Advanced ECLSS: closed loops, quality and degraded modes
Mastery objectives
- explain quantities, units and assumptions
- repeat at least one calculation by hand
- identify uncertainty, limits and failure modes
- turn the result into a decision for a Mars architecture
1. Closing a loop does not mean 100 percent recovery
Life-support systems recover a fraction of water, oxygen or nutrients. Even small losses accumulate and must be replaced by storage or local production.
Efficiency only becomes meaningful when linked to daily flow and mission duration.
2. Water has multiple streams and quality requirements
Urine, humidity condensate, hygiene water and process streams contain different contaminants. Keeping them separate can simplify treatment.
High throughput is not success unless product water meets quality requirements.
3. Air combines oxygen, CO₂ removal and trace contaminants
Atmospheric control requires oxygen supply, carbon dioxide removal, ventilation, filtration and trace-contaminant monitoring.
A safe cabin average can hide a dangerous local pocket if ventilation is poor.
4. Degraded modes and reserves
A robust ECLSS defines what happens when a water processor, sorbent bed or electrolyser is unavailable. Reserves buy time but do not replace repair.
Time-to-criticality after a failure is as important as nominal efficiency.
5. From ISS to Mars autonomy
ISS can receive logistics far more frequently than Mars. A Mars base needs deeper diagnostics, spares, cleaning and refurbishment capability.
Closed-loop design is ultimately about slowing residual dependence enough to survive between transport windows.
6. Closing a loop does not eliminate losses
A 98% recovery rate sounds nearly perfect, but a 2% daily loss becomes substantial over a long mission. Water, oxygen and waste loops therefore need explicit mass balances. Maintenance flushes, samples and inventory temporarily trapped inside equipment also matter. Any claimed closure percentage should state the system boundary to which it applies.
7. Water quality: recovery and potability are different functions
Recovering water does not mean it is immediately potable. Filtration, adsorption, catalytic oxidation, conductivity monitoring and disinfection address different contaminants. Sensors can detect some drift, while periodic analysis is still needed for microbiology and chemistry. A robust loop also defines what happens to out-of-specification water: reprocess it, isolate it or redirect it to a non-potable use according to diagnosis.
8. Degraded mode: survive while the loop is open
Maintainability requires the ability to isolate a pump, filter bed or reactor without instantly losing the entire function. Buffer tanks, bypasses, consumables and manual procedures create time to diagnose. The key metric is therefore not only nominal efficiency but the time for which the crew can preserve water, oxygen and carbon-dioxide control after a defined failure.
Closed-loop case: high recovery does not remove stored reserve
A 98 percent water recovery rate looks almost complete, but a settlement continuously loses the remaining fraction and must survive maintenance outages. Buffer inventory covers both normal losses and a credible treatment downtime. A closed loop is therefore a low-loss loop, not a machine that creates matter. Water, oxygen and consumable reserves buy operators time to diagnose a failure before it becomes immediately life-threatening.
9. Worked example step by step
A teaching comparison starts from the same daily process flow but asks how a few percentage points of recovery change long-duration logistics. The complete make-up calculation is developed in the “Daily verified make-up requirement for a closed water loop” mini-lesson below, including the distinction between theoretical recovery and verified qualified output.
10. Progressive exercise
For six people, build a daily balance including drinking, food preparation, hygiene and metabolic water. Choose a recovery rate and calculate makeup over 900 days. Then inject a 72 h failure of the primary processor and size the required buffer.
11. Reasoned solution
A reserve can look enormous against a small steady make-up loss and simultaneously look very small against a complete recovery failure. Use the make-up formula below for the steady-loss case, then recalculate the failure case from full essential demand; the two horizons answer different operational questions and must not be mixed.
12. Validation mini-project
Create a complete water-loop architecture: sources, collection, treatment, sensors, disinfection, storage, waste streams, degraded mode, maintenance, consumables and the decision protocol for out-of-specification water.
Closed-loop control laboratory — design for quality, reserve and recoverability
This closed-loop-systems extension connects balances, sensors, buffers, verified recovery, fault isolation and restart evidence so the learner can distinguish nominal closure from a system that is actually recoverable.
Close mass balances with explicit losses
A recovery percentage is meaningful only when the input stream and time basis are defined. Every loop has losses, purge flows, retained mass and maintenance events. Track those explicitly. A claimed 98% recovery rate does not mean only 2% makeup forever unless the same boundary and operating state are maintained.
Separate recovery from potability or breathability
Recovering water or air components is not the same as meeting a quality specification. Treatment, monitoring and release criteria are independent functions. A system can produce the required quantity while failing chemistry or microbiological acceptance. Buffer tanks and isolation valves are valuable because they allow production to be tested before it mixes with verified inventory.
Use buffers to buy diagnostic time
Stored water, oxygen and sorbent capacity turn repair time into a manageable variable. The buffer must be sized against essential demand and realistic isolation/repair/retest time, not average nominal operation alone. If a repair requires twenty hours but the safe buffer lasts twelve, the architecture is already in deficit before the failure occurs.
Control humidity and trace contaminants as coupled loads
Crew, plants, cooking, hygiene and equipment all add moisture and contaminants. Condensate recovery can support the water loop, but contamination control and microbial growth must be managed. Air processing is therefore a coupled mass-transfer and quality problem rather than a single carbon-dioxide-removal function.
Plan degraded manual operation before it is needed
Automatic control may fail through sensors, software, valves or power. Define which parameters can be monitored manually, which valves can be positioned safely, how often samples are required and how long the crew can sustain the workload. Manual operation should be rehearsed and documented because emergency improvisation creates new common-cause risk.
Restart through staged verification
After maintenance, prove local function before reconnecting the entire loop. Confirm sensor agreement, leak tightness, quality criteria and stable trends. If possible, route output to a quarantine or test volume first. A staged restart protects the rest of the habitat from a repair that is mechanically complete but chemically or biologically unverified.
Progressive mastery drills — eight linked checks
Drill 1 — Dynamic mass balance
Write inputs, outputs, stored inventory and losses for one loop over a defined time interval.
Expected reasoning for “Drill 1 — Dynamic mass balance”: state the evidence, the assumption, the uncertainty and the operational consequence; a label or definition alone is not a complete answer.
Drill 2 — Oxygen loop
Separate generation rate, cabin demand, stored reserve and release criteria.
Expected reasoning for “Drill 2 — Oxygen loop”: state the evidence, the assumption, the uncertainty and the operational consequence; a label or definition alone is not a complete answer.
Drill 3 — CO2 removal
Identify capacity, breakthrough or saturation indicators and the degraded alternative.
Expected reasoning for “Drill 3 — CO2 removal”: state the evidence, the assumption, the uncertainty and the operational consequence; a label or definition alone is not a complete answer.
Drill 4 — Water recovery
Separate recovery percentage from potable-water acceptance.
Expected reasoning for “Drill 4 — Water recovery”: state the evidence, the assumption, the uncertainty and the operational consequence; a label or definition alone is not a complete answer.
Drill 5 — Humidity and condensate
Trace moisture from cabin generation to collection, treatment and verified storage.
Expected reasoning for “Drill 5 — Humidity and condensate”: state the evidence, the assumption, the uncertainty and the operational consequence; a label or definition alone is not a complete answer.
Drill 6 — Trace contaminants
Identify monitoring, filtration and the action when measurement confidence is lost.
Expected reasoning for “Drill 6 — Trace contaminants”: state the evidence, the assumption, the uncertainty and the operational consequence; a label or definition alone is not a complete answer.
Drill 7 — Sensors and actuators
Show how a failed sensor can create a control failure even when the process hardware is healthy.
Expected reasoning for “Drill 7 — Sensors and actuators”: state the evidence, the assumption, the uncertainty and the operational consequence; a label or definition alone is not a complete answer.
Drill 8 — Buffers and autonomy
Calculate or estimate how stored reserve converts repair time into survivable time.
Expected reasoning for “Drill 8 — Buffers and autonomy”: state the evidence, the assumption, the uncertainty and the operational consequence; a label or definition alone is not a complete answer.
Integrated exercise — Eight-step ECLSS closure drill
Prepare a worked checklist for dynamic mass balance, oxygen generation, carbon-dioxide removal, water recovery, humidity/condensate, contaminants/filtration, sensors/actuators/control and buffer inventory. For each function, state the normal measurement, one failure indicator and the degraded-mode action.
Reasoned solution. A passing answer shows how the eight functions interact. It should include at least one case where quantity is acceptable but quality is not, and one case where a buffer gives the crew time to isolate, repair and verify before the reserve reaches its protected minimum.
Primary sources for this section. NASA — ISS water recovery milestone NASA — Environmental Control and Life Support System (ECLSS) NASA-STD-3001 Volume 2 — Human factors, habitability and environmental health. Use these references to verify the assumptions, limits and values that apply to the mission context.
Quantitative practice laboratory — close the life-support loops numerically
These ten mini-lessons reproduce the FR calculation competencies for dynamic mass balance, gas production and removal, water recovery, condensation, filtration, control, autonomy, spares and limiting system margin; the existing water make-up lesson remains as an additional integrative calculation.
Dynamic mass balance — account for every pathway
- 1 — Concrete question
For Dynamic mass balance — account for every pathway, how does
dM/dt = In - Out + Production - Consumptioninform tracking a reservoir in a closed-loop life-support system and the operational choice “Use signed mass balances to detect slow inventory drift before a tank alarm becomes the first evidence.”?- 2 — Intuition without symbols
Intuition. A life-support reservoir changes because material enters, leaves, is generated, is consumed and may be lost. A trustworthy balance accounts for every important pathway instead of looking only at the tank level.
- 3 — Quantities first
- In and Out are transfer rates; Production and Consumption are internal source/sink rates; dM/dt is net inventory change rate.
- 4 — Formula
- dM/dt = In - Out + Production - Consumption
- 5 — Read aloud
- “d M by d t equals In minus Out plus Production minus Consumption.”
- 6 — Symbols
Symbol map for Dynamic mass balance — account for every pathway. In and Out are transfer rates; Production and Consumption are internal source/sink rates; dM/dt is net inventory change rate.
- 7 — Pronunciation
Pronunciation. Say
dM/dt = In - Out + Production - Consumption. For Dynamic mass balance — account for every pathway, use the step-three names tied to tracking a reservoir in a closed-loop life-support system. Speak each Dynamic mass balance — account for every pathway unit with the quantity it measures.- 8 — Units
- kg/day
- 9 — Convention
Convention. For Dynamic mass balance — account for every pathway, keep tracking a reservoir in a closed-loop life-support system on one declared boundary. Apply
dM/dt = In - Out + Production - Consumptionunder that convention. A balanced total can hide incompatible chemical species; each conserved constituent may need its own balance.- 10 — Why this operation
Why this operation.
dM/dt = In - Out + Production - Consumptionanswers the Dynamic mass balance — account for every pathway question because it represents tracking a reservoir in a closed-loop life-support system. In this case it yields: The reservoir grows by 1 kg/day in this simplified balance.- 11 — Assumptions
Assumptions. Treat the Dynamic mass balance — account for every pathway values as one teaching case. For tracking a reservoir in a closed-loop life-support system, keep a single physical or operational boundary. A balanced total can hide incompatible chemical species; each conserved constituent may need its own balance.
