Platform Ecosystem — Engineering Plan
Global Risk · Food Security · Natural Resource Management
04

Global Risk Platform — Engineering Detail

RiskMap. Twelve perils under one MVP scope (Decision #1, resolved), each of which has to be answered on three different clocks: what is happening now, what the annualized baseline risk is, and how that baseline shifts under climate change. The matrix below is the build list — thirty-six cells, each one an element that has to exist, be wrapped, and interoperate with the other thirty-five.

Fig. 2 — The build matrix

Clock 1 · Near-real-timeWhat is happening now — event-triggered, minutes to days
Clock 2 · Annualized baselineWhat it costs in an average year — AAL, PML, exceedance curves
Clock 3 · Climate-adjustedHow the baseline moves — CMIP6 / ISIMIP forced
Earthquakenot climate-driven
PartnerUSGS ShakeMap / PAGER event feed → shaking footprint
PartnerOpenQuake (GEM) hazard + fragility curves → AAL
Out of scopeSeismicity is not climate-forced — baseline only
Floodfluvial · pluvial
Built — reuseHydraFloods SAR/optical extent + GEOGloWS discharge
PartnerCLIMADA river-flood on the GloFAS/JRC historical event set
Partner + buildISIMIP-forced discharge; recompute return periods per scenario
Droughtmeteorological · agricultural
Built — reuseClimateSERV SPI (CHIRPS/IMERG) + NOAA VHI/ESI; rendvi
PartnerSPI/SPEI return periods over the 40-year CHIRPS record
PartnerCMIP6 SPEI / ISIMIP drought indices, bias-corrected
Wildfirebehavior · burn probability
Reuse + buildFIRMS active fire (global, today) + pyretechnics spread engine. The engine is portable; its fuel-model input is not — Pyrecast runs on LANDFIRE, which is US-only. A fuels layer per SERVIR region is the actual Clock 1 blocker.
New buildBurn probability — pyretechnics is deterministic, with no ensemble driver, so this is Monte Carlo over it: ignition and weather sampling, thousands of runs (Westerling precedent).
Partner + buildFire Weather Index under CMIP6 — season length and severity
Storm / tropical cyclonewind · track
PartnerNOAA NHC / JTWC advisories, IBTrACS best-track
PartnerCLIMADA TC module — synthetic track sets, wind fields
PartnerCLIMADA TC under CMIP6 SST forcing — frequency and intensity shift
Heatwavehumid heat
New buildERA5 + GFS/ECMWF heat index; no reusable SERVIR tool today
New buildHeat-index exceedance return periods from the ERA5 record
New buildCMIP6 wet-bulb globe temperature — the highest-signal climate peril
Air pollutionPM2.5 · haze
Built — reuseSE Asia AQ Explorer + FIRMS hotspots + Sentinel-5P
New buildAnnual PM2.5 exposure-days against a WHO threshold
GapNo accepted climate-adjusted AQ method — ship clocks 1 and 2 only, say so
Storm surgecoastal
PartnerNOAA STOFS-2D, global, ~6-hourly
Partnerclimada_petals TC-surge on the same synthetic tracks
Partner + buildCompound surge + SLR — the joint distribution, not two separate layers
Sea level risetrend, not event
Out of scopeA trend has no event clock — nothing to monitor in near-real-time
PartnerCopernicus Marine altimetry trend × coastal DEM inundation
PartnerIPCC AR6 / NASA sea level projections by scenario and year
Tornadoglobal gap
Gap — regionalNOAA SPC (US) / ESWD (EU, sparse); CAPE-shear proxy elsewhere
Gap — regionalNo global catalogue exists to compute a return period from
Gap — researchCMIP6 convective proxies are research-stage, not operational
Wind gustglobal gap
Gap — proxyECMWF / GFS gust forecast fields — modeled, never observed
New buildERA5 gust return periods — computable, just not yet computed
Gap — low confidenceCMIP6 wind extremes carry wide model spread
Extreme coldcold spell
New buildERA5 + GFS cold index, mirroring the heat index code path
New buildCold-spell return periods from ERA5
New buildCMIP6 cold extremes — declining in frequency, shifting in place
Built inside SERVIR — reuse, do not rebuild Adopt an external open tool or dataset New build work, on top of an open foundation Genuine gap — ship with an explicit confidence flag Deliberately out of scope for this clock
What the matrix says at a glance. Four cells are already built and only need wrapping. Twelve are adopt-a-partner. Eleven are real build work. Six are gaps that should ship labelled rather than quietly proxied. Three are deliberately empty. The bottom-left corner is the risk: tornado and wind gust are weak on every clock, and they were added to scope by Decision #1 with that risk explicitly accepted — this is the picture that decision was accepting.

