- name
- air-traffic-management-safety-method
- description
- Clean-room evidence method for airspace, facility, procedure and system configuration, traffic demand and capacity, hazards and controls, occurrences, changes and safety assurance. Use for non-operational Air Traffic Management review without clearances, tactical advice, procedure approval, occurrence classification or risk acceptance.
# Air Traffic Management Safety Method
## Freeze authority and operating context
Record State and aviation authority, Air Navigation Service Provider, airspace/facility/unit, operating concept, dated procedure and system configuration, effective period, traffic and occurrence populations, demand and capacity definitions, Safety Management System source versions, protected-data boundary, evidence cutoff, accountable safety owner and requested review. Assign stable IDs to airspace elements, facilities, procedures, systems, configurations, traffic periods, hazards, controls, occurrences, changes and evidence.
Use current controlled FAA, ICAO or operator-authorized sources only as locators and applicability inputs. Do not copy controlled controller procedures, separation minima, thresholds or standard text. Distinguish authority requirement, local procedure, operational observation, derived measure and professional assessment.
## Reconcile airspace, facility and procedure configuration
Map airspace structures, sectors, routes, fixes, runways, facility/unit roles, surveillance, communication and navigation dependencies, procedure identifiers, agreements as supplied, system configuration and effective dates. Record interfaces and responsible owners.
Compare evidence only within compatible operating concepts and configurations. Preserve superseded, temporary, trial, contingency and unknown states. Do not determine that a procedure is operationally valid, approve a configuration or expose protected coordinates outside authorized purpose.
## Analyze demand, capacity and performance evidence
Freeze the operation population, time zone, interval, traffic measure, capacity definition, weather or configuration context and exclusion rules. Reconcile counts and rates with explicit numerator, denominator and unit. Stratify by sector, runway, facility, configuration and comparable period.
Capacity is an attributed planning or operational definition, not a tactical limit or clearance instruction. Preserve rerouted, cancelled, censored, missing and duplicated observations. Do not manufacture delay attribution, capacity values or thresholds.
## Trace hazards, consequences and controls
Map supplied system state or change to hazard, operational consequence, affected operation, existing control, control objective, implementation evidence, verification and residual uncertainty. Keep hazard description, causal factor, severity classification, likelihood classification and risk acceptance in separate attributed fields with owner and source.
Seek counterevidence and missing interfaces. A control description is not proof of implementation; implementation is not proof of effectiveness. Do not assign risk categories, set acceptable risk or recommend an operational action.
## Review occurrences, changes and safety assurance
Reconcile occurrence and safety-indicator populations by definition, reporting channel, period, facility and configuration. Separate raw report, validated event, investigation evidence, causal analysis and official occurrence classification. Respect protected safety information and purpose limitations.
For each proposed or implemented change, trace baseline, authorization as supplied, hazard assessment, controls, verification, monitoring indicator, contingency or rollback reference and post-change evidence. Test control effectiveness only against declared criteria, population and denominator. Do not approve the change.
## Join safety evidence
Run configuration, demand/capacity, hazard/control and occurrence/change-assurance branches from one frozen baseline. Join by airspace, facility, procedure, configuration, period, hazard, control, occurrence and change IDs. Reconcile effective dates, traffic denominators, system interfaces and monitoring results.
Separate raw observation, normalized value, derived measure, analyst hypothesis, attributed professional classification and human-owned risk acceptance. Every row records source/version/date, cutoff/effective date, unit/denominator, owner, qualified reviewer, applicability, assumptions, uncertainty, privacy/licence restriction, status, decision_not_made and stop reason.
## Stop and authority boundary
Stop on absent authority, unclear airspace/facility/configuration, stale or incompatible procedure versions, unknown traffic population, missing denominator, protected-data misuse, request for live information, unsupported hazard classification, missing safety owner or ambiguous external outcome.
Never issue or suggest a live clearance, route, vector, altitude, speed, separation, runway action, flow restriction, equipment action, Notice to Air Missions, warning or tactical response; approve a procedure or airspace change; classify an occurrence; assign severity/likelihood; accept risk; publish operational status; or contact an authority. Authorized controllers, facility managers, designers, technical operations, human-factors specialists, safety assessors, investigators and regulators retain those decisions.
GitHub에서 보기