The State Transition and Alert Map: How Civilisation Moves from Stability into Drift, Failure, Repair and Regeneration
A sensor reading is not yet a system state.
A delay may be temporary.
A poor examination result may be local.
A sudden rise in demand may remain within safe capacity.
A public complaint may identify a real failure, a communication problem or an isolated experience.
The Civilisation Atlas Control Tower must therefore do more than collect signals.
It must determine when those signals represent a meaningful change in the operating condition of the object.
It must know when:
- ordinary variation becomes pressure;
- pressure becomes sustained load;
- load begins to consume buffers;
- buffer loss becomes drift;
- drift approaches a threshold;
- threshold crossing becomes failure;
- stabilisation becomes repair;
- and repair becomes regeneration.
This requires a state model.
Without a state model, the Control Tower may react too early, too late or in the wrong direction.
It may treat noise as crisis.
It may treat visible activity as successful repair.
It may continue reporting a system as functional after its invariant has already failed.
The State Transition and Alert Map is the instrument that converts observation into an operating judgement.
One-Sentence Definition
The State Transition and Alert Map is the Control Tower instrument that converts validated sensor readings into declared operating states, threshold transitions, alert levels and repair conditions for every Civilisation Atlas object.
In compact form:
SIGNALS→ compared with baselines→ interpreted against the invariant→ tested against thresholds→ assigned an operating state→ connected to an alert→ routed towards observation,stabilisation, repair or regeneration
The map answers:
What state is the object in now?
What changed?
Is the change temporary or structural?
Which threshold has been crossed?
What response is justified?
What evidence is required before the state can be upgraded or downgraded?
Why State Must Be Declared
A civilisation object may appear different depending on who is observing it.
A school leader may see:
- stable attendance;
- completed curriculum;
- and acceptable examination results.
A teacher may see:
- rising misconceptions;
- less correction time;
- more student dependence;
- and lower confidence.
A parent may see:
- increasing homework stress;
- fluctuating marks;
- and weaker independence.
A student may experience:
- confusion;
- memory overload;
- and inability to begin unfamiliar questions.
All these observations may be valid.
The Control Tower must integrate them without collapsing them into one vague conclusion.
A declared state provides a disciplined summary:
OBJECT:Secondary Mathematics learnerCURRENT STATE:Functional but stressedMAIN PRESSURE:New algebra arriving before foundations stabiliseBUFFER:Tutor guidance and repeated practiceDRIFT SIGNAL:Increasing prompt dependenceFAILURE THRESHOLD:Cannot recognise the required method independentlyCURRENT ALERT:Warning
The state is not a label of identity.
It is a temporary operating judgement.
State Is Not Capability
An object may possess advanced capability while operating poorly.
A hospital may contain advanced medical technology but be overloaded.
A nation may possess Stage 4 digital systems while its administrative records weaken.
A learner may understand advanced concepts but perform poorly under examination pressure.
A civilisation may retain Stage 3 industrial capacity while moving through lifecycle descent.
The Control Tower therefore preserves:
CAPABILITY=what the object can reliably dounder valid conditionsSTATE=how well the object is operatingunder present conditions
The two should never be merged.
State Is Not Lifecycle
Lifecycle describes the broader path:
TAKEOFFCLIMBCRUISEDESCENT
State describes the present operational condition.
A system in Cruise may temporarily enter a critical state during shock.
A system in Descent may contain a local institution in stable repair.
For example:
LIFECYCLE:CruiseCURRENT STATE:Critical disruptionCAUSE:Sudden power failure
or:
LIFECYCLE:DescentCURRENT LOCAL STATE:RepairingCAUSE:New leadership, retraining and restored records
Lifecycle and state operate at different time depths.
State Is Not Phase
Runtime Phase provides the broader functional floor:
P0 — Below viable operationP1 — FragileP2 — Functional but stressedP3 — Stable regenerative continuityP4 — Bounded frontier operation
The State Transition Map provides more detailed movement inside and between these phases.
For example:
P2 FUNCTIONAL BUT STRESSEDmay contain states such as:HoldingLoadedDriftingWarningStabilising
The phase is the operating band.
The state is the present position and direction inside that band.
The Nine Control Tower States
The Control Tower uses nine primary operating states.
1. Unknown2. Stable3. Loaded4. Drifting5. Critical6. Failed7. Stabilising8. Repairing9. Regenerating
These states create a complete cycle from uncertainty through normal operation, deterioration, failure and recovery.
State 1: Unknown
The object cannot yet be located reliably
Unknown does not mean safe.
It means the available evidence is insufficient, contradictory, delayed or missing.
