Skip to main content
INSIGNIA.
Engage
EXERCISE0001
PG. SUB · kumbh-operations
DOC · INS-EXR-EXERCISE202609REV · 2026.Q2CLASS · DISCUSSION DRAFTPRACTICE · Consulting exercise§ · 7
PROPOSALEXERCISE / 2026.09
Read in
/State-Gov-India/

One Fact

Crowd operations doctrine for a Kumbh-scale gathering, 2027

PUBLIC SECTOR · CROWD OPERATIONS

This file is a consulting exercise: operating doctrine and service design prepared at proposal stage. Nothing on this page has shipped. Every number is either a proposed acceptance target or an illustrative operating concept, and the evidence ledger at the end says which.

/ 01
Read this first

For the reader who will not scroll. Six plain answers, the four questions leadership asks, and the promises this proposal refuses to make. Everything after this section is the mechanism.

What this is
One State capability for movement, safety and verified action during a Kumbh. Not another information app. The same system plans a pilgrim's journey, guides the crowd inside the mela, and gives the administration one verified picture of the ground.
What changes for a pilgrim
One app that helps before the trip, becomes a simple safety tool inside the gathering, and keeps working when the mobile network does not. Lost children, medical emergencies, family check-ins and help in the pilgrim's own language, without the phone becoming a tracking device.
What changes for an officer on the ground
An exact task, a safe way to reach it, the actions allowed, and the proof required to close it, on a tablet that keeps working offline. No more guessing which instruction is current.
What leadership sees
One screen with four answers instead of every camera feed: where pressure is rising, which exits and routes remain open, which action is underway and who owns it, and whether it actually worked on the ground.
What the State decides now
Approve a 15-day joint discovery and one controlled pilot corridor. Name the officers who own routes and incidents. Authorise access to the official map and the command centre interfaces. Scale only after field proof.
What this does not promise
Zero stampede. Perfect prediction. Every pilgrim using the app. Unbroken mobile service. Any AI making the final call. Technology shortens the time from warning to action and proves whether the action worked; officers remain accountable.
The four questions leadership asks, and what the screen answers
  1. 1
    Where is pressure rising now?
    Zone 3, density and route demand rising near the B-2 approach.
  2. 2
    Which exits and routes remain open?
    7 of 8 exits open. B-4 closed. Safe egress floor protected.
  3. 3
    Which action is underway?
    Diversion plus holding. Speakers S-11 and S-12. Two units. Acknowledged.
  4. 4
    Did it work?
    Movement reduced. Route physically verified at 10:55.

Sample answers are illustrative. No individual case detail appears on the leadership view; lost-child and medical cases open only for the officers handling them.

/ 02
Stakes

A Kumbh at Haridwar is a temporary city that runs for a 97-day season with ten major bathing festivals, routes that change by the hour, and peak days measured in lakhs of simultaneous sessions. The previous cycle at Prayagraj in January 2025 showed the limit of sensing on its own: linked control rooms, a large camera estate and digital lost-and-found all worked, and a crush still happened, because density alerts did not prevent closed exits and stagnant crowds, and navigation could look clear on a phone while ground travel took hours. The State's brief was therefore not another information app. It was one State capability for movement, safety and verified action: live operational truth on routes, pressure, hazards and teams; earlier and calmer intervention on 15 to 30 minute signals with protected exits; individual help at scale for lost persons, medical identity, families and language; and a reusable, India-hosted, government-controlled asset. Insignia's proposal, delivered as a discussion draft, asked the State to approve a 15-day joint discovery and one controlled live-route and response pilot, and to scale only after field proof.

/ 03
Approach
01

One authorised operating fact per route order

Sensors and users disagree. CCTV shows presence, the app shows intent, drones show a snapshot, gates count flow, beat teams confirm what is physically true. None of them publishes. A route order is the only thing that does: a versioned fact (Route order v27: Bridge B-2 closed, Blue Lotus diversion active) with an owner (Traffic Control Officer), an effective time, an expiry (11:10 unless verified and reissued), the evidence that justified it (beat photo, CCTV, order) and a public status that shows its own age (LIVE, 42 seconds old). App, public web, PA and VMD, beat tablets, response units and partner maps all read the same order. Detection is an input. Only an authorised, time-bound operating fact drives public instruction and field work.

02

Close the loop, do not add a dashboard

The value is not another screen. It is a governed loop: field signal (app, QR, IVR, officer) into one common picture (map, heatmap, cases), authorised by a named officer against a rule with an expiry, communicated to the affected zone through app, SMS, PA and VMD, acted on by beat, medical or civic teams, and verified by movement, an after-photo and a physical reopening. The loop is complete only when the crowd moved, the hazard cleared or the route safely reopened, and the outcome is visible. Closed in the system is not the final state; verified safe on the ground is.

