Skip to main content
Concept guide · GSN Community Standard · 12 chapters

Goal Structuring Notation (GSN)

Turn a pile of ISO 26262 work products into an explicit, reviewable safety argument across 12 chapters: every element shape, both relationship types, the six-step construction method, modular arguments at scale, and the review practices that survive a confirmation review.

Chapters
12
Chapters
Core Elements
6
Core Elements
Relationship Types
2
Relationship Types
Pitfall Patterns
10
Pitfall Patterns
Included inExpert
Why this course · ISO 26262, Part 2

Why it pays for itself

Make safety arguments reviewable

Prose buries inference and coverage once an ASIL D item accumulates thousands of work products. GSN makes the claim-argument-evidence chain explicit enough for an assessor to read in minutes.

Build with the six-step method

Kelly's construction loop - state the claim, fix its context, choose a strategy, repeat, stop at evidence - turns a blank canvas into a well-formed argument with the right granularity.

Scale across organizations

Modules, away elements, and contracts let one argument span OEM, supplier, and SEooC boundaries, mapping the argument structure directly onto the DIA and distributed development.

After the course

What you’ll be able to do

Write claims that can be false

Phrase goals as propositions a reviewer can judge true or false, instead of activities or document names.

Build arguments with the six-step method

Decompose a top claim down to evidence, fixing context at each level and stopping at the right granularity.

Apply both relationship types correctly

Use SupportedBy for inference and InContextOf for scope, and keep structures well formed and legal.

Scale arguments across organizations

Split large cases into modules with away elements and contracts mapped onto OEM, supplier and SEooC boundaries.

Argue confidence, not just safety

Add assurance claim points and reason about defeaters and counter-evidence rather than trusting a clean diagram.

Pass the confirmation review

Spot the recurring fallacies, run a self-audit, and present what the assessor reads first.

The curriculum · 12 chapters

Chapter by chapter

  1. 01

    Why Safety Arguments Need Structure

    ISO 26262-2 (6.4.8) requires a safety case that connects evidence to the claim of acceptable safety, and prose collapses once an ASIL D item accumulates thousands of work products.

    • Claim, argument and evidence layers
    • Why prose buries inference and coverage
    • The Nimrod lesson and origins of GSN
  2. 02

    The Safety Case in ISO 26262

    How the safety case is compiled progressively across the lifecycle, fed by HARA safety goals and the confirmation review with independence that grows as ASIL rises.

    • Safety case anatomy and lifecycle build-up
    • Confirmation review per Part 2 Table 1
    • Safety goals, FSC and TSC as inputs
  3. 03

    The Core GSN Elements

    Six element types form the whole vocabulary: Goal, Strategy and Solution build the argument chain while Context, Assumption and Justification attach sideways and control how it reads.

    • Goals as propositions, not activities
    • Strategies that name the inference
    • Solutions citing real work products
  4. 04

    Relationships and Well-Formed Structures

    SupportedBy carries the inference and InContextOf scopes it, with a permitted-connections matrix and structure rules that determine whether a diagram is even legal GSN.

    • SupportedBy versus InContextOf semantics
    • The ten legal connections
    • Common syntax errors side by side
  5. 05

    The Six-Step Construction Method

    Kelly's loop for building an argument from a blank canvas: state the claim, fix its basis with context, choose a strategy, repeat, and stop the decomposition at evidence.

    • One decomposition level worked live
    • Granularity: knowing when to stop
    • Three disciplines the loop enforces
  6. 06

    Worked Example: The EPS Safety Argument

    SG-01 of an electric power steering item built node by node from top claim to evidence, showing which step produced which node and where SG-02 and SG-03 stay honestly undeveloped.

    • Item, safety goal and safe state
    • Full argument built phase by phase
    • What an assessor reads in 60 seconds
  7. 07

    Modular GSN: Arguments at Scale

    Modules, away elements and contracts let one argument span OEM, supplier and SEooC boundaries, mapping argument structure onto the DIA and distributed development.

    • Modules and away elements
    • Contracts and public interfaces
    • DIA and SEooC boundaries
  8. 08

    Patterns and Argument Reuse

    Reusable argument fragments captured with the pattern notation, the classic catalogue of patterns, and the instantiation discipline that keeps reuse from becoming copy-paste.

    • Pattern notation and parameters
    • A tour of the classic patterns
    • Instantiation discipline and libraries
  9. 09

    Confidence Arguments and Defeaters

    A tidy diagram is not yet a trustworthy one: assurance claim points expose confidence separately from the safety argument, and defeater thinking forces engagement with counter-evidence.

    • Safety versus confidence argument and ACPs
    • Defeaters: rebut, undermine, undercut
    • Living with counter-evidence
  10. 10

    Reviewing GSN Arguments and Spotting Fallacies

    Three review layers check syntax, semantics and sufficiency, with a field guide to the recurring fallacy classes and review formats that actually catch them.