Fig. 3 — How the thirty-six elements interact

Copernicus CDS / GloFAS NASA FIRMS NOAA NHC / SPC / STOFS ECMWF / GFS USGS ShakeMap IBTrACS / ERA5 Ingestion → common staging, every product cataloged as a STAC item §07 SHARED LAYER Hazard modeling — twelve peril modules, three clocks each EQ FLOOD DROUGHT FIRE CYCLONE HEAT AIR SURGE SLR TORNADO GUST COLD every module emits the same object — HazardFootprint (E1) Shared exposure join (E3) — resolved once, consumed by every peril and every clock PEOPLE — WorldPop · age/sex · Relative Wealth Index NATURE — WDPA/IBAT · RLCMS land cover (§06) ASSETS — Open Buildings · LitPop · OSM lifelines Clock 1 — near-real-time engine Event-triggered. CLIMADA Forecast pattern. Answers: who is affected, right now. Clocks 2 & 3 — annualized + climate-adjusted engine AAL, PML, exceedance curves. CMIP6 / ISIMIP forcing. Answers: what to plan and finance against. one H-E-V data model, two computations — never two data models (E2) Peril agents, MCP-wrapped (E4) — registered in the Agent2Agent registry (§02) Flood Risk Agent Wildfire Risk Agent Probabilistic Loss Agent Global Alert Watch Agent Global Risk Orchestrator Agent — RiskMap's NL interface HUMAN-APPROVAL CHECKPOINT · NEVER AUTONOMOUS PUBLICATION ACCESS — OGC API · STAC catalog · CAP alert feeds · HXL/HDX humanitarian exports (E6)

Fig. 3 — The interaction contract. Elements E1–E6 are specified below; every peril module plugs into the same three seams.

The companion exposure layer

The matrix above answers what hazard, on what clock. It deliberately does not carry exposure, because exposure is not a per-peril question — the same population grid, the same protected-area layer and the same building footprints are joined against all twelve perils on all three clocks. Building it once, as a service rather than a per-peril lookup, is what keeps thirty-six cells from becoming thirty-six data pipelines.

StackLayerSource & licenceResolution / currencyOpen question
People
who is exposed
Population count & densityWorldPop — CC BY 4.0100 m gridded, annualRefresh cadence not agreed (Decision #17)
Social vulnerabilityWorldPop age/sex structures + Meta Relative Wealth Index100 m – 2.4 km, static-ishWhich vulnerability index is authoritative — unresolved
Nature
what ecosystems are exposed
Protected areas & species rangeWDPA / IUCN via IBAT (paid) or open GBIF + Planetary ComputerVector, quarterly (WDPA)Genuine licence-vs-build decision (Decision #17)
Ecosystem extentRLCMS + ESA CCI land cover — shared straight from §0610–30 m, annualNone — NRM already owns this pipeline
Assets
what physical stock is exposed
Building footprintsGoogle Open Buildings + Microsoft GlobalMLBuildingFootprintsFootprint-level; Global South coverage strongestDeduplication where both cover the same area
Economic value proxyLitPop — nightlights × population, CLIMADA-native~1 km, periodicNone — CLIMADA-native, comes free with Clock 2
Critical infrastructureOpenStreetMap — roads, health facilities, schools, powerVector, continuousCompleteness varies by country; needs a coverage flag
The exposure layer is the reuse point, not the hazard layer. SERVIR-AI/global-platform already overlays OpenStreetMap exposure assets against hazard rasters, under the stated guarantee that "every number is computed from real data, never generated by the model." That is this element, already running for one region. The build here is generalising it — not inventing it (Decision #12).

