Synthetic
MaxArc Global Health Impact Platform
Interoperability, Data Exchange, Partner Integration, Consent & Interface Governance
Cross-module interoperability, data-exchange, and integration governance.
A synthetic governance demonstration and simulation only — not a live integration engine, not a production API gateway, not a health information exchange, not a message broker, not a production FHIR or HL7 server, not a live DHIS2/OpenLMIS/OpenLab/EMR/EHR/laboratory/ministry/funder/banking/identity/customs/logistics/regulatory integration, not a real consent-management platform, not a real patient-data exchange, not a production webhook processor, and not a live data-export service. No outbound network calls, inbound webhooks, real OAuth/OIDC, real keys, real tokens, real message delivery, or real database writes occur. Approved does not mean production-connected; active-synthetic does not mean live; delivery does not prove receipt; receipt does not prove semantic correctness; acknowledgement does not prove reconciliation. Source systems remain authoritative. AI is assistive only and never transmits, activates, approves, discloses, or bypasses human controls.
Not activated
Remain visible
≠ live
Remain visible
Stays unknown
Flagged
Ambiguous / partial
Stays unknown
≠ active
≠ active
Human review
Distinct from consent
≠ security
Remain visible
Remain partial
Remain visible
Remain visible
No silent dupes
Not suppressed
Remain visible
Human-reviewed
Remain visible
Remain visible
Time-bound
Remain visible
High-risk
Blocked / pending
Human review required
Append-only
Interfaces (approved ≠ production-connected; active-synthetic ≠ live)
Every interface identifies source module, target capability, partner, type, exchange mode, status, version, schema, terminology mapping, data classification, consent requirement, lawful-basis/minimum-necessary/security/privacy reviews, owner, operator and reviewer roles, approval, activation, compatibility, last synthetic test, next review, retirement, evidence, and audit. Interface existence does not prove delivery; successful testing does not authorize production activation.
| Interface | Name / target | Status / compatibility | Posture / audit |
|---|---|---|---|
| IFACE-01 fund-accountability · api · synchronous |
Fund Accountability Exchange Interface → disbursement-and-expenditure-reconciliation · partner PTN-FUND · financial-sensitive |
active-synthetic compatible approval approved · activation activated-synthetic · v1.0 |
consent consent-not-required · schema SCH-01 · map TMAP-01 approved ≠ production-connected · active-synthetic ≠ live · audit AUD-IFACE-01 |
| IFACE-02 stockpile-logistics · message · asynchronous |
Stockpile Logistics Exchange Interface → commodity-stock-and-dispatch-sync · partner PTN-WH · operational |
approved compatible approval approved · activation not-activated · v2.0 |
consent consent-not-required · schema SCH-02 · map TMAP-02 approved ≠ production-connected · active-synthetic ≠ live · audit AUD-IFACE-02 |
| IFACE-03 lab-operations · file-batch · batch |
Lab Operations Exchange Interface → laboratory-order-and-result-routing · partner PTN-LAB · clinical-sensitive |
test-only compatible approval approved · activation not-activated · v3.0 |
consent consent-required · schema SCH-03 · map TMAP-03 approved ≠ production-connected · active-synthetic ≠ live · audit AUD-IFACE-03 |
| IFACE-04 patient-continuity · event-stream · offline-sync |
Patient Continuity Exchange Interface → referral-and-followup-exchange · partner PTN-FAC · clinical-sensitive |
draft unknown approval pending · activation not-activated · v1.0 |
consent consent-required · schema SCH-04 · map TMAP-04 approved ≠ production-connected · active-synthetic ≠ live · audit AUD-IFACE-04 |
| IFACE-05 restricted-patient-locator · reference-sync · synchronous |
Restricted Patient Locator Exchange Interface → authorized-locator-request-and-denial · partner PTN-FAC · restricted |
pending-review unknown approval pending · activation not-activated · v2.0 |
consent consent-required · schema SCH-05 · map TMAP-05 approved ≠ production-connected · active-synthetic ≠ live · audit AUD-IFACE-05 |
| IFACE-06 asset-management · api · asynchronous |
Asset Management Exchange Interface → asset-transfer-and-custody-update · partner PTN-LOG · operational |
degraded compatible approval approved · activation activated-synthetic · v3.0 |
consent consent-not-required · schema SCH-06 · map TMAP-06 approved ≠ production-connected · active-synthetic ≠ live · audit AUD-IFACE-06 |
| IFACE-07 program-performance · message · batch |
Program Performance Exchange Interface → program-results-reporting · partner PTN-NP · programmatic |
suspended compatible approval approved · activation not-activated · v1.0 |
consent consent-not-required · schema SCH-07 · map TMAP-07 approved ≠ production-connected · active-synthetic ≠ live · audit AUD-IFACE-07 |
| IFACE-08 ai-intelligence · file-batch · offline-sync |
Ai Intelligence Exchange Interface → ai-signal-exchange · partner PTN-TECH · operational |
rejected compatible approval rejected · activation not-activated · v2.0 |
consent consent-not-required · schema SCH-08 · map TMAP-08 approved ≠ production-connected · active-synthetic ≠ live · audit AUD-IFACE-08 |
| IFACE-09 country-rollout · event-stream · synchronous |
Country Rollout Exchange Interface → rollout-readiness-synchronization · partner PTN-MIN · operational |
expired compatible approval approved · activation not-activated · v3.0 |
consent consent-not-required · schema SCH-09 · map TMAP-09 approved ≠ production-connected · active-synthetic ≠ live · audit AUD-IFACE-09 |
| IFACE-10 authorized-review-room · reference-sync · asynchronous |
Authorized Review Room Exchange Interface → evidence-reference-exchange · partner PTN-AUD · restricted |
superseded incompatible approval approved · activation not-activated · v1.0 |
consent consent-unknown · schema SCH-10 · map TMAP-01 approved ≠ production-connected · active-synthetic ≠ live · audit AUD-IFACE-10 |
| IFACE-11 executive-review-packet · api · batch |
Executive Review Packet Exchange Interface → review-packet-reference-exchange · partner PTN-FUND · programmatic |
retired compatible approval approved · activation not-activated · v2.0 |
