MARS BIBLE — ORGANISATIONS
JAXA: history, capabilities, technology and its place in Mars exploration
MMX turns Phobos into a laboratory for understanding Mars and acquiring round-trip technologies from the Martian sphere.
BEFORE MARS — HOW THE ORGANIZATION WAS BORN
Before Mars: how JAXA came into being
The present JAXA is relatively young, but its roots are much older. On October 1, 2003, Japan merged three institutions: ISAS, focused on space and planetary science; NASDA, responsible for major launch vehicles, satellites and International Space Station activities; and NAL, the country’s aerospace research laboratory.
The merger was more than an administrative change. It brought together cultures that had previously been separate: basic science, launch-vehicle development, application satellites, international human-spaceflight cooperation and aeronautical technology. The result was an organization able to follow a much broader chain from science to mission engineering.
Japan already possessed a substantial record of scientific missions before 2003. ISAS had built a culture of highly specialized exploration, while NASDA developed the heavier infrastructure required for large programs. JAXA therefore inherited a legacy that does not begin with its legal creation.
For Mars, that genealogy is especially visible in MMX, the mission to Phobos and Deimos. It combines planetary science, deep-space navigation, robotics, sample collection and return to Earth — exactly the kind of project that benefits from an agency created by merging scientific and engineering traditions.
Founding sources: JAXA — History · JAXA — Introduction
Direct answer: why JAXA matters to the story of Mars
JAXA deserves its own dossier because MMX targets launch in Japanese fiscal year 2026. [1] The goal is not to rank organizations but to understand one as a system: history, decision centers, infrastructure, technologies, successes, failures and the capabilities it contributes — directly or indirectly — to Mars exploration.
MMX turns Phobos into a laboratory for understanding Mars and acquiring round-trip technologies from the Martian sphere. This dossier separates demonstrated achievements, formally committed programs and prospective concepts. Institutional sources are preferred; where an outside assessment is used, its origin is labelled explicitly.
Essential timeline
- Hayabusa/Hayabusa2Hayabusa/Hayabusa2 sample-return heritage
- 20152015 MMX project announcement
- 20232023 JAXA/DLR/CNES cooperation
- FY2026FY2026 planned launch
- 20272027 Mars/Phobos arrival sequence
- 20282028 IDEFIX deployment
- 20292029 sample collection
- FY2031FY2031 Earth return
Understand the organisation before looking at its rockets
A space organisation is never just a logo, a launch vehicle or a spectacular mission. To understand JAXA, one must separate political goal-setting, program management, engineering centers, industrial manufacturing, science teams and mission operations. This matters especially for Mars because a successful interplanetary mission requires many chains to remain coherent for years, across institutions that do not always share the same incentives or vocabulary. In this case, one useful anchor is that MMX targets launch in Japanese fiscal year 2026. [1] Another is that the mission will observe Phobos and Deimos. [2] These are verifiable facts; by themselves they do not guarantee success of any future program.
The theme Phobos is therefore best understood as a chain of functions rather than a keyword. A useful way to make this topic reproducible is to treat it as an input-output balance. What resources enter the subsystem? How much power does it consume? What data does it produce? What heat must be rejected? What degraded mode remains after a fault? This turns technical vocabulary into a chain of verifiable decisions. This helps non-specialists see why an apparently secondary property can become mission-critical millions of kilometres from Earth.
For Mars the useful question is: what dependency does this subsystem create? Even if JAXA masters one capability, it must still interface with transportation, power, communications, navigation and science operations. Real maturity lives at that boundary between local expertise and global architecture.
Institutional schedules must also be separated from physical constraints. Announcements can move; planetary geometry, mass, power and the speed of light do not negotiate. The dossier therefore gives priority to material evidence — tests, integrated hardware, launches and returned data — where available.
Why Mars exposes the true maturity of a space program
Mars is an unforgiving maturity test. Communications are delayed, launch windows are infrequent, mass and energy margins are tight, atmospheric entry is difficult and onboard autonomy matters more than in near-Earth operations. Looking at JAXA through Mars therefore reveals not only what it announces but which capabilities it can actually integrate, test and operate. In this case, one useful anchor is that the mission will observe Phobos and Deimos. [2] Another is that it will land on Phobos and return more than 10 g of material. [3] These are verifiable facts; by themselves they do not guarantee success of any future program.