Build detail — the six seams that make the elements interoperate

Thirty-six hazard cells, three exposure stacks and five agents only add up to a platform if they meet at defined seams. These six are the whole of the interoperability story; everything else is a peril specialist's business.

E1 The HazardFootprint contract

Every one of the thirty-six cells — a Sentinel-1 flood extent, an OpenQuake shaking grid, a CMIP6 heat projection — emits the same object. This is the single most load-bearing decision in the platform: it is what lets the exposure join, the risk engine, and the agents be written once instead of twelve times.

HazardFootprint peril enum(12) # the matrix row clock enum(nrt|annual|climate) # the matrix column geometry raster | vector # COG or GeoParquet, STAC-catalogued intensity float + unit # m depth, m/s wind, PGA g, °C WBGT … time instant | period | return_period | scenario+horizon provenance source, model, version, run_time confidence enum(observed|modeled|proxy) + note # E5

Why the enum matters. confidence is not decoration. It is what lets tornado and wind gust ship at all: a CAPE-shear proxy enters the system as proxy, is rendered differently, and can never be silently averaged into a number labelled observed.

E2 The two-clock risk engine, one data model

Near-real-time monitoring and annualized baseline risk are genuinely different computations, and the temptation is to build them as two systems with two data models. Do not. CLIMADA already demonstrates the correct shape: Hazard, Exposure and Impact classes shared across both, with a separate Forecast class for the event-triggered path. Clock 3 is not a third engine — it is Clock 2 with a different forcing dataset and a scenario label attached.

impact = f(HazardFootprint, ExposureBundle, VulnerabilityCurve) clock 1 → one footprint, now → affected counts, per exposure stack clock 2 → event set + frequencies → AAL, PML, exceedance curve clock 3 → clock 2, forced by CMIP6/ISIMIP, tagged scenario + horizon

The practical test: adding storm surge to Clock 3 should be a configuration and a dataset, not a new codebase. If it is not, E1 has been violated somewhere upstream.

E3 The exposure join service

A service, not a table. It takes a footprint and a requested exposure stack and returns the intersection with its own provenance and currency attached — so a downstream agent can state "1.2 M people, WorldPop 2024, 100 m" rather than an unsourced number. It resolves the People / Nature / Assets stacks specified above, and it is the same service the Food Security and NRM platforms call for their own exposure questions (§07).

join(footprint, stacks[], threshold) → ExposureBundle per stack: count | area | value source, licence, vintage, resolution coverage_flag # OSM completeness, WorldPop age

E4 The peril-agent contract

Each agent MCP-wraps its peril's tools and encodes the workflow a specialist actually follows — not a thin model wrapper. The Flood Risk Agent reconciles a GEOGloWS forecast against an observed HydraFloods extent and flags the divergence rather than picking a winner; that reconciliation logic is the domain expertise, and it is what makes the agent worth building. Registration with the gateway (§02) is what makes it callable by the other platforms' agents.

agent.tools MCP tools — run, query, explain agent.resources the context it can offer another agent agent.card peril, clocks served, data currency, known limitations agent.gate groundedness check before any number is published

E5 The confidence and provenance envelope

Six of the thirty-six cells are gaps. The platform's credibility depends on those six being visibly different from the other thirty, all the way through to the UI and the API — not just in a footnote. SERVIR-AI/global-platform's replayable, litestream-backed receipt, gated by a groundedness check before publishing, is the working precedent to generalise rather than reinvent.