03

Forecast 15 to 30 minutes ahead, intervene reversibly

A useful forecast says what changed, how certain it is, which reversible intervention it suggests and who must approve it. The proposal's forecast panel shows why the picture moved (rail arrivals plus 6,200 in 20 minutes, parking P-1 at 92 percent, route requests up, gate 4 inflow up, a beat confirming a stationary crowd) and proposes a bounded response (hold gate 4 inflow for 8 minutes, activate the Blue Lotus diversion, review again at 10:55) that a named officer approves. A forecast is decision support. It is never an automatic route order.

04

Counter the jam 500 km upstream

Ordinary navigation shows roads. The State needs a time-stamped operating plan for approach corridors, parking and open routes. Bookings, group plans, route searches and parking demand give an early view of pressure before vehicles reach the city, so the administration can stagger departure windows, activate remote holding, rebalance parking, coordinate rail and bus releases against available exits, and pre-position teams. The measure is whether arrival time actually changed. The last kilometre is then governed by one live, expiring route order.

05

Keep the guidance alive when the network dies

Inside the geofence, social media and large media sync are deferred; route, SOS, family and official alerts take priority. When cellular data is congested or gone, critical guidance survives through four layers: the device (offline official map, meeting point, cached route with signed expiry), fixed help points (QR and wristband scan, printed location code), public low-bandwidth channels (SMS, IVR, PA, VMD, physical signs) and the official local network (beat tablets, local Wi-Fi, compatible sensor nodes). Every screen declares whether what it shows is LIVE, CACHED, QUEUED or UNKNOWN. No signal means the screen says so; it never guesses.

06

Aggregate the crowd, protect the person

The normal operating map uses aggregated cells with a minimum group threshold; cells below the privacy threshold are suppressed or merged. Exact personal data opens only for a chosen service or a verified emergency, to a named role with an active case, with minimum fields, every view logged, and sharing that ends with the case. Lost-child, medical and family cases live in protected workspaces, not on the leadership map. Each role (leadership, police command, CCTV operator, health, civic, beat inspector) sees a workspace assembled from role, zone, purpose, time and active case. AI may cluster reports, translate approved content or propose a priority; an authorised officer publishes the public-safety fact.

/ 04
Doctrine

Technology cannot promise zero stampede. It can shorten warning-to-action time, keep exits visible and prove whether an intervention changed crowd movement. The control doctrine is five refusals.

No blind closure.

Every closure shows remaining exit capacity. Safe egress, open capacity that stays visible before any route or VIP decision, is the centre of the control circle, not a side effect of it.

No alert without an owner.

A named officer and a field unit receive every alert. An alert that belongs to nobody is a signal that was never turned into action, which is exactly how sensing fails.

No mass message by default.

Target the affected route, zone and language. One locked operating fact becomes different local instructions by speaker, direction and language without changing the safety instruction, then stops automatically when the route changes.

No resolved without proof.

Movement or physical condition is rechecked: an after-photo, a scan, an officer or a sensor. Administrative closure is not physical proof. The public status changes only after service and a second verification.

No AI final authority.

Models propose priority, cluster repeated reports and translate approved text. Authorised officers decide and publish. Accountability stays human; the audit trail shows which is which on every case.

/ 05
Architecture

Six stations arranged around the integrated command and control centre. Field signals from the app, help-point scans, IVR and officers enter at the top and the loop runs clockwise: common picture, authorise, communicate, field action, verify, back to signal. Every station reads and writes the same versioned operating fact held at the centre, with its owner, effective time, expiry and evidence. Existing systems (ICCC, CCTV and video management, drones, gates and scanners, rail and bus feeds, PA, VMD, telecom) stay authoritative for their own facts; the integration contract aligns time and location, gives each route, incident and facility one operational identity, shows confidence and disagreement rather than hiding them, applies privacy and authority at the boundary, and exchanges versioned facts and events, not shared databases. Nothing is ripped out and replaced.

1FIELD SIGNALapp · QR · IVR · officer2COMMON PICTUREmap · heatmap · cases3AUTHORISEofficer · rule · expiry4COMMUNICATEapp · SMS · PA · VMD5FIELD ACTIONbeat · medical · civic6VERIFYmovement · after-photoICCCONE AUTHORISEDOPERATING FACTowner · effective · expiry · evidenceloop closes only when the crowd moved and the field confirmed itFIG. i · one fact · operating loop
/ 06
Field stories

Three timed events an officer or a parent would recognise. Each shows the doctrine enacted: one route order across every channel, a private case that never becomes a broadcast, a responder who sees only what the case needs.

story 1

Bridge closed, route changed

Traffic Control Officer · Beat T-14 · a pilgrim on the B-2 approach

A field observation becomes one approved route order across the map, the signs, the local speakers and the staff, then expires only after verification.