consent consent-not-required · schema SCH-11 · map TMAP-02 approved ≠ production-connected · active-synthetic ≠ live · audit AUD-IFACE-11 |
| IFACE-12 identity-access-governance · message · offline-sync |
Identity Access Governance Exchange Interface → access-assertion-exchange · partner PTN-TECH · security-sensitive |
blocked compatible approval blocked · activation not-activated · v3.0 |
consent consent-not-required · schema SCH-12 · map TMAP-03 approved ≠ production-connected · active-synthetic ≠ live · audit AUD-IFACE-12 |
| IFACE-13 data-quality-reconciliation · file-batch · synchronous |
Data Quality Reconciliation Exchange Interface → data-quality-correction-exchange · partner PTN-REG · operational |
active-synthetic compatible approval approved · activation activated-synthetic · v1.0 |
consent consent-not-required · schema SCH-13 · map TMAP-04 approved ≠ production-connected · active-synthetic ≠ live · audit AUD-IFACE-13 |
| IFACE-14 risk-incident-case-governance · event-stream · asynchronous |
Risk Incident Case Governance Exchange Interface → risk-and-incident-escalation-exchange · partner PTN-AUD · restricted |
approved compatible approval approved · activation not-activated · v2.0 |
consent consent-unknown · schema SCH-14 · map TMAP-05 approved ≠ production-connected · active-synthetic ≠ live · audit AUD-IFACE-14 |
| IFACE-15 policy-compliance-control-governance · reference-sync · batch |
Policy Compliance Control Governance Exchange Interface → policy-and-control-evidence-exchange · partner PTN-REG · programmatic |
active-synthetic compatible approval approved · activation activated-synthetic · v3.0 |
consent consent-not-required · schema SCH-15 · map TMAP-06 approved ≠ production-connected · active-synthetic ≠ live · audit AUD-IFACE-15 |
| IFACE-16 service-reliability-continuity · api · offline-sync |
Service Reliability Continuity Exchange Interface → reliability-and-continuity-status-exchange · partner PTN-TECH · operational |
test-only compatible approval approved · activation not-activated · v1.0 |
consent consent-not-required · schema SCH-16 · map TMAP-07 approved ≠ production-connected · active-synthetic ≠ live · audit AUD-IFACE-16 |
Partners & agreements (existence ≠ legal sufficiency; self-approval prohibited)
Synthetic partner categories only — no real partner names, domains, emails, endpoints, credentials, or organization identifiers. Expired, revoked, rejected, and superseded agreements remain visible; missing approval blocks synthetic activation; agreement scope does not authorize unrestricted exchange; this module does not provide legal advice.
Partners
- PTN-MIN — Synthetic National Ministry of Health (demo) ministry active-syntheticcountry-alpha · org-ministry · onboarding approved · audit AUD-PTN-01
- PTN-NP — Synthetic National Disease Program (demo) national-program active-syntheticcountry-alpha · org-national-program · onboarding pending-review · audit AUD-PTN-02
- PTN-REG — Synthetic Regional Health Authority (demo) state-or-regional-authority active-syntheticcountry-beta · org-state-or-regional-authority · onboarding approved · audit AUD-PTN-03
- PTN-FAC — Synthetic District Facility Network (demo) facility active-syntheticcountry-alpha · org-facility · onboarding conditional · audit AUD-PTN-04
- PTN-LAB — Synthetic Reference Laboratory (demo) laboratory active-syntheticcountry-beta · org-laboratory · onboarding approved · audit AUD-PTN-05
- PTN-WH — Synthetic Central Warehouse (demo) warehouse active-syntheticcountry-alpha · org-warehouse · onboarding pending-review · audit AUD-PTN-06
- PTN-LOG — Synthetic Logistics Partner (demo) logistics-partner active-syntheticcountry-gamma · org-logistics-partner · onboarding approved · audit AUD-PTN-07
- PTN-IMP — Synthetic Implementation Partner (demo) implementation-partner active-syntheticcountry-beta · org-implementation-partner · onboarding conditional · audit AUD-PTN-08
- PTN-FUND — Synthetic Funding Partner (demo) funding-partner active-syntheticglobal · org-funding-partner · onboarding approved · audit AUD-PTN-09
- PTN-AUD — Synthetic Assurance Reviewer (demo) audit-or-assurance-reviewer under-reviewglobal · org-audit-or-assurance-reviewer · onboarding pending-review · audit AUD-PTN-10
- PTN-TECH — Synthetic Authorized Technology Partner (demo) authorized-technology-partner active-syntheticcountry-gamma · org-authorized-technology-partner · onboarding approved · audit AUD-PTN-11
| Agreement | State / approval | Permitted / prohibited | Posture / audit |
|---|---|---|---|
| AGR-01 PTN-MIN |
approved approved effective 2026-01-15 · expires 2027-01-15 |
permitted operational, programmatic prohibited restricted, patient-identifiers, precise-location |
existence ≠ legal sufficiency · self-approval prohibited · missing approval blocks activation · audit AUD-AGR-01 |
| AGR-02 PTN-NP |
approved approved effective 2026-01-15 · expires 2027-01-15 |
permitted operational, programmatic prohibited restricted, patient-identifiers, precise-location |
existence ≠ legal sufficiency · self-approval prohibited · missing approval blocks activation · audit AUD-AGR-02 |
| AGR-03 PTN-REG |
pending-review pending effective 2026-01-15 · expires 2027-01-15 |
permitted operational, programmatic prohibited restricted, patient-identifiers, precise-location |
existence ≠ legal sufficiency · self-approval prohibited · missing approval blocks activation · audit AUD-AGR-03 |
| AGR-04 PTN-FAC |
approved approved effective 2026-01-15 · expires 2027-01-15 |
permitted operational, programmatic prohibited restricted, patient-identifiers, precise-location |
existence ≠ legal sufficiency · self-approval prohibited · missing approval blocks activation · audit AUD-AGR-04 |
| AGR-05 PTN-LAB |
expired approved effective 2026-01-15 · expires 2026-04-01 |
permitted operational, programmatic, clinical-sensitive prohibited restricted, patient-identifiers, precise-location |
existence ≠ legal sufficiency · self-approval prohibited · missing approval blocks activation · audit AUD-AGR-05 |
| AGR-06 PTN-WH |
approved approved effective 2026-01-15 · expires 2027-01-15 |
permitted operational, programmatic prohibited restricted, patient-identifiers, precise-location |