The theme Deimos is therefore best understood as a chain of functions rather than a keyword. Margin is a central engineering concept. A system is not designed only for a nominal point: it must absorb manufacturing dispersion, ageing, environmental uncertainty and imperfect models. Too little margin increases risk; excessive margin adds mass and cost. Engineering is the art of placing margin where it actually protects the mission. This helps non-specialists see why an apparently secondary property can become mission-critical millions of kilometres from Earth.
For Mars the useful question is: what dependency does this subsystem create? Even if JAXA masters one capability, it must still interface with transportation, power, communications, navigation and science operations. Real maturity lives at that boundary between local expertise and global architecture.
Institutional schedules must also be separated from physical constraints. Announcements can move; planetary geometry, mass, power and the speed of light do not negotiate. The dossier therefore gives priority to material evidence — tests, integrated hardware, launches and returned data — where available.
The technical chain from Earth to the Martian system
For the public a mission may seem to start at launch. For engineers it starts far earlier with requirements, interfaces, verification, margins, software, navigation, thermal control and communications. The theme of quasi-satellite orbit illustrates this systems view. Each subsystem has its own physics, yet a mission can still fail at the interfaces. Integration is therefore a capability in its own right. In this case, one useful anchor is that it will land on Phobos and return more than 10 g of material. [3] Another is that Earth return is planned for fiscal year 2031. [4] These are verifiable facts; by themselves they do not guarantee success of any future program.
The theme quasi-satellite orbit is therefore best understood as a chain of functions rather than a keyword. Redundancy is not automatically equivalent to safety. Two identical units may share the same software, power source or manufacturing defect. Serious analysis therefore searches for common-cause failures. On Mars this matters because a backup that fails for the same reason as the primary is not a real backup. This helps non-specialists see why an apparently secondary property can become mission-critical millions of kilometres from Earth.
For Mars the useful question is: what dependency does this subsystem create? Even if JAXA masters one capability, it must still interface with transportation, power, communications, navigation and science operations. Real maturity lives at that boundary between local expertise and global architecture.
Institutional schedules must also be separated from physical constraints. Announcements can move; planetary geometry, mass, power and the speed of light do not negotiate. The dossier therefore gives priority to material evidence — tests, integrated hardware, launches and returned data — where available.
Why failures often teach more than success releases
Space history is full of failures, anomalies and redesigns. They do not automatically diminish an organisation; they reveal whether it can learn. A failure becomes useful when its cause is understood, procedures change and the next design absorbs the lesson. On Mars, where another attempt may wait for a new planetary window, institutional learning is an engineering asset. In this case, one useful anchor is that Earth return is planned for fiscal year 2031. [4] Another is that MMX carries the IDEFIX rover developed with DLR and CNES. [1] These are verifiable facts; by themselves they do not guarantee success of any future program.
The theme sampling is therefore best understood as a chain of functions rather than a keyword. Availability depends on both reliability and repairability. A component may fail rarely yet immobilize a system for weeks; another may fail more often but be replaced in hours. For a future Mars base, diagnosis, repair and local manufacturing can therefore matter as much as initial performance. This helps non-specialists see why an apparently secondary property can become mission-critical millions of kilometres from Earth.
For Mars the useful question is: what dependency does this subsystem create? Even if JAXA masters one capability, it must still interface with transportation, power, communications, navigation and science operations. Real maturity lives at that boundary between local expertise and global architecture.
Institutional schedules must also be separated from physical constraints. Announcements can move; planetary geometry, mass, power and the speed of light do not negotiate. The dossier therefore gives priority to material evidence — tests, integrated hardware, launches and returned data — where available.
Communications: commanding a machine that is no longer “live”
At interplanetary distance the word remote control changes meaning. Light-time delay cannot be negotiated away. Spacecraft must protect themselves, wait, diagnose some conditions and execute sequences without asking Earth for permission every second. The theme of Earth return therefore combines ground antennas, radio power, coding, onboard storage, mission planning and autonomous software. In this case, one useful anchor is that MMX carries the IDEFIX rover developed with DLR and CNES. [1] Another is that JAXA frames the mission as a step toward technologies useful for future human exploration. [2] These are verifiable facts; by themselves they do not guarantee success of any future program.
The theme Earth return is therefore best understood as a chain of functions rather than a keyword. Software must be treated like physical hardware because it commands valves, engines, batteries and critical sequences. Robust architectures isolate functions, monitor inconsistent states, preserve safe modes and retain enough observability to understand automated decisions. Useful autonomy is not the absence of humans; it is the ability to remain understandable when humans cannot intervene immediately. This helps non-specialists see why an apparently secondary property can become mission-critical millions of kilometres from Earth.