  1. 10:15

    Normal. B-2 carries the flow. Route version R-118 is field verified, no restriction.

  2. 10:22

    Closure. A beat photo and camera 22 show density rising at B-2. The Traffic Control Officer publishes route order v27: B-2 closed, B-4 and the holding lane active, expiry 11:10.

  3. 10:23

    The pilgrim's app shows one banner: B-2 closed, follow B-4 via Blue Lotus 17. Only speakers S-11 to S-14 and the signs on the affected approach carry it, in Hindi, Telugu and Bengali.

  4. 10:31

    Beat T-14's tablet receives the task, the safe approach and the evidence required. The order is cached on the tablet with its expiry in case the network drops.

  5. 10:50

    Verified. The engineer's check and the beat's after-photo confirm the crowd moved. The order is closed, B-2 reopens, every channel refreshes at once.

What stayed closed

Nothing was announced to the whole mela. Nobody could reopen the bridge from a screen. Closed in the system counted for nothing until the field said so.

story 2

A child found safe, without a public announcement

A parent · a help-point volunteer · the nearest officer

A free wristband, a private alert, nearby help points and human verification reduce search time without exposing the child to strangers.

  1. Entry

    At the gate the family takes a same-day photo and a free opaque band, code UK27-A4F9. A public scan of the band reveals no name and no phone number.

  2. 10:36

    Last seen at Blue Lotus 17. The parent opens a private case and chooses who receives it: family group, trusted friends, police and help desks. Nearby public stays off.

  3. 10:41

    A volunteer scans the band at the Blue Lotus 17 help pillar. Family and authorised staff receive the exact location. The public screen at the pillar shows only: please escort to official help.

  4. 10:46

    The nearest officer is assigned a protected route to the pillar. The parent's screen shows the officer en route, not a map of everyone else's children.

  5. 10:52

    Guardian verified by the officer, case closed, the exceptional location access expires with it. The audit trail keeps who viewed what and why.

What stayed private

No public broadcast. No photo on a big screen. Clothing narrowed the search; it never proved identity. A human verified the handover.

story 3

A medical SOS, and what the responder was allowed to see

A pilgrim with diabetes · Medical Post M-3 · Beat T-14

The nearest medical team receives the patient's location, an open response route and only the minimum emergency facts needed to act.

  1. Before

    The pilgrim keeps an emergency medical ID in the app: critical allergy, condition, essential medicine, language, one emergency contact. It is not a full health record.

  2. 11:02

    Medical SOS pressed near Har Ki Pauri. The system receipt is shown honestly: request received. An offline queue is never displayed as team dispatched.

  3. 11:03

    The nearest eligible team at Medical Post M-3 is selected, not simply the nearest pin. Route status and crowd conditions are checked before the assignment is sent; an open response lane is reserved.

  4. 11:04

    The team sees allergy, condition, essential medicine, language and contact. Nothing else. The beat officer keeps the lane clear on a task that expires when the case does.

  5. 11:19

    Care begins. The exceptional access expires; the audit record of actor, purpose, case and fields viewed remains.

What the team never saw

The pilgrim's full journey, unrelated photos, social profile, family trail. Medical details stay self-reported unless independently verified; emergency access is purpose-limited, time-bound and fully audited.

Times, route ids, band codes and post names are illustrative operating stories from the proposal, not records of events.

/ 07
Journey phases

A whole-journey companion outside the gathering becomes a simple, safety-first tool inside the geofence. Utility before the event earns installation; safety inside earns trust; memories after exit sustain relevance. The same service changes priority with place: rich planning outside, proactive guidance on approach, safety first inside, memory after exit. Emergency is an overlay, not a place.

Phase
Outside
Plan · book · belong
Phase
Approach
Prepare · stagger
Phase
Inside
Safety first
Overlay
Emergency
One incident screen
Phase
After exit
Resume · remember
Screen

Plan, verified stay, route and tickets, friends and community, attractions.

ETA and holding, parking reassignment, offline map ready, media reduced.

Open route now, my family, help and SOS, meeting point, nearest services.

One incident screen and responder status. Nothing else competes for attention.

Journey memory, queued media sync, feedback, next yatra.

