Skip to main content

AI safety brief

The assistant is read-only and draft-only by design.

A short, dense reference for privacy officers and clinician advisers. The constraints below are technical, not promises. Print it, circulate it, attach it to your procurement pack.

The assistant is read-only and draft-only by design

It looks up, summarises, and drafts. It never signs a MAR cell, gives a medication, holds or refuses a dose, or changes a chart. Every clinical write still flows through the audited workflow your auditor already approved.

Participant data never leaves Australia

Records are stored only in ISO 27001 data centres in Sydney and Melbourne. AI inference runs in-region under a written Data Processing Agreement that prohibits training on your prompts.

Every prompt is logged and replayable

We log every prompt, every tool call, every value each tool returned, and the card the user actually saw, with user, participant, and shift context. Retention matches your clinical audit log. Your compliance officer can replay any session.

Per-tenant, per-role, per-participant opt-out

AI is a per-tenant feature flag, a per-role permission, and a per-participant opt-out. Run it fully off, on for coordinators and supervisors only, or on for everyone with specific participants excluded. The opt-out is recorded in the audit log.

The assistant cannot do clinical decision support

Our privacy policy states it plainly: CareLedger does not provide healthcare services, medical advice, clinical decision support, diagnosis, prescribing guidance, or medication recommendations. The assistant does not change that. It is on our list of things the assistant is never used for:

  • Dose calculations (milligrams per kilogram, sliding-scale insulin)
  • Allergy checks and drug-interaction decisions
  • PRN authorisation
  • Triggering or silencing clinical alarms
  • Free-form clinical text or advice
  • Writing to any chart, audit log, or billing record

Dose math, allergy checks, interactions, PRN authorisation, and alarms all run on validated, deterministic engines inside CareLedger. The assistant can surface their result; it cannot replace them. Read the full privacy policy →

If a card looks wrong

The rollback procedure.

  1. 1

    Open the audit tab and find the session by user, participant, or time.

  2. 2

    Replay the receipt: the exact prompt, the tool called, and the fields returned.

  3. 3

    Compare against the MAR, which is the source of truth and was never written by the assistant.

  4. 4

    If a clinical entry was made in error, correct it in the MAR through the normal append-only workflow; the original entry remains in the audit trail.

  5. 5

    Use "report this card" to flag the rendered card for review by your CareLedger contact.

Assistant changelog

We walk things back when they shouldn’t ship.

A dated, append-only record of what changed in the assistant itself.

  • 2026-08-12v0.3

    Added "what changed since last handoff" card.

  • 2026-07-30v0.2Removed

    Removed "suggest dose" preview after clinician-adviser review. Decision logic moved fully into the deterministic rules engine.

  • 2026-07-05v0.1

    First pilot: shift-handoff card, read-only, behind a feature flag. Two pilot organisations.

Need the audit-log spec for procurement?

We will walk your privacy officer through the PHI boundary and share the assistant audit-log format.