A collision probability is not permission to maneuverby Burak Oktenli
|
| Space traffic management is approaching a category boundary that regulation and engineering must make explicit. A collision probability alone is not permission to maneuver. |
SpaceX therefore responds at a modeled risk more than 300 times smaller than the 1-in-10,000 industry benchmark cited in the filing. It is a deliberately conservative safety policy but also a vivid demonstration of a new fact of orbital life: at scale of a large constellation, a policy built on statistical estimates can generate physical behavior 207,152 times in six months.
The lesson is not that SpaceX maneuvers too often. Its disclosure documents substantial investment in safety, repeated coordination with other operators, and a willingness to move when other parties cannot. The lesson is that space traffic management is approaching a category boundary that regulation and engineering must make explicit. A collision probability alone is not permission to maneuver.
NASA's Conjunction Assessment Risk Analysis process outlines the essential sequence for avoiding collisions. Screening identifies predicted approaches that deserve attention, and risk assessment then examines the encounter. Mitigation follows only after the evidence has been interpreted. The probability of collision, commonly abbreviated as Pc, is therefore not an order but a model-dependent estimate derived from predicted trajectories, covariance information, object-size assumptions, tracking quality, and encounter geometry.
That distinction can disappear inside automation. A software pipeline receives a conjunction data message, calculates Pc, compares the result with a threshold, and generates a maneuver plan. Each step appears reasonable, but if this automated approach grants the system authority to move, the architecture has converted a measurement into a mandate. Judgment has not vanished, but has instead has been buried in code, configuration, and procurement choices made months or years earlier.
A maneuver consumes propellant, interrupts payload operations, changes future conjunctions, and may surprise another operator. It can invalidate existing forecasts until the new trajectory is propagated and shared. Two encounters with the same Pc may justify different actions when one involves stale ephemeris data, a maneuverable secondary spacecraft, a crewed or otherwise high-consequence asset, a narrow coordination window, or a mission with little remaining fuel.
| A maneuver consumes propellant, interrupts payload operations, changes future conjunctions, and may surprise another operator. |
Even a familiar threshold does not resolve those differences. The European Space Agency notes that a probability above 10-4 typically triggers work by several teams to prepare a collision-avoidance maneuver. Crossing the threshold begins analysis and preparation but it does not automatically command motion. One step asks whether the encounter warrants action, while another decides whether a machine may alter a shared physical environment.
Collision avoidance needs three distinct layers. The evidence layer estimates where the objects may be and how uncertain that estimate is. The decision layer compares options, consequences, timing, mission cost, and residual risk. The authority layer determines which maneuver classes the system may initiate, under what conditions, and who can veto, expand, or terminate that permission.
As a recent essay put it, at machine speed, governance is whatever was specified before the crisis (see “Decisions without deciders: authority at machine speed in the space enterprise”, The Space Review, August 10, 2026). Collision avoidance is the most physical expression of that principle. A fleet's thresholds can become maneuver policy before any operator realizes that a risk setting has also become a grant of operational authority.
The solution is not to require a person to approve every small correction. At orbital speeds and the size of satellite fleets, that rule could itself create danger. Low-consequence and reversible stationkeeping adjustments can be preauthorized inside a defined envelope. Larger deviations, maneuvers near protected regions, actions that materially change mission availability, or cases involving ambiguous intent should require stronger evidence, coordination, or fresh human authorization.
The critical principle is authority contraction. When the age of data increases, covariance quality deteriorates, models disagree, the secondary object's maneuverability is uncertain, or coordination channels fail, machine authority should narrow rather than expand. That does not require paralysis. The system may continue to monitor, request new observations, generate options, or execute only the safest response already authorized for degraded evidence. What it should not do is gain wider discretion merely because time is running out.
The United States is rapidly expanding its orbital risk infrastructure. As of August 2026, the Commerce Department's Traffic Coordination System for Space (TraCSS) had 70 pilot users covering more than 11,345 satellites, as well as national government accounts from ten countries. Created to implement Space Policy Directive-3, the system is a major advance in civil space safety services. Its growth also makes the boundary between information and permission more urgent.
