GSN Safety Case Overview
Saphira automatically generates Goal Structuring Notation (GSN) safety cases that demonstrate your system meets safety requirements through structured Goal → Strategy → Evidence chains—required for Proof of Validity (PoV) acceptance and regulatory approval.GSN Node Types
Goals (G)
Goals (G)
High-level safety claims to be demonstrated:
- Root goal: Overall system safety claim
- Sub-goals: Decomposed safety objectives
- Clear, measurable safety statements
Strategies (S)
Strategies (S)
How goals are argued to be satisfied:
- Argument approaches and methodologies
- Decomposition rationale
- Evidence grouping logic
Solutions (SOL)
Solutions (SOL)
Specific evidence supporting the argument:
- Requirements that address safety
- Test results and analyses
- Design documentation
- Certification artifacts
Assumptions (A)
Assumptions (A)
Key assumptions underlying the safety argument:
- Operational assumptions
- Environmental assumptions
- User behavior assumptions
- System boundary assumptions
Evidence (E)
Evidence (E)
Types of evidence required to support claims:
- Test reports
- Analysis results
- Certifications
- Verification activities
Context (C)
Context (C)
Contextual information for the argument:
- System description
- Operational domain
- Applicable standards
- Scope boundaries
Goal → Strategy → Evidence Chains
Complete Argument Structure
Saphira builds complete argument chains from your project data:Argument Strategies
Hazard Coverage Strategy
Hazard Coverage Strategy
Argue safety through hazard mitigation:
- All hazards identified
- Each hazard has mitigating controls
- Controls verified effective
- Residual risk acceptable
Design Control Strategy
Design Control Strategy
Argue safety through design measures:
- Requirements address safety
- Design implements requirements
- Architecture provides redundancy
- Fault tolerance demonstrated
Verification Strategy
Verification Strategy
Argue safety through V&V evidence:
- Test plans cover safety requirements
- Tests executed successfully
- Independent verification performed
- Compliance demonstrated
Standards Compliance Strategy
Standards Compliance Strategy
Argue safety through standards adherence:
- Applicable standards identified
- Clauses addressed
- Evidence documented
- Conformity demonstrated
GSN Generation Workflow
From Project Data
Step 1: Gather Project Artifacts
Step 1: Gather Project Artifacts
Saphira collects your safety artifacts:
- Requirements database
- HARA hazards and controls
- FMEA failure modes
- Test results and evidence
- Standards compliance status
Step 2: Generate GSN Structure
Step 2: Generate GSN Structure
AI generates the safety argument:
- Root goal from system description
- Strategies from analysis types
- Solutions from requirements
- Assumptions from project context
- Evidence links from test results
Step 3: Review and Refine
Step 3: Review and Refine
Edit the generated safety case:
- Adjust goal wording
- Add/remove strategies
- Link additional evidence
- Document assumptions
- Add contextual information
Step 4: Validate Completeness
Step 4: Validate Completeness
Verify safety case integrity:
- All goals supported by strategies
- All strategies have solutions/evidence
- No orphan nodes
- Traceability complete
- Gaps identified
Step 5: Export for Review
Step 5: Export for Review
Generate documentation:
- GSN diagram (visual)
- YAML/JSON structure
- PDF report
- Presentation format
GSN Wizard
For guided safety case creation:Answer-Driven Generation
Answer-Driven Generation
The GSN Wizard asks structured questions:System Context:
- System name and purpose
- Operational domain
- User types and assumptions
- Known hazards
- Mitigation strategies
- Risk assessment approach
- Safety function definitions
- Performance requirements
- Architectural elements
- Verification methods
- Test coverage
- Evidence types
- Applicable standards
- Compliance status
- Certification targets
Automatic Structure Generation
Automatic Structure Generation
From wizard answers, Saphira generates:
- Root goal using system name and purpose
- Strategies addressing specific hazards
- Solutions mapping wizard answers
- Assumptions from operational context
- Evidence requirements from verification strategy
Traceability and Links
Wizard Links
Each GSN node includes:- wizard_links: Question IDs that informed the node
- external_links: External references from answers
- requirement_ids: Linked requirements
- hazard_ids: Related hazards
- test_ids: Associated tests
Evidence Mapping
Automatic Evidence Linking
Automatic Evidence Linking
GSN nodes link to:
- Test reports from verification
- Analysis documents from assessments
- Certifications from third parties
- Design specifications from requirements
Gap Detection
Gap Detection
Saphira identifies:
- Goals without sufficient evidence
- Strategies without solutions
- Missing assumptions
- Incomplete argument chains
Industry Templates
Automotive Safety Case (ISO 26262)
Functional Safety Case
Functional Safety Case
Structure aligned with ISO 26262-10:
- Item definition goal
- HARA completeness argument
- Safety concept adequacy
- Verification evidence
- Confirmation measures
Industrial Safety Case (IEC 61508)
Safety Integrity Case
Safety Integrity Case
Structure for SIS justification:
- Safety function goals
- SIL allocation argument
- Architecture adequacy
- Validation evidence
- Lifecycle compliance
Autonomous Systems (UL 4600)
Autonomous Safety Case
Autonomous Safety Case
Structure for autonomous systems:
- ODD definition completeness
- Safety performance targets
- Development process adequacy
- Verification coverage
- Field monitoring plan
Export Formats
GSN Diagram Export
- SVG/PNG: Visual GSN diagram
- Mermaid: Embeddable diagram code
- Draw.io: Editable diagram format
Structured Export
- YAML: Machine-readable structure
- JSON: API integration format
- XML: Standards-based exchange
Documentation Export
- PDF: Formatted safety case report
- Word: Editable document
- HTML: Web-viewable format
Validation Features
Completeness Checking
Saphira validates:- All goals have supporting strategies
- All strategies have evidence or sub-goals
- No orphan nodes in structure
- Required assumptions documented
- Evidence references valid
Argument Strength Analysis
Assessment of:- Evidence quality ratings
- Assumption validity
- Traceability completeness
- Gap severity levels
Integration with Saphira Workflows
GSN safety cases integrate with:- Requirements: Goals trace to requirements
- HARA: Hazards become evidence for hazard coverage arguments
- FMEA: Failure modes support failure analysis arguments
- Tests: Test results become evidence nodes
- Standards: Clause compliance supports standards arguments
- Gap Analysis: Gaps become undeveloped goals or missing evidence

