The Structure looked unchanged from the last undock.
Its hull remained on Grid. Docking still worked for the pilot approaching it, and the familiar inventory was visible after arrival. Nothing in the scene announced a crisis.
Inside, one promised Service was unavailable. A job expected to continue had paused. The last Fuel Observation had passed its next check without a confirmed owner, and one pilot could no longer use the Corporation storage path tested the previous week. Each change appeared small beside the visible Structure. Together they meant that Home could no longer support the work its routine still promised.
Failure often begins as divergence between appearance and capability. This chapter diagnoses neither attack nor repair and does not turn every change into an emergency. It reads observable state, follows the dependencies affected and reduces commitment before the group needs those dependencies all at once.
Degradation Has Signals
Degradation is visible when the Baseline remains specific.
Chapter 5 recorded ordinary Home through dated observations of system, Chain, infrastructure and work. Chapters 8 and 13 added owners and next checks. Those records allow a present difference to be named without relying on a general feeling that something is wrong.
The useful signal is bounded. A Service expected online is observed offline. A Structure expected in Full Power is observed in Low Power. A Shared Location expected online for a Character is no longer available. Usable reserve falls below its replacement trigger. An owner misses the check needed to support an open commitment.
These signals do not explain their own causes. Deliberate management action, insufficient support or another event can leave a Service offline. An access path may change because a role, Profile or Access List changed, or because the earlier test covered a different context. A reserve may thin through ordinary use. Cause should be observed and investigated by the person with the appropriate authority; the capability effect can be stated now.
Signals gain importance from what depends on them. An offline Service with no open or planned work may require maintenance but little immediate reduction. The same Service beneath an installed job and a promised replacement changes two commitments. A changed access path to surplus is different from a changed path to the only usable reserve. The field is read through consequence, not the size of the interface warning.
Sequence matters as much as severity. A missed observation check can leave a support condition Unknown. New work approved after that point adds commitment to uncertainty. An observed Service change then affects more material and more people than it would have affected earlier. The final visible pause may appear to be the failure, although the preventable growth occurred between the first missed check and the last new promise.
The record should therefore connect changes rather than collect isolated warnings. The missed Fuel check, later Low Power Observation and paused job form one dependency sequence. A changed Access List and failed reserve action form another. Each sequence can be reduced at its earliest still-open choice instead of waiting for a single dramatic event to explain everything.
A signal needs Source and time. “Structure failure” combines many possible states and gives the next person no test. “At 19:40, Structure management showed the required Service offline; the open job no longer has confirmed support” separates evidence from consequence. It can be checked, owned and closed.
Missing signals matter too. A Fuel check without a report is not evidence that Fuel is absent. It is evidence that support is unconfirmed. The response may still be to pause new work because the promise required a current Observation. Unknown is an operational state when the next action depends on knowing.
In the opening Structure, the paused job is not the first failure. The missed check, unavailable Service and changed access were earlier points at which the supported scope could have been reduced. Crisis begins when such signals are allowed to accumulate under an unchanged promise.
Low Power Matters
Power State describes a specific relationship between a Structure and its Services.
An Upwell Structure with at least one online Service Module is in Full Power. Without an online Service Module, it is in Low Power. These terms do not grade the competence of the Corporation and do not describe every capability the Structure may still possess. They are bounded states with operational consequences.
The first reading of Low Power is therefore factual. Confirm the state from an appropriate Source and timestamp it. Identify which Service Modules were expected online and which work depended on them. Name the maintainer or administrator who can inspect the difference. Do not infer the entire cause from the Power State alone.
The second reading concerns promises. Docking, asset visibility or some actions may remain possible while the State is Low Power. Those remaining functions do not make the offline Services available. Plans should be reduced service by service. Stop new jobs that require unsupported Industry functions, reclassify outputs that no longer have a continuous path, and tell users which specific capability has ended.
This precision avoids two bad conclusions. “Continued Structure presence” can encourage continued dependence on functions it no longer supplies. “Home is gone” can provoke unnecessary movement while useful access and time remain. The observed State supports neither statement by itself.
Prolonged lack of Fuel consumption can move an Upwell Structure beyond Low Power into Abandoned. That state removes additional abilities and changes the consequences attached to the Structure. An exact timer is unnecessary for this decision. Continued unsupported state is not static, and further delay can remove options that were present at the first Low Power Observation.
The recovery boundary established in Chapter 3 makes this progression especially important for stored value. An inventory still visible inside a degrading Structure is not a guaranteed later recovery. Reduce concentration while access, time and ownership remain available, not after the state has supplied a crisis label.
