School Safety Index — Remote Screening Methodology
Version 0.3 · August 2026 · Crashfree India · SIGNED OFF (owner, 6 Aug 2026) — the version in force
v0.3 incorporates an independent expert review (27 flags; disposition record: ssi/notes/expert_review_response.md) and the owner's publication-posture decisions (BLUEPRINT §0.1 D14). It supersedes v0.2 (draft, never used for scoring) and v0.1 (pilot). Every published audit records the version it was scored under. Changes are listed in §14.
Sources and standing. This methodology draws on IRC:SP:32-2023 (the Indian Roads Congress guideline for safer school commutes), the iRAP/Star Rating for Schools attribute model, IRF school-zone guidance, and Crashfree India's field audit instrument. It follows none of them exactly, and says so wherever it departs. Where a threshold is ours rather than a source's, it is labelled [SSI]; where it derives from an IRC clause, the clause is cited.
---
1. What this measures — and what it does not
The School Safety Index (SSI) grades the **road environment around a school's main entrance** from dated Google Street View imagery, scored by an AI auditor and adversarially verified before publication.
It measures the road, never the school. A low score is a statement about infrastructure owed by the road-owning authority, not about any institution. No editorial language about any school appears anywhere in the index.
Scope, stated precisely:
- A main-entrance screen. IRC:SP:32 defines a School Access Zone for
- A screening instrument, not an audit. It covers what photographs of the
- Built for scale. India has ~1.5 million schools; field audits reach a
*every* entrance; this remote screen assesses one — the main entrance — and is therefore a scoped departure from IRC [SSI]. The main entrance is identified in imagery as the primary student entrance (name boards, gate width, school-transport presence), tie-broken by proximity to the mapped school point; the identification and its confidence are recorded in every audit. If no entrance can be identified, the school is not rated (§9). Additional entrances are recorded and routed to the field tier.
public road can show on their capture dates. It is not an IRC:SP:88 road safety audit and does not observe enforcement, school-hour behaviour, night conditions, or anything inside the gate.
few hundred a year. Remote screening covers every school with usable imagery in a city within weeks, directs scarce field capacity to the worst sites, and places the state of school-zone infrastructure on the public record.
2. Evidence base
Full citations with locators and evidence-strength labels: ssi/evidence/bibliography.md (published with the portal). Summary:
- 4.6% of recorded road crashes in India occur in school/college zones
- Pedestrian fatality risk rises steeply with impact speed — from roughly 10%
- Physical measures show the strongest child-pedestrian effects in the
- Weight and interpretation caveats for each claim are in the bibliography;
(e-DAR 2024); ~10,000 minors died on Indian roads in 2023 (MoRTH 2023).
at 30 km/h to a large majority at 60–70 km/h (Austroads 2015; NACTO synthesis); reductions in mean traffic speed of 1 km/h are associated with 3–4% lower fatal crash risk (World Bank 2024).
literature: children living near speed humps had roughly half the odds of pedestrian injury in a matched case-control study (Tester et al. 2004); speed humps reduced operating speeds 18–24% in a large Korean before-after study (Kang 2020); raised platforms and crossings perform best among crossing treatments in systematic review (TRIP 2025); an area-wide New York natural experiment associated calming and refuge provision with markedly lower pedestrian fatality odds (2024). Evidence for signage alone is weak and compliance-dependent.
transferability from high-income settings to Indian mixed traffic is noted there and treated as a limitation (§13).
3. Zones
Zone geometry draws on IRC:SP:32-2023 §2, applied as follows.
Scored zone — School Access Zone (SAZ). The frontage road(s) to **100 m either side of the main entrance**. Where an intersection lies within 100 m, the SAZ extends **to 30 m beyond that intersection in the direction away from the school** (IRC §2.1). Where the gate opens directly at an intersection, the SAZ covers at least 100 m along all arms (IRC §2.1).