- 12 — Unit check
Unit check. Reduce
dM/dt = In - Out + Production - Consumptionfor Dynamic mass balance — account for every pathway. The required dimension iskg/day. A different dimension invalidates “The reservoir grows by 1 kg/day in this simplified balance.”.- 13 — Numerical case
In = 95 kg/dayOut = 100 kg/dayProduction = 8 kg/dayConsumption = 2 kg/daydM/dt = 95−100+8−2 = +1 kg/day- 14 — Why each operation
Why each operation. For Dynamic mass balance — account for every pathway, substitute In = 95 kg/day; Out = 100 kg/day; Production = 8 kg/day; Consumption = 2 kg/day; dM/dt = 95−100+8−2 = +1 kg/day into
dM/dt = In - Out + Production - Consumption. Then verify the independent statement “95+8 = 103 in/source; 100+2 = 102 out/sink; difference = +1”.- 15 — Algebra check
Algebra check. Reverse
dM/dt = In - Out + Production - Consumptionfor Dynamic mass balance — account for every pathway using “95+8 = 103 in/source; 100+2 = 102 out/sink; difference = +1”. The recovered input should follow “A 2 kg/day increase in Out changes the net from +1 to −1 kg/day.”. If not, recheck units and boundaries.- 16 — Mental estimate
Mental estimate. Round the dominant inputs for Dynamic mass balance — account for every pathway. Compare that rough scale with “The reservoir grows by 1 kg/day in this simplified balance.”. If they diverge sharply, inspect
dM/dt = In - Out + Production - Consumptionfor units, signs or boundaries.- 17 — Interpretation
Interpretation. For Dynamic mass balance — account for every pathway, The reservoir grows by 1 kg/day in this simplified balance. Operationally: Use signed mass balances to detect slow inventory drift before a tank alarm becomes the first evidence. The interpretation remains limited by “A balanced total can hide incompatible chemical species; each conserved constituent may need its own balance.”.
- 18 — What it does not prove
What it does not prove. Dynamic mass balance — account for every pathway cannot support claims outside tracking a reservoir in a closed-loop life-support system. A balanced total can hide incompatible chemical species; each conserved constituent may need its own balance. Use the result only to justify: Use signed mass balances to detect slow inventory drift before a tank alarm becomes the first evidence.
- 19 — Sensitivity or limit case
- A 2 kg/day increase in Out changes the net from +1 to −1 kg/day.
- 20 — Practice
Guided exercise — Dynamic mass balance — account for every pathway. In=50, Out=54, Production=7, Consumption=1 kg/day. Find net change.
Guided correction — Dynamic mass balance — account for every pathway
- 50−54+7−1 = +2 kg/day.
- State which reservoir/species is being balanced.
Autonomous exercise — Dynamic mass balance — account for every pathway. Build a second case from “A 2 kg/day increase in Out changes the net from +1 to −1 kg/day.”. Re-evaluate
dM/dt = In - Out + Production - Consumption. Name the changed input. Decide whether “Use signed mass balances to detect slow inventory drift before a tank alarm becomes the first evidence.” still follows.Autonomous correction — Dynamic mass balance — account for every pathway
For Dynamic mass balance — account for every pathway, state the altered case. Preserve
kg/day. Match the direction in “A 2 kg/day increase in Out changes the net from +1 to −1 kg/day.”. Respect “A balanced total can hide incompatible chemical species; each conserved constituent may need its own balance.”. Finish by retaining or revising: Use signed mass balances to detect slow inventory drift before a tank alarm becomes the first evidence.- 21 — Mission decision
- Use signed mass balances to detect slow inventory drift before a tank alarm becomes the first evidence.
Electrolysis oxygen yield — connect processed water to theoretical oxygen mass
- 1 — Concrete question
For Electrolysis oxygen yield — connect processed water to theoretical oxygen mass, how does
m_O2 = eta_elec × (32/36) × m_H2Oinform estimating oxygen product from water electrolysis with a stated process efficiency and the operational choice “Use stoichiometric yield to reconcile oxygen inventory with water consumption and process telemetry.”?- 2 — Intuition without symbols
Intuition. Splitting water can produce oxygen, but chemistry fixes the theoretical share available from a given water mass. Real hardware then delivers only part of that ideal amount because efficiency is not perfect.
- 3 — Quantities first
- m_H2O is processed water; 32/36 is stoichiometric oxygen mass fraction from 2H2O→2H2+O2; eta_elec is recovery/production efficiency; m_O2 product mass.
- 4 — Formula
- m_O2 = eta_elec × (32/36) × m_H2O
- 5 — Read aloud
- “m O two equals eta electrolysis times thirty-two over thirty-six times m H two O.”
- 6 — Symbols
Symbol map for Electrolysis oxygen yield — connect processed water to theoretical oxygen mass. m_H2O is processed water; 32/36 is stoichiometric oxygen mass fraction from 2H2O→2H2+O2; eta_elec is recovery/production efficiency; m_O2 product mass.
- 7 — Pronunciation
Pronunciation. Say
m_O2 = eta_elec × (32/36) × m_H2O. For Electrolysis oxygen yield — connect processed water to theoretical oxygen mass, use the step-three names tied to estimating oxygen product from water electrolysis with a stated process efficiency. Speak each Electrolysis oxygen yield — connect processed water to theoretical oxygen mass unit with the quantity it measures.- 8 — Units
- dimensionless × dimensionless × kg = kg
- 9 — Convention
Convention. For Electrolysis oxygen yield — connect processed water to theoretical oxygen mass, keep estimating oxygen product from water electrolysis with a stated process efficiency on one declared boundary. Apply
m_O2 = eta_elec × (32/36) × m_H2Ounder that convention. Efficiency must be defined: conversion, collection and system availability are not automatically the same factor.- 10 — Why this operation
Why this operation.
m_O2 = eta_elec × (32/36) × m_H2Oanswers the Electrolysis oxygen yield — connect processed water to theoretical oxygen mass question because it represents estimating oxygen product from water electrolysis with a stated process efficiency. In this case it yields: The teaching case yields about 7.56 kg of collected oxygen.- 11 — Assumptions
Assumptions. Treat the Electrolysis oxygen yield — connect processed water to theoretical oxygen mass values as one teaching case. For estimating oxygen product from water electrolysis with a stated process efficiency, keep a single physical or operational boundary. Efficiency must be defined: conversion, collection and system availability are not automatically the same factor.
- 12 — Unit check
Unit check. Reduce
m_O2 = eta_elec × (32/36) × m_H2Ofor Electrolysis oxygen yield — connect processed water to theoretical oxygen mass. The required dimension isdimensionless × dimensionless × kg = kg. A different dimension invalidates “The teaching case yields about 7.56 kg of collected oxygen.”.- 13 — Numerical case
eta_elec = 0.85m_H2O = 10.0 kgm_O2 = 0.85×(32/36)×10.0 ≈ 7.56 kg- 14 — Why each operation
Why each operation. For Electrolysis oxygen yield — connect processed water to theoretical oxygen mass, substitute eta_elec = 0.85; m_H2O = 10.0 kg; m_O2 = 0.85×(32/36)×10.0 ≈ 7.56 kg into
m_O2 = eta_elec × (32/36) × m_H2O. Then verify the independent statement “The theoretical maximum from 10 kg water is 8.89 kg; 85% of that is 7.56 kg.”.- 15 — Algebra check
Algebra check. Reverse
m_O2 = eta_elec × (32/36) × m_H2Ofor Electrolysis oxygen yield — connect processed water to theoretical oxygen mass using “The theoretical maximum from 10 kg water is 8.89 kg; 85% of that is 7.56 kg.”. The recovered input should follow “Each percentage point of efficiency changes product proportionally at fixed feed mass.”. If not, recheck units and boundaries.- 16 — Mental estimate
Mental estimate. Round the dominant inputs for Electrolysis oxygen yield — connect processed water to theoretical oxygen mass. Compare that rough scale with “The teaching case yields about 7.56 kg of collected oxygen.”. If they diverge sharply, inspect
m_O2 = eta_elec × (32/36) × m_H2Ofor units, signs or boundaries.- 17 — Interpretation
Interpretation. For Electrolysis oxygen yield — connect processed water to theoretical oxygen mass, The teaching case yields about 7.56 kg of collected oxygen. Operationally: Use stoichiometric yield to reconcile oxygen inventory with water consumption and process telemetry. The interpretation remains limited by “Efficiency must be defined: conversion, collection and system availability are not automatically the same factor.”.
- 18 — What it does not prove
What it does not prove. Electrolysis oxygen yield — connect processed water to theoretical oxygen mass cannot support claims outside estimating oxygen product from water electrolysis with a stated process efficiency. Efficiency must be defined: conversion, collection and system availability are not automatically the same factor. Use the result only to justify: Use stoichiometric yield to reconcile oxygen inventory with water consumption and process telemetry.
- 19 — Sensitivity or limit case
- Each percentage point of efficiency changes product proportionally at fixed feed mass.
- 20 — Practice
Guided exercise — Electrolysis oxygen yield — connect processed water to theoretical oxygen mass. At eta=0.90 with 18 kg water processed, estimate collected O2.
Guided correction — Electrolysis oxygen yield — connect processed water to theoretical oxygen mass
- theoretical O2=18×32/36=16.0 kg; collected=14.4 kg.
- Track the hydrogen coproduct and power requirement separately.
Autonomous exercise — Electrolysis oxygen yield — connect processed water to theoretical oxygen mass. Build a second case from “Each percentage point of efficiency changes product proportionally at fixed feed mass.”. Re-evaluate
m_O2 = eta_elec × (32/36) × m_H2O. Name the changed input. Decide whether “Use stoichiometric yield to reconcile oxygen inventory with water consumption and process telemetry.” still follows.Autonomous correction — Electrolysis oxygen yield — connect processed water to theoretical oxygen mass
For Electrolysis oxygen yield — connect processed water to theoretical oxygen mass, state the altered case. Preserve
dimensionless × dimensionless × kg = kg. Match the direction in “Each percentage point of efficiency changes product proportionally at fixed feed mass.”. Respect “Efficiency must be defined: conversion, collection and system availability are not automatically the same factor.”. Finish by retaining or revising: Use stoichiometric yield to reconcile oxygen inventory with water consumption and process telemetry.- 21 — Mission decision
- Use stoichiometric yield to reconcile oxygen inventory with water consumption and process telemetry.
Net carbon-dioxide accumulation
- 1 — Concrete question
For Net carbon-dioxide accumulation, how does
m_CO2_net = m_CO2_prod - m_CO2_removedinform checking whether cabin CO₂ inventory tends to rise or fall and the operational choice “Keep net CO₂ mass balance near zero while controlling concentration at crew locations with independent sensors.”?- 2 — Intuition without symbols
Intuition. Cabin carbon dioxide rises when crew production exceeds removal and falls when removal exceeds production. The net difference determines whether the concentration trend is moving toward or away from a limit.
- 3 — Quantities first
- m_CO2_prod is crew/process production rate; m_CO2_removed is scrubber/removal rate; net is signed accumulation rate.
- 4 — Formula
- m_CO2_net = m_CO2_prod - m_CO2_removed
- 5 — Read aloud
- “m CO two net equals m CO two produced minus m CO two removed.”
- 6 — Symbols
Symbol map for Net carbon-dioxide accumulation. m_CO2_prod is crew/process production rate; m_CO2_removed is scrubber/removal rate; net is signed accumulation rate.
- 7 — Pronunciation
Pronunciation. Say
m_CO2_net = m_CO2_prod - m_CO2_removed. For Net carbon-dioxide accumulation, use the step-three names tied to checking whether cabin CO₂ inventory tends to rise or fall. Speak each Net carbon-dioxide accumulation unit with the quantity it measures.- 8 — Units
- kg/day
- 9 — Convention
Convention. For Net carbon-dioxide accumulation, keep checking whether cabin CO₂ inventory tends to rise or fall on one declared boundary. Apply
m_CO2_net = m_CO2_prod - m_CO2_removedunder that convention. Cabin concentration also depends on gas volume, mixing and pressure; mass rate alone does not give ppm.- 10 — Why this operation
Why this operation.
m_CO2_net = m_CO2_prod - m_CO2_removedanswers the Net carbon-dioxide accumulation question because it represents checking whether cabin CO₂ inventory tends to rise or fall. In this case it yields: CO₂ inventory rises by 0.2 kg/day if the rates persist and no other pathway acts.- 11 — Assumptions
Assumptions. Treat the Net carbon-dioxide accumulation values as one teaching case. For checking whether cabin CO₂ inventory tends to rise or fall, keep a single physical or operational boundary. Cabin concentration also depends on gas volume, mixing and pressure; mass rate alone does not give ppm.
