DELTA-SIERRAMARSEXPLORE · UNDERSTAND · SETTLE
Support my work
MODULE 27 · ADVANCED MARS CURRICULUM · UNDERSTAND, CALCULATE, VERIFY.

Advanced ECLSS: closed loops, quality and degraded modes

Before starting — Prerequisites: modules 00 to 22 as relevant. Every important symbol is defined at first use.

Mastery objectives

  • explain quantities, units and assumptions
  • repeat at least one calculation by hand
  • identify uncertainty, limits and failure modes
  • turn the result into a decision for a Mars architecture

1. Closing a loop does not mean 100 percent recovery

Life-support systems recover a fraction of water, oxygen or nutrients. Even small losses accumulate and must be replaced by storage or local production.

Efficiency only becomes meaningful when linked to daily flow and mission duration.

2. Water has multiple streams and quality requirements

Urine, humidity condensate, hygiene water and process streams contain different contaminants. Keeping them separate can simplify treatment.

High throughput is not success unless product water meets quality requirements.

3. Air combines oxygen, CO₂ removal and trace contaminants

Atmospheric control requires oxygen supply, carbon dioxide removal, ventilation, filtration and trace-contaminant monitoring.

A safe cabin average can hide a dangerous local pocket if ventilation is poor.

4. Degraded modes and reserves

A robust ECLSS defines what happens when a water processor, sorbent bed or electrolyser is unavailable. Reserves buy time but do not replace repair.

Time-to-criticality after a failure is as important as nominal efficiency.

5. From ISS to Mars autonomy

ISS can receive logistics far more frequently than Mars. A Mars base needs deeper diagnostics, spares, cleaning and refurbishment capability.

Closed-loop design is ultimately about slowing residual dependence enough to survive between transport windows.

6. Closing a loop does not eliminate losses

A 98% recovery rate sounds nearly perfect, but a 2% daily loss becomes substantial over a long mission. Water, oxygen and waste loops therefore need explicit mass balances. Maintenance flushes, samples and inventory temporarily trapped inside equipment also matter. Any claimed closure percentage should state the system boundary to which it applies.

7. Water quality: recovery and potability are different functions

Recovering water does not mean it is immediately potable. Filtration, adsorption, catalytic oxidation, conductivity monitoring and disinfection address different contaminants. Sensors can detect some drift, while periodic analysis is still needed for microbiology and chemistry. A robust loop also defines what happens to out-of-specification water: reprocess it, isolate it or redirect it to a non-potable use according to diagnosis.

8. Degraded mode: survive while the loop is open

Maintainability requires the ability to isolate a pump, filter bed or reactor without instantly losing the entire function. Buffer tanks, bypasses, consumables and manual procedures create time to diagnose. The key metric is therefore not only nominal efficiency but the time for which the crew can preserve water, oxygen and carbon-dioxide control after a defined failure.

Closed-loop case: high recovery does not remove stored reserve

A 98 percent water recovery rate looks almost complete, but a settlement continuously loses the remaining fraction and must survive maintenance outages. Buffer inventory covers both normal losses and a credible treatment downtime. A closed loop is therefore a low-loss loop, not a machine that creates matter. Water, oxygen and consumable reserves buy operators time to diagnose a failure before it becomes immediately life-threatening.

9. Worked example step by step

A teaching comparison starts from the same daily process flow but asks how a few percentage points of recovery change long-duration logistics. The complete make-up calculation is developed in the “Daily verified make-up requirement for a closed water loop” mini-lesson below, including the distinction between theoretical recovery and verified qualified output.

10. Progressive exercise

For six people, build a daily balance including drinking, food preparation, hygiene and metabolic water. Choose a recovery rate and calculate makeup over 900 days. Then inject a 72 h failure of the primary processor and size the required buffer.

11. Reasoned solution

A reserve can look enormous against a small steady make-up loss and simultaneously look very small against a complete recovery failure. Use the make-up formula below for the steady-loss case, then recalculate the failure case from full essential demand; the two horizons answer different operational questions and must not be mixed.

12. Validation mini-project

Create a complete water-loop architecture: sources, collection, treatment, sensors, disinfection, storage, waste streams, degraded mode, maintenance, consumables and the decision protocol for out-of-specification water.

Closed-loop control laboratory — design for quality, reserve and recoverability

This closed-loop-systems extension connects balances, sensors, buffers, verified recovery, fault isolation and restart evidence so the learner can distinguish nominal closure from a system that is actually recoverable.

Close mass balances with explicit losses

A recovery percentage is meaningful only when the input stream and time basis are defined. Every loop has losses, purge flows, retained mass and maintenance events. Track those explicitly. A claimed 98% recovery rate does not mean only 2% makeup forever unless the same boundary and operating state are maintained.

Separate recovery from potability or breathability

Recovering water or air components is not the same as meeting a quality specification. Treatment, monitoring and release criteria are independent functions. A system can produce the required quantity while failing chemistry or microbiological acceptance. Buffer tanks and isolation valves are valuable because they allow production to be tested before it mixes with verified inventory.

Use buffers to buy diagnostic time

Stored water, oxygen and sorbent capacity turn repair time into a manageable variable. The buffer must be sized against essential demand and realistic isolation/repair/retest time, not average nominal operation alone. If a repair requires twenty hours but the safe buffer lasts twelve, the architecture is already in deficit before the failure occurs.

Control humidity and trace contaminants as coupled loads

Crew, plants, cooking, hygiene and equipment all add moisture and contaminants. Condensate recovery can support the water loop, but contamination control and microbial growth must be managed. Air processing is therefore a coupled mass-transfer and quality problem rather than a single carbon-dioxide-removal function.

Plan degraded manual operation before it is needed

Automatic control may fail through sensors, software, valves or power. Define which parameters can be monitored manually, which valves can be positioned safely, how often samples are required and how long the crew can sustain the workload. Manual operation should be rehearsed and documented because emergency improvisation creates new common-cause risk.

Restart through staged verification

After maintenance, prove local function before reconnecting the entire loop. Confirm sensor agreement, leak tightness, quality criteria and stable trends. If possible, route output to a quarantine or test volume first. A staged restart protects the rest of the habitat from a repair that is mechanically complete but chemically or biologically unverified.

Progressive mastery drills — eight linked checks

Drill 1 — Dynamic mass balance

Write inputs, outputs, stored inventory and losses for one loop over a defined time interval.

Expected reasoning for “Drill 1 — Dynamic mass balance”: state the evidence, the assumption, the uncertainty and the operational consequence; a label or definition alone is not a complete answer.

Drill 2 — Oxygen loop

Separate generation rate, cabin demand, stored reserve and release criteria.

Expected reasoning for “Drill 2 — Oxygen loop”: state the evidence, the assumption, the uncertainty and the operational consequence; a label or definition alone is not a complete answer.

Drill 3 — CO2 removal

Identify capacity, breakthrough or saturation indicators and the degraded alternative.

Expected reasoning for “Drill 3 — CO2 removal”: state the evidence, the assumption, the uncertainty and the operational consequence; a label or definition alone is not a complete answer.

Drill 4 — Water recovery

Separate recovery percentage from potable-water acceptance.

Expected reasoning for “Drill 4 — Water recovery”: state the evidence, the assumption, the uncertainty and the operational consequence; a label or definition alone is not a complete answer.

Drill 5 — Humidity and condensate

Trace moisture from cabin generation to collection, treatment and verified storage.

Expected reasoning for “Drill 5 — Humidity and condensate”: state the evidence, the assumption, the uncertainty and the operational consequence; a label or definition alone is not a complete answer.

Drill 6 — Trace contaminants

Identify monitoring, filtration and the action when measurement confidence is lost.

Expected reasoning for “Drill 6 — Trace contaminants”: state the evidence, the assumption, the uncertainty and the operational consequence; a label or definition alone is not a complete answer.

Drill 7 — Sensors and actuators

Show how a failed sensor can create a control failure even when the process hardware is healthy.

Expected reasoning for “Drill 7 — Sensors and actuators”: state the evidence, the assumption, the uncertainty and the operational consequence; a label or definition alone is not a complete answer.

Drill 8 — Buffers and autonomy

Calculate or estimate how stored reserve converts repair time into survivable time.

Expected reasoning for “Drill 8 — Buffers and autonomy”: state the evidence, the assumption, the uncertainty and the operational consequence; a label or definition alone is not a complete answer.

Integrated exercise — Eight-step ECLSS closure drill

Prepare a worked checklist for dynamic mass balance, oxygen generation, carbon-dioxide removal, water recovery, humidity/condensate, contaminants/filtration, sensors/actuators/control and buffer inventory. For each function, state the normal measurement, one failure indicator and the degraded-mode action.

Reasoned solution. A passing answer shows how the eight functions interact. It should include at least one case where quantity is acceptable but quality is not, and one case where a buffer gives the crew time to isolate, repair and verify before the reserve reaches its protected minimum.

Primary sources for this section. NASA — ISS water recovery milestone NASA — Environmental Control and Life Support System (ECLSS) NASA-STD-3001 Volume 2 — Human factors, habitability and environmental health. Use these references to verify the assumptions, limits and values that apply to the mission context.

Quantitative practice laboratory — close the life-support loops numerically

These ten mini-lessons reproduce the FR calculation competencies for dynamic mass balance, gas production and removal, water recovery, condensation, filtration, control, autonomy, spares and limiting system margin; the existing water make-up lesson remains as an additional integrative calculation.

Dynamic mass balance — account for every pathway

dM/dt = In - Out + Production - Consumption
1 — Concrete question

For Dynamic mass balance — account for every pathway, how does dM/dt = In - Out + Production - Consumption inform tracking a reservoir in a closed-loop life-support system and the operational choice “Use signed mass balances to detect slow inventory drift before a tank alarm becomes the first evidence.”?

2 — Intuition without symbols

Intuition. A life-support reservoir changes because material enters, leaves, is generated, is consumed and may be lost. A trustworthy balance accounts for every important pathway instead of looking only at the tank level.

3 — Quantities first
In and Out are transfer rates; Production and Consumption are internal source/sink rates; dM/dt is net inventory change rate.
4 — Formula
dM/dt = In - Out + Production - Consumption
5 — Read aloud
“d M by d t equals In minus Out plus Production minus Consumption.”
6 — Symbols

Symbol map for Dynamic mass balance — account for every pathway. In and Out are transfer rates; Production and Consumption are internal source/sink rates; dM/dt is net inventory change rate.

7 — Pronunciation

Pronunciation. Say dM/dt = In - Out + Production - Consumption. For Dynamic mass balance — account for every pathway, use the step-three names tied to tracking a reservoir in a closed-loop life-support system. Speak each Dynamic mass balance — account for every pathway unit with the quantity it measures.

8 — Units
kg/day
9 — Convention

Convention. For Dynamic mass balance — account for every pathway, keep tracking a reservoir in a closed-loop life-support system on one declared boundary. Apply dM/dt = In - Out + Production - Consumption under that convention. A balanced total can hide incompatible chemical species; each conserved constituent may need its own balance.

10 — Why this operation

Why this operation. dM/dt = In - Out + Production - Consumption answers the Dynamic mass balance — account for every pathway question because it represents tracking a reservoir in a closed-loop life-support system. In this case it yields: The reservoir grows by 1 kg/day in this simplified balance.

11 — Assumptions

Assumptions. Treat the Dynamic mass balance — account for every pathway values as one teaching case. For tracking a reservoir in a closed-loop life-support system, keep a single physical or operational boundary. A balanced total can hide incompatible chemical species; each conserved constituent may need its own balance.

12 — Unit check

Unit check. Reduce dM/dt = In - Out + Production - Consumption for Dynamic mass balance — account for every pathway. The required dimension is kg/day. A different dimension invalidates “The reservoir grows by 1 kg/day in this simplified balance.”.

13 — Numerical case

In = 95 kg/day

Out = 100 kg/day

Production = 8 kg/day

Consumption = 2 kg/day

dM/dt = 95−100+8−2 = +1 kg/day

14 — Why each operation

Why each operation. For Dynamic mass balance — account for every pathway, substitute In = 95 kg/day; Out = 100 kg/day; Production = 8 kg/day; Consumption = 2 kg/day; dM/dt = 95−100+8−2 = +1 kg/day into dM/dt = In - Out + Production - Consumption. Then verify the independent statement “95+8 = 103 in/source; 100+2 = 102 out/sink; difference = +1”.

