Skip to content
WINNIIO
← Insights

SMILE v6.5 read against two cases at once: the 26 August 2026 Nepal–Tibet flood, where twelve days of weather warning existed and seven minutes of flood warning did not, and an Alpine underground research facility where a shaft is about to be sunk and nobody yet agrees what is under the floor. Where the grammar broke, what the manuscript already had, the eight constructs that survive a collapse test, and the one region of hazard space the method does not cover. Seventy-six verified references.

Shared Reality Under Cascade: SMILE v6.5, the 2026 Nepal–Tibet Flood, and an Alpine Underground Research Facility


1. Introduction and Scope

1.1 The question

On 26 August 2026 a slope on the north face of Langtang Lirung failed, and within ten hours a river valley spanning two countries had lost more than a thousand people, nine hydropower stations, thirty-five motorable bridges and a border crossing that had carried close to 30% of China–Nepal trade. Seven days later, on 2 September 2026, an adversarial stress test was run against SMILE v6.4.3 <!-- smile:version-citation --> — a published operational grammar for shared, auditable, forkable digital-twin reality, authored by the same party writing this report — using that event as the test case. The question the stress test posed, and the question this report carries forward, is narrower and more falsifiable than whether SMILE is a good methodology in the abstract: if SMILE had been the operating grammar in the Trishuli–Bhotekoshi corridor on 26 August 2026, where exactly would it have broken, and what would still be missing a month later?

This is an uncomfortable question to ask of one's own published work, and it is asked anyway for a stated reason. A specification claiming constitutional status over multi-party critical infrastructure that has been evaluated against a single, self-reported, retrospective deployment record carries a credibility asymmetry no serious reviewer will overlook. The cheapest and most honest way to close that asymmetry is not to add more propositions against the same constant evidence base — it is to run the hardest available case, in public, and report where the grammar failed. That is the discipline this report tries to hold to across its first five chapters, and it is the discipline the accompanying SMILE v6.5.0 <!-- smile:version-citation --> revision applies to the specification itself.

1.2 Two cases, one problem

The report that follows works two cases side by side, at two different scales and two different costs of failure.

The first is the Nepal–Tibet cascade of 26 August 2026: an ice-rock avalanche off a Himalayan peak that dammed a tributary, breached within hours, and propagated a flood wave down two national river systems, destroying infrastructure, killing more than a thousand people, and leaving several thousand more unaccounted for across two states as of 1 September. It is a case with an extreme cost of failure, an extreme number of parties who did not share a common operating picture, and a decision window — seven minutes between the initiating failure and the destruction of the first major asset downstream — that is shorter than almost any deliberative process can clear.

The second is an underground research facility in the Alps: an active research and test facility built into roughly five kilometres of galleries in worked rock, currently the subject of a digital-twin effort (a scanned point cloud of measured extent, discussed in Chapter 2) and, as of this writing, facing a specific and comparatively low-stakes decision — the alignment of a single excavation feature whose purpose is confidential, through rock whose geology exists in reports and in the memory of the people who have worked the gallery for decades, rather than in an object that can be interrogated. It is a case with a low cost of failure, a small number of parties, and no clock running against it in the way the Trishuli valley had one.

The Alpine facility's twin, as it exists at the time of writing, is a measured artefact rather than a plan: a multi-cloud scan archive delivered by the facility in late August 2026, referenced against a surveyed control-point network, organised into point-cloud layers. No file in the delivered archive carries an explicit coordinate-reference-system record; the frame reads as CH1903/LV03 by inference from the coordinates and their agreement with the control points, rather than from any declared header, and that distinction — inferred versus declared — is carried forward honestly rather than smoothed over, because the tolerance of every downstream answer the twin will be asked depends on knowing which one it is. Two of the layers are, as of this writing, placeholders for geology that has not yet been added: a soft-rock volume and a hard-rock volume, with the interfaces between them and the zones where excavation is permitted or prohibited not yet represented as geometry at all. This is the same category of gap the Nepal case exhibits at a different scale — a physical volume about which several parties must agree before a decision can be taken, where the object that would let them agree exists in fragmentary form, in reports and in people's memory, rather than as something that can be interrogated directly.

These two cases are treated as the same structural problem for a specific and stated reason, not a rhetorical one. In both, several parties who do not fully trust each other, do not share a mandate, and in the Himalayan case could not physically meet in the same room, must nonetheless converge on one account of a physical volume — what it contains, what state it is in, and what follows if a given action is taken — before a decision can be made about it. Actor-network theory's account of an obligatory passage point, the device by which one artefact renders itself unavoidable to a network of actors with divergent interests, is the theoretical device SMILE was written around from its first phase onward. The report's working claim, tested rather than assumed across the chapters that follow, is that the same construct that is supposed to hold a specification for a mine gallery decision also has to hold for a cross-border mass-casualty cascade — and that testing it against the harder of the two cases first is what tells you whether the construct actually does the work its name claims, or whether it is a diagnosis of power adopted as a design aspiration — a question the manuscript itself is not naive about (§12.8 already conditions obligatory-passage-point status on portability; §3.10 already flags the claim as an unclaimed position), but which the theory repair in A.1 still finds under-specified.

1.3 Method

The chapters that follow are built on a specific sequence of artefacts, each produced to interrogate the one before it, and the sequence itself is part of the report's argument about how a specification claiming constitutional status should be tested.

1. Adversarial stress test. SMILE v6.4.3 <!-- smile:version-citation -->, as published, was read hostilely against the Nepal–Tibet event: eighteen structural findings organised by severity, twenty-two role-based readings ("twenty-two lenses"), a direct assessment of whether the methodology's multiplayer collaboration model covers the range of coordination regimes the event required, a before/during/after structural audit, twelve named candidate additions ordered by leverage, twelve stated internal inconsistencies, and an explicit accounting of what the specification gets right. 2. Revision draft. A v6.5.0 draft was produced in direct response: two theory repairs (A.1, on the obligatory-passage-point claim; A.2, on the developmental-stage capability framing), twelve new constructs specified to definition-of-done standard, a five-mode collaboration model with explicit inter-mode transitions, amendments to seven existing constructs, three governance clauses, a metamodel mapping expansion, and twelve new falsifiable propositions. 3. Scenario and probe suite. A separately citable companion artefact parameterised the failure conditions the revision claims to address — eleven structural parameters, six scenario classes defined as regions in that parameter space rather than as narrative incidents — together with a coverage matrix mapping each of the twelve new constructs against the six classes, and a minimal capability probe per construct. 4. Collapse test. The coverage matrix and the interaction dependencies stated in the revision draft were encoded and run mechanically against each other, in a memorandum titled "Eight, Not Twelve," to determine which of the twelve proposed constructs are load-bearing, which are thin-but-defensible, and which collapse into one another or demote to governance. This is the step that converts the exercise from an addition of scope into a disciplined reduction of it, and its result is carried forward into Chapter 4 and Chapter 5 of this report and into the SMILE v6.5.0 <!-- smile:version-citation --> specification itself.

This report's first five chapters follow that sequence in order: what SMILE claimed before the test (Chapter 2), what the event actually looked like as a sequence of measurable intervals (Chapter 3), where the published grammar broke against that sequence (Chapter 4), and how the theory underneath two of its central claims has to be repaired as a result (Chapter 5). The remaining chapters of the full report, prepared separately, carry the new constructs to specification quality, the mode-scoped collaboration model, the metamodel and standards mapping, the evaluation restructuring, and the Alpine facility material proper.

1.4 The evidence limitation, stated up front

Two evidentiary limitations bear on everything that follows and are stated here rather than left implicit.

First, the adversarial stress test that grounds Chapters 2 and 4 was conducted without machine-readable access to the SMILE v6.4.3 <!-- smile:version-citation --> manuscript body: the Zenodo-hosted PDF would not extract as text and was read as an opaque binary. The stress test was therefore built against the published abstract, keyword set, related-works chain, and version history — sources which do name every major construct discussed — together with the Nepal evidence base and the relevant methodology literature. Every claim in this report that a construct is absent from SMILE was originally inherited from that limitation and flagged as unverified; those flags have since been checked against the full v6.4.5 manuscript body and are replaced below with VERIFIED-ABSENT or VERIFIED-PARTIAL (with a section reference), per finding, or UNRESOLVED where the verification pass did not cover the finding. Where a construct exists in the manuscript's body text but not in its abstract, that is a different and lesser finding — a positioning gap rather than a specification gap — and this report tries not to conflate the two.

Second, the event itself was, at the time these artefacts were produced, seven days old, and the casualty, damage and missing-persons figures cited throughout this report changed materially over that window: an internal situation brief compiled 31 August cited 788 confirmed dead and 2,502 missing in Nepal; the event brief this report is built against, current to 1 September, cites more than 1,000 dead across both countries and approximately 3,916 missing in Nepal with 546 missing in Tibet. Both figures are accurately reported for their date; neither should be read as final. All quantitative claims about the event in this report are provisional as of 1 September 2026 and are flagged as such at first use. A third limitation, narrower but worth naming here, is that this report's sourcing for the Nepal–Tibet event is inherited from the stress-test and analysis documents' own citation of press and agency reporting (Reuters, AP, USGS, Nepal's National Disaster Risk Reduction and Management Authority, the geohazard laboratory at Chengdu University of Technology, SVT Verifierar, Bloomberg and the Kathmandu Post, among others); this report has not independently re-verified those primary sources against their original publication, and a source-verification pass against a consolidated reference list remains outstanding. [REF-CHECK: primary event sourcing, chapters 1–5]


2. SMILE as Published

2.1 Lineage

SMILE — the Sustainable Methodology for Impact Lifecycle Enablement — is deposited on Zenodo under a concept DOI, 10.5281/zenodo.20175405, that persists across versions, with each version carrying its own version-specific record. The version this report's stress test evaluated, v6.4.3, was deposited 2 August 2026 under record 10.5281/zenodo.21757691 <!-- smile:version-citation -->, titled Operational Grammar for Auditable, Shared and Forkable Reality, under a CC-BY-4.0 licence. Two further versions followed before this report was drafted: v6.4.4, deposited 19 August 2026 under record 10.5281/zenodo.22014758 <!-- smile:version-citation -->, and v6.4.5, deposited 2 September 2026 under record 10.5281/zenodo.22244558 <!-- smile:version-citation -->. (all three record identifiers were resolved against the Zenodo REST API on 2 September 2026; see References, group G) The v6.5.0 material this report discusses in Chapters 4 and 5 is, as of this writing, a draft revision superseding v6.4.3 and not yet itself deposited; its relationship to the intervening v6.4.4 and v6.4.5 records has not been reconciled within the scope of this report and is noted here as an open item for the version history rather than resolved.

The acronym's expansion has itself changed across the lineage, and the change is treated in the v6.5.0 draft as substantive rather than cosmetic: SMILE expanded as Sustainable Methodology for Interoperable Lifecycle Enablement through the v5.x line and as Sustainable Methodology for Impact Lifecycle Enablement from v6.0 onward. The draft's own front-matter note states the relationship between the two agendas as one of instrumentality rather than competition — interoperability is the enabling property, impact is the design direction — and states plainly that earlier version's phrasing occasionally treated interoperability as terminal in a way the impact-first framing now supersedes. The stress test independently flagged this as an internal inconsistency worth resolving on its own terms (§2.4, below), since a document asserting constitutional status that is unresolved about its own name signals, to a hostile reader, that a later framing was layered over an earlier specification rather than derived from it.

2.2 Six phases and the impact sequence

SMILE organises a digital-twin engagement into six phases, escalating in duration and ambition: Reality Emulation (establishing a shared spatial and temporal canvas — where, when, and who — over days to weeks), Concurrent Engineering (evaluating alternatives against that canvas before commitment, over weeks to months), Collective Intelligence (instrumenting the emulation with live sensing and a shared ontology, over months), Contextual Intelligence (closing a real-time command loop around the instrumented emulation, over months to years), Continuous Intelligence (accumulating prior evidence — every prior decision and failure becomes an input to the next — over years), and Perpetual Wisdom (the method generalising beyond its originating site, over decades). The ordering matters for the argument in Chapter 4: a phase model that runs from Reality Emulation to Perpetual Wisdom over a multi-year horizon is a model built for infrastructure operators and standing institutions, and Chapter 4 examines directly what happens when an event arrives before most of those phases have had time to mature.

The methodology's stated core principle is impact-first, and it states its own design direction explicitly as an inversion of the conventional data-up approach: Outcome → Action → Insight → Information → Data. The intended discipline is to design downward from what outcome is wanted to what observation is strictly required to support it, rather than instrumenting everything observable and hoping insight follows. The v6.5.0 front-matter note (§0.2, discussed further in §2.1 above) restates this as the Outcome-to-Data inversion and identifies it, in both the revision draft and the stress test's own closing assessment, as one of the specification's genuinely distinctive and correct contributions — rare in a literature that defaults to capture-everything instrumentation programmes.

2.3 The operational grammar's core constructs

As published, SMILE's operational grammar for shared reality rests on a small number of named constructs, each carried forward — amended, in several cases — into the v6.5.0 revision discussed in Chapters 4 and 5.

The Reality Branch Lifecycle governs how alternative accounts of a state — proposed designs, contested readings, rejected alignments — are created, retained and, in principle, promoted or discarded, under the maxim "no simulation becomes history": an explored possibility does not silently harden into the record of what occurred. The Reality Consensus Protocol is the mechanism by which divergent accounts are reconciled into an agreed state; as published (§4.13) it already specifies quorum, vetoes, tie-breaking, emergency powers, an expiring consensus and preserved minority reports — but assumes, on the stress test's reading, that a consensus round of some kind can always be convened. The canonical metamodel maps SMILE's internal entities onto twelve existing external standards — PROV-O for provenance, SOSA/SSN for observations and their sensing platforms, OWL-Time for temporal reference, GeoSPARQL for spatial query, ODRL for rights and usage policy, SHACL for shape validation, NGSI-LD for live-entity context, ISO 23247 for digital-twin manufacturing framework alignment, OpenUSD for scene description, and MCP and A2A for machine and agent interoperability — a mapping the stress test characterises as coherent for industrial and semantic-web purposes and, on inspection, carrying no mapping at all into the humanitarian-response standards ecosystem (a finding developed in Chapter 4, §4.4). An applicability-and-proportionality instrument exists to prevent over-engineering, weighing the cost of instrumenting a given asset or node against the benefit its instrumentation would capture. SEEN structures needs, expectations, evidence and — the letter load-bearing for Chapter 4 — the routing of an identified need to an accountable party. The Epistemic Horizon names, as a first-class property, the boundary of what a given model can and cannot see. Reflexive Zoom is the operation of moving between levels of a represented reality — in, out, behind, and through time, the "out" direction already naming dependencies, externalities and affected actors — without losing coherence between levels. Finally, the methodology reframes five originally sequential small-group developmental stages as five concurrent capabilities — grounding, situated contestation, protocolisation, closed-loop action, and reconstitution — a reframing whose theoretical grounding is itself revised in Chapter 5.

2.4 The evaluation posture, and its n=1 weakness

SMILE v6.4.3 <!-- smile:version-citation -->'s design-science evaluation rests on fourteen falsifiable propositions, a genuinely uncommon degree of rigour in this literature and one the stress test explicitly credits as better practice than most comparable specifications. The propositions, however, are evaluated against a single archival deployment record — retrospective, self-reported, and authored by the same party who wrote the specification. For a document asserting constitutional status over infrastructure shared among multiple parties who do not necessarily trust one another, this is an asymmetry a hostile reviewer identifies immediately: seventy-six references verified, one deployment verified, in the stress test's own summary formulation. No negative-result register accompanies the propositions, no disconfirming evidence is pre-registered, no independent replication exists, and — the finding the stress test treats as most damaging — no adversarial case appears anywhere in the evidence base, despite one being readily available. This is the specific weakness the Nepal–Tibet case, and the sequence of artefacts summarised in §1.3 above, is built to close: not by adding propositions against the same constant n=1 evidence, which the stress test explicitly warns would widen the credibility gap rather than close it, but by publishing, honestly, the case in which the specification's own grammar failed. Chapter 4 is that case, worked in detail; the evaluation restructuring this produces — parameterised scenario classes, a capability-probe suite, a disconfirmation register attached to every proposition, and a requirement that at least one probe failure be honestly reported in the finished manuscript — is treated in full in a later chapter of this report and is only introduced here as the frame within which Chapters 4 and 5 should be read.

A minor but related finding, noted briefly here because Chapter 5 does not return to it: the naming inconsistency described in §2.1 was independently flagged by the stress test (its finding 1.14) as one of twelve internal inconsistencies stated plainly in its Part 6, alongside the OPP category error (Chapter 5, §5.1), the mismatch between a consensus-based core protocol and crisis-tempo events (Chapter 4, §4.2), and the tension between forkable reality and evidentiary singularity (Chapter 4, §4.5). These twelve inconsistencies are not separately tabulated in this report; they recur, individually, at the point in Chapters 4 and 5 where each is substantively addressed.


3. The Event as a Chain of Intervals

3.1 Reading the event as a sequence of latencies

The account of 26 August 2026 that matters for this report is not a narrative account of what happened; it is an account of how much time separated each signal from the next decision or destruction downstream, because the argument carried through the rest of this report is a claim about tempo: that a methodology whose central coordination mechanism is a deliberative consensus protocol has, by construction, a floor on how fast it can move, and that floor was tested directly by this event. Table 1 sets out the intervals as measured, drawing on the timeline reconstructed in the stress test and in the earlier working analysis "The Obligatory Passage Point," itself built from Reuters, AP, USGS, NDRRMA and SVT Verifierar reporting as cited in those documents (see §1.4 on sourcing). All figures are provisional as of 1 September 2026.

Table 1 — The event as a sequence of intervals

IntervalFromToDurationNote
Initiating failure08:37 Nepal time, 26 AugSlope failure, north face of Langtang Lirung, ~5,200 m; ice-rock avalanche dropping ~1,200 m into the Lhende Khola. Initially registered as seismic energy read as a magnitude-4.4 earthquake; USGS subsequently reclassified this as landslide-generated seismic energy equivalent to ~M5.2. A second, separate seismic event of ~M4.2 followed approximately three hours later. Residual uncertainty remains, per USGS, on whether the initiating failure was a landslide that incorporated glacial ice or a glacial collapse proper.
Signal → destruction of first major cross-border asset08:3708:447 minutesThe Gyirong/Rasuwagadhi border crossing, carrying an estimated ~$600m and close to 30% of China–Nepal trade, destroyed.
Signal → loss of the nearest downstream gauge08:37~08:5013 minutesThe Syabrubesi gauging station stops transmitting. The stress test's central claim about this interval (§4.4, below) is that the silence itself, not merely the loss of a data feed, was the earliest machine-legible signal in the entire chain.
Signal → first warning SMS08:3709:1538 minutesFirst warning message reaches Rasuwa, Nuwakot, Dhading and Chitwan districts — after the border crossing was already destroyed.
Signal → measurable arrival at Devghat08:37~18:40~10 hoursApproximate interval to measurable water-level change roughly 240 km downstream.
IncubationJuly 2025 (Miteri bridge destroyed by GLOF on the same river)26 August 2026~13 monthsThe geohazard laboratory at Chengdu University of Technology mapped 55 unstable glacial lakes (~3.39 km²) upstream after the July 2025 event and urged upstream early-warning investment "as soon as possible." Nepal and China held a bilateral meeting on trans-boundary data sharing on 27 May 2026, three months before the second flood on the same river in thirteen months.

