{
  "ok": true,
  "scope": "Cross-module risk, incident, investigation, corrective-action, escalation, and case-governance demonstration for the MaxArc Global Health Impact Platform. Demonstrates how risks, anomalies, control failures, suspected diversion, stock losses, laboratory quality concerns, privacy events, access violations, data-quality discrepancies, asset incidents, program underperformance, rollout blockers, evidence conflicts, and other cross-module concerns can be triaged, investigated, escalated, reviewed, remediated, and audited WITHOUT law-enforcement referral, whistleblower intake, live integration, real database mutation, autonomous investigation, or autonomous determination of fraud, misconduct, negligence, guilt, or liability.",
  "notice": "All data is synthetic and non-identifiable. No real names, real email addresses, real patient identifiers, real whistleblower identities, credentials, secrets, precise locations, real legal allegations, real financial account details, or real restricted operational data are included. This is a synthetic governance demonstration, not a law-enforcement system, whistleblower intake platform, legal case-management system, autonomous investigation service, fraud adjudication engine, regulatory reporting system, or replacement for authorized investigative authorities.",
  "authorizedReviewOnlyLabel": "FOR GLOBAL FUND / CCM / AUTHORIZED PARTNER REVIEW ONLY",
  "permittedUse": {
    "statement": "Materials are for authorized review only under minimum-necessary access; no anonymous or public access is implied. Review does not grant ownership or commercial reuse rights, and does not establish guilt, liability, fraud, diversion, misconduct, or negligence.",
    "prohibits": [
      "unauthorized copying",
      "redistribution",
      "derivative or commercial use",
      "representation as a legal, disciplinary, or regulatory determination",
      "representation as a law-enforcement, whistleblower-intake, or fraud-adjudication system",
      "representation as proof of guilt, liability, or misconduct"
    ],
    "excludes": [
      "real names",
      "real email addresses",
      "real patient identifiers",
      "real whistleblower identities",
      "credentials",
      "secrets",
      "precise location",
      "real legal allegations",
      "real financial account details",
      "real restricted operational data"
    ]
  },
  "summary": {
    "totalRisks": 8,
    "openRisks": 5,
    "totalIncidents": 14,
    "openIncidents": 10,
    "activeInvestigations": 14,
    "openCases": 14,
    "highSeverityCases": 8,
    "criticalCases": 1,
    "blockedCases": 3,
    "escalatedCases": 7,
    "casesAwaitingSecondReview": 10,
    "casesMissingEvidence": 3,
    "casesConflictingEvidence": 1,
    "overdueInvestigations": 14,
    "overdueCorrectiveActions": 12,
    "reopenedCases": 2,
    "appeals": 2,
    "containmentActionsInProgress": 1,
    "correctiveActionsInProgress": 6,
    "preventiveActionsInProgress": 5,
    "remediationCompletionRate": 29,
    "ineffectiveActions": 1,
    "crossModuleIncidents": 1,
    "openEscalations": 6,
    "separationOfDutiesRules": 18,
    "aiSignalCount": 13,
    "auditEvents": 15,
    "byModule": {
      "fund-accountability": 1,
      "stockpile-logistics": 2,
      "lab-operations": 2,
      "patient-continuity": 1,
      "restricted-patient-locator": 1,
      "asset-management": 1,
      "program-performance": 1,
      "ai-intelligence": 1,
      "country-rollout": 1,
      "identity-access-governance": 1,
      "executive-review-packet": 1,
      "data-quality-reconciliation": 1,
      "authorized-review-room": 1
    },
    "byCountry": {
      "CN-A": 14,
      "CN-B": 1
    },
    "byOrganization": {
      "ORG-MOH-A": 6,
      "ORG-IP-1": 5,
      "ORG-AUDIT-1": 1,
      "ORG-FUNDER-1": 3
    },
    "byFacility": {
      "FAC-A1": 11,
      "FAC-B1": 2,
      "FAC-A2": 2
    },
    "byProgram": {
      "PRG-HIV": 9,
      "PRG-MAL": 3,
      "PRG-TB": 3
    },
    "byCategory": {
      "financial-integrity": 1,
      "commodity-integrity": 2,
      "laboratory-quality": 2,
      "patient-safety-continuity": 1,
      "privacy-access": 1,
      "asset-accountability": 1,
      "program-integrity": 1,
      "ai-signal-review": 1,
      "rollout-control": 1,
      "identity-governance": 1,
      "review-access-control": 2,
      "data-quality-integrity": 1
    },
    "bySeverity": {
      "high": 8,
      "critical": 1,
      "medium": 6
    },
    "byStatus": {
      "open": 8,
      "blocked": 3,
      "closed": 1,
      "reopened": 1,
      "escalated": 2
    },
    "boundaryReminder": {
      "impactDomain": "impact.maxarchealth.com",
      "impactPort": "3201",
      "medicalLibraryBoundary": "library.maxarchealth.com remains separate (port 3101, not used here)",
      "maxTraxEhrBoundary": "MaxTrax EHR remains separate; this is not a full EHR"