Location

Off by default. Shared only for a chosen feature such as a booking.

Approximate corridor or itinerary intent, not a trail.

Anonymous heatmap cell if consented. Exact location only for chosen family or an active case.

Exact location for the minimum authorised team, for the life of the case.

Stops, unless the user keeps family sharing on.

Network

Normal media and social. Offline pack downloads in the background.

Maps and alerts rise. Large media begins to defer.

Safety, map and low-data text first. Social media and large media deferred.

Highest priority. An offline SOS is never shown as dispatched until confirmed.

Queued media resumes. Normal priority returns.

Visibility

Family and friends as selected. Public posts voluntary.

Administration sees aggregate demand by corridor, never a member trail.

Safety cases logged, purpose-limited and time-limited.

Every sensitive view and change is purpose-limited, logged and audited.

Event sharing expires. The user controls the album and the community.

The geofence changes relevance, network priority and data minimisation. It never creates permission by itself: consent, purpose, role, audit and expiry still decide who may see what.

/ 08
Degradation ladder

Core route, family and emergency functions degrade visibly across cached guidance, fixed help points and official local infrastructure. The ladder is ordered from the pilgrim's own phone outward; each layer carries less but survives more.

layer 1
live / cached

On device

Pilgrim phone
  • Offline official map and meeting point
  • Emergency instructions and family code
  • Cached route with signed expiry and version
  • Bounded on-device assistant, no live model call
layer 2
local

Fixed help point

Help pillar · kiosk
  • QR and wristband scan, officer lookup
  • Local case entry when the phone is dead
  • Printed location code on every pillar
  • Meeting-point check
layer 3
broadcast

Public low-bandwidth

SMS · IVR · PA · VMD · signs
  • Official warning by zone and language
  • Call guidance through IVR and help desk
  • Crowd direction from speakers and variable-message displays
  • Physical signs carry the same instruction
layer 4
controlled

Official local network

Beat tablet · local Wi-Fi · sensor nodes
  • Task dispatch to beat tablets, offline-ready
  • Local map and case entry on staff devices
  • Scanner, sensor and selected wearable data
  • Compatible LoRa nodes as a bounded pilot only
Every screen declares its freshness
LIVECurrent official fact, version and age shown.
CACHEDLast verified copy, with its expiry.
QUEUEDSent by the user, not yet delivered.
UNKNOWNNo current answer. Do not guess.

An offline SOS is never displayed as “team dispatched” until a server or an authorised help point confirms it. Ordinary phones do not receive LoRa; peer relay and LoRa nodes are optional, signed, bounded pilots after field testing.

/ 09
Privacy circles

One person can belong to several circles, but every circle receives only the information the user has chosen for that purpose. Heatmaps show the crowd, not the person. Individual data opens only for a chosen service or a verified emergency.

FAMILYTRUSTED FRIENDSCOMMUNITYAUTHORISED STATEPUBLICMEFIG. ii · five circles, one person
  • FAMILYsafe check-in · meeting point · low-data text
  • TRUSTED FRIENDSinvited check-ins, approximate zone
  • COMMUNITYbus status, group alerts, meeting-point demand
  • AUTHORISED STATEanonymous cells normally, exact only for a verified case
  • PUBLICvoluntary posts only
Information typeFamilyFriendsCommunityPublicState
Safe check-in
Meeting point
Exact live location
State: active case only
Group arrival plan
State: aggregate demand
Public post
Lost-child case
State: named role + case
Heatmap sample
anonymous cell, consented
default only when enabled not shared
What leadership sees

Aggregated cells with a minimum group threshold. Cells below the privacy threshold are suppressed or merged. Route pressure, incident totals by category and responder positions carry no person identity.

What opens a protected case
  • Consent or a verified emergency
  • A named role and an active case
  • Minimum necessary fields
  • Every view and export logged
  • Sharing ends with the case or journey

The geofence never creates permission by itself.

/ 10
Security commitments

Security expressed as seven State commitments: where data lives, who controls keys, what AI may do, who may view records, and how every action is proven. Numbered so a reviewer can cite one in a file note.

  1. 1

    Government control

    Accounts, repositories, encryption keys and logs sit under State-approved custody. Retention rules and deletion workflows are the government's, not the vendor's.

  2. 2

    India-only processing

    Production and disaster recovery run in a government data centre or an approved India region. No cross-border citizen-data path.

  3. 3

    Consent by purpose

    Heatmap participation, family sharing, medical ID and personalised guidance are separate, understandable choices. A geofence never creates permission by itself.

  4. 4

    Minimum access

    Role, zone, case, purpose and time determine the visible fields. Lost-child or life-threatening medical access is temporary, role-limited and fully logged.

