conditional",
              "gap": "Fictional authority assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evaluation",
              "status": "conditional",
              "gap": "Fictional evaluation assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "operations",
              "status": "conditional",
              "gap": "Fictional operations assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "service",
              "status": "gap",
              "gap": "Recovery staffing and spares response have not been tested."
            },
            {
              "dimension": "commercial",
              "status": "conditional",
              "gap": "Fictional commercial assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evidence",
              "status": "conditional",
              "gap": "Fictional evidence assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "scale",
              "status": "gap",
              "gap": "A second site's maps and workflows have not been evaluated."
            }
          ]
        },
        "failures": [
          {
            "type": "sensor_degradation",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "battery_limitation",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "supplier_delay",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "model_drift",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "commissioning_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "customer_change",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "policy_world_model_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "data_rights_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "intervention_unavailable",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "recovery_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "memory_state_loss",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "critic_common_mode",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "edge_cloud_disconnect",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "manufacturing_variance",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "service_overload",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "regulatory_change",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "claim_evidence_mismatch",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "rollback_failure",
            "enabled": false,
            "severityPercent": 50
          }
        ],
        "humanDecision": {
          "owner": "Illustrative accountable product owner",
          "role": "Product and operations sponsor",
          "decision": "Proceed to a bounded site pilot subject to the failed release conditions shown below.",
          "rationale": "The pilot is intended to close operational and integration evidence gaps before a fleet commitment.",
          "reviewDate": "2026-09-30"
        }
      },
      "result": {
        "engineVersion": "flight-engine-1.1.0",
        "scenarioId": "fictional-amr-baseline",
        "deterministic": true,
        "economics": {
          "upfrontInvestment": 1400640,
          "annualOperatingCost": 421880,
          "lifecycleTco": 3088160,
          "annualProductiveValue": 3889787.59,
          "annualContractRevenue": 432000,
          "lifecycleNetValue": 12470990.34,
          "paybackMonths": 4.8,
          "costPerProductiveHour": 6.75
        },
        "investment": {
          "totalBudget": 2400000,
          "allocatedTotal": 2400000,
          "allocations": {
            "productDiscovery": 288000,
            "hardware": 720000,
            "software": 480000,
            "dataAi": 288000,
            "safetyCompliance": 288000,
            "fieldOperations": 336000
          },
          "requiredUpfrontInvestment": 1400640,
          "fundingGap": 0,
          "fundingSurplus": 999360,
          "coveragePercent": 171.4
        },
        "operations": {
          "theoreticalAvailabilityPercent": 99.31,
          "effectiveAvailabilityPercent": 99.31,
          "targetAvailabilityPercent": 97,
          "productiveFleetHoursPerYear": 114405.5,
          "serviceHoursPerYear": 1728,
          "replacementUnitsPerYear": 0.96
        },
        "delivery": {
          "capacityUtilizationPercent": 35.5,
          "commissioningHoursPerMonth": 38.9,
          "queueDelayWeeks": 0,
          "forecastReleaseWeeks": 28,
          "supplierLeadTimeWeeks": 14
        },
        "risk": {
          "score": 39,
          "band": "elevated",
          "evidenceGapPercent": 28
        },
        "allocationTotalPercent": 100,
        "modeledExperimentSignal": "hold",
        "releaseRecommendation": "experiment_only",
        "productSystemDiagnostic": {
          "version": "product-system-diagnostic-1.0.0",
          "source": "visitor_supplied_fictional_assumptions",
          "gate": "scale",
          "decisionDoor": "demo_to_operated_product",
          "lensIds": [
            "customer-operator-value",
            "business-model-economics",
            "ai-data-evaluation-hmi",
            "system-architecture",
            "safety-governance-oversight",
            "operations-ecosystem"
          ],
          "reliabilityExposure": {
            "status": "declared_gap",
            "exposureUnit": "fictional pallet-transfer attempts per fleet-year",
            "successRatePercent": 95,
            "interventionRatePerThousandOutcomes": 20,
            "recoveryRatePercent": 80,
            "longestContinuousDutyHours": 8,
            "operatorMinutesPerDutyHour": 6,
            "costPerSuccessfulOutcome": 3.39
          },
          "completeness": [
            {
              "dimension": "capability",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional capability assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "reliability",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "Shift-length obstruction and recovery evidence is missing."
            },
            {
              "dimension": "authority",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional authority assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evaluation",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional evaluation assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "operations",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional operations assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "service",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "Recovery staffing and spares response have not been tested."
            },
            {
              "dimension": "commercial",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional commercial assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evidence",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional evidence assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "scale",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "A second site's maps and workflows have not been evaluated."
            }
          ],
          "evidenceGaps": [
            "Public visitor inputs are fictional assumptions, not release evidence; independent validation remains required.",
            "Evaluated and intended authority, supervision, intervention and stop controls are not aligned.",
            "Critic independence or shared-dependency disclosure is unresolved.",
            "reliability completeness is declared gap.",
            "service completeness is declared gap.",
            "scale completeness is declared gap."
          ],
          "requirementGaps": [
            "Define and evidence the human baseline for useful work, burden, quality and cost.",
            "Bound the product claim to one configuration, intended use and operating envelope.",
            "Translate the claim into verifiable product and system requirements.",
            "Resolve data provenance, IP and learning rights for the intended lifecycle.",
            "Specify memory, long-horizon task state and stale-state behaviour.",
            "Specify dead-end detection and accountable recovery escalation.",
            "Define generalization slices and the evidence required for each slice."
          ],
          "authorityMap": {
            "assessment": "declared_gap",
            "evaluatedAuthority": "bounded_actuation",
            "intendedAuthority": "bounded_actuation",
            "evaluatedSupervision": "continuous_operator",
            "intendedSupervision": "monitoring_only",
            "authorityGap": false,
            "supervisionGap": true,
            "interventionAvailable": true,
            "deterministicStop": true,
            "recoveryOwner": "Illustrative warehouse shift supervisor"
          },
          "critic": {
            "assessment": "declared_gap",
            "present": true,
            "independent": false,
            "sharedDependenciesDeclared": false,
            "calibrated": false,
            "deterministicChecks": true,
            "humanEscalation": true
          },
          "technologyCurve": {
            "assessment": "declared_gap",
            "technology": "Fictional warehouse task policy with deterministic motion limits",
            "plateauRisk": "unknown",
            "openDecisions": [
              "Required product bar is conditional.",
              "Expected ceiling is unknown.",
              "Future cost is unknown.",
              "Migration path is gap.",
              "Vendor exit is gap."
            ]
          },
          "capabilityComplexityDelta": {
            "capabilityAssessment": "requires_evidence",
            "complexityRisks": [
              "Edge/cloud boundary is gap.",
              "Data and learning rights are gap.",
              "The declared critic is not independent from the system it evaluates.",
              "manufacturing readiness is conditional.",
              "supply readiness is conditional.",
              "deployment readiness is conditional.",
              "service readiness is gap.",
              "regulatory readiness is unknown.",
              "cybersecurity readiness is unknown.",
              "commercialCommitment readiness is gap.",
              "rollback readiness is gap.",
              "retirement readiness is unknown."
            ],
            "netDecision": "hold"
          },
          "configurationImpact": [
            "Fictional AMR chassis, sensors, task policy, map and warehouse workflow; rollback rehearsal is missing.",
            "Validate the declared model-system set: task_specific_policy, physics_simulator, deterministic_controller.",
            "Revalidate world-model roles: scenario_generator.",
            "Rollback is not supported by evidence for the declared configuration."
          ],
          "reopeningConditions": [
            "Reopen after any policy, model, hardware, data, tooling or site configuration change.",
            "Reopen if sustained duty, intervention demand or recovery exceeds the declared assumptions.",
            "Reopen before any change to intended use, configuration, operating envelope, authority or commercial commitment.",
            "Reopen when evidence expires, is corrected or no longer matches the release configuration."
          ],
          "pdrScope": [
            "Resolve the demo to operated product decision at the scale gate.",
            "Public visitor inputs are fictional assumptions, not release evidence; independent validation remains required.",
            "Evaluated and intended authority, supervision, intervention and stop controls are not aligned.",
            "Critic independence or shared-dependency disclosure is unresolved.",
            "reliability completeness is declared gap.",
            "Define and evidence the human baseline for useful work, burden, quality and cost.",
            "Bound the product claim to one configuration, intended use and operating envelope.",
            "Translate the claim into verifiable product and system requirements.",
            "Required product bar is conditional.",
            "Expected ceiling is unknown."
          ],
          "releaseCase": {
            "recommendation": "experiment_only",
            "boundary": "An Integrated Product Release Case is the accountable product recommendation for one configuration, use, operating envelope and commitment. A release-ready result binds current evidence and product completeness to that configuration, envelope, claim set, intended Human–Machine Authority and operating supervision. It is not a safety case, certification, conformity assessment or legal opinion.",
            "rationale": "This public simulator evaluates fictional, visitor-supplied assumptions. It cannot establish release-grade evidence, specialist acceptance or authority-matched field performance."
          }
        },
        "constraints": [
          {
            "id": "availability",
            "label": "Fleet availability",
            "status": "pass",
            "observed": "99.3%",
            "threshold": "≥ 97%",
            "consequence": "A missed availability gate changes customer value, service load and the release case."
          },
          {
            "id": "capacity",
            "label": "Delivery and commissioning capacity",
            "status": "pass",
            "observed": "35.5%",
            "threshold": "≤ 80% preferred; >95% blocks",
            "consequence": "Overload creates queues across roadmap work, commissioning and field response."
          },
          {
            "id": "economics",
            "label": "Lifecycle customer-value case",
            "status": "pass",
            "observed": "€12,470,990 net; 4.8 months",
            "threshold": "Positive lifecycle net value inside contract term",
            "consequence": "A negative or late-return case requires scope, price, reliability or operating-model change."
          },
          {
            "id": "risk",
            "label": "Combined safety and evidence risk",
            "status": "warning",
            "observed": "39/100 · elevated",
            "threshold": "≤35 preferred; >55 blocks",
            "consequence": "Risk is a screening signal only; a named safety authority owns acceptance."
          },
          {
            "id": "evidence",
            "label": "Operating-envelope evidence",
            "status": "warning",
            "observed": "72%",
            "threshold": "≥80% preferred; <60% blocks",
            "consequence": "Unverified envelope claims cannot support a scaled release commitment."
          },
          {
            "id": "allocation",
            "label": "Investment allocation",
            "status": "pass",
            "observed": "100%",
            "threshold": "100%",
            "consequence": "Unallocated or double-counted investment obscures real trade-offs."
          },
          {
            "id": "budget-coverage",
            "label": "Upfront funding coverage",
            "status": "pass",
            "observed": "171.4% · €999,360 headroom",
            "threshold": "≥100% of modeled upfront investment; 90–99.9% conditional",
            "consequence": "An unfunded hardware, integration, spares or commissioning requirement invalidates the release plan."
          },
          {
            "id": "human-owner",
            "label": "Accountable human decision",
            "status": "pass",
            "observed": "Illustrative accountable product owner · Product and operations sponsor",
            "threshold": "Named owner, role and decision",
            "consequence": "No model or simulator can own a safety, release, investment or customer commitment."
          },
          {
            "id": "reliability-exposure",
            "label": "Reliability and exposure profile",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Declared denominator, sustained-duty, intervention, recovery, fallback and severity-tolerance basis",
            "consequence": "Architecture and release decisions cannot precede an explicit reliability and exposure profile."
          },
          {
            "id": "product-completeness",
            "label": "Product completeness",
            "status": "fail",
            "observed": "3 of 9 dimensions unresolved",
            "threshold": "All nine dimensions assessed; declarations still require evidence",
            "consequence": "Capability alone cannot waive reliability, authority, evaluation, operations, service, commercial, evidence or scale gaps."
          },
          {
            "id": "authority-match",
            "label": "Authority-matched operation",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Evaluated and intended authority/supervision aligned with intervention, recovery and stop controls",
            "consequence": "Evidence collected under lower authority or stronger supervision cannot silently justify intended operation."
          },
          {
            "id": "critic-independence",
            "label": "Agent–simulator–critic independence",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Versioned critic, disclosed dependencies, calibration, deterministic checks and human escalation",
            "consequence": "An evaluator with unresolved common-mode dependencies cannot establish product readiness."
          },
          {
            "id": "integrated-release-case",
            "label": "Integrated Product Release Case",
            "status": "warning",
            "observed": "experiment only",
            "threshold": "Release-grade, configuration-bound evidence and named specialist decisions",
            "consequence": "This public simulator can recommend a bounded next experiment, never release readiness."
          }
        ],
        "formulas": [
          {
            "id": "budget-coverage",
            "label": "Upfront funding coverage",
            "expression": "total investment budget ÷ modeled upfront investment",
            "units": "% funded"
          },
          {
            "id": "availability",
            "label": "Theoretical availability",
            "expression": "MTBF ÷ (MTBF + MTTR), then explicit failure penalties",
            "units": "% available time"
          },
          {
            "id": "upfront",
            "label": "Upfront investment",
            "expression": "units × (hardware + integration) + spares + commissioning days × day rate",
            "units": "EUR"
          },
          {
            "id": "annual-opex",
            "label": "Annual operating cost",
            "expression": "platform + data/AI ops + inference + energy + service labour + replacements",
            "units": "EUR/year"
          },
          {
            "id": "value",
            "label": "Annual productive value",
            "expression": "units × productive hours × effective availability × value/hour × injected modifiers",
            "units": "EUR/year"
          },
          {
            "id": "capacity",
            "label": "Capacity utilization",
            "expression": "(planned work + commissioning load) ÷ (team hours × teams)",
            "units": "% monthly capacity"
          },
          {
            "id": "risk",
            "label": "Risk screening score",
            "expression": "likelihood × impact + evidence gap + explicit failure increments",
            "units": "0–100 screening index"
          }
        ],
        "assumptions": [
          "All scenarios are fictional and illustrative; figures are visitor-controlled assumptions, not Hyperion client evidence.",
          "Currency is EUR and values are undiscounted; tax, financing and inflation are excluded from this thin slice.",
          "MTBF/MTTR availability is a planning approximation and does not establish functional-safety performance.",
          "Commissioning capacity assumes eight engineering hours per day and forty site-level setup hours per deployment.",
          "Failure injections are transparent multipliers, not probability forecasts or field observations.",
          "The investment budget is compared with modeled upfront hardware, integration, spares and commissioning cost; operating reserve and financing are excluded."
        ],
        "limitations": [
          "This result is not safety certification, legal advice, conformity assessment or an autonomous release decision.",
          "Queueing is a deterministic capacity approximation; it is not a discrete-event simulation of a specific operation.",
          "No real customer, personal, confidential, export-controlled or safety-critical operational data should be entered.",
          "A qualified human owner must validate evidence, operating envelope, compliance duties and consequential commitments."
        ],
        "failureEffects": [],
        "sensitivity": [
          {
            "variable": "Hardware cost (−20% / base / +20%)",
            "low": 12720974.34,
            "base": 12470990.34,
            "high": 12221006.34,
            "units": "EUR"
          },
          {
            "variable": "Productive value/hour (−20% / base / +20%)",
            "low": 9359160.28,
            "base": 12470990.34,
            "high": 15582820.41,
            "units": "EUR"
          },
          {
            "variable": "Availability (−5 pts / base / +5 pts)",
            "low": 11687630.34,
            "base": 12470990.34,
            "high": 12579040,
            "units": "EUR"
          }
        ],
        "methodFit": {
          "version": "method-fit-1.0.0",
          "recommendedOperatingModel": "Continuous discovery + systems engineering evidence spine + Kanban for constrained flow.",
          "governanceNote": "Method choice is contextual. Safety, compliance, investment, release and customer commitments remain owned human decisions regardless of agile method.",
          "scores": [
            {
              "id": "continuous-discovery",
              "name": "Continuous discovery",
              "score": 100,
              "fit": "strong",
              "rationale": "Keeps customer evidence, field learning and product assumptions connected to delivery decisions.",
              "condition": "Use evidence cadence and decision records; do not treat interviews as release authority."
            },
            {
              "id": "scrum",
              "name": "Scrum",
              "score": 71,
              "fit": "conditional",
              "rationale": "Supports bounded product increments where uncertainty can be reduced inside a stable team cadence.",
              "condition": "Keep hardware, safety and commissioning gates outside the fiction of a purely software Definition of Done."
            },
            {
              "id": "kanban",
              "name": "Kanban / flow",
              "score": 79,
              "fit": "strong",
              "rationale": "Makes integration, field defects, evidence work and service queues visible as constrained flow.",
              "condition": "Set explicit classes of service and WIP limits for safety, field and supplier work."
            },
            {
              "id": "systems-engineering",
              "name": "Systems engineering",
              "score": 100,
              "fit": "strong",
              "rationale": "Controls interfaces, operating-envelope evidence and verification across hardware, software, AI and operations.",
              "condition": "Use as a product evidence spine, not as a substitute for customer discovery or incremental learning."
            },
            {
              "id": "safe",
              "name": "SAFe",
              "score": 70,
              "fit": "conditional",
              "rationale": "May coordinate multiple teams and portfolio dependencies when scale is real and independently evidenced.",
              "condition": "Do not introduce enterprise-scale ceremony for a small team; Scrum, Kanban and systems interfaces are sufficient."
            }
          ]
        }
      },
      "provenance": {
        "schemaVersion": "provenance-1.1.0",
        "outputClassification": "deterministic",
        "inputClassification": "illustrative",
        "releaseRecommendation": "experiment_only",
        "productSystemDiagnosticVersion": "product-system-diagnostic-1.0.0",
        "configurationBaselineId": "fictional-amr-fleet.configuration-v1",
        "provider": "Hyperion deterministic engine",
        "exactModelIdentifier": null,
        "modelRole": "arithmetic-and-constraint-authority",
        "aiBoundary": {
          "provider": "Mistral AI",
          "exactModels": [
            "mistral-small-2603",
            "mistral-medium-3-5",
            "mistral-large-2512"
          ],
          "usedForThisOutput": false,
          "limitation": "Optional Mistral council commentary is separate model-derived material and cannot alter these deterministic calculations."
        },
        "promptTemplateVersion": "not-applicable-deterministic-output",
        "applicationVersion": "physical-ai-flight-simulator-1.1.0",
        "methodologyVersion": "method-fit-1.0.0",
        "engineVersion": "flight-engine-1.1.0",
        "evidence": [
          {
            "id": "scenario:fictional-amr-baseline",
            "classification": "illustrative",
            "label": "Visitor-controlled fictional scenario assumptions",
            "source": "In-browser Physical AI Product Flight Simulator form"
          },
          {
            "id": "engine:flight-engine-1.1.0",
            "classification": "deterministic",
            "label": "Deterministic economics, availability, capacity, risk and constraint result",
            "source": "Hyperion Physical AI Flight Engine"
          },
          {
            "id": "method:method-fit-1.0.0",
            "classification": "deterministic",
            "label": "Contextual method-fit result",
            "source": "Hyperion Method-Fit decision rules"
          }
        ],
        "assumptions": [
          "All scenarios are fictional and illustrative; figures are visitor-controlled assumptions, not Hyperion client evidence.",
          "Currency is EUR and values are undiscounted; tax, financing and inflation are excluded from this thin slice.",
          "MTBF/MTTR availability is a planning approximation and does not establish functional-safety performance.",
          "Commissioning capacity assumes eight engineering hours per day and forty site-level setup hours per deployment.",
          "Failure injections are transparent multipliers, not probability forecasts or field observations.",
          "The investment budget is compared with modeled upfront hardware, integration, spares and commissioning cost; operating reserve and financing are excluded."
        ],
        "limitations": [
          "This result is not safety certification, legal advice, conformity assessment or an autonomous release decision.",
          "Queueing is a deterministic capacity approximation; it is not a discrete-event simulation of a specific operation.",
          "No real customer, personal, confidential, export-controlled or safety-critical operational data should be entered.",
          "A qualified human owner must validate evidence, operating envelope, compliance duties and consequential commitments."
