Global Risk Platform — Engineering Detail
RiskMap. Twelve perils under one MVP scope (Decision #1, resolved), each of which has to be answered on three different clocks: what is happening now, what the annualized baseline risk is, and how that baseline shifts under climate change. The matrix below is the build list — thirty-six cells, each one an element that has to exist, be wrapped, and interoperate with the other thirty-five.
Fig. 2 — The build matrix
rendvipyretechnics spread engine. The engine is portable; its fuel-model input is not — Pyrecast runs on LANDFIRE, which is US-only. A fuels layer per SERVIR region is the actual Clock 1 blocker.pyretechnics is deterministic, with no ensemble driver, so this is Monte Carlo over it: ignition and weather sampling, thousands of runs (Westerling precedent).climada_petals TC-surge on the same synthetic tracksFig. 3 — How the thirty-six elements interact
Fig. 3 — The interaction contract. Elements E1–E6 are specified below; every peril module plugs into the same three seams.
The companion exposure layer
The matrix above answers what hazard, on what clock. It deliberately does not carry exposure, because exposure is not a per-peril question — the same population grid, the same protected-area layer and the same building footprints are joined against all twelve perils on all three clocks. Building it once, as a service rather than a per-peril lookup, is what keeps thirty-six cells from becoming thirty-six data pipelines.
| Stack | Layer | Source & licence | Resolution / currency | Open question |
|---|---|---|---|---|
| People who is exposed | Population count & density | WorldPop — CC BY 4.0 | 100 m gridded, annual | Refresh cadence not agreed (Decision #17) |
| Social vulnerability | WorldPop age/sex structures + Meta Relative Wealth Index | 100 m – 2.4 km, static-ish | Which vulnerability index is authoritative — unresolved | |
| Nature what ecosystems are exposed | Protected areas & species range | WDPA / IUCN via IBAT (paid) or open GBIF + Planetary Computer | Vector, quarterly (WDPA) | Genuine licence-vs-build decision (Decision #17) |
| Ecosystem extent | RLCMS + ESA CCI land cover — shared straight from §06 | 10–30 m, annual | None — NRM already owns this pipeline | |
| Assets what physical stock is exposed | Building footprints | Google Open Buildings + Microsoft GlobalMLBuildingFootprints | Footprint-level; Global South coverage strongest | Deduplication where both cover the same area |
| Economic value proxy | LitPop — nightlights × population, CLIMADA-native | ~1 km, periodic | None — CLIMADA-native, comes free with Clock 2 | |
| Critical infrastructure | OpenStreetMap — roads, health facilities, schools, power | Vector, continuous | Completeness varies by country; needs a coverage flag |
SERVIR-AI/global-platform already overlays OpenStreetMap exposure assets against hazard rasters, under the stated guarantee that "every number is computed from real data, never generated by the model." That is this element, already running for one region. The build here is generalising it — not inventing it (Decision #12).
Build detail — the six seams that make the elements interoperate
Thirty-six hazard cells, three exposure stacks and five agents only add up to a platform if they meet at defined seams. These six are the whole of the interoperability story; everything else is a peril specialist's business.
E1 The HazardFootprint contract
Every one of the thirty-six cells — a Sentinel-1 flood extent, an OpenQuake shaking grid, a CMIP6 heat projection — emits the same object. This is the single most load-bearing decision in the platform: it is what lets the exposure join, the risk engine, and the agents be written once instead of twelve times.
Why the enum matters. confidence is not decoration. It is what lets tornado and wind gust ship at all: a CAPE-shear proxy enters the system as proxy, is rendered differently, and can never be silently averaged into a number labelled observed.
E2 The two-clock risk engine, one data model
Near-real-time monitoring and annualized baseline risk are genuinely different computations, and the temptation is to build them as two systems with two data models. Do not. CLIMADA already demonstrates the correct shape: Hazard, Exposure and Impact classes shared across both, with a separate Forecast class for the event-triggered path. Clock 3 is not a third engine — it is Clock 2 with a different forcing dataset and a scenario label attached.
