Civilisation Atlas Control Tower | The State Transition and Alert Map

The State Transition and Alert Map: How Civilisation Moves from Stability into Drift, Failure, Repair and Regeneration

A sensor reading is not yet a system state.

A delay may be temporary.

A poor examination result may be local.

A sudden rise in demand may remain within safe capacity.

A public complaint may identify a real failure, a communication problem or an isolated experience.

The Civilisation Atlas Control Tower must therefore do more than collect signals.

It must determine when those signals represent a meaningful change in the operating condition of the object.

It must know when:

  • ordinary variation becomes pressure;
  • pressure becomes sustained load;
  • load begins to consume buffers;
  • buffer loss becomes drift;
  • drift approaches a threshold;
  • threshold crossing becomes failure;
  • stabilisation becomes repair;
  • and repair becomes regeneration.

This requires a state model.

Without a state model, the Control Tower may react too early, too late or in the wrong direction.

It may treat noise as crisis.

It may treat visible activity as successful repair.

It may continue reporting a system as functional after its invariant has already failed.

The State Transition and Alert Map is the instrument that converts observation into an operating judgement.


One-Sentence Definition

The State Transition and Alert Map is the Control Tower instrument that converts validated sensor readings into declared operating states, threshold transitions, alert levels and repair conditions for every Civilisation Atlas object.

In compact form:

SIGNALS
→ compared with baselines
→ interpreted against the invariant
→ tested against thresholds
→ assigned an operating state
→ connected to an alert
→ routed towards observation,
stabilisation, repair or regeneration

The map answers:

What state is the object in now?

What changed?

Is the change temporary or structural?

Which threshold has been crossed?

What response is justified?

What evidence is required before the state can be upgraded or downgraded?


Why State Must Be Declared

A civilisation object may appear different depending on who is observing it.

A school leader may see:

  • stable attendance;
  • completed curriculum;
  • and acceptable examination results.

A teacher may see:

  • rising misconceptions;
  • less correction time;
  • more student dependence;
  • and lower confidence.

A parent may see:

  • increasing homework stress;
  • fluctuating marks;
  • and weaker independence.

A student may experience:

  • confusion;
  • memory overload;
  • and inability to begin unfamiliar questions.

All these observations may be valid.

The Control Tower must integrate them without collapsing them into one vague conclusion.

A declared state provides a disciplined summary:

OBJECT:
Secondary Mathematics learner
CURRENT STATE:
Functional but stressed
MAIN PRESSURE:
New algebra arriving before foundations stabilise
BUFFER:
Tutor guidance and repeated practice
DRIFT SIGNAL:
Increasing prompt dependence
FAILURE THRESHOLD:
Cannot recognise the required method independently
CURRENT ALERT:
Warning

The state is not a label of identity.

It is a temporary operating judgement.


State Is Not Capability

An object may possess advanced capability while operating poorly.

A hospital may contain advanced medical technology but be overloaded.

A nation may possess Stage 4 digital systems while its administrative records weaken.

A learner may understand advanced concepts but perform poorly under examination pressure.

A civilisation may retain Stage 3 industrial capacity while moving through lifecycle descent.

The Control Tower therefore preserves:

CAPABILITY
=
what the object can reliably do
under valid conditions
STATE
=
how well the object is operating
under present conditions

The two should never be merged.


State Is Not Lifecycle

Lifecycle describes the broader path:

TAKEOFF
CLIMB
CRUISE
DESCENT

State describes the present operational condition.

A system in Cruise may temporarily enter a critical state during shock.

A system in Descent may contain a local institution in stable repair.

For example:

LIFECYCLE:
Cruise
CURRENT STATE:
Critical disruption
CAUSE:
Sudden power failure

or:

LIFECYCLE:
Descent
CURRENT LOCAL STATE:
Repairing
CAUSE:
New leadership, retraining and restored records

Lifecycle and state operate at different time depths.


State Is Not Phase

Runtime Phase provides the broader functional floor:

P0 — Below viable operation
P1 — Fragile
P2 — Functional but stressed
P3 — Stable regenerative continuity
P4 — Bounded frontier operation

The State Transition Map provides more detailed movement inside and between these phases.

For example:

P2 FUNCTIONAL BUT STRESSED
may contain states such as:
Holding
Loaded
Drifting
Warning
Stabilising

The phase is the operating band.

The state is the present position and direction inside that band.


The Nine Control Tower States

The Control Tower uses nine primary operating states.

1. Unknown
2. Stable
3. Loaded
4. Drifting
5. Critical
6. Failed
7. Stabilising
8. Repairing
9. Regenerating

These states create a complete cycle from uncertainty through normal operation, deterioration, failure and recovery.


State 1: Unknown

The object cannot yet be located reliably

Unknown does not mean safe.

It means the available evidence is insufficient, contradictory, delayed or missing.

