Outdoor Risk Calibration Guidelines Version 1.0 · Source & corrections on GitHub

Outdoor Risk Calibration Guidelines (ORCG) 1.0

Status: Working draft for public comment. Criteria may change in future versions. Corrections are credited in the changelog. Editor: Patrick Scanlan Published alongside: Design on a Ridgeline, issue 03.


How to read this document

Sections 1 through 5 are normative. They define what the standard covers, what its terms mean, and what conformance requires. A product either satisfies a criterion or it does not.

The Techniques and Common failures passages inside each guideline are informative. They describe known ways to satisfy or fail a criterion. They are not exhaustive and a product is not required to use them.

Rationale and Limitations passages are informative. They state the evidence for a criterion and the known constraints on implementing it.

Citation convention. Numbered sections are cited as "section 5.4." Numbered requirements inside a guideline are cited as "criterion 5.4." The prefix distinguishes them.

Implementers should read section 5 and then the guidelines. Evaluators should read section 5.4 first.


1. Scope

1.1 The governing principle

Obligation follows recommendation. The more a product decides what a person attempts, the more of this document applies to it. A product that names an objective, rates it, illustrates it, and invites a user to do it has made a recommendation and owns the calibration that recommendation produces. A product that supplies a blank canvas has not.

This principle sorts the category into three tiers. A basemap is not responsible for a route its user invented.

1.2 Tier 1: Products presenting predetermined objectives

All nine guidelines apply. These are products that present a curated objective as a unit a person may attempt, typically with a name, a rating, a description, imagery, and a recorded track the user follows rather than creates.

This is the center of the standard. Here the gap between what the product communicated and what the terrain demanded is authored by the product rather than by the user.

1.3 Tier 2: Trail data and map layers

Guidelines 1, 2, 3, and 5 apply to the attributes carried. Guidelines 8 and 9 do not apply. These are products that render trails as legible, named, followable features without recommending any particular one: open map layers, tile providers, topographic products, and the underlying trail datasets.

Rendering a trail as a followable line is a weaker act than recommending it, and it is not a neutral one. A path drawn on a map asserts that a path exists and can be traveled, and users read it that way.

1.3(a) Where a data layer carries an attribute this document governs, the layer conforms by rendering that attribute faithfully and by not discarding it. Where it carries no such attribute, it conforms by not implying one.

1.3(b) Where a Tier 1 product consumes a Tier 2 layer, conformance obligation sits with the Tier 1 product. A provider may not discard a consequence or exposure attribute present in its source data and then claim the data was unavailable. The Thunderforest Outdoors layer, derived from OpenStreetMap and consumed by numerous consumer applications, grades hiking paths by the SAC scale, darkening and breaking the line as exposure rises. Consequence classification is present in the open data layer. A product that renders a three-value difficulty adjective on top of it has discarded it.

1.4 Tier 3: User-authored routes

Guidelines 5, 8, and 9 apply. Guidelines 1, 2, 3, 4, 6, and 7 do not. Where a user draws their own line, selects their own waypoints, or imports a track from outside the product, the product did not choose the objective and does not carry the obligation to have characterized it.

Some guidelines attach to the objective and some attach to the product:

Attaches to the objective Attaches to the product
1 Route provenance 5 Temporal validity
2 Reference frame 8 Field operability
3 Consequence exposure 9 Outcome symmetry
4 Response reality
6 Sample disclosure
7 Decision architecture

A product that lets a user draw their own route owes that user a timestamp on its conditions layer, an interface that works in rain, and a data model that can record a retreat. These obligations are properties of the product's own behavior and do not depend on who authored the line.

1.4(a) A product may not escape Tier 1 obligations by presenting a curated objective through a user-authored mechanism. Where a provider supplies the track, the obligation follows the track regardless of the interface used to deliver it.

1.5 What this does not cover

1.6 Who this is addressed to

Product teams, as the parties who implement it.

Public safety agencies, as the parties positioned to give it force. Land management agencies, sheriff's offices with SAR responsibility, and state emergency management have no concrete specification to endorse, require, or point at. The available public safety message is a version of "be prepared," which is unfalsifiable, unenforceable, and places the entire burden on the individual. This document is the specific alternative.

A specification of this kind can be referenced in land manager partnership and data-sharing agreements, in permit and concession conditions, in procurement for agency-facing tools, and in statute.

Insurers and underwriters, as the parties with the most direct financial interest in the difference between a conforming and a non-conforming product.

On endorsement. Endorsement without the capacity to evaluate conformance produces a rubber stamp, which launders a claim the endorsing party has not verified. An agency endorsement should be tied to the evaluation procedure in section 5.4, should require published conformance claims including scope and date, and should treat provider self-assessment as acceptable only where the method is published. An agency that cannot verify a claim should endorse the practice of publishing conformance claims rather than any particular product's claim.