Checked zone — School Proximal Zone (SPZ). Used for the zone-extent items of the conformance screen (§7), not for full-weight scoring — panorama density off the frontage does not support uniform SPZ scoring at screening cost [SSI]. Radius per IRC Table 2.1, by road class × the school's oldest age group:
| Road type (IRC Table 2.1) | Primary (m) | Secondary (m) | Senior Secondary (m) |
|---|---|---|---|
| Urban / Interurban Roads | 400 | 450 | 500 |
| Arterial Roads / Highways | 300 | 350 | 400 |
| Collector / Other District Roads | 200 | 250 | 300 |
| Local Streets / Other Roads (incl. PMGSY) | 150 | 200 | 250 |
IRC's boundary conditions apply: intersections or public-transport stops within 20% of the applicable radius (IRC Table 2.2: 30–100 m by class × age) pull the boundary out to include them (+30 m on all arms for intersections); a school opening onto an urban-expressway service road is treated as sub-arterial. A school's SPZ radius, class and age-group inputs are recorded per audit.
Transition Zone. The approach length where advance signage stands (IRC §2.3, Table 2.3). Absence of transition signage registers only within P4's upper levels; children do not occupy this zone.
Crash context. The crash panel (where police data exists) uses a **fixed 500 m radius** [SSI], independent of the SPZ, and sits entirely outside the score.
4. Acquisition standard
Replaces the pilot's fixed-heading pull after its documented failure (ssi/notes/2026-08-05-imagery-probe.md). Platform cost, storage and attribution assumptions behind this section are recorded, with the terms links and the dates they were checked, in ssi/evidence/platform_terms.md.
1. Traverse. Metadata sweep on a ~40 m grid (origin: the gate point) to 150 m radius; every distinct outdoor panorama recorded (pano_id de-duplication) with position, capture date, distance and bearing. All captures at a position are recorded; the newest usable one is preferred for scoring views. Failed requests are retried three times, then logged. 2. Segments. The SAZ is decomposed into named segments: gate frontage, each approach in ~40 m sections, each candidate crossing, each footpath side. Segment list and geometry are stored in the audit record. 3. Aimed views. From the panoramas nearest the gate: computed bearing to the gate (fov 90) and a gate zoom (fov 35); road-axis pairs (fov 90) from traverse panoramas chosen so that **every segment falls in the mid-ground (~10–30 m) of at least one view** — carriageway markings are legible only there. Any candidate sign face, marking, beacon or gate detail is re-shot at fov 35; no sign is classified without a view in which its face is legible or its shape unambiguous. 4. Coverage map (machine-checkable). Each segment is marked covered / partially occluded / not covered, from view geometry plus an occlusion check (vegetation, vehicles, structures blocking the sight line). The map is stored with the audit and drives observability (§6.2). 5. Provenance. Every image is pinned by pano_id, heading, fov, pitch and capture date, hashed (SHA-256) into a public manifest, and displayed with © Google attribution and its capture date. Cited evidence is archived; everything is re-fetchable from its recorded request parameters. 6. Imagery age [owner policy, BLUEPRINT §0]: newest usable panorama older than 2 years → audit flagged stale and queued for re-audit; older than 4 years → not ratable. Rationale: metro imagery refresh cadence and the risk of misrepresenting changed streets. Re-audit triggers when metadata shows a new panorama (which detects imagery refresh, not street change — a limitation stated in §13).
5. Relationship to CFI's field instrument
The remote tests are derived from Crashfree India's field instrument (41 items in the shipped capture app v2026-06: 38 scored + 3 reference; the project blueprint's earlier "44-check" label refers to a prior draft of the same instrument). The version-controlled crosswalk ssi/evidence/field_crosswalk.csv is the single source of truth: every field item maps to a remote test ID, IRC reference, applicability rule, observability class, capture-moment status, scoring role (or an explicit exclusion with reason), and the provisionally responsible agency.
Summary of the crosswalk: **30 field checks are remotely verifiable at high confidence, 5 at medium, 2 at low, 1 not at all.** Three high-confidence checks describe momentary conditions (parked vehicles, vendors, movable obstructions): because a panorama is one instant, these are never scored; they publish as dated observations feeding the fix recipe.
6. Scoring model
For every rated school:
``` Σp provision points earned (over observable sub-items) Σo provision points observable (≤ 100; see §6.2) P provision score = 100 × Σp / Σo W exposure weight ∈ [0.55, 1.00] (provisional policy model, §6.3) SSI headline score = round(P × W) C coverage = Σo / 100 ```
Σp/Σo, P, W (with its inputs), SSI and C all publish on the school page. The one-sentence model: **what protection exists, discounted by what the road demands.** The published data and the site's sorting also provide a provision-only view (W = 1) so anyone can re-rank without the exposure policy layer.