15 — Algebra check

Algebra check. Reverse dM/dt = In - Out + Production - Consumption for Dynamic mass balance — account for every pathway using “95+8 = 103 in/source; 100+2 = 102 out/sink; difference = +1”. The recovered input should follow “A 2 kg/day increase in Out changes the net from +1 to −1 kg/day.”. If not, recheck units and boundaries.

16 — Mental estimate

Mental estimate. Round the dominant inputs for Dynamic mass balance — account for every pathway. Compare that rough scale with “The reservoir grows by 1 kg/day in this simplified balance.”. If they diverge sharply, inspect dM/dt = In - Out + Production - Consumption for units, signs or boundaries.

17 — Interpretation

Interpretation. For Dynamic mass balance — account for every pathway, The reservoir grows by 1 kg/day in this simplified balance. Operationally: Use signed mass balances to detect slow inventory drift before a tank alarm becomes the first evidence. The interpretation remains limited by “A balanced total can hide incompatible chemical species; each conserved constituent may need its own balance.”.

18 — What it does not prove

What it does not prove. Dynamic mass balance — account for every pathway cannot support claims outside tracking a reservoir in a closed-loop life-support system. A balanced total can hide incompatible chemical species; each conserved constituent may need its own balance. Use the result only to justify: Use signed mass balances to detect slow inventory drift before a tank alarm becomes the first evidence.

19 — Sensitivity or limit case
A 2 kg/day increase in Out changes the net from +1 to −1 kg/day.
20 — Practice

Guided exercise — Dynamic mass balance — account for every pathway. In=50, Out=54, Production=7, Consumption=1 kg/day. Find net change.

Guided correction — Dynamic mass balance — account for every pathway
  1. 50−54+7−1 = +2 kg/day.
  2. State which reservoir/species is being balanced.

Autonomous exercise — Dynamic mass balance — account for every pathway. Build a second case from “A 2 kg/day increase in Out changes the net from +1 to −1 kg/day.”. Re-evaluate dM/dt = In - Out + Production - Consumption. Name the changed input. Decide whether “Use signed mass balances to detect slow inventory drift before a tank alarm becomes the first evidence.” still follows.

Autonomous correction — Dynamic mass balance — account for every pathway

For Dynamic mass balance — account for every pathway, state the altered case. Preserve kg/day. Match the direction in “A 2 kg/day increase in Out changes the net from +1 to −1 kg/day.”. Respect “A balanced total can hide incompatible chemical species; each conserved constituent may need its own balance.”. Finish by retaining or revising: Use signed mass balances to detect slow inventory drift before a tank alarm becomes the first evidence.

21 — Mission decision
Use signed mass balances to detect slow inventory drift before a tank alarm becomes the first evidence.

Electrolysis oxygen yield — connect processed water to theoretical oxygen mass

m_O2 = eta_elec × (32/36) × m_H2O
1 — Concrete question

For Electrolysis oxygen yield — connect processed water to theoretical oxygen mass, how does m_O2 = eta_elec × (32/36) × m_H2O inform estimating oxygen product from water electrolysis with a stated process efficiency and the operational choice “Use stoichiometric yield to reconcile oxygen inventory with water consumption and process telemetry.”?

2 — Intuition without symbols

Intuition. Splitting water can produce oxygen, but chemistry fixes the theoretical share available from a given water mass. Real hardware then delivers only part of that ideal amount because efficiency is not perfect.

3 — Quantities first
m_H2O is processed water; 32/36 is stoichiometric oxygen mass fraction from 2H2O→2H2+O2; eta_elec is recovery/production efficiency; m_O2 product mass.
4 — Formula
m_O2 = eta_elec × (32/36) × m_H2O
5 — Read aloud
“m O two equals eta electrolysis times thirty-two over thirty-six times m H two O.”
6 — Symbols

Symbol map for Electrolysis oxygen yield — connect processed water to theoretical oxygen mass. m_H2O is processed water; 32/36 is stoichiometric oxygen mass fraction from 2H2O→2H2+O2; eta_elec is recovery/production efficiency; m_O2 product mass.

7 — Pronunciation

Pronunciation. Say m_O2 = eta_elec × (32/36) × m_H2O. For Electrolysis oxygen yield — connect processed water to theoretical oxygen mass, use the step-three names tied to estimating oxygen product from water electrolysis with a stated process efficiency. Speak each Electrolysis oxygen yield — connect processed water to theoretical oxygen mass unit with the quantity it measures.

8 — Units
dimensionless × dimensionless × kg = kg
9 — Convention

Convention. For Electrolysis oxygen yield — connect processed water to theoretical oxygen mass, keep estimating oxygen product from water electrolysis with a stated process efficiency on one declared boundary. Apply m_O2 = eta_elec × (32/36) × m_H2O under that convention. Efficiency must be defined: conversion, collection and system availability are not automatically the same factor.

10 — Why this operation

Why this operation. m_O2 = eta_elec × (32/36) × m_H2O answers the Electrolysis oxygen yield — connect processed water to theoretical oxygen mass question because it represents estimating oxygen product from water electrolysis with a stated process efficiency. In this case it yields: The teaching case yields about 7.56 kg of collected oxygen.

11 — Assumptions

Assumptions. Treat the Electrolysis oxygen yield — connect processed water to theoretical oxygen mass values as one teaching case. For estimating oxygen product from water electrolysis with a stated process efficiency, keep a single physical or operational boundary. Efficiency must be defined: conversion, collection and system availability are not automatically the same factor.

12 — Unit check

Unit check. Reduce m_O2 = eta_elec × (32/36) × m_H2O for Electrolysis oxygen yield — connect processed water to theoretical oxygen mass. The required dimension is dimensionless × dimensionless × kg = kg. A different dimension invalidates “The teaching case yields about 7.56 kg of collected oxygen.”.

13 — Numerical case

eta_elec = 0.85

m_H2O = 10.0 kg

m_O2 = 0.85×(32/36)×10.0 ≈ 7.56 kg

14 — Why each operation

Why each operation. For Electrolysis oxygen yield — connect processed water to theoretical oxygen mass, substitute eta_elec = 0.85; m_H2O = 10.0 kg; m_O2 = 0.85×(32/36)×10.0 ≈ 7.56 kg into m_O2 = eta_elec × (32/36) × m_H2O. Then verify the independent statement “The theoretical maximum from 10 kg water is 8.89 kg; 85% of that is 7.56 kg.”.

15 — Algebra check

Algebra check. Reverse m_O2 = eta_elec × (32/36) × m_H2O for Electrolysis oxygen yield — connect processed water to theoretical oxygen mass using “The theoretical maximum from 10 kg water is 8.89 kg; 85% of that is 7.56 kg.”. The recovered input should follow “Each percentage point of efficiency changes product proportionally at fixed feed mass.”. If not, recheck units and boundaries.

16 — Mental estimate

Mental estimate. Round the dominant inputs for Electrolysis oxygen yield — connect processed water to theoretical oxygen mass. Compare that rough scale with “The teaching case yields about 7.56 kg of collected oxygen.”. If they diverge sharply, inspect m_O2 = eta_elec × (32/36) × m_H2O for units, signs or boundaries.

17 — Interpretation

Interpretation. For Electrolysis oxygen yield — connect processed water to theoretical oxygen mass, The teaching case yields about 7.56 kg of collected oxygen. Operationally: Use stoichiometric yield to reconcile oxygen inventory with water consumption and process telemetry. The interpretation remains limited by “Efficiency must be defined: conversion, collection and system availability are not automatically the same factor.”.

18 — What it does not prove

What it does not prove. Electrolysis oxygen yield — connect processed water to theoretical oxygen mass cannot support claims outside estimating oxygen product from water electrolysis with a stated process efficiency. Efficiency must be defined: conversion, collection and system availability are not automatically the same factor. Use the result only to justify: Use stoichiometric yield to reconcile oxygen inventory with water consumption and process telemetry.

19 — Sensitivity or limit case
Each percentage point of efficiency changes product proportionally at fixed feed mass.
20 — Practice

Guided exercise — Electrolysis oxygen yield — connect processed water to theoretical oxygen mass. At eta=0.90 with 18 kg water processed, estimate collected O2.

Guided correction — Electrolysis oxygen yield — connect processed water to theoretical oxygen mass
  1. theoretical O2=18×32/36=16.0 kg; collected=14.4 kg.
  2. Track the hydrogen coproduct and power requirement separately.

Autonomous exercise — Electrolysis oxygen yield — connect processed water to theoretical oxygen mass. Build a second case from “Each percentage point of efficiency changes product proportionally at fixed feed mass.”. Re-evaluate m_O2 = eta_elec × (32/36) × m_H2O. Name the changed input. Decide whether “Use stoichiometric yield to reconcile oxygen inventory with water consumption and process telemetry.” still follows.

Autonomous correction — Electrolysis oxygen yield — connect processed water to theoretical oxygen mass

For Electrolysis oxygen yield — connect processed water to theoretical oxygen mass, state the altered case. Preserve dimensionless × dimensionless × kg = kg. Match the direction in “Each percentage point of efficiency changes product proportionally at fixed feed mass.”. Respect “Efficiency must be defined: conversion, collection and system availability are not automatically the same factor.”. Finish by retaining or revising: Use stoichiometric yield to reconcile oxygen inventory with water consumption and process telemetry.

21 — Mission decision
Use stoichiometric yield to reconcile oxygen inventory with water consumption and process telemetry.

Net carbon-dioxide accumulation

m_CO2_net = m_CO2_prod - m_CO2_removed
1 — Concrete question

For Net carbon-dioxide accumulation, how does m_CO2_net = m_CO2_prod - m_CO2_removed inform checking whether cabin CO₂ inventory tends to rise or fall and the operational choice “Keep net CO₂ mass balance near zero while controlling concentration at crew locations with independent sensors.”?

2 — Intuition without symbols

Intuition. Cabin carbon dioxide rises when crew production exceeds removal and falls when removal exceeds production. The net difference determines whether the concentration trend is moving toward or away from a limit.

3 — Quantities first
m_CO2_prod is crew/process production rate; m_CO2_removed is scrubber/removal rate; net is signed accumulation rate.
4 — Formula
m_CO2_net = m_CO2_prod - m_CO2_removed
5 — Read aloud
“m CO two net equals m CO two produced minus m CO two removed.”
6 — Symbols

Symbol map for Net carbon-dioxide accumulation. m_CO2_prod is crew/process production rate; m_CO2_removed is scrubber/removal rate; net is signed accumulation rate.

7 — Pronunciation

Pronunciation. Say m_CO2_net = m_CO2_prod - m_CO2_removed. For Net carbon-dioxide accumulation, use the step-three names tied to checking whether cabin CO₂ inventory tends to rise or fall. Speak each Net carbon-dioxide accumulation unit with the quantity it measures.

8 — Units
kg/day
9 — Convention

Convention. For Net carbon-dioxide accumulation, keep checking whether cabin CO₂ inventory tends to rise or fall on one declared boundary. Apply m_CO2_net = m_CO2_prod - m_CO2_removed under that convention. Cabin concentration also depends on gas volume, mixing and pressure; mass rate alone does not give ppm.

10 — Why this operation

Why this operation. m_CO2_net = m_CO2_prod - m_CO2_removed answers the Net carbon-dioxide accumulation question because it represents checking whether cabin CO₂ inventory tends to rise or fall. In this case it yields: CO₂ inventory rises by 0.2 kg/day if the rates persist and no other pathway acts.

11 — Assumptions

Assumptions. Treat the Net carbon-dioxide accumulation values as one teaching case. For checking whether cabin CO₂ inventory tends to rise or fall, keep a single physical or operational boundary. Cabin concentration also depends on gas volume, mixing and pressure; mass rate alone does not give ppm.

12 — Unit check

Unit check. Reduce m_CO2_net = m_CO2_prod - m_CO2_removed for Net carbon-dioxide accumulation. The required dimension is kg/day. A different dimension invalidates “CO₂ inventory rises by 0.2 kg/day if the rates persist and no other pathway acts.”.