E6 The access layer

Two consumption modes off one capability: LLM and agent applications reach it via MCP; dashboards, national warning systems and backend services reach the same computation via curated APIs. The standards below are not aspirational — CAP in particular is the format that carries an alert into a national warning channel, which is the difference between a risk platform and a warning system.

Interoperability standards

StandardSolvesAdoption
STACDiscovering time/space-indexed hazard and EO data across sourcesNear-default for cloud-native EO
OGC APIWeb-native access to vector/raster risk layersStrong and growing
CAPOne alert format into many national warning channelsBackbone of WMO/UNDRR Early Warnings for All
CF ConventionsSelf-describing climate/forecast NetCDF outputDe facto standard for climate/NWP output
HXL / HDXMachine-readable humanitarian tabular exchangeWidely used across OCHA/cluster system

Already built, not to be re-built

Flagship

RiskMap

With ADPC, SE Asia hub — satellite + street-level imagery + grey literature behind an NL interface.

Flood

HydraFloods + GEOGloWS

SAR/optical surface-water extent, and discharge forecasting — complementary, not competing. Repo: Servir-Mekong/hydra-floods, active July 2025.

Fire

Pyregence / pyretechnics

Built by SIG-GIS — wildfire behavior forecasting, HRRR/NAM/RTMA-driven. Repo: github.com/pyregence, 8 repos, active Sept 2026. Reviewed §04. The library is genuinely reusable — pip-installable, EPL-2.0, in-house authorship. Pyrecast the service is California/US grid-safety scoped; what transfers to SERVIR regions is the library, not the service.

Prototype

SERVIR-AI/global-platform

Live MCP server answering NL disaster-risk questions across 9 perils for SE Asia today — the only repo of 259 with an MCP endpoint.

Plus ClimateSERV (precipitation, active since 2015 — SERVIR/ClimateSERV2, updated June 2026), and a deep bench of hazard code in the hub orgs: flood_mapping_intercomparison, fierpy, RHEAS, lhasa, mrc_ffgs, hiwat_model_viewer — inventoried repo by repo in §02.

Where to partner, what to build

GapStatusPartner
Probabilistic / annualized loss (AAL, PML)PartnerRiskLayer — already the named in-development partnership.
Open-source fallback / benchmarkPartnerCLIMADA (ETH Zurich) — free, GPLv3, covers most perils via climada_petals.
Global multi-hazard alertingPartnerGDACS — free, global, not yet integrated anywhere internally.
Storm surge, sea level risePartnerNOAA STOFS-2D / Copernicus Marine — open data, near-term risk accepted per Decision #1.
Tornado / wind gustPartner + BuildNOAA SPC, ECMWF — genuine global coverage gap, new detection logic on open forecast fields.
Heat and cold index (all three clocks)New buildERA5 + CMIP6 WBGT — no reusable SERVIR asset exists; nine matrix cells depend on it.
H-E-V fusion enginePartner + BuildOpenQuake (earthquake) + CLIMADA (climate perils) + IBF-system (trigger/alert layer).
Shared feature-extraction / eval harnessNew buildTorchGeo + TerraTorch (IBM/NASA) + PANGAEA-bench.

Domain agents

AgentMCP-wrapped toolsWorkflow it encodes
Flood Risk AgentHydraFloods (extent) + GEOGloWS (discharge)Forecast → observed extent → reconcile → overlay exposure → flag divergence for review.
Wildfire Risk AgentPyregence / PyrecastFuel/weather inputs → spread forecast → overlay exposure → escalate past threshold.
Probabilistic Loss AgentRiskLayer + CLIMADA (same interface contract)Take H-E-V bundle → run RiskLayer → cross-check CLIMADA → surface material disagreement.
Global Alert Watch AgentGDACS feedPoll → dedupe against native hazard agents → surface only new signals.
Global Risk Orchestrator AgentOpenQuake + CLIMADA + IBF-system (RiskMap's NL interface)Parse query → call peril agents via A2A → fuse → route through IBF-system triggers → cite sources and limitations → human-approval checkpoint, never autonomous.