2. Purpose and evidence base

A person deciding whether to attempt an objective is performing a calibration: estimating what the terrain will demand and comparing it to what they can supply. Products in this category shape that estimate and are under no obligation to disclose how.

The largest available analysis of search and rescue in US national parks, covering 65,439 incidents involving 78,488 people between 1992 and 2007, found the leading contributing factors were fatigue and physical condition (22.8 percent), insufficient information or error in judgment (18.8 percent), falls (10 percent), insufficient equipment, clothing, or experience (8 percent), and darkness (6 percent). Roughly 56 percent of contributing factors describe a mismatch between what a person expected and what the terrain required, and most of that expectation was formed before the person left the trailhead.

This dataset predates smartphone trip planning. It describes a period ending in 2007 and is used here as a distribution of failure modes rather than as a statement of current incidence.

Where the information environment has improved, outcomes have moved. Grand Canyon's Preventive Search and Rescue program measured a 42 percent reduction in heat-related SAR incidents and a 21 percent reduction in non-heat-related incidents. Olympic National Park reported a 66 percent reduction in trail-related SAR incidents after conditions and closures began reaching users through a planning application.

This document specifies what a conforming product does, in terms two independent reviewers can agree on.


3. What this document is not

It is not a law and it is not a certification. It is a specification. Web accessibility followed this path: WCAG is not itself binding, and procurement contracts, liability exposure, and statutes attached themselves to a testable specification that already existed. The same attachment is available here.

It does not prevent incidents. Preparation changes odds and outcomes rather than eliminating emergencies, and a standard governing information design is subject to the same limit. Marketing conformance as safety misrepresents it.

It is not a novel body of theory. Six of the nine guidelines restate interaction design principles settled and taught for decades. Their appearance here reflects an industry that did not apply them.

It does not address the transfer problem. Information is consumed before a trip, in calm conditions, and applied during it, by a group, under time and social pressure. No interface design survives that transfer intact. See section 8.


4. Definitions

Objective. A discrete destination or route that the product presents as a unit a person may attempt. A trail, a peak, a loop, a traverse, a named route.

Presented objective. An objective the provider supplies to the user, including its track, name, and attributes. The user selects it; they do not author it.

User-authored route. A route the user creates within the product or imports from outside it, where the provider supplied the canvas and the user supplied the line.

Product. The software, print, or physical artifact through which a provider presents objectives. Where a provider ships multiple surfaces, each surface is evaluated separately unless the provider claims conformance across all of them.

Difficulty. The effort, technical skill, or endurance an objective demands of a person who completes it successfully.

Consequence. The severity of outcome for a person who experiences a failure at a given location, independent of the probability of that failure occurring. Consequence is a property of place.

Severe consequence. Consequence at or above the threshold of serious injury, meaning injury that would prevent self-evacuation. Death is included. A provider applying a different threshold publishes it.

Consequence-bearing feature. A discrete, locatable element of an objective at which failure produces severe consequence. Examples: unprotected exposure above a drop, a water crossing subject to current, a section with sustained runout, a cliff band adjacent to the travel corridor, terrain from which no egress exists.

Conditional information. Any information presented about an objective whose accuracy depends on weather, season, snowpack, water level, daylight, closure status, or any other time-varying factor.

Validity window. The stated period during which the provider represents conditional information as current.

Response interval. The estimated elapsed time between a request for assistance at a given location and the arrival of assistance at that location, under typical conditions for the jurisdiction.

Egress. A route by which a party may leave an objective before completing it.

Bail-out point. A location on an objective from which egress is available.

Commitment point. The location beyond which the time or difficulty of egress increases materially, such that retreat ceases to be a low-cost option.

Sample. The set of user-contributed photographs, reviews, ratings, or reports the product displays for an objective.

Progress mechanic. Any feature that represents advancement toward a goal state, including completion marks, badges, streaks, lists, counters, and progress bars.

Recorded outcome. A result the product's data model is capable of storing for an attempt at an objective.

Field conditions. The environmental and physical circumstances under which the product is used away from the trailhead, including precipitation, cold, direct sunlight, gloved hands, single-handed operation, reduced battery, and absent connectivity.

Qualified party. A person or organization with jurisdictional responsibility for, or professional expertise in, the terrain in question. Land management agencies, avalanche centers, and SAR organizations are qualified parties. A frequent user is not.

Provider. The organization that publishes the product and would make a conformance claim.


5. Conformance

5.1 Levels

Three levels. Each level includes all criteria from the levels below it.