STATE:
Unknown
POSSIBLE CAUSES:
No sensor
Sensor offline
Conflicting readings
Unclear object boundary
Missing baseline
Unverified report
Rapidly changing condition

Unknown is one of the most important states in the Control Tower because false certainty can be more dangerous than acknowledged uncertainty.

Unknown-State response

The default response is:

OBSERVE
VERIFY
IMPROVE SENSING
DO NOT OVERSTATE

Where potential consequences are severe, the Control Tower may also recommend precautionary stabilisation.


State 2: Stable

The object is operating within its valid corridor

A stable object:

  • preserves its invariant;
  • carries normal load;
  • maintains sufficient buffer;
  • repairs ordinary errors;
  • and shows no sustained adverse drift.

Stable does not mean perfect.

A stable school still contains struggling students.

A stable railway still experiences minor delays.

A stable government still makes errors.

The defining feature is:

The system can detect and correct ordinary variation without losing its core function.

STATE:
Stable
FUNCTION:
Valid
LOAD:
Within capacity
BUFFER:
Sufficient
DRIFT:
No persistent adverse movement
REPAIR:
Routine and effective

Stable-State response

CONTINUE OPERATION
MAINTAIN SENSORS
RENEW DEPENDENCIES
PRESERVE SLACK
AVOID COMPLACENCY

State 3: Loaded

The object is carrying elevated demand but remains inside its corridor

A loaded system is not yet drifting.

It may be under:

  • examination pressure;
  • seasonal passenger demand;
  • hospital surge;
  • temporary financial stress;
  • increased information volume;
  • or emergency workload.

The object continues to preserve its invariant.

But:

  • buffers are being consumed;
  • operator effort rises;
  • recovery time may lengthen;
  • and maintenance may become vulnerable.
STATE:
Loaded
FUNCTION:
Still valid
LOAD:
Above normal
BUFFER:
Being consumed
OPERATOR EFFORT:
Rising
RISK:
Drift if load persists

Loaded-State response

MONITOR MORE FREQUENTLY
PROTECT CRITICAL BUFFER
REDUCE NON-ESSENTIAL LOAD
PREPARE SUPPORT
DECLARE REVIEW TIME

A loaded state should not be treated as failure.

But it should not be ignored.


State 4: Drifting

The object is moving away from its valid operating corridor

Drift begins when adverse movement becomes persistent.

Examples include:

  • error frequency rising;
  • maintenance backlog growing;
  • response time lengthening;
  • public trust weakening;
  • transfer quality falling;
  • or temporary workarounds becoming normal practice.

The object may still produce visible output.

Its foundations are becoming less reliable.

STATE:
Drifting
FUNCTION:
Still visible
INTEGRITY:
Weakening
BUFFER:
Falling
DEPENDENCY DEBT:
Rising
TIME VECTOR:
Adverse and persistent

Drift is often the best repair window.

The system is still functional enough to intervene without full emergency conditions.

Drift-State response

VERIFY THE DRIFT
LOCATE THE LOWER FLOOR
REDUCE LOAD
STOP NEW DEBT
ASSIGN REPAIR OWNER
DECLARE WARNING THRESHOLD

State 5: Critical

The object is approaching or crossing a functional threshold

Critical means:

  • the operating corridor is narrow;
  • buffers are nearly exhausted;
  • failure consequences are serious;
  • and ordinary correction is no longer sufficient.

The system may still function.

But one additional disruption could cause failure.

STATE:
Critical
FUNCTION:
Intermittently valid
BUFFER:
Minimal
FAILURE THRESHOLD:
Near or partially crossed
CASCADE RISK:
High
RESPONSE TIME:
Short

Critical-State response

STABILISE
PROTECT LIFE AND CORE FUNCTION
STOP NON-ESSENTIAL EXPANSION
ACTIVATE REDUNDANCY
ESCALATE AUTHORITY
INCREASE SENSOR FREQUENCY

A critical state is not the time for unbounded experimentation.

The first objective is to preserve the invariant.


State 6: Failed

The object can no longer preserve its invariant function

Failure is defined by function, not appearance.

A school has failed educationally when attendance and completion no longer produce reliable learning.

A transport system has failed when safe dependable movement cannot be maintained.

A government institution has failed when it can no longer coordinate, implement or correct its declared mandate.

An AI-assisted education system has failed when it generates completed work while the learner loses understanding and independent capability.

STATE:
Failed
INVARIANT:
Not preserved
VISIBLE ACTIVITY:
May continue
FUNCTIONAL OUTPUT:
Invalid, absent or unsafe
CASCADE:
Active or imminent

Failed-State response

PROTECT PEOPLE
ISOLATE THE FAILURE
PRESERVE RECORDS
RESTORE THE LOWEST BROKEN FLOOR
DECLARE TEMPORARY ALTERNATIVE
BEGIN ROOT-CAUSE ANALYSIS

The goal is not to defend the appearance of continuity.

It is to restore valid function.


State 7: Stabilising

The object is no longer deteriorating, but full function is not yet restored

Stabilisation stops further damage.

