Physics / Cosmology / Simulation

Scenario Event Studio Specification for the IARPA Planetary Atlas

Report summary

The public Planetary Atlas already contains several foundations that this specification should preserve and extend: a browser-local simulation posture, explicit separation between factual research and fictional branches, a globe-first interface, a Simple versus “Advanced academic” input split, a non

Status
Research archive item
Category
Physics / Cosmology / Simulation
Length
8,092 words
Reading time
37 minutes
Report type
evaluation

Key topics

  • Physics / Cosmology / Simulation
  • Physics
  • Cosmology
  • Simulation
  • AI
  • Privacy
  • Semantic Systems
  • Research Archive
  • Strategy

Research provenance

Archive status
Research archive item
Content identity
sha256:750779796f7c3079498cd84afbcf09035a104e34f384f91f9fa7db78383adc5e

For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.

Source availability: 59 citation markers in the source export have no recoverable source links. Those markers are omitted from this reader; any supplied bibliography and ordinary links remain. Check the original sources before relying on the cited claims.

This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.

Full report

On this page

Executive summary

The public Planetary Atlas already contains several foundations that this specification should preserve and extend: a browser-local simulation posture, explicit separation between factual research and fictional branches, a globe-first interface, a Simple versus “Advanced academic” input split, a noncommitting “Preview on globe” action, synthetic-cell location abstraction instead of exact coordinates, authoritative deterministic simulation results, and an optional OpenAI consequence brief that is explicitly subordinate to the deterministic engine. The site also states clear boundaries against targeting, weapon-effects calculation, casualty modeling, emergency-routing, and operational detail. This specification builds directly on those observable patterns rather than replacing them.

The recommended product direction is a two-lane authoring experience. Guided mode should feel like a modern scenario builder for visitors, classrooms, and curious readers: short, plain-language, qualitative, and visually legible. Advanced Academic mode should expose a disciplined set of ordinal controls for expert users without crossing into physical-effects or operational planning. Both lanes should write into one common deterministic event schema, so the same event can be previewed, submitted, replayed, exported, and discussed consistently across audiences.

The studio should treat uncertainty as a first-class object, not a footnote. The most defensible pattern is to separate at least three concepts: evidence uncertainty, confidence in assumptions, and qualitative consequence pressure. That approach is consistent both with the Atlas’s existing emphasis on claim-level confidence and with established uncertainty-communication guidance that distinguishes evidence, agreement, and confidence.

The central design constraint is educational safety. Every event remains synthetic, high-level, and non-operational. No control may accept real yield, target, route, dose, blast radius, inundation depth, crater size, fire-spread prediction, evacuation routing, or casualty estimation. The preview must therefore communicate consequence pressure and system coupling rather than physical lethality or tactical effectiveness. This still allows rich learning outcomes for systems thinking, preparedness, resilience, institutional coordination, and long-run recovery.

Product context and personas

The observable Atlas experience is already explicitly fictional in Simulation Earth, read-only in Current Statistics, and transparent about the reviewed-history boundary, projection horizon, and fictional what-if branching. The event authoring surface is also already framed as an “abstract globe event” with normalized consequence intensity and qualitative controls. That means the next-generation studio should be an elaboration of an existing language of interaction, not a new conceptual model.

The recommended personas are as follows.

General visitor. This user wants to understand “what kind of systems would be stressed if something big happened?” Their success condition is finishing an event in under two minutes, understanding the preview, and learning without feeling overwhelmed or frightened. The current Atlas already has a session-only, no-profile, guided discovery posture, so Guided mode should preserve that low-friction trust contract.

Secondary-school or undergraduate educator. This user wants a safe classroom scenario that can be discussed without becoming a real-world targeting or emergency-operational exercise. Their success condition is being able to select a preset, show uncertainty notes, compare horizons, and open a dossier that reads like a teaching artifact. The Atlas’s publicly stated educational identity and visible fiction/research separation strongly support this use case.

Scholar or analyst. This user wants to vary preparedness, trust, system coupling, monitoring readiness, and recovery duration to discuss institutional or socio-technical consequences. Their success condition is reproducibility: the same inputs on the same ruleset must return the same consequence vectors and the same dossier contents. That requirement aligns with the Atlas’s current deterministic-local-first wording and its broader emphasis on preserved source records, hashes, and reviewable methods.

Scientist or subject-matter expert. This user does not need exact physics in this studio; they need a disciplined abstract surrogate for system stress and uncertainty. Their success condition is having domain-specific control sets that are recognizable and intellectually honest: defense in depth and containment for nuclear-facility crises, radio blackout pressure and satellite vulnerability for solar storms, water stress and adaptation for warming scenarios, and so on. Those lenses are consistent with official hazard-program framing from IAEA/CNSC, NOAA, NASA, WHO, USGS, WMO, IPCC, EPA, and UNDRR.

Emergency-management researcher and infrastructure professional. This user wants to discuss resilience, redundancy, lifelines, public trust, and compound failures in a non-operational setting. Their success condition is being able to observe likely affected systems and phase transitions without receiving route advice, tactical instructions, or targetable calculations. This is directly aligned with the Atlas’s stated safety boundary, which excludes operational detail while allowing high-level consequence and coordination analysis.

Information architecture and interaction model

Guided-mode information architecture

Guided mode should be a five-step progressive disclosure flow inside a modal event studio launched from the globe, a toolbar button, or the existing globe context entry point. Because the Atlas already uses overlay surfaces and explicit Close actions, the safest interaction pattern is a true modal dialog with inert background content, initial focus inside the dialog, Tab containment, and Escape to close, following WAI-ARIA modal guidance.

The five steps should be:

Context. Selected event name, synthetic location chip, selected cell alias, and a static reminder that exact coordinates are neither displayed nor sent to AI services. The user may optionally rename the scenario with a pedagogical title, but the location remains synthetic-cell based.

Type. Event category, event subtype, initiating fictional actor or natural cause. The wording should prefer plain-language labels first and technical glosses second. For example, “Solar flare or geomagnetic storm” rather than “space weather event”; “Civilian nuclear-facility emergency” rather than “radiological source term incident.” This follows the Atlas’s general emphasis on understandable guidance while maintaining analytic seriousness.

Scale and time. Abstract scale, consequence horizon, and educational preset. This step is where the user chooses how broad and how prolonged the scenario should be. The design should explicitly explain that scale controls synthetic footprint and systemic coupling, not physical blast or forecast range.

