20. Control authority, autonomy, operations, and fallback state
Control is the allocation of sensing, deciding, commanding, monitoring and recovering for a named function in a named phase. Capability, legal permission, technical readiness, engagement and actual execution are separate. The same blimp can have automated…
Control is the allocation of sensing, deciding, commanding, monitoring and recovering for a named function in a named phase. Capability, legal permission, technical readiness, engagement and actual execution are separate. The same blimp can have automated attitude stabilization, remote propulsion, human mission approval and an independent onboard emergency controller at the same moment.

Authority and execution are eventful states; revocation and envelope exit can force a transition at any time.
#20.1 Controlled-function register
| Function family | Examples |
|---|---|
| Mission | accept job; plan mission; select objectives; reprioritize; terminate |
| Route / trajectory | route, path, waypoint, orbit, berth, docking corridor and transition selection |
| Tactical motion | lane/path choice, obstacle response, right of way, formation spacing and collision avoidance |
| Stabilization | attitude, trim, speed, altitude/depth, lateral/vertical stability and traction |
| Propulsion | start/stop, torque/thrust/power, direction, propulsor allocation and limits |
| Steering / attitude | directional and rotational command across wheels, surfaces, thrust, ballast or body |
| Stop / hold | brake, anchor, park, hover, loiter, station keep, safe descent and shutdown |
| Domain transition | deploy/fold, ballast/flood, launch/recover, couple/separate and mode handover |
| Energy / thermal | source selection, reserve, charging/refueling, load shed, cooling and emergency power |
| Payload / tool | arm, position, operate, release, manipulate, spray, lift, film, sample and stow |
| Perception / data | sense, record, classify, transmit, redact, retain and expose telemetry/media |
| Safety | limit, veto, emergency stop, isolate, contain, recover, evacuate and distress |
| Social / persona | draft, speak, post, reply, follow, invite, disclose synthetic media and moderate |
| Commercial | list, bid, book, quote, purchase, sell, invoice, receive revenue and reconcile |
#20.2 ControlAuthorityAssignment
| Field group | Required content |
|---|---|
| scope | function(s), phase, asset/assembly, configuration, operation, geography/domain and time interval |
| controller | human, onboard automation, remote automation, infrastructure, peer, leader, fleet agent or independent safety controller |
| authority role | observe; advise; propose; approve; limit; veto; command; override; emergency stop; configure |
| command abstraction | actuator; force/torque; rate; speed/attitude; trajectory; path; waypoint; task; goal; mission; constraints/policy |
| feedback closure | open loop; human closed; onboard closed; remote closed; infrastructure closed; distributed |
| allocation | exclusive, shared, blended, hierarchical, priority, consensus, veto or arbitration policy |
| supervision | continuous control, continuous monitoring, intermittent supervision, alert response, approval, dispatch, none |
| communications | link, direction, latency/jitter, bandwidth, availability, authentication, redundancy and loss behavior |
| operating envelope | ODD/domain definition, current-domain monitor, margins, prohibited conditions and exit detection |
| fallback | trigger, performer, response deadline, behavior, safe state, recovery path and evidence |
| authority grant | principal, purpose, rights, limits, approval requirement, budget/rate and revocation |
| implementation lock | software/model/calibration/configuration versions and safety partition |
#20.3 Functional independence vector
| Function | Meaning |
|---|---|
| Sense | Acquire raw signals or human observations |
| Perceive | Detect/classify objects, state, events, conditions or work targets |
| Localize | Estimate pose, time and uncertainty in one or more frames |
| Predict | Estimate future state, behavior, risk, wear or resource use |
| Plan | Generate routes, trajectories, task sequences, resource plans or content plans |
| Decide | Select an action under constraints and authority |
| Command | Produce a bounded setpoint, task, goal or action request |
| Actuate | Create physical/digital effect through an interface |
| Monitor | Compare expected and actual state, health, envelope and authority |
| Diagnose | Identify fault, cause, conflict, uncertainty or missing prerequisite |
| Recover | Replan, reallocate, fallback, hold, stop, return or repair |
| Coordinate | Negotiate or synchronize with people, peers, infrastructure or a fleet |
| Learn/adapt | Offline update, bounded online adaptation or open-ended learning with approval state |
| Explain/receipt | Expose inputs, policy, decision, action, result and unresolved uncertainty |
For every controlled function, allocate each step above to an actor/system and record whether it is designed, available, authorized, engaged and evidenced. This produces a comparable control vector without pretending that road, marine, aerial, space, industrial and social autonomy share one ladder.
