Prioritization only
MaxArc Global Health Impact Platform
Risk, Incident, Investigation & Case Governance
Cross-module risk, incident, investigation, and case governance with human approval.
A synthetic governance demonstration — not a law-enforcement system, whistleblower intake platform, legal case-management system, autonomous investigation service, fraud adjudication engine, regulatory reporting system, or replacement for authorized investigative authorities. A signal is not a finding, an anomaly is not proof, an allegation is not a determination, and a risk score is not a legal conclusion. Opening a case does not establish guilt, diversion, fraud, misconduct, negligence, or liability. Source-module records remain authoritative; cases reference but never silently modify them. No live integration, real database mutation, autonomous investigation, real evidence upload, real file delivery, or punitive automation is implemented. AI is assistive only and never substantiates allegations, approves findings, closes or reopens cases, notifies external parties, or bypasses controls.
Unmitigated
Cross-module
Not yet contained
In progress
Not closed
Priority
Highest priority
Insufficient evidence / SoD
Independent review
High-risk
Remain visible
Both retained
Past due date
Remain visible
Auditable
Remain visible
Active
Active
Active
Completion ≠ effectiveness
Remain visible
Span modules
Enforced
Human review required
Append-only
Risks (prioritization only)
Risk scores support prioritization only. Low confidence remains visible; a high score does not establish wrongdoing. Stale assessments require re-review and residual risk remains visible after mitigation.
| Risk | Description | Score / severity | Status |
|---|---|---|---|
| RISK-001 fund-accountability · financial |
Risk of undocumented expenditure variance across grant disbursements. | score 72 high likelihood medium · impact high · confidence medium |
in-progress residual medium · review 2025-09-01 · audit AUD-001 |
| RISK-002 stockpile-logistics · supply-chain |
Risk of commodity diversion between dispatch and receipt. | score 78 high likelihood medium · impact high · confidence medium |
open residual high · review 2025-08-15 · audit AUD-002 |
| RISK-003 lab-operations · clinical-quality |
Risk of laboratory quality-control failure affecting result reliability. | score 58 medium likelihood low · impact high · confidence high |
in-progress residual low · review 2025-09-10 · audit AUD-004 |
| RISK-004 restricted-patient-locator · privacy |
Risk of unauthorized restricted-locator access. | score 70 high likelihood low · impact high · confidence medium |
open residual medium · review 2025-08-20 · audit AUD-007 |
| RISK-005 asset-management · operational |
Risk of asset loss or unauthorized transfer. | score 55 medium likelihood medium · impact medium · confidence medium |
in-progress residual medium · review 2025-09-05 · audit AUD-008 |
| RISK-006 program-performance · information-integrity |
Risk of program-result integrity concerns from implausible reporting. | score 74 high likelihood medium · impact high · confidence medium |
open residual high · review 2025-08-25 · audit AUD-009 |
| RISK-007 identity-access-governance · governance |
Risk of identity-governance violations from expired-but-active access. | score 76 high likelihood medium · impact high · confidence medium |
open residual high · review 2025-09-15 · audit AUD-013 |
| RISK-008 fund-accountability · financial |
Legacy risk assessment retained for prioritization history; assessment is stale. | score 50 medium likelihood medium · impact medium · confidence low · stale |
requires-re-review residual medium · review 2024-11-01 · audit AUD-018 |
Incidents (an incident is not a finding)
Each incident records category, detection, source module, affected scope, severity, containment, evidence, impact, and audit reference across all covered modules.