Assumptions. In Guided mode only five common assumptions should be shown by default: preparedness, response capacity, infrastructure resilience, institutional trust, and evidence uncertainty. Domain-specific controls appear as one compact card beneath these when the category demands them. This keeps the path approachable while still revealing the most meaningful consequence-shaping levers.

Preview and create. The right side or lower region shows the live noncommitting preview. Actions are Preview on Globe, Create event, and Cancel. Preview on Globe must never alter the branch state; Cancel must restore the prior visual state entirely. The Atlas already states that preview is temporary and illustrative; this specification should tighten that into an explicit state-reversion rule.

Advanced Academic mode information architecture

Advanced Academic mode should live on the same dialog shell and same schema, but open three additional panels: System assumptions, Domain assumptions, and Uncertainty and notes. These panels should use disclosure/accordion behavior rather than one giant form, because both WAI-ARIA and USWDS patterns support progressive disclosure for complex forms, especially where stress, cognitive load, and discoverability matter.

The Advanced panels should be arranged as follows.

System assumptions. Preparedness; response capacity; infrastructure resilience; institutional trust; monitoring readiness; defense in depth; redundancy; environmental persistence; recovery duration; system coupling; cascade complexity; onset speed. All use the normalized band scale described below.

Domain assumptions. Only the event-type-specific fields appear here. These are event templates, not hidden formulas; the user should always see what high-level variables are shaping the result.

Uncertainty and notes. Evidence uncertainty; confidence in assumptions; source-note mode; instructor note; analyst note. The private browser-local note already exists in the public surface and should remain local-only by default. If saved in the dossier, it should be explicitly labeled “local note” and excluded from any optional AI request unless the user affirmatively opts in.

Progressive-disclosure rules

Progressive disclosure should follow seven product rules.

First, Guided mode never hides the preview; it hides only uncommon controls. The user should always see the event name, synthetic location, selected assumptions summary, consequence bars, affected systems, planet-state sequence, and phase labels.

Second, switching from Guided mode to Advanced Academic mode must preserve all current selections and only reveal more controls; it must not reinterpret prior values silently. If Guided mode used a preset, Advanced mode should display the preset’s resolved assumptions and mark deviations once the user edits them.

Third, Advanced controls should remain collapsed until a category is chosen. A user selecting “Earthquake” should never see “Cooling resilience,” and a user selecting “Solar flare” should never see “Containment condition.”

Fourth, any domain field that is irrelevant because of subtype choice should be disabled with an explanatory inline note rather than removed abruptly. For example, Tsunami harbor resonance pressure should hide unless subtype is regional-source or distant-source tsunami.

Fifth, only one uncertainty explanation block should expand automatically: the one attached to any field set to Severe or Very low confidence. This keeps risk-significant assumptions visible.

Sixth, all previews should update live with a short debounce while remaining noncommitting. This matches the Atlas’s current “adjust the controls to preview” posture and creates a workshop-friendly interaction rhythm.

Seventh, the interface should retain “trauma-informed” calm: no red-flashing alarms, siren sounds, or sensational labels. USWDS guidance for complex forms emphasizes reducing cognitive load and progressing users respectfully, which is appropriate here given the hazard content.

Preset definitions

Use four presets in both modes. Each preset should set only assumption defaults, never lock the user out of editing.

PresetPurposeDefault assumption posture
Balanced assumptionsBaseline teaching modePreparedness Moderate; Response capacity Moderate; Infrastructure resilience Moderate; Institutional trust Moderate; Monitoring readiness Moderate; Redundancy Moderate; Recovery duration Moderate; System coupling Moderate; Evidence uncertainty Moderate; Confidence in assumptions Medium
High preparednessStress a resilient society or institutionPreparedness High; Response capacity High; Infrastructure resilience High; Monitoring readiness High; Redundancy High; Institutional trust Moderate to High; Recovery duration Low; Cascade complexity Low to Moderate
Strained systemsStress limited capacity and fragmentationPreparedness Low; Response capacity Low; Infrastructure resilience Low; Monitoring readiness Low; Institutional trust Low; Redundancy Low; Recovery duration High; Cascade complexity High
Cascading systemsEmphasize cross-sector knock-on effectsPreparedness Moderate; Response capacity Moderate; Infrastructure resilience Moderate; Monitoring readiness Moderate; System coupling High; Cascade complexity High; Environmental persistence High where relevant; Recovery duration High

These presets are consistent with the Atlas’s already observable focus on system strain, recovery choices, and coupled consequences, and with public hazard institutions’ emphasis on preparedness, monitoring, resilience, and recovery rather than purely event physics.

Event data schema and domain field catalog

Common schema and normalized values

All event categories should write into one shared event object.

Core identity fields. event_id, schema_version, ruleset_version, created_at, created_by_mode (guided or advanced_academic), event_category, event_subtype, display_name, synthetic_cell_id, synthetic_cell_alias, event_point, initiating_class, fictional_actor_label_optional, preset, abstract_scale, consequence_horizon.

Common assumption fields. preparedness, response_capacity, infrastructure_resilience, institutional_trust, monitoring_readiness, defense_in_depth, redundancy, environmental_persistence, recovery_duration, system_coupling, cascade_complexity, onset_speed, evidence_uncertainty, confidence_in_assumptions.

Preview/result fields. preview_vector, likely_affected_systems, visual_intensity, planet_state_sequence, phase_immediate, phase_medium_term, phase_long_term, affected_synthetic_cells, persistent_footprint, deterministic_consequence_metrics, connected_blurb, narrative_source, dossier_id, replay_visual_action, restore_preceding_visual_state_action.

Normalized value bands. All ordinal assumptions should use the same five-band vocabulary: Very low, Low, Moderate, High, Severe. The single exception is confidence_in_assumptions, which should use Very low, Low, Medium, High, Very high to match established confidence language. This is close to IPCC calibrated confidence terminology and also gives the UI a consistent surface across domains.

Abstract scale values. Isolated, Localized, Regional, Systemic, Global.

Consequence horizon values. Immediate, Thirty days, One year, Long run.

Initiating class values. Natural cause, Accidental technical failure, Compound systems failure, Fictional state actor, Fictional non-state actor, Unknown fictional actor, Cascading environmental driver.

Domain fields and allowed values

The existing Atlas already says that advanced mode reveals qualitative domain assumptions for nuclear emergencies, space weather, asteroid impacts, climate warming, fire, earthquakes, water disasters, volcanoes, storms, biological events, and general system dependencies. The field catalog below keeps that same qualitative strategy and removes any operationally dangerous physical inputs.

