AEROEAutonomous fleet orchestration
Meridian · SRS v4.0 Simulation live
Technology · for engineers and evaluators

Declare, then refuse.

One canonical agent model. One deterministic gate. One event record that explains everything that happened.

This page is the engineering view of AEROE: the architectural rules, the constraint gate's verbatim output, the formation library with the gate's own measurements, and what the current increment adds. Requirement and unit identifiers refer to SRS v4.0 (Project Meridian). For the plain-language overview, start here.

The platform

Not a better robot. The layer that makes fleets of them one system.

AEROE is a coordination platform. Mission, orchestration and planning depend only on a canonical agent interface and a capability model — never on a vehicle, a vendor or an application. Everything else, from a survey sweep to a display programme, is built on it and lives outside the core.

01 · Agnostic by construction

No core file may name a vehicle.

A new robot type is an adapter alone — a published SPI, a conformance suite and an offline-verifiable certificate. A build gate fails the moment a neutral layer names a platform or branches on an adapter id. Agnosticism is not a promise in a brochure; it is a test that runs on every commit.

ARC-001ARC-002NFR-016RAL-014
02 · Declare, then refuse

The adapter declares. The gate holds it to the declaration.

Link latency and silence interval, command rate, endurance, positioning uncertainty, time-sync error — each is a declared value that becomes the limit the orchestrator enforces. A separation the fleet cannot hold is not a separation; a cue tighter than the clock is refused before launch, naming the shortfall.

RAL-019RAL-020RAL-022MIS-021
03 · An application is not a layer

Would it be worth building if the application never happened?

If not, it does not enter the core. A programme is a sequence of formations — a survey's flight lines as much as a show's figures. An effector is an abstract state on a declared capability, never a device. Nothing below the console knows what it is being used for.

ADR 0030PRG-001EFF-006
Inside the console

One fleet, one committed version, one screen.

Author a mission in structured controls or plain language. The gate checks it before anything is dispatched. Then watch the fleet take station in a 3D twin or a top-down plan view — both driven by the same mission state — beside the mission's own event log, its armed contingencies and the version in force.

The AEROE operator console mid-transition: the command panel on the left shows an executing three-formation programme
                with its armed contingencies; the 3D twin in the centre shows twenty-four agents leaving their ring slots for a wedge,
                trails on; the timeline on the right lists the mission's own events.
A programme in transition. Twenty-four agents leave a 45 m ring for a wedge one altitude band up. The rings they left are still drawn — those are the committed slots, not where the agents are. The contingency panel states, before launch, what the programme will do if an agent is lost: fly on as committed, with a gap where the agent was.
The same programme in its final figure: a line of twenty-four agents at 70 m in the 3D twin, all healthy, with the timeline beside it.
Final figure, 3D twin. The third formation of the programme, a line at 70 m. The command rail carries only the actions the mission state actually allows; the footer carries the twin's own sustained frame rate.
The same figure in plan view: twenty-four agents on a line, the ring of the first formation shown as vacant slots, and a health legend reading Healthy 24.
Plan view. The same state from above. Health is carried by shape as well as by colour, so a failure survives a monochrome screenshot. Replay walks the mission's own event stream, not a recording of the display.

Screenshots are the console's own output, captured from a running installation. All state shown is produced by AEROE's kinematic simulator — no figure on this page is evidence of physical flight.

Formation library · §12.3.1

Fourteen formation types. Every one drawn from the generator that flies it.

A formation type is one generator interface, registered — validation and assignment never change. Each panel below is the console's plan view of a mission the gate passed and the simulator flew, with the numbers a customer asks about measured the way the gate measures them: closest pair (CV-001) and extent (CV-005), against a 3 m minimum.

Not shown: rectangle (a grid under another name) and traced image — an uploaded picture is traced once, at authoring time, onto a fitted hexagonal lattice; the mission carries the points and never the picture, so generation stays a pure function of its parameters. Flags are geometry only: showing a colour needs a declared effector, and an effector is an abstract state the core never names.

The gate

Refused in numbers, never in adjectives.

Every rule in the constraint ruleset returns the measured value, the limit and, where one exists, the value that would pass. These are the verbatim answers the platform gave while the missions on this page were being authored.

CV-021 · swept-volume transitionRefused
Asked for: a programme moving 60 agents from a ring into a wedge in 45 s
Moving from formation 0 to 1, two agents pass within 1.53 m of each other — 3.00 m is needed — 23% of the way across, although both formations are themselves legal. Lengthen the 45.0 s transition, or re-order the formations so the paths do not cross.

The only rule that measures something moving. A transition validated at its endpoints has not been validated.

CV-014 · settle bandRefused
Asked for: a 200-agent flag whose closest slots were 3.09 m apart
Agents for slots 148 and 189 converge within 2.1 m at settle: their slots are 3.09 m apart and each may be 0.50 m off. 3.00 m required.

An agent is "at" its slot anywhere inside its tolerance. The gate measures the worst case, not the drawing.

