Skip to content
HONESTASDecision-Evidence Operating System

Capability deep-dive · peril simulation

The event is three days out, and every what-if you run lands in the same tables as your live book.

So the analysis happens in a spreadsheet beside the system, the system keeps serving yesterday’s view, and nobody can reconstruct afterwards which numbers the decision was actually taken on. The alternative is not a cleaner spreadsheet. It is a scenario that runs inside the decision and is reversible in one transaction.

A worked scenario, quarantined

Everything below this banner is simulated. The banner is sticky rather than dismissible, and Escape does not close it, because a quarantine is not a thing you close — leaving is an explicit act. Every panel derived from the run carries the rail, so a screenshot of any fragment still identifies itself.

Simulated value — not live data.
€XX.Xmprojected impact for this scenario — [P: to be calibrated][P]
seed 8812the run key every simulated row carries, alongside the simulation flag[D]
tick 34the scenario clock; seek and inject are logged control verbs, not silent edits[D]
reversibleone predicate, three tables, one transaction, scoped to this tenant and this run[O]

There is no calibrated loss number behind this figure and there will not be one until the catastrophe financial chain exists. A plausible euro amount here would be a fabrication, so the placeholder stays.

Simulated value — not live data.

Simulated — what a scenario writes

  • props.sim = true — mandatory on every row the producer emits, in the type rather than by convention.
  • props.scenario_run_id — the run key the scrub predicate narrows on, so two open scenarios reverse independently.
  • data_source: live | partial | pending — the producer declares its own posture; the interface does not infer it.

What is deployed, and what it computes

6peril simulators in the deployed engine: flood, storm surge, wildfire, tsunami, volcanic ash, liquefaction[O]
6live disaster feed clients, each surfacing an unreachable upstream as a typed error rather than as stale data[O]
8 minutesa published external benchmark for a city-scale pluvial flood run at 10 m resolution — an external result on an external stack, not ours[V]
not builtthe catastrophe financial chain that would turn any of this into a loss — [P: to be calibrated][P]

Peril physics is not a catastrophe model. The chain from an intensity field to a paid loss is designed and not built, and no figure on this page crosses that gap.

The engines, and the posture they share

A hazard engine scoring route peril over real elevation data; an evacuation router running four published solvers to a clearance time; weather feeds that answer a missing upstream key with an explicit refusal rather than a cheaper substitute; a manifest-driven ingest worker; a satellite-imagery worker. The posture is common to all of them: an unreachable upstream, a missing binary or an unknown solver returns a typed error naming what failed. There is no synthesised success anywhere in the fleet.

Feeds are observations, not settlement indexes

A parametric wording settles on an index. A weather feed is not one, and we say so here rather than in the terms, because a structuring team that builds a product on that misunderstanding discovers it at the first disputed trigger. What the feed carries is a timestamped observation with provenance and a refusal state — which is exactly what makes a governed parametric adjudication admissible, and exactly why the feed itself cannot be the trigger.

peril simulators and feed clients(shipped)route peril over terrain(shipped)provenance envelope, one write path(shipped)the executor that lets the orchestrator drive the simulator(designed, not built)

Why the overlay is reversible, and the condition that makes it so

Simulated entities are not written to a side table. They go through the same single write path a real sensor bridge uses — deliberately, so that every surface lights up through hooks it already has, with no per-surface rewrite. What separates them is provenance: the producer stamps a simulation flag and a scenario run id into the type itself, and the scrub deletes on exactly that predicate, across three tables, inside one transaction, with the tenant set on the connection.

Two more obligations follow from the same honesty: a scrub receipt, so a reversal can be proved rather than assumed, and a residue query that surfaces simulated rows with no live run as a watcher row. Both are designed and neither is built.

Where a governed run fails closed

The honest limit

The gap is not compute. Published GPU physics has crossed the operational threshold. The gap is the join between a hazard field and a book, and then the curves that map an intensity to a paid claim — which are learned from decades of proprietary claims data and are not produced by any simulation. That moat is data, not compute, and it does not erode with GPU price curves. So we do not author vulnerability curves and do not claim to: the admissible postures are your own curves, a licensed vendor’s curves under your licence, or a refusal.

What this connects to

Exposure and the living map

Where the book would come from, on the industry’s neutral schema — and why the join is the hard part.

Stress testing

What turns a deterministic footprint into a distribution, and why reproducibility is the product rather than the result.

Governed simulation

The pillar this sits under, for the reader who wants the argument before the mechanism.