Leadership, spaceflight CRM and crew performance
Train a small isolated crew to communicate, decide, challenge safely, manage fatigue and conflict, redistribute workload and preserve shared situational awareness.
Mastery objectives
- connect principles to architecture or operational decisions
- repeat simple calculations and verify units and assumptions
- identify degraded modes, interfaces and uncertainty
- produce a verifiable procedure or plan
1. A technically strong crew can still fail through poor coordination
Six excellent specialists do not automatically make an excellent team. Missing information, rigid hierarchy or unreported fatigue can cancel technical skill. Spaceflight resource management treats communication, decision-making and cooperation as trainable capabilities.
2. Shared situational awareness
Each crewmember holds part of the picture: vehicle state, weather, health, power and science. Robust teams verbalize important changes and maintain a shared model of what is happening, what is expected next and what may go wrong.
3. Leadership and followership
A commander should neither decide everything alone nor abandon decision responsibility. Leadership sets priorities, distributes roles and creates conditions in which a specialist can report danger. Followership means supporting the team while still challenging a potentially unsafe decision clearly.
4. Closed-loop communication and verification
For critical actions an instruction should be heard, repeated and confirmed. Closed-loop communication reduces misunderstanding. It may appear slow, but with training it becomes rapid and costs far less time than executing the correct procedure on the wrong valve.
5. Fatigue, workload and redistribution
A high-performing team monitors who is approaching saturation. When workload rises, it simplifies objectives, redistributes tasks and protects vital functions. Fatigue alters attention and memory and must therefore be treated as an operational condition rather than a moral weakness.
6. Useful conflict and destructive conflict
Technical disagreement is valuable when it addresses evidence and remains oriented toward the problem. Conflict becomes dangerous when it attacks people, blocks information or forms persistent factions. Mediation and debriefing methods must be known before a crisis occurs.
7. Distributed leadership: expertise can temporarily move practical authority
A Mars crew has a formal hierarchy, but not every situation is best directed by the same person. During a power failure, the electrical specialist may hold the most relevant technical picture; during a medical emergency, the clinical lead needs initiative within that domain. Distributed leadership does not erase command structure. It defines how command makes use of expertise. The commander must be able to delegate clearly, define decision boundaries and resume overall coordination when several functions conflict. Crewmembers also need professional followership: raising risk, challenging an assumption respectfully and then supporting the decision once an adjudication is made.
8. Workload, sleep and error: treating human performance as a resource
A crew can have excellent hardware and still degrade safety through chronic overload. Inadequate sleep, repeated alarms, interrupted tasks and competing priorities reduce attention and working memory. Scheduling therefore needs margin, rotation, protected periods and the ability to defer noncritical activity. Indicators should not only count hours worked; they should also track accumulated tasks, duration of high-intensity periods, repeated error and recovery needs. Fatigue is neither a moral failure nor an invisible variable. It is an operational constraint that must be managed alongside power, water and consumables.
9. After-action review: turning team error into shared knowledge
After a difficult simulation, EVA or incident, a useful debrief reconstructs events before assigning responsibility. What did the team expect? What did it observe? When did mental models diverge? Which communication was missing? Which barriers still worked? The goal is to modify procedures, training and interfaces rather than produce a story in which one individual carries all blame. This practice builds collective memory and trust because crewmembers know that honest reporting will improve the system. On Mars, where the same small team accumulates experience for years, the ability to learn collectively becomes a safety function.
10. Worked example: team workload margin
An EVA requires 14 elementary tasks per hour. Four available people can each sustain 4 tasks/h, giving 16 tasks/h of capacity. Margin is only 2/16 = 12.5%. If one person becomes unavailable, capacity falls to 12 tasks/h and the plan is overloaded. At least 2 tasks/h must then be removed or deferred.
Calculated case study: how much time should critical handovers reserve?
TEACHING ASSUMPTION — A six-person crew schedules 12 critical responsibility handovers per sol. Each closed-loop handover, including the message, receiver read-back and confirmation, takes an average of 2.25 minutes.
Let N be the number of handovers, dimensionless; t their mean duration in minutes; m the planning margin, dimensionless; and T the total time in minutes.
T = N × t = 12 × 2.25 = 27 min. With m = 0.25, T_plan = T × (1 + m) = 27 × 1.25 = 33.75 min.
The crew therefore reserves about 34 minutes per sol. This calculation does not prove that longer briefings reduce errors; it simply makes the time cost of a CRM procedure visible and shows how to preserve margin when real operations drift from the plan.
11. Progressive exercise
Simulate an electrical failure in which the commander proposes an action and the power engineer identifies a hazard. Write a short exchange that challenges the decision without disrupting team control.
Reasoned correction
An effective CRM exchange could be: “Commander, safety objection: if we re-energize now, bus B may exceed its thermal limit.” — “Acknowledged. State the risk and alternative.” — “Hold the shed configuration for three minutes, confirm converter temperatures, then restore one load group at a time. If temperature does not fall, remain in refuge configuration.” — “Approved. You own the verification; operations announces the revised sequence.” The challenge is brief, factual and paired with an option. Command authority remains clear while technical expertise can stop a decision before a manageable fault becomes a system loss.
Mini-project
Design a six-month crew-training program covering communication, decision-making, conflict, fatigue, handovers, integrated simulations, debriefing and observable team-performance criteria.
