Performing Safety Analyses in Capella with ATICA: Our Experience

Webinar Transcript Summary

 

Sept 2025 |  Fernando Macías & Daniel Villafañe (ANZEN Engineering) | EN   

Video       Slides

Introduction

Safety and reliability analyses are essential in the development of complex systems, particularly in aerospace. However, these activities are still often performed using separate documents, spreadsheets, and specialized tools. As systems become more complex and engineering iterations multiply, maintaining consistency between system architecture, safety analyses, requirements, and design decisions becomes increasingly difficult.

Anzen developed ATICA for Capella to address this challenge. ATICA integrates safety and reliability engineering directly into a Model-Based Systems Engineering environment, allowing system and safety engineers to work from the same model and maintain a shared source of truth throughout the development lifecycle.

Why Adopt an MBSE Approach?

In a traditional workflow, requirements guide the design of system functions and architecture. Safety, reliability, maintainability, and other quality characteristics are then assessed, generating feedback that may require further design changes.

For simple systems, this process remains manageable. For complex systems, however, the loop may be repeated many times. Managing these updates through Word and Excel creates significant traceability, consistency, and configuration challenges.

Using Capella as a shared engineering repository offers three main benefits. Safety engineers can work directly with the latest architecture, introduce safety requirements into the same environment used by systems engineers, and identify risks earlier in the lifecycle. This shift-left approach helps reduce late design changes, costs, and project delays.

Standards-Based Implementation

ATICA is based on the safety assessment process defined in ARP4761, also known in Europe as ED-135. Rather than introducing a new methodology, Anzen mapped the standard’s concepts and analyses into the Capella metamodel.

ATICA adds safety concepts such as failure conditions, functional failures, failure modes, severity levels, effects, assumptions, failure rates, and probabilities. It also provides dedicated representations for Functional Hazard Assessment (FHA), Fault Tree Analysis (FTA), and Failure Modes and Effects Analysis (FMEA).

These elements are linked across the Capella architecture layers. System-level failure conditions can be connected to logical functional failures, which can then be related to physical failure modes. This creates end-to-end consistency between architecture and safety information.

Integrated Safety Analyses

At the System Analysis level, ATICA supports FHA through structured tables associated with system functions. Engineers can create failure conditions, assign severity levels, document assumptions, and define safety effects directly in Capella.

At the Logical Architecture level, functional failures are analyzed using graphical fault trees. The FTA editor supports logic gates, basic events, transfer gates, probabilities, failure rates, and recalculation of dependent trees.

At the Physical Architecture level, ATICA provides FMEA tables linked to physical components and failure modes. Engineers can document causes, effects, observability, failure rates, and links to higher-level functional failures. Piece-part FMEA workflows are also supported through Bill of Materials import capabilities.

Automation, Reporting, and Demonstration

ATICA automates repetitive tasks by importing structured data, preconfiguring failure modes, and reusing model content across projects. For stakeholders who do not use Capella, M2Doc templates generate Microsoft Word reports directly from the model, including FHA, FMEA, Safety Assessment, and Bill of Materials documents.

The webinar demonstrated these capabilities using the Wheel Brake System example from ARP4761. The presenters showed how engineers can create and edit FHA, FTA, and FMEA information through familiar tables and diagrams while keeping all Capella elements synchronized.

Q&A Highlights

  • Q: Does ATICA support standards beyond aerospace?
    A: ATICA currently focuses on ARP4761 and ED-135, but the same approach could be adapted to other domains, including space standards such as ECSS.
  • Q: Can alternative safety methods be implemented?
    A: Yes. Methods such as STPA could be added, although Anzen generally develops new capabilities through customer projects and partnerships.
  • Q: How are calculations validated?
    A: Fault tree probabilities and related calculations are performed directly in ATICA and checked through extensive test suites and comparisons with established tools.
  • Q: Can results be exported or imported?
    A: Safety analyses can be exported to Word using M2Doc. Bills of Materials and FMEA data can also be imported from Excel, CSV, or other structured formats. API-based integration is under development.
  • Q: Is ATICA connected to reliability databases?
    A: Not yet. Reliability predictions are currently imported from external tools, but direct database integration is on the roadmap.
  • Q: Does ATICA support multi-system analysis and project reuse?
    A: ATICA relies on Capella’s existing mechanisms for model reuse and system transitions. Multi-system workflows generally require project-specific tailoring.

By integrating architecture, safety, and reliability information into one environment, ATICA improves traceability, reduces manual effort, and supports earlier risk detection.

The ATICA documentation website: https://docs.atica.anzenengineering.com/