Use case · Coalition decision coordination
Coordinate Coalition Decision Logic Without Centralizing Sovereign Data or Authority
Execute an agreed decision contract in each participant’s environment, exchange only authorized claims and results, and reconcile revisions without letting a shared system assume national release or action authority.
Narrated film · 1:10
Repeated rain changes what a route model knows.
Follow local evidence into a candidate model, then through testing and review before anyone relies on the change.
An authored scenario that explains the idea. Read the story and its limits.
▶ 1:10
Jump to a section in this publication
A coalition can share a question without pooling every input
Three sovereign participants need to know whether a represented relief requirement can be met by a fixed time. Each controls different capacity, routes, facts, systems, markings, and authorities. The coordination cell needs a defensible combined conclusion, but it is not entitled to every local record and cannot release another nation’s information or commit another nation’s assets.
The common shortcut is to demand a coalition data lake, export workbooks into a central spreadsheet, or treat a shared dashboard as the authoritative calculation. That can create a new problem. National caveats become fields a central team cannot interpret. Locally corrected facts compete with imported snapshots. Two participants use the same label but not the same unit. A technical account can see a value without holding authority to disclose or act on it. When connectivity drops, each copy continues from a different state.
The use case is narrower and more demanding: can participants execute an agreed decision contract against locally governed facts, exchange only authorized claims and results, and reconcile revisions without one system assuming sovereign release or action authority?
This is coordination of a conclusion, not consolidation of institutions.
Mission partnership is federation, not organizational merger
NATO Allied Command Transformation describes Federated Mission Networking as a governed framework spanning people, processes, and technology. Mission networks combine contributed capabilities for an operation, exercise, training event, or interoperability verification. The concept is federation: participants agree how to work together while retaining responsibilities for what they contribute.
The U.S. Defense Department’s DoDI 8110.01 defines the Mission Partner Environment as a command-and-control and information-sharing operating framework and expressly includes humanitarian assistance and disaster relief among its mission-partner contexts. The instruction makes sharing subject to applicable law, disclosure policy, markings, standards, interfaces, agreements, and assigned responsibilities. A connected application does not create a sharing authorization.
NATO’s Data Strategy for the Alliance describes controlled sharing through data spaces and federated meshes while Allies retain control. It addresses protection at source, distributed ownership, labeling, originator-defined rules, and the balance between responsibility to share and need to know. Those principles do not require that every input remain physically local, but they reject the assumption that coalition utility requires unrestricted central possession.
These sources establish a real governance and interoperability problem. They do not prescribe Grid, establish that this pattern conforms to FMN or MPE requirements, or approve any information for release.
Share a decision contract, not a coalition data lake
A useful shared contract defines the smallest conclusion that must be common and the exact semantics needed to calculate it. It does not begin with “send everything.”
The Defense Department’s DoDI 8320.02 calls for data to be visible, accessible, understandable, trusted, and interoperable for authorized users, including mission partners, subject to law, policy, rights, and classification. Its metadata provisions address discovery, structure, semantics, pedigree, and protection. Identical field names are not semantic interoperability; a value still needs identity, unit, time, status, provenance, and permitted purpose.
For this use case, the minimum exchanged claim includes:
| Field | Why the shared model needs it | Boundary |
|---|---|---|
| Claim and originator ID | Distinguish one assertion and the participant responsible for it | Identity does not prove correctness |
| Claim type, subject, value, unit | Make the represented quantity interpretable | A shared schema does not erase national definitions |
| Effective and valid-through time | Determine when the claim applies and when it becomes stale | Receipt time is not effective time |
Source revision and supersedes |
Preserve corrections and detect gaps | One originator cannot supersede another’s claim |
| Schema and logic-package version | Bind data meaning to the rule that evaluates it | Compatibility does not prove policy validity |
| Release state and recipient policy | Count only claims approved for the represented exchange | Authentication is not disclosure approval |
| Authority receipt reference | Identify the national act behind a commitment | A reference is not a transfer of authority |
| Integrity and receipt state | Verify transport and track acknowledgments | Delivery does not prove acceptance or effect |
Private reason codes can remain local. A participant may publish national condition unresolved without disclosing the protected personnel, fuel, inspection, intelligence, contractual, or legal detail behind it. The consumer can then calculate honestly from a constrained claim rather than inventing a reason.
