196
Sensemaking in Safety Critical and Complex Situations
This term is further described as an operational envelope ( Fjørtoft and Rødseth,
2020). An operational envelope defines precisely what situation the MASS must be
able to handle by assigning responsibilities to the human operators and the automation. It defines conditions of operations, describes the characteristics and requirements of the system and enables the design of H uman–Autonomy Interface ( HAI),
based on specific task analysis, safety-critical tasks and challenges of sensemaking.
Several different guidelines are developed for autonomous shipping. IMO has
published an Interim Guideline for MASS trials which aims to assist authorities and
relevant stakeholders to perform autonomous tests. It includes risk management, how
to comply with existing rules and regulations, safe manning, the human element and
HMI, infrastructure, trial awareness, and communication and information sharing.
Lessons Learned from Autonomy at Sea
Based on the preliminary testing and risk analysis, it is evident that MASS is a system of systems, depending on local sensor systems, automated port services, communication with RCC, other autonomous ships, conventional ships, Vessel Traffic
Centres ( VTS) and similar. These interactions are critical factors and should be
addressed in design and operations. The degree of autonomy varies and is affected
by the complexity of the operation. A MASS will operate in phases with transitions
between human control and automation control. A w ell-defined operational envelope
is key for addressing safety issues and carrying out a risk assessment. Potential hazards within each transition must be identified with fallback procedures in place, with
focus on the sensemaking process and how humans should enter the control loop.
Challenges related to communicating the intent of a MASS in interactions
between autonomous, unmanned ships and manned ships are addressed by Porathe
( 2019). The authors argue for “ automation transparency” and methods allowing other
seafarers to “ look into the mind” of the autonomous ship, to see if they themselves
are detected, and the present intentions of the MASS, i.e. sensemaking among all
actors. This can be done by sharing information about the intention, what the automation knows about its surroundings, what other vessels are observed by its sensors
and similar by a live chart screen accessible o n-line through a web portal by other
vessels, VTS, coastguard, etc. Such a common system could be the responsibility of
the VTS and should be specified as a requirement for the operational design domain
and the operational envelope.
In a guideline from the Bureau Veritas ( 2019), several hazards are listed as important: voyage, navigation, object detection, communication, ship integrity, machinery and related to systems, cargo and passenger management, remote control and
security. Within each of them, a list of factors is mentioned. Using this, Hoem et al.
( 2019) identified a list of hazards comparing autonomous and manned ships. The
scenarios were focussed on the following differentiating factors: fully unmanned,
constrained autonomy, RCC, higher technical resilience and improved voyage planning. The paper gave a draft attempt to classify risk factors that can either be characterised as new types of incidents caused by technology, what is most characterised in
regard to today’s incidents in shipping and if the incidents are averted by crew today.
As an example, the category fully unmanned points to a higher risk for technical
failure but may improve some of today’s operators’ errors caused by poor design and
Précédent

- 219/293

Suivant