Nuclear detonation or abstract nuclear emergency

Subtype values. Abstract nuclear emergency, Detonation context, Escalatory radiological crisis. Abstract environment. Atmospheric, Surface, Underground, Underwater, High altitude. Domain fields. preparedness, response_capacity, service_resilience, environmental_persistence, monitoring_readiness, institutional_coordination. Guided defaults. Environment defaults to Surface; all assumptions default from preset. Validation. No real yield, delivery method, target class, blast radius, thermal radius, fallout contour, dose, casualty input, or real place name in the event title. Cross-field dependency. High altitude automatically raises the salience of communications, grid, and orbital-system preview bars and suppresses contamination-language emphasis; Underground raises infrastructure disruption salience and lowers visible environmental spread; Underwater raises maritime-service salience. This domain framing is consistent with the Atlas’s current prohibition on nuclear blast/fallout/casualty calculations and with public emergency-preparedness emphasis on coordination, monitoring, and response capability rather than offensive detail.

Civilian nuclear-facility emergency or meltdown

Subtype values. Cooling failure crisis, Containment challenge, Spent-fuel management crisis, Multi-system plant emergency. Domain fields. cooling_resilience, containment_condition, defense_in_depth_quality, common_cause_failure_pressure, monitoring_readiness, emergency_coordination, environmental_persistence, remediation_capacity, safety_culture_strength, public_trust_condition. Guided defaults. cooling_resilience, containment_condition, and emergency_coordination appear as the three visible domain controls; the others are behind Advanced Academic mode. Validation. No operating procedure, sabotage method, evacuation route, or radioactive-dose calculation. Cross-field dependency. If containment_condition is Severe, then environmental_persistence may not default below Moderate; if defense_in_depth_quality is High, common_cause_failure_pressure cannot silently nullify it and must remain visible as a separate assumption. This structure tracks recognized nuclear-safety layers: multiple independent levels of defense, monitoring, containment, common-cause failure, safety culture, and off-site emergency response.

Solar flare or geomagnetic storm

Subtype values. Solar flare, Geomagnetic storm, Compound space-weather event, Communications-led disruption. Domain fields. radio_blackout_pressure, satellite_vulnerability, grid_resilience, navigation_dependency, communications_redundancy, recovery_capacity, compound_space_weather_conditions. Guided defaults. radio_blackout_pressure, grid_resilience, communications_redundancy. Validation. No satellite-command instructions, no real orbital control procedure, no precise outage forecast. Cross-field dependency. If radio_blackout_pressure is High or Severe, the preview must always list communications systems among likely affected systems; if navigation_dependency is High, transport and logistics salience rises regardless of geographic scale. The category is grounded in NOAA’s public framing of radio blackouts, GPS/GNSS degradation, satellite effects, and power-grid impacts from solar events.

Asteroid or meteorite event

Subtype values. Airburst, Land impact, Ocean impact, Fragment field. Domain fields. abstract_scale, detection_lead_time, preparedness, infrastructure_resilience, environmental_persistence. Detection lead time values. Minimal, Short, Moderate, Long, Extended. Guided defaults. detection_lead_time, preparedness, infrastructure_resilience. Validation. No object mass, velocity, impact energy, crater diameter, blast radius, tsunami height, or casualty estimate. Cross-field dependency. Airburst lowers long-run environmental persistence by default unless the user raises it; Ocean impact amplifies maritime systems and coastal adaptation visuals; Fragment field broadens the synthetic footprint irregularly but with lower peak visual intensity. NASA’s planetary-defense strategy and monitoring systems emphasize detection, characterization, warning, and response preparedness, which is the right abstraction layer for this studio.

Global warming, drought, and heatwave

Subtype values. Heatwave, Drought, Compound warming and drought, Long-run warming pressure. Domain fields. time_horizon, water_stress, ecosystem_pressure, heat_adaptation, energy_system_resilience, agricultural_resilience, coastal_or_infrastructure_adaptation, migration_pressure, reduced_ice_or_dry_earth_visual_progression. Time horizon values. Immediate, Thirty days, One year, Long run, with Long run the default for this category. Guided defaults. water_stress, heat_adaptation, energy_system_resilience, agricultural_resilience. Validation. Must show an explicit notice that output is an educational scenario and not a climate forecast. Cross-field dependency. If subtype is Heatwave, heat_adaptation is required; if subtype is Drought, water_stress is required; if subtype is Long-run warming pressure, the preview must show a planet-state progression strip by default. This domain should mirror public climate-risk framing around water security, ecosystem impacts, health, food systems, infrastructure, adaptation capacity, and uncertainty across time horizons.

Wildfire

Subtype values. Surface fire, Crown-fire pressure, Peat or subsurface fire, Multi-front fire. Domain fields. fuel_dryness, response_capacity, air_quality_pressure, ecosystem_resilience, infrastructure_exposure. Guided defaults. fuel_dryness, response_capacity, air_quality_pressure. Validation. No ignition instructions, fire-spread prediction, evacuation route, or casualty calculation. Cross-field dependency. Peat or subsurface fire raises environmental_persistence visibility and defaults it no lower than Moderate; Multi-front fire increases cascade complexity salience and likely affected systems breadth. Official wildfire and smoke guidance supports focusing on fuels, smoke exposure, public-health burden, and response readiness rather than tactical fire operations.

Earthquake

Subtype values. Shallow crustal, Deep focus, Offshore, Aftershock sequence. Domain fields. built_environment_resilience, service_redundancy, preparedness, recovery_capacity. Guided defaults. built_environment_resilience, service_redundancy, preparedness. Validation. No fault-engineering instructions, building-target analysis, or casualty model. Cross-field dependency. Aftershock sequence requires onset_speed and recovery_duration to remain visible; Offshore increases tsunami-watch dependency only when the user explicitly pairs the event with the tsunami family in a compound scenario template. USGS public materials emphasize earthquake sequences, aftershocks, impacts to infrastructure, hazards assessment, and public preparedness tools, making these the correct qualitative controls.

Volcano, flood, tsunami, and severe storm

This cluster should be implemented as one category family with subtype-specific domain cards.

Volcano subtype values. Explosive eruption pressure, Lava-effusion pressure, Lahar pressure, Prolonged unrest. Volcano fields. monitoring_readiness, ash_persistence, ground_disruption_pressure, aviation_disruption_pressure, recovery_capacity. USGS emphasizes monitoring, unrest detection, notifications, hazards-zonation, and disruption minimization, which strongly supports these fields.