  5. 5

    Encryption and tokenisation

    Stored and transmitted data are protected. Sensitive values are revealed narrowly, to the person handling the case, for as long as the case is open.

  6. 6

    Bounded AI

    No China-hosted models, APIs or processing. No silent model training on citizen photos, medical data, location or messages. AI may cluster, translate or propose; it never makes the final public-safety decision.

  7. 7

    Audit and independent testing

    Views, changes, exports, recovery and security controls generate evidence. Independent security testing and a disaster-recovery rehearsal happen before go-live, not after.

Non-negotiableNo cross-border citizen-data pathNo hidden trainingNo unlogged break-glassNo public individual heatmap

Designed for India's data-protection framework and CERT-In directions. Final policy, retention, incident and audit language require the State's legal, cyber and data-governance approval.

/ 11
Access matrix

No officer or operator sees everything. Each workspace combines only the information and actions needed for that role, zone and active purpose. This is an operational access model; the technical spine is attribute-based access control per NIST SP 800-162.

Role · what the workspace showsAggregate mapProtected casePublish alertAssign taskView evidenceClose / reopen
Leadership
critical zones, exits open, unit readiness, decisions pending
Police command
sector picture, priority cases, route orders, deployment
CCTV operator
camera wall with current order, gate count, app reports beside the feed
Health team
medical cases, open response lanes, minimum emergency facts
Civic officer
facility cases, contractor queue, service clocks, closure proof
Beat inspector
own beat, assigned tasks, safe approach, required evidence
full, role-approved limited, case-bound not available

Role, zone, purpose, time and active case determine the workspace. The same identity may move between roles only after authorisation; a volunteer screen never becomes an officer screen. Every sensitive view is logged, and offline authority on a beat tablet is bounded by beat, shift, task and expiry, then rechecked on reconnection.

/ 12
Operations readiness

The leadership screen as it would look on a peak morning, the severity clocks that make 24x7 support a measurable commitment, and the drills the programme must pass before anyone calls it ready.

Leadership view · illustrative · 10:42LIVE
3
critical zones
7 / 8
exits open
11
priority cases
86%
units ready
2
rumour clusters
Four answers
What is happening now?
Crowd pressure rising at the B-2 approach; Gate 4 inflow above plan.
What may happen next?
If unchanged, the Blue Lotus corridor reaches the intervention threshold in 18 minutes.
Who is acting?
Traffic Sector 2, Beat T-14, PA zones S-11 and S-12. Acknowledged.
Did it work?
Diversion adoption up; density falling; bridge stays closed pending the field check.
Decisions requiring a signature
  1. 1
    Extend the Blue Lotus diversion to 11:10
    Traffic Control Officer
  2. 2
    Move two platoons to the Gate 4 holding line
    Sector Commander
  3. 3
    Approve the local rumour correction in three languages
    Public Information Officer
  4. 4
    Keep B-2 closed pending the engineering check
    Bridge Safety Officer

No individual case detail is shown on the leadership view.

24x7 peak-event support · severity clocks
Severity 1
  1. Report
    0
  2. Acknowledge
    10 min
  3. Contain
    30 min
  4. Core restore
    2 hr
Severity 2
  1. Report
    0
  2. Acknowledge
    30 min
  3. Service restore
    4 hr
  4. Review
    next business day

During all notified bathing festivals and peak windows, with a named command lead, platform SRE, GIS and route support, incident support and provider coordination on duty. Service credits and penalties are tied to notified SLA measures. Final severity definitions and exclusions belong in the RFP and contract.

Year-one commitments
  • 12-month defect warranty
  • Government repository and runbooks
  • Administrator and developer handover
  • Disaster-recovery rehearsal
  • Daily, weekly and post-incident reviews
  • Optional years 2 to 5 operations and maintenance
Mandatory operating drills · the programme is accepted when these pass, not when screens look good
  1. 01
    Route closure and expiry
    one fact on all channels, expiry honoured
  2. 02
    Peak crowd with medical SOS
    egress protected while a case is served
  3. 03
    Rumour cluster
    local correction measured, not broadcast
  4. 04
    Lost-child band scan
    private case, guardian check
  5. 05
    Cellular degradation
    cache, QR, PA and tablets carry on
  6. 06
    Civic closure
    contractor plus second check before public status
  7. 07
    Speaker-zone failure
    backup speaker and expiry
  8. 08
    Service restart and duplicate
    one logical outcome, no double dispatch

Each drill produces an acceptance pack: measured result, trace and log, screen recording, field sign-off, rollback result and a named owner for residual risk. Acceptance is witnessed by the owning State department.