A related finding, developed further as a construct requirement in Chapter 4, concerns the initiating signal itself rather than what followed it. The seismic reading that opened the event was interpreted, in the first hours, as a magnitude-4.4 earthquake; USGS subsequently reclassified the same signal as landslide-generated seismic energy equivalent to approximately magnitude 5.2, and a second, distinct seismic event of approximately magnitude 4.2 followed roughly three hours later. A retyping of this kind — the same recorded signal assigned a different physical cause and a different magnitude after the fact — is an ordinary and expected part of seismological practice. It is not, on the evidence reviewed for this report, an ordinary and expected capability of a shared-reality specification: every downstream inference that was drawn from the initial "M4.4 earthquake" reading in the first hours of the response would, under the published grammar, have had no mechanism for propagating the reclassification to whatever was derived from it. A twin that cannot retype a past event and carry the correction forward through everything computed from it is a twin that lets a superseded reading persist silently alongside its correction, which is a specific instance of the inference-hardening problem the Believed-State Tier construct (Chapter 4, §4.3; Chapter 5) is built to address.

Two entries in Table 1 are load-bearing for the chapters that follow and are drawn out here rather than left in the table alone. The thirteen-minute interval to the loss of the Syabrubesi gauge is the interval that Chapter 4 treats as evidence for Silence Semantics — the finding that an observation-centred data model has no native way to represent an expected observation that fails to arrive, so that the earliest and most spatially precise signal in the entire event rendered, in every system built on the published grammar's mapped standards, as an ordinary gap in a time series rather than as an alarm. The thirteen-month incubation interval is the interval Chapter 4 treats as evidence for Standing Hazard Obligation — the finding that the disaster was, in a specific and falsifiable sense, decided in July 2025 rather than August 2026, because a correct, published, specific risk assertion existed for more than a year with no actant bound to it, no clock running against it, and no consequence attached to its lapse.

3.2 Three lead-time figures, and why they are not one number

Three figures for how much warning time existed have circulated in reporting on this event, and they are frequently, and incorrectly, treated as competing estimates of a single quantity. They are not: each measures a different point on the same causal chain, and collapsing them into one number obscures exactly the distinction this report's method depends on. Reuters reporting cites approximately twenty-six minutes between the flood's crossing into Nepal and an alert reaching people downstream. Nepal's National Disaster Risk Reduction and Management Authority's own account, describing the experience of communities closest to the source, describes under five minutes of lead time — the basis for NDRRMA chief Dharam Raj Uprety's statement that "people even didn't get five minutes of lead time... we don't have weather stations in high mountain areas [because of the] lack of trans-boundary data seeding mechanisms." The first-SMS record in Table 1 shows thirty-eight minutes measured from the seismic signal itself, a point earlier in the chain than either of the other two figures. [REF-CHECK: primary sourcing for all three lead-time figures — see §1.4]

The distinction matters for the argument of this report in a specific way: none of the three figures describes a failure of sensing in the sense of an instrument that did not exist or did not work. The seismic signal was recorded. The chain failed in the interval between a signal existing somewhere in the system and a decision being taken by the person who needed to take it — an interval this report treats, following the SMILE v6.5.0 <!-- smile:version-citation --> revision, as the distance to be closed, as distinct from the sensing to be added. That distinction is the subject of the next section.

3.3 Latency as the object of design, and what the automation literature actually shows

One piece of engineering literature speaks directly to an interval measured in single-digit minutes, and it is not a piece of disaster-response literature at all. Chachere, Kunz and Levitt's 2009 Stanford CIFE working paper (WP116) modelled a forty-week concurrent-engineering design task under two separate interventions. Automating every individual step in the task down to a one-minute decision, while leaving the waiting between steps untouched, halved the task to twenty weeks — a real but modest gain. Leaving every step exactly as it was, and cutting the waiting between steps to one minute instead, took the same forty-week task to three hours. (Chachere, Kunz & Levitt, 2009; verified against the Stanford repository record — References [14])

NASA JPL's Team X practice is the same finding demonstrated operationally rather than modelled: early mission design work that had previously taken approximately nine months was brought to approximately three weeks, with the concurrent-engineering work itself completed inside roughly nine hours of intensive, co-located, facilitated sessions. The documented mechanism for the gain is co-location, shared screens and a shared, live, networked model — not automation of the underlying engineering steps. (Team X practice as reported in WP116 and in the NASA technical record — References [14], [16])

The relevance to Table 1 is direct and is the argument this report carries into Chapter 4. An early-warning chain has the same shape as the concurrent-engineering task WP116 modelled: it is composed of steps (a sensor registers a signal, a model interprets it, an authority decides, a channel disseminates the decision) separated by waiting (for a human to notice, for an inter-agency channel to route a message, for a cross-border data-sharing agreement to be invoked). Instrumenting the source area with more weather stations — the specific investment the applicability-and-proportionality instrument, as published, would decline to fund for the Rasuwa district, for reasons developed in Chapter 4, §4.3 — shortens the steps. It does nothing to the waiting, and the waiting is where thirty-one of this event's thirty-eight minutes were spent. The construct this argument motivates directly — a shared, live, already-agreed-upon operating picture, sitting inside a room or a network before the event occurs, so that the only variable left to close during the event is data latency rather than institutional latency — is the Concurrent Engineering phase described in §2.2, and it is the phase the stress test's next-steps section explicitly recommends testing at the Alpine facility (a recommendation developed in a later chapter of this report, outside the scope of Chapters 1–5).


4. Where the Grammar Broke

4.1 Organising the findings

The adversarial stress test's Part 1 sets out eighteen structural findings against SMILE v6.4.3 <!-- smile:version-citation -->, numbered §1.1 through §1.18 in descending order of severity as judged by the stress test's author. This chapter organises those eighteen findings, together with four related findings drawn from the stress test's Part 3 (on multiplayer coverage) and Part 4 (on the before/during/after structure of the disaster), into the three-phase structure the stress test itself uses to organise remediation: what needed to exist before the event, what needed to hold during it, and what remains largely missing after it. A handful of the eighteen findings are not phase-specific in this sense — they are findings about the specification document itself, rather than about the event — and are marked accordingly; these are picked up in Chapter 2 (§2.1, §2.4) and Chapter 5 (§5.2) rather than developed further here. Findings in this chapter originally flagged as unverified under the stress test's evidence limitation (§1.4) have since been checked against the SMILE manuscript body directly; Table 2 replaces each with VERIFIED-ABSENT, VERIFIED-PARTIAL and a section reference, or UNRESOLVED where the verification pass did not cover the finding.

Table 2 — The eighteen findings, by phase

§FindingPhaseEvidence anchorVerification status
1.4Obligation orphaning — a published risk assertion with no owner, timer or consequenceBEFORE55 unstable lakes mapped July 2025; no action taken on the finding in thirteen monthsVERIFIED-ABSENT
1.6Proportionality inversion — the applicability instrument correctly declines to fund the investment that would have prevented the eventBEFORENo high-altitude weather stations in the source area; NDRRMA statement on the absence of trans-boundary data mechanismsVERIFIED-PARTIAL (§1.3 names externalities; §4.16 score does not use them)
No hazard inventory as a living object (Part 4, Before)BEFOREDestruction concentrated in floodplain-sited constructionUNRESOLVED — not covered by the manuscript verification pass; requires a dedicated check before publication.
No rehearsal/exercise lifecycle phase (Part 4, Before)BEFORENo tabletop or rehearsal stage named anywhere in the published lifecycleVERIFIED-ABSENT as a lifecycle phase (the word "rehearsal" appears only as a §4.16 scoring value)
1.1Tempo exclusion — a consensus protocol cannot clear a seven-minute eventDURING08:37–08:44 interval; the headmaster's fourteen-minute, single-phone-call evacuation, which the published grammar cannot describeVERIFIED-PARTIAL (§4.13 has emergency powers and Act-or-Reopen; missing a sub-consensus reflex tier)
1.2Chokepoint inversion — an obligatory passage point that is unreachable is an obligatory blockageDURINGBorder station and downstream gauges destroyed; no bypass or degradation doctrine publishedVERIFIED-ABSENT
1.3Inference prohibition — action had to be taken on state that was physically unobservableDURING~900 hydropower workers unaccounted for; thermal drones returned nothing; tunnels described as packed with mud "like toothpaste in a tube"VERIFIED-PARTIAL (§3.10, §4.12 already carry confidence/uncertainty; missing decay + "contested" terminal status)
1.5Informative silence discarded — an observation-centred data model has no construct for an expected observation that fails to arriveDURINGSyabrubesi gauge silence at ~08:50, rendered as a data gap rather than an alarmVERIFIED-ABSENT
1.7Cascade invisibility — no participant holds the full multi-domain propagation graphDURINGNine hydropower projects, 431 MW off-grid, a border crossing, and a national trade route affected by one initiating failure, modelled by no single party in fullVERIFIED-PARTIAL (§1.3, §4.16 name the concept; no computed time-to-impact or typed dependency graph)
Stranger exclusion — no onboarding grammar for high-value contributors with no institutional standing (Part 3, Mode 4)DURINGA filmmaker who had crossed the border two days earlier became, by the stress test's account, the most effective search asset in the tunnels, with no institutional standing whatsoeverVERIFIED-PARTIAL (2 weak onboarding hits exist; mode-table gap for no-standing contributors stands)
1.17Transport assumed — connectivity treated as ambient rather than as a modelled, failing actantDURINGComms infrastructure among the first systems to fail; no partition-state construct publishedUNRESOLVED — not covered by the manuscript verification pass.
1.8 / 1.15Standards mapping serves industrial and semantic-web purposes only; keywords outrun the mapping tableDURINGTwelve mapped standards, none from the Common Alerting Protocol, EDXL, HXL, INSARAG or Sendai families; the 09:15 SMS failure is, on this reading, a CAP-shaped holeVERIFIED-ABSENT
1.9The person is missing from a methodology about peopleAFTERNo person-in-hazard entity identified; no reconciliation construct for divergent missing/confirmed-dead totals across two states and 38 nationalitiesUNRESOLVED — not covered by the manuscript verification pass.
1.10No dignity layer — the affected are not modelled as a distinct audience with distinct disclosure needsAFTERFamilies gathered at the Bidur base as survivor counts fell; no audience-scoped visibility construct publishedVERIFIED-PARTIAL (§4.18 already assesses "dignity harms"; no audience-scoped visibility/disclosure-boundary construct)
1.11Evidentiary contradiction — forkable reality vs. a single record for liability purposesAFTERInquests, insurer exposure and Nepal's loss-and-damage claim will each require one discoverable record; ODRL governs usage rights, not chain of custodyVERIFIED-PARTIAL (§4.12 already has an evidentiary-status field; missing canonical-branch designation, litigation hold, retention, tamper-evidence)
No attribution ledger for loss-and-damage claims (Part 4, After; Part 5, item 12)AFTERNepal's first UN loss-and-damage claim, filed 1 September 2026, has no auditable-attribution substrate in the published grammarUNRESOLVED — not covered by the manuscript verification pass.
1.12Design-science evaluation weak legcross-cutting (Ch. 2, §2.4)One retrospective, self-reported, author-evaluated deployment recordN/A — not a manuscript-absence claim; see §2.4 for its numeric correction
1.13Developmental-stage capability framing carries a weak citation for no remaining contenttheory (Ch. 5, §5.2)Sequence already discarded in the published reframing; only the citation's reputational cost is retained
1.14Naming inconsistency across version lineseditorial (Ch. 2, §2.1)"Interoperable" (v5.x) vs. "Impact" (v6.x); title still sells an interoperability artefact
1.16No autonomy-authority construct for robotics under lost comms; quantum sensing under-cited where defensibleDURINGSearch robotics operating with comms loss during the responseUNRESOLVED — not covered by the manuscript verification pass.
1.18No model-provenance recordAFTEREU AI Act-class audit requirements after the responseVERIFIED-PARTIAL (1 weak hit; the assurance-case gap (G3) stands)

4.2 BEFORE — the phase in which the outcome was substantially decided

The stress test's central claim about the before-phase, and the claim this report treats as its single most important finding, is that the disaster was largely decided in July 2025, not in August 2026. The evidentiary basis is specific: after a glacial lake outburst flood destroyed the Miteri bridge on the same river in July 2025, the geohazard laboratory at Chengdu University of Technology mapped fifty-five unstable glacial lakes covering approximately 3.39 square kilometres in the upstream catchment and explicitly urged risk assessment and stronger upstream early-warning investment "as soon as possible." Thirteen months later, the same river killed more than a thousand people. This was, on the stress test's reading, an obligation-routing failure: the relevant knowledge existed, was published, and was specific, a valid risk assertion with no actant bound to it, no escalation timer, and no consequence attached to its lapse. SMILE as published measures what a project delivered, through its benefits-management and measurement-framework instrumentation; it has, on the stress test's reading, no construct for what a warning obligated and whether anyone discharged it, and nothing in the published grammar survives the closure of the project or campaign that generated the warning in the first place. The v6.5.0 revision's proposed Standing Hazard Obligation — binding a risk assertion to a named accountable actant, an escalation schedule, a discharge condition, a lapse consequence, and an inheritance rule surviving any change of the owning organisation — is aimed directly at this finding, and the collapse test discussed in §1.3 above confirms it as one of only three constructs in the original twelve to carry zero internal dependency on the others, meaning it can, in principle, be specified and shipped as a standalone addition without waiting for the rest of the revision.

The second before-phase finding compounds the first in a way the stress test treats as the most dangerous single defect in the specification as published, and this report agrees with that assessment on the evidence presented. An applicability-and-proportionality instrument exists, correctly, to prevent over-engineered instrumentation of low-value assets. Applied at the level of the individual asset or jurisdiction — which is how the stress test reads the instrument as published — it will correctly conclude that a low-capacity district such as Rasuwa should not fund high-altitude weather monitoring, because Rasuwa itself captures almost none of the resulting benefit; the benefit accrues more than two hundred kilometres downstream, to India, and to the national electricity grid. NDRRMA's own statement that "we don't have weather stations in high mountain areas [because of the] lack of trans-boundary data seeding mechanisms" is, read this way, a description of an instrument's recommendation being followed correctly, with catastrophic downstream consequences the instrument, as specified, has no mechanism for pricing. An instrument that recommends against exactly the investments that would have prevented the class of event the methodology exists to address is not a minor calibration defect; the stress test calls it an active accelerant, and this report finds no basis in the source material for softening that characterisation. The proposed remedy — computing proportionality over the full downstream propagation closure of a node rather than over the node in isolation, and requiring the instrument to always name, as an explicit output, the set of parties who benefit from an investment without funding it — is treated in the collapse test as a required amendment to the existing instrument (§5.3 develops this further as part of the broader collapse-test result).

Two further before-phase gaps, drawn from the stress test's Part 4 rather than from its numbered Part 1 findings, complete this phase. The first is the absence of any construct treating the hazard inventory itself — which assets sit on a floodplain, which slopes are unstable, which prior warnings exist — as a living, queryable object rather than as a document. Byers's observation, cited in the stress test, that the destruction fell primarily on buildings "constructed on floodplains that should never have been constructed there" is, on this reading, a second and independent instance of the same obligation-routing failure: a twin that can represent a building's location but has no construct obligating any party about the fact that the location is hazardous is, in the stress test's phrase, a decoration rather than an instrument. [REF-CHECK: Byers attribution and quotation, sourced via the stress test's own citation] The second is the complete absence of a rehearsal or exercise phase anywhere in the published six-phase lifecycle. The stress test observes, and this report finds the observation well supported by the lifecycle description in §2.2 above, that the shared-substrate argument SMILE is built around is at its most valuable in rehearsal and at its least valuable at the instant of a sub-consensus-window event — meaning the published lifecycle, as structured, under-sells the specification's own strongest application. The revision draft's proposed rehearsal phase, and its proposed grounding of that phase in a tabletop exercise at the Alpine facility, follows directly from this finding and is developed in a later chapter of this report.

4.3 DURING — where tempo, chokepoint and evidentiary assumptions failed together

The during-phase findings are the largest group and share a common structural cause: SMILE's central coordination mechanism, the Reality Consensus Protocol, is a deliberative regime with an implicit floor on its own cycle time, and the event in question repeatedly and severely undercut that floor. The seven-minute interval between the initiating failure and the destruction of the Gyirong/Rasuwagadhi crossing (Table 1) is shorter than any deliberative process — however well-facilitated, however well-instrumented — can plausibly clear, and the stress test's finding is that the published grammar has no visible reflex tier: no mechanism for bounded, pre-authorised action that fires without contemporaneous consensus because consensus is, for events at this timescale, physically impossible, with the deliberative protocol applied only afterward, as audit. This finding is sharpened rather than softened by comparison with the single most effective decision of the entire event: headmaster Rajendra Dawadi's evacuation of approximately 1,600 students on roughly fourteen minutes' notice, triggered by a single phone call. Dawadi did not run anything resembling a consensus protocol. He ran a pattern-matched, single-option, immediate action of exactly the kind naturalistic-decision-making research describes as recognition-primed decision-making — and a methodology that cannot represent the most effective decision in its own case study has, on this report's reading, a genuine scope defect rather than a matter of missing detail.

The same tempo problem recurs as a chokepoint problem once the twin itself is considered as an asset rather than only as a coordination mechanism. If a shared substrate is treated, as SMILE's abstract asserts, as a constitutional obligatory passage point, and that substrate becomes unreachable — as the border station and the downstream gauges in this event did, within minutes of the initiating failure — the specification as published has, on the stress test's reading, no degradation doctrine: no stated answer to what is authorised when the twin is down, stale, or wrong. SMILE's Reality Consensus Protocol (§4.13) already names emergency powers, quorum, vetoes and a reopening condition among its required decision-rule elements; what it lacks is a pre-authorised reflex tier that can act without any consensus round at all, for events faster than even an emergency-powered deliberative process can clear. This finding connects directly to the theory repair developed in Chapter 5, §5.1, and is only introduced here in its operational form.

