Industry: Utilities Product: Tamara Application: Power outage risk analysis
A metropolitan utility launched a grid-hardening programme to cut outage exposure across an aging distribution network — undergrounding overhead feeders, replacing end-of-life transformers, building a storm-resilient substation, and rolling out automated reclosers and advanced metering. The whole point of the programme is reliability, yet it has to be executed on a live grid, so every overrunning day extends the very outage exposure it is meant to remove and burns extended-crew and continued-exposure money (~$0.10M/day). On a build like this, schedule slip and cost overrun are not two separate risks to be buffered apart — they are the same risk seen twice. The orthodox plan saw neither: most-likely durations for eleven activities, chained through the network, gave a 760-day, June 2028 completion at a $167M budget, on the assumption that no storm hits, no transformer is late, and every activity lands on its most-likely duration.
Rebuild the same network in Tamara, Vose Software's Monte Carlo project risk tool, link finish-date slip to extended-crew and exposure carry, and the two risks resolve into one joint picture. The chart below is the whole argument: each cell counts the simulated runs that landed at that combination of finish date and total cost; the dashed lines mark the 760-day plan and the $167M budget, splitting the cloud into quadrants.
The mass sits up and to the right. 36% of all runs land in the worst quadrant — later than the June 2028 plan and over the $167M budget — and the cloud tilts on a diagonal, the signature of coupled risk: the late runs are the expensive runs. A planner who buffered schedule and budget as two independent contingencies would double-count the easy iterations and miss this coupled tail entirely.
A deterministic schedule adds most-likely durations along one assumed-longest chain. Two things break it. First, durations are right-skewed — long-lead transformers and live-circuit work can finish a little early but overrun badly — so the mean simulated finish is 935 days against the 760-day plan, with a P50 of November 2028 and a P90 of March 2029; the probability of finishing by the published June 2028 date is just 1%. Second, the network runs parallel chains (switchgear procurement, transformer procurement and substation construction all branch off design), and whichever chain is longest in a given iteration drives the finish, so the programme inherits the worst of several paths, not the average of one. The deterministic method captures neither effect.
To pull in both the date and the cost, you need the activities that are both frequently on the critical path and strongly correlated with the finish. Tamara plots each activity's criticality index (how often it lands on the critical path) against its cruciality (the rank-correlation of its duration with the programme finish); the top-right corner is where mitigation effort pays.
Transformer procurement is the standout — a 50% criticality index and the highest cruciality at 0.44 — sitting clear in the upper-right. Feeder undergrounding follows (49% / 0.35) and integration and cutover testing is critical in every run but lower-impact (100% / 0.32), with the automated-recloser rollout (65% / 0.29) trailing. The long-lead transformer is the one activity worth a framework supply agreement and a pre-staged spare.
The same simulation gives the full distribution of the completion date — not a cumulative curve but the frequency of each finish month across the 60,000 runs.
The distribution is right-skewed and sits well past the June 2028 plan, with a P50 of November 2028 and a P90 of March 2029 — a 276-day tail beyond the plan. The body is wide because the programme inherits several parallel chains, and the right tail is where the live-network exposure compounds: those are the runs in which customers keep absorbing outages the programme exists to prevent.
Beyond continuous duration uncertainty, six discrete events were modelled as Bernoulli risks — each may or may not occur, but if it does it adds delay and cost. Ranking them by expected schedule impact (probability × delay) gives a clean Pareto:
Five of the six events carry ~80% of the expected discrete-event delay — a transformer supply delay (5.5 weeks expected), severe-storm lost days (4.2), underground obstructions and dig-ups (2.9), live-circuit switching limits (2.8) and a lineworker-crew shortage (2.7). The transformer leading both this list and the de-risk scatter is the strongest possible signal of where to spend.
Because schedule drives cost on a live grid, a mitigation package that pulls in the schedule also pulls in the budget. Tamara let the utility price three mitigations together — pre-staging spare transformers, planning work around storm-season windows, and a live-line switching protocol that cuts circuit-access waits — and compare before/after on the same axis:
Without mitigation the cost distribution runs to a mean of $163M and a P90 of $178M, with a 36% probability of breaching the $167M budget — exactly the mass in the late-and-over-budget quadrant that opened the analysis. The ~$3.5M mitigation package cuts the P80 finish by 63 days (1,000 → 937 days) and, because schedule drives cost, brings the overrun probability down from 36% to 19% — shrinking the coupled quadrant rather than buffering against it.
A resilience programme on a live grid is not a date and a budget; it is one coupled distribution with a quadrant — late and over budget — the utility cannot afford to leave unquantified. Tamara is what turns "when, and at what cost, does the grid get more reliable?" into a single probability the operations team, the regulator and the public can all sign.