Scenario · Humanitarian evacuation under uncertainty

The Road That Learned the Rain

A flooded causeway, 612 civilians, and a road model that is wrong force an evacuation team to learn from local evidence without letting the model promote itself or choose the route.

10 min readDefense and national securityIllustrative evidence
What this is
A published decision scenario. Its setting and values are invented for illustration.
What this shows
How declared facts and rules produce a traceable result when conditions change.
What this does not show
A customer deployment, measured outcome, or transfer of authority to software.

Narrated film · 1:10

The Road That Learned the Rain

Follow local evidence into a candidate model, then through testing and review before anyone relies on the change.

Watch narrated film · 1:10 Read the story · 10 min
1:10

Story

Start with the event and the decision it creates.

The story

02:13 — the road on the screen

At 02:13, the map still shows Gannet Causeway as usable. Outside the command shelter, the rain has reduced it to a question.

On one side wait 612 civilians, including twenty-four patients whose machines are running on borrowed diesel. On the other is high ground. Vale owns the evacuation decision. She has seventy-two hours, eighteen percent fuel, and a road-risk model called CINDER-7.2 that has seen storms but almost no roads saturated twice before they recovered.

Pike, the person who inspected the causeway, returns with red mud to his knees. “Your screen says green. My boots say the shoulder is moving.”

The green state is not an autonomous military judgment. It is the mission application's current projection of a water gauge, route report, model score, and rules authored for the exercise. Pike's report is neither discarded nor allowed to overwrite a number anonymously. It enters as attributable, time-bounded evidence.

Vale asks the question that governs everything after it: What do we know, what do we only predict, and who is allowed to decide?

Hour zero — four human-authored courses

The staff lays out four provisional courses. Alder sends everyone over Gannet. Birch puts every vehicle on North Ridge. Cedar splits the fleet. Echo reserves Gannet for light medical carriers inside Pike's verified window, sends heavy buses over North Ridge, and requests additional light capacity.

Grid does not invent these courses. The authored composition evaluates them against the same vehicle classes, capacities, time windows, travel times, fuel rules, reserves, hazards, and evidence states. At hour zero, Alder depends on a route whose heavy suitability Pike has challenged. Birch misses a medical deadline under the incumbent assumptions. Cedar consumes the fuel margin. Echo lacks vehicles.

The screen reports the states the represented evidence can justify. It does not call a course safe.

Hours 6–28 — learning without self-promotion

At hour six, weather cuts the higher link. The local server keeps working because the signed model, mission packages, trust material, local tables, policies, and required feeds were provisioned beforehand. Remote values retain their source time and become visibly stale. Local continuity is not magical synchronization through the rain, and a long outage would require a separate durable transfer and reconciliation design.

At hour fourteen, a light relief vehicle returns from Gannet nineteen minutes later than the active model allowed. The driver report, vehicle clock, segment, load class, and arrival observation are reviewed and admitted. The source revisions are correct. The exact incumbent is the one named in the receipt. Nothing was silently swapped. The model was wrong on this case.

Pike studies the sequence: “The ground isn't wet. It remembers being wet.” Nia, working on the model team, turns the phrase into a testable human hypothesis: elapsed time since prior saturation may matter more than current rain alone. Grid did not discover the feature. People define it and its measurement.

Before examining performance, Nia defines which observations may enter training. Each needs a resolved route and vehicle class, the facts available when the decision was made, a later reviewed outcome, an attributable source and time, no unresolved correction, and permission for this use. A limited batch creates CINDER-7.3E as a new local candidate. It does not edit the active model, learn from one event at a time, or become active because one metric looks favorable.

At hour twenty-eight, the application compares the active model and the candidate on evidence neither model saw during training. The record identifies the data, feature and preparation rules, evaluation policy, whole-set and repeated-saturation results, passed and failed gates, and reviewer. The candidate clears the predeclared local gate, but the sample is small. Nia labels it eligible for higher review—not “better everywhere.” CINDER-7.2 remains active.

Hours 35–43 — facts and model evidence travel differently

When the link returns briefly, two kinds of information follow different routes. A narrow Grid connection publishes selected facts: the current risk band, active model version, observation time, and identifiers for the candidate evidence. Raw training rows and model weights do not travel through that connection.

A separately authorized mission-data channel carries the reviewed row package and evidence needed for higher review. Classification, encryption, releasability, cross-domain controls, radios, and receipts belong to external systems and policy. The story does not rename that transfer “model sync.”