CV-019 · shared airspaceRefused
Asked for: a second mission while the first still held its claim
This mission's airspace overlaps mission "Circle — 20 agents, 15 m" (EXECUTING) by 33.0 m east-west, 33.0 m north-south and 3.0 m vertically. Move 3.0 m along the vertical, change the altitude band, or wait for it to finish.

Concurrent missions hold claims derived from their geometry. Two missions never share airspace by accident.

NFR-044 · declared ceilingRefused
Asked for: an eleventh concurrent mission on an installation declared for ten
This installation is declared for 10 concurrent missions; accepting this would make 11. To proceed, complete or abort a mission.

Capacity is a declaration too. The installation says what it will carry, and the gate holds it to that.

Increment 5 · Programmes

A formation is a photograph. The journey between two is not.

The current increment takes the platform from a single held formation to a programme: an ordered set of committed formations with declared transition and hold times, validated as a whole, composed for a declared observer, and recorded figure by figure. Every mechanism is general — the same machinery flies a survey's lines and a patrol's legs.

U-70MIS-023

Formations stand up

A formation declares the plane it stands in — a tilt and the bearing it faces. The shape is rotated rigidly, so every pairwise distance, and every separation rule, means exactly what it meant when it was flat.

U-71PRG-001 · 003

Programmes, validated as a whole

Steps follow the mission's own formation. Over each transition, no pair of agents may come within the separation minimum at any instant — computed in closed form, never sampled. Execution needed no new mechanism: each figure compiles to a barrier the fleet already knew how to wait at.

U-72 · U-79RAL-021 · 022

Two declared envelopes

An adapter declares its positioning uncertainty; commanded separation is checked against the convolved pairwise uncertainty plus the minimum. It declares its time-sync class and error bound; a programme whose cue tolerance is tighter than the clock is refused. A barrier waits for the slowest — a cue does not.

U-73PRG-006

The viewpoint is part of the composition

An observer position is on the versioned specification, not a camera setting. A five-agent line is fifteen degrees wide from the east and a dot from the south; the console renders what the audience sees — bearing and elevation per slot, with no lens anywhere in the model.

U-74 · U-75PRG-004 · 005

Energy, launch, and the hole

A launch is a transition from surveyed ground; the programme's whole duration is validated against the worst declared endurance minus reserve. On agent loss the operator chooses, before launch: hold the shape with a hole, re-derive, or end early. The default is the hole — a crew can predict it.

U-77DAT-013

Evidence per figure, per transition

A committed version records what was flown — every figure's slots and assignments — and a rehearsal is compared with the plan per formation and per transition, in simulation time. "Record 17 differs" is a determinism check; a crew asks which figure, and by how much.

U-69EFF-001 · 006

Effectors, without a device

The first command in the vocabulary that moves nothing. An effector is a declared capability with abstract states, stamped on slots, never safety-bearing — and the core never learns what it is.

The 3D twin showing sixty agents holding the word AEROE standing upright in the sky above a ground grid.
An upright wordmark. Sixty agents, the text generator unchanged, the plane declared at 90° facing north. The twin's fixed camera foreshortens it; the observer view in the editor does not.
The 3D twin: twenty agents on a 15 m ring, each facing the centre, each sitting in its slot ring.
The north-star ring. Twenty agents, 15 m radius, centre-facing, 4.69 m adjacent. Every slot ring occupied.
The 3D twin: one hundred agents filling a disc in a phyllotactic spiral at uniform density.
A hundred agents, one disc. The spiral is the formation that scales — its suggested radius is measured off a unit spiral rather than derived, because the closed form runs about 20 % optimistic at real counts.
Engineering ledger

The specification is the acceptance contract, and the repository checks itself against it.

Traceability, vendor neutrality, import boundaries, schema drift, adapter effort, release reproducibility and the air-gapped posture are all build gates, not review habits. A requirement a unit claims is a requirement CI measures.

395
Requirements · SRS v4.0
64
Acceptance tests
14
Formation types
40
Architecture decisions
0.2SPI
Adapter interface · published
0.3suite
Conformance · offline-verifiable
Air-gapped by default

Nothing leaves the site.

The console names no host but its own API; images are pinned; the installer runs from a bundle. A gate fails the build on any external fetch. The optional model provider is the one declared exception, and the console says so on screen.

Evidence, byte for byte

Bundles somebody else can check.

Evidence exports are canonical and byte-deterministic; audit logs are append-only and hash-chained; every archive ships its own dependency-free verifier. A bundle only verifiable by the software that produced it proves nothing to a third party.

Simulation first, honestly

No figure here is evidence of flight.

Every result on this page comes from a kinematic simulator with fixed seeds. The physical track is gated separately, and the software that enables it — edge agents, site models, checklists, declared envelopes — is built and tested before a vehicle is asked to.

Product
AEROE
Baseline
● MERIDIAN · SRS v4.0
Track
Increment 5 · in progress