ACROS PHASE 0 / EARTH

THRIEVE

TESTBED FOR HIGH-RISK ITERATION & EVALUATION VIA ENGINEERING

Before humans remain beyond Earth,
the infrastructure must fail here.

THRIEVE is the failure-driven entry phase of ACROS. Earth-based laboratories and analogue environments expose systems to degradation, latency, isolation and collapse before a single kilogram is trusted to flight.

THRIEVE / PHASE 0BREAK — TRACE — RECOVER

00

THE FAILURE IMPERATIVE

Success too early
is a dangerous signal.

THRIEVE creates no flight-ready system. It creates failure-literate ones.

If a subsystem fails gracefully, it advances. If it succeeds too easily, it is challenged again. If it cannot break, the test has not yet become real.

STRATEGIC ROLE

A place where weaknesses
are still repairable.

On Earth, interruption is inconvenient. Beyond Earth, it can become irreversible. THRIEVE creates the time and proximity required to expose hidden dependencies, revise procedures and understand what sustained operation actually demands.

SELECTED SYSTEM PRINCIPLES

Not a simulation of a mission.
A rehearsal for continuity.

01

INTEGRATION

Life support, power, work, maintenance and habitation are evaluated as one operating environment.

02

REPETITION

Systems must survive routine use, changing crews and accumulated wear — not merely one successful demonstration.

03

HUMAN REALITY

Fatigue, privacy, medical events, errors and social dynamics belong inside the test architecture.

04

RECOVERY

A resilient system is measured by how it responds when components, procedures or assumptions fail.

Stylized interconnected THRIEVE systems under a controlled failure cascade
01 / STRESS & FAILURE

Break the system.
Preserve the evidence.

Fault injection is not staged catastrophe. It is a controlled path through dependencies, fallback logic and traceable consequence.

CORE TECHNICAL OBJECTIVES

Six fields.
One deliberate collision with reality.

Each field is tested independently and through the dependencies that turn a local defect into a system-level failure.

ENGINEERING BASIS

Resilience becomes credible
when it can be measured.

These are not isolated research themes. They are coupled test domains with explicit envelopes, failure injection and evidence requirements.

01 / CLS / MLS

Life support is a mass-balance problem before it is a comfort system.

THRIEVE operates air, water, waste, thermal control and crew demand as one coupled loop. A stable cabin reading is insufficient if that stability depends on rising consumables, hidden accumulation or continuous intervention from outside the habitat.

TEST ENVELOPE

30–180 day continuous campaigns

Representative loads for 3–7 occupants

Nominal, degraded and emergency operating modes

MEASURED

O₂ / CO₂ partial pressure, humidity and trace contaminants

Water recovery, microbial load and stored-mass drift

Energy per crew-day, filter loading and maintenance burden

FAILURE INJECTION

Sensor bias, pump loss, fouled membranes, biological upset and power restriction are introduced individually and in combination.

EVIDENCE RETURNED

Time-resolved mass balances, recovery margins, consumables forecasts and verified safe-state procedures.

02 / ISRU / FEEDSTOCK

A process is not resource utilization until variable material enters it.

Extraction hardware is tested against mineralogical uncertainty, abrasive dust and uneven feedstock rather than a single convenient simulant. The system boundary includes excavation, preparation, separation, product storage and waste heat.

TEST ENVELOPE

Lunar and Martian analogue batches with controlled variance

Vacuum, pressure and thermal-cycle exposure

Interrupted feed, contamination and reduced-power operation

MEASURED

Product yield and purity per kilogram of feedstock

Specific energy, water demand and thermal rejection

Tool wear, dust migration and rejected material

FAILURE INJECTION

Feed composition is shifted beyond the tuned case; seals, heaters, conveyors and separation stages are degraded deliberately.

EVIDENCE RETURNED

Process maps that connect feedstock class to yield, energy, maintenance demand and recoverable failure modes.

03 / 20–40 MIN RTT

Autonomy begins where real-time supervision ends.

The test removes Earth from the immediate control loop. Local systems must distinguish urgency from uncertainty, preserve crew authority and explain why they entered a safe state, deferred an action or committed limited resources.

TEST ENVELOPE

20–40 minute round-trip delay

Scheduled and unannounced blackouts up to 72 hours

Conflicting, incomplete and time-shifted telemetry

MEASURED

Detection-to-decision and decision-to-recovery time

False alarms, missed faults and unsafe command rejection

Traceability of machine recommendations and crew overrides

FAILURE INJECTION

Multiple faults are introduced across power, mobility, habitat and communications while remote support receives an outdated system picture.

EVIDENCE RETURNED

Decision logs, autonomy boundaries, escalation rules and validated minimum data required for remote reconstruction.

04 / PASSIVE / ACTIVE

Shielding performance must be measured as system mass, dose and consequence.

Materials and configurations are evaluated against solar-particle and galactic-cosmic-ray spectra, including the secondary radiation created inside the shield. Protection is traded against structure, thermal behavior, volume and power.