At the regional node, reviewers combine the permitted records with approved evidence from two other units, train a fresh batch model, and test it on a broader holdout. This is centralized retraining after selective transfer, not weight sharing between nodes. A human-only workflow binds the proposed model version to the data snapshot, evaluation report, gate policy, and release record. The producer cannot be the sole approver. Higher authority signs CINDER-7.4.

Approval changes which model may be deployed. It does not authorize a mission.

Each compatible receiving node independently verifies the publisher, signature, digests, and variant before installation. One older node rejects the release as incompatible and remains visibly on CINDER-7.2. Installation is still not activation. A deployment operator canaries the release and separately changes the consuming configuration. Partner teams make their own activation decisions. Distribution never means silent activation.

Hour 48 — disagreement remains disagreement

The second storm arrives. A gauge supports heavy use of Gannet during the relevant window. Pike's authenticated inspection refutes heavy use under bus-equivalent load. The two reports address the same proposition and remain visible as supporting and refuting evidence. The authored mission policy requires positive, unopposed support, so the UI marks heavy movement unresolved.

The system does not average disagreement into a reassuring number. Pike separately supports a narrower proposition: light vehicles at or below the declared payload may use Gannet for a bounded period. Different subject, load class, and validity window; no blanket declaration that the causeway is safe.

Hours 51–53 — one feasible course and a human decision

Under the fixed exercise facts, Alder fails because the heavy-route evidence is unresolved. Birch misses the patient and civilian deadlines under the conservative planning estimate. Cedar violates both the heavy-route gate and the protected fuel floor. Echo avoids heavy use of Gannet and fits the represented deadlines and fuel rule—if two additional light medical carriers arrive before hour fifty-two.

That number belongs to the composed authored oracle, not to Grid generally. The fixture enumerates zero, one, and two added carriers against its declared facts. Four carriers are required to move twenty-four patients in one six-person-per-vehicle wave. The battalion has two. One addition raises capacity only to eighteen; two raise it to twenty-four, and the complete represented course remains feasible. The exercise therefore establishes two as the minimum only inside this authored problem.

Vale's staff—not Grid—requests the vehicles through the authorized process. Noor, who controls the requested vehicles, signs a time-bounded commitment. The affected plan updates, and Echo becomes the only represented course currently feasible under the accepted assumptions. The screen does not call it an optimal evacuation.

Vale reviews an immutable snapshot: active model identity, source revisions, unresolved evidence, uncertainty assumptions, rejected courses, margins, vehicle commitment, and the consequence of error. She records her reason and signs under the human mission workflow. Starting review was not approval; approval is not dispatch; dispatch is not outcome.

Hours 61–72 — the world changes after approval

A rockfall closes part of North Ridge. A previously surveyed detour adds forty-seven minutes. The local model recalculates and finds that the course still meets the absolute deadline, but its conservative ending-fuel estimate falls below the ordinary twelve-percent reserve. Grid cannot lower policy. Vale has declared emergency authority to release reserve down to 10.5 percent. She reviews the changed plan and signs a second decision. The first record remains intact; the later one supersedes it for execution.

In the scenario ending, the last civilian bus crosses the flood line at 71 hours and 38 minutes. The twenty-four patients have reached stable power and clinical handoff. No heavy bus used Gannet. Minutes later, the causeway shoulder becomes impassable to heavy vehicles.

CINDER did not predict that exact moment. Grid did not make the crossing safe. The system preserved uncertainty, retained disagreement, kept model release separate from mission authority, and joined prediction, decision, and later observation without treating them as one event.

After reconnection, only reviewed, eligible outcomes may enter the next dataset. A future CINDER release can exist only after fresh training, evaluation, human review, signing, installation, and activation. The battalion has not taught a machine to command. In the story's careful metaphor, it has taught a road model to remember the rain while preserving the human right—and responsibility—to decide when to cross.

Where the model stops

Grid can preserve evidence, train and compare candidates, distribute an exact reviewed release, and explain an authored course evaluation. It cannot target, employ a weapon, exercise command, select an operational route, move resources, or promote a model automatically. Model-release authority and mission authority remain separate and human-governed.

What remains to prove

This source has no reviewed external domain-evidence claim and remains R1. Any controlled evaluation would require mission-owned integrations, independent safety and security work, non-targeting review, release and rollback controls, representative negative cases, and retained evidence. The narrative outcome is illustrative, not operational-performance evidence.

Decision path

Follow the changed fact step by step.

A calculation, proposal, approval, execution report, and outcome are different events. The order keeps those boundaries visible.

