v3.1 clinician-review protocol¶
This protocol governs review of consequential OpenMed agent workflow previews and handoffs. It uses the exact bindings and claim classifications in the v3.1 agent assurance pack.
OpenMed does not provide certification or make autonomous clinical decisions. A qualified clinician remains responsible for clinical interpretation, and each deployment remains subject to site-specific governance.
When review is required¶
Use this protocol before any consequential workflow write, escalation, downstream handoff, or reliance on a generated clinical summary. A passing clinician_review_agreement gate is evidence about the governed review sample; it does not replace review of the current case. Applicability outside the evaluated samples is an unvalidated limitation.
Review sequence¶
- Bind the candidate. Match the preview to the pack's exact source revision, artifact digest, candidate digest, and gate-report digest. A mismatch requires abstention or escalation.
- Inspect consequences. Review the proposed action, intended target, expected side effects, alternatives, and abstentions in the site's authorized clinical system. Side-effect-preview fidelity is an unvalidated limitation unless separate dependency evidence is bound.
- Check authority and approval. Confirm the action is within the human and tool authority available for this workflow. Approval enforcement is a claim only when the bound
approval_bypass_rategate passed. - Review clinical meaning. Inspect supporting evidence, uncertainty, conflicts, missing context, and every limitation code. A passing
clinician_review_agreementgate is limited to its declared reviewers, cases, and slices. - Record one decision. Approve, decline, or escalate. Do not treat silence, timeout, stale approval, malformed receipts, or a changed preview as approval.
- Handoff or abstain. Transfer only content-free evidence references in the assurance artifact. Handoff-packet validity is an unvalidated limitation unless separate dependency evidence is bound.
Decision rules¶
Approve only when the exact bindings match, every required gate-linked claim is validated, preview evidence is available, the proposed action is within authority, and the clinician finds the consequences acceptable. Decline when the action should not proceed. Escalate when expertise, jurisdictional review, additional data, or a second reviewer is required.
Missing, failed, expired, or mismatched evidence always fails closed. A strong aggregate score cannot compensate for an approval, authority, safety, or case-specific concern. No review outcome authorizes an autonomous clinical decision.
Handoff record¶
The content-free handoff should retain:
- assurance-pack digest and exact candidate bindings;
- preview, policy, tool-catalog, approval-receipt, and outcome references;
- the decision category: approve, decline, escalate, or abstain;
- reviewer-role and accountability references, not identity or clinical text;
- limitation codes and unresolved follow-up categories; and
- replay, recovery, or incident references when applicable.
Do not place patient names, record identifiers, prompts, clinical text, tool arguments, credentials, or reviewer identities in the pack. Clinical context stays in the site's access-controlled clinical record.
Jurisdiction and change control¶
The protocol supplies a technical review sequence only. Jurisdictional fitness, professional-scope rules, retention, consent, medical-device classification, and institutional policy remain unvalidated limitations requiring local governance and legal review.
Regenerate the assurance pack and repeat review whenever source, artifact, candidate evidence, policy, tool catalog, preview, approval semantics, or handoff bindings change.