existence ≠ legal sufficiency · self-approval prohibited · missing approval blocks activation · audit AUD-AGR-06 |
| AGR-07 PTN-LOG |
revoked approved revoked · effective 2026-01-15 · expires 2027-01-15 |
permitted operational, programmatic prohibited restricted, patient-identifiers, precise-location |
existence ≠ legal sufficiency · self-approval prohibited · missing approval blocks activation · audit AUD-AGR-07 |
| AGR-08 PTN-IMP |
approved approved effective 2026-01-15 · expires 2027-01-15 |
permitted operational, programmatic prohibited restricted, patient-identifiers, precise-location |
existence ≠ legal sufficiency · self-approval prohibited · missing approval blocks activation · audit AUD-AGR-08 |
| AGR-09 PTN-FUND |
approved approved effective 2026-01-15 · expires 2027-01-15 |
permitted operational, programmatic prohibited restricted, patient-identifiers, precise-location |
existence ≠ legal sufficiency · self-approval prohibited · missing approval blocks activation · audit AUD-AGR-09 |
| AGR-10 PTN-AUD |
rejected rejected effective 2026-01-15 · expires 2027-01-15 |
permitted operational, programmatic prohibited restricted, patient-identifiers, precise-location |
existence ≠ legal sufficiency · self-approval prohibited · missing approval blocks activation · audit AUD-AGR-10 |
| AGR-11 PTN-TECH |
superseded approved effective 2026-01-15 · expires 2027-01-15 |
permitted operational, programmatic prohibited restricted, patient-identifiers, precise-location |
existence ≠ legal sufficiency · self-approval prohibited · missing approval blocks activation · audit AUD-AGR-11 |
Schema versions (superseded / incompatible remain visible)
- SCHV-01-CUR — SCH-01 vs1.0 current compatiblesuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-01
- SCHV-01-OLD — SCH-01 vs0.1 superseded incompatible breakingsuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-OLD-01
- SCHV-02-CUR — SCH-02 vs2.0 current compatiblesuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-02
- SCHV-02-OLD — SCH-02 vs0.2 superseded incompatible stale breakingsuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-OLD-02
- SCHV-03-CUR — SCH-03 vs3.0 current compatiblesuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-03
- SCHV-03-OLD — SCH-03 vs0.3 superseded unknown breakingsuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-OLD-03
- SCHV-04-CUR — SCH-04 vs1.0 current compatiblesuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-04
- SCHV-04-OLD — SCH-04 vs0.4 retired incompatible breakingsuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-OLD-04
- SCHV-05-CUR — SCH-05 vs2.0 current compatiblesuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-05
- SCHV-05-OLD — SCH-05 vs0.5 superseded incompatible breakingsuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-OLD-05
- SCHV-06-CUR — SCH-06 vs3.0 current compatiblesuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-06
- SCHV-07-CUR — SCH-07 vs1.0 current compatiblesuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-07
- SCHV-08-CUR — SCH-08 vs2.0 current compatiblesuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-08
- SCHV-09-CUR — SCH-09 vs3.0 current compatiblesuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-09
- SCHV-10-CUR — SCH-10 vs1.0 current compatiblesuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-10
- SCHV-11-CUR — SCH-11 vs2.0 current compatiblesuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-11
- SCHV-12-CUR — SCH-12 vs3.0 current compatiblesuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-12
- SCHV-13-CUR — SCH-13 vs1.0 current compatiblesuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-13
- SCHV-14-CUR — SCH-14 vs2.0 current compatiblesuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-14
- SCHV-15-CUR — SCH-15 vs3.0 current compatiblesuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-15
- SCHV-16-CUR — SCH-16 vs1.0 current compatiblesuperseded/incompatible remain visible · silent replacement prohibited · linked AEV-SCHV-16
Terminology mappings (synthetic, not authoritative)
- TMAP-01 — icd-style-diagnosis-category one-to-many ambiguous-unresolved AI-suggestedSynthetic ICD-style diagnosis categories · not authoritative clinical/legal · human review: pending · deprecated codes remain visible
- TMAP-02 — laboratory-test-code many-to-one resolved-syntheticSynthetic laboratory test codes · not authoritative clinical/legal · human review: reviewed · deprecated codes remain visible
- TMAP-03 — specimen-type one-to-one resolved-syntheticSynthetic specimen types · not authoritative clinical/legal · human review: reviewed · deprecated codes remain visible
- TMAP-04 — commodity-category one-to-many resolved-syntheticSynthetic commodity categories · not authoritative clinical/legal · human review: reviewed · deprecated codes remain visible
- TMAP-05 — facility-type many-to-one resolved-syntheticSynthetic facility types · not authoritative clinical/legal · human review: reviewed · deprecated codes remain visible
- TMAP-06 — program-indicator one-to-one partialSynthetic program indicators · not authoritative clinical/legal · human review: reviewed · deprecated codes remain visible
- TMAP-07 — asset-category one-to-many resolved-syntheticSynthetic asset categories · not authoritative clinical/legal · human review: reviewed · deprecated codes remain visible
- TMAP-08 — incident-category many-to-one resolved-syntheticSynthetic incident categories · not authoritative clinical/legal · human review: reviewed · deprecated codes remain visible
- TMAP-09 — country-administrative-area one-to-one resolved-syntheticSynthetic country and administrative-area references · not authoritative clinical/legal · human review: reviewed · deprecated codes remain visible
Consent, lawful basis, privacy, security & minimum necessary
This module does not collect real consent; consent status is synthetic. Consent does not override role restrictions or authorize unrestricted disclosure; withdrawn or expired consent is not treated as active; unknown consent stays unknown. Lawful basis requires authorized human review; privacy review is distinct from security review; minimum-necessary review is distinct from consent; denials do not reveal restricted record existence; patient identity and precise location never appear.