Use cases from the SERVIR archive

These are documented services with a named institution and a named decision — the demand evidence this platform is being built against. They are also the acceptance tests: if the matrix above is built correctly, every one of these becomes a query the orchestrator can answer rather than a bespoke tool someone has to maintain.

Mekong / Southeast Asia

Flood emergency preparedness — Myanmar

User
Department of Disaster Management (DDM), Ministry of Social Welfare, Relief & Resettlement
Tool
Historical Flood Analysis Tool — Landsat 5/7/8 + JRC flood frequency + population
Decision
Where to pre-position emergency supplies, shelters and personnel, by ranking flood-prone areas instead of relying on manually collected local knowledge
Matrix
Flood × Clock 2 · People + Assets
servirglobal.net/services/supporting-flood-emergency-preparedness-myanmar
Hindu Kush Himalaya · ICIMOD

HIWAT severe-weather forecasting — Bangladesh

User
Bangladesh Meteorological Department (BMD) — "has adopted the toolkit to enhance its operational forecasting"
Tool
HIWAT — 54-hour probabilistic rainfall, lightning, hail and supercell forecast
Decision
Whether and when BMD issues severe-weather warnings during the pre-monsoon and monsoon season
Matrix
Storm × Clock 1 · People
servir.icimod.org/science-applications/high-impact-weather-assessment-toolkit-hiwat-bangladesh
Hindu Kush Himalaya · ICIMOD

Streamflow + Flash Flood Prediction — Nepal

User
Department of Hydrology and Meteorology (DHM), Ministry of Energy, Water Resources and Irrigation
Tool
Streamflow Prediction Tool (10-day, 519 reaches) + HIWAT-driven Flash Flood Tool (48-hour, 12,428 reaches)
Decision
What goes into DHM's daily monsoon flood bulletin, and the forecast-based-financing actions triggered off it
Matrix
Flood × Clock 1 · People
servir.icimod.org/science-applications/streamflow-prediction-tool-nepal
South Asia

Satellite flood forecasting — Bangladesh

User
Bangladesh Water Development Board — Flood Forecasting and Warning Centre (FFWC)
Tool
Jason-2 altimetry over the Ganges and Brahmaputra basins
Decision
How far ahead FFWC issues warnings — lead time extended from 3–5 days to 8 days, for an audience of ~80 million people
Matrix
Flood × Clock 1 · People
science.nasa.gov — Bangladesh flood forecasting
Eastern & Southern Africa · RCMRD

Community flood early warning — Malawi

Users
DoDMA, Department of Water Resources, DCCMS, Malawi Red Cross Society
Tool
GEOGloWS–ECMWF streamflow + telemetric water-level sensors, 21 rivers across 8 districts
Decision
When to activate community warnings and evacuation — during Cyclone Ana (Jan 2022) lead time went "from hours to days"
Matrix
Flood × Clock 1 · People
Status
Listed active — App Center entry /detail/57, read directly from the live page 9 Sep 2026: one of 79 services, and not among the 5 marked inactive. Corroborated independently by WMO (Apr 2026) for the national EWS and the same institutions — DCCMS, DoDMA, Malawi Red Cross — though that source does not name the GEOGloWS/21-river component. The RCMRD confirmation is still worth having; it is no longer blocking.
earthobservations.org — Malawi CBFEWS/GEOGloWS integration
Southeast Asia · ADPC

Air Quality Explorer — Thailand, Laos, regional

Users
Thai Pollution Control Department, GISTDA, Laos MONRE, UN ESCAP
Tool
SE Asia AQ Explorer / AQ Tracker — fire hotspots plus PM2.5, CO, CO₂, methane
Decision
How authorities regulate and time agricultural burning, and what advisories they issue during haze episodes
Matrix
Air pollution × Clock 1 · People
servir.adpc.net/tools/aq_detail.html
Mesoamerica

