Arc Skills / Safety
Build a fault tree for a hazardous event
This task works backward from a hazardous top event to the conditions sufficient to cause it. Arc Skills produces a qualitative fault tree with transparent gates and cut sets before any probability is attempted.
Use this skill
Use Arc Skills to build a fault tree for the stated top event, phase, configuration and exposure interval. Define each leaf so common and intrinsic failures are not counted twice.
Inputs:
- Exact top event and system boundary.
- Command architecture, fault definitions and phase.
- Any approved failure data and dependence assumptions.
Return an indented Boolean tree, minimal cut sets, source for each leaf and completeness questions. Quantify only if the event models and data justify it.What you provide and what you get
| What you have | How it is used | What you get |
|---|---|---|
| Top event and phase | Fixes what the tree must explain | Event definition |
| Architecture and fault definitions | Supports OR/AND decomposition | Gates and leaves |
| Dependency/data record | Prevents double counting and unsupported arithmetic | Cut sets and limits |
One bus event and one simultaneous intrinsic pair
Illustrative engineering example.
In a synthetic brake-command design, channels A and B both need bus P. Either channel alone can issue the command when P is available. Define A and B “intrinsic failure” to exclude failures caused by P; assume no other command path in this deliberately narrow model.
Top event T: no brake command at landing.
Synthetic architecture ARCH-B rev A: channels A and B both require bus P; either healthy channel can command when P works.
Fault definitions FAULT-B rev A: intrinsic channel failures exclude loss caused by P. Voter/output-driver details absent.| Minimal cut set | Why it causes T | Model boundary |
|---|---|---|
| {P_loss} | Both channels lack their required bus | Shared event appears once |
| {A_intrinsic_fail, B_intrinsic_fail} | Neither channel can command while P is available | Joint event; independence not yet established |
| Not modeled: voter/output interface | Could block both channel commands | Requires architecture inspection before completeness claim |
The Boolean expression has exactly two minimal cut sets within its stated boundary. P loss is already separated from intrinsic A/B failures, so the shared bus is not duplicated inside both channel leaves. The AND gate is justified because one healthy channel suffices when P works.
The third row is a completeness gap, not a third derived cut set: the design description does not say whether a voter or common output driver exists. No probability follows from the tree without event probabilities for the landing exposure and a dependency model for A and B.
Derived qualitative tree
T: No brake command at landing
OR
├─ P_loss: both channels lose required bus P
│ Source: ARCH-B rev A, shared power dependency
└─ Both intrinsic command channels fail
AND
├─ A_intrinsic_fail
│ Source: ARCH-B rev A + FAULT-B rev A
└─ B_intrinsic_fail
Source: ARCH-B rev A + FAULT-B rev A
T = P_loss OR (A_intrinsic_fail AND B_intrinsic_fail)
Open: common voter or output-driver behavior is not supplied.Keep gate logic tied to the event statement
- Define the top event, phase, configuration and exposure interval before decomposition.
- Use OR only for individually sufficient causes and AND only when joint occurrence is needed.
- Name leaves with mutually clear scopes, then reduce the Boolean expression to cut sets.
- Check omitted common paths and dependencies before considering quantification.
Questions about this task
Can a cut set contain one event?
Yes. A single shared bus loss is a one-event cut set when it alone causes the defined top event.
Does an AND gate imply independence?
No. It describes logical necessity, while independence is a separate probabilistic assumption requiring evidence.
Sources and further reading
- NASA Fault Tree Handbook with Aerospace Applications: NASA-hosted guidance for fault-tree gates, cut sets and reliability block diagrams.