#20.4 Handover, arbitration, and fallback events
| Event / area | Required semantics |
|---|---|
| Handover offer | offering controller, functions, current state, reason, deadline, required recipient capability |
| Readiness | recipient identity, attention/health/link state, situational context and acceptance criteria |
| Acceptance | explicit acknowledgment, functions accepted, limits, effective time and unresolved exceptions |
| Command continuity | last command, neutralization, state synchronization, double-command prevention and ownership token |
| Arbitration | priority, veto, deadlock resolution, tie-breaker, safety-controller precedence and audit log |
| Failed handover | trigger, timeout, minimum-risk behavior, alerts, escalation and recovery |
| Fallback execution | performer, safe behavior, achieved state, deviations, residual hazard and action receipt |
| Return of authority | re-entry conditions, checks, new assignment and re-engagement evidence |
#20.5 Communications dependency profiles
| Profile | Meaning | Loss-of-link requirement |
|---|---|---|
| Independent | Function does not require an external link while active | Continue within local authority and envelope |
| Optional enhancement | Link improves data or supervision but is not required | Degrade service; preserve safe function |
| Start authorization | Link required to arm/start but not continuously | No new mission/phase after authorization expires |
| Periodic lease | Authority renewed by heartbeat or lease | Grace period then named fallback |
| Continuous supervisory | Remote/infrastructure supervision required | Bounded response based on latency and safe-state feasibility |
| Remote closed loop | Human/offboard controller closes the motion or tool loop | Immediate local stabilizer/neutral/stop/hold response |
| Tethered control/power | Physical/data/energy tether is part of operation | Detect break, isolate, preserve buoyancy/landing/holding state |
| Delayed/disconnected | Space, underwater or underground link is intermittent by design | Store-and-forward plus onboard bounded autonomy and timed contingency |
#20.6 Multi-asset coordination
| Pattern | Required distinction |
|---|---|
| Dispatcher | Central service assigns jobs; each asset executes locally |
| Leader-follower | Leader provides path/state; followers retain local safety and spacing |
| Platoon/convoy | Coordinated longitudinal/lateral motion with membership and join/leave protocol |
| Parent-child | Carrier deploys, tasks, monitors and recovers a subordinate vehicle |
| Peer cooperative | Assets exchange intentions/state and negotiate tasks or collision avoidance |
| Centralized swarm | Coordinator allocates formation/tasks; local agents execute |
| Distributed swarm | Collective behavior emerges from peer/local rules; membership and rule version explicit |
| Infrastructure managed | Traffic, guideway, warehouse, launch, port or airspace system controls allocation |
| Human multi-asset | One operator supervises many assets with workload, alert and takeover limits |
#20.7 Cross-domain control examples
| Asset / phase | Function allocation | Critical boundary |
|---|---|---|
| KUN road drive | Human steering/propulsion; electronic engine/brake assistance; independent protective limits | Social agent receives read-only telemetry and no actuator authority |
| RC racer | Remote human trajectory intent; onboard stabilization and failsafe neutral/brake | Radio loss, track geofence, marshal recovery and battery state |
| Blimp cruise | Remote/supervisory mission; onboard attitude/altitude loops; ground crew for mooring | Wind envelope, lost link, lift/ballast state and recovery site |
| Underwater glider | Supervisory mission upload; onboard buoyancy/trim/navigation; intermittent acoustic/satellite contact | Depth/pressure/energy envelope and timed surface contingency |
| eVTOL passenger mission | Function-specific flight automation under certified/authorized operation | Do not infer global autonomy from one feature; diversion/landing fallback explicit |
| Warehouse swarm | Fleet scheduler assigns tasks; local navigation; infrastructure zones and human safety controller | Membership, traffic priority, e-stop and one-to-many supervision load |
| Vehicle persona | Agent drafts/replies inside canon; human or policy approves sensitive posts; transaction skills separately granted | No media, social or commerce grant crosses into physical motion control |