Portal — System B · restricted

Specialist console

Review queue for patient questions. No draft answer is released without a clinician pressing send.

C1 · Access

Sign-in is not commissioned yet

The console needs authenticated, role-restricted, India-hosted server access with an audit log of every release decision. That server is specified but not yet built, and three decisions are outstanding (below). Named reviewers: to be filled by the CoE.

C2 · Decisions blocking the build

  • Who staffs the queue?

    A named clinician and a named backup, with a stated review window. Without this the queue silently becomes unanswered mail.

  • Where does the language model run?

    Self-hosted in India, an India-managed service, or a commercial API. Data residency and the DPO review both depend on this answer.

  • What escalation rate can the team absorb?

    Every fail-closed message becomes human work. The boundary is deliberately over-cautious, so the escalation share is the operating cost.

C3 · De-identification boundary — self-check

runs on this device only

Paste a realistic patient message to see exactly what a language model would receive. Nothing is sent anywhere — this check runs in your browser and is here so the boundary can be reviewed before sign-off.

C4 · Boundaries that do not move

  • No identifiable text reaches a language model, ever.
  • The boundary fails closed: uncertainty means a human, not a guess.
  • No model output reaches a patient unread by a clinician.
  • Screening instruments stay device-local. RD-T1, RD-T2 and the tracker never talk to this server.