The practical test: adding storm surge to Clock 3 should be a configuration and a dataset, not a new codebase. If it is not, E1 has been violated somewhere upstream.
E3 The exposure join service
A service, not a table. It takes a footprint and a requested exposure stack and returns the intersection with its own provenance and currency attached — so a downstream agent can state "1.2 M people, WorldPop 2024, 100 m" rather than an unsourced number. It resolves the People / Nature / Assets stacks specified above, and it is the same service the Food Security and NRM platforms call for their own exposure questions (§07).
E4 The peril-agent contract
Each agent MCP-wraps its peril's tools and encodes the workflow a specialist actually follows — not a thin model wrapper. The Flood Risk Agent reconciles a GEOGloWS forecast against an observed HydraFloods extent and flags the divergence rather than picking a winner; that reconciliation logic is the domain expertise, and it is what makes the agent worth building. Registration with the gateway (§02) is what makes it callable by the other platforms' agents.
E5 The confidence and provenance envelope
Six of the thirty-six cells are gaps. The platform's credibility depends on those six being visibly different from the other thirty, all the way through to the UI and the API — not just in a footnote. SERVIR-AI/global-platform's replayable, litestream-backed receipt, gated by a groundedness check before publishing, is the working precedent to generalise rather than reinvent.
E6 The access layer
Two consumption modes off one capability: LLM and agent applications reach it via MCP; dashboards, national warning systems and backend services reach the same computation via curated APIs. The standards below are not aspirational — CAP in particular is the format that carries an alert into a national warning channel, which is the difference between a risk platform and a warning system.
Interoperability standards
| Standard | Solves | Adoption |
|---|---|---|
| STAC | Discovering time/space-indexed hazard and EO data across sources | Near-default for cloud-native EO |
| OGC API | Web-native access to vector/raster risk layers | Strong and growing |
| CAP | One alert format into many national warning channels | Backbone of WMO/UNDRR Early Warnings for All |
| CF Conventions | Self-describing climate/forecast NetCDF output | De facto standard for climate/NWP output |
| HXL / HDX | Machine-readable humanitarian tabular exchange | Widely used across OCHA/cluster system |
Already built, not to be re-built
RiskMap
With ADPC, SE Asia hub — satellite + street-level imagery + grey literature behind an NL interface.
HydraFloods + GEOGloWS
SAR/optical surface-water extent, and discharge forecasting — complementary, not competing. Repo: Servir-Mekong/hydra-floods, active July 2025.
Pyregence / pyretechnics
Built by SIG-GIS — wildfire behavior forecasting, HRRR/NAM/RTMA-driven. Repo: github.com/pyregence, 8 repos, active Sept 2026. Reviewed §04. The library is genuinely reusable — pip-installable, EPL-2.0, in-house authorship. Pyrecast the service is California/US grid-safety scoped; what transfers to SERVIR regions is the library, not the service.
SERVIR-AI/global-platform
Live MCP server answering NL disaster-risk questions across 9 perils for SE Asia today — the only repo of 259 with an MCP endpoint.
Plus ClimateSERV (precipitation, active since 2015 — SERVIR/ClimateSERV2, updated June 2026), and a deep bench of hazard code in the hub orgs: flood_mapping_intercomparison, fierpy, RHEAS, lhasa, mrc_ffgs, hiwat_model_viewer — inventoried repo by repo in §02.