Flood subtype values. Riverine flood, Flash flood, Coastal flood, Compound flood. Flood fields. watershed_saturation, drainage_capacity, warning_reach, service_resilience, environmental_persistence, recovery_capacity. WMO and NOAA public water and flood materials emphasize monitoring, water-cycle variability, flood hazard preparedness, and strategic adaptation rather than precise local routing within this kind of interface.

Tsunami subtype values. Local-source, Regional-source, Distant-source, Harbor resonance pressure. Tsunami fields. warning_lead_time, communications_redundancy, near_shore_exposure, service_resilience, recovery_capacity. NOAA’s tsunami program centers research, detection, forecasts, mitigation, and coordination, which maps well to these abstract controls.

Severe storm subtype values. Severe convective outbreak, Tropical cyclone pressure, Winter storm pressure, Atmospheric-river pressure. Severe storm fields. warning_lead_time, grid_exposure, communications_redundancy, shelter_readiness, service_resilience, recovery_capacity. NOAA’s severe-storm and hurricane preparedness materials make lead time, communication, and resilience more appropriate for this studio than any fine-grained forecast surfaces.

Validation for the entire family. No real forecast, inundation depth, flow map, wind field, or evacuation routing.

Default-value rules

Default assignment should be rule-based and visible.

For all domains, the default preset is Balanced assumptions, the default scale is Localized, the default horizon is Thirty days, and the default uncertainty pair is Evidence uncertainty: Moderate with Confidence in assumptions: Medium. These defaults match the current Atlas tendency toward balanced context instead of alarmist first states.

Natural-hazard categories default initiating_class to Natural cause. Civilian nuclear-facility emergencies default it to Accidental technical failure. Nuclear emergency scenarios default it to Unknown fictional actor only when the user chooses a human-initiated pathway; otherwise they may also be Compound systems failure.

If the user opens Advanced mode after selecting a preset, every advanced field resolves to a visible value immediately. No advanced field should remain in an indeterminate state after the mode switch.

Validation rules

The validation layer should be firm, specific, and educational.

Invalid submissions include the following: missing required category or subtype; missing synthetic location; empty display name only if the user removed an autogenerated name; any prohibited operational keyword pattern; free text containing exact coordinates or real target labels; attempts to use banned quantitative inputs in pasted notes; and contradictory values such as Detection lead time: Extended with Onset speed: Instantaneous in the asteroid family without an explanatory override note.

Use three validation severities.

Blocking validation. Safety boundary violations, missing required fields, invalid enum values, schema mismatches.

Correctable warning. Logically unusual but still educational combinations, such as High preparedness with Very low confidence in assumptions, or Peat fire with Very low environmental persistence.

Advisory note. Teachable ambiguity, such as Institutional trust: High and Evidence uncertainty: Severe, which can be coherent but merits a preview note explaining the tension between social compliance and uncertain evidence.

Cross-field dependency rules

The studio should encode dependencies qualitatively and transparently.

If abstract_scale is Global, the preview must include at least one globally coupled system layer such as economy, information, orbital, climate, or energy. If a domain cannot credibly express global pressure, the UI should show a soft warning recommending Systemic instead.

If consequence_horizon is Immediate, recovery_duration still informs the long-run preview panel but should not dominate the main visual intensity bar.

If evidence_uncertainty is Severe, the preview must add a striped overlay to each consequence bar and show a note reading “Illustrative pressure is driven by low-certainty assumptions.”

If confidence_in_assumptions is Very low, dossier export should include an “Exploratory scenario only” badge.

If institutional_trust is Low or Very low, communication-dependent mitigations should be de-emphasized in the deterministic blurb rather than hidden.

Deterministic preview and submission workflow

Qualitative preview calculation rules

The preview engine should stay deterministic, normalized, and nonphysical. The design goal is not to simulate physics; it is to compute a reproducible set of system-pressure outcomes from qualitative assumptions. That approach is already consistent with the Atlas’s “normalized system strain,” “normalized consequence intensity,” and “illustrative, not physical” language, and it is also consistent with public effect scales such as NOAA’s hazard scales, which communicate user-facing consequence categories rather than raw physics to the public.

Use the following deterministic pipeline:

Band normalization. Map Very low/Low/Moderate/High/Severe to ordinal values 0–4. Map confidence bands separately as metadata; they do not directly lower risk pressure except through uncertainty overlays.

Domain template vector. Each event family owns a base consequence vector across eight systems: services, health_environment, displacement, institutions, economy_logistics, information_comms, orbital_space, ecology_long_run. For example, space-weather templates load heavier base weights into information, services, orbital, and economy; wildfire loads into health/environment, services, ecology, and displacement; earthquake loads into services, displacement, and institutions through continuity strain.

Protective and amplifying modifiers. Protective variables subtract pressure in bounded, domain-specific ways: preparedness, response capacity, redundancy, resilience, monitoring readiness, and adaptation variables all reduce some vectors. Amplifiers add pressure: environmental persistence, high system coupling, high cascade complexity, low trust, poor containment condition, strong radio blackout pressure, high water stress, and so on. Every modifier table is versioned.

Scale modifier. Isolated changes footprint concentration, not peak system intensity alone. Global broadens systems breadth and raises coupling multipliers rather than mechanically maxing all bars.

Horizon modifier. Immediate emphasizes services, acute health/environment, and communications. Thirty days emphasizes recovery, trust, logistics, and displacement. One year emphasizes institutional adaptation, economy, ecosystem pressure, and remediation. Long run emphasizes environmental persistence, adaptation limits, and system coupling.

Uncertainty overlay. Evidence uncertainty never makes an event “more severe,” but it changes how the preview is drawn: striped fills, dotted confidence outlines, and stronger source-note callouts. Confidence in assumptions changes wording tone in the blurb and dossier, not the deterministic bars.

Cell footprint generation. A synthetic footprint generator converts the selected cell into a contiguous or semi-contiguous synthetic-cell set based on scale and subtype. The generator must be deterministic and seedless beyond the canonical cell ID and ruleset version. The same input always returns the same set.

Visual intensity. The preview visual intensity should be a rounded label such as Low, Moderate, High, Severe, derived from the upper-middle of the weighted consequence vector, not the single maximum bar. This avoids one anomalous system dominating the entire visual.

Preview requirements and behavior

The preview must always show the following, in the same order, because the current public surface already primes users to read scenario inputs next to an illustrative effect panel.