STATE:UnknownPOSSIBLE CAUSES:No sensorSensor offlineConflicting readingsUnclear object boundaryMissing baselineUnverified reportRapidly changing condition
Unknown is one of the most important states in the Control Tower because false certainty can be more dangerous than acknowledged uncertainty.
Unknown-State response
The default response is:
OBSERVEVERIFYIMPROVE SENSINGDO NOT OVERSTATE
Where potential consequences are severe, the Control Tower may also recommend precautionary stabilisation.
State 2: Stable
The object is operating within its valid corridor
A stable object:
- preserves its invariant;
- carries normal load;
- maintains sufficient buffer;
- repairs ordinary errors;
- and shows no sustained adverse drift.
Stable does not mean perfect.
A stable school still contains struggling students.
A stable railway still experiences minor delays.
A stable government still makes errors.
The defining feature is:
The system can detect and correct ordinary variation without losing its core function.
STATE:StableFUNCTION:ValidLOAD:Within capacityBUFFER:SufficientDRIFT:No persistent adverse movementREPAIR:Routine and effective
Stable-State response
CONTINUE OPERATIONMAINTAIN SENSORSRENEW DEPENDENCIESPRESERVE SLACKAVOID COMPLACENCY
State 3: Loaded
The object is carrying elevated demand but remains inside its corridor
A loaded system is not yet drifting.
It may be under:
- examination pressure;
- seasonal passenger demand;
- hospital surge;
- temporary financial stress;
- increased information volume;
- or emergency workload.
The object continues to preserve its invariant.
But:
- buffers are being consumed;
- operator effort rises;
- recovery time may lengthen;
- and maintenance may become vulnerable.
STATE:LoadedFUNCTION:Still validLOAD:Above normalBUFFER:Being consumedOPERATOR EFFORT:RisingRISK:Drift if load persists
Loaded-State response
MONITOR MORE FREQUENTLYPROTECT CRITICAL BUFFERREDUCE NON-ESSENTIAL LOADPREPARE SUPPORTDECLARE REVIEW TIME
A loaded state should not be treated as failure.
But it should not be ignored.
State 4: Drifting
The object is moving away from its valid operating corridor
Drift begins when adverse movement becomes persistent.
Examples include:
- error frequency rising;
- maintenance backlog growing;
- response time lengthening;
- public trust weakening;
- transfer quality falling;
- or temporary workarounds becoming normal practice.
The object may still produce visible output.
Its foundations are becoming less reliable.
STATE:DriftingFUNCTION:Still visibleINTEGRITY:WeakeningBUFFER:FallingDEPENDENCY DEBT:RisingTIME VECTOR:Adverse and persistent
Drift is often the best repair window.
The system is still functional enough to intervene without full emergency conditions.
Drift-State response
VERIFY THE DRIFTLOCATE THE LOWER FLOORREDUCE LOADSTOP NEW DEBTASSIGN REPAIR OWNERDECLARE WARNING THRESHOLD
State 5: Critical
The object is approaching or crossing a functional threshold
Critical means:
- the operating corridor is narrow;
- buffers are nearly exhausted;
- failure consequences are serious;
- and ordinary correction is no longer sufficient.
The system may still function.
But one additional disruption could cause failure.
STATE:CriticalFUNCTION:Intermittently validBUFFER:MinimalFAILURE THRESHOLD:Near or partially crossedCASCADE RISK:HighRESPONSE TIME:Short
Critical-State response
STABILISEPROTECT LIFE AND CORE FUNCTIONSTOP NON-ESSENTIAL EXPANSIONACTIVATE REDUNDANCYESCALATE AUTHORITYINCREASE SENSOR FREQUENCY
A critical state is not the time for unbounded experimentation.
The first objective is to preserve the invariant.
State 6: Failed
The object can no longer preserve its invariant function
Failure is defined by function, not appearance.
A school has failed educationally when attendance and completion no longer produce reliable learning.
A transport system has failed when safe dependable movement cannot be maintained.
A government institution has failed when it can no longer coordinate, implement or correct its declared mandate.
An AI-assisted education system has failed when it generates completed work while the learner loses understanding and independent capability.
STATE:FailedINVARIANT:Not preservedVISIBLE ACTIVITY:May continueFUNCTIONAL OUTPUT:Invalid, absent or unsafeCASCADE:Active or imminent
Failed-State response
PROTECT PEOPLEISOLATE THE FAILUREPRESERVE RECORDSRESTORE THE LOWEST BROKEN FLOORDECLARE TEMPORARY ALTERNATIVEBEGIN ROOT-CAUSE ANALYSIS
The goal is not to defend the appearance of continuity.
It is to restore valid function.
State 7: Stabilising
The object is no longer deteriorating, but full function is not yet restored
Stabilisation stops further damage.