Level Name What it requires Typical implementation cost
A Disclose The product states what it knows and marks what it does not Labeling and copy. No new data collection.
AA Calibrate The product relates its information to this user, this date, and these conditions Connecting data the provider already holds.
AAA Support the decision The product actively supports the go/no-go and the retreat New data collection or acquisition.

Levels describe the demand a criterion places on the provider, not the importance of the criterion. A Level A criterion is cheaper than a Level AAA criterion, not less important.

5.2 Conformance scope

Conformance is claimed against a declared scope. A provider presenting large numbers of objectives is not expected to satisfy every criterion for every objective.

5.2(a) A conformance claim states the scope it covers. Scope may be defined by jurisdiction, region, objective set, or product surface.

5.2(b) Objectives outside the declared scope are marked as such in the interface, at the point of use. A user viewing a non-scoped objective is told that it has not been assessed.

5.2(c) A provider may not claim conformance for a product as a whole while applying it to a subset. Partial conformance is stated as partial.

5.2(d) Where a criterion cannot be satisfied for an objective because the underlying information does not exist, the product states that the information does not exist. Absence disclosed is conforming. Absence rendered as blank space is not.

5.3 Claim format

A conformance claim states, at minimum: the version of this document, the tier under section 1, the level claimed, any per-guideline variance, the declared scope, and the date of assessment.

Example: ORCG 1.0, Tier 1. Level A across all guidelines, Level AA for Guidelines 2, 5, and 6. Scope: all presented objectives within Washington State. Assessed 2026-09-14.

A product operating at more than one tier states each. A planning application that both presents curated objectives and allows user-authored routes is Tier 1 for the former and Tier 3 for the latter, and states both.

A claim that omits scope or date is not a conformance claim.

5.4 Evaluation procedure

The core test. A criterion is satisfied when two independent reviewers, examining the same product interface for the same objective, independently reach the same conclusion that it is satisfied. A criterion that fails to produce reviewer agreement is defective and is reported for correction in the next version.

Procedure.

  1. Define the scope under evaluation, as in 5.2.
  2. Draw a stratified sample of presented objectives from within that scope. User-authored routes are not sampled. Stratify by at least difficulty rating, region, and popularity, so the sample is not dominated by well-documented flagship objectives. A minimum of 30 objectives, or the full set if fewer, is recommended.
  3. Evaluate each sampled objective against each criterion at the claimed level, using two independent reviewers who do not confer.
  4. Resolve disagreements with a third reviewer, and record every disagreement. Disagreement rate measures the quality of this document as well as the product.
  5. A criterion fails at the product level if it fails for any objective in the sample. Report the failure count alongside the pass or fail.
  6. Publish the sample size, the stratification method, and the disagreement rate alongside the claim. A claim without a stated method is not verifiable.

Reviewer independence. Reviewers may be internal to the provider. The requirement is that they do not confer before recording results, not that they are third parties. Self-assessment with a published method is acceptable.


6. The guidelines

Nine guidelines, forty-five criteria. Ordered by where in a person's experience the corresponding gap opens.

# Guideline Moment Design principle it descends from
1 Route provenance Choosing the objective Provenance and chart reliability (CATZOC)
2 Reference frame Sizing the objective Gulf of evaluation (Norman)
3 Consequence exposure Sizing the objective Affordance and signifier (Norman)
4 Response reality Sizing the objective Conceptual model and system image (Norman)
5 Temporal validity Committing to a date Visibility of system status (Nielsen 1)
6 Sample disclosure Forming the picture Graphical integrity (Tufte)
7 Decision architecture The go/no-go User control and freedom (Nielsen 3)
8 Field operability In motion Situationally-induced impairments (HCI)
9 Outcome symmetry The retreat Design for error (Norman)

Guideline 1: Route provenance

A product must disclose the origin and standing of the routes it presents.

Design principle. Provenance and source reliability. Nautical charts encode this directly through Categories of Zones of Confidence (CATZOC), a published A-to-D scale with a further "unassessed" category, describing how far a mariner should trust the survey behind each area. The confidence a user should place in a route is a function of its source, and the user cannot weigh it without seeing the source.

The failure. A route rendered as a clean line carries no indication of where it came from. An official, maintained, surveyed trail and a single user's GPS track through terrain that has no trail are drawn identically. So are a route that crosses private or closed land and one that does not, and a route generated by an algorithm and one walked by a person. The line asserts existence, legitimacy, and passability, and frequently asserts all three falsely.

Precedent. Nautical charts state survey reliability per area through CATZOC. Aviation charts distinguish published, surveyed procedures from user-entered waypoints. Cadastral and land-status data underlie the entire category of boundary-aware navigation. Encyclopedic reference requires each claim to carry a source before it is treated as established.