| Incident | Category | Severity / containment | Impact assessment |
|---|---|---|---|
| INC-001 suspected-commodity-diversion |
suspected-diversion fund-accountability · grant-disbursement |
high in-progress | Potential undocumented disbursement variance under review; not established as diversion. case CASE-001 · audit AUD-001 |
| INC-002 warehouse-dispatch-receipt-discrepancy |
dispatch-receipt-discrepancy stockpile-logistics · warehouse-to-facility |
high in-progress | Dispatch of 5,000 units with receipt confirmation missing; discrepancy under review. case CASE-002 · audit AUD-002 |
| INC-003 unexplained-stock-loss |
stock-loss stockpile-logistics · facility-store |
medium contained | Recorded balance exceeds movement-derived balance by 25 units; cause unresolved. case CASE-003 · audit AUD-003 |
| INC-004 lab-qc-failure |
lab-qc-failure lab-operations · lab-batch |
medium contained | Quality-control run outside control limits; affected batch quarantined pending re-run. case CASE-004 · audit AUD-004 |
| INC-005 delayed-misrouted-lab-result |
result-routing lab-operations · restricted-result |
high in-progress | Restricted result not routed to clinician; potential care delay under review. case CASE-005 · audit AUD-005 |
| INC-006 patient-continuity-interruption |
continuity-interruption patient-continuity · referral-transfer-followup |
medium in-progress | Follow-up record missing for a completed transfer; continuity interruption under review. case CASE-005B · audit AUD-006 |
| INC-007 restricted-locator-access-concern |
restricted-access-concern restricted-patient-locator · restricted-records |
high contained | Access concern raised on a restricted-locator request; no restricted details disclosed. case CASE-006 · audit AUD-007 |
| INC-008 asset-loss-unauthorized-transfer |
asset-loss asset-management · facility-asset |
medium in-progress | Asset register active but custody unverified; possible unauthorized transfer under review. case CASE-007 · audit AUD-008 |
| INC-009 program-result-integrity-concern |
program-result-integrity program-performance · program-reporting |
high in-progress | Reported result implausibly exceeds target; integrity concern under review, not a finding. case CASE-008 · audit AUD-009 |
| INC-010 unusual-ai-pattern |
ai-pattern ai-intelligence · cross-module |
medium monitoring | AI clustered a possible-duplicate-disbursement pattern; an anomaly is not a finding. case CASE-009 · audit AUD-010 |
| INC-011 rollout-control-failure |
rollout-control-failure country-rollout · facility-readiness |
medium in-progress | Readiness claimed while a dependency remains incomplete; rollout control failure under review. case CASE-010 · audit AUD-011 |
| INC-012 unauthorized-reviewroom-packet-access |
unauthorized-access-attempt authorized-review-room · review-package |
high contained | Unauthorized review-room / packet access attempt blocked; no restricted content disclosed. case CASE-012 · audit AUD-012 |
| INC-013 identity-governance-violation |
identity-violation identity-access-governance · privileged-access |
high in-progress | Access decision approved but authorization expired while still represented as active. case CASE-011 · audit AUD-013 |
| INC-014 data-quality-reconciliation-conflict |
reconciliation-conflict data-quality-reconciliation · cross-module-claim |
high in-progress | Reconciliation conflict between a packet claim and verified capability state; both remain visible. case CASE-013 · audit AUD-014 |
Cases (allegation is not a determination)
Every case identifies category, source module, owner, assigned roles, status, severity, confidentiality, evidence, timeline, review status, and audit reference. Unresolved cases are never represented as closed. Missing and conflicting evidence remain visible.
| Case | Category / scope | Status | Evidence / posture |
|---|---|---|---|
| CASE-001 fund-accountability · FUND-DISB-1187 |
financial-integrity CN-A · FAC-A1 · PRG-HIV · owner ACT-03 |
high open SoD compliant 2nd review | allegation ≠ finding audit AUD-001 |
| CASE-002 stockpile-logistics · DISP-7781 |
commodity-integrity CN-A · FAC-B1 · PRG-MAL · owner ACT-03 |
critical blocked SoD violation 2nd review | missing evidence allegation ≠ finding rule SOD-008 · audit AUD-002 |
| CASE-003 stockpile-logistics · STOCK-BAL-A1-0925 |
commodity-integrity CN-A · FAC-A1 · PRG-TB · owner ACT-08 |
medium open SoD compliant | allegation ≠ finding audit AUD-003 |
| CASE-004 lab-operations · LAB-BATCH-3390 |
laboratory-quality CN-A · FAC-A1 · PRG-HIV · owner ACT-03 |
medium closed SoD compliant | allegation ≠ finding audit AUD-004 |
| CASE-005 lab-operations · RES-55121 |
laboratory-quality CN-A · FAC-A1 · PRG-HIV · owner ACT-03 |
high blocked SoD violation 2nd review | allegation ≠ finding rule SOD-009 · audit AUD-005 |
| CASE-005B patient-continuity · REF-2201 |
patient-safety-continuity CN-A · FAC-A2 · PRG-TB · owner ACT-03 |
medium open SoD compliant | missing evidence allegation ≠ finding audit AUD-006 |
| CASE-006 restricted-patient-locator · LOC-REQ-770 |
privacy-access CN-A · FAC-A1 · PRG-HIV · owner ACT-03 |
high open SoD violation 2nd review | allegation ≠ finding rule SOD-010 · audit AUD-007 |
| CASE-007 asset-management · ASSET-9032 |
asset-accountability CN-A · FAC-A1 · PRG-MAL · owner ACT-08 |
medium reopened SoD violation | allegation ≠ finding rule SOD-011 · audit AUD-008 |
| CASE-008 program-performance · PRG-RES-6612 |
program-integrity CN-A · FAC-A2 · PRG-TB · owner ACT-03 |