For Mars the useful question is: what dependency does this subsystem create? Even if JAXA masters one capability, it must still interface with transportation, power, communications, navigation and science operations. Real maturity lives at that boundary between local expertise and global architecture.
Institutional schedules must also be separated from physical constraints. Announcements can move; planetary geometry, mass, power and the speed of light do not negotiate. The dossier therefore gives priority to material evidence — tests, integrated hardware, launches and returned data — where available.
Why mass governs almost everything
Every kilogram sent to Mars propagates through the design: structure, propulsion, thermal needs, power, atmospheric entry and surface logistics. Mass discipline is not simply about making hardware light; it is about knowing where an extra kilogram buys robustness or science. The architectures of JAXA can therefore be read as repeated trades among mass, energy, risk, cost and schedule. In this case, one useful anchor is that JAXA frames the mission as a step toward technologies useful for future human exploration. [2] Another is that MMX targets launch in Japanese fiscal year 2026. [3] These are verifiable facts; by themselves they do not guarantee success of any future program.
The theme IDEFIX is therefore best understood as a chain of functions rather than a keyword. A useful way to make this topic reproducible is to treat it as an input-output balance. What resources enter the subsystem? How much power does it consume? What data does it produce? What heat must be rejected? What degraded mode remains after a fault? This turns technical vocabulary into a chain of verifiable decisions. This helps non-specialists see why an apparently secondary property can become mission-critical millions of kilometres from Earth.
For Mars the useful question is: what dependency does this subsystem create? Even if JAXA masters one capability, it must still interface with transportation, power, communications, navigation and science operations. Real maturity lives at that boundary between local expertise and global architecture.
Institutional schedules must also be separated from physical constraints. Announcements can move; planetary geometry, mass, power and the speed of light do not negotiate. The dossier therefore gives priority to material evidence — tests, integrated hardware, launches and returned data — where available.
Science and engineering must learn each other’s language
A science instrument may demand stability, temperature control or viewing geometry that complicates the spacecraft. A systems team may simplify the vehicle so aggressively that scientific value is lost. Strong missions make these communities converge early. The theme of microgravity shows how a scientific question becomes a requirement, an instrument, an interface, an operations sequence and finally interpretable data. In this case, one useful anchor is that MMX targets launch in Japanese fiscal year 2026. [3] Another is that the mission will observe Phobos and Deimos. [4] These are verifiable facts; by themselves they do not guarantee success of any future program.
The theme microgravity is therefore best understood as a chain of functions rather than a keyword. Margin is a central engineering concept. A system is not designed only for a nominal point: it must absorb manufacturing dispersion, ageing, environmental uncertainty and imperfect models. Too little margin increases risk; excessive margin adds mass and cost. Engineering is the art of placing margin where it actually protects the mission. This helps non-specialists see why an apparently secondary property can become mission-critical millions of kilometres from Earth.
For Mars the useful question is: what dependency does this subsystem create? Even if JAXA masters one capability, it must still interface with transportation, power, communications, navigation and science operations. Real maturity lives at that boundary between local expertise and global architecture.
Institutional schedules must also be separated from physical constraints. Announcements can move; planetary geometry, mass, power and the speed of light do not negotiate. The dossier therefore gives priority to material evidence — tests, integrated hardware, launches and returned data — where available.
From one-off missions to infrastructure
A program becomes more powerful when it stops rebuilding every capability from zero. Reusable software, standards, test facilities, ground networks, teams and interfaces lower the cognitive cost of the next mission. This is why the history of JAXA is more interesting than a list of launches: the key question is which capabilities persist across generations. In this case, one useful anchor is that the mission will observe Phobos and Deimos. [4] Another is that it will land on Phobos and return more than 10 g of material. [1] These are verifiable facts; by themselves they do not guarantee success of any future program.
The theme deep-space communications is therefore best understood as a chain of functions rather than a keyword. Redundancy is not automatically equivalent to safety. Two identical units may share the same software, power source or manufacturing defect. Serious analysis therefore searches for common-cause failures. On Mars this matters because a backup that fails for the same reason as the primary is not a real backup. This helps non-specialists see why an apparently secondary property can become mission-critical millions of kilometres from Earth.
For Mars the useful question is: what dependency does this subsystem create? Even if JAXA masters one capability, it must still interface with transportation, power, communications, navigation and science operations. Real maturity lives at that boundary between local expertise and global architecture.