Criteria

1.1 Declare source (A). Each presented objective states its origin: official or land-manager data, editorial, user-contributed, or algorithmically generated.

1.2 Distinguish sanctioned from unsanctioned (A). The product indicates whether a route is an established, maintained trail or an informal line with no maintaining authority.

1.3 Flag land and access status (A). Routes that cross private land, closed areas, or seasonal restrictions are marked as such at the point of use.

1.4 State existence confidence (AA). Where a route's on-the-ground existence is unverified, derived from a single track, sparse data, or automated generation, the product states that it is unverified.

1.5 Support retirement and correction (AAA). A qualified party can flag a route as nonexistent, rerouted, closed, or misclassified, and the product reflects the change.

Techniques (informative)

Common failures (informative)

Rationale. Following a route that does not exist on the ground is a documented and rising cause of incidents. Two hikers were extracted from Medicine Bow Peak in September 2025 after an app placed them on a trail that was not there. The introduction of algorithmically generated routes drew direct warnings from search and rescue organizations that hikers following generated routes without cross-checking are at elevated risk. A route's origin determines how far a user should trust it, and it is the attribute these products almost never show.

Limitations. Provenance data is uneven. Land-status boundaries are well mapped in some jurisdictions and poorly in others, and the distinction between an established trail and an informal path is contested in the underlying open data. Marking a route unverified where data is merely sparse risks discouraging use of legitimate remote routes, the tension Guideline 6 also carries. Criterion 1.4 states unverified rather than unsafe for this reason.


Guideline 2: Reference frame

A product must disclose what its rating measures and what it assumes.

Design principle. Norman's gulf of evaluation, the distance between the state a system is in and a user's ability to interpret that state. A difficulty rating is a computed output. The interface displays the result and conceals the computation, leaving the user unable to judge whether the rating was ever about someone like them.

The failure. A difficulty rating carries three hidden variables: an assumed person, assumed conditions, and an implicit comparison set. Products disclose none of the three, so the rating reads as a property of the terrain when it is a claim about a relationship between terrain and a person who was never described.

Precedent. ATES v.2 rates terrain across five classes using eight parameters with published thresholds, and excludes daily conditions because terrain and conditions change on different clocks. The Drug Facts rule, 21 CFR 201.66, specifies both what must be disclosed and the exact order and format, on the finding that standardization rather than volume is what makes disclosure usable.

Criteria

2.1 Declare inputs (A). Any difficulty or exposure rating states the variables from which it was derived, available at the point the rating is displayed.

2.2 Declare assumptions (A). The rating states the person and conditions it assumes. At minimum: assumed fitness, assumed conditions, assumed daylight, assumed navigational demand.

2.3 Separate terrain from conditions (AA). A terrain rating does not vary with weather, season, or daily hazard. Conditions are expressed through a separate indicator governed by Guideline 5.

2.4 Provide a comparison anchor (AA). The rating is expressed relative to at least one objective the user can independently verify, rather than as a standalone adjective.

2.5 Calibrate to the individual (AAA). Where the product holds a user's completion history, the rating is expressed relative to objectives that user has already completed, with the difference stated.

Techniques (informative)

Common failures (informative)

Rationale. Fatigue and physical condition is the single largest contributing factor in the SAR evidence at 22.8 percent. It is a sizing failure, and sizing happens before departure using the information this guideline governs. Criterion 2.5 answers "hard for whom" rather than deferring it, and the data it requires already sits in the user's account.

Limitations. A disclosed assumption is a claim, and a claim carries liability that an adjective does not. This is the principal barrier to implementation. Objective trail measurement models already exist and are federally maintained: FSTAG specifies running slope, cross slope, and tread width to stated tolerances, and the Forest Service maintains Trail Class 1 through 5 with national design parameters. The measurement problem was solved for accessibility and has not been connected to difficulty.


Guideline 3: Consequence exposure

A product must present difficulty and consequence as separate variables.

Design principle. Norman's distinction between affordance and signifier. An affordance is what the world makes possible, and it exists whether or not anyone perceives it. A signifier is the perceptible signal that communicates it. A cliff band affords a fatal fall regardless of what any interface renders. Consequence exposure is the missing signifier.

The failure. Difficulty describes what an objective demands of a person who succeeds. Consequence describes what happens to a person who does not. These are orthogonal properties and frequently run in opposite directions. A steep, sustained climb on a graded trail through timber is high difficulty and low consequence. A flat, exposed traverse above a cliff band is low difficulty and unsurvivable consequence. A product reporting only the first reports that the second does not vary.

