Method · 29 Jul 2026 · Samuel Pouyt

What is a possible course of action (PCOA)?

A possible course of action is an option prepared in advance for a condition that may occur — a trigger written as a fact pattern, and a ranked set of responses that each point at something real on the ground. It is not a prediction that the thing will happen, and it carries no probability. The point is narrower and more useful than forecasting: when the road is blocked, nobody should be looking at a map for the first time. The decision was made before the stress, and it is already on the map.

What does a PCOA actually look like?

Concretely, an entry from a route package: primary blocked or incident ahead on the arrival leg, segment 2 of 9. Beneath it, four options, in order:

  1. Reroute on the alternate — 24 min, 27.9 km
  2. Execute the pre-staged spur to the safe haven — 13 min, 13.5 km
  3. Move to nearest medical — 5 min, 3.8 km
  4. Move to nearest safe haven — 10 min, 2.2 km

Every line names something that was measured, not imagined: an alternate route that was graded, a spur that was computed, a facility whose drive time was checked. The ranking follows doctrine rather than taste — take the biggest, fastest option first; the spur is the pre-staged escape.

Two entries from the same package show why this matters more than it looks. One reads: derived no-go zone active while moving on this legtake the alternate; it does not cross this zone. The next reads, for a different zone: abort the movement; hold at origin or last safe haven until the zone read clears — with no alternate offered, because on that zone the alternate crosses it too. There was no second option to give, so none was invented. A planning document that always produces a reassuring answer is telling you about its author, not about the ground.

Why must a trigger be a fact pattern, not a probability?

Because a trigger has to be something a person can actually observe, under pressure, and agree on. “Elevated risk of disruption” is not a trigger — two people reading it will act at different moments, or not at all. Compare an actual one: traffic flow stops completely for more than five minutes with no visible cause. That is a stopwatch. Or: an unknown vehicle closes to within one vehicle length and holds position through two or more turns. That is a count.

Written that way, the trigger does the work that the analyst can’t do from a desk three weeks earlier: it hands over a condition that the person on the ground can check for themselves, and a response already attached to it.

Where does “most likely” and “most dangerous” fit?

They are priority categories, not estimates. Courses-of-action tradecraft ranks scenarios as most likely, most dangerous, or possible — and the most dangerous branch is deliberately not the same as the most probable one. You plan against the worst credible outcome because its consequence is severe, not because you expect it.

The line we hold isn’t a banned word — it’s a defined vocabulary. Estimative language is legitimate and always has been; “the likely route is watched” is ordinary professional English. What isn’t legitimate is precision nobody earned: a percentage attached to a single future event, produced by a machine that read a few dozen incident reports. That is arithmetic performed over judgements, and the output looks measured without being measured. We check for it mechanically and reject the text if it appears.

The reason we define the terms rather than avoid them is Sherman Kent’s. In 1951 he wrote “serious possibility” into a national estimate on Yugoslavia, then discovered his own colleagues had read it as anything from about 20 percent to about 80 percent. His fix wasn’t to forbid the phrase — it was to publish a table saying what each term meant. That’s the right lesson: ban the word and analysts simply write “a real chance” instead, which is the same problem wearing a disguise. So the frames stay a fixed, published set rather than a drawer of comfortable adjectives, and every scenario carries its indicators, so you can check the world rather than the wording. A number becomes legitimate the day there’s a scoreboard to earn it — not the day a model is fluent enough to produce one.

Where do the options come from?

From the layers underneath, which is what keeps this from being creative writing. A route package measures a set of things first, and only then assembles options out of them:

Emergency spurs. A pre-staged escape from a point on the route to a specific safety asset — one to the nearest medical facility and one to the nearest safe haven per leg, plus an extra wherever a segment fails its coverage check.

Safe havens. Not a category we invent, but the union of police, military, and diplomatic posts as they exist in the sources.

Medical, graded by what it can treat. Facilities are tiered — hospital, clinic, fire station, aid station — and anything unrecognised falls to the bottom tier rather than being flattered upward. Trauma capability is the exception that proves the discipline: no open source we use carries a reliable trauma grade, so we never write one. The field is fixed at “to verify,” permanently, and the option text says so out loud: casualty: move to X — trauma grade unverified, confirm on the ground. Every consumer app will show you the nearest hospital pin. The pin is not the answer to whether that building can take a trauma case at three in the morning.

