Scenario · Public warning correction

The Warning That Had to Be Corrected Everywhere

A map correction narrows one county's warning area; each jurisdiction retains its authority, each channel receipt keeps its exact meaning, and the original exercise record remains intact.

9 min readGovernment and public sectorIllustrative evidence
What this is
A published decision scenario. Its setting and values are invented for illustration.
What this shows
How declared facts and rules produce a traceable result when conditions change.
What this does not show
A customer deployment, measured outcome, or transfer of authority to software.

Narrated film · 1:10

The Warning That Had to Be Corrected Everywhere

Follow one correction across languages and jurisdictions, and see the difference between sending an update and knowing it arrived.

Watch narrated film · 1:10 Read the story · 9 min
1:10

Story

Start with the event and the decision it creates.

The story

08:47 — a correction arrives after submission

At 08:47, after two exact warning revisions have entered represented exercise channels, geographic source ZONE-EAST v13 narrows Kestrel County's affected area from six blocks to two. Harbor's geography has not changed. Kestrel's warning team must advance a referenced successor without editing Harbor's message, losing the earlier record, or claiming that any channel delivered the warning to the public.

No new deadline is introduced: until Kestrel's exact successor is authorized, the modeled active instruction remains the six-block Kestrel revision. The trace now rewinds to show how Harbor and Kestrel reached that state.

08:10 — evidence has more than one clock

Exercise Harborline-27 begins when an invented pressure source records a fall from 58 to 12 psi inside Port Alder Water Cooperative. The record, PRS-204 r17, says when the condition was observed and when it entered the exercise. Three minutes later, field gauge revision FG-88 r2 reports 14 psi and corroborates the represented pressure loss.

A normal laboratory result also arrives. Its sample was collected at 06:00, before the pressure event. The exercise preserves the result but will not let its later arrival time make it evidence about conditions after the loss. A record can be current in a queue and still be wrong for the decision interval.

The active geographic source is ZONE-EAST v12. It covers Harbor East and six blocks in neighboring Kestrel County. That polygon creates a shared problem, not shared authority. Harbor's protective-action owner can decide the represented action inside Harbor; Kestrel's protective-action owner holds the equivalent role inside Kestrel. Alerting permissions are also scoped by jurisdiction, event, geography, pathway, and user.

At 08:21, draft HBR-DRAFT r1 tries to release one Harbor message for both counties. The jurisdiction check stops it. A shared map does not make Harbor responsible for Kestrel, and urgency does not expand a credential's scope.

08:24 — exact meaning before exact approval

The team creates sibling Harbor and Kestrel packets so each protective-action owner can consider the represented action. A second stop appears. The Harbor English rendering says East Zone; the Spanish rendering says West Zone.

The model does not decide which translation is correct, quietly omit Spanish, or approve the common parts. Geography and protective action are material meaning. Both language versions must carry the same meaning before the exact multilingual revision can advance.

At 08:28, a qualified exercise language reviewer corrects the mismatch. The two protective-action owners separately authorize the represented actions. Each jurisdiction's exact-message approver then approves the fingerprint for HBR-001 r3 or KES-001 r3: jurisdiction, polygon, action, timing, English and Spanish artifacts, and intended pathways.

The distinction between protective-action authority and exact-message authority is deliberate. Deciding what the exercise audience should do is not the same act as approving the particular words, geography, languages, timing, and channels that communicate it. Neither is equivalent to permission to operate an alerting system.

08:30 — the channels do not say the same thing

The approved packets enter several represented exercise channels, which return different kinds of evidence. Across those handoffs, a WEA adapter accepts an authorized r3 packet at 08:30:04, and the represented EAS/IPAWS path accepts one a second later. A designated exercise receiver observes audio at 08:30:17, while an All-Hazards Feed monitor observes an item at 08:30:08. One English county webpage returns HTTP 201; its Spanish counterpart times out. These are representative channel records, not proof that both packets reached every pathway.

There is no honest single word for this state. “Sent” would conceal the difference between submission, adapter acceptance, channel observation, server response, and unresolved handoff. The overall result is partial handoff.

