Training-Simulator Mode
The same interface, driven by the twin instead of live diagnostics, so operators rehearse both machines — including unsafe-to-create upsets — before and between real runs.
Rehearse on the real interface, not a mock-up
Operators build reliable intuition only by practicing on the interface they will actually use. Training-simulator mode runs the full control-room surface — 3D twin overlay, dashboards, alerting, countdown — driven by the KRONOS-CTRL twin instead of live diagnostics. Nothing about the operator's mental model changes between training and operation, which is why the twin-first approach is central while the machines are still being built toward first-of-a-kind first tritium (~2030).
Scripted scenarios, including the unsafe ones
The simulator can present situations that would be reckless to create on real hardware: a breeder disruption sequence, a cascading diagnostic failure that forces the twin onto imputed inputs, a burner plug-density excursion, a magnet quench precursor at the 16.84 T peak field. Operators rehearse the recognition, the triage, and the countdown decision under realistic time pressure, and learn where the AI's confidence should and should not be trusted.
- Breeder: disruption avoidance, vertical-stability loss, shape drift off delta -0.30
- Burner: plug-density excursion, ambipolar-potential collapse, DEC grid fault
- Cross-cutting: diagnostic loss and imputation, alarm floods, out-of-distribution models
- Scenarios reuse the what-if console and recorded real shots as seeds
Measuring and closing the loop
The simulator is also where the interface itself is tested. Operator situational awareness is probed with SAGAT-style freezes, cognitive load is estimated during scripted upsets, and any display that spikes load or degrades awareness is revised. Notification thresholds, alarm rationalization, and layout are all tuned against simulator evidence rather than opinion. Trainee performance and the interface's performance improve together.
Training draws directly on the what-if scenario console and recorded incident replays as scenario seeds, and its findings feed cognitive-load and notification design. The same firewall applies: the simulator can never reach live actuation.