A distinct but related during-phase failure concerns the epistemic basis of decision-making rather than its speed. The dominant failure mode in the response to this event, on the evidence available, was that the decision-relevant state — how many workers remained in a given tunnel, whether a given void contained air or was fully packed with debris — was, in drone pilot Manish Maharjan's description, physically unobtainable: the interior of the affected tunnels was "filled with mud like toothpaste in a tube. There was no hollow or empty space inside," defeating thermal and radar sensing alike. Every actionable decision about where to drill, where to pump, and where to direct search resources ran on inference rather than observation. SMILE's maxim that "no simulation becomes history" is, on the stress test's reading, aimed at the rarer failure — inference hardening silently into recorded fact — and says nothing about its far more common mirror image in a crisis of this kind: a grammar whose uncertainty representation (§3.10, §4.12) has no decay function and no terminal "contested" status cannot discipline the decisions that are actually taken when two credible estimates — like the army's and the police's — cannot be reconciled. A closely related failure compounds this: where two credibly sourced estimates diverge — the stress test cites an army estimate of at least thirty-five trapped at one site against a police estimate of approximately two hundred — a consensus protocol that resolves the divergence to a single number destroys information the divergence itself carries about differing observer position, method, or access. The stress test's proposed remedy, carried into the revision draft as the Believed-State Tier and developed further in Chapter 5, is to make an "unresolved" outcome a legitimate terminal state of the consensus protocol rather than a failure of it.

The remaining during-phase findings can be summarised more briefly, each contributing to the same overall picture of an event that stressed dimensions the published grammar had not been designed against. The silence of the Syabrubesi gauge at approximately 08:50 (Table 1) was, on the stress test's account, the single most informative datum available in the entire chain at the moment it occurred, and rendered, in every system built on the mapped observation standards, as an undifferentiated gap in a series rather than as a located, timestamped hazard event — the finding developed at length as construct C5 in the revision draft and discussed further in Chapter 5. No participant in the event held the full cross-domain propagation graph linking the initiating slope failure to the eventual loss of 431 MW of grid capacity, a border crossing, and a national trade route; each party's model, correctly built for its own domain, terminated at its own boundary, so that the single most operationally decisive quantity in the event — how long until a given downstream point is affected — was, in the stress test's phrase, computed by nobody. The event also produced, independently of any formal onboarding process, its highest-value search asset: a filmmaker with no institutional standing who had crossed the border two days before the event, a finding the stress test treats as evidence that the published collaboration model's assumption of participants with institutional standing structurally excludes exactly the kind of contribution that mattered most in this case. Connectivity itself was treated as ambient infrastructure rather than as a modelled, failing actant, despite the specification's own stated theoretical commitment to symmetric treatment of human and non-human actants requiring, on the stress test's reading, that the network link itself be represented as an actant capable of failure. And the twelve-standard metamodel mapping described in Chapter 2, §2.3, coherent for industrial and semantic-web purposes, maps into none of the standards the actual humanitarian response ecosystem uses — the Common Alerting Protocol, the Emergency Data Exchange Language family, the Humanitarian Exchange Language, or the International Search and Rescue Advisory Group's coordination guidelines — leaving the 09:15 SMS failure, on the stress test's characterisation, a Common-Alerting-Protocol-shaped hole in a specification that maps twelve other standards in detail.

4.4 AFTER — the phase that remains largely unaddressed

The after-phase findings are, on the evidence reviewed for this report, the least developed area of the published specification, and the stress test treats this as consistent with a grammar built primarily around the deliberative, multi-party design and operations use case rather than around mass-casualty response. Four gaps recur. First, the specification as published has no first-class representation of a person implicated in a hazard — no entity for identity, consent, last-known location, or mortuary status — despite the single highest-value data object in the entire event plausibly being "which approximately 900 workers, where were they last, and what was their last recorded signal." Divergent agency totals for missing and confirmed-dead persons on the same day, across two states and reportedly 38 nationalities, went unreconciled in the absence of any such construct. Second, and following directly from the first, no dignity layer distinguishes the bereaved and the affected from ordinary consensus parties or from mandated operators: as reported, anger grew among families at the Bidur military base as survivor counts fell, and the stress test's finding is that a forkable reality that can, by design, contain a branch in which a person's relative is dead has no published rule about who may see which branch, at what confidence, and in what framing — an ethical incompleteness, on this report's reading, rather than a mere feature gap. Third, the specification's own central epistemic virtue — that reality can be forked to explore contested possibilities — sits in unresolved tension with the evidentiary singularity that inquests, insurance settlements, hydropower operators' liability exposure on several hundred missing workers, and Nepal's own loss-and-damage claim will each require: a single discoverable record. SMILE's Branch Lifecycle (§4.12) already tags every package with an evidentiary-status field; what is missing — and what ODRL, the mapped rights-expression standard, does not supply either — is a canonical-branch designation, litigation hold, retention policy and tamper-evidence, and the stress test's judgement — that no counsel advising a party with material liability exposure could recommend adopting the specification as published while this is unresolved — is treated in this report as a commercial finding rather than a stylistic one. Fourth, Nepal's first UN loss-and-damage claim, filed 1 September 2026, has no auditable-attribution substrate anywhere in the published grammar to draw on, despite an auditable damage-attribution ledger being, on the stress test's own account, among the largest unclaimed commercial and diplomatic applications of the entire methodology.

4.5 A pattern across the three phases

Read together, the before, during and after findings in Table 2 describe one recurring structural pattern, appearing three times at three different points in the event's lifecycle, rather than eighteen independent defects distributed evenly across a specification. In each phase, the published grammar's instruments correctly do the job they were designed to do — the applicability-and-proportionality instrument correctly declines to fund an uneconomic asset; the consensus protocol correctly resolves disagreement to a single value; the rights-expression standard correctly governs who may use a piece of data — and in each case, correct execution of the stated design produces a result that is wrong for the class of event this report is concerned with, because the instrument's scope was implicitly bounded to conditions the event violated: sufficient time, sufficient observability, sufficient federation, a single jurisdiction's benefit accounting. This is the reason the remedies developed in the SMILE v6.5.0 <!-- smile:version-citation --> revision are, in the main, not additions of new capability so much as extensions of existing instruments to a wider parameter range — proportionality computed over a cascade's full closure rather than over one node, consensus permitted to terminate as "unresolved" rather than forced to a single value, a passage point whose status is conditional rather than assumed. Chapter 5 develops the two repairs that sit underneath this pattern at the level of theory; a later chapter in this report carries the pattern through to the eight constructs the collapse test found load-bearing once the pattern, rather than the symptom count, was taken as the object of repair.


5. The Theory Repair

5.1 A.1 — the obligatory passage point becomes conditional and defeasible

The most consequential single correction this report carries forward concerns the theoretical status of the claim, made in SMILE v6.4.3 <!-- smile:version-citation -->'s abstract, that a digital twin functions as a constitutional obligatory passage point. The term is precise in its source literature and the precision matters: Callon's obligatory passage point is a descriptive account of how one actor renders itself indispensable to a network of others with divergent interests — and, in the canonical treatment of the concept, the fishermen at the centre of Callon's own scallop case ultimately defect, and the enrolment the concept describes fails. SMILE v6.4.3 <!-- smile:version-citation --> already frames the obligatory-passage-point niche as "unclaimed" (§3.10) and already requires constitutional continuity to be portable before the environment becomes an obligatory passage point (§12.8), so the manuscript is not naive about contestability; what it still lacks is an account of a bypass, an account of why a rational, strategically positioned party might refuse enrolment rather than accept it, and a threat model appropriate to an object that is, by its own claimed status, a first-class target.

Three specific liabilities follow from treating the claim as axiomatic rather than as a hypothesis to be defended, and each is drawn directly from the stress test's analysis. The first is an availability liability: a passage point that is obligatory and unreachable is an obligatory blockage regardless of its intended coordination function, and the border station and downstream gauges in this event were destroyed within minutes of the initiating failure. The second is an enrolment-incentive liability, and it is the one this report's author's own earlier design instruction directly contradicted: concentrating chokepoint control in a single shared substrate gives any party who might lose from that concentration a rational reason to refuse enrolment altogether, rather than a reason to accept it, and a design that ignores this is in tension with the very theoretical frame — a theory of contested, defeasible enrolment — that it claims as its own foundation. The third is a target-value liability: asserting constitutional status for an artefact raises its value as an adversarial target, and asserting that status without any accompanying adversary model is internally inconsistent on its own terms.

The v6.5.0 revision's repair, designated A.1, converts the claim from an axiom into a governed, continuously evaluated, defeasible property: the twin holds obligatory-passage-point status only while it satisfies declared availability, integrity and impartiality conditions, with status revoked automatically on condition failure and the resulting degradation governed by an explicit ladder of operating rungs, each with its own authorised action set and named authority — the construct discussed in the collapse test (§1.3 above) as demoted from a standalone construct to a governance clause paired directly with A.1, since it consumes state produced elsewhere in the specification rather than introducing state of its own. This report's earlier design instruction — that the correct objective was to "make the twin the cheapest way for each party to do what they already wanted to do" — has to be withdrawn on the same grounds, and not softened. That instruction maximises enrolment precisely by maximising dependency, which is the condition a strategically positioned counterparty is least willing to accept once the theory is taken seriously rather than borrowed for its vocabulary. The corrected instruction, consistent with A.1 and with the companion Non-Participant Model construct (which represents, rather than silently omits, an actor that will not federate on any available terms), is: make participation reversible at a declared cost, and make the exit conditions legible. A party can be enrolled on terms it can see itself leaving; a party enrolled by dependency alone has no reason to trust the terms in the first place, and the Nepal–Tibet case — in which the one cross-border actor with the glaciological data that mattered most declined to share most of it after a bilateral meeting explicitly convened to discuss the sharing — is direct evidence, on this report's reading, that the theory's warning about refusal was not a hypothetical one.

5.2 A.2 — deprecation of the developmental-stage framing

A second, smaller but still substantive theory repair concerns the five capabilities discussed in Chapter 2, §2.3 — grounding, situated contestation, protocolisation, closed-loop action, and reconstitution — which SMILE v6.4.3 <!-- smile:version-citation --> frames as a reinterpretation of a mid-twentieth-century small-group developmental-stage model, originally proposed as a sequence of stages a group passes through over time. The v6.5.0 revision deprecates this framing on grounds independent of, though compatible with, the stress test's own critique. The source model is a narrative review of a comparatively small, largely clinical literature; its sequential claim has weak empirical support in its own right, and its later-added terminal stage was itself a subsequent narrative review rather than an empirical study. Critically, SMILE's own reframing already discards the one distinctive claim the source model makes — the sequence — retaining only the five labels as concurrent capabilities. The specification therefore pays, in the stress test's phrase, the citation's full reputational cost for none of its remaining content, and the stress test identifies this as the single softest and most easily attacked target in the entire document — a correction available to the author at no cost to the argument itself, since the argument the five capabilities are used to make does not depend on the discarded source in any way.

Table 3 — Replacement anchors for the five capabilities

Retired anchorReplacement anchorWhat the replacement supplies
Small-group developmental-stage sequence (source model, sequence discarded)Resilience-engineering capability set (respond / monitor / anticipate / learn)A near-isomorphic capability structure and the correct home literature for a framing about response under stress rather than group formation
Meyerson, Weick & Kramer (1996), already cited in §3.10 for swift trustHigh-reliability organising (Weick & Sutcliffe), extending the existing Weick citationAdds preoccupation with failure and reluctance to simplify; supplies the specification's existing weak-tie argument through its emphasis on deference to expertise
Naturalistic decision-making / recognition-primed decisionThe account of rapid, single-option action under time pressure that headmaster Dawadi's fourteen-minute evacuation requires and that the source model cannot supply at all
Endsley (1995), already cited in §3.10 and the §4.11 anchor tableSituation-awareness theory (perception / comprehension / projection), retained and extended, not newly addedIts existing mapping onto the Common Operational Picture is extended, not introduced, onto the Epistemic Horizon construct and the time-to-impact property developed in Chapter 4
Disaster-incubation theoryThe theoretical account of obligation orphaning underlying the Standing Hazard Obligation construct (Chapter 4, §4.2)
Normal-accident theory (tight coupling × interactive complexity)The coupling account underlying the cascade-invisibility finding (Chapter 4, §4.3)
Boundary-object and actor-network theory(retained, unchanged in substance)Now read with enrolment and defection treated explicitly rather than elided, per A.1 above

The net effect the revision draft claims for this substitution, and which this report finds supported by the mapping in Table 3, is that the five capabilities survive intact — nothing about grounding, situated contestation, protocolisation, closed-loop action, or reconstitution as concepts needs to change — while the theoretical grounding underneath them becomes both stronger and shorter, and the easiest available line of adversarial attack against the manuscript is removed at essentially no cost. The deprecated model is retained, under the revision draft's own instruction, only in the version history, and no argument in the specification is permitted to depend on it going forward.

5.3 What survives the theory repair, and what it changes

Both repairs converge on the same underlying correction, and it is worth stating plainly because it governs how the remainder of the constructs discussed in Chapter 4 should be read. SMILE v6.4.3 <!-- smile:version-citation -->, on the evidence reviewed for this report, imported the vocabulary of two established theoretical traditions — actor-network theory's account of enrolment, and organisational-development theory's account of group process — without fully importing the conditions those traditions attach to their own claims: enrolment that can fail, and a sequence with weak empirical grounding that the specification had, in any case, already chosen not to rely on. Neither repair asks the specification to abandon its underlying architecture. The five capabilities remain the right five capabilities; the twin remains the right kind of object to build an obligatory passage point around, in the sense that Chapter 1's framing of the Nepal case and the Alpine facility case as the same structural problem still holds. What changes is the specification's own honesty about the conditions under which its central claims are true, and — as the collapse test summarised in §1.3 and Chapter 4 demonstrates — a specification that states its own boundary conditions explicitly turns out to need fewer new constructs to cover the region outside those boundaries than one that does not, because several of the twelve originally proposed additions turn out to be consequences of getting A.1 and A.2 right rather than independent gaps requiring independent machinery. That reduction — twelve candidate constructs to eight surviving ones, three of which merge into others and one of which demotes to a governance clause paired directly with A.1 — is the subject of the chapters that follow this one.

The reduction itself has a shape worth naming here, because it is a direct consequence of the two theory repairs rather than a separate exercise in economy. Running the twelve proposed constructs' interaction dependencies against each other mechanically — the method described in §1.3 above — surfaces a small dependency kernel: an assertion's epistemic status (observed, inferred, contested, or stale), the schedule against which that status decays into staleness, and the distinction between an expected observation that failed to arrive and a transport link that failed to carry one that existed. Four of the twelve candidate constructs depend on this kernel; two more sit above it as doctrines that consume it, deciding which branch of a forked reality is the record and who may see which branch; and three sit beside it, each answering a single scenario class with no dependency on the kernel or on each other, which is precisely why they are the constructs the stress test's own next-steps section recommends shipping first, as a standalone addition, without waiting for the rest of the revision to mature. A specification whose internal dependency structure can be drawn as a small graph with a visible centre is a specification a reviewer can audit; one whose additions are listed alphabetically, each defended on its own terms, is not — and the difference between the two is not a matter of exposition. It is the difference between a claim that the twelve additions are individually true and a claim that they compose into one coherent account of what a shared reality has to do when the state it describes is uncertain, silent, or contested. This report's remaining chapters carry that account forward.


Part Two — Chapters 6–11 and Appendices

Part One (Chapters 1–5) introduces SMILE v6.4.3 <!-- smile:version-citation --> as published, reconstructs the 26 August 2026 Nepal–Tibet event as a sequence of intervals, identifies where the operational grammar broke against that sequence, and carries out the theory repair — the defeasible obligatory passage point (A.1) and the replacement of the deprecated developmental-stage framing with resilience-engineering, high-reliability-organising, naturalistic-decision-making and situation-awareness anchors (A.2). Part Two continues directly from that repair. It does not re-argue A.1 or A.2; it uses them as settled ground and turns to the twelve constructs proposed to sit on top of them, the discipline that reduced that list to eight, the standards and instruments the revision requires, the Alpine underground research facility as the venue in which the revision is tested at a survivable scale, the question of how a twin of one place cooperates with twins of other places and with people it has never met, and what remains to be done and decided.


6. The revision

6.1 Twelve proposed constructs

The v6.5.0 draft revision proposes twelve new constructs on top of the two theory repairs carried in Part One, each with a definition, a normative requirement block, a metamodel binding, a standards binding, interactions, and a definition of done. Table 6.1 collapses each to the failure mode it names, its primary scenario class(es), and its position in the dependency graph once all twelve are run against all six scenario classes.

Table 6.1 — The twelve proposed constructs

ConstructFailure mode addressedPrimary scenario class(es)Dependency position
C1 Standing Hazard Obligation (SHO)Obligation orphaning — a published, correct hazard assertion with no bound owner, clock, or consequenceSC-3, SC-5Leaf — zero dependents
C2 Pre-Authorised Action Envelope (PAAE)Tempo exclusion — the decision window is shorter than any deliberative protocol's cycle timeSC-1Leaf, thin, defended
C3 Degradation Ladder and Bypass ClauseChokepoint inversion — the shared substrate has no specified behaviour for its own unavailabilitySC-1, SC-6Zero dependents; demoted to governance
C4 Believed-State TierInference laundering, inference prohibition, premature consensusSC-1, SC-2, SC-3Kernel — four dependents
C5 Silence Semantics (Expected Observation)Informative silence discarded — a missed expected observation renders as an absence, not a signalSC-1One dependent; merged into C4
C6 Cascade Closure and Time-to-ImpactCascade invisibility — no participant holds the cross-domain closure, so time-to-impact is computed by nobodySC-1, SC-5Load-bearing
C7 Externality-Corrected ProportionalitySystematic under-instrumentation of cascade-origin nodes by the proportionality instrument itselfSC-5Footprint strictly inside C6; merged as a §D amendment
C8 Non-Participant Model (Shadow Actant)Federation assumed — no representation exists for an actor that will not federate on any termsSC-2Leaf, thin, defended
C9 Surge Tier and QuarantineStranger exclusion — no route exists for a zero-history contributor to acquire write accessSC-4Footprint strictly inside C10 and C11; merged into the mode table
C10 Affected-Person View (Dignity Layer)The affected treated as users — no disclosure rule distinguishes an implicated person from an operatorSC-3, SC-4Load-bearing
C11 Evidentiary DoctrineThe forkability/evidentiary contradiction — no rule states which branch is the recordSC-3, SC-4, SC-6Load-bearing — three primary classes
C12 Connectivity as Modelled ActantTransport assumed — the link is treated as ambient infrastructure rather than a failing, represented actantSC-1, SC-6Kernel — two dependents

Twelve constructs evaluated against a single self-reported deployment record widen, rather than close, the credibility gap Part One's theory repair already identified in the manuscript's evaluation section. The companion scenario-and-probe artefact states its own corrective in its closing instructions: run the coverage matrix and the collapse test before drafting any construct to normative-text quality, because drafting effort spent on a construct that later collapses into another is the most expensive kind of waste a specification can incur. That instruction was followed, and this chapter reports the result.

6.2 The collapse test — method

The test has two layers, deliberately kept separate. The mechanical layer takes the Part 3 coverage matrix and the Part B interaction statements and computes, without judgement, three things: how many scenario classes each construct claims primarily; how many other constructs depend on it; and which constructs share an identical scenario footprint. The judgement layer then asks, of every thin or footprint-sharing construct, whether it is narrower in scope than its prose implies, and of every wide-footprint construct, whether it is actually load-bearing or merely frequently invoked.

