Consider a level-crossing wayside controller for a light-rail operator: the trackside electronics that reads the axle counters, decides the crossing state, drives the barriers and lamps, and reports to the control centre. The procurement contract sets its reliability target: MTBF ≥ 20,000 hours. Four subsystems, four different design owners, and no detailed design yet. Every number below is an illustrative teaching value; the arithmetic is the method's.
The target converts to the working currency first: λ* = 10⁶ / 20,000 = 50 failures per 10⁶ hours of rate budget to distribute.
Level 1: feasibility of objectives
At this stage nothing exists but the architecture and engineering judgement, so the level-1 split uses feasibility-of-objectives ratings, scored 1–10 against written ground rules and reconciled between two senior engineers:
| Subsystem | Intricacy | State of art | Perf. time | Environment | Weight w | Share | λ (f/10⁶ h) | Allocated MTBF |
|---|---|---|---|---|---|---|---|---|
| A · Axle-counter interface | 5 | 3 | 8 | 7 | 840 | 19.1% | 9.56 | 104,600 h |
| B · Interlocking logic unit | 8 | 6 | 8 | 4 | 1,536 | 35.0% | 17.49 | 57,200 h |
| C · Trackside power module | 4 | 2 | 8 | 9 | 576 | 13.1% | 6.56 | 152,400 h |
| D · Communications gateway | 6 | 5 | 8 | 6 | 1,440 | 32.8% | 16.39 | 61,000 h |
| Σ | 4,392 | 100% | 50.0 |
Reading the ratings: everything operates continuously (performance time 8 across the board), the interlocking unit is the most intricate and least proven (8 and 6), the power module is simple mature technology but the most exposed (environment 9), and the gateway sits in the middle on everything. The multiplication does the rest: the two hard subsystems claim two-thirds of the failure allowance between them, and the simple, exposed power module is asked to be the most reliable single element, 152,400 hours, precisely because nothing about it justifies a large share of the budget.
Level 2: ARINC inside the interlocking unit
A month later the interlocking logic unit has a preliminary parts list, and its owner runs an early parts-count prediction over its three assemblies: processor card 6.0, I/O card 9.0, power supply 7.5: 22.5 f/10⁶ h predicted against a budget of 17.49. The unit is 29% over budget before detailed design has begun; the allocation now decides how that pain is distributed. ARINC shares it in proportion to today's estimates:
| Assembly | Predicted λ | Share | Allocated λ | Allocated MTBF | Implied improvement |
|---|---|---|---|---|---|
| B1 · Processor card | 6.0 | 26.7% | 4.66 | 214,600 h | ×0.777 |
| B2 · I/O card | 9.0 | 40.0% | 7.00 | 142,900 h | ×0.777 |
| B3 · Power supply | 7.5 | 33.3% | 5.83 | 171,500 h | ×0.777 |
| Σ | 22.5 | 100% | 17.49 |
The last column is ARINC's signature: every assembly is asked for the same 22% rate reduction, because the method preserves relative standing by construction. Whether that is fair is an engineering conversation (perhaps the I/O card has easy derating wins and should absorb more), and that conversation is exactly what the table exists to trigger. Its output, whatever is negotiated, re-enters as a weighted-factor split.
An AGREE view of the gateway
The communications gateway's internals differ in a way ratings cannot see: duty cycles and criticality. Its radio module runs whenever the system runs; its fallback cellular path is energised rarely; and losing the fallback alone does not take the system down. That is AGREE territory. Over a 730-hour reporting month, with the gateway's own budget (61,000 h) as the goal: −ln R* = 730 / 61,000 = 0.01197.
| Unit | Modules nᵢ | Importance wᵢ | Operating tᵢ | Allocated MTBF θᵢ |
|---|---|---|---|---|
| Radio module | 40 | 1.0 | 730 h | 91,500 h |
| Fallback cellular path | 15 | 0.4 | 200 h | 26,700 h |
| Antenna interface | 5 | 1.0 | 730 h | 732,000 h |
The pattern is the method's teaching: the complex, always-on, indispensable radio carries a demanding target; the fallback path, rarely energised, survivable when lost, is allowed to be an order of magnitude worse; and the five-module antenna interface must be extremely reliable because simplicity leaves it no claim on the budget. Note the two operating-time columns quietly doing real work: AGREE is the only method in the family that saw the fallback path's 200 hours at all.
The feasibility check bites
The budgets now meet reality. Fleet history for comparable trackside power supplies shows demonstrated MTBFs around 90,000 hours, and subsystem C's allocated 152,400 hours sits far beyond anything the technology has shown. The budget is infeasible not because C is weak but because the ratings gave it too small a share of the failure allowance. The rebalance shifts allowance from the gateway, which vendor data shows is comfortably placed:
| Subsystem | Before | After | New MTBF budget |
|---|---|---|---|
| C · Trackside power module | 6.56 | 11.00 | 90,900 h, inside demonstrated capability |
| D · Communications gateway | 16.39 | 11.95 | 83,700 h, still above vendor-supported levels |
| Σ (with A, B unchanged) | 50.0 | 50.0 | budget conserved |
Downstream numbers move with it: the gateway's AGREE sub-targets tighten when its budget drops to 83,700 hours and get re-run. That is not churn; it is the point: an allocation is a living negotiation between the target and the evidence, and every re-run leaves the tree more honest than it found it.