Institutional schedules must also be separated from physical constraints. Announcements can move; planetary geometry, mass, power and the speed of light do not negotiate. The dossier therefore gives priority to material evidence — tests, integrated hardware, launches and returned data — where available.
Partners: autonomy does not mean isolation
Even major space powers depend on partners for instruments, ground stations, launch services, laboratories, components or science expertise. Cooperation can accelerate a mission but also creates dependencies. A Mars architecture therefore needs to decide what may be shared, what should be redundant and which strategic capabilities an actor wants to control directly. In this case, one useful anchor is that it will land on Phobos and return more than 10 g of material. [1] Another is that Earth return is planned for fiscal year 2031. [2] These are verifiable facts; by themselves they do not guarantee success of any future program.
The theme planetary protection is therefore best understood as a chain of functions rather than a keyword. Availability depends on both reliability and repairability. A component may fail rarely yet immobilize a system for weeks; another may fail more often but be replaced in hours. For a future Mars base, diagnosis, repair and local manufacturing can therefore matter as much as initial performance. This helps non-specialists see why an apparently secondary property can become mission-critical millions of kilometres from Earth.
For Mars the useful question is: what dependency does this subsystem create? Even if JAXA masters one capability, it must still interface with transportation, power, communications, navigation and science operations. Real maturity lives at that boundary between local expertise and global architecture.
Institutional schedules must also be separated from physical constraints. Announcements can move; planetary geometry, mass, power and the speed of light do not negotiate. The dossier therefore gives priority to material evidence — tests, integrated hardware, launches and returned data — where available.
Technical data explained in plain language
A technical number matters only if its consequence is understood. Thrust tells us how much mass can be accelerated; electrical power determines what computers and instruments can do; data rate constrains how many images and spectra can be returned; navigation accuracy shapes the arrival corridor. This dossier keeps sourced numbers but always links them to mission consequences. In this case, one useful anchor is that Earth return is planned for fiscal year 2031. [2] Another is that MMX carries the IDEFIX rover developed with DLR and CNES. [3] These are verifiable facts; by themselves they do not guarantee success of any future program.
The theme human-exploration technologies is therefore best understood as a chain of functions rather than a keyword. Software must be treated like physical hardware because it commands valves, engines, batteries and critical sequences. Robust architectures isolate functions, monitor inconsistent states, preserve safe modes and retain enough observability to understand automated decisions. Useful autonomy is not the absence of humans; it is the ability to remain understandable when humans cannot intervene immediately. This helps non-specialists see why an apparently secondary property can become mission-critical millions of kilometres from Earth.
For Mars the useful question is: what dependency does this subsystem create? Even if JAXA masters one capability, it must still interface with transportation, power, communications, navigation and science operations. Real maturity lives at that boundary between local expertise and global architecture.
Institutional schedules must also be separated from physical constraints. Announcements can move; planetary geometry, mass, power and the speed of light do not negotiate. The dossier therefore gives priority to material evidence — tests, integrated hardware, launches and returned data — where available.
Maturity: demonstrated, qualified, planned or merely studied
Space programs use words that may sound similar but are not equivalent. A studied technology is not built hardware; a ground prototype is not flight-qualified equipment; an approved mission is not a launched mission. For JAXA, this dossier separates achievements, committed programs, announced schedules and prospective concepts so that ambition is not silently converted into fact. In this case, one useful anchor is that MMX carries the IDEFIX rover developed with DLR and CNES. [3] Another is that JAXA frames the mission as a step toward technologies useful for future human exploration. [4] These are verifiable facts; by themselves they do not guarantee success of any future program.
The theme Phobos is therefore best understood as a chain of functions rather than a keyword. A useful way to make this topic reproducible is to treat it as an input-output balance. What resources enter the subsystem? How much power does it consume? What data does it produce? What heat must be rejected? What degraded mode remains after a fault? This turns technical vocabulary into a chain of verifiable decisions. This helps non-specialists see why an apparently secondary property can become mission-critical millions of kilometres from Earth.
For Mars the useful question is: what dependency does this subsystem create? Even if JAXA masters one capability, it must still interface with transportation, power, communications, navigation and science operations. Real maturity lives at that boundary between local expertise and global architecture.
Institutional schedules must also be separated from physical constraints. Announcements can move; planetary geometry, mass, power and the speed of light do not negotiate. The dossier therefore gives priority to material evidence — tests, integrated hardware, launches and returned data — where available.