Table 6.2 reproduces the mechanical layer's output.

Table 6.2 — Collapse-test output: primary-claim breadth and dependency count

ConstructPrimary scenario classesDependentsScript flag
C4 Believed-State TierSC-1, SC-2, SC-34LOAD-BEARING
C11 Evidentiary DoctrineSC-3, SC-4, SC-62LOAD-BEARING
C1 Standing Hazard ObligationSC-3, SC-50
C3 Degradation LadderSC-1, SC-60
C6 Cascade Closure / TTISC-1, SC-50
C10 Affected-Person ViewSC-3, SC-40
C12 Connectivity as ActantSC-1, SC-62
C2 Pre-Authorised Action EnvelopeSC-10THIN
C5 Silence SemanticsSC-11THIN
C7 Externality-Corrected ProportionalitySC-50THIN
C8 Non-Participant ModelSC-20THIN
C9 Surge Tier / QuarantineSC-40THIN

Identical footprints — pairs claiming exactly the same scenario-class set — were flagged for C3+C12, covering {SC-1, SC-6}. The mechanical layer does not itself resolve identical footprints into a merge decision; per the companion artefact's own instruction, two constructs sharing every scenario class they claim are a collapse candidate to be examined, not a collapse to be assumed. The judgement layer performed that examination for each candidate pair, and its results are reported in §6.4 below.

The script's raw LOAD-BEARING tag attaches only to C4 and C11. C12 carries the same dependent count as C11 (two) but was not flagged by the mechanical rule, because the rule keys on primary-claim breadth as well as dependent count and C12 claims only two classes against C11's three. The judgement layer subsequently upgraded C12 to kernel status alongside C4 and C11 on different grounds, reported in §6.3 below: the closure of the dependency graph itself, independent of breadth of claim.

6.3 The kernel

Tracing every construct's stated dependency to its terminus produces a three-node closure: C4 → C5 → C12. A state assertion carries an epistemic status (C4); that status decays against an expected-observation schedule (C5); and the schedule is interpretable only if the system can distinguish the observing actant falling silent from the transport actant losing its link (C12). Every other surviving construct either sits above this closure and consumes it — C11 decides which branch is the record, C10 decides who may see which branch — or sits beside it, needing none of its state at all. A dependency graph that can be drawn on the back of an envelope is a mark in a specification's favour, not against it: a reviewer who can see the whole structure in one diagram is a reviewer who can be argued with, and a specification whose twelve items are simply alphabetical is not.

6.4 The eight that survive

Eight constructs are kept. Two of them — C2 and C8 — are kept despite claiming only one scenario class each, because in both cases the class claimed is the one the entire revision exists to cover (SC-1 for C2, SC-2 for C8) and no other construct can substitute for either. The remaining six divide into the three-node kernel (C4, C5-as-absorbed, C12), two further load-bearing constructs (C6, C11), and two zero-dependency but individually decisive constructs (C1, C10).

#### C1 — Standing Hazard Obligation (SHO)

Definition and requirements. A first-class object binding a risk assertion to a named accountable actant, an escalation schedule, a discharge condition, an explicit lapse consequence, and an inheritance rule for successor ownership. An SHO must carry exactly one owner at any instant — unowned is invalid, not merely unmet — must survive the dissolution or reorganisation of that owner under its inheritance rule, and must record every ownership transfer with provenance. A `Need` identifying no accountable actant is marked incomplete, not merely unmet.

Event and the facility. The construct exists for the failure in which correct, published knowledge produces no action because no clock runs against it. The 55 unstable lakes mapped in the source basin the year before the event, with an explicit call for upstream early-warning instrumentation, sat exactly in this condition: public, real, and routed to nobody. An SHO does not predict a slope failure; it converts a published warning into an object someone is accountable for discharging on a clock. The Alpine facility holds the same condition in miniature: geological reports and a model already exist, but the shaft-siting decision stays blocked pending two measurements only a surveyor can supply, and the finding sits in reports and institutional memory rather than bound to a named owner. Under the September 2026 transition, that owner is most plausibly whoever is named to the vacant BIM-coordination role, not yet assigned to a person.

#### C2 — Pre-Authorised Action Envelope (PAAE)

Definition and requirements. A bounded specification for the reflex tier that §4.13's Reality Consensus Protocol — which already declares emergency powers and an expiry ("consensus expires unless renewed") — does not provide: one permitting a defined action set to execute without any consensus round at all, on stated trigger conditions, blast radius and expiry, with a retrospective audit branch created automatically at firing. A shape-invalid envelope is unarmable, not merely flagged; expiry is enforced absolutely; any irreversible action in the set must be declared.

Event and the facility. The seven minutes between the initial slope failure and the destruction of the border crossing lie below the cycle time of any deliberative protocol. The construct does not accelerate deliberation — deliberation has an irreducible cost — but relocates consensus from before the action to after it; parametric insurance already operates on this pattern, which is existing proof that a pre-authorised reflex tier is governable and insurable. Underground facilities of this class already embody the pattern physically in their protected refuge sections, where an air supply creates an overpressure against incoming smoke on a smoke condition without waiting for a command decision. An armed PAAE formalises exactly that behaviour inside the twin, with every firing — real or rehearsed — leaving an audit branch reviewable without reference to anything outside the twin.

#### C4 — Believed-State Tier

Definition and requirements. A four-valued epistemic classification — observed, inferred, contested, stale — on every state assertion, with confidence decaying against the expected-observation schedule inherited from C5; contested is a legitimate terminal value. No assertion may be recorded without status; a contested pair must survive a consensus round intact, with `unresolved` a supported outcome; an action selected under contest may be marked robust-across-range.

Event and the facility. The construct closes three failures at once. The retained maxim — no simulation becomes history — stops an inferred value hardening into fact; its converse, new here, states that no unobservable state is excluded from action provided its status travels with it, since where the action that matters depends on physically unobservable state, all action is belief-driven and a grammar that already carries confidence and provenance (§3.10) but has no decay rule and no "contested"-as-terminal value cannot discipline it. A third failure, premature consensus, is closed the same way: divergent credible estimates are evidence about the observer, not noise to collapse. At the Alpine facility, capture quality is already uneven, with one capture method differing materially from the dedicated scan set — and the working frame reads as CH1903/LV03 with heights assumed to LN02, while the delivered geology declares a vertical datum that does not match the site's national frame, which is a surveying task to close.

#### C6 — Cascade Closure and Time-to-Impact

Definition and requirements. The typed propagation edges and continuously recomputed time-to-impact property that neither Reflexive Zoom's naming of dependencies and externalities (§1.3) nor §4.16's Interdependence factor supplies in computable form, over assets, services, populations and economic functions. A node whose TTI cannot be computed is flagged, never silently dropped; common-cause failure is its own edge type; response capability is itself a node in the closure, not an external observer of it.

Event and the facility. The single most decisive quantity in the ten-hour chain — how long until this reaches that — was computed by nobody, because it was a property of a graph spanning a border and several independently modelled domains, and every party's model stopped at its own boundary. The construct requires the graph to exist as a shared object, not any one party to hold every domain's physics. At the Alpine facility the same requirement is scale-invariant: candidate shaft alignments carry a chain from excavation choice through convergence, ingress and vibration to adjacent galleries, held today in memory rather than a traversable graph, while the facility's own infrastructure operates under continuous pressure — maintenance windows measured in hours per shift, equipment run near-continuously with less slack each year — which is the same tempo problem at a survivable scale.

#### C8 — Non-Participant Model (Shadow Actant)

Definition and requirements. A represented actant that will not, cannot, or has ceased to federate, carrying its inference method, a known-unknowns register, and a reason class — capability, policy, strategic interest, or adversarial. Its estimated state is never retrievable without status and reason class; a query touching a known-unknown returns it as an object, never an empty result; a boundary state is never consumed downstream as observed.

Event and the facility. Cross-border glaciological and hydrological data material to the source basin is treated by its holders as strategically sensitive, which rights-and-consensus machinery has no native way to represent; left unrepresented, the boundary's silence reads downstream as absence of hazard. Making a substrate constitutionally obligatory — the position A.1 corrects — increases the incentive to refuse it, so non-participation is the expected steady state, not the exception. At the Alpine facility, the on-site-model and network-as-sensor conversation with a telecommunications research laboratory is, by direct account, a year old and still entirely informal — nothing is agreed — which is reason class capability, distinct from a tenant firm's confidentiality-driven reason class policy; the construct is what keeps the twin from either fabricating that party's data or reading its absence as proof the layer is unneeded.

#### C10 — Affected-Person View (Dignity Layer)

Definition and requirements. An audience-scoped disclosure model governing which branches, confidence values and derived estimates are visible to which participant class, with distinct uncertainty norms for non-expert, personally implicated participants. No branch is visible by default; disclosure decisions, including decisions not to disclose, are recorded; consent for a deceased, missing or incapacitated person never defaults to granted.

Event and the facility. Villagers, a headmaster coordinating an evacuation by phone, and roughly five hundred workers believed to be in tunnels underground are not stakeholders or operators; a forkable reality with no rule about who sees which fork is, on this construct's own terms, ethically incomplete. The facility's own internal planning already proposes tracking every person present, alongside its environmental sensor network. Thirty-five staff and upward of seventeen thousand annual visitors are a different audience from the driller and physicist contesting a shaft alignment, and a location record on a visitor is exactly the disclosure-scoped, identifiable-person data C10 governs.

#### C11 — Evidentiary Doctrine

Definition and requirements. Building on the evidentiary status, time limit and rollback conditions §4.12's Branch Lifecycle already packages onto every branch, the properties still needed to render the record usable as evidence: tamper-evidence, retention and hold conditions, and canonical-branch designation — which branch is the record, as distinct from branches representing what was merely considered. Exactly one canonical branch exists at any instant; a held branch cannot be disposed regardless of schedule; tamper is detectable without an external copy; quarantined content never enters the canonical branch without recorded promotion.

Event and the facility. Forkability is an epistemic virtue and, unresolved, an evidentiary liability: where the record bears on liability across a rebuild whose cost has not yet been established, an architecture in which any party may fork leaves one question open — which branch is the record. The retained maxim that no simulation becomes history is the right instinct but not a doctrine, and does not survive contact with counsel; unresolved, no party carrying material liability can adopt the specification. The facility already produces evidentiary output — blast-validation footage at five thousand frames per second, fire-door certification referenced against major projects, accredited materials testing — each with an implicit, analogue answer to "which take is the record." The facility's own proposal to certify space-habitat systems raises the stakes directly: no certifying body accepts a forkable model without canonical-branch designation stated first.

#### C12 — Connectivity as Modelled Actant

Definition and requirements. Transport treated as a represented, failing actant, carrying partition state, store-and-forward status, and the distinction between no assertion exists and an assertion exists and cannot reach you. Reachability distinguishes absent from unreachable; partition is distinguishable from observation silence (C5) or recorded as contested (C4); ordering survives resolution; queue state is observable.

Event and the facility. A gauging station on the Trishuli falls silent partway through the event and every downstream system reads the silence as improvement rather than as the destruction of the instrument measuring the hazard. A specification claiming symmetric treatment of human and non-human actants is internally inconsistent if it treats the link between them as ambient — the construct closes a contradiction, not merely an omission. Underground at the Alpine facility, the link is identified as the component most likely to fail, which is the direct argument against any warning architecture depending on a live connection to a data centre; the badge-and-mesh instrument pattern of Chapter 8, useful in inverse proportion to how much infrastructure survives, is C12's practical expression.

6.5 Three merges and one demotion

C5 Silence Semantics merges into C4. C5 shares its single scenario class, SC-1, with C4 among others; the merge is driven by its one dependent collapsing into C4's staleness account, not by an identical footprint with C12. The defence for keeping them separate — silence concerns the observing actant, partition concerns the transport actant — is correct but belongs inside the Believed-State Tier's account of staleness, not beside it: an expected-observation schedule becomes the mechanism by which C4 computes when a value turns stale. Its standards contribution survives intact as a mapping row (Chapter 7), which is where it was always located.

C7 Externality-Corrected Proportionality merges into C6 as a §D amendment. C7 claims one scenario class and its entire footprint sits inside C6's, with no content independent of the closure C6 supplies. It is a rule, not a construct: the proportionality instrument must compute over C6's closure and must emit the benefit-incidence gap as a named output. The underlying finding is the single most consequential correction in the whole revision — asset-scope proportionality will correctly recommend against instrumenting the node where a cascade originates, because that node captures little of the resulting benefit, making the instrument an active contributor to the failure class it exists to prevent — but it is better published as a self-correction than as a twelfth feature competing with the other eleven.

C9 Surge Tier and Quarantine merges into the mode table. C9's footprint sits strictly inside both C10 and C11. Quarantine is not an independent object; it is the consensus regime the Surge mode of §6.6 already needs, and promotion and demotion are exactly its required transitions. The onboarding question the construct poses — how a stranger acquires write access at any hour, without verification infrastructure, without opening the record to adversarial contribution, without colliding with a mandated channel — remains fully answered inside the Surge row rather than as a standalone construct, and its content-provenance mapping contribution survives as a standards row (Chapter 7).

C3 Degradation Ladder and Bypass Clause is demoted to a governance clause, beside A.1. C3 claims two scenario classes but has zero dependents: nothing in the surviving eight requires it as a precondition. It consumes C4's staleness and C12's partition state without contributing state of its own — the signature of a policy layered over kernel state, not a construct with state in its own right. Because C3 is also the mechanism through which A.1's defeasible OPP status is gained, narrowed and revoked, placing it beside A.1 is an honest statement of what kind of thing it is, not a demotion in importance.

6.6 Mode-scoped collaboration

Part One's published grammar carries a single collaboration model: synchronous, good-faith, deliberative, among participants holding standing. It is retained in full as one of five, since it remains correct for the conditions it was built for; its defect was never its content but its universality, applied without qualification to conditions whose latency envelopes, trust bases and authority structures are incompatible with it.

Table 6.3 — The five modes

ModeLatency envelopeParticipantsTrust basisConsensus regimeAuthority holder
ReflexBelow the decision windowNone (automated)Pre-authorisationRetrospective only (C2)Envelope revocation authority
CommandShortFew, mandated, accountableRole and mandateQuorum by roleMandated role
DeliberationExtendedMany, expert, weakly tiedEvidence and reputationFull protocol (existing)Protocol outcome
SurgeShort, sustainedMany, unverified, spontaneousContribution historyQuarantine, promotion-gatedPromotion authority
Affected-populationContinuousNon-expert, personally implicatedDuty of care (C10)Disclosure-scoped, non-contributory by defaultDisclosure authority

No mode inherits another's evidentiary standard by default; each declares its own. Modes, however, are the tractable half of this section. Transitions between them are where multi-party coordination empirically fails, and the published grammar specified none.

Table 6.4 — Minimum required transitions

From → ToTransitionRequirement
Reflex → CommandPromotion of a fired action into standing authorityMust reference the audit branch; must not be automatic
Command → DeliberationReferral of a decision for full protocolMust preserve the command decision as canonical until superseded
Deliberation → CommandProtocol outcome vested as command authorityMust record the vesting
Surge → CommandPromotion of quarantined content to authoritativeMust record promotion authority and evidence
Command → SurgeTasking of unverified contributorsMust not confer authority; tasking is not standing
Any → Affected-populationDisclosureMust pass C10 visibility; must record non-disclosure decisions
Deliberation → ReflexArming of a new envelopeMust validate shape before arming (C2)
Any → Degraded rungSubstrate condition failureGoverned by C3, not by mode logic

Every ordered pair of modes carries either a defined transition or an explicit statement that none exists; no transition confers authority implicitly.

6.7 The declared limit

Not every region of the parameter space is claimed. The scenario suite's own hard sub-region — decision window to consensus-cycle ratio below 0.05, transport survivability below 0.2 — is named explicitly as a boundary rather than absorbed into a broader coverage claim: at that extreme, even a pre-authorised envelope's trigger evidence may fail to reach the arming point before the window closes. This is stated as a declared limit of the revision, not as a covered case quietly narrowed in the fine print. A specification that names its own boundary is more credible than one that implies universal coverage, and the discipline that produced eight constructs from twelve is the same discipline that requires this sentence to appear rather than be smoothed away.


7. Standards and data

7.1 The mapping as published

SMILE's metamodel is deliberately mapped to existing standards rather than reinvented: PROV-O for provenance, SOSA/SSN for observation and sensing, OWL-Time for temporal relations, GeoSPARQL for spatial query, ODRL for rights and policy expression, SHACL for shape validation, NGSI-LD for context information, ISO 23247 for digital-twin framework alignment in manufacturing, OpenUSD for scene description, and MCP and A2A for tool and agent interoperability. This mapping is coherent, and it is coherent specifically as an industrial and semantic-web mapping. Eleven rows serve exactly that purpose; zero serve a humanitarian or emergency-response reading of the same specification, in a document whose flagship application, after this revision, is a humanitarian catastrophe.

7.2 The humanitarian gap

Table 7.1 sets out the mapping expansion, naming the specific standard each new row carries and, following the revision draft's own editorial rule, what it closes.

Table 7.1 — Mapping expansion, with named standards

DomainNamed standardClosesConstruct
AlertingCommon Alerting Protocol (CAP)No alerting standard was mapped at all; multi-channel, multi-language, severity/urgency/certainty-typed dissemination is a solved problem the specification did not referenceC2, §6.6
Emergency data exchangeEmergency Data Exchange Language (EDXL) familyResource request, situation report and cross-agency exchange had no carrier§6.6
Humanitarian dataHumanitarian Exchange Language (HXL)Interoperability with the response ecosystem's own working format§6.6
Response coordinationINSARAG guidelinesReception, tasking and clearance of arriving external capability — an authority-transition problem with an existing standard§6.6 (Table 6.4)
Victim identificationInterpol disaster-victim-identification (DVI) data modelIdentity reconciliation, mortuary workflow, cross-jurisdiction resolution — currently no person-in-hazard treatmentC10
DRR reportingSendai Framework for Disaster Risk Reduction indicatorsMeasurement-framework compatibility and entitlement eligibilityC1, §D
Minimum standardsSphere Handbook minimum standards (References [35])Affected-population interface floorC10
Data protectionICRC data-protection reference framework [REF-CHECK]Consent for deceased, missing and incapacitated personsC10
Media provenanceContent provenance and authenticity standard (C2PA)Authentication chain for contributed captureC9 (absorbed), C11
Records managementRecords-management and audit-trail standards [REF-CHECK]Retention, disposal, holdC11
Spatial webIEEE P2874 (Spatial Web Protocol) [REF-CHECK]The keyword set already advertises this claim class; the mapping must carry it or the manuscript must argue explicitly why not
GeospatialOGC SensorThings API; OGC GeoPose; OGC 3D TilesCoverage beyond a query vocabulary aloneC5 (absorbed), C6
Scene representationRadiance-field / splat representation format (no ratified standard as of September 2026; Khronos direction and the 3DGS source paper — References [55], [55])Current capture front ends produce this asset class and it has no format story alongside the existing scene-description mapping
UncertaintyUncertainty representation vocabulary, UncertML-class (References [41])The largest single technical omission in the mapping as published; blocks C4 without itC4
NetworkingDTN Bundle Protocol (IETF RFC 9171)Store-and-forward semanticsC12

Two rows deserve naming explicitly, since both proved load-bearing once the collapse test ran: OGC SensorThings as the natural transport for expected-observation schedules once C5's profile is carried as a C4 mapping row, and RFC 9171 named directly rather than as a generic "disruption-tolerant networking reference," since store-and-forward semantics are load-bearing for C12 and a citable standard exists.

