We argue, in spite of the added uncertainty, that this approach
is worth pursuing because it opens up a possibility to verify structures
and data used for models and controls. This means that it
would be possible to validate their behaviour in selected transient
situations. According to this approach selected subsystems would
be considered in their own right and would be provided with their
own protective controls for maintaining their states within allowed
boundaries and with safety systems for bringing them back
from excursions into unsafe states. Before polycentric controls can
be introduced as a design principle for safety critical systems, it is
necessary that the concept is thoroughly assessed and amended
with new design rules.
7. Management