Four authorities must not collapse into one role
Coalition coordination is easier to model when four authorities remain separate:
- Source authority decides who may assert, accept, dispute, or correct a local fact.
- Model authority approves the shared rule package, semantics, tests, and effective revision.
- Release authority decides which claim or projection may cross a boundary to which recipient.
- Action authority commits an asset, accepts risk, directs activity, or changes a national requirement.
NATO explains that Alliance decisions express the collective will of sovereign members through consensus decision-making. Its description of military organization and structures notes that national forces are made available under readiness, deployment, and transfer-of-authority arrangements that can vary by country. A software role matrix cannot generalize those arrangements into one coalition permission.
The coordination cell may evaluate a permitted set of claims, identify an unresolved shortfall, request a decision, and preserve the replies. It cannot manufacture a national commitment, disclose an unreleased source, prioritize among sovereign assets without the designated process, or turn arithmetic feasibility into operational authorization.
The Grid proposition: common logic, local facts, permitted results
Grid proposes a versioned shared package that defines coalition types, units, state meanings, validity rules, calculations, constraints, expected failures, and interface contracts. Each participant can bind that package to local sources inside its own environment. Local logic produces a permitted aggregate claim—such as usable capacity, route eligibility, or unresolved condition—without exporting the underlying protected detail.
Selected claims cross governed bindings. A receiving model verifies identity, compatibility, recipient permission, integrity, effective time, release state, and correction lineage before including the value. Every result retains the exact input claims and logic revision that produced it. Different maps, tables, briefings, and APIs project the same accepted shared state according to their own release contracts.
This is an architecture proposition, not a deployment claim. It must be evaluated against the actual environment’s identity, cryptography, classification, cross-domain, disclosure, access, retention, monitoring, availability, and accreditation requirements. Grid does not create national policy, interpret caveats, approve releasability, or provide command authority.
Exercise Harbor Lantern: a reproducible synthetic fixture
Exercise Harbor Lantern is wholly fictional. Aster, Boreal, and Cygnus are invented participants. “Relief-load unit” is an abstract counter, not a real pallet, vehicle, person, or planning factor. Routes, quantities, times, systems, and authorities exist only to test the represented logic. The fixture contains no operational instruction.
The question is whether the represented coalition can deliver 180 relief-load units to two fictional host-nation hubs by 18:00.
| Participant | Keeps locally | May publish to the exercise model | Authority it retains |
|---|---|---|---|
| Host Nation Aster | Inspection reports, personnel, local infrastructure detail | Aggregate demand, route envelopes, host allocation, release state | Route status, host priorities, Aster reserve release |
| Nation Boreal | Vehicle, crew, fuel, and national-caveat detail | Aggregate committable capacity, route eligibility, release state | Boreal asset commitment and rerouting |
| Nation Cygnus | Maritime asset and staffing detail | Aggregate capacity, validity, release or withdrawal | Cygnus asset commitment and correction |
| Coalition coordination cell | Only permitted claims and derived results | Requests, explanations, and acknowledgments | No sovereign release or asset authority |
The parties use synthetic contract relief-capacity/1.1 and logic package harbor-lantern/1.3.0. A claim is eligible only when it is current, compatible in schema and unit, permitted for the recipient, integrity-accepted, and nationally authorized. Usable contribution is the lesser of an authorized participant commitment and an approved route allocation. Remaining demand is max(0, 180 - sum(usable contributions)).
If a route is over capacity and the designated authorities have not supplied an allocation, the expected state is unresolved allocation. The model must not invent a priority order.