Percentile context is computed within city among audited schools and shown as a caption. No letter grades, no colour bands (owner decision, BLUEPRINT §0).
6.1 Provision parameters (Σ max = 100)
Five parameters. Levels are cumulative checklists: each level requires all lower levels' conditions plus its own. Where a requirement is class-conditioned, that follows IRC's own conditionality. Distances are measured along the road from the gate via panorama geometry. Thresholds marked [SSI] are our operationalisations, argued from the cited IRC principle but not stated by it.
P1 · Physical speed control — 30 points. Weight rationale: speed is the mechanism of harm, and physical devices carry the strongest child-injury evidence (§2).
| Level | Cumulative conditions |
|---|---|
| L0 · 0 | No physical device in the SAZ |
| L1 · 7.5 | Markings-only measures (transverse bar markings / rumble strips), or a single badly worn device far from the gate |
| L2 · 15 | ≥1 sound physical device (hump / speed table) within the SAZ |
| L3 · 22.5 | L2 + a sound device within 30 m of the gate on each usable approach [SSI; motivated by IRC §5.4.3's 20 m raised-crossing clause and §5.2's require-speed-reduction-at-gate principle] |
| L4 · 30 | L3 + the gate device is a raised table/crossing and devices repeat across the SAZ (zone-wide control) |
P2 · Safe crossing — 25 points. Refuge applicability [SSI], operationalising IRC §5.4.4's "wide streets which cannot be crossed in one go": a refuge is required for full marks where the crossing spans **≥2 lanes per direction, or an undivided carriageway of ≥4 lanes total**. Crossing type, geometry, island condition and position relative to the gate desire line are recorded.
| Level | Cumulative conditions |
|---|---|
| L0 · 0 | No crossing visible in the SAZ |
| L1 · 6.25 | A faded/illegible remnant, or a legible crossing far from the gate |
| L2 · 12.5 | Legible marked crossing in the SAZ |
| L3 · 18.75 | L2 + within 20 m of the gate (IRC §5.4.3) + refuge island in sound condition where the applicability rule requires one |
| L4 · 25 | L3 + the crossing is raised (table-top) or signalised |
P3 · Footpath & separation — 25 points. Applicability follows IRC §5.4.1: raised footpaths both sides are required on collector class and above; on local streets a continuous clear walkable edge is the assessed provision (the guideline does not mandate footpaths there). **"Continuous" and "usable" refer to permanent built condition only**: surface, geometry, fixed obstructions (poles, trees, transformer plinths, permanent encroachments) and durable defects — cross-checked across capture dates where multi-date imagery exists. Parked vehicles, movable carts and temporary materials never lower P3; they publish as dated observations (§5).
| Level | Local streets | Collector and above |
|---|---|---|
| L0 · 0 | No usable walking edge; children walk on the carriageway | No footpath either side |
| L1 · 6.25 | An edge exists but is broken/blocked (permanent causes) along most of the frontage | Footpath fragments, mostly unusable |
| L2 · 12.5 | Continuous clear walkable edge, one side | Continuous usable footpath, one side |
| L3 · 18.75 | L2 both sides | L2 both sides |
| L4 · 25 | L3 + physical separation (guard rail / bollard line) between the gate and the first crossing | L3 + guard rail continuous gate→first crossing on either side, discontinuous only at vehicular gates (IRC §5.4.2) |
P4 · Signage & zone identity — 10 points. Weight rationale: effects are compliance-dependent and weak in the literature; but signage is the guideline's most visible requirement and the cheapest fix. Speed-limit credit requires the displayed value to be **≤ the IRC Table 5.1 value for the sign's zone position and road class** — SAZ: 25 km/h (20 on local streets); SPZ: 30 km/h (20 on local streets). The sign's zone position (TZ / SPZ / SAZ) is recorded; a value above the applicable limit earns nothing.