What this organisation contributes specifically to Mars
The Mars relevance of JAXA is better measured through transferable capabilities — Deimos, deep-space navigation, autonomy, sample return, surface operations, instrumentation or transportation — than by counting how often the word Mars appears in public messaging. An organisation can matter greatly to Mars without currently running a human settlement program. In this case, one useful anchor is that JAXA frames the mission as a step toward technologies useful for future human exploration. [4] Another is that MMX targets launch in Japanese fiscal year 2026. [1] These are verifiable facts; by themselves they do not guarantee success of any future program.
The theme Deimos is therefore best understood as a chain of functions rather than a keyword. Margin is a central engineering concept. A system is not designed only for a nominal point: it must absorb manufacturing dispersion, ageing, environmental uncertainty and imperfect models. Too little margin increases risk; excessive margin adds mass and cost. Engineering is the art of placing margin where it actually protects the mission. This helps non-specialists see why an apparently secondary property can become mission-critical millions of kilometres from Earth.
For Mars the useful question is: what dependency does this subsystem create? Even if JAXA masters one capability, it must still interface with transportation, power, communications, navigation and science operations. Real maturity lives at that boundary between local expertise and global architecture.
Institutional schedules must also be separated from physical constraints. Announcements can move; planetary geometry, mass, power and the speed of light do not negotiate. The dossier therefore gives priority to material evidence — tests, integrated hardware, launches and returned data — where available.
The people behind the systems
Vehicles are visible; organizations are less so. Behind every mission stand design teams, quality engineers, operators, scientists and specialists in software, propulsion, materials and communications. Much of their job is to make the extraordinary repeatable: turn intuition into requirements, a one-time sequence into procedure and an anomaly into a design rule. In this case, one useful anchor is that MMX targets launch in Japanese fiscal year 2026. [1] Another is that the mission will observe Phobos and Deimos. [2] These are verifiable facts; by themselves they do not guarantee success of any future program.
The theme quasi-satellite orbit is therefore best understood as a chain of functions rather than a keyword. Redundancy is not automatically equivalent to safety. Two identical units may share the same software, power source or manufacturing defect. Serious analysis therefore searches for common-cause failures. On Mars this matters because a backup that fails for the same reason as the primary is not a real backup. This helps non-specialists see why an apparently secondary property can become mission-critical millions of kilometres from Earth.
For Mars the useful question is: what dependency does this subsystem create? Even if JAXA masters one capability, it must still interface with transportation, power, communications, navigation and science operations. Real maturity lives at that boundary between local expertise and global architecture.
Institutional schedules must also be separated from physical constraints. Announcements can move; planetary geometry, mass, power and the speed of light do not negotiate. The dossier therefore gives priority to material evidence — tests, integrated hardware, launches and returned data — where available.
What to watch over the next decade
To follow JAXA, it is more useful to watch funded missions, hardware entering integration, system tests, launch contracts, planetary windows and qualification of critical elements than to count distant announcements. Dates may move; physical hardware and verification campaigns usually provide a stronger signal of real progress. In this case, one useful anchor is that the mission will observe Phobos and Deimos. [2] Another is that it will land on Phobos and return more than 10 g of material. [3] These are verifiable facts; by themselves they do not guarantee success of any future program.
The theme sampling is therefore best understood as a chain of functions rather than a keyword. Availability depends on both reliability and repairability. A component may fail rarely yet immobilize a system for weeks; another may fail more often but be replaced in hours. For a future Mars base, diagnosis, repair and local manufacturing can therefore matter as much as initial performance. This helps non-specialists see why an apparently secondary property can become mission-critical millions of kilometres from Earth.
For Mars the useful question is: what dependency does this subsystem create? Even if JAXA masters one capability, it must still interface with transportation, power, communications, navigation and science operations. Real maturity lives at that boundary between local expertise and global architecture.
Institutional schedules must also be separated from physical constraints. Announcements can move; planetary geometry, mass, power and the speed of light do not negotiate. The dossier therefore gives priority to material evidence — tests, integrated hardware, launches and returned data — where available.
Mars as a system of systems
A Mars settlement would not be one large science mission. It would be a network of transportation, energy, habitats, health, communications, local production, mobility and maintenance. The theme of Earth return is therefore one node in a larger architecture. Studying JAXA helps reveal which nodes are already mature, which are developing and which still depend on other actors. In this case, one useful anchor is that it will land on Phobos and return more than 10 g of material. [3] Another is that Earth return is planned for fiscal year 2031. [4] These are verifiable facts; by themselves they do not guarantee success of any future program.