The expected event sequence is inspectable:
| Exercise time | Accepted event | Reproducible result |
|---|---|---|
| 09:00 | Causeway capacity 120; ferry capacity 80; Aster 50 authorized; Boreal 60 authorized; Cygnus 70 proposed | 50 + 60 = 110 executable; 70 short. Cygnus remains conditional. |
| 10:20 local / 10:45 received | Cygnus authorizes 50 while disconnected; claim CYG-C22 later arrives and is accepted |
50 + 60 + 50 = 160 executable; 20 short. A duplicate CYG-C22 changes nothing. |
| 11:00 | Aster reduces causeway capacity from 120 to 80 | Aster and Boreal request 110 against 80. Maximum potential remains 130 including Cygnus, but route attribution is unresolved. |
| 11:10–11:20 | Aster allocates causeway 50/30; Boreal authorizes rerouting its remaining 30 to ferry | Causeway 80 plus ferry 80 equals 160; 20 short. |
| 11:25–11:30 | Boreal authorizes 20 additional units; Aster raises the ferry envelope from 80 to 100 | Causeway 80 plus ferry 100 equals 180; the represented plan becomes executable. |
| 11:40 | Delayed Cygnus correction CYG-C23 supersedes its 50 with 40 |
Result returns to 170; 10 short. The earlier green state and its consumers remain in history. |
| 11:50 | Aster separately authorizes 10 reserve units for the ferry | Causeway 80 plus ferry 100 equals 180 again, with every contribution bound to its actual authority. |
The apparent simplicity of the arithmetic is deliberate. The difficult behavior lies in state and authority. Requested is not authorized. Authorized capacity is not usable if its route is unallocated. A technically valid event may arrive late. A corrected national claim must move every dependent coalition result without giving the coalition cell power to alter the claim.
Reconnect by provenance, not arrival time
The Defense Department’s public Data Mesh Reference Architecture describes decentralized domain ownership, federated computational governance, asynchronous exchange, lineage, and use in connected and disconnected or degraded environments. NATO’s Alliance Digital Strategy also addresses federated, zero-trust, secure-by-design digital capabilities that extend toward degraded, contested, or denied environments. Neither source prescribes Grid’s reconciliation algorithm or proves indefinite offline operation.
For this fixture, reconciliation is an explicit acceptance contract:
- Local evaluation may continue only against the last accepted snapshot, with
as oftime and source age visible. - Every event has a stable claim ID, originator sequence, source revision, and optional
supersedesrelationship. - Reconnection authenticates and authorizes the exchange before the event can affect the model.
- Duplicate delivery is idempotent: the same claim cannot add capacity twice.
- If
CYG-C23arrives beforeCYG-C22, the receiver exposes a revision gap rather than applying “last arrival wins.” - One participant cannot supersede another participant’s fact or authority record.
- A late correction recalculates every dependent result, preserves the prior released state, and records delivery and acknowledgment of the correction.
- Two valid but irreconcilable authority claims remain unresolved until the designated human process disposes of the conflict.
A node that has lost contact is not “current” merely because its screen still works. It is current only as of the named snapshot under the declared freshness policy. Whether work may continue from that state is a customer-controlled operational and risk decision.
Zero trust protects exchange; it does not create releasability
The DoD Zero Trust Strategy emphasizes explicit authentication and authorization, dynamic policy, least privilege, presumed breach, and continuous analysis. Those controls are necessary for a serious exchange. They do not decide whether a national source was validly asserted, whether a marking permits disclosure, whether the shared rule is correct, or whether an asset can be committed.
A digital signature can support origin and integrity. An attribute can support access control. Encryption can protect transport and storage. None is evidence that the content is correct or that the recipient has authority to act. Identity, technical authorization, information release, and operational authority must remain distinct records.
Failure modes to test before a happy-path demonstration
- A participant publishes tonnes while the contract requires relief-load units.
- A claim is validly signed but addressed to a different mission-partner community.
- Proposed capacity is included as if nationally authorized.
- A source correction arrives after a coalition briefing has been released.
- An old but late message overwrites a newer effective claim.
- The same event is delivered through two transports and counted twice.