Consent reviews
- CNS-01 — IFACE-01 consent-requiredtreated as active: yes · does not override roles · does not authorize unrestricted disclosure · review reviewed
- CNS-02 — IFACE-02 consent-not-requiredtreated as active: yes · does not override roles · does not authorize unrestricted disclosure · review reviewed
- CNS-03 — IFACE-03 consent-unknowntreated as active: no · does not override roles · does not authorize unrestricted disclosure · review pending
- CNS-04 — IFACE-04 consent-expiredtreated as active: no · does not override roles · does not authorize unrestricted disclosure · review reviewed
- CNS-05 — IFACE-05 consent-withdrawntreated as active: no · does not override roles · does not authorize unrestricted disclosure · review reviewed
- CNS-06 — IFACE-06 consent-requiredtreated as active: yes · does not override roles · does not authorize unrestricted disclosure · review reviewed
Lawful-basis reviews
- LBR-01 — public-health-mandate-synthetic approvedrequires authorized human review · distinct from consent · distinct from privacy review
- LBR-02 — authorized-agreement-synthetic approvedrequires authorized human review · distinct from consent · distinct from privacy review
- LBR-03 — public-health-mandate-synthetic pendingrequires authorized human review · distinct from consent · distinct from privacy review
- LBR-04 — authorized-agreement-synthetic approvedrequires authorized human review · distinct from consent · distinct from privacy review
- LBR-05 — public-health-mandate-synthetic rejectedrequires authorized human review · distinct from consent · distinct from privacy review
- LBR-06 — authorized-agreement-synthetic approvedrequires authorized human review · distinct from consent · distinct from privacy review
Privacy reviews
- PRV-01 — IFACE-01 approvedprivacy ≠ security · denials do not reveal restricted record existence
- PRV-02 — IFACE-02 approvedprivacy ≠ security · denials do not reveal restricted record existence
- PRV-03 — IFACE-03 pendingprivacy ≠ security · denials do not reveal restricted record existence
- PRV-04 — IFACE-04 approvedprivacy ≠ security · denials do not reveal restricted record existence
- PRV-05 — IFACE-05 blockedprivacy ≠ security · denials do not reveal restricted record existence
- PRV-06 — IFACE-06 approvedprivacy ≠ security · denials do not reveal restricted record existence
Security reviews
- SEC-01 — IFACE-01 approvedsecurity ≠ privacy · no real credentials · no real certificates
- SEC-02 — IFACE-02 approvedsecurity ≠ privacy · no real credentials · no real certificates
- SEC-03 — IFACE-03 approvedsecurity ≠ privacy · no real credentials · no real certificates
- SEC-04 — IFACE-04 pendingsecurity ≠ privacy · no real credentials · no real certificates
- SEC-05 — IFACE-05 approvedsecurity ≠ privacy · no real credentials · no real certificates
- SEC-06 — IFACE-06 blockedsecurity ≠ privacy · no real credentials · no real certificates
Minimum-necessary
- MNR-01 — IFACE-01 passedminimum-necessary ≠ consent · excessive fields flagged: no
- MNR-02 — IFACE-02 partialminimum-necessary ≠ consent · excessive fields flagged: yes
- MNR-03 — IFACE-03 failedminimum-necessary ≠ consent · excessive fields flagged: yes
- MNR-04 — IFACE-04 passedminimum-necessary ≠ consent · excessive fields flagged: no
- MNR-05 — IFACE-05 partialminimum-necessary ≠ consent · excessive fields flagged: yes
- MNR-06 — IFACE-06 passedminimum-necessary ≠ consent · excessive fields flagged: no
Module coverage
Interface testing (six result states; missing evidence blocks pass)
Results use pass, partial, fail, blocked, not-tested, and not-applicable. Missing evidence blocks a pass; later success does not erase prior failure; retests append history; passing tests do not authorize production activation; not-tested is not not-applicable; partial remains partial; blocked remains visible.
