Clinical safety architecture

Automation prepares the work. People decide care.

Records, routing, and approved actions can move deterministically. A named clinician retains the patient-specific decision.

Deterministic boundaries Full decision audit Named clinician sign-off

Hover or select the lock to trace the review boundary

01
Automated preparation

Approved sources and deterministic rules assemble the work.

02
Human review

Patient-specific interpretation stops at a named clinical boundary.

03
Audited action

Every decision, owner, and resulting action remains visible.

0AI-only diagnoses
0Autonomous dose changes
Every eventTraceable and reviewable

02A signal through the boundary

Information moves quickly. Clinical authority does not.

The product can capture, preserve, and route a patient-reported signal while keeping interpretation and patient-specific action with licensed people.

CRV / OPERATING VIEW
Page-specific model
01

Patient reports

01

“My swelling feels worse.”

The statement remains visibly patient-reported and time-stamped.

Unverified input
02

Cairava prepares

02

Context and routing

Approved rules attach source context, identify the review queue, and log the event.

Prepared for review
03

Licensed team decides

03

Meaning and next action

A qualified person interprets severity, determines treatment, and documents the response.

Human authority
04

Episode records

04

A visible resolution

The action, owner, timestamp, and remaining work stay reviewable.

Auditable ending
Boundary note

No generative output diagnoses the patient, changes a medication, or silently converts a patient statement into verified clinical fact.

A close profile of a person’s eye crossed by warm and teal light paths.
Clinical meaning remains with the qualified person reviewing the whole situation.

03Attention stays human

The system can prepare the signal. A person must see the patient.

Useful automation makes context easier to review without claiming the authority to interpret severity, determine treatment, or replace licensed judgment.

  • 01Source preserved
  • 02Review required
  • 03Action audited

04The boundary in practice

Move information toward review without pretending to interpret it.

Workflow automation and approved rules can organize and route. Licensed people retain authority over meaning, severity, treatment, and resolution.

CAN

Cairava can prepare

Explain approved content, organize due work, adapt communication, capture barriers, and apply approved routing rules.

  • Source remains visible
  • Patient reports remain distinct
  • Every event is logged
HUMAN

Only people can decide

Diagnose, interpret symptoms, recommend treatment, change medication, set clinical thresholds, or close a clinical concern.

  • Licensed review owns meaning
  • Hospitals approve pathway rules
  • Resolution requires documented action

HUMANThe boundary in practice

Only people can decide

Diagnose, interpret symptoms, recommend treatment, change medication, set clinical thresholds, or close a clinical concern.

Inside this chapterMove information toward review without pretending to interpret it.

Workflow automation and approved rules can organize and route. Licensed people retain authority over meaning, severity, treatment, and resolution.

  • Licensed review owns meaning
  • Hospitals approve pathway rules
  • Resolution requires documented action
Learn moreSee the human review gate in action

05Provenance stays visible

Verified, patient-reported, and pending are not interchangeable.

Every important item should show where it came from, whether it has been reviewed, and what the system is permitted to do next.

01

Verified plan

Hospital-authored instructions

The approved source and review state remain attached.

02

Patient reported

A barrier needs review

A patient statement is visible without being promoted into verified clinical information.

02Provenance stays visible

A barrier needs review

A patient statement is visible without being promoted into verified clinical information.

Inside this chapterVerified, patient-reported, and pending are not interchangeable.

Every important item should show where it came from, whether it has been reviewed, and what the system is permitted to do next.

Learn moreExplore the provenance states
03

Pending action

Follow-up is prepared

The next operational action remains human-owned until it is reviewed and resolved.

06Authenticated server boundary

Clinical change follows a narrow, auditable path.

The patient experience does not write directly to clinical tables or resolve conflicts locally.

01

Patient confirms

A person intentionally submits the reported update.

02

Server authenticates

Authorization and scope are checked before mutation.

03

Idempotency protects

A stable key prevents accidental duplicate actions.

04

Human reviews

Clinical meaning and escalation remain staff-owned.

05

Audit records

Source, owner, state, and resolution remain traceable.

07Privacy-conscious by construction

Keep sensitive detail out of places it does not belong.

These are product and engineering principles—not certification claims. Production controls remain subject to partner review.

01

Minimum necessary

Each surface receives only the information required for its narrow role.

02

Sensitive detail stays inside

Notifications stay generic; context belongs behind authenticated boundaries.

03

Credentials stay server-side

Clients receive only short-lived, narrowly scoped access.

04

No sensitive logging

Patient details, free text, tokens, and source documents stay out of logs.

08Governance before production

Safe boundaries need an operating process—not only interface language.

Each partner should approve how pathways change, who can access the system, how escalations are rehearsed, and how incidents or unexpected behavior are reviewed.

01

Pathway version control

Clinical content, routing rules, thresholds, and owners change only through an approved review path.

02

Role and access review

Access reflects job responsibility and is reviewed as people, teams, and vendors change.

03

Escalation rehearsal

Synthetic cases test handoffs, fallback behavior, missing data, and after-hours ownership.

03Governance before production

Escalation rehearsal

Synthetic cases test handoffs, fallback behavior, missing data, and after-hours ownership.

Inside this chapterSafe boundaries need an operating process—not only interface language.

Each partner should approve how pathways change, who can access the system, how escalations are rehearsed, and how incidents or unexpected behavior are reviewed.

Learn moreReview the partner validation path
04

Incident and change review

Unexpected behavior has a documented owner, evidence trail, containment step, and approval before release.

09Questions, clearly answered

What hospital teams usually ask first.

Specific boundaries create better first conversations.

Does Cairava independently assess severity or recommend treatment?+

No. AI supports language and workflow; licensed care teams own interpretation, treatment, medication changes, and clinical resolution.

How is patient-reported information shown?+

It stays visibly distinct from verified clinical information and pending review state.

Is this a compliance certification?+

No. It describes intended product and engineering boundaries. Regulatory, security, legal, and deployment claims require partner-specific review.

11See the workflow together

Make the boundary reviewable.

Review what the system prepares, where it stops, and what the hospital must approve before deployment.

Review the human gates