System of record
A visible value keeps its source and version; a copied update does not silently become truth.
How TOOSA works
Current eventArrival time changedNamed review required
Follow the service promise through planning, live change, verified action, and closeout.
The model connects the system of record, work, decision, action, and evidence. Exact fields and sources are configured for the selected workflow.
Preserve the request, requirements, source, and service promise.
Shape legs, stops, timing, capacity, and commercial conditions.
Name vehicles, people, responsibilities, and acknowledgements.
Link each event to its source version, consequence, options, and owner.
Apply the authorized action and verify the records and messages that changed.
Carry actuals, variance reasons, charge context, and invoice preparation into review.
Follow the decision sequence from a changed arrival through options, named approval, and verification.
Duty 08 and the next passenger commitment need review.
Connect a delayed arrival to the affected duty and passenger commitment.
Present available options with service and commercial consequences visible.
Pause the exact change for the person authorized to decide.
Read back the attempted update, acknowledgements, and any partial failure.
Each consequential step retains a named system of record, decision owner, write scope, and review point.
A visible value keeps its source and version; a copied update does not silently become truth.
The person who can view an option is not automatically allowed to commit it.
Actuals and variance reasons remain reviewable before they become financial conclusions.
Test the operating model
Describe the trigger, decision, handoffs, and closeout without sharing operational records.