- 12 — Unit check
Unit check. Reduce
m_CO2_net = m_CO2_prod - m_CO2_removedfor Net carbon-dioxide accumulation. The required dimension iskg/day. A different dimension invalidates “CO₂ inventory rises by 0.2 kg/day if the rates persist and no other pathway acts.”.- 13 — Numerical case
production = 4.2 kg/dayremoval = 4.0 kg/daynet = 4.2−4.0 = +0.2 kg/day- 14 — Why each operation
Why each operation. For Net carbon-dioxide accumulation, substitute production = 4.2 kg/day; removal = 4.0 kg/day; net = 4.2−4.0 = +0.2 kg/day into
m_CO2_net = m_CO2_prod - m_CO2_removed. Then verify the independent statement “4.0+0.2=4.2 kg/day”.- 15 — Algebra check
Algebra check. Reverse
m_CO2_net = m_CO2_prod - m_CO2_removedfor Net carbon-dioxide accumulation using “4.0+0.2=4.2 kg/day”. The recovered input should follow “A 5% loss of a 4.0 kg/day removal capability cuts removal to 3.8 kg/day and doubles this example imbalance.”. If not, recheck units and boundaries.- 16 — Mental estimate
Mental estimate. Round the dominant inputs for Net carbon-dioxide accumulation. Compare that rough scale with “CO₂ inventory rises by 0.2 kg/day if the rates persist and no other pathway acts.”. If they diverge sharply, inspect
m_CO2_net = m_CO2_prod - m_CO2_removedfor units, signs or boundaries.- 17 — Interpretation
Interpretation. For Net carbon-dioxide accumulation, CO₂ inventory rises by 0.2 kg/day if the rates persist and no other pathway acts. Operationally: Keep net CO₂ mass balance near zero while controlling concentration at crew locations with independent sensors. The interpretation remains limited by “Cabin concentration also depends on gas volume, mixing and pressure; mass rate alone does not give ppm.”.
- 18 — What it does not prove
What it does not prove. Net carbon-dioxide accumulation cannot support claims outside checking whether cabin CO₂ inventory tends to rise or fall. Cabin concentration also depends on gas volume, mixing and pressure; mass rate alone does not give ppm. Use the result only to justify: Keep net CO₂ mass balance near zero while controlling concentration at crew locations with independent sensors.
- 19 — Sensitivity or limit case
- A 5% loss of a 4.0 kg/day removal capability cuts removal to 3.8 kg/day and doubles this example imbalance.
- 20 — Practice
Guided exercise — Net carbon-dioxide accumulation. Production=3.6 and removal=3.9 kg/day. Find net.
Guided correction — Net carbon-dioxide accumulation
- net=−0.3 kg/day.
- A negative net means removal exceeds production, not that concentration instantly falls everywhere.
Autonomous exercise — Net carbon-dioxide accumulation. Build a second case from “A 5% loss of a 4.0 kg/day removal capability cuts removal to 3.8 kg/day and doubles this example imbalance.”. Re-evaluate
m_CO2_net = m_CO2_prod - m_CO2_removed. Name the changed input. Decide whether “Keep net CO₂ mass balance near zero while controlling concentration at crew locations with independent sensors.” still follows.Autonomous correction — Net carbon-dioxide accumulation
For Net carbon-dioxide accumulation, state the altered case. Preserve
kg/day. Match the direction in “A 5% loss of a 4.0 kg/day removal capability cuts removal to 3.8 kg/day and doubles this example imbalance.”. Respect “Cabin concentration also depends on gas volume, mixing and pressure; mass rate alone does not give ppm.”. Finish by retaining or revising: Keep net CO₂ mass balance near zero while controlling concentration at crew locations with independent sensors.- 21 — Mission decision
- Keep net CO₂ mass balance near zero while controlling concentration at crew locations with independent sensors.
Water recovery fraction — quantify recovered product from incoming wastewater
- 1 — Concrete question
For Water recovery fraction — quantify recovered product from incoming wastewater, how does
R_water = m_recovered / m_inputinform tracking loop closure without confusing throughput with make-up need and the operational choice “Track recovery and water quality separately; make-up planning depends on verified net loss, not a headline percentage alone.”?- 2 — Intuition without symbols
Intuition. A recovery system returns only part of the wastewater it receives. The recovered share measures how effectively the loop closes and how much make-up water must still come from inventory or local resources.
- 3 — Quantities first
- m_recovered is qualified recovered water; m_input is wastewater feed; R_water is recovery fraction.
- 4 — Formula
- R_water = m_recovered / m_input
- 5 — Read aloud
- “R water equals m recovered divided by m input.”
- 6 — Symbols
Symbol map for Water recovery fraction — quantify recovered product from incoming wastewater. m_recovered is qualified recovered water; m_input is wastewater feed; R_water is recovery fraction.
- 7 — Pronunciation
Pronunciation. Say
R_water = m_recovered / m_input. For Water recovery fraction — quantify recovered product from incoming wastewater, use the step-three names tied to tracking loop closure without confusing throughput with make-up need. Speak each Water recovery fraction — quantify recovered product from incoming wastewater unit with the quantity it measures.- 8 — Units
- kg/kg = dimensionless fraction
- 9 — Convention
Convention. For Water recovery fraction — quantify recovered product from incoming wastewater, keep tracking loop closure without confusing throughput with make-up need on one declared boundary. Apply
R_water = m_recovered / m_inputunder that convention. Recovery percentage does not prove product-water quality or account for inventory trapped in equipment.- 10 — Why this operation
Why this operation.
R_water = m_recovered / m_inputanswers the Water recovery fraction — quantify recovered product from incoming wastewater question because it represents tracking loop closure without confusing throughput with make-up need. In this case it yields: The loop recovers 95% of incoming wastewater mass as qualified water in this simplified example.- 11 — Assumptions
Assumptions. Treat the Water recovery fraction — quantify recovered product from incoming wastewater values as one teaching case. For tracking loop closure without confusing throughput with make-up need, keep a single physical or operational boundary. Recovery percentage does not prove product-water quality or account for inventory trapped in equipment.
- 12 — Unit check
Unit check. Reduce
R_water = m_recovered / m_inputfor Water recovery fraction — quantify recovered product from incoming wastewater. The required dimension iskg/kg = dimensionless fraction. A different dimension invalidates “The loop recovers 95% of incoming wastewater mass as qualified water in this simplified example.”.- 13 — Numerical case
m_input = 80 kg/daym_recovered = 76 kg/dayR_water = 76/80 = 0.95 = 95%- 14 — Why each operation
Why each operation. For Water recovery fraction — quantify recovered product from incoming wastewater, substitute m_input = 80 kg/day; m_recovered = 76 kg/day; R_water = 76/80 = 0.95 = 95% into
R_water = m_recovered / m_input. Then verify the independent statement “80−76=4 kg/day unrecovered; 4/80=5%”.- 15 — Algebra check
Algebra check. Reverse
R_water = m_recovered / m_inputfor Water recovery fraction — quantify recovered product from incoming wastewater using “80−76=4 kg/day unrecovered; 4/80=5%”. The recovered input should follow “At 80 kg/day, improving recovery from 95% to 97% cuts unrecovered mass from 4.0 to 2.4 kg/day.”. If not, recheck units and boundaries.- 16 — Mental estimate
Mental estimate. Round the dominant inputs for Water recovery fraction — quantify recovered product from incoming wastewater. Compare that rough scale with “The loop recovers 95% of incoming wastewater mass as qualified water in this simplified example.”. If they diverge sharply, inspect
R_water = m_recovered / m_inputfor units, signs or boundaries.- 17 — Interpretation
Interpretation. For Water recovery fraction — quantify recovered product from incoming wastewater, The loop recovers 95% of incoming wastewater mass as qualified water in this simplified example. Operationally: Track recovery and water quality separately; make-up planning depends on verified net loss, not a headline percentage alone. The interpretation remains limited by “Recovery percentage does not prove product-water quality or account for inventory trapped in equipment.”.
- 18 — What it does not prove
What it does not prove. Water recovery fraction — quantify recovered product from incoming wastewater cannot support claims outside tracking loop closure without confusing throughput with make-up need. Recovery percentage does not prove product-water quality or account for inventory trapped in equipment. Use the result only to justify: Track recovery and water quality separately; make-up planning depends on verified net loss, not a headline percentage alone.
- 19 — Sensitivity or limit case
- At 80 kg/day, improving recovery from 95% to 97% cuts unrecovered mass from 4.0 to 2.4 kg/day.
- 20 — Practice
Guided exercise — Water recovery fraction — quantify recovered product from incoming wastewater. Input=100 kg/day, recovered=92 kg/day. Find recovery.
Guided correction — Water recovery fraction — quantify recovered product from incoming wastewater
- R=92%.
- Unrecovered mass is 8 kg/day before other return pathways.
Autonomous exercise — Water recovery fraction — quantify recovered product from incoming wastewater. Build a second case from “At 80 kg/day, improving recovery from 95% to 97% cuts unrecovered mass from 4.0 to 2.4 kg/day.”. Re-evaluate
R_water = m_recovered / m_input. Name the changed input. Decide whether “Track recovery and water quality separately; make-up planning depends on verified net loss, not a headline percentage alone.” still follows.Autonomous correction — Water recovery fraction — quantify recovered product from incoming wastewater
For Water recovery fraction — quantify recovered product from incoming wastewater, state the altered case. Preserve
kg/kg = dimensionless fraction. Match the direction in “At 80 kg/day, improving recovery from 95% to 97% cuts unrecovered mass from 4.0 to 2.4 kg/day.”. Respect “Recovery percentage does not prove product-water quality or account for inventory trapped in equipment.”. Finish by retaining or revising: Track recovery and water quality separately; make-up planning depends on verified net loss, not a headline percentage alone.- 21 — Mission decision
- Track recovery and water quality separately; make-up planning depends on verified net loss, not a headline percentage alone.
Condensate collection — water removed from an air stream
- 1 — Concrete question
For Condensate collection — water removed from an air stream, how does
m_cond = m_vapor_in - m_vapor_outinform quantifying moisture removed by a condensing heat exchanger over a defined interval and the operational choice “Use condensate mass balance to cross-check humidity-control telemetry and water-loop accounting.”?- 2 — Intuition without symbols
Intuition. Moist air carries water that can be removed when conditions force vapour to condense. The collected amount depends on the difference between the water carried into and out of the air-treatment step.
- 3 — Quantities first
- m_vapor_in and m_vapor_out are water-vapor mass crossing the device boundary; m_cond is collected condensate.
- 4 — Formula
- m_cond = m_vapor_in - m_vapor_out
- 5 — Read aloud
- “m condensate equals m vapor in minus m vapor out.”
- 6 — Symbols
Symbol map for Condensate collection — water removed from an air stream. m_vapor_in and m_vapor_out are water-vapor mass crossing the device boundary; m_cond is collected condensate.
- 7 — Pronunciation
Pronunciation. Say
m_cond = m_vapor_in - m_vapor_out. For Condensate collection — water removed from an air stream, use the step-three names tied to quantifying moisture removed by a condensing heat exchanger over a defined interval. Speak each Condensate collection — water removed from an air stream unit with the quantity it measures.- 8 — Units
- kg − kg = kg
- 9 — Convention
Convention. For Condensate collection — water removed from an air stream, keep quantifying moisture removed by a condensing heat exchanger over a defined interval on one declared boundary. Apply
m_cond = m_vapor_in - m_vapor_outunder that convention. Condensate quality may require treatment; this balance assumes no leaks or unmeasured storage change in the device.- 10 — Why this operation
Why this operation.
m_cond = m_vapor_in - m_vapor_outanswers the Condensate collection — water removed from an air stream question because it represents quantifying moisture removed by a condensing heat exchanger over a defined interval. In this case it yields: The exchanger removes 4.5 kg of water vapor over the stated interval.- 11 — Assumptions
Assumptions. Treat the Condensate collection — water removed from an air stream values as one teaching case. For quantifying moisture removed by a condensing heat exchanger over a defined interval, keep a single physical or operational boundary. Condensate quality may require treatment; this balance assumes no leaks or unmeasured storage change in the device.
