Arc Skills / Safety
Perform a preliminary hazard analysis
This task identifies credible hazardous conditions while architecture and operations are still developing. Arc Skills produces a preliminary register that separates observed design facts from control hypotheses and open decisions.
Use this skill
Use Arc Skills to perform a preliminary hazard analysis for the supplied concept, system boundary and lifecycle phases. Follow energy or material sources through initiating circumstances and exposed people or assets.
Inputs:
- Mission and servicing concept, early architecture and energy inventory.
- Operating phases, exposed parties and known incidents.
- Existing controls and project severity terminology.
Return hazard rows with condition, cause hypothesis, exposure, consequence, existing/proposed control and evidence needed. Leave likelihood and acceptance unassigned when the criteria or data are missing.What you provide and what you get
| What you have | How it is used | What you get |
|---|---|---|
| Concept and phase list | Defines exposure and incomplete design scope | Analysis boundary |
| Energy/material inventory | Supports causal scenarios | Hazard register |
| Control evidence and taxonomy | Separates implemented from proposed mitigation | Open control questions |
A proposed cutout does not close a servicing hazard
Illustrative engineering example.
A synthetic battery assembly uses an electric heater. During ground servicing, a stuck-on power switch could leave heating active near adjacent material. A thermal cutout appears on a concept drawing, but its independence, trip setting and test record are unavailable.
| Scenario and phase | Exposed consequence | Control status | Next investigation |
|---|---|---|---|
| H-1: heater stuck on, ground servicing | Adjacent material may overheat while a technician is nearby | Thermal cutout proposed only | Confirm cutout placement, independence and trip behavior |
| H-1: service-mode command inhibit | May prevent commanded heating but not a shorted switch | Controller behavior not verified | Separate command and physical fault paths |
| H-1: inspection before return to service | Could reveal damage after an event | Procedure not provided | Decide whether recovery inspection is credited |
The first row defines a hazardous condition and exposure path. The stuck-on switch is an initiating hypothesis; no failure rate or probability is claimed. The proposed cutout might interrupt the path, but a shared sensor or supply could make it ineffective.
The three rows describe one hazard’s prevention, limitation and recovery questions, not three independent hazard counts. As the design matures, an FMEA can test item failure propagation and a fault tree can test combinations. The register remains open until the project defines controls, verifies them and assigns formal risk decisions.
Work from exposure to control evidence
- Set system boundary, lifecycle phases and people or assets exposed.
- Describe the hazardous condition, initiating circumstance and causal path.
- Separate existing controls, proposed controls and recovery actions.
- Record what analysis or test would establish each control’s effectiveness.
Questions about this task
Is a candidate hazard a measured risk?
No. Early scenarios identify credible paths for investigation; likelihood and acceptability need project definitions and evidence.
Should maintenance be included?
Yes when the lifecycle includes servicing, because energy exposure and control availability can differ from normal operation.
Sources and further reading
- NASA Systems Engineering Handbook: Lifecycle, requirements, verification and technical-management guidance.
- NASA Fault Tree Handbook with Aerospace Applications: NASA-hosted guidance for fault-tree gates, cut sets and reliability block diagrams.