Skip to content

For teachers

Prepare a mission

Everything you need to run the lesson: the prompts for this academic depth, the diagnostic answer key, the misconceptions to watch for, and the truth boundary to hold.

Choose the mission and depth

Write the rule before you need it.

When a fault happens, nobody on the ground can react in time. Whatever the spacecraft does next was decided months earlier, by whoever wrote its rules. Your team will read a mission that went wrong and write the rule that should have been there.

Pilot lesson

What to say at University

These prompts come from the academic layer, so they change with the depth you selected.

Theory

State professional terminology, lineage, and model-limit questions. Stage intent: verification.

Prediction

Predict where the model is expected to be useful and where it is not.

Running the Twin

Inspect allowed lineage/hash channels only if the profile discloses them. Runtime remains the frozen Twin; this plan does not execute physics.

Checkpoint

Separate simulated, derived, reference, and (if ever present) measured evidence.

Analysis

Design, integrate, verify, and validate within frozen Core V1 limits. Evidence intent: policy/state artifact + scenario tests + safety/verification rationale.

Engineering decision

Produce a V&V-style conclusion that does not claim flight qualification.

Limitation

Name at least one frozen-model limitation that this experiment cannot answer.

Provenance

Keep simulated, simulated_sensor, estimator_state, derived, reference, and measured distinct. Never label simulated as measured.

Diagnostic answer key

Why can a spacecraft not simply wait for instructions when a fault happens?

  • It may be out of contact, and the fault will not wait
  • · It can always reach the ground instantly
  • · Faults never happen quickly

Timing

One session of 55–70 minutes. Adjust freely — the sequence matters more than the clock.

Suggested lesson timing
WhenStageWhat you are doing
0 → 5–6 minMissionSet the role, objective, mission question, and success criterion.
5–6 → 17–21 minPreparationDiagnostic, theory, and a written prediction before any run.
17–21 → 20–25 minReadinessLearners confirm the local formative gate after preparation passes.
20–25 → 30–38 minOperateRun the bounded baseline, then the candidate where comparison is disclosed.
30–38 → 47–60 minEvidenceInspect provenance, select evidence, decide, state a limitation, and complete the formative assessment.
47–60 → 53–68 minCompleteReview the result band, reflect, and finalize local practice at any band.
53–68 → 55–70 minRecognitionExplain the local record and the separate future verified-recognition boundary.

Misconceptions to watch for

Authored lesson design — what a class reliably gets wrong here, and where you can catch it. Not a claim about any learner.

A good policy is an intention to manage resources carefully.

An intention cannot execute. Insist on a condition the spacecraft can evaluate and an action it can perform — this is the most common wrong answer and the most important to correct.

Watch: the decision option "A general intention to be careful with resources" · Code: cause_effect_or_control_logic_reversal

A protective rule is free, because it only fires in an emergency.

Ask what the rule gives up each time it fires, and what it costs when it fires and did not need to. A rule with no cost is usually not a rule.

Watch: evidence — The mission readings for this run · Code: constraint_budget_or_tradeoff_omission

The ground team can decide when the fault happens.

The spacecraft may be out of contact, and the fault will not wait. Tie this back to the contact windows — the rule exists because the link is not always there.

Watch: the "policy" diagnostic · Code: truth_estimate_measurement_confusion

Reflection and extension

What a good reflection contains

What does your safety rule cost the mission, and how would you test that the rule does not create a new hazard?

  • States the rule as a condition the spacecraft can test paired with an action it can take.
  • Says what the rule costs when it fires, and when it fires unnecessarily.
  • Keeps this fault-recovery scenario distinct from the eclipse scenario used by the diagnosis mission.

If they finish early, or go further

  • Make the rule fail safely (University and above)

    Describe what your policy does if the reading it depends on is itself wrong. State whether it fails towards protecting the spacecraft or towards continuing the mission, and defend the choice.

  • Two rules that conflict (University and above)

    Write a second rule that is individually sensible and that can contradict your first. Say how the spacecraft should resolve the conflict, and who decided that ordering.

Facilitation and the truth boundary

While they work

  • Insist on condition and action. Intentions are the most common wrong answer and the most important one to correct.
  • Ask what each proposed rule costs. A rule with no cost is usually not a rule.
  • This is the fault-recovery scenario, not the eclipse one used by the diagnosis mission.

Is the rule expressed as a testable condition and a concrete action, with its cost acknowledged?

Hold this line

  • These mission readings are produced by a model. No real fault occurred.
  • A rule that works here has not been shown to be safe on real hardware.
  • This lesson is not an operational assurance result.

Home mission

Home mission: the rule you already follow

Write down one rule you follow without thinking, as a condition and an action - for example, if the battery reaches ten per cent, stop watching video. Then write what it costs you, because every safety rule costs something.

Tell us what did not work

Ten questions, answered locally. Nothing is submitted or tracked — you download the file and send it if you want to.

Informal educator feedback

This local-first form contains the ten approved pilot-review questions. It does not submit, track, or store data remotely. Optional name/contact should be handled outside this form only if a reviewer volunteers it.