How TOOSA works

One passenger job. Handoffs recorded.

TOOSAPassenger job lifecycle
01Request
02Plan
03Assign
04Change
05Operate
06Close out

Current eventArrival time changedNamed review required

Follow the service promise through planning, live change, verified action, and closeout.

The operating record

Carry context forward without flattening responsibility.

The model connects the system of record, work, decision, action, and evidence. Exact fields and sources are configured for the selected workflow.

  1. 01Request

    Preserve the request, requirements, source, and service promise.

  2. 02Plan

    Shape legs, stops, timing, capacity, and commercial conditions.

  3. 03Assign

    Name vehicles, people, responsibilities, and acknowledgements.

  4. 04Change

    Link each event to its source version, consequence, options, and owner.

  5. 05Operate

    Apply the authorized action and verify the records and messages that changed.

  6. 06Close out

    Carry actuals, variance reasons, charge context, and invoice preparation into review.

Airport recovery flow

A late arrival becomes a focused recovery decision.

Follow the decision sequence from a changed arrival through options, named approval, and verification.

TOOSAAirport recovery workflow
Source changeArrival moved by 24 minutes

Duty 08 and the next passenger commitment need review.

  1. 01DetectConflict found
  2. 02Compare2 options
  3. 03ApproveNamed owner
  4. 04VerifyReadback ready
  1. 01
    Detect

    Connect a delayed arrival to the affected duty and passenger commitment.

  2. 02
    Compare

    Present available options with service and commercial consequences visible.

  3. 03
    Approve

    Pause the exact change for the person authorized to decide.

  4. 04
    Verify

    Read back the attempted update, acknowledgements, and any partial failure.

Authority boundaries

A shared record does not create shared permission.

Each consequential step retains a named system of record, decision owner, write scope, and review point.

System of record

A visible value keeps its source and version; a copied update does not silently become truth.

Decision authority

The person who can view an option is not automatically allowed to commit it.

Closeout authority

Actuals and variance reasons remain reviewable before they become financial conclusions.

Test the operating model

Bring one change that crosses teams or systems.

Describe the trigger, decision, handoffs, and closeout without sharing operational records.