Precedent. The outdoor world has solved this repeatedly, and consumer software has adopted none of the solutions.

Criteria

3.1 Do not encode consequence in difficulty (A). Where a product publishes a difficulty rating, it states that the rating describes effort or technical demand and does not describe consequence.

3.2 Disclose consequence-bearing features (A). Known consequence-bearing features are identified for the objective.

3.3 Locate consequence on the route (AA). Consequence is expressed positionally rather than as a single summary value. It is a property of specific places rather than of an objective as a whole.

3.4 State the failure mode (AA). For each identified feature, the product states what happens in a failure: the outcome of a slip, a swim, a missed turn, or an arrival after dark.

3.5 Separate exposure from likelihood (AAA). Consequence exposure is presented independently of conditional likelihood, so a user can see that a feature is always severe while the probability of trouble there varies by day.

Techniques (informative)

Common failures (informative)

Rationale. The two leading causes of death on Park Service lands are drowning and falls. These are consequence events. They occur at specific features, not across whole objectives, and they are largely uncorrelated with the effort required to arrive at them. A rating system organized around effort cannot surface either.

The primitive exists in professional tooling and is absent from every consumer default surface. Slope angle shading in CalTopo and Gaia renders a terrain property that maps to consequence, and it lives in an overlay menu, off by default, aimed at users who already understand it.

Limitations. This is the hardest guideline in this document to implement. Consequence is positional, requiring per-feature data rather than per-objective data, and no national dataset provides it. It cannot be crowd-sourced naively, because a user who did not fall has no information about what would have happened. It carries the sharpest liability exposure here, because stating that a fall at a named location is likely to be fatal is a specific factual claim about a specific place.

Two factors make it tractable. Consequence is far more stable than conditions, so the data ages slowly and does not require the continuous labor Guideline 5 demands. And criterion 3.2 is a disclosure obligation rather than a modeling obligation: land managers hold most of that knowledge already.


Guideline 4: Response reality

A product that describes terrain must also describe the complexity of an emergency response.

Design principle. Norman's conceptual model and system image. A user builds a mental model of a situation from the signals a system provides. Where the system image is silent about the response environment, the user's model fills the gap with an assumption imported from everyday life, that help arrives quickly. In most terrain these products cover, that assumption is wrong by an order of magnitude.

The failure. Consequence exposure, Guideline 3, tells a person that a failure at a given place is severe. It says nothing about what happens next. Whether assistance is forty minutes or nine hours away, whether a call can be placed at all, and what an evacuation involves are the variables that convert a severe event into an outcome. Products display distance from the trailhead as a hiking statistic and never as a rescue statistic, though it is the same number.

Precedent. Wilderness medicine treats the response interval as a defining variable: the field is organized around the fact that definitive care is hours rather than minutes away, and protocols diverge from urban EMS for that reason. Aviation requires a named alternate before departure. Commercial diving, offshore work, and remote industrial operations require a documented evacuation plan as a condition of operating, because an activity's risk is inseparable from the response available to it.

Criteria

4.1 Disclose connectivity (A). The product states where along an objective a call for assistance can and cannot be placed, or states that it does not know.

4.2 State the response environment (A). The product identifies the responsible response jurisdiction for the objective and states, at minimum, whether response is volunteer, professional, or unavailable.

4.3 Express distance as response time (AA). Distance from the nearest road or trailhead is expressed in terms of evacuation implications, not only in terms of travel distance for a healthy party.

4.4 Locate the response interval (AA). Where response intervals vary materially along an objective, the variation is expressed positionally, consistent with criterion 3.3.

4.5 Reflect conditions in response (AAA). The stated response environment accounts for conditions that materially change it, including darkness, weather that grounds aircraft, and seasonal access closures.

Techniques (informative)

Common failures (informative)

Rationale. Severity and response together determine outcome, and a product disclosing only the first has told a user half of what they need. The Lafayette rescue described in issue 02 ran roughly twelve hours from the first call to the trailhead, on a peak under 5,300 feet, in a range with among the densest SAR coverage in the United States. Cellular coverage in national parks is highly inconsistent and in many parks nearly absent. Neither fact appears in any consumer product describing those places.

Limitations. Response intervals are estimates that vary with factors no product controls, and a published interval invites reliance on a number that may be wrong on the day. Criterion 4.3 requires implications rather than a promised time for this reason. The moral hazard question shared with Guideline 7, whether disclosing a slow response deters the marginal unprepared party or becomes ignored fine print, has not been studied. A disclosed response environment informs a decision; it does not transfer blame, and a provider using it for the latter satisfies the letter of the criterion and defeats its purpose.


Guideline 5: Temporal validity

A product must attach a clock to the risk information it presents.

