Airspace modernization · Position paper
Certifying high-density AAM operations on first principles
Tactical separation does not scale to the traffic densities Advanced Air Mobility assumes. If collision risk can be quantified as a function of scheduling policy, regulators gain something they can certify against before the first flight - rather than a controller workload argument after it.

The promise and the bottleneck
Advanced Air Mobility rests on a specific economic assumption: high frequency. The business case for electric air taxis, regional eVTOL shuttles, and cargo drones does not close at a few flights per hour. It closes at hundreds of operations per day moving through shared corridors, converging on vertiports embedded in dense urban terrain, flown by a mixed fleet of aircraft with very different performance characteristics.
Nearly every serious ConOps for the sector acknowledges this. What fewer acknowledge is that the safety architecture inherited from conventional aviation cannot carry that load. Today's airspace is kept safe, in large part, tactically. A controller watches traffic, detects a developing conflict, and issues an instruction. The system works because a trained human can hold a manageable number of aircraft in their scan and intervene in time.
That word, manageable, is the whole problem. Controller workload is a hard ceiling. It caps sector throughput in the busiest en route airspace today, and it would be overwhelmed entirely by AAM densities. Adding controllers does not fix it; coordination overhead grows faster than capacity. Automating the controller's tactical role simply relocates the question, because now the regulator must certify that an algorithm can detect and resolve conflicts in real time, under uncertainty, at scale, with lives on the line. That is one of the hardest certification arguments in all of aviation.
There is another way to frame the problem, and it starts by asking what separation is actually for.
What a separation standard really is
Strip away the procedures and the phraseology, and a separation standard is a claim about probability. Keep aircraft this far apart, under these conditions, and the likelihood of collision stays below an accepted threshold. Aviation has a name for that threshold: the Target Level of Safety. For decades, collision-risk analysis has used targets on the order of one fatal accident per billion flight hours to justify separation minima on oceanic tracks, where no radar exists and no controller can tactically intervene.
This history matters more than it first appears. Oceanic airspace is the proof that aviation already knows how to operate safely without tactical control. The North Atlantic tracks were never protected by a controller watching a scope. They were protected by mathematics: the Reich collision risk model and its successors, which quantified how navigation errors, altimetry errors, and traffic density combine into collision probability, and then derived the lateral, longitudinal, and vertical spacing needed to keep that probability below the target. Regulators did not certify a person's ability to react. They certified an analysis.
High-density AAM is, structurally, the same problem wearing new clothes. The corridors are shorter, the aircraft are smaller, and the uncertainties are different, wind at low altitude, departure timing, battery-constrained performance. But the underlying question is unchanged. Given a set of routes that cross, and aircraft that must share those crossing points, what spacing policy keeps collision risk below the threshold society accepts?
If that question can be answered analytically, something important happens to the certification problem. It inverts.
Inverting the certification problem
Consider what a regulator is actually being asked to approve in each paradigm.
Under tactical separation, the safety case is a claim about intervention. Conflicts will arise, and someone or something will detect and resolve them fast enough. The evidence for that claim is necessarily indirect: workload studies, human-in-the-loop simulations, reliability analyses of detect-and-avoid systems. Each is an argument about behavior under conditions that have not occurred yet. The regulator is asked to extrapolate.
Under strategic, schedule-based separation, the safety case is a claim about design. Conflicts are priced into the schedule before any aircraft leaves the ground. Every crossing of every pair of aircraft is assigned a temporal buffer derived from a quantified risk model, and the schedule is only valid if every buffer meets the threshold. The evidence is the model itself: its inputs, its assumptions, its validation, and the resulting risk numbers. The regulator is asked to audit an analysis, which is precisely what regulators are equipped to do.
This is what we mean by certifying on first principles. Instead of asking an authority to trust that intervention will work at densities no one has operated, the framework hands the authority a function: collision risk expressed in terms of scheduling policy. Tighten the schedule and risk rises, measurably. Loosen it and risk falls, measurably. The safety debate becomes an argument about numbers and assumptions rather than an argument about workload, and it can be settled before the first commercial flight rather than litigated after the first incident.
The obvious objection is that such a function is easy to describe and hard to build. Low-altitude urban operations are messy. Wind fields interact with buildings. Departures slip. A lightweight multirotor and a winged eVTOL cross the same waypoint with completely different speed and error profiles. Any credible risk model has to absorb all of that. So we built one.
STARDOM: collision risk as a computable function
STARDOM, short for Safe Temporal Assignment, Requirements, Deconfliction and Optimization Model, is Concept Solutions' probabilistic scheduling framework for AAM operations. Its purpose is exactly the inversion described above: make collision risk a computable function of the schedule, then generate schedules that satisfy the safety target by construction.
The framework proceeds in three stages.
First, it defines the operational geometry. Vertiport locations, flight corridors, and the shared intersection points where routes cross are mapped for the region in question. These intersections are where collision risk concentrates, so they are where the analysis focuses.
