Field playbooks

Hard problems, composable answers.

Sixteen operational patterns operators build on Nexus Atlas — written at operator depth, each labeled for what it is. Capability means the whole mechanism is shipped product; Pattern means Atlas plus systems and procedure you bring; Concept means it would take roadmap engineering, stated plainly so nobody buys vapor. The decision-maker versions live on nexusatlas.eu.

Capabilitya composition of shipped or opt-in product capabilities — demonstrable today
PatternAtlas’s share is shipped; the external systems and procedure are yours
Conceptwould require roadmap engineering — an idea we’ve thought through, not a feature

Capabilities 3

The whole mechanism is shipped product — demonstrable on a call today.

Capability

A fleet as the transport fabric

Aircraft, vehicles or vessels don’t just use the network — they are it.

The problem. A formation strung out over terrain has no infrastructure to lean on, and the interesting failure isn’t “a link drops” — it’s “the platform carrying the link drops.” Any architecture with a special relay node has a special target.

The pattern. Every airframe runs a node; every node relays. The LSDB gives each platform the whole formation’s topology, SPF threads routes through whoever currently has geometry, and losing an aircraft is topologically identical to losing a link: the loss is detected the same way — five missed probes, ≈1.25 s at defaults — the topology refloods on the event rather than waiting for the advertisement to age out, and traffic flows through the survivors. Spatial diversity comes free (routes bend around losses); spectral diversity comes from mixing bands across the formation so one interference event doesn’t take every edge.

Capability

MANET + cellular + VSAT triplex

No single transport survives a whole route. Stop pretending one will.

The problem. A mixed route — urban canyon, open highway, dead valley — defeats each bearer somewhere: cellular dies in the valley, the MANET dies at range, VSAT dies under the overpass and lags everywhere. Manual switchover means somebody is always switching.

The pattern. Bond all three (plus a second cellular carrier if you have one) and let continuous scoring do the driving. Each link’s declared capacity and measured RTT/loss put it exactly where it belongs minute by minute: the MANET carries bulk while it has geometry, cellular carries the middle miles, VSAT holds the long tail — and the transitions are reweightings, not events. Nobody switches anything; the logs just show the mix shifting with the terrain.

Capability

Sneakernet with auto-resume

Hours of RF silence, gigabytes queued, zero operator actions.

The problem. Blackout windows — EMCON, terrain, jamming, doctrine — turn every naive transfer into a babysitting job: retry loops, resumed uploads, lost partials.

The pattern. Mark the bulk traffic CS1 and stop thinking about it. The bundle store holds it through the outage — in the file backend, surviving reboots — and drains priority-then-FIFO the instant any path returns, at whatever the bonded links can carry. The “passing relay vehicle” case is the same mechanism: the mule comes into range, becomes a path, and the queue drains through it.

Patterns 9

Atlas’s share is shipped; the external systems and the procedure around it are yours.

Pattern

Multi-constellation satellite bonding

One LEO operator is a commercial and political single point of failure.

The problem. A single constellation is one company’s pricing decision, one jurisdiction’s export ruling, one network’s bad week. If the mission can’t tolerate that dependency, no SLA fixes it.

The pattern. Bond terminals from different constellations — different orbits, different gateways, different jurisdictions — plus a GEO VSAT as the slow anchor. To Atlas each terminal is just a link with its own declared capacity and measured behaviour; per-class policy pins Control to the most resilient path while Video aggregates across whatever is fat this hour. When one operator goes dark, the others absorb the load and the burst channel carries control telemetry only.

Pattern

HF NVIS — bandwidth of last resort

Everything else is denied, and the mission still needs “asset alive, position X” once a minute.

The problem. There are days when the answer to “what still propagates?” is: HF, straight up and back down. Near-vertical incidence covers a wide radius with no infrastructure and no line of sight — at kilobit rates that would choke any normal stack.

The pattern. Treat the HF modem as an Atlas link with its capacity declared honestly (hundreds of bits to a few kbps) and let the class system do the triage: Position and Control ride it, everything else waits in the bundle store for a wider link to return. Tiny links are first-class citizens in the scheduler — the engine is proven down to 64 kbps serial radios, and declared capacity keeps every bulky fragment off the thin pipe automatically.

Pattern

Pre-positioned mesh relays

A 100–300 km dead zone, and the asset can’t carry SATCOM.

The problem. Some corridors have nothing: no cellular, no line of sight back, no payload budget for a dish. The transit is known in advance; the connectivity isn’t.

The pattern. Stage battery-powered relay nodes along the route — masts, rooftops, cached boxes. Each is just an Atlas node: the transiting asset discovers it via mesh join as it comes into range, traffic hops forward while geometry holds, and the store-carry-forward class rides whatever contact windows exist. A relay that sleeps between contacts spends its battery on minutes per day.

Pattern

Cross-border SIMs & in-flight eSIM cycling

Enumerated SIMs get cut at the border. The bond shouldn’t notice.

The problem. Identity is the fragile part of cellular: a SIM that was profiled yesterday stops working today, and a profile swap normally means a session reset at the worst moment.

The pattern. Stage physical SIMs by country and provision eSIM profiles only after departure; cycle profiles mid-mission on whatever schedule the threat model wants. To Atlas, each modem is just a link whose public address keeps changing — and endpoint roaming is built for exactly that: an authenticated packet from a new source address updates the endpoint, sessions survive, and the bond holds while identities rotate underneath it.