- 12 — Unit check
Unit check. Reduce
m_cond = m_vapor_in - m_vapor_outfor Condensate collection — water removed from an air stream. The required dimension iskg − kg = kg. A different dimension invalidates “The exchanger removes 4.5 kg of water vapor over the stated interval.”.- 13 — Numerical case
m_vapor_in = 6.0 kgm_vapor_out = 1.5 kgm_cond = 6.0−1.5 = 4.5 kg- 14 — Why each operation
Why each operation. For Condensate collection — water removed from an air stream, substitute m_vapor_in = 6.0 kg; m_vapor_out = 1.5 kg; m_cond = 6.0−1.5 = 4.5 kg into
m_cond = m_vapor_in - m_vapor_out. Then verify the independent statement “1.5+4.5=6.0 kg”.- 15 — Algebra check
Algebra check. Reverse
m_cond = m_vapor_in - m_vapor_outfor Condensate collection — water removed from an air stream using “1.5+4.5=6.0 kg”. The recovered input should follow “If outlet vapor rises to 2.0 kg with inlet unchanged, collected condensate drops to 4.0 kg.”. If not, recheck units and boundaries.- 16 — Mental estimate
Mental estimate. Round the dominant inputs for Condensate collection — water removed from an air stream. Compare that rough scale with “The exchanger removes 4.5 kg of water vapor over the stated interval.”. If they diverge sharply, inspect
m_cond = m_vapor_in - m_vapor_outfor units, signs or boundaries.- 17 — Interpretation
Interpretation. For Condensate collection — water removed from an air stream, The exchanger removes 4.5 kg of water vapor over the stated interval. Operationally: Use condensate mass balance to cross-check humidity-control telemetry and water-loop accounting. The interpretation remains limited by “Condensate quality may require treatment; this balance assumes no leaks or unmeasured storage change in the device.”.
- 18 — What it does not prove
What it does not prove. Condensate collection — water removed from an air stream cannot support claims outside quantifying moisture removed by a condensing heat exchanger over a defined interval. Condensate quality may require treatment; this balance assumes no leaks or unmeasured storage change in the device. Use the result only to justify: Use condensate mass balance to cross-check humidity-control telemetry and water-loop accounting.
- 19 — Sensitivity or limit case
- If outlet vapor rises to 2.0 kg with inlet unchanged, collected condensate drops to 4.0 kg.
- 20 — Practice
Guided exercise — Condensate collection — water removed from an air stream. Inlet vapor=8.2 kg, outlet=2.7 kg. Find condensate.
Guided correction — Condensate collection — water removed from an air stream
- m_cond=5.5 kg.
- Check drain inventory to close the physical balance.
Autonomous exercise — Condensate collection — water removed from an air stream. Build a second case from “If outlet vapor rises to 2.0 kg with inlet unchanged, collected condensate drops to 4.0 kg.”. Re-evaluate
m_cond = m_vapor_in - m_vapor_out. Name the changed input. Decide whether “Use condensate mass balance to cross-check humidity-control telemetry and water-loop accounting.” still follows.Autonomous correction — Condensate collection — water removed from an air stream
For Condensate collection — water removed from an air stream, state the altered case. Preserve
kg − kg = kg. Match the direction in “If outlet vapor rises to 2.0 kg with inlet unchanged, collected condensate drops to 4.0 kg.”. Respect “Condensate quality may require treatment; this balance assumes no leaks or unmeasured storage change in the device.”. Finish by retaining or revising: Use condensate mass balance to cross-check humidity-control telemetry and water-loop accounting.- 21 — Mission decision
- Use condensate mass balance to cross-check humidity-control telemetry and water-loop accounting.
Filter removal efficiency — calculate downstream concentration
- 1 — Concrete question
For Filter removal efficiency — calculate downstream concentration, how does
C_out = C_in × (1 - eta_filter)inform estimating contaminant concentration after a single-pass removal stage and the operational choice “Trend filter efficiency and pressure drop so replacement occurs before downstream exposure approaches a limit.”?- 2 — Intuition without symbols
Intuition. A filter reduces a contaminant by removing a fraction of what enters. The downstream concentration therefore depends on both the inlet level and the fraction that escapes removal.
- 3 — Quantities first
- C_in is inlet concentration; eta_filter is fractional removal efficiency; C_out is downstream concentration.
- 4 — Formula
- C_out = C_in × (1 - eta_filter)
- 5 — Read aloud
- “C out equals C in times one minus eta filter.”
- 6 — Symbols
Symbol map for Filter removal efficiency — calculate downstream concentration. C_in is inlet concentration; eta_filter is fractional removal efficiency; C_out is downstream concentration.
- 7 — Pronunciation
Pronunciation. Say
C_out = C_in × (1 - eta_filter). For Filter removal efficiency — calculate downstream concentration, use the step-three names tied to estimating contaminant concentration after a single-pass removal stage. Speak each Filter removal efficiency — calculate downstream concentration unit with the quantity it measures.- 8 — Units
- ppm × dimensionless = ppm
- 9 — Convention
Convention. For Filter removal efficiency — calculate downstream concentration, keep estimating contaminant concentration after a single-pass removal stage on one declared boundary. Apply
C_out = C_in × (1 - eta_filter)under that convention. Efficiency can depend on flow, loading, humidity and contaminant species; ppm is not a mass flow without volumetric flow and gas state.- 10 — Why this operation
Why this operation.
C_out = C_in × (1 - eta_filter)answers the Filter removal efficiency — calculate downstream concentration question because it represents estimating contaminant concentration after a single-pass removal stage. In this case it yields: The idealized single-pass outlet concentration is 3 ppm.- 11 — Assumptions
Assumptions. Treat the Filter removal efficiency — calculate downstream concentration values as one teaching case. For estimating contaminant concentration after a single-pass removal stage, keep a single physical or operational boundary. Efficiency can depend on flow, loading, humidity and contaminant species; ppm is not a mass flow without volumetric flow and gas state.
- 12 — Unit check
Unit check. Reduce
C_out = C_in × (1 - eta_filter)for Filter removal efficiency — calculate downstream concentration. The required dimension isppm × dimensionless = ppm. A different dimension invalidates “The idealized single-pass outlet concentration is 3 ppm.”.- 13 — Numerical case
C_in = 100 ppmeta_filter = 0.97C_out = 100×(1−0.97) = 3 ppm- 14 — Why each operation
Why each operation. For Filter removal efficiency — calculate downstream concentration, substitute C_in = 100 ppm; eta_filter = 0.97; C_out = 100×(1−0.97) = 3 ppm into
C_out = C_in × (1 - eta_filter). Then verify the independent statement “Removed amount in concentration units is 97 ppm; 100−97=3 ppm”.- 15 — Algebra check
Algebra check. Reverse
C_out = C_in × (1 - eta_filter)for Filter removal efficiency — calculate downstream concentration using “Removed amount in concentration units is 97 ppm; 100−97=3 ppm”. The recovered input should follow “A drop from 97% to 90% efficiency raises outlet from 3 ppm to 10 ppm at the same inlet concentration.”. If not, recheck units and boundaries.- 16 — Mental estimate
Mental estimate. Round the dominant inputs for Filter removal efficiency — calculate downstream concentration. Compare that rough scale with “The idealized single-pass outlet concentration is 3 ppm.”. If they diverge sharply, inspect
C_out = C_in × (1 - eta_filter)for units, signs or boundaries.- 17 — Interpretation
Interpretation. For Filter removal efficiency — calculate downstream concentration, The idealized single-pass outlet concentration is 3 ppm. Operationally: Trend filter efficiency and pressure drop so replacement occurs before downstream exposure approaches a limit. The interpretation remains limited by “Efficiency can depend on flow, loading, humidity and contaminant species; ppm is not a mass flow without volumetric flow and gas state.”.
- 18 — What it does not prove
What it does not prove. Filter removal efficiency — calculate downstream concentration cannot support claims outside estimating contaminant concentration after a single-pass removal stage. Efficiency can depend on flow, loading, humidity and contaminant species; ppm is not a mass flow without volumetric flow and gas state. Use the result only to justify: Trend filter efficiency and pressure drop so replacement occurs before downstream exposure approaches a limit.
- 19 — Sensitivity or limit case
- A drop from 97% to 90% efficiency raises outlet from 3 ppm to 10 ppm at the same inlet concentration.
- 20 — Practice
Guided exercise — Filter removal efficiency — calculate downstream concentration. C_in=250 ppm and eta=0.96. Find C_out.
Guided correction — Filter removal efficiency — calculate downstream concentration
- C_out=250×0.04=10 ppm.
- Compare with the sensor uncertainty and allowable concentration criterion.
Autonomous exercise — Filter removal efficiency — calculate downstream concentration. Build a second case from “A drop from 97% to 90% efficiency raises outlet from 3 ppm to 10 ppm at the same inlet concentration.”. Re-evaluate
C_out = C_in × (1 - eta_filter). Name the changed input. Decide whether “Trend filter efficiency and pressure drop so replacement occurs before downstream exposure approaches a limit.” still follows.Autonomous correction — Filter removal efficiency — calculate downstream concentration
For Filter removal efficiency — calculate downstream concentration, state the altered case. Preserve
ppm × dimensionless = ppm. Match the direction in “A drop from 97% to 90% efficiency raises outlet from 3 ppm to 10 ppm at the same inlet concentration.”. Respect “Efficiency can depend on flow, loading, humidity and contaminant species; ppm is not a mass flow without volumetric flow and gas state.”. Finish by retaining or revising: Trend filter efficiency and pressure drop so replacement occurs before downstream exposure approaches a limit.- 21 — Mission decision
- Trend filter efficiency and pressure drop so replacement occurs before downstream exposure approaches a limit.
Control error — preserve the sign between setpoint and measurement
- 1 — Concrete question
For Control error — preserve the sign between setpoint and measurement, how does
e = Setpoint - Measurementinform feedback-control reasoning for temperature, pressure or concentration loops and the operational choice “Keep sign conventions identical across displays, procedures and controller logs to prevent operator reversal errors.”?- 2 — Intuition without symbols
Intuition. A controller needs to know not only the size of a mismatch but also its direction. Keeping the sign between desired and measured state tells the control system which way corrective action must move.
- 3 — Quantities first
- Setpoint is desired value; Measurement is observed value; e is signed error under the stated convention.
- 4 — Formula
- e = Setpoint - Measurement
- 5 — Read aloud
- “e equals setpoint minus measurement.”
- 6 — Symbols
Symbol map for Control error — preserve the sign between setpoint and measurement. Setpoint is desired value; Measurement is observed value; e is signed error under the stated convention.
- 7 — Pronunciation
Pronunciation. Say
e = Setpoint - Measurement. For Control error — preserve the sign between setpoint and measurement, use the step-three names tied to feedback-control reasoning for temperature, pressure or concentration loops. Speak each Control error — preserve the sign between setpoint and measurement unit with the quantity it measures.- 8 — Units
- same unit as controlled variable
- 9 — Convention
Convention. For Control error — preserve the sign between setpoint and measurement, keep feedback-control reasoning for temperature, pressure or concentration loops on one declared boundary. Apply
e = Setpoint - Measurementunder that convention. Error alone does not determine actuator command; controller gains, limits, deadbands and dynamics matter.- 10 — Why this operation
Why this operation.
e = Setpoint - Measurementanswers the Control error — preserve the sign between setpoint and measurement question because it represents feedback-control reasoning for temperature, pressure or concentration loops. In this case it yields: The negative error means the measured temperature is 1.4 °C above setpoint under this convention.- 11 — Assumptions
Assumptions. Treat the Control error — preserve the sign between setpoint and measurement values as one teaching case. For feedback-control reasoning for temperature, pressure or concentration loops, keep a single physical or operational boundary. Error alone does not determine actuator command; controller gains, limits, deadbands and dynamics matter.
