Dana Reyes met me in the lobby with a badge already printed — RAY DELGADO, CONTRACTOR — which told me she’d planned for me to stay. The badge reader beeped me through and she didn’t slow down.
I followed her onto the ops floor and the first thing I registered was the quiet. Not the pleasant kind. Twelve people at consoles and nobody looked up when the door opened. The overhead displays showed a cluster of telemetry plots and one of them had a red trace curving the wrong direction.
Dana stopped behind a console in the second row and I stopped with her. She didn’t introduce me.
The man at the console was Gus Marchetti. I knew him by the nameplate on the console face, not because anyone said so. He had a headset on one ear and a paper printout spread flat beside his keyboard. Sixty-something, gray at the temples, reading glasses pushed up on his forehead.
“PROCVAULT. Vehicle config dash seven, mission phase three-bravo. Thermal, coolant loop B.”
His voice was level. A controller to his left pulled up a search interface on her own screen without being asked. Another controller, one row forward, was already on a separate terminal. The PROCVAULT screen in front of Gus filled with a procedure index: seventeen entries keyed on vehicle configuration and mission phase. He scrolled, stopped, opened one.
“Pass window at thirty-six minutes,” someone said from across the room. Not an announcement. Just a fact, stated once.
I looked at the overhead telemetry display. The red trace was the coolant-loop temperature on a cargo vehicle somewhere between Earth and Mars. Eleven minutes away at the speed of light, which meant twenty-two before you could know if anything you sent had worked. The relay window closed in thirty-six minutes. If the uplink didn’t go out before that, the vehicle would be on its own for fourteen more hours.
Gus found his candidate procedure. He read the header, read the revision number, read it again.
“Change notice on this one?”
“CN-4409,” the controller to his left said. “Issued after the acceptance test series.”
“Pull the applicability section.”
The paper on his console was the vehicle’s configuration summary. Printed from somewhere, three-hole punched, held together with a binder clip. The edges were soft with handling.
“Thirty-one minutes,” from across the room.
CN-4409 restricted applicability by serial-number range. Gus read it and his expression didn’t change. He picked up the configuration summary and checked the vehicle serial against the range.
“CN-4409 doesn’t apply. We’re below the cutoff.” He moved back to the procedure. “Waiver status on the coolant-loop safing mode.”
The controller one row forward looked up. “Waiver W-2281. It’s open. Cites ATR-1144.”
“What’s ATR-1144 say about temperature exceedance?”
A pause. The sound of a keyboard. “Acceptance within plus-four of nominal, with approved safing response. We’re at plus-two-point-seven.”
“Twenty-three minutes.”
Gus pulled ATR-1144 into a new window and read the relevant section. The controller to his left was already there, reading the same lines from her own screen. Nobody said this was the plan.
Nobody on the floor raised their voice. Hands moved fast and the voices stayed flat, and I kept noticing the gap between those two facts.
“Eighteen minutes.”
Gus cross-referenced two more entries, both pulled by the controller to his left, both handed off with a file number and a page number and nothing else. He read. He made a note on the yellow pad. He read again.
The PROCVAULT terminal had the look of software extended across multiple decades rather than rebuilt. Nested menus opened in separate windows. Documents loaded slowly and rendered in a fixed-width font. Gus had eight windows open on his screen and moved between them without pause.
“Twelve minutes.”
He lifted his headset to his other ear. “Flight, Marchetti. Coolant loop B, vehicle seven-seven-four. Recommending safing to passive thermal mode per Procedure 14-Bravo-9, Revision F. Applicability confirmed. CN-4409 non-applicable by serial. Waiver W-2281 covers the exceedance. Ready to uplink.”
A voice came back through the headset. I couldn’t hear the words. Gus nodded once.
“Copy. Uplink on my mark.”
He said mark. The controller to his left entered the command sequence. The controller one row forward confirmed receipt on the relay.
Eight minutes on the pass window.
Nobody said anything for about four seconds. Then the room returned to its ordinary frequency: other voices on other circuits, other displays, other work. Someone swapped out a printout at the back of the room and filed it in a binder.
“Thrilling as always,” the forward controller said, to no one in particular.
Dana touched my arm and I stepped back with her toward the entry.
