[SystemSafety] The States and Modes debate

Les Chambers les at chambers.com.au
Tue May 19 11:14:31 CEST 2026


Agreed, mode confusion in aerospace is a lethal issue, and it’s exactly why
I argue we need absolute semantic clarity in our engineering standards.

My grievance isn’t with the *colloquial* use of the word 'mode' by
operators or pilots. My grievance is with INCOSE—a  premier international
systems engineering body—explicitly stating that a State and a Mode
are *different
entities*, yet failing to provide a rigorous, structural definition to
separate them.

If we are to assert that they are distinct architectural concepts, we
should be able to define them by their attributes.

>From a systems engineering and computer science perspective, a *State* is a
well-defined condition of a system, governed by an internal data structure
(variables, inputs, and history) that determines how it responds to a given
set of inputs.

To help me bridge the gap between aerospace practice and rigorous systems
modelling, how would you define the unique attributes of a *Mode* versus a
*State*?

   -

   Where do their data attributes actually differ?
   -

   Is a 'mode' simply a higher-level abstraction (a 'super-state' or
   collection of sub-states, like an autopilot operational regime)? This is
   hard to justify as David Harel’s Statecharts (and subsequently UML/SysML)
   solved this decades ago without needing the word "mode." They
introduced *composite
   states* (states within states) and *orthogonal/concurrent states*
   (parallel state machines I applied extensively in chemical processing).
   -

   Or does it possess fundamentally different behavioural properties that a
   classic finite state machine cannot capture?

I contend that if a 'mode' can be entirely modelled, verified, and executed
using standard state-engine logic, then introducing it as a
fundamentally *distinct
entity* in a foundational handbook—without definition—only invites the very
'mode confusion' Sarter and Woods warned us about."

There is a path to the truth. I assert that modelling a State as an entity
defined by system attributes, invariants, and relationships, will reveal
that what the industry calls a "mode" is structurally identical to a state.

Les

On Tue, 19 May 2026 at 17:10, Prof. Dr. Peter Bernard Ladkin <
ladkin at causalis.com> wrote:

> On 2026-05-19 09:03 , Les Chambers wrote:
> > My view is that the word "mode" needs to be banished from the face of
> the Earth!
>
> Modes are essential when talking about autopilots, and have been for 30
> years, ever since "mode
> confusion" was introduced in Woods and Sarter's analysis of A320 AP
> workings.
>
> PBL
>
> Prof. Dr. Peter Bernard Ladkin
> Causalis Limited/Causalis IngenieurGmbH, Bielefeld, Germany
> Tel: +49 (0)521 3 29 31 00
>
> _______________________________________________
> The System Safety Mailing List
> systemsafety at TechFak.Uni-Bielefeld.DE
> Manage your subscription:
> https://lists.techfak.uni-bielefeld.de/mailman/listinfo/systemsafety
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.techfak.uni-bielefeld.de/pipermail/systemsafety/attachments/20260519/0ca923f1/attachment.html>


More information about the systemsafety mailing list