1. The Problem: Static Envelopes Against Changing Ground

A manufacturer specification is a static envelope fixed at design time. The present capability of a specific machine on a specific shift, with worn brakes, contaminated hydraulics, ground-engaging tooling near the end of its life, and a tire approaching its load limit, is a different quantity from that published envelope. In the widely deployed architecture, a fleet-management dispatcher sends a route to a vehicle whose internal control loops execute that route within published specifications, so the question whether an executable form of the route can exist on this machine, under this grade, at this rolling resistance, right now, is answered by the published specification rather than by a present-condition determination.

This matters because mining is a domain of irreversible physical action. A haul truck committed to a loaded descent on a steep ramp cannot retroactively recover brake capacity it did not have. The capability awareness inventive step disclosed in United States Patent Application 19/647,395 was designed precisely for the case where physical actions are categorically more severe than computational ones and where the inability to act safely must be a valid, planned-for result rather than a runtime failure.

2. The Regulatory Frame

The deployment frame is a dense safety-regulatory regime. In the United States, the Mine Safety and Health Administration (MSHA) administers the Federal Mine Safety and Health Act of 1977 (30 U.S.C. 801 et seq.), with overlapping jurisdiction from OSHA on surface ancillary operations and EPA on environmental discharge. The provisions most directly engaged by autonomous haulage and drilling include 30 CFR Part 56 (surface metal and nonmetal), Part 57 (underground metal and nonmetal), Part 75 (underground coal), and Part 77 (surface coal): sections 56.14101 and 57.14101 set service and parking brake performance that machines must meet under all loaded conditions including grade; sections 56.9100 and 57.9100 require traffic-control rules sufficient to prevent collisions; sections 75.1403 and 77.1403 require safeguards adequate to minimize hazards.

The Safety Program for Surface Mobile Equipment rule (30 CFR 56.23000 and 57.23000, effective January 2024) imposes a written safety-program obligation that explicitly contemplates autonomous and semi-autonomous equipment, requiring procedures to ensure that mobile equipment is operated within design and operational limits at all times. Internationally, ISO 17757:2019 (autonomous and semi-autonomous machine system safety), the Global Mining Guidelines Group functional-safety guideline, the Earth-Moving Equipment Safety Round Table (EMESRT) PR-5 performance requirements, and the Australian and Canadian provincial mining regimes converge on a structurally similar obligation. Each regime, read against autonomous equipment, asks the same question after an incident: was the machine operating within its capability for the conditions, and was the capability assessment sound? A written program that attests to operating within limits answers that question procedurally; the architecture described here answers it structurally, through an element that admits or refuses the actuation.

3. Procedural Attestation and Structural Admission

The prevailing response to operational-limits obligations is a procedural overlay on a conventional autonomous-haulage stack. Major autonomous-haulage and autonomous-drilling platforms publish capability documentation and expose telemetry feeds; operators write safety programs that reference that documentation, schedule pre-shift inspections, and log telemetry to a historian. When inspectors arrive, the operator presents the program, the inspection records, and the telemetry archive.

Two distinctions are carried by that arrangement. Published specification stands in for present capability, and surveyed condition stands in for present condition. A telemetry historian can record clean operation right up to the moment of an event because, by published specification, the machine was within service limits the whole time. The composition that determines admissibility, the comparison of the present capability of this machine against the present demand of this grade at this load and rolling resistance, is assigned to a participant only where the architecture places it there. Procedural compliance produces artifacts; the architecture described here adds a structural element that admits or refuses the actuation.

4. What Capability Awareness Provides

The capability awareness layer disclosed in U.S. Patent Application 19/647,395 introduces capability as a first-class computational state variable. Capability is not a metric, a score, or a probability. It is a computed determination, derived from the structural characteristics of the execution substrate (here, the machine), the structural requirements of the objective (the proposed action), and the current state of the execution environment (the ground and the conditions), that resolves to one of a bounded set of outcomes: the action is structurally possible, structurally impossible, structurally deferred, or must be rerouted to an alternative substrate. None of these is an error or a timeout. Each is a valid result that informs what happens next.

Three properties of the disclosed mechanism carry the mining application:

Capability envelope over defined dimensions. Each machine is described by a capability envelope, a structured object describing its current characteristics along defined dimensions. The disclosure enumerates dimensions including compute class, memory architecture, model access, locality, execution guarantees, and sensor and actuator interfaces, and discloses embodied capability envelopes describing physical affordances (degrees of freedom, force capacity, reach envelope, locomotion) matched against the requirements of a physical task. In the mining embodiment, the envelope carries brake and traction capacity, hydraulic and structural condition reported through onboard sensing, sensor reliability, and ground-engaging-tool state; the operating-environment state carries grade, curvature, surface friction, ground-pressure response, and, underground, ventilation and gas conditions.

Pre-synthesis evaluation with three-valued matching. Capability is evaluated before any executable process is constructed; the system does not build a plan and then check it, it determines whether any executable form of the action can exist on this machine under these conditions, and only then proceeds. The objective's requirements are matched against the envelope dimension by dimension, and each dimension produces one of three outcomes: satisfied, unsatisfied, or conditionally satisfiable (resolvable through temporal deferral, reconfiguration, or decomposition). The aggregate then composes to the bounded outcome: all satisfied gives structurally possible; an unsatisfiable dimension with no conditional path gives structurally impossible (refusal); a conditionally satisfiable dimension within a bounded horizon gives structurally deferred (wait, or de-rate to a reduced action that the present envelope does satisfy); a dimension satisfiable only on another machine gives rerouted. A truck whose brake dimension is unsatisfied for a loaded descent on a given grade cannot be admitted to that descent, and the architecture surfaces the reduced action it can satisfy.

