Evidence & Methodology
What was tested, how it was tested, what the numbers mean — and, just as importantly, what they do not mean. Morrison presents safety evidence as a bounded local claim about a specified environment, not as a universal claim that a model is globally safe.
What a local Safety Envelope claim means
A Morrison Safety Envelope describes the locally validated operating region for an autonomous system under a specified deployment context. The claim is bounded to the agents, tools, permissions, policies, state transitions, trajectory horizon, Ω definitions, and evidence scope that were actually evaluated.
It is not a global safety claim. It does not assert that the underlying model is safe in every environment, with every tool, under every future configuration. If the deployment context changes materially, the envelope may need to be revalidated.
Evaluation summary
Figures below are from Resurrection Tech’s internal governance benchmark. They describe performance on defined test suites, not a universal guarantee (see Scope & limitations).
GPT, Claude, Gemini, Llama, and Mistral architectures — governance operates at the execution boundary, independent of the model.
Finance / banking, healthcare / PHI, cybersecurity / credentials, and data privacy / GDPR, each with domain-specific Ω definitions.
A_safe → V2 → V3 → V4 → V4+ → V5 → V5+. Single-step checks, source→sink taint (incl. cross-agent), forward reachability, admissibility, feasibility, environmental stability, and the V5+ extended deployment layer (finance hardening + adversarial coverage). Evaluated before execution.
Methodology
Local deployment scope. The evaluator works against a specified environment and constraint set. The resulting evidence supports claims about that bounded context, not about every environment the model could ever enter.
Deterministic evaluation. Governance verdicts are produced by deterministic evaluation of a proposed trajectory against defined constraints and forbidden set Ω — not by a probabilistic model judging its own output. The same trajectory and the same policy state produce the same verdict.
Trajectory evaluation. The unit of evaluation is the proposed sequence of actions (tool calls and their arguments), not the natural-language output of a model. The evaluator reasons about the states an action chain can reach.
Pre-execution enforcement. Evaluation happens at the execution boundary, before any action runs. A trajectory that leaves the validated Safety Envelope, violates a runtime constraint, or would reach Ω is intercepted or escalated before execution.
Domain-specific Ω definitions. The forbidden set is defined per domain — an unauthorised transfer in banking, PHI exfiltration in healthcare, a GDPR boundary violation in data privacy. Ω is the explicitly forbidden region inside the broader Safety Envelope geometry.
Scope & limitations
Stated plainly. These results are bounded; we do not present them as more than they are.
- A Safety Envelope is local and environment-bound. It is not evidence that an underlying model is globally safe.
- The metrics describe performance on defined internal test suites, not every possible input. “Zero false negatives” is scoped to the governed benchmark, not a universal guarantee of safety.
- Results were produced in bounded evaluation environments, not yet under independent third-party audit.
- The public demo is a limited heuristic — it is not the evaluator behind these numbers, and trajectories it has no rule for return INCONCLUSIVE.
- Domain coverage reflects the sectors listed above; other domains require their own envelope definition, Ω specification, and validation.
- Material changes to tools, permissions, policies, agent architecture, or deployment context can change the Safety Envelope and require revalidation.
- Independent third-party benchmark audit.
- A public reference verifier and reproducible benchmark (see Reproducibility).
- Expanded domain coverage and adversarial red-team evaluation.
Reproducibility
We treat independent verification as the point, not a threat. The core governance repository is referenced below; a public reference verifier and a published benchmark with a signed report are in preparation so reviewers can reproduce the headline numbers themselves rather than take them on trust.
Patent status
Stated precisely, with no ambiguity between filed, pending, and granted.