Design principle. Nielsen heuristic 1, visibility of system status. The age and validity of conditional information is system state. An interface that does not render that state has silently reported a status of current.

The failure. Products present ratings and descriptions as static properties of an objective, teaching users that an objective is a fixed thing. Risk is a time-varying function of terrain and conditions, and an interface with no affordance for that variation claims the variation does not matter.

Precedent. An avalanche advisory's most important structural property is not its danger scale but its expiration. The product declares its own shelf life, refuses to be a property of the terrain, and is reissued by a human on a fixed cadence. Fire danger ratings, the UV index, and NWS watch, warning, and advisory tiering share the property.

Criteria

5.1 Timestamp conditional information (A). Every element whose accuracy depends on conditions displays when it was last updated.

5.2 Declare silence (A). Absence of recent information is rendered as an explicit state. A blank space is not conforming; it is indistinguishable from benign conditions.

5.3 Match the reporting period to the plan (AA). Freshness is reported relative to the date the user is planning for, not relative to today. A report from three days ago in a different season is displayed as what it is.

5.4 Expire conditional information (AA). Conditional information carries a stated validity window and visibly enters an expired state at its end.

5.5 Accept managed input (AAA). A qualified party with jurisdiction over the terrain can issue, update, and expire conditional information directly, without provider mediation.

Techniques (informative)

Common failures (informative)

Rationale. Insufficient equipment, clothing, or experience accounts for 8 percent of contributing factors, the signature of a party packing for an objective rather than for a day. Criterion 5.3 is the least implemented and highest value criterion in this guideline; seasonal mismatch is invisible under a conventional recency sort.

Limitations. Freshness at scale is a labor problem rather than a technology problem, and land managers are not staffed for it. The Olympic result is a single reportable success rather than the norm. Temporal design is also necessary and not sufficient: the avalanche forecast has carried an expiration for decades and is still systematically misread, with roughly 65 percent of North American users interpreting an exponential danger scale as linear.


Guideline 6: Sample disclosure

A product must disclose the shape of the user-generated sample it presents.

Design principle. Tufte's graphical integrity, the requirement that a representation not distort what the underlying data shows. This guideline descends from the ethics of statistical display rather than from usability practice.

The failure. Photo grids and review lists are samples presented as populations. The bias is knowable and directional: benign conditions are systematically overrepresented, because people photograph summits on clear days and rarely write detailed accounts of the attempts they abandoned.

Precedent. Clinical trial reporting requires n. Financial disclosure requires past-performance language because a filtered track record misleads by construction. Forecasting products surface observation density, on the principle that the confidence of an information product is a function of how much went into it and cannot be calibrated by a user who cannot see it.

Criteria

6.1 State the sample size (A). Counts are displayed for photographs and reviews.

6.2 Date and characterize each item (A). Every photograph and review carries its date and the conditions it represents.

6.3 Default to relevance (AA). Media and reviews are filtered by default to the conditions the user is planning for, rather than to recency or engagement.

6.4 Display the distribution (AA). The composition of the sample is shown, at minimum by month or season.

6.5 Render absence (AAA). Conditions with no coverage are displayed as explicit gaps rather than omitted from the interface.

Techniques (informative)

Common failures (informative)

Rationale. Criterion 6.3 is the highest-leverage criterion in this document relative to implementation cost.

Limitations. Surfacing a thin sample teaches users to discount lightly documented objectives, which are disproportionately the remote ones where caution matters most. A well-documented objective is popular, not safe, and a naive confidence display conflates the two. Criterion 6.5 renders absence rather than scoring confidence for this reason: it communicates the gap without issuing a verdict.


Guideline 7: Decision architecture

A product must expose the decision, not only the route.

Design principle. Nielsen heuristic 3, user control and freedom, defined around giving users a clearly marked emergency exit from a state they no longer want to be in. A bail-out point is an emergency exit in the literal sense the heuristic describes. The heuristic was published in 1994.

The failure. Route display communicates intent. It does not communicate the structure of the choice a party faces once the intent stops being sound: where they can exit, what retreat costs from here versus further on, and where the last inexpensive reversal lies.

Precedent. Instrument flight rules require a named alternate, and decision height specifies the altitude at which a choice must already have been made rather than deliberated. The decision is made in advance, in calm conditions, and the moment in the field is execution.

Criteria

7.1 Publish the exits (A). Bail-out points and egress routes are identified on the route.

7.2 Time the retreat (AA). Estimated retreat time is stated from each identified decision point.

7.3 Name the commitment point (AA). The point beyond which retreat cost rises materially is identified explicitly.

7.4 Support pre-commitment (AA). The user can set a turnaround time or condition before departure, recorded before the decision becomes difficult.