Crew performance is an engineered resource: leadership and CRM keep expertise connected under pressure
A Mars crew can contain excellent specialists and still fail if information, authority and workload are badly coordinated. Crew resource management, often shortened to CRM, treats communication, leadership, followership, workload and shared situation awareness as operational systems. The objective is not to make everyone agree. It is to make critical information visible and to ensure the person with authority actually receives, understands and uses the best available expertise.
Long missions amplify small coordination problems. Fatigue, monotony, interrupted sleep, repeated alarms and private frustration can degrade attention before anyone identifies a dramatic conflict. Performance therefore needs observable signals: workload saturation, missed call-backs, repeated procedural deviations, delayed decisions and incomplete handovers. Human factors become safer when treated with the same seriousness as consumable margins rather than as personal weakness.
Leadership on Mars is situational. A commander retains formal responsibility, but during a medical emergency the physician may lead technical decisions; during an electrical fault the power specialist may direct immediate diagnostic steps. Effective crews make these temporary shifts explicit so expertise can move practical authority without creating ambiguity about overall command or stop rules.
Closed-loop communication is one of the simplest protections against error. A sender states a critical message, the receiver repeats the relevant content, and the sender confirms or corrects it. The loop costs seconds, which can feel inefficient during urgency, but those seconds can prevent minutes of wrong action. The same principle extends to digital handovers and delayed Earth communication: important decisions need acknowledgement and a shared representation of current state.
Four CRM concepts that convert a group of specialists into a reliable crew
Shared situation awareness
A common working picture of what is happening, what matters next, which uncertainties remain and how team actions interact. It does not require every crewmember to know every technical detail.
Closed-loop communication
Communication pattern in which a critical instruction or observation is transmitted, repeated or acknowledged by the receiver, then confirmed or corrected by the sender.
Leadership and followership
Leadership directs priorities and decisions; good followership actively contributes expertise, challenges unsafe assumptions and confirms execution instead of remaining passive.
Workload management
Deliberate allocation, postponement or redistribution of tasks so human attention stays within a manageable range during routine and abnormal operations.
Calculation laboratory
Formula 1 — team workload margin
Quantitative mini-lessons
Team workload margin
- 1 — Concrete question
- What does “M_team = C_available - W_required” compute in “Team workload margin”?
- 2 — Intuition without symbols
- Crew performance requires comparing required work with capacity actually available.
- 3 — Quantities
- M_team: team capacity margin [personne-h]; C_available: actually available capacity [personne-h]; W_required: required workload [personne-h]
- 4 — Formula
- M_team = C_available - W_required
- 5 — Read aloud
- Read “M_team = C_available - W_required” by naming every operation, subscript and grouping explicitly.
- 6 — Symbols and meaning
- M_team: team capacity margin [personne-h]; C_available: actually available capacity [personne-h]; W_required: required workload [personne-h]
- 7 — Pronunciation
- The “Read aloud” line above is the oral reference for “Team workload margin”. Any subscript, exponent or grouping that changes the meaning of the relation should be spoken explicitly.
- 8 — Units
- M_team [personne-h]; C_available [personne-h]; W_required [personne-h]
- 9 — Convention
- For “Team workload margin”, substitute values without changing the reference frame, time basis, system boundary or sign convention halfway through the calculation. Stated units: M_team [personne-h]; C_available [personne-h]; W_required [personne-h].
- 10 — Why this operation
- In “Team workload margin”, subtraction measures a margin or difference between comparable quantities expressed in the same frame.
- 11 — Assumptions
- The relation “M_team = C_available - W_required” applies here only to the scenario described by the card. Inputs must be mutually consistent and satisfy the physical assumptions associated with “Team workload margin”.
- 12 — Independent check
- Adding the margin back to the subtracted term should reconstruct the initial state.
- 13 — Numerical case
- With C_available = 24 personne-h, W_required = 20 personne-h: M_team = 24 - 20 = 4 personne-h.
- 14 — Why the calculation works
- The numerical case applies “M_team = C_available - W_required” directly to the stated values. The calculation is meaningful because the quantities are substituted into the same relation before the result is interpreted for “Team workload margin”.
- 15 — Verification
- Quick check: adding the subtracted term back to the result should reconstruct the starting quantity in “Team workload margin”.
- 16 — Mental estimate
- Before calculating “Team workload margin” precisely, round the inputs to one useful digit and predict the sign and order of magnitude. The detailed result should remain consistent with that estimate.
- 17 — Interpretation
- A negative margin requires removing, deferring, automating or reassigning work.
- 18 — What the result does not prove
- For “Team workload margin”, the number obtained answers only the model “M_team = C_available - W_required” under the stated scenario. It does not by itself validate the input data or the model outside those conditions.
- 19 — Sensitivity
- Vary one input at a time around the nominal case to identify what drives the result of “Team workload margin” and whether that variation can change the mission decision.
- 20 — Guided and autonomous exercises
Guided exercise. Recalculate this scenario: With C_available = 21 personne-h, W_required = 24 personne-h: M_team = 21 - 24 ?
Detailed guided correction — open after trying
With C_available = 21 personne-h, W_required = 24 personne-h: M_team = 21 - 24 = -3 personne-h. The decision must then be checked against the module margins and assumptions.
Autonomous exercise. Recalculate this scenario: With C_available = 32 personne-h, W_required = 27 personne-h: M_team = 32 - 27 ?
Autonomous correction — open after trying
With C_available = 32 personne-h, W_required = 27 personne-h: M_team = 32 - 27 = 5 personne-h. The decision must then be checked against the module margins and assumptions.