The theme Earth return is therefore best understood as a chain of functions rather than a keyword. Software must be treated like physical hardware because it commands valves, engines, batteries and critical sequences. Robust architectures isolate functions, monitor inconsistent states, preserve safe modes and retain enough observability to understand automated decisions. Useful autonomy is not the absence of humans; it is the ability to remain understandable when humans cannot intervene immediately. This helps non-specialists see why an apparently secondary property can become mission-critical millions of kilometres from Earth.
For Mars the useful question is: what dependency does this subsystem create? Even if JAXA masters one capability, it must still interface with transportation, power, communications, navigation and science operations. Real maturity lives at that boundary between local expertise and global architecture.
Institutional schedules must also be separated from physical constraints. Announcements can move; planetary geometry, mass, power and the speed of light do not negotiate. The dossier therefore gives priority to material evidence — tests, integrated hardware, launches and returned data — where available.
What a non-specialist should retain
One does not need to be an engineer to read a space architecture. Three questions go a long way: what must work, how long must it work without rescue, and what happens when one element fails? Applied to JAXA, these questions separate institutional messaging from operational reality without falling into cynicism. Space exploration is difficult precisely because thousands of constraints must become one coherent system. In this case, one useful anchor is that Earth return is planned for fiscal year 2031. [4] Another is that MMX carries the IDEFIX rover developed with DLR and CNES. [1] These are verifiable facts; by themselves they do not guarantee success of any future program.
The theme IDEFIX is therefore best understood as a chain of functions rather than a keyword. A useful way to make this topic reproducible is to treat it as an input-output balance. What resources enter the subsystem? How much power does it consume? What data does it produce? What heat must be rejected? What degraded mode remains after a fault? This turns technical vocabulary into a chain of verifiable decisions. This helps non-specialists see why an apparently secondary property can become mission-critical millions of kilometres from Earth.
For Mars the useful question is: what dependency does this subsystem create? Even if JAXA masters one capability, it must still interface with transportation, power, communications, navigation and science operations. Real maturity lives at that boundary between local expertise and global architecture.
Institutional schedules must also be separated from physical constraints. Announcements can move; planetary geometry, mass, power and the speed of light do not negotiate. The dossier therefore gives priority to material evidence — tests, integrated hardware, launches and returned data — where available.
Technical appendix 1 — reading IDEFIX as an architecture of capabilities
This appendix returns to IDEFIX to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that it will land on Phobos and return more than 10 g of material provides a documented starting point. [1]
Margin is a central engineering concept. A system is not designed only for a nominal point: it must absorb manufacturing dispersion, ageing, environmental uncertainty and imperfect models. Too little margin increases risk; excessive margin adds mass and cost. Engineering is the art of placing margin where it actually protects the mission.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 2 — reading microgravity as an architecture of capabilities
This appendix returns to microgravity to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that Earth return is planned for fiscal year 2031 provides a documented starting point. [2]
Redundancy is not automatically equivalent to safety. Two identical units may share the same software, power source or manufacturing defect. Serious analysis therefore searches for common-cause failures. On Mars this matters because a backup that fails for the same reason as the primary is not a real backup.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 3 — reading deep-space communications as an architecture of capabilities
This appendix returns to deep-space communications to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that MMX carries the IDEFIX rover developed with DLR and CNES provides a documented starting point. [3]
Availability depends on both reliability and repairability. A component may fail rarely yet immobilize a system for weeks; another may fail more often but be replaced in hours. For a future Mars base, diagnosis, repair and local manufacturing can therefore matter as much as initial performance.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 4 — reading planetary protection as an architecture of capabilities
This appendix returns to planetary protection to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that JAXA frames the mission as a step toward technologies useful for future human exploration provides a documented starting point. [4]
Software must be treated like physical hardware because it commands valves, engines, batteries and critical sequences. Robust architectures isolate functions, monitor inconsistent states, preserve safe modes and retain enough observability to understand automated decisions. Useful autonomy is not the absence of humans; it is the ability to remain understandable when humans cannot intervene immediately.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 5 — reading human-exploration technologies as an architecture of capabilities
This appendix returns to human-exploration technologies to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that MMX targets launch in Japanese fiscal year 2026 provides a documented starting point. [1]
A useful way to make this topic reproducible is to treat it as an input-output balance. What resources enter the subsystem? How much power does it consume? What data does it produce? What heat must be rejected? What degraded mode remains after a fault? This turns technical vocabulary into a chain of verifiable decisions.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 6 — reading Phobos as an architecture of capabilities
This appendix returns to Phobos to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that the mission will observe Phobos and Deimos provides a documented starting point. [2]