An adapter acceptance does not prove that a gateway distributed the warning. A gateway record does not prove device presentation. One observed test device does not represent the population. Presentation does not establish understanding, protective action, or safety. Each rung needs its own evidence and method.

The timeout also preserves the exact approved artifact. An operator may retry the same Spanish revision and record the response. The failure does not authorize an after-the-fact edit to the page text. If material meaning changes, exact-message review must happen again.

Returning to 08:47 — the correction advances

The exercise GIS owner publishes ZONE-EAST v13, the correction introduced at the opening. Version 12 remains immutable because it is the geographic evidence that supported the 08:28 authorization. The new source makes Kestrel's current geography stale; it does not erase what the team knew or what officials approved earlier.

Candidate KES-002 is an update that explicitly points back to KES-001. A seeded version without that predecessor reference is blocked. Kestrel's protective-action owner and exact-message approver review the new polygon, languages, timing, action, and fingerprint. At 08:52, their authorization advances KES-002 as Kestrel's active represented instruction and supersedes KES-001 in that modeled state. Submission over the represented original pathways follows at 08:53 as a separate channel event; neither transition proves delivery.

Harbor's warning remains governed by Harbor's evidence and authority. Kestrel's correction cannot silently edit it. Shared incident context does not make one jurisdiction's later decision authoritative for another.

The trace can now answer a question that ordinary channel logs often cannot. At 08:40, Harbor East and six Kestrel blocks were represented as active under the first authorized revisions. At 09:00, Harbor East and two Kestrel blocks were represented as active under Harbor's original and Kestrel's successor revisions. Replay shows the modeled authorized-instruction state at each time; it still does not claim what every person received or understood.

11:05 — stopping repetition is not saying it is over

Later synthetic evidence supports ending the exercise instruction. A referenced cancellation stops simulated repeated dissemination. That technical action is necessary, but it is not a public all-clear. The responsible officials separately review and authorize an exact follow-up that tells the exercise audience the advisory has ended. Only after that message advances does the model show no active instruction.

This final boundary matters because a system can successfully cancel retransmission while leaving people with the last protective instruction they saw. The public meaning of “it is over” requires its own owner, wording, languages, channels, and evidence.

The opening question now has a bounded answer. Kestrel's referenced successor changes only Kestrel's active represented instruction; Harbor's remains unchanged. The English and Spanish artifacts stay bound to exact approved fingerprints, every channel keeps the response it actually produced, and cancellation remains separate from the public-facing end instruction. “Corrected everywhere” means every represented dependent record and view carries the exact correction state—not that every channel delivered it or every person received it.

An AI assistant may help compare variants or propose summaries, but it cannot invent a fact, change a polygon, strengthen an instruction, or approve a consequential message.

Where the model stops

Grid can represent evidence, scope, exact revisions, channel states, and correction dependencies. It cannot order protective action, approve a warning, certify language or accessibility, operate public channels, or turn acknowledgments into delivery, understanding, action, or safety evidence.

What remains to prove

A controlled evaluation needs a frozen exercise fixture, independent oracle, jurisdiction and language negative cases, exact replay, retained per-channel evidence, trained operators, qualified reviewers, and actual integration contracts. This scenario is not a live alert or proof of public outcome.

Decision path

Follow the changed fact step by step.

A calculation, proposal, approval, execution report, and outcome are different events. The order keeps those boundaries visible.

  1. 01 · 08:10–08:13

    Pressure evidence crosses a declared threshold

    A named source and field gauge corroborate the exercise condition while a pre-event lab result remains time-qualified.

  2. 02 · 08:20

    One polygon crosses two authorities

    The affected area includes Harbor and Kestrel, but neither jurisdiction inherits the other's protective-action or warning authority.

  3. 03 · 08:21

    The first draft is blocked

    Harbor cannot authorize the six Kestrel blocks merely because both counties appear in one geographic source.

  4. 04 · 08:24

    One language variant disagrees

    English says East and Spanish says West, so semantic parity prevents exact-message approval.

  5. 05 · 08:28

    Two exact revisions are authorized

    Each jurisdiction approves its own action, geography, timing, language set, message hash, and pathways.