- 21 — Mission decision
- A negative margin requires removing, deferring, automating or reassigning work.
Communication-loop time
- 1 — Concrete question
- What does “T_comm = N_calls × t_loop” compute in “Communication-loop time”?
- 2 — Intuition without symbols
- Repeated short loops can consume a significant share of an operational window.
- 3 — Quantities
- T_comm: total time spent on critical calls [s]; N_calls: number of calls [appels]; t_loop: mean duration per call [s/appel]
- 4 — Formula
- T_comm = N_calls × t_loop
- 5 — Read aloud
- Read “T_comm = N_calls × t_loop” by naming every operation, subscript and grouping explicitly.
- 6 — Symbols and meaning
- T_comm: total time spent on critical calls [s]; N_calls: number of calls [appels]; t_loop: mean duration per call [s/appel]
- 7 — Pronunciation
- The “Read aloud” line above is the oral reference for “Communication-loop time”. Any subscript, exponent or grouping that changes the meaning of the relation should be spoken explicitly.
- 8 — Units
- T_comm [s]; N_calls [appels]; t_loop [s/appel]
- 9 — Convention
- For “Communication-loop time”, substitute values without changing the reference frame, time basis, system boundary or sign convention halfway through the calculation. Stated units: T_comm [s]; N_calls [appels]; t_loop [s/appel].
- 10 — Why this operation
- In “Communication-loop time”, multiplication combines the factors that directly build the requested quantity; the factors must describe the same case.
- 11 — Assumptions
- The relation “T_comm = N_calls × t_loop” applies here only to the scenario described by the card. Inputs must be mutually consistent and satisfy the physical assumptions associated with “Communication-loop time”.
- 12 — Independent check
- Dividing the result by a non-zero factor should recover the product of the others.
- 13 — Numerical case
- With N_calls = 18 appels, t_loop = 12 s/appel: T_comm = 18 × 12 = 216 s.
- 14 — Why the calculation works
- The numerical case applies “T_comm = N_calls × t_loop” directly to the stated values. The calculation is meaningful because the quantities are substituted into the same relation before the result is interpreted for “Communication-loop time”.
- 15 — Verification
- Quick check: for any non-zero factor, dividing the result by that factor should recover the other expected contribution in “Communication-loop time”.
- 16 — Mental estimate
- Before calculating “Communication-loop time” precisely, round the inputs to one useful digit and predict the sign and order of magnitude. The detailed result should remain consistent with that estimate.
- 17 — Interpretation
- Limit nonessential calls when coordination time threatens the primary task.
- 18 — What the result does not prove
- For “Communication-loop time”, the number obtained answers only the model “T_comm = N_calls × t_loop” under the stated scenario. It does not by itself validate the input data or the model outside those conditions.
- 19 — Sensitivity
- Vary one input at a time around the nominal case to identify what drives the result of “Communication-loop time” and whether that variation can change the mission decision.
- 20 — Guided and autonomous exercises
Guided exercise. Recalculate this scenario: With N_calls = 24 appels, t_loop = 9 s/appel: T_comm = 24 × 9 ?
Detailed guided correction — open after trying
With N_calls = 24 appels, t_loop = 9 s/appel: T_comm = 24 × 9 = 216 s. The decision must then be checked against the module margins and assumptions.
Autonomous exercise. Recalculate this scenario: With N_calls = 10 appels, t_loop = 20 s/appel: T_comm = 10 × 20 ?
Autonomous correction — open after trying
With N_calls = 10 appels, t_loop = 20 s/appel: T_comm = 10 × 20 = 200 s. The decision must then be checked against the module margins and assumptions.
- 21 — Mission decision
- Limit nonessential calls when coordination time threatens the primary task.
Planned task time with margin
- 1 — Concrete question
- What does “T_plan = N_tasks × t_task × (1 + m_margin)” compute in “Planned task time with margin”?
- 2 — Intuition without symbols
- A realistic sequence must include margin beyond nominal task time.
- 3 — Quantities
- T_plan: total planned time [min]; N_tasks: number of tasks [tâches]; t_task: mean time per task [min/tâche]; m_margin: fractional margin [sans dimension]
- 4 — Formula
- T_plan = N_tasks × t_task × (1 + m_margin)
- 5 — Read aloud
- Read “T_plan = N_tasks × t_task × (1 + m_margin)” by naming every operation, subscript and grouping explicitly.
- 6 — Symbols and meaning
- T_plan: total planned time [min]; N_tasks: number of tasks [tâches]; t_task: mean time per task [min/tâche]; m_margin: fractional margin [sans dimension]
- 7 — Pronunciation
- The “Read aloud” line above is the oral reference for “Planned task time with margin”. Any subscript, exponent or grouping that changes the meaning of the relation should be spoken explicitly.
- 8 — Units
- T_plan [min]; N_tasks [tâches]; t_task [min/tâche]; m_margin [sans dimension]
- 9 — Convention
- For “Planned task time with margin”, substitute values without changing the reference frame, time basis, system boundary or sign convention halfway through the calculation. Stated units: T_plan [min]; N_tasks [tâches]; t_task [min/tâche]; m_margin [sans dimension].
- 10 — Why this operation
- In “Planned task time with margin”, multiplication combines the factors that directly build the requested quantity; the factors must describe the same case.
- 11 — Assumptions
- The relation “T_plan = N_tasks × t_task × (1 + m_margin)” applies here only to the scenario described by the card. Inputs must be mutually consistent and satisfy the physical assumptions associated with “Planned task time with margin”.