13 — Numerical case

production = 4.2 kg/day

removal = 4.0 kg/day

net = 4.2−4.0 = +0.2 kg/day

14 — Why each operation

Why each operation. For Net carbon-dioxide accumulation, substitute production = 4.2 kg/day; removal = 4.0 kg/day; net = 4.2−4.0 = +0.2 kg/day into m_CO2_net = m_CO2_prod - m_CO2_removed. Then verify the independent statement “4.0+0.2=4.2 kg/day”.

15 — Algebra check

Algebra check. Reverse m_CO2_net = m_CO2_prod - m_CO2_removed for Net carbon-dioxide accumulation using “4.0+0.2=4.2 kg/day”. The recovered input should follow “A 5% loss of a 4.0 kg/day removal capability cuts removal to 3.8 kg/day and doubles this example imbalance.”. If not, recheck units and boundaries.

16 — Mental estimate

Mental estimate. Round the dominant inputs for Net carbon-dioxide accumulation. Compare that rough scale with “CO₂ inventory rises by 0.2 kg/day if the rates persist and no other pathway acts.”. If they diverge sharply, inspect m_CO2_net = m_CO2_prod - m_CO2_removed for units, signs or boundaries.

17 — Interpretation

Interpretation. For Net carbon-dioxide accumulation, CO₂ inventory rises by 0.2 kg/day if the rates persist and no other pathway acts. Operationally: Keep net CO₂ mass balance near zero while controlling concentration at crew locations with independent sensors. The interpretation remains limited by “Cabin concentration also depends on gas volume, mixing and pressure; mass rate alone does not give ppm.”.

18 — What it does not prove

What it does not prove. Net carbon-dioxide accumulation cannot support claims outside checking whether cabin CO₂ inventory tends to rise or fall. Cabin concentration also depends on gas volume, mixing and pressure; mass rate alone does not give ppm. Use the result only to justify: Keep net CO₂ mass balance near zero while controlling concentration at crew locations with independent sensors.

19 — Sensitivity or limit case
A 5% loss of a 4.0 kg/day removal capability cuts removal to 3.8 kg/day and doubles this example imbalance.
20 — Practice

Guided exercise — Net carbon-dioxide accumulation. Production=3.6 and removal=3.9 kg/day. Find net.

Guided correction — Net carbon-dioxide accumulation
  1. net=−0.3 kg/day.
  2. A negative net means removal exceeds production, not that concentration instantly falls everywhere.

Autonomous exercise — Net carbon-dioxide accumulation. Build a second case from “A 5% loss of a 4.0 kg/day removal capability cuts removal to 3.8 kg/day and doubles this example imbalance.”. Re-evaluate m_CO2_net = m_CO2_prod - m_CO2_removed. Name the changed input. Decide whether “Keep net CO₂ mass balance near zero while controlling concentration at crew locations with independent sensors.” still follows.

Autonomous correction — Net carbon-dioxide accumulation

For Net carbon-dioxide accumulation, state the altered case. Preserve kg/day. Match the direction in “A 5% loss of a 4.0 kg/day removal capability cuts removal to 3.8 kg/day and doubles this example imbalance.”. Respect “Cabin concentration also depends on gas volume, mixing and pressure; mass rate alone does not give ppm.”. Finish by retaining or revising: Keep net CO₂ mass balance near zero while controlling concentration at crew locations with independent sensors.

21 — Mission decision
Keep net CO₂ mass balance near zero while controlling concentration at crew locations with independent sensors.

Water recovery fraction — quantify recovered product from incoming wastewater

R_water = m_recovered / m_input
1 — Concrete question

For Water recovery fraction — quantify recovered product from incoming wastewater, how does R_water = m_recovered / m_input inform tracking loop closure without confusing throughput with make-up need and the operational choice “Track recovery and water quality separately; make-up planning depends on verified net loss, not a headline percentage alone.”?

2 — Intuition without symbols

Intuition. A recovery system returns only part of the wastewater it receives. The recovered share measures how effectively the loop closes and how much make-up water must still come from inventory or local resources.

3 — Quantities first
m_recovered is qualified recovered water; m_input is wastewater feed; R_water is recovery fraction.
4 — Formula
R_water = m_recovered / m_input
5 — Read aloud
“R water equals m recovered divided by m input.”
6 — Symbols

Symbol map for Water recovery fraction — quantify recovered product from incoming wastewater. m_recovered is qualified recovered water; m_input is wastewater feed; R_water is recovery fraction.

7 — Pronunciation

Pronunciation. Say R_water = m_recovered / m_input. For Water recovery fraction — quantify recovered product from incoming wastewater, use the step-three names tied to tracking loop closure without confusing throughput with make-up need. Speak each Water recovery fraction — quantify recovered product from incoming wastewater unit with the quantity it measures.

8 — Units
kg/kg = dimensionless fraction
9 — Convention

Convention. For Water recovery fraction — quantify recovered product from incoming wastewater, keep tracking loop closure without confusing throughput with make-up need on one declared boundary. Apply R_water = m_recovered / m_input under that convention. Recovery percentage does not prove product-water quality or account for inventory trapped in equipment.

10 — Why this operation

Why this operation. R_water = m_recovered / m_input answers the Water recovery fraction — quantify recovered product from incoming wastewater question because it represents tracking loop closure without confusing throughput with make-up need. In this case it yields: The loop recovers 95% of incoming wastewater mass as qualified water in this simplified example.

11 — Assumptions

Assumptions. Treat the Water recovery fraction — quantify recovered product from incoming wastewater values as one teaching case. For tracking loop closure without confusing throughput with make-up need, keep a single physical or operational boundary. Recovery percentage does not prove product-water quality or account for inventory trapped in equipment.

12 — Unit check

Unit check. Reduce R_water = m_recovered / m_input for Water recovery fraction — quantify recovered product from incoming wastewater. The required dimension is kg/kg = dimensionless fraction. A different dimension invalidates “The loop recovers 95% of incoming wastewater mass as qualified water in this simplified example.”.

13 — Numerical case

m_input = 80 kg/day

m_recovered = 76 kg/day

R_water = 76/80 = 0.95 = 95%

14 — Why each operation

Why each operation. For Water recovery fraction — quantify recovered product from incoming wastewater, substitute m_input = 80 kg/day; m_recovered = 76 kg/day; R_water = 76/80 = 0.95 = 95% into R_water = m_recovered / m_input. Then verify the independent statement “80−76=4 kg/day unrecovered; 4/80=5%”.

15 — Algebra check

Algebra check. Reverse R_water = m_recovered / m_input for Water recovery fraction — quantify recovered product from incoming wastewater using “80−76=4 kg/day unrecovered; 4/80=5%”. The recovered input should follow “At 80 kg/day, improving recovery from 95% to 97% cuts unrecovered mass from 4.0 to 2.4 kg/day.”. If not, recheck units and boundaries.

16 — Mental estimate

Mental estimate. Round the dominant inputs for Water recovery fraction — quantify recovered product from incoming wastewater. Compare that rough scale with “The loop recovers 95% of incoming wastewater mass as qualified water in this simplified example.”. If they diverge sharply, inspect R_water = m_recovered / m_input for units, signs or boundaries.

17 — Interpretation

Interpretation. For Water recovery fraction — quantify recovered product from incoming wastewater, The loop recovers 95% of incoming wastewater mass as qualified water in this simplified example. Operationally: Track recovery and water quality separately; make-up planning depends on verified net loss, not a headline percentage alone. The interpretation remains limited by “Recovery percentage does not prove product-water quality or account for inventory trapped in equipment.”.

18 — What it does not prove

What it does not prove. Water recovery fraction — quantify recovered product from incoming wastewater cannot support claims outside tracking loop closure without confusing throughput with make-up need. Recovery percentage does not prove product-water quality or account for inventory trapped in equipment. Use the result only to justify: Track recovery and water quality separately; make-up planning depends on verified net loss, not a headline percentage alone.

19 — Sensitivity or limit case
At 80 kg/day, improving recovery from 95% to 97% cuts unrecovered mass from 4.0 to 2.4 kg/day.
20 — Practice

Guided exercise — Water recovery fraction — quantify recovered product from incoming wastewater. Input=100 kg/day, recovered=92 kg/day. Find recovery.

Guided correction — Water recovery fraction — quantify recovered product from incoming wastewater
  1. R=92%.
  2. Unrecovered mass is 8 kg/day before other return pathways.

Autonomous exercise — Water recovery fraction — quantify recovered product from incoming wastewater. Build a second case from “At 80 kg/day, improving recovery from 95% to 97% cuts unrecovered mass from 4.0 to 2.4 kg/day.”. Re-evaluate R_water = m_recovered / m_input. Name the changed input. Decide whether “Track recovery and water quality separately; make-up planning depends on verified net loss, not a headline percentage alone.” still follows.

Autonomous correction — Water recovery fraction — quantify recovered product from incoming wastewater

For Water recovery fraction — quantify recovered product from incoming wastewater, state the altered case. Preserve kg/kg = dimensionless fraction. Match the direction in “At 80 kg/day, improving recovery from 95% to 97% cuts unrecovered mass from 4.0 to 2.4 kg/day.”. Respect “Recovery percentage does not prove product-water quality or account for inventory trapped in equipment.”. Finish by retaining or revising: Track recovery and water quality separately; make-up planning depends on verified net loss, not a headline percentage alone.

21 — Mission decision
Track recovery and water quality separately; make-up planning depends on verified net loss, not a headline percentage alone.

Condensate collection — water removed from an air stream

m_cond = m_vapor_in - m_vapor_out
1 — Concrete question

For Condensate collection — water removed from an air stream, how does m_cond = m_vapor_in - m_vapor_out inform quantifying moisture removed by a condensing heat exchanger over a defined interval and the operational choice “Use condensate mass balance to cross-check humidity-control telemetry and water-loop accounting.”?

2 — Intuition without symbols

Intuition. Moist air carries water that can be removed when conditions force vapour to condense. The collected amount depends on the difference between the water carried into and out of the air-treatment step.

3 — Quantities first
m_vapor_in and m_vapor_out are water-vapor mass crossing the device boundary; m_cond is collected condensate.
4 — Formula
m_cond = m_vapor_in - m_vapor_out
5 — Read aloud
“m condensate equals m vapor in minus m vapor out.”
6 — Symbols

Symbol map for Condensate collection — water removed from an air stream. m_vapor_in and m_vapor_out are water-vapor mass crossing the device boundary; m_cond is collected condensate.

7 — Pronunciation

Pronunciation. Say m_cond = m_vapor_in - m_vapor_out. For Condensate collection — water removed from an air stream, use the step-three names tied to quantifying moisture removed by a condensing heat exchanger over a defined interval. Speak each Condensate collection — water removed from an air stream unit with the quantity it measures.

8 — Units
kg − kg = kg
9 — Convention

Convention. For Condensate collection — water removed from an air stream, keep quantifying moisture removed by a condensing heat exchanger over a defined interval on one declared boundary. Apply m_cond = m_vapor_in - m_vapor_out under that convention. Condensate quality may require treatment; this balance assumes no leaks or unmeasured storage change in the device.

10 — Why this operation

Why this operation. m_cond = m_vapor_in - m_vapor_out answers the Condensate collection — water removed from an air stream question because it represents quantifying moisture removed by a condensing heat exchanger over a defined interval. In this case it yields: The exchanger removes 4.5 kg of water vapor over the stated interval.

11 — Assumptions

Assumptions. Treat the Condensate collection — water removed from an air stream values as one teaching case. For quantifying moisture removed by a condensing heat exchanger over a defined interval, keep a single physical or operational boundary. Condensate quality may require treatment; this balance assumes no leaks or unmeasured storage change in the device.

12 — Unit check

Unit check. Reduce m_cond = m_vapor_in - m_vapor_out for Condensate collection — water removed from an air stream. The required dimension is kg − kg = kg. A different dimension invalidates “The exchanger removes 4.5 kg of water vapor over the stated interval.”.

13 — Numerical case

m_vapor_in = 6.0 kg

m_vapor_out = 1.5 kg

m_cond = 6.0−1.5 = 4.5 kg

14 — Why each operation

Why each operation. For Condensate collection — water removed from an air stream, substitute m_vapor_in = 6.0 kg; m_vapor_out = 1.5 kg; m_cond = 6.0−1.5 = 4.5 kg into m_cond = m_vapor_in - m_vapor_out. Then verify the independent statement “1.5+4.5=6.0 kg”.