First, the selected event name. Second, the synthetic location chip. Third, a one-line assumptions summary. Fourth, normalized consequence-pressure bars. Fifth, likely affected systems. Sixth, proposed planet-state image sequence. Seventh, approximate visual intensity. Eighth, immediate, medium-term, and long-term phase notes. Ninth, the explicit label Illustrative and nonphysical. Tenth, the action Preview on Globe. Eleventh, Cancel or Close, which must restore the prior planet state exactly.

The bars should avoid false precision. Show values in bands or in 5-point increments only. Label them with accessible text equivalents such as “Services pressure: High” rather than only bar length. The Atlas and W3C accessibility guidance both support visible, keyboard-operable, semantically understandable interfaces rather than purely visual encodings.

Event-submission state machine

Use the following deterministic state machine.

StateMeaningAllowed actionsExit conditions
IdleNo event editor openOpen studioUser launches studio
Draft initializedEditor opened with synthetic cell contextEdit fields, switch mode, cancelAny valid field change or cancel
Editing guidedGuided controls activeChange guided fields, preview, switch to advancedValid preview or mode switch
Editing advancedAdvanced controls activeChange advanced fields, preview, switch to guidedValid preview or mode switch
Preview generatedEphemeral preview computedPreview on globe, continue editing, cancel, createCommit or edit or cancel
Globe preview activeTemporary visual layer appliedClose preview, create, return to editorRestore prior state or create
SubmittingConfiguration locked, deterministic result being writtenNone except view progressSuccess or recoverable failure
CreatedEvent persisted to current branchOpen dossier, replay visual, restore prior visual, request narrativeUser action
Narrative pendingOptional bounded narrative request submitted after deterministic writeCancel narrative, keep deterministic briefNarrative success or failure
Narrative availableDossier contains AI brief with provenanceView, export, compare with deterministic briefUser action
Error recoverableValidation or write failed without corruptionRetry, edit, discardSuccess or cancel
Closed restoredEditor closed and prior globe state restoredReopen studioNew launch

The narrative path must be strictly downstream of deterministic creation. The Atlas already states that OpenAI may explain deterministic results but cannot alter them; this should become a hard guard in the state machine and persisted provenance metadata.

Error, loading, and recovery states

Errors should be categorized and phrased in plain language.

Validation error. “Some selections need attention before this illustrative event can be created.” Focus moves to the first blocking issue.

Safety-boundary error. “This studio does not accept operational, targeting, route, casualty, dose, or physical-effects details.” The offending field is highlighted and the prohibited text is not persisted.

Preview-generation error. “Preview could not be refreshed. Your selections are still in the editor.” The user may retry without losing data.

Submission-write error. “Event could not be written to this branch. Nothing was committed.” This is critical for trust.

Narrative-service error. “Deterministic event saved. Optional narrative unavailable.” The dossier stays complete with the deterministic brief.

Restore-state error. If replay restoration fails, the system should offer Reset visual state to authoritative branch view and never leave the user unsure whether the branch itself changed. The Atlas’s current distinction between visual overlays and authoritative state strongly justifies this safeguard.

Loading indicators should describe what is happening in non-technical language: “Computing illustrative consequence profile,” “Applying temporary globe preview,” “Saving event dossier,” and “Generating optional brief.” Avoid spinner-only states.

Dossier, accessibility, mobile behavior, and safety boundaries

Dossier design

The dossier should be the canonical study artifact for every submitted event. The public Atlas already uses dossiers for selected records and exposes replay and restore actions for fictional consequence briefs, so the event studio should turn those ideas into a fully structured scenario dossier.

Each dossier should contain these panels.

Summary. Event name, category, subtype, synthetic cell alias, scale, horizon, preset, created mode, ruleset version.

Configuration. All guided selections and all advanced assumptions, with non-default values visually marked.

Uncertainty and source notes. Evidence uncertainty, confidence in assumptions, explanation text, and whether the narrative source is deterministic only or deterministic plus bounded OpenAI narrative.

Deterministic consequence metrics. The normalized vector, phase summaries, likely affected systems, persistent footprint summary, and affected synthetic-cell list.

Planet-state sequence. The proposed globe-image sequence and replay controls.

Connected blurb. A deterministic paragraph produced from templates, followed optionally by a separately labeled AI narrative block. The AI block must always include a note that it did not alter numeric state.

Actions. Replay event visual, restore preceding visual state, copy scenario link, export dossier, copy deterministic summary, compare deterministic versus AI narrative.

Boundary statement. A permanent footer stating that the scenario is fictional, educational, synthetic-cell based, illustrative, nonphysical, non-operational, and not a forecast or emergency instruction.

Accessibility and keyboard behavior

Accessibility should be treated as core product behavior, not compliance afterthought. The Atlas’s own accessibility page already commits to keyboard use, visible focus, text enlargement, mobile reflow, reduced motion, right-to-left support, semantic headings, and printable reports, and the public globe documents command keys and Escape/focus behavior. W3C guidance supplies the rest of the modal and keyboard contract.

Detailed behavior should be as follows.

When the studio opens, focus lands on the dialog title or first explanatory paragraph if the content is long; otherwise on the first interactive control. Tab and Shift+Tab loop within the dialog. Escape closes the dialog and returns focus to the invoking globe control or marker. This is directly aligned with WAI-ARIA dialog guidance.

Every consequence bar must have visible text plus programmatic labels. For example: “Institutions pressure, moderate, due to low trust and high cascade complexity.” Do not rely on color alone.

Every select or segmented control must be keyboard-operable without timing-sensitive gestures, consistent with WCAG keyboard requirements.

Preview image strips must respect reduced-motion preferences. If the user prefers reduced motion, the strip becomes a manual step carousel rather than an auto-animated dissolve. This matches both the Atlas accessibility statement and WCAG techniques for reduced motion.

The dialog should expose a ? shortcut to open a short “How this studio works” help sheet, matching the Atlas’s existing help/keyboard-disclosure approach.

Mobile behavior

The Atlas already states that pages should reflow at narrow widths and high zoom with wrapping identifiers rather than forced horizontal scroll. The studio should therefore use a mobile-first bottom-sheet or full-height stepper layout, not desktop tables squeezed onto a phone.

On mobile, Guided mode should render as a stepper with a sticky summary tray showing category, subtype, scale, and horizon.

On mobile, Advanced Academic mode should convert each assumptions group into an accordion. Only one advanced group should be expanded at a time by default. This is a straightforward application of progressive disclosure and accordion patterns for complex forms on small screens.

