Fleet risk
Each vessel gets a risk score from 0 to 100. Higher means more risk. The score is three parts added together: survey trend (35), competency gaps (35) and safety reports from the last 90 days (30). Every part is shown. The score starts a conversation; the reporting officer decides.
Risk spread
Recent runs
Each bar is one saved run, split by band. Newest first.
What moved since the last run
No vessel matches that name.
| Vessel | Risk score | Survey trend | Competency | Safety (90 days) |
|---|
Patterns across the fleet
Built from the same rows as the scores. A pattern is a prompt to look, not a finding.
Competency gaps by vessel
Gaps out of records. Darker means a bigger share of required levels not met.
Safety themes shared by vessels
Words that recur in reports from two or more vessels.
Fleet heatmap by part
Each vessel's three parts, darker where that part contributed more of its score. A vessel with no data shows no cells.
Converging signals
A vessel is flagged when its survey trend is falling, its recent safety reports are rising, and its competency gap share is high. Two of the three is a watch. These are thresholds we chose, not validated outcomes:
Read with AI
Sends redacted text to the Claude API using your own key. Names, email addresses and phone numbers are replaced before anything is sent. The exact text sent is shown below each answer.
What was sent
Load your data, or try the synthetic sample, to see the fleet here.
Reference
How to use this page
- Load data. Open Data sources. Connect Performance Delta if it is configured, or upload the four CSV files. Use "Use synthetic sample instead" to see the page with made-up data.
- Score. Press Score these files, or Ctrl or Cmd with Enter. Problems appear in a list with their file and row, and can be downloaded as a CSV.
- Read the summary. The risk spread shows how many vessels are high, medium, low or without data. Press a band to filter the list to it.
- Read Converging signals. These vessels have two or more warning signs at once. Each line gives the figures behind the sign.
- Check the fleet list. Filter by name, sort, or save a view. Watch a vessel to mark it in the list. Download the scores as a CSV.
- Open a vessel. The score history, the reason it moved since the last run, the survey trend, the competency records and the safety reports are all in its view. Keys: j and k move between vessels, Escape goes back.
- Make the committee brief. Press Committee brief (print). It opens in a new tab, ready to print with a reviewer line at the foot.
- Read with AI (optional). Enter your own Claude API key. Only redacted text is sent, and the panel shows exactly what was sent.
Model card: what each feature does, its limits and how it was checked
| Feature | What it does | Limits | How it was checked |
|---|---|---|---|
| Fleet score | Rules add three parts to 0 to 100: survey trend, competency gaps, recent safety reports. | Thresholds and weights are our choices, not tested against outcomes. | Golden file on sample data; property tests on bounds and monotonicity. |
| Converging signals | Flags vessels where all three parts point the wrong way. | Competency is a level, not a trend; survey needs six months. | Unit tests for alert, watch and edge cases. |
| Why it moved | Explains a score change part by part, naming the records. | Needs a second run from the same source; older runs lack detail. | Unit tests; browser check with a changed run. |
| Run charts | Shows score history and fleet movement, with a written summary. | Only compares runs from the same source. | Unit tests; browser check with a changed run. |
| Shorthand expansion | Expands a short list of report abbreviations before counting themes. | Short list on purpose; a wrong expansion would change a theme. | Unit tests for listed and unlisted words. |
| Read with AI | Sends redacted text to the Claude API using the user's own key. | Redaction is pattern-based; names may slip through; output is a draft. | Unit tests on redaction and the request; browser check with a stubbed network. |
| Calibration | Measures how well scores separate vessels with outcomes (AUC). | Needs outcome records; none exist yet. | Unit tests with perfect, random and empty cases. |
Method, data dictionary and known limits
How a score is made
- Survey trend (35 points): the average of the last 3 survey months against the 3 before. A fall of 15 points or more gives the full 35. Needs 6 months of survey data.
- Competency (35 points): the share of required levels not met. 25% or more gives the full 35.
- Safety reports (30 points): the severity-weighted total of reports (1 to 3) in the last 90 days, divided by 3. A result of 4 or more gives the full 30, which means a weighted total of 12 or more.
- Bands: high 60 or more, medium 35 to 59, low under 35. A vessel with no records at all shows no data, not low.
- Points are whole numbers, rounded per part, and the total is their sum.