- 12 — Independent check
- A second method or inverse relation should recover the same order of magnitude.
- 13 — Numerical case
- With N_tasks = 12 tâches, t_task = 2.25 min/tâche, m_margin = 0.25 sans dimension: T_plan = 12 × 2.25 × (1 + 0.25) = 33.75 min.
- 14 — Why the calculation works
- The numerical case applies “T_plan = N_tasks × t_task × (1 + m_margin)” directly to the stated values. The calculation is meaningful because the quantities are substituted into the same relation before the result is interpreted for “Planned task time with margin”.
- 15 — Verification
- Quick check: for any non-zero factor, dividing the result by that factor should recover the other expected contribution in “Planned task time with margin”.
- 16 — Mental estimate
- Before calculating “Planned task time with margin” precisely, round the inputs to one useful digit and predict the sign and order of magnitude. The detailed result should remain consistent with that estimate.
- 17 — Interpretation
- Reject a plan whose time including margin exceeds the actual available window.
- 18 — What the result does not prove
- For “Planned task time with margin”, the number obtained answers only the model “T_plan = N_tasks × t_task × (1 + m_margin)” under the stated scenario. It does not by itself validate the input data or the model outside those conditions.
- 19 — Sensitivity
- Vary one input at a time around the nominal case to identify what drives the result of “Planned task time with margin” and whether that variation can change the mission decision.
- 20 — Guided and autonomous exercises
Guided exercise. Recalculate this scenario: With N_tasks = 8 tâches, t_task = 4 min/tâche, m_margin = 0.2 sans dimension: T_plan = 8 × 4 × (1 + 0.2) ?
Detailed guided correction — open after trying
With N_tasks = 8 tâches, t_task = 4 min/tâche, m_margin = 0.2 sans dimension: T_plan = 8 × 4 × (1 + 0.2) = 38.4 min. The decision must then be checked against the module margins and assumptions.
Autonomous exercise. Recalculate this scenario: With N_tasks = 15 tâches, t_task = 1.5 min/tâche, m_margin = 0.3 sans dimension: T_plan = 15 × 1.5 × (1 + 0.3) ?
Autonomous correction — open after trying
With N_tasks = 15 tâches, t_task = 1.5 min/tâche, m_margin = 0.3 sans dimension: T_plan = 15 × 1.5 × (1 + 0.3) = 29.25 min. The decision must then be checked against the module margins and assumptions.
- 21 — Mission decision
- Reject a plan whose time including margin exceeds the actual available window.
Crew capacity utilization
- 1 — Concrete question
- What does “U_crew = W_required / C_available” compute in “Crew capacity utilization”?
- 2 — Intuition without symbols
- Utilization indicates what fraction of available human capacity is already committed.
- 3 — Quantities
- U_crew: fraction of capacity used [sans dimension]; W_required: required workload [personne-h]; C_available: available capacity [personne-h]
- 4 — Formula
- U_crew = W_required / C_available
- 5 — Read aloud
- Read “U_crew = W_required / C_available” by naming every operation, subscript and grouping explicitly.
- 6 — Symbols and meaning
- U_crew: fraction of capacity used [sans dimension]; W_required: required workload [personne-h]; C_available: available capacity [personne-h]
- 7 — Pronunciation
- The “Read aloud” line above is the oral reference for “Crew capacity utilization”. Any subscript, exponent or grouping that changes the meaning of the relation should be spoken explicitly.
- 8 — Units
- U_crew [sans dimension]; W_required [personne-h]; C_available [personne-h]
- 9 — Convention
- For “Crew capacity utilization”, substitute values without changing the reference frame, time basis, system boundary or sign convention halfway through the calculation. Stated units: U_crew [sans dimension]; W_required [personne-h]; C_available [personne-h].
- 10 — Why this operation
- In “Crew capacity utilization”, division relates a quantity to a reference, duration or capacity; the denominator must belong to the same case and remain non-zero.
- 11 — Assumptions
- The relation “U_crew = W_required / C_available” applies here only to the scenario described by the card. Inputs must be mutually consistent and satisfy the physical assumptions associated with “Crew capacity utilization”.
- 12 — Independent check
- Multiplying the result by the denominator should reconstruct the numerator.
- 13 — Numerical case
- With W_required = 20 personne-h, C_available = 24 personne-h: U_crew = 20 / 24 = 0.8333 .
- 14 — Why the calculation works
- The numerical case applies “U_crew = W_required / C_available” directly to the stated values. The calculation is meaningful because the quantities are substituted into the same relation before the result is interpreted for “Crew capacity utilization”.
- 15 — Verification
- Quick check: multiplying the result by the denominator should reconstruct the numerator of “Crew capacity utilization” within rounding.
- 16 — Mental estimate
- Before calculating “Crew capacity utilization” precisely, round the inputs to one useful digit and predict the sign and order of magnitude. The detailed result should remain consistent with that estimate.
- 17 — Interpretation
- Utilization near one leaves little room for interruptions and anomalies.
- 18 — What the result does not prove
- For “Crew capacity utilization”, the number obtained answers only the model “U_crew = W_required / C_available” under the stated scenario. It does not by itself validate the input data or the model outside those conditions.
- 19 — Sensitivity
- Vary one input at a time around the nominal case to identify what drives the result of “Crew capacity utilization” and whether that variation can change the mission decision.
