Scenario · Humanitarian evacuation under uncertainty
The Road That Learned the Rain
A flooded causeway, 612 civilians, and a road model that is wrong force an evacuation team to learn from local evidence without letting the model promote itself or choose the route.
- What this is
- A published decision scenario. Its setting and values are invented for illustration.
- What this shows
- How declared facts and rules produce a traceable result when conditions change.
- What this does not show
- A customer deployment, measured outcome, or transfer of authority to software.
Narrated film · 1:10
The Road That Learned the Rain
Follow local evidence into a candidate model, then through testing and review before anyone relies on the change.
1:10
Story
Start with the event and the decision it creates.
The story
02:13 — the road on the screen
At 02:13, the map still shows Gannet Causeway as usable. Outside the command shelter, the rain has reduced it to a question.
On one side wait 612 civilians, including twenty-four patients whose machines are running on borrowed diesel. On the other is high ground. Vale owns the evacuation decision. She has seventy-two hours, eighteen percent fuel, and a road-risk model called CINDER-7.2 that has seen storms but almost no roads saturated twice before they recovered.
Pike, the person who inspected the causeway, returns with red mud to his knees. “Your screen says green. My boots say the shoulder is moving.”
The green state is not an autonomous military judgment. It is the mission application's current projection of a water gauge, route report, model score, and rules authored for the exercise. Pike's report is neither discarded nor allowed to overwrite a number anonymously. It enters as attributable, time-bounded evidence.
Vale asks the question that governs everything after it: What do we know, what do we only predict, and who is allowed to decide?
Hour zero — four human-authored courses
The staff lays out four provisional courses. Alder sends everyone over Gannet. Birch puts every vehicle on North Ridge. Cedar splits the fleet. Echo reserves Gannet for light medical carriers inside Pike's verified window, sends heavy buses over North Ridge, and requests additional light capacity.
Grid does not invent these courses. The authored composition evaluates them against the same vehicle classes, capacities, time windows, travel times, fuel rules, reserves, hazards, and evidence states. At hour zero, Alder depends on a route whose heavy suitability Pike has challenged. Birch misses a medical deadline under the incumbent assumptions. Cedar consumes the fuel margin. Echo lacks vehicles.
The screen reports the states the represented evidence can justify. It does not call a course safe.
Hours 6–28 — learning without self-promotion
At hour six, weather cuts the higher link. The local server keeps working because the signed model, mission packages, trust material, local tables, policies, and required feeds were provisioned beforehand. Remote values retain their source time and become visibly stale. Local continuity is not magical synchronization through the rain, and a long outage would require a separate durable transfer and reconciliation design.
At hour fourteen, a light relief vehicle returns from Gannet nineteen minutes later than the active model allowed. The driver report, vehicle clock, segment, load class, and arrival observation are reviewed and admitted. The source revisions are correct. The exact incumbent is the one named in the receipt. Nothing was silently swapped. The model was wrong on this case.
Pike studies the sequence: “The ground isn't wet. It remembers being wet.” Nia, working on the model team, turns the phrase into a testable human hypothesis: elapsed time since prior saturation may matter more than current rain alone. Grid did not discover the feature. People define it and its measurement.
Before examining performance, Nia defines which observations may enter training. Each needs a resolved route and vehicle class, the facts available when the decision was made, a later reviewed outcome, an attributable source and time, no unresolved correction, and permission for this use. A limited batch creates CINDER-7.3E as a new local candidate. It does not edit the active model, learn from one event at a time, or become active because one metric looks favorable.
At hour twenty-eight, the application compares the active model and the candidate on evidence neither model saw during training. The record identifies the data, feature and preparation rules, evaluation policy, whole-set and repeated-saturation results, passed and failed gates, and reviewer. The candidate clears the predeclared local gate, but the sample is small. Nia labels it eligible for higher review—not “better everywhere.” CINDER-7.2 remains active.
Hours 35–43 — facts and model evidence travel differently
When the link returns briefly, two kinds of information follow different routes. A narrow Grid connection publishes selected facts: the current risk band, active model version, observation time, and identifiers for the candidate evidence. Raw training rows and model weights do not travel through that connection.
A separately authorized mission-data channel carries the reviewed row package and evidence needed for higher review. Classification, encryption, releasability, cross-domain controls, radios, and receipts belong to external systems and policy. The story does not rename that transfer “model sync.”
At the regional node, reviewers combine the permitted records with approved evidence from two other units, train a fresh batch model, and test it on a broader holdout. This is centralized retraining after selective transfer, not weight sharing between nodes. A human-only workflow binds the proposed model version to the data snapshot, evaluation report, gate policy, and release record. The producer cannot be the sole approver. Higher authority signs CINDER-7.4.
Approval changes which model may be deployed. It does not authorize a mission.