- 12 — Unit check
Unit check. Reduce
e = Setpoint - Measurementfor Control error — preserve the sign between setpoint and measurement. The required dimension issame unit as controlled variable. A different dimension invalidates “The negative error means the measured temperature is 1.4 °C above setpoint under this convention.”.- 13 — Numerical case
Setpoint = 21.0 °CMeasurement = 22.4 °Ce = 21.0−22.4 = −1.4 °C- 14 — Why each operation
Why each operation. For Control error — preserve the sign between setpoint and measurement, substitute Setpoint = 21.0 °C; Measurement = 22.4 °C; e = 21.0−22.4 = −1.4 °C into
e = Setpoint - Measurement. Then verify the independent statement “Measurement + e = 22.4−1.4 = 21.0 °C”.- 15 — Algebra check
Algebra check. Reverse
e = Setpoint - Measurementfor Control error — preserve the sign between setpoint and measurement using “Measurement + e = 22.4−1.4 = 21.0 °C”. The recovered input should follow “Changing the sign convention reverses the sign but not the physical deviation; document the convention.”. If not, recheck units and boundaries.- 16 — Mental estimate
Mental estimate. Round the dominant inputs for Control error — preserve the sign between setpoint and measurement. Compare that rough scale with “The negative error means the measured temperature is 1.4 °C above setpoint under this convention.”. If they diverge sharply, inspect
e = Setpoint - Measurementfor units, signs or boundaries.- 17 — Interpretation
Interpretation. For Control error — preserve the sign between setpoint and measurement, The negative error means the measured temperature is 1.4 °C above setpoint under this convention. Operationally: Keep sign conventions identical across displays, procedures and controller logs to prevent operator reversal errors. The interpretation remains limited by “Error alone does not determine actuator command; controller gains, limits, deadbands and dynamics matter.”.
- 18 — What it does not prove
What it does not prove. Control error — preserve the sign between setpoint and measurement cannot support claims outside feedback-control reasoning for temperature, pressure or concentration loops. Error alone does not determine actuator command; controller gains, limits, deadbands and dynamics matter. Use the result only to justify: Keep sign conventions identical across displays, procedures and controller logs to prevent operator reversal errors.
- 19 — Sensitivity or limit case
- Changing the sign convention reverses the sign but not the physical deviation; document the convention.
- 20 — Practice
Guided exercise — Control error — preserve the sign between setpoint and measurement. Setpoint=45% RH, measurement=41% RH. Find error using setpoint−measurement.
Guided correction — Control error — preserve the sign between setpoint and measurement
- e=+4 percentage points.
- Positive means measured humidity is below target under this convention.
Autonomous exercise — Control error — preserve the sign between setpoint and measurement. Build a second case from “Changing the sign convention reverses the sign but not the physical deviation; document the convention.”. Re-evaluate
e = Setpoint - Measurement. Name the changed input. Decide whether “Keep sign conventions identical across displays, procedures and controller logs to prevent operator reversal errors.” still follows.Autonomous correction — Control error — preserve the sign between setpoint and measurement
For Control error — preserve the sign between setpoint and measurement, state the altered case. Preserve
same unit as controlled variable. Match the direction in “Changing the sign convention reverses the sign but not the physical deviation; document the convention.”. Respect “Error alone does not determine actuator command; controller gains, limits, deadbands and dynamics matter.”. Finish by retaining or revising: Keep sign conventions identical across displays, procedures and controller logs to prevent operator reversal errors.- 21 — Mission decision
- Keep sign conventions identical across displays, procedures and controller logs to prevent operator reversal errors.
Stock autonomy — convert usable inventory into time at net demand
- 1 — Concrete question
For Stock autonomy — convert usable inventory into time at net demand, how does
t_auto = Stock_usable / q_netinform estimating how long a buffer lasts after accounting for accessible usable stock and the operational choice “Use autonomy to order recovery actions by time-to-loss-of-function and keep emergency reserve separate.”?- 2 — Intuition without symbols
Intuition. A consumable stock becomes an autonomy time when it is compared with the net rate at which the system uses that stock. Lower demand stretches the same inventory; higher demand shortens it.
- 3 — Quantities first
- Stock_usable is qualified accessible inventory; q_net is net depletion rate; t_auto is autonomy duration.
- 4 — Formula
- t_auto = Stock_usable / q_net
- 5 — Read aloud
- “t autonomy equals usable stock divided by q net.”
- 6 — Symbols
Symbol map for Stock autonomy — convert usable inventory into time at net demand. Stock_usable is qualified accessible inventory; q_net is net depletion rate; t_auto is autonomy duration.
- 7 — Pronunciation
Pronunciation. Say
t_auto = Stock_usable / q_net. For Stock autonomy — convert usable inventory into time at net demand, use the step-three names tied to estimating how long a buffer lasts after accounting for accessible usable stock. Speak each Stock autonomy — convert usable inventory into time at net demand unit with the quantity it measures.- 8 — Units
- kg / (kg/day) = day
- 9 — Convention
Convention. For Stock autonomy — convert usable inventory into time at net demand, keep estimating how long a buffer lasts after accounting for accessible usable stock on one declared boundary. Apply
t_auto = Stock_usable / q_netunder that convention. Constant-rate autonomy ignores demand transients, inaccessible stock and uncertainty; do not count protected reserve as routine stock.- 10 — Why this operation
Why this operation.
t_auto = Stock_usable / q_netanswers the Stock autonomy — convert usable inventory into time at net demand question because it represents estimating how long a buffer lasts after accounting for accessible usable stock. In this case it yields: The buffer lasts 15 days at the stated constant net demand.- 11 — Assumptions
Assumptions. Treat the Stock autonomy — convert usable inventory into time at net demand values as one teaching case. For estimating how long a buffer lasts after accounting for accessible usable stock, keep a single physical or operational boundary. Constant-rate autonomy ignores demand transients, inaccessible stock and uncertainty; do not count protected reserve as routine stock.
- 12 — Unit check
Unit check. Reduce
t_auto = Stock_usable / q_netfor Stock autonomy — convert usable inventory into time at net demand. The required dimension iskg / (kg/day) = day. A different dimension invalidates “The buffer lasts 15 days at the stated constant net demand.”.- 13 — Numerical case
Stock_usable = 120 kgq_net = 8 kg/dayt_auto = 120/8 = 15 days- 14 — Why each operation
Why each operation. For Stock autonomy — convert usable inventory into time at net demand, substitute Stock_usable = 120 kg; q_net = 8 kg/day; t_auto = 120/8 = 15 days into
t_auto = Stock_usable / q_net. Then verify the independent statement “15×8=120 kg”.- 15 — Algebra check
Algebra check. Reverse
t_auto = Stock_usable / q_netfor Stock autonomy — convert usable inventory into time at net demand using “15×8=120 kg”. The recovered input should follow “If net demand rises 25% to 10 kg/day, autonomy falls to 12 days.”. If not, recheck units and boundaries.- 16 — Mental estimate
Mental estimate. Round the dominant inputs for Stock autonomy — convert usable inventory into time at net demand. Compare that rough scale with “The buffer lasts 15 days at the stated constant net demand.”. If they diverge sharply, inspect
t_auto = Stock_usable / q_netfor units, signs or boundaries.- 17 — Interpretation
Interpretation. For Stock autonomy — convert usable inventory into time at net demand, The buffer lasts 15 days at the stated constant net demand. Operationally: Use autonomy to order recovery actions by time-to-loss-of-function and keep emergency reserve separate. The interpretation remains limited by “Constant-rate autonomy ignores demand transients, inaccessible stock and uncertainty; do not count protected reserve as routine stock.”.
- 18 — What it does not prove
What it does not prove. Stock autonomy — convert usable inventory into time at net demand cannot support claims outside estimating how long a buffer lasts after accounting for accessible usable stock. Constant-rate autonomy ignores demand transients, inaccessible stock and uncertainty; do not count protected reserve as routine stock. Use the result only to justify: Use autonomy to order recovery actions by time-to-loss-of-function and keep emergency reserve separate.
- 19 — Sensitivity or limit case
- If net demand rises 25% to 10 kg/day, autonomy falls to 12 days.
- 20 — Practice
Guided exercise — Stock autonomy — convert usable inventory into time at net demand. Usable stock=210 kg, net demand=14 kg/day. Find autonomy.
Guided correction — Stock autonomy — convert usable inventory into time at net demand
- t=210/14=15 days.
- Subtract inaccessible or quarantined inventory before computing.
Autonomous exercise — Stock autonomy — convert usable inventory into time at net demand. Build a second case from “If net demand rises 25% to 10 kg/day, autonomy falls to 12 days.”. Re-evaluate
t_auto = Stock_usable / q_net. Name the changed input. Decide whether “Use autonomy to order recovery actions by time-to-loss-of-function and keep emergency reserve separate.” still follows.Autonomous correction — Stock autonomy — convert usable inventory into time at net demand
For Stock autonomy — convert usable inventory into time at net demand, state the altered case. Preserve
kg / (kg/day) = day. Match the direction in “If net demand rises 25% to 10 kg/day, autonomy falls to 12 days.”. Respect “Constant-rate autonomy ignores demand transients, inaccessible stock and uncertainty; do not count protected reserve as routine stock.”. Finish by retaining or revising: Use autonomy to order recovery actions by time-to-loss-of-function and keep emergency reserve separate.- 21 — Mission decision
- Use autonomy to order recovery actions by time-to-loss-of-function and keep emergency reserve separate.
Expected spare demand — link failure rate, exposure time and units consumed per failure
- 1 — Concrete question
For Expected spare demand — link failure rate, exposure time and units consumed per failure, how does
N_spare_exp = lambda × t × cinform first-order planning estimate for replaceable items and the operational choice “Treat expected demand as one input to spares policy, alongside criticality, common causes and repair capability.”?- 2 — Intuition without symbols
Intuition. Failures create replacement demand over time. Combining failure frequency, exposure duration and the number of units consumed per event gives a planning estimate for how many spares the campaign may need.
- 3 — Quantities first
- lambda is expected failure rate; t mission exposure time; c units consumed per failure; N_spare_exp is expected demand, not a guaranteed integer.
- 4 — Formula
- N_spare_exp = lambda × t × c
- 5 — Read aloud
- “N spare expected equals lambda times t times c.”
- 6 — Symbols
Symbol map for Expected spare demand — link failure rate, exposure time and units consumed per failure. lambda is expected failure rate; t mission exposure time; c units consumed per failure; N_spare_exp is expected demand, not a guaranteed integer.
- 7 — Pronunciation
Pronunciation. Say
N_spare_exp = lambda × t × c. For Expected spare demand — link failure rate, exposure time and units consumed per failure, use the step-three names tied to first-order planning estimate for replaceable items. Speak each Expected spare demand — link failure rate, exposure time and units consumed per failure unit with the quantity it measures.- 8 — Units
- failures/day × day × units/failure = units
- 9 — Convention
Convention. For Expected spare demand — link failure rate, exposure time and units consumed per failure, keep first-order planning estimate for replaceable items on one declared boundary. Apply
N_spare_exp = lambda × t × cunder that convention. Expected value does not capture variance, common-cause failures or aging; a Poisson or reliability model may be needed.- 10 — Why this operation
Why this operation.
N_spare_exp = lambda × t × canswers the Expected spare demand — link failure rate, exposure time and units consumed per failure question because it represents first-order planning estimate for replaceable items. In this case it yields: Expected demand is 5.4 units; stocking requires a reliability/service-level decision and integer quantity, not simply rounding by habit.- 11 — Assumptions
Assumptions. Treat the Expected spare demand — link failure rate, exposure time and units consumed per failure values as one teaching case. For first-order planning estimate for replaceable items, keep a single physical or operational boundary. Expected value does not capture variance, common-cause failures or aging; a Poisson or reliability model may be needed.
- 12 — Unit check
Unit check. Reduce
N_spare_exp = lambda × t × cfor Expected spare demand — link failure rate, exposure time and units consumed per failure. The required dimension isfailures/day × day × units/failure = units. A different dimension invalidates “Expected demand is 5.4 units; stocking requires a reliability/service-level decision and integer quantity, not simply rounding by habit.”.- 13 — Numerical case
lambda = 0.03 failures/dayt = 180 daysc = 1 unit/failureN_exp = 0.03×180×1 = 5.4 units- 14 — Why each operation
Why each operation. For Expected spare demand — link failure rate, exposure time and units consumed per failure, substitute lambda = 0.03 failures/day; t = 180 days; c = 1 unit/failure; N_exp = 0.03×180×1 = 5.4 units into
N_spare_exp = lambda × t × c. Then verify the independent statement “0.03×180=5.4 expected failures”.- 15 — Algebra check
Algebra check. Reverse
N_spare_exp = lambda × t × cfor Expected spare demand — link failure rate, exposure time and units consumed per failure using “0.03×180=5.4 expected failures”. The recovered input should follow “A 20% longer mission raises expected demand by 20% if failure rate stays valid.”. If not, recheck units and boundaries.- 16 — Mental estimate
Mental estimate. Round the dominant inputs for Expected spare demand — link failure rate, exposure time and units consumed per failure. Compare that rough scale with “Expected demand is 5.4 units; stocking requires a reliability/service-level decision and integer quantity, not simply rounding by habit.”. If they diverge sharply, inspect
N_spare_exp = lambda × t × cfor units, signs or boundaries.- 17 — Interpretation
Interpretation. For Expected spare demand — link failure rate, exposure time and units consumed per failure, Expected demand is 5.4 units; stocking requires a reliability/service-level decision and integer quantity, not simply rounding by habit. Operationally: Treat expected demand as one input to spares policy, alongside criticality, common causes and repair capability. The interpretation remains limited by “Expected value does not capture variance, common-cause failures or aging; a Poisson or reliability model may be needed.”.