| Test | Result | Posture |
|---|---|---|
| TR-01 schema-validation · IFACE-01 |
pass evidence present: yes |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-02 version-compatibility · IFACE-02 |
partial evidence present: yes |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-03 required-field-validation · IFACE-03 |
fail evidence present: no |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-04 terminology-validation · IFACE-04 |
blocked evidence present: no |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-05 duplicate-detection · IFACE-05 |
not-tested evidence present: yes |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-06 acknowledgement-handling · IFACE-06 |
not-applicable evidence present: yes |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-07 retry-handling · IFACE-07 |
pass evidence present: yes |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-08 dead-letter-handling · IFACE-08 |
partial evidence present: yes |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-09 reconciliation · IFACE-09 |
fail evidence present: no |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-10 privacy-filtering · IFACE-10 |
pass evidence present: yes |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-11 minimum-necessary-filtering · IFACE-11 |
pass evidence present: yes |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-12 authorization-expiry · IFACE-12 |
fail evidence present: no |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-13 conflict-handling · IFACE-13 |
partial evidence present: yes |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-14 offline-synchronization · IFACE-14 |
pass evidence present: yes |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-15 stale-message-handling · IFACE-15 |
blocked evidence present: no |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-16 ordering-validation · IFACE-16 |
pass evidence present: yes |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-17 idempotency-review · IFACE-01 |
not-tested evidence present: yes |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
| TR-RETEST-01 required-field-validation · IFACE-03 |
partial retest of TR-03 (prior fail) evidence present: yes |
missing evidence blocks pass · later success does not erase prior failure · retests append history · passing ≠ production authorization |
Synthetic exchange events (no message transmitted)
No actual message is transmitted. Synthetic delivery status is not production delivery; successful delivery does not prove semantic acceptance; retries do not create silent duplicates; duplicate candidates, conflicts, dead-letter records, missing acknowledgements, and failed deliveries remain visible; later successful delivery does not erase earlier failures.
| Event | Delivery / ack / recon | Duplicate / conflict / retry / DLR | Posture / audit |
|---|---|---|---|
| XEV-01 fund-disbursement-summary · IFACE-01 |
delivered-synthetic acknowledged recon matched |
no message transmitted · delivery ≠ receipt ≠ semantic · ack ≠ reconciliation · failures remain visible · audit AUD-XEV-01 | |
| XEV-02 commodity-stock-status · IFACE-02 |
failed missing recon unmatched |
retry retry-scheduled · | no message transmitted · delivery ≠ receipt ≠ semantic · ack ≠ reconciliation · failures remain visible · audit AUD-XEV-02 |
| XEV-03 lab-order-result · IFACE-03 |
delivered-synthetic acknowledged recon partially-matched |
no message transmitted · delivery ≠ receipt ≠ semantic · ack ≠ reconciliation · failures remain visible · audit AUD-XEV-03 | |
| XEV-04 referral-followup · IFACE-04 |
pending missing recon missing-target |
no message transmitted · delivery ≠ receipt ≠ semantic · ack ≠ reconciliation · failures remain visible · audit AUD-XEV-04 | |
| XEV-05 locator-request · IFACE-05 |
delivered-synthetic acknowledged recon conflicting |
conflict conflicting-pending-human-review · | no message transmitted · delivery ≠ receipt ≠ semantic · ack ≠ reconciliation · failures remain visible · audit AUD-XEV-05 |
| XEV-06 asset-custody-update · IFACE-06 |
failed missing recon missing-source |
retry retry-scheduled · DLR dead-letter-visible | no message transmitted · delivery ≠ receipt ≠ semantic · ack ≠ reconciliation · failures remain visible · audit AUD-XEV-06 |
| XEV-07 program-indicator-report · IFACE-07 |
delivered-synthetic pending recon duplicate-candidate |
dup duplicate-candidate · | no message transmitted · delivery ≠ receipt ≠ semantic · ack ≠ reconciliation · failures remain visible · audit AUD-XEV-07 |
| XEV-08 ai-signal · IFACE-08 |
delivered-synthetic acknowledged recon stale |
no message transmitted · delivery ≠ receipt ≠ semantic · ack ≠ reconciliation · failures remain visible · audit AUD-XEV-08 |
Reconciliation (not silent overwriting; original values preserved)
- REC-01 — matched source
synthetic-source-value-1vs targetsynthetic-target-value-1not silent overwrite · original preserved · corrected values require attribution · audit AUD-REC-01 - REC-02 — partially-matched source
synthetic-source-value-2vs targetsynthetic-target-value-2not silent overwrite · original preserved · corrected values require attribution · audit AUD-REC-02 - REC-03 — unmatched source
synthetic-source-value-3vs targetsynthetic-target-value-3not silent overwrite · original preserved · corrected values require attribution · audit AUD-REC-03 - REC-04 — duplicate-candidate source
synthetic-source-value-4vs targetsynthetic-target-value-4not silent overwrite · original preserved · corrected values require attribution · audit AUD-REC-04 - REC-05 — conflicting source
synthetic-source-value-5vs targetsynthetic-target-value-52nd reviewnot silent overwrite · original preserved · corrected values require attribution · audit AUD-REC-05 - REC-06 — stale source
synthetic-source-value-6vs targetsynthetic-target-value-6not silent overwrite · original preserved · corrected values require attribution · audit AUD-REC-06 - REC-07 — missing-source source
synthetic-source-value-7vs targetsynthetic-target-value-72nd reviewnot silent overwrite · original preserved · corrected values require attribution · audit AUD-REC-07 - REC-08 — missing-target source
synthetic-source-value-8vs targetsynthetic-target-value-8not silent overwrite · original preserved · corrected values require attribution · audit AUD-REC-08 - REC-09 — blocked source