Margin is a central engineering concept. A system is not designed only for a nominal point: it must absorb manufacturing dispersion, ageing, environmental uncertainty and imperfect models. Too little margin increases risk; excessive margin adds mass and cost. Engineering is the art of placing margin where it actually protects the mission.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 7 — reading Deimos as an architecture of capabilities
This appendix returns to Deimos to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that it will land on Phobos and return more than 10 g of material provides a documented starting point. [3]
Redundancy is not automatically equivalent to safety. Two identical units may share the same software, power source or manufacturing defect. Serious analysis therefore searches for common-cause failures. On Mars this matters because a backup that fails for the same reason as the primary is not a real backup.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 8 — reading quasi-satellite orbit as an architecture of capabilities
This appendix returns to quasi-satellite orbit to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that Earth return is planned for fiscal year 2031 provides a documented starting point. [4]
Availability depends on both reliability and repairability. A component may fail rarely yet immobilize a system for weeks; another may fail more often but be replaced in hours. For a future Mars base, diagnosis, repair and local manufacturing can therefore matter as much as initial performance.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 9 — reading sampling as an architecture of capabilities
This appendix returns to sampling to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that MMX carries the IDEFIX rover developed with DLR and CNES provides a documented starting point. [1]
Software must be treated like physical hardware because it commands valves, engines, batteries and critical sequences. Robust architectures isolate functions, monitor inconsistent states, preserve safe modes and retain enough observability to understand automated decisions. Useful autonomy is not the absence of humans; it is the ability to remain understandable when humans cannot intervene immediately.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 10 — reading Earth return as an architecture of capabilities
This appendix returns to Earth return to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that JAXA frames the mission as a step toward technologies useful for future human exploration provides a documented starting point. [2]
A useful way to make this topic reproducible is to treat it as an input-output balance. What resources enter the subsystem? How much power does it consume? What data does it produce? What heat must be rejected? What degraded mode remains after a fault? This turns technical vocabulary into a chain of verifiable decisions.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 11 — reading IDEFIX as an architecture of capabilities
This appendix returns to IDEFIX to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that MMX targets launch in Japanese fiscal year 2026 provides a documented starting point. [3]
Margin is a central engineering concept. A system is not designed only for a nominal point: it must absorb manufacturing dispersion, ageing, environmental uncertainty and imperfect models. Too little margin increases risk; excessive margin adds mass and cost. Engineering is the art of placing margin where it actually protects the mission.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 12 — reading microgravity as an architecture of capabilities
This appendix returns to microgravity to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that the mission will observe Phobos and Deimos provides a documented starting point. [4]
Redundancy is not automatically equivalent to safety. Two identical units may share the same software, power source or manufacturing defect. Serious analysis therefore searches for common-cause failures. On Mars this matters because a backup that fails for the same reason as the primary is not a real backup.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 13 — reading deep-space communications as an architecture of capabilities
This appendix returns to deep-space communications to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that it will land on Phobos and return more than 10 g of material provides a documented starting point. [1]
Availability depends on both reliability and repairability. A component may fail rarely yet immobilize a system for weeks; another may fail more often but be replaced in hours. For a future Mars base, diagnosis, repair and local manufacturing can therefore matter as much as initial performance.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 14 — reading planetary protection as an architecture of capabilities
This appendix returns to planetary protection to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that Earth return is planned for fiscal year 2031 provides a documented starting point. [2]
Software must be treated like physical hardware because it commands valves, engines, batteries and critical sequences. Robust architectures isolate functions, monitor inconsistent states, preserve safe modes and retain enough observability to understand automated decisions. Useful autonomy is not the absence of humans; it is the ability to remain understandable when humans cannot intervene immediately.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 15 — reading human-exploration technologies as an architecture of capabilities
This appendix returns to human-exploration technologies to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that MMX carries the IDEFIX rover developed with DLR and CNES provides a documented starting point. [3]
A useful way to make this topic reproducible is to treat it as an input-output balance. What resources enter the subsystem? How much power does it consume? What data does it produce? What heat must be rejected? What degraded mode remains after a fault? This turns technical vocabulary into a chain of verifiable decisions.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 16 — reading Phobos as an architecture of capabilities
This appendix returns to Phobos to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that JAXA frames the mission as a step toward technologies useful for future human exploration provides a documented starting point. [4]
