Home/Product
The object
Clinical Action Record
Raw model text does not enter the chart. A finding is a typed claim. The gate returns one object: what was proposed, what supports it, who may authorize this exact write, and what was decided.
Not for consequential clinical use. Research prototype.
What the object holds.
One record per proposed write. Fields below are the specified shape. Implementation status is on the right.
- Built
action
What would change in the record (write a finding, not “the model said”).
- Tested
payload
The typed finding: concept, value, laterality, status. Not a paragraph of prose.
- Proposed
payload_hash
Hash of the canonical payload. Approval names this hash.
- Tested
evidence[]
Identified sources. A quote, a reference, a source type. Attachment is not proof of truth.
- Open
sufficiency
Whether the attached evidence is enough for this consequence.
- Proposed
consequence
What happens if this is written: other clinicians will treat it as examined fact.
- Tested
policy.version
Which vocabulary and rules ran. ENT ear YAML is a placeholder, unverified by a clinician.
Registry shape tested. Clinical content Open.
- Not defended
authority
The person, bound to payload_hash. A click that does not name the hash is not this field.
Modelled, not enforced.
- Tested
decision
ALLOW · HOLD · REJECT · ACQUIRE plus a checkable reason code.
Construct/refuse tested. Hash mismatch Proposed.
- Open
receipt
Append-only record of the decision, for replay.
No durable audit module.
A typed claim is not a sentence the model generated. If the model cannot fill these fields, there is no finding to write.
Four decisions, in clinic language.
| Code | What the clinician sees | What happens to the chart |
|---|---|---|
| ALLOW | Evidence-backed finding. May enter the draft note. | Eligible to write. Still needs a person if policy says so. Not a production write today. |
| HOLD | Shown on screen. Not written as fact. | Chart unchanged. The proposal remains visible. |
| REJECT | Cannot construct the finding. No source, or the object is illegal. | No finding object exists. The refusal is still shown (as HOLD in the UI). Not a silent drop. |
| ACQUIRE | A named next question or missing exam. | Chart unchanged. The missing fact is named. Do not reason it into existence. |
Code
ALLOW
What the clinician sees
Evidence-backed finding. May enter the draft note.
What happens to the chart
Eligible to write. Still needs a person if policy says so. Not a production write today.
Code
HOLD
What the clinician sees
Shown on screen. Not written as fact.
What happens to the chart
Chart unchanged. The proposal remains visible.
Code
REJECT
What the clinician sees
Cannot construct the finding. No source, or the object is illegal.
What happens to the chart
No finding object exists. The refusal is still shown (as HOLD in the UI). Not a silent drop.
Code
ACQUIRE
What the clinician sees
A named next question or missing exam.
What happens to the chart
Chart unchanged. The missing fact is named. Do not reason it into existence.
REJECT is construction. HOLD is presentation. A finding that cannot be built is still shown, so a person can see what was refused.
What exists. What does not.
Exists (Tested)
Typed claim. Evidence required to construct a stated finding. One validation boundary. Draft / approve / amend state machine in memory. Refusal can be surfaced and the original value preserved.
Specified, not built (Proposed / Open)
payload_hash binding. Sufficiency engine. Durable append-only log. Standalone gateway service. Approver authentication.
Not defended
Approve-then-swap in the running kernel. Evidence injection (a quote can be attached and still be wrong). Adversarial testing. Production writes.
Designed for, not trusted by.
- ENT / outpatient clinicians — people who will say whether the schema is wrong.
- Health-IT — people who already own the chart, and should not confuse this with an EMR.
- Researchers — people who will argue with the decision codes.