Across 6 governed categories.
Command & Overview
Enterprise Overview
prototype TAPSingle-glance synthetic composite of ecosystem health, activity, and readiness.
view oc.overview.view · act oc.overview.act
Weighted synthetic composite of platform, security, data-quality, and continuity signals.
healthyAll demonstration services responding on the local runtime.
healthySynthetic alerts across modules awaiting authorized human review.
attentionAI is bounded and assistive; no autonomous high-impact action.
healthynode --check, build:web, and the verifier chain are green.
healthySynthetic attributable events recorded in the demonstration audit stream (24h).
healthyExecutive Dashboards
implemented SAPGoverned links into the delivered executive and operational dashboards (one capability among many).
view oc.dashboards.view · act oc.dashboards.act
Operations Monitoring
monitor-only SAPCross-module operational monitoring surface; observes synthetic operational signals.
view oc.opsmon.view · act oc.opsmon.act
Declared capability domain — not yet implemented in this foundation. This surface is reserved and honestly marked monitor-only; it can be promoted incrementally without structural redesign.
Health & Diagnostics
Enterprise Health
prototype TAPPlatform, system, service, build, deployment, repository, and documentation health.
view oc.health.view · act oc.health.act
All demonstration services respond on the local runtime.
healthySynthetic infrastructure indicators within expected ranges.
healthySynthetic enterprise services reporting healthy.
healthynode --check, build:web, and the verifier chain pass.
healthyNo deployment performed; monitoring/validation only.
infoGHI-MERGE-001 recovery normalized the approved stack onto main.
healthyWhole-repo documentation link validation passes.
healthyEnterprise Diagnostics
planned TAPDeep synthetic diagnostics across services; reserved for future expansion.
view oc.diagnostics.view · act oc.diagnostics.act
Declared capability domain — not yet implemented in this foundation. This surface is reserved and honestly marked planned; it can be promoted incrementally without structural redesign.
Platform Readiness
monitor-only TAPEcosystem readiness by domain (synthetic estimate).
view oc.readiness.view · act oc.readiness.act
Declared capability domain — not yet implemented in this foundation. This surface is reserved and honestly marked monitor-only; it can be promoted incrementally without structural redesign.
Repository Health
monitor-only TAPBranch, merge, and baseline status (synthetic summary of BuildOps records).
view oc.repo.view · act oc.repo.act
Declared capability domain — not yet implemented in this foundation. This surface is reserved and honestly marked monitor-only; it can be promoted incrementally without structural redesign.
Documentation Health
monitor-only TAPDocumentation link integrity and register completeness.
view oc.dochealth.view · act oc.dochealth.act
Declared capability domain — not yet implemented in this foundation. This surface is reserved and honestly marked monitor-only; it can be promoted incrementally without structural redesign.
Architecture Readiness
monitor-only TAPADR acceptance and baseline conformance (synthetic summary).
view oc.archready.view · act oc.archready.act
Declared capability domain — not yet implemented in this foundation. This surface is reserved and honestly marked monitor-only; it can be promoted incrementally without structural redesign.
Intelligence & AI
AI Operations
prototype TAPAI supervision. AI is assistive only; no autonomous high-impact action; human final authority.
view oc.ai.view · act oc.ai.act
AI is assistive only. It never approves, closes, overrides, or acts without human decision. Every AI recommendation is attributable and can be rejected.
| Service | State | Autonomy | Detail |
|---|---|---|---|
| MaxArc Assist | assistive | none | Bounded guidance; human-decided. |
| Voice Services | prototype | none | Synthetic voice-capture prototype only. |
| Translation | planned | none | Synthetic multilingual monitoring placeholder. |
| Coding Engine | planned | none | Synthetic ICD-10 coding suggestions only; human confirms. |
| Decision Support | prototype | none | Advisory signals; never a directive. |
| Knowledge Search | planned | none | Library boundary; no content served here. |
MaxArc Assist
monitor-only SAPAssist guidance monitoring; bounded and human-decided.
view oc.assist.view · act oc.assist.act
Declared capability domain — not yet implemented in this foundation. This surface is reserved and honestly marked monitor-only; it can be promoted incrementally without structural redesign.
ICD-10 & Clinical Terminology Oversight
planned SAPSynthetic ICD-10 coding oversight; human confirms every code. Terminology licensing not yet cleared.
view oc.icd.view · act oc.icd.act
Declared capability domain — not yet implemented in this foundation. This surface is reserved and honestly marked planned; it can be promoted incrementally without structural redesign.