Preview on Globe on mobile should split the screen only when landscape is available. In portrait, it should transition to a temporary full-screen preview with a clear Return to editor action.

Large tables in the dossier should become definition cards on mobile. The acceptance-test list and scenario examples should export cleanly to print/PDF-readable layouts, consistent with the Atlas’s printable-reports commitment.

Educational disclaimers and safety boundaries

The studio should present its boundaries in three layers: always-visible microcopy, a preview label, and a dossier footer.

Always-visible microcopy. “Fictional educational simulation. Synthetic cells only.”

Preview label. “Illustrative and nonphysical. Not a blast, fallout, dose, casualty, inundation, routing, or forecast model.”

Dossier footer. “This dossier is for education about systems, resilience, uncertainty, and consequence. It is not operational guidance.”

These boundaries are not just prudent; they are already part of the Atlas’s public identity and safety model. The safety page excludes practical harm instructions and real-world exploitation detail; the simulation pages exclude targeting, casualty, and physical-effects calculations; the About page describes the simulation as a high-level educational consequence laboratory.

Scenario library, acceptance tests, backlog, and risks

Complete example scenarios

The examples below are fictional fixture scenarios for product design, QA, education, and user research. They are not forecasts, operational instructions, or physical models. Their control combinations are chosen to reflect the qualitative hazard dimensions emphasized by public preparedness and hazard institutions.

Nuclear detonation or abstract nuclear emergency

High-altitude systems shock. Category Nuclear detonation or abstract nuclear emergency; subtype Abstract nuclear emergency; environment High altitude; scale Regional; horizon Immediate; preset Cascading systems; preparedness Moderate; response capacity Moderate; service resilience Low; monitoring readiness High; environmental persistence Low; institutional coordination Moderate. Expected preview: highest pressures in information/communications, services, and institutional continuity; contamination pressure stays secondary; visual intensity High.

Surface emergency with strained coordination. Environment Surface; scale Localized; horizon Thirty days; preset Strained systems; preparedness Low; response capacity Low; service resilience Low; environmental persistence High; monitoring readiness Low; institutional coordination Low. Expected preview: services and health/environment lead; displacement rises in medium term; uncertainty note prominent if evidence uncertainty is High.

Underground escalatory crisis with resilient services. Environment Underground; scale Isolated; horizon One year; preset High preparedness; preparedness High; response capacity High; service resilience High; environmental persistence Moderate; monitoring readiness High; institutional coordination High. Expected preview: infrastructure disruption localized, institutions remain stable, long-term remediation pressure remains visible but bounded.

Civilian nuclear-facility emergency or meltdown

Cooling failure under weak defense in depth. Subtype Cooling failure crisis; scale Localized; horizon Thirty days; preset Strained systems; cooling resilience Low; containment condition Moderate; defense-in-depth quality Low; common-cause failure pressure High; monitoring readiness Low; emergency coordination Low; environmental persistence High; remediation capacity Low; safety culture strength Low; public trust condition Low. Expected preview: services, institutions, and health/environment all rise sharply; long-term persistence prominent.

Containment challenge with strong coordination. Subtype Containment challenge; scale Localized; horizon One year; preset Balanced assumptions; cooling resilience Moderate; containment condition High; defense-in-depth quality High; common-cause failure pressure Moderate; monitoring readiness High; emergency coordination High; environmental persistence Moderate; remediation capacity High; safety culture strength High; public trust condition Moderate. Expected preview: acute pressure moderated, long-run remediation visible but not dominant.

Multi-system plant emergency during trust crisis. Subtype Multi-system plant emergency; scale Regional; horizon Long run; preset Cascading systems; cooling resilience Moderate; containment condition Moderate; defense-in-depth quality Moderate; common-cause failure pressure High; monitoring readiness Moderate; emergency coordination Moderate; environmental persistence High; remediation capacity Moderate; safety culture strength Moderate; public trust condition Very low. Expected preview: institutions and information response become almost as important as environmental burden.

Solar flare or geomagnetic storm

Radio blackout dominant event. Subtype Solar flare; scale Regional; horizon Immediate; preset Balanced assumptions; radio blackout pressure Severe; satellite vulnerability Moderate; grid resilience Moderate; navigation dependency Moderate; communications redundancy Low; recovery capacity Moderate; compound conditions Low. Expected preview: communications and services first, then logistics; visual intensity High.

Grid-stress geomagnetic storm. Subtype Geomagnetic storm; scale Systemic; horizon Thirty days; preset Cascading systems; radio blackout pressure Moderate; satellite vulnerability High; grid resilience Low; navigation dependency High; communications redundancy Moderate; recovery capacity Low; compound conditions High. Expected preview: services, economy/logistics, and information pressures run together; orbital pressure visible.

Short-lived flare with strong redundancy. Subtype Solar flare; scale Localized; horizon Immediate; preset High preparedness; radio blackout pressure High; satellite vulnerability Low; grid resilience High; navigation dependency Low; communications redundancy High; recovery capacity High; compound conditions Low. Expected preview: only temporary communications and navigation strain; quick recovery note.

Asteroid or meteorite event

Airburst with short warning. Subtype Airburst; scale Localized; horizon Thirty days; preset Balanced assumptions; detection lead time Short; preparedness Moderate; infrastructure resilience Moderate; environmental persistence Low. Expected preview: sharp immediate peak, low long-run persistence, strong services and displacement bars.

Ocean impact with resilient coast systems. Subtype Ocean impact; scale Regional; horizon One year; preset High preparedness; detection lead time Moderate; preparedness High; infrastructure resilience High; environmental persistence Moderate. Expected preview: maritime and coastal systems emphasized; broad but moderated recovery pathway.

Fragment field with minimal warning. Subtype Fragment field; scale Systemic; horizon Thirty days; preset Strained systems; detection lead time Minimal; preparedness Low; infrastructure resilience Low; environmental persistence Moderate. Expected preview: wider synthetic footprint, medium visual intensity, complex multi-sector disruption.

Global warming, drought, and heatwave

Urban heatwave under weak adaptation. Subtype Heatwave; scale Regional; horizon Thirty days; preset Strained systems; water stress Moderate; ecosystem pressure Moderate; heat adaptation Low; energy-system resilience Low; agricultural resilience Moderate; coastal/infrastructure adaptation Moderate; migration pressure Low; dry-Earth progression Low. Expected preview: health/environment and energy/services dominant; medium-term trust and recovery signals.

