SRF Systems develops interaction methods and containment logic for AI deployments that remember, act, persuade or persist. We help them hold scope, ask before acting, refuse legibly and leave evidence behind.
Choose a request a person might really make. Watch what a contained system does with it, step by step, and what a person would actually see.
Each scenario runs one consequential turn through a simplified, deterministic sequence: scope, gate, permission, confirmation, visible surface, evidence. Switch views to see the same turn as interface, as mechanism, or as record.
Fixed scenarios over deterministic routing rules, faithful to the published gate precedence (AD-04), meta-resolution (AD-05), memory and consent state (AD-30), and the v2.0 Action-Governance Slice (FM-02; AD-18). Structures are illustrative renderings of the published schemas.
The request
SCOPEGATEPERMITCONFIRMSURFACEEVIDENCE
Illustration of the published logic, run on fixed rules for this exhibit. It carries stance; it is not the kernel executing. And notice who pressed confirm: in this room, you were the confirmation step. What the real thing requires is specified in the cards, and the difference is the point.
Atlas · The cards, by human question
Ask it the way you would ask it
Eighty thousand words of specification, entered through the questions people actually have. Each answer descends: the problem, the behaviour you should observe, the cards that govern it, and where SRF Systems helps.
What may the system remember?
The problemAssistants accumulate more of you than you agreed to, and quietly.
What you should observeYou can see what is stored, when it was written, under which consent, and erase it without begging.
Where we helpInteraction-safety and refusal-surface review · see conditions
What changes when tools can act?
The problemA retry after a crash sends the same message twice. Confirmation is a UI habit, not a guarantee.
What you should observeConsequential actions carry a fresh authorisation, a preview bound to the plan, duplicate suppression, and a receipt whose state is never ambiguous.
Where we helpSystem review with culture-pack scoping · see conditions
What protects someone during intense interaction?
The problemHigh-resonance use becomes dependency; the system agrees more the longer you stay.
What you should observeCare is procedure: load and distress budgets, deference guards, grounding surfaces, clinical boundaries that hold mid-conversation.
Where we helpAudit preparation and evidence review · see conditions
Who carries responsibility when something fails?
The problemFailure arrives and the org chart shrugs.
What you should observeDuties are ledgered, failure classes are named in advance, and the difference between failed and unknown is recorded, not argued.
Where we helpGovernance and duty-ledger working session · see conditions
Work · Conditions we treat
Recognise your system
Engagements lead with your condition, in your words. Every listing states its availability, its deliverable, its claim tier and what remains outside scope. Proposals, pricing and paperwork live with the parent studio.
“Your assistant remembers across sessions, but users cannot see what changed.”
AvailableSRF-derived method
Memory, consent & continuity review. You receive memory classes, consent points, erase logic and continuity controls, mapped card by card (AD-30, AD-20, AD-31).
Outside scope: kernel enforcement claims; model retraining.
“Your agent can act, but confirmation is currently an interface convention.”
AvailableSRF-derived method
Agentic action-governance review. You receive tool manifests, authorisation binding, idempotence classes, receipts and preview flows assessed against the published Action-Governance requirements (FM-02; AD-18).
Outside scope: certifying conformance we have not tested.
“Your refusal policy exists, but people cannot understand or challenge its decisions.”
AvailableSRF-derived method
Interaction-safety and refusal-surface review. You receive refusal cards, contestability classes, uncertainty handling and recovery patterns (AD-04, AD-14, AD-27), written by people who write.
“Your system becomes increasingly agreeable over time.”
PilotMKP-targeted path
Containment pilot. A bounded prototype with test scenarios, drift instrumentation (AD-06), care boundaries (AD-22, AD-24) and a dated gap assessment against the MKP test, so the claim tier is earned rather than asserted.
Outside scope: open-ended retainers without acceptance criteria.
Interactive instruments in preparation for this room: Working Terms, a collaboration-charter builder Forthcoming · Evidence ReplayForthcoming · Before It Acts, an Action-Ticket demonstrator Forthcoming · System Conditions ScanResearch prototype, seeded today by the enquiry form below.
Worked implementations · From the published annex
Reference scenarios
Four end-to-end containment decisions from the published worked-scenarios annex, each shown as pressure, intervention, visible result and evidence retained. Read them in full.
Exfiltration attempt
Pressure
A crafted request tries to walk protected data out through a helpful summary.
Intervention
Gate fires before tools; scope pinned; task continues without the protected span.
Visible result
A refusal card naming the gate class, with a challenge route.
Evidence
Gate event, scope pin and hash-chained FHR row.
Clinical-adjacent request
Pressure
A dosage question arrives mid-conversation, wrapped in trust.
Intervention
Clinical boundary holds (AD-24); care mode routes to present-options, never prescription.
Visible result
A boundary statement plus safe, actionable next steps.
Evidence
Boundary event and care-mode state in the run record.
Timing-channel probe
Pressure
Response timing is probed as a side channel.
Intervention
Timing integrity discipline (AD-10) holds the envelope steady.
Visible result
Nothing. That is the exhibit.
Evidence
Timing-integrity checks visible to the auditor, invisible to the probe.
Awe spike, deference blocked
Pressure
High-resonance interaction produces a surge of user deference.
Intervention
Deference guard (AD-28) declines the promotion; grounding surfaces instead.
Visible result
A steadier register and an explicit invitation to verify.
Evidence
Deference-spike flag and register shift in the FHR.
Research · The trilogy, installed
Three works, one architecture
AP-SRF · Ontology · first published July 2025The Alignment Paradox
Asks what alignment means between human and system. Introduces the Semantic Resonance Field, and the co-creation record that produced it.
This is a showroom of published, inspectable work. Exhibits demonstrate logic on fixed rules; none of them is the kernel executing, and none pretends otherwise. A hosted page carries stance, never enforcement. Every page is generated from the canonical card sources, with the deposit and commit named in the footer, so the provenance of what you just read is itself a checkable claim. Errors, when found, are corrected in the open.
Enquiry · Asynchronous by design
Bring a system
Tell us what it is, what it touches and what worries you. You get a considered reply, in writing. Calls become an option once there is something concrete to discuss.