TEST ENVELOPE

Habitat, storm-shelter and mobile-system geometries

Hydrogen-rich, water, composite and regolith-derived concepts

Active-field nominal, degraded and power-loss states

MEASURED

Absorbed dose and dose equivalent behind the configuration

Areal density, secondary-particle production and weak paths

Mass, power, heat rejection and inspection requirements

FAILURE INJECTION

Gaps, joints, penetrations, material aging and loss of active protection are assessed as credible configuration failures.

EVIDENCE RETURNED

Dose maps, geometry-specific protection factors and operational shelter rules tied to measurable exposure limits.

05 / FAST-FAIL

Modularity is proven by replacement under pressure, not by a drawing.

Mechanical, electrical, fluid, data and software interfaces are treated as one contract. Modules are removed, substituted and rolled back with constrained tools, incomplete spares and realistic crew workload.

TEST ENVELOPE

Cold, dusty, gloved and low-visibility maintenance conditions

Known-good, degraded and incompatible replacement units

Software rollback and data-schema migration

MEASURED

Mean time to isolate, exchange and restore function

Tools, consumables, instructions and crew-hours required

Common-cause failures transferred through shared interfaces

FAILURE INJECTION

Misalignment, connector damage, stale configuration data and cascading interface faults challenge the claimed independence of a module.

EVIDENCE RETURNED

Verified interface control documents, repair envelopes, spare strategies and redesign priorities ranked by operational consequence.

06 / HUMAN SYSTEM

The crew is neither the weakest component nor an unlimited redundancy.

THRIEVE examines how isolation, workload, delayed communication, privacy loss and equipment behavior alter judgement and recovery. Human performance is tested as part of the architecture without treating distress as expendable data.

TEST ENVELOPE

Progressive 30–90 day analogue campaigns

Mixed routine, maintenance, emergency and medical workloads

Delayed contact, reduced privacy and disrupted schedules

MEASURED

Sleep, cognitive workload, procedural errors and recovery

Team coordination, conflict patterns and decision latency

Habitat usability, alarm burden and demand for outside support

FAILURE INJECTION

Workload peaks, ambiguous alarms, leadership transfer and communication loss are combined under pre-approved, reversible protocols.

EVIDENCE RETURNED

Human-system requirements, workload ceilings, abort criteria, privacy provisions and procedures reviewed under independent ethics oversight.

Stylized autonomous rover operating through delayed and interrupted communications
02 / AUTONOMY & LATENCY

When Earth cannot answer,
the system still must.

Mars-class latency and blackout conditions remove live supervision from the decision loop and expose whether autonomy is accountable or merely convenient.

FAILURE ACCEPTANCE

Failure is permitted.
False confidence is not.

“What survives when the narrative ends and only physics remains?”
ACCEPTEDSYSTEM-LEVEL BREAKDOWN

Breakdown is an intended part of stress testing when it produces traceable evidence.

REJECTEDFALSE-POSITIVE STABILITY

Apparent stability must be challenged across several stress axes before it is trusted.

REJECTEDEARLY SUCCESS AS PROOF

Phase progression is connected to failure quality and recovery evidence, not a clean first run.

CONDITIONALHUMAN TRIALS

Isolation and psychological protocols require mission-equivalent ethical review and transparency.

Stylized closed-loop infrastructure rerouting around a controlled break
03 / CLOSED-LOOP & RECOVERY

Recovery is not survival
by accident.

A system advances only when interruption is detected, explained and routed through known fallback margins without an invisible rescue from outside.

THE THRIEVE GATE

A system advances only when
failure has produced knowledge.

01

TRACEABLE FAILURE

The system has failed at least once under designed stress with diagnostics that explain what happened.

02

KNOWN RECOVERY

Fallback logic has restored function inside defined margins rather than through improvised intervention.

03

30+ DAYS

Closed-loop operation has continued for more than thirty days without a reset.

04

TOTAL BLACKOUT

At least one complete communications-loss scenario has been executed and evaluated.

05

KNOWLEDGE RETURN

The test has produced error models, fatigue maps or procedural insight beyond a binary pass or fail.

Stylized human participant inside an isolation and resilience test environment
04 / HUMAN RESILIENCE

The human trial is not
another subsystem test.

Isolation, fatigue and distorted communication are examined under ethical review. Vulnerability is evidence — never expendable test material.

OUTPUTS INTO ACROS

What leaves THRIEVE
is not confidence.
It is evidence.

STRIDE

Validated subsystems, failure signatures, autonomy profiles and baseline orbital candidates.

VANTAGE

Modules prepared for thermal, radiation and mechanical exposure in later qualification.

RELAY LOGIC

First-generation communications behavior for long-latency and blackout scenarios.

FAILURE TAXONOMY

Shared definitions that embed robustness expectations across the following ACROS phases.

WHAT IT ENABLES

Evidence before architecture
moves farther away.

Validated operating assumptions

Integrated human-system requirements

Failure and recovery knowledge

A disciplined foundation for ACROS

THRIEVEACROS

What THRIEVE proves, ACROS develops into the wider CelestiQ architecture.

Return to architecture ↗