All projects

Wildcraft Group / Simulation product

Ghostlight.

Rehearse the attraction.
Then build it.

Ghostlight is a product for rehearsing a show, a ride or a whole park from its documents, so the faults between systems turn up while they are still lines on a page. I designed and built it: four tools, the model they share, the sign-in and the page that explains the engine.

Visit wildcraftgroup.com
Product design, engineering & infrastructureWildcraft Group is a separate company I foundedIn development
Ghostlight’s opening screen: the wordmark, the line Rehearse your attractions before you build, and a glowing purple ghost lighting the page
01 / The front doorwildcraftgroup.com · September 2026

The product

Four tools.
One model.

All four read and write the same model, so a number revised in one changes what the next one finds. Everything below is the actual interface, working on a fictional coaster. Its results are illustrative.

01 / Gather

Start with
what exists.

Drawings, specifications, cue sheets, schedules. The register tracks every document, its revision and who supplied it, and shows where the set is still thin. In this version a file is registered by name only. Nothing leaves the browser, and the interface says so.

The Gather tool: a register of twenty-three documents with type, system, revision, supplier and the facts read from each
The document registerView full size

02 / Model

Every number
beside its clause.

Model turns documents into facts an engine can read. Each fact sits next to the sentence it was read from, with its confidence. Disagreements between documents are reconciled in the open, and eight admission checks run before anything compiles. A compiled model carries a SHA-256 hash, so a run always names exactly what it ran on.

The Model tool: quoted clauses from a ride control document on the left, each beside the named, editable fact the engine receives
What the document says, beside what the engine receivesView full size

03 / Rehearse

Run it. Then follow
one fault down.

The studio runs the attraction on a seeded clock, with a ride stop you can inject at any second. Findings land as the run crosses them. Pick one and it opens downward: the record of what caused it, the signal, the bytes on the wire, the physics and the clause it came from. A fifty-day sweep shows which findings hold.

The rehearsal studio: seven system lanes on a timeline, four findings landed, and one finding opened to its record, signal traces and the bytes on the wire
A rehearsal with a ride stop injected at 44 secondsView full size

04 / Report

Findings
with an owner.

Every finding names the two values that disagree, the systems between them, where it was found and who owns it. Dispositions move it from open to closed. The issue prints, and the ledger exports as CSV.

The Report tool: a ledger of five findings, each with the two disagreeing values, severity, owner and status
The findings ledgerView full size

The engine, explained

One moment.
Seven depths.

A rehearsal is only worth trusting if you can see how deep it goes. So the engine has a page of its own: one transformer failing on one rehearsed afternoon, followed down through physics, the wire, power and network, the day, the record, the source and the repeat. Every instrument on the page works out what it shows, from the transformer’s losses to the checksum on a Modbus frame.

The physics instrument: a transformer’s copper loss curve, secondary current, efficiency and hot-spot temperature, recomputed as the load slider moves
Depth 01 / Physics. Drag the load and the losses, hot spot and insulation ageing follow.
The record instrument: one transformer fault traced to the nine events it caused, with four rules checked across the whole run
Depth 05 / The record. One fault, traced to everything it caused.
Try the engine page

Backend & infrastructure

A door that
stays shut.

Ghostlight is invitation-only, so the sign-in is part of the product. I built it on Cloudflare Pages Functions and a D1 database.

Accounts by invitation.
There is no sign-up form. An operator issues a one-time link that expires, and issuing a new one retires the last. Passwords are stored as salted PBKDF2 hashes, and sign-in attempts are rate limited.
Sessions the server can end.
The browser holds a host-locked, HTTP-only cookie. The database holds only a hash of it, so a person’s sessions can be revoked at once. Everything except the sign-in pages sits behind one gate.
Managed from my own desk.
Accounts are managed from Tallest Giant’s operations desk over a token-protected machine API: invite, disable, recover, revoke. Links are handed to the operator rather than emailed, and every action lands in an audit log.

Next project

Wildcraft Group