        ],
        "canonicalInputHash": "1abf5a4fb2ca063e41b85c9099060dcb5684b6b27183d2e93ffd12cd031e3a55",
        "deterministicResultHash": "df3de3c899ae987bff2565ce8b2752ef9bdb5b17cf9bf069715803f3e3f7f785",
        "createdAt": "2026-09-06T00:00:00Z",
        "responsibleHumanDecisionOwner": "Illustrative accountable product owner",
        "responsibleHumanDecisionRole": "Product and operations sponsor",
        "humanDecision": "Proceed to a bounded site pilot subject to the failed release conditions shown below.",
        "reviewDate": "2026-09-30",
        "reviewStatus": "illustrative_unapproved",
        "humanDecisionRecorded": false,
        "expiryStatus": "within_review_period"
      }
    },
    {
      "id": "service-overload",
      "label": "Service overload, severity 75%",
      "scenario": {
        "schemaVersion": "1.0.0",
        "scenarioId": "fictional-amr-service-overload",
        "name": "Service overload, severity 75%",
        "fictional": true,
        "customerProblem": "A distribution operator needs to reduce repetitive pallet movement without making throughput brittle.",
        "buyer": "VP Operations and site general manager",
        "productPromise": "Move priority loads safely within a bounded warehouse envelope while preserving accountable human release authority.",
        "economics": {
          "fleetUnits": 24,
          "deploymentsPerYear": 4,
          "contractYears": 4,
          "revenuePerUnitYear": 18000,
          "productiveValuePerHour": 34,
          "productiveHoursPerUnitYear": 4800,
          "hardwareCostPerUnit": 42000,
          "integrationCostPerUnit": 11000,
          "platformCostPerYear": 95000,
          "dataOpsCostPerYear": 48000,
          "inferenceCostPerUnitMonth": 65,
          "serviceHoursPerUnitYear": 72,
          "serviceLaborRatePerHour": 105,
          "energyCostPerUnitYear": 1600,
          "engineerDayRate": 1250
        },
        "operations": {
          "mtbfHours": 720,
          "mttrHours": 5,
          "commissioningDaysPerUnit": 1.6,
          "supplierLeadTimeWeeks": 14,
          "sparesPercent": 8,
          "replacementPercentPerYear": 4,
          "targetAvailabilityPercent": 97
        },
        "delivery": {
          "availableTeamHoursPerMonth": 520,
          "plannedTeamHoursPerMonth": 330,
          "teamCount": 2,
          "coordinationTeams": 3,
          "roadmapWeeks": 28,
          "deliveryCadenceWeeks": 2
        },
        "investment": {
          "totalBudget": 2400000,
          "productDiscoveryPercent": 12,
          "hardwarePercent": 30,
          "softwarePercent": 20,
          "dataAiPercent": 12,
          "safetyCompliancePercent": 12,
          "fieldOperationsPercent": 14
        },
        "methodContext": {
          "uncertainty": 4,
          "hardwareSoftwareCoupling": 4,
          "safetyCriticality": 4,
          "regulatoryBurden": 3,
          "coordinationScale": 3,
          "fieldLearningNeed": 5
        },
        "operatingEnvelope": {
          "minTemperatureC": 5,
          "maxTemperatureC": 40,
          "maxPayloadKg": 1000,
          "minimumConnectivityPercent": 85,
          "operatorTrainingHours": 8,
          "evidenceCoveragePercent": 72
        },
        "risk": {
          "baseSafetyLikelihood": 2,
          "baseSafetyImpact": 4
        },
        "productization": {
          "stageId": "scale",
          "decisionDoor": "demo_to_operated_product",
          "lensIds": [
            "customer-operator-value",
            "business-model-economics",
            "ai-data-evaluation-hmi",
            "system-architecture",
            "safety-governance-oversight",
            "operations-ecosystem"
          ],
          "configuration": {
            "baselineId": "fictional-amr-fleet.configuration-v1",
            "status": "conditional",
            "changeSummary": "Fictional AMR chassis, sensors, task policy, map and warehouse workflow; rollback rehearsal is missing.",
            "rollbackStatus": "gap",
            "reopeningTriggers": [
              "Reopen after any policy, model, hardware, data, tooling or site configuration change.",
              "Reopen if sustained duty, intervention demand or recovery exceeds the declared assumptions."
            ]
          },
          "humanBaseline": {
            "status": "gap",
            "statement": "Measure manual pallet-movement throughput, errors, waiting and operator burden; no baseline has been observed."
          },
          "productClaim": {
            "status": "conditional",
            "statement": "Fictional hypothesis: move priority pallets across one mapped warehouse shift with accountable recovery."
          },
          "requirement": {
            "status": "conditional",
            "statement": "Define a successful pallet transfer, obstruction recovery and safe-stop acceptance before testing the fleet."
          },
          "architecture": {
            "modelSystems": [
              "task_specific_policy",
              "physics_simulator",
              "deterministic_controller"
            ],
            "worldModelRoles": [
              "scenario_generator"
            ],
            "policyStatus": "conditional",
            "worldModelStatus": "conditional",
            "dataLearningRightsStatus": "gap",
            "edgeCloudBoundaryStatus": "gap"
          },
          "reliabilityExposure": {
            "exposureUnit": "fictional pallet-transfer attempts per fleet-year",
            "attemptedOutcomesPerYear": 240000,
            "successfulOutcomesPerYear": 228000,
            "interventionsPerYear": 4800,
            "recoveryAttemptsPerYear": 3600,
            "successfulRecoveriesPerYear": 2880,
            "longestContinuousDutyHours": 8,
            "operatorMinutesPerDutyHour": 6,
            "toleratedSevereEventsPerYear": 0,
            "severityTolerancesStatus": "unknown",
            "fallbackStatus": "gap"
          },
          "authority": {
            "evaluatedAuthority": "bounded_actuation",
            "intendedAuthority": "bounded_actuation",
            "evaluatedSupervision": "continuous_operator",
            "intendedSupervision": "monitoring_only",
            "interventionAvailable": true,
            "deterministicStop": true,
            "recoveryOwner": "Illustrative warehouse shift supervisor"
          },
          "learning": {
            "memoryStatus": "conditional",
            "taskProgressStatus": "conditional",
            "deadEndDetectionStatus": "gap",
            "autonomousExperienceStatus": "unknown",
            "humanCorrectionsStatus": "conditional",
            "generalizationStatus": "gap",
            "fleetLearningStatus": "unknown"
          },
          "critic": {
            "present": true,
            "version": "fictional-amr-fleet-critic-v1",
            "independent": false,
            "sharedDependenciesDeclared": false,
            "calibrated": false,
            "deterministicChecks": true,
            "humanEscalation": true
          },
          "technologyCurve": {
            "technology": "Fictional warehouse task policy with deterministic motion limits",
            "plateauRisk": "unknown",
            "requiredProductBarStatus": "conditional",
            "expectedCeilingStatus": "unknown",
            "futureCostStatus": "unknown",
            "migrationPathStatus": "gap",
            "vendorExitStatus": "gap"
          },
          "lifecycleReadiness": {
            "manufacturing": "conditional",
            "supply": "conditional",
            "deployment": "conditional",
            "service": "gap",
            "regulatory": "unknown",
            "cybersecurity": "unknown",
            "commercialCommitment": "gap",
            "rollback": "gap",
            "retirement": "unknown"
          },
          "completeness": [
            {
              "dimension": "capability",
              "status": "conditional",
              "gap": "Fictional capability assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "reliability",
              "status": "gap",
              "gap": "Shift-length obstruction and recovery evidence is missing."
            },
            {
              "dimension": "authority",
              "status": "conditional",
              "gap": "Fictional authority assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evaluation",
              "status": "conditional",
              "gap": "Fictional evaluation assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "operations",
              "status": "conditional",
              "gap": "Fictional operations assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "service",
              "status": "gap",
              "gap": "Recovery staffing and spares response have not been tested."
            },
            {
              "dimension": "commercial",
              "status": "conditional",
              "gap": "Fictional commercial assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evidence",
              "status": "conditional",
              "gap": "Fictional evidence assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "scale",
              "status": "gap",
              "gap": "A second site's maps and workflows have not been evaluated."
            }
          ]
        },
        "failures": [
          {
            "type": "sensor_degradation",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "battery_limitation",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "supplier_delay",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "model_drift",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "commissioning_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "customer_change",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "policy_world_model_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "data_rights_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "intervention_unavailable",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "recovery_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "memory_state_loss",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "critic_common_mode",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "edge_cloud_disconnect",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "manufacturing_variance",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "service_overload",
            "enabled": true,
            "severityPercent": 75
          },
          {
            "type": "regulatory_change",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "claim_evidence_mismatch",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "rollback_failure",
            "enabled": false,
            "severityPercent": 50
          }
        ],
        "humanDecision": {
          "owner": "Illustrative accountable product owner",
          "role": "Product and operations sponsor",
          "decision": "Proceed to a bounded site pilot subject to the failed release conditions shown below.",
          "rationale": "The pilot is intended to close operational and integration evidence gaps before a fleet commitment.",
          "reviewDate": "2026-09-30"
        }
      },
      "result": {
        "engineVersion": "flight-engine-1.1.0",
        "scenarioId": "fictional-amr-service-overload",
        "deterministic": true,
        "economics": {
          "upfrontInvestment": 1400640,
          "annualOperatingCost": 489920,
          "lifecycleTco": 3360320,
          "annualProductiveValue": 3772283.59,
          "annualContractRevenue": 432000,
          "lifecycleNetValue": 11728814.34,
          "paybackMonths": 5.1,
          "costPerProductiveHour": 7.57
        },
        "investment": {
          "totalBudget": 2400000,
          "allocatedTotal": 2400000,
          "allocations": {
            "productDiscovery": 288000,
            "hardware": 720000,
            "software": 480000,
            "dataAi": 288000,
            "safetyCompliance": 288000,
            "fieldOperations": 336000
          },
          "requiredUpfrontInvestment": 1400640,
          "fundingGap": 0,
          "fundingSurplus": 999360,
          "coveragePercent": 171.4
        },
        "operations": {
          "theoreticalAvailabilityPercent": 99.31,
          "effectiveAvailabilityPercent": 96.31,
          "targetAvailabilityPercent": 97,
          "productiveFleetHoursPerYear": 110949.5,
          "serviceHoursPerYear": 2376,
          "replacementUnitsPerYear": 0.96
        },
        "delivery": {
          "capacityUtilizationPercent": 39,
          "commissioningHoursPerMonth": 38.9,
          "queueDelayWeeks": 0,
          "forecastReleaseWeeks": 28,
          "supplierLeadTimeWeeks": 14
        },
        "risk": {
          "score": 48,
          "band": "elevated",
          "evidenceGapPercent": 28
        },
        "allocationTotalPercent": 100,
        "modeledExperimentSignal": "hold",
        "releaseRecommendation": "experiment_only",
        "productSystemDiagnostic": {
          "version": "product-system-diagnostic-1.0.0",
          "source": "visitor_supplied_fictional_assumptions",
          "gate": "scale",
          "decisionDoor": "demo_to_operated_product",
          "lensIds": [
            "customer-operator-value",
            "business-model-economics",
            "ai-data-evaluation-hmi",
            "system-architecture",
            "safety-governance-oversight",
            "operations-ecosystem"
          ],
          "reliabilityExposure": {
            "status": "declared_gap",
            "exposureUnit": "fictional pallet-transfer attempts per fleet-year",
            "successRatePercent": 95,
            "interventionRatePerThousandOutcomes": 20,
            "recoveryRatePercent": 80,
            "longestContinuousDutyHours": 8,
            "operatorMinutesPerDutyHour": 6,
            "costPerSuccessfulOutcome": 3.68
          },
          "completeness": [
            {
              "dimension": "capability",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional capability assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "reliability",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "Shift-length obstruction and recovery evidence is missing."
            },
            {
              "dimension": "authority",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional authority assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evaluation",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional evaluation assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "operations",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional operations assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "service",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "Recovery staffing and spares response have not been tested."
            },
            {
              "dimension": "commercial",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional commercial assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evidence",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional evidence assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "scale",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "A second site's maps and workflows have not been evaluated."
            }
          ],
          "evidenceGaps": [
            "Public visitor inputs are fictional assumptions, not release evidence; independent validation remains required.",
            "Evaluated and intended authority, supervision, intervention and stop controls are not aligned.",
            "Critic independence or shared-dependency disclosure is unresolved.",
            "reliability completeness is declared gap.",
            "service completeness is declared gap.",
            "scale completeness is declared gap."
          ],
          "requirementGaps": [
            "Define and evidence the human baseline for useful work, burden, quality and cost.",
            "Bound the product claim to one configuration, intended use and operating envelope.",
            "Translate the claim into verifiable product and system requirements.",
            "Resolve data provenance, IP and learning rights for the intended lifecycle.",
            "Specify memory, long-horizon task state and stale-state behaviour.",
            "Specify dead-end detection and accountable recovery escalation.",
            "Define generalization slices and the evidence required for each slice."
          ],
          "authorityMap": {
            "assessment": "declared_gap",
            "evaluatedAuthority": "bounded_actuation",
            "intendedAuthority": "bounded_actuation",
            "evaluatedSupervision": "continuous_operator",
            "intendedSupervision": "monitoring_only",
            "authorityGap": false,
            "supervisionGap": true,
            "interventionAvailable": true,
            "deterministicStop": true,
            "recoveryOwner": "Illustrative warehouse shift supervisor"
          },
          "critic": {
            "assessment": "declared_gap",
            "present": true,
            "independent": false,
            "sharedDependenciesDeclared": false,
            "calibrated": false,
            "deterministicChecks": true,
            "humanEscalation": true
          },
          "technologyCurve": {
            "assessment": "declared_gap",
            "technology": "Fictional warehouse task policy with deterministic motion limits",
            "plateauRisk": "unknown",
            "openDecisions": [
              "Required product bar is conditional.",
              "Expected ceiling is unknown.",
              "Future cost is unknown.",
              "Migration path is gap.",
              "Vendor exit is gap."
            ]
          },
          "capabilityComplexityDelta": {
            "capabilityAssessment": "requires_evidence",
            "complexityRisks": [
              "Edge/cloud boundary is gap.",
              "Data and learning rights are gap.",
              "The declared critic is not independent from the system it evaluates.",
              "manufacturing readiness is conditional.",
              "supply readiness is conditional.",
              "deployment readiness is conditional.",
              "service readiness is gap.",
              "regulatory readiness is unknown.",
              "cybersecurity readiness is unknown.",
              "commercialCommitment readiness is gap.",
              "rollback readiness is gap.",
              "retirement readiness is unknown."
            ],
            "netDecision": "hold"
          },
          "configurationImpact": [
            "Fictional AMR chassis, sensors, task policy, map and warehouse workflow; rollback rehearsal is missing.",
            "Validate the declared model-system set: task_specific_policy, physics_simulator, deterministic_controller.",
            "Revalidate world-model roles: scenario_generator.",
            "Rollback is not supported by evidence for the declared configuration."
          ],
          "reopeningConditions": [
            "Reopen after any policy, model, hardware, data, tooling or site configuration change.",
            "Reopen if sustained duty, intervention demand or recovery exceeds the declared assumptions.",
            "Reopen when service demand exceeds the support model or customer commitment.",
            "Reopen before any change to intended use, configuration, operating envelope, authority or commercial commitment.",
            "Reopen when evidence expires, is corrected or no longer matches the release configuration."
          ],
          "pdrScope": [
            "Resolve the demo to operated product decision at the scale gate.",
            "Public visitor inputs are fictional assumptions, not release evidence; independent validation remains required.",
            "Evaluated and intended authority, supervision, intervention and stop controls are not aligned.",
            "Critic independence or shared-dependency disclosure is unresolved.",
            "reliability completeness is declared gap.",
            "Define and evidence the human baseline for useful work, burden, quality and cost.",
            "Bound the product claim to one configuration, intended use and operating envelope.",
            "Translate the claim into verifiable product and system requirements.",
            "Required product bar is conditional.",
            "Expected ceiling is unknown."
          ],
          "releaseCase": {
            "recommendation": "experiment_only",
            "boundary": "An Integrated Product Release Case is the accountable product recommendation for one configuration, use, operating envelope and commitment. A release-ready result binds current evidence and product completeness to that configuration, envelope, claim set, intended Human–Machine Authority and operating supervision. It is not a safety case, certification, conformity assessment or legal opinion.",
            "rationale": "This public simulator evaluates fictional, visitor-supplied assumptions. It cannot establish release-grade evidence, specialist acceptance or authority-matched field performance."
          }
        },
        "constraints": [
          {
            "id": "availability",
            "label": "Fleet availability",
            "status": "warning",
            "observed": "96.3%",
            "threshold": "≥ 97%",
            "consequence": "A missed availability gate changes customer value, service load and the release case."
          },
          {
            "id": "capacity",
            "label": "Delivery and commissioning capacity",
            "status": "pass",
            "observed": "39%",
            "threshold": "≤ 80% preferred; >95% blocks",
            "consequence": "Overload creates queues across roadmap work, commissioning and field response."
          },
          {
            "id": "economics",
            "label": "Lifecycle customer-value case",
            "status": "pass",
            "observed": "€11,728,814 net; 5.1 months",
            "threshold": "Positive lifecycle net value inside contract term",
            "consequence": "A negative or late-return case requires scope, price, reliability or operating-model change."
          },
          {
            "id": "risk",
            "label": "Combined safety and evidence risk",
            "status": "warning",
            "observed": "48/100 · elevated",
            "threshold": "≤35 preferred; >55 blocks",
            "consequence": "Risk is a screening signal only; a named safety authority owns acceptance."
          },
          {
            "id": "evidence",
            "label": "Operating-envelope evidence",
            "status": "warning",
            "observed": "72%",
            "threshold": "≥80% preferred; <60% blocks",
            "consequence": "Unverified envelope claims cannot support a scaled release commitment."
          },
          {
            "id": "allocation",
            "label": "Investment allocation",
            "status": "pass",
            "observed": "100%",
            "threshold": "100%",
            "consequence": "Unallocated or double-counted investment obscures real trade-offs."
          },
          {
            "id": "budget-coverage",
            "label": "Upfront funding coverage",
            "status": "pass",
            "observed": "171.4% · €999,360 headroom",
            "threshold": "≥100% of modeled upfront investment; 90–99.9% conditional",
            "consequence": "An unfunded hardware, integration, spares or commissioning requirement invalidates the release plan."
          },
          {
            "id": "human-owner",
            "label": "Accountable human decision",
            "status": "pass",
            "observed": "Illustrative accountable product owner · Product and operations sponsor",
            "threshold": "Named owner, role and decision",
            "consequence": "No model or simulator can own a safety, release, investment or customer commitment."
          },
          {
            "id": "reliability-exposure",
            "label": "Reliability and exposure profile",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Declared denominator, sustained-duty, intervention, recovery, fallback and severity-tolerance basis",
            "consequence": "Architecture and release decisions cannot precede an explicit reliability and exposure profile."
          },
          {
            "id": "product-completeness",
            "label": "Product completeness",
            "status": "fail",
            "observed": "3 of 9 dimensions unresolved",
            "threshold": "All nine dimensions assessed; declarations still require evidence",
            "consequence": "Capability alone cannot waive reliability, authority, evaluation, operations, service, commercial, evidence or scale gaps."
          },
          {
            "id": "authority-match",
            "label": "Authority-matched operation",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Evaluated and intended authority/supervision aligned with intervention, recovery and stop controls",
            "consequence": "Evidence collected under lower authority or stronger supervision cannot silently justify intended operation."
          },
          {
            "id": "critic-independence",
            "label": "Agent–simulator–critic independence",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Versioned critic, disclosed dependencies, calibration, deterministic checks and human escalation",
            "consequence": "An evaluator with unresolved common-mode dependencies cannot establish product readiness."
          },
          {
            "id": "integrated-release-case",
            "label": "Integrated Product Release Case",
            "status": "warning",
            "observed": "experiment only",
            "threshold": "Release-grade, configuration-bound evidence and named specialist decisions",
            "consequence": "This public simulator can recommend a bounded next experiment, never release readiness."
