INTEGRATION
Life support, power, work, maintenance and habitation are evaluated as one operating environment.
ACROS PHASE 0 / EARTH
TESTBED FOR HIGH-RISK ITERATION & EVALUATION VIA ENGINEERING
THRIEVE is the failure-driven entry phase of ACROS. Earth-based laboratories and analogue environments expose systems to degradation, latency, isolation and collapse before a single kilogram is trusted to flight.
00
THE FAILURE IMPERATIVE
THRIEVE creates no flight-ready system. It creates failure-literate ones.
If a subsystem fails gracefully, it advances. If it succeeds too easily, it is challenged again. If it cannot break, the test has not yet become real.
STRATEGIC ROLE
On Earth, interruption is inconvenient. Beyond Earth, it can become irreversible. THRIEVE creates the time and proximity required to expose hidden dependencies, revise procedures and understand what sustained operation actually demands.
SELECTED SYSTEM PRINCIPLES
Life support, power, work, maintenance and habitation are evaluated as one operating environment.
Systems must survive routine use, changing crews and accumulated wear — not merely one successful demonstration.
Fatigue, privacy, medical events, errors and social dynamics belong inside the test architecture.
A resilient system is measured by how it responds when components, procedures or assumptions fail.

Fault injection is not staged catastrophe. It is a controlled path through dependencies, fallback logic and traceable consequence.
CORE TECHNICAL OBJECTIVES
Each field is tested independently and through the dependencies that turn a local defect into a system-level failure.
Closed-loop and hybrid architectures are subjected to cycle degradation and failures across dependent systems.
ENGINEERING BASIS ↓Oxygen, metals and water extraction are tested against lunar and Martian material analogues.
ENGINEERING BASIS ↓Decision systems operate through Mars-class communication delay, degraded information and multiple failure events.
ENGINEERING BASIS ↓Hydrogen-rich materials, regolith concepts and active shielding approaches are evaluated before flight qualification.
ENGINEERING BASIS ↓Structural, software and procedural modules are broken, diagnosed and redesigned through short iteration cycles.
ENGINEERING BASIS ↓Mixed reality, distorted communication and synthetic confinement expose human-system weaknesses under controlled protocols.
ENGINEERING BASIS ↓ENGINEERING BASIS
These are not isolated research themes. They are coupled test domains with explicit envelopes, failure injection and evidence requirements.
THRIEVE operates air, water, waste, thermal control and crew demand as one coupled loop. A stable cabin reading is insufficient if that stability depends on rising consumables, hidden accumulation or continuous intervention from outside the habitat.
30–180 day continuous campaigns
Representative loads for 3–7 occupants
Nominal, degraded and emergency operating modes
O₂ / CO₂ partial pressure, humidity and trace contaminants
Water recovery, microbial load and stored-mass drift
Energy per crew-day, filter loading and maintenance burden
Sensor bias, pump loss, fouled membranes, biological upset and power restriction are introduced individually and in combination.
Time-resolved mass balances, recovery margins, consumables forecasts and verified safe-state procedures.
Extraction hardware is tested against mineralogical uncertainty, abrasive dust and uneven feedstock rather than a single convenient simulant. The system boundary includes excavation, preparation, separation, product storage and waste heat.
Lunar and Martian analogue batches with controlled variance
Vacuum, pressure and thermal-cycle exposure
Interrupted feed, contamination and reduced-power operation
Product yield and purity per kilogram of feedstock
Specific energy, water demand and thermal rejection
Tool wear, dust migration and rejected material
Feed composition is shifted beyond the tuned case; seals, heaters, conveyors and separation stages are degraded deliberately.
Process maps that connect feedstock class to yield, energy, maintenance demand and recoverable failure modes.
The test removes Earth from the immediate control loop. Local systems must distinguish urgency from uncertainty, preserve crew authority and explain why they entered a safe state, deferred an action or committed limited resources.
20–40 minute round-trip delay
Scheduled and unannounced blackouts up to 72 hours
Conflicting, incomplete and time-shifted telemetry
Detection-to-decision and decision-to-recovery time
False alarms, missed faults and unsafe command rejection
Traceability of machine recommendations and crew overrides
Multiple faults are introduced across power, mobility, habitat and communications while remote support receives an outdated system picture.
Decision logs, autonomy boundaries, escalation rules and validated minimum data required for remote reconstruction.
Materials and configurations are evaluated against solar-particle and galactic-cosmic-ray spectra, including the secondary radiation created inside the shield. Protection is traded against structure, thermal behavior, volume and power.
Habitat, storm-shelter and mobile-system geometries
Hydrogen-rich, water, composite and regolith-derived concepts
Active-field nominal, degraded and power-loss states
Absorbed dose and dose equivalent behind the configuration
Areal density, secondary-particle production and weak paths
Mass, power, heat rejection and inspection requirements
Gaps, joints, penetrations, material aging and loss of active protection are assessed as credible configuration failures.
Dose maps, geometry-specific protection factors and operational shelter rules tied to measurable exposure limits.
Mechanical, electrical, fluid, data and software interfaces are treated as one contract. Modules are removed, substituted and rolled back with constrained tools, incomplete spares and realistic crew workload.
Cold, dusty, gloved and low-visibility maintenance conditions
Known-good, degraded and incompatible replacement units
Software rollback and data-schema migration
Mean time to isolate, exchange and restore function
Tools, consumables, instructions and crew-hours required
Common-cause failures transferred through shared interfaces
Misalignment, connector damage, stale configuration data and cascading interface faults challenge the claimed independence of a module.
Verified interface control documents, repair envelopes, spare strategies and redesign priorities ranked by operational consequence.
THRIEVE examines how isolation, workload, delayed communication, privacy loss and equipment behavior alter judgement and recovery. Human performance is tested as part of the architecture without treating distress as expendable data.
Progressive 30–90 day analogue campaigns
Mixed routine, maintenance, emergency and medical workloads
Delayed contact, reduced privacy and disrupted schedules
Sleep, cognitive workload, procedural errors and recovery
Team coordination, conflict patterns and decision latency
Habitat usability, alarm burden and demand for outside support
Workload peaks, ambiguous alarms, leadership transfer and communication loss are combined under pre-approved, reversible protocols.
Human-system requirements, workload ceilings, abort criteria, privacy provisions and procedures reviewed under independent ethics oversight.