- 18 — What it does not prove
What it does not prove. Expected spare demand — link failure rate, exposure time and units consumed per failure cannot support claims outside first-order planning estimate for replaceable items. Expected value does not capture variance, common-cause failures or aging; a Poisson or reliability model may be needed. Use the result only to justify: Treat expected demand as one input to spares policy, alongside criticality, common causes and repair capability.
- 19 — Sensitivity or limit case
- A 20% longer mission raises expected demand by 20% if failure rate stays valid.
- 20 — Practice
Guided exercise — Expected spare demand — link failure rate, exposure time and units consumed per failure. lambda=0.015/day, t=300 days, c=2 units/failure. Find expected units.
Guided correction — Expected spare demand — link failure rate, exposure time and units consumed per failure
- N_exp=0.015×300×2=9 units.
- Then size actual stock from desired confidence and resupply strategy.
Autonomous exercise — Expected spare demand — link failure rate, exposure time and units consumed per failure. Build a second case from “A 20% longer mission raises expected demand by 20% if failure rate stays valid.”. Re-evaluate
N_spare_exp = lambda × t × c. Name the changed input. Decide whether “Treat expected demand as one input to spares policy, alongside criticality, common causes and repair capability.” still follows.Autonomous correction — Expected spare demand — link failure rate, exposure time and units consumed per failure
For Expected spare demand — link failure rate, exposure time and units consumed per failure, state the altered case. Preserve
failures/day × day × units/failure = units. Match the direction in “A 20% longer mission raises expected demand by 20% if failure rate stays valid.”. Respect “Expected value does not capture variance, common-cause failures or aging; a Poisson or reliability model may be needed.”. Finish by retaining or revising: Treat expected demand as one input to spares policy, alongside criticality, common causes and repair capability.- 21 — Mission decision
- Treat expected demand as one input to spares policy, alongside criticality, common causes and repair capability.
Minimum subsystem margin — the weakest protected margin controls the immediate gate
- 1 — Concrete question
For Minimum subsystem margin — the weakest protected margin controls the immediate gate, how does
M_system = min(M_i)inform screening a coupled life-support system for its tightest current margin and the operational choice “Direct recovery effort first at the limiting protected function while checking that the intervention does not create a new bottleneck.”?- 2 — Intuition without symbols
Intuition. A chain of subsystems is constrained by its weakest protected reserve. Even generous margin elsewhere cannot compensate when one critical subsystem approaches its limit first.
- 3 — Quantities first
- M_i are comparable normalized margins for required functions; min selects the smallest; M_system is limiting margin.
- 4 — Formula
- M_system = min(M_i)
- 5 — Read aloud
- “M system equals the minimum of M i.”
- 6 — Symbols
Symbol map for Minimum subsystem margin — the weakest protected margin controls the immediate gate. M_i are comparable normalized margins for required functions; min selects the smallest; M_system is limiting margin.
- 7 — Pronunciation
Pronunciation. Say
M_system = min(M_i). For Minimum subsystem margin — the weakest protected margin controls the immediate gate, use the step-three names tied to screening a coupled life-support system for its tightest current margin. Speak each Minimum subsystem margin — the weakest protected margin controls the immediate gate unit with the quantity it measures.- 8 — Units
- dimensionless or %, only if all inputs use the same definition
- 9 — Convention
Convention. For Minimum subsystem margin — the weakest protected margin controls the immediate gate, keep screening a coupled life-support system for its tightest current margin on one declared boundary. Apply
M_system = min(M_i)under that convention. Do not take a minimum across incompatible units or differently defined margins; normalize the decision metric first.- 10 — Why this operation
Why this operation.
M_system = min(M_i)answers the Minimum subsystem margin — the weakest protected margin controls the immediate gate question because it represents screening a coupled life-support system for its tightest current margin. In this case it yields: The CO₂-removal branch is the limiting normalized margin at 9%.- 11 — Assumptions
Assumptions. Treat the Minimum subsystem margin — the weakest protected margin controls the immediate gate values as one teaching case. For screening a coupled life-support system for its tightest current margin, keep a single physical or operational boundary. Do not take a minimum across incompatible units or differently defined margins; normalize the decision metric first.
- 12 — Unit check
Unit check. Reduce
M_system = min(M_i)for Minimum subsystem margin — the weakest protected margin controls the immediate gate. The required dimension isdimensionless or %, only if all inputs use the same definition. A different dimension invalidates “The CO₂-removal branch is the limiting normalized margin at 9%.”.- 13 — Numerical case
water margin = 22%oxygen margin = 15%CO₂-removal margin = 9%power margin = 18%M_system = min(22,15,9,18) = 9%- 14 — Why each operation
Why each operation. For Minimum subsystem margin — the weakest protected margin controls the immediate gate, substitute water margin = 22%; oxygen margin = 15%; CO₂-removal margin = 9%; power margin = 18%; M_system = min(22,15,9,18) = 9% into
M_system = min(M_i). Then verify the independent statement “Every other listed margin is ≥9%, so 9% is the minimum.”.- 15 — Algebra check
Algebra check. Reverse
M_system = min(M_i)for Minimum subsystem margin — the weakest protected margin controls the immediate gate using “Every other listed margin is ≥9%, so 9% is the minimum.”. The recovered input should follow “Improving a non-limiting 22% margin does not change system minimum until the 9% branch improves.”. If not, recheck units and boundaries.- 16 — Mental estimate
Mental estimate. Round the dominant inputs for Minimum subsystem margin — the weakest protected margin controls the immediate gate. Compare that rough scale with “The CO₂-removal branch is the limiting normalized margin at 9%.”. If they diverge sharply, inspect
M_system = min(M_i)for units, signs or boundaries.- 17 — Interpretation
Interpretation. For Minimum subsystem margin — the weakest protected margin controls the immediate gate, The CO₂-removal branch is the limiting normalized margin at 9%. Operationally: Direct recovery effort first at the limiting protected function while checking that the intervention does not create a new bottleneck. The interpretation remains limited by “Do not take a minimum across incompatible units or differently defined margins; normalize the decision metric first.”.
- 18 — What it does not prove
What it does not prove. Minimum subsystem margin — the weakest protected margin controls the immediate gate cannot support claims outside screening a coupled life-support system for its tightest current margin. Do not take a minimum across incompatible units or differently defined margins; normalize the decision metric first. Use the result only to justify: Direct recovery effort first at the limiting protected function while checking that the intervention does not create a new bottleneck.
- 19 — Sensitivity or limit case
- Improving a non-limiting 22% margin does not change system minimum until the 9% branch improves.
- 20 — Practice
Guided exercise — Minimum subsystem margin — the weakest protected margin controls the immediate gate. Margins are 14%, 11%, 16% and 13%. Find system minimum.
Guided correction — Minimum subsystem margin — the weakest protected margin controls the immediate gate
- M_system=11%.
- Identify which subsystem owns that value before acting.
Autonomous exercise — Minimum subsystem margin — the weakest protected margin controls the immediate gate. Build a second case from “Improving a non-limiting 22% margin does not change system minimum until the 9% branch improves.”. Re-evaluate
M_system = min(M_i). Name the changed input. Decide whether “Direct recovery effort first at the limiting protected function while checking that the intervention does not create a new bottleneck.” still follows.Autonomous correction — Minimum subsystem margin — the weakest protected margin controls the immediate gate
For Minimum subsystem margin — the weakest protected margin controls the immediate gate, state the altered case. Preserve
dimensionless or %, only if all inputs use the same definition. Match the direction in “Improving a non-limiting 22% margin does not change system minimum until the 9% branch improves.”. Respect “Do not take a minimum across incompatible units or differently defined margins; normalize the decision metric first.”. Finish by retaining or revising: Direct recovery effort first at the limiting protected function while checking that the intervention does not create a new bottleneck.- 21 — Mission decision
- Direct recovery effort first at the limiting protected function while checking that the intervention does not create a new bottleneck.
Primary sources and bridges
First Man closed-loop ECLSS dossier — close mass, quality, buffers and recovery states
A closed loop is not “a recycler with a high percentage.” It is a controlled network of inventories, processors, sensors, quality gates, buffers, reject paths and degraded modes. This dossier teaches the learner to follow mass and evidence through that network and to protect crew survival when the process is uncertain.
Start with a mass balance, not a recovery percentage
NASA — Environmental Control and Life Support System describes the functions of environmental control and life support as an integrated set. A recovery percentage alone is not an inventory. The learner must know the demand basis, collectable stream, verified recovered stream, unavoidable losses, storage and make-up source.
Write the boundary first. If hygiene water, food water and technical water are mixed into one demand number, make sure the recovery stream covers the same categories. Otherwise a ninety-five-percent figure can be mathematically correct and operationally misleading.
Separate gross recovery from qualified recovery
NASA has reported high water-recovery performance on ISS, as described in the NASA — ISS water recovery milestone. The operational lesson is not that a Mars system may assume the same performance. It is that recovery, quality verification and inventory release are separate steps. Product held for analysis cannot be counted as crew water simply because it exited a processor.
The formula below therefore subtracts only verified recovered water from demand. Quarantine and off-spec streams stay visible.
Use buffers to buy diagnostic time
A buffer decouples crew demand from a processor for a limited period. Its value is measured in time under the degraded demand, not merely tank volume. Buffers allow isolation, sampling, repair and staged restart without immediately turning every process anomaly into a crew emergency.
But a buffer creates false confidence if the level sensor, valve path or water quality is uncertain. Keep verified accessible inventory separate from total physical inventory.
Treat humidity and trace contaminants as coupled loads
Cabin atmosphere quality is not only oxygen and carbon dioxide. Humidity, trace contaminants, particulates and microbial conditions can interact with thermal control and material behavior. A failed condensing heat exchanger can therefore change both humidity control and water recovery.
Coupling matters during troubleshooting. If one component supports several functions, isolating it to solve one problem can worsen another. The system diagram should show shared dependencies rather than only nominal flow arrows.
Plan manual degraded operation before automation fails
A closed-loop system often depends on sensors, control software and automatic valve sequencing. Manual operation is not a generic “crew can take over” statement. It requires accessible controls, procedures, training, time, communication and a safe range in which slower human action remains effective.
Record which variables must be monitored manually, at what interval, by which qualification and for how long. Human workload can become the limiting resource of a degraded ECLSS mode.
Restart through staged verification
NASA-STD-3001 Volume 2 reinforces the broader human-system discipline: restoring a machine is not identical to restoring a safe crew environment. After repair, verify function, product quality, sensor agreement, leak integrity and stable trends before reconnecting the full crew load.
A failed verification should send the loop back to isolation or diagnosis, not be treated as an inconvenience to be waived. The second atlas figure makes this state logic explicit.
Track common-cause dependencies across water, air and thermal
Power, cooling, controls, pumps and shared sensors can create common-cause failures. Two processors do not create true redundancy if both depend on the same unprotected power controller or coolant loop. The architecture review should identify what each “independent” path actually shares.
A useful drill is to remove one common support function and ask which loops remain controllable. The answer often reveals that the real redundancy problem sits outside the processor itself.
Board scenario — high recovery, rising quarantine
The water processor still reports excellent gross recovery, but conductivity and microbial screening place an increasing fraction of product in quarantine. Storage is falling even though the dashboard headline says recovery is above ninety percent.