15 — Algebra check

Algebra check. Reverse m_cond = m_vapor_in - m_vapor_out for Condensate collection — water removed from an air stream using “1.5+4.5=6.0 kg”. The recovered input should follow “If outlet vapor rises to 2.0 kg with inlet unchanged, collected condensate drops to 4.0 kg.”. If not, recheck units and boundaries.

16 — Mental estimate

Mental estimate. Round the dominant inputs for Condensate collection — water removed from an air stream. Compare that rough scale with “The exchanger removes 4.5 kg of water vapor over the stated interval.”. If they diverge sharply, inspect m_cond = m_vapor_in - m_vapor_out for units, signs or boundaries.

17 — Interpretation

Interpretation. For Condensate collection — water removed from an air stream, The exchanger removes 4.5 kg of water vapor over the stated interval. Operationally: Use condensate mass balance to cross-check humidity-control telemetry and water-loop accounting. The interpretation remains limited by “Condensate quality may require treatment; this balance assumes no leaks or unmeasured storage change in the device.”.

18 — What it does not prove

What it does not prove. Condensate collection — water removed from an air stream cannot support claims outside quantifying moisture removed by a condensing heat exchanger over a defined interval. Condensate quality may require treatment; this balance assumes no leaks or unmeasured storage change in the device. Use the result only to justify: Use condensate mass balance to cross-check humidity-control telemetry and water-loop accounting.

19 — Sensitivity or limit case
If outlet vapor rises to 2.0 kg with inlet unchanged, collected condensate drops to 4.0 kg.
20 — Practice

Guided exercise — Condensate collection — water removed from an air stream. Inlet vapor=8.2 kg, outlet=2.7 kg. Find condensate.

Guided correction — Condensate collection — water removed from an air stream
  1. m_cond=5.5 kg.
  2. Check drain inventory to close the physical balance.

Autonomous exercise — Condensate collection — water removed from an air stream. Build a second case from “If outlet vapor rises to 2.0 kg with inlet unchanged, collected condensate drops to 4.0 kg.”. Re-evaluate m_cond = m_vapor_in - m_vapor_out. Name the changed input. Decide whether “Use condensate mass balance to cross-check humidity-control telemetry and water-loop accounting.” still follows.

Autonomous correction — Condensate collection — water removed from an air stream

For Condensate collection — water removed from an air stream, state the altered case. Preserve kg − kg = kg. Match the direction in “If outlet vapor rises to 2.0 kg with inlet unchanged, collected condensate drops to 4.0 kg.”. Respect “Condensate quality may require treatment; this balance assumes no leaks or unmeasured storage change in the device.”. Finish by retaining or revising: Use condensate mass balance to cross-check humidity-control telemetry and water-loop accounting.

21 — Mission decision
Use condensate mass balance to cross-check humidity-control telemetry and water-loop accounting.

Filter removal efficiency — calculate downstream concentration

C_out = C_in × (1 - eta_filter)
1 — Concrete question

For Filter removal efficiency — calculate downstream concentration, how does C_out = C_in × (1 - eta_filter) inform estimating contaminant concentration after a single-pass removal stage and the operational choice “Trend filter efficiency and pressure drop so replacement occurs before downstream exposure approaches a limit.”?

2 — Intuition without symbols

Intuition. A filter reduces a contaminant by removing a fraction of what enters. The downstream concentration therefore depends on both the inlet level and the fraction that escapes removal.

3 — Quantities first
C_in is inlet concentration; eta_filter is fractional removal efficiency; C_out is downstream concentration.
4 — Formula
C_out = C_in × (1 - eta_filter)
5 — Read aloud
“C out equals C in times one minus eta filter.”
6 — Symbols

Symbol map for Filter removal efficiency — calculate downstream concentration. C_in is inlet concentration; eta_filter is fractional removal efficiency; C_out is downstream concentration.

7 — Pronunciation

Pronunciation. Say C_out = C_in × (1 - eta_filter). For Filter removal efficiency — calculate downstream concentration, use the step-three names tied to estimating contaminant concentration after a single-pass removal stage. Speak each Filter removal efficiency — calculate downstream concentration unit with the quantity it measures.

8 — Units
ppm × dimensionless = ppm
9 — Convention

Convention. For Filter removal efficiency — calculate downstream concentration, keep estimating contaminant concentration after a single-pass removal stage on one declared boundary. Apply C_out = C_in × (1 - eta_filter) under that convention. Efficiency can depend on flow, loading, humidity and contaminant species; ppm is not a mass flow without volumetric flow and gas state.

10 — Why this operation

Why this operation. C_out = C_in × (1 - eta_filter) answers the Filter removal efficiency — calculate downstream concentration question because it represents estimating contaminant concentration after a single-pass removal stage. In this case it yields: The idealized single-pass outlet concentration is 3 ppm.

11 — Assumptions

Assumptions. Treat the Filter removal efficiency — calculate downstream concentration values as one teaching case. For estimating contaminant concentration after a single-pass removal stage, keep a single physical or operational boundary. Efficiency can depend on flow, loading, humidity and contaminant species; ppm is not a mass flow without volumetric flow and gas state.

12 — Unit check

Unit check. Reduce C_out = C_in × (1 - eta_filter) for Filter removal efficiency — calculate downstream concentration. The required dimension is ppm × dimensionless = ppm. A different dimension invalidates “The idealized single-pass outlet concentration is 3 ppm.”.

13 — Numerical case

C_in = 100 ppm

eta_filter = 0.97

C_out = 100×(1−0.97) = 3 ppm

14 — Why each operation

Why each operation. For Filter removal efficiency — calculate downstream concentration, substitute C_in = 100 ppm; eta_filter = 0.97; C_out = 100×(1−0.97) = 3 ppm into C_out = C_in × (1 - eta_filter). Then verify the independent statement “Removed amount in concentration units is 97 ppm; 100−97=3 ppm”.

15 — Algebra check

Algebra check. Reverse C_out = C_in × (1 - eta_filter) for Filter removal efficiency — calculate downstream concentration using “Removed amount in concentration units is 97 ppm; 100−97=3 ppm”. The recovered input should follow “A drop from 97% to 90% efficiency raises outlet from 3 ppm to 10 ppm at the same inlet concentration.”. If not, recheck units and boundaries.

16 — Mental estimate

Mental estimate. Round the dominant inputs for Filter removal efficiency — calculate downstream concentration. Compare that rough scale with “The idealized single-pass outlet concentration is 3 ppm.”. If they diverge sharply, inspect C_out = C_in × (1 - eta_filter) for units, signs or boundaries.

17 — Interpretation

Interpretation. For Filter removal efficiency — calculate downstream concentration, The idealized single-pass outlet concentration is 3 ppm. Operationally: Trend filter efficiency and pressure drop so replacement occurs before downstream exposure approaches a limit. The interpretation remains limited by “Efficiency can depend on flow, loading, humidity and contaminant species; ppm is not a mass flow without volumetric flow and gas state.”.

18 — What it does not prove

What it does not prove. Filter removal efficiency — calculate downstream concentration cannot support claims outside estimating contaminant concentration after a single-pass removal stage. Efficiency can depend on flow, loading, humidity and contaminant species; ppm is not a mass flow without volumetric flow and gas state. Use the result only to justify: Trend filter efficiency and pressure drop so replacement occurs before downstream exposure approaches a limit.

19 — Sensitivity or limit case
A drop from 97% to 90% efficiency raises outlet from 3 ppm to 10 ppm at the same inlet concentration.
20 — Practice

Guided exercise — Filter removal efficiency — calculate downstream concentration. C_in=250 ppm and eta=0.96. Find C_out.

Guided correction — Filter removal efficiency — calculate downstream concentration
  1. C_out=250×0.04=10 ppm.
  2. Compare with the sensor uncertainty and allowable concentration criterion.

Autonomous exercise — Filter removal efficiency — calculate downstream concentration. Build a second case from “A drop from 97% to 90% efficiency raises outlet from 3 ppm to 10 ppm at the same inlet concentration.”. Re-evaluate C_out = C_in × (1 - eta_filter). Name the changed input. Decide whether “Trend filter efficiency and pressure drop so replacement occurs before downstream exposure approaches a limit.” still follows.

Autonomous correction — Filter removal efficiency — calculate downstream concentration

For Filter removal efficiency — calculate downstream concentration, state the altered case. Preserve ppm × dimensionless = ppm. Match the direction in “A drop from 97% to 90% efficiency raises outlet from 3 ppm to 10 ppm at the same inlet concentration.”. Respect “Efficiency can depend on flow, loading, humidity and contaminant species; ppm is not a mass flow without volumetric flow and gas state.”. Finish by retaining or revising: Trend filter efficiency and pressure drop so replacement occurs before downstream exposure approaches a limit.

21 — Mission decision
Trend filter efficiency and pressure drop so replacement occurs before downstream exposure approaches a limit.

Control error — preserve the sign between setpoint and measurement

e = Setpoint - Measurement
1 — Concrete question

For Control error — preserve the sign between setpoint and measurement, how does e = Setpoint - Measurement inform feedback-control reasoning for temperature, pressure or concentration loops and the operational choice “Keep sign conventions identical across displays, procedures and controller logs to prevent operator reversal errors.”?

2 — Intuition without symbols

Intuition. A controller needs to know not only the size of a mismatch but also its direction. Keeping the sign between desired and measured state tells the control system which way corrective action must move.

3 — Quantities first
Setpoint is desired value; Measurement is observed value; e is signed error under the stated convention.
4 — Formula
e = Setpoint - Measurement
5 — Read aloud
“e equals setpoint minus measurement.”
6 — Symbols

Symbol map for Control error — preserve the sign between setpoint and measurement. Setpoint is desired value; Measurement is observed value; e is signed error under the stated convention.

7 — Pronunciation

Pronunciation. Say e = Setpoint - Measurement. For Control error — preserve the sign between setpoint and measurement, use the step-three names tied to feedback-control reasoning for temperature, pressure or concentration loops. Speak each Control error — preserve the sign between setpoint and measurement unit with the quantity it measures.

8 — Units
same unit as controlled variable
9 — Convention

Convention. For Control error — preserve the sign between setpoint and measurement, keep feedback-control reasoning for temperature, pressure or concentration loops on one declared boundary. Apply e = Setpoint - Measurement under that convention. Error alone does not determine actuator command; controller gains, limits, deadbands and dynamics matter.

10 — Why this operation

Why this operation. e = Setpoint - Measurement answers the Control error — preserve the sign between setpoint and measurement question because it represents feedback-control reasoning for temperature, pressure or concentration loops. In this case it yields: The negative error means the measured temperature is 1.4 °C above setpoint under this convention.

11 — Assumptions

Assumptions. Treat the Control error — preserve the sign between setpoint and measurement values as one teaching case. For feedback-control reasoning for temperature, pressure or concentration loops, keep a single physical or operational boundary. Error alone does not determine actuator command; controller gains, limits, deadbands and dynamics matter.

12 — Unit check

Unit check. Reduce e = Setpoint - Measurement for Control error — preserve the sign between setpoint and measurement. The required dimension is same unit as controlled variable. A different dimension invalidates “The negative error means the measured temperature is 1.4 °C above setpoint under this convention.”.

13 — Numerical case

Setpoint = 21.0 °C

Measurement = 22.4 °C

e = 21.0−22.4 = −1.4 °C

14 — Why each operation

Why each operation. For Control error — preserve the sign between setpoint and measurement, substitute Setpoint = 21.0 °C; Measurement = 22.4 °C; e = 21.0−22.4 = −1.4 °C into e = Setpoint - Measurement. Then verify the independent statement “Measurement + e = 22.4−1.4 = 21.0 °C”.

15 — Algebra check

Algebra check. Reverse e = Setpoint - Measurement for Control error — preserve the sign between setpoint and measurement using “Measurement + e = 22.4−1.4 = 21.0 °C”. The recovered input should follow “Changing the sign convention reverses the sign but not the physical deviation; document the convention.”. If not, recheck units and boundaries.

16 — Mental estimate

Mental estimate. Round the dominant inputs for Control error — preserve the sign between setpoint and measurement. Compare that rough scale with “The negative error means the measured temperature is 1.4 °C above setpoint under this convention.”. If they diverge sharply, inspect e = Setpoint - Measurement for units, signs or boundaries.