7.5 Surface the aggregate decision (AAA). Where the provider holds retreat data under Guideline 9, the locations and conditions under which parties most often turn around are surfaced on the objective.

Techniques (informative)

Common failures (informative)

Rationale. Darkness accounts for 6 percent of contributing factors and is rarely a lighting failure. It is the observable signature of a party that did not establish when it had to turn around.

Limitations. This is among the most expensive guidelines to implement. It requires per-objective terrain analysis, is not reliably crowd-sourceable, and has no engagement benefit. The moral hazard question, whether a legible retreat plan increases willingness to commit to terrain a party should avoid, has not been tested in this domain and is asserted in neither direction.


Guideline 8: Field operability

A product must keep field-critical information available under field conditions.

Design principle. Situationally-induced impairments and disabilities, an established body of HCI research concerning users whose capability is reduced by context rather than by permanent impairment. Cold, glare, precipitation, gloved hands, divided attention, and fear degrade interaction, and the research documents slower and less accurate target acquisition in cold conditions specifically. The conditions that produce backcountry emergencies are situational impairment conditions.

The failure. Every preceding guideline concerns information the product supplies. This one concerns whether that information exists at the moment of need. A capacitive touchscreen stops responding in driving rain. A screen is illegible in direct sun. A battery degrades in cold well ahead of its stated spec. An application that requires connectivity to display a route has no route where there is no signal. A product whose safety information becomes inaccessible in bad weather has not communicated it.

Precedent. Aviation checklists exist on paper in the cockpit of aircraft with glass panels, because the paper works when the panel does not. Marine charts are carried in printed form under the same reasoning. The principle is redundancy across failure modes rather than perfection within one.

Criteria

8.1 Provide a device-independent form (A). Safety-relevant information for an objective is available in a form that does not require the product to be operating: printable, exportable, or otherwise transferable off the device.

8.2 Function without connectivity (A). Route, consequence, and decision information for a saved objective is available offline, and the product states clearly which information is unavailable offline.

8.3 Remain operable with degraded input (AA). Critical information is reachable without precise touch input, accommodating gloved hands, wet screens, and single-handed operation.

8.4 Remain legible in field lighting (AA). Safety-relevant information meets contrast and type-size requirements sufficient for direct sunlight and for dark adaptation at night.

8.5 Degrade predictably (AAA). As battery, connectivity, or sensor availability declines, the product preserves safety-relevant function preferentially and tells the user what has been lost.

Techniques (informative)

Common failures (informative)

Rationale. A hiker rescued unconscious from Mount Lafayette in June 2026 could not operate his phone in wind-driven rain at the summit, and became lost as a result. A navigation aid that fails in the weather that produces emergencies is not available at the moment it is needed, and any decision support that lives only inside it inherits that failure. Conformance to Guidelines 1 through 7 is void where the information cannot be retrieved, which is why this guideline carries Level A criteria despite its late position.

Limitations. Field operability conflicts with the interface density that drives engagement, and no provider will accept a browsing experience designed for gloved hands. Criterion 8.3 scopes the requirement to critical information rather than to the whole product for this reason. Some of the failure is platform-level, since a provider cannot change how a capacitive touchscreen behaves in rain, and criterion 8.1 requires an off-device form rather than a working screen in response.


Guideline 9: Outcome symmetry

A product that records outcomes must be able to record more than one.

Design principle. Norman's design for error, which holds that systems should assume error and make recovery ordinary rather than exceptional. The issue is structural: a system can only support decisions it models, and these products model a single outcome.

The failure. Where completion is the only recordable outcome, retreat is not a lesser result but an absence of data, which is worse. The interface assigns the correct decision no value and the risky one a reward, at the moment the user is least equipped to discount it.

The mechanism is documented. The goal-gradient effect describes effort accelerating as a reward approaches. In the 2006 Kivetz, Urminsky and Zheng study, participants given a twelve-stamp reward card with two stamps pre-filled completed ten purchases faster than those given a blank ten-stamp card. Identical remaining effort, different perceived proximity, measurably different behavior. Progress indication changes how hard people push near the end.

Precedent. High reliability organizations make the stop recordable, routine, and non-punitive. Aviation established the go-around as a normal logged maneuver rather than a failure. Manufacturing gave every worker an andon cord and made pulling it an event that summons assistance rather than blame.

Criteria

9.1 Record the retreat (A). Turning around is a recordable outcome.

9.2 Weight outcomes equally (A). The retreat outcome is presented at the same visual and interaction weight as completion. It is not nested in a secondary menu.

