Pre-Directive technical evidence · preserved for provenance

Governed Harness 2.0

A bounded Hermes-based implementation candidate created before NIN–NAIO Master Directive v1.1. Its receipts remain inspectable; its older vocabulary no longer defines the canonical architecture.

Historical implementation evidence46/46 unit tests8/8 synthetic evaluationsDetached signature verifiedNot clinical or institutional deployment
Current authority: Directive v1.1 governs public definition, risk, data, action, applicability, and status claims. This page does not establish current conformance or universal enforcement.

Download the historical architecture statement Inspect machine evidence Download signature

Canonical definition

The environment is larger than any one runtime

Nurse AI OS is the governed professional environment in which nursing applications, agents, models, knowledge, memory, tools, and workflows operate. Florence-X is the orchestration and execution control plane. EDENA is the governance and assurance control plane. Authorized humans remain accountable.

Hermes currently provides a provisional, replaceable agent and memory substrate. OpenClaw is a provisional, replaceable tool-execution binding where implemented. Models and tools are replaceable utilities—not the product, authority, or accountable clinician.

The historical Harness tested one Hermes-native control approach. Nurse AI OS does not mechanically enforce every Florence-X or EDENA requirement across ChatGPT, Claude, Hermes, OpenClaw, or other hosts today.

Boundary: This evidence does not authorize PHI, patient-specific decisions, EHR access, named-personnel decisions, payments, credential handling, or unreviewed external action. It is not a HIPAA audit, clinical validation, security certification, conformance decision, or institutional approval.

Read it by role

What each executive should inspect

CNO · accountable authority

  • AI may observe, draft, recommend, or prepare work within scope.
  • Patient, workforce, and practice decisions remain human or institutional.
  • Orange and Red-E require formal controls; Red-P is prohibited.
  • No patient-outcome or compliance claim is made.

CIO · effective control

  • Data class and action mode must match the actual environment.
  • Every layer may narrow; none may re-grant denied authority.
  • Unknown fields and unmanifested tools should fail closed.
  • Profiles are not institutional security boundaries.

CTO · scoped evidence

  • Typed, content-hashed capability manifests were tested.
  • Hermes-native pre-tool and result-transform hooks were exercised.
  • Evidence is version- and environment-specific.
  • Historical tests do not prove complete mediation or current Directive conformance.

Directive v1.1 semantics

Risk tier, data class, and action mode are separate

DimensionValuesMeaning
Risk tierGreen · Yellow · Orange · Red-P · Red-EConsequence, review, prohibition, and exceptional controlled use. Red-P is prohibited; Red-E requires explicit authorization and assurance.
Data classD0 · D1 · D2 · D3 · D4Public/synthetic through restricted critical data. The public Community experience is D0/D1 only.
Action modeObserve · Draft · Recommend · Prepare Action · Act With Approval · Constrained AutonomyHow a capability may act after scope and risk are set. Unrestricted Autonomy is prohibited.

Invariants: risk never grants authority; action mode never lowers risk; data sensitivity never disappears; ambiguity moves risk upward and authority downward; a downstream configuration may narrow but never restore a denied capability.

Evidence retained—not generalized

What the July 2026 Harness snapshot established

46unit tests passed
8/8synthetic cases passed
2Hermes hooks exercised
0PHI used in testing
ControlHistorical scoped evidence
Capability registryContent-hash-verified manifests; unknown and unmanifested capabilities blocked in the tested source.
Monotonic compilerTests showed a downstream layer could not re-grant authority removed upstream.
Runtime hookThe plugin loaded through Hermes's plugin manager in an isolated temporary home.
RedlinesSynthetic MRN and credential-field cases blocked without logging argument values.
Human approvalAn external side-effect class returned Hermes's native approval directive.
ProvenanceA SHA-256 sequence chain detected mutation, deletion, and reordering.
Restart safetySide effects returned to review; only bounded idempotent read-only work could resume.

Dataset naio-edena-runtime-core · version 2026.07.13.1 · SHA-256 c8259d32dd85842c95f674050db930c25cfb264874e92a1bb8668bd31da1d223

Known · Assumed · Unknown · Recommended · Decide

Read the receipts with their limits

Known

The source executed in the tested canary; Hermes loaded the plugin; 46 unit tests and eight synthetic trajectories passed; the release evidence was signed with the existing trust anchor.

Assumed

The host operator remains trusted; Hermes behavior remains consistent with the tested version; any institution adds identity, endpoint, network, retention, procurement, labor, legal, privacy, and incident-response controls.

Unknown

Institutional concurrency, broad adversarial error rates, usability burden, council acceptability, organization-specific requirements, and complete input/output mediation remain unestablished.

Recommended

Treat the artifact as historical implementation evidence. Use public or synthetic data in an isolated profile; reassess after any model, tool, manifest, policy, connector, or host change.

Decide

Any promotion, integration, or new implementation requires current Directive semantics, exact scope, evidence, authorization, rollback, and accountable human ownership. Historical founder approval is not current institutional authorization.

Status: pre-Directive implementation evidence · no default-profile activation · no PHI eligibility · no clinical validation · no institutional approval · no NAIO Conformant claim.