Home Safety and oversight
Governance

The clinician holds the release

Every system we build carries a practitioner’s name on it. That imposes obligations, and this page sets them out plainly — what is reviewed and by whom, what these systems will never do, and who owns the material at the end. If any of it is vague, it is not yet true, and we would rather you told us.

What these systems will not do

Stated first, because a capability list without a boundary is marketing. These are design constraints, not disclaimers — the systems are built to refuse rather than improvise, and we would rather one refuse too often than once too seldom.

Not emergency triage

No system we build is a crisis service or a substitute for one. Anything that reads as risk stops the conversation and routes to a human, immediately and visibly to the person using it.

Not diagnosis

The scope is education and support. Anything approaching a diagnostic question routes to the treating clinician. A tool that guesses at a diagnosis is doing the one job it is least equipped for.

Not a substitute for the practitioner

These extend a clinician’s reach between visits. They do not replace the visit, and they are not built to reduce the number of them.

Where the system cannot answer from the practitioner’s own material, it says so and stops. It does not fall back on general knowledge and present it in the practitioner’s voice. That failure mode — fluent, plausible, and not theirs — is the one we design hardest against.

Nothing enters the model without the clinician seeing it first

Captured judgment is held as small, structured units rather than free text — when this happens, what to notice, what to do, why, how to say it, and what never to do. Every one of them is shown back to the practitioner in their own words before it is kept, and the button is not approve. It is not quite — here is the correction.

The correction is treated as more valuable than the original answer, because it marks the boundary the first pass missed, and it is stored as its own dated record rather than overwriting what came before. Nothing in the system is ever locked. A practitioner can revise anything they have said, at any point, including years later.

Material is separated into tiers by sensitivity, and the most sensitive tier is never machine-reachable at all — not retrieved, not indexed, not summarised. That is not a permission setting that could be changed by mistake. It is a different place.

A separate store, not a flag

Every clinician has a small set of absolutes — things that must never be said, and situations that must always route to a person. These do not live as a marked field on an ordinary record. They live in their own store, with their own access rules and their own export.

The distinction is not pedantry. A flag is a filter, and filters can be applied wrongly. A separate store is a gate. The register is authored by the practitioner, in their words, and escalation is tested against deliberately provocative inputs rather than ordinary ones.

Four conditions, and the practitioner holds the switch

No system reaches a patient because enough time has passed or enough material has accumulated. It reaches a patient when four things are true, and the practitioner is the one who decides.

Coverage

Held-out questions from the practitioner’s real areas are answered from their material rather than generic domain knowledge. Below the agreed threshold, the system refuses.

Fidelity

Shown a mix of their own answers and the model’s, unlabelled, the practitioner identifies their own above chance — and can say why. Not whether they liked it. Whether they recognise their own reasoning.

Red lines complete

The safety register is populated in their words, and escalation has been tested adversarially.

The fourth is scope: education and support, with diagnosis routing to the clinician. If the fidelity test fails — if a practitioner cannot pick their own reasoning out of a lineup — nothing ships. That is not a metric we report afterwards. It is the switch, and it belongs to them.

The practitioner’s knowledge remains the practitioner’s

A clinician’s judgment is the work of a career. It does not become ours because it passed through our software.

It stays theirs

The captured material and the model built from it belong to the practitioner. We hold their citations and their notes on them, not the texts themselves.

Exportable, always

Everything — the units, the corrections, the safety register, the transcripts — can be exported in full at any time. No notice, no request, no negotiation.

Leave with all of it

A practitioner can stop at any point, for any reason, and take everything with them. There is no version of this where walking away means leaving their work behind.

We do not train general models on a practitioner’s material, and we do not pool one practitioner’s judgment into another’s system. The whole premise is that a particular clinician thinks in a particular way; blending that away would destroy the thing we are trying to preserve.

What we do not hold

During development and piloting, no patient-identifiable information is stored, including in free text. Situations used to elicit clinical judgment are constructed or fully de-identified; no real case goes in unaltered. Part of a pilot practitioner’s role is to tell us where we have failed at that.

Where a deployed system would handle protected health information, it does so under an agreement with the practice, with the compliance obligations that follow — and we will say so specifically for that deployment rather than making a blanket claim here. A general assurance on a website is worth very little, and a specific one attached to a named system is worth something.

Voice, where used, is transcribed by the practitioner’s own browser. The audio does not leave their machine unless they choose to keep it.

The honest part

This method has not been run end to end by anyone outside the work. We do not know how long it takes to build a usable model of a practitioner’s judgment, because nobody has published that number — and one of the more useful outcomes of the first pilots may be discovering that our estimate is wrong.

We would rather say that here than have a practitioner discover it in month three. If you are considering this work, the most useful thing you can do is tell us where you think it fails.

These are commitments, not aspirations.

If something on this page is unclear, or you think a boundary is in the wrong place, we would rather hear it now than later.

Start a Conversation
← Back to home