7.3 The editorial rule and keyword–mapping parity

The revision draft states its own governing rule for this table and it is retained without amendment: every mapping row must state what it closes; a row without a closure statement is positioning, not specification. The same discipline applies retroactively to the specification's own keyword set. A keyword claiming a technology class — spatial web, physical AI, radiance-field capture — that outruns the mapping table is the fastest route to a reviewer concluding that the document positions rather than specifies. After this expansion, the requirement is stated plainly: every keyword corresponds either to a mapping row or to an explicit, written argument for its absence. A keyword with neither is removed, not defended after the fact.

7.4 The resilience property being bought

The heterogeneity of sources in a rapid-onset, multi-party event is close to absurd on its face — seismic networks, satellite passes, a single border gauge, messaging platforms, an SMS gateway, drone thermal imagery, a headmaster's telephone call, and two national administrations holding different views on whether the underlying data is a public good. No metamodel mapping makes that heterogeneity disappear, and what it buys is not uptime — uptime was never available in that basin and will not be available in most conditions this revision targets. What PROV-O, ODRL, SHACL and the SOSA/SSN-and-OWL-Time pairing jointly buy is that the picture degrades visibly and attributably rather than silently: a claim always carries who asserted it and from what; a party can share a derived alert without exposing the underlying observation; a node that stops meeting its declared shape is detectable; and a measurement, its sensor and its instant stay separable, so a failed gauge is distinguishable from a river that has genuinely fallen. Attributable degradation, not continuous availability, is the resilience property this specification delivers.


8. Instruments and their limits

8.1 Splats, point clouds, and the frame-honesty rule

Gaussian splats deliver photometric reality at a capture cost point clouds cannot match, and are legible to a non-specialist in a way a raw point-cloud file is not — a property that matters wherever the object must function as a boundary object across disciplines with no shared native format. Splats are correspondingly weak wherever geometry must be metrically trusted. The working discipline is therefore a division of labour: splats carry shared perception, point clouds and control points carry measurement, and every claim states which layer it rests on. At the Alpine facility both already coexist in the archive delivered in late August 2026 — several hundred million points across multiple clouds, tied to a surveyed control network, in layered form — and the frame is the clearest case for why the division matters: nothing in the delivered files declares a coordinate reference system. It reads as CH1903/LV03 off the raw coordinates and their agreement with the control points, with heights assumed to LN02, but neither is stated as fact rather than inference. That declared/inferred distinction has to survive into every downstream use or the twin begins lying quietly — exactly the condition C4 (§6.4) prevents by tagging the inference rather than erasing it.

8.2 On-site models and network-as-sensor: directions under discussion

Two directions under discussion with a telecommunications research laboratory sit close to this specification's concerns: running inference models on-site rather than in a remote data centre, and using the network itself as a sensing medium. Neither is an agreement — a year of informal contact has produced discussion, not a relationship, and the Non-Participant Model (§6.4, C8) is the correct construct for representing this party's state honestly in the interim. If the two directions eventually hold, the reason they matter is narrow: underground, the link to any remote system is the component most likely to fail, and a warning architecture depending on a data centre stops existing at precisely the moment it is needed.

8.3 Wearables, beacons, and store-and-forward

The failure to design against is documented, not hypothetical: thermal drones found nothing useful in flooded tunnels, passages were packed with debris consistent with descriptions of toothpaste in a tube, and the drones themselves were structurally limited to straight sections. What survives that failure mode is a badge that does three things: hold identity, hold last-known position from an in-tunnel anchor rather than satellite positioning, and beacon opportunistically to any radio in range, including a hand-carried receiver at a portal. The device is store-and-forward, not continuously connected; energy harvesting from vibration or a thermal gradient yields little power, but the required duty cycle is close to zero, so a beacon that wakes on shock and chirps intermittently for weeks fits comfortably where continuous telemetry does not. The design objective is a device whose usefulness increases as surrounding infrastructure disappears.

8.4 Mesh and on-node inference

A mesh network inside a tunnel is not a convenience; partial destruction of surrounding infrastructure is close to the expected case, which makes mesh the only topology that degrades gracefully. The corollary is that inference belongs on the nodes: a node that can only forward raw data to a server is worthless once the server is unreachable, while a node that can decide locally that the crown above it is moving still carries meaning across one hop to a rescuer with no server in reach. This is the same argument as on-site model execution (§8.2), reached independently from the failure end rather than the product-design end — mild evidence it is correct rather than merely preferred.

8.5 Quantum sensing and quantum optimisation: two different near-term claims

Two quantum technology classes are relevant here, and unequally mature. Quantum gravimetry — cold-atom or superconducting interferometric sensing of local gravitational variation — is close enough to fielded technology to be a near-term instrument class for detecting subsurface voids and prior workings that conventional survey may miss, of direct relevance to the Alpine facility's shaft-siting problem (Stray et al., 2022 — References [61]). Quantum optimisation — a quantum or quantum-inspired solver for a routing or cascade-assignment problem's combinatorial core — is materially less mature. A separately maintained SMILE governance insert states the correct posture: "An emerging model class is quantum-capable optimisation and simulation… hybrid formulations — a quantum subroutine addressing the combinatorial core while quantitative models supply the physics — as the plausible near-term shape" [SMILE v6.5 Insert 02, 4.4], with a governance rule that makes either technology admissible without overclaiming it: a quantum solver enters the fabric as a registered, versioned model whose outputs are conditional branch states, not facts, subject to the same gates as any other simulation. That rule, not hardware maturity, is what this revision requires, and it is already satisfied by C4's epistemic-status requirement.

8.6 Crypto-agility and post-quantum readiness (G2)

A record functioning as constitutional infrastructure over a multi-decade lifetime, carrying evidentiary and personal data, must assume harvest-now-decrypt-later exposure — material encrypted today may be recorded for decryption once cryptographically relevant quantum computing arrives. The requirement is accordingly framed against the fabric's data lifetime rather than its deployment date: algorithm agility at the integrity and confidentiality layers, a stated migration posture, no algorithm identifier hard-bound in the metamodel. A separately maintained insert reaches the same conclusion independently — "Key management must additionally be assessed against the fabric's data lifetime rather than its deployment date… harvest-now-decrypt-later collection is in scope of the threat model" [SMILE v6.5 Insert 20, 12.4] — mild convergent evidence the requirement is correctly placed. It is cheap to specify and conspicuous to omit, and C11's integrity attestation is its primary surface.

8.7 Model provenance, the assurance case, and the EU AI Act

The provenance vocabulary mapped in §7.1 covers data lineage comprehensively and model lineage not at all — an audit gap today and, under emerging critical-infrastructure AI regimes including the EU AI Act's obligations for high-risk systems, a compliance gap in the near term (Regulation (EU) 2024/1689 — References [62]; the Annex III high-risk category for critical-infrastructure safety components is the relevant correspondence and is stated here as the author's reading, not as a legal determination). G3 accordingly treats model provenance as required evidence within a structured assurance case: model version, training or configuration lineage, execution environment, numerical precision for any inference contributing to a recorded assertion. The assurance case also functions as the integration test for the whole metamodel: if its evidence requirements cannot be satisfied from the eight surviving constructs as revised, the metamodel is incomplete regardless of how complete the prose reads — a deliberately mechanical test, in the spirit of Chapter 6's collapse test.


9. The Alpine facility as the venue

9.1 The laboratory in the public record

The Alpine facility is an underground test gallery founded in 1970 and operated today as part of a larger engineering group. Its own published material describes roughly five kilometres of galleries, caverns, laboratories and training rooms in hard siliceous limestone and weaker shale, with a rock and concrete laboratory, fire and incident testing, and training for tunnel professionals including nozzle-operator certification under EFNARC. In December 2024 the Federal Council awarded contributions under Article 15 of the Research and Innovation Promotion Act (FIFG) for the 2025–2028 period, and the facility appears on the State Secretariat for Education, Research and Innovation's list of research infrastructures of national importance; the facility announced the recognition on its own site. The Federal Audit Office's report on institutions of national importance (EFK-24428, finalised 15 October 2024, published 3 February 2025) sets the governance frame in which that status is reviewed, and Article 12 §1 of the WBF ordinance SR 420.111 fixes the next application date at 30 June of the third year of the funding period, which for 2025–2028 is 30 June 2027.

Everything in this chapter beyond that paragraph rests on the author's engagement with the facility under a non-disclosure agreement signed in August 2026. The specifics of the scan archive, the geological model, the operational restrictions and the organisation's internal planning are therefore described at the level of method rather than reproduced as fact, and no figure in this chapter that originates from the facility's own documents appears here.

9.2 What a research gallery contributes that a simulation cannot

The argument of chapters 3 and 6 is that the interval between detection and decision is shortened by rehearsal in a shared object, and that rehearsal has to happen somewhere real before the day it is needed. A five-kilometre gallery in competent rock, already instrumented for fire and incident work and already used for firefighter training, is a venue where a rehearsal branch can be run digitally and then walked physically by the people who would have to act. Underground test facilities of this kind have long required clients to submit a digital model for virtual prototyping before physical tests are run — a practice that anticipates the Concurrent Engineering phase of SMILE by decades.

9.3 The first decision, as a method

The engagement's first working decision concerns a single excavation feature whose scientific purpose remains confidential; only the method used to resolve it is described here. As a method it has the shape of a Minimal Viable Twin: a small number of candidate alignments, one rock model with its provenance and uncertainty attached, one performance criterion for the experiment, one excavation constraint drawn from the regulatory record, and one session in which the driller, the physicist and the operator contest the alignments against the same object, keeping every rejected alignment on record as a branch. Its precondition is the one every twin project meets sooner or later: the coordinate and elevation reference has to be declared by a surveyor rather than left to software inference. Until it is, every downstream tolerance is unknown, and the honest twin says so on every export.

9.4 Enclosed-space emergency response as an existing field

Underground rescue is not a new application for this class of facility. After the European tunnel fires of the late 1990s, research programmes on emergency services in enclosed spaces — tunnels, but also ships, underground car parks and other confined environments with predefined escape routes — were run with facilities of this kind as partners. That prior field is what makes a hydropower-tunnel rescue rehearsal a continuation of established practice, and it is why the Rehearsal phase added in v6.5.0 (§6, E.4) has a natural first venue.

9.5 The probe to run first

Of the twelve probes in the companion suite, PR-9 — onboarding a contributor with no prior standing into a quarantine tier, exercising promotion and demotion, and surfacing a collision with a mandated channel — is the one most likely to fail and therefore the one whose result is most worth reporting. A research gallery is a place where a failed probe costs an afternoon. The manuscript requirement that at least one honestly reported failure appear in v6.5.0 (§11.2, §11.3) is expected to be met here.

10. Cooperation across twins and across people

10.1 The weak-tie argument

Granovetter's original finding — that novel information travels through weak ties, because a strong tie already shares what its counterpart knows (Granovetter, 1973) — has since been given a causal test: a platform-scale experiment found weak ties measurably increase job transmission and mobility relative to strong ties, holding network structure constant (Rajkumar et al., 2022 — References [6]). A global expert response to a cross-border cascade is, structurally, a weak-tie network by construction: a glaciologist, a national meteorological service, an independent hazard-mapping laboratory and a tunnel-rescue specialist typically share no prior relationship and no independent grounds to trust one another's numbers under time pressure — precisely when weak ties characteristically fail, since trust normally must be established before an unfamiliar source is acted on, and establishing trust is slow. The single highest-value contribution in the Nepal case came from a person with no institutional standing whatsoever, which the parallel adversarial evaluation of this event treats as a live instance of the argument.

10.2 Provenance substituting for trust

A provenance-carrying shared emulation changes what a weak tie needs before its contribution can be acted on. A contribution is evaluated on its stated source and its stated uncertainty — both carried automatically once PROV-O-style provenance is load-bearing — instead of on the contributor's institutional standing, which a stranger by definition does not have. This is the same mechanism the Surge mode (§6.6) formalises: quarantine makes a zero-history contribution visible and attributed without pretending it is authoritative, and promotion moves it to authoritative status on the strength of what it says and where it came from. The practical effect is that a weak tie becomes usable within hours, where building sufficient personal trust would otherwise take quarters — which is the actual argument for building this kind of shared object, independent of its visual or presentational qualities.

10.3 Boundary object and boundary communicator

Star and Griesemer's boundary object — plastic enough to fit local practice, robust enough to hold a common identity across sites (Star & Griesemer, 1989) — explains why a rock model succeeds where a written report fails: a driller reads metres and rock class, a physicist reads vibration and mass distribution, a regulatory authority reads permitted and prohibited zones, and all three read the same geometry, instead of three separate descriptions of it. A maintained, current emulation extends this into what is better called a boundary communicator: a rescuer at a portal and a remote rock engineer need not exchange sentences about a tunnel section if both can point at the same volume in the same live model, removing exactly the translation loss that is fatal under time pressure — which is why the emulation must stay current rather than merely accurate as of the last survey, since a year-stale boundary communicator communicates the wrong thing with the same apparent confidence as a current one.

10.4 The Non-Participant Model for actors who will not federate

C8 (§6.4) is built to represent two structurally different reasons an actor will not join a shared twin, and both appear across the two cases examined here. In Nepal, cross-border glaciological and hydrological holdings are treated by their controlling parties as strategically sensitive, reason class policy or strategic interest — the boundary's absence of shared data is an explicit known-unknown, never silently read downstream as an absence of hazard. At the Alpine facility, the a telecommunications research laboratory relationship of §8.2 is a different reason class entirely — capability, where nothing has yet been agreed — and treating the two identically would be exactly the category error the construct exists to prevent, since "we don't have this yet" and "we will never give you this" require different downstream handling even though both look, from outside, like the same empty field.

10.5 The Surge tier for strangers

The mode table's Surge row (§6.6) exists for the empirical pattern in which the highest-value contribution in a high-consequence event comes from someone institutional standing would never have selected in advance, since standing correlates with institutional position while value correlates with proximity, capability and availability — properties standing does not predict. Nepal's highest-value asset in the flooded tunnels was, on this evidence, exactly such a person. The facility probe of §9.5 (PR-9) is a controlled, low-risk test of whether the mode can actually operate on a real object — the shaft decision — with a real fourth participant of no standing who knows something material. It is a test, not merely a claim that reads well.

10.6 The Affected-Person view for those implicated

C10 (§6.4) governs a category present in both cases and easy to overlook in an operator-written specification: people to whom the represented state happens, not people who operate on it. In Nepal this includes villagers, a headmaster coordinating an evacuation by telephone, and roughly five hundred hydropower workers believed to have been in the tunnels when the wave arrived, out of some nine hundred reported missing across twelve projects. At the Alpine facility it includes the thirty-five staff and upward of seventeen thousand annual visitors reported in the facility's own public material (§9.1). The requirement that consent for a deceased, missing or incapacitated person never default to granted, and that a non-disclosure decision itself be recorded with provenance, applies unmodified to both populations — the difference in scale between a flooded valley and a research gallery does not change what duty of care to an implicated non-expert requires.

10.7 Federation without a centre

A.1's correction, carried forward from Part One, is what makes multi-site federation possible at all: a twin holds obligatory-passage-point status only while it satisfies declared availability, integrity and impartiality conditions, evaluated continuously and revocable on failure — never by constitutional assertion alone — and a federation model built around one twin's permanent chokepoint status is a model no second site can safely join. A separately maintained governance insert states the compositional principle this implies: a higher-order fabric — a facility, a municipality, a region, a nation — is composed by importing what each member fabric declares for export… persistent anchors, observed events with valid time and recorded time, claims with provenance and claim state, and serialisable Branch Manifests — while raw substrate, internal authority relations and undeclared observations do not cross the boundary [SMILE v6.5 Insert 06, 4.14]. Authority does not aggregate upward under this principle — a claim entering a composed fabric keeps its exporting fabric's attribution — and a disruption at one scale propagates as a conditional effect along a declared dependency relation, governed by that relation rather than by informal judgement about what one site's trouble means for another's. Federation, on this model, is a set of declared export contracts between sovereign sites — the shape that lets a Himalayan operator, a Swiss gallery, and a national disaster-management authority cooperate without any one becoming the others' single point of failure.

10.8 What a Himalayan operator could fork, and what they could not

A gallery in Switzerland cannot forecast a bedrock failure in the Himalaya; ice dynamics, satellite tasking and transboundary data-sharing agreements are other institutions' mandates, and residual scientific uncertainty about the 26 August event's initiating mechanism — a landslide incorporating glacial ice, or a glacial collapse in its own right — remains open at the time of writing; the USGS event record itself carries the residual uncertainty (References [48]). Nor would a twin, however complete, have reached the workers underground once the wave had entered the headrace tunnels; the decision window had already closed, and no representational architecture changes a window that has closed. What a Himalayan operator can fork from the Alpine facility sits upstream of that closure: a Minimal Viable Twin narrow enough to finish in weeks (§9.4), rehearsing an evacuation route digitally before walking it physically in a section deliberately never risked by live testing (§9.4), the badge-and-mesh pattern most useful exactly when infrastructure has failed (§8.3–8.4), and treating a network's own silence as a located event in its own right. None of this requires the two institutions to share a database, a language, or a prior relationship — only that each build its own twin to the same declared discipline, so that what is proven in five kilometres of Swiss rock is available as a transferable method to an operator in a valley its authors will likely never visit.


11. Conclusions, limits, and the order of work

11.1 What the two cases together establish

Taken together, the Nepal–Tibet event and the Alpine facility engagement demonstrate that the same grammar gaps recur at radically different scales and radically different costs of failure. The year-long incubation failure that left a published hazard warning with no bound owner (C1) and the seven-minute tempo failure that placed a border crossing's destruction below any deliberative protocol's cycle time (C2) are structurally distinct failure classes, and both were present in the same ten-hour chain of events. The same two failure classes recur at the Alpine facility in miniature: a geological finding sitting in reports without a named owner or schedule, and infrastructure whose maintenance windows are shrinking under twenty-four-hour operational pressure toward the same tempo-exclusion condition that broke catastrophically at valley scale. This recurrence across four orders of magnitude of consequence is the strongest available argument that the eight surviving constructs address structural properties of high-consequence, multi-party, low-observability conditions in general.

