Not part of a guided workflow —
Next best move:Open the platform atlas Atlas
AutoResilienceCommand
Ops clock2026-03-17 14:00ZFirst impactT−22.4h

BMW-targeted concept demonstration. Operational entities, suppliers, parts, inventory, production, financial values and incident conditions are synthetic and do not represent BMW systems, performance or current exposure.

Method, data and proof

The authoritative results in this system come from these visible rules. No model or language system decides an exposure number — it may only describe one.

INC-2026-0113 · S1 · responding

Supply and inventory

R1

Dependency traversal

start = incident supplier
  → marked supplier sites
  → parts supplied by those sites
  → inventory records that consume those parts (line)
  → plant, product program, customer orders
plus: marked supplier systems → interfaces → business processes → lines
Edges are only followed while effectiveFrom <= now and (effectiveTo is null or > now).

Traversal is breadth-first and records the full path to each node, so every affected entity can name the chain of records that put it there.

R2

Usable inventory

usable = onHand − quarantined − (consumeSafetyStock ? 0 : safetyStock)

Quarantined stock is always excluded — it cannot be consumed. Safety stock is excluded by default (currently protected), because releasing it is a decision, not an assumption.

R3

Effective consumption

consumption/hr = hourlyConsumption × 1 × (1 + scrapRate × 1)

Scrap increases draw on stock. Both multipliers are visible assumptions the commander can change on the runout timeline.

R4

Inbound and in-transit stock

counted only if (countInTransit) and eta exists and eta_hours < baseRunoutHours

A shipment with no confirmed ETA is never counted. A shipment arriving after stock is already exhausted does not prevent the stoppage; it only shortens it.

R5

Runout hours

runoutHours = usable ÷ consumption/hr, then + qualifying inbound cover

If the inventory record for a part on a line is missing, the pair is marked unresolved and contributes no runout hours at all. It is never treated as sufficient stock.

Production, orders and money

R6

Line impact

line runout = min(runout of every exposed part on that line)
line status = worst impact status among those parts

The first part to run out stops the line; the line cannot be better than its worst part.

R7

Downtime and mitigation

mitigation = min(qualified alternate activation  without expedite, tested continuity RTO)
downtime = max(0, min(supplierRecovery 72h, mitigation) − runout), capped at 48h horizon

Only qualified and validated alternates and tested continuity plans reduce downtime. A claimed capability does not.

R8

Units and revenue exposure

units = downtime × unitsPerHour
revenue = units × revenuePerUnit

Revenue exposure is lost build value at risk over the horizon, not a penalty or claim estimate.

R9

Customer order shortfall

productiveHours(order) = runout + max(0, dueHour − max(resumeHour, runout))
capacity = floor(productiveHours × unitsPerHour)
shortfall = ordered − min(ordered, capacity − units already committed to earlier-due orders)

Orders are filled in due-date order. A line with no calculable runout leaves its orders unresolved rather than satisfied.

R10

Confidence and impact status

path confidence = product of edge confidences
confirmed  : confidence ≥ 0.85 and every edge validated
probable   : confidence ≥ 0.6
possible   : below that, or an unvalidated edge on the path
unresolved : a material input is missing

Depth and validation state both reduce confidence; unresolved is never merged into a lower-risk state.

R11

Operational exposure score

score = Σ (factor value × weight), 0–100, incomplete when any factor lacks input

Current score 62.8 / 100 across 7 weighted factors — flagged incomplete because at least one input is missing.Each factor shows its input, source, owner, validation date and explanation on the command center.

R12

Missing data

missing input → unresolved status → raises risk, never lowers it

Where material inputs are absent the interface states: “Exposure cannot be fully determined. Missing information increases—not decreases—decision risk.”

R13

Recovery gates

gate n opens only when gate n−1 is passed
gate passes only with attached evidence and the named approver role

Reconnection requires both cyber and operational approval recorded against gates. No gate can be skipped.