17 — Interpretation

Interpretation. For Control error — preserve the sign between setpoint and measurement, The negative error means the measured temperature is 1.4 °C above setpoint under this convention. Operationally: Keep sign conventions identical across displays, procedures and controller logs to prevent operator reversal errors. The interpretation remains limited by “Error alone does not determine actuator command; controller gains, limits, deadbands and dynamics matter.”.

18 — What it does not prove

What it does not prove. Control error — preserve the sign between setpoint and measurement cannot support claims outside feedback-control reasoning for temperature, pressure or concentration loops. Error alone does not determine actuator command; controller gains, limits, deadbands and dynamics matter. Use the result only to justify: Keep sign conventions identical across displays, procedures and controller logs to prevent operator reversal errors.

19 — Sensitivity or limit case
Changing the sign convention reverses the sign but not the physical deviation; document the convention.
20 — Practice

Guided exercise — Control error — preserve the sign between setpoint and measurement. Setpoint=45% RH, measurement=41% RH. Find error using setpoint−measurement.

Guided correction — Control error — preserve the sign between setpoint and measurement
  1. e=+4 percentage points.
  2. Positive means measured humidity is below target under this convention.

Autonomous exercise — Control error — preserve the sign between setpoint and measurement. Build a second case from “Changing the sign convention reverses the sign but not the physical deviation; document the convention.”. Re-evaluate e = Setpoint - Measurement. Name the changed input. Decide whether “Keep sign conventions identical across displays, procedures and controller logs to prevent operator reversal errors.” still follows.

Autonomous correction — Control error — preserve the sign between setpoint and measurement

For Control error — preserve the sign between setpoint and measurement, state the altered case. Preserve same unit as controlled variable. Match the direction in “Changing the sign convention reverses the sign but not the physical deviation; document the convention.”. Respect “Error alone does not determine actuator command; controller gains, limits, deadbands and dynamics matter.”. Finish by retaining or revising: Keep sign conventions identical across displays, procedures and controller logs to prevent operator reversal errors.

21 — Mission decision
Keep sign conventions identical across displays, procedures and controller logs to prevent operator reversal errors.

Stock autonomy — convert usable inventory into time at net demand

t_auto = Stock_usable / q_net
1 — Concrete question

For Stock autonomy — convert usable inventory into time at net demand, how does t_auto = Stock_usable / q_net inform estimating how long a buffer lasts after accounting for accessible usable stock and the operational choice “Use autonomy to order recovery actions by time-to-loss-of-function and keep emergency reserve separate.”?

2 — Intuition without symbols

Intuition. A consumable stock becomes an autonomy time when it is compared with the net rate at which the system uses that stock. Lower demand stretches the same inventory; higher demand shortens it.

3 — Quantities first
Stock_usable is qualified accessible inventory; q_net is net depletion rate; t_auto is autonomy duration.
4 — Formula
t_auto = Stock_usable / q_net
5 — Read aloud
“t autonomy equals usable stock divided by q net.”
6 — Symbols

Symbol map for Stock autonomy — convert usable inventory into time at net demand. Stock_usable is qualified accessible inventory; q_net is net depletion rate; t_auto is autonomy duration.

7 — Pronunciation

Pronunciation. Say t_auto = Stock_usable / q_net. For Stock autonomy — convert usable inventory into time at net demand, use the step-three names tied to estimating how long a buffer lasts after accounting for accessible usable stock. Speak each Stock autonomy — convert usable inventory into time at net demand unit with the quantity it measures.

8 — Units
kg / (kg/day) = day
9 — Convention

Convention. For Stock autonomy — convert usable inventory into time at net demand, keep estimating how long a buffer lasts after accounting for accessible usable stock on one declared boundary. Apply t_auto = Stock_usable / q_net under that convention. Constant-rate autonomy ignores demand transients, inaccessible stock and uncertainty; do not count protected reserve as routine stock.

10 — Why this operation

Why this operation. t_auto = Stock_usable / q_net answers the Stock autonomy — convert usable inventory into time at net demand question because it represents estimating how long a buffer lasts after accounting for accessible usable stock. In this case it yields: The buffer lasts 15 days at the stated constant net demand.

11 — Assumptions

Assumptions. Treat the Stock autonomy — convert usable inventory into time at net demand values as one teaching case. For estimating how long a buffer lasts after accounting for accessible usable stock, keep a single physical or operational boundary. Constant-rate autonomy ignores demand transients, inaccessible stock and uncertainty; do not count protected reserve as routine stock.

12 — Unit check

Unit check. Reduce t_auto = Stock_usable / q_net for Stock autonomy — convert usable inventory into time at net demand. The required dimension is kg / (kg/day) = day. A different dimension invalidates “The buffer lasts 15 days at the stated constant net demand.”.

13 — Numerical case

Stock_usable = 120 kg

q_net = 8 kg/day

t_auto = 120/8 = 15 days

14 — Why each operation

Why each operation. For Stock autonomy — convert usable inventory into time at net demand, substitute Stock_usable = 120 kg; q_net = 8 kg/day; t_auto = 120/8 = 15 days into t_auto = Stock_usable / q_net. Then verify the independent statement “15×8=120 kg”.

15 — Algebra check

Algebra check. Reverse t_auto = Stock_usable / q_net for Stock autonomy — convert usable inventory into time at net demand using “15×8=120 kg”. The recovered input should follow “If net demand rises 25% to 10 kg/day, autonomy falls to 12 days.”. If not, recheck units and boundaries.

16 — Mental estimate

Mental estimate. Round the dominant inputs for Stock autonomy — convert usable inventory into time at net demand. Compare that rough scale with “The buffer lasts 15 days at the stated constant net demand.”. If they diverge sharply, inspect t_auto = Stock_usable / q_net for units, signs or boundaries.

17 — Interpretation

Interpretation. For Stock autonomy — convert usable inventory into time at net demand, The buffer lasts 15 days at the stated constant net demand. Operationally: Use autonomy to order recovery actions by time-to-loss-of-function and keep emergency reserve separate. The interpretation remains limited by “Constant-rate autonomy ignores demand transients, inaccessible stock and uncertainty; do not count protected reserve as routine stock.”.

18 — What it does not prove

What it does not prove. Stock autonomy — convert usable inventory into time at net demand cannot support claims outside estimating how long a buffer lasts after accounting for accessible usable stock. Constant-rate autonomy ignores demand transients, inaccessible stock and uncertainty; do not count protected reserve as routine stock. Use the result only to justify: Use autonomy to order recovery actions by time-to-loss-of-function and keep emergency reserve separate.

19 — Sensitivity or limit case
If net demand rises 25% to 10 kg/day, autonomy falls to 12 days.
20 — Practice

Guided exercise — Stock autonomy — convert usable inventory into time at net demand. Usable stock=210 kg, net demand=14 kg/day. Find autonomy.

Guided correction — Stock autonomy — convert usable inventory into time at net demand
  1. t=210/14=15 days.
  2. Subtract inaccessible or quarantined inventory before computing.

Autonomous exercise — Stock autonomy — convert usable inventory into time at net demand. Build a second case from “If net demand rises 25% to 10 kg/day, autonomy falls to 12 days.”. Re-evaluate t_auto = Stock_usable / q_net. Name the changed input. Decide whether “Use autonomy to order recovery actions by time-to-loss-of-function and keep emergency reserve separate.” still follows.

Autonomous correction — Stock autonomy — convert usable inventory into time at net demand

For Stock autonomy — convert usable inventory into time at net demand, state the altered case. Preserve kg / (kg/day) = day. Match the direction in “If net demand rises 25% to 10 kg/day, autonomy falls to 12 days.”. Respect “Constant-rate autonomy ignores demand transients, inaccessible stock and uncertainty; do not count protected reserve as routine stock.”. Finish by retaining or revising: Use autonomy to order recovery actions by time-to-loss-of-function and keep emergency reserve separate.

21 — Mission decision
Use autonomy to order recovery actions by time-to-loss-of-function and keep emergency reserve separate.

Expected spare demand — link failure rate, exposure time and units consumed per failure

N_spare_exp = lambda × t × c
1 — Concrete question

For Expected spare demand — link failure rate, exposure time and units consumed per failure, how does N_spare_exp = lambda × t × c inform first-order planning estimate for replaceable items and the operational choice “Treat expected demand as one input to spares policy, alongside criticality, common causes and repair capability.”?

2 — Intuition without symbols

Intuition. Failures create replacement demand over time. Combining failure frequency, exposure duration and the number of units consumed per event gives a planning estimate for how many spares the campaign may need.

3 — Quantities first
lambda is expected failure rate; t mission exposure time; c units consumed per failure; N_spare_exp is expected demand, not a guaranteed integer.
4 — Formula
N_spare_exp = lambda × t × c
5 — Read aloud
“N spare expected equals lambda times t times c.”
6 — Symbols

Symbol map for Expected spare demand — link failure rate, exposure time and units consumed per failure. lambda is expected failure rate; t mission exposure time; c units consumed per failure; N_spare_exp is expected demand, not a guaranteed integer.

7 — Pronunciation

Pronunciation. Say N_spare_exp = lambda × t × c. For Expected spare demand — link failure rate, exposure time and units consumed per failure, use the step-three names tied to first-order planning estimate for replaceable items. Speak each Expected spare demand — link failure rate, exposure time and units consumed per failure unit with the quantity it measures.

8 — Units
failures/day × day × units/failure = units
9 — Convention

Convention. For Expected spare demand — link failure rate, exposure time and units consumed per failure, keep first-order planning estimate for replaceable items on one declared boundary. Apply N_spare_exp = lambda × t × c under that convention. Expected value does not capture variance, common-cause failures or aging; a Poisson or reliability model may be needed.

10 — Why this operation

Why this operation. N_spare_exp = lambda × t × c answers the Expected spare demand — link failure rate, exposure time and units consumed per failure question because it represents first-order planning estimate for replaceable items. In this case it yields: Expected demand is 5.4 units; stocking requires a reliability/service-level decision and integer quantity, not simply rounding by habit.

11 — Assumptions

Assumptions. Treat the Expected spare demand — link failure rate, exposure time and units consumed per failure values as one teaching case. For first-order planning estimate for replaceable items, keep a single physical or operational boundary. Expected value does not capture variance, common-cause failures or aging; a Poisson or reliability model may be needed.

12 — Unit check

Unit check. Reduce N_spare_exp = lambda × t × c for Expected spare demand — link failure rate, exposure time and units consumed per failure. The required dimension is failures/day × day × units/failure = units. A different dimension invalidates “Expected demand is 5.4 units; stocking requires a reliability/service-level decision and integer quantity, not simply rounding by habit.”.

13 — Numerical case

lambda = 0.03 failures/day

t = 180 days

c = 1 unit/failure

N_exp = 0.03×180×1 = 5.4 units

14 — Why each operation

Why each operation. For Expected spare demand — link failure rate, exposure time and units consumed per failure, substitute lambda = 0.03 failures/day; t = 180 days; c = 1 unit/failure; N_exp = 0.03×180×1 = 5.4 units into N_spare_exp = lambda × t × c. Then verify the independent statement “0.03×180=5.4 expected failures”.

15 — Algebra check

Algebra check. Reverse N_spare_exp = lambda × t × c for Expected spare demand — link failure rate, exposure time and units consumed per failure using “0.03×180=5.4 expected failures”. The recovered input should follow “A 20% longer mission raises expected demand by 20% if failure rate stays valid.”. If not, recheck units and boundaries.

16 — Mental estimate

Mental estimate. Round the dominant inputs for Expected spare demand — link failure rate, exposure time and units consumed per failure. Compare that rough scale with “Expected demand is 5.4 units; stocking requires a reliability/service-level decision and integer quantity, not simply rounding by habit.”. If they diverge sharply, inspect N_spare_exp = lambda × t × c for units, signs or boundaries.

17 — Interpretation

Interpretation. For Expected spare demand — link failure rate, exposure time and units consumed per failure, Expected demand is 5.4 units; stocking requires a reliability/service-level decision and integer quantity, not simply rounding by habit. Operationally: Treat expected demand as one input to spares policy, alongside criticality, common causes and repair capability. The interpretation remains limited by “Expected value does not capture variance, common-cause failures or aging; a Poisson or reliability model may be needed.”.

18 — What it does not prove

What it does not prove. Expected spare demand — link failure rate, exposure time and units consumed per failure cannot support claims outside first-order planning estimate for replaceable items. Expected value does not capture variance, common-cause failures or aging; a Poisson or reliability model may be needed. Use the result only to justify: Treat expected demand as one input to spares policy, alongside criticality, common causes and repair capability.