  1. 01 · 02:13

    The road on the screen disagrees with the boots

    Pike's attributable field observation challenges the active model's represented road state.

  2. 02 · Hour fourteen

    Correct provenance meets an incomplete model

    The evidence is attributable, but the model lacks a relevant saturation and traffic relationship.

  3. 03 · Hours fourteen through twenty-eight

    Local training produces an inactive candidate

    Edge computation creates a candidate that cannot replace the active model on its own.

  4. 04 · Hours thirty-five through forty-three

    Small facts and large evidence use distinct planes

    Bounded updates and heavier evidence move under different declared transfer and review rules.

  5. 05 · Hours thirty-five through forty-three

    Higher authority retrains and reviews

    A separate team compares evidence, negative cases, and candidate behavior.

  6. 06 · Hours thirty-five through forty-three

    Release, installation, and activation remain separate

    A reviewed artifact still requires attributable distribution, installation, and local activation decisions.

  7. 07 · Hour forty-eight

    Contradictory evidence remains unresolved

    The system does not silently choose between authoritative but incompatible observations.

  8. 08 · Hours fifty-one through seventy-two and later review

    A human authorizes one course and reviewed outcomes feed the next batch

    The authored oracle compares represented courses, while command authority and later evidence remain external.

Evidence and limits

What the scenario represents—and what real-world use still requires.

Represented in this scenario

  • Provenance-preserving observations and explicit model limitations
  • Inactive candidates, review states, signed releases, installation, and activation as distinct transitions
  • Authored course comparison with uncertainty and explanation

Required integration and operating work

  • Mission-owned sensing, identity, transfer, release, rollback, and command-system integrations
  • Independent non-targeting safety, security, assurance, and operational evaluation

Decisions that remain with people and institutions

  • Targeting or weapons employment
  • Command, route selection, movement, or resource allocation
  • Automatic model promotion, installation, or activation
Evidence, authority, and publication recordView the scenario contract, capability record, authority stages, verification status, and related work.

Scenario contract

The setting, trigger, decision, and authority boundary.

Setting
An invented battalion supporting a humanitarian evacuation while a rain-sensitive road model fails outside its prior evidence.
Timeframe
Seventy-two hours through a later governed model release
Trigger
The road on the screen remains green while verified crossings show the model no longer represents current saturation and traffic effects.
Decision
How can local evidence contribute to a reviewed model release while the formation continues planning under uncertainty and human command?
Authority
Grid may train candidates, compare evidence, distribute exact reviewed releases, and evaluate authored courses; model-release and mission authority remain separate and human-governed.

Learning without self-promotion

Evidence may create a candidate; it does not create release or command authority.

The scenario separates observed contradiction, local training, higher review, exact release, local activation, and mission decision.

  1. SourcesVerified local observations

    Attributable evidence contradicts the active model without automatically selecting a replacement.

  2. ModelInactive edge candidate

    Local training produces an inspectable candidate and declared limitations.

  3. AlternativesAuthored course comparison

    The composed oracle evaluates only the authored alternatives and constraints declared in this fixture.

  4. Human authorityRelease and command decisions

    Separate accountable authorities govern model release and any mission action.

  5. External evidenceInstallation, activation, and observations

    Receipts, reported state transitions, and outcomes retain distinct provenance.

The authored two-carrier minimality finding is an oracle result inside this declared fixture, not a Grid product or operational-performance claim.

What is established

What is documented, what this scenario combines, and what still needs testing.

This separates documented capabilities from authored combinations in the scenario. Neither proves a complete deployment or outcome.

Documented

Documented building blocks

Capabilities described in maintained Grid documentation or another named source.

  • Reviewed product primitives document local evaluation and bounded training, typed value delivery, candidate and version identity, and signed per-node model installation; this is not defense qualification or deployment evidence.
  • Reviewed product primitives document predicates, planning and routing, provenance, and generic governed approvals; they do not establish mission release or command operations.
Combined here

Combined in this scenario

Capability combinations represented in this scenario that still require end-to-end evaluation.

  • The authored design composes local observations, inactive candidate evidence, higher review, exact release, separate activation, and explained course comparison.
  • Mission-owned sensing, artifact relay, rollout, rollback, identity, and decision-record integrations would connect those states while preserving human command.
Needs testing

Not yet proved

Integration, operating, policy, or evidence work that is not complete.

  • A governed candidate-to-release bridge, candidate evidence contract, fleet activation plan, and selective artifact relay remain missing.
  • An executable independently checked fixture, external non-targeting domain evidence, safety and security assurance, and long-disconnection qualification remain outstanding.