“The part where he decided took about twelve seconds,” she said.
She turned and walked back to the ops floor. I stood at the entry with my badge lanyard and watched a controller in the third row pull up a new set of telemetry and start a conference call.
The kickoff started closer to ten than nine; nobody schedules around a coolant loop.
I’d driven up Boulder Canyon that morning, three parabolic dishes white on the ridge above the campus. I knew Corvus Space Systems the way you know a competitor you’ve tracked through conferences and incident reports: names of programs, rough head count, the Bellwether-1 loss that everyone talked about for a year and a half and then stopped talking about.
I took the contract because the rate was good and because Bellwether-2 was nine months out. Six years of ground-segment work at another operator, all of it cargo, and I had never worked anything with a crew manifest. I wanted to, before I was done.
On the way to the conference room I got to two hundred and seventy-two days on the Bellwether-2 countdown clock before Dana was at the door. On the far wall, in a black frame behind glass, hung a single sheet of paper. Above it, fixed with two strips of blue tape, a printout in large capital letters: READ IT AGAIN. The tape had dried and the paper had gone faintly yellow at the edges.
Dana ran Mission Operations. Sam Whitfield was on speakerphone. He ran ground-segment infrastructure, fourteen systems by his own description, something like thirty engineers depending on who counted the contractors. There was also a consortium program manager on the call. Dana hadn’t mentioned one. I didn’t catch the name.
Dana said, “We need a chatbot for the console.”
I wrote it down word for word, then asked what problem it solved.
She said, “You just watched it. Console workload during anomaly response. Controllers are burning hours searching thirty years of procedures every time something goes sideways. We need that time back.”
The 774 uplink had gone out with eight minutes left on a thirty-six-minute window. Call it twenty-eight minutes of research for twelve seconds of decision. She’d routed me across the floor on purpose.
Sam said, from the phone, “Ticket deflection. My team gets pulled into every anomaly event because ops can’t find the right procedure without help. That’s where the cost sits.”
The consortium program manager said, “Innovation,” and then the line clicked to dial tone.
We sat with the speakerphone between us. Consortium PMs on innovation initiatives run on quarterly reporting cycles and vague mandates; once the line went dead, the meeting got simpler.
I asked who had a number on the time loss. Dana said they’d documented three incidents last quarter where anomaly response was delayed, but the reports stopped at “delayed,” no duration. Sam thought the average was around two hours per event, maybe less. He said “around” and “maybe” in the same sentence and didn’t seem to notice. Nobody had measured it.
Maybe the right move was to push for a number before committing to anything. But a single conversation wasn’t going to surface a number worth defending. I told them I’d take two weeks of discovery. No architecture, no vendor evaluation, no prototype. Measurement only: what the current process actually costs, in time and error rate, rigorous enough to survive a skeptic.
Dana said, “Fine, Delgado. Don’t let it become twelve.”
I said I wouldn’t.
On the way out I stopped at the framed sheet on the wall. The header read BELLWETHER-1 MISSION ANOMALY REPORT, EXECUTIVE SUMMARY, and the incident date was three years back. One page, dense eleven-point type. Two paragraphs of findings, three of recommendations. The READ IT AGAIN sign had been printed on the same paper, probably the same printer, probably the same day Dana put the frame up.
I didn’t ask about it.
The next morning I found Gus Marchetti at the same second-row console, running monitoring checks on a satellite downlink. He’d been a flight controller at three different operators over thirty-three years, and he had a settled view of which software projects were real and which were someone’s response to a difficult meeting. He told me this inside the first five minutes. He preferred a fair fight.
He had a three-inch procedure binder on the corner of his console, a Bellwether-1 mission sticker on the spine and a coffee ring on the cover.
I asked if he used it.
“Nobody opens it,” he said. “It’s been there since 2019. Moving it would require an explanation, and nobody wants that conversation.”
I asked if 774’s twenty-eight minutes of research was typical.
“Seven-seven-four was a friendly one,” he said. “One change notice, didn’t apply. One waiver, already open, bound in our favor. On a friendly one the documents agree with each other.”
I asked what it looked like when the change notices did apply.
