Chosen for determinism and replay
Every component here was picked for one of three properties: it fails without losing a decision, it can be replayed against recorded input, or it can prove who did what.
Firmware
MICROCONTROLLER CLASSReal-time scheduling with a verified boot chain, so a device that cannot prove what it is running cannot influence a rule.
Edge
GATEWAYStreaming ingestion, deterministic rule evaluation, and an approval queue that survives a power cut.
Orchestration
SERVERDurable workflows survive restarts and partial failures. A run resumes rather than replays.
Explanation
MODEL LAYERTurns scores and signal features into the sentence at the top of an approval card, constrained to evidence present in the proposal.
Applications
WEB AND MOBILEOperations console, rule builder, fleet view and ledger. The approval surface is designed for a phone at arm's length, one-handed.
Identity
CROSS-CUTTINGWorkload identity everywhere, human identity at the gate, and a migration path for long-lived signatures.
Why Temporal
A workflow halfway through paging cardiology when a node dies resumes at that point elsewhere. It does not restart from the top, and it does not page twice.
Why Rust at the edge
The gateway has a hard latency budget and no operator. Predictable memory behaviour matters more than developer velocity in that one place.
Why a constrained model
The explanation layer may only restate evidence present in the proposal. It cannot introduce a clinical claim, because a card someone trusts must never be able to invent one.
Start with one ward, one shift, or one squad
A pilot runs four to sixteen weeks depending on deployment model. You bring the population and the responders. We bring devices, gateways and the first set of rules, and we measure override rate and time-to-answer from day one.