Portal — System B · restricted
Specialist console
Review queue for patient questions. No draft answer is released without a clinician pressing send.
C1 · Access
Sign-in is not commissioned yet
The console needs authenticated, role-restricted, India-hosted server access with an audit log of every release decision. That server is specified but not yet built, and three decisions are outstanding (below). Named reviewers: to be filled by the CoE.
C2 · Decisions blocking the build
Who staffs the queue?
A named clinician and a named backup, with a stated review window. Without this the queue silently becomes unanswered mail.
Where does the language model run?
Self-hosted in India, an India-managed service, or a commercial API. Data residency and the DPO review both depend on this answer.
What escalation rate can the team absorb?
Every fail-closed message becomes human work. The boundary is deliberately over-cautious, so the escalation share is the operating cost.
C3 · De-identification boundary — self-check
runs on this device onlyPaste a realistic patient message to see exactly what a language model would receive. Nothing is sent anywhere — this check runs in your browser and is here so the boundary can be reviewed before sign-off.
C4 · Boundaries that do not move
- No identifiable text reaches a language model, ever.
- The boundary fails closed: uncertainty means a human, not a guess.
- No model output reaches a patient unread by a clinician.
- Screening instruments stay device-local. RD-T1, RD-T2 and the tracker never talk to this server.