He thought for a moment, scrolled something, and pulled up a thermal event from a cargo mission seven months back. Secondary coolant loop anomaly, mid-transit, no crew aboard. He said the resolution was straightforward. Finding the right procedure was not: that vehicle flew a hardware revision two updates ahead of the procedure base, with two change notices in force.
“Show me the process,” I said. “Not what you eventually did. How you got there.”
He ran it as a replay, live keystrokes, no shortcuts, starting from the master procedure index and the same three lookup fields I’d watched him work on 774: vehicle serial number, mission phase, configuration revision level. I put my phone face-down on the corner of the console.
When he’d read both change notices and settled which steps were superseded, I turned the phone over. Eighteen minutes.
Then the waiver log. A performance waiver accepted at vehicle delivery had shifted the thermal trigger limits from the base-procedure values, and it cited an acceptance test report in a separate repository. Finding it, getting to the coolant section, and cross-referencing the numbers took twenty-two more minutes. Forty total, and he hadn’t made a decision yet. The flight rules had told him from the start what was allowed. The chase was for how.
Three response paths: one eliminated by the waiver’s thermal limits, one requiring a second comm pass to uplink a parameter update, one executable immediately with what was already on board. He made the call in about four minutes. The decision had always been fast. The research was where the time went.
“Forty-four minutes,” I said. “And that’s a moderate case?”
“Moderate,” he said. “I’ve run ninety minutes on a complex one. Different company, longer mission life, more accumulated waivers and change notices on the vehicle.” He said it the way you give a mileage figure.
I asked what happened when he needed an answer from the vehicle before he could commit.
He looked at the adjacent console, where the Bellwether-2 transit simulation was running. “Then you look at the geometry first. Two exchanges at yesterday’s distance is most of an hour of signal travel, on top of the document chase. Mars can’t wait on it twice.”
He said it without looking at me, and I let it stand.
I asked about the document tools the ground-segment team had built. He’d been walked through three. Two were slower than doing it by hand; one added a separate authentication portal and three steps to every lookup. The third he used sometimes: it handled the index queries and pulled the right document version, but it didn’t know about waivers, didn’t cross-reference change notices, and didn’t know the configuration unless he typed it in every time.
“So it handles the easy part,” I said.
“The easy part,” he agreed.
I asked about Bellwether-1. He said he was on console that day. He said it without a pause, a matter of record.
Walt Okonjo’s office was in the corner of the ops building, one window onto the console floor through internal glass, one up at the ridge. Behind his desk was a shelf of simulation binders labeled by mission and date, spine out. The Bellwether-1 binder was at the end nearest my chair. He’d been VP of Mission Assurance for eleven years, or twelve; I’d gotten two different answers and hadn’t pushed on it. Bellwether-1 had come through his office, a fact everyone at Corvus had filed without quite discussing.
He asked for the ROI number first.
I told him I didn’t have one. Any number I gave him now would be invented, and an invented number was worse than no number because it would travel: he’d make a resource decision based on it, Dana would repeat it in a steering review, and in six months someone would ask me to account for the gap.
He gave me the look of a man who has heard the “I need more time” version of that argument many times and is deciding whether this one is honest or protective.
I said, “Give me the baseline and I’ll show you the arithmetic.”
He said, “Go.”
Roughly fourteen thousand documentation research events a year across the fleet, counting everything that ran through config-controlled paper — pass prep, commanding verification, configuration checks, waiver lookups — anomaly response the sharpest slice. I told him to treat the count as an order-of-magnitude estimate from fleet size and ops tempo, not a data pull. Time per event: twenty-eight minutes on 774, a friendly case worked live; forty-four on the moderate replay I’d timed at Gus’s console; ninety on the complex cases, Gus’s number from his own history. Controllers at eighty-five dollars an hour, fully loaded cost.
Walt didn’t write anything. He said, “You’re low. Certification currency and shift differential puts it at ninety-two.”
I wrote down ninety-two.
He picked up a pen and worked through the numbers on a notepad by hand, without commentary. He took the top of the range. Fourteen thousand events, ninety minutes each, ninety-two dollars an hour. He pushed the notepad across the desk. The figure came out just under two million dollars a year in research time, if the ninety-minute estimate held and the event count was in range. Cut the research time by half: call it a million a year back. And that was the research cost alone, before you priced a single delayed response against a vehicle that was about to start carrying people. The day before, the margin on 774 had been eight minutes, with nothing aboard but cargo.
