Secondary-Capacity Reserve Activation¶
Reserve-activation policy — instantiates Overshoot-Crash Load Management
Holds a protected reserve of the resource the crash will consume — oxygen, liquidity, staffing, treatment — and releases it when the crash-load forecast approaches the floor that must never be breached.
Secondary-Capacity Reserve Activation protects the resource the unwind consumes, not the one the growth consumed. Its premise is that a crash does not merely shrink the stock — it draws down a secondary resource (oxygen, liquidity, treatment capacity, staff attention, restoration funds) faster than that resource can be resupplied, and if it hits zero the failure cascades into everything that depended on it. So this mechanism fixes a floor below which the secondary resource must never fall, holds a protected reserve above that floor, and activates the reserve when the forecast crash load threatens to breach it. Its defining move is pre-committing capacity to the decline before the decline arrives — reserving now what the crash will demand later, and protecting it for the critical functions and vulnerable parties the floor exists to serve.
Example¶
A hospital system models a respiratory-illness wave whose case stock is climbing toward a peak. The danger is not the case count itself — it is that severe cases will draw on medical oxygen and ICU staffing (the secondary resource) faster than either can be replenished, and if oxygen pressure falls below the level that keeps ventilated patients alive, the crash turns lethal for everyone dependent on it. The reserve-activation policy sets that floor with a margin, holds back protected oxygen and cross-trained staff above it, and triggers activation — reserve supply online, surge staff called in, crisis standards of care invoked — when the crash-load forecast shows the floor being approached roughly two weeks out.
It makes no attempt to stop the wave. It guarantees the one resource whose exhaustion would turn a hard surge into a collapse. Because activation fires on the forecast rather than on the shortfall, the reserve comes online while resupply still has time to matter — the difference between a stretched system and a failed one is entirely in that lead time.
How it works¶
- Name the floor. A minimum level of the secondary resource is fixed in advance, below which critical function fails — with distributional limits, not just a system-wide average.
- Reserve above it. Protected capacity is held back from ordinary use so it is genuinely available when the crash arrives, not already spent on routine demand.
- Trigger on the forecast, not the shortfall. Activation fires when the projected crash load approaches the floor, since resupply has lead time and reacting at the shortfall is already too late.
- Protect the priorities. Released capacity goes first to the critical functions and vulnerable parties the floor was drawn to defend.
Tuning parameters¶
- Floor height — how much margin the floor carries above true failure; higher is safer but ties up more idle reserve.
- Reserve size — how much protected capacity is held back; larger covers a worse crash but is costly to keep unused.
- Activation lead — how far ahead of the projected breach the reserve releases; earlier is safer but spends the reserve on crashes that might not fully materialize.
- Allocation priority — who receives released capacity first; this encodes the distributional floor rather than just the aggregate one.
- Replenishment rule — how the reserve is rebuilt after activation, so it is ready for the delayed tail or a second wave.
When it helps, and when it misleads¶
Its strength is that it converts a resource that would otherwise fail silently under load into a guaranteed floor, and by triggering on the forecast it acts while resupply can still change the outcome. Protecting the floor distributionally is what stops a system from preserving its comfortable average while quietly sacrificing its most vulnerable.
Its failure modes track the cost of holding something idle. An unused reserve is a standing expense, so the perennial pressure is to shrink it or raid it for ordinary demand — leaving it empty precisely when the crash arrives. A guaranteed backstop can also breed moral hazard: knowing the reserve exists, the growth phase runs hotter and enlarges the very overshoot the reserve was meant to cushion.[1] And a floor set as a system average can be satisfied on paper while a vulnerable subgroup falls through it. The discipline is to ring-fence the reserve from ordinary use, price its activation so it does not subsidize reckless growth, and define the floor distributionally rather than in aggregate.
How it implements the components¶
secondary_resource_floor— it defines and defends the minimum level of the crash-consumed resource, including the distributional limits that protect vulnerable parties, not just a system-wide average.recovery_resource— it holds and activates the protected restoration and resupply capacity that keeps the floor intact through the unwind and into recovery.
It does not forecast how much crash load the peak will create (Growth-and-Crash Stock-Flow Model), verify that downstream sinks can absorb the drawdown (Sink Capacity Audit), or decide when normal operation may resume (Reentry Gate Review). It guarantees the resource; it neither sizes the load nor judges recovery.
Related¶
- Instantiates: Overshoot-Crash Load Management — the mechanism that keeps the crash from exhausting the resource the unwind runs on.
- Consumes: the crash-load forecast that determines when to activate (Growth-and-Crash Stock-Flow Model).
- Sibling mechanisms: Reentry Gate Review · Controlled Drawdown Schedule · Sink Capacity Audit · Clearance Pathway Enhancement · Cohort Staggering · Hotspot Containment and Removal · Post-Crash Residual-Load Dashboard · Threshold-Triggered Input Cap · Source Reduction Program · Saturation Dashboard · Early Warning Indicator · Growth-and-Crash Stock-Flow Model · Staged Harvesting or Decommissioning
Notes¶
The resource this reserve protects is the secondary one — the capacity the crash consumes as the stock unwinds — which is distinct from the primary carrying capacity that a Threshold-Triggered Input Cap and Source Reduction Program defend during growth. Conflating the two is a common first-encounter error: capping the inflow protects the ceiling, but only a protected reserve keeps the floor from being breached on the way down.
References¶
[1] Moral hazard — the tendency to take on more risk when insulated from its consequences — is this mechanism's built-in trap: a visible backstop (a liquidity facility, a guaranteed bailout, a surge reserve) can encourage exactly the overshoot it is meant to absorb. The standard corrective is to make activation costly or conditional, so the reserve cushions the crash without subsidizing the boom that caused it. ↩