Observe Abandoned as its own bounded state. Do not infer who caused it or whether active hostile pressure exists. Link it to the functions and assets whose outcome changed, stop additional deposits and move the decision towards recovery or deliberate exit. Those actions follow the visible capability loss without entering defence doctrine.
Power State also changes the urgency of ownership. An unanswered Fuel check while Services remain online is already a support Unknown. Once no Service is online and the Structure is observed in Low Power, the difference is no longer only about a future threshold. Current functionality has changed. The owner must either restore and test the supported state or close dependent commitments.
The chapter does not set Fuel quantities or consumption schedules. Those values depend on fitted Services and current mechanics. The operational record names which Service needs support, who observes it, what work it carries and when the next check occurs. A current specialised Source supplies any necessary values at the time of action.
For the pilot at the start, Low Power does not explain why the job paused. The State tells the group that its previous claim of maintained Services is no longer current. That is enough to stop adding dependency while authorised people inspect the cause.
Services Can Vanish
A fitted Service Module is not the same as an online Service.
Service Modules provide Structure functions and consume Fuel while online. A module can remain associated with the Structure while its function is not available. A glance at the fitting or memory of the Structure’s usual purpose cannot replace observation of the Service state the work needs.
When a Service disappears from use, begin with dependent verbs. Identify jobs that cannot start and installed work that may be paused. Find output or access paths that expected the function. Revisit replacement deadlines that assumed uninterrupted support. This produces a smaller, clearer response than declaring all infrastructure failed.
Next separate users from maintainers. A user may be able to observe that a function is unavailable without possessing the right to online a module, inspect Fuel or change Structure configuration. Their report should not be discounted because they cannot repair the state. It supplies the user-path evidence. A maintainer or administrator then observes the underlying module and support state within their authority.
The handover joins the two observations. “User could not start the expected activity” describes effect. “Required Service observed offline” describes the infrastructure condition. “Fuel not yet confirmed” remains an Unknown until the appropriate person checks it. Keeping these lines separate prevents a plausible cause from being reported as fact.
Jobs require their own state. Official Structure guidance distinguishes a Service going offline, which can pause associated work, from removal of the Service or destruction of the Structure, which can cancel it. The group records what the interface shows for the actual job. Do not describe a paused job as completed, cancelled or guaranteed to resume.
If the Service returns, users retest the complete path. Online state is necessary but may not resolve changed access, input location or output ownership. After restoration, the job owner confirms what resumed and revises the expected receipt. Restoration is evidence, not a command to restore every postponed commitment at once.
If support cannot be restored within the accepted period, reduction becomes closure. Cancel or defer plans only through authorised, current procedure; move uncommitted inputs back to an honest inventory state; mark the output unavailable; and choose an alternative replacement path if one exists. This is capability management, not repair doctrine.
Access Can Change
Access is a live relationship between person, ownership and configured rules.
Structure Profiles determine offered Services, while Access Lists help determine who may use them. Corporation roles govern other actions, including specific relationships to Corporation assets and Industry. A Character’s success last week does not prove that all these relationships remain unchanged today.
The first signal of access degradation is often a failed verb. The pilot can see but not take. They can reach the Structure but not use a Service. They can open one Corporation division but not the location named in the job. Record the failed action and context before describing the person as generally lacking access.
Specificity matters because access rules can distinguish Characters, Corporations, Alliances and Everyone, with more specific entries taking precedence over more general ones. Multiple lists associated with a Service can combine. This means a broad statement such as “the Corporation is allowed” may not explain the result for a particular Character. The administrator checks the configured path; the user tests the intended action.
Access failure can reveal concentration. If one unaffected administrator can release every critical item, Home may continue for that person’s available period while appearing generally capable. The routine should name the temporary dependency and either restore a tested second path or reduce who the reserve is promised to support.
Do not solve every access problem by expanding authority. First identify the minimum verb the responsibility needs. Correct the narrow Role, Profile, Access List or ownership path through an authorised person, then test with an unimportant action. Broad permission can hide the original design error and increase the consequence of future change.
Access closure includes people who should no longer retain it. A transfer, departure or ended guest relationship should trigger review of the relevant list and shared information. Leaving old access in place because it does not currently block work preserves an unowned dependency. Chapter 15 will close these paths during deliberate exit; routine should close them whenever their purpose ends.
The failed storage action at the start is neither proof that the item vanished nor proof that every Corporation role is wrong. This remains a bounded failure of the tested path. The group protects the reserve from further commitment until that path is restored, or a smaller promise replaces it.
Reserves Reveal Fragility
Reserve is where several slow failures become visible together.
A Service pause delays output. An access change makes existing stock unusable. An ageing route delays imported replacement. A missing owner delays the next check. Each dependency may appear tolerable alone. When usable reserve reaches the agreed trigger, their combined effect becomes a capability gap with fewer easy choices.