          }
        ],
        "formulas": [
          {
            "id": "budget-coverage",
            "label": "Upfront funding coverage",
            "expression": "total investment budget ÷ modeled upfront investment",
            "units": "% funded"
          },
          {
            "id": "availability",
            "label": "Theoretical availability",
            "expression": "MTBF ÷ (MTBF + MTTR), then explicit failure penalties",
            "units": "% available time"
          },
          {
            "id": "upfront",
            "label": "Upfront investment",
            "expression": "units × (hardware + integration) + spares + commissioning days × day rate",
            "units": "EUR"
          },
          {
            "id": "annual-opex",
            "label": "Annual operating cost",
            "expression": "platform + data/AI ops + inference + energy + service labour + replacements",
            "units": "EUR/year"
          },
          {
            "id": "value",
            "label": "Annual productive value",
            "expression": "units × productive hours × effective availability × value/hour × injected modifiers",
            "units": "EUR/year"
          },
          {
            "id": "capacity",
            "label": "Capacity utilization",
            "expression": "(planned work + commissioning load) ÷ (team hours × teams)",
            "units": "% monthly capacity"
          },
          {
            "id": "risk",
            "label": "Risk screening score",
            "expression": "likelihood × impact + evidence gap + explicit failure increments",
            "units": "0–100 screening index"
          }
        ],
        "assumptions": [
          "All scenarios are fictional and illustrative; figures are visitor-controlled assumptions, not Hyperion client evidence.",
          "Currency is EUR and values are undiscounted; tax, financing and inflation are excluded from this thin slice.",
          "MTBF/MTTR availability is a planning approximation and does not establish functional-safety performance.",
          "Commissioning capacity assumes eight engineering hours per day and forty site-level setup hours per deployment.",
          "Failure injections are transparent multipliers, not probability forecasts or field observations.",
          "The investment budget is compared with modeled upfront hardware, integration, spares and commissioning cost; operating reserve and financing are excluded."
        ],
        "limitations": [
          "This result is not safety certification, legal advice, conformity assessment or an autonomous release decision.",
          "Queueing is a deterministic capacity approximation; it is not a discrete-event simulation of a specific operation.",
          "No real customer, personal, confidential, export-controlled or safety-critical operational data should be entered.",
          "A qualified human owner must validate evidence, operating envelope, compliance duties and consequential commitments."
        ],
        "failureEffects": [
          {
            "type": "service_overload",
            "label": "Service overload",
            "severityPercent": 75,
            "consequences": [
              "37.5% service-load increase",
              "3 availability points removed",
              "Support capacity and customer commitments require revalidation"
            ]
          }
        ],
        "sensitivity": [
          {
            "variable": "Hardware cost (−20% / base / +20%)",
            "low": 11978798.34,
            "base": 11728814.34,
            "high": 11478830.34,
            "units": "EUR"
          },
          {
            "variable": "Productive value/hour (−20% / base / +20%)",
            "low": 8710987.48,
            "base": 11728814.34,
            "high": 14746641.21,
            "units": "EUR"
          },
          {
            "variable": "Availability (−5 pts / base / +5 pts)",
            "low": 10945454.34,
            "base": 11728814.34,
            "high": 12306880,
            "units": "EUR"
          }
        ],
        "methodFit": {
          "version": "method-fit-1.0.0",
          "recommendedOperatingModel": "Continuous discovery + systems engineering evidence spine + Kanban for constrained flow.",
          "governanceNote": "Method choice is contextual. Safety, compliance, investment, release and customer commitments remain owned human decisions regardless of agile method.",
          "scores": [
            {
              "id": "continuous-discovery",
              "name": "Continuous discovery",
              "score": 100,
              "fit": "strong",
              "rationale": "Keeps customer evidence, field learning and product assumptions connected to delivery decisions.",
              "condition": "Use evidence cadence and decision records; do not treat interviews as release authority."
            },
            {
              "id": "scrum",
              "name": "Scrum",
              "score": 71,
              "fit": "conditional",
              "rationale": "Supports bounded product increments where uncertainty can be reduced inside a stable team cadence.",
              "condition": "Keep hardware, safety and commissioning gates outside the fiction of a purely software Definition of Done."
            },
            {
              "id": "kanban",
              "name": "Kanban / flow",
              "score": 79,
              "fit": "strong",
              "rationale": "Makes integration, field defects, evidence work and service queues visible as constrained flow.",
              "condition": "Set explicit classes of service and WIP limits for safety, field and supplier work."
            },
            {
              "id": "systems-engineering",
              "name": "Systems engineering",
              "score": 100,
              "fit": "strong",
              "rationale": "Controls interfaces, operating-envelope evidence and verification across hardware, software, AI and operations.",
              "condition": "Use as a product evidence spine, not as a substitute for customer discovery or incremental learning."
            },
            {
              "id": "safe",
              "name": "SAFe",
              "score": 70,
              "fit": "conditional",
              "rationale": "May coordinate multiple teams and portfolio dependencies when scale is real and independently evidenced.",
              "condition": "Do not introduce enterprise-scale ceremony for a small team; Scrum, Kanban and systems interfaces are sufficient."
            }
          ]
        }
      },
      "provenance": {
        "schemaVersion": "provenance-1.1.0",
        "outputClassification": "deterministic",
        "inputClassification": "illustrative",
        "releaseRecommendation": "experiment_only",
        "productSystemDiagnosticVersion": "product-system-diagnostic-1.0.0",
        "configurationBaselineId": "fictional-amr-fleet.configuration-v1",
        "provider": "Hyperion deterministic engine",
        "exactModelIdentifier": null,
        "modelRole": "arithmetic-and-constraint-authority",
        "aiBoundary": {
          "provider": "Mistral AI",
          "exactModels": [
            "mistral-small-2603",
            "mistral-medium-3-5",
            "mistral-large-2512"
          ],
          "usedForThisOutput": false,
          "limitation": "Optional Mistral council commentary is separate model-derived material and cannot alter these deterministic calculations."
        },
        "promptTemplateVersion": "not-applicable-deterministic-output",
        "applicationVersion": "physical-ai-flight-simulator-1.1.0",
        "methodologyVersion": "method-fit-1.0.0",
        "engineVersion": "flight-engine-1.1.0",
        "evidence": [
          {
            "id": "scenario:fictional-amr-service-overload",
            "classification": "illustrative",
            "label": "Visitor-controlled fictional scenario assumptions",
            "source": "In-browser Physical AI Product Flight Simulator form"
          },
          {
            "id": "engine:flight-engine-1.1.0",
            "classification": "deterministic",
            "label": "Deterministic economics, availability, capacity, risk and constraint result",
            "source": "Hyperion Physical AI Flight Engine"
          },
          {
            "id": "method:method-fit-1.0.0",
            "classification": "deterministic",
            "label": "Contextual method-fit result",
            "source": "Hyperion Method-Fit decision rules"
          }
        ],
        "assumptions": [
          "All scenarios are fictional and illustrative; figures are visitor-controlled assumptions, not Hyperion client evidence.",
          "Currency is EUR and values are undiscounted; tax, financing and inflation are excluded from this thin slice.",
          "MTBF/MTTR availability is a planning approximation and does not establish functional-safety performance.",
          "Commissioning capacity assumes eight engineering hours per day and forty site-level setup hours per deployment.",
          "Failure injections are transparent multipliers, not probability forecasts or field observations.",
          "The investment budget is compared with modeled upfront hardware, integration, spares and commissioning cost; operating reserve and financing are excluded."
        ],
        "limitations": [
          "This result is not safety certification, legal advice, conformity assessment or an autonomous release decision.",
          "Queueing is a deterministic capacity approximation; it is not a discrete-event simulation of a specific operation.",
          "No real customer, personal, confidential, export-controlled or safety-critical operational data should be entered.",
          "A qualified human owner must validate evidence, operating envelope, compliance duties and consequential commitments."
        ],
        "canonicalInputHash": "58f05814e53584e92f9a00bf6dfcf2c461d8bbe2c73b3e059f08ea77e027c1a3",
        "deterministicResultHash": "6d213cdf5bf324f4acd179a0f9c6bbfe51581b6bf177623e538c3c3928804467",
        "createdAt": "2026-09-06T00:00:00Z",
        "responsibleHumanDecisionOwner": "Illustrative accountable product owner",
        "responsibleHumanDecisionRole": "Product and operations sponsor",
        "humanDecision": "Proceed to a bounded site pilot subject to the failed release conditions shown below.",
        "reviewDate": "2026-09-30",
        "reviewStatus": "illustrative_unapproved",
        "humanDecisionRecorded": false,
        "expiryStatus": "within_review_period"
      }
    },
    {
      "id": "recovery-failure",
      "label": "Recovery failure, severity 75%",
      "scenario": {
        "schemaVersion": "1.0.0",
        "scenarioId": "fictional-amr-recovery-failure",
        "name": "Recovery failure, severity 75%",
        "fictional": true,
        "customerProblem": "A distribution operator needs to reduce repetitive pallet movement without making throughput brittle.",
        "buyer": "VP Operations and site general manager",
        "productPromise": "Move priority loads safely within a bounded warehouse envelope while preserving accountable human release authority.",
        "economics": {
          "fleetUnits": 24,
          "deploymentsPerYear": 4,
          "contractYears": 4,
          "revenuePerUnitYear": 18000,
          "productiveValuePerHour": 34,
          "productiveHoursPerUnitYear": 4800,
          "hardwareCostPerUnit": 42000,
          "integrationCostPerUnit": 11000,
          "platformCostPerYear": 95000,
          "dataOpsCostPerYear": 48000,
          "inferenceCostPerUnitMonth": 65,
          "serviceHoursPerUnitYear": 72,
          "serviceLaborRatePerHour": 105,
          "energyCostPerUnitYear": 1600,
          "engineerDayRate": 1250
        },
        "operations": {
          "mtbfHours": 720,
          "mttrHours": 5,
          "commissioningDaysPerUnit": 1.6,
          "supplierLeadTimeWeeks": 14,
          "sparesPercent": 8,
          "replacementPercentPerYear": 4,
          "targetAvailabilityPercent": 97
        },
        "delivery": {
          "availableTeamHoursPerMonth": 520,
          "plannedTeamHoursPerMonth": 330,
          "teamCount": 2,
          "coordinationTeams": 3,
          "roadmapWeeks": 28,
          "deliveryCadenceWeeks": 2
        },
        "investment": {
          "totalBudget": 2400000,
          "productDiscoveryPercent": 12,
          "hardwarePercent": 30,
          "softwarePercent": 20,
          "dataAiPercent": 12,
          "safetyCompliancePercent": 12,
          "fieldOperationsPercent": 14
        },
        "methodContext": {
          "uncertainty": 4,
          "hardwareSoftwareCoupling": 4,
          "safetyCriticality": 4,
          "regulatoryBurden": 3,
          "coordinationScale": 3,
          "fieldLearningNeed": 5
        },
        "operatingEnvelope": {
          "minTemperatureC": 5,
          "maxTemperatureC": 40,
          "maxPayloadKg": 1000,
          "minimumConnectivityPercent": 85,
          "operatorTrainingHours": 8,
          "evidenceCoveragePercent": 72
        },
        "risk": {
          "baseSafetyLikelihood": 2,
          "baseSafetyImpact": 4
        },
        "productization": {
          "stageId": "scale",
          "decisionDoor": "demo_to_operated_product",
          "lensIds": [
            "customer-operator-value",
            "business-model-economics",
            "ai-data-evaluation-hmi",
            "system-architecture",
            "safety-governance-oversight",
            "operations-ecosystem"
          ],
          "configuration": {
            "baselineId": "fictional-amr-fleet.configuration-v1",
            "status": "conditional",
            "changeSummary": "Fictional AMR chassis, sensors, task policy, map and warehouse workflow; rollback rehearsal is missing.",
            "rollbackStatus": "gap",
            "reopeningTriggers": [
              "Reopen after any policy, model, hardware, data, tooling or site configuration change.",
              "Reopen if sustained duty, intervention demand or recovery exceeds the declared assumptions."
            ]
          },
          "humanBaseline": {
            "status": "gap",
            "statement": "Measure manual pallet-movement throughput, errors, waiting and operator burden; no baseline has been observed."
          },
          "productClaim": {
            "status": "conditional",
            "statement": "Fictional hypothesis: move priority pallets across one mapped warehouse shift with accountable recovery."
          },
          "requirement": {
            "status": "conditional",
            "statement": "Define a successful pallet transfer, obstruction recovery and safe-stop acceptance before testing the fleet."
          },
          "architecture": {
            "modelSystems": [
              "task_specific_policy",
              "physics_simulator",
              "deterministic_controller"
            ],
            "worldModelRoles": [
              "scenario_generator"
            ],
            "policyStatus": "conditional",
            "worldModelStatus": "conditional",
            "dataLearningRightsStatus": "gap",
            "edgeCloudBoundaryStatus": "gap"
          },
          "reliabilityExposure": {
            "exposureUnit": "fictional pallet-transfer attempts per fleet-year",
            "attemptedOutcomesPerYear": 240000,
            "successfulOutcomesPerYear": 228000,
            "interventionsPerYear": 4800,
            "recoveryAttemptsPerYear": 3600,
            "successfulRecoveriesPerYear": 2880,
            "longestContinuousDutyHours": 8,
            "operatorMinutesPerDutyHour": 6,
            "toleratedSevereEventsPerYear": 0,
            "severityTolerancesStatus": "unknown",
            "fallbackStatus": "gap"
          },
          "authority": {
            "evaluatedAuthority": "bounded_actuation",
            "intendedAuthority": "bounded_actuation",
            "evaluatedSupervision": "continuous_operator",
            "intendedSupervision": "monitoring_only",
            "interventionAvailable": true,
            "deterministicStop": true,
            "recoveryOwner": "Illustrative warehouse shift supervisor"
          },
          "learning": {
            "memoryStatus": "conditional",
            "taskProgressStatus": "conditional",
            "deadEndDetectionStatus": "gap",
            "autonomousExperienceStatus": "unknown",
            "humanCorrectionsStatus": "conditional",
            "generalizationStatus": "gap",
            "fleetLearningStatus": "unknown"
          },
          "critic": {
            "present": true,
            "version": "fictional-amr-fleet-critic-v1",
            "independent": false,
            "sharedDependenciesDeclared": false,
            "calibrated": false,
            "deterministicChecks": true,
            "humanEscalation": true
          },
          "technologyCurve": {
            "technology": "Fictional warehouse task policy with deterministic motion limits",
            "plateauRisk": "unknown",
            "requiredProductBarStatus": "conditional",
            "expectedCeilingStatus": "unknown",
            "futureCostStatus": "unknown",
            "migrationPathStatus": "gap",
            "vendorExitStatus": "gap"
          },
          "lifecycleReadiness": {
            "manufacturing": "conditional",
            "supply": "conditional",
            "deployment": "conditional",
            "service": "gap",
            "regulatory": "unknown",
            "cybersecurity": "unknown",
            "commercialCommitment": "gap",
            "rollback": "gap",
            "retirement": "unknown"
          },
          "completeness": [
            {
              "dimension": "capability",
              "status": "conditional",
              "gap": "Fictional capability assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "reliability",
              "status": "gap",
              "gap": "Shift-length obstruction and recovery evidence is missing."
            },
            {
              "dimension": "authority",
              "status": "conditional",
              "gap": "Fictional authority assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evaluation",
              "status": "conditional",
              "gap": "Fictional evaluation assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "operations",
              "status": "conditional",
              "gap": "Fictional operations assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "service",
              "status": "gap",
              "gap": "Recovery staffing and spares response have not been tested."
            },
            {
              "dimension": "commercial",
              "status": "conditional",
              "gap": "Fictional commercial assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evidence",
              "status": "conditional",
              "gap": "Fictional evidence assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "scale",
              "status": "gap",
              "gap": "A second site's maps and workflows have not been evaluated."
            }
          ]
        },
        "failures": [
          {
            "type": "sensor_degradation",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "battery_limitation",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "supplier_delay",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "model_drift",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "commissioning_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "customer_change",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "policy_world_model_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "data_rights_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "intervention_unavailable",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "recovery_failure",
            "enabled": true,
            "severityPercent": 75
          },
          {
            "type": "memory_state_loss",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "critic_common_mode",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "edge_cloud_disconnect",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "manufacturing_variance",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "service_overload",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "regulatory_change",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "claim_evidence_mismatch",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "rollback_failure",
            "enabled": false,
            "severityPercent": 50
          }
        ],
        "humanDecision": {
          "owner": "Illustrative accountable product owner",
          "role": "Product and operations sponsor",
          "decision": "Proceed to a bounded site pilot subject to the failed release conditions shown below.",
          "rationale": "The pilot is intended to close operational and integration evidence gaps before a fleet commitment.",
          "reviewDate": "2026-09-30"
        }
      },
      "result": {
        "engineVersion": "flight-engine-1.1.0",
        "scenarioId": "fictional-amr-recovery-failure",
        "deterministic": true,
        "economics": {
          "upfrontInvestment": 1400640,
          "annualOperatingCost": 462704,
          "lifecycleTco": 3251456,
          "annualProductiveValue": 3596027.59,
          "annualContractRevenue": 432000,
          "lifecycleNetValue": 11132654.34,
          "paybackMonths": 5.4,
          "costPerProductiveHour": 7.69
        },
        "investment": {
          "totalBudget": 2400000,
          "allocatedTotal": 2400000,
          "allocations": {
            "productDiscovery": 288000,
            "hardware": 720000,
            "software": 480000,
            "dataAi": 288000,
            "safetyCompliance": 288000,
            "fieldOperations": 336000
          },
          "requiredUpfrontInvestment": 1400640,
          "fundingGap": 0,
          "fundingSurplus": 999360,
          "coveragePercent": 171.4
        },
        "operations": {
          "theoreticalAvailabilityPercent": 99.31,
          "effectiveAvailabilityPercent": 91.81,
          "targetAvailabilityPercent": 97,
          "productiveFleetHoursPerYear": 105765.5,
          "serviceHoursPerYear": 2116.8,
          "replacementUnitsPerYear": 0.96
        },
        "delivery": {
          "capacityUtilizationPercent": 35.5,
          "commissioningHoursPerMonth": 38.9,
          "queueDelayWeeks": 0,
          "forecastReleaseWeeks": 28,
          "supplierLeadTimeWeeks": 14
        },
        "risk": {
          "score": 55.5,
          "band": "high",
          "evidenceGapPercent": 28
        },
        "allocationTotalPercent": 100,
        "modeledExperimentSignal": "hold",
        "releaseRecommendation": "experiment_only",
        "productSystemDiagnostic": {
          "version": "product-system-diagnostic-1.0.0",
          "source": "visitor_supplied_fictional_assumptions",
          "gate": "scale",
          "decisionDoor": "demo_to_operated_product",
          "lensIds": [
            "customer-operator-value",
            "business-model-economics",
            "ai-data-evaluation-hmi",
            "system-architecture",
            "safety-governance-oversight",
            "operations-ecosystem"
          ],
          "reliabilityExposure": {
            "status": "declared_gap",
            "exposureUnit": "fictional pallet-transfer attempts per fleet-year",
            "successRatePercent": 95,
            "interventionRatePerThousandOutcomes": 20,
            "recoveryRatePercent": 80,
            "longestContinuousDutyHours": 8,
            "operatorMinutesPerDutyHour": 6,
            "costPerSuccessfulOutcome": 3.57
          },
          "completeness": [
            {
              "dimension": "capability",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional capability assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "reliability",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "Shift-length obstruction and recovery evidence is missing."
            },
            {
              "dimension": "authority",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional authority assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evaluation",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional evaluation assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "operations",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional operations assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "service",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "Recovery staffing and spares response have not been tested."
            },
            {
              "dimension": "commercial",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional commercial assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evidence",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional evidence assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "scale",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "A second site's maps and workflows have not been evaluated."
            }
          ],
          "evidenceGaps": [
            "Public visitor inputs are fictional assumptions, not release evidence; independent validation remains required.",
            "Evaluated and intended authority, supervision, intervention and stop controls are not aligned.",
            "Critic independence or shared-dependency disclosure is unresolved.",
            "reliability completeness is declared gap.",
            "service completeness is declared gap.",
            "scale completeness is declared gap."
