# PWR-235 — Redundancy and resilience: learner worksheet

Release: Revision 7T · Full Tutorial Edition
Estimated time: Estimated 28 min reading and worksheet pass
Difficulty: Intermediate
Equipment: Common household or practice equipment — Fictional community information service with a primary laptop, spare laptop, one shared cloud account, paper telephone list, separate mailbox and four staff roles.; Function/dependency table, common-cause map, failover trigger card and tabletop clock.; Three supplied failure cards plus an observer rubric. F1 says the shared cloud account is locked while both laptops still work; the expected switch is to paper intake plus the separate mailbox. F2 says the trained coordinator is absent; the expected response is to name the authorised alternate role before proceeding. F3 says both paper forms and the separate mailbox are unavailable; minimum service cannot be met, so the tabletop stops and escalates to the service owner rather than inventing another route.
Space: Desk / seated

Automated structural checklist: 10 of 10 structural checks present
Evidence quality/context: G1; Focused research depth
Automated method-quality band: Comprehensive
Method-rating basis: Structure coverage, instruction/check specificity, alternative distinctness, source troubleshooting, comparison depth and whether purpose/check fields are authored rather than derived.

Editorial review: Pending manual editorial sign off

## Before you begin
- [ ] I read the tutorial authority and stop conditions.
- [ ] I have the required equipment/space or a declared accessible alternative.

## Canonical source context

This lesson teaches redundancy and resilience through a fictional service map. You will define the minimum function, trace dependencies, test whether a backup has capacity and independence, write a failover trigger, run a benign tabletop, test failure of both routes, recover and assign maintenance. A plan or spare object is not counted as resilience until the function test passes.

Target outcome: The learner produces a dependency and failover map for one fictional service and demonstrates a tabletop switch to an independent route within the declared recovery time.

### Authority and setup conditions

- Label every item fictional and keep the exercise disconnected from live systems.
- Name the smallest acceptable service and fictional maximum interruption before mapping backups.
- Agree that any resemblance to a live incident ends the exercise and requires authorised review.

### Required or supplied materials

- Fictional community information service with a primary laptop, spare laptop, one shared cloud account, paper telephone list, separate mailbox and four staff roles.
- Function/dependency table, common-cause map, failover trigger card and tabletop clock.
- Three supplied failure cards plus an observer rubric. F1 says the shared cloud account is locked while both laptops still work; the expected switch is to paper intake plus the separate mailbox. F2 says the trained coordinator is absent; the expected response is to name the authorised alternate role before proceeding. F3 says both paper forms and the separate mailbox are unavailable; minimum service cannot be met, so the tabletop stops and escalates to the service owner rather than inventing another route.

## 1. Define minimum function

State the fictional caller, verified callback output, acceptable quality and two-day maximum interruption.

Why: Resilience cannot be judged without a service target.

Success check: The function is observable and deliberately smaller than “keep everything running.”

Accessible alternative: Complete “State the fictional caller, verified callback output, acceptable quality and two-day maximum interruption.” in shorter passes, or use keyboard input, dictation or a support person, while preserving this success check: “The function is observable and deliberately smaller than “keep everything running.”” Use readable role cards, diagrams, AAC and asynchronous tabletop input.

Alternative relationship: Target preserving when declared check is preserved

Learner notes:

________________________________________________________________________________

Completed: [ ]

## 2. Map primary dependencies

List people, building, power, device, account, network, supplier, information and decision authority.

Why: Invisible dependencies cause a backup to fail with the same upstream service.

Success check: Every dependency has an owner or unknown marker.

Accessible alternative: Complete “List people, building, power, device, account, network, supplier, information and decision authority.” in shorter passes, or use keyboard input, dictation or a support person, while preserving this success check: “Every dependency has an owner or unknown marker.” Test the intended user’s access to the fallback; do not treat a technically working route as resilient if it excludes them.

Alternative relationship: Target preserving when declared check is preserved

Learner notes:

________________________________________________________________________________

Completed: [ ]

## 3. Describe backup capacity

Record what each alternative can deliver, for how long, to whom and with what loss of quality.

Why: A backup can exist but be too small or inaccessible.

Success check: Capacity is compared directly with the minimum function.

Accessible alternative: Complete the same research action — “Record what each alternative can deliver, for how long, to whom and with what loss of quality.” — using speech-to-text, text-to-speech, enlarged text, keyboard-only navigation, shorter work blocks or a support person. Preserve this declared check: “Capacity is compared directly with the minimum function.” Do not convert the research task into capability practice.