Examples include:
- emergency power restored;
- class load temporarily reduced;
- additional hospital staff deployed;
- unsafe system isolated;
- financial liquidity supplied;
- or misinformation source removed.
STATE:StabilisingDAMAGE RATE:FallingCORE FUNCTION:Partially restored or protectedDEPENDENCY FLOOR:Still fragileTEMPORARY SUPPORT:Active
Stabilisation is necessary.
But it can become a trap if temporary measures become permanent substitutes for repair.
Stabilising-State response
CONFIRM DAMAGE HAS STOPPEDIDENTIFY TEMPORARY SUPPORTLOCATE ROOT FAILURESET REPAIR SEQUENCEDEFINE EXIT CONDITIONS
State 8: Repairing
The object is restoring the broken capability and its supporting dependencies
Repair differs from stabilisation.
Stabilisation stops decline.
Repair restores function.
Examples include:
- rebuilding mathematical foundations;
- replacing rail components;
- retraining operators;
- correcting records;
- redesigning an overloaded process;
- rebuilding trust through reliable action;
- or restoring ecological capacity.
STATE:RepairingFUNCTION:ReturningROOT CAUSE:Located sufficientlyDEPENDENCY FLOOR:Being restoredERROR RECURRENCE:FallingVERIFICATION:In progress
Repairing-State response
CONTINUE RESTORATIONVERIFY EACH DEPENDENCYTEST UNDER REAL LOADREMOVE TEMPORARY SUPPORT GRADUALLYCHECK FOR RECURRING FAILURE
Repair is not complete because work has been performed.
Repair is complete when valid function is demonstrated.
State 9: Regenerating
The object has restored function and improved future continuity
Regeneration is the strongest recovery state.
A regenerating object:
- performs its function;
- detects errors earlier;
- maintains stronger buffers;
- carries lower dependency debt;
- trains successors;
- and reduces the probability of repeated failure.
STATE:RegeneratingFUNCTION:RestoredBUFFER:RenewedSENSING:ImprovedREPAIR RATE:HigherSUCCESSION:StrengthenedFUTURE FAILURE RISK:Reduced
Regenerating-State response
DOCUMENT THE REPAIRTRANSFER THE LESSONUPDATE STANDARDSTRAIN SUCCESSORSREVIEW AFTER TIME DELAYRETURN TO STABLE STATE WHEN VERIFIED
Regeneration is not a permanent badge.
After verification, the object returns to Stable with a stronger operating floor.
The Main State Cycle
The normal deterioration cycle is:
STABLE→ LOADED→ DRIFTING→ CRITICAL→ FAILED
The recovery cycle is:
FAILED→ STABILISING→ REPAIRING→ REGENERATING→ STABLE
The system may move backwards or skip states.
For example:
STABLE→ FAILED
through sudden shock.
Or:
DRIFTING→ STABLE
through early successful correction.
The state map is not a rigid staircase.
It is a controlled vocabulary for movement.
State Transition Conditions
Every movement between states should be triggered by declared evidence.
FROM STATE→ transition condition→ TO STATE
For example:
STABLE→ sustained load above normal range→ LOADED
LOADED→ buffer falling and adverse trend persisting→ DRIFTING
DRIFTING→ warning threshold reached→ CRITICAL
CRITICAL→ invariant lost→ FAILED
FAILED→ damage contained→ STABILISING
STABILISING→ root dependency restoration begins→ REPAIRING
REPAIRING→ valid function demonstrated→ REGENERATING
REGENERATING→ function sustained across time and load→ STABLE
Transition Evidence
A state transition should not depend on one unsupported judgement.
The Control Tower should seek:
SIGNAL TREND+THRESHOLD CONDITION+INDEPENDENT CONFIRMATION+OPERATOR REVIEW+EVIDENCE CONFIDENCE
The required level of evidence depends on consequence.
A state upgrade may require stronger evidence than a precautionary downgrade.
For example:
- entering Critical may require credible warning evidence;
- returning to Stable should require sustained proof.
State Downgrade and Upgrade
A downgrade means movement towards greater risk.
Stable→ Loaded→ Drifting→ Critical→ Failed
An upgrade means movement towards restored function.
Failed→ Stabilising→ Repairing→ Regenerating→ Stable
Upgrades should be conservative.
A single good reading should not erase a sustained failure pattern.
The Control Tower should require:
- repeated valid readings;
- real-load testing;
- repaired dependencies;
- and reduced recurrence.
Hysteresis
A system may require more recovery than the amount of decline that caused failure.
This is called hysteresis.