19 — Sensitivity or limit case
A 20% longer mission raises expected demand by 20% if failure rate stays valid.
20 — Practice

Guided exercise — Expected spare demand — link failure rate, exposure time and units consumed per failure. lambda=0.015/day, t=300 days, c=2 units/failure. Find expected units.

Guided correction — Expected spare demand — link failure rate, exposure time and units consumed per failure
  1. N_exp=0.015×300×2=9 units.
  2. Then size actual stock from desired confidence and resupply strategy.

Autonomous exercise — Expected spare demand — link failure rate, exposure time and units consumed per failure. Build a second case from “A 20% longer mission raises expected demand by 20% if failure rate stays valid.”. Re-evaluate N_spare_exp = lambda × t × c. Name the changed input. Decide whether “Treat expected demand as one input to spares policy, alongside criticality, common causes and repair capability.” still follows.

Autonomous correction — Expected spare demand — link failure rate, exposure time and units consumed per failure

For Expected spare demand — link failure rate, exposure time and units consumed per failure, state the altered case. Preserve failures/day × day × units/failure = units. Match the direction in “A 20% longer mission raises expected demand by 20% if failure rate stays valid.”. Respect “Expected value does not capture variance, common-cause failures or aging; a Poisson or reliability model may be needed.”. Finish by retaining or revising: Treat expected demand as one input to spares policy, alongside criticality, common causes and repair capability.

21 — Mission decision
Treat expected demand as one input to spares policy, alongside criticality, common causes and repair capability.

Minimum subsystem margin — the weakest protected margin controls the immediate gate

M_system = min(M_i)
1 — Concrete question

For Minimum subsystem margin — the weakest protected margin controls the immediate gate, how does M_system = min(M_i) inform screening a coupled life-support system for its tightest current margin and the operational choice “Direct recovery effort first at the limiting protected function while checking that the intervention does not create a new bottleneck.”?

2 — Intuition without symbols

Intuition. A chain of subsystems is constrained by its weakest protected reserve. Even generous margin elsewhere cannot compensate when one critical subsystem approaches its limit first.

3 — Quantities first
M_i are comparable normalized margins for required functions; min selects the smallest; M_system is limiting margin.
4 — Formula
M_system = min(M_i)
5 — Read aloud
“M system equals the minimum of M i.”
6 — Symbols

Symbol map for Minimum subsystem margin — the weakest protected margin controls the immediate gate. M_i are comparable normalized margins for required functions; min selects the smallest; M_system is limiting margin.

7 — Pronunciation

Pronunciation. Say M_system = min(M_i). For Minimum subsystem margin — the weakest protected margin controls the immediate gate, use the step-three names tied to screening a coupled life-support system for its tightest current margin. Speak each Minimum subsystem margin — the weakest protected margin controls the immediate gate unit with the quantity it measures.

8 — Units
dimensionless or %, only if all inputs use the same definition
9 — Convention

Convention. For Minimum subsystem margin — the weakest protected margin controls the immediate gate, keep screening a coupled life-support system for its tightest current margin on one declared boundary. Apply M_system = min(M_i) under that convention. Do not take a minimum across incompatible units or differently defined margins; normalize the decision metric first.

10 — Why this operation

Why this operation. M_system = min(M_i) answers the Minimum subsystem margin — the weakest protected margin controls the immediate gate question because it represents screening a coupled life-support system for its tightest current margin. In this case it yields: The CO₂-removal branch is the limiting normalized margin at 9%.

11 — Assumptions

Assumptions. Treat the Minimum subsystem margin — the weakest protected margin controls the immediate gate values as one teaching case. For screening a coupled life-support system for its tightest current margin, keep a single physical or operational boundary. Do not take a minimum across incompatible units or differently defined margins; normalize the decision metric first.

12 — Unit check

Unit check. Reduce M_system = min(M_i) for Minimum subsystem margin — the weakest protected margin controls the immediate gate. The required dimension is dimensionless or %, only if all inputs use the same definition. A different dimension invalidates “The CO₂-removal branch is the limiting normalized margin at 9%.”.

13 — Numerical case

water margin = 22%

oxygen margin = 15%

CO₂-removal margin = 9%

power margin = 18%

M_system = min(22,15,9,18) = 9%

14 — Why each operation

Why each operation. For Minimum subsystem margin — the weakest protected margin controls the immediate gate, substitute water margin = 22%; oxygen margin = 15%; CO₂-removal margin = 9%; power margin = 18%; M_system = min(22,15,9,18) = 9% into M_system = min(M_i). Then verify the independent statement “Every other listed margin is ≥9%, so 9% is the minimum.”.

15 — Algebra check

Algebra check. Reverse M_system = min(M_i) for Minimum subsystem margin — the weakest protected margin controls the immediate gate using “Every other listed margin is ≥9%, so 9% is the minimum.”. The recovered input should follow “Improving a non-limiting 22% margin does not change system minimum until the 9% branch improves.”. If not, recheck units and boundaries.

16 — Mental estimate

Mental estimate. Round the dominant inputs for Minimum subsystem margin — the weakest protected margin controls the immediate gate. Compare that rough scale with “The CO₂-removal branch is the limiting normalized margin at 9%.”. If they diverge sharply, inspect M_system = min(M_i) for units, signs or boundaries.

17 — Interpretation

Interpretation. For Minimum subsystem margin — the weakest protected margin controls the immediate gate, The CO₂-removal branch is the limiting normalized margin at 9%. Operationally: Direct recovery effort first at the limiting protected function while checking that the intervention does not create a new bottleneck. The interpretation remains limited by “Do not take a minimum across incompatible units or differently defined margins; normalize the decision metric first.”.

18 — What it does not prove

What it does not prove. Minimum subsystem margin — the weakest protected margin controls the immediate gate cannot support claims outside screening a coupled life-support system for its tightest current margin. Do not take a minimum across incompatible units or differently defined margins; normalize the decision metric first. Use the result only to justify: Direct recovery effort first at the limiting protected function while checking that the intervention does not create a new bottleneck.

19 — Sensitivity or limit case
Improving a non-limiting 22% margin does not change system minimum until the 9% branch improves.
20 — Practice

Guided exercise — Minimum subsystem margin — the weakest protected margin controls the immediate gate. Margins are 14%, 11%, 16% and 13%. Find system minimum.

Guided correction — Minimum subsystem margin — the weakest protected margin controls the immediate gate
  1. M_system=11%.
  2. Identify which subsystem owns that value before acting.

Autonomous exercise — Minimum subsystem margin — the weakest protected margin controls the immediate gate. Build a second case from “Improving a non-limiting 22% margin does not change system minimum until the 9% branch improves.”. Re-evaluate M_system = min(M_i). Name the changed input. Decide whether “Direct recovery effort first at the limiting protected function while checking that the intervention does not create a new bottleneck.” still follows.

Autonomous correction — Minimum subsystem margin — the weakest protected margin controls the immediate gate

For Minimum subsystem margin — the weakest protected margin controls the immediate gate, state the altered case. Preserve dimensionless or %, only if all inputs use the same definition. Match the direction in “Improving a non-limiting 22% margin does not change system minimum until the 9% branch improves.”. Respect “Do not take a minimum across incompatible units or differently defined margins; normalize the decision metric first.”. Finish by retaining or revising: Direct recovery effort first at the limiting protected function while checking that the intervention does not create a new bottleneck.

21 — Mission decision
Direct recovery effort first at the limiting protected function while checking that the intervention does not create a new bottleneck.

Primary sources and bridges

First Man closed-loop ECLSS dossier — close mass, quality, buffers and recovery states

A closed loop is not “a recycler with a high percentage.” It is a controlled network of inventories, processors, sensors, quality gates, buffers, reject paths and degraded modes. This dossier teaches the learner to follow mass and evidence through that network and to protect crew survival when the process is uncertain.

Start with a mass balance, not a recovery percentage

NASA — Environmental Control and Life Support System describes the functions of environmental control and life support as an integrated set. A recovery percentage alone is not an inventory. The learner must know the demand basis, collectable stream, verified recovered stream, unavoidable losses, storage and make-up source.

Write the boundary first. If hygiene water, food water and technical water are mixed into one demand number, make sure the recovery stream covers the same categories. Otherwise a ninety-five-percent figure can be mathematically correct and operationally misleading.

Separate gross recovery from qualified recovery

NASA has reported high water-recovery performance on ISS, as described in the NASA — ISS water recovery milestone. The operational lesson is not that a Mars system may assume the same performance. It is that recovery, quality verification and inventory release are separate steps. Product held for analysis cannot be counted as crew water simply because it exited a processor.

The formula below therefore subtracts only verified recovered water from demand. Quarantine and off-spec streams stay visible.

Closed-loop mass balance with quality gates. Recovery flow is separated from verification, buffer storage, reject and quarantine paths.
Recovery flow is separated from verification, buffer storage, reject and quarantine paths. Pedagogical synthesis by Delta-Sierra from the primary sources cited at the point of use; not a mission-certified drawing.

Use buffers to buy diagnostic time

A buffer decouples crew demand from a processor for a limited period. Its value is measured in time under the degraded demand, not merely tank volume. Buffers allow isolation, sampling, repair and staged restart without immediately turning every process anomaly into a crew emergency.

But a buffer creates false confidence if the level sensor, valve path or water quality is uncertain. Keep verified accessible inventory separate from total physical inventory.

Treat humidity and trace contaminants as coupled loads

Cabin atmosphere quality is not only oxygen and carbon dioxide. Humidity, trace contaminants, particulates and microbial conditions can interact with thermal control and material behavior. A failed condensing heat exchanger can therefore change both humidity control and water recovery.

Coupling matters during troubleshooting. If one component supports several functions, isolating it to solve one problem can worsen another. The system diagram should show shared dependencies rather than only nominal flow arrows.

Plan manual degraded operation before automation fails

A closed-loop system often depends on sensors, control software and automatic valve sequencing. Manual operation is not a generic “crew can take over” statement. It requires accessible controls, procedures, training, time, communication and a safe range in which slower human action remains effective.

Record which variables must be monitored manually, at what interval, by which qualification and for how long. Human workload can become the limiting resource of a degraded ECLSS mode.

Degraded-mode restart state machine. Recovery proceeds through isolate, stabilize, repair, verify and staged-release gates.
Recovery proceeds through isolate, stabilize, repair, verify and staged-release gates. Pedagogical synthesis by Delta-Sierra from the primary sources cited at the point of use; not a mission-certified drawing.

Restart through staged verification

NASA-STD-3001 Volume 2 reinforces the broader human-system discipline: restoring a machine is not identical to restoring a safe crew environment. After repair, verify function, product quality, sensor agreement, leak integrity and stable trends before reconnecting the full crew load.

A failed verification should send the loop back to isolation or diagnosis, not be treated as an inconvenience to be waived. The second atlas figure makes this state logic explicit.

Track common-cause dependencies across water, air and thermal

Power, cooling, controls, pumps and shared sensors can create common-cause failures. Two processors do not create true redundancy if both depend on the same unprotected power controller or coolant loop. The architecture review should identify what each “independent” path actually shares.

A useful drill is to remove one common support function and ask which loops remain controllable. The answer often reveals that the real redundancy problem sits outside the processor itself.

Board scenario — high recovery, rising quarantine

The water processor still reports excellent gross recovery, but conductivity and microbial screening place an increasing fraction of product in quarantine. Storage is falling even though the dashboard headline says recovery is above ninety percent.

A strong response shifts the dashboard to verified inventory, isolates the quality problem, protects reserve, reduces nonessential demand and decides how long the crew can operate before a repair or resupply path becomes mandatory. High process efficiency does not overrule a failed release gate.

Operational review drills — explain the evidence, not only the answer

  1. Boundary drill. Define demand and recovery on the same accounting boundary before quoting a percentage.
  2. Quality drill. Explain why quarantined recovered water cannot be credited to crew inventory.
  3. Buffer drill. Convert verified tank inventory and net deficit into diagnostic time.
  4. Manual-mode drill. List the variables and crew minutes needed for six hours of manual control.
  5. Common-cause drill. Remove one shared power controller and identify which supposedly redundant functions disappear.
  6. Restart drill. Write the verification sequence after replacing a contaminated process line.