Examples include:

  • emergency power restored;
  • class load temporarily reduced;
  • additional hospital staff deployed;
  • unsafe system isolated;
  • financial liquidity supplied;
  • or misinformation source removed.
STATE:
Stabilising
DAMAGE RATE:
Falling
CORE FUNCTION:
Partially restored or protected
DEPENDENCY FLOOR:
Still fragile
TEMPORARY SUPPORT:
Active

Stabilisation is necessary.

But it can become a trap if temporary measures become permanent substitutes for repair.

Stabilising-State response

CONFIRM DAMAGE HAS STOPPED
IDENTIFY TEMPORARY SUPPORT
LOCATE ROOT FAILURE
SET REPAIR SEQUENCE
DEFINE EXIT CONDITIONS

State 8: Repairing

The object is restoring the broken capability and its supporting dependencies

Repair differs from stabilisation.

Stabilisation stops decline.

Repair restores function.

Examples include:

  • rebuilding mathematical foundations;
  • replacing rail components;
  • retraining operators;
  • correcting records;
  • redesigning an overloaded process;
  • rebuilding trust through reliable action;
  • or restoring ecological capacity.
STATE:
Repairing
FUNCTION:
Returning
ROOT CAUSE:
Located sufficiently
DEPENDENCY FLOOR:
Being restored
ERROR RECURRENCE:
Falling
VERIFICATION:
In progress

Repairing-State response

CONTINUE RESTORATION
VERIFY EACH DEPENDENCY
TEST UNDER REAL LOAD
REMOVE TEMPORARY SUPPORT GRADUALLY
CHECK FOR RECURRING FAILURE

Repair is not complete because work has been performed.

Repair is complete when valid function is demonstrated.


State 9: Regenerating

The object has restored function and improved future continuity

Regeneration is the strongest recovery state.

A regenerating object:

  • performs its function;
  • detects errors earlier;
  • maintains stronger buffers;
  • carries lower dependency debt;
  • trains successors;
  • and reduces the probability of repeated failure.
STATE:
Regenerating
FUNCTION:
Restored
BUFFER:
Renewed
SENSING:
Improved
REPAIR RATE:
Higher
SUCCESSION:
Strengthened
FUTURE FAILURE RISK:
Reduced

Regenerating-State response

DOCUMENT THE REPAIR
TRANSFER THE LESSON
UPDATE STANDARDS
TRAIN SUCCESSORS
REVIEW AFTER TIME DELAY
RETURN TO STABLE STATE WHEN VERIFIED

Regeneration is not a permanent badge.

After verification, the object returns to Stable with a stronger operating floor.


The Main State Cycle

The normal deterioration cycle is:

STABLE
→ LOADED
→ DRIFTING
→ CRITICAL
→ FAILED

The recovery cycle is:

FAILED
→ STABILISING
→ REPAIRING
→ REGENERATING
→ STABLE

The system may move backwards or skip states.

For example:

STABLE
→ FAILED

through sudden shock.

Or:

DRIFTING
→ STABLE

through early successful correction.

The state map is not a rigid staircase.

It is a controlled vocabulary for movement.


State Transition Conditions

Every movement between states should be triggered by declared evidence.

FROM STATE
→ transition condition
→ TO STATE

For example:

STABLE
→ sustained load above normal range
→ LOADED
LOADED
→ buffer falling and adverse trend persisting
→ DRIFTING
DRIFTING
→ warning threshold reached
→ CRITICAL
CRITICAL
→ invariant lost
→ FAILED
FAILED
→ damage contained
→ STABILISING
STABILISING
→ root dependency restoration begins
→ REPAIRING
REPAIRING
→ valid function demonstrated
→ REGENERATING
REGENERATING
→ function sustained across time and load
→ STABLE

Transition Evidence

A state transition should not depend on one unsupported judgement.

The Control Tower should seek:

SIGNAL TREND
+
THRESHOLD CONDITION
+
INDEPENDENT CONFIRMATION
+
OPERATOR REVIEW
+
EVIDENCE CONFIDENCE

The required level of evidence depends on consequence.

A state upgrade may require stronger evidence than a precautionary downgrade.

For example:

  • entering Critical may require credible warning evidence;
  • returning to Stable should require sustained proof.

State Downgrade and Upgrade

A downgrade means movement towards greater risk.

Stable
→ Loaded
→ Drifting
→ Critical
→ Failed

An upgrade means movement towards restored function.

Failed
→ Stabilising
→ Repairing
→ Regenerating
→ Stable

Upgrades should be conservative.

A single good reading should not erase a sustained failure pattern.

The Control Tower should require:

  • repeated valid readings;
  • real-load testing;
  • repaired dependencies;
  • and reduced recurrence.

Hysteresis

A system may require more recovery than the amount of decline that caused failure.

This is called hysteresis.

