Clinical release boundary
Implemented in the repository
- Patient APIs withhold machine-drafted clinical content until release.
- Release requires an active, verified doctor profile and recorded registration number.
- The assigned reviewer must access the retained source record before release.
Still open
- Isolated deployment and row-level-security validation
- Independent RMP workflow and usability review
- Clinically governed critical-result escalation