I would add:
And assure the man-machine interface will always be able to HELP effectively the crew even when facing (all possible) extreme conditions. Allowing a FAST ("immediate", if possible) understanding of the problem(s) or threat(s).
In order, at least, to allow the very basic:
Aviate and Navigate safely.
In a "graceful degradation" environment in order to increase chances ("giving" time) to succeed.
(*) The "effective aircraft" (System + crew) must
always have (good) chances to "survive".
Redundancy is the Key. "Sully" case may be is a good example on the need of a "pilot" up front. The System suffered a major failure. Compare "tiny ice crystals" with "flock of canadian geese"
Problem seems:
You need a System specialist
and a Pilot. "Better" would be, first a Pilot and (last but not least) a System specialist.
The "microprocessor fired" the FE's. Is the automation (Super Systems) threatening the "pilot side" of the guys up front?