/ 13
Scope and gates

The State can choose the complete vision, but the safety foundation is frozen first. Optional pilots must not delay route truth, incidents or field readiness. The programme rail ends every stage with an acceptance gate; the go-live gates cannot be skipped.

Core for 2027

Must be production-ready before peak operations.

  • ·Live route truth and diversions
  • ·Incident, SOS and dispatch
  • ·Family QR and reunification
  • ·Medical ID and multilingual help
  • ·ICCC, PA/VMD and field integration
  • ·Offline maps, help points and audit
Selectable pilots

Adopt only after bounded field proof in one corridor.

  • ·Verified stay and vendor registry
  • ·Connected QR/RFID for selected groups
  • ·Speaker-level automation
  • ·Local Wi-Fi and official sensor nodes
  • ·15 to 30 minute crowd forecast
  • ·Community and volunteer matching
Future reuse

Expand once the event foundation holds.

  • ·Wider pilgrimage and tourism network
  • ·Full booking and commerce rails
  • ·Journey memories and social community
  • ·Other Kumbh, Char Dham, Kanwar
  • ·Stadium and civic gatherings
  • ·Disaster and evacuation support
Programme rail · each stage ends with an acceptance gate
  1. gate 0
    15-day discovery
    owners, official GIS, interfaces, SOPs
  2. gate 1
    Core safety
    routes, incidents, QR family and alerts
  3. gate 2
    Field pilot
    one corridor, help points, real teams
  4. gate 3
    Hardening
    security, scale, low data, India DR
  5. gate 4
    Dress rehearsal
    peak-day and combined-failure drills
  6. gate 5
    Operations
    freeze, 24x7 war room, measured outcomes
Go-live gates that cannot be skipped
Route owner namedOne corridor provenField teams trainedPeak load certifiedDR and rollback provenNo peak-day experiments

Every gate produces a measured result, a field sign-off, rollback evidence and a named owner for residual risk.

The Day-15 package · what the State holds at the end of discovery
basis for the pilot, the RFP and the contract
  1. 01
    Approved pilot map
    One corridor, official GIS layers, route ids and the field owners who sign for it.
  2. 02
    Dependency register
    Every State, third-party and vendor dependency with an owner, baseline and fallback.
  3. 03
    RFP-ready scope
    Core, selectable pilots and future reuse, frozen at the tier boundaries above.
  4. 04
    Hosting and IP terms
    India custody option, key ownership, source and runbook transfer, public-sector reuse rights.
  5. 05
    Acceptance and SLA matrix
    Targets, drills, evidence pack and severity clocks as contract language.
  6. 06
    Implementation schedule
    Gates 1 to 5 against the bathing-festival calendar, with the freeze date.
days 1-3
Owners and evidence: routes, incidents, privacy
days 4-6
Pilot corridor: official GIS and field walk
days 7-9
Interfaces and hosting: ICCC, PA, CCTV, India servers
days 10-12
Scope and acceptance: SLA, tests, dependencies
days 13-15
Approval package: pilot, RFP, price, IP, schedule
/ 14
Who provides what

A credible programme names what the technology team controls, what the State must provide, what remains a third-party dependency, and what nobody should claim.

We commit
  • Versioned route and incident workflows
  • Secure, audited access for every role
  • Field task assignment and closure proof
  • Load, failure and disaster-recovery testing
The State provides
  • Named route and incident owners
  • Official GIS and route orders
  • Police, health and civic SOPs
  • ICCC, PA and CCTV interface access
Third-party dependency
  • Telecom and message delivery
  • Map and transport provider quotas
  • Existing camera and speaker health
  • Government procurement timelines
We do not claim
  • Zero stampede
  • Perfect prediction
  • Universal app participation
  • Unbroken cellular service or AI final authority

The dependency register is a Day-15 deliverable. Each third-party item carries an owner, a measured baseline and a fallback before the pilot corridor goes live.

/ 15
Challenges
Challenge · 01

Density alerts that never became action. The 2025 lesson was that more sensors do not compensate for constrained exits, stagnant crowds and delayed operational decisions.

Design response

Make the route order the unit of governance, not the alert. Each order carries an owner, an effective time, an expiry and evidence, and the loop counts as closed only when movement is verified on the ground. Leadership sees four answers, not every feed: where pressure is rising, which exits and routes remain open, which action is underway, and whether it worked.

Challenge · 02

Rumour outruns the official fact. Bridge B-2 collapsed, all exits closed, run toward the station: repeated claims arrive through the app, WhatsApp, help desks and voice notes faster than any channel can answer.

