Historical implementation evidence · July 13–22, 2026

Pre-Directive Nurse AI OS architecture evidence

Created before NIN–NAIO Master Directive v1.1 and preserved for provenance. This is not the current canonical architecture and not a conformance claim.

Current authority: Directive v1.1 now defines Nurse AI OS, Florence-X, EDENA, applicability, evidence, risk tier, data class, and action mode. The downloadable report below preserves the historical body with a prominent superseding status notice; its old vocabulary is not controlling.

What the report recorded

A signed shadow-governance implementation candidate

The report captured one Hermes-native governance implementation, a six-package English distribution, its tests, evidence ledger, known gaps, and a recommendation not to promote enforcement. Its central safety decision remains valid: do not activate consequential capability without exact scope, evidence, human authorization, rollback, and current governance semantics.

Scoped evidence46/46 unit tests, 8/8 synthetic evaluations, detached signature verified for the recorded source.
Shadow observationThe plugin observed policy decisions but did not mechanically block tool execution.
Role packagesfive governed self-install Hermes build kits and one review-first overlay; inert on download.
No universal enforcementThe evidence does not prove complete mediation across hosts, memory, tools, channels, or outputs.
No PHI eligibilityThe public experience was not authorized to accept patient data or provide patient-specific support.
No formal authoritySigning did not establish clinical readiness, institutional approval, credential status, or conformance.

Current canonical model

Environment, orchestration, governance, and human authority

ComponentDirective roleCurrent public-status boundary
Authorized humansDecide what enters practice and remain accountable.Required in every state.
Nurse AI OSThe governed professional environment.Public Community experience available; higher editions gated.
Florence-XOrchestration and execution control plane.Capability-specific and developing; not a finished public mission-control service.
EDENAGovernance and assurance control plane.Advisory materials available; mechanical enforcement exists only where implemented and evidenced.
HermesProvisional, replaceable agent and memory substrate.Optional desktop host; not the product or authority.
OpenClawProvisional, replaceable tool-execution binding.Does not imply public deployment.
Models and toolsReplaceable intelligence utilities.Provider behavior and privacy remain separate boundaries.
Governing rule: every layer may narrow authority. No downstream layer may restore a capability denied upstream.

Directive v1.1 decision dimensions

Risk tier, data class, and action mode

DimensionCanonical valuesRule
Risk tierGreen · Yellow · Orange · Red-P · Red-ERed-P is prohibited. Red-E is exceptional controlled use requiring explicit authorization and assurance.
Data classD0 · D1 · D2 · D3 · D4The public Community experience is D0/D1 only. D2–D4 require separately governed environments.
Action modeObserve · Draft · Recommend · Prepare Action · Act With Approval · Constrained AutonomyUnrestricted Autonomy is prohibited.

The historical report's former autonomy labels are retired from current public governance. They may remain inside immutable evidence artifacts only as provenance of what was tested at the time.

Evidence snapshot

Implemented was not the same as enforced

EvidenceHistorical verified state
Harness releaseSigned implementation candidate; RSA-SHA256 verification returned Verified OK.
Runtime pluginnaio-edena-runtime 2.0.0-canary.2 operated in shadow observation; tool override false.
Tests46/46 unit tests and 8/8 synthetic trajectory evaluations passed.
Shadow ledger345 chain-verified events at the snapshot: 198 observed allows and 147 observed blocks.
Payload flagZero events with payload_captured=true at the report snapshot.
DistributionSix inert-on-download role packages with repository checksum verification.

A “would block” shadow event was observation evidence only. It did not mean the action was mechanically prevented.

Non-claims

What the historical report did not—and does not—establish

  • Current canonical architecture or Directive v1.1 conformance
  • Clinical safety, patient outcomes, clinical readiness, or medical-device status
  • HIPAA compliance, a BAA, security certification, or permission to process PHI
  • Institutional, procurement, legal, regulatory, or deployment approval
  • Nursing licensure, employment, competency, credential validity, or authority from role selection
  • Complete mediation of every input, memory, tool, connector, channel, or output path
  • Stewardship Council authorization or an active NAIO Conformant program
Bedside test: The public system may help prepare personal, learning, and professional D0/D1 work. It is not authorized to take a nurse's judgment, accept patient data, or act beyond the approved scope.

Preserved archive

Inspect the original evidence in context

The publication report includes its original diagrams, component matrix, runtime flows, role handoff, trust boundaries, residual risks, acceptance criteria, and appendices. The mutable publication adds only the superseding status notice; the dated July 13 pair remains the unchanged provenance snapshot.

Current mutable historical publication: 39 pages
PDF SHA-256: 0a48677e8027dfce5bbf598ded834242c13eafc2886bfa6a2adf33aeb2ac102d
Markdown SHA-256: d3b7f599581300492fb430c899e250d7a8b90571fe42b42c7eacba4432242b0d