Multi-year drought and food-system stress. Subtype Drought; scale Systemic; horizon One year; preset Cascading systems; water stress Severe; ecosystem pressure High; heat adaptation Moderate; energy-system resilience Moderate; agricultural resilience Low; coastal/infrastructure adaptation Moderate; migration pressure High; dry-Earth progression High. Expected preview: long-run ecology, food-water security, and displacement/migration pressures dominate.

Long-run warming with strong adaptation. Subtype Long-run warming pressure; scale Global; horizon Long run; preset High preparedness; water stress Moderate; ecosystem pressure High; heat adaptation High; energy-system resilience High; agricultural resilience High; coastal/infrastructure adaptation High; migration pressure Moderate; reduced-ice progression High. Expected preview: lower acute pressure but visible persistent planet-state transformation strip.

Wildfire

Multi-front wildfire in strained systems. Subtype Multi-front fire; scale Regional; horizon Thirty days; preset Strained systems; fuel dryness Severe; response capacity Low; air-quality pressure High; ecosystem resilience Low; infrastructure exposure High. Expected preview: services, health/environment, and displacement all elevated; smoky visual strip.

Peat fire with long persistence. Subtype Peat or subsurface fire; scale Localized; horizon Long run; preset Balanced assumptions; fuel dryness High; response capacity Moderate; air-quality pressure Moderate; ecosystem resilience Low; infrastructure exposure Moderate; environmental persistence auto-raised to High. Expected preview: modest peak intensity, unusually long environmental persistence.

Surface fire with strong response network. Subtype Surface fire; scale Localized; horizon Immediate; preset High preparedness; fuel dryness Moderate; response capacity High; air-quality pressure Moderate; ecosystem resilience Moderate; infrastructure exposure Low. Expected preview: limited footprint, low-to-moderate visual intensity, fast recovery.

Earthquake

Shallow crustal event in brittle built environment. Subtype Shallow crustal; scale Regional; horizon Thirty days; preset Strained systems; built-environment resilience Low; service redundancy Low; preparedness Low; recovery capacity Low. Expected preview: services, displacement, and institutional continuity all high.

Offshore event with strong redundancy. Subtype Offshore; scale Regional; horizon Immediate; preset High preparedness; built-environment resilience High; service redundancy High; preparedness High; recovery capacity High. Expected preview: moderate acute service disruption but fast stabilization, with optional note that tsunami modeling is outside this scenario unless separately selected.

Aftershock sequence recovery drag. Subtype Aftershock sequence; scale Localized; horizon One year; preset Balanced assumptions; built-environment resilience Moderate; service redundancy Moderate; preparedness Moderate; recovery capacity Low; recovery duration High; onset speed Moderate. Expected preview: immediate peak smaller than long-tail recovery burden.

Volcano, flood, tsunami, and severe storm

Explosive eruption pressure with strong monitoring. Subtype Explosive eruption pressure; scale Regional; horizon Thirty days; preset Balanced assumptions; monitoring readiness High; ash persistence High; ground disruption pressure Moderate; aviation disruption pressure High; recovery capacity Moderate. Expected preview: services, transport, and environmental burden salient; monitoring mitigates uncertainty.

Compound flood in low-drainage system. Subtype Compound flood; scale Regional; horizon Thirty days; preset Strained systems; watershed saturation High; drainage capacity Low; warning reach Moderate; service resilience Low; environmental persistence Moderate; recovery capacity Low. Expected preview: services and displacement rise together; medium-term recovery remains stressed.

Regional-source tsunami with redundant communications. Subtype Regional-source; scale Regional; horizon Immediate; preset High preparedness; warning lead time Moderate; communications redundancy High; near-shore exposure Moderate; service resilience High; recovery capacity High. Expected preview: acute coastal services stress but strong immediate response note.

Tropical cyclone pressure with fragile grid. Subtype Tropical cyclone pressure; scale Systemic; horizon Thirty days; preset Cascading systems; warning lead time High; grid exposure High; communications redundancy Moderate; shelter readiness Moderate; service resilience Low; recovery capacity Moderate. Expected preview: services and economy/logistics dominate; information pressure depends on trust and redundancy.

Acceptance tests

The following acceptance tests are written as product-facing behavior, not implementation instructions.