Coverage, as an enforced invariant. Every segment must have medical and a safe haven reachable inside ten minutes’ drive — or five kilometres where only a straight-line distance is available, with the basis recorded so the weaker measure can never be quietly swapped in for the stronger. Segments that fail must be rescued by a spur or carried as an off-map indicator with bearing and distance. The count is published: so many segments covered, so many spurred, so many off-map.

Nothing in the register is generated prose. Every option resolves to an object that was measured — an alternate, a spur, an asset with a drive time. Assembly, never invention.

Two rules from the doctrine this method comes from are worth stating, because they discipline the whole exercise. The first: raise options as different from each other as possible — the more genuinely distinct the options, the more room there is to find a good one. That’s the same principle the alternate-route test enforces geometrically; an alternate that shares your primary’s river crossing isn’t a second option, it’s the first one drawn twice. The second: a pre-staged plan must be re-verified as still applicable and available before it is offered. A contingency written six weeks ago is a hypothesis about the world, and the world moves. That is the doctrinal reason every asset in the register enters marked “to verify” and stays that way until a person confirms it.

What about the adversary’s courses of action?

That is the second layer, and it’s where a language model earns its place — under supervision. From the same measured context plus a bounded set of citable incidents, it proposes what could develop: a scenario, at least two observable indicators, a trigger, and counter-options that execute the pre-staged register wherever one already answers.

Then it goes through two gates and a red team, and this is the part worth understanding, because it’s where most AI-assisted analysis quietly fails:

  • Grounding gate. Every scenario must cite incident identifiers that actually exist in the context it was given. A fabricated or malformed identifier fails on string equality — no interpretation, no benefit of the doubt.
  • Probability gate. Every prose field is scanned. Quantified likelihood language is rejected outright.
  • Red team. A second pass prompted to refute: is this grounded, or a leap from one distant incident? Are the indicators genuinely observable before the trigger fires? Are the counter-actions executable by a small detail? A plausible-sounding but ungrounded scenario is dropped, not polished. And a scenario the red team never ruled on is dropped too — nothing survives by default.

In one real run, three scenarios reached the client and three were killed before the red team ever saw them: one for using the word “probability,” two for citing incident identifiers that didn’t exist — including one with a doubled prefix, the signature of a model inventing a plausible-looking reference. Those rejections are published in the document, with their reasons. The dropped judgements are part of the deliverable, because a method you can only see when it succeeds is a method you cannot audit.

What can’t a PCOA do?

Several things, and they should be said plainly.

It cannot tell you what will happen. It reasons from a bounded window of cited incidents around a specific movement — not from a named adversary with attributed intent. Where a scenario needs an actor it can’t attribute, that becomes an information request, not a claim.

It cannot confirm the ground. Choke points are geometric candidates flagged for confirmation, never asserted as threats. Facilities are leads graded by corroboration, not verified sites. Everything auto-populated enters as to verify and stays there until a human confirms it — which does not happen inside a machine.

It does not yet know your policy or your budget. Today the register ranks on operational merit — time and distance — not on whether an option sits inside your organisation’s travel rules, or what it would cost, or who could authorise it at three in the morning. That’s a real gap, and an instructive one: the doctrine is explicit that out-of-policy options should be listed and flagged, never quietly deleted, because the option a client would actually take under duress is often the expensive one nobody planned for. Carrying policy status and cost band on every option is in design.

And today it is computed before you move. The register is fixed at release; it does not yet update itself against a journey in progress. Resolving courses of action live, on target, is the next tier and we say so rather than implying it already exists.

Why prepare options for a day that probably won’t come?

Because the cost is asymmetric and the timing is impossible. Preparing an option costs a few minutes at a desk, weeks early, with maps and time and a second opinion available. Choosing one costs seconds, at the worst moment, with none of those things. The work is the same work; only the conditions change, and the conditions are what determine whether it gets done well.

That is the whole argument for pre-staging. Not that we know what will happen — we’re explicit that we don’t — but that if it does, the thinking has already been done, checked, argued against, and put on the map where someone can reach it with one hand.

This register ships as part of any route or journey assessment, and the same logic extends to a home and a family’s routine on the property lifecycle. The method behind the route layers is on the record in how to assess a route through a high-risk city; resolving these options live against a moving picture is in build, and tracked honestly on Monitoring.

Keep reading

Related field notes.

Ready when you are

Have a question worth answering well?

Start a conversation

This is the method on the record. Applied to your decision, it's an Aegilo Report or an Assessment.