Actions

Work Header

Rating:
Archive Warning:
Fandoms:
Characters:
Additional Tags:
Language:
English
Stats:
Published:
2026-08-16
Completed:
2026-08-16
Words:
4,100
Chapters:
2/2
Comments:
2
Kudos:
5
Hits:
28

Systems and Assumptions

Summary:

Two vignettes about Geordi and Data working through technical problems aboard the Enterprise that lead into philosophical questions about engineering, risk, causation, and what it actually means for a system to work.

Chapter 1: Data notices a redundant component that will almost certainly never be needed during the remaining service life of the Enterprise. Removing it would save mass, power and maintenance time, but Geordi refuses. This leads to a discussion about probability, acceptable risk, and the strange human distinction between something being extremely unlikely and something being allowed to happen.

Chapter 2: A component fails, and while replacing it they discover that the failure has accidentally corrected a subtle performance problem elsewhere. Data wants to understand exactly why before restoring the original configuration. This leads into causality, optimization, and the dangerous assumption that knowing what each component is for means knowing what the whole system is doing.

Chapter 1: Unnecessary Redundancy

Chapter Text

Geordi had learned years ago that Data could make an ordinary maintenance review dangerous. They were currently three hours into the Enterprise’s quarterly engineering redundancy audit, which meant working through systems that almost never appeared in incident reports because, when properly maintained, they spent their entire operational lives waiting for something else to fail.

Geordi stood at the master systems table in Main Engineering with one hand braced against its edge. A schematic of the port-side secondary plasma distribution network showed on the display. Data occupied the opposite side, scrolling through reliability projections faster than Geordi cared to follow.

“Next,” Geordi said.

Data enlarged a section of the diagram. “Emergency isolation controller EPS-42-B.”

“Status?”

“Fully operational. Last diagnostic eleven days ago. No degradation.”

“Great. Next.”

“I recommend removing it.”

Geordi looked up.

Data had already opened another window.

“Removing what?”

“EPS-42-B.”

Geordi studied the schematic again. “The emergency isolation controller.”

“Yes.”

“The redundant emergency isolation controller.”

“Yes.”

“The one whose entire job is to take over if EPS-42-A fails.”

“That is correct.”

Geordi stared at him for a second, then leaned over the table and checked the maintenance notes himself.

“Why?”

“Because it is unnecessary.”

Geordi gave him a suspicious look. “You’re going to have to do better than that.”

Data rotated the schematic and highlighted several junctions.

“EPS-42-A has a projected mean service life of one hundred eighty-three years under current operating conditions. Its probability of complete failure during the remaining projected service life of the Enterprise is approximately 0.0038 percent.”

“And B?”

“Identical.”

“So we have two extremely reliable controllers.”

“Yes.”

“That sounds good.”

“It is inefficient.”

Geordi folded his arms as Data continued.

“EPS-42-B requires twelve kilograms of dedicated hardware, fourteen meters of shielded control conduit, periodic diagnostic time, replacement isolinear elements, and a continuous standby power draw of 0.7 kilowatts.”

“Seven hundred watts.”

“Yes.”

“Data, Ten Forward probably loses that much through the coffee machines.”

“I have not examined their energy efficiency.”

“Don’t.”

Data tilted his head slightly.

Geordi enlarged the relevant section of the power network. “You’re proposing we strip out a safety system because it uses less power than a kitchen appliance.”

“The power consumption is only one factor. The controller also introduces additional complexity into the network. Every component added to a system creates its own possible failure modes.”

Geordi’s expression changed a little at that. “That part’s true.”

Data brought up another analysis. “Removing EPS-42-B would eliminate twenty-nine connectors, two control relays, six monitoring taps, and one automatic transfer interface. The resulting system would be simpler and marginally more reliable during normal operation.”

“During normal operation.”

“Yes.”

“And if A fails?”

“Manual isolation could be performed from Junction 42.”

Geordi looked toward the aft bulkhead as though Junction 42 might be personally responsible for this conversation.

“Where is Junction 42?”

“Deck thirty-four, frame seven hundred twelve.”

“Access?”

“A maintenance crawlway.”

Geordi nodded slowly. “So if A fails, somebody crawls down there and shuts the line manually.”

“Yes.”

“How long?”

“Under ideal conditions, approximately four minutes.”

Geordi turned back to him. “And under the conditions where an emergency plasma isolation controller has actually failed?”