| Level | Cumulative conditions |
|---|---|
| L0 · 0 | No school-related signage on either approach |
| L1 · 2.5 | One school warning sign, any condition |
| L2 · 5 | School warning signs on both approaches, legible |
| L3 · 7.5 | L2 + compliant speed-limit signage or a carriageway speed stamp |
| L4 · 10 | L3 + at least one named 2023-identity asset, each recorded separately: transition "School Zone Ahead" / "School Zone Starts" / fluorescent yellow-green sign faces / red-white school-zone markings / flashing-beacon hardware (a still image cannot verify operation, and this credit does not claim it) |
P5 · Gate environment — 10 points. Built form only; capture-moment conditions are reported, not scored.
| Level | Cumulative conditions |
|---|---|
| L0 · 0 | Gate opens directly onto the carriageway; no setback, rail or refuge |
| L1 · 2.5 | Minimal setback or partial barrier |
| L2 · 5 | Clear setback or railing giving off-carriageway assembly space |
| L3 · 7.5 | L2 + a separate pedestrian opening visible in a zoom view, or continuous rail from gate to the crossing |
| L4 · 10 | L3 + an apparent marked pick-up/drop-off bay whose near edge is ≥ 20 m from the gate [IRC §4 principle; distance measured from imagery; bay dimensions, accessibility and actual use are field-tier questions] |
6.2 Observability — segment level
Observability is judged per sub-item per segment, from the coverage map (§4.4), not per parameter:
- A sub-item (e.g. "footpath, school side, approach A") is observable
- **"Absent" may be recorded only when every segment relevant to the element
- Σp uses the nominal points of the level awarded (the level is judged
- Coverage
C = Σo/100publishes on every page. **C < 60% → the audit is - The raw
Σp/Σopublishes beside the normalisedP(owner decision D1).
only where its segments are covered un-occluded at usable resolution.
is covered un-occluded.** Anything less → *not observable*: the sub-item's points enter neither Σp nor Σo. Partial coverage counts partially — a parameter can be 60% observable.
on the observable portion); observability scales Σo only, as in the §15 worked example. [Editorial codification, 6 Aug 2026, from calibration finding F4 — two agents read the earlier compute note differently. No parameter, level or weight changed; sums are computed in code, not by the auditing model.]
withheld** and queued for re-acquisition; a score that saw less than three-fifths of the rubric is not published [SSI].
Final index construction across a growing sample remains an open, versioned decision (D1 revisit).
6.3 Exposure weight — a provisional policy model
W expresses that identical infrastructure protects less on faster, heavier roads. **It is a policy simplification, versioned v0.3, not an empirically calibrated risk model and not "the iRAP model"** — it is inspired by the risk logic of such models. Its full rationale, alternatives considered and revision plan publish with the methodology; anyone who rejects it can use the published W = 1 view.
| Frontage road class | W |
|---|---|
| Local street / colony lane | 1.00 |
| Collector / other district road | 0.85 |
| Arterial / sub-arterial / highway | 0.70 |
| Urban-expressway service road at the gate | 0.55 |
One modifier: +0.05 where the frontage carriageway is median-divided (permanent built form, readable from imagery). Result bounded to [0.55, 1.00]. The v0.2 draft's heavy-vehicle modifier is removed — two frames cannot establish traffic composition; heavy-vehicle presence is reported as an unscored dated observation.
Road-class decision tree (class, source and confidence publish per school): official road inventory where one exists → OpenStreetMap highway= classification via a published mapping table → imagery geometry (lanes, width, median) → reviewer arbitration. In practice OSM decides most cases in these cities; that is a stated limitation (§13), not a hidden one.
The deliberate consequence, stated publicly: a school gate on an undivided arterial cannot reach 100. IRC §5.2's own position is that school gates should not open onto arterial roads; the weight encodes that stance. A fully-provisioned arterial school still outranks nearly everything unprotected (P 100 × 0.70 = SSI 70).
6.4 Speed exposure slot
Measured speed remains a displayed "PENDING" slot with weight 0. When speed data exists, weights rebalance under a versioned change; earlier audits are annotated, never silently rescored.
7. Remote visual conformance screen — IRC:SP:32-derived provisions
Separate from the SSI score, from the same imagery: the share of applicable high-confidence remote tests (the 30-test set in the crosswalk, each carrying its IRC reference and provisionally responsible agency) that the zone visibly meets, including the zone-extent items (provision across the SAZ, not just at the gate). Published itemised: Remote conformance screen: 4 of 22 applicable provisions visible.