I said the twenty-eight was one live event, the forty-four one timed replay, and the ninety one controller’s recall from a different company. Three data points were still an anecdote. I needed a sample before any of it meant something defensible.
Walt said, “Build the sample.”
I said that was the proposal.
He authorized discovery and nothing else: no architecture work, no vendor outreach, no solution design until I had numbers I could defend. He also said any tooling I proposed would have to demonstrate results in simulation before it touched an operational console. That was a requirement.
I said that was fine.
He was already pulling the next binder off the shelf. “Show me the sim results,” he said, the way a line comes out when a man has said it many times and expects to keep saying it.
Dana had booked the small conference room for three hours; we used five. By mid-afternoon the whiteboard held Gus’s anomaly timing in blue with 774’s window numbers beside it, Sam’s systems matrix in red, and three competing definitions of “anomaly” nobody would cross out, because that meant an argument we hadn’t scheduled.
Dr. Yael Drescher arrived ten minutes early and claimed the head of the table. She held the crew health portfolio for the consortium; on Bellwether-2, anomaly response time in the hours after orbital insertion was a variable in her crew’s safety case. She had a yellow legal pad and the measured patience of someone who had spent a long career reviewing safety documents other people had written in a hurry. She did not appear to be in one.
She opened before I’d finished connecting my laptop.
“Any AI system touching anomaly response,” she said, “needs to be one hundred percent accurate before it goes near a console.” She said it without heat, the way you state a physical constant. Because this was a crewed program and she was the flight surgeon, nobody laughed. Including me.
I didn’t disagree with her. I asked what accuracy the current process achieved.
The room went quiet, the kind where everyone had assumed someone else held the answer.
Gus pulled his chin, the thing he did when he was being careful about something uncertain. “Procedure-selection errors — controller pulls the wrong rev, or the wrong procedure for the symptom set — those get caught in review.” He stopped. “When they get caught.”
“So there’s no measured rate,” I said.
“No measured rate.”
Dr. Drescher wrote something on the legal pad. Dana looked at the whiteboard, then back at me. Sam was very still.
The hundred-percent requirement was a real concern, and there was no way to test it: against any finite sample you find no errors and learn nothing about the next case. We converted it into something we could evaluate: fifty as-worked anomaly cases from the logs, a 94 percent citation-accuracy threshold, the reasoning written next to the number. Every draft would carry citations traceable to a document, a section, and a page.
Sam pushed on the 94. He wanted 97.
I asked where 97 came from.
He thought for a second. “Felt right.”
“Ninety-four is three misses in fifty,” I said. “That’s a characterizable failure mode. Ninety-seven in fifty is one and a half, which means a clean sample tells you nothing.” He didn’t move the number. He didn’t love it either, which seemed fair.
The authorship question took less time than expected. The assistant drafts; the controller decides. It went in as a constraint, no exceptions enumerated.
Error handling went in by consequence tier, one sentence per tier: a wrong procedure revision on a crewed thermal case was a hard stop and immediate human escalation; a formatting error on a cargo telemetry summary was not. Dr. Drescher read the tiers, made a note, and said nothing.
Then Gus asked the question he’d been sitting on all day.
“When it’s wrong,” he said, “how do I know?”
He meant the individual case: the anomaly on watch at two in the morning, the draft that reads right and isn’t, the controller who doesn’t already know the error and so can’t recognize it by inspection.
It was better than anything on my list, and I said so. My list had the failure modes I already knew to worry about.
We wrote it in as a requirement, not a comment or an action item. The system had to give a controller the means to detect an error without already knowing what it was.
We finished at 6:20. Sam erased two-thirds of the whiteboard and left the rest. Dr. Drescher said she’d send a formal comment on the error-tier language by end of week, which she did; it was specific and required no negotiation.
Dana and I stood in the parking lot. “That went better than it should have,” she said.
I thought that was probably right.
The one-page problem statement took four drafts over five weeks. The third draft was where the data problem surfaced, and the data problem changed what the page had to say.
