Maritime Science Life

Calculations with context

ETA event-tree calculator

Calculate every outcome sequence and annual frequency for one to three binary barriers using path-specific conditional probabilities; inspect conservation totals.

EVENT TREE ANALYSIS · 1.0.0

ETA · follow every conditional path

One initiating event, up to three binary barriers, and an explicit probability for each reachable history. The worksheet calculates sequence frequencies, not safety acceptance.

A synthetic deck-transfer release

The initiating event is a defined small release during a hypothetical shipboard transfer. Detection, isolation and retention are assessed in that order. S means the stated response criterion is met; F means it is not. Even after failed detection, a separate observation route may achieve isolation. Every number below was invented for this lesson and is not accident data.

State definitions and symbols

  1. D: release detected within 10 s
  2. I: transfer isolated within 30 s, including a separate observation route
  3. C: no material leaves the modeled collection boundary by 10 min

λ₀: initiating-event frequency. qₕ: probability of success at the next barrier given IE and history h. S: success; F: failure. πₛ: probability of terminal sequence s conditional on IE. λₛ: frequency of that sequence. D, I and C identify detection, isolation and containment/retention.

The chain rule, not an independence shortcut

For each history h, the two outgoing fractions are qₕ and 1 − qₕ. A sequence takes one fraction at each stage. Multiplying these conditional factors is the probability chain rule; it does not assume the barriers are independent. Equal inputs across histories would be an additional modeling choice, not evidence of independence.

πₛ = ∏ P(outcomeᵢ | IE, previous outcomes); λₛ = λ₀ πₛ

Σ πₛ = 1; Σ λₛ = λ₀

The engine checks |Σπ − 1| ≤ 10⁻¹² and |Σλ − λ₀| ≤ 10⁻¹² max(1, λ₀). Checks allow floating-point roundoff and do not detect missing real-world scenarios.

The conditional branching structureThe teaching tree is shown left to right. Each split has S above and F below. The result table provides each current path, conditional product, endpoint description and frequency; no branch is silently removed. SSS, SSF, SFS, SFF, FSS, FSF, FFS, FFF.IEDICSFSFSFSFSFSFSFIESFSSSFFSFFSSS1SSF2SFS3SFF4FSS5FSF6FFS7FFF8
The teaching tree is shown left to right. Each split has S above and F below. The result table provides each current path, conditional product, endpoint description and frequency; no branch is silently removed.
Build the conditional tree

Use a decimal point or comma; scientific notation is accepted. Each q is a success probability conditioned on the initiating event and the exact prior S/F history. Frequency is events/year, not a yearly event probability.

Software bounds: q = 0 or 1, or 10⁻¹² ≤ q ≤ 1 − 10⁻¹²; λ₀ = 0 or 10⁻¹² ≤ λ₀ ≤ 10⁶ events/year. These bounds protect numerical behavior and are not engineering limits.

Sequence results

The interactive controls require JavaScript; the full lesson is available below.

Runs only in this page. No network requests, account, cookies or persistent storage. CSV downloads only when clicked; edits disappear when you leave.

Worked example: eight sequences

  1. Set λ₀ = 0.2 events/year and keep all three barriers. Enter q∅ = 0.9; qS = 0.95; qF = 0.2; qSS = 0.98; qSF = 0.6; qFS = 0.7; qFF = 0.1.
  2. SSS follows successful detection, isolation and retention: πSSS = 0.9 × 0.95 × 0.98 = 0.8379, so λSSS = 0.2 × 0.8379 = 0.16758 events/year.
  3. SFF uses the failed-isolation history: πSFF = 0.9 × (1 − 0.95) × (1 − 0.6) = 0.018, so λSFF = 0.0036 events/year. Do not substitute qSS = 0.98 at this node.
  4. FFF uses qF and qFF: πFFF = (1 − 0.9) × (1 − 0.2) × (1 − 0.1) = 0.072, so λFFF = 0.0144 events/year.
  5. Sum all eight disjoint sequence probabilities to obtain 1 and all sequence frequencies to obtain 0.2 events/year. No single sequence is a complete measure of risk.
Current terminal sequences. Products are conditional on the initiating event. S/F order follows the selected barriers.
Path / endpointConditional productπₛλₛ (events/year)Model status
SSSdetected / isolated / retained0.9 × 0.95 × 0.980.83790.16758Reachable
SSFdetected / isolated / not retained0.9 × 0.95 × 0.0200000000000000180.0171000000000000140.003420000000000003Reachable
SFSdetected / not isolated / retained0.9 × 0.050000000000000044 × 0.60.0270000000000000240.0054000000000000055Reachable
SFFdetected / not isolated / not retained0.9 × 0.050000000000000044 × 0.40.0180000000000000160.0036000000000000034Reachable
FSSnot detected / isolated / retained0.09999999999999998 × 0.2 × 0.70.0139999999999999970.0027999999999999995Reachable
FSFnot detected / isolated / not retained0.09999999999999998 × 0.2 × 0.300000000000000040.0060.0012000000000000001Reachable
FFSnot detected / not isolated / retained0.09999999999999998 × 0.8 × 0.10.0079999999999999980.0015999999999999999Reachable
FFFnot detected / not isolated / not retained0.09999999999999998 × 0.8 × 0.90.0720.0144Reachable

Where this model stops

  • A full study needs a justified initiator definition, operating basis, event ordering, credible time windows, dependence treatment, source data and uncertainty analysis. This form supplies none of that evidence.
  • The tree includes all combinations of the selected binary criteria. If a combination is physically impossible, use justified 0/1 branching and document why. Never remove a branch merely because it is inconvenient.
  • Choosing one or two barriers ends the model earlier. Those endpoints are partial histories, not final physical consequences; containment is not modeled unless three barriers are selected.
  • Conditioning can represent dependence only if credible conditional inputs are provided. Common support systems, crew actions and latent conditions are not discovered or quantified automatically.
  • All selected barriers are evaluated on every path. No recovery beyond the defined windows, continuous-time progression, nonbinary severity, multiple initiating events, consequence magnitude, SIL or acceptance threshold is modeled.
  • The frequency of events per year is not the probability of at least one occurrence in a year. Converting it requires a justified occurrence model.

At a zero-probability prefix, downstream conditional probabilities are mathematically undefined. Their entered placeholders do not affect results. Keep all zero paths visible; validate any claim of impossibility against physical evidence.

With λ₀ = 0 all frequencies are zero, but conditional path probabilities still sum to one. This is an entered assumption, not evidence that the release cannot occur.

Method sources and further study

Government sources explain event-tree structure and path calculation. The marine definitions, numbers, illustrations and teaching limits on this page are authored for this exercise. They are not quoted standard tables.

Related context

The method explanation and worked example are on this page. The articles below provide additional context.

All calculators