// WHITE PAPER

Image credit NASA; article not affiliated with NASA
In a perfect world, where aircraft are operating nominally, an operator supervising a fleet of highly autonomous Unmanned Aircraft Systems (UAS) may rarely need to provide input. Operator workload spikes in off-nominal events when an aircraft encounters an issue that requires intervention. During these off-nominal events,,an operator must rapidly determine:
What changed, and how urgent is it?
What has autonomy already attempted?
What intervention options remain and what are their potential outcomes?
What could happen if no one intervenes?
While the operator orients to the issue, the rest of the fleet does not pause. Additional events may already be developing, particularly if the condition that triggered the first alert affects multiple aircraft.
Autonomy is already enabling larger-scale UAS operations, but human factors challenges still exist when an operation stops being routine. During off-nominal conditions, the system must support a complete intervention cycle: detect, prioritize, understand, decide, act, support the rest of the operation, and recover.
We have previously discussed the paradigm shift from aircraft count to optimizing operator workload. The next important consideration for multi-UAS operations is what the system asks of an operator when autonomy reaches a condition it cannot resolve alone.
Orienting to the issue is part of the intervention
During nominal m:N operations, an operator works at the fleet level: monitoring mission progress, checking weather and airspace, coordinating with others, and approving decisions. With high levels of autonomy, fleet-level oversight does not require continuous knowledge of every aircraft metric. When an alert occurs, however, an operator must rapidly gather enough detail to make a sound intervention decision.
A fleet-level alert may identify which aircraft needs attention without providing enough context to evaluate the event. Before deciding what the alert means, the operator may need to assemble the aircraft's recent state, mission intent, surrounding traffic, current constraints, and actions already taken by the automation.
NASA measured part of this transition in a multi-UAS detect-and-avoid simulation. When pilots had to shift the display's focus to an aircraft that was not already selected, their initial responses were approximately two to three seconds slower. During simultaneous caution-level threats, pilots responded more slowly to the aircraft outside the current focus (Monk et al., 2019). Those numbers belong to one display and scenario, but the finding illustrates a practical design concern: changing focus adds work, and concurrent demands force prioritization.
An interface supporting multi-UAS supervision needs to treat orientation to an issue as a design requirement. Operators need a clear path from fleet status to the relevant aircraft, event history, mission intent, current constraints, and available actions. If those elements are scattered across displays, buried behind multiple interactions, or obscured by unfamiliar terminology, the operator will take longer to orient, potentially delaying effective intervention.
An alert should establish priority, not merely attract attention
An alert stating “UAS07: Anomaly” attracts attention but does not provide an operator with the context or priority needed to rapidly determine next steps. Is the alert important enough to interrupt all other current tasks? Can the response wait? Alert priority should answer these questions before issue diagnosis begins.
FAA research offers a useful, though non-UAS-specific, framing: categorize messages by the consequence of not responding, urgency, and time available. This research included a cognitive walkthrough where six supervisory controllers identified alerts that were insufficiently salient, overly attention-grabbing, or missing information. The findings informed four recommendations (Hah, Hallman, & Williams, 2017):
Use consistent coding.
Match salience to severity.
Make aural signals distinguishable.
Avoid presentations that obscure other work.
The FAA Human Factors Design Standard similarly addresses operational significance and the priority of simultaneous alarms (Ahlstrom, 2016). The FAA Human Factors Design Standard (HFDS) is an exhaustive compilation of human factors practices and principles integral to the procurement, design, development, and testing of FAA systems, facilities, and equipment. The purpose of the HFDS is to provide a single, easy-to-use source of human factors design criteria, oriented to the needs of the FAA mission and systems.
The HFDW discusses how consequence, urgency, and time available inevitably vary with operational context. For example, a battery warning can have different levels of urgency depending on aircraft location, mission completion, nearby traffic, and whether human action is required. In another example, a degraded altitude alert could represent extreme urgency if an aircraft is over a populated area, but in other circumstances might be rapidly resolved by automated course correction.