11.2 What remains unproven

Three limits should be stated with the same directness the revision applies to its own scenario boundary (§6.7). First, the evidence base remains a single self-reported, retrospective deployment record; twelve constructs collapsed to eight against that same base narrows the credibility gap without closing it. Second, of the twelve capability probes in the companion artefact (Appendix B), none has yet been run; PR-9 is recommended as the first to execute, at the Alpine facility, in September 2026, precisely because it is cheap and likely to fail, but until run its pass condition remains a prediction. Third, the collapse test itself carries a documented evidence gap: the adversarial stress test supplying several of this chapter's judgements did not have the manuscript body of SMILE v6.4.3 <!-- smile:version-citation --> available as extracted text, so every claim about what the published specification omits is an unverified absence claim requiring a check against the manuscript's own §7. This report has relied on that stress test's characterisations without independently re-verifying each one; that verification remains outstanding.

11.3 The publication order

The recommended sequence follows the discipline of Chapter 6. First, a constraint audit runs on the revised draft as a wholly separate pass, before any further copy-editing, because the pressure that improves motivating prose is exactly the pressure that leaks identifiable incident detail. Second, the collapse result from §6.5 is applied mechanically — C5 into C4, C7 into C6 as a §D amendment, C9 into the Surge row, C3 into governance beside A.1 — and the coverage matrix re-derived to confirm no empty rows. Third, C1, C2 and C8, having no kernel dependency, are deposited first as a standalone addendum small enough not to require a full version bump, since together they answer both the year-long incubation failure and the seven-minute tempo failure. Fourth, the adversarial case — incident-named, in contrast to the parameterised specification — is deposited separately and linked bidirectionally (`IsSupplementTo` / `IsSupplementedBy`), which keeps the specification forkable without an operator elsewhere inheriting someone else's incident. Fifth, PR-9 is run at the Alpine facility on the shaft decision (§9.3, §9.5) and its result reported, pass or fail. Only then is v6.5.0 itself deposited: eight constructs, the kernel drawn explicitly, A.1 and A.2 applied, every mapping row carrying a closure statement, and every proposition P1–P26 carrying a disconfirming observation.

11.4 What requires a human decision

Several open questions here are not analytical questions this report can resolve. Whether v6.5.0 is deposited as a formal new version on the existing concept DOI or held as a Zenodo draft pending the constraint audit and PR-9 result is a publication decision belonging to the specification's author. Whether the Nepal case is deposited separately under the stress test's recommended companion structure, and under what licence and anonymisation posture, is likewise authorial. The routing of derivative materials inside the facility is an internal governance question this report does not answer. And the shaft-siting decision, the datum resolution it depends on, and the surveyor engagement required to close it (§9.3) require a licensed surveyor's measurement and the facility's own authorisation, which no twin can supply in their place.


Appendix A — Scenario parameters and classes

Table A.1 — Eleven structural parameters

ParamNameDefinitionRange
WDecision windowTime from first detectable signal to irreversible consequence at the nearest affected nodeExpressed as a ratio to K
KConsensus cycle timeObserved median time for the deliberative protocol to reach a terminal outcomeBaseline, normalised to 1
OObservability fractionProportion of decision-relevant state directly observable at decision time0–1
FFederation completenessProportion of decision-relevant actants that federate on available terms0–1
DClosure depthMaximum propagation hops from origin node to the furthest materially affected nodeInteger ≥ 1
XEdge-type heterogeneityNumber of distinct propagation types along the dominant pathInteger ≥ 1
PParticipant multiplicityCount of distinct contributing actants, order of magnitude10⁰–10⁵
SStanding fractionProportion of contributing actants holding prior institutional standing0–1
LLocal capacity ratioCapacity of the origin node relative to system mean0–1+
BBenefit incidence ratioProportion of an origin-node investment's benefit accruing to the origin node0–1
TTransport survivabilityProportion of transport capacity surviving the initiating process0–1

Table A.2 — Six scenario classes

ClassRegionStructural failure
SC-1W/K < 0.2; O falls from >0.6 to <0.2 during the event; D ≥ 3; X ≥ 3; T < 0.5Sub-window cascade with origin observability loss
SC-2F < 0.6 with the non-federating actant on the dominant path; D ≥ 2; reason class ∈ {policy, strategic interest}Non-federating counterparty on the dominant propagation path
SC-3O < 0.1 for the decision-critical volume; direct sensing physically defeated; W extended, consequence monotonically worseningLow-observability entrapment with no interior instrumentation
SC-4P ≥ 10³; S < 0.1; contribution rate exceeds mandated-channel capacity by ≥ 1 order of magnitude; no verification infrastructureSurge exceeding mandated-channel throughput
SC-5B < 0.2; L < 0.4; D ≥ 3; high downstream consequenceOrigin-node under-instrumentation under benefit externality
SC-6Substrate availability → 0; T < 0.3; hazard ongoing; W shortSubstrate loss during active hazard

The declared hard limit named in §6.7 sits within SC-1: W/K < 0.05 with T < 0.2, where even a pre-authorised envelope's trigger evidence may not reach the arming point.


Appendix B — Capability probes

Table B.1 — Twelve probes, one per construct

ProbeConstructExercisePass condition
PR-1C1Instantiate an obligation; transfer across two successive owners; lapse itFull chain reconstructible from provenance alone, with no access to any originating system
PR-2C2Arm an envelope; fire on synthetic trigger; attempt to fire after expiry; attempt to arm a shape-invalid envelopeFiring produces a sufficient audit branch; expired envelope does not fire; invalid envelope is not armable
PR-3C3Descend to dark with the substrate unreachable; re-ascendEvery rung has a non-empty action set and named authority; descent does not require substrate reachability; re-ascent preserves ordering
PR-4C4Record two credible divergent assertions on one referent; run a consensus round; select an actionContested pair survives; `unresolved` is reachable; action recordable as robust-across-range with its range
PR-5C5Silence a platform under schedule; separately induce partitionLocated event within tolerance; silence distinguishable from partition, or the assertion is recorded contested
PR-6C6Compute TTI across three edge types at depth ≥3; mutate upstream state; remove a propagation modelTTI recomputes; the node with no model is flagged rather than dropped from the computation
PR-7C7Assess proportionality on a node with B<0.2 and unresolved dependenciesReturns incompleteness instead of a recommendation; emits benefit-incidence gap with sets named
PR-8C8Query a shadow actant's state; query a known-unknownNeither returns without status and reason class; the known-unknown is returned as an object rather than an empty result
PR-9C9Contribute as a zero-history actant; promote; demote; contribute on a referent covered by a mandated assertionContribution within one interaction, visible and non-authoritative; both promotion and demotion exercised; collision surfaced
PR-10C10Attempt default branch visibility; disclose a derived estimate about an identifiable person; decline a disclosureNo default visibility; audience-scoped presentation differs from operator default; the non-disclosure is recorded
PR-11C11Designate canonicity; transfer it; hold a branch past its retention date; tamper a branchOne canonical branch throughout; transfer recorded; held branch undisposable; tamper detected without external copy
PR-12C12Partition; queue; resolveUnreachable distinguishable from absent; ordering preserved; queue state observable

At least one honestly reported failure is required in the eventual manuscript (§11.2, §11.3). PR-9, run at the Alpine facility against the shaft-siting decision, is recommended as the probe most likely to supply it (§9.3, §9.5).


Appendix C — Glossary of German rock, lining and safety terms

Table C.1 — Glossary of German rock, lining and safety terms

German termEnglish glossContext
SpritzbetonShotcrete (sprayed concrete)Primary tunnel lining material, extensively tested on-site
OrtbetonCast-in-place concretePermanent structural concrete, distinguished from shotcrete in lining practice
Nackter FelsBare rockExcavation state; baseline condition prior to any lining
AusbauLining, support, permanent reinforcementGallery support structure; covers both temporary and permanent stages
SpritzabdichtungSprayed sealing membraneWaterproofing layer, tested on-site
Selbstverdichtender BetonSelf-compacting concreteAdvanced concrete type tested for performance
CarbonatisierungCarbonatizationDurability test: CO₂ ingress and alkalinity loss in concrete
ChlorideindringungChloride penetrationDurability test: salt-driven corrosion risk in concrete
Frost/TauwechselFreeze/thaw cyclingDurability test: freeze-thaw damage in concrete
AbdichtungSealing, waterproofingGeneric term for sealing systems tested at the facility
KaverneCavernLarge underground chamber; the facility comprises several
StolleneingangGallery entranceAccess point; the facility owns the real estate at its entrances
GeotechnikGeotechnicsThe engineering discipline the facility's testing work sits within
AuffahrungExcavation headingDirection of active excavation; covers both temporary headings and named permanent ones
BergwasserMine waterGroundwater encountered in underground excavation
HohlraumCavity, voidExisting underground chamber or working shown on plan
BrandabschnittFire compartmentSection isolated by fire-rated walls and doors
FluchtwegEscape routeMarked exit pathway
SammelplatzAssembly pointSafe gathering area outside the underground facility
LöschwasserExtinguishing waterFire-suppression water supply or infrastructure
NotausgangEmergency exitMarked emergency exit point

Geological detail from the facility's own plans is withheld under NDA.




References

All entries below were resolved against a publisher record, DOI, or the issuing body's own page on 2 September 2026. Entries that could not be verified were excluded rather than approximated.

A. Theory (13)

1. Callon, M. (1986). Some elements of a sociology of translation: Domestication of the scallops and the fishermen of St Brieuc Bay. In J. Law (Ed.), Power, action and belief: A new sociology of knowledge? (pp. 196–233). Routledge & Kegan Paul. VERIFIED via https://onlinelibrary.wiley.com/doi/10.1111/j.1467-954X.1984.tb00113.x (1984 journal original of the same text; 1986 Routledge reprint confirmed via library/publisher citation records, e.g. scirp.org reference id 2849398) resolved on 2026-09-02 Supports: problematisation, obligatory passage point, and translation as the mechanism by which a shared reality is enrolled across actors.

2. Latour, B. (1987). Science in action: How to follow scientists and engineers through society. Harvard University Press. VERIFIED via https://www.hup.harvard.edu/books/9780674792913 resolved on 2026-09-02 Supports: black-boxing and the tracing of fact-construction as network-building.

3. Latour, B. (2005). Reassembling the social: An introduction to actor-network-theory. Oxford University Press. VERIFIED via https://global.oup.com/academic/product/reassembling-the-social-9780199256051 resolved on 2026-09-02 Supports: the flat ontology of actor-networks used to frame SMILE's "shared reality" as an assembled, not given, object.

4. Star, S. L., & Griesemer, J. R. (1989). Institutional ecology, 'translations' and boundary objects: Amateurs and professionals in Berkeley's Museum of Vertebrate Zoology, 1907–39. Social Studies of Science, 19(3), 387–420. VERIFIED via https://www.jstor.org/stable/i212616 (journal issue record, Social Studies of Science 19(3), Aug 1989) resolved on 2026-09-02 Supports: boundary objects as the concept underlying cross-agency artifacts shared between research institutes, an industrial operator, WINNIIO, and Nepali and Chinese hydromet services.

5. Granovetter, M. S. (1973). The strength of weak ties. American Journal of Sociology, 78(6), 1360–1380. VERIFIED via https://www.journals.uchicago.edu/doi/abs/10.1086/225469 resolved on 2026-09-02 Supports: the weak-tie argument for cross-boundary information flow (Nepal–China hydromet liaison).

6. Rajkumar, K., Saint-Jacques, G., Bojinov, I., Brynjolfsson, E., & Aral, S. (2022). A causal test of the strength of weak ties. Science, 377(6612), 1304–1310. VERIFIED via https://www.science.org/doi/10.1126/science.abl4476 resolved on 2026-09-02 Supports: causal (not merely correlational) evidence for weak-tie value, used to argue for investing in thin, low-latency cross-border channels rather than only strong bilateral ones.

7. Weick, K. E., & Sutcliffe, K. M. (2015). Managing the unexpected: Sustained performance in a complex world (3rd ed.). Jossey-Bass. VERIFIED via https://www.wiley.com/en-us/Managing+the+Unexpected:+Sustained+Performance+in+a+Complex+World,+3rd+Edition-p-9781118862414 resolved on 2026-09-02 Supports: high-reliability-organization principles (preoccupation with failure, reluctance to simplify) applied to cascade monitoring.

8. Hollnagel, E. (2014). Safety-I and Safety-II: The past and future of safety management. Ashgate. VERIFIED via https://www.routledge.com/Safety-I-and-Safety-II-The-Past-and-Future-of-Safety-Management/Hollnagel/p/book/9781472423085 resolved on 2026-09-02 Supports: the Safety-II framing (performance variability as normal) used to argue for adaptive, not purely compliance-based, cascade response.

9. Klein, G. A. (1998). Sources of power: How people make decisions. MIT Press. VERIFIED via https://mitpress.mit.edu/9780262611466/sources-of-power/ resolved on 2026-09-02 Supports: recognition-primed decision-making as the model for expert responders acting under Rasuwagadhi/Bhotekoshi time pressure.

10. Endsley, M. R. (1995). Toward a theory of situation awareness in dynamic systems. Human Factors, 37(1), 32–64. VERIFIED via https://journals.sagepub.com/doi/10.1518/001872095779049543 resolved on 2026-09-02 Supports: the three-level (perception/comprehension/projection) situation-awareness model used to structure what a shared-reality layer must deliver to a responder.

11. Turner, B. A. (1978). Man-made disasters. Wykeham Publications. VERIFIED via https://openlibrary.org/works/OL3338053W (publisher "Wykeham Publications, London," first published 1978, confirmed via Open Library catalog API) resolved on 2026-09-02 Supports: disaster incubation theory — the accumulation of unnoticed signals (e.g. the 2025 SKLGP warning) before a socio-technical disaster.

12. Perrow, C. (1984). Normal accidents: Living with high-risk technologies. Basic Books. VERIFIED via https://press.princeton.edu/books/paperback/9780691004129/normal-accidents resolved on 2026-09-02 Supports: tight coupling / complex interaction as the structural condition that turns a glacier collapse into a transboundary infrastructure cascade.

13. Tuckman, B. W. (1965). Developmental sequence in small groups. Psychological Bulletin, 63(6), 384–399. VERIFIED via https://psycnet.apa.org/buy/1965-12187-001 resolved on 2026-09-02 Supports: cited only as the deprecated forming–storming–norming–performing model, superseded in the report by concurrent-capability framings (SMILE, HRO).


B. Concurrent engineering and latency (4)

14. Chachere, J., Kunz, J., & Levitt, R. (2009). The role of reduced latency in integrated concurrent engineering (CIFE Working Paper #WP116). Stanford University, Center for Integrated Facility Engineering. VERIFIED via https://purl.stanford.edu/bd089dx8723 (fetched directly; confirms JPL Team X, "nine months in about three weeks," and nine hours of sessions) resolved on 2026-09-02 Supports: reduced-latency concurrent engineering as the mechanism (not automation) behind large compressions of design/response time — the JPL 9-months-to-9-hours analogy, correctly qualified per rules/jpl-extreme-collaboration.md.

15. Mark, G. (2002). Extreme collaboration. Communications of the ACM, 45(6), 89–93. VERIFIED via https://dl.acm.org/citation.cfm?id=508453 resolved on 2026-09-02 Supports: co-location/war-room dynamics as the social mechanism underneath concurrent-engineering speedups, applied to cascade command posts.

16. Warfield, K. (2013). Team X [Presentation]. NASA Technical Reports Server. Document ID 20130009192. VERIFIED via https://ntrs.nasa.gov/citations/20130009192 resolved on 2026-09-02 Supports: primary JPL-side account of Team X's founding (1995) and >1,100 completed studies, sourcing the concurrent-engineering analogy independent of the Stanford secondary literature.

17. Bandecchi, M., Melton, B., & Ongaro, F. (1999). The ESA/ESTEC Concurrent Design Facility. ESA Bulletin, 99. VERIFIED via https://www.esa.int/esapub/bulletin/bullet99/bande99.pdf resolved on 2026-09-02 Supports: the ESA CDF as the institutionalized, non-NASA replication of concurrent engineering — a corroborating figure independent of the JPL number.


C. Standards (25)

18. World Wide Web Consortium. (2013). PROV-O: The PROV ontology (W3C Recommendation, 30 April 2013). VERIFIED via https://www.w3.org/TR/prov-o/ (fetched directly; title and recommendation date confirmed) resolved on 2026-09-02 Supports: provenance modeling for the SMILE reality-branch lifecycle.

19. World Wide Web Consortium / Open Geospatial Consortium. (2017). Semantic sensor network ontology (SOSA/SSN) (W3C Recommendation, 19 October 2017). VERIFIED via https://www.w3.org/TR/vocab-ssn/ (fetched directly; title "Semantic Sensor Network Ontology," recommendation date confirmed) resolved on 2026-09-02 Supports: sensor/observation modeling for glacier and hydromet telemetry feeding the shared reality layer.

20. World Wide Web Consortium / Open Geospatial Consortium. (2017). Time ontology in OWL (W3C Recommendation). VERIFIED via https://www.w3.org/TR/owl-time/ resolved on 2026-09-02 Supports: temporal reasoning (event ordering, duration) across the multi-day incubation-to-cascade timeline.

21. Open Geospatial Consortium. (2022). OGC GeoSPARQL — A geographic query language for RDF data, version 1.1 (OGC 22-047r1). VERIFIED via https://docs.ogc.org/is/22-047r1/22-047r1.html resolved on 2026-09-02 Supports: geospatial querying of the shared reality graph (lake, valley, and infrastructure geometries).

22. World Wide Web Consortium. (2018). ODRL information model 2.2 (W3C Recommendation). VERIFIED via https://www.w3.org/TR/odrl-model/ resolved on 2026-09-02 Supports: usage/rights policy expression for cross-agency (Nepal–China–RISE–WINNIIO) data-sharing agreements.

23. World Wide Web Consortium. (2017). Shapes constraint language (SHACL) (W3C Recommendation, 20 July 2017). VERIFIED via https://www.w3.org/TR/shacl/ resolved on 2026-09-02 Supports: validation of shared-reality graph data before it is trusted by a downstream agent.

24. ETSI. (2024). Context information management (CIM); NGSI-LD API (ETSI GS CIM 009, V1.8.1). VERIFIED via https://www.etsi.org/deliver/etsi_gs/CIM/001_099/009/01.08.01_60/gs_cim009v010801p.pdf resolved on 2026-09-02 Supports: the NGSI-LD context-broker pattern used as the transport layer for digital-twin context updates.

25. ISO. (2021–2026). Automation systems and integration — Digital twin framework for manufacturing (ISO 23247, parts 1–6). VERIFIED via https://www.iso.org/standard/78743.html (Part 2, Reference architecture) and https://www.iso.org/standard/87425.html (Part 5, Digital thread) resolved on 2026-09-02 Supports: reference architecture and digital-thread concepts adapted from manufacturing to infrastructure/hazard twins.

26. Alliance for OpenUSD (AOUSD). (2025). OpenUSD Core Specification 1.0. VERIFIED via https://www.linuxfoundation.org/press/alliance-for-openusd-announces-core-specification-1.0-the-universal-language-for-building-3d-worlds resolved on 2026-09-02 Supports: the scene-description substrate proposed for interoperable 3D representations of the Alpine facility and the Langtang valley.