    }
  },
  "positioning": {
    "isSyntheticGovernanceDemonstration": true,
    "isNotLawEnforcementSystem": true,
    "isNotWhistleblowerIntakePlatform": true,
    "isNotLegalCaseManagementSystem": true,
    "isNotAutonomousInvestigationService": true,
    "isNotFraudAdjudicationEngine": true,
    "isNotRegulatoryReportingSystem": true,
    "isNotReplacementForInvestigativeAuthorities": true,
    "noLiveExternalIntegration": true,
    "noRealDatabaseMutation": true,
    "noAutonomousInvestigation": true,
    "noPunitiveAutomation": true,
    "noRealEvidenceUpload": true,
    "noRealFileDelivery": true,
    "noRealWhistleblowerIntake": true,
    "sourceModuleRecordsAuthoritative": true,
    "notAnEhr": true,
    "coversModules": [
      "fund-accountability",
      "stockpile-logistics",
      "lab-operations",
      "patient-continuity",
      "restricted-patient-locator",
      "asset-management",
      "program-performance",
      "ai-intelligence",
      "country-rollout",
      "authorized-review-room",
      "executive-review-packet",
      "identity-access-governance",
      "data-quality-reconciliation"
    ]
  },
  "caseGovernancePosture": {
    "statement": "A signal is not a finding, an anomaly is not proof, an allegation is not a determination, and a risk score is not a legal conclusion. Opening a case does not establish guilt, diversion, fraud, misconduct, negligence, or liability. Source-module records remain authoritative; cases may reference source records but never silently modify them. Every case identifies its category, source module, owner, assigned roles, status, severity, confidentiality, evidence, timeline, review status, and audit reference. Every material decision identifies the decision-maker, role, reason, evidence, timestamp, and audit reference.",
    "signalIsNotFinding": true,
    "anomalyIsNotProof": true,
    "allegationIsNotDetermination": true,
    "riskScoreIsNotLegalConclusion": true,
    "caseOpeningDoesNotEstablishGuilt": true,
    "sourceModuleRecordsAuthoritative": true,
    "noSilentSourceModification": true,
    "everyCaseAttributed": true,
    "everyMaterialDecisionAttributed": true,
    "missingAndConflictingEvidenceRemainVisible": true,
    "unsupportedFindingsRemainUnconfirmedOrBlocked": true,
    "unresolvedCasesNotRepresentedAsClosed": true,
    "closureRequiresExplicitCriteriaAndHumanApproval": true,
    "closedCasesReopenableThroughAuditableProcess": true,
    "appealsOrReconsiderationsRemainVisible": true,
    "dispositionDistinctFromRemediation": true,
    "remediationDoesNotEraseHistoricalFindingsOrEvidence": true,
    "noSilentRewriteOrDeletionOfCaseHistory": true
  },
  "riskPosture": {
    "statement": "Risk scores support prioritization only. Low confidence remains visible. A high score does not establish wrongdoing. Risk acceptance, mitigation, transfer, or escalation requires authorized human review. Expired or stale risk assessments require re-review. Residual risk remains visible after mitigation.",
    "scoresSupportPrioritizationOnly": true,
    "lowConfidenceRemainsVisible": true,
    "highScoreDoesNotEstablishWrongdoing": true,
    "acceptanceMitigationTransferEscalationRequiresHumanReview": true,
    "staleAssessmentsRequireReReview": true,
    "residualRiskRemainsVisible": true
  },
  "incidentPosture": {
    "statement": "Incidents record what was detected, when, by whom, and its assessed impact. An incident is not a finding of wrongdoing. Containment is distinct from investigation and remediation. Incidents reference source-module records but never silently modify them.",
    "incidentIsNotFinding": true,
    "containmentDistinctFromInvestigation": true,
    "referencesSourceWithoutModification": true
  },
  "investigationPosture": {
    "statement": "Investigations are structured, attributable, and evidence-bounded. The investigator cannot provide sole final approval where independent review is required. The case creator cannot independently approve closure. The source-record owner cannot independently resolve a disputed case where independent review is required. An AI-generated hypothesis cannot become a finding without human evidence review. Contradictory evidence and investigation limitations remain visible. A finding must identify supporting and conflicting evidence, and no conclusion may exceed the available evidence.",
    "investigatorCannotProvideSoleFinalApproval": true,
    "caseCreatorCannotApproveClosure": true,
    "ownerCannotResolveDisputedCase": true,
    "aiHypothesisCannotBecomeFindingWithoutHumanReview": true,
    "contradictoryEvidenceRemainsVisible": true,
    "limitationsRemainVisible": true,
    "findingIdentifiesSupportingAndConflictingEvidence": true,
    "findingStatesRemainDistinct": true,
    "noConclusionExceedsEvidence": true
  },
  "findingsPosture": {