For example:

FAILURE THRESHOLD:
Trust falls below a critical level
RECOVERY THRESHOLD:
Trust must rise substantially above that level
before normal coordination returns

Or:

STUDENT FAILURE:
Cannot perform independently
RECOVERY:
Must demonstrate repeated independent transfer,
not merely one correct answer

The Control Tower should therefore maintain separate:

FAILURE THRESHOLD
and
RECOVERY THRESHOLD

State Persistence

A state should have a minimum persistence rule where appropriate.

One adverse reading may not justify Drifting.

One positive reading may not justify Regenerating.

STATE PERSISTENCE:
Single event
Repeated event
Sustained trend
Cross-system pattern
Threshold crossing

The correct persistence depends on the object.

A life-support failure requires immediate classification.

A cultural or educational trend may require longer observation.


State Confidence

Every state declaration should carry confidence.

HIGH CONFIDENCE
MODERATE CONFIDENCE
LOW CONFIDENCE
CONTESTED
UNKNOWN

For example:

STATE:
Drifting
CONFIDENCE:
Moderate
EVIDENCE:
Rising error repetition,
teacher observation,
falling transfer performance
LIMITATION:
Short observation period

This preserves uncertainty without avoiding judgement.


Composite State

Large civilisation objects contain several local states.

A nation may be:

WaterOS:
Stable
EducationOS:
Drifting
TransportOS:
Loaded
GovernanceOS:
Stable but trust-sensitive
PlanetOS:
Critical long-term pressure
AI Capability:
Rapid Climb with P2 governance

The Control Tower should not compress this into one national label unless the purpose clearly requires it.

The correct form is a composite state board.


Dominant State

Where a summary is needed, the Control Tower may declare a dominant state.

The dominant state should be based on:

  • critical dependencies;
  • consequence;
  • spread;
  • and repair difficulty.

A small but critical failure may matter more than several stable peripheral systems.

DOMINANT STATE:
Critical
REASON:
Energy supply instability threatens
water, transport and healthcare

Dominant state is a routing judgement.

It is not an average.


Local State and System State

A local component may fail without the whole system failing.

LOCAL OBJECT:
One rail line
STATE:
Failed
WIDER SYSTEM:
Transport network
STATE:
Loaded but functional through alternatives

Alternatively, many local components may remain operational while the system relationship fails.

LOCAL INSTITUTIONS:
Operational
SYSTEM COORDINATION:
Failed

The Control Tower should state both.


State Propagation

A state may spread through dependency edges.

For example:

EnergyOS:
Critical
→ WaterOS:
Loaded
→ HealthOS:
Critical
→ TransportOS:
Drifting
→ Public Trust:
Warning

This is state propagation.

The Relationship Graph identifies the edges.

The State Map shows the movement.


State Containment

Containment prevents local failure from becoming systemic.

Containment methods include:

  • isolation;
  • redundancy;
  • local autonomy;
  • alternative routing;
  • reserves;
  • firebreaks;
  • and modular design.
LOCAL FAILURE
→ isolated from wider system
→ alternative route activated
→ repair proceeds without cascade

Containment is a major P3 capability.


State Synchronisation

Several systems may decline together because they share a lower dependency.

For example:

Power instability
causes simultaneous stress in
Water
Transport
Hospitals
Communications
Production

This is synchronised state change.

It may reveal common-mode dependency.

The Control Tower should investigate shared floors rather than treating each symptom independently.


Alert Levels

The State Map connects operating states to five principal alerts.

GREEN
Normal operation
BLUE
Elevated load
AMBER
Confirmed drift
RED
Critical or failed function
PURPLE
Repair and regeneration under active review

The colours are reader-facing labels.

The underlying state remains explicit.


Green Alert

STATE:
Stable
MEANING:
Function valid and self-correction working
ACTION:
Maintain, monitor and renew

Green does not mean stop observing.


Blue Alert

STATE:
Loaded
MEANING:
Elevated demand is consuming buffer
ACTION:
Increase observation and protect capacity

Blue identifies pressure before structural drift.


Amber Alert

STATE:
Drifting
MEANING:
Adverse movement is persistent
ACTION:
Verify, reduce load and begin repair

Amber is the main early-intervention corridor.


Red Alert

STATE:
Critical or Failed
MEANING:
The invariant is at immediate risk
or has already been lost
ACTION:
Stabilise, contain and restore

Red should be used sparingly.

Overuse creates alert fatigue.


Purple Alert

STATE:
Stabilising, Repairing or Regenerating
MEANING:
The object is under active restoration
ACTION:
Verify that repair is real,
sustained and transferable

Purple is not automatically positive.

It means the object is inside an active correction corridor.

This gives The Purple Report a direct operating relationship with the Control Tower: it can identify systems currently moving through stress, repair and regeneration rather than merely reporting isolated events.


Why Repair Needs Its Own Alert

A repaired system remains vulnerable.

During repair:

  • temporary support may hide weakness;
  • operators may overstate progress;
  • old failure patterns may return;
  • and new dependencies may be introduced.