  6. 06 · 08:30

    The channels report different facts

    Adapter acceptances, receiver observations, server responses, and a timeout remain separate evidence rather than one sent state.

  7. 07 · 08:47–08:53

    The geography changes

    Kestrel authorizes a referenced successor for two blocks while Harbor's separately governed message remains unchanged.

  8. 08 · 11:05

    Cancellation and public correction remain separate

    Retransmission stops, then a separately authorized follow-up tells the exercise audience that the instruction has ended.

Evidence and limits

What the scenario represents—and what real-world use still requires.

Represented in this scenario

  • Time-qualified incident evidence and jurisdiction-scoped authority
  • Exact multilingual message revisions, channel-specific receipts, retries, updates, and cancellations
  • Replay of which authorized instruction was represented as active at a declared time

Required integration and operating work

  • Actual plans, delegations, identity, GIS, alerting, website, records, security, and channel contracts
  • Qualified language and accessibility review, operator exercises, retained receipts, replay tests, and outcome methods

Decisions that remain with people and institutions

  • Protective action outside a responsible official's actual scope
  • Exact warning, update, cancellation, or public all-clear
  • Public delivery, understanding, protective action, or safety outcome
Evidence, authority, and publication recordView the scenario contract, capability record, authority stages, verification status, and related work.

Scenario contract

The setting, trigger, decision, and authority boundary.

Setting
Exercise Harborline-27 across invented Harbor County and neighboring Kestrel County.
Timeframe
08:10 through the separately authorized end instruction at 11:05
Trigger
Geographic source ZONE-EAST v13 narrows Kestrel County's affected area after exact warning revisions have entered several channels.
Decision
Which jurisdictions may authorize which exact correction, what did each channel actually report, and when is the active instruction superseded?
Authority
Grid may represent evidence, scope, exact revisions, channel states, and correction dependencies; responsible officials retain protective-action, message, channel, and end-instruction authority.

A warning after the send button

Accepted is not delivered, and cancel is not all-clear.

The exercise preserves exact authority, message, channel, correction, and end-state evidence without promoting one receipt into another claim.

  1. SourcesPressure and geography revisions

    Observation intervals and source ownership determine what evidence may support the exercise instruction.

  2. ModelTwo jurisdiction-scoped packets

    One shared polygon becomes separate exact revisions under separate protective-action and message authority.

  3. ChannelsAcceptances, observations, and timeout

    Each handoff retains its specific response instead of collapsing into a generic sent status.

  4. Human authorityExact correction approval

    Kestrel's responsible officials approve the narrowed area and successor message without editing Harbor's revision.

  5. External evidenceCancel plus follow-up

    Technical retransmission stop and the public-facing end instruction remain separate attributable acts.

Every channel statement is limited to what the exercise evidence actually observed; none establishes population delivery or safety.

What is established

What is documented, what this scenario combines, and what still needs testing.

This separates documented capabilities from authored combinations in the scenario. Neither proves a complete deployment or outcome.

Documented

Documented building blocks

Capabilities described in maintained Grid documentation or another named source.

  • Reviewed product primitives document typed exchange, versioned logic, reactive dependencies, provenance, explanation, governed approvals, and multiple surfaces; they do not establish public-warning integration or authority.
  • Reviewed product primitives document constrained transitions and human authority; they do not turn channel acknowledgments into public delivery, understanding, action, or safety evidence.
Combined here

Combined in this scenario

Capability combinations represented in this scenario that still require end-to-end evaluation.

  • The authored design connects incident evidence, jurisdictional scope, exact-message approval, semantic language variants, channel-specific receipts, referenced updates, and a separate end instruction.
  • Staff, oversight, public, and API views can derive from one semantic revision while retaining distinct disclosure, accessibility, language, and channel rules.
Needs testing

Not yet proved

Integration, operating, policy, or evidence work that is not complete.

  • A package-owned fixture, independent oracle, exact replay and negative-case tests, retained execution evidence, and derivative parity review remain outstanding.
  • No live sensor, GIS, identity, CAP, IPAWS, WEA, EAS, website, translation, accessibility, jurisdictional, or public-outcome integration is qualified.