    "statement": "Findings use distinct evidence-bounded states and remain distinct from disposition. This platform does not represent criminal guilt, civil liability, disciplinary guilt, regulatory violation, or a formal fraud determination except as explicitly unavailable and outside platform authority.",
    "supportedStates": [
      "unreviewed",
      "unsubstantiated",
      "inconclusive",
      "partially-substantiated",
      "substantiated",
      "disproven",
      "blocked-insufficient-evidence"
    ],
    "doesNotRepresentCriminalGuilt": true,
    "doesNotRepresentCivilLiability": true,
    "doesNotRepresentDisciplinaryGuilt": true,
    "doesNotRepresentRegulatoryViolation": true,
    "doesNotRepresentFormalFraudDetermination": true,
    "suchDeterminationsMarkedUnavailableAndOutsideAuthority": true
  },
  "correctiveActionPosture": {
    "statement": "Action completion is not the same as effectiveness verification. Overdue and failed or ineffective actions remain visible. Action owners cannot independently verify high-risk actions where second review is required. Case closure requires the required corrective actions and closure criteria. Ineffective remediation may trigger case reopening. Remediation does not erase the original incident or investigation record.",
    "completionIsNotEffectivenessVerification": true,
    "overdueActionsRemainVisible": true,
    "failedOrIneffectiveActionsRemainVisible": true,
    "ownersCannotIndependentlyVerifyHighRiskActions": true,
    "closureRequiresRequiredActionsAndCriteria": true,
    "ineffectiveRemediationMayTriggerReopen": true,
    "remediationDoesNotEraseOriginalRecord": true
  },
  "separationOfDutiesPosture": {
    "statement": "Risk, incident, investigation, finding, disposition, closure, and remediation duties are separated. Signal creators, incident reporters, case creators, investigators, evidence capturers, source-record owners, and module actors cannot independently approve, substantiate, close, or verify their own work where independent review is required. Violations remain blocked or pending, identify the violated rule, require reassignment, independent review, or second review, remain auditable, and are never silently overridden.",
    "violationsRemainBlockedOrPending": true,
    "violationsIdentifyRule": true,
    "violationsRequireReassignmentIndependentOrSecondReview": true,
    "violationsAuditable": true,
    "neverSilentlyOverridden": true
  },
  "confidentialityPosture": {
    "statement": "All actor references are masked. Access is minimum-necessary and role-scoped. Confidentiality classifications apply; restricted cases remain non-public and denied access does not confirm restricted case details. There is no real whistleblower intake or anonymous-reporting workflow, no patient identity, no precise location, and no credentials or secrets. Evidence export is never unrestricted; export eligibility is explicit, time-bound, approved, revocable, and auditable. This task does not implement real access enforcement or authentication.",
    "maskedActorReferencesOnly": true,
    "minimumNecessaryDisclosure": true,
    "roleScopedCaseAccess": true,
    "confidentialityClassificationsApply": true,
    "restrictedCasesRemainNonPublic": true,
    "deniedAccessDoesNotConfirmRestrictedDetails": true,
    "noRealWhistleblowerIntake": true,
    "noRealAnonymousReportingWorkflow": true,
    "noPatientIdentity": true,
    "noPreciseLocation": true,
    "noCredentialsOrSecrets": true,
    "noUnrestrictedEvidenceExport": true,
    "exportEligibilityExplicitTimeBoundApprovedRevocableAuditable": true,
    "noRealAccessEnforcementOrAuthentication": true
  },
  "auditPosture": {
    "statement": "Audit events are append-only in this demonstration model. Historical states remain visible. Corrections, finding reversals, and reopen events require new linked events. Deletion is not an allowed case-management control. Source-module audit records remain authoritative. This task does not implement a production cryptographic evidence or audit ledger.",
    "appendOnly": true,
    "historicalStatesRemainVisible": true,
    "correctionsRequireNewLinkedEvent": true,
    "findingReversalsRequireNewLinkedEvent": true,
    "reopenEventsRequireNewLinkedEvent": true,
    "deletionNotAnAllowedControl": true,
    "sourceModuleRecordsAuthoritative": true,
    "notProductionCryptographicLedger": true
  },
  "exportPosture": {
    "statement": "Case and evidence export is a controlled, demonstration-only concept. Export eligibility is explicit, time-bound, approved, revocable, and auditable. No real file delivery, real evidence upload, or unrestricted case export is implemented.",
    "exportEligibilityExplicit": true,
    "exportTimeBound": true,
    "exportRequiresApproval": true,
    "exportRevocable": true,
    "exportAuditable": true,
    "noRealFileDelivery": true,
    "noUnrestrictedCaseExport": true
  },
  "aiPosture": {