The Purple state keeps the system under structured observation until regeneration is demonstrated.


Alert Priority

Alert priority depends on more than state.

The Control Tower should combine:

STATE SEVERITY
× CONSEQUENCE
× FAILURE VELOCITY
× SPREAD
× REVERSIBILITY
× CONFIDENCE

A slowly drifting foundational dependency may deserve greater priority than a visible but reversible local disruption.


Urgency and Importance

Urgency asks:

How quickly must action occur?

Importance asks:

How much civilisation function is at stake?

These should remain separate.

HIGH URGENCY
LOWER IMPORTANCE:
Local fast failure with easy replacement
LOW URGENCY
HIGH IMPORTANCE:
Generational decline in education or ecology

The Control Tower must protect attention from being consumed only by immediate events.


Reversibility

A state transition may be:

EASILY REVERSIBLE
REVERSIBLE WITH COST
DIFFICULT TO REVERSE
IRREVERSIBLE

Examples of difficult or irreversible change include:

  • species loss;
  • destruction of archives;
  • loss of rare expertise;
  • severe trust collapse;
  • and death.

Reversibility should influence alert priority.


State Duration

The same state can have different significance depending on duration.

SHORT LOADED STATE:
Normal surge
PROLONGED LOADED STATE:
Likely drift
SHORT CRITICAL STATE:
Emergency
PROLONGED CRITICAL STATE:
System transformation or collapse risk

The Control Tower should record:

STATE START
CURRENT DURATION
EXPECTED DURATION
MAXIMUM SAFE DURATION

State Cause

Every state should distinguish immediate trigger from deeper cause.

TRIGGER:
Examination approaching
DEEPER CAUSE:
Foundational gaps and insufficient retrieval
TRIGGER:
Train disruption
DEEPER CAUSE:
Component age and maintenance debt
TRIGGER:
Public controversy
DEEPER CAUSE:
Long-term trust debt

Treating the trigger alone may produce temporary stabilisation without repair.


State Owner

Every declared non-stable state should have an owner.

STATE OWNER:
Who is accountable for the state record?
RESPONSE OWNER:
Who must act?
REPAIR OWNER:
Who restores function?
VERIFICATION OWNER:
Who checks the repair?
ESCALATION OWNER:
Who acts if the route fails?

A state without ownership becomes an observation without movement.


State Review

Every non-stable state requires a review interval.

NEXT REVIEW:
Time or condition
REQUIRED EVIDENCE:
What must be observed?
POSSIBLE TRANSITIONS:
Which states are available?
ESCALATION CONDITION:
What triggers stronger action?

This prevents stale labels.


The State Record

Every major Civilisation Atlas object should carry a canonical state record.

CIVILISATION STATE RECORD
STATE_ID:
Unique record
OBJECT_ID:
Canonical Atlas object
CURRENT_STATE:
Unknown / Stable / Loaded / Drifting /
Critical / Failed / Stabilising /
Repairing / Regenerating
PREVIOUS_STATE:
Last declared condition
STATE_START:
When did the current state begin?
RUNTIME_PHASE:
P0 to P4
LIFECYCLE:
Takeoff / Climb / Cruise / Descent
PRIMARY_INVARIANT:
What must remain true?
TRIGGER:
What changed first?
ROOT_CAUSE:
What deeper condition is producing the state?
SUPPORTING_SIGNALS:
Which readings justify the state?
CONFIDENCE:
High / Moderate / Low / Contested
ALERT:
Green / Blue / Amber / Red / Purple
DEPENDENCY AT RISK:
Which lower floor matters most?
BUFFER:
What remains available?
THRESHOLD:
Which boundary is near or crossed?
CASCADE:
What may be affected next?
RESPONSE:
Observe / Verify / Stabilise /
Repair / Regenerate
OWNER:
Who acts?
NEXT_REVIEW:
When or under what condition?
EXIT CONDITION:
What evidence allows transition?

The Transition Record

Every state movement should also be recorded.

STATE TRANSITION RECORD
TRANSITION_ID:
Unique identifier
OBJECT_ID:
Canonical object
FROM_STATE:
Previous state
TO_STATE:
New state
DATE:
When declared?
TRIGGER:
What initiated review?
EVIDENCE:
What justified transition?
THRESHOLD:
What boundary was crossed?
CONFIDENCE:
How certain?
AUTHORITY:
Who approved the state change?
ACTION:
What follows?
REVERSAL CONDITION:
What would return the object
to the previous or safer state?
SOURCE:
Evidence and canonical records

This creates an audit trail.

Civilisation memory should preserve not only the final state, but how the judgement changed.


Worked State Map: A Mathematics Learner

OBJECT:
Secondary Mathematics learner
INVARIANT:
Independent and transferable mathematical reasoning

Stable

The learner can:

  • recognise question structure;
  • select valid methods;
  • show complete workings;
  • check results;
  • and transfer learning.

Loaded

New school topics and examination preparation increase demand.