The reserve record from Chapter 12 distinguishes usable, reserved, incoming, in-progress and unverified states. Degradation moves stock between those states before quantity reaches zero. An item behind failed access becomes unverified for the intended user. A promised output in a paused job remains in progress, not usable. Cargo waiting beyond an unsupported route remains incoming, not local reserve.
These state changes should reduce the reported capability immediately. The physical item may still exist, and the job may later resume. Neither possibility can answer today’s need. Honest reserve describes what the current people and paths can release.
Replacement horizon exposes the urgency. The next usable item may depend on a restored Service, changed permissions and a route that has not been renewed. The slowest credible path may then exceed the useful horizon of the remaining stock. The trigger has been reached even if one final item remains.
Fragility also appears when all alternatives share one condition. Several replacement jobs in the same Structure are not independent if the same Service supports them. Stock across several Corporation divisions may still depend on one Role holder. Cargo on different ships may still depend on the same ageing Connection. Count independent paths, not only separate objects.
The response begins by protecting what remains. Stop optional consumption or movement that draws on the same reserve. Confirm who can release current stock. Prioritise the capability that preserves observation, return or the ability to reduce other commitments. Begin the credible replacement path while the final usable item still allows time.
Hoarding everything is unnecessary. Surplus without a purpose can deepen Structure concentration and complicate an eventual exit. Reserve exists to support named capability through an accepted period. Material outside that purpose should be distributed, moved or released according to the group’s plan, not counted as vague reassurance.
Test the reserve during ordinary routine, not by consuming the critical item. An authorised user can confirm visibility and retrieval with an unimportant object in the same path. The owner verifies that the record points to the correct ownership context and that the replacement trigger still has a current next check. This small rehearsal exposes access and handover failure while the real reserve remains intact. It also shows whether the claimed alternative is independent or quietly depends on the same person and permission.
Reduce Before Crisis
Reduction is the decision to stop making the field harder to recover.
When signals accumulate, the tempting response is to repair everything while normal work continues. That preserves appearances and divides attention. A controlled reduction first prevents new dependencies, then closes or supports the commitments already open.
Stop new jobs under an unconfirmed Service. Keep new cargo inside an unsupported return branch. Withdraw reserve promises that rely on an untested access path. Return working ships whose purpose is no longer more important than their release. These actions preserve optionality without claiming that the underlying cause is hostile or permanent.
Next account for people and assets already committed. Who remains outside? What job is paused? Which output is expected, and which stock is inaccessible? Who can observe each condition and who can act? Assign a next check or explicitly end the promise.
Reduction follows consequence rather than convenience. Preserve the capability to observe the Chain, communicate current state, access essential reserve and close work. Optional production, surplus movement and expansion wait. The exact order belongs to the group’s purpose, but the reason for each retained function must be visible.
The smaller state needs its own Baseline. Record which Services remain available, which users have tested access, what reserve is usable and which Connections support outstanding return. Remove inactive promises from the current handover. Otherwise, the next shift may restart work from the appearance of ordinary Home rather than from the reduced reality.
If capability returns, expansion occurs one dependency at a time. Observe the Service, test the user path, confirm reserve and assign owners before opening new work. Restoration of one signal does not erase the other Unknowns that accumulated alongside it.
If capability continues to shrink, the reduction prepares the next decision. Home may need to close Services, move value or end the commitment entirely. Those are planned choices while access and time remain. Chapter 15 will follow that path. It is not a tactical evacuation under attack; it is the deliberate ending made possible by noticing failure early.
No dramatic appearance was needed in the opening scene. The combination of a paused job, Low Power state, changed access and ageing support record was enough. The group stops new work, accounts for open commitments and restores a smaller Baseline. It has prevented degraded capability from borrowing the name of Home.
Field Principle
Read failure as a change in supported capability.
Observe Power State, Service state, access paths, reserve states and ownership without inventing their cause. Full Power, Low Power and Abandoned are bounded Structure states, not general verdicts. A fitted module is not an online Service, and an existing item is not usable reserve when access has failed.
Connect every signal to the work it affects. Stop new commitment, account for what is already open, preserve observation and release paths, and establish a smaller current Baseline. Restore scope only from fresh evidence and tested access.
The calm Structure at the start had already diverged from its promises. Noticing the divergence before active hostile pressure preserved the choice to repair, reduce or leave. The next chapter takes the final option seriously and shows how Home can end without becoming an improvisation.
Early reduction does not solve every dependency. It prevents new work from claiming support that no longer exists, keeps remaining capability legible and gives authorised owners time to choose the next bounded state. That interval is the practical difference between degradation managed as evidence and failure encountered as crisis.