A traffic service should distribute better observations, standardized messages, validated analytical methods, and clearer uncertainty. It should not, by default or design, turn a shared alert into a universal maneuver policy. Future message formats should distinguish an observation from an estimate and an estimate from a nonbinding recommendation. Authorization must remain a separate operator decision, bounded by mission rules and applicable law. Data age, model version, covariance source, confidence, and material assumptions should travel with the alert rather than remain buried in a backend system.
| A traffic service should distribute better observations, standardized messages, validated analytical methods, and clearer uncertainty. It should not, by default or design, turn a shared alert into a universal maneuver policy. |
Scale also creates interaction risk. If thousands of autonomous spacecraft respond to uncertain predictions using rigid thresholds, one fleet's maneuver can invalidate another fleet's forecast, prompt a second maneuver, and generate a new set of conjunctions. That does not make a cascade inevitable. It means local optimization is not automatically global safety. ESA’s work on automated collision avoidance emphasizes precise communication of maneuver intentions because separate safety systems can interfere with one another.
International practice does not need a single global Pc threshold. Instead, it needs shared semantics and coordination rules: what data are being conveyed, what action is merely recommended, who has accepted maneuver responsibility, for what time window, and when that arrangement expires. The United Nations long-term sustainability guidelines already encourage accurate contact information and operational coordination. Autonomous fleets make those expectations architectural requirements.
TraCSS should remain an information service rather than a command authority. Commerce can make that boundary explicit in the service's outputs and future message formats: identify what is observed, what is estimated, and what is merely recommended. Authorization should remain separate. A coordination message should also state who has accepted maneuver responsibility, for how long, and when that responsibility expires.
The FCC's orbital debris rules already require applicants to disclose the maneuverability of planned spacecraft. For autonomous fleets, that disclosure should go one step further: applicants should state which maneuver classes are preauthorized, what conditions narrow or suspend that authority, how the system coordinates with other operators, and what audit record each action creates. Regulators need not approve every burn. They need operators to declare, before launch, what evidence can activate what authority.
Standards bodies and industry groups can then make those fields interoperable across fleets. That division of labor avoids two bad extremes: a central traffic controller deciding every burn, and each operator burying its maneuver doctrine inside a proprietary threshold.
First, Pc should trigger attention but not grant permission. An operator may choose a conservative threshold but crossing it should open a decision process whose required evidence and authority are specified separately.
Second, maneuver authority should be typed by consequence and reversibility. A small, recoverable adjustment within a protected envelope is not equivalent to a major orbital change. Delegation should reflect delta-v, fuel margin, mission interruption, proximity to other operational regions, coordination status, and the cost of reversing the action.
Third, weak evidence should narrow the option set. Stale data, physically implausible ephemerides, unrealistic covariance, and missing operator contact information are not theoretical problems; SpaceX's filing describes them. Automation should respond by limiting which actions remain available, escalating the case, or acquiring better information. It should not treat uncertainty as resolved because a single scalar crossed a line.
| Orbital safety will not fail for lack of probabilities. It may fail if the industry forgets what probabilities are. |
Fourth, every autonomous maneuver should produce a maneuver receipt. The record should preserve the Pc value, covariance and ephemeris versions, data age, model, alternatives considered, applicable authority envelope, coordination attempts, chosen action, and expected residual risk. As I have argued previously in The Space Review, future accountability will depend on whether orbital records remain trustworthy. Before a log can prove what happened, however, the system must record the decision that mattered: why the spacecraft was permitted to move.
These rules do not oppose autonomy. They make autonomy governable. Human oversight should not mean forcing a tired operator to click “approve” on thousands of routine actions. It should mean that humans and institutions define the envelope, machines act only within it, uncertainty changes the envelope predictably, and exceptional actions return to an identifiable authority.
Orbital safety will not fail for lack of probabilities. It may fail if the industry forgets what probabilities are. A collision estimate is evidence about a possible future. A maneuver is an intervention that changes the shared environment. Between them belongs an explicit grant of authority.
Note: we are now moderating comments. There will be a delay in posting comments and no guarantee that all submitted comments will be posted.