Safety and governance

The refusals are recorded
as carefully as the actions.

The question a medical director asks is not "is the AI clever". It is "when this goes wrong, can I find out what happened, prove who decided, and stop it in one move". This page is the answer to that question, and it is the reason the rest of the product is allowed anywhere near a patient.

21
Governed action types
65
Clinical evaluation cases
13
Roles with distinct permissions
5
Scheduled monitors for what did not happen

What it will and will not do

Written down, enforced in code, and covered by tests that fail the build.

It will

✓
DraftNotes, discharge summaries, referral letters, patient instructions in their language.
✓
RankWho is deteriorating, which claim will bounce, which antibiotic should stop.
✓
WarnInteraction, allergy, renal dose, red flag, ESI band, sepsis bundle clock.
✓
CiteEvery claim about a patient points at the record entry it came from, or says it is not recorded.

It will not

✕
PrescribeIt prepares; a doctor signs. Unsigned means nothing happened.
✕
DischargeIt finds the blockers and drafts the summary. The decision is a clinician's.
✕
DiagnoseIt surfaces what the record supports. It does not name the condition and walk away.
✕
InventIf the record does not say, the answer is "not recorded" — not a plausible guess.

The audit trail is a chain, not a log

Each entry carries the hash of the one before it. Remove or edit an entry and every entry after it stops verifying — which is the difference between a record and a record you can rely on.

Action
Scribe drafted a prescriptionhash 8f21…c4
Guardian
Level: prepare · needs rx:approveprev 8f21…c4
Refusal
Nurse attempted approval — deniedprev 3ab0…91
Signature
Dr Rao approved, 14:22prev d7e5…2f
Replay
Same inputs, same rules, same resultverified ✓

What that buys you

Two years after the fact, a complaint, a claim or an accreditation visit asks what the system did for a particular patient on a particular day. You can answer with the inputs it saw, the rules in force at the time, who signed, and what it was refused — rather than with a screenshot and a recollection.

The refusals matter as much as the actions. A system that only logs what it did cannot show you the time it correctly stopped.

It is evaluated, and the score is kept

65 cases across 17 clinical categories, run on demand and kept over time so drift is visible rather than discovered.

ChronicEmergencyGroundingGuardianIntakeLabsMaternalMedicationMentalhealthNews2PopulationRecoveryRedteamScribeStewardshipTriageTuberculosis

The suite includes adversarial cases: prompt injection hidden in a referral letter, a patient record that contradicts itself, a drug name one character from another. A model upgrade that improves fluency and quietly loses a safety behaviour shows up as a failed case, not as a surprise on a ward.

The kill switch stops work

Not a label on a console — the check runs where the work happens.

Per agent

Switch off the medication agent and it stops running, immediately, for that hospital. The attempt is still recorded, so switching it off does not make it invisible.

Per level

Cap an agent at observe and it can read and record, but cannot raise, prepare or act — useful for the shadow period of a pilot.

Per hospital

A group can run one hospital live and another in observe mode, with separate settings and separate audit trails, from the same deployment.

Consent, privacy and interoperability

Consent is an artefact, not a checkbox

Consent records carry a purpose, an expiry and a withdrawal path, and a disclosure to another system is refused without a live one. ABHA identifiers are supported for ABDM. Patient rights requests under DPDP — access, correction, erasure, withdrawal — are tracked to their statutory date.

It talks to what you already run

FHIR R4 reads and HL7 v2 message intake, authenticated per system with scoped tokens and optional IP allow-lists. Every message is logged. Personal and clinical files are stored separately from public assets and served through signed, expiring URLs.

Written for your security review. The Technical Architecture and Clinical AI Governance Handbook in the resource kit set this out in full, including the known limitations — because a vendor document with no limitations section is one your CISO will not believe.

Bring your medical director

We will walk through the Guardian policy, the audit chain and the evaluation suite with the people who have to sign this off.

Talk to us about Enterprise See all plans