- 20 — Guided and autonomous exercises
Guided exercise. Recalculate this scenario: With W_required = 22 personne-h, C_available = 24 personne-h: U_crew = 22 / 24 ?
Detailed guided correction — open after trying
With W_required = 22 personne-h, C_available = 24 personne-h: U_crew = 22 / 24 = 0.9167 . The decision must then be checked against the module margins and assumptions.
Autonomous exercise. Recalculate this scenario: With W_required = 16 personne-h, C_available = 20 personne-h: U_crew = 16 / 20 ?
Autonomous correction — open after trying
With W_required = 16 personne-h, C_available = 20 personne-h: U_crew = 16 / 20 = 0.8 . The decision must then be checked against the module margins and assumptions.
- 21 — Mission decision
- Utilization near one leaves little room for interruptions and anomalies.
Handover completeness
- 1 — Concrete question
- What does “C_handover = N_transferred / N_required” compute in “Handover completeness”?
- 2 — Intuition without symbols
- A safe handover depends less on word count than on transfer of required items.
- 3 — Quantities
- C_handover: fraction of required handover items transferred [sans dimension]; N_transferred: items actually transferred [éléments]; N_required: required items [éléments]
- 4 — Formula
- C_handover = N_transferred / N_required
- 5 — Read aloud
- Read “C_handover = N_transferred / N_required” by naming every operation, subscript and grouping explicitly.
- 6 — Symbols and meaning
- C_handover: fraction of required handover items transferred [sans dimension]; N_transferred: items actually transferred [éléments]; N_required: required items [éléments]
- 7 — Pronunciation
- The “Read aloud” line above is the oral reference for “Handover completeness”. Any subscript, exponent or grouping that changes the meaning of the relation should be spoken explicitly.
- 8 — Units
- C_handover [sans dimension]; N_transferred [éléments]; N_required [éléments]
- 9 — Convention
- For “Handover completeness”, substitute values without changing the reference frame, time basis, system boundary or sign convention halfway through the calculation. Stated units: C_handover [sans dimension]; N_transferred [éléments]; N_required [éléments].
- 10 — Why this operation
- In “Handover completeness”, division relates a quantity to a reference, duration or capacity; the denominator must belong to the same case and remain non-zero.
- 11 — Assumptions
- The relation “C_handover = N_transferred / N_required” applies here only to the scenario described by the card. Inputs must be mutually consistent and satisfy the physical assumptions associated with “Handover completeness”.
- 12 — Independent check
- Multiplying the result by the denominator should reconstruct the numerator.
- 13 — Numerical case
- With N_transferred = 19 éléments, N_required = 20 éléments: C_handover = 19 / 20 = 0.95 .
- 14 — Why the calculation works
- The numerical case applies “C_handover = N_transferred / N_required” directly to the stated values. The calculation is meaningful because the quantities are substituted into the same relation before the result is interpreted for “Handover completeness”.
- 15 — Verification
- Quick check: multiplying the result by the denominator should reconstruct the numerator of “Handover completeness” within rounding.
- 16 — Mental estimate
- Before calculating “Handover completeness” precisely, round the inputs to one useful digit and predict the sign and order of magnitude. The detailed result should remain consistent with that estimate.
- 17 — Interpretation
- Any critical omission must be closed before the handover is considered complete.
- 18 — What the result does not prove
- For “Handover completeness”, the number obtained answers only the model “C_handover = N_transferred / N_required” under the stated scenario. It does not by itself validate the input data or the model outside those conditions.
- 19 — Sensitivity
- Vary one input at a time around the nominal case to identify what drives the result of “Handover completeness” and whether that variation can change the mission decision.
- 20 — Guided and autonomous exercises
Guided exercise. Recalculate this scenario: With N_transferred = 24 éléments, N_required = 24 éléments: C_handover = 24 / 24 ?
Detailed guided correction — open after trying
With N_transferred = 24 éléments, N_required = 24 éléments: C_handover = 24 / 24 = 1 . The decision must then be checked against the module margins and assumptions.
Autonomous exercise. Recalculate this scenario: With N_transferred = 17 éléments, N_required = 20 éléments: C_handover = 17 / 20 ?
Autonomous correction — open after trying
With N_transferred = 17 éléments, N_required = 20 éléments: C_handover = 17 / 20 = 0.85 . The decision must then be checked against the module margins and assumptions.
- 21 — Mission decision
- Any critical omission must be closed before the handover is considered complete.
Operational-window margin
- 1 — Concrete question
- What does “B_task = T_window - T_required” compute in “Operational-window margin”?
- 2 — Intuition without symbols
- A schedule is robust only if real free time remains after planned tasks.
- 3 — Quantities
- B_task: remaining window margin [min]; T_window: available window [min]; T_required: time required by plan [min]
- 4 — Formula
- B_task = T_window - T_required
- 5 — Read aloud
- Read “B_task = T_window - T_required” by naming every operation, subscript and grouping explicitly.
- 6 — Symbols and meaning
- B_task: remaining window margin [min]; T_window: available window [min]; T_required: time required by plan [min]
- 7 — Pronunciation
- The “Read aloud” line above is the oral reference for “Operational-window margin”. Any subscript, exponent or grouping that changes the meaning of the relation should be spoken explicitly.
- 8 — Units
- B_task [min]; T_window [min]; T_required [min]
- 9 — Convention
- For “Operational-window margin”, substitute values without changing the reference frame, time basis, system boundary or sign convention halfway through the calculation. Stated units: B_task [min]; T_window [min]; T_required [min].