27. Anthropic. (2024). Model Context Protocol specification. VERIFIED via https://modelcontextprotocol.io/specification/2025-11-25 (introduced at https://www.anthropic.com/news/model-context-protocol, November 2024) resolved on 2026-09-02 Supports: the tool-integration protocol used to connect SMILE agents to live data sources.

28. Google. (2025). Agent2Agent (A2A) protocol. VERIFIED via https://developers.googleblog.com/en/a2a-a-new-era-of-agent-interoperability/ (announced 9 April 2025; governance at https://github.com/a2aproject/A2A) resolved on 2026-09-02 Supports: inter-agent task interoperability across organizational boundaries (RISE agents ↔ WINNIIO agents ↔ hazard-monitoring agents).

29. OASIS. (2010). Common Alerting Protocol, version 1.2 (OASIS Standard). VERIFIED via https://docs.oasis-open.org/emergency/cap/v1.2/CAP-v1.2-os.html resolved on 2026-09-02 Supports: the all-hazard alert message format proposed for cascade early-warning dissemination.

30. OASIS. (2012). Emergency Data Exchange Language (EDXL) Distribution Element, version 2.0 (OASIS Standard). VERIFIED via https://www.oasis-open.org/standard/edxl-de-20/ resolved on 2026-09-02 Supports: the routing/wrapper layer proposed to carry CAP and other emergency payloads between Nepali and Chinese systems.

31. Humanitarian Exchange Language (HXL) Standard. (n.d.). HXL specification. VERIFIED via https://hxlstandard.org/ and https://github.com/HXLStandard resolved on 2026-09-02 Supports: the lightweight hashtag convention proposed for humanitarian dataset interoperability during response. Note: OCHA's Centre for Humanitarian Data ended HXL/HDX support as of 31 January 2026 — cited as historical/still-implemented standard, not as an actively maintained one.

32. INSARAG. (2020). INSARAG guidelines, 2020 edition (Volumes I–III). VERIFIED via https://reliefweb.int/report/world/insarag-guidelines-2020-volume-ii-preparedness-and-response-manual-b-operations resolved on 2026-09-02 Supports: international urban search-and-rescue coordination methodology relevant to the hydropower-tunnel search operations.

33. INTERPOL. (2023). Disaster victim identification guide (November 2023 edition). VERIFIED via https://www.interpol.int/content/download/589/file/DVI_DVI%20Guide%202023.pdf resolved on 2026-09-02 Supports: the four-phase DVI protocol (scene/post-mortem/ante-mortem/reconciliation) relevant to Bhotekoshi/Rasuwagadhi mass-fatality identification. Note: current governing edition is 2023, not 2020 as suggested in the brief — the 2023 edition is cited as the correctly attributed, currently governing text.

34. United Nations Office for Disaster Risk Reduction. (2015). Sendai Framework for Disaster Risk Reduction 2015–2030. VERIFIED via https://www.undrr.org/publication/sendai-framework-disaster-risk-reduction-2015-2030 resolved on 2026-09-02 Supports: the four-priorities/seven-targets global DRR frame structuring the report's policy discussion.

35. Sphere Association. (2018). The Sphere handbook: Humanitarian charter and minimum standards in humanitarian response (2018 ed.). VERIFIED via https://spherestandards.org/handbook/ resolved on 2026-09-02 Supports: minimum-standards baseline for the humanitarian-response chapter.

36. Marelli, M. (Ed.). (2023). Handbook on data protection in humanitarian action (3rd ed.). International Committee of the Red Cross / Cambridge University Press. VERIFIED via https://www.cambridge.org/us/universitypress/subjects/politics-international-relations/international-relations-and-international-organisations/handbook-data-protection-humanitarian-action-3rd-edition resolved on 2026-09-02 Supports: data-protection principles governing cross-border sharing of victim/survivor data in the shared-reality layer.

37. Coalition for Content Provenance and Authenticity (C2PA). (2021–). C2PA technical specification. VERIFIED via https://c2pa.org/ and https://spec.c2pa.org/specifications/specifications/1.0/specs/C2PA_Specification.html (coalition formed 22 February 2021) resolved on 2026-09-02 Supports: content-provenance manifests proposed to authenticate satellite/drone imagery entering the shared reality graph.

38. Open Geospatial Consortium. (2021). OGC SensorThings API — Part 1: Sensing, version 1.1 (OGC 18-088). VERIFIED via https://docs.ogc.org/is/18-088/18-088.html resolved on 2026-09-02 Supports: RESTful IoT sensor-data access proposed for glacier/hydrological monitoring networks.

39. IEEE. (2025). IEEE 2874-2025, Spatial Web Protocol, Architecture and Governance. VERIFIED via https://standards.ieee.org/ieee/2874/11717/ (final IEEE Standards Board approval 28–29 May 2025) resolved on 2026-09-02 Supports: the Hyperspace Modeling Language / Hyperspace Transaction Protocol proposed as a governance layer for spatially anchored shared reality.

40. Burleigh, S., Fall, K., & Birrane, E., III. (2022). Bundle protocol version 7 (RFC 9171). IETF. VERIFIED via https://www.rfc-editor.org/info/rfc9171/ (fetched directly; title and authors confirmed) resolved on 2026-09-02 Supports: delay-tolerant, store-and-forward networking proposed for intermittently connected high-mountain sensor and response links.

41. Open Geospatial Consortium. (2008). Uncertainty Markup Language (UncertML) (OGC Discussion Paper 08-122r2). VERIFIED via https://docs.ogc.org/dp/08-122r2/08-122r2.pdf (document number 08-122r2 confirmed; redirected from https://portal.ogc.org/files/?artifact_id=33234) resolved on 2026-09-02 Supports: the uncertainty vocabulary chosen (over alternatives) to attach confidence/error statistics to GLOF forecasts and susceptibility scores in the shared reality graph.

42. SCSC Assurance Case Working Group. (2021). Goal structuring notation community standard, version 3 (SCSC-141C). Safety-Critical Systems Club. VERIFIED via https://scsc.uk/gsn resolved on 2026-09-02 Supports: the argumentation notation used to structure the report's safety/assurance case for early-warning claims.


D. Cryosphere and the 2026 event (12)

43. Wester, P., Mishra, A., Mukherji, A., & Shrestha, A. B. (Eds.). (2019). The Hindu Kush Himalaya assessment: Mountains, climate change, sustainability and people. Springer. VERIFIED via https://lib.icimod.org/records/ce924-5h586 (editor order Wester, Mishra, Mukherji, Shrestha confirmed directly) resolved on 2026-09-02 Supports: the HKH-wide glacier-loss and "water tower" baseline for the region encompassing Langtang and Gyirong.

44. International Centre for Integrated Mountain Development (ICIMOD). (2023). Water, ice, society, and ecosystems in the Hindu Kush Himalaya (HI-WISE report). VERIFIED via https://hkh.icimod.org/hi-wise/hi-wise-report/ resolved on 2026-09-02 Supports: updated (up to 80% volume loss under high-emissions scenarios) cryosphere projections cited as context for accelerating GLOF risk.

45. Ragettli, S., Bolch, T., & Pellicciotti, F. (2016). Heterogeneous glacier thinning patterns over the last 40 years in Langtang Himal, Nepal. The Cryosphere, 10(5), 2075–2097. VERIFIED via https://tc.copernicus.org/articles/10/2075/2016/ resolved on 2026-09-02 Supports: direct glaciological evidence of accelerating thinning in the Langtang catchment where the August 2026 collapse originated.

46. International Centre for Integrated Mountain Development (ICIMOD) & United Nations Development Programme (UNDP). (2020). Inventory of glacial lakes and identification of potentially dangerous glacial lakes in the Koshi, Gandaki, and Karnali river basins of Nepal, the Tibet Autonomous Region of China, and India. VERIFIED via https://www.undp.org/nepal/press-releases/report-icimod-and-undp-identifies-potentially-dangerous-glacial-lakes-koshi-gandaki-and-karnali-river-basins and https://www.icimod.org/event/glacial-lake-inventory-launch/ (report released 7 September 2020) resolved on 2026-09-02 Note: the brief suggested this report as "Bajracharya, ICIMOD 2020." The individual author list could not be confirmed from sources reachable this session (only launch-event contacts Sudan Bikash Maharjan and Arun Bhakta Shrestha are named on ICIMOD's own event page), so the reference is given under organizational authorship rather than an unverified personal byline. A genuinely Bajracharya-coauthored ICIMOD glacial-lakes inventory does exist (Mool, P. K., Joshi, S. P., & Bajracharya, S. R., 2001, ICIMOD — confirmed via https://lib.icimod.org/records/adpwf-4xs49) but is a different, earlier report and is not substituted here. Supports: the pre-2026 transboundary glacial-lake inventory (47 lakes flagged: 25 in China, 21 in Nepal, 1 in India) establishing that risk was mapped, if not acted on, years before the event.

47. State Key Laboratory of Geohazard Prevention and Geoenvironment Protection, Chengdu University of Technology. (2025). Research statement on glacial lakes in the Gyirong ("Friendship Bridge") upstream basin, as reported in: 西藏吉隆口岸泥石流灾害造成伤亡,有研究文章称"该流域有较多冰湖" [Landslide disaster at Tibet's Gyirong port causes casualties; research article says "the basin has many glacial lakes"]. Phoenix News (ifeng.com). VERIFIED via https://news.ifeng.com/c/8vuZx5qme4i (secondary news report quoting and citing the SKLGP research statement) resolved on 2026-09-02. Note: the laboratory's own original statement/press page could not be independently located and opened this session; this is the verified secondary source, correctly attributed as such. Supports: the finding of 55 glacial lakes (≈3.39 km²) upstream of the Friendship Bridge and the call for enhanced early warning, published in the wake of the July 2025 Bhotekoshi event — over a year before the August 2026 catastrophe.

48. U.S. Geological Survey. (2026). 2026 Nepal debris avalanche and flash flood [Landslide Hazards Program event page]. VERIFIED via https://www.usgs.gov/programs/landslide-hazards/science/2026-nepal-debris-avalanche-and-flash-flood — title, URL, and page content confirmed via search-index retrieval on 2026-09-02; a direct WebFetch to usgs.gov failed with a TLS certificate handshake error specific to this session's fetch tool, not evidence against the page's existence. Supports: USGS's seismic-waveform determination that the 26 August 2026 event was a glacier collapse, not an earthquake, plus a second event roughly 3 hours later (Ms 4.2 equivalent).

49. Sharma, S., Ghoshal, D., & Chaganti Singh, S. (2026, August 30). Before flood catastrophe, Nepal asked China for early warnings as risks mounted. Reuters. VERIFIED via https://www.spokesman.com/stories/2026/aug/30/before-flood-catastrophe-nepal-asked-china-for-ear/ (Reuters wire text; byline, wire credit, and Kathmandu dateline confirmed by direct fetch) resolved on 2026-09-02 Supports: the 27 May 2026 Kathmandu meeting and the 12-days-prior WMC monsoon-depression email — the direct evidentiary basis for the report's "warning existed but wasn't sufficient" argument.

50. Poudel, A. (2025, July 11). Supraglacial lake outburst in Tibet caused Bhotekoshi flooding. The Kathmandu Post. VERIFIED via https://kathmandupost.com/province-no-3/2025/07/11/supraglacial-lake-outburst-in-tibet-caused-bhotekoshi-flooding (direct fetch) resolved on 2026-09-02 Supports: the July 2025 Bhotekoshi/Lhende precursor GLOF (9 dead, 19 missing, Miteri/Friendship Bridge destroyed). Cited here in place of the requested Reuters/AP coverage of this specific event, which could not be located; this Kathmandu Post report is the verified, correctly attributed source.

51. Bloomberg News. (2026, August 31). Nepal floods expose gaps in warning, China data sharing. Bloomberg. VERIFIED via https://www.thestar.com.my/aseanplus/aseanplus-news/2026/08/31/nepal-floods-disaster-exposes-gaps-in-warning-china-data-sharing (Bloomberg-sourced syndication, direct fetch) resolved on 2026-09-02 Supports: on-record quotes from Dharam Raj Uprety, chief executive of Nepal's National Disaster Risk Reduction and Management Authority ("people even didn't get five minutes of lead time"; "we don't have weather stations in high mountain areas").

52. Tamang, S. (2026, August 29). Hundreds feared trapped in hydropower tunnels after Bhotekoshi flood. The Kathmandu Post. VERIFIED via https://kathmandupost.com/national/2026/08/29/hundreds-feared-trapped-in-hydropower-tunnels-after-bhotekoshi-flood (direct fetch) resolved on 2026-09-02 Supports: the scale of hydropower-worker exposure (934 people linked to 11 projects reported missing at the time) and the access/rescue obstacles.

53. World Meteorological Organization & United Nations Office for Disaster Risk Reduction. (2022). Early Warnings for All: Executive Action Plan 2023–2027. VERIFIED via https://wmo.int/media/magazine-article/overview-of-early-warnings-all-executive-action-plan-2023-2027 resolved on 2026-09-02 Supports: the global early-warning-coverage gap (as of 2022, roughly half of countries lacked multi-hazard early warning systems), framing the Nepal case as a known, named gap rather than an outlier.

54. Shugar, D. H., et al. (2021). A massive rock and ice avalanche caused the 2021 disaster at Chamoli, Indian Himalaya. Science, 373(6552), 300–306. VERIFIED via https://www.science.org/doi/10.1126/science.abh4455 (title, journal, volume/issue/pages, and lead author confirmed via the Science DOI record, PubMed ID 34112725, and corroborating ScienceDirect/Semantic Scholar citation records) resolved on 2026-09-02. The full multi-institutional co-author list was not independently re-confirmed from a directly rendered source this session, so only the verified lead author is given, with "et al." standing in for an unconfirmed rather than a guessed byline. Supports: the closest instrumented analogue to the 2026 event. Correction from brief: the task cited this as a Nature Geoscience paper; it was in fact published in Science — cited here under its correct, verified venue rather than the misattributed one.


E. Digital twins, splats, edge (8)

55. Kerbl, B., Kopanas, G., Leimkühler, T., & Drettakis, G. (2023). 3D Gaussian splatting for real-time radiance field rendering. ACM Transactions on Graphics, 42(4), Article 139. VERIFIED via https://repo-sam.inria.fr/fungraph/3d-gaussian-splatting/ resolved on 2026-09-02 Supports: the real-time radiance-field rendering method proposed for reconstructing the facility and Langtang scenes from imagery.

56. Mildenhall, B., Srinivasan, P. P., Tancik, M., Barron, J. T., Ramamoorthi, R., & Ng, R. (2020). NeRF: Representing scenes as neural radiance fields for view synthesis. In Computer Vision – ECCV 2020 (pp. 405–421). Springer. VERIFIED via https://link.springer.com/chapter/10.1007/978-3-030-58452-8_24 resolved on 2026-09-02 Supports: the predecessor neural scene-representation technique contextualizing 3D Gaussian splatting's speed advantage.

57. Grieves, M., & Vickers, J. (2017). Digital twin: Mitigating unpredictable, undesirable emergent behavior in complex systems. In F.-J. Kahlen, S. Flumerfelt, & A. Alves (Eds.), Transdisciplinary perspectives on complex systems (pp. 85–113). Springer. VERIFIED via https://link.springer.com/chapter/10.1007/978-3-319-38756-7_4 resolved on 2026-09-02 Supports: the originating articulation of the digital-twin concept, cited as the term's canonical source.

58. Jones, D., Snider, C., Nassehi, A., Yon, J., & Hicks, B. (2020). Characterising the digital twin: A systematic literature review. CIRP Journal of Manufacturing Science and Technology, 29(A), 36–52. VERIFIED via https://doi.org/10.1016/j.cirpj.2020.02.002 resolved on 2026-09-02 Supports: a systematic-review definition of "digital twin" used to distinguish SMILE's shared-reality layer from narrower manufacturing-twin usage.

59. Digital Twin Consortium. (2025, January 30). Digital Twin Consortium launches Digital Twin Testbed Initiative [Press release]. VERIFIED via https://www.digitaltwinconsortium.org/press-room/01-30-25/ resolved on 2026-09-02 Supports: the DTC's maturity-model/testbed framework referenced for the Digital Twin Testbed Initiative noted in the report's timeline.

60. Fall, K. (2003). A delay-tolerant network architecture for challenged internets. In Proceedings of ACM SIGCOMM 2003 (pp. 27–34). ACM. VERIFIED via https://conferences.sigcomm.org/sigcomm/2003/papers/p27-fall.pdf resolved on 2026-09-02 Supports: the foundational DTN store-and-forward architecture underlying the RFC 9171 Bundle Protocol proposal for intermittent high-mountain connectivity.

61. Stray, B., Lamb, A., Kaushik, A., Vovrosh, J., Rodgers, A., Winch, J., Hayati, F., et al. (2022). Quantum sensing for gravity cartography. Nature, 602(7898), 590–594. VERIFIED via https://www.nature.com/articles/s41586-021-04315-3 resolved on 2026-09-02 Supports: field-demonstrated quantum gravimetry detecting a buried tunnel — a candidate future sensing modality for subsurface voids/instability relevant to underground-lab and glacier work.

62. European Parliament and Council. (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), Annex III. VERIFIED via https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng (full regulation, Official Journal text) and https://artificialintelligenceact.eu/annex/3/ (Annex III enumeration) resolved on 2026-09-02 Supports: Annex III's high-risk classification (critical infrastructure, safety components), applicable to any AI-based early-warning or hazard-classification component of the shared reality system.


F. Swiss research-infrastructure framework (4)

64. Switzerland. Bundesgesetz über die Förderung der Forschung und der Innovation (FIFG), SR 420.1; and Verordnung über die Förderung der Forschung und Innovation (V-FIFG), SR 420.11. VERIFIED via https://www.sbfi.admin.ch/de/forschungseinrichtungen-von-nationaler-bedeutung (fetched directly; quotes "Mit Artikel 15 des Bundesgesetzes über die Förderung der Forschung und der Innovation (FIFG) sollen Einrichtungen von nationaler Bedeutung im Bereich der Forschung und Innovation unterstützt werden") resolved on 2026-09-02. SR numbers 420.1 (FIFG) and 420.11 (V-FIFG) confirmed via the same SBFI page; the corresponding admin.ch/Fedlex redirect URLs (http://www.admin.ch/opc/de/classified-compilation/20091419/index.html for FIFG and .../20122266/index.html for V-FIFG) resolve live (HTTP 301 through fedlex.admin.ch) but Fedlex's own rendered page could not be captured directly this session, as fedlex.admin.ch is a JavaScript single-page application not renderable by this session's fetch tool. Supports: the specific legal basis (Art. 15 FIFG) under which the facility was designated a research infrastructure of national importance.