Per the HFDS, the interface must make relative alert priority immediately apparent. Queue order and clear aircraft association can show what needs attention first and where. Consistent labels, color, and salience can distinguish levels of concern; aural cues can interrupt when warranted; and persistent visual cues can preserve identity and status after the sound ends. No single cue should carry the full meaning.
Alert reliability also shapes attention. False alarms altered system sampling and lengthened problem-solving during multiple disturbances in a supervisory-control experiment (Kerstholt & Passenier, 2000). FAA field research found high nuisance-alert rates in some ATC environments (Friedman-Berg, Allendoerfer, & Pai, 2008). Neither source establishes a UAS threshold; both show that alerts consume capacity even when no intervention follows.

Notification is not diagnosis
Once the system directs attention to the highest-priority event, the operator must quickly understand the issue. An operator may need to answer questions the alert itself cannot immediately provide. What was the aircraft doing or trying to do? What triggered the condition? Which options have already been attempted through automation? Which functions remain available? How certain is the diagnosis? What happens if no action is taken?
Automation transparency can support diagnosis without exposing every internal calculation. Transparency should make the automation's activity, rationale, constraints, uncertainty, and likely effects observable and understandable at the level needed for an operator to make a decision.
A systematic review of 17 experiments found a beneficial trend for transparency in situation awareness and operator performance, but effects varied by task, agent type, information level, and display integration (van de Merwe, Mallam, & Nazir, 2024). In another study, a multi-unmanned-vehicle experiment shows how different transparency designs can produce different outcomes. Information about the automation's reasoning improved the accurate use of its recommendations without increasing decision time or subjective workload. Adding projected-outcome visualizations made decisions faster but less accurate and increased automation bias (Bhaskara et al., 2021).
Useful transparency is selective and decision-centered. A concise event timeline might show the state change, the automation's detection, actions already attempted, current result, and remaining options. An explanation might reveal constraints influencing a reroute recommendation. An uncertainty indicator might tell the operator when additional verification is warranted. As we have talked about in our own research and reporting, each element should earn its place by improving a defined decision, not by making the interface look more informative.
NASA's 2021 multi-UAS cognitive task analysis provides a concrete example. Aviation subject-matter experts using an exploratory interface struggled with some alert terminology, what an “auto resolver” intended to do, how to obtain more information, and how to take the next step (Scheff, 2021). The study did not validate operational performance, but participants' difficulties illustrate the gap between indicating that automation is acting and making that action understandable.
The rest of the fleet does not pause
An intervention creates simultaneous responsibilities for an operator: resolve the emergent issue, continue to monitor the wider operation, and address or delegate new issues. Depending on the concept of operations, the operator may also be communicating and coordinating with others.
Focused intervention creates a discrete “return-to-fleet” task. In Gartenberg et al.'s supervisory-control experiment, participants returned from a visual-search interruption while five aircraft continued moving. They took longer to resume action, scanned more objects, and revisited earlier cues; behaviors the authors interpreted as reconstructing goals, plans, and system state (Gartenberg et al., 2014).
Maintaining fleet awareness becomes harder as operations scale. In NASA's exploratory cognitive task analysis, participants in a 100-UAS scenario relied more on reactive exception management and mission-timeline and telemetry panels, and looked less at nominal aircraft, than participants in a 12-UAS scenario (Scheff, 2021). The findings suggest exception management becomes more prominent with scale, increasing the system's responsibility to preserve aircraft state outside the operator's focus.
Interfaces can support this work with a prioritized event queue, persistent indications of unresolved conditions, safeguards, and a fleet view of changes. They also need a return path showing what changed, waited, was resolved, or now requires attention.
