A common pattern of operational
failure is of
coordination or
cooperation problems, due to
mode ambiguity.
Often, the source for the ambiguity is that the
mode set is not defined formally in the
system specification documents, and thereof, is missing from the
system design.
Many legacy
systems implement algorithms for
inferring the operators intention based on the history of the
operators commands. However, it sometimes happens that the
operator's intention is different from that obtained by these algorithms.
If during the operation, the operational scenario is implicit, then the machine does not have any means to learn about the operator's intention, namely, which of the possible scenarios is active.
A common source of operational failure is when an operator performs a maintenance procedure when the system is in functional mode (such as production).
Nagoya, Asiana 214
In order to prevent
scenario
ambiguity, the
states defining the
scenario (operational situation) should be defined explicitly, and represented in the rule database.
Updated on 29 May 2016.