Each compatible receiving node independently verifies the publisher, signature, digests, and variant before installation. One older node rejects the release as incompatible and remains visibly on CINDER-7.2. Installation is still not activation. A deployment operator canaries the release and separately changes the consuming configuration. Partner teams make their own activation decisions. Distribution never means silent activation.
Hour 48 — disagreement remains disagreement
The second storm arrives. A gauge supports heavy use of Gannet during the relevant window. Pike's authenticated inspection refutes heavy use under bus-equivalent load. The two reports address the same proposition and remain visible as supporting and refuting evidence. The authored mission policy requires positive, unopposed support, so the UI marks heavy movement unresolved.
The system does not average disagreement into a reassuring number. Pike separately supports a narrower proposition: light vehicles at or below the declared payload may use Gannet for a bounded period. Different subject, load class, and validity window; no blanket declaration that the causeway is safe.
Hours 51–53 — one feasible course and a human decision
Under the fixed exercise facts, Alder fails because the heavy-route evidence is unresolved. Birch misses the patient and civilian deadlines under the conservative planning estimate. Cedar violates both the heavy-route gate and the protected fuel floor. Echo avoids heavy use of Gannet and fits the represented deadlines and fuel rule—if two additional light medical carriers arrive before hour fifty-two.
That number belongs to the composed authored oracle, not to Grid generally. The fixture enumerates zero, one, and two added carriers against its declared facts. Four carriers are required to move twenty-four patients in one six-person-per-vehicle wave. The battalion has two. One addition raises capacity only to eighteen; two raise it to twenty-four, and the complete represented course remains feasible. The exercise therefore establishes two as the minimum only inside this authored problem.
Vale's staff—not Grid—requests the vehicles through the authorized process. Noor, who controls the requested vehicles, signs a time-bounded commitment. The affected plan updates, and Echo becomes the only represented course currently feasible under the accepted assumptions. The screen does not call it an optimal evacuation.
Vale reviews an immutable snapshot: active model identity, source revisions, unresolved evidence, uncertainty assumptions, rejected courses, margins, vehicle commitment, and the consequence of error. She records her reason and signs under the human mission workflow. Starting review was not approval; approval is not dispatch; dispatch is not outcome.
Hours 61–72 — the world changes after approval
A rockfall closes part of North Ridge. A previously surveyed detour adds forty-seven minutes. The local model recalculates and finds that the course still meets the absolute deadline, but its conservative ending-fuel estimate falls below the ordinary twelve-percent reserve. Grid cannot lower policy. Vale has declared emergency authority to release reserve down to 10.5 percent. She reviews the changed plan and signs a second decision. The first record remains intact; the later one supersedes it for execution.
In the scenario ending, the last civilian bus crosses the flood line at 71 hours and 38 minutes. The twenty-four patients have reached stable power and clinical handoff. No heavy bus used Gannet. Minutes later, the causeway shoulder becomes impassable to heavy vehicles.
CINDER did not predict that exact moment. Grid did not make the crossing safe. The system preserved uncertainty, retained disagreement, kept model release separate from mission authority, and joined prediction, decision, and later observation without treating them as one event.
After reconnection, only reviewed, eligible outcomes may enter the next dataset. A future CINDER release can exist only after fresh training, evaluation, human review, signing, installation, and activation. The battalion has not taught a machine to command. In the story's careful metaphor, it has taught a road model to remember the rain while preserving the human right—and responsibility—to decide when to cross.
Where the model stops
Grid can preserve evidence, train and compare candidates, distribute an exact reviewed release, and explain an authored course evaluation. It cannot target, employ a weapon, exercise command, select an operational route, move resources, or promote a model automatically. Model-release authority and mission authority remain separate and human-governed.
What remains to prove
This source has no reviewed external domain-evidence claim and remains R1. Any controlled evaluation would require mission-owned integrations, independent safety and security work, non-targeting review, release and rollback controls, representative negative cases, and retained evidence. The narrative outcome is illustrative, not operational-performance evidence.
Decision path
Follow the changed fact step by step.
A calculation, proposal, approval, execution report, and outcome are different events. The order keeps those boundaries visible.
- 01 · 02:13
The road on the screen disagrees with the boots
Pike's attributable field observation challenges the active model's represented road state.
- 02 · Hour fourteen
Correct provenance meets an incomplete model
The evidence is attributable, but the model lacks a relevant saturation and traffic relationship.
- 03 · Hours fourteen through twenty-eight
Local training produces an inactive candidate
Edge computation creates a candidate that cannot replace the active model on its own.
- 04 · Hours thirty-five through forty-three
Small facts and large evidence use distinct planes
Bounded updates and heavier evidence move under different declared transfer and review rules.
- 05 · Hours thirty-five through forty-three
Higher authority retrains and reviews
A separate team compares evidence, negative cases, and candidate behavior.
- 06 · Hours thirty-five through forty-three
Release, installation, and activation remain separate
A reviewed artifact still requires attributable distribution, installation, and local activation decisions.