Overlapping events make this more than an interface layout problem. In a NASA multi-vehicle study, reported workload rose during contingencies, was higher with two contingencies than with one, and remained above the pre-event level immediately afterward. Participants transferred vehicles to another operator more often when two contingencies occurred and when the interface provided assisted handoffs (Chandarana et al., 2022). The study does not prescribe a team structure, but demonstrates that redistribution of supervised assets is a key capability. An operation needs criteria for escalation, clear ownership, and enough transferred context for the receiving operator to contribute quickly.

Give the operator the right level of intervention
Operator intervention does not have to mean taking over low-level flight control. In a multi-UAS operation, direct flight control may rarely be an appropriate or feasible form of intervention. Instead, an operator may approve a proposed alternate route, modify a constraint, select a predefined contingency plan, change mission priorities, or transfer responsibility. The interface must make authority clear: what the automation controls now, what the operator can change, what will happen when they act, and how the system returns to automated operation.
NASA research comparing ground control station (GCS) capabilities illustrates the value of flexible control. In simulated airspace restriction events, a hybrid GCS combined automated “plays” with manual mission changes. Participants made more mission-preserving decisions than with automation alone while maintaining similar workload and response time, and 11 of 12 ranked the hybrid configuration first (Saephan et al., 2023). Automation-only responses were fastest overall, so the lesson is not that manual control is superior. Timely automation and targeted human authority can complement each other when the available automated response is not the best response for the mission.
After the immediate problem is contained, an operator needs confirmation of the new vehicle state, the current owner of each responsibility, any temporary constraints, and the conditions for resuming normal supervision. Without a clear endpoint and confirmation of next steps, an intervention can continue consuming attention and spiking workload even after the necessary steps are complete.
Test the bad day, not only the quiet one
A nominal test can show that autonomy handles expected work but cannot establish whether the human-autonomy system will be effective when an operator must intervene in a realistic scenario.
The FAA's 2025 Part 108 proposal makes this distinction relevant to emerging Beyond Visual Line of Sight (BVLOS) operations. Proposed §108.210 would evaluate how many aircraft a flight coordinator can handle across normal, abnormal, and emergency conditions. Other proposed provisions address flight-coordinator situation awareness and procedures for transferring control between coordinators. Note however, that as of September 9, 2026, Part 108 remains a proposal, with a final rule pending OIRA review (Office of Information and Regulatory Affairs, 2026). As such, in its current form, Part 108’s language is not binding and must be rechecked before publication. Even so, the framing reinforces the need for scalable operations to account for off-nominal conditions.
To test human-autonomy systems, human-in-the-loop evaluations should combine credible events for the intended operation instead of staging an implausible cascade of every possible failure. Depending on the concept, scenarios might include degraded communications, navigation anomalies, vehicle-health warnings, route conflicts, changing weather, route interdictions by crewed aircraft, unsuccessful automated actions, or two events close enough to compete for attention.
Measures should follow the intervention cycle. Teams may need detection time, time to establish priority, context-recovery time, response time, decision quality, errors, workload, situation awareness, intervention effectiveness, and time to stabilize recovery. Measures should also assess fleet-level impacts like missed or delayed events, mission effects on other aircraft, and the effectiveness of any transfers to other operators.
The strongest test should ask more than whether the operator successfully resolved the issue. Teams should evaluate whether the system helped the operator recognize the right problem, understand it quickly enough, act at the appropriate level, and maintain the safety of the broader operation within acceptable bounds.
Multi-UAS scalability depends on what autonomy can accomplish during routine operations and on how well the system supports people when routine operations are interrupted. HF Designworks can help teams identify operator information requirements through cognitive task analysis, analyze task and workload demands, design and audit supervisory interfaces and conduct human-in-the-loop evaluations for representative off-nominal conditions. When appropriate, our team can also leverage FortiFly to support continuous workload assessment during simulation or evaluation, complementing performance, behavioral, and subjective measures. If your team is designing or evaluating a multi-UAS operation, contact us to discuss how your system can better support operators through off-nominal events and human intervention.