Where to partner, what to build
| Gap | Status | Partner |
|---|---|---|
| Probabilistic / annualized loss (AAL, PML) | Partner | RiskLayer — already the named in-development partnership. |
| Open-source fallback / benchmark | Partner | CLIMADA (ETH Zurich) — free, GPLv3, covers most perils via climada_petals. |
| Global multi-hazard alerting | Partner | GDACS — free, global, not yet integrated anywhere internally. |
| Storm surge, sea level rise | Partner | NOAA STOFS-2D / Copernicus Marine — open data, near-term risk accepted per Decision #1. |
| Tornado / wind gust | Partner + Build | NOAA SPC, ECMWF — genuine global coverage gap, new detection logic on open forecast fields. |
| Heat and cold index (all three clocks) | New build | ERA5 + CMIP6 WBGT — no reusable SERVIR asset exists; nine matrix cells depend on it. |
| H-E-V fusion engine | Partner + Build | OpenQuake (earthquake) + CLIMADA (climate perils) + IBF-system (trigger/alert layer). |
| Shared feature-extraction / eval harness | New build | TorchGeo + TerraTorch (IBM/NASA) + PANGAEA-bench. |
Domain agents
| Agent | MCP-wrapped tools | Workflow it encodes |
|---|---|---|
| Flood Risk Agent | HydraFloods (extent) + GEOGloWS (discharge) | Forecast → observed extent → reconcile → overlay exposure → flag divergence for review. |
| Wildfire Risk Agent | Pyregence / Pyrecast | Fuel/weather inputs → spread forecast → overlay exposure → escalate past threshold. |
| Probabilistic Loss Agent | RiskLayer + CLIMADA (same interface contract) | Take H-E-V bundle → run RiskLayer → cross-check CLIMADA → surface material disagreement. |
| Global Alert Watch Agent | GDACS feed | Poll → dedupe against native hazard agents → surface only new signals. |
| Global Risk Orchestrator Agent | OpenQuake + CLIMADA + IBF-system (RiskMap's NL interface) | Parse query → call peril agents via A2A → fuse → route through IBF-system triggers → cite sources and limitations → human-approval checkpoint, never autonomous. |
Use cases from the SERVIR archive
These are documented services with a named institution and a named decision — the demand evidence this platform is being built against. They are also the acceptance tests: if the matrix above is built correctly, every one of these becomes a query the orchestrator can answer rather than a bespoke tool someone has to maintain.
Flood emergency preparedness — Myanmar
- User
- Department of Disaster Management (DDM), Ministry of Social Welfare, Relief & Resettlement
- Tool
- Historical Flood Analysis Tool — Landsat 5/7/8 + JRC flood frequency + population
- Decision
- Where to pre-position emergency supplies, shelters and personnel, by ranking flood-prone areas instead of relying on manually collected local knowledge
- Matrix
- Flood × Clock 2 · People + Assets
HIWAT severe-weather forecasting — Bangladesh
- User
- Bangladesh Meteorological Department (BMD) — "has adopted the toolkit to enhance its operational forecasting"
- Tool
- HIWAT — 54-hour probabilistic rainfall, lightning, hail and supercell forecast
- Decision
- Whether and when BMD issues severe-weather warnings during the pre-monsoon and monsoon season
- Matrix
- Storm × Clock 1 · People
Streamflow + Flash Flood Prediction — Nepal
- User
- Department of Hydrology and Meteorology (DHM), Ministry of Energy, Water Resources and Irrigation
- Tool
- Streamflow Prediction Tool (10-day, 519 reaches) + HIWAT-driven Flash Flood Tool (48-hour, 12,428 reaches)
- Decision
- What goes into DHM's daily monsoon flood bulletin, and the forecast-based-financing actions triggered off it
- Matrix
- Flood × Clock 1 · People
Satellite flood forecasting — Bangladesh
- User
- Bangladesh Water Development Board — Flood Forecasting and Warning Centre (FFWC)
- Tool
- Jason-2 altimetry over the Ganges and Brahmaputra basins
- Decision
- How far ahead FFWC issues warnings — lead time extended from 3–5 days to 8 days, for an audience of ~80 million people
- Matrix
- Flood × Clock 1 · People
Community flood early warning — Malawi
- Users
- DoDMA, Department of Water Resources, DCCMS, Malawi Red Cross Society
- Tool
- GEOGloWS–ECMWF streamflow + telemetric water-level sensors, 21 rivers across 8 districts
- Decision
- When to activate community warnings and evacuation — during Cyclone Ana (Jan 2022) lead time went "from hours to days"
- Matrix
- Flood × Clock 1 · People
- Status
- Listed active — App Center entry
/detail/57, read directly from the live page 9 Sep 2026: one of 79 services, and not among the 5 marked inactive. Corroborated independently by WMO (Apr 2026) for the national EWS and the same institutions — DCCMS, DoDMA, Malawi Red Cross — though that source does not name the GEOGloWS/21-river component. The RCMRD confirmation is still worth having; it is no longer blocking.
