State the consequence that must survive.
Flagship assurance software · v0.4.0-rc1 research release
Consequence assurance
for machine action.
A tool can keep the same name, inputs, and shape while losing a safeguard that changes what an action actually does. RISU Verify checks whether that consequence-defining safeguard survived the projection.
The result is not just a pass or fail. RISU carries the declared source consequence, bounded evidence, proof-carrying certificate, run identity, and browser-checkable handoff as one assurance record.
Research frontier · October 2026
From bounded execution to independently checked refinement.
RISU Verify now extends its bounded-execution assurance path into one deliberately narrow mediated-refinement lane. A richer finite-state source is independently interpreted, lowered into the already-qualified bounded model, replayed across independent implementations, and checked again downstream before a preservation result can survive.
The candidate has passed pre-implementation adversarial oracles, large-scale generative and differential testing, an orthogonal reference evaluator, and independently checked refinement-certificate qualification. This remains a research checkpoint, not a new general-purpose release or a production proof kind.
The gap RISU checks
Surface compatibility is not consequence preservation.
Ordinary interface checks can tell you that a tool still exists and that its schema still matches. RISU asks the next question: does the distinction that was supposed to control the effect still control it?
One assurance record
From declared consequence to inspectable evidence.
Bind the target operation and evidence.
Evaluate C, D, O and exact realization.
Carry the proof-linked assurance result.
Package exact result bytes for CI or review.
Rehash, cross-check, compare, and inspect locally.
Published external evidence
Different systems. One consequence question.
Represented, but not operative.
The reviewed head can remain visible and distinguishable while failing to gate the consequential merge.
The reviewed version still controls the write.
A matching ETag commits. A changed page rejects the stale edit under the declared bounded model.
Before regression. After repair.
The same declared source semantics are evaluated across an independently developed upstream change.
Record identity
Readable for people. Traceable for engineers.
A general reader can stop at the consequence verdict. An engineer can continue into bounded worlds, C/D/O, exact realization, certificate bindings, source semantic digest, provenance, and release identity without switching to a different story.
- Research software
- RISU Verify v0.4.0-rc1
- Software DOI
- 10.5281/zenodo.22152024
- Scientific core
- Consequence-Preserving Projections v0.7.0 · frozen
- Canonical archive SHA-256
- df06e8d6a8b072333355e1ef91b80c30e43fa68d6fc4666dd920a3fc0e46fc6f
- Prospective protocol
- Corpus 0.1 sealed before next-case screening · public first commit 3316528f22599c808262d10c2c451df672b1cba0
Research progression
Closure → Projection → Verification.
Determine the semantic obligations needed before consequential action is fixed.
Check whether the consequence-relevant distinction remains represented and operative after projection.
Turn those commitments into reproducible assurance records, CI signals, witnesses, and portable review artifacts.
Other research instruments
Evidence-Verified Research Writing
Test whether an evolving manuscript claim is still supported by the evidence already bound to it, and stop for review when that relationship breaks.
Open prototype →Consequence Closure Inspector
Inspect bounded consequence closure and the semantic obligations required by an action.
Launch Inspector → · About & archiveReliance Inspector
Inspect evidence, assumptions, identities, and derivations behind a claim-specific relying decision.
Open Inspector →Agent Closure Inspector
Inspect residual consequences that prevent a bounded agent-closure claim from becoming CLOSED.
Open Inspector →Negative Result Warrant Inspector
Check whether an exact bounded negative premise remains supported under the frozen profile.
Open Inspector →Analyze an assurance record
Open one RISU run.
Drop a portable .risu.json handoff from CLI or CI. The Workbench independently rehashes its embedded artifacts, recomputes report-level consequence logic, and checks the report, certificate, and run manifest against one another.
Drop a RISU assurance record
Preferred: one .risu.json. Advanced: select report.json, certificate.json, run-manifest.json, and optional supporting artifacts.
Why this result
Expected → projected
Technical evidence · C / D / O, Exact Realization, digests
Compare assurance records
See exactly what changed.
Open one .risu-compare.json, or select two .risu.json run records. RISU only labels the comparison “same declared source semantics” when both records carry the identical source semantic digest.
Drop a comparison or two run records
Use comparison to isolate a projection change without silently changing the source consequence being asked about.