synthetic-source-value-9vs targetsynthetic-target-value-9not silent overwrite · original preserved · corrected values require attribution · audit AUD-REC-09 - REC-10 — pending-review source
synthetic-source-value-10vs targetsynthetic-target-value-10not silent overwrite · original preserved · corrected values require attribution · audit AUD-REC-10
Dead-letter records (not suppressed)
- DLR-01 — IFACE-06 dead-lettersynthetic unrecoverable delivery failure · visible: yes · suppression allowed: no · review pending
Duplicate candidates
- DUP-01 — IFACE-01 candidateauto-resolved: no · review pending
- DUP-02 — IFACE-02 candidateauto-resolved: no · review pending
Conflicts (human-reviewed resolution)
- CFL-01 — IFACE-05 pending-human-reviewsilently resolved: no · resolution requires human review: yes
Exceptions (attributable, time-bound, revocable)
- EXC-01 — interface-exception approvedactive: yes · attributable/time-bound/revocable/monitored/audited · expires 2026-12-31 · audit AUD-EXC-01
- EXC-02 — schema-exception approvedactive: yes · attributable/time-bound/revocable/monitored/audited · expires 2026-12-31 · audit AUD-EXC-02
- EXC-03 — mapping-exception approvedactive: yes · attributable/time-bound/revocable/monitored/audited · expires 2026-12-31 · audit AUD-EXC-03
- EXC-04 — consent-exception expiredactive: no · attributable/time-bound/revocable/monitored/audited · expires 2026-05-20 · audit AUD-EXC-04
- EXC-05 — privacy-exception approvedactive: yes · attributable/time-bound/revocable/monitored/audited · expires 2026-12-31 · audit AUD-EXC-05
- EXC-06 — security-exception rejectedactive: no · attributable/time-bound/revocable/monitored/audited · expires 2026-12-31 · audit AUD-EXC-06
- EXC-07 — delivery-exception approvedactive: yes · attributable/time-bound/revocable/monitored/audited · expires 2026-12-31 · audit AUD-EXC-07
- EXC-08 — reconciliation-exception approvedactive: yes · attributable/time-bound/revocable/monitored/audited · expires 2026-12-31 · audit AUD-EXC-08
- EXC-09 — compatibility-exception expiredactive: no · attributable/time-bound/revocable/monitored/audited · expires 2026-05-20 · audit AUD-EXC-09
Remediation (completion ≠ effectiveness)
- CA-01 — completed effectivecompletion ≠ effectiveness · residual reduced-synthetic · linked IINC-01 · audit AUD-CA-01
- CA-02 — in-progress pendingcompletion ≠ effectiveness · residual reduced-synthetic · linked IINC-02 · audit AUD-CA-02
- CA-03 — overdue overdue ineffectivecompletion ≠ effectiveness · residual elevated · linked IINC-03 · audit AUD-CA-03
- CA-04 — completed pendingcompletion ≠ effectiveness · residual reduced-synthetic · linked EXC-01 · audit AUD-CA-04
Separation-of-duties rules
Violations remain blocked or pending, identify the violated rule, require reassignment, independent review, or second review, remain auditable, and are never silently overridden.
| Rule | Enforcement | Override / audit |
|---|---|---|
| Interface author cannot independently approve activation SOD-01 · interface-author-cannot-approve-activation |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Schema author cannot independently approve compatibility SOD-02 · schema-author-cannot-approve-compatibility |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Mapping author cannot independently approve terminology accuracy SOD-03 · mapping-author-cannot-approve-terminology-accuracy |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Partner owner cannot independently approve agreement scope SOD-04 · partner-owner-cannot-approve-agreement-scope |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Consent reviewer cannot independently approve their own request SOD-05 · consent-reviewer-cannot-approve-own-request |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Lawful-basis reviewer cannot independently approve their own determination SOD-06 · lawful-basis-reviewer-cannot-approve-own-determination |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Privacy reviewer cannot independently provide final security approval SOD-07 · privacy-reviewer-cannot-provide-final-security-approval |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Security reviewer cannot independently provide final privacy approval SOD-08 · security-reviewer-cannot-provide-final-privacy-approval |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Test performer cannot independently approve final test results SOD-09 · test-performer-cannot-approve-final-test-results |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Message creator cannot independently certify delivery SOD-10 · message-creator-cannot-certify-delivery |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Acknowledgement creator cannot independently certify reconciliation SOD-11 · acknowledgement-creator-cannot-certify-reconciliation |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Retry operator cannot independently close duplicate risk SOD-12 · retry-operator-cannot-close-duplicate-risk |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Dead-letter reviewer cannot independently suppress failed records SOD-13 · dead-letter-reviewer-cannot-suppress-failed-records |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Reconciliation operator cannot independently approve high-risk correction SOD-14 · reconciliation-operator-cannot-approve-high-risk-correction |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Exception requestor cannot independently approve exception SOD-15 · exception-requestor-cannot-approve-exception |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Remediation owner cannot independently verify high-risk effectiveness SOD-16 · remediation-owner-cannot-verify-high-risk-effectiveness |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| AI signal generator cannot activate, approve, transmit, reconcile, disclose, or close SOD-17 · ai-generator-cannot-activate-approve-transmit-reconcile-disclose-close |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Fund-accountability owner cannot independently approve financial-data exchange SOD-18 · fund-owner-cannot-approve-financial-data-exchange |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Laboratory operator cannot independently approve result-routing activation SOD-19 · lab-operator-cannot-approve-result-routing-activation |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Restricted-locator requestor cannot independently approve disclosure SOD-20 · locator-requestor-cannot-approve-disclosure |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Asset custodian cannot independently approve custody-transfer reconciliation SOD-21 · asset-custodian-cannot-approve-custody-transfer-reconciliation |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Program submitter cannot independently certify reporting exchange SOD-22 · program-submitter-cannot-certify-reporting-exchange |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Identity approver cannot independently certify access-assertion exchange SOD-23 · identity-approver-cannot-certify-access-assertion-exchange |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Incident investigator cannot independently approve incident-record exchange SOD-24 · incident-investigator-cannot-approve-incident-record-exchange |