Data considered the question for roughly half a second, which Geordi had learned was Data’s equivalent of conceding a point without admitting one existed.

“The transit time could increase.”

“Could.”

“Yes.”

“How much?”

“That would depend upon the nature of the emergency.”

“Exactly.”

Data shifted the analysis. “Even allowing for significant delay, the probability of a sequence requiring EPS-42-B remains exceedingly small.”

“How small?”

“Approximately one chance in twenty-six million during a five-year operating interval.”

Geordi let out a quiet whistle. “Okay. That is small.”

“Yes.”

Data waited while Geordi studied the numbers. The figures were difficult to argue with. Starfleet engineers liked redundancy, but they also liked clean design, and redundancy had a cost. A backup system needed its own sensors, pathways, logic, testing, maintenance and spare parts. Enough backups eventually created an entire secondary machine whose sole function was waiting for the primary machine to become unreliable.

Geordi tapped the display. “Let me ask you something. What’s the probability of us needing the saucer separation system next year?”

Data answered immediately. “That depends upon mission profile.”

“Ballpark.”

“Very low.”

“Should we remove it?”

“No.”

“Why?”

“The saucer separation system provides capabilities beyond emergency redundancy.”

“All right. Escape pods.”

“Those are required under Starfleet safety regulations.”

“I know they’re required. Pretend they aren’t.”

Data’s eyes shifted slightly toward him.

Geordi smiled. “Come on. Thought experiment.”

“Very well.”

“Statistically, how many escape pods aboard this ship will ever be launched during an actual emergency?”

“That cannot be predicted with useful precision.”

“Sure it can. Give me your best estimate.”

Data glanced toward the engineering records. “Given Starfleet historical data and the Enterprise’s mission profile, the expected number is substantially below one.”

“So most of these pods will spend their whole lives attached to the hull.”

“Almost certainly.”

“And every one of them takes maintenance.”

“Yes.”

“Also mass, space, and inspection time.”

“Yes.”

Geordi spread his hands.

Data studied him. “You are suggesting that engineering efficiency cannot be evaluated solely through expected utilization.”

“I’m suggesting you already knew that.”

“I knew it as a design principle.”

“Apparently the principle needed exercise.”

Data looked again at EPS-42-B. “The difference is quantitative.”

“Most engineering differences are.”

“The probability of requiring an escape pod is considerably greater than the probability of requiring this controller.”

“So where’s the cutoff?”

Data didn't immediately answer.

Geordi noticed and smiled. “There’s your problem.”

“I am uncertain which problem you mean.”

“The number.” Geordi moved around the table and stood beside him. “You’ve got one chance in twenty-six million. Fine. Too small. Suppose it was one in ten million.”

“That would still be extremely low.”

“One in a million.”

“I would require additional analysis.”

“One in a hundred thousand?”

“The redundancy would likely be justified.”

Geordi pointed at him. “Somewhere between those numbers, you changed your answer.”

“Yes.”

“Where?”

“I would need to define the consequences of failure more precisely.”

“Okay. Worst-case failure.”

“A rupture in the associated plasma transfer conduit could produce extensive damage to decks thirty-three through thirty-five and potentially result in fatalities.”

“How many?”

“The range is broad.”

“Give me the ugly end.”

“Depending upon occupancy and secondary damage, perhaps thirty-seven.”

Geordi looked at the display again. “One chance in twenty-six million that this thing prevents thirty-seven deaths.”

“The figure represents a simplified estimate.”

“I know.”

Data regarded him. “You believe that probability alone is insufficient.”

“I think probability tells you how often you expect something to happen. It doesn’t tell you what you’re willing to let happen.”

Data’s brow tightened faintly. “That distinction is interesting.”

“It becomes really interesting when you’re Chief Engineer.”

Geordi collapsed several windows and brought up the physical layout of the controller.

“When I sign off on removing B, I’m saying something very specific. I’m saying that if A fails and somebody dies because B isn’t there, the design still made sense.”

“If the statistical analysis was valid, that conclusion would remain logically defensible.”

“Sure.”

“You disagree.”

“I didn’t say that. Engineering always has tradeoffs. We accept risks every day. Every shuttlecraft could have six engines. Every corridor could have four pressure doors. We could put independent life support in every crew cabin. Eventually the ship would be nothing except backup systems. But there’s a difference between accepting a risk because you have to and removing protection because the spreadsheet says you probably won’t need it.”

Data examined the controller schematic again. “That may be an emotional distinction rather than a technical one.”