Sources
Ahlstrom, V. (2016). Human factors design standard (HF-STD-001B). Federal Aviation Administration, William J. Hughes Technical Center. https://hf.tc.faa.gov/publications/2016-12-human-factors-design-standard/full_text.pdf
Bhaskara, A., Duong, L., Brooks, J., Li, R., McInerney, R., Skinner, M., Pongracic, H., & Loft, S. (2021). Effect of automation transparency in the management of multiple unmanned vehicles. Applied Ergonomics, 90, 103243. https://doi.org/10.1016/j.apergo.2020.103243
Chandarana, M., Sadler, G. G., Keeler, J. N., Smith, C. L., Rorie, R. C., Wong, D. G., Scheff, S., Pham, C., & Dolgov, I. (2022). Streamlining tactical operator handoffs during multi-vehicle applications. IFAC-PapersOnLine, 55(29), 79–84. https://doi.org/10.1016/j.ifacol.2022.10.235
Federal Aviation Administration, & Transportation Security Administration. (2025, August 7). Normalizing unmanned aircraft systems beyond visual line of sight operations [Notice of proposed rulemaking] (90 Fed. Reg. 38212; Docket No. FAA-2025-1908). Federal Register. https://www.faa.gov/newsroom/BVLOS_NPRM_website_version.pdf
Friedman-Berg, F., Allendoerfer, K., & Pai, S. (2008). Nuisance alerts in operational ATC environments: Classification and frequencies. Proceedings of the Human Factors and Ergonomics Society Annual Meeting, 52(1), 104–108. https://doi.org/10.1177/154193120805200123
Gartenberg, D., Breslow, L., McCurry, J. M., & Trafton, J. G. (2014). Situation awareness recovery. Human Factors, 56(4), 710–727. https://doi.org/10.1177/0018720813506223
Hah, S., Hallman, K., & Williams, B. (2017). NextGen air traffic control and technical operations alarms and alerts evaluation (DOT/FAA/TC-17/61). Federal Aviation Administration, William J. Hughes Technical Center. https://hf.tc.faa.gov/publications/2017-12-01-nextgen-atc-tech-ops-alarms-alerts/TC-17-61.pdf
Kerstholt, J. H., & Passenier, P. O. (2000). Fault management in supervisory control: The effect of false alarms and support. Ergonomics, 43(9), 1371–1389. https://pubmed.ncbi.nlm.nih.gov/11014759/
Monk, K. J., Rorie, R. C., Brandt, S. L., Sadler, G. G., & Roberts, Z. S. (2019). A detect and avoid system in the context of multiple-unmanned aircraft systems operations. In AIAA Aviation 2019 Forum. American Institute of Aeronautics and Astronautics. https://doi.org/10.2514/6.2019-3315
Office of Information and Regulatory Affairs. (n.d.). Pending EO 12866 regulatory review: RIN 2120-AL82—Normalizing unmanned aircraft systems beyond visual line of sight operations. Retrieved September 3, 2026, from https://www.reginfo.gov/public/do/eoDetails?rrid=1457213
Saephan, M. C., Sadler, G. G., Pradhan, K., Keeler, J., Dulchinos, V., Kirkley, C., Holm, L. J., & Wong, D. G. (2024). sUAS ground control station capabilities: Impact on fleet management. In 2024 IEEE 4th International Conference on Human-Machine Systems (ICHMS) (pp. 1–6). IEEE. https://doi.org/10.1109/ICHMS59971.2024.10555628
Scheff, S. (2021, March 26). HAT m:N cognitive task analysis (CTA) [Presentation]. National Aeronautics and Space Administration. https://ntrs.nasa.gov/citations/20210011503
van de Merwe, K., Mallam, S., & Nazir, S. (2024). Agent transparency, situation awareness, mental workload, and operator performance: A systematic literature review. Human Factors, 66(1), 180–208. https://doi.org/10.1177/00187208221077804
Contact
HF Designworks, Inc.
PO Box 19911
Boulder, CO 80308
(720) 362-7066