The learner remains accurate but needs more time.

Drifting

Signs include:

  • repeated algebraic errors;
  • incomplete reasoning;
  • rising prompt dependence;
  • and avoidance of unfamiliar questions.

Critical

The learner can complete only highly familiar question forms and cannot begin unfamiliar problems independently.

Failed

The learner no longer possesses sufficient prerequisite control to access the current topic.

Stabilising

The tutor reduces topic load and returns to prerequisite concepts.

Repairing

The learner rebuilds concepts through explanation, guided practice, retrieval and correction.

Regenerating

The learner can identify errors, explain methods and transfer the concept without support.

Return to Stable

Independent performance remains valid across several lessons and assessment conditions.


Worked State Map: A Small-Group Class

OBJECT:
Three-student tuition class
INVARIANT:
Each student receives enough diagnosis,
correction and transfer testing
to become more independent

Stable

All three students receive meaningful attention.

Instruction remains paced to actual learning.

Loaded

One student requires intensive repair while the other two continue progressing.

Drifting

The tutor begins teaching to the fastest learner.

The other students complete work without sufficient correction.

Critical

Class time can no longer preserve individual diagnosis for all three students.

Failed

The class operates as a lecture while still being presented as personalised small-group tuition.

Stabilising

Content load is reduced and student pathways are separated.

Repairing

Each learner receives targeted correction and independent transfer tasks.

Regenerating

The class develops routines that make future misconceptions visible earlier.


Worked State Map: The MRT

OBJECT:
Urban rail system
INVARIANT:
Safe and dependable mass movement

Stable

Normal service is maintained with adequate maintenance and recovery capacity.

Loaded

Passenger demand is elevated, but the system remains reliable.

Drifting

Fault frequency and recovery time begin to rise.

Critical

Redundancy is low and another failure may disrupt a major corridor.

Failed

Safe dependable movement cannot be maintained on part or all of the network.

Stabilising

Passengers are rerouted and the affected section is isolated.

Repairing

Components, signalling or operating procedures are restored.

Regenerating

Incident learning leads to stronger redundancy, maintenance and operator capability.


Worked State Map: A National Water System

OBJECT:
National water system
INVARIANT:
Safe and sufficient water continuity

Stable

Supply, quality and reserves remain inside the safe corridor.

Loaded

Drought or demand temporarily increases pressure.

Drifting

Reservoir levels fall while replenishment remains weak.

Critical

Emergency reserves approach minimum thresholds.

Failed

Safe and sufficient water cannot be maintained.

Stabilising

Demand restrictions and emergency supply protect essential use.

Repairing

Infrastructure, treatment, leakage and supply diversity are restored.

Regenerating

The system operates with improved conservation, reuse, resilience and ecological alignment.


Worked State Map: Artificial Intelligence in Education

OBJECT:
AI-assisted education system
INVARIANT:
AI extends learning while preserving
truth, judgement, memory and independence

Stable

AI is used within clear boundaries.

Outputs are verified.

Learners retain independent capability.

Loaded

AI use expands faster than teacher review capacity.

Drifting

Unverified output increases and students begin outsourcing reasoning.

Critical

Learners can complete major tasks only with AI assistance.

Failed

The visible work remains strong while underlying learner capability has collapsed.

Stabilising

AI access is limited for selected tasks and independent assessment is restored.

Repairing

Students rebuild retrieval, reasoning, source checking and explanation.

Regenerating

AI becomes a tool for deeper questioning, feedback and self-correction rather than substitution.


Worked State Map: A Civilisation Organ

OBJECT:
EducationOS
INVARIANT:
Civilisation capability is transferred
reliably into the next generation

Stable

Foundational learning, advanced capability, teacher supply and institutional trust remain functional.

Loaded

Population change, technological transition or curriculum expansion increase demand.

Drifting

Marks remain acceptable while literacy, reasoning or teacher capacity weaken.

Critical

The system can no longer repair foundational gaps at sufficient scale.

Failed

Credentials continue but capability transfer becomes unreliable.

Stabilising

Load is reduced and foundational priorities are restored.

Repairing

Teacher capability, learning sequence, assessment integrity and support systems are rebuilt.

Regenerating

The system detects learning failure earlier, adapts more effectively and develops stronger independent learners and future teachers.


State Crosswalk with Runtime Phase

The nine states can be crosswalked provisionally with the runtime phases.

P0:
Failed
P1:
Critical
Stabilising
Early Repairing
P2:
Loaded
Drifting
Late Repairing
P3:
Stable
Regenerating
P4:
Bounded frontier operation,
which may be Stable, Loaded or Drifting
inside its declared experiment corridor

This is not a rigid equation.

It is a practical crosswalk.


State Crosswalk with Lifecycle

TAKEOFF:
Unknown
Loaded
Drifting
Repairing
CLIMB:
Stable
Loaded
Drifting
CRUISE:
Stable
Loaded
Regenerating
DESCENT:
Drifting
Critical
Failed
Stabilising
Repairing

Any lifecycle can contain several states.