high escalated SoD violation 2nd review | allegation ≠ finding rule SOD-012 · audit AUD-009 |
| CASE-009 ai-intelligence · AIC-2050 |
ai-signal-review CN-A · FAC-A1 · PRG-HIV · owner ACT-04 |
medium open SoD violation 2nd review | allegation ≠ finding rule SOD-013 · audit AUD-010 |
| CASE-010 country-rollout · RDY-CLAIM-330 |
rollout-control CN-B · FAC-B1 · PRG-MAL · owner ACT-02 |
medium open SoD violation | missing evidence allegation ≠ finding rule SOD-014 · audit AUD-011 |
| CASE-011 identity-access-governance · IAG-DEC-508 |
identity-governance CN-A · FAC-A1 · PRG-HIV · owner ACT-10 |
high escalated SoD violation 2nd review | allegation ≠ finding rule SOD-016 · audit AUD-013 |
| CASE-012 executive-review-packet · PKT-ACCESS-14 |
review-access-control CN-A · FAC-A1 · PRG-HIV · owner ACT-07 |
high open SoD violation 2nd review | allegation ≠ finding rule SOD-015 · audit AUD-012 |
| CASE-013 data-quality-reconciliation · DQC-014 |
data-quality-integrity CN-A · FAC-A1 · PRG-HIV · owner ACT-01 |
high blocked SoD violation 2nd review | conflicting evidence allegation ≠ finding rule SOD-017 · audit AUD-014 |
| CASE-014 authorized-review-room · RVR-PKG-22 |
review-access-control CN-A · FAC-A1 · PRG-HIV · owner ACT-07 |
high open SoD violation 2nd review | allegation ≠ finding rule SOD-015 · audit AUD-012 |
Investigations
The investigator cannot provide sole final approval where independent review is required; contradictory evidence and limitations remain visible; no conclusion may exceed available evidence.
| Investigation | Scope | Status / roles | Limitations |
|---|---|---|---|
| INV-001 case CASE-001 |
Assess whether the disbursement-expenditure variance reflects timing or unrecorded expenditure. | in-progress 2nd review SoD compliant investigator investigator · independent independent-reviewer · due 2025-04-08 |
Expenditure evidence partially unverified. |
| INV-002 case CASE-002 |
Determine cause of the dispatch/receipt discrepancy with missing receipt confirmation. | overdue 2nd review SoD violation investigator investigator · independent independent-reviewer · due 2025-06-20 |
Receipt confirmation missing; conclusion cannot exceed evidence. |
| INV-003 case CASE-003 |
Investigate the 25-unit stock balance/movement divergence. | in-progress SoD compliant investigator investigator · independent independent-reviewer · due 2025-08-03 |
Physical recount pending. |
| INV-004 case CASE-004 |
Investigate the laboratory quality-control failure and confirm remediation. | completed SoD compliant investigator investigator · independent independent-reviewer · due 2025-05-27 |
None material. |
| INV-005 case CASE-005 |
Investigate the unrouted restricted laboratory result. | overdue 2nd review SoD violation investigator investigator · independent independent-reviewer · due 2025-06-15 |
Restricted case; minimum-necessary access. |
| INV-006 case CASE-005B |
Investigate the missing follow-up record for a completed transfer. | in-progress SoD compliant investigator investigator · independent independent-reviewer · due 2025-06-21 |
Follow-up evidence missing. |
| INV-007 case CASE-006 |
Investigate the restricted-locator access concern. | in-progress 2nd review SoD violation investigator investigator · independent independent-reviewer · due 2025-06-03 |
Restricted case; denied access does not confirm details. |
| INV-008 case CASE-007 |
Investigate the asset custody discrepancy and prior ineffective remediation. | in-progress SoD violation investigator investigator · independent independent-reviewer · due 2025-09-02 |
Custody unverified. |
| INV-009 case CASE-008 |
Investigate the implausible program result. | in-progress 2nd review SoD violation investigator investigator · independent independent-reviewer · due 2025-07-22 |
Source document unverified. |
| INV-010 case CASE-009 |
Review the AI-clustered duplicate-disbursement pattern against source evidence. | in-progress 2nd review SoD violation investigator investigator · independent independent-reviewer · due 2025-07-02 |
AI hypothesis cannot become a finding without human evidence review. |
| INV-011 case CASE-010 |
Investigate the rollout control failure (readiness vs dependency). | in-progress SoD violation investigator investigator · independent independent-reviewer · due 2025-10-02 |
Dependency evidence missing. |
| INV-012 case CASE-011 |
Investigate the expired-but-active privileged access. | in-progress 2nd review SoD violation investigator investigator · independent independent-reviewer · due 2025-09-16 |
Approver cannot resolve their own discrepancy. |
| INV-013 case CASE-012 |
Investigate the unauthorized packet-access attempt. | in-progress 2nd review SoD violation investigator investigator · independent independent-reviewer · due 2025-08-11 |
Restricted case. |
| INV-014 case CASE-013 |
Investigate the reconciliation conflict between a packet claim and verified capability state. | in-progress 2nd review SoD violation investigator investigator · independent independent-reviewer · due 2025-08-05 |
Conflicting verified evidence; conclusion cannot exceed evidence. |
| INV-015 case CASE-014 |
Investigate an authorized review-room access-attribution concern for a shared evidence package. | in-progress 2nd review SoD violation investigator investigator · independent independent-reviewer · due 2025-08-13 |
Restricted case; minimum-necessary access. |
Finding states (distinct & evidence-bounded)
- Unreviewed — No human evidence review has occurred.