Design response

Repeated questions become a verification task, never an automatic announcement. Three checks (route order, CCTV or gate, beat officer) produce one authorised fact that a named authority publishes to only the affected people and places, in their language, with an expiry. The effect is measured after the message: repeated questions fall, diversion use rises, the alert expires on time.

Challenge · 03

Cellular collapse inside the geofence. Ordinary phones are not represented as receiving LoRa; peak-day networks queue or drop exactly when instructions matter most.

Design response

A four-layer degradation ladder with declared freshness on every screen. A signed, cached route order with expiry lives on the device; help pillars carry printed location codes and scanners; SMS, IVR, PA and VMD carry the same instruction; beat tablets stay offline-ready with bounded authority. An offline SOS is never shown as dispatched until confirmed.

Challenge · 04

Individual privacy under a crowd heatmap. The State needs presence, intent and confusion by zone; it must never hold a public individual trail, silently train models on citizen photos, or let a geofence create permission.

Design response

Aggregate cells with suppression thresholds for the normal map; protected case workspaces opened by consent or a verified emergency, a named role and active case, minimum fields, logged views and automatic expiry. Data stays in India in a government or approved India region; the government owns encryption keys, access records, retention rules and deletion workflows; no China-hosted models, no silent model training, no unlogged break-glass.

Challenge · 05

Sensors disagree with users, and a digital sample is easily mistaken for the whole crowd. Two app-active devices among a hundred estimated visitors is useful for intent, not a headcount.

Design response

A calibrated estimate from six sources: the app sample (intent, questions, destination), CCTV (presence, direction, density), gates (flow through fixed points), transport (arriving demand), field checks (physical truth and coverage gaps) and the event plan (known attractors and timing). The output states its confidence (an illustrative 118 plus or minus 12 people, medium-high, 35 seconds old). Low digital participation triggers more signs, volunteers, PA and field verification, never profiling of individuals.

/ 16
Proposed stack

Channels

  • ·App and PWA on Android and iOS, with a low-data safety mode inside the geofence
  • ·WhatsApp and SMS for official alerts, IVR and help desk for non-smartphone users
  • ·PA and VMD with per-speaker zones, direction and language, repeat interval and expiry
  • ·Physical signs, help pillars and printed location codes carrying the same instruction

Field devices

  • ·Beat tablets, offline-ready, task authority bounded by beat, shift, task and expiry
  • ·QR and RFID help points; opaque QR wristbands for children and vulnerable persons
  • ·Same-day clothing photo at entrance for attribute-assisted search, never identity proof
  • ·Compatible LoRa sensor nodes and peer relay as optional, signed, bounded pilots

Integration contract

  • ·Existing ICCC, CCTV and video management, drones, gates and scanners, rail and bus, PA, VMD, telecom, field tablets
  • ·Align time and location: every observation carries a common clock, zone and map reference
  • ·One operational identity per route, incident, facility or person-case reference
  • ·Show confidence and disagreement; conflicting app, camera or field signals create a verification task
  • ·Privacy and authority applied at the boundary: only permitted role, purpose and minimum fields cross
  • ·Versioned APIs and events; no shared databases, no rip-and-replace

Hosting and custody

  • ·India-only processing and disaster recovery, government or approved India region
  • ·Option A: State data centre, government accounts, keys, logs and operating access
  • ·Option B: dedicated private India region with State-approved key custody and 24x7 managed operations
  • ·Government owns encryption keys, access records, retention rules and deletion workflows
  • ·No China-hosted models, APIs or processing; only government-approved India-hosted or self-hosted models
  • ·No silent model training on citizen photos, medical data, location or messages; consent by purpose
  • ·Designed for India's data-protection framework and CERT-In directions; final policy approved by the State

Assurance

  • ·Acceptance evidence pack per feature: measured result, trace and log, screen recording, field sign-off, rollback result, residual-risk owner
  • ·A feature is complete only when its normal path, denial, duplicate, restart, network loss, privacy and recovery behaviour have been tested and accepted
  • ·Recovery objectives: critical-service recovery under 15 minutes, critical-state data-loss under 60 seconds, India DR rehearsal before go-live
  • ·Drills, severity clocks and year-one commitments are set out under Operations readiness above
/ 17
Try it

Route Order Desk

Walk one route order through its lifecycle: propose, check, approve, publish, verify, expire. Pick a field signal, flip the mandatory gates, and try to publish before the checks pass. Once published, the same fact fans out to five channels with a freshness state on each; simulate carrier congestion and WhatsApp drops to QUEUED, never LIVE. Advance the clock past the expiry and every channel flips to EXPIRED until you reissue. Reopening is only available after the field has verified. The refusals are the doctrine.