- 10 — Why this operation
- In “Operational-window margin”, subtraction measures a margin or difference between comparable quantities expressed in the same frame.
- 11 — Assumptions
- The relation “B_task = T_window - T_required” applies here only to the scenario described by the card. Inputs must be mutually consistent and satisfy the physical assumptions associated with “Operational-window margin”.
- 12 — Independent check
- Adding the margin back to the subtracted term should reconstruct the initial state.
- 13 — Numerical case
- With T_window = 90 min, T_required = 72 min: B_task = 90 - 72 = 18 min.
- 14 — Why the calculation works
- The numerical case applies “B_task = T_window - T_required” directly to the stated values. The calculation is meaningful because the quantities are substituted into the same relation before the result is interpreted for “Operational-window margin”.
- 15 — Verification
- Quick check: adding the subtracted term back to the result should reconstruct the starting quantity in “Operational-window margin”.
- 16 — Mental estimate
- Before calculating “Operational-window margin” precisely, round the inputs to one useful digit and predict the sign and order of magnitude. The detailed result should remain consistent with that estimate.
- 17 — Interpretation
- An insufficient margin requires simplifying the plan before entering the critical phase.
- 18 — What the result does not prove
- For “Operational-window margin”, the number obtained answers only the model “B_task = T_window - T_required” under the stated scenario. It does not by itself validate the input data or the model outside those conditions.
- 19 — Sensitivity
- Vary one input at a time around the nominal case to identify what drives the result of “Operational-window margin” and whether that variation can change the mission decision.
- 20 — Guided and autonomous exercises
Guided exercise. Recalculate this scenario: With T_window = 60 min, T_required = 58 min: B_task = 60 - 58 ?
Detailed guided correction — open after trying
With T_window = 60 min, T_required = 58 min: B_task = 60 - 58 = 2 min. The decision must then be checked against the module margins and assumptions.
Autonomous exercise. Recalculate this scenario: With T_window = 120 min, T_required = 95 min: B_task = 120 - 95 ?
Autonomous correction — open after trying
With T_window = 120 min, T_required = 95 min: B_task = 120 - 95 = 25 min. The decision must then be checked against the module margins and assumptions.
- 21 — Mission decision
- An insufficient margin requires simplifying the plan before entering the critical phase.
- Starting question
- Does the crew have enough effective human capacity to perform the required tasks without overloading the team?
- Read aloud
- Read: “team margin equals available capacity minus required workload.”
- Symbols, pronunciation and meaning
- Cavailable is the effective capacity available in a defined period; Wrequired is the workload demand in the same capacity units; M is surplus or deficit.
- Units
- Both capacity and workload must use the same planning unit, such as effective person-hours per shift.
- Origin and status of values
- Capacity should account for sleep, medical limits, EVA restrictions and mandatory monitoring. Workload comes from the current task plan and anomaly response.
- Why this operation
- Subtraction compares what the crew can safely provide with what the plan asks them to do. Positive margin indicates spare capacity; negative margin signals overload.
- Substitution and calculation
- If four crewmembers provide 24 effective person-hours in a shift and required work totals 20 person-hours, M = 24 − 20 = 4 person-hours.
- Calculator entry
- Enter 24 − 20. Keep the period definition fixed; do not mix daily work with per-shift capacity.
- Mental estimate
- Twenty hours of demand against roughly two dozen available leaves only a few hours spare, so a margin of four is plausible.
- Independent check
- Add required workload and margin: 20 + 4 = 24, recovering available capacity.
- Physical or operational interpretation
- The four-hour reserve can absorb interruption, cross-checking or an unexpected anomaly without immediately dropping lower-priority tasks.
- Plain-English translation
- The team has about four effective person-hours of remaining capacity in the defined shift.
- Variation / sensitivity
- If one crewmember loses 6 h of capacity, available capacity falls to 18 and margin becomes −2 h; priorities must change.
- Limit / assumption
- Person-hours are not perfectly interchangeable. Skill, fatigue and task concurrency can make two hours from one specialist very different from two hours from another.
Formula 2 — communication verification budget
- Starting question
- How much timeline should be reserved for closed-loop verification of a set of critical messages?
- Read aloud
- Read: “communication time equals the number of critical loops times the average time per loop.”
- Symbols, pronunciation and meaning
- N is the number of messages requiring a full verification loop; tloop is average duration of one transmit-readback-confirm cycle.
- Units
- If t is in seconds, T is seconds and can be converted to minutes. N is a count.
- Origin and status of values
- N comes from the procedure or event plan. Loop duration should come from drills under realistic suit, radio or noise conditions.
- Why this operation
- Repeated verification cycles add linearly, so multiplication estimates the communication block required by the plan.
- Substitution and calculation
- If 18 critical calls each require 12 s, T = 18 × 12 = 216 s = 3.6 min.
- Calculator entry
- Enter 18 × 12, then divide by 60 to convert seconds to minutes.
- Mental estimate
- Twenty calls at about ten seconds each would be around 200 s, so 216 s is reasonable.
- Independent check
- Divide 216 s by 18 calls and recover 12 s per loop.
- Physical or operational interpretation
- A few minutes of deliberate verification can be cheaper than recovering from one misunderstood valve, route or medical instruction.
- Plain-English translation
- The planned set of 18 critical communications consumes about 3.6 minutes of timeline.