For example:
FAILURE THRESHOLD:Trust falls below a critical levelRECOVERY THRESHOLD:Trust must rise substantially above that levelbefore normal coordination returns
Or:
STUDENT FAILURE:Cannot perform independentlyRECOVERY:Must demonstrate repeated independent transfer,not merely one correct answer
The Control Tower should therefore maintain separate:
FAILURE THRESHOLDandRECOVERY THRESHOLD
State Persistence
A state should have a minimum persistence rule where appropriate.
One adverse reading may not justify Drifting.
One positive reading may not justify Regenerating.
STATE PERSISTENCE:Single eventRepeated eventSustained trendCross-system patternThreshold crossing
The correct persistence depends on the object.
A life-support failure requires immediate classification.
A cultural or educational trend may require longer observation.
State Confidence
Every state declaration should carry confidence.
HIGH CONFIDENCEMODERATE CONFIDENCELOW CONFIDENCECONTESTEDUNKNOWN
For example:
STATE:DriftingCONFIDENCE:ModerateEVIDENCE:Rising error repetition,teacher observation,falling transfer performanceLIMITATION:Short observation period
This preserves uncertainty without avoiding judgement.
Composite State
Large civilisation objects contain several local states.
A nation may be:
WaterOS:StableEducationOS:DriftingTransportOS:LoadedGovernanceOS:Stable but trust-sensitivePlanetOS:Critical long-term pressureAI Capability:Rapid Climb with P2 governance
The Control Tower should not compress this into one national label unless the purpose clearly requires it.
The correct form is a composite state board.
Dominant State
Where a summary is needed, the Control Tower may declare a dominant state.
The dominant state should be based on:
- critical dependencies;
- consequence;
- spread;
- and repair difficulty.
A small but critical failure may matter more than several stable peripheral systems.
DOMINANT STATE:CriticalREASON:Energy supply instability threatenswater, transport and healthcare
Dominant state is a routing judgement.
It is not an average.
Local State and System State
A local component may fail without the whole system failing.
LOCAL OBJECT:One rail lineSTATE:FailedWIDER SYSTEM:Transport networkSTATE:Loaded but functional through alternatives
Alternatively, many local components may remain operational while the system relationship fails.
LOCAL INSTITUTIONS:OperationalSYSTEM COORDINATION:Failed
The Control Tower should state both.
State Propagation
A state may spread through dependency edges.
For example:
EnergyOS:Critical→ WaterOS:Loaded→ HealthOS:Critical→ TransportOS:Drifting→ Public Trust:Warning
This is state propagation.
The Relationship Graph identifies the edges.
The State Map shows the movement.
State Containment
Containment prevents local failure from becoming systemic.
Containment methods include:
- isolation;
- redundancy;
- local autonomy;
- alternative routing;
- reserves;
- firebreaks;
- and modular design.
LOCAL FAILURE→ isolated from wider system→ alternative route activated→ repair proceeds without cascade
Containment is a major P3 capability.
State Synchronisation
Several systems may decline together because they share a lower dependency.
For example:
Power instabilitycauses simultaneous stress inWaterTransportHospitalsCommunicationsProduction
This is synchronised state change.
It may reveal common-mode dependency.
The Control Tower should investigate shared floors rather than treating each symptom independently.
Alert Levels
The State Map connects operating states to five principal alerts.
GREENNormal operationBLUEElevated loadAMBERConfirmed driftREDCritical or failed functionPURPLERepair and regeneration under active review
The colours are reader-facing labels.
The underlying state remains explicit.
Green Alert
STATE:StableMEANING:Function valid and self-correction workingACTION:Maintain, monitor and renew
Green does not mean stop observing.
Blue Alert
STATE:LoadedMEANING:Elevated demand is consuming bufferACTION:Increase observation and protect capacity
Blue identifies pressure before structural drift.
Amber Alert
STATE:DriftingMEANING:Adverse movement is persistentACTION:Verify, reduce load and begin repair
Amber is the main early-intervention corridor.
Red Alert
STATE:Critical or FailedMEANING:The invariant is at immediate riskor has already been lostACTION:Stabilise, contain and restore
Red should be used sparingly.
Overuse creates alert fatigue.
Purple Alert
STATE:Stabilising, Repairing or RegeneratingMEANING:The object is under active restorationACTION:Verify that repair is real,sustained and transferable
Purple is not automatically positive.
It means the object is inside an active correction corridor.
This gives The Purple Report a direct operating relationship with the Control Tower: it can identify systems currently moving through stress, repair and regeneration rather than merely reporting isolated events.
Why Repair Needs Its Own Alert
A repaired system remains vulnerable.
During repair:
- temporary support may hide weakness;
- operators may overstate progress;
- old failure patterns may return;
- and new dependencies may be introduced.
The Purple state keeps the system under structured observation until regeneration is demonstrated.