1 · pick the field signal
  1. now
    Propose
  2. step 2
    Check
  3. step 3
    Approve
  4. step 4
    Publish
  5. step 5
    Verify
  6. step 6
    Expire / reopen
Route order
v27 · Bridge B-2 closed
Use Blue Lotus 17 via the Green Route. Keep the medical lane clear.
clock
10:42
Owner
Traffic Control Officer
Effective
on publish
Expires
28 min after publish
Zones
B-2 approach · Blue Lotus · Medical lane
Public status
not public
Evidence attached
  • Beat T-14 photo, crowd stationary near B-2
  • CAM 22, density rising
  • B-4 open, egress floor 2 exits for 8,000 people
Mandatory gates before publication
2 · you confirm the two open gates, then run checks
  • Field evidence attached to the fact (photo, officer note or sensor event)AUTO
  • One version, one expiry: 28 min TTL, reissue required afterAUTO
Optional · network condition
One fact, every channel
  • App / public web
    NOT ISSUED

    Waiting for an authorised order. Nothing is broadcast from a draft.

  • WhatsApp / SMS
    NOT ISSUED

    Waiting for an authorised order. Nothing is broadcast from a draft.

  • PA / VMD
    NOT ISSUED

    Waiting for an authorised order. Nothing is broadcast from a draft.

  • Beat tablets
    NOT ISSUED

    Waiting for an authorised order. Nothing is broadcast from a draft.

  • Partner maps
    NOT ISSUED

    Waiting for an authorised order. Nothing is broadcast from a draft.

Same fact, same expiry, every channel. Local instruction differs by speaker, direction and language; the safety instruction does not.

Audit trail · order v27
  1. 10:42Signal: Beat T-14 photo, crowd stationary near B-2. Draft order opened.
/ 18
Acceptance targets
Targets

These are proposed tender acceptance targets, accepted only through measured scripts, field drills, failure injection, security testing and signed State evidence. They are not claims of proven event-scale performance. Reach targets in the proposal: 1 crore registered identities or devices, 50 lakh peak-day active users, 10 lakh simultaneous sessions, 100,000 public map and facility reads per second, 2,000 critical transactions per second sustained with a 5,000 per second burst.

Route change to core channels
< 60 s
proposed target
Route + SOS availability, peak windows
99.99%
proposed target
Incident receipt, 95 of 100 requests
< 2 s
proposed target
Heatmap refresh
15-30 s
proposed target
highlowPRESSUREreview threshold10:30EARLY SIGNALroute searches risinggate inflow +18%exits open 3 / 410:42AUTHORISED ACTIONholding H-3 activeB-4 diversion publishedexits protected10:55VERIFIED EFFECTflow changed: yespressure fallingfield check doneFIG. iii · one fact · detect to verified effect, illustrative
  • Route owner named and one corridor proven before any scale funding
  • Field teams trained; peak load certified against the stated targets
  • Disaster recovery and rollback proven in an India region before go-live
  • No peak-day experiments: the core is frozen, pilots stay bounded
  • State receives source code, designs, runbooks, test and DR assets, with perpetual public-sector reuse rights
Addressee

Prepared for [STATE GOVERNMENT] as a discussion draft ahead of a 97-day operating season with ten major bathing festivals. Requested decision: nominate accountable route and incident owners, authorise GIS and ICCC interfaces, and approve one live pilot corridor. The Day-15 package converts the concept into an RFP-ready implementation and acceptance plan.

Evidence

Proposal stage. No production deployment and no measured results. This file publishes the operating doctrine, service design and acceptance criteria from the discussion draft; commercial figures, hosting prices and unaudited third-party statistics are withheld. Official GIS, legal notices, device surveys, CCTV and ICCC interfaces, operating SOPs, service levels and procurement language require joint validation before award and production use.

How to read the numbers on this page
Documented

A cited event result or source statement, with audit limits stated.

The January 2025 Prayagraj crush as public record; the State's brief and requested decision.

Proposed target

A tender acceptance objective to be jointly sized and tested.

Propagation, availability, receipt, refresh, reach and severity-clock figures.

Commercial estimate

An indicative price or hosting basis, not a notified government rate.

Withheld. Not published on this site.

Illustrative

A map, adoption ratio, scanner spacing or workflow concept for discussion.

Route ids, speaker ids, zones, the Route Order Desk scenarios, the detect-to-action timeline.

REGISTER · CONSULTING EXERCISEIN.↓ § 06
File a brief