9.3 Capture the reason (AA). A structured prompt records why, at minimum: weather, time, conditions, party, injury.

9.4 Do not penalize retreat (AA). Recording a retreat does not break a streak, reset progress, or reduce standing in any progress mechanic.

9.5 Return the aggregate (AAA). Aggregated retreat data is surfaced on the objective, including where and under what conditions parties most often turn around.

Techniques (informative)

Common failures (informative)

Rationale. Criterion 9.4 is where this guideline collides with the mechanic the product is built on, and it is the criterion that matters: a retreat that costs the user a streak is not a neutral outcome regardless of how it is labeled.

Guideline 9 is the cheapest guideline in this document and it generates the data the others require. Where parties turn around, when, and why is the calibration data missing from Guideline 2, the positional consequence data missing from Guideline 3, the conditions data missing from Guideline 5, the unbiased sample missing from Guideline 6, and the decision points that are prohibitively expensive to survey under Guideline 7. No product in this category collects it. The outcome was never modeled.

Limitations. No growth organization ships a feature whose stated purpose is to record not using the product. The path to adoption is that this is a data acquisition feature as well as a safety feature.


7. Adoption sequence

Start at Level A across all nine guidelines rather than at AAA on one. Level A is disclosure. It requires no new data, no partnerships, and no terrain analysis, and can be implemented by a provider with no external dependency. A product at Level A across the board is more honest than one at AAA on a single guideline.

Guideline 8 is a precondition, not a phase. Conformance to the informational guidelines is void where the information cannot be retrieved in the field. Verify 8.1 and 8.2 before claiming Level A anywhere else.

Guideline 9 before Guideline 7. Guideline 7 is among the most expensive and Guideline 9 is the cheapest, and Guideline 9 produces inputs that reduce Guideline 7's cost over time.

Guideline 3 is the long project. Begin the disclosure obligation in 3.2 immediately, since land managers hold the knowledge, and treat positional consequence data as a multi-year acquisition effort rather than a release.

Responsibility does not distribute evenly. Providers can reach Level A on all nine guidelines without external dependency. Land managers hold the data required for Guidelines 3, 4, and 5 and lack the interface to deliver it. Discovery platforms sit upstream of Guideline 6 and have no stake in the downstream outcome.


8. Open problems

Known gaps in version 1.0.

  1. Consequence data does not exist at scale. Guideline 3 asks for positional consequence information that no national dataset provides. It is the most valuable guideline here and the least implementable today.
  2. Response intervals are estimates with no standard method. Guideline 4 has no equivalent of a published carry-rate standard a provider could adopt, and the figures available are drawn from studies with different terrain, staffing, and aircraft assumptions.
  3. Guideline 6 has no upstream reach. Discovery happens on platforms with no stake in downstream outcomes and no plausible reason to adopt this.
  4. The moral hazard question is unresolved across Guidelines 4, 7, and 9. Whether better decision support increases or decreases risk exposure has not been studied in this domain. This document asserts an answer nowhere.
  5. The evidence base is dated. The SAR contributing-factor distribution covers 1992 to 2007 and predates smartphone trip planning.
  6. No party composition guidelines exist here. Fatigue and physical condition is the largest single contributing factor, and this document addresses it only from the terrain side. Group size, pace of the slowest member, experience mix, and trip-plan filing are candidates for version 2.
  7. Tier 2 obligations are the least settled part of this document. Whether a tile provider, an upstream open dataset, or the application consuming both carries obligation for a discarded attribute is answered in section 1.3 by assertion rather than by consensus. It is the provision most likely to change.
  8. No incident feedback loop is required. Nothing obliges a provider to ingest incident data from land managers or SAR organizations for objectives it presents.
  9. The transfer problem is unaddressed. Information is consumed before a trip, in calm conditions, and applied during it, by a group, under pressure. No interface design survives that transfer intact.

9. Versioning

Version numbers follow the pattern MAJOR.MINOR. A MINOR release may add techniques, clarify definitions, correct errors, and add criteria at existing levels. A MAJOR release may add or remove guidelines, change criterion levels, or change the conformance model, all of which invalidate prior claims.

Conformance claims cite the version they were assessed against. A claim against an earlier version remains valid for that version and does not carry forward.

Criteria found to produce reviewer disagreement under section 5.4 are rewritten or removed in the next version.


10. Changelog

1.0 (draft). Initial publication. Nine guidelines, forty-five criteria, three conformance levels. Adds definitions, a three-tier scope model keyed to whether the provider or the user authored the objective, conformance scoping, evaluation procedure, and per-guideline techniques and common failures to the six-guideline draft circulated privately. Guidelines 1 (route provenance), 4 (response reality), and 8 (field operability) are new in this version.