Alert Priority
Alert priority depends on more than state.
The Control Tower should combine:
STATE SEVERITY× CONSEQUENCE× FAILURE VELOCITY× SPREAD× REVERSIBILITY× CONFIDENCE
A slowly drifting foundational dependency may deserve greater priority than a visible but reversible local disruption.
Urgency and Importance
Urgency asks:
How quickly must action occur?
Importance asks:
How much civilisation function is at stake?
These should remain separate.
HIGH URGENCYLOWER IMPORTANCE:Local fast failure with easy replacementLOW URGENCYHIGH IMPORTANCE:Generational decline in education or ecology
The Control Tower must protect attention from being consumed only by immediate events.
Reversibility
A state transition may be:
EASILY REVERSIBLEREVERSIBLE WITH COSTDIFFICULT TO REVERSEIRREVERSIBLE
Examples of difficult or irreversible change include:
- species loss;
- destruction of archives;
- loss of rare expertise;
- severe trust collapse;
- and death.
Reversibility should influence alert priority.
State Duration
The same state can have different significance depending on duration.
SHORT LOADED STATE:Normal surgePROLONGED LOADED STATE:Likely driftSHORT CRITICAL STATE:EmergencyPROLONGED CRITICAL STATE:System transformation or collapse risk
The Control Tower should record:
STATE STARTCURRENT DURATIONEXPECTED DURATIONMAXIMUM SAFE DURATION
State Cause
Every state should distinguish immediate trigger from deeper cause.
TRIGGER:Examination approachingDEEPER CAUSE:Foundational gaps and insufficient retrieval
TRIGGER:Train disruptionDEEPER CAUSE:Component age and maintenance debt
TRIGGER:Public controversyDEEPER CAUSE:Long-term trust debt
Treating the trigger alone may produce temporary stabilisation without repair.
State Owner
Every declared non-stable state should have an owner.
STATE OWNER:Who is accountable for the state record?RESPONSE OWNER:Who must act?REPAIR OWNER:Who restores function?VERIFICATION OWNER:Who checks the repair?ESCALATION OWNER:Who acts if the route fails?
A state without ownership becomes an observation without movement.
State Review
Every non-stable state requires a review interval.
NEXT REVIEW:Time or conditionREQUIRED EVIDENCE:What must be observed?POSSIBLE TRANSITIONS:Which states are available?ESCALATION CONDITION:What triggers stronger action?
This prevents stale labels.
The State Record
Every major Civilisation Atlas object should carry a canonical state record.
CIVILISATION STATE RECORDSTATE_ID:Unique recordOBJECT_ID:Canonical Atlas objectCURRENT_STATE:Unknown / Stable / Loaded / Drifting /Critical / Failed / Stabilising /Repairing / RegeneratingPREVIOUS_STATE:Last declared conditionSTATE_START:When did the current state begin?RUNTIME_PHASE:P0 to P4LIFECYCLE:Takeoff / Climb / Cruise / DescentPRIMARY_INVARIANT:What must remain true?TRIGGER:What changed first?ROOT_CAUSE:What deeper condition is producing the state?SUPPORTING_SIGNALS:Which readings justify the state?CONFIDENCE:High / Moderate / Low / ContestedALERT:Green / Blue / Amber / Red / PurpleDEPENDENCY AT RISK:Which lower floor matters most?BUFFER:What remains available?THRESHOLD:Which boundary is near or crossed?CASCADE:What may be affected next?RESPONSE:Observe / Verify / Stabilise /Repair / RegenerateOWNER:Who acts?NEXT_REVIEW:When or under what condition?EXIT CONDITION:What evidence allows transition?
The Transition Record
Every state movement should also be recorded.
STATE TRANSITION RECORDTRANSITION_ID:Unique identifierOBJECT_ID:Canonical objectFROM_STATE:Previous stateTO_STATE:New stateDATE:When declared?TRIGGER:What initiated review?EVIDENCE:What justified transition?THRESHOLD:What boundary was crossed?CONFIDENCE:How certain?AUTHORITY:Who approved the state change?ACTION:What follows?REVERSAL CONDITION:What would return the objectto the previous or safer state?SOURCE:Evidence and canonical records
This creates an audit trail.
Civilisation memory should preserve not only the final state, but how the judgement changed.
Worked State Map: A Mathematics Learner
OBJECT:Secondary Mathematics learnerINVARIANT:Independent and transferable mathematical reasoning
Stable
The learner can:
- recognise question structure;
- select valid methods;
- show complete workings;
- check results;
- and transfer learning.
Loaded
New school topics and examination preparation increase demand.
The learner remains accurate but needs more time.
Drifting
Signs include:
- repeated algebraic errors;
- incomplete reasoning;
- rising prompt dependence;
- and avoidance of unfamiliar questions.