          ],
          "requirementGaps": [
            "Define and evidence the human baseline for useful work, burden, quality and cost.",
            "Bound the product claim to one configuration, intended use and operating envelope.",
            "Translate the claim into verifiable product and system requirements.",
            "Resolve data provenance, IP and learning rights for the intended lifecycle.",
            "Specify memory, long-horizon task state and stale-state behaviour.",
            "Specify dead-end detection and accountable recovery escalation.",
            "Define generalization slices and the evidence required for each slice."
          ],
          "authorityMap": {
            "assessment": "declared_gap",
            "evaluatedAuthority": "bounded_actuation",
            "intendedAuthority": "bounded_actuation",
            "evaluatedSupervision": "continuous_operator",
            "intendedSupervision": "monitoring_only",
            "authorityGap": false,
            "supervisionGap": true,
            "interventionAvailable": true,
            "deterministicStop": true,
            "recoveryOwner": "Illustrative warehouse shift supervisor"
          },
          "critic": {
            "assessment": "declared_gap",
            "present": true,
            "independent": false,
            "sharedDependenciesDeclared": false,
            "calibrated": false,
            "deterministicChecks": true,
            "humanEscalation": true
          },
          "technologyCurve": {
            "assessment": "declared_gap",
            "technology": "Fictional warehouse task policy with deterministic motion limits",
            "plateauRisk": "unknown",
            "openDecisions": [
              "Required product bar is conditional.",
              "Expected ceiling is unknown.",
              "Future cost is unknown.",
              "Migration path is gap.",
              "Vendor exit is gap."
            ]
          },
          "capabilityComplexityDelta": {
            "capabilityAssessment": "requires_evidence",
            "complexityRisks": [
              "Edge/cloud boundary is gap.",
              "Data and learning rights are gap.",
              "The declared critic is not independent from the system it evaluates.",
              "manufacturing readiness is conditional.",
              "supply readiness is conditional.",
              "deployment readiness is conditional.",
              "service readiness is gap.",
              "regulatory readiness is unknown.",
              "cybersecurity readiness is unknown.",
              "commercialCommitment readiness is gap.",
              "rollback readiness is gap.",
              "retirement readiness is unknown."
            ],
            "netDecision": "hold"
          },
          "configurationImpact": [
            "Fictional AMR chassis, sensors, task policy, map and warehouse workflow; rollback rehearsal is missing.",
            "Validate the declared model-system set: task_specific_policy, physics_simulator, deterministic_controller.",
            "Revalidate world-model roles: scenario_generator.",
            "Rollback is not supported by evidence for the declared configuration."
          ],
          "reopeningConditions": [
            "Reopen after any policy, model, hardware, data, tooling or site configuration change.",
            "Reopen if sustained duty, intervention demand or recovery exceeds the declared assumptions.",
            "Reopen when recovery effectiveness falls below the declared exposure tolerance.",
            "Reopen before any change to intended use, configuration, operating envelope, authority or commercial commitment.",
            "Reopen when evidence expires, is corrected or no longer matches the release configuration."
          ],
          "pdrScope": [
            "Resolve the demo to operated product decision at the scale gate.",
            "Public visitor inputs are fictional assumptions, not release evidence; independent validation remains required.",
            "Evaluated and intended authority, supervision, intervention and stop controls are not aligned.",
            "Critic independence or shared-dependency disclosure is unresolved.",
            "reliability completeness is declared gap.",
            "Define and evidence the human baseline for useful work, burden, quality and cost.",
            "Bound the product claim to one configuration, intended use and operating envelope.",
            "Translate the claim into verifiable product and system requirements.",
            "Required product bar is conditional.",
            "Expected ceiling is unknown."
          ],
          "releaseCase": {
            "recommendation": "experiment_only",
            "boundary": "An Integrated Product Release Case is the accountable product recommendation for one configuration, use, operating envelope and commitment. A release-ready result binds current evidence and product completeness to that configuration, envelope, claim set, intended Human–Machine Authority and operating supervision. It is not a safety case, certification, conformity assessment or legal opinion.",
            "rationale": "This public simulator evaluates fictional, visitor-supplied assumptions. It cannot establish release-grade evidence, specialist acceptance or authority-matched field performance."
          }
        },
        "constraints": [
          {
            "id": "availability",
            "label": "Fleet availability",
            "status": "fail",
            "observed": "91.8%",
            "threshold": "≥ 97%",
            "consequence": "A missed availability gate changes customer value, service load and the release case."
          },
          {
            "id": "capacity",
            "label": "Delivery and commissioning capacity",
            "status": "pass",
            "observed": "35.5%",
            "threshold": "≤ 80% preferred; >95% blocks",
            "consequence": "Overload creates queues across roadmap work, commissioning and field response."
          },
          {
            "id": "economics",
            "label": "Lifecycle customer-value case",
            "status": "pass",
            "observed": "€11,132,654 net; 5.4 months",
            "threshold": "Positive lifecycle net value inside contract term",
            "consequence": "A negative or late-return case requires scope, price, reliability or operating-model change."
          },
          {
            "id": "risk",
            "label": "Combined safety and evidence risk",
            "status": "fail",
            "observed": "55.5/100 · high",
            "threshold": "≤35 preferred; >55 blocks",
            "consequence": "Risk is a screening signal only; a named safety authority owns acceptance."
          },
          {
            "id": "evidence",
            "label": "Operating-envelope evidence",
            "status": "warning",
            "observed": "72%",
            "threshold": "≥80% preferred; <60% blocks",
            "consequence": "Unverified envelope claims cannot support a scaled release commitment."
          },
          {
            "id": "allocation",
            "label": "Investment allocation",
            "status": "pass",
            "observed": "100%",
            "threshold": "100%",
            "consequence": "Unallocated or double-counted investment obscures real trade-offs."
          },
          {
            "id": "budget-coverage",
            "label": "Upfront funding coverage",
            "status": "pass",
            "observed": "171.4% · €999,360 headroom",
            "threshold": "≥100% of modeled upfront investment; 90–99.9% conditional",
            "consequence": "An unfunded hardware, integration, spares or commissioning requirement invalidates the release plan."
          },
          {
            "id": "human-owner",
            "label": "Accountable human decision",
            "status": "pass",
            "observed": "Illustrative accountable product owner · Product and operations sponsor",
            "threshold": "Named owner, role and decision",
            "consequence": "No model or simulator can own a safety, release, investment or customer commitment."
          },
          {
            "id": "reliability-exposure",
            "label": "Reliability and exposure profile",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Declared denominator, sustained-duty, intervention, recovery, fallback and severity-tolerance basis",
            "consequence": "Architecture and release decisions cannot precede an explicit reliability and exposure profile."
          },
          {
            "id": "product-completeness",
            "label": "Product completeness",
            "status": "fail",
            "observed": "3 of 9 dimensions unresolved",
            "threshold": "All nine dimensions assessed; declarations still require evidence",
            "consequence": "Capability alone cannot waive reliability, authority, evaluation, operations, service, commercial, evidence or scale gaps."
          },
          {
            "id": "authority-match",
            "label": "Authority-matched operation",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Evaluated and intended authority/supervision aligned with intervention, recovery and stop controls",
            "consequence": "Evidence collected under lower authority or stronger supervision cannot silently justify intended operation."
          },
          {
            "id": "critic-independence",
            "label": "Agent–simulator–critic independence",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Versioned critic, disclosed dependencies, calibration, deterministic checks and human escalation",
            "consequence": "An evaluator with unresolved common-mode dependencies cannot establish product readiness."
          },
          {
            "id": "integrated-release-case",
            "label": "Integrated Product Release Case",
            "status": "warning",
            "observed": "experiment only",
            "threshold": "Release-grade, configuration-bound evidence and named specialist decisions",
            "consequence": "This public simulator can recommend a bounded next experiment, never release readiness."
          }
        ],
        "formulas": [
          {
            "id": "budget-coverage",
            "label": "Upfront funding coverage",
            "expression": "total investment budget ÷ modeled upfront investment",
            "units": "% funded"
          },
          {
            "id": "availability",
            "label": "Theoretical availability",
            "expression": "MTBF ÷ (MTBF + MTTR), then explicit failure penalties",
            "units": "% available time"
          },
          {
            "id": "upfront",
            "label": "Upfront investment",
            "expression": "units × (hardware + integration) + spares + commissioning days × day rate",
            "units": "EUR"
          },
          {
            "id": "annual-opex",
            "label": "Annual operating cost",
            "expression": "platform + data/AI ops + inference + energy + service labour + replacements",
            "units": "EUR/year"
          },
          {
            "id": "value",
            "label": "Annual productive value",
            "expression": "units × productive hours × effective availability × value/hour × injected modifiers",
            "units": "EUR/year"
          },
          {
            "id": "capacity",
            "label": "Capacity utilization",
            "expression": "(planned work + commissioning load) ÷ (team hours × teams)",
            "units": "% monthly capacity"
          },
          {
            "id": "risk",
            "label": "Risk screening score",
            "expression": "likelihood × impact + evidence gap + explicit failure increments",
            "units": "0–100 screening index"
          }
        ],
        "assumptions": [
          "All scenarios are fictional and illustrative; figures are visitor-controlled assumptions, not Hyperion client evidence.",
          "Currency is EUR and values are undiscounted; tax, financing and inflation are excluded from this thin slice.",
          "MTBF/MTTR availability is a planning approximation and does not establish functional-safety performance.",
          "Commissioning capacity assumes eight engineering hours per day and forty site-level setup hours per deployment.",
          "Failure injections are transparent multipliers, not probability forecasts or field observations.",
          "The investment budget is compared with modeled upfront hardware, integration, spares and commissioning cost; operating reserve and financing are excluded."
        ],
        "limitations": [
          "This result is not safety certification, legal advice, conformity assessment or an autonomous release decision.",
          "Queueing is a deterministic capacity approximation; it is not a discrete-event simulation of a specific operation.",
          "No real customer, personal, confidential, export-controlled or safety-critical operational data should be entered.",
          "A qualified human owner must validate evidence, operating envelope, compliance duties and consequential commitments."
        ],
        "failureEffects": [
          {
            "type": "recovery_failure",
            "label": "Recovery failure",
            "severityPercent": 75,
            "consequences": [
              "7.5 availability points removed",
              "22.5% service-load increase",
              "Recovery evidence and sustained-duty claims require revalidation"
            ]
          }
        ],
        "sensitivity": [
          {
            "variable": "Hardware cost (−20% / base / +20%)",
            "low": 11382638.34,
            "base": 11132654.34,
            "high": 10882670.34,
            "units": "EUR"
          },
          {
            "variable": "Productive value/hour (−20% / base / +20%)",
            "low": 8255832.28,
            "base": 11132654.34,
            "high": 14009476.41,
            "units": "EUR"
          },
          {
            "variable": "Availability (−5 pts / base / +5 pts)",
            "low": 10349294.34,
            "base": 11132654.34,
            "high": 11916014.34,
            "units": "EUR"
          }
        ],
        "methodFit": {
          "version": "method-fit-1.0.0",
          "recommendedOperatingModel": "Continuous discovery + systems engineering evidence spine + Kanban for constrained flow.",
          "governanceNote": "Method choice is contextual. Safety, compliance, investment, release and customer commitments remain owned human decisions regardless of agile method.",
          "scores": [
            {
              "id": "continuous-discovery",
              "name": "Continuous discovery",
              "score": 100,
              "fit": "strong",
              "rationale": "Keeps customer evidence, field learning and product assumptions connected to delivery decisions.",
              "condition": "Use evidence cadence and decision records; do not treat interviews as release authority."
            },
            {
              "id": "scrum",
              "name": "Scrum",
              "score": 71,
              "fit": "conditional",
              "rationale": "Supports bounded product increments where uncertainty can be reduced inside a stable team cadence.",
              "condition": "Keep hardware, safety and commissioning gates outside the fiction of a purely software Definition of Done."
            },
            {
              "id": "kanban",
              "name": "Kanban / flow",
              "score": 79,
              "fit": "strong",
              "rationale": "Makes integration, field defects, evidence work and service queues visible as constrained flow.",
              "condition": "Set explicit classes of service and WIP limits for safety, field and supplier work."
            },
            {
              "id": "systems-engineering",
              "name": "Systems engineering",
              "score": 100,
              "fit": "strong",
              "rationale": "Controls interfaces, operating-envelope evidence and verification across hardware, software, AI and operations.",
              "condition": "Use as a product evidence spine, not as a substitute for customer discovery or incremental learning."
            },
            {
              "id": "safe",
              "name": "SAFe",
              "score": 70,
              "fit": "conditional",
              "rationale": "May coordinate multiple teams and portfolio dependencies when scale is real and independently evidenced.",
              "condition": "Do not introduce enterprise-scale ceremony for a small team; Scrum, Kanban and systems interfaces are sufficient."
            }
          ]
        }
      },
      "provenance": {
        "schemaVersion": "provenance-1.1.0",
        "outputClassification": "deterministic",
        "inputClassification": "illustrative",
        "releaseRecommendation": "experiment_only",
        "productSystemDiagnosticVersion": "product-system-diagnostic-1.0.0",
        "configurationBaselineId": "fictional-amr-fleet.configuration-v1",
        "provider": "Hyperion deterministic engine",
        "exactModelIdentifier": null,
        "modelRole": "arithmetic-and-constraint-authority",
        "aiBoundary": {
          "provider": "Mistral AI",
          "exactModels": [
            "mistral-small-2603",
            "mistral-medium-3-5",
            "mistral-large-2512"
          ],
          "usedForThisOutput": false,
          "limitation": "Optional Mistral council commentary is separate model-derived material and cannot alter these deterministic calculations."
        },
        "promptTemplateVersion": "not-applicable-deterministic-output",
        "applicationVersion": "physical-ai-flight-simulator-1.1.0",
        "methodologyVersion": "method-fit-1.0.0",
        "engineVersion": "flight-engine-1.1.0",
        "evidence": [
          {
            "id": "scenario:fictional-amr-recovery-failure",
            "classification": "illustrative",
            "label": "Visitor-controlled fictional scenario assumptions",
            "source": "In-browser Physical AI Product Flight Simulator form"
          },
          {
            "id": "engine:flight-engine-1.1.0",
            "classification": "deterministic",
            "label": "Deterministic economics, availability, capacity, risk and constraint result",
            "source": "Hyperion Physical AI Flight Engine"
          },
          {
            "id": "method:method-fit-1.0.0",
            "classification": "deterministic",
            "label": "Contextual method-fit result",
            "source": "Hyperion Method-Fit decision rules"
          }
        ],
        "assumptions": [
          "All scenarios are fictional and illustrative; figures are visitor-controlled assumptions, not Hyperion client evidence.",
          "Currency is EUR and values are undiscounted; tax, financing and inflation are excluded from this thin slice.",
          "MTBF/MTTR availability is a planning approximation and does not establish functional-safety performance.",
          "Commissioning capacity assumes eight engineering hours per day and forty site-level setup hours per deployment.",
          "Failure injections are transparent multipliers, not probability forecasts or field observations.",
          "The investment budget is compared with modeled upfront hardware, integration, spares and commissioning cost; operating reserve and financing are excluded."
        ],
        "limitations": [
          "This result is not safety certification, legal advice, conformity assessment or an autonomous release decision.",
          "Queueing is a deterministic capacity approximation; it is not a discrete-event simulation of a specific operation.",
          "No real customer, personal, confidential, export-controlled or safety-critical operational data should be entered.",
          "A qualified human owner must validate evidence, operating envelope, compliance duties and consequential commitments."
        ],
        "canonicalInputHash": "41a505364bbb654597f0f29602935362c48e5790d62d47a6a4daaac09621a6d6",
        "deterministicResultHash": "a3d4ab5af5a4e71414578c23588483f2f26f2f1a733806068f8b75c1fb4b8838",
        "createdAt": "2026-09-06T00:00:00Z",
        "responsibleHumanDecisionOwner": "Illustrative accountable product owner",
        "responsibleHumanDecisionRole": "Product and operations sponsor",
        "humanDecision": "Proceed to a bounded site pilot subject to the failed release conditions shown below.",
        "reviewDate": "2026-09-30",
        "reviewStatus": "illustrative_unapproved",
        "humanDecisionRecorded": false,
        "expiryStatus": "within_review_period"
      }
    },
    {
      "id": "supplier-delay",
      "label": "Supplier delay, severity 75%",
      "scenario": {
        "schemaVersion": "1.0.0",
        "scenarioId": "fictional-amr-supplier-delay",
        "name": "Supplier delay, severity 75%",
        "fictional": true,
        "customerProblem": "A distribution operator needs to reduce repetitive pallet movement without making throughput brittle.",
        "buyer": "VP Operations and site general manager",
        "productPromise": "Move priority loads safely within a bounded warehouse envelope while preserving accountable human release authority.",
        "economics": {
          "fleetUnits": 24,
          "deploymentsPerYear": 4,
          "contractYears": 4,
          "revenuePerUnitYear": 18000,
          "productiveValuePerHour": 34,
          "productiveHoursPerUnitYear": 4800,
          "hardwareCostPerUnit": 42000,
          "integrationCostPerUnit": 11000,
          "platformCostPerYear": 95000,
          "dataOpsCostPerYear": 48000,
          "inferenceCostPerUnitMonth": 65,
          "serviceHoursPerUnitYear": 72,
          "serviceLaborRatePerHour": 105,
          "energyCostPerUnitYear": 1600,
          "engineerDayRate": 1250
        },
        "operations": {
          "mtbfHours": 720,
          "mttrHours": 5,
          "commissioningDaysPerUnit": 1.6,
          "supplierLeadTimeWeeks": 14,
          "sparesPercent": 8,
          "replacementPercentPerYear": 4,
          "targetAvailabilityPercent": 97
        },
        "delivery": {
          "availableTeamHoursPerMonth": 520,
          "plannedTeamHoursPerMonth": 330,
          "teamCount": 2,
          "coordinationTeams": 3,
          "roadmapWeeks": 28,
          "deliveryCadenceWeeks": 2
        },
        "investment": {
          "totalBudget": 2400000,
          "productDiscoveryPercent": 12,
          "hardwarePercent": 30,
          "softwarePercent": 20,
          "dataAiPercent": 12,
          "safetyCompliancePercent": 12,
          "fieldOperationsPercent": 14
        },
        "methodContext": {
          "uncertainty": 4,
          "hardwareSoftwareCoupling": 4,
          "safetyCriticality": 4,
          "regulatoryBurden": 3,
          "coordinationScale": 3,
          "fieldLearningNeed": 5
        },
        "operatingEnvelope": {
          "minTemperatureC": 5,
          "maxTemperatureC": 40,
          "maxPayloadKg": 1000,
          "minimumConnectivityPercent": 85,
          "operatorTrainingHours": 8,
          "evidenceCoveragePercent": 72
        },
        "risk": {
          "baseSafetyLikelihood": 2,
          "baseSafetyImpact": 4
        },
        "productization": {
          "stageId": "scale",
          "decisionDoor": "demo_to_operated_product",
          "lensIds": [
            "customer-operator-value",
            "business-model-economics",
            "ai-data-evaluation-hmi",
            "system-architecture",
            "safety-governance-oversight",
            "operations-ecosystem"
          ],
          "configuration": {
            "baselineId": "fictional-amr-fleet.configuration-v1",
            "status": "conditional",
            "changeSummary": "Fictional AMR chassis, sensors, task policy, map and warehouse workflow; rollback rehearsal is missing.",
            "rollbackStatus": "gap",
            "reopeningTriggers": [
              "Reopen after any policy, model, hardware, data, tooling or site configuration change.",
              "Reopen if sustained duty, intervention demand or recovery exceeds the declared assumptions."
            ]
          },
          "humanBaseline": {
            "status": "gap",
            "statement": "Measure manual pallet-movement throughput, errors, waiting and operator burden; no baseline has been observed."
          },
          "productClaim": {
            "status": "conditional",
            "statement": "Fictional hypothesis: move priority pallets across one mapped warehouse shift with accountable recovery."
          },
          "requirement": {
            "status": "conditional",
            "statement": "Define a successful pallet transfer, obstruction recovery and safe-stop acceptance before testing the fleet."
