Autonomy & Doctrine
How autonomy (ALFUS), Rules of Engagement, Courses of Action, and tasking logic relate to STANAG 4817 — what the standard carries, and what it deliberately leaves to policy and the system.
BLUF
STANAG 4817 is an interoperability contract, not autonomy or ROE doctrine. It does not set an autonomy level, encode Rules of Engagement, or generate Courses of Action. What it does is carry, in a vendor-neutral form, the things a command node and an executing system must agree on:
- the tasking intent — a doctrinal verb (Survey, Escort, Engage, …),
- the limits — machine-readable constraints derived from ROE and airspace/EMCON policy,
- the logic — conditions that gate or sequence tasks,
- the authority — who issued and may change the task,
- the capability — what each node advertises it can interpret and honour.
The decisions — how autonomous to be, whether ROE permit an action, which COA to fly — stay with policy, the human command, and the system's own software. 4817 is the wire between them.
Separation of concerns
The single most common point of confusion is where each thing lives. ROE, autonomy policy, and COA generation are not in the message format — they sit on either side of it.
The anatomy of a task
Everything doctrinal attaches to one structure —
TaskDescriptionAndDetails.
A single task bundles:
| Field | Carries | Doctrinal meaning |
|---|---|---|
description | the task verb and its parameters | what to do — the COA intent |
constraints | constraints with a strength | the limits (ROE / airspace / EMCON) |
conditions | task conditions | the logic — when it may run |
authority | Authority | who tasked / may change it |
template_conditions | reusable condition templates | standardised behavioural rules |
On the return path, TaskFeedback and TaskResult
carry constraints_compliance — the node reporting whether it stayed inside the
limits it was given.
Autonomy and ALFUS
ALFUS (Autonomy Levels for Unmanned Systems, the NIST framework) scores a system on three axes — Mission Complexity, Environmental Complexity, and Human Independence. It is a way to describe how much a system decides for itself; it is not part of 4817.
4817 is deliberately autonomy-level-agnostic. The same Engage or Survey
task can go to a remotely-piloted platform or a fully autonomous one — the
difference is only who computes the Course of Action. A node advertises the
interop-visible slice of its autonomy through
Capabilities:
task_capabilities— which task verbs it can accept,task_conditions_mode— how much conditional logic it understands (SIMPLE_TASK_STATE→FOLLOW_TASK_STATE→COMPLEX, orNOT_SUPPORTED),task_conditions_template— whether it accepts reusable condition templates,predict_capabilities— whether it can predict/evaluate a task before acting,global_constraints— which standing limits it honours.
The higher the autonomy, the more abstract the task a node can be given — and
the more the COA is computed on-board. 4817 spans the whole spectrum because the
task verb set ranges from concrete (Navigate, Reposition) to mission-level
(Reconnaissance, Screen, Picket).
Rules of Engagement
ROE are policy — national and coalition rules on conduct and the use of force. 4817 does not contain ROE and cannot enforce them. What it carries is the machine-readable limits derived from ROE and airspace control, expressed as constraints:
- Strength —
ConstraintStrengthEnum:REQUIRED(hard limit),ADVISORY,OPTIONAL. - Standing limits —
GlobalConstraintTypeEnum: keep-in / keep-out zones (ZONE_INCLUSION/ZONE_EXCLUSION), emission control (EMCON_ROUTINE/EMCON_ESSENTIAL/EMCON_SILENCE), lost-link behaviour (LOST_LINK_BEHAVIOR_RTH/LOITER/LAND/TERMINATE), speed and separation minima. - Authority —
AuthorityandRoleEnumrecord who issued a task and in what command role.
Use-of-force task verbs exist in the model — Engage,
Neutralize, Destroy, Warn, Deter, Jam — but they are tasking vocabulary,
not authorisation.
4817 transports intent and limits; it does not grant authority. Weapon-release
authority, positive identification, and ROE compliance remain with the human
command and the C2 system, governed by policy. A REQUIRED constraint is a
contract the executing node agrees to honour and reports against
(constraints_compliance) — it is not a substitute for a lawful order.
Courses of Action
A COA is the plan to accomplish a task. 4817 touches the COA at three points:
- Prescribed COA — the tasker sends a fully-specified task (route, waypoints, stand-off) and the node executes it. Suited to low-autonomy systems.
- Delegated COA — the tasker sends an abstract task plus constraints, and the node plans its own COA. Suited to higher-autonomy systems.
- Predicted COA — with
PredictTaskandpredict_capabilities, a tasker can ask a node to evaluate a task before committing — lightweight COA analysis / wargaming.
Execution is then observable: TaskFeedback streams progress and state, and
TaskResult returns the products and a ResultReason. The COA generation is the
node's autonomy; 4817 carries its inputs (task + constraints + conditions) and
its outputs (feedback, result, prediction).
Logic — conditions and sequencing
The behavioural "logic" people ask about is expressed as
task conditions. A
TaskCondition gates or
sequences tasks by kind
(TaskConditionTypeEnum):
SIMPLE_TASK_STATE— run when another task reaches a state (e.g. start B when A isSUCCEEDED).FOLLOW_TASK_STATE— track another task's state continuously.COMPLEX— boolean trees of conditions for richer triggering.
A node only accepts the logic it advertises in task_conditions_mode, so the
tasker knows in advance whether to pre-compute the sequence or let the node handle
it.
Doctrine → 4817, at a glance
| Concept | Where it lives | 4817 construct |
|---|---|---|
| Autonomy level (ALFUS) | system + policy | advertised via Capabilities; implied by task abstraction |
| Rules of Engagement | policy / human command | constraints + authority; compliance reported in feedback/result |
| Course of Action | the node (or tasker) | task description + PredictTask; outcome in TaskResult |
| Tasking logic | the message | TaskCondition |
| Command authority | C2 system | Authority / RoleEnum |
What 4817 does not do
- It does not set or certify an autonomy level.
- It does not encode ROE policy or grant release/engagement authority.
- It does not generate Courses of Action.
- It does not guarantee a node will honour a constraint — it gives the node a way to agree to and report on one.