Air quality forecasting — El Salvador, Costa Rica

Users
MARN (El Salvador); IMN (Costa Rica)
Tool
MODIS aerosol optical depth visualisation plus a nationally customised CMAQ forecast system
Decision
When MARN issues public air-quality alerts and which emissions-control and public-health measures to trigger
Matrix
Air pollution × Clocks 1–2 · People
servirglobal.net/news — Mesoamerica air quality
Hindu Kush Himalaya · ICIMOD

Forest Fire Detection and Monitoring — Nepal

User
Department of Forests and Soil Conservation (DoFSC), Ministry of Forests and Environment
Tool
Forest Fire Detection and Monitoring System, including a fire-danger outlook module
Decision
Where forest managers allocate suppression resources and when to schedule controlled burns
Matrix
Wildfire × Clocks 1–2 · Nature + People
servir.icimod.org — Nepal forest fire monitoring
Southeast Asia

Anticipatory action for disaster and climate resilience

Users
Mekong River Commission; ASEAN AHA Centre
Tool
Satellite and geospatial early-warning products feeding impact-oriented warnings
Decision
What anticipatory, pre-impact actions member countries take ahead of floods and droughts
Matrix
Flood + Drought × Clock 1 · all three exposure stacks
servirglobal.net/services/enhancing-anticipatory-actions-disaster-and-climate-resilience
Southeast Asia

Reservoir Assessment Tool — Lower Mekong

User
Mekong River Commission and its member countries
Tool
RAT-Mekong — reservoir storage and outflow assessment and forecasting
Decision
Reservoir operation and basin planning for flood and drought management
Matrix
Flood + Drought × Clocks 1–2 · Assets
servir.adpc.net/tools/rat_detail.html
Amazonia

Hydrometeorological monitoring — Colombia

Users
IDEAM; UNGRD (National Disaster Risk Management Unit) as designated end-user
Tool
IDEAM GEOGloWS portal, under the IDEAM–CIAT agreement for SERVIR Amazonia
Decision
National hydrological forecasting and disaster-risk-management action by UNGRD
Matrix
Flood × Clock 1 · People
appcenter.servirglobal.net/detail/59
Amazonia

National hydromet portals — Peru, Ecuador, Brazil

Users
SENAMHI (Peru); INAMHI (Ecuador); CEMADEN (Brazil)
Tool
GEOGloWS ECMWF Streamflow Service delivered through national Tethys portals
Decision
Water-resource management and flood forecasting by the national hydromet agencies themselves — explicitly built so they operate and maintain the tools independently
Matrix
Flood × Clock 1 · People + Assets
appliedsciences.nasa.gov — SERVIR boosts forecasting power in South America

Four further Global Risk services are documented as tools without a named downstream government user on their public pages, and are carried here as capability evidence rather than demand evidence: HYDRAFloods (Lower Mekong flood mapping), LHASA-Mekong (landslide situational awareness), Mekong X-Ray (multidimensional flood vulnerability) and West Africa Flash Flood Vulnerability Mapping (ICRISAT-led consortium).

Landscape differentiation. No existing platform combines near-real-time multi-hazard monitoring with annualized, climate-adjusted risk across 12 perils in one system — which is precisely what the three columns of the matrix are. GDACS alerts but has no annualized baseline; ThinkHazard/RDLS and INFORM are static or index-level; Copernicus EMS is activation-based, not continuous. Today an analyst manually stitches these together.
Governance question (Decision #18). Regional hubs should be co-producers: a hub's locally-calibrated hazard model plugs into the matrix as a first-class override of the global default for its own region — which the E1 contract makes technically trivial. Who is accountable for an override, and how quality disputes are handled, is unresolved.
← Previous03 · GeoAI Strategy Alignment Next →05 · Food Security Platform — Engineering Detail