A strong response shifts the dashboard to verified inventory, isolates the quality problem, protects reserve, reduces nonessential demand and decides how long the crew can operate before a repair or resupply path becomes mandatory. High process efficiency does not overrule a failed release gate.
Operational review drills — explain the evidence, not only the answer
- Boundary drill. Define demand and recovery on the same accounting boundary before quoting a percentage.
- Quality drill. Explain why quarantined recovered water cannot be credited to crew inventory.
- Buffer drill. Convert verified tank inventory and net deficit into diagnostic time.
- Manual-mode drill. List the variables and crew minutes needed for six hours of manual control.
- Common-cause drill. Remove one shared power controller and identify which supposedly redundant functions disappear.
- Restart drill. Write the verification sequence after replacing a contaminated process line.
Qualification notebook — closed-loop survival when the dashboard looks healthy
Closed loops fail in ways that headline recovery percentages can hide. These cases train the learner to follow verified inventory, quality, buffers, common causes and human workload through degraded operations.
Review-board ledger
- Qualified demand
- Gross recovered flow
- Quarantined / off-spec
- Verified recovered flow
- Verified storage
- Daily make-up
- Manual crew minutes
- Next quality / recovery gate
Case 1 — ninety-six percent recovery, falling potable inventory
Situation. The processor reports 96% gross water recovery, yet potable storage falls every day because an increasing fraction of output remains in quarantine. Management wants to advertise the recovery number as evidence the loop is healthy.
Reasoned disposition. Shift the primary operational metric to verified recovered mass and accessible potable inventory. Keep gross process recovery as a diagnostic metric, not a release metric. Calculate daily make-up from verified recovery, estimate time to the protected reserve and investigate the quality failure. A high recovery percentage cannot close a crew water balance with quarantined product.
Case 2 — redundant processors share one controller
Situation. Two water processors are installed and the architecture labels them redundant. A controller failure disables the valves and sensors serving both.
Reasoned disposition. The processors are duplicated, but the function is not independent. Redundancy analysis must follow power, control, cooling, feed and discharge paths. Add an independent control or manual safe configuration, or change the claim from redundant to duplicated hardware with a common-cause dependency. Terminology matters because it changes what failures the crew expects to survive.
Case 3 — manual mode consumes the maintenance team
Situation. Automatic control is unavailable. The loop can be kept safe manually, but it requires two qualified operators for ten minutes every half hour. The same people are needed for a power-system repair.
Reasoned disposition. Translate manual mode into person-hours and qualification occupancy. The loop may be physically controllable but operationally unsustainable. Prioritize actions that reduce monitoring frequency, add backup operators or simplify the degraded configuration. Human workload belongs in the ECLSS failure model because it can become the shared resource that causes a second failure.
Case 4 — repaired hardware, failed quality verification
Situation. A contaminated line is replaced and flow returns to normal. A quick sensor check looks acceptable, but a required laboratory quality result is still pending.
Reasoned disposition. Do not equate restored flow with restored safe service. Keep the branch isolated or in controlled recirculation until the release evidence closes. If storage margin permits, preserve the verification sequence. If margin does not permit, escalate the conflict explicitly rather than silently waiving the quality gate.
Case 5 — surplus recovery with full storage
Situation. A repaired system temporarily produces more qualified water than daily demand, and the make-up equation correctly returns zero. Storage is already near maximum.
Reasoned disposition. Use a separate storage balance. Decide whether surplus can be routed to another qualified use, stored in another tank or safely curtailed. Never report negative make-up as though it were a credit that can be spent elsewhere. The state of tanks and alternate sinks becomes the limiting condition once demand is fully covered.
Daily verified make-up requirement for a closed water loop
- 1 — Concrete question
- How much new qualified water must enter the crew inventory each day after verified recovery is counted?
- 2 — Intuition without symbols
- Start from the day’s qualified demand and subtract only the recovered water that has actually passed the quality gate. If recovery exceeds demand, make-up cannot become negative; handle the surplus as storage or another stream.
- 3 — Quantities first
- m_demand is qualified daily water demand; m_verified,recovered is recovered water released by the quality gate; m_makeup is the external or stored qualified water needed to close the daily balance.
- 4 — Formula
- m_makeup = max(0, m_demand − m_verified,recovered)
- 5 — Read aloud
- “m makeup equals the maximum of zero and m demand minus m verified recovered.”
- 6 — Symbols
- m denotes mass over the stated daily accounting period. The max function prevents a physically meaningless negative make-up requirement.
- 7 — Pronunciation
- max is read “maximum”. The verified-recovered subscript means the recovered stream has passed its release criteria.
- 8 — Units
- kg/day − kg/day = kg/day.
- 9 — Convention
- Recovered process flow is not counted until quality is verified. Any surplus above demand is accounted for separately as storage accumulation, export to another use or controlled disposal.
- 10 — Why this operation
- Demand must be met by qualified inventory. Subtracting verified recovery shows the residual that must come from make-up sources; clipping at zero keeps the meaning of make-up physically valid.
- 11 — Assumptions
- The daily accounting boundary includes the same uses in demand and recovery. Storage changes and intentionally nonrecoverable uses are tracked separately rather than hidden inside recovery percentage.
- 12 — Unit check
- Both input terms are daily mass flows, so the difference is kg/day.
- 13 — Numerical case
Qualified demand m_demand = 80 kg/day.Processor reports 76 kg/day gross recovery, but 3 kg/day remains quarantined after quality checks.Verified recovered water = 76 − 3 = 73 kg/day.m_makeup = max(0, 80 − 73) = 7 kg/day.- 14 — Why each operation
- First remove unverified product from the recovery claim. Then subtract verified recovery from qualified demand. The max operator prevents surplus production from being mislabeled as negative make-up.
- 15 — Algebra check
- When verified recovery is below demand, m_verified,recovered = m_demand − m_makeup. If verified recovery is at or above demand, make-up is zero and the surplus requires a separate storage-balance equation.
- 16 — Mental estimate
- If demand is eighty and verified recovery is a little above seventy, make-up should be around seven, so the result is plausible.
- 17 — Interpretation
- The crew loop needs 7 kg/day of qualified make-up under this accounting state.
- 18 — What it does not prove
- It does not prove storage is sufficient, pumps are reliable, microbiological quality is stable, recovery can be sustained or the make-up source is accessible.
- 19 — Sensitivity or limit case
- If quarantine rises from 3 to 10 kg/day while gross recovery stays at 76, verified recovery falls to 66 and make-up doubles to 14 kg/day. Quality performance can dominate the inventory even when gross recovery looks unchanged.
- 20 — Practice
Guided exercise. Demand is 95 kg/day. Gross recovery is 90 kg/day but 4 kg/day is held pending quality release. Find verified recovery and make-up.
Detailed guided correction.
- Verified recovery = 90 − 4 = 86 kg/day.
- Make-up = max(0, 95 − 86) = 9 kg/day.
- The 4 kg/day hold is not silently credited until the quality gate releases it.
Autonomous exercise. Demand is 70 kg/day and verified recovery is 74 kg/day for three days. Explain what the formula returns and write the separate storage change if all 4 kg/day surplus can be stored.
Autonomous correction — open after attempting the exercise
One defensible worked solution.
- m_makeup = max(0, 70 − 74) = 0 kg/day.
- There is no negative make-up; the loop simply needs no external make-up under this simplified daily balance.
- Storage accumulation = (74 − 70) × 3 = 12 kg if storage capacity and quality remain available.
- If storage is full, the 4 kg/day surplus needs another disposition rather than changing the meaning of make-up.
- 21 — Mission decision
- Use only verified recovery to close the crew water balance. Treat quarantine, storage capacity and surplus disposition as explicit states so a high recovery percentage cannot hide a shortage of releasable water.
Primary-source map for this operational dossier
Closed-loop ECLSS qualification casebook — mass balance, quality, buffers and staged recovery
A high recovery percentage is not the same as a survivable loop. A habitat must close mass, verify product quality, maintain buffers, detect contamination, preserve manual modes and recover through evidence gates. This dossier deepens the learner’s ability to reason across the water, air, humidity, trace-contaminant and thermal interfaces as one coupled survival system.
Dynamic mass balance comes before efficiency slogans
Primary source: NASA — Environmental Control and Life Support System.
Every loop has inputs, outputs, storage and losses that vary with time. A recovery percentage describes one relationship but does not reveal whether the inventory is rising or falling. The operator needs to know the actual make-up demand, buffer level and trend.
A healthy-looking percentage can coexist with a serious shortfall if total demand rises, product is quarantined or the recovered stream fails quality checks. Use mass balance and verified product flow together.
Qualified recovery is the only recovery the crew can drink or breathe
A processor may produce fluid or gas while downstream quality is uncertain. That stream is physically recovered but not operationally available. The distinction between gross and qualified recovery prevents dashboards from crediting inventory that the crew cannot safely use.
Quarantine should therefore have its own storage, sampling plan and release authority. If quality evidence is delayed, the buffer must absorb the gap without forcing premature acceptance.
Buffers buy diagnostic time, not permission to delay forever
Storage tanks, compressed gas, sorbent capacity and contingency consumables are time buffers. They convert an immediate failure into a bounded diagnostic window. Their value depends on verified usable inventory and the degraded-mode consumption rate.
Operators should know the trigger points that change behaviour: begin conservation, stop discretionary use, isolate a suspected stream, switch to backup processing or enter a safe-haven mode. A buffer without action thresholds is only a number.
Humidity and trace contaminants cross subsystem boundaries
Primary source: NASA — ISS water recovery milestone.
Water removal from cabin air interacts with temperature, airflow and microbial risk. Trace contaminants interact with materials, cleaning products, payloads and fire response. These loads do not respect the organisational chart of the hardware.
When one measurement trends abnormally, the investigation should follow physical pathways. A humidity change can indicate thermal-control behaviour, ventilation imbalance or condensate-processing problems rather than a stand-alone ‘humidity system’ failure.
Sensors and automation require an independent reality check
Closed loops depend heavily on measurement. A drifting sensor can cause the controller to move the process in the wrong direction while the automation reports that it is responding correctly.
Critical variables therefore need cross-checks, plausibility limits and manual diagnostic procedures. The crew must know how to recognise a sensor fault from a process fault and how to hold a safe configuration while that distinction is unresolved.
Manual degraded mode should be designed before it is needed
When automation or one processor fails, the crew may have to sample manually, move valves, change filters, ration use or bypass a component. These actions consume time and can create new contamination risks.
The degraded-mode procedure should state which functions can be lost temporarily, which must continue, which measurements become manual, how often they are taken and when crew workload itself becomes the limiting factor.
Restart should progress through evidence states
Primary source: NASA-STD-3001 Volume 2.
After maintenance, the safest sequence is not ‘turn everything back on’. Isolate, inspect, leak-check, start at controlled conditions, verify sensor agreement, quarantine initial product if needed and only then reconnect to the crew loop.
Each step has a rollback point. If evidence fails, the operator returns to the previous stable configuration rather than pushing forward because the schedule expects recovery.
Common-cause dependencies can defeat nominal redundancy
Two redundant water processors may share power, cooling, software, a common filter stock or the same specialist. A pair of diagrams showing two boxes does not prove independent resilience.
The architecture should map shared utilities, consumables, maintenance access and human expertise. True redundancy is a property of failure independence and recovery capability, not of box count.
Qualification casebook — six board decisions
1. Recovery percentage is high but the potable tank is falling. Demand increased during a medical event.
Reasoned disposition — open after making your own decision
Use the mass balance: high percentage does not guarantee positive inventory. Reduce discretionary demand and verify qualified production against the new load.
2. Recovered water enters quarantine after an unexpected reading. Storage can support the crew for two days.
Reasoned disposition — open after making your own decision
Use the buffer to investigate; do not release uncertain product merely to preserve a dashboard target. Define sampling and release criteria.
3. Humidity rises while the water processor appears normal. Cabin temperature also changed.
Reasoned disposition — open after making your own decision
Trace the coupled path through ventilation, condensation and thermal control rather than assuming one dedicated component is at fault.
4. One CO2 sensor drifts slowly. The controller increases removal effort.
Reasoned disposition — open after making your own decision
Cross-check independent measurements and crew/environment indicators. Stabilise the loop while determining whether the sensor or process is wrong.