          },
          "architecture": {
            "modelSystems": [
              "task_specific_policy",
              "physics_simulator",
              "deterministic_controller"
            ],
            "worldModelRoles": [
              "scenario_generator"
            ],
            "policyStatus": "conditional",
            "worldModelStatus": "conditional",
            "dataLearningRightsStatus": "gap",
            "edgeCloudBoundaryStatus": "gap"
          },
          "reliabilityExposure": {
            "exposureUnit": "fictional pallet-transfer attempts per fleet-year",
            "attemptedOutcomesPerYear": 240000,
            "successfulOutcomesPerYear": 228000,
            "interventionsPerYear": 4800,
            "recoveryAttemptsPerYear": 3600,
            "successfulRecoveriesPerYear": 2880,
            "longestContinuousDutyHours": 8,
            "operatorMinutesPerDutyHour": 6,
            "toleratedSevereEventsPerYear": 0,
            "severityTolerancesStatus": "unknown",
            "fallbackStatus": "gap"
          },
          "authority": {
            "evaluatedAuthority": "bounded_actuation",
            "intendedAuthority": "bounded_actuation",
            "evaluatedSupervision": "continuous_operator",
            "intendedSupervision": "monitoring_only",
            "interventionAvailable": true,
            "deterministicStop": true,
            "recoveryOwner": "Illustrative warehouse shift supervisor"
          },
          "learning": {
            "memoryStatus": "conditional",
            "taskProgressStatus": "conditional",
            "deadEndDetectionStatus": "gap",
            "autonomousExperienceStatus": "unknown",
            "humanCorrectionsStatus": "conditional",
            "generalizationStatus": "gap",
            "fleetLearningStatus": "unknown"
          },
          "critic": {
            "present": true,
            "version": "fictional-amr-fleet-critic-v1",
            "independent": false,
            "sharedDependenciesDeclared": false,
            "calibrated": false,
            "deterministicChecks": true,
            "humanEscalation": true
          },
          "technologyCurve": {
            "technology": "Fictional warehouse task policy with deterministic motion limits",
            "plateauRisk": "unknown",
            "requiredProductBarStatus": "conditional",
            "expectedCeilingStatus": "unknown",
            "futureCostStatus": "unknown",
            "migrationPathStatus": "gap",
            "vendorExitStatus": "gap"
          },
          "lifecycleReadiness": {
            "manufacturing": "conditional",
            "supply": "conditional",
            "deployment": "conditional",
            "service": "gap",
            "regulatory": "unknown",
            "cybersecurity": "unknown",
            "commercialCommitment": "gap",
            "rollback": "gap",
            "retirement": "unknown"
          },
          "completeness": [
            {
              "dimension": "capability",
              "status": "conditional",
              "gap": "Fictional capability assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "reliability",
              "status": "gap",
              "gap": "Shift-length obstruction and recovery evidence is missing."
            },
            {
              "dimension": "authority",
              "status": "conditional",
              "gap": "Fictional authority assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evaluation",
              "status": "conditional",
              "gap": "Fictional evaluation assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "operations",
              "status": "conditional",
              "gap": "Fictional operations assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "service",
              "status": "gap",
              "gap": "Recovery staffing and spares response have not been tested."
            },
            {
              "dimension": "commercial",
              "status": "conditional",
              "gap": "Fictional commercial assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evidence",
              "status": "conditional",
              "gap": "Fictional evidence assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "scale",
              "status": "gap",
              "gap": "A second site's maps and workflows have not been evaluated."
            }
          ]
        },
        "failures": [
          {
            "type": "sensor_degradation",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "battery_limitation",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "supplier_delay",
            "enabled": true,
            "severityPercent": 75
          },
          {
            "type": "model_drift",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "commissioning_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "customer_change",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "policy_world_model_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "data_rights_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "intervention_unavailable",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "recovery_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "memory_state_loss",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "critic_common_mode",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "edge_cloud_disconnect",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "manufacturing_variance",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "service_overload",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "regulatory_change",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "claim_evidence_mismatch",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "rollback_failure",
            "enabled": false,
            "severityPercent": 50
          }
        ],
        "humanDecision": {
          "owner": "Illustrative accountable product owner",
          "role": "Product and operations sponsor",
          "decision": "Proceed to a bounded site pilot subject to the failed release conditions shown below.",
          "rationale": "The pilot is intended to close operational and integration evidence gaps before a fleet commitment.",
          "reviewDate": "2026-09-30"
        }
      },
      "result": {
        "engineVersion": "flight-engine-1.1.0",
        "scenarioId": "fictional-amr-supplier-delay",
        "deterministic": true,
        "economics": {
          "upfrontInvestment": 1400640,
          "annualOperatingCost": 421880,
          "lifecycleTco": 3088160,
          "annualProductiveValue": 3889787.59,
          "annualContractRevenue": 432000,
          "lifecycleNetValue": 12470990.34,
          "paybackMonths": 4.8,
          "costPerProductiveHour": 6.75
        },
        "investment": {
          "totalBudget": 2400000,
          "allocatedTotal": 2400000,
          "allocations": {
            "productDiscovery": 288000,
            "hardware": 720000,
            "software": 480000,
            "dataAi": 288000,
            "safetyCompliance": 288000,
            "fieldOperations": 336000
          },
          "requiredUpfrontInvestment": 1400640,
          "fundingGap": 0,
          "fundingSurplus": 999360,
          "coveragePercent": 171.4
        },
        "operations": {
          "theoreticalAvailabilityPercent": 99.31,
          "effectiveAvailabilityPercent": 99.31,
          "targetAvailabilityPercent": 97,
          "productiveFleetHoursPerYear": 114405.5,
          "serviceHoursPerYear": 1728,
          "replacementUnitsPerYear": 0.96
        },
        "delivery": {
          "capacityUtilizationPercent": 37.4,
          "commissioningHoursPerMonth": 38.9,
          "queueDelayWeeks": 0,
          "forecastReleaseWeeks": 28,
          "supplierLeadTimeWeeks": 23
        },
        "risk": {
          "score": 42.8,
          "band": "elevated",
          "evidenceGapPercent": 28
        },
        "allocationTotalPercent": 100,
        "modeledExperimentSignal": "hold",
        "releaseRecommendation": "experiment_only",
        "productSystemDiagnostic": {
          "version": "product-system-diagnostic-1.0.0",
          "source": "visitor_supplied_fictional_assumptions",
          "gate": "scale",
          "decisionDoor": "demo_to_operated_product",
          "lensIds": [
            "customer-operator-value",
            "business-model-economics",
            "ai-data-evaluation-hmi",
            "system-architecture",
            "safety-governance-oversight",
            "operations-ecosystem"
          ],
          "reliabilityExposure": {
            "status": "declared_gap",
            "exposureUnit": "fictional pallet-transfer attempts per fleet-year",
            "successRatePercent": 95,
            "interventionRatePerThousandOutcomes": 20,
            "recoveryRatePercent": 80,
            "longestContinuousDutyHours": 8,
            "operatorMinutesPerDutyHour": 6,
            "costPerSuccessfulOutcome": 3.39
          },
          "completeness": [
            {
              "dimension": "capability",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional capability assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "reliability",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "Shift-length obstruction and recovery evidence is missing."
            },
            {
              "dimension": "authority",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional authority assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evaluation",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional evaluation assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "operations",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional operations assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "service",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "Recovery staffing and spares response have not been tested."
            },
            {
              "dimension": "commercial",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional commercial assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evidence",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional evidence assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "scale",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "A second site's maps and workflows have not been evaluated."
            }
          ],
          "evidenceGaps": [
            "Public visitor inputs are fictional assumptions, not release evidence; independent validation remains required.",
            "Evaluated and intended authority, supervision, intervention and stop controls are not aligned.",
            "Critic independence or shared-dependency disclosure is unresolved.",
            "reliability completeness is declared gap.",
            "service completeness is declared gap.",
            "scale completeness is declared gap."
          ],
          "requirementGaps": [
            "Define and evidence the human baseline for useful work, burden, quality and cost.",
            "Bound the product claim to one configuration, intended use and operating envelope.",
            "Translate the claim into verifiable product and system requirements.",
            "Resolve data provenance, IP and learning rights for the intended lifecycle.",
            "Specify memory, long-horizon task state and stale-state behaviour.",
            "Specify dead-end detection and accountable recovery escalation.",
            "Define generalization slices and the evidence required for each slice."
          ],
          "authorityMap": {
            "assessment": "declared_gap",
            "evaluatedAuthority": "bounded_actuation",
            "intendedAuthority": "bounded_actuation",
            "evaluatedSupervision": "continuous_operator",
            "intendedSupervision": "monitoring_only",
            "authorityGap": false,
            "supervisionGap": true,
            "interventionAvailable": true,
            "deterministicStop": true,
            "recoveryOwner": "Illustrative warehouse shift supervisor"
          },
          "critic": {
            "assessment": "declared_gap",
            "present": true,
            "independent": false,
            "sharedDependenciesDeclared": false,
            "calibrated": false,
            "deterministicChecks": true,
            "humanEscalation": true
          },
          "technologyCurve": {
            "assessment": "declared_gap",
            "technology": "Fictional warehouse task policy with deterministic motion limits",
            "plateauRisk": "unknown",
            "openDecisions": [
              "Required product bar is conditional.",
              "Expected ceiling is unknown.",
              "Future cost is unknown.",
              "Migration path is gap.",
              "Vendor exit is gap."
            ]
          },
          "capabilityComplexityDelta": {
            "capabilityAssessment": "requires_evidence",
            "complexityRisks": [
              "Edge/cloud boundary is gap.",
              "Data and learning rights are gap.",
              "The declared critic is not independent from the system it evaluates.",
              "manufacturing readiness is conditional.",
              "supply readiness is conditional.",
              "deployment readiness is conditional.",
              "service readiness is gap.",
              "regulatory readiness is unknown.",
              "cybersecurity readiness is unknown.",
              "commercialCommitment readiness is gap.",
              "rollback readiness is gap.",
              "retirement readiness is unknown."
            ],
            "netDecision": "hold"
          },
          "configurationImpact": [
            "Fictional AMR chassis, sensors, task policy, map and warehouse workflow; rollback rehearsal is missing.",
            "Validate the declared model-system set: task_specific_policy, physics_simulator, deterministic_controller.",
            "Revalidate world-model roles: scenario_generator.",
            "Rollback is not supported by evidence for the declared configuration."
          ],
          "reopeningConditions": [
            "Reopen after any policy, model, hardware, data, tooling or site configuration change.",
            "Reopen if sustained duty, intervention demand or recovery exceeds the declared assumptions.",
            "Reopen when supplier lead time changes the release configuration or customer commitment.",
            "Reopen before any change to intended use, configuration, operating envelope, authority or commercial commitment.",
            "Reopen when evidence expires, is corrected or no longer matches the release configuration."
          ],
          "pdrScope": [
            "Resolve the demo to operated product decision at the scale gate.",
            "Public visitor inputs are fictional assumptions, not release evidence; independent validation remains required.",
            "Evaluated and intended authority, supervision, intervention and stop controls are not aligned.",
            "Critic independence or shared-dependency disclosure is unresolved.",
            "reliability completeness is declared gap.",
            "Define and evidence the human baseline for useful work, burden, quality and cost.",
            "Bound the product claim to one configuration, intended use and operating envelope.",
            "Translate the claim into verifiable product and system requirements.",
            "Required product bar is conditional.",
            "Expected ceiling is unknown."
          ],
          "releaseCase": {
            "recommendation": "experiment_only",
            "boundary": "An Integrated Product Release Case is the accountable product recommendation for one configuration, use, operating envelope and commitment. A release-ready result binds current evidence and product completeness to that configuration, envelope, claim set, intended Human–Machine Authority and operating supervision. It is not a safety case, certification, conformity assessment or legal opinion.",
            "rationale": "This public simulator evaluates fictional, visitor-supplied assumptions. It cannot establish release-grade evidence, specialist acceptance or authority-matched field performance."
          }
        },
        "constraints": [
          {
            "id": "availability",
            "label": "Fleet availability",
            "status": "pass",
            "observed": "99.3%",
            "threshold": "≥ 97%",
            "consequence": "A missed availability gate changes customer value, service load and the release case."
          },
          {
            "id": "capacity",
            "label": "Delivery and commissioning capacity",
            "status": "pass",
            "observed": "37.4%",
            "threshold": "≤ 80% preferred; >95% blocks",
            "consequence": "Overload creates queues across roadmap work, commissioning and field response."
          },
          {
            "id": "economics",
            "label": "Lifecycle customer-value case",
            "status": "pass",
            "observed": "€12,470,990 net; 4.8 months",
            "threshold": "Positive lifecycle net value inside contract term",
            "consequence": "A negative or late-return case requires scope, price, reliability or operating-model change."
          },
          {
            "id": "risk",
            "label": "Combined safety and evidence risk",
            "status": "warning",
            "observed": "42.8/100 · elevated",
            "threshold": "≤35 preferred; >55 blocks",
            "consequence": "Risk is a screening signal only; a named safety authority owns acceptance."
          },
          {
            "id": "evidence",
            "label": "Operating-envelope evidence",
            "status": "warning",
            "observed": "72%",
            "threshold": "≥80% preferred; <60% blocks",
            "consequence": "Unverified envelope claims cannot support a scaled release commitment."
          },
          {
            "id": "allocation",
            "label": "Investment allocation",
            "status": "pass",
            "observed": "100%",
            "threshold": "100%",
            "consequence": "Unallocated or double-counted investment obscures real trade-offs."
          },
          {
            "id": "budget-coverage",
            "label": "Upfront funding coverage",
            "status": "pass",
            "observed": "171.4% · €999,360 headroom",
            "threshold": "≥100% of modeled upfront investment; 90–99.9% conditional",
            "consequence": "An unfunded hardware, integration, spares or commissioning requirement invalidates the release plan."
          },
          {
            "id": "human-owner",
            "label": "Accountable human decision",
            "status": "pass",
            "observed": "Illustrative accountable product owner · Product and operations sponsor",
            "threshold": "Named owner, role and decision",
            "consequence": "No model or simulator can own a safety, release, investment or customer commitment."
          },
          {
            "id": "reliability-exposure",
            "label": "Reliability and exposure profile",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Declared denominator, sustained-duty, intervention, recovery, fallback and severity-tolerance basis",
            "consequence": "Architecture and release decisions cannot precede an explicit reliability and exposure profile."
          },
          {
            "id": "product-completeness",
            "label": "Product completeness",
            "status": "fail",
            "observed": "3 of 9 dimensions unresolved",
            "threshold": "All nine dimensions assessed; declarations still require evidence",
            "consequence": "Capability alone cannot waive reliability, authority, evaluation, operations, service, commercial, evidence or scale gaps."
          },
          {
            "id": "authority-match",
            "label": "Authority-matched operation",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Evaluated and intended authority/supervision aligned with intervention, recovery and stop controls",
            "consequence": "Evidence collected under lower authority or stronger supervision cannot silently justify intended operation."
          },
          {
            "id": "critic-independence",
            "label": "Agent–simulator–critic independence",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Versioned critic, disclosed dependencies, calibration, deterministic checks and human escalation",
            "consequence": "An evaluator with unresolved common-mode dependencies cannot establish product readiness."
          },
          {
            "id": "integrated-release-case",
            "label": "Integrated Product Release Case",
            "status": "warning",
            "observed": "experiment only",
            "threshold": "Release-grade, configuration-bound evidence and named specialist decisions",
            "consequence": "This public simulator can recommend a bounded next experiment, never release readiness."
          }
        ],
        "formulas": [
          {
            "id": "budget-coverage",
            "label": "Upfront funding coverage",
            "expression": "total investment budget ÷ modeled upfront investment",
            "units": "% funded"
          },
          {
            "id": "availability",
            "label": "Theoretical availability",
            "expression": "MTBF ÷ (MTBF + MTTR), then explicit failure penalties",
            "units": "% available time"
          },
          {
            "id": "upfront",
            "label": "Upfront investment",
            "expression": "units × (hardware + integration) + spares + commissioning days × day rate",
            "units": "EUR"
          },
          {
            "id": "annual-opex",
            "label": "Annual operating cost",
            "expression": "platform + data/AI ops + inference + energy + service labour + replacements",
            "units": "EUR/year"
          },
          {
            "id": "value",
            "label": "Annual productive value",
            "expression": "units × productive hours × effective availability × value/hour × injected modifiers",
            "units": "EUR/year"
          },
          {
            "id": "capacity",
            "label": "Capacity utilization",
            "expression": "(planned work + commissioning load) ÷ (team hours × teams)",
            "units": "% monthly capacity"
          },
          {
            "id": "risk",
            "label": "Risk screening score",
            "expression": "likelihood × impact + evidence gap + explicit failure increments",
            "units": "0–100 screening index"
          }
        ],
        "assumptions": [
          "All scenarios are fictional and illustrative; figures are visitor-controlled assumptions, not Hyperion client evidence.",
          "Currency is EUR and values are undiscounted; tax, financing and inflation are excluded from this thin slice.",
          "MTBF/MTTR availability is a planning approximation and does not establish functional-safety performance.",
          "Commissioning capacity assumes eight engineering hours per day and forty site-level setup hours per deployment.",
          "Failure injections are transparent multipliers, not probability forecasts or field observations.",
          "The investment budget is compared with modeled upfront hardware, integration, spares and commissioning cost; operating reserve and financing are excluded."
        ],
        "limitations": [
          "This result is not safety certification, legal advice, conformity assessment or an autonomous release decision.",
          "Queueing is a deterministic capacity approximation; it is not a discrete-event simulation of a specific operation.",
          "No real customer, personal, confidential, export-controlled or safety-critical operational data should be entered.",
          "A qualified human owner must validate evidence, operating envelope, compliance duties and consequential commitments."
        ],
        "failureEffects": [
          {
            "type": "supplier_delay",
            "label": "Supplier delay",
            "severityPercent": 75,
            "consequences": [
              "9 weeks added to supplier lead time",
              "6% coordination-load increase"
            ]
          }
        ],
        "sensitivity": [
          {
            "variable": "Hardware cost (−20% / base / +20%)",
            "low": 12720974.34,
            "base": 12470990.34,
            "high": 12221006.34,
            "units": "EUR"
          },
          {
            "variable": "Productive value/hour (−20% / base / +20%)",
            "low": 9359160.28,
            "base": 12470990.34,
            "high": 15582820.41,
            "units": "EUR"
          },
          {
            "variable": "Availability (−5 pts / base / +5 pts)",
            "low": 11687630.34,
            "base": 12470990.34,
            "high": 12579040,
            "units": "EUR"
          }
        ],
        "methodFit": {
          "version": "method-fit-1.0.0",
          "recommendedOperatingModel": "Continuous discovery + systems engineering evidence spine + Kanban for constrained flow.",
          "governanceNote": "Method choice is contextual. Safety, compliance, investment, release and customer commitments remain owned human decisions regardless of agile method.",
          "scores": [
            {
              "id": "continuous-discovery",
              "name": "Continuous discovery",
              "score": 100,
              "fit": "strong",
              "rationale": "Keeps customer evidence, field learning and product assumptions connected to delivery decisions.",
              "condition": "Use evidence cadence and decision records; do not treat interviews as release authority."
            },
            {
              "id": "scrum",
              "name": "Scrum",
              "score": 71,
              "fit": "conditional",
              "rationale": "Supports bounded product increments where uncertainty can be reduced inside a stable team cadence.",
              "condition": "Keep hardware, safety and commissioning gates outside the fiction of a purely software Definition of Done."
            },
            {
              "id": "kanban",
              "name": "Kanban / flow",
              "score": 79,
              "fit": "strong",
              "rationale": "Makes integration, field defects, evidence work and service queues visible as constrained flow.",
              "condition": "Set explicit classes of service and WIP limits for safety, field and supplier work."
            },
            {
              "id": "systems-engineering",
              "name": "Systems engineering",
              "score": 100,
              "fit": "strong",
              "rationale": "Controls interfaces, operating-envelope evidence and verification across hardware, software, AI and operations.",
              "condition": "Use as a product evidence spine, not as a substitute for customer discovery or incremental learning."
            },
            {
              "id": "safe",
              "name": "SAFe",
              "score": 70,
              "fit": "conditional",
              "rationale": "May coordinate multiple teams and portfolio dependencies when scale is real and independently evidenced.",
              "condition": "Do not introduce enterprise-scale ceremony for a small team; Scrum, Kanban and systems interfaces are sufficient."