This is not a compliance finding. Whether a road complies with IRC:SP:32-2023 is a determination for a competent on-site assessment; this screen reports what dated imagery shows, item by item, with evidence anchors and limitations. Agency attributions are provisional (from the field instrument's mapping, not an ownership record) and correctable via the disputes channel (§12).
The screen exists apart from the score because the two answer different questions — "how protected is this child's route?" (SSI) and "which prescribed provisions are visibly present?" (this screen) — and merging them would let widespread absence of the 2023 visual identity flatten the protection ranking. The expectation that conformance rates will read low is a descriptive statement to be measured and reported neutrally, not a conclusion of this document.
8. Confidence
Each parameter call carries confidence graded on five recorded dimensions: visibility, resolution, occlusion, capture-date consistency, inter-view agreement.
- HIGH — element (or its absence across all relevant covered segments)
- MED — visible but single-view, partially occluded, or marginal
- LOW — indirect inference; imagery cannot settle it. Treatment:
clear in ≥2 views at adequate resolution, views consistent.
resolution. Treatment: full credit, flagged, priority re-examination in verification.
scored at the lower candidate level, and **never the sole basis for an L3 or L4 claim** — top-two levels require HIGH confidence on their qualifying attributes.
Two or more LOW parameters place an evidence-limited chip on the page. Confidence-vs-verification agreement is reported from the first cycles (§11).
9. When a school is not rated
1. No outdoor panorama within 150 m of the school point after full traverse; 2. The main entrance cannot be identified in imagery (§1); 3. Coverage C < 60% after aimed acquisition; 4. Newest usable imagery older than 4 years; 5. The record is not a school (coaching centre, duplicate, office) — removed from the universe with the exclusion logged publicly.
Not-rated schools are listed with reasons; coverage statistics publish alongside rankings. Silence is also a finding.
10. Quality control
1. Audit pass — scores every parameter with level, per-dimension confidence, note, and 4×4 grid-cell evidence anchors (rendered as SVG overlays on unaltered imagery). 2. Verify pass — separate context, different model tier (ssi/model_policy.md); receives imagery + rubric + the auditor's final calls only; case order randomised; rubric and prompts version-locked and hashed per batch; instructed to refute each call and to confirm every marker placement. Any parameter moved ≥2 levels or any rated/not-rated flip → arbitration; unresolved → withheld. 3. 10% blind double-read every 10th cycle: the verifier scores from scratch without seeing the audit, then differences are computed. Item-level agreement statistics publish on this page, continuously. 4. Distribution watch — if a cycle's scores collapse into one narrow band (the v0.1 pilot failure mode), the cycle pauses for instrument review instead of publishing. Discrimination failure is treated as an instrument fault, not a finding. 5. Audit trail per audit: model id, prompt-version hash, imagery manifest, pass dates, verification changes, adjudication outcome. Nothing publishes without verified status; verification changes are logged publicly per school. High-impact or unresolved cases escalate to the owner's spot-check queue (mandatory in the first three cycles).
11. Validation & credibility architecture
Owner decision D14: this index **publishes on its own verification architecture and does not depend on field visits.** Concretely:
- Every published score has survived independent cross-tier adversarial
- Published, continuously updated internal statistics: audit-verify
- Editorial claims of the form "the N worst zones" are made only once the
- Score differences: treated as not meaningful when small; a quantified
- Field ground-truthing is invited, not required: road authorities,
verification (§10.2).
disagreement rates, blind double-read agreement (item-level), withheld and not-rated counts with reasons.
first ten cycles' agreement statistics are published and stable — an internal, self-contained gate [SSI]. Until then the index publishes scores, evidence and rankings without superlative claims.
equivalence band will be published from verification statistics rather than asserted in advance.
researchers and CFI field teams (when available) can assess any zone with the published field instrument; structured comparisons feed the next methodology version under §14's rules. Independent checking is possible today from any school page — every image is pinned to a public panorama anyone can re-fetch.