- Variation / sensitivity
- If noisy conditions double loop duration to 24 s, the budget doubles to 7.2 min; timeline design should reflect real communication conditions.
- Limit / assumption
- The model assumes similar call duration. Complex messages may need structured data displays rather than longer verbal readbacks.
Mission reasoning: make authority, workload and dissent visible before stress narrows attention
Brief the decision structure
Before a high-risk operation, the crew should know who holds formal command, who leads each technical domain, which conditions require a stop and how anyone can raise a safety concern. Ambiguous authority becomes most dangerous when several specialists see different fragments of the same problem.
Build a shared picture, not a flood of detail
Situation awareness is lost when every person receives every alarm and data stream. Role-specific displays can filter detail while a common board shows mission phase, major hazards, resource margins, open anomalies and next decision points.
Use graded assertiveness
A junior crewmember should have language and authority to escalate concern when a hint is ignored: observation, concern, explicit challenge and stop if a declared safety threshold is crossed. Hierarchy should organize decisions without silencing evidence.
Redistribute before overload becomes failure
A saturated specialist is more likely to omit cross-checks and miss new information. The team should postpone noncritical work, assign a helper, reduce communication burden or shift monitoring roles before the specialist reaches obvious collapse.
Debrief behaviour and system conditions together
After an error, asking only “who made the mistake?” misses workload, interface and procedure contributors. A useful debrief reconstructs what each person knew, which signals were available, how authority moved and what the system made easy or difficult.
Protect sleep as mission capability
Repeated sleep restriction affects vigilance, memory and emotional regulation. Schedules should preserve protected rest, monitor cumulative fatigue and avoid using emergency tempo as the normal operating pattern simply because the crew can endure it briefly.
CRM exercises — coordinate expertise when the team picture begins to fracture
Exercise A — Unacknowledged command
During EVA, the commander says “close sample bay two” but receives no readback. What should happen?
Reveal the reasoned solution
Treat the communication loop as incomplete. Repeat or re-establish contact until the receiver acknowledges the correct bay and action, unless an immediate emergency requires another predeclared response. Silence is not confirmation.
Exercise B — Specialist overload
The only electrical specialist is diagnosing a power anomaly while also receiving routine science questions. What should the team do?
Reveal the reasoned solution
Protect the specialist’s attention. Route routine questions elsewhere, assign a note-taker or monitoring partner, defer noncritical work and make one person responsible for communications. The objective is to reduce cognitive switching during a high-consequence diagnosis.
Exercise C — Commander challenged
A junior crewmember believes a planned depressurization test violates a limit. What is good followership?
Reveal the reasoned solution
State the specific observation and limit, ask for acknowledgement, escalate the concern if not addressed, and invoke a stop rule if the declared safety condition is met. Respectful challenge is part of mission safety, not insubordination.
Exercise D — Workload calculation
A shift has 21 effective person-hours of capacity and 24 person-hours of required work. What does the margin mean?
Reveal the reasoned solution
M = 21 − 24 = −3 person-hours. The plan is overloaded even before interruptions. Work must be postponed, simplified, automated or reassigned; telling the crew to “work harder” does not create the missing capacity.
Exercise E — Debrief after near miss
A rover nearly leaves with an unsecured hatch. What should the debrief examine besides the person who missed it?
Reveal the reasoned solution
Examine checklist design, interruption, lighting, role assignment, readback, time pressure, prior handover and whether the hatch status was visible. The individual action matters, but the aim is to remove conditions that make recurrence likely.
Exercise F — Fatigue escalation
Two crewmembers report poor sleep for three nights, yet the schedule contains a difficult EVA. What should leadership consider?
Reveal the reasoned solution
Assess cumulative fatigue, task criticality, redundancy, weather and whether another rested crewmember can substitute. Delay or reduce scope if safety margin is impaired. The decision should treat rest status as operational data, not moral commitment.
Interactive beginner glossary
These terms describe how crews share information, authority and workload under routine and abnormal conditions.
- CRM — Crew resource management: methods for using communication, leadership, teamwork and workload management to improve operational safety.
- situation awareness — Perception and understanding of relevant current conditions combined with anticipation of how they may change.
- shared mental model — Common understanding of the plan, roles, system state and likely next events that supports coordinated action.
- closed-loop communication — Message exchange in which receipt and correct understanding are explicitly verified.
- readback — Receiver repetition of critical information so the sender can confirm or correct it.
- callout — Concise spoken announcement of a relevant state, value, hazard or action for the team.
- leadership — Process of setting priorities, coordinating action and accepting responsibility for decisions within assigned authority.
- followership — Active contribution by team members who execute, question, inform and challenge appropriately rather than remaining passive.
- authority gradient — Difference in perceived status or power that can make it easier or harder for one person to challenge another.
- graded assertiveness — Escalating communication technique that increases clarity and urgency when a safety concern is not resolved.
- stop rule — Predeclared condition allowing or requiring an activity to halt for safety.
- workload — Combined physical, cognitive and communication demand placed on a person or team during a defined period.
- task saturation — Condition in which workload exceeds the ability to process tasks reliably and attention begins to narrow or omit information.
- cross-check — Independent or reciprocal verification intended to detect an error before it propagates.
- handover — Structured transfer of responsibility, current state, open risks and expected next actions between people or teams.
- fatigue — Reduced physical or cognitive performance associated with insufficient rest, circadian disruption, workload or prolonged demand.
- circadian rhythm — Biological timing process that influences sleep, alertness and performance across the day.