pending | never silently overridden auditable · requires reassignment / independent / second review |
| Compliance owner cannot independently attest interface compliance SOD-25 · compliance-owner-cannot-attest-interface-compliance |
blocked | never silently overridden auditable · requires reassignment / independent / second review |
| Continuity owner cannot independently certify interface recoverability SOD-26 · continuity-owner-cannot-certify-interface-recoverability |
pending | never silently overridden auditable · requires reassignment / independent / second review |
Evidence (presence ≠ verification; conflicts remain visible)
- EVD-01 — interface-config-synthetic present verified currentfund-accountability · IFACE-01
- EVD-02 — schema-artifact-synthetic present verified currentstockpile-logistics · IFACE-02
- EVD-03 — mapping-artifact-synthetic missing missing currentlab-operations · IFACE-03
- EVD-04 — test-artifact-synthetic present conflicting currentpatient-continuity · IFACE-04
- EVD-05 — agreement-artifact-synthetic present verified supersededrestricted-patient-locator · IFACE-05
- EVD-06 — reconciliation-artifact-synthetic present verified currentasset-management · IFACE-06
AI exchange signals (human review required)
- missing-mapping — synthetic AI-assisted observation: missing-mapping confidence lowhuman review: yes · autonomous action: none
- incompatible-version — synthetic AI-assisted observation: incompatible-version confidence mediumhuman review: yes · autonomous action: none
- stale-schema — synthetic AI-assisted observation: stale-schema confidence highhuman review: yes · autonomous action: none
- duplicate-candidate — synthetic AI-assisted observation: duplicate-candidate confidence lowhuman review: yes · autonomous action: none
- missing-acknowledgement — synthetic AI-assisted observation: missing-acknowledgement confidence mediumhuman review: yes · autonomous action: none
- failed-delivery-priority — synthetic AI-assisted observation: failed-delivery-priority confidence highhuman review: yes · autonomous action: none
- source-target-divergence — synthetic AI-assisted observation: source-target-divergence confidence lowhuman review: yes · autonomous action: none
- unresolved-reconciliation — synthetic AI-assisted observation: unresolved-reconciliation confidence mediumhuman review: yes · autonomous action: none
- consent-expiry — synthetic AI-assisted observation: consent-expiry confidence highhuman review: yes · autonomous action: none
- minimum-necessary-concern — synthetic AI-assisted observation: minimum-necessary-concern confidence lowhuman review: yes · autonomous action: none
- overdue-agreement — synthetic AI-assisted observation: overdue-agreement confidence mediumhuman review: yes · autonomous action: none
- second-review-recommended — synthetic AI-assisted observation: second-review-recommended confidence highhuman review: yes · autonomous action: none
Immutable audit events (append-only)
Interface, schema, and mapping changes; agreement approval/revocation/expiration/supersession; consent withdrawal and expiration; test execution and retest; delivery failure and retry; acknowledgement; duplicate identification; conflict resolution; reconciliation decision; exception approval and expiration; remediation effectiveness; and interface suspension and retirement all require new linked events. Deletion is not an allowed governance control; source-module audit records remain authoritative. This is not a production cryptographic audit ledger.
- AEV-01 — recorded synthetic interface-version-change resulting-synthetic-state interface-version-changeintegration-governance-role · fund-accountability · 2026-06-01T12:00:00Z · immutable: yes
- AEV-02 — recorded synthetic schema-change resulting-synthetic-state schema-changeintegration-governance-role · stockpile-logistics · 2026-06-02T12:00:00Z · immutable: yes
- AEV-03 — recorded synthetic mapping-change resulting-synthetic-state mapping-changeintegration-governance-role · lab-operations · 2026-06-03T12:00:00Z · immutable: yes
- AEV-04 — recorded synthetic agreement-approval resulting-synthetic-state agreement-approvalintegration-governance-role · patient-continuity · 2026-06-04T12:00:00Z · immutable: yes
- AEV-05 — recorded synthetic agreement-revocation resulting-synthetic-state agreement-revocationintegration-governance-role · restricted-patient-locator · 2026-06-05T12:00:00Z · immutable: yes
- AEV-06 — recorded synthetic agreement-expiration resulting-synthetic-state agreement-expirationintegration-governance-role · asset-management · 2026-06-06T12:00:00Z · immutable: yes
- AEV-07 — recorded synthetic agreement-supersession resulting-synthetic-state agreement-supersessionintegration-governance-role · program-performance · 2026-06-07T12:00:00Z · immutable: yes
- AEV-08 — recorded synthetic consent-withdrawal resulting-synthetic-state consent-withdrawalintegration-governance-role · ai-intelligence · 2026-06-08T12:00:00Z · immutable: yes
- AEV-09 — recorded synthetic consent-expiration resulting-synthetic-state consent-expirationintegration-governance-role · country-rollout · 2026-06-09T12:00:00Z · immutable: yes
- AEV-10 — recorded synthetic test-execution resulting-synthetic-state test-executionintegration-governance-role · authorized-review-room · 2026-06-10T12:00:00Z · immutable: yes
- AEV-11 — recorded synthetic test-retest resulting-synthetic-state test-retestintegration-governance-role · executive-review-packet · 2026-06-11T12:00:00Z · immutable: yes