Critical
The learner can complete only highly familiar question forms and cannot begin unfamiliar problems independently.
Failed
The learner no longer possesses sufficient prerequisite control to access the current topic.
Stabilising
The tutor reduces topic load and returns to prerequisite concepts.
Repairing
The learner rebuilds concepts through explanation, guided practice, retrieval and correction.
Regenerating
The learner can identify errors, explain methods and transfer the concept without support.
Return to Stable
Independent performance remains valid across several lessons and assessment conditions.
Worked State Map: A Small-Group Class
OBJECT:Three-student tuition classINVARIANT:Each student receives enough diagnosis,correction and transfer testingto become more independent
Stable
All three students receive meaningful attention.
Instruction remains paced to actual learning.
Loaded
One student requires intensive repair while the other two continue progressing.
Drifting
The tutor begins teaching to the fastest learner.
The other students complete work without sufficient correction.
Critical
Class time can no longer preserve individual diagnosis for all three students.
Failed
The class operates as a lecture while still being presented as personalised small-group tuition.
Stabilising
Content load is reduced and student pathways are separated.
Repairing
Each learner receives targeted correction and independent transfer tasks.
Regenerating
The class develops routines that make future misconceptions visible earlier.
Worked State Map: The MRT
OBJECT:Urban rail systemINVARIANT:Safe and dependable mass movement
Stable
Normal service is maintained with adequate maintenance and recovery capacity.
Loaded
Passenger demand is elevated, but the system remains reliable.
Drifting
Fault frequency and recovery time begin to rise.
Critical
Redundancy is low and another failure may disrupt a major corridor.
Failed
Safe dependable movement cannot be maintained on part or all of the network.
Stabilising
Passengers are rerouted and the affected section is isolated.
Repairing
Components, signalling or operating procedures are restored.
Regenerating
Incident learning leads to stronger redundancy, maintenance and operator capability.
Worked State Map: A National Water System
OBJECT:National water systemINVARIANT:Safe and sufficient water continuity
Stable
Supply, quality and reserves remain inside the safe corridor.
Loaded
Drought or demand temporarily increases pressure.
Drifting
Reservoir levels fall while replenishment remains weak.
Critical
Emergency reserves approach minimum thresholds.
Failed
Safe and sufficient water cannot be maintained.
Stabilising
Demand restrictions and emergency supply protect essential use.
Repairing
Infrastructure, treatment, leakage and supply diversity are restored.
Regenerating
The system operates with improved conservation, reuse, resilience and ecological alignment.
Worked State Map: Artificial Intelligence in Education
OBJECT:AI-assisted education systemINVARIANT:AI extends learning while preservingtruth, judgement, memory and independence
Stable
AI is used within clear boundaries.
Outputs are verified.
Learners retain independent capability.
Loaded
AI use expands faster than teacher review capacity.
Drifting
Unverified output increases and students begin outsourcing reasoning.
Critical
Learners can complete major tasks only with AI assistance.
Failed
The visible work remains strong while underlying learner capability has collapsed.
Stabilising
AI access is limited for selected tasks and independent assessment is restored.
Repairing
Students rebuild retrieval, reasoning, source checking and explanation.
Regenerating
AI becomes a tool for deeper questioning, feedback and self-correction rather than substitution.
Worked State Map: A Civilisation Organ
OBJECT:EducationOSINVARIANT:Civilisation capability is transferredreliably into the next generation
Stable
Foundational learning, advanced capability, teacher supply and institutional trust remain functional.
Loaded
Population change, technological transition or curriculum expansion increase demand.
Drifting
Marks remain acceptable while literacy, reasoning or teacher capacity weaken.
Critical
The system can no longer repair foundational gaps at sufficient scale.
Failed
Credentials continue but capability transfer becomes unreliable.
Stabilising
Load is reduced and foundational priorities are restored.
Repairing
Teacher capability, learning sequence, assessment integrity and support systems are rebuilt.
Regenerating
The system detects learning failure earlier, adapts more effectively and develops stronger independent learners and future teachers.
State Crosswalk with Runtime Phase
The nine states can be crosswalked provisionally with the runtime phases.
P0:FailedP1:CriticalStabilisingEarly RepairingP2:LoadedDriftingLate RepairingP3:StableRegeneratingP4:Bounded frontier operation,which may be Stable, Loaded or Driftinginside its declared experiment corridor
This is not a rigid equation.
It is a practical crosswalk.
State Crosswalk with Lifecycle
TAKEOFF:UnknownLoadedDriftingRepairingCLIMB:StableLoadedDriftingCRUISE:StableLoadedRegeneratingDESCENT:DriftingCriticalFailedStabilisingRepairing
Any lifecycle can contain several states.
