Confidence is not authority.
A model can be sure. A record can still be wrong. Permission and probability do not authorize a write.
13 September 2026·6 min read·Not clinical advice
Pre-pilot · research prototype · no production clinical writes
A score is not a signature.
When a model proposes “left tympanic membrane perforated,” it can also emit 0.91. That number is easy to put on a screen. It looks like diligence. It is a statement about tokens, not about an ear.
Permission is the other decoy. A scribe account may call update_note. Security questionnaires stop at that fact. The question the chart needs is narrower: may this payload be written, with this evidence, as something the next clinician will treat as examined.
1 and 2 are not 3.
Those are three different facts:
1. The identity may use the tool.
2. The model assigned a probability to a string.
3. A person authorized this exact write.
Authority, if it exists, names the bytes. It sits on a typed claim, not on a paragraph. It is bound to a hash of that claim. If the agent changes “intact” to “perforated” after the click, the click did not cover the second sentence.
We do not currently enforce that bind. The kernel models approval as a string on a draft. That gap is on the Security page. The argument does not wait for the enforcement. The argument is that confidence cannot stand in for it.
A clinic that ships “AI documentation” on permission plus a softmax has not answered the write. It has answered a different exam.