- AEV-12 — recorded synthetic delivery-failure resulting-synthetic-state delivery-failureintegration-governance-role · identity-access-governance · 2026-06-12T12:00:00Z · immutable: yes
- AEV-13 — recorded synthetic delivery-retry resulting-synthetic-state delivery-retryintegration-governance-role · data-quality-reconciliation · 2026-06-13T12:00:00Z · immutable: yes
- AEV-14 — recorded synthetic acknowledgement resulting-synthetic-state acknowledgementintegration-governance-role · risk-incident-case-governance · 2026-06-14T12:00:00Z · immutable: yes
- AEV-15 — recorded synthetic duplicate-identification resulting-synthetic-state duplicate-identificationintegration-governance-role · policy-compliance-control-governance · 2026-06-15T12:00:00Z · immutable: yes
- AEV-16 — recorded synthetic conflict-resolution resulting-synthetic-state conflict-resolutionintegration-governance-role · service-reliability-continuity · 2026-06-16T12:00:00Z · immutable: yes
- AEV-17 — recorded synthetic reconciliation-decision resulting-synthetic-state reconciliation-decisionintegration-governance-role · fund-accountability · 2026-06-17T12:00:00Z · immutable: yes
- AEV-18 — recorded synthetic exception-approval resulting-synthetic-state exception-approvalintegration-governance-role · stockpile-logistics · 2026-06-18T12:00:00Z · immutable: yes
- AEV-19 — recorded synthetic exception-expiration resulting-synthetic-state exception-expirationintegration-governance-role · lab-operations · 2026-06-19T12:00:00Z · immutable: yes
- AEV-20 — recorded synthetic remediation-effectiveness resulting-synthetic-state remediation-effectivenessintegration-governance-role · patient-continuity · 2026-06-20T12:00:00Z · immutable: yes
- AEV-21 — recorded synthetic interface-suspension resulting-synthetic-state interface-suspensionintegration-governance-role · restricted-patient-locator · 2026-06-21T12:00:00Z · immutable: yes
- AEV-22 — recorded synthetic interface-retirement resulting-synthetic-state interface-retirementintegration-governance-role · asset-management · 2026-06-22T12:00:00Z · immutable: yes
By module
- fund-accountability 1
- stockpile-logistics 1
- lab-operations 1
- patient-continuity 1
- restricted-patient-locator 1
- asset-management 1
- program-performance 1
- ai-intelligence 1
- country-rollout 1
- authorized-review-room 1
- executive-review-packet 1
- identity-access-governance 1
- data-quality-reconciliation 1
- risk-incident-case-governance 1
- policy-compliance-control-governance 1
- service-reliability-continuity 1
By interface state
- active-synthetic 3
- approved 2
- test-only 2
- draft 1
- pending-review 1
- degraded 1
- suspended 1
- rejected 1
- expired 1
- superseded 1
- retired 1
- blocked 1
By partner / country
- PTN-FUND 2
- PTN-WH 1
- PTN-LAB 1
- PTN-FAC 2
- PTN-LOG 1
- PTN-NP 1
- PTN-TECH 3
- PTN-MIN 1
- PTN-AUD 2
- PTN-REG 2
- country-alpha 4
- country-beta 3
- country-gamma 2
- global 2
By interface type
- api 4
- message 3
- file-batch 3
- event-stream 3
- reference-sync 3
By message type
- fund-disbursement-summary 1
- commodity-stock-status 1
- lab-order-result 1
- referral-followup 1
- locator-request 1
- asset-custody-update 1
- program-indicator-report 1
- ai-signal 1
- rollout-readiness 1
- evidence-reference 1
By classification / consent
- financial-sensitive 1
- operational 6
- clinical-sensitive 2
- restricted 3
- programmatic 3
- security-sensitive 1
- consent-required 2
- consent-not-required 1
- consent-unknown 1
- consent-expired 1
- consent-withdrawn 1
By compatibility / delivery
- compatible 13
- unknown 2
- incompatible 1
- delivered-synthetic 5
- failed 2
- pending 1
By reconciliation state
- matched 1
- partially-matched 1
- unmatched 1
- duplicate-candidate 1
- conflicting 1
- stale 1
- missing-source 1
- missing-target 1
- blocked 1
- pending-review 1
AI posture — assistive only, non-autonomous
AI assists with
- identify missing mappings
- identify incompatible versions
- flag stale schemas
- detect duplicate candidates
- identify missing acknowledgements
- prioritize failed deliveries
- compare source and target values
- identify unresolved reconciliation
- suggest terminology mappings for human review
- flag consent or authorization expiry
- identify minimum-necessary concerns
- identify overdue agreements and remediation
- recommend second review
AI must never
- transmit messages
- call external systems
- activate interfaces
- approve agreements
- approve consent
- determine lawful basis autonomously
- approve privacy or security reviews
- approve terminology mappings
- suppress failed deliveries
- silently resolve duplicates or conflicts
- overwrite source records
- fabricate acknowledgements or evidence
- authorize disclosure
- notify external parties
- bypass human approval, evidence, expiration, revocation, separation of duties, or audit controls
AI is assistive only. It may prioritize and summarize for authorized human reviewers, but never transmits, calls external systems, activates interfaces, approves agreements/consent, determines lawful basis, approves privacy/security reviews or terminology mappings, suppresses failures, silently resolves duplicates/conflicts, overwrites source records, fabricates acknowledgements/evidence, authorizes disclosure, notifies external parties, or bypasses human approval, evidence, expiration, revocation, separation of duties, or audit controls.
Runtime boundary & module coverage
- Impact runtime:
impact.maxarchealth.comon127.0.0.1:3201. - Covers interoperability and data-exchange governance for fund accountability, stockpile & logistics, lab operations, patient continuity, restricted locator, asset management, program performance, AI intelligence, country rollout, the authorized review room, the executive review packet & controlled download center, identity & access governance, data quality & reconciliation, risk, incident & case governance, policy, compliance & control governance, and service reliability & continuity — without coupling to MaxTrax EHR.
- No outbound network call, inbound webhook, message transmission, real OAuth/OIDC, real key/token/certificate, real database write, or real file transfer occurs. No Apache, PM2, systemd, firewall, DNS, TLS, secrets, or environment file is read or modified.
- Medical Library boundary remains separate at
library.maxarchealth.com(port3101) and is not used here. - MaxTrax EHR remains separate; this is not a full EHR and implements no live integration or real database mutation.