But certain state patterns may be more common.
State Crosswalk with Alerts
UNKNOWN:GreySTABLE:GreenLOADED:BlueDRIFTING:AmberCRITICAL:RedFAILED:RedSTABILISING:PurpleREPAIRING:PurpleREGENERATING:Purple moving towards Green
Grey may be used internally where state evidence is insufficient.
The State Summary Card
A reader-facing article may display:
CURRENT CONTROL TOWER STATEObject:Secondary Mathematics learnerState:DriftingAlert:AmberWhat remains functional:Familiar question proceduresWhat is weakening:Independent recognition and algebra accuracyMain pressure:New content arriving before foundations stabiliseFailure threshold:Cannot begin unfamiliar questions independentlyCurrent route:Reduce load, rebuild prerequisites and verify transfer
This gives the reader a clear operating picture.
The Control Tower State Board
The future Control Tower interface should offer several views.
Current State View
What is the declared condition now?
Transition View
How did the object arrive here?
Threshold View
Which boundary is near or crossed?
Cause View
What is the trigger and deeper cause?
Cascade View
What other objects may change state?
Ownership View
Who must respond?
Repair View
What evidence shows recovery?
Historical State View
Has this pattern occurred before?
The State Update Runtime
SELECT OBJECT→ retrieve invariant→ load current state→ collect new sensor readings→ test signal quality→ compare baseline and thresholds→ identify persistence and trend→ distinguish trigger from root cause→ evaluate cascade risk→ declare or retain state→ assign alert→ route response→ set next review→ preserve transition record
State Governance
State declarations can influence:
- funding;
- institutional reputation;
- public confidence;
- student pathways;
- emergency action;
- and political authority.
They therefore require governance.
The Control Tower should declare:
WHO MAY PROPOSE A STATE CHANGE?WHO VERIFIES IT?WHO APPROVES IT?WHO MAY CHALLENGE IT?WHAT EVIDENCE IS VISIBLE?WHEN MUST IT BE REVIEWED?
State classification must not become an unchallengeable label.
Provisional States
Where evidence is incomplete, the Control Tower may use:
PROVISIONAL DRIFTPROVISIONAL CRITICALPROVISIONAL REPAIR
A provisional state should include:
- confidence;
- evidence limitation;
- immediate precaution;
- and verification deadline.
Disputed States
Two credible observers may disagree.
For example:
Official view:StableFrontline view:DriftingPublic view:CriticalIndependent audit:Loaded
The Control Tower should display the disagreement rather than manufacture false consensus.
The correct state may be:
STATE:ContestedOPERATING PRECAUTION:Treat as Drifting until verification
State Manipulation
Institutions may resist an adverse state because it affects reputation, authority or funding.
Common manipulation patterns include:
- redefining the invariant;
- changing the baseline;
- removing a sensor;
- delaying reports;
- narrowing the object boundary;
- blaming local operators;
- or declaring repair complete through activity measures.
The Control Tower should preserve:
- historical baselines;
- sensor definitions;
- transition records;
- and independent verification.
Premature Return to Green
A system may be declared stable too early.
Warning signs include:
- temporary support still active;
- unresolved root cause;
- no real-load testing;
- repaired output but weak dependencies;
- no successor training;
- and recurrence risk remaining high.
The return-to-Green test should require:
FUNCTION RESTOREDDEPENDENCIES RESTOREDBUFFER RENEWEDTEMPORARY SUPPORT REDUCEDREAL LOAD TESTEDRECURRENCE FALLINGSUCCESSOR CAPABILITY PRESENT
Permanent Emergency
A system may remain in Critical or Stabilising state for so long that emergency operation becomes normal.
This creates:
- operator exhaustion;
- institutional shortcuts;
- deferred maintenance;
- public adaptation to poor service;
- and loss of the original invariant.
The Control Tower should flag:
PROLONGED EMERGENCY STATECURRENT DURATION:Beyond safe periodRISK:Temporary workaround becoming permanent systemREQUIRED DECISION:Repair, redesign or formally replace
Replacement State
Sometimes the original object cannot or should not be restored.
The Control Tower may declare:
STATE:Replacement Required
This is not one of the nine ordinary operating states.
It is a strategic decision that the invariant should be transferred into a new structure.
For example:
- an obsolete record system;
- an institution that cannot be repaired;
- unsafe infrastructure;
- or a process whose incentives repeatedly invert its function.
Replacement must preserve the valid invariant.
Sunset State
Some objects should end.
A Sunset State is appropriate where:
- the function is no longer necessary;
- a better system has taken over;
- continued operation creates greater harm;
- or maintenance cost exceeds valid benefit.