Language Translation Monitoring
planned SAPSynthetic multilingual translation monitoring; human reviews output.
view oc.translation.view · act oc.translation.act
Declared capability domain — not yet implemented in this foundation. This surface is reserved and honestly marked planned; it can be promoted incrementally without structural redesign.
Voice Intelligence Monitoring
planned SAPSynthetic voice-capture monitoring placeholder; reserved for future expansion.
view oc.voice.view · act oc.voice.act
Declared capability domain — not yet implemented in this foundation. This surface is reserved and honestly marked planned; it can be promoted incrementally without structural redesign.
Validation & Testing
Validation Center
prototype TAPLatest validation, regression, workflow tests, route validation, coverage, and synthetic scenarios.
view oc.validation.view · act oc.validation.act
| Signal | Value | Detail |
|---|---|---|
| Latest validation | passing | node --check, build:web, npm test all green. |
| Regression | no regressions | Existing route verifiers remain green. |
| Workflow tests | 9/9 | node:test workflow-orchestration suite. |
| Route validation | all routes 200 | Per-dashboard route verifiers. |
| Coverage | verifier-based | Deterministic verifier coverage across dashboards (synthetic estimate). |
| Synthetic scenarios | 8 available | Testing Center scenarios available for explicit-confirmation runs. |
Testing Center
prototype TAPSafe execution of bounded synthetic scenarios. Read-only by default; running requires explicit confirmation; every run is audited.
view oc.testing.view · act oc.testing.run
Read-only by default. Selecting a scenario shows its plan; running it requires explicit confirmation and records a synthetic audit event. No production data; scenarios are replayed, never executed against a real module.
Governance & Audit
Audit Intelligence
prototype TAPRecent overrides, emergency access, configuration changes, workflow overrides, and AI recommendations (accepted/rejected).
view oc.audit.view · act oc.audit.act
| Event | Type | Actor | Summary | State |
|---|---|---|---|---|
AUD-OC-0001 | emergency-access | synthetic-clinician-01 | Break-glass access to a synthetic restricted record; justification recorded; second review pending. | review-pending |
AUD-OC-0002 | workflow-override | synthetic-supervisor-02 | Emergency override on a synthetic bedless-admission workflow; distinct second approver required. | review-pending |
AUD-OC-0003 | configuration-change | synthetic-tap-operator | Synthetic Enterprise Configuration Registry change; immutable history preserved. | recorded |
AUD-OC-0004 | ai-recommendation | maxarc-assist | AI suggested a synthetic corrective action; awaiting human decision. | recorded |
AUD-OC-0005 | ai-recommendation-rejected | synthetic-reviewer-03 | Human rejected a synthetic AI severity suggestion; rejection recorded. | recorded |
AUD-OC-0006 | override | synthetic-supervisor-01 | Synthetic policy exception granted with justification and expiry. | recorded |
Override Review Center
monitor-only TAPEmergency overrides awaiting a distinct authorized second review (separation of duties).
view oc.override.view · act oc.override.act
Declared capability domain — not yet implemented in this foundation. This surface is reserved and honestly marked monitor-only; it can be promoted incrementally without structural redesign.
Workflow Engine
prototype TAPWorkflow engine awareness. Synthetic instances only; no production workflow activation.
view oc.workflow.view · act oc.workflow.act
Engine status: operational-synthetic
| Signal | Value | Detail |
|---|---|---|
| Running synthetic workflows | 4 | Lab result routing, protected bedless admission, commodity stockout escalation, corrective action review. |
| Pending reviews | 3 | Awaiting authorized human review. |
| Approvals | 2 | Awaiting distinct authorized approver (separation of duties). |
| Exceptions | 1 | Under review with justification and evidence. |
Security Operations
prototype TAPAuthentication, authorization, audit health, break-glass events, and policy violations.
view oc.security.view · act oc.security.act
| Signal | Value | Detail |
|---|---|---|
| Authentication | deny-by-default | Console is private; production must gate to Enterprise Owner + authorized reviewers. |
| Authorization | least-privilege | Module-level authorization; no console bypass. |
| Audit health | append-only | Synthetic audit stream is immutable and attributable. |
| Break-glass events | 1 | Synthetic emergency access recorded; second review pending. |
| Policy violations | 0 | No synthetic policy violations open. |
Delivery & Configuration
BuildOps
prototype TAPDirective progress, PR/merge pipeline, architecture status, documentation, and technical debt.