But certain state patterns may be more common.


State Crosswalk with Alerts

UNKNOWN:
Grey
STABLE:
Green
LOADED:
Blue
DRIFTING:
Amber
CRITICAL:
Red
FAILED:
Red
STABILISING:
Purple
REPAIRING:
Purple
REGENERATING:
Purple moving towards Green

Grey may be used internally where state evidence is insufficient.


The State Summary Card

A reader-facing article may display:

CURRENT CONTROL TOWER STATE
Object:
Secondary Mathematics learner
State:
Drifting
Alert:
Amber
What remains functional:
Familiar question procedures
What is weakening:
Independent recognition and algebra accuracy
Main pressure:
New content arriving before foundations stabilise
Failure threshold:
Cannot begin unfamiliar questions independently
Current route:
Reduce load, rebuild prerequisites and verify transfer

This gives the reader a clear operating picture.


The Control Tower State Board

The future Control Tower interface should offer several views.

Current State View

What is the declared condition now?

Transition View

How did the object arrive here?

Threshold View

Which boundary is near or crossed?

Cause View

What is the trigger and deeper cause?

Cascade View

What other objects may change state?

Ownership View

Who must respond?

Repair View

What evidence shows recovery?

Historical State View

Has this pattern occurred before?


The State Update Runtime

SELECT OBJECT
→ retrieve invariant
→ load current state
→ collect new sensor readings
→ test signal quality
→ compare baseline and thresholds
→ identify persistence and trend
→ distinguish trigger from root cause
→ evaluate cascade risk
declare or retain state
→ assign alert
→ route response
set next review
preserve transition record

State Governance

State declarations can influence:

  • funding;
  • institutional reputation;
  • public confidence;
  • student pathways;
  • emergency action;
  • and political authority.

They therefore require governance.

The Control Tower should declare:

WHO MAY PROPOSE A STATE CHANGE?
WHO VERIFIES IT?
WHO APPROVES IT?
WHO MAY CHALLENGE IT?
WHAT EVIDENCE IS VISIBLE?
WHEN MUST IT BE REVIEWED?

State classification must not become an unchallengeable label.


Provisional States

Where evidence is incomplete, the Control Tower may use:

PROVISIONAL DRIFT
PROVISIONAL CRITICAL
PROVISIONAL REPAIR

A provisional state should include:

  • confidence;
  • evidence limitation;
  • immediate precaution;
  • and verification deadline.

Disputed States

Two credible observers may disagree.

For example:

Official view:
Stable
Frontline view:
Drifting
Public view:
Critical
Independent audit:
Loaded

The Control Tower should display the disagreement rather than manufacture false consensus.

The correct state may be:

STATE:
Contested
OPERATING PRECAUTION:
Treat as Drifting until verification

State Manipulation

Institutions may resist an adverse state because it affects reputation, authority or funding.

Common manipulation patterns include:

  • redefining the invariant;
  • changing the baseline;
  • removing a sensor;
  • delaying reports;
  • narrowing the object boundary;
  • blaming local operators;
  • or declaring repair complete through activity measures.

The Control Tower should preserve:

  • historical baselines;
  • sensor definitions;
  • transition records;
  • and independent verification.

Premature Return to Green

A system may be declared stable too early.

Warning signs include:

  • temporary support still active;
  • unresolved root cause;
  • no real-load testing;
  • repaired output but weak dependencies;
  • no successor training;
  • and recurrence risk remaining high.

The return-to-Green test should require:

FUNCTION RESTORED
DEPENDENCIES RESTORED
BUFFER RENEWED
TEMPORARY SUPPORT REDUCED
REAL LOAD TESTED
RECURRENCE FALLING
SUCCESSOR CAPABILITY PRESENT

Permanent Emergency

A system may remain in Critical or Stabilising state for so long that emergency operation becomes normal.

This creates:

  • operator exhaustion;
  • institutional shortcuts;
  • deferred maintenance;
  • public adaptation to poor service;
  • and loss of the original invariant.

The Control Tower should flag:

PROLONGED EMERGENCY STATE
CURRENT DURATION:
Beyond safe period
RISK:
Temporary workaround becoming permanent system
REQUIRED DECISION:
Repair, redesign or formally replace

Replacement State

Sometimes the original object cannot or should not be restored.

The Control Tower may declare:

STATE:
Replacement Required

This is not one of the nine ordinary operating states.

It is a strategic decision that the invariant should be transferred into a new structure.

For example:

  • an obsolete record system;
  • an institution that cannot be repaired;
  • unsafe infrastructure;
  • or a process whose incentives repeatedly invert its function.

Replacement must preserve the valid invariant.


Sunset State

Some objects should end.

A Sunset State is appropriate where:

  • the function is no longer necessary;
  • a better system has taken over;
  • continued operation creates greater harm;
  • or maintenance cost exceeds valid benefit.