    "statement": "AI is assistive only. It surfaces risk signals, clusters incidents, compares cases, maps findings to evidence, and prioritizes review for authorized humans, and never opens punitive cases, determines fraud or liability, substantiates allegations, approves findings, closes or reopens cases, notifies external parties, assigns discipline, suppresses evidence, fabricates evidence, alters source records, approves remediation effectiveness, authorizes export, or bypasses controls.",
    "assists": [
      "detect risk signals and anomalies",
      "cluster related incidents",
      "compare cases across authorized modules",
      "detect missing or conflicting evidence",
      "identify stale cases and overdue actions",
      "suggest investigation hypotheses",
      "suggest competing explanations",
      "map findings to supporting evidence",
      "identify unsupported conclusions",
      "prioritize cases for review",
      "recommend escalation or second review",
      "summarize chronology for authorized reviewers",
      "detect separation-of-duties conflicts",
      "identify potentially ineffective remediation",
      "support root-cause analysis"
    ],
    "mustNot": [
      "autonomously open a punitive case",
      "autonomously determine fraud, diversion, misconduct, negligence, guilt, or liability",
      "autonomously substantiate allegations",
      "autonomously approve findings",
      "autonomously close or reopen cases",
      "autonomously notify law enforcement, regulators, funders, employers, or affected individuals",
      "autonomously assign disciplinary action",
      "autonomously suppress exculpatory or conflicting evidence",
      "autonomously fabricate evidence",
      "autonomously alter source records",
      "autonomously approve corrective-action effectiveness",
      "autonomously authorize case export",
      "bypass human review, second review, separation of duties, confidentiality, evidence, expiration, revocation, or audit controls"
    ]
  },
  "humanControls": {
    "humanApprovalMandatory": true,
    "secondReviewForHighRisk": true,
    "separationOfDutiesEnforced": true,
    "reviewersAttributable": true,
    "closureRequiresHumanApproval": true
  },
  "boundary": {
    "impactDomain": "impact.maxarchealth.com",
    "impactPort": "3201",
    "medicalLibraryBoundary": "library.maxarchealth.com remains separate (port 3101, not used here)",
    "maxTraxEhrBoundary": "MaxTrax EHR remains separate; this is not a full EHR and implements no live integration or real database mutation",
    "protectedStaging": "/opt/operations-catch-them-young-staging remains untouched"
  },
  "modules": [
    {
      "id": "fund-accountability",
      "name": "Fund Accountability"
    },
    {
      "id": "stockpile-logistics",
      "name": "Stockpile & Logistics"
    },
    {
      "id": "lab-operations",
      "name": "Laboratory Operations"
    },
    {
      "id": "patient-continuity",
      "name": "Patient Continuity"
    },
    {
      "id": "restricted-patient-locator",
      "name": "Restricted Patient Locator"
    },
    {
      "id": "asset-management",
      "name": "Asset Management"
    },
    {
      "id": "program-performance",
      "name": "Program Performance"
    },
    {
      "id": "ai-intelligence",
      "name": "AI Intelligence"
    },
    {
      "id": "country-rollout",
      "name": "Country Rollout"
    },
    {
      "id": "authorized-review-room",
      "name": "Authorized Review Room"
    },
    {
      "id": "executive-review-packet",
      "name": "Executive Review Packet & Controlled Download Center"
    },
    {
      "id": "identity-access-governance",
      "name": "Identity & Access Governance"
    },
    {
      "id": "data-quality-reconciliation",
      "name": "Data Quality & Reconciliation"
    }
  ],
  "caseCategories": [
    "financial-integrity",
    "commodity-integrity",
    "laboratory-quality",
    "patient-safety-continuity",
    "privacy-access",
    "asset-accountability",
    "program-integrity",
    "ai-signal-review",
    "rollout-control",
    "review-access-control",
    "identity-governance",
    "data-quality-integrity"
  ],
  "incidentCategories": [
    "suspected-diversion",
    "dispatch-receipt-discrepancy",
    "stock-loss",
    "lab-qc-failure",
    "result-routing",
    "continuity-interruption",
    "restricted-access-concern",
    "asset-loss",
    "program-result-integrity",
    "ai-pattern",
    "rollout-control-failure",
    "unauthorized-access-attempt",
    "identity-violation",
    "reconciliation-conflict"
  ],
  "riskCategories": [
    "financial",
    "supply-chain",
    "clinical-quality",
    "privacy",
    "operational",
    "governance",
    "information-integrity"
  ],
  "findingStates": [
    {
      "id": "unreviewed",
      "name": "Unreviewed",
      "description": "No human evidence review has occurred."