Qualification notebook — closed-loop survival when the dashboard looks healthy

Closed loops fail in ways that headline recovery percentages can hide. These cases train the learner to follow verified inventory, quality, buffers, common causes and human workload through degraded operations.

Review-board ledger

  • Qualified demand
  • Gross recovered flow
  • Quarantined / off-spec
  • Verified recovered flow
  • Verified storage
  • Daily make-up
  • Manual crew minutes
  • Next quality / recovery gate
Case 1 — ninety-six percent recovery, falling potable inventory

Situation. The processor reports 96% gross water recovery, yet potable storage falls every day because an increasing fraction of output remains in quarantine. Management wants to advertise the recovery number as evidence the loop is healthy.

Reasoned disposition. Shift the primary operational metric to verified recovered mass and accessible potable inventory. Keep gross process recovery as a diagnostic metric, not a release metric. Calculate daily make-up from verified recovery, estimate time to the protected reserve and investigate the quality failure. A high recovery percentage cannot close a crew water balance with quarantined product.

Case 2 — redundant processors share one controller

Situation. Two water processors are installed and the architecture labels them redundant. A controller failure disables the valves and sensors serving both.

Reasoned disposition. The processors are duplicated, but the function is not independent. Redundancy analysis must follow power, control, cooling, feed and discharge paths. Add an independent control or manual safe configuration, or change the claim from redundant to duplicated hardware with a common-cause dependency. Terminology matters because it changes what failures the crew expects to survive.

Case 3 — manual mode consumes the maintenance team

Situation. Automatic control is unavailable. The loop can be kept safe manually, but it requires two qualified operators for ten minutes every half hour. The same people are needed for a power-system repair.

Reasoned disposition. Translate manual mode into person-hours and qualification occupancy. The loop may be physically controllable but operationally unsustainable. Prioritize actions that reduce monitoring frequency, add backup operators or simplify the degraded configuration. Human workload belongs in the ECLSS failure model because it can become the shared resource that causes a second failure.

Case 4 — repaired hardware, failed quality verification

Situation. A contaminated line is replaced and flow returns to normal. A quick sensor check looks acceptable, but a required laboratory quality result is still pending.

Reasoned disposition. Do not equate restored flow with restored safe service. Keep the branch isolated or in controlled recirculation until the release evidence closes. If storage margin permits, preserve the verification sequence. If margin does not permit, escalate the conflict explicitly rather than silently waiving the quality gate.

Case 5 — surplus recovery with full storage

Situation. A repaired system temporarily produces more qualified water than daily demand, and the make-up equation correctly returns zero. Storage is already near maximum.

Reasoned disposition. Use a separate storage balance. Decide whether surplus can be routed to another qualified use, stored in another tank or safely curtailed. Never report negative make-up as though it were a credit that can be spent elsewhere. The state of tanks and alternate sinks becomes the limiting condition once demand is fully covered.

Daily verified make-up requirement for a closed water loop

m_makeup = max(0, m_demand − m_verified,recovered)
1 — Concrete question
How much new qualified water must enter the crew inventory each day after verified recovery is counted?
2 — Intuition without symbols
Start from the day’s qualified demand and subtract only the recovered water that has actually passed the quality gate. If recovery exceeds demand, make-up cannot become negative; handle the surplus as storage or another stream.
3 — Quantities first
m_demand is qualified daily water demand; m_verified,recovered is recovered water released by the quality gate; m_makeup is the external or stored qualified water needed to close the daily balance.
4 — Formula
m_makeup = max(0, m_demand − m_verified,recovered)
5 — Read aloud
“m makeup equals the maximum of zero and m demand minus m verified recovered.”
6 — Symbols
m denotes mass over the stated daily accounting period. The max function prevents a physically meaningless negative make-up requirement.
7 — Pronunciation
max is read “maximum”. The verified-recovered subscript means the recovered stream has passed its release criteria.
8 — Units
kg/day − kg/day = kg/day.
9 — Convention
Recovered process flow is not counted until quality is verified. Any surplus above demand is accounted for separately as storage accumulation, export to another use or controlled disposal.
10 — Why this operation
Demand must be met by qualified inventory. Subtracting verified recovery shows the residual that must come from make-up sources; clipping at zero keeps the meaning of make-up physically valid.
11 — Assumptions
The daily accounting boundary includes the same uses in demand and recovery. Storage changes and intentionally nonrecoverable uses are tracked separately rather than hidden inside recovery percentage.
12 — Unit check
Both input terms are daily mass flows, so the difference is kg/day.
13 — Numerical case

Qualified demand m_demand = 80 kg/day.

Processor reports 76 kg/day gross recovery, but 3 kg/day remains quarantined after quality checks.

Verified recovered water = 76 − 3 = 73 kg/day.

m_makeup = max(0, 80 − 73) = 7 kg/day.

14 — Why each operation
First remove unverified product from the recovery claim. Then subtract verified recovery from qualified demand. The max operator prevents surplus production from being mislabeled as negative make-up.
15 — Algebra check
When verified recovery is below demand, m_verified,recovered = m_demand − m_makeup. If verified recovery is at or above demand, make-up is zero and the surplus requires a separate storage-balance equation.
16 — Mental estimate
If demand is eighty and verified recovery is a little above seventy, make-up should be around seven, so the result is plausible.
17 — Interpretation
The crew loop needs 7 kg/day of qualified make-up under this accounting state.
18 — What it does not prove
It does not prove storage is sufficient, pumps are reliable, microbiological quality is stable, recovery can be sustained or the make-up source is accessible.
19 — Sensitivity or limit case
If quarantine rises from 3 to 10 kg/day while gross recovery stays at 76, verified recovery falls to 66 and make-up doubles to 14 kg/day. Quality performance can dominate the inventory even when gross recovery looks unchanged.
20 — Practice

Guided exercise. Demand is 95 kg/day. Gross recovery is 90 kg/day but 4 kg/day is held pending quality release. Find verified recovery and make-up.

Detailed guided correction.

  1. Verified recovery = 90 − 4 = 86 kg/day.
  2. Make-up = max(0, 95 − 86) = 9 kg/day.
  3. The 4 kg/day hold is not silently credited until the quality gate releases it.

Autonomous exercise. Demand is 70 kg/day and verified recovery is 74 kg/day for three days. Explain what the formula returns and write the separate storage change if all 4 kg/day surplus can be stored.

Autonomous correction — open after attempting the exercise

One defensible worked solution.

  1. m_makeup = max(0, 70 − 74) = 0 kg/day.
  2. There is no negative make-up; the loop simply needs no external make-up under this simplified daily balance.
  3. Storage accumulation = (74 − 70) × 3 = 12 kg if storage capacity and quality remain available.
  4. If storage is full, the 4 kg/day surplus needs another disposition rather than changing the meaning of make-up.
21 — Mission decision
Use only verified recovery to close the crew water balance. Treat quarantine, storage capacity and surplus disposition as explicit states so a high recovery percentage cannot hide a shortage of releasable water.

Primary-source map for this operational dossier

Closed-loop ECLSS qualification casebook — mass balance, quality, buffers and staged recovery

A high recovery percentage is not the same as a survivable loop. A habitat must close mass, verify product quality, maintain buffers, detect contamination, preserve manual modes and recover through evidence gates. This dossier deepens the learner’s ability to reason across the water, air, humidity, trace-contaminant and thermal interfaces as one coupled survival system.

Crew demand, water, air, humidity, buffers, quality and shared utilities are shown as one closed-loop network.
Crew demand, water, air, humidity, buffers, quality and shared utilities are shown as one closed-loop network. Pedagogical synthesis by Delta-Sierra from the primary sources cited in this dossier; not a mission-certified drawing.

Dynamic mass balance comes before efficiency slogans

Primary source: NASA — Environmental Control and Life Support System.

Every loop has inputs, outputs, storage and losses that vary with time. A recovery percentage describes one relationship but does not reveal whether the inventory is rising or falling. The operator needs to know the actual make-up demand, buffer level and trend.

A healthy-looking percentage can coexist with a serious shortfall if total demand rises, product is quarantined or the recovered stream fails quality checks. Use mass balance and verified product flow together.

Qualified recovery is the only recovery the crew can drink or breathe

A processor may produce fluid or gas while downstream quality is uncertain. That stream is physically recovered but not operationally available. The distinction between gross and qualified recovery prevents dashboards from crediting inventory that the crew cannot safely use.

Quarantine should therefore have its own storage, sampling plan and release authority. If quality evidence is delayed, the buffer must absorb the gap without forcing premature acceptance.

Buffers buy diagnostic time, not permission to delay forever

Storage tanks, compressed gas, sorbent capacity and contingency consumables are time buffers. They convert an immediate failure into a bounded diagnostic window. Their value depends on verified usable inventory and the degraded-mode consumption rate.

Operators should know the trigger points that change behaviour: begin conservation, stop discretionary use, isolate a suspected stream, switch to backup processing or enter a safe-haven mode. A buffer without action thresholds is only a number.

Humidity and trace contaminants cross subsystem boundaries

Primary source: NASA — ISS water recovery milestone.

Water removal from cabin air interacts with temperature, airflow and microbial risk. Trace contaminants interact with materials, cleaning products, payloads and fire response. These loads do not respect the organisational chart of the hardware.

When one measurement trends abnormally, the investigation should follow physical pathways. A humidity change can indicate thermal-control behaviour, ventilation imbalance or condensate-processing problems rather than a stand-alone ‘humidity system’ failure.

Normal, degraded, isolated and recovery states include rollback when evidence fails.
Normal, degraded, isolated and recovery states include rollback when evidence fails. Pedagogical synthesis by Delta-Sierra from the primary sources cited in this dossier; not a mission-certified drawing.

Sensors and automation require an independent reality check

Closed loops depend heavily on measurement. A drifting sensor can cause the controller to move the process in the wrong direction while the automation reports that it is responding correctly.

Critical variables therefore need cross-checks, plausibility limits and manual diagnostic procedures. The crew must know how to recognise a sensor fault from a process fault and how to hold a safe configuration while that distinction is unresolved.

Manual degraded mode should be designed before it is needed

When automation or one processor fails, the crew may have to sample manually, move valves, change filters, ration use or bypass a component. These actions consume time and can create new contamination risks.

The degraded-mode procedure should state which functions can be lost temporarily, which must continue, which measurements become manual, how often they are taken and when crew workload itself becomes the limiting factor.

Restart should progress through evidence states

Primary source: NASA-STD-3001 Volume 2.

After maintenance, the safest sequence is not ‘turn everything back on’. Isolate, inspect, leak-check, start at controlled conditions, verify sensor agreement, quarantine initial product if needed and only then reconnect to the crew loop.

Each step has a rollback point. If evidence fails, the operator returns to the previous stable configuration rather than pushing forward because the schedule expects recovery.

Common-cause dependencies can defeat nominal redundancy

Two redundant water processors may share power, cooling, software, a common filter stock or the same specialist. A pair of diagrams showing two boxes does not prove independent resilience.

The architecture should map shared utilities, consumables, maintenance access and human expertise. True redundancy is a property of failure independence and recovery capability, not of box count.

Qualification casebook — six board decisions

  1. 1. Recovery percentage is high but the potable tank is falling. Demand increased during a medical event.

    Reasoned disposition — open after making your own decision

    Use the mass balance: high percentage does not guarantee positive inventory. Reduce discretionary demand and verify qualified production against the new load.

  2. 2. Recovered water enters quarantine after an unexpected reading. Storage can support the crew for two days.

    Reasoned disposition — open after making your own decision

    Use the buffer to investigate; do not release uncertain product merely to preserve a dashboard target. Define sampling and release criteria.

  3. 3. Humidity rises while the water processor appears normal. Cabin temperature also changed.

    Reasoned disposition — open after making your own decision

    Trace the coupled path through ventilation, condensation and thermal control rather than assuming one dedicated component is at fault.

  4. 4. One CO2 sensor drifts slowly. The controller increases removal effort.

    Reasoned disposition — open after making your own decision

    Cross-check independent measurements and crew/environment indicators. Stabilise the loop while determining whether the sensor or process is wrong.

  5. 5. Automation fails during a weekend science campaign. The manual mode exists only in a maintenance manual.

    Reasoned disposition — open after making your own decision

    Activate the predefined degraded procedure, reduce optional loads and account for crew-hours. A theoretically possible manual mode is not operationally available unless practised.