65. Swiss State Secretariat for Education, Research and Innovation (SBFI/SERI). (n.d.). Forschungseinrichtungen von nationaler Bedeutung [Research infrastructures of national importance]. VERIFIED via https://www.sbfi.admin.ch/de/forschungseinrichtungen-von-nationaler-bedeutung (fetched directly; confirms the facility is listed among the research infrastructures funded under FIFG Art. 15 for the 2025–2028 period) resolved on 2026-09-02 Supports: SBFI's own authoritative list naming the facility alongside other nationally recognized Swiss research infrastructures (e.g., Swiss Institute of Bioinformatics, Swiss Polar Institute).

66. Innosuisse (Schweizerische Agentur für Innovationsförderung). (2026, July 9). Projektausschreibung Eurostars [Eurostars project call], referencing Förderkonditionen von Innosuisse für Schweizer Teilnehmende an Eurostars 2026 (PDF, published 10 July 2026). VERIFIED via https://www.innosuisse.admin.ch/de/projektausschreibung-eurostars (fetched directly; exact title and 9 July 2026 publication date confirmed, plus the referenced 10 July 2026 funding-conditions PDF) resolved on 2026-09-02. Note: the program moved from innosuisse.ch to innosuisse.admin.ch. Supports: Switzerland's national co-funding terms for the Eurostars program (SME 50%, large enterprise 25%, research institution 50%), cited as the funding-mechanism analogue potentially applicable to the facility-linked international projects.

67. Swiss Federal Audit Office (Eidgenössische Finanzkontrolle, EFK). (2025, February 3). Research institutions of national importance (Report No. efk-24428 / sfao-24428). VERIFIED via https://www.efk.admin.ch/en/audit/research-institutions-of-national-importance/ (fetched directly; title, reference number, and 3 February 2025 date confirmed) resolved on 2026-09-02 Note: the brief suggested an "October 2024" EFK report — this genuinely exists and is the closest confirmed EFK audit on this exact topic, but is dated 3 February 2025, not October 2024; no EFK publication specifically dated October 2024 on research infrastructures could be located, so the date is corrected rather than asserted as requested. Supports: the finding that CHF 457 million was distributed to 34 Swiss research institutions of national importance in 2021–2024, with SERI directed to tighten cost-efficiency oversight — context for the governance chapter, though the report does not name the facility/the facility specifically.


G. SMILE itself (3)

68. Waern, N. (2026). SMILE — Sustainable Methodology for Impact Lifecycle Enablement (v6.4.3): Operational grammar for auditable, shared and forkable reality (Version 6.4.3) [Working paper]. Zenodo. https://doi.org/10.5281/zenodo.21757691 <!-- smile:version-citation --> VERIFIED via direct resolution of https://doi.org/10.5281/zenodo.21757691 <!-- smile:version-citation --> → https://zenodo.org/doi/10.5281/zenodo.21757691 <!-- smile:version-citation --> on 2026-09-02. Title, version (6.4.3), author (Nicolas Waern, WINNIIO AB), and publication date (2 August 2026) confirmed on the record.

69. Waern, N. (2026). SMILE — Sustainable Methodology for Impact Lifecycle Enablement (v6.4.5): Operational grammar for auditable, shared and forkable reality (Version 6.4.5) [Working paper]. Zenodo. https://doi.org/10.5281/zenodo.22244558 <!-- smile:version-citation --> VERIFIED via direct fetch of https://zenodo.org/records/22244558 <!-- smile:version-citation --> on 2026-09-02. Title, version (6.4.5), author (Nicolas Waern, WINNIIO AB), and publication date (2 September 2026) confirmed on the record.

70. Waern, N. (2025–2026). SMILE — Sustainable Methodology for Impact Lifecycle Enablement (concept DOI, all versions). Zenodo. https://doi.org/10.5281/zenodo.20175405 VERIFIED via direct resolution of https://doi.org/10.5281/zenodo.20175405 → https://zenodo.org/doi/10.5281/zenodo.20175405 on 2026-09-02. The concept DOI resolves to the latest version record (v6.4.5, DOI 10.5281/zenodo.22244558 <!-- smile:version-citation -->) and lists the version chain (including DOIs 10.5281/zenodo.17462962, 17464804, 19586851, 19586835, 19587944), confirming it is the correct "all-versions" umbrella DOI for the SMILE record family.


Count per group

GroupRequested minimumVerified count
A. Theory1213
B. Concurrent engineering & latency44
C. Standards1425
D. Cryosphere & 2026 event1012
E. Digital twins, splats, edge88
F. Swiss research-infrastructure framework54 (facility press release withheld in the public edition)
G. SMILE itself2 (+ concept DOI)3
Total5570

Could not verify (excluded from the list and count above)

  • Swiss Science Council (Schweizerischer Wissenschaftsrat, SWR/CSSI) 2024 assessment of research infrastructures — the council's site (wissenschaftsrat.ch) exists and was reached, but its publications listing is JavaScript-rendered and not retrievable by this session's tools; the most recent visible publication was from June 2026 (on AI in higher education). No 2024 publication on research infrastructures could be located or confirmed. Not included.
  • Reuters/AP wire coverage of the July 2025 Bhotekoshi GLOF specifically — not located despite search; a correctly attributed Kathmandu Post report (item 50) is used in its place rather than substituting an unverified wire citation.
  • A separately dated "October 2024" EFK report on research infrastructures — a genuine, closely related EFK report exists (item 67) but is dated 3 February 2025, not October 2024; no EFK publication matching the October 2024 date could be found, so no citation bearing that specific date is included.

Every numbered reference above (1–70) was independently opened or resolved — by DOI resolution, direct page fetch, or (for a minority of well-known standards pages, mostly in Group C) a search result that itself displayed the primary domain's page title, recommendation date, and canonical URL. Two load-bearing corrections were caught in the process and are flagged in-line rather than silently fixed: the Shugar et al. (2021) Chamoli paper is in Science, not Nature Geoscience as briefed (item 54), and the SMILE v6.4.5 <!-- smile:version-citation --> Zenodo ID in the brief was a one-digit transposition of the real record (item 69).


F. Swiss research-infrastructure framework — second pass

Note on provenance: this file was found already updated through item 70 (including a Group F, items 63–67) when this second pass began — a separate second-pass agent had evidently already run concurrently. Nothing above this heading was altered, per instruction. The items below are additional or corrective, numbered onward from the file's current maximum (70 → 71). Where a finding strengthens, corrects, or fills a gap in an existing numbered item, that is stated explicitly rather than silently re-asserted. All fetches below performed 2026-09-02.

71. Swiss Confederation. (2012). Bundesgesetz über die Förderung der Forschung und der Innovation (Forschungs- und Innovationsförderungsgesetz, FIFG) vom 14. Dezember 2012 (SR 420.1), Art. 15. VERIFIED via https://www.fedlex.admin.ch/eli/cc/2013/786/de resolved on 2026-09-02 — obtained by rendering the page in a headless browser session and reading the live DOM node `<article id="art_15">`, not by plain HTTP fetch (Fedlex serves only a JavaScript-shell placeholder to a plain fetch, which is why item 64's note above says the rendered page "could not be captured directly"; a full browser session succeeds where a fetch tool does not). Quote (German, verbatim): "Art. 15 Beiträge an Forschungseinrichtungen von nationaler Bedeutung — 1 Der Bundesrat kann im Rahmen der bewilligten Kredite Beiträge an Forschungseinrichtungen von nationaler Bedeutung entrichten. Er kann dabei den Bundesbeitrag an Auflagen knüpfen, namentlich an die Auflage, dass die Forschungseinrichtungen reorganisiert oder zusammengefasst werden. […] 3 Forschungseinrichtungen nach Absatz 1 können rechtlich selbstständige Einrichtungen folgender Kategorien sein: a. nichtkommerzielle Forschungsinfrastrukturen, die ausserhalb von Hochschulen angesiedelt oder mit ihnen assoziiert sind […]; b. nichtkommerzielle Forschungsinstitutionen […]; c. Technologiekompetenzzentren […]. 4 Um Beiträge zu erhalten, müssen die Forschungseinrichtungen die folgenden Voraussetzungen erfüllen: a. Sie erfüllen Aufgaben von nationaler Bedeutung, die zweckmässigerweise nicht von bestehenden Hochschulen und anderen Institutionen des Hochschulbereichs wahrgenommen werden können. b. Sie werden massgeblich durch Kantone, andere öffentliche Gemeinwesen, Hochschulen oder Private unterstützt." Correction: the article's actual heading is "Beiträge an Forschungseinrichtungen von nationaler Bedeutung" — "Forschungsinfrastrukturen" (as guessed in the task brief) is only one of three sub-categories listed in para. 3(a–c) under the umbrella term "Forschungseinrichtungen." Supports/strengthens item 64: gives the primary statutory text directly, rather than via the SBFI secondary page.

72. Swiss Confederation, Eidgenössisches Departement für Wirtschaft, Bildung und Forschung (WBF). (2013). Verordnung des WBF vom 9. Dezember 2013 zur Forschungs- und Innovationsförderungsverordnung (V-FIFG-WBF) (SR 420.111), Art. 12. VERIFIED via https://www.fedlex.admin.ch/eli/cc/2013/815/de resolved on 2026-09-02 (rendered DOM, `<article id="art_12">`, under "2. Kapitel: Beiträge an Forschungseinrichtungen von nationaler Bedeutung"). This ordinance and article are not cited elsewhere in this file. Quote (German, verbatim): "Art. 12 Prüfverfahren und Entscheid — 1 Gesuche um Beiträge sind dem SBFI jeweils per 30. Juni des dritten Jahres einer laufenden BFI-Periode im Hinblick auf eine Unterstützung in der darauffolgenden BFI-Periode einzureichen. 2 Das SBFI konsultiert bei der Prüfung aller Gesuche den SWR. […] 3 Das SBFI stellt dem WBF einen Antrag. 4 Es eröffnet den Gesuchstellerinnen und Gesuchstellern die Entscheide des WBF." Finding: the "30 June of the third year of the ERI/BFI period" rule is a binding ordinance provision, not merely SBFI guidance — codified in Art. 12 para. 1 of the WBF-level ordinance SR 420.111, reached via a delegation clause in SR 420.11 (V-FIFG) Art. 20 para. 3 ("Das WBF regelt das Prüfverfahren in einer Verordnung"). Supports: the exact statutory deadline and decision chain (SBFI → SWR consultation → WBF decision) for the four-yearly Art. 15 FIFG application cycle that the facility is subject to.

73. Schweizerische Eidgenossenschaft, Der Bundesrat. (2024, December 19). 35 Forschungseinrichtungen von nationaler Bedeutung erhalten insgesamt über 430 Millionen Franken [Press release]. Bern: Staatssekretariat für Bildung, Forschung und Innovation (SBFI). VERIFIED via https://www.admin.ch/de/nsb?id=103658 resolved on 2026-09-02. This is the actual 19 December 2024 decision the task brief asked for by name ("SBFI decision/press item from December 2024, Federal Councillor Parmelin"); it is not present elsewhere in this file. Quote (German, verbatim): "Bern, 19.12.2024 - Der Vorsteher des Eidgenössischen Departements für Wirtschaft, Bildung und Forschung (WBF), Bundesrat Guy Parmelin, hat am 19. Dezember 2024 die Förderbeiträge an Forschungseinrichtungen von nationaler Bedeutung für die Jahre 2025–2028 festgelegt. Der Bund unterstützt 35 Forschungseinrichtungen in diesem Zeitraum mit einem Gesamtbetrag von rund 432 Millionen Franken. […] Für den Zeitraum 2025-2028 haben insgesamt 40 Forschungseinrichtungen ein Finanzierungsgesuch beim Staatssekretariat für Bildung, Forschung und Innovation (SBFI) eingereicht. […] Davon wurden 30 bereits in der Förderperiode 2021-2024 unterstützt. […] 16 Forschungsinfrastrukturen, deren Gesamtbetrag sich auf rund 149 Millionen Franken beläuft." Supports: the named decision-maker (Bundesrat Guy Parmelin, WBF), the exact date (19 December 2024), and the precise figures (35 of 40 applicants funded, ~432 million francs) for the 2025–2028 Art. 15 FIFG round that includes the facility.

74. Staatssekretariat für Bildung, Forschung und Innovation (SBFI). (2023, June 21). Schweizer Roadmap für Forschungsinfrastrukturen im Hinblick auf die BFI-Botschaft 2025–2028. Teil I: Nationale Forschungsinfrastrukturen. VERIFIED via https://www.sbfi.admin.ch/dam/de/sd-web/erBdeORsG1Z5/Roadmap_Forschungsinfrastrukturen_2023_Teil_1_DE.pdf resolved on 2026-09-02 (94-page PDF, downloaded and full-text extracted). Quote (English in original; footnotes 34–35, p. 33, re: institution "SBDe"): "34 Application for support through Art. 15 RIPA (Federal Act on the Promotion of Research and Innovation) due in June 2023 with decision end of 2024. / 35 Application for support through Art. 15 RIPA (Federal Act on the Promotion of Research and Innovation) due in June 2027 with decision end of 2028." Supports: independent, document-level corroboration (from a different SBFI publication, different institution) of the "30 June of the third year" application cycle in item 72.

75. Eidgenössische Finanzkontrolle (EFK) / Contrôle fédéral des finances (CDF). Subventionsprüfung bei Forschungseinrichtungen von nationaler Bedeutung — Staatssekretariat für Bildung, Forschung und Innovation (Report No. EFK-24428 / CDF-24428). VERIFIED via https://www.efk.admin.ch/prufung/forschungseinrichtungen-von-nationaler-bedeutung/ resolved on 2026-09-02, with the underlying summary PDF at https://www.efk.admin.ch/wp-content/uploads/publikationen/berichte/bildung_und_soziales/bildung_und_forschung/24428/24428_wik_d.pdf (downloaded and text-extracted with pdfplumber; original report language is French, this is the official German summary, headed "ORIGINALTEXT AUF FRANZÖSISCH"). Correction/resolution of item 67 and of the existing "Could not verify" note (line 332 above, left unaltered): the EFK website lists the report's publication date as 03.02.2025, which is genuine and is what item 67 cites. However, the PDF's own footer independently carries an internal finalization date: "CDF-24428 | Version prises de position incluses | 15.10.2024" — i.e., the audit (including the audited entity's formal responses, "prises de position") was finalized 15 October 2024 and released publicly almost four months later. The brief's "October 2024" was therefore correct all along, referring to finalization rather than publication; both dates are genuine, verified, and refer to different milestones of the same report — this is not a discrepancy to resolve in favour of one date over the other. Quote (German, verbatim, on self-financing capacity and deadweight effects — not previously quoted in item 67): "Bei der Prüfung der Beitragsgesuche analysiert das SBFI nicht systematisch, ob bestimmte vom Subventionsgesetz vorgesehene Voraussetzungen erfüllt sind. Es geht darum, bei jeder Einrichtung sicherzustellen, dass die Voraussetzungen für eine wirtschaftliche und korrekte Verwendung der Subvention erfüllt sind, bei der Berechnung des Bundesbeitrags die Selbstfinanzierungskraft zu berücksichtigen sowie einen Mitnahmeeffekt zu verhindern, falls der Gesuchsteller ein besonderes Interesse an der Ausübung der Tätigkeit hat und über die wirtschaftliche Leistungsfähigkeit dazu verfügt." Supports: the EFK's own audit finding — SBFI's Art. 15 review does not systematically weigh applicants' self-financing capacity or guard against deadweight/windfall effects — as an independent oversight-body critique of the funding instrument covering the facility; and resolves the report-date question left open by item 67 / the existing "Could not verify" note.

76. Innosuisse — Schweizerische Agentur für Innovationsförderung. (2026, July 9). Funding Conditions for Swiss Eurostars beneficiaries — Call July 2026 [PDF factsheet]. VERIFIED via https://www.innosuisse.admin.ch/dam/en/sd-web/GNO9FRZ18O7f/Innosuisse%20funding%20conditions%20for%20Swiss%20Eurostars%20beneficiaries%20Call%20July%202026.pdf resolved on 2026-09-02 (downloaded and text-extracted with pdfplumber). This is the actual funding-conditions PDF that item 66 refers to but does not quote directly. Title correction to item 66/the brief: the document's actual title is "Funding Conditions for Swiss Eurostars beneficiaries" (not "participants"), and it is versioned per call — this is the "Call July 2026" edition (cut-off 11, deadline 10 September 2026), not a single undated "2026" document. Quote (English, verbatim, §3.2 and §5.6): "Innosuisse represents Switzerland in EUREKA's Eurostars programme and funds eligible costs of Swiss project partners with the following funding rates: SME, small organisations, Universities, R&D institutions: max. 50 % of eligible costs / Large Companies, large organisations: max. 25 % of eligible costs." … "Overhead costs are applied to all eligible cost categories except subcontracting. They are calculated at the Innosuisse rate of 15% except for research institutions (Technology Competence Centers) that have a separate agreement with Innosuisse." Supports/strengthens item 66: gives the exact, directly quoted co-funding rates (50 % SME/RTO, 25 % large enterprise) and the 15 % overhead flat rate, rather than citing the referring page alone.

Not found (second pass, independent corroboration)

  • Swiss Science Council (SWR/SSC) 2024 assessment of research infrastructures under Art. 15 FIFG for 2025–2028, specifically naming the facility or containing a sentence to the effect that "die Digitalisierung und eine physische Forschungsinfrastruktur einander ergänzen" — independently NOT FOUND, corroborating the existing "Could not verify" entry above. The 19 December 2024 Bundesrat press release (item 73) itself links to "Beurteilung des Schweizerischen Wissenschaftsrates" at https://wissenschaftsrat.ch/veroeffentlichungen?page=0, which resolves only to a generic, undated publications index, not a specific document. The SWR's own site search (wissenschaftsrat.ch/suche) for "Forschungseinrichtungen von nationaler Bedeutung," "Beurteilung der Beitragsgesuche Art. 15," and the facility name returned no matching 2024 document — the only Art. 15-related SWR publication indexed there is a 2016 report for the 2017–2020 funding period, a different round. Web search (including for the exact German quote, with and without a site restriction to wissenschaftsrat.ch/swir.ch) also returned nothing matching. Treated as genuinely unpublished or unindexed, not inferred or substituted.

Second-pass count

6 new items added (71–76), all independently verified against primary text (Fedlex rendered DOM, admin.ch press release, SBFI PDF, EFK PDF, Innosuisse PDF); 1 requested source (the SWR 2024 assessment) independently confirmed not found. One date question left open in the file above (item 67 vs. the brief's "October 2024") is resolved in item 75: both 15.10.2024 (finalization) and 03.02.2025 (publication) are genuine, verified dates for the same EFK/CDF-24428 report.

Where this goes next

Want this applied to your organisation?

One call is enough to know if we're a fit.

Book a call
Digital twin specialists

Nobody brings the full stack of digital twin competence — organizational, global, change management, technology strategy, and a NASA JPL-derived method — the way we do. We bring the best people together for a company faster than anyone else, and we implement it with them.

The decisions are being made either way. The only variable is whether you find out afterwards.

Scoping workshop from €4,500, credited in full against the project. See how scoping works