Second, it quantifies risk at each intersection. STARDOM runs Monte Carlo simulations, thousands of iterations per vehicle pairing, that incorporate the real sources of uncertainty in low-altitude flight: wind, departure delays, and the performance envelope of each aircraft type. The output is not a single number but a fitted probability distribution that expresses collision probability as a function of the scheduled time interval between two aircraft at a crossing. Give the model any two vehicle types and any planned separation, and it returns the risk.
Third, it generates schedules. With risk expressed as a function of temporal spacing, schedule construction becomes a constrained optimization problem. STARDOM produces executable daily flight schedules in which every crossing, for every pair of aircraft, meets the required collision-risk threshold. Safety is not something a controller adds during operations. It is a property the schedule possesses when it is published.
Three design choices in this framework deserve emphasis, because each answers a question regulators will inevitably ask.
Pair-specific separation. One-size-fits-all spacing rules are simultaneously unsafe and wasteful. They are unsafe when the rule was calibrated for a more forgiving pairing than the one actually flying, and wasteful when a blanket buffer holds back capacity that a particular pairing does not need. STARDOM derives minimum safe intervals for each combination of vehicle types. In our demonstrations, the model analyzed fifteen distinct vehicle pairings across six simulated aircraft types, each with its own performance-informed interval. Heterogeneity stops being a complication the rules ignore and becomes an input the schedule reflects.
Geographic transferability. A risk model calibrated to a single city is a case study, not infrastructure. We have demonstrated STARDOM across two metropolitan areas with distinct route geometries, wind regimes, and operational constraints. The methodology held across both. Routes, weather, and fleet mix change; the framework does not. That venue independence is what allows a certification approach developed in one region to extend to the next without starting the safety case from zero.
Alignment with established safety targets. STARDOM is calibrated to collision-risk criteria consistent with the Target Levels of Safety used in existing collision-risk and procedure-safety analyses, with demonstrated scheduling against a threshold on the order of ten to the minus seven. This is deliberate. The goal is not to invent a new definition of safe. It is to hold a new operational paradigm to the standard aviation already trusts, using the analytical machinery aviation already understands.
From analytical proof to operational systems
A model earns credibility through its lineage as much as its mathematics, and this framework did not emerge from a whiteboard exercise.
STARDOM's scheduling engine runs on AvenGIS, Concept Solutions' geospatial platform for airspace management. AvenGIS is not a prototype. It is mission-critical technology in operational service today, deployed by the FAA for the Central Altitude Reservation Function, by the United States Air Force for the European Central Altitude Reservation Function at Ramstein Air Base, and by NAV CANADA. Altitude reservation is itself a strategic deconfliction discipline: reserving volumes of airspace across time so that missions do not conflict. STARDOM extends that same time-based logic to the density and heterogeneity of AAM, on a platform that aviation authorities on two continents already rely on.
The surrounding expertise matters too. Concept Solutions has supported FAA airspace modernization for more than 25 years. Our teams currently support UAS integration work that borders AAM directly, including the FAA and NASA effort to prioritize common UTM capabilities and the definition of airspace-authorization workflows for emerging Part 108 operations. We know what it takes to move a concept through the FAA's acquisition and safety processes, because that is where we work every day.
What regulators and states can do with this
The near-term consequences of a quantified, schedule-based safety case are practical, and they land first with the authorities who will govern AAM at the state and regional level.
They can certify corridors. A defined route network with quantified crossing risk supports an analytically defensible safety case for opening specific corridors to commercial operations, at defined density limits, with the evidence in hand before operations begin.
They can set performance-based entry requirements. Because separation intervals are pair-specific and derived from vehicle performance, an authority can tell any prospective operator exactly what scheduling standards their aircraft must meet, backed by simulation data rather than negotiation.
They can build economic models on throughput. Once safe capacity is a computed quantity rather than a guess, fee structures for shared airspace access can be tied to it, giving states a sustainable revenue basis for the infrastructure they operate.
And they can attract investment. Operators and vertiport developers commit capital where the regulatory path is legible. A jurisdiction that can show quantified safety infrastructure offers something its neighbors cannot: a credible answer to the question of when, and under what conditions, high-density operations will be approved. The early autonomous-vehicle corridors taught this lesson on the ground. The states that built the evaluation infrastructure shaped the policy that followed.
The choice in front of the industry
AAM will not scale on the strength of aircraft alone. It will scale when the safety architecture scales, and tactical separation, whether human or automated, carries a structural ceiling that no amount of vehicle innovation removes. Strategic, probabilistically grounded scheduling removes it. It replaces an argument about intervention with an audit of analysis, and it gives every stakeholder, from the FAA to a state DOT to an operator planning its network, the same quantified ground to stand on.
Aviation has certified airspace on first principles before. The oceanic tracks have run that way for half a century. The tooling now exists to do it again, at urban scale, for the traffic that is coming.
We built STARDOM to be that tooling. If you are working on AAM scheduling, safety analysis, or the policy framework for high-density operations, we would like to compare notes. Visit stardom.concept-solutions.com for the capabilities overview, or contact our team directly.

