Once a fault is detected the system enforces and retains a safe state: the negation action (shutdown, restriction to a safe subset of functions, transfer to a redundant item) is defined per fault class, its negation time is bounded so that safe down time stays within what the TFFR requires, the safe state is held until authorised restoration after repair, and the retention of the safe state is itself protected against a second fault or an unsafe restart.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.