12. Right of reply
Disputes: helpdesk@crashfreeindia.org, printed on every page. A dispute pauses the page pending fresh verification; corrections and outcomes are logged publicly. Schools, parents and authorities use the same channel; the fix recipe names the provisionally responsible agency, and misattributions are corrected through the same route.
13. Limitations (read before citing)
- A score reflects visible infrastructure on the imagery capture dates —
- One entrance is assessed (§1); multi-gate schools may have unassessed
- Street View coverage and recency vary by street; coverage statistics
- Remote screening under-detects small or worn elements despite zoom passes;
- Road class comes mostly from OpenStreetMap (§6.3) and carries that
- The exposure weight is an uncalibrated policy simplification (§6.3); the
- Effect sizes in §2 derive largely from non-Indian settings; transfer to
- No field-calibrated error estimate exists yet (D14); internal agreement
not today's conditions, behaviour, enforcement, or lighting.
frontages.
publish. Panorama-refresh detection tracks imagery, not reality.
the verify pass and the field tier exist for exactly that.
source's errors; the class and its source publish per school.
provision-only view is published for anyone who rejects it.
Indian mixed traffic is assumed, not demonstrated.
statistics (§11) are the published uncertainty measure meanwhile.
14. Versioning
Methodology changes are versioned; previously published audits are annotated, never silently rescored. The changelog (kept in full):
- v0.1 → v0.2 (draft): letter grades retired; absent split from
- v0.2 → v0.3 (this version): main-entrance scope made explicit as a
- v0.3 editorial (6 Aug 2026, post-sign-off): one sentence added to
not-observable; additive sum → provision × exposure; aimed acquisition; signage down-weighted; class-conditioned levels; conformance separated from score; momentary conditions unscored; staleness 2y/4y; SVG grid-cell annotations.
departure [review flag 1]; SAZ intersection rule corrected [flag 2]; SPZ tables embedded [flag 3]; segment-level observability and coverage maps [flags 4–6]; SSI-vs-IRC threshold labelling throughout, corrected speed values, cumulative checklists, permanent-condition rules [flags 8–15]; exposure weight relabelled provisional with W = 1 view, heavy-vehicle modifier removed, road-class tree published [flags 16–18]; "IRC compliance" renamed to remote visual conformance screen; field crosswalk file; provisional agency labels [flags 19–21]; five-dimension confidence rubric with level thresholds; randomised, hashed, blind-double-read verification [flags 22, 24]; validation architecture per owner D14 with internal claims-gating [flags 23, 25]; bibliography with locators; platform-terms appendix; "guideline" not "statute"; neutral phrasing; portal-based transparency wording [flags 26, 7, 27]; fictional worked example [flag 28].
§6.2 codifying the Σp/Σo convention the §15 worked example already used (nominal level points over an observability-scaled Σo), after calibration finding F4 showed the earlier phrasing read two ways (ssi/evidence/calibration_v0.3.md). No parameter, level, weight or threshold changed; no audit rescored (none published).
15. Worked example (fictional, illustrative only)
A school on a colony street (local class). Traverse finds 24 panoramas, newest capture five months old; all segments covered except 30 m of the far south approach (occluded by a parked truck → those sub-items not observable). Calls: P1 L0 (no device, all segments covered; HIGH) = 0 · P2 L1 (faded remnant 40 m from gate; HIGH) = 6.25 · P3 L2 (continuous clear edge on school side only; MED) = 12.5 · P4 L1 (one warning sign, zoom legible; HIGH) = 2.5 · P5 L2 (walled setback; HIGH) = 5. Σo = 93.75 (south-approach portion of P1/P3 excluded), Σp = 26.25, P = 28, W = 1.00 (local), SSI 28, C = 94%. Conformance screen: 3 of 19 applicable provisions visible. The page shows all of this plus the coverage map and every evidence image with its panorama pin.
16. Sources
Full bibliography with URLs/DOIs, locators and evidence-strength labels: ssi/evidence/bibliography.md. Primary documents: IRC:SP:32-2023 (owner-supplied copy; clause map in ssi/evidence/irc_sp32_clause_map.md) · iRAP Star Rating for Schools methodology and SR4S coding form · CFI field instrument v2026-06 (crosswalk in ssi/evidence/field_crosswalk.csv) · platform assumptions in ssi/evidence/platform_terms.md.