Alternative relationship: Target preserving when declared check is preserved

Learner notes:

________________________________________________________________________________

Completed: [ ]

## 4. Test independence

Mark shared power, building, credential, supplier, data source and key person.

Why: Redundancy inside one failure domain is fragile.

Success check: The map shows which failures take down both routes.

Accessible alternative: Complete “Mark shared power, building, credential, supplier, data source and key person.” in shorter passes, or use keyboard input, dictation or a support person, while preserving this success check: “The map shows which failures take down both routes.” Use readable role cards, diagrams, AAC and asynchronous tabletop input.

Alternative relationship: Target preserving when declared check is preserved

Learner notes:

________________________________________________________________________________

Completed: [ ]

## 5. Write the failover trigger

Specify the event, decision role, ordered switch steps, communication and time limit.

Why: Improvised switching can cause duplicate or conflicting work.

Success check: A participant can follow the trigger without additional explanation.

Accessible alternative: A supported, seated, reduced-range or slower version of “Specify the event, decision role, ordered switch steps, communication and time limit.” is equivalent only when it keeps the same trained or measured target, declared configuration and success check: “A participant can follow the trigger without additional explanation.” If any of those change, record it as a related alternative rather than an equivalent repetition.

Alternative relationship: Conditional equivalence requires target and configuration check

Learner notes:

________________________________________________________________________________

Completed: [ ]

## 6. Run the benign failover

Draw a fictional primary-failure card, start the clock and switch records/roles to the approved alternative without touching live systems.

Why: A tabletop checks sequence and ownership safely.

Success check: The minimum service resumes within the fictional target or the gap is recorded.

Accessible alternative: Complete the same research action — “Draw a fictional primary-failure card, start the clock and switch records/roles to the approved alternative without touching live systems.” — using speech-to-text, text-to-speech, enlarged text, keyboard-only navigation, shorter work blocks or a support person. Preserve this declared check: “The minimum service resumes within the fictional target or the gap is recorded.” Do not convert the research task into capability practice.

Alternative relationship: Target preserving when declared check is preserved

Learner notes:

________________________________________________________________________________

Completed: [ ]

## 7. Test both-routes failure

Draw the relevant common-cause or backup-failure card and choose degraded service, safe stop or external handoff.

Why: Resilience includes naming when fallback capacity no longer meets minimum service.

Success check: No participant invents an unauthorised third route.

Accessible alternative: Complete “Draw the relevant common-cause or backup-failure card and choose degraded service, safe stop or external handoff.” in shorter passes, or use keyboard input, dictation or a support person, while preserving this success check: “No participant invents an unauthorised third route.” Use readable role cards, diagrams, AAC and asynchronous tabletop input.

Alternative relationship: Target preserving when declared check is preserved

Learner notes:

________________________________________________________________________________

Completed: [ ]

## 8. Recover and reconcile

Return to the primary in the story, compare records, resolve duplicates and tell users which version is current.

Why: Failback can create a second incident.

Success check: The current record and service owner are unambiguous.

Accessible alternative: Complete the same research action — “Return to the primary in the story, compare records, resolve duplicates and tell users which version is current.” — using speech-to-text, text-to-speech, enlarged text, keyboard-only navigation, shorter work blocks or a support person. Preserve this declared check: “The current record and service owner are unambiguous.” Do not convert the research task into capability practice.

Alternative relationship: Target preserving when declared check is preserved

Learner notes:

________________________________________________________________________________

Completed: [ ]

## 9. Assign maintenance

Set owners and dates for contacts, access, paper copies and the next test; verify one correction.

Why: Backups decay when contacts, credentials and role knowledge are never exercised.

Success check: The repaired dependency passes a matched retest.

Accessible alternative: Complete “Set owners and dates for contacts, access, paper copies and the next test; verify one correction.” in shorter passes, or use keyboard input, dictation or a support person, while preserving this success check: “The repaired dependency passes a matched retest.” Include accessible communications, alternate formats and support roles as dependencies and capacity requirements.

Alternative relationship: Target preserving when declared check is preserved

Learner notes:

________________________________________________________________________________

Completed: [ ]

## Reflection

What changed?

________________________________________________________________________________

What remains difficult?

________________________________________________________________________________

What will I repeat, adapt, ask for help with, or stop?

________________________________________________________________________________

---
Completion of this worksheet demonstrates tutorial participation only. It does not establish capability, qualification, safety clearance, diagnosis, treatment or independent validation.