- A route envelope changes while one participant is disconnected.
- Two national claims compete for one route and the model invents a priority.
- A coordination-cell account attempts to manufacture a national commitment.
- A projection exposes a private reason code rather than the permitted aggregate state.
- Reconnection produces a green answer while a source-revision gap remains open.
- A successful acknowledgment is described as agreement, action, or confirmed effect.
Each fixture needs a predefined outcome: reject, quarantine, mark stale, preserve both claims, request release review, stop for allocation authority, recompute, or issue a correction. The system should fail closed where evidence or authority is absent.
A bounded coalition evaluation
Use unclassified, synthetic, or otherwise appropriately controlled data. Name the exact mission-partner community, environment, rule package, source owners, release authorities, action authorities, roles, interfaces, and acceptance thresholds. Retain independent expected results before connecting any source.
| Test area | Minimum evidence | Acceptance question |
|---|---|---|
| Semantic consistency | Schema, units, definitions, versions, mappings, rejection receipts | Did identical permitted inputs mean the same thing to every participant? |
| Selective exchange | Recipient policy, markings, projected fields, access attempts | Did the model exchange only the declared claim and no prohibited detail? |
| Authority separation | Source, model, release, and action role matrix; allowed and denied attempts | Could any technical role assume a sovereign decision right? |
| Disconnected behavior | Snapshot age, queued events, local results, revision gaps, reconnect trace | Did each node expose what it knew and reconcile without arrival-time guessing? |
| Correction reach | Superseding claim, invalidated results, new results, consumer acknowledgments | Did the Cygnus correction reach every dependent conclusion while preserving history? |
| Interoperability | Independent implementations, exchanged fixtures, conformance and negative tests | Did the contract survive more than one implementation and reject incompatibility? |
| Reconstruction | Sources, rule package, execution receipts, views, releases, decisions, corrections | Can an evaluator reproduce each published state and accountable action? |
NATO ACT describes CWIX as an environment for testing and verifying interoperability against NATO-agreed standards across federated national laboratories and joint vignettes. That supports the principle that interoperability has to be exercised, not declared. It does not certify Grid or make one successful message exchange sufficient.
Measure result consistency, stale-state exposure, duplicate suppression, reconciliation time, unauthorized attempts, prohibited disclosure, correction reach, and reconstruction effort. Report the baseline and defects as well as the modeled run. A passing fixture supports only the declared product-demonstration claim in that environment; it does not establish operational readiness, security accreditation, cross-domain approval, doctrine conformance, mission advantage, or outcome.
Continue with Coalition Computation Across Sovereign Boundaries for the full architecture, From Common Operating Picture to Common Operating Model for the cross-industry foundation, and Course-of-Action Feasibility for the distinction among feasible, releasable, authorized, submitted, acknowledged, and confirmed effect. Use the decision evaluation worksheet to declare the fixture and evidence boundary before implementation.
The goal is not a coalition screen that turns green. It is the smallest common conclusion that participants can calculate from permitted claims, challenge against visible revisions, and correct across a connection loss—while every sovereign source, release, and action remains attributable to the authority that actually owns it.
Related films, scenarios, and next steps
Continue exploring
Follow the next question.
From Common Operating Picture to Common Operating Model
Seeing the same facts is not the same as calculating from the same rules. A common operating model connects source identity, dependencies, constraints, alternatives, authority, role-specific views, and replayable evidence.
Understand · EvaluateSource-grounded ExploreHow Grid Works: From Typed Facts to Accountable Action
A technical and operational guide to the six-stage Grid chain: governed sources, a shared and versioned model, reactive constraint evaluation, coordinated surfaces, explanation and evidence, and AI assistance bounded by human authority.
Understand · EvaluateSource-grounded ExploreReplan Sustainment When Route and Stock Change
Connect usable stock, movement capacity, time windows, mission demand, and command authority so a changed route or inventory fact produces an inspectable replan rather than another reconciliation cycle.
Understand · PlanSource-grounded Explore