The Control Tower should distinguish:
FAILUREfromPLANNED COMPLETION
Ending an obsolete object may protect civilisation capacity.
Frontier State
A P4 frontier object should carry an experimental state overlay.
FRONTIER STATE:ProposedTestingBounded OperationPausedExpandedTerminatedIntegrated
A frontier project should not be classified simply as Stable because it functions once.
It must remain inside its declared experimental corridor.
The Purple Report State Feed
The Purple Report can translate current events into state movements.
EVENT:New policy announcedOBJECT:Education systemPREVIOUS STATE:DriftingPOSSIBLE TRANSITION:RepairingEVIDENCE REQUIRED:Implementation, teacher capacity,learning improvement and reduced recurrenceCURRENT STATE:Remain Drifting until operational evidence appears
This prevents announcements from being mistaken for repair.
Education State Spine
The education-to-civilisation state movement can be expressed as:
Learner confusion→ local driftRepeated cohort weakness→ classroom driftWidespread classroom drift→ institutional warningPersistent national transfer weakness→ EducationOS critical stateEducationOS failure→ workforce and institutional capability declineRepair→ rebuild foundations, teachers and measurementRegeneration→ stronger independent learningand successor capability
This allows eduKateSG classroom observations to connect upward without overstating scale.
AI Extraction Box
OBJECT:CIVILISATION.ATLAS.STATE.TRANSITION.MAP.v1.0PURPOSE:Convert validated signals intodeclared operating states,alerts and transition records.PRIMARY STATES:1. Unknown2. Stable3. Loaded4. Drifting5. Critical6. Failed7. Stabilising8. Repairing9. RegeneratingNORMAL DETERIORATION PATH:Stable→ Loaded→ Drifting→ Critical→ FailedNORMAL RECOVERY PATH:Failed→ Stabilising→ Repairing→ Regenerating→ StableALERT CROSSWALK:Unknown= GreyStable= GreenLoaded= BlueDrifting= AmberCritical / Failed= RedStabilising / Repairing / Regenerating= PurpleSTATE TRANSITION UNIT:From State+ Trigger+ Evidence+ Threshold+ To State+ Response+ ReviewCORE DISTINCTIONS:State ≠ CapabilityState ≠ LifecycleState ≠ Runtime PhaseStabilisation ≠ RepairRepair ≠ RegenerationActivity ≠ Restored FunctionAnnouncement ≠ State ChangeOne Good Reading ≠ Stable RecoveryFAILURE RULE:An object is failed when itsprimary invariant is no longer preserved,even if visible activity continues.REPAIR RULE:Repair is complete only whenvalid function is demonstratedunder real operating conditions.REGENERATION RULE:Regeneration requires stronger sensing,maintenance, buffer, successionand future self-correction.GOVERNANCE RULE:Every non-stable state must declareevidence, confidence, owner,response and next review.FINAL LOCK:The Control Tower should not waitfor collapse before changing state.It should detect the transitionwhile repair remains possible.
Final Lock
Civilisation rarely moves from normal operation to collapse in one clean step.
The movement is usually:
pressure→ higher load→ falling buffer→ repeated workaround→ hidden debt→ persistent drift→ threshold crossing→ visible failure
Repair moves in the opposite direction:
containment→ stabilisation→ lower-floor restoration→ function recovery→ real-load testing→ renewed buffer→ stronger self-correction→ stable continuity
The State Transition and Alert Map gives the Control Tower a disciplined way to describe this movement.
It asks:
WHAT STATE IS THE OBJECT IN?WHAT WAS ITS PREVIOUS STATE?WHAT SIGNAL JUSTIFIES THE CHANGE?WHICH THRESHOLD WAS CROSSED?HOW CERTAIN IS THE READING?WHAT IS THE ALERT LEVEL?WHO MUST RESPOND?WHAT EVIDENCE ALLOWS RECOVERY?WHEN WILL THE STATE BE REVIEWED?
The Object-Class System tells us what the object is.
The Ten-Coordinate Method tells us where it sits.
The Relationship Graph shows what it connects to.
The Dependency Map shows what supports it.
The Sensor Map shows what is changing.
The State Transition Map declares what that change means.
The complete route is:
OBSERVE THE SIGNAL→ VERIFY THE READING→ COMPARE THE THRESHOLD→ DECLARE THE STATE→ ASSIGN THE ALERT→ ROUTE THE RESPONSE→ VERIFY THE TRANSITION→ PRESERVE THE STATE HISTORY→ TEACH THE REPAIR FORWARD
A civilisation becomes governable when it can recognise movement before movement becomes catastrophe.
The State Transition and Alert Map is the Control Tower instrument that makes that recognition possible.
