| Vose Software

Industry: Defense
Product: ModelRisk
Application: Tactical planning under uncertainty


The Plan Fit The 4-Hour Window. The Mission Beat It Only 58% Of The Time.

A time-sensitive six-phase raid was planned at 175 minutes — comfortably inside a 240-minute tasking window. On paper the mission fits with an hour to spare, and the operations cell briefs it as low-risk on time. The Monte Carlo version of the same mission, run 100,000 times in ModelRisk, tells a different story: the median completion time is 190 minutes, the P90 is 271 minutes — past the window — and once the phase success-gates are included the mission actually completes inside the window only 57.8% of the time. The 65-minute "buffer" in the deterministic plan was an illusion created by summing most-likely phase durations and ignoring both their spread and the chance that a phase simply fails.

The cell rebuilt its mission timeline in ModelRisk as a chain of sequential phases, each with a stochastic LogNormal duration and a Beta-based success gate. The mission completes only if every gate passes and the total time lands inside the window. Across 100,000 executions, the completion-time distribution the deterministic plan never produced is this:

Distribution of total mission completion time across 100,000 executions

Why a single timeline fails

Adding up each phase's most-likely duration produces a single number that sits well below the realistic median, for two reasons a deterministic plan cannot capture. First, phase durations are right-skewed — a breach or an action-on-objective can run long but rarely runs short — so the sum of medians understates the mean. Second, and more important, every phase in a given mission shares the same operating conditions: weather, electronic-warfare environment, and adversary alert level. The model draws one conditions factor per mission run that stretches all phase durations together and erodes all success gates together. That shared factor is what produces the heavy right tail; treating phases as independent — the implicit deterministic assumption — would cancel the good and bad phases against each other and badly understate the probability of a long, failed mission.

Completion time: the shape behind the plan

Return to the distribution above. The mean completion time is 198 minutes and the P50 is 190, both already above the 175-minute plan. The P90 is 271 minutes, and the average of the runs beyond P90 is 311 minutes — well past the window. The dotted line marks the 240-minute window: 20% of executions overrun it on time alone, before any consideration of whether the mission's success-gates all pass. A plan briefed as having an hour of slack is, in the simulation, late one time in five.

How much window the mission really needs

The planner's lever is the size of the tasking window. Sweeping it and recomputing the probability of completing inside it — for the baseline plan and for a contingency plan that pre-positions a reserve (12% shorter median phase durations, gate base-rates lifted 3 points) — gives the trade directly:

Probability of completing inside the tasking window versus window size

At the actual 240-minute window the baseline plan completes 57.8% of the time; the pre-positioned-reserve plan lifts that to 75.5% — a 17.7-point gain from a contingency the deterministic plan gave no way to value. The dotted line marks a 75% planning threshold: the baseline plan never reaches it at any window size because its completion probability is capped by the all-gates-pass rate, while the reserve plan crosses 75% at about a 238-minute window. The flat ceiling on the baseline curve is itself the finding — buying more time cannot fix a mission whose binding constraint is gate failure, not clock.

Where the time slips — and the critical phase

Decomposing the spread in total mission time by phase, and separately tracking which gate most often fails the mission, identifies where to apply effort:

Tornado of drivers of total mission time spread by phase

The largest single contributor to time spread is the shared operating conditions factor (±44 minutes), confirming that the dominant timeline risk is the common environment, not any one phase. Among the phases, actions on objective contributes most to time spread (±37 minutes), consistent with its long median and high variability. On the success side, the critical phase is also actions on objective: it accounts for 9.1% of all missions failing at its gate, the highest of any phase, followed by the breach at 8.0%. Time risk and failure risk both point at the same phase — the rare alignment that makes a mitigation decision easy.

Where the slip accumulates across the timeline

Laying the phases out as a stochastic timeline — P50 finish bars with P10–P90 uncertainty whiskers — shows the uncertainty compounding phase by phase:

Mission phase timeline with P10 to P90 uncertainty whiskers

Early phases are tight: insertion finishes between 22 and 56 minutes (P10–P90). But because each phase starts only when the previous one ends, the uncertainty accumulates down the chain. By exfiltration, the P10–P90 finish spans 134 to 271 minutes — a 137-minute band on the final phase against a 35-minute band on the first. The whiskers widening as they march right is the visual signature of compounding schedule risk, and it tells the planner exactly where a slip becomes irrecoverable: the back half of the mission has no room to absorb a delay that the front half let through.

What the model changed

  • The "65-minute buffer" was retired. Planning shifted from the 175-minute deterministic sum to the 190-minute median and the 20% overrun probability, giving commanders an honest time-risk figure.
  • Contingency was valued, not just listed. The pre-positioned reserve's 17.7-point gain in window-completion probability (58% to 76%) made the case for the supporting assets quantitatively rather than as boilerplate.
  • Effort concentrated on actions-on-objective. Because that phase topped both the time-spread tornado and the gate-failure ranking, rehearsal time, redundancy and the reserve were focused there rather than spread evenly.
  • The gate-failure ceiling was exposed. Recognising that no amount of extra window time could push baseline completion past its gate-pass cap reframed the problem from "buy more time" to "raise phase success rates," redirecting the mitigation entirely.

ModelRisk Functionality Used

  • Monte Carlo simulation of a six-phase sequential mission chain over 100,000 executions, combining stochastic phase durations with phase success-gates.
  • LogNormal duration distributions per phase for right-skewed task times, and Beta-based success gates giving each phase a bounded pass probability.
  • A shared per-mission common factor (operating conditions) correlating every phase's duration and success within a run — the dependence that produces the heavy completion-time tail instead of an artificially tight independent sum.
  • A parameter sweep of window-completion probability against window size, for baseline and contingency plans, quantifying the value of the pre-positioned reserve.
  • Tornado sensitivity and gate-failure attribution ranking phases by their contribution to time spread and to mission failure, isolating the critical phase.
  • A stochastic timeline (P50 with P10–P90 whiskers) showing schedule uncertainty compounding across sequential phases.

A mission plan built on a sum of most-likely durations is a forecast of the one execution where nothing varies and nothing fails. Built on a distribution, it is a forecast of the executions that will actually happen — late ones, failed ones, and the specific phase that drives both. ModelRisk is what turns the timeline from a single number into a risk picture the commander can plan against.