From model result to outcome evidence

A modeled answer does not perform the work.

Calculation, review, authorization, submission acknowledgment, execution reporting, and observed outcome produce different records and must remain independently inspectable.

  1. 01 · ModelEvaluate the declared facts, rules, dependencies, and constraints.

    The result is model output, not an authorized decision.

  2. 02 · ProposalPrepare an exact candidate plan and explanation for review.

    A proposal does not carry institutional authority.

  3. 03 · Human authorizationThe named responsible actor accepts, rejects, or changes the exact reviewed revision.

    An interface action records the scenario step; authority still comes from the responsible institution.

  4. 04 · Submission acknowledgmentThe receiving system records that it accepted the exact instruction for processing.

    Receipt establishes neither execution nor outcome.

  5. 05 · Execution reportThe responsible execution owner separately reports what action was performed.

    Reported execution is not proof of the intended outcome.

  6. 06 · Outcome evidenceAuthoritative observation records what occurred and with what effect.

    An outcome claim requires evidence beyond the model, submission record, and execution report.

Acknowledgment ≠ execution ≠ outcome. Each state requires its own responsible source and evidence record.

Proof and limits

What this scenario supports—and what remains to validate.

These states describe the scenario source and its defined checks. Real-world validation requires separate evidence.

Scenario publication
PublishedReleased August 27, 2026 as a synthetic decision scenario.
Source readiness
R2 · Sources reviewedDomain support and product capability boundaries have been reviewed.
Scenario check
Checks not runScenario revision 2026-08-27.1 defines the steps and expected results; the checks have not run yet.
Independent review
PendingThe expected results have not received independent review.
Deployment evidence
NoneNo customer deployment, production performance, or real-world outcome is claimed.
Next proof required
Advance beyond R2Run the defined checks, retain the results, and have an independent reviewer check the expected results.

Evidence and stewardship

What supports this scenario—and when it must be reviewed again.

Illustrative evidence

Authored public-warning exercise grounded by reviewed official guidance; it is not a live alert, certified integration, proof of delivery, or public-safety outcome.

Invented elements. Every organization, official, source, URL, message, polygon, language artifact, channel event, time, and result is invented and labeled as an exercise. Official sources ground responsibilities and semantics, not Grid adoption or public outcome.

Owner
Grid FYI Editorial
Reviewed
August 27, 2026
Review due
February 27, 2027
Source revision
2026-08-27.1
Scenario package
public-warning-corrected-everywhere

Related work

Related reading and examples.

These links are chosen as direct companions to this scenario.

Use cases

Insights

White paperProve, Authorize, Send, Correct: An Accountable Model for Public AlertsPublic warning is not one send action. This paper separates incident evidence, alerting authority, message validation, human release, channel handoff, and correction into an accountable model for bounded evaluation.White paperOne Program Rule, Many Public Surfaces: Governed Policy Across Staff Tools, Public Explanations, Reports, and APIsPublic programs often reimplement one rule in staff tools, websites, notices, reports, and partner interfaces. This paper proposes a governed, versioned rule package with audience-specific surfaces and a bounded way to test whether they remain aligned.White paperAI Can Propose. Who Authorizes? A Control Model for High-Consequence Government Work.High-consequence AI needs more than a human approval button. This paper separates proposals, facts, models, review, authority, and outcomes, then defines a bounded way to evaluate whether oversight is real.

Films

Continue

Read, watch, or explore the next step.

Thematic companion · 0:58How Live Data Moves Through a ModelNew data enters under explicit permissions, recalculates only the affected results, and carries its source and history into every view. This released film approaches the same operating theme through a different scenario.Inspect implementation conceptsExplain and validate a changing decisionContinue into Grid Developers for maintained behavior, prerequisites, and implementation limits.Apply the operating patternAuthorize and Correct a Public Warning Across Evidence, Channels, and JurisdictionsConnect incident evidence, scoped public-warning permissions, exact-message authorization, channel-specific receipts, and versioned corrections without treating technical acceptance as public receipt or a model as warning authority.