Mars-class latency and blackout conditions remove live supervision from the decision loop and expose whether autonomy is accountable or merely convenient.
FAILURE ACCEPTANCE
“What survives when the narrative ends and only physics remains?”
Breakdown is an intended part of stress testing when it produces traceable evidence.
Apparent stability must be challenged across several stress axes before it is trusted.
Phase progression is connected to failure quality and recovery evidence, not a clean first run.
Isolation and psychological protocols require mission-equivalent ethical review and transparency.

A system advances only when interruption is detected, explained and routed through known fallback margins without an invisible rescue from outside.
THE THRIEVE GATE
The system has failed at least once under designed stress with diagnostics that explain what happened.
Fallback logic has restored function inside defined margins rather than through improvised intervention.
Closed-loop operation has continued for more than thirty days without a reset.
At least one complete communications-loss scenario has been executed and evaluated.
The test has produced error models, fatigue maps or procedural insight beyond a binary pass or fail.

Isolation, fatigue and distorted communication are examined under ethical review. Vulnerability is evidence — never expendable test material.
OUTPUTS INTO ACROS
Validated subsystems, failure signatures, autonomy profiles and baseline orbital candidates.
Modules prepared for thermal, radiation and mechanical exposure in later qualification.
First-generation communications behavior for long-latency and blackout scenarios.
Shared definitions that embed robustness expectations across the following ACROS phases.
WHAT IT ENABLES
Validated operating assumptions
Integrated human-system requirements
Failure and recovery knowledge
A disciplined foundation for ACROS
What THRIEVE proves, ACROS develops into the wider CelestiQ architecture.
Return to architecture ↗