            }
          ]
        }
      },
      "provenance": {
        "schemaVersion": "provenance-1.1.0",
        "outputClassification": "deterministic",
        "inputClassification": "illustrative",
        "releaseRecommendation": "experiment_only",
        "productSystemDiagnosticVersion": "product-system-diagnostic-1.0.0",
        "configurationBaselineId": "fictional-amr-fleet.configuration-v1",
        "provider": "Hyperion deterministic engine",
        "exactModelIdentifier": null,
        "modelRole": "arithmetic-and-constraint-authority",
        "aiBoundary": {
          "provider": "Mistral AI",
          "exactModels": [
            "mistral-small-2603",
            "mistral-medium-3-5",
            "mistral-large-2512"
          ],
          "usedForThisOutput": false,
          "limitation": "Optional Mistral council commentary is separate model-derived material and cannot alter these deterministic calculations."
        },
        "promptTemplateVersion": "not-applicable-deterministic-output",
        "applicationVersion": "physical-ai-flight-simulator-1.1.0",
        "methodologyVersion": "method-fit-1.0.0",
        "engineVersion": "flight-engine-1.1.0",
        "evidence": [
          {
            "id": "scenario:fictional-amr-supplier-delay",
            "classification": "illustrative",
            "label": "Visitor-controlled fictional scenario assumptions",
            "source": "In-browser Physical AI Product Flight Simulator form"
          },
          {
            "id": "engine:flight-engine-1.1.0",
            "classification": "deterministic",
            "label": "Deterministic economics, availability, capacity, risk and constraint result",
            "source": "Hyperion Physical AI Flight Engine"
          },
          {
            "id": "method:method-fit-1.0.0",
            "classification": "deterministic",
            "label": "Contextual method-fit result",
            "source": "Hyperion Method-Fit decision rules"
          }
        ],
        "assumptions": [
          "All scenarios are fictional and illustrative; figures are visitor-controlled assumptions, not Hyperion client evidence.",
          "Currency is EUR and values are undiscounted; tax, financing and inflation are excluded from this thin slice.",
          "MTBF/MTTR availability is a planning approximation and does not establish functional-safety performance.",
          "Commissioning capacity assumes eight engineering hours per day and forty site-level setup hours per deployment.",
          "Failure injections are transparent multipliers, not probability forecasts or field observations.",
          "The investment budget is compared with modeled upfront hardware, integration, spares and commissioning cost; operating reserve and financing are excluded."
        ],
        "limitations": [
          "This result is not safety certification, legal advice, conformity assessment or an autonomous release decision.",
          "Queueing is a deterministic capacity approximation; it is not a discrete-event simulation of a specific operation.",
          "No real customer, personal, confidential, export-controlled or safety-critical operational data should be entered.",
          "A qualified human owner must validate evidence, operating envelope, compliance duties and consequential commitments."
        ],
        "canonicalInputHash": "ecbff9288e1edc36cefe6a9ce401e4c389b277eeef97219c4afdca1d5ec23996",
        "deterministicResultHash": "5bfb786c097cdfe3c7a65c1d36cdd2bcd2162fe7d16c90f65e0b58ee5c95846e",
        "createdAt": "2026-09-06T00:00:00Z",
        "responsibleHumanDecisionOwner": "Illustrative accountable product owner",
        "responsibleHumanDecisionRole": "Product and operations sponsor",
        "humanDecision": "Proceed to a bounded site pilot subject to the failed release conditions shown below.",
        "reviewDate": "2026-09-30",
        "reviewStatus": "illustrative_unapproved",
        "humanDecisionRecorded": false,
        "expiryStatus": "within_review_period"
      }
    },
    {
      "id": "sensor-degradation",
      "label": "Sensor degradation, severity 75%",
      "scenario": {
        "schemaVersion": "1.0.0",
        "scenarioId": "fictional-amr-sensor-degradation",
        "name": "Sensor degradation, severity 75%",
        "fictional": true,
        "customerProblem": "A distribution operator needs to reduce repetitive pallet movement without making throughput brittle.",
        "buyer": "VP Operations and site general manager",
        "productPromise": "Move priority loads safely within a bounded warehouse envelope while preserving accountable human release authority.",
        "economics": {
          "fleetUnits": 24,
          "deploymentsPerYear": 4,
          "contractYears": 4,
          "revenuePerUnitYear": 18000,
          "productiveValuePerHour": 34,
          "productiveHoursPerUnitYear": 4800,
          "hardwareCostPerUnit": 42000,
          "integrationCostPerUnit": 11000,
          "platformCostPerYear": 95000,
          "dataOpsCostPerYear": 48000,
          "inferenceCostPerUnitMonth": 65,
          "serviceHoursPerUnitYear": 72,
          "serviceLaborRatePerHour": 105,
          "energyCostPerUnitYear": 1600,
          "engineerDayRate": 1250
        },
        "operations": {
          "mtbfHours": 720,
          "mttrHours": 5,
          "commissioningDaysPerUnit": 1.6,
          "supplierLeadTimeWeeks": 14,
          "sparesPercent": 8,
          "replacementPercentPerYear": 4,
          "targetAvailabilityPercent": 97
        },
        "delivery": {
          "availableTeamHoursPerMonth": 520,
          "plannedTeamHoursPerMonth": 330,
          "teamCount": 2,
          "coordinationTeams": 3,
          "roadmapWeeks": 28,
          "deliveryCadenceWeeks": 2
        },
        "investment": {
          "totalBudget": 2400000,
          "productDiscoveryPercent": 12,
          "hardwarePercent": 30,
          "softwarePercent": 20,
          "dataAiPercent": 12,
          "safetyCompliancePercent": 12,
          "fieldOperationsPercent": 14
        },
        "methodContext": {
          "uncertainty": 4,
          "hardwareSoftwareCoupling": 4,
          "safetyCriticality": 4,
          "regulatoryBurden": 3,
          "coordinationScale": 3,
          "fieldLearningNeed": 5
        },
        "operatingEnvelope": {
          "minTemperatureC": 5,
          "maxTemperatureC": 40,
          "maxPayloadKg": 1000,
          "minimumConnectivityPercent": 85,
          "operatorTrainingHours": 8,
          "evidenceCoveragePercent": 72
        },
        "risk": {
          "baseSafetyLikelihood": 2,
          "baseSafetyImpact": 4
        },
        "productization": {
          "stageId": "scale",
          "decisionDoor": "demo_to_operated_product",
          "lensIds": [
            "customer-operator-value",
            "business-model-economics",
            "ai-data-evaluation-hmi",
            "system-architecture",
            "safety-governance-oversight",
            "operations-ecosystem"
          ],
          "configuration": {
            "baselineId": "fictional-amr-fleet.configuration-v1",
            "status": "conditional",
            "changeSummary": "Fictional AMR chassis, sensors, task policy, map and warehouse workflow; rollback rehearsal is missing.",
            "rollbackStatus": "gap",
            "reopeningTriggers": [
              "Reopen after any policy, model, hardware, data, tooling or site configuration change.",
              "Reopen if sustained duty, intervention demand or recovery exceeds the declared assumptions."
            ]
          },
          "humanBaseline": {
            "status": "gap",
            "statement": "Measure manual pallet-movement throughput, errors, waiting and operator burden; no baseline has been observed."
          },
          "productClaim": {
            "status": "conditional",
            "statement": "Fictional hypothesis: move priority pallets across one mapped warehouse shift with accountable recovery."
          },
          "requirement": {
            "status": "conditional",
            "statement": "Define a successful pallet transfer, obstruction recovery and safe-stop acceptance before testing the fleet."
          },
          "architecture": {
            "modelSystems": [
              "task_specific_policy",
              "physics_simulator",
              "deterministic_controller"
            ],
            "worldModelRoles": [
              "scenario_generator"
            ],
            "policyStatus": "conditional",
            "worldModelStatus": "conditional",
            "dataLearningRightsStatus": "gap",
            "edgeCloudBoundaryStatus": "gap"
          },
          "reliabilityExposure": {
            "exposureUnit": "fictional pallet-transfer attempts per fleet-year",
            "attemptedOutcomesPerYear": 240000,
            "successfulOutcomesPerYear": 228000,
            "interventionsPerYear": 4800,
            "recoveryAttemptsPerYear": 3600,
            "successfulRecoveriesPerYear": 2880,
            "longestContinuousDutyHours": 8,
            "operatorMinutesPerDutyHour": 6,
            "toleratedSevereEventsPerYear": 0,
            "severityTolerancesStatus": "unknown",
            "fallbackStatus": "gap"
          },
          "authority": {
            "evaluatedAuthority": "bounded_actuation",
            "intendedAuthority": "bounded_actuation",
            "evaluatedSupervision": "continuous_operator",
            "intendedSupervision": "monitoring_only",
            "interventionAvailable": true,
            "deterministicStop": true,
            "recoveryOwner": "Illustrative warehouse shift supervisor"
          },
          "learning": {
            "memoryStatus": "conditional",
            "taskProgressStatus": "conditional",
            "deadEndDetectionStatus": "gap",
            "autonomousExperienceStatus": "unknown",
            "humanCorrectionsStatus": "conditional",
            "generalizationStatus": "gap",
            "fleetLearningStatus": "unknown"
          },
          "critic": {
            "present": true,
            "version": "fictional-amr-fleet-critic-v1",
            "independent": false,
            "sharedDependenciesDeclared": false,
            "calibrated": false,
            "deterministicChecks": true,
            "humanEscalation": true
          },
          "technologyCurve": {
            "technology": "Fictional warehouse task policy with deterministic motion limits",
            "plateauRisk": "unknown",
            "requiredProductBarStatus": "conditional",
            "expectedCeilingStatus": "unknown",
            "futureCostStatus": "unknown",
            "migrationPathStatus": "gap",
            "vendorExitStatus": "gap"
          },
          "lifecycleReadiness": {
            "manufacturing": "conditional",
            "supply": "conditional",
            "deployment": "conditional",
            "service": "gap",
            "regulatory": "unknown",
            "cybersecurity": "unknown",
            "commercialCommitment": "gap",
            "rollback": "gap",
            "retirement": "unknown"
          },
          "completeness": [
            {
              "dimension": "capability",
              "status": "conditional",
              "gap": "Fictional capability assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "reliability",
              "status": "gap",
              "gap": "Shift-length obstruction and recovery evidence is missing."
            },
            {
              "dimension": "authority",
              "status": "conditional",
              "gap": "Fictional authority assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evaluation",
              "status": "conditional",
              "gap": "Fictional evaluation assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "operations",
              "status": "conditional",
              "gap": "Fictional operations assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "service",
              "status": "gap",
              "gap": "Recovery staffing and spares response have not been tested."
            },
            {
              "dimension": "commercial",
              "status": "conditional",
              "gap": "Fictional commercial assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evidence",
              "status": "conditional",
              "gap": "Fictional evidence assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "scale",
              "status": "gap",
              "gap": "A second site's maps and workflows have not been evaluated."
            }
          ]
        },
        "failures": [
          {
            "type": "sensor_degradation",
            "enabled": true,
            "severityPercent": 75
          },
          {
            "type": "battery_limitation",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "supplier_delay",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "model_drift",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "commissioning_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "customer_change",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "policy_world_model_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "data_rights_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "intervention_unavailable",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "recovery_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "memory_state_loss",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "critic_common_mode",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "edge_cloud_disconnect",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "manufacturing_variance",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "service_overload",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "regulatory_change",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "claim_evidence_mismatch",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "rollback_failure",
            "enabled": false,
            "severityPercent": 50
          }
        ],
        "humanDecision": {
          "owner": "Illustrative accountable product owner",
          "role": "Product and operations sponsor",
          "decision": "Proceed to a bounded site pilot subject to the failed release conditions shown below.",
          "rationale": "The pilot is intended to close operational and integration evidence gaps before a fleet commitment.",
          "reviewDate": "2026-09-30"
        }
      },
      "result": {
        "engineVersion": "flight-engine-1.1.0",
        "scenarioId": "fictional-amr-sensor-degradation",
        "deterministic": true,
        "economics": {
          "upfrontInvestment": 1400640,
          "annualOperatingCost": 454539.2,
          "lifecycleTco": 3218796.8,
          "annualProductiveValue": 3713531.59,
          "annualContractRevenue": 432000,
          "lifecycleNetValue": 11635329.54,
          "paybackMonths": 5.2,
          "costPerProductiveHour": 7.37
        },
        "investment": {
          "totalBudget": 2400000,
          "allocatedTotal": 2400000,
          "allocations": {
            "productDiscovery": 288000,
            "hardware": 720000,
            "software": 480000,
            "dataAi": 288000,
            "safetyCompliance": 288000,
            "fieldOperations": 336000
          },
          "requiredUpfrontInvestment": 1400640,
          "fundingGap": 0,
          "fundingSurplus": 999360,
          "coveragePercent": 171.4
        },
        "operations": {
          "theoreticalAvailabilityPercent": 99.31,
          "effectiveAvailabilityPercent": 94.81,
          "targetAvailabilityPercent": 97,
          "productiveFleetHoursPerYear": 109221.5,
          "serviceHoursPerYear": 2039,
          "replacementUnitsPerYear": 0.96
        },
        "delivery": {
          "capacityUtilizationPercent": 35.5,
          "commissioningHoursPerMonth": 38.9,
          "queueDelayWeeks": 0,
          "forecastReleaseWeeks": 28,
          "supplierLeadTimeWeeks": 14
        },
        "risk": {
          "score": 52.5,
          "band": "elevated",
          "evidenceGapPercent": 28
        },
        "allocationTotalPercent": 100,
        "modeledExperimentSignal": "hold",
        "releaseRecommendation": "experiment_only",
        "productSystemDiagnostic": {
          "version": "product-system-diagnostic-1.0.0",
          "source": "visitor_supplied_fictional_assumptions",
          "gate": "scale",
          "decisionDoor": "demo_to_operated_product",
          "lensIds": [
            "customer-operator-value",
            "business-model-economics",
            "ai-data-evaluation-hmi",
            "system-architecture",
            "safety-governance-oversight",
            "operations-ecosystem"
          ],
          "reliabilityExposure": {
            "status": "declared_gap",
            "exposureUnit": "fictional pallet-transfer attempts per fleet-year",
            "successRatePercent": 95,
            "interventionRatePerThousandOutcomes": 20,
            "recoveryRatePercent": 80,
            "longestContinuousDutyHours": 8,
            "operatorMinutesPerDutyHour": 6,
            "costPerSuccessfulOutcome": 3.53
          },
          "completeness": [
            {
              "dimension": "capability",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional capability assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "reliability",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "Shift-length obstruction and recovery evidence is missing."
            },
            {
              "dimension": "authority",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional authority assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evaluation",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional evaluation assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "operations",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional operations assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "service",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "Recovery staffing and spares response have not been tested."
            },
            {
              "dimension": "commercial",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional commercial assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evidence",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional evidence assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "scale",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "A second site's maps and workflows have not been evaluated."
            }
          ],
          "evidenceGaps": [
            "Public visitor inputs are fictional assumptions, not release evidence; independent validation remains required.",
            "Evaluated and intended authority, supervision, intervention and stop controls are not aligned.",
            "Critic independence or shared-dependency disclosure is unresolved.",
            "reliability completeness is declared gap.",
            "service completeness is declared gap.",
            "scale completeness is declared gap."
          ],
          "requirementGaps": [
            "Define and evidence the human baseline for useful work, burden, quality and cost.",
            "Bound the product claim to one configuration, intended use and operating envelope.",
            "Translate the claim into verifiable product and system requirements.",
            "Resolve data provenance, IP and learning rights for the intended lifecycle.",
            "Specify memory, long-horizon task state and stale-state behaviour.",
            "Specify dead-end detection and accountable recovery escalation.",
            "Define generalization slices and the evidence required for each slice."
          ],
          "authorityMap": {
            "assessment": "declared_gap",
            "evaluatedAuthority": "bounded_actuation",
            "intendedAuthority": "bounded_actuation",
            "evaluatedSupervision": "continuous_operator",
            "intendedSupervision": "monitoring_only",
            "authorityGap": false,
            "supervisionGap": true,
            "interventionAvailable": true,
            "deterministicStop": true,
            "recoveryOwner": "Illustrative warehouse shift supervisor"
          },
          "critic": {
            "assessment": "declared_gap",
            "present": true,
            "independent": false,
            "sharedDependenciesDeclared": false,
            "calibrated": false,
            "deterministicChecks": true,
            "humanEscalation": true
          },
          "technologyCurve": {
            "assessment": "declared_gap",
            "technology": "Fictional warehouse task policy with deterministic motion limits",
            "plateauRisk": "unknown",
            "openDecisions": [
              "Required product bar is conditional.",
              "Expected ceiling is unknown.",
              "Future cost is unknown.",
              "Migration path is gap.",
              "Vendor exit is gap."
            ]
          },
          "capabilityComplexityDelta": {
            "capabilityAssessment": "requires_evidence",
            "complexityRisks": [
              "Edge/cloud boundary is gap.",
              "Data and learning rights are gap.",
              "The declared critic is not independent from the system it evaluates.",
              "manufacturing readiness is conditional.",
              "supply readiness is conditional.",
              "deployment readiness is conditional.",
              "service readiness is gap.",
              "regulatory readiness is unknown.",
              "cybersecurity readiness is unknown.",
              "commercialCommitment readiness is gap.",
              "rollback readiness is gap.",
              "retirement readiness is unknown."
            ],
            "netDecision": "hold"
          },
          "configurationImpact": [
            "Fictional AMR chassis, sensors, task policy, map and warehouse workflow; rollback rehearsal is missing.",
            "Validate the declared model-system set: task_specific_policy, physics_simulator, deterministic_controller.",
            "Revalidate world-model roles: scenario_generator.",
            "Rollback is not supported by evidence for the declared configuration."
          ],
          "reopeningConditions": [
            "Reopen after any policy, model, hardware, data, tooling or site configuration change.",
            "Reopen if sustained duty, intervention demand or recovery exceeds the declared assumptions.",
            "Reopen when sensing degradation changes the validated operating envelope or fallback behaviour.",
            "Reopen before any change to intended use, configuration, operating envelope, authority or commercial commitment.",
            "Reopen when evidence expires, is corrected or no longer matches the release configuration."
          ],
          "pdrScope": [
            "Resolve the demo to operated product decision at the scale gate.",
            "Public visitor inputs are fictional assumptions, not release evidence; independent validation remains required.",
            "Evaluated and intended authority, supervision, intervention and stop controls are not aligned.",
            "Critic independence or shared-dependency disclosure is unresolved.",
            "reliability completeness is declared gap.",
            "Define and evidence the human baseline for useful work, burden, quality and cost.",
            "Bound the product claim to one configuration, intended use and operating envelope.",
            "Translate the claim into verifiable product and system requirements.",
            "Required product bar is conditional.",
            "Expected ceiling is unknown."
          ],
          "releaseCase": {
            "recommendation": "experiment_only",
            "boundary": "An Integrated Product Release Case is the accountable product recommendation for one configuration, use, operating envelope and commitment. A release-ready result binds current evidence and product completeness to that configuration, envelope, claim set, intended Human–Machine Authority and operating supervision. It is not a safety case, certification, conformity assessment or legal opinion.",
            "rationale": "This public simulator evaluates fictional, visitor-supplied assumptions. It cannot establish release-grade evidence, specialist acceptance or authority-matched field performance."
          }
        },
        "constraints": [
          {
            "id": "availability",
            "label": "Fleet availability",
            "status": "fail",
            "observed": "94.8%",
            "threshold": "≥ 97%",
            "consequence": "A missed availability gate changes customer value, service load and the release case."
          },
          {
            "id": "capacity",
            "label": "Delivery and commissioning capacity",
            "status": "pass",
            "observed": "35.5%",
            "threshold": "≤ 80% preferred; >95% blocks",
            "consequence": "Overload creates queues across roadmap work, commissioning and field response."