5. Automation fails during a weekend science campaign. The manual mode exists only in a maintenance manual.
Reasoned disposition — open after making your own decision
Activate the predefined degraded procedure, reduce optional loads and account for crew-hours. A theoretically possible manual mode is not operationally available unless practised.
6. A repaired processor produces good output for ten minutes. The team wants to reconnect immediately.
Reasoned disposition — open after making your own decision
Continue staged verification for the required endurance and sensor agreement, quarantine initial product if appropriate and preserve the rollback state until evidence closes the gate.
Mastery studio — four extended review problems
Use these ECLSS problems to trace mass, quality, buffers and recovery state across coupled loops instead of trusting one efficiency number.
1. High recovery, falling inventory. The water processor reports 96% gross recovery, yet verified potable storage falls every day.
Extended reasoned answer — open after attempting the problem
Build the actual mass balance. Compare crew demand, qualified recovered output, quarantined product, leaks, cleaning loads and other losses. The percentage may be calculated on processor feed while mission demand has increased elsewhere. Protect buffer thresholds and change operations based on verified inventory trend, not the reassuring recovery number. If the qualified output cannot meet essential demand, the loop is in deficit regardless of the headline efficiency.
2. Sensor-driven false correction. A drifting humidity sensor causes the controller to increase dehumidification and changes cabin thermal behaviour.
Extended reasoned answer — open after attempting the problem
Freeze the automation in a safe bounded mode if necessary, compare independent humidity and temperature measurements, inspect condensate flow and check sensor calibration. The symptom crosses humidity, thermal control and water recovery, so a single subsystem dashboard is insufficient. After identifying the bad sensor, restore control gradually and verify that the water and thermal loops return to expected state without creating a second transient.
3. Quarantined product fills storage. A quality anomaly leaves several days of recovered water in quarantine tanks while the verified potable buffer declines.
Extended reasoned answer — open after attempting the problem
The system has mass but not usable inventory. Define a sampling plan and release criteria, protect verified potable stock for essential uses and decide whether nonessential water demand must be reduced. If quarantine capacity becomes the new bottleneck, the crew may need to stop or reroute recovery even though the processor itself is healthy. The case demonstrates why quality and storage architecture are part of loop closure.
4. Recovery after maintenance. A repaired CO2 removal assembly meets its target for fifteen minutes after restart.
Extended reasoned answer — open after attempting the problem
Do not declare recovery from one good reading. Verify sensor agreement, stable performance over the required endurance, acceptable cabin trend and the absence of new leakage or thermal effects. Maintain a rollback configuration until the evidence gate is satisfied. Only then return from degraded operation to normal automation. Recovery means restored function plus enough proof that the function will persist, not merely a successful startup transient.
Primary sources used in this qualification dossier
- NASA — Environmental Control and Life Support System
- NASA — ISS water recovery milestone
- NASA-STD-3001 Volume 2
Closure standard. The learner can close a dynamic life-support balance, distinguish gross from qualified recovery, protect buffers and restore the loop through staged evidence rather than optimistic automation.
ECLSS fault isolation and recovery proof — do not let one sensor become reality
Closed-loop systems create a particular trap: a dashboard can look efficient while quality, inventory or instrumentation is drifting. The operational layer adds a diagnostic discipline that asks which independent observations should change if a hypothesis is true, and turns restart into an evidence sequence rather than a switch flip.
Independent evidence separates sensor drift from process drift
If a water-quality value changes, the team should look for independent corroboration: grab sample, tank level, conductivity, flow, humidity or process chemistry depending on the loop. A single sensor is evidence, not reality. The expected cross-effects help distinguish a bad measurement from a real mass-balance problem.
The anomaly-isolation matrix in the atlas is deliberately qualitative. Its purpose is to train the learner to predict what else should change under each hypothesis before touching the system.
Buffers provide diagnostic time but can hide worsening faults
A large potable-water tank can keep crew supply stable while recovery output degrades. That is good because the crew remains protected, but dangerous if the buffer masks the deterioration until little reserve remains. Operations should track both buffer state and process health.
A board therefore asks not only ‘how many days remain?’ but ‘is the underlying process improving, stable or worsening?’ A buffer is a time resource, not a repair.
Microbial and chemical quality need trend context
A closed water loop can meet bulk recovery targets while trace contaminants or microbial conditions drift. Sampling frequency, analytical sensitivity and quarantine policy therefore influence how quickly the problem becomes visible.
The module should avoid implying that one recovery percentage certifies water. NASA ECLSS material is the primary bridge for actual ISS environmental-control functions; the diagnostic matrices here are pedagogical abstractions.
Restart should requalify outputs before reconnecting critical loads
After maintenance or isolation, a loop may flow before its product is qualified. Water can circulate while quality remains uncertain; an air loop can move gas while a contaminant-control branch is still unstable. Recovery therefore separates mechanical restart from functional qualification and from return to normal redundancy.
The staged sequence is: verify configuration, establish controlled operation, measure independent evidence, qualify output, reconnect critical users and only then retire the degraded-state restrictions. This prevents the crew from becoming the acceptance test.
Common-cause failures often live outside the process hardware
Two pumps can be redundant and still share power, cooling, software, sensors or maintenance expertise. A common calibration procedure can bias multiple sensors at once. A shared tank can propagate contamination across nominally separate branches.
The reliability review therefore draws dependencies across loops. NASA-STD-3001 Volume 2 provides a primary human-factors/habitability bridge for environmental conditions; detailed loop design requires the relevant subsystem standards and test evidence.
Operational review board — five decisions to defend
1. Water recovery percentage is normal, tank falls. The dashboard says 92% recovery.
Reasoned disposition — open after making your own decision
Check real flows, leaks, usage and instrumentation. Percentage alone cannot close a mass balance.
2. Two sensors drift together. Both were calibrated in the same maintenance session.
Reasoned disposition — open after making your own decision
Treat common calibration error as a hypothesis and use an independent method before changing the process.
3. Buffer remains healthy while product quality worsens. Crew supply is still adequate.
Reasoned disposition — open after making your own decision
Use the buffer to diagnose deliberately, but impose a decision deadline based on trend and remaining qualified inventory.
4. Loop restarts and flow looks normal. Quality sample is pending.
Reasoned disposition — open after making your own decision
Keep critical users isolated or supplied from qualified reserve until output passes the required acceptance evidence.
5. Redundant processors fail after a software update. Hardware is physically independent.
Reasoned disposition — open after making your own decision
Treat the shared software/configuration path as common cause; rollback or isolate configuration before claiming redundancy restored.
Mission rehearsal notebook — reason through evidence before revealing the disposition
Diagnostic drill — apparent leak is actually demand growth
Tank inventory declines faster than last month while recovery efficiency appears unchanged. Before opening plumbing panels, the team reconciles crew use, plant experiments, humidity recovery and new cleaning procedures. The balance shows that demand increased after a new greenhouse activity began. The exercise demonstrates that an unexplained inventory trend is not automatically a hardware leak; complete accounting precedes invasive troubleshooting.
Diagnostic drill — common calibration error
Two redundant quality sensors were calibrated from the same reference solution and drift together. Agreement between them is therefore not independent confirmation. A grab sample using a different analytical method becomes more valuable than a third reading from the same calibration chain. The lesson generalizes beyond ECLSS: redundancy of hardware does not imply independence of evidence.
Recovery drill — output returns before redundancy
A repaired processor produces qualified water again, but its backup train remains isolated and the buffer is still low. Operations may leave the emergency state but should not declare full mission recovery. The board defines intermediate states—function restored, reserve rebuilt, redundancy restored—and ties mission tempo to those states. This prevents a premature return to aggressive operations while the system is still one fault away from renewed crisis.
Primary sources used in this exercise
Closure review — closed-loop resilience is mass balance, qualified output and recoverability
A recovery percentage can be technically impressive while the crew still depends on large reserves, fragile sensors or one specialist. The final standard therefore asks five separate questions. Does the mass balance close? Is the output actually qualified for its intended use? Is enough protected reserve available while diagnosis occurs? Can the system be isolated without contaminating other loops? Can a degraded crew recover it with evidence rather than hope?
Mass balance is the first diagnostic, not the last audit
If tank level declines faster than expected, the team reconciles all known inflows, outflows and transfers before declaring a leak. Crew demand may have changed. A greenhouse or cleaning campaign may add load. Condensate recovery may shift. A sensor may be biased. The balance does not prove which cause is correct, but it makes hidden consumption visible and tells the team how quickly the inventory problem is becoming operational.
Qualified output is a different state from gross recovered output
Recovered water in a process tank is not automatically drinking-water inventory. Air circulated through a loop is not automatically proven safe. Sampling, independent sensor evidence, microbial/chemical acceptance and configuration state can place output in quarantine. The inventory ledger therefore distinguishes gross recovered, awaiting qualification, rejected/rework and qualified available output.
Buffers buy investigation time only while the trend remains bounded
A healthy buffer can make a failing process look calm. The board uses the buffer to create diagnostic time, but it sets a deadline based on current inventory, trend and uncertainty. If quality is worsening or a common-cause failure is plausible, the correct action can be to isolate earlier rather than consume the entire buffer while waiting for certainty.
Evidence independence should be visible in the diagnostic matrix
The anomaly-isolation atlas now uses P, S and ! symbols in addition to colour. The accessibility improvement also reinforces the engineering lesson: an independent measurement is not the same thing as a second display using the same sensor chain. A laboratory grab sample, physical inventory measurement or independently calibrated instrument can carry more diagnostic value than another reading generated from the same calibration source.
Manual degraded mode must have staffing and duration limits
Manual sampling, transfers or valve alignment can preserve life-support functions after automation is lost, but the workaround consumes crew time and raises human-error exposure. The procedure should specify qualification, two-person verification where hazardous, maximum sustainable cadence, protected rest and the trigger for simplifying the configuration or reducing demand. A workaround that can be sustained for one shift may not be a viable multi-day operating mode.
Restart is a sequence of evidence states
A pump running or a normal flow indication is only the start. The team proves the cause is controlled, verifies the configuration, restarts at bounded conditions, checks process response, qualifies output, reconnects critical loads and then rebuilds reserve/redundancy. The system can therefore pass through function restored, reserve rebuilt and redundancy restored as separate states. Mission tempo should reflect which state has actually been reached.
Closure case 1 — two quality sensors agree after shared calibration
Agreement is not independent confirmation. Treat common calibration bias as a live hypothesis and seek an independent analytical method or reference. Do not reconfigure the process solely because two instruments share the same number.
Closure case 2 — buffer remains strong but microbial trend is worsening
Set an isolation/decision deadline before the buffer becomes the reason to delay. Protect a qualified reserve, increase independent sampling and determine whether the affected inventory must be quarantined. The buffer is buying evidence time, not permission to ignore trend.
Closure case 3 — manual mode restores water but consumes half the maintenance shift
Record the workload as part of system status. Reduce other demand, train backup operators and determine how long the manual mode can be sustained without creating maintenance debt or fatigue-related risk elsewhere.
Closure case 4 — output is qualified but backup train remains isolated
Function may be restored, but resilience is not. Keep the architecture in an intermediate recovery state until reserve and redundancy are rebuilt or the mission formally accepts the reduced fault tolerance.
Freeze criteria for this module
- The learner can close a water or air mass balance before discussing recovery percentage.
- The learner distinguishes gross recovery from qualified output.
- The learner explains why buffers, independent evidence and workload determine diagnostic time.
- The learner can describe staged restart and why “output returned” is not equivalent to “mission recovered”.
- The learner can identify shared power, thermal, software, calibration and human dependencies as common causes.
Closure drill — a closed loop still exchanges mass with storage and the crew
No loop should be described as “closed” without naming its remaining imports, exports, losses and stored buffers. The learner should be able to draw the boundary around the process, identify what crosses it and explain why a high recovery percentage does not remove the need for verified reserve.
Closure drill — contamination creates inventory states
If a tank is quarantined, the water still exists physically but is not qualified crew inventory. The operations ledger should therefore avoid counting quarantined output as available until the acceptance evidence closes. This same state-based reasoning is used in the ISRU module.