Data dictionary
| File | Column | Meaning | Allowed values |
|---|---|---|---|
| vessels.csv | name | Vessel name, unique | Text |
| vessels.csv | type | Vessel type | Text, e.g. PSV, AHTS, CSV |
| surveys.csv | vessel | Must match a vessel name | Text |
| surveys.csv | cycle_date | Survey cycle, by month | YYYY-MM or YYYY-MM-DD, not in the future |
| surveys.csv | score | Survey score | 0 to 100 (85% is read as 85) |
| competencies.csv | vessel, crew_id | Vessel and crew identifier | Text. Shown as Crew 01 and so on. |
| competencies.csv | competency | Competency name | Text |
| competencies.csv | level, required | Level held and level required | Whole numbers |
| safety.csv | vessel, date | Vessel and report date | Date, not in the future |
| safety.csv | severity | Severity of the report | 1, 2 or 3 |
| safety.csv | text | Report text, used for word counts | Text. Not stored between visits. |
Open scoring decisions
| No. | Question | Status |
|---|---|---|
| D1 | Should a level 1 against required 3 count worse than 2 against 3? Today every unmet level counts the same. | Open. Needs a decision on gap size. |
| D2 | Should some competencies, such as dynamic positioning, weigh more than others? | Open. Needs a named owner to set weights. |
| D3 | Score per crew member, or per required competency? A small crew and a large crew face the same 25% line today. | Open. |
| D4 | What is the minimum survey data before a trend counts, and should an unknown trend show as unknown rather than low? | Open. Six months is the current minimum. |
| D5 | Should safety reports be scaled for crew size or days at sea? No exposure data is loaded today. | Open. Needs exposure data. |
| D6 | The 90-day window drops a report in one step. Should it fade gradually, or should serious injuries stay longer? | Open. |
| D7 | Which outcomes will test the bands before a high score is read as a verdict? | Open. Needs outcome records. |
Known limits
- The thresholds and weights are our choices. They have not been tested against incidents, detentions or audit findings.
- Competency records have no dates, so the competency part is a level, not a trend.
- A score is a prompt for review. It does not judge any crew member.
- Performance Delta answers do not yet carry question polarities, so those scores are provisional.
- Movement is compared only between runs from the same source.
Terms used on this page
- Survey trend
- Change in the average survey score, the last three months against the three before. Needs six months of surveys.
- Competency gap
- A crew record where the level held is below the level required.
- Weighted report
- A safety report counted by severity (1 to 3) within the last 90 days.
- Band
- High is 60 or more, medium is 35 to 59, low is under 35. No data means the vessel has no records at all.
- Pseudonym
- A stable label such as Crew 01, used in place of a crew ID so that crew are not named.
- Survey cycle
- One survey round for a vessel, grouped by month.
If data from this page is exposed: a starting checklist
A practical starting point for this specific prototype, grounded in how it actually works, not generic advice and not a substitute for legal advice.
Why this looks different from a normal incident response plan
There is no backend and no database (see "Where this is hosted" in Settings). The page cannot be breached the way a server can: there is no server-side store of anyone's data to break into. The realistic ways data from this page could be exposed are different, and each needs a different response.
If a browser holding saved runs, notes or watch lists is lost, stolen or compromised
- That browser's local storage held vessel names, scores, review notes and which vessels were watched (see the Settings privacy table for exactly what, per store). It did not hold crew names, competency text or safety report text: those are not stored.
- Open the page on that device if possible and press Clear saved runs. If the device cannot be reached, the data is confined to that one browser profile; there is nothing to revoke centrally, because nothing was ever sent anywhere to be stored.
- Decide, based on what was in the review notes specifically (the one store that may name someone), whether anyone needs telling.
If an exported file (CSV, JSON, the committee brief, a de-identified incident set) was sent to the wrong person
- Check the export log (Settings) for what was exported and when, to know exactly what went out.
- A de-identified incident export has already had emails, phone numbers and likely names pattern-matched out of the report text; that is a reduction of risk, not a guarantee. Treat it as you would any other document with that caveat.
- Ask the recipient to delete it and confirm. There is no remote revoke: once a file has left the browser, this page has no further reach over it.
If a Claude API key typed into Read with AI may have been exposed
- The key is held in memory for that visit only and is never written to storage or sent anywhere except api.anthropic.com (the page's content security policy only allows that one outbound host). Closing the tab discards it.
- If the key itself (not just the page) may have leaked some other way, revoke and reissue it from Anthropic's console; that is unrelated to this page's own storage.
Settings
What this browser stores, and the control that clears it.
| Store | Holds | May include a name | Retention |
|---|
Where this is hosted
This is a prototype. There is no backend and no database: the page is static files served from Cloudflare's global network (Cloudflare Pages), and no specific region is pinned for this prototype. Everything described in the table above stays in your own browser's local storage; nothing is sent to Nordrin or to Cloudflare as part of using the page. The one exception is Read with AI, which sends redacted text to Anthropic's Claude API, under your own API key, only when you use that feature. See the privacy line in the footer for exactly what that sends.