          },
          {
            "id": "economics",
            "label": "Lifecycle customer-value case",
            "status": "pass",
            "observed": "€11,635,330 net; 5.2 months",
            "threshold": "Positive lifecycle net value inside contract term",
            "consequence": "A negative or late-return case requires scope, price, reliability or operating-model change."
          },
          {
            "id": "risk",
            "label": "Combined safety and evidence risk",
            "status": "warning",
            "observed": "52.5/100 · elevated",
            "threshold": "≤35 preferred; >55 blocks",
            "consequence": "Risk is a screening signal only; a named safety authority owns acceptance."
          },
          {
            "id": "evidence",
            "label": "Operating-envelope evidence",
            "status": "warning",
            "observed": "72%",
            "threshold": "≥80% preferred; <60% blocks",
            "consequence": "Unverified envelope claims cannot support a scaled release commitment."
          },
          {
            "id": "allocation",
            "label": "Investment allocation",
            "status": "pass",
            "observed": "100%",
            "threshold": "100%",
            "consequence": "Unallocated or double-counted investment obscures real trade-offs."
          },
          {
            "id": "budget-coverage",
            "label": "Upfront funding coverage",
            "status": "pass",
            "observed": "171.4% · €999,360 headroom",
            "threshold": "≥100% of modeled upfront investment; 90–99.9% conditional",
            "consequence": "An unfunded hardware, integration, spares or commissioning requirement invalidates the release plan."
          },
          {
            "id": "human-owner",
            "label": "Accountable human decision",
            "status": "pass",
            "observed": "Illustrative accountable product owner · Product and operations sponsor",
            "threshold": "Named owner, role and decision",
            "consequence": "No model or simulator can own a safety, release, investment or customer commitment."
          },
          {
            "id": "reliability-exposure",
            "label": "Reliability and exposure profile",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Declared denominator, sustained-duty, intervention, recovery, fallback and severity-tolerance basis",
            "consequence": "Architecture and release decisions cannot precede an explicit reliability and exposure profile."
          },
          {
            "id": "product-completeness",
            "label": "Product completeness",
            "status": "fail",
            "observed": "3 of 9 dimensions unresolved",
            "threshold": "All nine dimensions assessed; declarations still require evidence",
            "consequence": "Capability alone cannot waive reliability, authority, evaluation, operations, service, commercial, evidence or scale gaps."
          },
          {
            "id": "authority-match",
            "label": "Authority-matched operation",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Evaluated and intended authority/supervision aligned with intervention, recovery and stop controls",
            "consequence": "Evidence collected under lower authority or stronger supervision cannot silently justify intended operation."
          },
          {
            "id": "critic-independence",
            "label": "Agent–simulator–critic independence",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Versioned critic, disclosed dependencies, calibration, deterministic checks and human escalation",
            "consequence": "An evaluator with unresolved common-mode dependencies cannot establish product readiness."
          },
          {
            "id": "integrated-release-case",
            "label": "Integrated Product Release Case",
            "status": "warning",
            "observed": "experiment only",
            "threshold": "Release-grade, configuration-bound evidence and named specialist decisions",
            "consequence": "This public simulator can recommend a bounded next experiment, never release readiness."
          }
        ],
        "formulas": [
          {
            "id": "budget-coverage",
            "label": "Upfront funding coverage",
            "expression": "total investment budget ÷ modeled upfront investment",
            "units": "% funded"
          },
          {
            "id": "availability",
            "label": "Theoretical availability",
            "expression": "MTBF ÷ (MTBF + MTTR), then explicit failure penalties",
            "units": "% available time"
          },
          {
            "id": "upfront",
            "label": "Upfront investment",
            "expression": "units × (hardware + integration) + spares + commissioning days × day rate",
            "units": "EUR"
          },
          {
            "id": "annual-opex",
            "label": "Annual operating cost",
            "expression": "platform + data/AI ops + inference + energy + service labour + replacements",
            "units": "EUR/year"
          },
          {
            "id": "value",
            "label": "Annual productive value",
            "expression": "units × productive hours × effective availability × value/hour × injected modifiers",
            "units": "EUR/year"
          },
          {
            "id": "capacity",
            "label": "Capacity utilization",
            "expression": "(planned work + commissioning load) ÷ (team hours × teams)",
            "units": "% monthly capacity"
          },
          {
            "id": "risk",
            "label": "Risk screening score",
            "expression": "likelihood × impact + evidence gap + explicit failure increments",
            "units": "0–100 screening index"
          }
        ],
        "assumptions": [
          "All scenarios are fictional and illustrative; figures are visitor-controlled assumptions, not Hyperion client evidence.",
          "Currency is EUR and values are undiscounted; tax, financing and inflation are excluded from this thin slice.",
          "MTBF/MTTR availability is a planning approximation and does not establish functional-safety performance.",
          "Commissioning capacity assumes eight engineering hours per day and forty site-level setup hours per deployment.",
          "Failure injections are transparent multipliers, not probability forecasts or field observations.",
          "The investment budget is compared with modeled upfront hardware, integration, spares and commissioning cost; operating reserve and financing are excluded."
        ],
        "limitations": [
          "This result is not safety certification, legal advice, conformity assessment or an autonomous release decision.",
          "Queueing is a deterministic capacity approximation; it is not a discrete-event simulation of a specific operation.",
          "No real customer, personal, confidential, export-controlled or safety-critical operational data should be entered.",
          "A qualified human owner must validate evidence, operating envelope, compliance duties and consequential commitments."
        ],
        "failureEffects": [
          {
            "type": "sensor_degradation",
            "label": "Sensor degradation",
            "severityPercent": 75,
            "consequences": [
              "4.5 availability points removed",
              "18% service-load increase",
              "13.5 risk points added"
            ]
          }
        ],
        "sensitivity": [
          {
            "variable": "Hardware cost (−20% / base / +20%)",
            "low": 11885313.54,
            "base": 11635329.54,
            "high": 11385345.54,
            "units": "EUR"
          },
          {
            "variable": "Productive value/hour (−20% / base / +20%)",
            "low": 8664504.28,
            "base": 11635329.54,
            "high": 14606154.81,
            "units": "EUR"
          },
          {
            "variable": "Availability (−5 pts / base / +5 pts)",
            "low": 10851969.54,
            "base": 11635329.54,
            "high": 12418689.54,
            "units": "EUR"
          }
        ],
        "methodFit": {
          "version": "method-fit-1.0.0",
          "recommendedOperatingModel": "Continuous discovery + systems engineering evidence spine + Kanban for constrained flow.",
          "governanceNote": "Method choice is contextual. Safety, compliance, investment, release and customer commitments remain owned human decisions regardless of agile method.",
          "scores": [
            {
              "id": "continuous-discovery",
              "name": "Continuous discovery",
              "score": 100,
              "fit": "strong",
              "rationale": "Keeps customer evidence, field learning and product assumptions connected to delivery decisions.",
              "condition": "Use evidence cadence and decision records; do not treat interviews as release authority."
            },
            {
              "id": "scrum",
              "name": "Scrum",
              "score": 71,
              "fit": "conditional",
              "rationale": "Supports bounded product increments where uncertainty can be reduced inside a stable team cadence.",
              "condition": "Keep hardware, safety and commissioning gates outside the fiction of a purely software Definition of Done."
            },
            {
              "id": "kanban",
              "name": "Kanban / flow",
              "score": 79,
              "fit": "strong",
              "rationale": "Makes integration, field defects, evidence work and service queues visible as constrained flow.",
              "condition": "Set explicit classes of service and WIP limits for safety, field and supplier work."
            },
            {
              "id": "systems-engineering",
              "name": "Systems engineering",
              "score": 100,
              "fit": "strong",
              "rationale": "Controls interfaces, operating-envelope evidence and verification across hardware, software, AI and operations.",
              "condition": "Use as a product evidence spine, not as a substitute for customer discovery or incremental learning."
            },
            {
              "id": "safe",
              "name": "SAFe",
              "score": 70,
              "fit": "conditional",
              "rationale": "May coordinate multiple teams and portfolio dependencies when scale is real and independently evidenced.",
              "condition": "Do not introduce enterprise-scale ceremony for a small team; Scrum, Kanban and systems interfaces are sufficient."
            }
          ]
        }
      },
      "provenance": {
        "schemaVersion": "provenance-1.1.0",
        "outputClassification": "deterministic",
        "inputClassification": "illustrative",
        "releaseRecommendation": "experiment_only",
        "productSystemDiagnosticVersion": "product-system-diagnostic-1.0.0",
        "configurationBaselineId": "fictional-amr-fleet.configuration-v1",
        "provider": "Hyperion deterministic engine",
        "exactModelIdentifier": null,
        "modelRole": "arithmetic-and-constraint-authority",
        "aiBoundary": {
          "provider": "Mistral AI",
          "exactModels": [
            "mistral-small-2603",
            "mistral-medium-3-5",
            "mistral-large-2512"
          ],
          "usedForThisOutput": false,
          "limitation": "Optional Mistral council commentary is separate model-derived material and cannot alter these deterministic calculations."
        },
        "promptTemplateVersion": "not-applicable-deterministic-output",
        "applicationVersion": "physical-ai-flight-simulator-1.1.0",
        "methodologyVersion": "method-fit-1.0.0",
        "engineVersion": "flight-engine-1.1.0",
        "evidence": [
          {
            "id": "scenario:fictional-amr-sensor-degradation",
            "classification": "illustrative",
            "label": "Visitor-controlled fictional scenario assumptions",
            "source": "In-browser Physical AI Product Flight Simulator form"
          },
          {
            "id": "engine:flight-engine-1.1.0",
            "classification": "deterministic",
            "label": "Deterministic economics, availability, capacity, risk and constraint result",
            "source": "Hyperion Physical AI Flight Engine"
          },
          {
            "id": "method:method-fit-1.0.0",
            "classification": "deterministic",
            "label": "Contextual method-fit result",
            "source": "Hyperion Method-Fit decision rules"
          }
        ],
        "assumptions": [
          "All scenarios are fictional and illustrative; figures are visitor-controlled assumptions, not Hyperion client evidence.",
          "Currency is EUR and values are undiscounted; tax, financing and inflation are excluded from this thin slice.",
          "MTBF/MTTR availability is a planning approximation and does not establish functional-safety performance.",
          "Commissioning capacity assumes eight engineering hours per day and forty site-level setup hours per deployment.",
          "Failure injections are transparent multipliers, not probability forecasts or field observations.",
          "The investment budget is compared with modeled upfront hardware, integration, spares and commissioning cost; operating reserve and financing are excluded."
        ],
        "limitations": [
          "This result is not safety certification, legal advice, conformity assessment or an autonomous release decision.",
          "Queueing is a deterministic capacity approximation; it is not a discrete-event simulation of a specific operation.",
          "No real customer, personal, confidential, export-controlled or safety-critical operational data should be entered.",
          "A qualified human owner must validate evidence, operating envelope, compliance duties and consequential commitments."
        ],
        "canonicalInputHash": "f50c2736e148eb043defc9bdee2505094a4d773dd360692b58a30e9904c44e33",
        "deterministicResultHash": "61070cbb36d6d8587c7aede184b1befeb1015f297de49fabf4a5f3584c49bed9",
        "createdAt": "2026-09-06T00:00:00Z",
        "responsibleHumanDecisionOwner": "Illustrative accountable product owner",
        "responsibleHumanDecisionRole": "Product and operations sponsor",
        "humanDecision": "Proceed to a bounded site pilot subject to the failed release conditions shown below.",
        "reviewDate": "2026-09-30",
        "reviewStatus": "illustrative_unapproved",
        "humanDecisionRecorded": false,
        "expiryStatus": "within_review_period"
      }
    },
    {
      "id": "combined-service-recovery",
      "label": "Service overload and recovery failure, each 75%",
      "scenario": {
        "schemaVersion": "1.0.0",
        "scenarioId": "fictional-amr-combined-service-recovery",
        "name": "Service overload and recovery failure, each 75%",
        "fictional": true,
        "customerProblem": "A distribution operator needs to reduce repetitive pallet movement without making throughput brittle.",
        "buyer": "VP Operations and site general manager",
        "productPromise": "Move priority loads safely within a bounded warehouse envelope while preserving accountable human release authority.",
        "economics": {
          "fleetUnits": 24,
          "deploymentsPerYear": 4,
          "contractYears": 4,
          "revenuePerUnitYear": 18000,
          "productiveValuePerHour": 34,
          "productiveHoursPerUnitYear": 4800,
          "hardwareCostPerUnit": 42000,
          "integrationCostPerUnit": 11000,
          "platformCostPerYear": 95000,
          "dataOpsCostPerYear": 48000,
          "inferenceCostPerUnitMonth": 65,
          "serviceHoursPerUnitYear": 72,
          "serviceLaborRatePerHour": 105,
          "energyCostPerUnitYear": 1600,
          "engineerDayRate": 1250
        },
        "operations": {
          "mtbfHours": 720,
          "mttrHours": 5,
          "commissioningDaysPerUnit": 1.6,
          "supplierLeadTimeWeeks": 14,
          "sparesPercent": 8,
          "replacementPercentPerYear": 4,
          "targetAvailabilityPercent": 97
        },
        "delivery": {
          "availableTeamHoursPerMonth": 520,
          "plannedTeamHoursPerMonth": 330,
          "teamCount": 2,
          "coordinationTeams": 3,
          "roadmapWeeks": 28,
          "deliveryCadenceWeeks": 2
        },
        "investment": {
          "totalBudget": 2400000,
          "productDiscoveryPercent": 12,
          "hardwarePercent": 30,
          "softwarePercent": 20,
          "dataAiPercent": 12,
          "safetyCompliancePercent": 12,
          "fieldOperationsPercent": 14
        },
        "methodContext": {
          "uncertainty": 4,
          "hardwareSoftwareCoupling": 4,
          "safetyCriticality": 4,
          "regulatoryBurden": 3,
          "coordinationScale": 3,
          "fieldLearningNeed": 5
        },
        "operatingEnvelope": {
          "minTemperatureC": 5,
          "maxTemperatureC": 40,
          "maxPayloadKg": 1000,
          "minimumConnectivityPercent": 85,
          "operatorTrainingHours": 8,
          "evidenceCoveragePercent": 72
        },
        "risk": {
          "baseSafetyLikelihood": 2,
          "baseSafetyImpact": 4
        },
        "productization": {
          "stageId": "scale",
          "decisionDoor": "demo_to_operated_product",
          "lensIds": [
            "customer-operator-value",
            "business-model-economics",
            "ai-data-evaluation-hmi",
            "system-architecture",
            "safety-governance-oversight",
            "operations-ecosystem"
          ],
          "configuration": {
            "baselineId": "fictional-amr-fleet.configuration-v1",
            "status": "conditional",
            "changeSummary": "Fictional AMR chassis, sensors, task policy, map and warehouse workflow; rollback rehearsal is missing.",
            "rollbackStatus": "gap",
            "reopeningTriggers": [
              "Reopen after any policy, model, hardware, data, tooling or site configuration change.",
              "Reopen if sustained duty, intervention demand or recovery exceeds the declared assumptions."
            ]
          },
          "humanBaseline": {
            "status": "gap",
            "statement": "Measure manual pallet-movement throughput, errors, waiting and operator burden; no baseline has been observed."
          },
          "productClaim": {
            "status": "conditional",
            "statement": "Fictional hypothesis: move priority pallets across one mapped warehouse shift with accountable recovery."
          },
          "requirement": {
            "status": "conditional",
            "statement": "Define a successful pallet transfer, obstruction recovery and safe-stop acceptance before testing the fleet."
          },
          "architecture": {
            "modelSystems": [
              "task_specific_policy",
              "physics_simulator",
              "deterministic_controller"
            ],
            "worldModelRoles": [
              "scenario_generator"
            ],
            "policyStatus": "conditional",
            "worldModelStatus": "conditional",
            "dataLearningRightsStatus": "gap",
            "edgeCloudBoundaryStatus": "gap"
          },
          "reliabilityExposure": {
            "exposureUnit": "fictional pallet-transfer attempts per fleet-year",
            "attemptedOutcomesPerYear": 240000,
            "successfulOutcomesPerYear": 228000,
            "interventionsPerYear": 4800,
            "recoveryAttemptsPerYear": 3600,
            "successfulRecoveriesPerYear": 2880,
            "longestContinuousDutyHours": 8,
            "operatorMinutesPerDutyHour": 6,
            "toleratedSevereEventsPerYear": 0,
            "severityTolerancesStatus": "unknown",
            "fallbackStatus": "gap"
          },
          "authority": {
            "evaluatedAuthority": "bounded_actuation",
            "intendedAuthority": "bounded_actuation",
            "evaluatedSupervision": "continuous_operator",
            "intendedSupervision": "monitoring_only",
            "interventionAvailable": true,
            "deterministicStop": true,
            "recoveryOwner": "Illustrative warehouse shift supervisor"
          },
          "learning": {
            "memoryStatus": "conditional",
            "taskProgressStatus": "conditional",
            "deadEndDetectionStatus": "gap",
            "autonomousExperienceStatus": "unknown",
            "humanCorrectionsStatus": "conditional",
            "generalizationStatus": "gap",
            "fleetLearningStatus": "unknown"
          },
          "critic": {
            "present": true,
            "version": "fictional-amr-fleet-critic-v1",
            "independent": false,
            "sharedDependenciesDeclared": false,
            "calibrated": false,
            "deterministicChecks": true,
            "humanEscalation": true
          },
          "technologyCurve": {
            "technology": "Fictional warehouse task policy with deterministic motion limits",
            "plateauRisk": "unknown",
            "requiredProductBarStatus": "conditional",
            "expectedCeilingStatus": "unknown",
            "futureCostStatus": "unknown",
            "migrationPathStatus": "gap",
            "vendorExitStatus": "gap"
          },
          "lifecycleReadiness": {
            "manufacturing": "conditional",
            "supply": "conditional",
            "deployment": "conditional",
            "service": "gap",
            "regulatory": "unknown",
            "cybersecurity": "unknown",
            "commercialCommitment": "gap",
            "rollback": "gap",
            "retirement": "unknown"
          },
          "completeness": [
            {
              "dimension": "capability",
              "status": "conditional",
              "gap": "Fictional capability assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "reliability",
              "status": "gap",
              "gap": "Shift-length obstruction and recovery evidence is missing."
            },
            {
              "dimension": "authority",
              "status": "conditional",
              "gap": "Fictional authority assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evaluation",
              "status": "conditional",
              "gap": "Fictional evaluation assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "operations",
              "status": "conditional",
              "gap": "Fictional operations assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "service",
              "status": "gap",
              "gap": "Recovery staffing and spares response have not been tested."
            },
            {
              "dimension": "commercial",
              "status": "conditional",
              "gap": "Fictional commercial assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evidence",
              "status": "conditional",
              "gap": "Fictional evidence assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "scale",
              "status": "gap",
              "gap": "A second site's maps and workflows have not been evaluated."