From model result to outcome evidence

A modeled answer does not perform the work.

Calculation, review, authorization, submission acknowledgment, execution reporting, and observed outcome produce different records and must remain independently inspectable.

  1. 01 · ModelEvaluate the declared facts, rules, dependencies, and constraints.

    The result is model output, not an authorized decision.

  2. 02 · ProposalPrepare an exact candidate plan and explanation for review.

    A proposal does not carry institutional authority.

  3. 03 · Human authorizationThe named responsible actor accepts, rejects, or changes the exact reviewed revision.

    An interface action records the scenario step; authority still comes from the responsible institution.

  4. 04 · Submission acknowledgmentThe receiving system records that it accepted the exact instruction for processing.

    Receipt establishes neither execution nor outcome.

  5. 05 · Execution reportThe responsible execution owner separately reports what action was performed.

    Reported execution is not proof of the intended outcome.

  6. 06 · Outcome evidenceAuthoritative observation records what occurred and with what effect.

    An outcome claim requires evidence beyond the model, submission record, and execution report.

Acknowledgment ≠ execution ≠ outcome. Each state requires its own responsible source and evidence record.

Proof and limits

What this scenario supports—and what remains to validate.

These states describe the scenario source and its defined checks. Real-world validation requires separate evidence.

Scenario publication
PublishedReleased August 27, 2026 as an operating scenario.
Source readiness
R2 · Sources reviewedDomain support and product capability boundaries have been reviewed.
Scenario check
Checks not runScenario revision 2026-08-27.2 defines the steps and expected results; the checks have not run yet.
Independent review
PendingThe expected results have not received independent review.
Deployment evidence
NoneNo customer deployment, production performance, or real-world outcome is claimed.
Next proof required
Advance beyond R2Run the defined checks, retain the results, and have an independent reviewer check the expected results.

Evidence and stewardship

What supports this scenario—and when it must be reviewed again.

Illustrative evidence

Authored, non-targeting exercise; it is not operational route advice, a battlefield deployment, a performance result, or authority for any mission action.

Invented elements. Every organization, location, observation, value, timing, candidate, course, and outcome is authored. The two-carrier result belongs only to the composed authored oracle in this fixture, not to Grid generally.

Owner
Grid FYI Editorial
Reviewed
August 27, 2026
Review due
February 27, 2027
Source revision
2026-08-27.1
Scenario package
battlefield-edge-road-that-learned-the-rain

Related work

Related reading and examples.

These links are chosen as direct companions to this scenario.

Use cases

Insights

White paperInventory Is Not Availability: An Executable Model for Contested LogisticsInventory creates mission value only when identity, location, condition, demand, authority, and a feasible route resolve together. This paper separates the public logistics record from a bounded Grid proposition and evaluation method.White paperCourse-of-Action Feasibility Without the Slide-Deck Reconciliation CycleA course of action remains feasible only while its facts, assumptions, resources, timing, constraints, and authority remain aligned. This paper separates the public planning record from a bounded Grid proposition for keeping that conclusion inspectable as conditions change.White paperAI Can Propose. Who Authorizes? A Control Model for High-Consequence Government Work.High-consequence AI needs more than a human approval button. This paper separates proposals, facts, models, review, authority, and outcomes, then defines a bounded way to evaluate whether oversight is real.

Films

1:10The Road That Learned the RainA humanitarian logistics team learns from local evidence, proves a regional model release, preserves unresolved route disagreement, and keeps command human.0:29Local Compute and Selective SharingA technical cut shows one model compute locally and send only a named, versioned result to the connected models that need it.0:36When the Plan BreaksSeveral disruptions invalidate the plan; the affected models recalculate and a person authorizes the response.1:27The Mission Is a Living ModelSeveral local models recalculate as conditions change, share selected results, and keep authorization with a person.0:40AI with Human AuthorityFive AI-written versions of the same requirement return different answers; the film moves the rule into one visible model and keeps approval with a person.

Continue

Read, watch, or explore the next step.

Thematic companion · 0:29Local Compute and Selective SharingA technical cut shows one model compute locally and send only a named, versioned result to the connected models that need it. This released film approaches the same operating theme through a different scenario.Inspect implementation conceptsRead the Grid product conceptsContinue into Grid Developers for maintained behavior, prerequisites, and implementation limits.Apply the operating patternReplan Sustainment When Route and Stock ChangeConnect usable stock, movement capacity, time windows, mission demand, and command authority so a changed route or inventory fact produces an inspectable replan rather than another reconciliation cycle.