Pre-pilot · research prototype · no production clinical writes

Home/Work

kernel/

Three tested modules. Two empty directories.

The kernel is not a model. It is the gate the Clinical Action Record runs through. Empty folders are a decision, not unfinished homework.

If a public repo exists it will be linked here first.

Solid vs dashed.

  1. Proposal (typed claim)

    Concept, value, laterality, status.

    Built
  2. evidence-engine

    No source, no stated finding.

    Tested
  3. policy-engine

    One validation boundary. Claim or Refusal.

    Tested
  4. sufficiency

    Enough information for this write?

    Open
  5. authority / payload_hash

    Person bound to these bytes.

    Not defended
  6. workflow-engine

    Draft, approve, amend. In memory.

    Tested
  7. audit-engine

    Empty directory. No durable log.

    Open
  8. model-router

    Empty directory. No second model to extract from.

    Proposed
  9. Chart write

    0 production writes.

    Open
Solid = tested code. Dashed = specified or empty. Persistence is not a kernel directory; its absence limits what authorization and audit can mean.

Modules.

  • evidence-engine

    Tested

    Claim, evidence, four-property Refusal. A stated finding with no source cannot be constructed.

    What it is
    The Claim / Evidence / Status model, plus Refusal: rejects, records, surfaces, preserves.
    Why it exists
    Extracted from ENT Clinical OS findings. Construction is the control, not a later filter.
    Status rests on
    evidence.py, with tests in test_evidence.py.
    What it does not do
    It does not verify that attached evidence supports the value. Attachment is not support.
  • policy-engine

    Tested

    Vocabulary registry. One boundary. validate() returns Claim or Refusal. The model does not choose which.

    What it is
    The vocabulary registry and the validator-disposes-candidates pattern.
    Why it exists
    Two domains converged on the same shape. That shared boundary is what was generalised.
    Status rests on
    registry.py, with tests in test_registry.py.
    What it does not do
    No declarative rule chains, and no laterality policy as a general feature.
  • workflow-engine

    Tested

    Draft, approve, amend. A correction is a new version. The prior version is kept. In memory.

    What it is
    The draft and approval state machine. amend() keeps the old version.
    Why it exists
    Extracted from ENT record.py. The point where a proposal becomes state.
    Status rests on
    draft.py, with tests in test_draft.py.
    What it does not do
    No persistence layer. No authentication on the approver. approver_id is a string.
  • audit-engine

    Open

    Empty. Versioning lives in workflow-engine once, on purpose. Storage-level guarantee is missing.

    What it is
    A directory with a README and no code.
    Why it exists
    Splitting it would duplicate the one versioning mechanism that is tested.
    Status rests on
    Nothing. Empty on purpose.
    What it does not do
    Nothing here is cryptographic. Durability is not a claim.
  • model-router

    Proposed

    Empty on purpose. Neither environment routes across models. Designing it now would be guessing.

    What it is
    Reserved, and deliberately empty.
    Why it exists
    Extract what two callers share. Do not invent the third.
    Status rests on
    A written research program, which is not a build trigger.
    What it does not do
    No code. No routing. No second model.

Empty on purpose.

audit-engine/ and model-router/ contain a README and no implementation. Splitting audit out of workflow would duplicate the one versioning mechanism that is tested. Building a router before a second model is forced would invert the extraction rule: extract what two callers share, do not invent the third.

Persistence is not a kernel folder. Neither environment has a store. Durability is therefore not a claim.

Claim in. Refusal out.

From the test test_a_stated_claim_needs_evidence. Research simulation. Not a clinical decision.

InputJSON
{
  "concept": "left_tympanic_membrane",
  "value": "normal",
  "status": "stated",
  "evidence": null
}
OutputJSON
{
  "error": "ClaimError",
  "message": "left_tympanic_membrane was recorded as stated with no evidence. Every stated claim traces to an identified source"
}
What a caller should surfaceJSON
{
  "type": "Refusal",
  "concept": "left_tympanic_membrane",
  "reason": "NO_EVIDENCE",
  "surfaced": true,
  "preserved_value": "normal",
  "next": "Do not write normal. The structure was not examined."
}

The object does not exist. The refusal does.

The same refusal, as a clinician would see it