Temporal forecasting, uncertainty, negotiation, and genealogy. The determination is conditioned jointly on structural capability, a forecasted temporal window during which execution could occur (confidence-bounded), and the explicit uncertainty of those assessments, and the described determination proceeds only where all three are simultaneously satisfied. Each envelope dimension's trajectory is projected forward in time, so capability that is degrading across a shift narrows the admissible envelope of later hours without external orchestration. Where a dimension is conditionally satisfiable, an envelope negotiation protocol may reconfigure the substrate. Every determination is written to the agent's lineage as a structured, append-only capability determination record (substrate identity, requirements, retrieved envelope, per-dimension results, aggregate outcome, uncertainty bounds, and forecasted change conditions), and a capability genealogy tracks when capabilities were added, removed, or modified over time, supporting trend analysis and post-incident reconstruction of why a capability changed.

A complementary primitive in the same disclosure reinforces the embodied case: for agents that control physical actuators, the platform applies a physical safety floor, a minimum confidence threshold below which no physical action is permitted regardless of task urgency or external command, which the disclosure specifies is not overridable by the agent's own deliberation or by a parent command, and a defined safe physical state (actuators brought to a controlled stop, end effectors moved to safe positions) entered when confidence falls below that floor. In mining terms, that is the structural basis for a machine that brings itself to a controlled, safe configuration rather than completing an action it can no longer execute safely, including the disclosed recognition that a controlled stop is itself an action whose reversibility and harm must be evaluated.

5. Mapping to the Regulatory Obligations

The mapping from the disclosed primitive to the regulatory regime is direct. The brake-performance obligations of 30 CFR 56.14101 and 57.14101 are addressed structurally: a machine whose brake dimension is unsatisfied for a proposed loaded descent resolves to structurally impossible for that action and is not admitted. The traffic-control adequacy of 56.9100 and 57.9100 is supported by condition observations propagating across the fleet, so deterioration first observed by one machine on a route narrows the admissible envelope of those that follow. The operational-limits obligation of the 56.23000 and 57.23000 safety-program rule, that equipment be operated within design and operational limits at all times, is the capability determination itself: operating within limits becomes a structural property rather than a procedural attestation, and the capability determination record and genealogy are the written-program evidentiary backbone. The adequate-safeguards obligations of 75.1403 and 77.1403 are addressed by the graduated outcome set (de-rate and defer, not only stop). The immediate-notification and written-report needs of 50.10 and 50.20 are addressed by lineage that reconstructs what the machine observed, how it matched, what it determined, and what it did. ISO 17757 functional-safety obligations and EMESRT PR-5 performance requirements map onto the safe-physical-state behavior and the graduated outcome respectively, and the Australian, Canadian, and Chilean (Sernageomin) regimes find their counterpart in the same determination.

6. Deployment Pathway and Embodiments

The application admits several embodiments, deployable along a graduated adoption path.

Supervisory overlay. The capability awareness layer runs on the operator's edge gateway alongside an existing original-equipment autonomy stack, ingesting the telemetry the equipment already produces and the condition data from the mine's geotechnical and ventilation sensors, and emitting capability determination records and graduated recommendations to the fleet-management system while the existing autonomy continues to drive the machine. The operator gains the structural operational-limits property and the lineage evidentiary backbone without replacing the autonomy stack.

Embedded admissibility layer. The capability determination is embedded inside the autonomy stack as the layer between the route planner and the actuator, so that no route command reaches an actuator before the capability determination admits it. In this embodiment the operational-limits property is carried at the actuation boundary: the planner does not dispatch an action whose executable form cannot exist on the present machine under present conditions.

Governance-coupled deployment. In next-generation and tele-remote operations, the capability envelopes, the genealogy, and the lineage belong to the operator's authority taxonomy and survive equipment refresh, vendor consolidation, and contract-mining transitions. The capability genealogy of a specific orebody, route, and machine population becomes portable across vendors and across decades, and that portability is a property of holding capability determinations in the operator's own authority taxonomy.

Across embodiments, the application generalizes beyond surface haulage to underground autonomous loaders and trucks (where ventilation, gas concentration, and pillar and back conditions enter the operating-environment state), to autonomous and semi-autonomous drilling (where the proposed action is drill at depth and the conditionally-satisfiable outcome supports de-rated penetration), and to mixed fleets where rerouting an objective to a more capable machine is itself a bounded outcome of the determination.

Disclosure Scope

This article is an application-level disclosure of the capability awareness inventive step described in United States Patent Application 19/647,395. The technology described here, capability as first-class state, the capability envelope and its defined dimensions, pre-synthesis capability-native computation with three-valued per-dimension matching, the bounded outcomes (structurally possible, impossible, deferred, rerouted), temporal capability forecasting with confidence-bounded windows, uncertainty propagation, envelope negotiation, capability genealogy, the physical safety floor, and the safe physical state, trace to that application. The mining domain, the regulatory frame, the market problem, and the deployment scenarios are application context describing a faithful, enabling implementation of the disclosed technology. Quantitative thresholds, machine-specific capacities, and condition values are deployment parameters, not claims of the cited application.