PROCVAULT was the program’s system of record for operational documentation: 26 million pages of procedures, anomaly logs, engineering memos, and flight rules, every revision, every red-lined update. The OCR quality tracked the decade: born digital from roughly 2005 forward read cleanly; before that it degraded in steps. ORRERY, the consortium’s nightly configuration replica, solved access to revision and waiver records but not content: the documents themselves lived in PROCVAULT, errors and all.
When I sampled the 1990s ground-station procedures, a tranche came back as scanned faxes. Not scanned documents, scanned faxes. The original procedure had been printed, faxed to a remote ground station, printed again on the receiving end, filed as paper, and scanned into the system in the 2000s. Three generations of degradation: the thermal noise of the fax, the resolution loss of the printout, the scanning error of the digitization. On one sampled procedure for a thermal ground-support valve — closed-loop coolant circuit, closed out in 1997 — the OCR had flipped a word.
“Do not proceed” had rendered as “do proceed.”
The sentence read cleanly. It was not clean.
I wrote it into the problem statement as a fact about the data environment, with the same specificity as the baseline cost and the acceptance criteria. The retrieval layer would operate on source material with at least one confirmed inversion of safety-critical text. We did not know the scale, because nobody had sampled the tranche systematically; the scale went onto the page as an open question.
The final version described the business problem, the measured baseline, and the success criteria from the workshop, Gus’s question written in as a formal requirement. The baseline carried the 774 pass, Gus’s replay timing, Walt’s $92/hr loaded cost, and the annualized exposure, roughly $1.9 million a year against the current process. It described PROCVAULT and ORRERY and the fax tranche. It did not recommend a solution or describe an architecture. The word “chatbot” did not appear anywhere on the page.
Dana read it at her desk while I sat across from her. She went through it once at normal speed, then went back to the top and read it again more slowly, stopping twice. She signed it and passed it back.
Walt signed it without a meeting. His assistant forwarded the scanned copy with a sticky note on the signature block: Scope the fax problem before build. That was the complete note.
Dana caught me in the corridor two days later.
“You spent five weeks,” she said, “writing one page.”
“That page,” I said, “is the only thing that survives contact with engineering.”
She made a face that was not disagreement. Then she walked back toward her consoles.
I put the signed copy in a binder, set it on the passenger seat, and drove down the canyon in the thin late-afternoon light.
My daughter’s meet had been Thursday of the third-draft week, the week the fax tranche surfaced. I’d been at a terminal in Boulder until nine with the 1997 valve procedure, and she’d sent me twenty-three seconds of phone video from the pool deck, her lane half out of frame, the sound all echo. I watched it twice in the Corvus parking lot and texted her that the start looked fast.
“We need a chatbot” is a proposed solution, not a problem statement. Before any architecture:
Red flags the chapter dramatized: three stakeholders, three different goals, zero numbers; success defined as a technology (“AI”) rather than an outcome; the sponsor who wants the demo before the problem statement.
| They say | You hear | You deliver |
|---|---|---|
| “We need a chatbot for the console” | A solution chosen before the problem | Structured discovery: problem, users, success measures, data, constraints |
| “It must be 100% accurate” | No baseline exists for the current process | Measurable acceptance criteria + error handling proportionate to risk |
| “Innovation” (no metric) | Sponsorship that will dissolve at budget review | Politely ignore until a number attaches |
| “How much will we save?” (too early) | A demand for fiction | The measured baseline now (~$1.9M/yr of controller time), the projection after feasibility |
| “When it’s wrong, how will I know?” | The end user’s real acceptance criterion | Visible citations + below-threshold flagging — design for when, not if |
Questions drawn from the companion practice-exam bank. Try them before reading the answers section.
During discovery for an AI document-processing system, the operations director insists the system must run fully automated end to end, while the compliance officer states that every output touching customer accounts must be human-reviewed. Both were interviewed separately and each believes their requirement is settled. The project sponsor asks the architect to “just write up the requirements.” What should the architect do FIRST?
An architecture review board challenges an architect’s decision to use a retrieval-based design instead of fine-tuning for a policy-lookup assistant. Two board members favor fine-tuning because a vendor demo impressed them, and the meeting is scheduled to end in a decision. Which TWO actions best serve the architect in communicating the decision?
The remaining 3 questions for this chapter — and every chapter after it — are in the full book, every answer option explained.