The planned scenario

Rail Operator combines passenger information with a separate view of operational systems. Public routes represent passenger information, tickets, train status, and vendor maintenance. Private context covers signalling telemetry, crew rosters, asset maintenance, and yard inventory.

A suitable exercise asks how public service information and supplier work relate to internal operations without assuming they share access rights. Participants can inventory visible routes, identify the synthetic records they expose, and explain the boundary between a service alert and the maintenance or crew context behind it.

Public surfaces

These reference routes describe possible entry points in the scenario model. They are not live customer services or a guarantee of the routes in a particular product release. Use your configured exercise inventory as the authoritative scope.

Public routes declared in the Rail Operator catalog
RouteSurfaceContext
/passenger-infoPassenger information and service alert portal.
/ticketsticketingTicketing and passenger account facade.
/statusstatus-apiPublic train status and station API simulation.
/vendorsvendor-maintenanceVendor maintenance and parts workflow.

Private systems

These service names and segments describe the internal context of Rail Operator. They help define exercise boundaries and interpret the generated records.

signalling-telemetry

Signalling telemetry representation in private app segments. Catalog segment: private application.

crew-roster

Crew scheduling and roster data. Catalog segment: private application.

asset-maintenance

Rolling stock and track maintenance service. Catalog segment: private application.

yard-inventory

Yard inventory and equipment location data. Catalog segment: private data.

Configure your exercise

Choose a question for the assignment and define the evidence participants should collect.

  • Which details belong in a public service alert, and which should remain in crew or maintenance records?
  • How should vendor maintenance context be limited relative to the wider asset and yard inventory?
  • Can an investigator distinguish ticket or passenger information exposure from operational telemetry context?

What to hand in

Write an information boundary report organized around passengers, vendors, and internal operations. Include supporting records and limit operational impact claims to the observations recorded during the exercise.

Records and evidence

Stations, service alerts, and tickets form the passenger context. Crew rosters, maintenance orders, and yard assets supply the operational perspective. Use both groups to explain where passenger information ends and internal staffing, maintenance, and equipment context begins.

  • stations
  • service-alerts
  • tickets
  • crew-rosters
  • maintenance-orders
  • yard-assets

Preserve the scenario and product version, the record or observation, and its source with each finding. Distinguish what a participant observed from what the reviewer inferred. Use synthetic data and your defined evidence-retention rules.

Public self-service at launch

Managed Verse is planned for 1 January 2027. Users will create an account, choose a scenario and configure their own authorized exercise boundaries. Vulnverse will host and operate the platform and cloud; users will not need to provision or maintain an exercise cloud.

Managed Verse is planned to replace all previous services. All new inquiries are paused during the transition. Read Managed Verse →.