Pre-pilot · research prototype · no production clinical writes

Home/Notes

Security of the write

Approval must name the bytes.

A click on a screen is not an approval of whatever the agent writes next. If the payload can change, the click did not cover it.

13 September 2026·6 min read·Not clinical advice

Pre-pilot · research prototype · no production clinical writes

Approve-then-swap is an ordinary bug if you describe it in engineering language. It is a different event in a chart.

A person reads wording A: “Right tympanic membrane intact.” They approve. An agent, a retry, a helpful rewrite, commits wording B: “Right tympanic membrane perforated.” The log says a clinician signed. The bytes are not what they saw.

If the payload can change, the click did not cover it.

Access control does not catch this. The same role, the same session, the same tool. Review UX does not catch this if the payload is not frozen. “Human in the loop” does not catch this if the loop is a click on a moving target.

The specified fix is dull on purpose. Hash the canonical payload. Bind the approval to that hash. If the write does not present the same hash, the decision is APPROVAL_HASH_MISMATCH. The chart keeps A. B does not inherit the click.

This is Proposed. Experiment X-01 in the internal register is designed against the gap and is not run. approve() in the kernel still accepts an identity string and does not name the bytes. Showing the mismatch on the ENT page is a specification, not a production control.

The name of the failure is the contribution we can make today. If a vendor says a person approved, ask: approved which bytes?

The designed failure: APPROVAL_HASH_MISMATCH →