Research program

From meaning to consequence.

RISU studies how machine-readable claims acquire operational force as they move from semantic identity, through evidence and reliance, to action. Each project remains bounded to its own formal and empirical record.

Program map

01

Closure and reliance

What must be established before a consequence can safely govern action?

02

Evidence transport

What justifies a machine-readable premise after it crosses a system boundary?

03

Semantic preservation

What meaning survives translation into another interface or carrier?

Research thread 01

Reliance, finality, and consequence closure.

01.1

Consequence Closure

At the moment a machine acts, what can still change the specified consequence, and what would make that consequence determinate?

Consequence Closure turns residual action-boundary uncertainty into an inspectable assurance object. It preserves concrete consequence-divergent witnesses, derives inclusion-minimal semantic obligation families, keeps those obligations separate from realizable Establishments and Routes, and qualifies source-to-Core claims through P0/P1/P2 preservation. The frozen record includes an exact bounded Cedar P1 gate and prospective, cross-system commissioning at real effect cuts.

Understand Consequence Closure →Technical Note 2026-03 →Open the Inspector →Inspector archive v0.5.0 →
01.2

Reliance Before Closure

When can a machine act on one stable claim even though the broader workflow has not finished?

Reliance Before Closure turns that gap into an evidence-to-reliance interface. Provider-specific evidence qualifies the unresolved future boundary and a claim-specific stability margin, a proposed action receives its own claim-worsening bound, and a provider-blind consumer checks exact semantic and trust identity before deciding whether the action fits.

Understand Reliance Before Closure →Technical Note 2026-02 →Open Reliance Inspector →Inspector archive v0.4.0 →
01.3

Bounded Agent Closure

When an autonomous agent is retired, what evidence shows that the consequences still attributable to it have actually reached a stable end state?

Bounded Agent Closure separates revocation from operational closure. Its deterministic verifier follows a principal-relative consequence cone across authority, execution, commitments, and operational state, applies a terminal rule appropriate to each consequence, keeps missing coverage as UNKNOWN, and requires final-pair semantic convergence before issuing CLOSED.

Understand Bounded Agent Closure →Technical Note 2026-01 →Open the Inspector →Software archive v0.3.1 →

Research thread 02

Evidence qualification and transport.

02.1

Native++ v0.2

When a platform already provides a cryptographically verified native proof, can a frozen consequence-evidence substrate use it without rebuilding the same facts or changing its generic semantics?

Native++ v0.2 tested that question with GitHub release attestations. The fresh primary passed four precommitted release and asset-binding claims with no changes to the generic core, judgment vocabulary, provider I/O, proof algebra, or evidence-atom model. Mutation and wrong-release controls were rejected as required.

Read the experimental record →Canonical GitHub record →
02.2

ClosureProbe

When a system says nothing exists, did that conclusion remain warranted as evidence crossed adapters, protocols, clients, and model-facing boundaries?

ClosureProbe treats a negative conclusion as an evidence chain rather than a terminal string. It reconstructs the root at the receiver, binds the exact request, source context, scope, traversal, profile, and proposition, then identifies the first observed boundary where the claim loses, changes, or exceeds its support. The rc3 record freezes 50 adversarial and control cases.

Read ClosureProbe →Frozen rc3 release →
02.3

Negative Result Warrant

When a bounded query returns zero, what evidence is sufficient for a downstream operation to use that exact negative premise?

Negative Result Warrant separates an empty observation from an admissible machine premise. Provider-reported evidence must satisfy the source profile, bind one exact ZeroProposition, survive transport and receiver reconstruction, and then match the premise independently derived from the consuming operation. The frozen Algolia Q/Q′ contrast carries that chain from UNKNOWN to WARRANTED_ZERO and exact premise consumption.

Understand Negative Result Warrant →Open the Inspector →Reference profile →Agents SDK consumer →

Research thread 03

Semantic identity and preservation.

03.1

Projection Assurance

When a source operation becomes an agent-facing tool, do the distinctions that determine its consequence survive the projection and still govern the effect?

Projection Assurance tests preservation against a declared consequence rather than interface similarity. It separates correspondence, discrimination, operative placement, Exact Realization, and coverage, so a visible safeguard can fail when it stops governing the effect while a narrower target mechanism can still pass when it realizes the same consequence. The active RISU Verify frontier now extends that discipline toward executable behavior: observed counterexamples can ground regression, while positive preservation is admitted only inside a bounded execution model whose consequence relation is independently reconstructed. General native-software preservation remains out of scope.

Understand Projection Assurance →Technical Note 2026-04 →RISU Verify Workbench →Current software v0.7.0 →Frozen Evaluation Capsule →
03.2

OpenAPI→MCP Problem-Semantics Preservation Profile

When an OpenAPI-described API already exposes RFC 9457 Problem Details, does OpenAPI→MCP translation keep that meaning machine-addressable?

Under the frozen 12-case profile, three tested translation architectures each classified 11 in-scope cases as LOSS. A constructive translation over the tested MCP carrier capacity preserved all 11.

Experimental record →Canonical repository →Archived v0.1.0-rc1 →
03.3

HTTP→MCP Method-Inference Soundness Profile

When HTTP operations become MCP tools, what machine claims can safely be inferred from the HTTP method alone?

HTTP methods carry real semantics, but not enough to justify every annotation a translator might attach to an agent-facing tool. This executable profile turns that boundary into a 40-state oracle across GET, POST, PUT, PATCH, and DELETE, then compares the rule against frozen implementation and operation-level witnesses.

Read the experimental profile →Public review artifact →
03.4

Appeal

Can a generic client recognize that an affordance is for requesting review or reconsideration without learning every provider's vocabulary?

Appeal defines a carrier-neutral semantic identity for that purpose. Its first experimental Web Linking binding uses an RFC 8288 extension relation URI controlled by RISU Institute.

Semantic specification →Interoperability evidence →