            }
          ]
        },
        "failures": [
          {
            "type": "sensor_degradation",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "battery_limitation",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "supplier_delay",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "model_drift",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "commissioning_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "customer_change",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "policy_world_model_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "data_rights_failure",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "intervention_unavailable",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "recovery_failure",
            "enabled": true,
            "severityPercent": 75
          },
          {
            "type": "memory_state_loss",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "critic_common_mode",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "edge_cloud_disconnect",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "manufacturing_variance",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "service_overload",
            "enabled": true,
            "severityPercent": 75
          },
          {
            "type": "regulatory_change",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "claim_evidence_mismatch",
            "enabled": false,
            "severityPercent": 50
          },
          {
            "type": "rollback_failure",
            "enabled": false,
            "severityPercent": 50
          }
        ],
        "humanDecision": {
          "owner": "Illustrative accountable product owner",
          "role": "Product and operations sponsor",
          "decision": "Proceed to a bounded site pilot subject to the failed release conditions shown below.",
          "rationale": "The pilot is intended to close operational and integration evidence gaps before a fleet commitment.",
          "reviewDate": "2026-09-30"
        }
      },
      "result": {
        "engineVersion": "flight-engine-1.1.0",
        "scenarioId": "fictional-amr-combined-service-recovery",
        "deterministic": true,
        "economics": {
          "upfrontInvestment": 1400640,
          "annualOperatingCost": 530744,
          "lifecycleTco": 3523616,
          "annualProductiveValue": 3478523.59,
          "annualContractRevenue": 432000,
          "lifecycleNetValue": 10390478.34,
          "paybackMonths": 5.7,
          "costPerProductiveHour": 8.61
        },
        "investment": {
          "totalBudget": 2400000,
          "allocatedTotal": 2400000,
          "allocations": {
            "productDiscovery": 288000,
            "hardware": 720000,
            "software": 480000,
            "dataAi": 288000,
            "safetyCompliance": 288000,
            "fieldOperations": 336000
          },
          "requiredUpfrontInvestment": 1400640,
          "fundingGap": 0,
          "fundingSurplus": 999360,
          "coveragePercent": 171.4
        },
        "operations": {
          "theoreticalAvailabilityPercent": 99.31,
          "effectiveAvailabilityPercent": 88.81,
          "targetAvailabilityPercent": 97,
          "productiveFleetHoursPerYear": 102309.5,
          "serviceHoursPerYear": 2764.8,
          "replacementUnitsPerYear": 0.96
        },
        "delivery": {
          "capacityUtilizationPercent": 39,
          "commissioningHoursPerMonth": 38.9,
          "queueDelayWeeks": 0,
          "forecastReleaseWeeks": 28,
          "supplierLeadTimeWeeks": 14
        },
        "risk": {
          "score": 64.5,
          "band": "high",
          "evidenceGapPercent": 28
        },
        "allocationTotalPercent": 100,
        "modeledExperimentSignal": "hold",
        "releaseRecommendation": "experiment_only",
        "productSystemDiagnostic": {
          "version": "product-system-diagnostic-1.0.0",
          "source": "visitor_supplied_fictional_assumptions",
          "gate": "scale",
          "decisionDoor": "demo_to_operated_product",
          "lensIds": [
            "customer-operator-value",
            "business-model-economics",
            "ai-data-evaluation-hmi",
            "system-architecture",
            "safety-governance-oversight",
            "operations-ecosystem"
          ],
          "reliabilityExposure": {
            "status": "declared_gap",
            "exposureUnit": "fictional pallet-transfer attempts per fleet-year",
            "successRatePercent": 95,
            "interventionRatePerThousandOutcomes": 20,
            "recoveryRatePercent": 80,
            "longestContinuousDutyHours": 8,
            "operatorMinutesPerDutyHour": 6,
            "costPerSuccessfulOutcome": 3.86
          },
          "completeness": [
            {
              "dimension": "capability",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional capability assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "reliability",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "Shift-length obstruction and recovery evidence is missing."
            },
            {
              "dimension": "authority",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional authority assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evaluation",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional evaluation assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "operations",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional operations assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "service",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "Recovery staffing and spares response have not been tested."
            },
            {
              "dimension": "commercial",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional commercial assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "evidence",
              "declaredStatus": "conditional",
              "assessment": "requires_evidence",
              "gap": "Fictional evidence assumption; configuration-bound evidence is absent."
            },
            {
              "dimension": "scale",
              "declaredStatus": "gap",
              "assessment": "declared_gap",
              "gap": "A second site's maps and workflows have not been evaluated."
            }
          ],
          "evidenceGaps": [
            "Public visitor inputs are fictional assumptions, not release evidence; independent validation remains required.",
            "Evaluated and intended authority, supervision, intervention and stop controls are not aligned.",
            "Critic independence or shared-dependency disclosure is unresolved.",
            "reliability completeness is declared gap.",
            "service completeness is declared gap.",
            "scale completeness is declared gap."
          ],
          "requirementGaps": [
            "Define and evidence the human baseline for useful work, burden, quality and cost.",
            "Bound the product claim to one configuration, intended use and operating envelope.",
            "Translate the claim into verifiable product and system requirements.",
            "Resolve data provenance, IP and learning rights for the intended lifecycle.",
            "Specify memory, long-horizon task state and stale-state behaviour.",
            "Specify dead-end detection and accountable recovery escalation.",
            "Define generalization slices and the evidence required for each slice."
          ],
          "authorityMap": {
            "assessment": "declared_gap",
            "evaluatedAuthority": "bounded_actuation",
            "intendedAuthority": "bounded_actuation",
            "evaluatedSupervision": "continuous_operator",
            "intendedSupervision": "monitoring_only",
            "authorityGap": false,
            "supervisionGap": true,
            "interventionAvailable": true,
            "deterministicStop": true,
            "recoveryOwner": "Illustrative warehouse shift supervisor"
          },
          "critic": {
            "assessment": "declared_gap",
            "present": true,
            "independent": false,
            "sharedDependenciesDeclared": false,
            "calibrated": false,
            "deterministicChecks": true,
            "humanEscalation": true
          },
          "technologyCurve": {
            "assessment": "declared_gap",
            "technology": "Fictional warehouse task policy with deterministic motion limits",
            "plateauRisk": "unknown",
            "openDecisions": [
              "Required product bar is conditional.",
              "Expected ceiling is unknown.",
              "Future cost is unknown.",
              "Migration path is gap.",
              "Vendor exit is gap."
            ]
          },
          "capabilityComplexityDelta": {
            "capabilityAssessment": "requires_evidence",
            "complexityRisks": [
              "Edge/cloud boundary is gap.",
              "Data and learning rights are gap.",
              "The declared critic is not independent from the system it evaluates.",
              "manufacturing readiness is conditional.",
              "supply readiness is conditional.",
              "deployment readiness is conditional.",
              "service readiness is gap.",
              "regulatory readiness is unknown.",
              "cybersecurity readiness is unknown.",
              "commercialCommitment readiness is gap.",
              "rollback readiness is gap.",
              "retirement readiness is unknown."
            ],
            "netDecision": "hold"
          },
          "configurationImpact": [
            "Fictional AMR chassis, sensors, task policy, map and warehouse workflow; rollback rehearsal is missing.",
            "Validate the declared model-system set: task_specific_policy, physics_simulator, deterministic_controller.",
            "Revalidate world-model roles: scenario_generator.",
            "Rollback is not supported by evidence for the declared configuration."
          ],
          "reopeningConditions": [
            "Reopen after any policy, model, hardware, data, tooling or site configuration change.",
            "Reopen if sustained duty, intervention demand or recovery exceeds the declared assumptions.",
            "Reopen when recovery effectiveness falls below the declared exposure tolerance.",
            "Reopen when service demand exceeds the support model or customer commitment.",
            "Reopen before any change to intended use, configuration, operating envelope, authority or commercial commitment.",
            "Reopen when evidence expires, is corrected or no longer matches the release configuration."
          ],
          "pdrScope": [
            "Resolve the demo to operated product decision at the scale gate.",
            "Public visitor inputs are fictional assumptions, not release evidence; independent validation remains required.",
            "Evaluated and intended authority, supervision, intervention and stop controls are not aligned.",
            "Critic independence or shared-dependency disclosure is unresolved.",
            "reliability completeness is declared gap.",
            "Define and evidence the human baseline for useful work, burden, quality and cost.",
            "Bound the product claim to one configuration, intended use and operating envelope.",
            "Translate the claim into verifiable product and system requirements.",
            "Required product bar is conditional.",
            "Expected ceiling is unknown."
          ],
          "releaseCase": {
            "recommendation": "experiment_only",
            "boundary": "An Integrated Product Release Case is the accountable product recommendation for one configuration, use, operating envelope and commitment. A release-ready result binds current evidence and product completeness to that configuration, envelope, claim set, intended Human–Machine Authority and operating supervision. It is not a safety case, certification, conformity assessment or legal opinion.",
            "rationale": "This public simulator evaluates fictional, visitor-supplied assumptions. It cannot establish release-grade evidence, specialist acceptance or authority-matched field performance."
          }
        },
        "constraints": [
          {
            "id": "availability",
            "label": "Fleet availability",
            "status": "fail",
            "observed": "88.8%",
            "threshold": "≥ 97%",
            "consequence": "A missed availability gate changes customer value, service load and the release case."
          },
          {
            "id": "capacity",
            "label": "Delivery and commissioning capacity",
            "status": "pass",
            "observed": "39%",
            "threshold": "≤ 80% preferred; >95% blocks",
            "consequence": "Overload creates queues across roadmap work, commissioning and field response."
          },
          {
            "id": "economics",
            "label": "Lifecycle customer-value case",
            "status": "pass",
            "observed": "€10,390,478 net; 5.7 months",
            "threshold": "Positive lifecycle net value inside contract term",
            "consequence": "A negative or late-return case requires scope, price, reliability or operating-model change."
          },
          {
            "id": "risk",
            "label": "Combined safety and evidence risk",
            "status": "fail",
            "observed": "64.5/100 · high",
            "threshold": "≤35 preferred; >55 blocks",
            "consequence": "Risk is a screening signal only; a named safety authority owns acceptance."
          },
          {
            "id": "evidence",
            "label": "Operating-envelope evidence",
            "status": "warning",
            "observed": "72%",
            "threshold": "≥80% preferred; <60% blocks",
            "consequence": "Unverified envelope claims cannot support a scaled release commitment."
          },
          {
            "id": "allocation",
            "label": "Investment allocation",
            "status": "pass",
            "observed": "100%",
            "threshold": "100%",
            "consequence": "Unallocated or double-counted investment obscures real trade-offs."
          },
          {
            "id": "budget-coverage",
            "label": "Upfront funding coverage",
            "status": "pass",
            "observed": "171.4% · €999,360 headroom",
            "threshold": "≥100% of modeled upfront investment; 90–99.9% conditional",
            "consequence": "An unfunded hardware, integration, spares or commissioning requirement invalidates the release plan."
          },
          {
            "id": "human-owner",
            "label": "Accountable human decision",
            "status": "pass",
            "observed": "Illustrative accountable product owner · Product and operations sponsor",
            "threshold": "Named owner, role and decision",
            "consequence": "No model or simulator can own a safety, release, investment or customer commitment."
          },
          {
            "id": "reliability-exposure",
            "label": "Reliability and exposure profile",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Declared denominator, sustained-duty, intervention, recovery, fallback and severity-tolerance basis",
            "consequence": "Architecture and release decisions cannot precede an explicit reliability and exposure profile."
          },
          {
            "id": "product-completeness",
            "label": "Product completeness",
            "status": "fail",
            "observed": "3 of 9 dimensions unresolved",
            "threshold": "All nine dimensions assessed; declarations still require evidence",
            "consequence": "Capability alone cannot waive reliability, authority, evaluation, operations, service, commercial, evidence or scale gaps."
          },
          {
            "id": "authority-match",
            "label": "Authority-matched operation",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Evaluated and intended authority/supervision aligned with intervention, recovery and stop controls",
            "consequence": "Evidence collected under lower authority or stronger supervision cannot silently justify intended operation."
          },
          {
            "id": "critic-independence",
            "label": "Agent–simulator–critic independence",
            "status": "fail",
            "observed": "declared gap",
            "threshold": "Versioned critic, disclosed dependencies, calibration, deterministic checks and human escalation",
            "consequence": "An evaluator with unresolved common-mode dependencies cannot establish product readiness."
          },
          {
            "id": "integrated-release-case",
            "label": "Integrated Product Release Case",
            "status": "warning",
            "observed": "experiment only",
            "threshold": "Release-grade, configuration-bound evidence and named specialist decisions",
            "consequence": "This public simulator can recommend a bounded next experiment, never release readiness."
          }
        ],
        "formulas": [
          {
            "id": "budget-coverage",
            "label": "Upfront funding coverage",
            "expression": "total investment budget ÷ modeled upfront investment",
            "units": "% funded"
          },
          {
            "id": "availability",
            "label": "Theoretical availability",
            "expression": "MTBF ÷ (MTBF + MTTR), then explicit failure penalties",
            "units": "% available time"
          },
          {
            "id": "upfront",
            "label": "Upfront investment",
            "expression": "units × (hardware + integration) + spares + commissioning days × day rate",
            "units": "EUR"
          },
          {
            "id": "annual-opex",
            "label": "Annual operating cost",
            "expression": "platform + data/AI ops + inference + energy + service labour + replacements",
            "units": "EUR/year"
          },
          {
            "id": "value",
            "label": "Annual productive value",
            "expression": "units × productive hours × effective availability × value/hour × injected modifiers",
            "units": "EUR/year"
          },
          {
            "id": "capacity",
            "label": "Capacity utilization",
            "expression": "(planned work + commissioning load) ÷ (team hours × teams)",
            "units": "% monthly capacity"
          },
          {
            "id": "risk",
            "label": "Risk screening score",
            "expression": "likelihood × impact + evidence gap + explicit failure increments",
            "units": "0–100 screening index"
          }
        ],
        "assumptions": [
          "All scenarios are fictional and illustrative; figures are visitor-controlled assumptions, not Hyperion client evidence.",
          "Currency is EUR and values are undiscounted; tax, financing and inflation are excluded from this thin slice.",
          "MTBF/MTTR availability is a planning approximation and does not establish functional-safety performance.",
          "Commissioning capacity assumes eight engineering hours per day and forty site-level setup hours per deployment.",
          "Failure injections are transparent multipliers, not probability forecasts or field observations.",
          "The investment budget is compared with modeled upfront hardware, integration, spares and commissioning cost; operating reserve and financing are excluded."
        ],
        "limitations": [
          "This result is not safety certification, legal advice, conformity assessment or an autonomous release decision.",
          "Queueing is a deterministic capacity approximation; it is not a discrete-event simulation of a specific operation.",
          "No real customer, personal, confidential, export-controlled or safety-critical operational data should be entered.",
          "A qualified human owner must validate evidence, operating envelope, compliance duties and consequential commitments."
        ],
        "failureEffects": [
          {
            "type": "recovery_failure",
            "label": "Recovery failure",
            "severityPercent": 75,
            "consequences": [
              "7.5 availability points removed",
              "22.5% service-load increase",
              "Recovery evidence and sustained-duty claims require revalidation"
            ]
          },
          {
            "type": "service_overload",
            "label": "Service overload",
            "severityPercent": 75,
            "consequences": [
              "37.5% service-load increase",
              "3 availability points removed",
              "Support capacity and customer commitments require revalidation"
            ]
          }
        ],
        "sensitivity": [
          {
            "variable": "Hardware cost (−20% / base / +20%)",
            "low": 10640462.34,
            "base": 10390478.34,
            "high": 10140494.34,
            "units": "EUR"
          },
          {
            "variable": "Productive value/hour (−20% / base / +20%)",
            "low": 7607659.48,
            "base": 10390478.34,
            "high": 13173297.21,
            "units": "EUR"
          },
          {
            "variable": "Availability (−5 pts / base / +5 pts)",
            "low": 9607118.34,
            "base": 10390478.34,
            "high": 11173838.34,
            "units": "EUR"
          }
        ],
        "methodFit": {
          "version": "method-fit-1.0.0",
          "recommendedOperatingModel": "Continuous discovery + systems engineering evidence spine + Kanban for constrained flow.",
          "governanceNote": "Method choice is contextual. Safety, compliance, investment, release and customer commitments remain owned human decisions regardless of agile method.",
          "scores": [
            {
              "id": "continuous-discovery",
              "name": "Continuous discovery",
              "score": 100,
              "fit": "strong",
              "rationale": "Keeps customer evidence, field learning and product assumptions connected to delivery decisions.",
              "condition": "Use evidence cadence and decision records; do not treat interviews as release authority."
            },
            {
              "id": "scrum",
              "name": "Scrum",
              "score": 71,
              "fit": "conditional",
              "rationale": "Supports bounded product increments where uncertainty can be reduced inside a stable team cadence.",
              "condition": "Keep hardware, safety and commissioning gates outside the fiction of a purely software Definition of Done."
            },
            {
              "id": "kanban",
              "name": "Kanban / flow",
              "score": 79,
              "fit": "strong",
              "rationale": "Makes integration, field defects, evidence work and service queues visible as constrained flow.",
              "condition": "Set explicit classes of service and WIP limits for safety, field and supplier work."
            },
            {
              "id": "systems-engineering",
              "name": "Systems engineering",
              "score": 100,
              "fit": "strong",
              "rationale": "Controls interfaces, operating-envelope evidence and verification across hardware, software, AI and operations.",
              "condition": "Use as a product evidence spine, not as a substitute for customer discovery or incremental learning."
            },
            {
              "id": "safe",
              "name": "SAFe",
              "score": 70,
              "fit": "conditional",
              "rationale": "May coordinate multiple teams and portfolio dependencies when scale is real and independently evidenced.",
              "condition": "Do not introduce enterprise-scale ceremony for a small team; Scrum, Kanban and systems interfaces are sufficient."
            }
          ]
        }
      },
      "provenance": {
        "schemaVersion": "provenance-1.1.0",
        "outputClassification": "deterministic",
        "inputClassification": "illustrative",
        "releaseRecommendation": "experiment_only",
        "productSystemDiagnosticVersion": "product-system-diagnostic-1.0.0",
        "configurationBaselineId": "fictional-amr-fleet.configuration-v1",
        "provider": "Hyperion deterministic engine",
        "exactModelIdentifier": null,
        "modelRole": "arithmetic-and-constraint-authority",
        "aiBoundary": {
          "provider": "Mistral AI",
          "exactModels": [
            "mistral-small-2603",
            "mistral-medium-3-5",
            "mistral-large-2512"
          ],
          "usedForThisOutput": false,
          "limitation": "Optional Mistral council commentary is separate model-derived material and cannot alter these deterministic calculations."
        },
        "promptTemplateVersion": "not-applicable-deterministic-output",
        "applicationVersion": "physical-ai-flight-simulator-1.1.0",
        "methodologyVersion": "method-fit-1.0.0",
        "engineVersion": "flight-engine-1.1.0",
        "evidence": [
          {
            "id": "scenario:fictional-amr-combined-service-recovery",
            "classification": "illustrative",
            "label": "Visitor-controlled fictional scenario assumptions",
            "source": "In-browser Physical AI Product Flight Simulator form"
          },
          {
            "id": "engine:flight-engine-1.1.0",
            "classification": "deterministic",
            "label": "Deterministic economics, availability, capacity, risk and constraint result",
            "source": "Hyperion Physical AI Flight Engine"
          },
          {
            "id": "method:method-fit-1.0.0",
            "classification": "deterministic",
            "label": "Contextual method-fit result",
            "source": "Hyperion Method-Fit decision rules"
          }
        ],
        "assumptions": [
          "All scenarios are fictional and illustrative; figures are visitor-controlled assumptions, not Hyperion client evidence.",
          "Currency is EUR and values are undiscounted; tax, financing and inflation are excluded from this thin slice.",
          "MTBF/MTTR availability is a planning approximation and does not establish functional-safety performance.",
          "Commissioning capacity assumes eight engineering hours per day and forty site-level setup hours per deployment.",
          "Failure injections are transparent multipliers, not probability forecasts or field observations.",
          "The investment budget is compared with modeled upfront hardware, integration, spares and commissioning cost; operating reserve and financing are excluded."
        ],
        "limitations": [
          "This result is not safety certification, legal advice, conformity assessment or an autonomous release decision.",
          "Queueing is a deterministic capacity approximation; it is not a discrete-event simulation of a specific operation.",
          "No real customer, personal, confidential, export-controlled or safety-critical operational data should be entered.",
          "A qualified human owner must validate evidence, operating envelope, compliance duties and consequential commitments."
        ],
        "canonicalInputHash": "bbc3dad4e28fd3c8bee01f2fc1ab3823abfcff7bf60f2d0fc05168e0e52a616e",
        "deterministicResultHash": "49b9ddf512df668ac854fe02ff5101c73088f2b2fa9810ae3738694576f435b4",
        "createdAt": "2026-09-06T00:00:00Z",
        "responsibleHumanDecisionOwner": "Illustrative accountable product owner",
        "responsibleHumanDecisionRole": "Product and operations sponsor",
        "humanDecision": "Proceed to a bounded site pilot subject to the failed release conditions shown below.",
        "reviewDate": "2026-09-30",
        "reviewStatus": "illustrative_unapproved",
        "humanDecisionRecorded": false,
        "expiryStatus": "within_review_period"
      }
    }
  ],
  "payloadHash": "dad1910669fa3526b0190aa028def2daf8fc479edf94bad1d1428b7788d6a8cd"
}