  1. Given the globe is focused, when the user launches the studio, then focus moves into the dialog and the background becomes inert.
  2. Given the dialog is open, when the user presses Escape, then the dialog closes and focus returns to the invoking control.
  3. Given Guided mode is selected, when the user has not chosen a category, then no domain-specific fields are shown.
  4. Given Guided mode is selected, when the user switches to Advanced Academic mode, then all existing guided selections persist unchanged.
  5. Given Advanced Academic mode is selected, when the user returns to Guided mode, then advanced values are preserved in the underlying draft.
  6. Given no synthetic cell is selected, when the user attempts creation, then creation is blocked with a location-required error.
  7. Given a preview exists, when the user edits any field, then the preview refreshes noncommitting after debounce.
  8. Given a preview is active on the globe, when the user presses Cancel, then the prior globe visual state is restored.
  9. Given the user previews a scenario, when they do not submit it, then no branch state changes are written.
  10. Given the user submits a valid scenario, when the write succeeds, then a dossier record is created with configuration, assumptions, uncertainty, footprint, and consequence metrics.
  11. Given deterministic submission succeeds, when the narrative service is unavailable, then the dossier remains complete with deterministic content only.
  12. Given deterministic submission succeeds, when the user requests an AI narrative, then the AI result is stored as optional narrative provenance and numeric state remains unchanged.
  13. Given a category of Nuclear detonation or abstract nuclear emergency, when the user enters a yield value in notes, then the note is rejected as prohibited operational detail.
  14. Given a category of Civilian nuclear-facility emergency, when the user attempts to enter an evacuation route, then submission is blocked with a safety-boundary message.
  15. Given a category of Asteroid or meteorite event, when the user attempts to enter velocity or crater diameter, then the input is rejected.
  16. Given a category of Wildfire, when the user attempts to enter ignition instructions, then the input is rejected.
  17. Given a category of Earthquake, when the user attempts to enter casualty calculations, then the input is rejected.
  18. Given a category of Flood, when the user attempts to enter inundation depth, then the input is rejected.
  19. Given a category of Severe storm, when the user attempts to enter a real wind-field forecast, then the input is rejected.
  20. Given High altitude is selected for a nuclear emergency, when preview renders, then communications and services appear in likely affected systems.
  21. Given Underground is selected for a nuclear emergency, when preview renders, then visual contamination emphasis is lower than for Surface, all else equal.
  22. Given Containment condition is Severe, when the event is previewed, then environmental persistence cannot render lower than Moderate without a prominent warning.
  23. Given Radio blackout pressure is Severe, when a solar event is previewed, then information/communications pressure is at least High.
  24. Given Navigation dependency is High, when a solar event is previewed, then logistics or transport appears in likely affected systems.
  25. Given an asteroid Airburst subtype, when horizon is Long run, then long-run persistence defaults lower than for Land impact, unless overridden.
  26. Given a warming Long-run horizon, when preview renders, then a planet-state progression strip is visible.
  27. Given a warming scenario, when the user reaches preview, then the notice “educational scenario, not a physical climate forecast” is shown.
  28. Given wildfire subtype Peat or subsurface fire, when preview renders, then environmental persistence is emphasized.
  29. Given earthquake subtype Aftershock sequence, when preview renders, then recovery duration remains visible in the phase summary.
  30. Given a tsunami subtype Regional-source, when preview renders, then warning lead time appears in the assumptions summary.
  31. Given the evidence uncertainty is Severe, when consequence bars render, then they use uncertainty overlays and explanatory microcopy.
  32. Given confidence in assumptions is Very low, when the dossier opens, then it displays an “Exploratory scenario only” badge.
  33. Given the user tabs through the dialog, when they reach the last control, then focus cycles to the first control inside the dialog.
  34. Given the user uses screen-reader navigation, when they reach the consequence bars, then each bar announces label, band, and main drivers.
  35. Given reduced-motion preference is active, when the preview image sequence renders, then it does not auto-animate.
  36. Given the user is on a narrow viewport, when the studio opens, then it reflows into a stepper or bottom-sheet layout without horizontal scrolling for core controls.
  37. Given the user reopens the studio from the same marker, when they choose “start new event,” then the prior unsaved draft does not overwrite the new draft.
  38. Given the user chooses a preset, when they open Advanced mode, then every advanced field shows the preset-resolved value.
  39. Given the user edits any preset-resolved advanced field, when they return to the preset row, then the preset is marked “customized.”
  40. Given the same event configuration and ruleset version, when two users preview it independently, then the deterministic bars and affected synthetic-cell set are identical.
  41. Given the ruleset version changes, when an older dossier is reopened, then its original result remains preserved under its original ruleset version.
  42. Given a narrative exists, when the user compares it with the deterministic brief, then both provenance labels are visible.
  43. Given a restore-state failure occurs after replay, when the user selects Reset visual state, then the globe returns to the authoritative branch view.
  44. Given the user copies a story link, when another user opens it, then the shared state reproduces the same visible dossier configuration without exposing private local notes.
  45. Given a private local note exists, when the user requests an AI narrative without opt-in, then the local note is excluded from the request.
  46. Given a dialog help shortcut exists, when the user presses ?, then concise studio help opens without losing current draft state.
  47. Given the user attempts to close with unsaved changes, when they confirm discard, then the studio closes and restores prior globe state.
  48. Given the user exports a dossier, when the export completes, then the file includes configuration, assumptions, uncertainty, deterministic outputs, and provenance labels but no banned physical or operational fields.

Prioritized product backlog

Priority now

  1. Formalize the shared event schema and ruleset-version contract.
  2. Build the guided five-step studio shell using the current Atlas visual language.
  3. Preserve the existing Simple/Advanced split but rename and group controls more clearly.
  4. Implement noncommitting preview with guaranteed restore behavior.
  5. Add per-domain field definitions and validation guards for all eight domain families.
  6. Persist full dossiers with deterministic metrics and replay/restore actions.
  7. Enforce hard safety filters on free-text notes and prohibited quantitative inputs.
  8. Implement uncertainty overlays and uncertainty/source-note blocks.
  9. Ensure narrative generation is strictly post-deterministic with provenance.
  10. Make all dialog, preview, and dossier workflows keyboard complete.

Priority next

  1. Add comparison mode for two dossier scenarios side by side.
  2. Add classroom-facing printable dossier layouts and “discussion prompts.”
  3. Add “preset rationale” tooltips explaining why each preset changes specific assumptions.
  4. Add rule-explanation panels showing why a likely affected system appeared.
  5. Add saved local scenario notebooks with no account requirement, matching current privacy posture.
  6. Add mobile-specific preview full-screen mode and better thumb-target affordances.
  7. Add branch-aware scenario folders for scholars comparing counterfactuals.
  8. Add export formats for JSON and human-readable PDF/print view.

Priority later

  1. Add instructor-curated scenario packs linked from the Learn area.
  2. Add domain glossary chips inside advanced controls.
  3. Add accessibility personalization, such as higher-contrast control-density presets.
  4. Add localized language support for dossier labels while keeping scenario data language-stable.
  5. Add research instrumentation that is strictly local/session based unless the project’s privacy stance changes.

Risks and unresolved design questions

The biggest product risk is accidental operational drift. A richer hazard studio can easily become an inappropriate pseudo-planning tool unless the validation layer, microcopy, and quantity restrictions are designed first and audited repeatedly. The Atlas’s public safety boundary is strong; the studio must not erode it through “helpful” details.

A second risk is hidden pseudo-precision. If the preview exposes too many numeric values, users may overread the output as science-grade measurement or forecast. Using normalized bands, versioned rulesets, and explicit uncertainty notes reduces that risk and tracks both Atlas language and calibrated uncertainty practice.

A third risk is mode divergence. If Guided mode and Advanced Academic mode behave like different products, users will lose trust. The shared schema and preview engine eliminate this risk by making mode a visibility choice, not a distinct model.

A fourth risk is domain imbalance. Some families, especially climate and severe weather, naturally encourage forecast-like expectations. The interface should repeatedly state that the output is an illustrative educational scenario, not a forecast, and should avoid map surfaces or terms that imply operational meteorology or geophysics.

A fifth risk is narrative overreach. Users may trust polished language more than deterministic outputs. The dossier must therefore visually subordinate the narrative and allow one-click fallback to a deterministic brief. The public Atlas already establishes this principle; the next-generation studio should make it unmistakable.

The main unresolved design questions are these: whether compound multi-hazard scenarios should be allowed in the first release; how much of the ruleset explanation should be exposed to users versus only to QA and educators; whether local notes should ever be exportable by default; whether branch comparison should be dossier-first or globe-first; and whether the strongest uncertainty cases should produce alternate preview ranges rather than a single striped result. Those questions are product-defining, but none blocks the core studio described above.