Every sweep until now priced pieces of the keeper doctrine against literature. This one watches the real system run once, live, on a real rock: 2024 YR4, a 60-meter object found by ATLAS Chile on December 27, 2024, two days after it had already passed. For eight weeks in early 2025 it was the second-most-dangerous asteroid ever catalogued. The episode is now complete — JWST closed the file in February 2026 — and it reads like the doctrine’s three components (watch, readiness, assurance) running their first dress rehearsal with the strengths and the gaps exactly where the ledger predicted.
The run, compressed
Discovered at magnitude 16.2, 2.2 lunar distances out. Impact probability for December 22, 2032: 0.05% → 1% on January 27 (Torino 3, triggering the first formal IAWN notification in history — issued jointly, pre-coordinated, by all three orbit centers) → 2.3% → peak 3.1% on February 18 → collapse: 0.27% by February 20, 0.004% and formal all-clear February 24. Residual: a lunar impact probability that climbed the other way — 1% → 3.8% → 4.3% — until JWST, in February 2026, imaged the faintest NEO ever targeted, cut position uncertainty from 700 to 50 mas, and ruled the Moon safe too (miss by 22,900 ± 800 km). SMPAG convened on a real threat for the first time — and correctly did nothing three times, then stood down. The machinery worked, and the post-mortem (36 experts interviewed, 900 emails reviewed) says so with caveats rather than triumphalism.
The epistemics lesson the media missed
The climb to 3.1% was not the rock getting closer — it was the uncertainty corridor shrinking onto a stationary Earth, a statistically expected phase of every honest risk assessment. Chodas said so in advance (“no one should be concerned that the impact probability is rising… we expect it to drop to zero”); Farnocchia had pre-computed the probability distribution of future probabilities and presented it at the IAWN steering meeting two weeks before the peak. The assurance reading: the experts already sell the only product that matters in week three of a scare — a calibrated statement about how the number will behave. They give it away free, on science budgets, against headlines that monetized the uncalibrated version (“CITY KILLER NOW 1-IN-32”). Priced assurance is, at bottom, the market structure for the thing Chodas does pro bono.
The machinery’s quiet skeletons
Three details from the post-mortem deserve ledger permanence. First, Arecibo’s ghost: Goldstone’s radar window closed December 29, two days before Torino 1; only Arecibo could have imaged it afterward — and had it existed, the rock would likely have been struck from the risk list within days. The system’s most powerful certainty-machine has been rubble since 2020, and the episode priced its absence in weeks of global anxiety. Second: the characterization community was never alerted — IRTF could have observed until January 2 but nobody told them; the surveys weren’t notified to hunt precoveries; the post-mortem lists “no automated alert to physical-characterization assets” as gap number one, and the fix (automated Torino-1 alerting) was only trialed on the next object. Third, the human frame: JPL coordinated the response during the LA wildfires, with 150 staff having lost homes and the servers offline, into a new administration unfamiliar with notification procedures — and the definitive lessons-learned document was assembled by an Air Force SkillBridge fellow. The machinery’s load-bearing members are people, goodwill, and borrowed time.
The counterfactual branch
Had the corridor held onto Earth: Barbee et al. ran the mission options and the honest answer is impractical — kinetic-deflection windows for the Earth-impact case closed early 2029, robust disruption needed launch by 2030–32, nuclear was the fallback, and the best reconnaissance option required a launch by late 2028 against no funded program. Eight years of notice and the response still would have been an emergency build. Meanwhile the lunar branch — which held at 4.3% for months — would have delivered a ~1 km crater, ~200,000 tonnes of ejecta, LEO micrometeoroid flux up to 1000× background for days, and what JPL called a once-in-a-millennium real-time cratering experiment. Note what the lunar branch is, in doctrine terms: an unplanned kinetic test on the one body whose bombardment threatens our satellites but not our cities — the Moon as the solar system’s designated shock absorber, the same body that mails us minimoons (Entry 115). Nobody budgeted for either role.
The assurance ledger, settled
Total charged for certainty during the entire episode: zero dollars. The watch ran on survey science budgets; the characterization on discretionary JWST time; the coordination on volunteer committees; the markets — the sweep checked — didn’t move at all; no insurance product exists that would have priced the risk. This is Entry 109’s niche and Entry 112’s readiness economics demonstrated live, once, in public: when the planet actually needed certainty, the supply chain was astronomers, and the pricing mechanism was gratitude. The keeper’s priced-assurance thesis doesn’t need the next 2024 YR4 to be real. It needs the next one to be funded — and the record says funding arrives only as fear, never as retainer.
Recalled
- The Hammer of God (Arthur C. Clarke, 1993). Clarke’s Kali is the YR4 scenario run to completion: found by a Spaceguard survey, probability debated in public, deflection decided late and flown in a hurry. Two resonances the sweep made eerie: the novel’s deflection engine is called ATLAS — the name of the survey that found YR4 thirty-one years later — and Clarke’s fictional machinery exists because a catastrophe (his analog of Tunguska-era indifference) finally funded it. The 2025 episode is the friendlier timeline: the machinery got its live run without paying Clarke’s tuition. His coda stands as the ledger’s warning: after Kali is deflected, Spaceguard’s budget is immediately questioned. Paying for nothing, year after quiet year, is the whole business model — Entry 112’s cycle, in fiction, in 1993.
What this changes
- The watch doctrine gets its first end-to-end validation: discovery → triage → notification → characterization → stand-down all worked; the gaps are alerting automation, radar coverage (post-Arecibo), and characterization-asset notification — all fixable, none priced.
- Priced assurance gains its live demonstration: certainty was supplied entirely by unfunded coordination; the market offered nothing; the insurance industry didn’t twitch. The niche is not theoretical.
- The readiness bracket gains its counterfactual: with eight years’ notice, deflection was still assessed impractical on timeline and reconnaissance unfunded — readiness exists on paper (DART-derived) but not as a standing capability. Entry 112’s Victus-Sol-shaped standby is what was missing.
- The Moon’s double role is logged: minimoon factory (115) and designated shock absorber (lunar branch, 4.3% for months, LEO debris 1000× had it hit). Any keeper-era infrastructure in cislunar space inherits the lunar-impact debris environment as a design input.
- Backlog addition: the radar gap. Arecibo’s absence was the single largest avoidable uncertainty in the episode; the ledger flags “radar for small bodies” as an unpriced public good alongside the corridor watch.