  6. 6. A repaired processor produces good output for ten minutes. The team wants to reconnect immediately.

    Reasoned disposition — open after making your own decision

    Continue staged verification for the required endurance and sensor agreement, quarantine initial product if appropriate and preserve the rollback state until evidence closes the gate.

Mastery studio — four extended review problems

Use these ECLSS problems to trace mass, quality, buffers and recovery state across coupled loops instead of trusting one efficiency number.

  1. 1. High recovery, falling inventory. The water processor reports 96% gross recovery, yet verified potable storage falls every day.

    Extended reasoned answer — open after attempting the problem

    Build the actual mass balance. Compare crew demand, qualified recovered output, quarantined product, leaks, cleaning loads and other losses. The percentage may be calculated on processor feed while mission demand has increased elsewhere. Protect buffer thresholds and change operations based on verified inventory trend, not the reassuring recovery number. If the qualified output cannot meet essential demand, the loop is in deficit regardless of the headline efficiency.

  2. 2. Sensor-driven false correction. A drifting humidity sensor causes the controller to increase dehumidification and changes cabin thermal behaviour.

    Extended reasoned answer — open after attempting the problem

    Freeze the automation in a safe bounded mode if necessary, compare independent humidity and temperature measurements, inspect condensate flow and check sensor calibration. The symptom crosses humidity, thermal control and water recovery, so a single subsystem dashboard is insufficient. After identifying the bad sensor, restore control gradually and verify that the water and thermal loops return to expected state without creating a second transient.

  3. 3. Quarantined product fills storage. A quality anomaly leaves several days of recovered water in quarantine tanks while the verified potable buffer declines.

    Extended reasoned answer — open after attempting the problem

    The system has mass but not usable inventory. Define a sampling plan and release criteria, protect verified potable stock for essential uses and decide whether nonessential water demand must be reduced. If quarantine capacity becomes the new bottleneck, the crew may need to stop or reroute recovery even though the processor itself is healthy. The case demonstrates why quality and storage architecture are part of loop closure.

  4. 4. Recovery after maintenance. A repaired CO2 removal assembly meets its target for fifteen minutes after restart.

    Extended reasoned answer — open after attempting the problem

    Do not declare recovery from one good reading. Verify sensor agreement, stable performance over the required endurance, acceptable cabin trend and the absence of new leakage or thermal effects. Maintain a rollback configuration until the evidence gate is satisfied. Only then return from degraded operation to normal automation. Recovery means restored function plus enough proof that the function will persist, not merely a successful startup transient.

Primary sources used in this qualification dossier

Closure standard. The learner can close a dynamic life-support balance, distinguish gross from qualified recovery, protect buffers and restore the loop through staged evidence rather than optimistic automation.

ECLSS fault isolation and recovery proof — do not let one sensor become reality

Closed-loop systems create a particular trap: a dashboard can look efficient while quality, inventory or instrumentation is drifting. The operational layer adds a diagnostic discipline that asks which independent observations should change if a hypothesis is true, and turns restart into an evidence sequence rather than a switch flip.

ECLSS fault isolation and recovery proof — do not let one sensor become reality. Operational decision diagram for module 27.
Decision atlas — ECLSS fault isolation and recovery proof — do not let one sensor become reality. Pedagogical synthesis by Delta-Sierra; use the full-size link for fine labels.

Independent evidence separates sensor drift from process drift

If a water-quality value changes, the team should look for independent corroboration: grab sample, tank level, conductivity, flow, humidity or process chemistry depending on the loop. A single sensor is evidence, not reality. The expected cross-effects help distinguish a bad measurement from a real mass-balance problem.

The anomaly-isolation matrix in the atlas is deliberately qualitative. Its purpose is to train the learner to predict what else should change under each hypothesis before touching the system.

Buffers provide diagnostic time but can hide worsening faults

A large potable-water tank can keep crew supply stable while recovery output degrades. That is good because the crew remains protected, but dangerous if the buffer masks the deterioration until little reserve remains. Operations should track both buffer state and process health.

A board therefore asks not only ‘how many days remain?’ but ‘is the underlying process improving, stable or worsening?’ A buffer is a time resource, not a repair.

Microbial and chemical quality need trend context

A closed water loop can meet bulk recovery targets while trace contaminants or microbial conditions drift. Sampling frequency, analytical sensitivity and quarantine policy therefore influence how quickly the problem becomes visible.

The module should avoid implying that one recovery percentage certifies water. NASA ECLSS material is the primary bridge for actual ISS environmental-control functions; the diagnostic matrices here are pedagogical abstractions.

Restart should requalify outputs before reconnecting critical loads

After maintenance or isolation, a loop may flow before its product is qualified. Water can circulate while quality remains uncertain; an air loop can move gas while a contaminant-control branch is still unstable. Recovery therefore separates mechanical restart from functional qualification and from return to normal redundancy.

The staged sequence is: verify configuration, establish controlled operation, measure independent evidence, qualify output, reconnect critical users and only then retire the degraded-state restrictions. This prevents the crew from becoming the acceptance test.

Common-cause failures often live outside the process hardware

Two pumps can be redundant and still share power, cooling, software, sensors or maintenance expertise. A common calibration procedure can bias multiple sensors at once. A shared tank can propagate contamination across nominally separate branches.

The reliability review therefore draws dependencies across loops. NASA-STD-3001 Volume 2 provides a primary human-factors/habitability bridge for environmental conditions; detailed loop design requires the relevant subsystem standards and test evidence.

Operational review board — five decisions to defend

  1. 1. Water recovery percentage is normal, tank falls. The dashboard says 92% recovery.

    Reasoned disposition — open after making your own decision

    Check real flows, leaks, usage and instrumentation. Percentage alone cannot close a mass balance.

  2. 2. Two sensors drift together. Both were calibrated in the same maintenance session.

    Reasoned disposition — open after making your own decision

    Treat common calibration error as a hypothesis and use an independent method before changing the process.

  3. 3. Buffer remains healthy while product quality worsens. Crew supply is still adequate.

    Reasoned disposition — open after making your own decision

    Use the buffer to diagnose deliberately, but impose a decision deadline based on trend and remaining qualified inventory.

  4. 4. Loop restarts and flow looks normal. Quality sample is pending.

    Reasoned disposition — open after making your own decision

    Keep critical users isolated or supplied from qualified reserve until output passes the required acceptance evidence.

  5. 5. Redundant processors fail after a software update. Hardware is physically independent.

    Reasoned disposition — open after making your own decision

    Treat the shared software/configuration path as common cause; rollback or isolate configuration before claiming redundancy restored.

Mission rehearsal notebook — reason through evidence before revealing the disposition

Diagnostic drill — apparent leak is actually demand growth

Tank inventory declines faster than last month while recovery efficiency appears unchanged. Before opening plumbing panels, the team reconciles crew use, plant experiments, humidity recovery and new cleaning procedures. The balance shows that demand increased after a new greenhouse activity began. The exercise demonstrates that an unexplained inventory trend is not automatically a hardware leak; complete accounting precedes invasive troubleshooting.

Diagnostic drill — common calibration error

Two redundant quality sensors were calibrated from the same reference solution and drift together. Agreement between them is therefore not independent confirmation. A grab sample using a different analytical method becomes more valuable than a third reading from the same calibration chain. The lesson generalizes beyond ECLSS: redundancy of hardware does not imply independence of evidence.

Recovery drill — output returns before redundancy

A repaired processor produces qualified water again, but its backup train remains isolated and the buffer is still low. Operations may leave the emergency state but should not declare full mission recovery. The board defines intermediate states—function restored, reserve rebuilt, redundancy restored—and ties mission tempo to those states. This prevents a premature return to aggressive operations while the system is still one fault away from renewed crisis.

Primary sources used in this exercise

Closure review — closed-loop resilience is mass balance, qualified output and recoverability

A recovery percentage can be technically impressive while the crew still depends on large reserves, fragile sensors or one specialist. The final standard therefore asks five separate questions. Does the mass balance close? Is the output actually qualified for its intended use? Is enough protected reserve available while diagnosis occurs? Can the system be isolated without contaminating other loops? Can a degraded crew recover it with evidence rather than hope?

Mass balance is the first diagnostic, not the last audit

If tank level declines faster than expected, the team reconciles all known inflows, outflows and transfers before declaring a leak. Crew demand may have changed. A greenhouse or cleaning campaign may add load. Condensate recovery may shift. A sensor may be biased. The balance does not prove which cause is correct, but it makes hidden consumption visible and tells the team how quickly the inventory problem is becoming operational.

Qualified output is a different state from gross recovered output

Recovered water in a process tank is not automatically drinking-water inventory. Air circulated through a loop is not automatically proven safe. Sampling, independent sensor evidence, microbial/chemical acceptance and configuration state can place output in quarantine. The inventory ledger therefore distinguishes gross recovered, awaiting qualification, rejected/rework and qualified available output.

Buffers buy investigation time only while the trend remains bounded

A healthy buffer can make a failing process look calm. The board uses the buffer to create diagnostic time, but it sets a deadline based on current inventory, trend and uncertainty. If quality is worsening or a common-cause failure is plausible, the correct action can be to isolate earlier rather than consume the entire buffer while waiting for certainty.

Evidence independence should be visible in the diagnostic matrix

The anomaly-isolation atlas now uses P, S and ! symbols in addition to colour. The accessibility improvement also reinforces the engineering lesson: an independent measurement is not the same thing as a second display using the same sensor chain. A laboratory grab sample, physical inventory measurement or independently calibrated instrument can carry more diagnostic value than another reading generated from the same calibration source.

Manual degraded mode must have staffing and duration limits

Manual sampling, transfers or valve alignment can preserve life-support functions after automation is lost, but the workaround consumes crew time and raises human-error exposure. The procedure should specify qualification, two-person verification where hazardous, maximum sustainable cadence, protected rest and the trigger for simplifying the configuration or reducing demand. A workaround that can be sustained for one shift may not be a viable multi-day operating mode.

Restart is a sequence of evidence states

A pump running or a normal flow indication is only the start. The team proves the cause is controlled, verifies the configuration, restarts at bounded conditions, checks process response, qualifies output, reconnects critical loads and then rebuilds reserve/redundancy. The system can therefore pass through function restored, reserve rebuilt and redundancy restored as separate states. Mission tempo should reflect which state has actually been reached.

Closure case 1 — two quality sensors agree after shared calibration

Agreement is not independent confirmation. Treat common calibration bias as a live hypothesis and seek an independent analytical method or reference. Do not reconfigure the process solely because two instruments share the same number.

Closure case 2 — buffer remains strong but microbial trend is worsening

Set an isolation/decision deadline before the buffer becomes the reason to delay. Protect a qualified reserve, increase independent sampling and determine whether the affected inventory must be quarantined. The buffer is buying evidence time, not permission to ignore trend.

Closure case 3 — manual mode restores water but consumes half the maintenance shift

Record the workload as part of system status. Reduce other demand, train backup operators and determine how long the manual mode can be sustained without creating maintenance debt or fatigue-related risk elsewhere.

Closure case 4 — output is qualified but backup train remains isolated

Function may be restored, but resilience is not. Keep the architecture in an intermediate recovery state until reserve and redundancy are rebuilt or the mission formally accepts the reduced fault tolerance.

Freeze criteria for this module

  • The learner can close a water or air mass balance before discussing recovery percentage.
  • The learner distinguishes gross recovery from qualified output.
  • The learner explains why buffers, independent evidence and workload determine diagnostic time.
  • The learner can describe staged restart and why “output returned” is not equivalent to “mission recovered”.
  • The learner can identify shared power, thermal, software, calibration and human dependencies as common causes.

Closure drill — a closed loop still exchanges mass with storage and the crew

No loop should be described as “closed” without naming its remaining imports, exports, losses and stored buffers. The learner should be able to draw the boundary around the process, identify what crosses it and explain why a high recovery percentage does not remove the need for verified reserve.

Closure drill — contamination creates inventory states

If a tank is quarantined, the water still exists physically but is not qualified crew inventory. The operations ledger should therefore avoid counting quarantined output as available until the acceptance evidence closes. This same state-based reasoning is used in the ISRU module.

Primary bridges: NASA ECLSS, the ISS water-recovery milestone, and NASA-STD-3001 Volume 2.