“Maybe.”

“Would that make it invalid?”

Geordi glanced sideways. “Now you’re asking the right question.”

Data turned fully toward him. “If two designs produce nearly identical expected outcomes, but one is preferred because its failure would be perceived as more preventable, then the preference reflects human judgment rather than engineering necessity.”

Geordi shook his head. “You’re drawing the line too cleanly. Engineering includes human judgment.”

“The physical behavior of the system does not.”

“No. But deciding what behavior is acceptable does.”

Data absorbed that, then enlarged the reliability graph again. “If the probability were one in one trillion, would you retain EPS-42-B?”

Geordi considered it. “Probably not.”

“One in one billion?”

“I’d want to know what it costs us.”

“One in one hundred million?”

“Now you’re getting irritating.”

“I am attempting to identify your threshold.”

“I know.” Geordi rubbed the side of his jaw. “And I don’t think I have one.”

“That seems inconsistent.”

“It probably is.” Geordi pointed toward the warp core. “You know how many things on this ship can kill people?”

“Approximately—”

“Rhetorical question.”

“Understood.”

“Every design decision is somebody deciding how much danger is acceptable. Usually we hide that inside specifications. Maximum pressure. Minimum containment strength. Triple redundancy. Inspection interval. Those numbers look objective once they’re written down.”

“They are derived from objective measurements.”

“Derived from them. Somebody still decides what the margin should be.”

Data nodded slowly. “A warp plasma conduit capable of tolerating twelve percent above maximum operational pressure could be redesigned to tolerate thirteen percent.”

“Exactly.”

“And fourteen.”

“Yep.”

“There is therefore no physically mandated point at which the safety margin becomes sufficient.”

“Now you see why engineers drink coffee.”

Data glanced toward him. “I had assumed caffeine consumption was primarily related to work schedules.”

“That too.”

Data returned to the controller. “Then perhaps the relevant question is whether EPS-42-B represents prudent redundancy or excessive redundancy.”

“That’s the audit.”

“And the answer cannot be obtained purely by calculating the probability of its use.”

“Now you’re making progress.”

Data began entering new parameters. Geordi watched several categories appear: consequence severity, accessibility of manual intervention, common-mode failure vulnerability, maintenance burden, replacement availability.

Then Data added another.

Recoverability.

Geordi raised an eyebrow. “You’re adding factors.”

“My previous analysis treated the controller primarily as an additional component. That was incomplete.”

“What changed your mind?”

“The manual alternative.”

Data highlighted Junction 42. “Should EPS-42-A fail during ordinary operation, manual isolation is straightforward. During the specific conditions most likely to produce a controller failure, however, access to Junction 42 may itself be compromised.”

Geordi smiled faintly. “So B isn’t just another way to do the same thing.”

“No. It preserves the ability to act when other options have degraded.”

“Exactly.”

Data processed the revised model. “Under that interpretation, the controller’s value is disproportionately concentrated in very rare, very severe circumstances.”

“Welcome to emergency systems.”

Data looked at the result. “My recommendation has changed.”

“Keep it?”

“Yes.”

Geordi nodded and reached for the next item in the audit.

Data remained focused on EPS-42-B. “There is still an unresolved issue.”

“And what's that?”

“If the controller is justified despite its exceptionally low probability of use, then Starfleet may maintain other redundant systems whose costs exceed their actual value simply because engineers are reluctant to accept responsibility for removing them.”

Geordi stopped scrolling. “That also happens.”

“Then caution itself can create poor engineering.”

“Absolutely.”

“And efficiency can create unsafe engineering.”

“Absolutely.”

Data looked at him. “The optimal position is therefore neither maximum redundancy nor minimum redundancy.”

“Usually.”

“And there is no universal mathematical boundary separating the two.”

“Nope.”

Data considered this for several seconds. “That is inconvenient.”

Geordi laughed. “You wanted engineering to be clean?”

“I had hoped it might be cleaner.”

Geordi called up the next system. “Data, every machine eventually turns into philosophy if you stare at it long enough.”

“I am uncertain whether that is an engineering principle.”

“Give it time.”

Data closed the EPS-42-B analysis and marked the controller RETAIN — SAFETY CRITICAL.

Then he opened the next item. “Secondary coolant circulation pump C-12.”

Geordi glanced at its service history. “All right. What about it?”

Data examined the numbers. “I recommend removing it.”

Geordi sighed and leaned toward the console. “Okay. Convince me."