Calculations with context
ETA event-tree calculator
Calculate every outcome sequence and annual frequency for one to three binary barriers using path-specific conditional probabilities; inspect conservation totals.
ETA · follow every conditional path
One initiating event, up to three binary barriers, and an explicit probability for each reachable history. The worksheet calculates sequence frequencies, not safety acceptance.
A synthetic deck-transfer release
The initiating event is a defined small release during a hypothetical shipboard transfer. Detection, isolation and retention are assessed in that order. S means the stated response criterion is met; F means it is not. Even after failed detection, a separate observation route may achieve isolation. Every number below was invented for this lesson and is not accident data.
State definitions and symbols
- D: release detected within 10 s
- I: transfer isolated within 30 s, including a separate observation route
- C: no material leaves the modeled collection boundary by 10 min
λ₀: initiating-event frequency. qₕ: probability of success at the next barrier given IE and history h. S: success; F: failure. πₛ: probability of terminal sequence s conditional on IE. λₛ: frequency of that sequence. D, I and C identify detection, isolation and containment/retention.
The chain rule, not an independence shortcut
For each history h, the two outgoing fractions are qₕ and 1 − qₕ. A sequence takes one fraction at each stage. Multiplying these conditional factors is the probability chain rule; it does not assume the barriers are independent. Equal inputs across histories would be an additional modeling choice, not evidence of independence.
πₛ = ∏ P(outcomeᵢ | IE, previous outcomes); λₛ = λ₀ πₛ
Σ πₛ = 1; Σ λₛ = λ₀
The engine checks |Σπ − 1| ≤ 10⁻¹² and |Σλ − λ₀| ≤ 10⁻¹² max(1, λ₀). Checks allow floating-point roundoff and do not detect missing real-world scenarios.
Sequence results
The interactive controls require JavaScript; the full lesson is available below.
Runs only in this page. No network requests, account, cookies or persistent storage. CSV downloads only when clicked; edits disappear when you leave.
Worked example: eight sequences
- Set λ₀ = 0.2 events/year and keep all three barriers. Enter q∅ = 0.9; qS = 0.95; qF = 0.2; qSS = 0.98; qSF = 0.6; qFS = 0.7; qFF = 0.1.
- SSS follows successful detection, isolation and retention: πSSS = 0.9 × 0.95 × 0.98 = 0.8379, so λSSS = 0.2 × 0.8379 = 0.16758 events/year.
- SFF uses the failed-isolation history: πSFF = 0.9 × (1 − 0.95) × (1 − 0.6) = 0.018, so λSFF = 0.0036 events/year. Do not substitute qSS = 0.98 at this node.
- FFF uses qF and qFF: πFFF = (1 − 0.9) × (1 − 0.2) × (1 − 0.1) = 0.072, so λFFF = 0.0144 events/year.
- Sum all eight disjoint sequence probabilities to obtain 1 and all sequence frequencies to obtain 0.2 events/year. No single sequence is a complete measure of risk.
| Path / endpoint | Conditional product | πₛ | λₛ (events/year) | Model status |
|---|---|---|---|---|
| SSSdetected / isolated / retained | 0.9 × 0.95 × 0.98 | 0.8379 | 0.16758 | Reachable |
| SSFdetected / isolated / not retained | 0.9 × 0.95 × 0.020000000000000018 | 0.017100000000000014 | 0.003420000000000003 | Reachable |
| SFSdetected / not isolated / retained | 0.9 × 0.050000000000000044 × 0.6 | 0.027000000000000024 | 0.0054000000000000055 | Reachable |
| SFFdetected / not isolated / not retained | 0.9 × 0.050000000000000044 × 0.4 | 0.018000000000000016 | 0.0036000000000000034 | Reachable |
| FSSnot detected / isolated / retained | 0.09999999999999998 × 0.2 × 0.7 | 0.013999999999999997 | 0.0027999999999999995 | Reachable |
| FSFnot detected / isolated / not retained | 0.09999999999999998 × 0.2 × 0.30000000000000004 | 0.006 | 0.0012000000000000001 | Reachable |
| FFSnot detected / not isolated / retained | 0.09999999999999998 × 0.8 × 0.1 | 0.007999999999999998 | 0.0015999999999999999 | Reachable |
| FFFnot detected / not isolated / not retained | 0.09999999999999998 × 0.8 × 0.9 | 0.072 | 0.0144 | Reachable |
Where this model stops
- A full study needs a justified initiator definition, operating basis, event ordering, credible time windows, dependence treatment, source data and uncertainty analysis. This form supplies none of that evidence.
- The tree includes all combinations of the selected binary criteria. If a combination is physically impossible, use justified 0/1 branching and document why. Never remove a branch merely because it is inconvenient.
- Choosing one or two barriers ends the model earlier. Those endpoints are partial histories, not final physical consequences; containment is not modeled unless three barriers are selected.
- Conditioning can represent dependence only if credible conditional inputs are provided. Common support systems, crew actions and latent conditions are not discovered or quantified automatically.
- All selected barriers are evaluated on every path. No recovery beyond the defined windows, continuous-time progression, nonbinary severity, multiple initiating events, consequence magnitude, SIL or acceptance threshold is modeled.
- The frequency of events per year is not the probability of at least one occurrence in a year. Converting it requires a justified occurrence model.
At a zero-probability prefix, downstream conditional probabilities are mathematically undefined. Their entered placeholders do not affect results. Keep all zero paths visible; validate any claim of impossibility against physical evidence.
With λ₀ = 0 all frequencies are zero, but conditional path probabilities still sum to one. This is an entered assumption, not evidence that the release cannot occur.
Method sources and further study
Government sources explain event-tree structure and path calculation. The marine definitions, numbers, illustrations and teaching limits on this page are authored for this exercise. They are not quoted standard tables.
The calculation interface could not load. The example and explanation below remain readable; reload the page to recalculate.
Related context
The method explanation and worked example are on this page. The articles below provide additional context.
All calculators