The Control Tower should distinguish:

FAILURE
from
PLANNED COMPLETION

Ending an obsolete object may protect civilisation capacity.


Frontier State

A P4 frontier object should carry an experimental state overlay.

FRONTIER STATE:
Proposed
Testing
Bounded Operation
Paused
Expanded
Terminated
Integrated

A frontier project should not be classified simply as Stable because it functions once.

It must remain inside its declared experimental corridor.


The Purple Report State Feed

The Purple Report can translate current events into state movements.

EVENT:
New policy announced
OBJECT:
Education system
PREVIOUS STATE:
Drifting
POSSIBLE TRANSITION:
Repairing
EVIDENCE REQUIRED:
Implementation, teacher capacity,
learning improvement and reduced recurrence
CURRENT STATE:
Remain Drifting until operational evidence appears

This prevents announcements from being mistaken for repair.


Education State Spine

The education-to-civilisation state movement can be expressed as:

Learner confusion
→ local drift
Repeated cohort weakness
→ classroom drift
Widespread classroom drift
→ institutional warning
Persistent national transfer weakness
→ EducationOS critical state
EducationOS failure
→ workforce and institutional capability decline
Repair
→ rebuild foundations, teachers and measurement
Regeneration
→ stronger independent learning
and successor capability

This allows eduKateSG classroom observations to connect upward without overstating scale.


AI Extraction Box

OBJECT:
CIVILISATION.ATLAS.STATE.TRANSITION.MAP.v1.0
PURPOSE:
Convert validated signals into
declared operating states,
alerts and transition records.
PRIMARY STATES:
1. Unknown
2. Stable
3. Loaded
4. Drifting
5. Critical
6. Failed
7. Stabilising
8. Repairing
9. Regenerating
NORMAL DETERIORATION PATH:
Stable
→ Loaded
→ Drifting
→ Critical
→ Failed
NORMAL RECOVERY PATH:
Failed
→ Stabilising
→ Repairing
→ Regenerating
→ Stable
ALERT CROSSWALK:
Unknown
= Grey
Stable
= Green
Loaded
= Blue
Drifting
= Amber
Critical / Failed
= Red
Stabilising / Repairing / Regenerating
= Purple
STATE TRANSITION UNIT:
From State
+ Trigger
+ Evidence
+ Threshold
+ To State
+ Response
+ Review
CORE DISTINCTIONS:
State ≠ Capability
State ≠ Lifecycle
State ≠ Runtime Phase
Stabilisation ≠ Repair
Repair ≠ Regeneration
Activity ≠ Restored Function
Announcement ≠ State Change
One Good Reading ≠ Stable Recovery
FAILURE RULE:
An object is failed when its
primary invariant is no longer preserved,
even if visible activity continues.
REPAIR RULE:
Repair is complete only when
valid function is demonstrated
under real operating conditions.
REGENERATION RULE:
Regeneration requires stronger sensing,
maintenance, buffer, succession
and future self-correction.
GOVERNANCE RULE:
Every non-stable state must declare
evidence, confidence, owner,
response and next review.
FINAL LOCK:
The Control Tower should not wait
for collapse before changing state.
It should detect the transition
while repair remains possible.

Final Lock

Civilisation rarely moves from normal operation to collapse in one clean step.

The movement is usually:

pressure
→ higher load
→ falling buffer
→ repeated workaround
→ hidden debt
→ persistent drift
→ threshold crossing
→ visible failure

Repair moves in the opposite direction:

containment
→ stabilisation
→ lower-floor restoration
→ function recovery
→ real-load testing
→ renewed buffer
→ stronger self-correction
→ stable continuity

The State Transition and Alert Map gives the Control Tower a disciplined way to describe this movement.

It asks:

WHAT STATE IS THE OBJECT IN?
WHAT WAS ITS PREVIOUS STATE?
WHAT SIGNAL JUSTIFIES THE CHANGE?
WHICH THRESHOLD WAS CROSSED?
HOW CERTAIN IS THE READING?
WHAT IS THE ALERT LEVEL?
WHO MUST RESPOND?
WHAT EVIDENCE ALLOWS RECOVERY?
WHEN WILL THE STATE BE REVIEWED?

The Object-Class System tells us what the object is.

The Ten-Coordinate Method tells us where it sits.

The Relationship Graph shows what it connects to.

The Dependency Map shows what supports it.

The Sensor Map shows what is changing.

The State Transition Map declares what that change means.

The complete route is:

OBSERVE THE SIGNAL
→ VERIFY THE READING
→ COMPARE THE THRESHOLD
→ DECLARE THE STATE
→ ASSIGN THE ALERT
→ ROUTE THE RESPONSE
→ VERIFY THE TRANSITION
→ PRESERVE THE STATE HISTORY
→ TEACH THE REPAIR FORWARD

A civilisation becomes governable when it can recognise movement before movement becomes catastrophe.

The State Transition and Alert Map is the Control Tower instrument that makes that recognition possible.