Air Quality Explorer — Thailand, Laos, regional
- Users
- Thai Pollution Control Department, GISTDA, Laos MONRE, UN ESCAP
- Tool
- SE Asia AQ Explorer / AQ Tracker — fire hotspots plus PM2.5, CO, CO₂, methane
- Decision
- How authorities regulate and time agricultural burning, and what advisories they issue during haze episodes
- Matrix
- Air pollution × Clock 1 · People
Air quality forecasting — El Salvador, Costa Rica
- Users
- MARN (El Salvador); IMN (Costa Rica)
- Tool
- MODIS aerosol optical depth visualisation plus a nationally customised CMAQ forecast system
- Decision
- When MARN issues public air-quality alerts and which emissions-control and public-health measures to trigger
- Matrix
- Air pollution × Clocks 1–2 · People
Forest Fire Detection and Monitoring — Nepal
- User
- Department of Forests and Soil Conservation (DoFSC), Ministry of Forests and Environment
- Tool
- Forest Fire Detection and Monitoring System, including a fire-danger outlook module
- Decision
- Where forest managers allocate suppression resources and when to schedule controlled burns
- Matrix
- Wildfire × Clocks 1–2 · Nature + People
Anticipatory action for disaster and climate resilience
- Users
- Mekong River Commission; ASEAN AHA Centre
- Tool
- Satellite and geospatial early-warning products feeding impact-oriented warnings
- Decision
- What anticipatory, pre-impact actions member countries take ahead of floods and droughts
- Matrix
- Flood + Drought × Clock 1 · all three exposure stacks
Reservoir Assessment Tool — Lower Mekong
- User
- Mekong River Commission and its member countries
- Tool
- RAT-Mekong — reservoir storage and outflow assessment and forecasting
- Decision
- Reservoir operation and basin planning for flood and drought management
- Matrix
- Flood + Drought × Clocks 1–2 · Assets
Hydrometeorological monitoring — Colombia
- Users
- IDEAM; UNGRD (National Disaster Risk Management Unit) as designated end-user
- Tool
- IDEAM GEOGloWS portal, under the IDEAM–CIAT agreement for SERVIR Amazonia
- Decision
- National hydrological forecasting and disaster-risk-management action by UNGRD
- Matrix
- Flood × Clock 1 · People
National hydromet portals — Peru, Ecuador, Brazil
- Users
- SENAMHI (Peru); INAMHI (Ecuador); CEMADEN (Brazil)
- Tool
- GEOGloWS ECMWF Streamflow Service delivered through national Tethys portals
- Decision
- Water-resource management and flood forecasting by the national hydromet agencies themselves — explicitly built so they operate and maintain the tools independently
- Matrix
- Flood × Clock 1 · People + Assets
Four further Global Risk services are documented as tools without a named downstream government user on their public pages, and are carried here as capability evidence rather than demand evidence: HYDRAFloods (Lower Mekong flood mapping), LHASA-Mekong (landslide situational awareness), Mekong X-Ray (multidimensional flood vulnerability) and West Africa Flash Flood Vulnerability Mapping (ICRISAT-led consortium).