- Unsubstantiated — Reviewed; evidence does not support the allegation.
- Inconclusive — Evidence neither supports nor refutes the allegation.
- Partially substantiated — Some, not all, elements are supported by evidence.
- Substantiated — Evidence supports the allegation within platform scope; not a legal determination.
- Disproven — Evidence refutes the allegation.
- Blocked (insufficient evidence) — A finding is blocked because required evidence is missing or conflicting.
Dispositions (distinct from findings & remediation)
- DISP-001 — case CASE-001 monitoringdecided by compliance-reviewer · distinct from finding & remediation · audit AUD-001
- DISP-002 — case CASE-002 referral-blockeddecided by compliance-reviewer · distinct from finding & remediation · audit AUD-002
- DISP-003 — case CASE-003 control-remediationdecided by independent-reviewer · distinct from finding & remediation · audit AUD-003
- DISP-004 — case CASE-004 closed-after-approvaldecided by compliance-reviewer · distinct from finding & remediation · audit AUD-004
- DISP-005 — case CASE-005 management-reviewdecided by independent-reviewer · distinct from finding & remediation · audit AUD-005
- DISP-006 — case CASE-005B no-further-actiondecided by case-owner · distinct from finding & remediation · audit AUD-006
- DISP-007 — case CASE-006 compliance-reviewdecided by compliance-reviewer · distinct from finding & remediation · audit AUD-007
- DISP-008 — case CASE-007 case-reopeneddecided by independent-reviewer · distinct from finding & remediation · audit AUD-008
- DISP-009 — case CASE-008 referral-eligibledecided by compliance-reviewer · distinct from finding & remediation · audit AUD-009
- DISP-010 — case CASE-009 monitoringdecided by independent-reviewer · distinct from finding & remediation · audit AUD-010
- DISP-011 — case CASE-010 control-remediationdecided by independent-reviewer · distinct from finding & remediation · audit AUD-011
- DISP-012 — case CASE-011 management-reviewdecided by compliance-reviewer · distinct from finding & remediation · audit AUD-013
- DISP-013 — case CASE-012 closure-pendingdecided by compliance-reviewer · distinct from finding & remediation · audit AUD-012
- DISP-014 — case CASE-013 compliance-reviewdecided by compliance-reviewer · distinct from finding & remediation · audit AUD-014
- DISP-015 — case CASE-014 management-reviewdecided by compliance-reviewer · distinct from finding & remediation · audit AUD-012
Findings
Each finding identifies the allegation or question reviewed, its evidence-bounded state, confidence, and supporting, conflicting, and missing evidence. This platform does not represent criminal guilt, civil liability, disciplinary guilt, regulatory violation, or a formal fraud determination; such authority is outside the platform.
