Skip to content

Arc Skills / Safety

Build a fault tree for a hazardous event

This task works backward from a hazardous top event to the conditions sufficient to cause it. Arc Skills produces a qualitative fault tree with transparent gates and cut sets before any probability is attempted.

Use this skill

Use Arc Skills to build a fault tree for the stated top event, phase, configuration and exposure interval. Define each leaf so common and intrinsic failures are not counted twice.

Inputs:
- Exact top event and system boundary.
- Command architecture, fault definitions and phase.
- Any approved failure data and dependence assumptions.

Return an indented Boolean tree, minimal cut sets, source for each leaf and completeness questions. Quantify only if the event models and data justify it.

Set up the toolkit · Read the skill instructions

What you provide and what you get

Inputs and outputs
What you haveHow it is usedWhat you get
Top event and phaseFixes what the tree must explainEvent definition
Architecture and fault definitionsSupports OR/AND decompositionGates and leaves
Dependency/data recordPrevents double counting and unsupported arithmeticCut sets and limits

One bus event and one simultaneous intrinsic pair

Illustrative engineering example.

In a synthetic brake-command design, channels A and B both need bus P. Either channel alone can issue the command when P is available. Define A and B “intrinsic failure” to exclude failures caused by P; assume no other command path in this deliberately narrow model.

Top event T: no brake command at landing.
Synthetic architecture ARCH-B rev A: channels A and B both require bus P; either healthy channel can command when P works.
Fault definitions FAULT-B rev A: intrinsic channel failures exclude loss caused by P. Voter/output-driver details absent.
Qualitative cut sets for the stated model
Minimal cut setWhy it causes TModel boundary
{P_loss}Both channels lack their required busShared event appears once
{A_intrinsic_fail, B_intrinsic_fail}Neither channel can command while P is availableJoint event; independence not yet established
Not modeled: voter/output interfaceCould block both channel commandsRequires architecture inspection before completeness claim

The Boolean expression has exactly two minimal cut sets within its stated boundary. P loss is already separated from intrinsic A/B failures, so the shared bus is not duplicated inside both channel leaves. The AND gate is justified because one healthy channel suffices when P works.

The third row is a completeness gap, not a third derived cut set: the design description does not say whether a voter or common output driver exists. No probability follows from the tree without event probabilities for the landing exposure and a dependency model for A and B.

Derived qualitative tree

T: No brake command at landing
OR
├─ P_loss: both channels lose required bus P
│  Source: ARCH-B rev A, shared power dependency
└─ Both intrinsic command channels fail
   AND
   ├─ A_intrinsic_fail
   │  Source: ARCH-B rev A + FAULT-B rev A
   └─ B_intrinsic_fail
      Source: ARCH-B rev A + FAULT-B rev A

T = P_loss OR (A_intrinsic_fail AND B_intrinsic_fail)
Open: common voter or output-driver behavior is not supplied.

Keep gate logic tied to the event statement

  1. Define the top event, phase, configuration and exposure interval before decomposition.
  2. Use OR only for individually sufficient causes and AND only when joint occurrence is needed.
  3. Name leaves with mutually clear scopes, then reduce the Boolean expression to cut sets.
  4. Check omitted common paths and dependencies before considering quantification.

Questions about this task

Can a cut set contain one event?

Yes. A single shared bus loss is a one-event cut set when it alone causes the defined top event.

Does an AND gate imply independence?

No. It describes logical necessity, while independence is a separate probabilistic assumption requiring evidence.

Sources and further reading