Pattern

ASN & peering diversity

Carriers that share an upstream fail together.

The problem. Two SIMs from two brands are not two paths if both ride the same wholesale network or exchange at the same point. Correlated failure hides until the day it matters.

The pattern. Curate the SIM stack by actual routing — different ASNs, different upstreams, ideally different physical exchanges — so each modem exits the internet somewhere genuinely different. Atlas measures and schedules each as a fully independent link, so what you bought as diversity behaves as diversity: an upstream outage takes one link, and the reweighting handles the rest.

Pattern

Drive-by opportunistic backhaul

Stranded sensors, and something passes within range every few hours.

The problem. Instruments in RF shadow — under bridges, in basements, over the ridge — can’t justify a dedicated uplink, but something drives, flies or floats past on a schedule.

The pattern. The transiting asset runs a node; the stranded sites run nodes with their telemetry queued in the bundle store. Mesh join handles discovery as geometry opens, the queue drains while contact holds, and the application never sees the discontinuity — it sees a laggy but complete series. Roaming means the sensor doesn’t care what address the mule wore today.

Pattern

HAPS & tethered aerostats as relays

Terrain or policy blocks line of sight. Altitude un-blocks it.

The problem. Some links are impossible at ground level and trivial from 300 m up — but a single elevated relay is a single point of failure with excellent visibility, in every sense.

The pattern. The aerostat or high-altitude platform is just another mesh node with a horizon measured in tens or hundreds of kilometres — and, critically, its own bonded uplink set, so the relay itself isn’t one link deep. Ground nodes route through it when SPF says it wins and around it when the tether comes down; nothing re-configures either way.

Pattern

Moving-target ground endpoint

Once your ground station is identified, it’s a target.

The problem. A fixed, known egress point accumulates risk with every hour of operation — RF, network, and physical.

The pattern. Run the ground side as a rotating pool of egress points and re-anchor on schedule or on quality drop. The machinery is shipped: sessions are bound to keys rather than addresses, endpoint roaming follows authenticated traffic to the new anchor, and relay re-election converges both ends on the same next relay with no negotiation. The pool orchestration — how many anchors, where, on what rotation — is doctrine, and it’s yours.

Pattern

Recovery seed for electromagnetic events

After an EMP-class event, survivors need a clean baseline to re-form around.

The problem. The nodes that survive a severe electromagnetic event come back with uncertain state, uncertain configs, uncertain trust — at exactly the moment coordination matters most.

The pattern. One fully-provisioned node stays powered off in shielding. It boots clean, joins the mesh, and gossips the authoritative signed configuration epoch to every survivor — the same epoch machinery that does routine fleet pushes doubles as a deterministic recovery path, for the cost of one spare node in a box. The doctrine — when to break the seal, who holds the author key — is yours.

Concepts 4

Would require roadmap engineering. Published so nobody buys an idea as a feature.

Concept

Time-shifted mission intent

When real-time control is impossible, push intent, not commands.

The problem. Past a certain link budget there is no “control loop” — there are contact windows. Joysticks don’t work across a 40-minute gap; intentions do.

The idea. Encode conditional intent — “if no contact for 60 s: descend, orbit, report” — and let store-carry-forward deliver it over whatever touches the asset next; autonomy executes, and the queued telemetry catches the operator up on reconnect. Atlas ships the delivery half today (the queue, the contact-window drain, the priority order). The intent semantics live in your autopilot or C2 — packaging them as a product feature is a roadmap conversation, and this essay stays labeled Concept until it isn’t.

Concept

DPI-resistant transport encapsulation

The only path is a network that drops anything unusual-looking.

The problem. Some networks pass only traffic shaped like the traffic they expect. Encryption isn’t the hard part — volumetric shape is: packet sizes, timing, burst profiles.

The idea. A pluggable outer wrapper that matches the statistical profile of common protocols, carrying the tunnel inside it. We have designed for where it would attach (the outer transport is already a clean boundary) — and we say plainly that profile-matching is genuinely hard, unbuilt, and not something to buy on faith. If a vendor tells you otherwise, ask for their packet-size histograms.

Concept

Decoy traffic & volumetric flattening

Even encrypted, tempo leaks through volume.

The problem. An observer who can’t read a single packet can still read the pattern: the burst before the move, the silence before the strike. Traffic analysis doesn’t need plaintext.

The idea. A lowest-priority cover class that keeps every link at a steady volumetric envelope — real traffic displaces cover byte for byte, so the outside shape never changes. It is a natural extension of the class system (a seventh class with inverted priority) and it is designed, not built. The bandwidth cost is real and permanent; that trade belongs to the mission, not to marketing.

Concept

Power-budget-aware link selection

On a solar buoy, a satellite byte costs ten mesh bytes of battery.

The problem. The scheduler optimises delivery; some platforms need it to optimise joules per delivered byte, which is a different answer on a cloudy week.

The idea. An energy hint per link feeding the cost model — designed-for, not built. Today the honest approximation is per-class policy plus declared capacities: pin patient traffic to the cheap link, let only Control touch the expensive one, and let the bundle store shift bulk into the sunny hours. It works; it just isn’t closed-loop yet.

Request an evaluation

Bring your nightmare. We’ve probably sketched it.

Half of these patterns started as someone’s worst operational day. If yours isn’t here, that’s the most interesting conversation on this site.