view oc.buildops.view · act oc.buildops.act
| Signal | Value | Detail |
|---|---|---|
| Directive progress | GHI-1806–GHI-1814 on main | Normalized via GHI-MERGE-001 recovery PRs #50–#55. |
| PR pipeline | closeout merged (#56) | GHI-MERGE-001 recovery closeout recorded. |
| Merge pipeline | sequential, human-approved | No direct pushes to main; Enterprise Owner merges. |
| Architecture status | baseline v1.0 | ADR-0001–0010 accepted; ADR-0011/0012 proposed. |
| Documentation | complete | Handbook, registers, traceability all present on main. |
| Technical debt | tracked | RISK-A1 / DEBT-03 resolved by recovery; others tracked. |
Implementation Progress
monitor-only TAPDirective and roadmap progress across the enterprise program.
view oc.progress.view · act oc.progress.act
Declared capability domain — not yet implemented in this foundation. This surface is reserved and honestly marked monitor-only; it can be promoted incrementally without structural redesign.
Enterprise Configuration
planned TAPGoverned configuration registry oversight with immutable history (synthetic).
view oc.config.view · act oc.config.act
Declared capability domain — not yet implemented in this foundation. This surface is reserved and honestly marked planned; it can be promoted incrementally without structural redesign.
Future Enterprise Services
planned TAPReserved slot demonstrating that new capability domains attach without structural redesign.
view oc.future.view · act oc.future.act
Declared capability domain — not yet implemented in this foundation. This surface is reserved and honestly marked planned; it can be promoted incrementally without structural redesign.
Authorization & operating profiles
CAP / SAP / TAP
- CAP — Client Administration Platform — a single authorized organization operating its own services.
- SAP — Supervisory Administration Platform — governed oversight across a supervised scope; aggregate-by-default; identifiable data requires lawful basis and role authorization.
- TAP — Technical Administration Platform — reserved exclusively for MaxArc Health technical operations; the Operations Center is a TAP-stewarded environment; no customer receives unrestricted access.
Every capability domain carries a distinct view permission and a distinct act permission. Seeing an awareness signal never confers authority to run a test or to act inside an underlying module.
Enterprise Operating Profiles
- EOP-S — Standard — monitoring and awareness surfaces render; test-execution surfaces are inert until explicitly confirmed.
- EOP-G — Guided — validation prompts and quality reminders may appear where enabled.
- EOP-O — Optimized — orchestration, journey intelligence, and operational analytics surfaces may appear where enabled.
Profiles are additive (EOP-S ⊆ EOP-G ⊆ EOP-O). Profile selection changes which surfaces render; it never weakens authorization, audit, patient safety, or record integrity.
Extensibility
- Capability domains are declared in a single registry (capabilityDomains) and grouped by category. Adding a domain is additive: append a registry entry (and optionally a panel) — navigation, summary, and API surface adapt automatically with no structural redesign.
- A domain's `panel` names a render strategy. `placeholder` renders a governed, honest 'declared / not yet implemented here' surface. New panel types are added without touching existing domains.
- Enterprise Diagnostics, ICD-10 oversight, Translation monitoring, Voice monitoring, Enterprise Configuration, and Future Enterprise Services are declared now and can be promoted from planned/monitor-only to prototype/implemented incrementally in later directives.
Event-Driven Foundation synthetic
Architecture + prototype contract only. This foundation is FIXTURE-BACKED: no live streaming, no durable persistence, no production telemetry, and no production-grade event delivery are implemented or claimed here. A static synthetic stream demonstrates the canonical shape.
UI boundary. Dashboards, alerts, activity trays, validation results, audit intelligence, and future command capabilities MUST consume normalized Enterprise Operations Events through this envelope, and MUST NOT be permanently coupled to hard-coded page-specific data structures. Panels in this prototype read fixture data shaped toward this envelope; the boundary is the contract future implementations bind to.
