Research · modelling · evidence · learning

Safety science for complex systems.

Cambrensis develops practical methods and AI-supported applications for understanding how safety-critical systems work, vary and adapt.

HealthcareAviationProcess industriesInfrastructureResearch networks
What we do

A research and innovation hub for safety science.

Cambrensis brings together systems thinking, quantitative analysis and operational evidence. We develop methods, working models and research partnerships that help people examine complex sociotechnical systems with greater clarity.

01 / FUNCTIONAL MODELLING

Model how work is accomplished

Functional System Modelling reveals the activities, dependencies and conditions through which real systems produce both successful and unwanted outcomes.

02 / QUANTITATIVE ANALYSIS

Explore variability and uncertainty

We develop transparent analyses that connect functions, operational data, assumptions and simulation to test how system behaviour changes across conditions.

03 / INCIDENT INVESTIGATION

Reconstruct events as system behaviour

Structured investigation combines evidence, functional modelling and disciplined inquiry to explain what happened, how it emerged and why existing controls did not resolve it.

04 / AI-SUPPORTED APPLICATIONS

Make advanced methods usable

We design governed AI-supported tools that help analysts assemble evidence, build models, explore scenarios and retain an auditable line from source to conclusion.

An evidence-led approach

From system definition to useful action.

FrameDefine the system, purpose, boundary and questions.
ModelRepresent functions, couplings and operating conditions.
ConnectLink documents, observations, data and uncertainty.
ExploreTest variability, scenarios and alternative explanations.
LearnTranslate findings into decisions, trials and further research.
Application domains

Where complexity has consequences.

Our work concentrates on settings in which performance emerges from interactions between people, technology, organisation, information and changing operational conditions.

Care systems

Healthcare

Patient flow, bed occupancy, clinical work, incident investigation and the resilience of services under pressure.

Operational data

Aviation & flight analysis

Functional interpretation of flight data, actual-versus-expected performance and evidence-led examination of operational events.

Major hazards

Process industries

Functional HAZOP, barrier performance, plant operations and quantitative exploration of how deviations propagate through complex systems.

Under controlled evaluation

FRAIXL™

Functional modelling, evidence and governed AI reasoning

An emerging workbench for functional modelling, evidence and governed systemic reasoning.

FRAIXL™ is an emerging workbench for understanding and analysing complex sociotechnical systems. It combines executable Functional System Modelling, evidence, quantitative analysis and simulation with SAGE 1 — Systemic Agent Governance & Epistemics, our protocol for governed agentic reasoning.

Rather than asking an AI to absorb an entire system and produce an answer, FRAIXL keeps the model, evidence and system state explicit. SAGE 1 then governs how AI reasons over selected parts of that system.

  • Functional System Modelling
  • Evidence & provenance
  • Executable analysis
  • SAGE 1 reasoning
  • Challenger analysis
  • System Synthesis
  • Human review

Selected supervised trials are being used to establish how well the workbench supports users who were not involved in its development.

Discuss a supervised research trial FRAIXL is a trade mark applied for by Cambrensis Ltd. UK application UK00004446658.
Governed AI reasoning

SAGE 1

Systemic Agent Governance & Epistemics

AI that reasons within the system, not instead of it

SAGE 1 is the governance protocol used for agentic reasoning in FRAIXL and IRAG3. It constrains reasoning to evidence-linked, graph-bounded questions while preserving the wider system context.

Analyse locally. Explain systemically.

AI reasoning is organised into bounded Analysis Atoms, each tied to evidence, system state and surrounding relationships. Conclusions receive an explicit epistemic status so that evidence, derivation, inference, assumptions, hypotheses, contested interpretations and unresolved questions remain distinguishable.

Deterministic checks are applied wherever possible before AI interpretation is accepted. A separate Challenger tests assumptions, contradictory evidence and alternative explanations, while risk-based review directs human attention towards the findings that matter most.

System Synthesis then brings local analyses back together to examine feedback, interacting variability, shared constraints, adaptation, barrier dependencies and other behaviour visible only at system level. This prevents detailed AI analysis from becoming reductionist.

SAGE 1 systemic agent governance process from evidence through bounded analysis, validation, challenge and whole-system synthesis.
SAGE 1 preserves the line from evidence and local, bounded analysis to governed conclusions and whole-system understanding.

From evidence to governed human review

  1. Evidence
  2. System / Incident Graph
  3. Analysis Atoms
  4. Mechanical Validation
  5. Epistemic Classification
  6. Challenger
  7. System Synthesis
  8. Human Review
Model the system. Govern the reasoning. Understand the whole. Analyse locally. Explain systemically.
The Analysis Atom is the unit of reasoning, not the unit of system meaning. Whole-system context → local analysis → interaction between local findings → System Synthesis → revised understanding of the whole.

Current research status

Implemented and under controlled research evaluation
  • SAGE 1 has been implemented as an additive research capability.
  • 1,227 unique checks have been verified.
  • Demonstrations have been completed in Cement, Hospital, Air / Stable Approach, and IRAG3 incident analysis.
  • Analysis Atoms, controlled epistemic status, bounded retrieval, Challenger analysis, adjudication, review priority, replay and cross-atom System Synthesis have been implemented.
  • The generic FRAIXL kernel remains unchanged.
  • Domain models remain unchanged.
  • System-level interpretations remain human-confirmed.
  • The capability is not yet deployed as an independently qualified operational system.

Governed roles for software, AI and people

SAGE 1 keeps each contribution explicit so that AI supports expert judgement without replacing it.

System modelProvides structure and preserves the wider operating context.
EvidenceProvides provenance and a traceable basis for claims.
Deterministic softwarePerforms checks that can be resolved mechanically.
AI reasoningContributes interpretation, pattern recognition, hypotheses and challenge.
System SynthesisExamines interaction, emergence, feedback and shared constraints.
Human authorityRetains responsibility for important system interpretations and decisions.
Collaboration

Building the work around the problem.

Cambrensis convenes the combination of operational, academic, technical and domain expertise that complex safety questions require.

NETWORK / 01

Research consortia

We are exploring research consortia in three areas: healthcare systems, flight-data analysis and process industries. Each would bring operational evidence together with a functional model to examine how the system performs. We welcome interest from researchers, practitioners and organisations with relevant questions, expertise or suitable data.

Express your interest ↗
EXCHANGE / 02

International conferences and workshops

We organise focused events that bring researchers, practitioners, regulators and technology partners together to examine methods, cases and emerging applications.

Start a conversation

Bring us the system that needs to be understood.

We welcome conversations with research partners, safety practitioners, universities, healthcare organisations, aviation specialists and process-industry teams.

info@cambrensis.org
Cambrensis Ltd
Carey Dene
Carey
Herefordshire HR2 6NG
UK

01432 840 493