- sleep debt — Accumulated shortfall between needed and obtained restorative sleep over time.
- briefing — Pre-activity communication that aligns goals, roles, hazards, contingencies and decision points.
- debriefing — Structured post-activity review used to reconstruct events, learn and improve future performance.
- near miss — Event that could have produced harm or mission loss but did not, often because of timing, recovery or chance.
- cognitive load — Amount of mental processing demand imposed by tasks, information and decisions.
- interruption — Event that forces attention away from the current task and creates risk of losing task state.
- sterile cockpit — Operational rule restricting nonessential communication during a critical phase so attention remains on required tasks.
- role clarity — Shared understanding of who is responsible for which decisions, actions and monitoring functions.
- distributed leadership — Temporary movement of practical leadership toward the person with the most relevant expertise while formal command remains defined.
- psychological safety — Team condition in which members can raise questions, uncertainty and concerns without inappropriate interpersonal punishment.
- conflict — Disagreement over information, priorities or relationships; task-focused conflict can be useful when managed constructively.
- work-rest cycle — Planned sequence of duty and recovery periods intended to sustain safe performance.
- human performance — Observable capacity of people to perceive, decide, communicate and execute tasks under actual mission conditions.
Operational depth: turn human factors into observable mission controls
Measure signals of overload
Repeated checklist skips, slow readbacks, increasing correction rate and unfinished documentation can be treated as operational indicators. They do not diagnose a person; they warn that the system may be demanding more attention than the team can safely provide.
Design quiet roles during emergencies
One crewmember may manage overall coordination while specialists diagnose. Assigning a communications gatekeeper prevents every external message from interrupting the person working the fault.
Record decision rationale
When crews deviate from plan, a short record of evidence, options, authority and rationale helps Earth understand the change later and supports fair debriefing. Without rationale, retrospective review can mistake reasonable uncertainty for carelessness.
Train leaders to receive bad news
If leaders react defensively to uncertainty or criticism, crews learn to filter information upward. Simulation should reward early concern reporting and show that changing a decision when new evidence appears is strength, not loss of authority.
Protect private conflict from contaminating operations
Interpersonal tension can exist without becoming a mission hazard if roles, professional communication and mediation paths remain intact. Repeated personal conflict that affects handovers or cross-checking should be treated as an operational risk requiring intervention.
Use Earth support asynchronously
Ground teams can review trends, debrief logs and suggest schedule changes without controlling every interpersonal event. The crew remains responsible for immediate coordination while Earth contributes wider analysis and longitudinal patterns.
Applied crew cases: workload, fatigue and authority
Applied case — multiple anomalies compete for one commander
Imagine a power alarm, a medical complaint and a weather warning arriving within the same ten minutes. The commander should not personally solve all three problems. A stronger response assigns technical leads, establishes which event can threaten life first, protects one shared situation display and sets a time for cross-team updates. Delegation is not loss of control; it is how command preserves attention for integration. The leader watches interactions between teams, resource conflicts and stop conditions while specialists work within their domains. A short, scheduled synchronization point can be safer than continuous interruption because each lead can complete diagnostic steps and then report evidence, uncertainty and requested decisions.
Applied case — fatigue can distort authority as well as attention
A tired commander may become overly decisive, while a tired specialist may stop challenging assumptions. CRM therefore needs behaviours that remain valid even when personalities shift under fatigue: required readbacks, explicit dissent prompts, cross-checks and objective stop limits. Crews can also use buddy monitoring for signs of slowed speech, repeated omissions or unusual irritability. None of these signals proves incapacity, but together they can trigger workload redistribution or rest. The goal is to avoid making one person self-diagnose perfectly at the moment their judgement may already be degraded. Team procedures should make protective intervention normal rather than embarrassing.
Applied case — Earth debriefing can detect patterns the crew cannot see
A ground team has access to weeks of logs, sleep data, task durations and communication errors. It may notice that handover omissions increase after a certain sequence of shifts or that one type of maintenance repeatedly creates interruptions. Earth can send that pattern back asynchronously with recommended experiments or schedule changes. The local crew then decides how to apply the evidence within current conditions. This division of labour is valuable: the crew sees immediate context, while ground analysts can see longitudinal patterns. Neither perspective should automatically dominate. Strong CRM treats them as complementary sources of evidence about human performance and operational design.
Applied case — conflict can improve decisions when it stays attached to evidence
Two specialists may disagree about whether a rover battery anomaly is thermal or electrical. Productive conflict states observations, competing hypotheses and what measurement would distinguish them. Destructive conflict attacks competence or status and makes later cooperation harder. A leader can keep the disagreement technical by asking each person to state evidence, uncertainty and a disconfirming test. The team then chooses the safest diagnostic action rather than voting on personalities. This method is especially important in a small Mars crew where people cannot simply avoid colleagues after a dispute. The objective is not harmony at every moment; it is preserving trust in the process by which disagreement becomes a better decision.
Operational review checklist
- Brief command, technical leadership and stop rules before critical work.
- Require closed-loop communication for safety-critical instructions.
- Protect saturated specialists from avoidable interruptions.
- Track workload margin and reduce scope before overload.
- Encourage specific, graded safety challenges regardless of rank.
- Preserve protected sleep and monitor cumulative fatigue.
- Use debriefs to examine system conditions as well as individual actions.
- Maintain concise handovers with state, risks and expected decisions.
- Record rationale when crews change the approved plan.
- Treat good followership as an active safety responsibility.
