648d3254d6
Capture that refusing at capacity is the default, not absolute: an operator may opt into valet over-capacity (customer hands over keys, operator stacks the car into custody). Manned-only, new custody/session shape. Deferred; not built into the entry flow. Made capacity-occupancy's FULL gate a soft policy knob.
49 lines
2.3 KiB
Markdown
49 lines
2.3 KiB
Markdown
---
|
||
type: concept
|
||
tags: [parking, domain, business, occupancy]
|
||
sources: []
|
||
updated: 2026-06-15
|
||
status: open
|
||
---
|
||
|
||
# Capacity & Occupancy
|
||
|
||
How many vehicles are inside, how many spaces remain, and what happens when the lot is full.
|
||
|
||
## Occupancy is a projection (like everything else)
|
||
|
||
`occupancy = count(open [[parking-session|sessions]])` — an entry with no matching exit. It is a
|
||
**fold over the signed [[append-only-event-chain]]**, never a hand-maintained counter (a counter is
|
||
editable and drifts; the chain is the truth). Spaces-free = `capacity − occupancy`.
|
||
|
||
- **`capacity`** is admin-set per site (and per **zone/level** if the lot has sections — model a
|
||
`zone` on capacity + on the entry so multi-level is a later addition, not a rewrite).
|
||
- Permit concurrency (`maxConcurrent`, see [[permit]]) is the same kind of fold, scoped to one
|
||
permit's open sessions.
|
||
|
||
## Full → refuse entry + FULL sign
|
||
|
||
- When `occupancy ≥ capacity`, the entry flow **refuses** (no `vehicle_entry`, no barrier open) and
|
||
can drive a **"FULL" sign** (a relay/output, via the device adapter layer).
|
||
- **Safety/policy nuance:** "full" blocks *entry* only — **exit always works** ([[fail-state-safety]]:
|
||
exit fails open; never trap a vehicle). Permit holders may be allowed in past a "transient full"
|
||
threshold (reserve spaces for subscribers) — an optional policy knob.
|
||
- **Counting drift is real:** tailgating (two cars, one entry) and missed reads make the live count
|
||
diverge from physical reality. The count is the *system's* occupancy; periodic ground-truth (a
|
||
loop count, or the [[opencv-anpr-service|vision]] count) reconciles it — surfaced as an anomaly,
|
||
not silently corrected.
|
||
|
||
## "Full" is a soft, operator-configurable policy
|
||
|
||
Refusing at capacity is the **default**, not an absolute. An operator may opt into
|
||
**[[valet-overcapacity|valet over-capacity]]** — accept the car into operator custody (keys handed
|
||
over, stacked beyond the marked count) instead of refusing. So the FULL gate is a policy knob
|
||
(refuse vs. valet-accept), set by the operator per site. Valet is a manned-mode feature with its
|
||
own custody/session shape — see [[valet-overcapacity]] (deferred).
|
||
|
||
## Open
|
||
|
||
- Zone/level granularity at launch vs. single capacity number.
|
||
- Reserve-for-permits threshold.
|
||
- The valet over-capacity mode + custody model ([[valet-overcapacity]]).
|