Canonical Enterprise Operations Event
| Field | Requirement | Description |
|---|---|---|
eventId | required | Globally unique, stable event identifier. |
eventType | required | Dotted event type, e.g. audit.override.granted. |
eventVersion | required | Schema version of this event type (semantic). |
sourceProduct | required | Originating MaxArc product (GHIP, EHR, Medical Library, BuildOps). |
sourceModule | required | Originating module or capability within the product. |
environment | required | Origin environment (synthetic, dev, staging, production). |
timestampUtc | required | Event time in UTC (ISO-8601). |
timestampLocal | optional | Relevant local time + zone where applicable. |
actor | optional | { identity, role } where an actor applies. |
context | optional | { organization, facility } where applicable. |
correlationId | required | Correlates related events across a flow. |
causationId | optional | Identifier of the event that directly caused this one. |
workflowOrValidationRef | optional | Reference to a workflow instance or validation/test run. |
severity | required | info | notice | warning | high | critical. |
classification | required | Data/handling classification of the event. |
summary | required | Human-readable one-line summary. |
payloadRef | optional | Reference/pointer to a structured payload (not inlined). |
syntheticIndicator | required | synthetic | live — never 'live' unless truly live. |
acknowledgmentStatus | required | unacknowledged | acknowledged | resolved. |
retentionClass | required | Retention/handling class (e.g. standard, extended, legal-hold). |
provenance | required | { integrityHash, signer, chain } integrity/provenance metadata. |
Supported future event families
audit.change— Audit and configuration-change events.override— Override events and required justification.workflow.transition— Workflow lifecycle transitions.approval.sod— Approval and separation-of-duties events.ai.decision— AI recommendations and human decisions.security.breakglass— Security and break-glass events.validation.result— Validation and test results.system.health— System health and diagnostics.buildops.repo— BuildOps and repository events.terminology.icd10— ICD-10 and clinical-terminology activity.voice.dictation— Voice dictation activity.translation— Language translation activity.notification.escalation— Notification and escalation events.
Synthetic event stream fixture-backed
| Event ID | Type | Source | Severity | Origin | Summary |
|---|---|---|---|---|---|
EVT-OC-0001 | security.breakglass.access | GHIP · enterprise-audit | high | synthetic | Break-glass access to a synthetic restricted record; justification recorded; second review pending. |
EVT-OC-0002 | workflow.transition.override | GHIP · workflow-engine | warning | synthetic | Emergency override on a synthetic bedless-admission workflow; distinct second approver required. |
EVT-OC-0003 | ai.decision.rejected | GHIP · maxarc-assist | info | synthetic | Human rejected a synthetic AI severity suggestion; rejection recorded; AI remains assistive only. |
Production gate — DEBT-09
Until production authentication, authorization, session controls, and persisted tamper-evident auditing are implemented and approved, this gate blocks:
- production deployment
- live data or telemetry connection
- broader user access
- operational commands
- production event ingestion
Enterprise Architecture Impact Review — GHI-1815
| Area | Effect | Risk |
|---|---|---|
| Client Administration Platform | Adds no CAP behavior; console only observes synthetic CAP-scoped status. | none |
| Supervisory Administration Platform | Surfaces SAP-scoped awareness aggregate-by-default; no identifiable data. | none |
| Technical Administration Platform | Console is a TAP-stewarded private environment; no customer receives TAP access. | none |
| MaxArc EHR | Boundary preserved; EHR remains a separate product; monitoring placeholder only. | none |
| MaxArc Assist | AI monitoring is read-only; AI remains assistive with no autonomous action. | none |
| MEFS | Records status observed only; no patient data read; no persistence change. | none |
| Laboratory | Synthetic laboratory scenario is replay-only; no real lab integration. | none |
| Patient Continuity | Synthetic referral/journey scenarios are replay-only. | none |
| Security | Read-only by default; testing requires explicit confirmation; every action audited; deny-by-default. | none |
| Offline Services | No change; console is additive and dependency-free. | none |
| Shared Enterprise Services | Observed as synthetic status only; no service invoked. | none |
| Patient Safety | No production workflow activated; safety controls unchanged. | none |
| Record Integrity | No writes to any authoritative record; synthetic-only. | none |
GHI-1815 is additive, synthetic-only, read-only by default, and private. It introduces no production behavior, no deployment, and no change to architecture, governance, security, or documentation meaning. It establishes the permanent, modular foundation of the MaxArc Enterprise Operations Center, extensible for future AI, audit, multilingual, ICD-10, voice, governance, and enterprise command capabilities.
Ownership & boundary
- Enterprise owner & human final authority: Engineer Oluwaseyi Olawore.
- Console steward: MaxArc Enterprise Architecture (Technical Administration Platform steward).
- Impact runtime:
maxarc-impact-platform (port 3201, synthetic runtime). - MaxArc Medical Library is a separate product at library.maxarchealth.com (port 3101). No library functionality is implemented here; this console only monitors its status as a boundary placeholder.
- MaxArc EHR / MaxTrax is a separate product/repository. No EHR functionality is implemented here; this console only monitors its status as a boundary placeholder.
- The Operations Center monitors, validates, and tests; it does not own or replace any module and enforces no production behavior.