    • What a GSN review actually checks
    • The fallacy field guide
    • Running the review effectively
  11. 11

    Tooling, Interchange and Alternative Notations

    Where GSN sits among argument notations, how the SACM metamodel enables interchange between tools, and what keeps an argument alive and maintained between releases.

    • The notation landscape
    • SACM as one metamodel underneath
    • Tool categories and keeping arguments alive
  12. 12

    Pitfalls, Checklist and Assessment Readiness

    The ten failure patterns reviewers see most often, what the assessor reads first, and a self-audit to run before the confirmation review.

    • The pitfall field guide
    • What the assessor reads first
    • A pre-review self-audit
Diagrams & Visuals

Not just text: the visual toolkit

Safety Case Anatomy

The three layers of claims, argument and evidence, fed by HARA safety goals and grounded in lifecycle work products.

Element Gallery

The six core shapes (Goal, Strategy, Solution, Context, Assumption, Justification) with phrasing rules and the classic mistake for each.

EPS Argument Structure

SG-01 decomposed from top claim to evidence, with SupportedBy and InContextOf links built phase by phase.

Permitted-Connections Matrix

Which elements may legally connect to which, separating load-bearing support from contextual scoping.

Modular Contracts

Modules, away goals and away contexts spanning OEM, supplier and SEooC boundaries across the DIA.

Safe State and Item Context

The EPS item, its safety goal and the safe state that scopes the worked argument.

Worked Example

An EPS Safety Argument from Goal to Evidence

Build the safety argument for SG-01 (unintended self-steering is prevented) of an electric power steering item, node by node, using the six-step method.

  • State the top goal: unintended self-steering of the EPS item is prevented
  • Scope it with context: the item boundary, the safe state, and the confirmed HARA
  • Choose a strategy: argue over each fault class that could cause self-steering
  • Decompose into sub-goals for detection, reaction and the assist limitation
  • Ground the leaves in evidence: FMEDA results, fault injection reports, verification reports
  • Leave SG-02 and SG-03 visibly undeveloped rather than faking closure
SG-01 Argument Skeleton
G1: Unintended self-steering is prevented (in context of safe state SS-01)

Unlock the full node-by-node build

Built for

Who this guide is for

  • Safety managers compiling a safety case toward a confirmation review
  • Engineers who must turn a pile of work products into an explicit argument
  • OEM and supplier teams splitting a safety case across a DIA boundary
  • Reviewers and assessors judging whether an argument actually supports its claim

Frequently Asked Questions

Common questions about Goal Structuring Notation (GSN)

GSN is a graphical notation for constructing and presenting safety arguments, defined by the GSN Community Standard. It expresses an argument through six core element types - Goals (claims), Strategies (the inference between claims), Solutions (evidence), plus Context, Assumption, and Justification attached sideways - connected by exactly two relationship types: SupportedBy, which carries the inference, and InContextOf, which scopes it. In automotive use, GSN structures the safety case that ISO 26262-2 requires, connecting lifecycle work products such as HARA results, FMEDA reports, and verification records into an explicit, reviewable argument that the item achieves acceptable safety.
No. ISO 26262-2 requires a safety case - a compiled argument connecting evidence to the claim of acceptable functional safety, progressively assembled across the lifecycle and checked by a confirmation review whose independence grows with ASIL. The standard does not mandate any notation for that argument. GSN is simply the most widely adopted way to make the argument explicit, because prose safety cases collapse under the volume of work products an ASIL D item generates, hiding gaps that a structured notation exposes.
Goals are propositions a reviewer can judge true or false - not activities or document names. Strategies name the inference used to decompose a goal, such as arguing over each fault class. Solutions are the evidence leaves, citing real work products. The three sideways elements control how the argument reads: Context fixes the meaning and scope of a claim, Assumptions state what is taken as given, and Justifications explain why an approach is adequate. Only ten element-to-element connections are legal, and the permitted-connections matrix decides whether a diagram is even well-formed GSN.
The construction loop popularized by Tim Kelly: state the claim as a falsifiable goal, fix the basis of the claim with context, choose and name a strategy for decomposing it, define the sub-goals that strategy produces, and repeat until claims can be grounded directly in evidence - then stop. The discipline it enforces is what matters: every inference is named, every claim has a fixed scope, and the decomposition stops at evidence instead of trailing off into undeveloped branches nobody flagged.
Twelve chapters covering the 6 core elements, both relationship types, the six-step construction method, modular GSN, confidence arguments and defeaters, review technique, and a catalogue of 10 pitfall patterns. The worked example builds the safety argument for an electric power steering safety goal node by node, from top claim to evidence. A free account starts you off, and the Pro and Expert plans unlock more of the library.

Start the course today

A free account unlocks one full concept guide, 3 work product templates, 1 guided process, the Markov simulator, and 5 practice exams per month. The Pro and Expert plans unlock more of the 78-guide library. No credit card required.