- 07 · Hour forty-eight
Contradictory evidence remains unresolved
The system does not silently choose between authoritative but incompatible observations.
- 08 · Hours fifty-one through seventy-two and later review
A human authorizes one course and reviewed outcomes feed the next batch
The authored oracle compares represented courses, while command authority and later evidence remain external.
Evidence and limits
What the scenario represents—and what real-world use still requires.
Represented in this scenario
- Provenance-preserving observations and explicit model limitations
- Inactive candidates, review states, signed releases, installation, and activation as distinct transitions
- Authored course comparison with uncertainty and explanation
Required integration and operating work
- Mission-owned sensing, identity, transfer, release, rollback, and command-system integrations
- Independent non-targeting safety, security, assurance, and operational evaluation
Decisions that remain with people and institutions
- Targeting or weapons employment
- Command, route selection, movement, or resource allocation
- Automatic model promotion, installation, or activation
Evidence, authority, and publication recordView the scenario contract, capability record, authority stages, verification status, and related work.
Scenario contract
The setting, trigger, decision, and authority boundary.
- Setting
- An invented battalion supporting a humanitarian evacuation while a rain-sensitive road model fails outside its prior evidence.
- Timeframe
- Seventy-two hours through a later governed model release
- Trigger
- The road on the screen remains green while verified crossings show the model no longer represents current saturation and traffic effects.
- Decision
- How can local evidence contribute to a reviewed model release while the formation continues planning under uncertainty and human command?
- Authority
- Grid may train candidates, compare evidence, distribute exact reviewed releases, and evaluate authored courses; model-release and mission authority remain separate and human-governed.
Learning without self-promotion
Evidence may create a candidate; it does not create release or command authority.
The scenario separates observed contradiction, local training, higher review, exact release, local activation, and mission decision.
- SourcesVerified local observations
Attributable evidence contradicts the active model without automatically selecting a replacement.
- ModelInactive edge candidate
Local training produces an inspectable candidate and declared limitations.
- AlternativesAuthored course comparison
The composed oracle evaluates only the authored alternatives and constraints declared in this fixture.
- Human authorityRelease and command decisions
Separate accountable authorities govern model release and any mission action.
- External evidenceInstallation, activation, and observations
Receipts, reported state transitions, and outcomes retain distinct provenance.
What is established
What is documented, what this scenario combines, and what still needs testing.
This separates documented capabilities from authored combinations in the scenario. Neither proves a complete deployment or outcome.
Documented building blocks
Capabilities described in maintained Grid documentation or another named source.
- Reviewed product primitives document local evaluation and bounded training, typed value delivery, candidate and version identity, and signed per-node model installation; this is not defense qualification or deployment evidence.
- Reviewed product primitives document predicates, planning and routing, provenance, and generic governed approvals; they do not establish mission release or command operations.
Combined in this scenario
Capability combinations represented in this scenario that still require end-to-end evaluation.
- The authored design composes local observations, inactive candidate evidence, higher review, exact release, separate activation, and explained course comparison.
- Mission-owned sensing, artifact relay, rollout, rollback, identity, and decision-record integrations would connect those states while preserving human command.
Not yet proved
Integration, operating, policy, or evidence work that is not complete.
- A governed candidate-to-release bridge, candidate evidence contract, fleet activation plan, and selective artifact relay remain missing.
- An executable independently checked fixture, external non-targeting domain evidence, safety and security assurance, and long-disconnection qualification remain outstanding.
Proof and limits
What this scenario supports—and what remains to validate.
These states describe the scenario source and its defined checks. Real-world validation requires separate evidence.
- Scenario publication
- PublishedReleased August 27, 2026 as an operating scenario.
- Source readiness
- R2 · Sources reviewedDomain support and product capability boundaries have been reviewed.
- Scenario check
- Checks not runScenario revision 2026-08-27.2 defines the steps and expected results; the checks have not run yet.
- Independent review
- PendingThe expected results have not received independent review.
- Deployment evidence
- NoneNo customer deployment, production performance, or real-world outcome is claimed.
- Next proof required
- Advance beyond R2Run the defined checks, retain the results, and have an independent reviewer check the expected results.
Evidence and stewardship
What supports this scenario—and when it must be reviewed again.
Illustrative evidence
Authored, non-targeting exercise; it is not operational route advice, a battlefield deployment, a performance result, or authority for any mission action.
Invented elements. Every organization, location, observation, value, timing, candidate, course, and outcome is authored. The two-carrier result belongs only to the composed authored oracle in this fixture, not to Grid generally.
- Owner
- Grid FYI Editorial
- Reviewed
- August 27, 2026
- Review due
- February 27, 2027
- Source revision
- 2026-08-27.1
- Scenario package
- battlefield-edge-road-that-learned-the-rain
Related work
Related reading and examples.
These links are chosen as direct companions to this scenario.