Margin is a central engineering concept. A system is not designed only for a nominal point: it must absorb manufacturing dispersion, ageing, environmental uncertainty and imperfect models. Too little margin increases risk; excessive margin adds mass and cost. Engineering is the art of placing margin where it actually protects the mission.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 17 — reading Deimos as an architecture of capabilities
This appendix returns to Deimos to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that MMX targets launch in Japanese fiscal year 2026 provides a documented starting point. [1]
Redundancy is not automatically equivalent to safety. Two identical units may share the same software, power source or manufacturing defect. Serious analysis therefore searches for common-cause failures. On Mars this matters because a backup that fails for the same reason as the primary is not a real backup.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 18 — reading quasi-satellite orbit as an architecture of capabilities
This appendix returns to quasi-satellite orbit to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that the mission will observe Phobos and Deimos provides a documented starting point. [2]
Availability depends on both reliability and repairability. A component may fail rarely yet immobilize a system for weeks; another may fail more often but be replaced in hours. For a future Mars base, diagnosis, repair and local manufacturing can therefore matter as much as initial performance.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 19 — reading sampling as an architecture of capabilities
This appendix returns to sampling to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that it will land on Phobos and return more than 10 g of material provides a documented starting point. [3]
Software must be treated like physical hardware because it commands valves, engines, batteries and critical sequences. Robust architectures isolate functions, monitor inconsistent states, preserve safe modes and retain enough observability to understand automated decisions. Useful autonomy is not the absence of humans; it is the ability to remain understandable when humans cannot intervene immediately.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 20 — reading Earth return as an architecture of capabilities
This appendix returns to Earth return to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that Earth return is planned for fiscal year 2031 provides a documented starting point. [4]
A useful way to make this topic reproducible is to treat it as an input-output balance. What resources enter the subsystem? How much power does it consume? What data does it produce? What heat must be rejected? What degraded mode remains after a fault? This turns technical vocabulary into a chain of verifiable decisions.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 21 — reading IDEFIX as an architecture of capabilities
This appendix returns to IDEFIX to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that MMX carries the IDEFIX rover developed with DLR and CNES provides a documented starting point. [1]
Margin is a central engineering concept. A system is not designed only for a nominal point: it must absorb manufacturing dispersion, ageing, environmental uncertainty and imperfect models. Too little margin increases risk; excessive margin adds mass and cost. Engineering is the art of placing margin where it actually protects the mission.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 22 — reading microgravity as an architecture of capabilities
This appendix returns to microgravity to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that JAXA frames the mission as a step toward technologies useful for future human exploration provides a documented starting point. [2]
Redundancy is not automatically equivalent to safety. Two identical units may share the same software, power source or manufacturing defect. Serious analysis therefore searches for common-cause failures. On Mars this matters because a backup that fails for the same reason as the primary is not a real backup.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 23 — reading deep-space communications as an architecture of capabilities
This appendix returns to deep-space communications to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that MMX targets launch in Japanese fiscal year 2026 provides a documented starting point. [3]
Availability depends on both reliability and repairability. A component may fail rarely yet immobilize a system for weeks; another may fail more often but be replaced in hours. For a future Mars base, diagnosis, repair and local manufacturing can therefore matter as much as initial performance.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Technical appendix 24 — reading planetary protection as an architecture of capabilities
This appendix returns to planetary protection to avoid a common mistake: confusing the existence of a piece of hardware with a durable capability. A capability requires hardware, software, procedures, trained operators, logistics, test facilities and a decision chain. For JAXA, the fact that the mission will observe Phobos and Deimos provides a documented starting point. [4]
Software must be treated like physical hardware because it commands valves, engines, batteries and critical sequences. Robust architectures isolate functions, monitor inconsistent states, preserve safe modes and retain enough observability to understand automated decisions. Useful autonomy is not the absence of humans; it is the ability to remain understandable when humans cannot intervene immediately.
From a Mars perspective the next question is repeatability. A single success proves that one sequence can work; it does not yet prove that it can be repeated at high cadence, repaired locally or integrated into permanent human presence. Moving from missions to infrastructure means turning tacit team knowledge into standards, interfaces, documentation and industrial means.
Robustness can be tested mentally with three scenarios: loss of a resource, delayed communication and an unavailable component. If the architecture still provides a minimum function under all three, it begins to look operational. If not, it remains dependent on a fragile nominal case. This is not a score assigned to JAXA; it is a teaching tool for reading public programs without over-interpreting them.
Primary and institutional sources
External links open in a new tab. For schedules that may change, the most recent official source takes precedence.