    },
    {
      "id": "unsubstantiated",
      "name": "Unsubstantiated",
      "description": "Reviewed; evidence does not support the allegation."
    },
    {
      "id": "inconclusive",
      "name": "Inconclusive",
      "description": "Evidence neither supports nor refutes the allegation."
    },
    {
      "id": "partially-substantiated",
      "name": "Partially substantiated",
      "description": "Some, not all, elements are supported by evidence."
    },
    {
      "id": "substantiated",
      "name": "Substantiated",
      "description": "Evidence supports the allegation within platform scope; not a legal determination."
    },
    {
      "id": "disproven",
      "name": "Disproven",
      "description": "Evidence refutes the allegation."
    },
    {
      "id": "blocked-insufficient-evidence",
      "name": "Blocked (insufficient evidence)",
      "description": "A finding is blocked because required evidence is missing or conflicting."
    }
  ],
  "dispositionStates": [
    "no-further-action",
    "monitoring",
    "control-remediation",
    "management-review",
    "compliance-review",
    "referral-eligible",
    "referral-blocked",
    "case-reopened",
    "closure-pending",
    "closed-after-approval"
  ],
  "actionTypes": [
    "containment",
    "correction",
    "corrective",
    "preventive",
    "recovery",
    "monitoring",
    "policy-update",
    "training",
    "control-redesign",
    "access-restriction",
    "inventory-recount",
    "evidence-re-verification",
    "reconciliation-rerun",
    "independent-review"
  ],
  "policies": [
    {
      "id": "POL-RIC-01",
      "name": "Signal is not a finding",
      "statement": "Signals, anomalies, allegations, and risk scores are not findings, proof, determinations, or legal conclusions."
    },
    {
      "id": "POL-RIC-02",
      "name": "Source-authoritative",
      "statement": "Cases reference source records but never silently modify them; source-module records remain authoritative."
    },
    {
      "id": "POL-RIC-03",
      "name": "Evidence-bounded findings",
      "statement": "A finding identifies supporting and conflicting evidence and no conclusion may exceed the available evidence."
    },
    {
      "id": "POL-RIC-04",
      "name": "Closure & reopen",
      "statement": "Closure requires explicit criteria and human approval; closed cases are reopenable through an auditable process."
    },
    {
      "id": "POL-RIC-05",
      "name": "Append-only audit",
      "statement": "Corrections, finding reversals, and reopen events require new linked events; deletion is not an allowed control."
    }
  ],
  "routes": [
    "/risk-incident-case-governance/risks",
    "/risk-incident-case-governance/incidents",
    "/risk-incident-case-governance/cases",
    "/risk-incident-case-governance/investigations",
    "/risk-incident-case-governance/triage",
    "/risk-incident-case-governance/evidence",
    "/risk-incident-case-governance/timelines",
    "/risk-incident-case-governance/hypotheses",
    "/risk-incident-case-governance/findings",
    "/risk-incident-case-governance/dispositions",
    "/risk-incident-case-governance/containment-actions",
    "/risk-incident-case-governance/corrective-actions",
    "/risk-incident-case-governance/preventive-actions",
    "/risk-incident-case-governance/escalations",
    "/risk-incident-case-governance/closure-reviews",
    "/risk-incident-case-governance/reopens",
    "/risk-incident-case-governance/appeals",
    "/risk-incident-case-governance/risk-signals",
    "/risk-incident-case-governance/audit-events",
    "/risk-incident-case-governance/summary",
    "/risk-incident-case-governance-dashboard"
  ]
}