A plan is feasible or it is not, and that is computable exactly. What it cannot tell you is whether the plan clears by four hours or by four minutes, and which single thing running long would end it. That gap is where cases are lost.
On the case in the capture, every deadline has hours of slack and every field is filled in. caseclock is right: the plan is feasible. fray is also right: it holds in barely a third of futures, and when it holds it clears by twenty-four minutes.
The reason is not the reference lab. The case file's own figure for team mobilisation is 120 minutes; the distributions the site supplied say 120 to 210, mean 155. The offer window is nominally 180 and drawn 150 to 240. Summed, the expected durations are 711 minutes against a budget of 695 — the plan is under water on average while every individual figure in it looks reasonable.
That is a sentence no single timer, and no amount of staring at a filled-in form, will produce.
A file the site owns maps a constraint's label to a distribution: fixed, uniform, triangular or lognormal stated as two quantiles, because "usually six hours, sometimes six forty" is what a site can actually say.
A constraint with no rule does not vary. Silence means certainty, and the run reports how many were silent rather than inventing a spread for them.
A draw is a pure function of (seed, future, constraint) — not a stream. Future 148,203 can be replayed on its own, without running the 148,202 before it.
That is also what makes a counterfactual honest: an action re-runs at the same seed, so everything it did not touch draws the same minutes and the difference is the action's.
Times entered during a shift live on caseclock's tape, not in the case file. fray folds the tape in, so it measures the plan as it stands rather than as it was filed.
The tape's hash chain is verified first, and a broken one is refused. This is the input that decides the answer.
fray descends from a 2025 specification for a GPU demonstration that ranked organ allocations by score. That layer was cut rather than adapted. These tools never determine organ viability and never make or override an allocation or clinical decision — so what fray varies is how long things take, and what it reports is a schedule's fragility.
The boundary is enforced where a file is read, not in a comment. An action naming a recipient, a candidate or an organ is refused at load, with its reason, and the refusal is one of the sixty-four checks in the tool's own test.
Its only counterfactuals are things the OPO does with its own resources: draw earlier, put a courier on standby, call a second crew. A coordinator decides what to do; fray measures how thin the margin is.
A Monte Carlo tool is easy to make plausible and hard to make right. Every check below was written with its threshold stated before the run, not adjusted afterwards to whatever the tool happened to do.
Windows 10 1809 or later, x64, 437 KB, linking kernel32 and nothing else. It reads caseclock's case files unchanged, so if you have a case you have an input. The binary is unsigned, so Windows will warn on first run.