| Finding | Allegation / question | State | Evidence |
|---|---|---|---|
| FND-001 case CASE-001 |
Does the disbursement variance reflect unrecorded expenditure? | inconclusive confidence medium · approval pending |
support: EVD-001 · conflict: — · missing: verified-expenditure-report |
| FND-002 case CASE-002 |
Was the dispatch/receipt gap caused by diversion? | blocked-insufficient-evidence confidence low · approval blocked |
support: — · conflict: — · missing: receipt-confirmation |
| FND-003 case CASE-003 |
Is the stock divergence a counting error? | partially-substantiated confidence medium · approval pending |
support: EVD-003 · conflict: — · missing: physical-recount |
| FND-004 case CASE-004 |
Was the QC failure caused by a reagent lot issue and remediated? | substantiated confidence high · approval approved |
support: EVD-004 · conflict: — · missing: — |
| FND-005 case CASE-005 |
Why was the restricted result not routed? | blocked-insufficient-evidence confidence low · approval blocked |
support: EVD-005 · conflict: EVD-017 · missing: verified-routing-record |
| FND-006 case CASE-005B |
Was follow-up performed but unrecorded? | unreviewed confidence low · approval pending |
support: — · conflict: — · missing: follow-up-record |
| FND-007 case CASE-006 |
Was the restricted-locator access appropriately authorized? | inconclusive confidence medium · approval pending |
support: EVD-007 · conflict: — · missing: — |
| FND-008 case CASE-007 |
Was the asset transferred without authorization? | unsubstantiated confidence medium · approval reopened |
support: EVD-008, EVD-016 · conflict: — · missing: — |
| FND-009 case CASE-008 |
Does the implausible result reflect fabrication? | blocked-insufficient-evidence confidence low · approval blocked |
support: EVD-009 · conflict: — · missing: verified-source-document |
| FND-010 case CASE-009 |
Is the AI-clustered pattern a true duplicate? | inconclusive confidence low · approval pending |
support: EVD-010 · conflict: — · missing: verified-signal-source |
| FND-011 case CASE-010 |
Was rollout readiness claimed prematurely? | partially-substantiated confidence medium · approval pending |
support: — · conflict: — · missing: dependency-status-record |
| FND-012 case CASE-011 |
Why did expired access remain active? | partially-substantiated confidence medium · approval pending |
support: EVD-013 · conflict: — · missing: — |
| FND-013 case CASE-012 |
Was the packet-access attempt deliberate? | disproven confidence medium · approval pending |
support: EVD-012 · conflict: — · missing: — |
| FND-014 case CASE-013 |
Did the packet claim overstate the capability? | blocked-insufficient-evidence confidence low · approval blocked |
support: EVD-014 · conflict: EVD-015 · missing: — |
| FND-015 case CASE-014 |
Was the authorized review-room access correctly attributed? | inconclusive confidence low · approval pending |
support: EVD-012 · conflict: — · missing: EVD-MISSING-ATTRIB |
Containment, corrective, preventive, recovery & effectiveness actions
Action completion is not effectiveness verification. Overdue and ineffective actions remain visible. Action owners cannot independently verify high-risk effectiveness where second review is required; ineffective remediation can trigger reopening; remediation does not erase incident or investigation history.
| Action | Type | Status / verification | Effectiveness |
|---|---|---|---|
| ACT-CN-001 case CASE-002 |
containment Hold further dispatches on the affected route pending reconciliation. |
in-progress verify not-verified · 2nd review |
pending review 2025-07-01 · reopen: recurrence of discrepancy |
| ACT-CN-002 case CASE-005 |
containment Quarantine the unrouted restricted result pending independent release review. |
completed verify verified · 2nd review |
effective review 2025-06-01 · reopen: further routing failure |
| ACT-CN-003 case CASE-012 |
access-restriction Restrict packet access pending investigation. |
completed verify verified |
effective review 2025-08-01 · reopen: further unauthorized attempt |
| ACT-CA-001 case CASE-001 |
corrective Obtain and verify the outstanding expenditure report. |
in-progress verify not-verified · 2nd review |
pending review 2025-05-01 · reopen: unresolved variance |
| ACT-CA-002 case CASE-003 |
inventory-recount Perform an independent physical stock recount. |
overdue overdue verify not-verified |
pending review 2025-08-01 · reopen: divergence persists |
| ACT-CA-003 case CASE-007 |
corrective Re-verify asset custody with independent confirmation. |
completed verify not-verified · 2nd review |
ineffective review 2025-08-18 · reopen: custody still unverified |
| ACT-CA-004 case CASE-008 |
reconciliation-rerun Re-run numerator/denominator reconciliation with independent review. |
in-progress verify not-verified · 2nd review |
pending review 2025-08-15 · reopen: implausibility persists |
| ACT-CA-005 case CASE-011 |
access-restriction Deactivate expired-but-active access pending review. |
completed verify verified · 2nd review |
effective review 2025-09-10 · reopen: reactivation without approval |
| ACT-CA-006 case CASE-013 |
evidence-re-verification Independently re-verify conflicting capability evidence. |
in-progress verify not-verified · 2nd review |
pending review 2025-08-20 · reopen: conflict unresolved |
| ACT-CA-007 case CASE-004 |
independent-review Independent review of QC remediation effectiveness. |
completed verify verified |
effective review 2025-05-20 · reopen: QC failure recurs |
| ACT-CA-008 case CASE-002 |
control-redesign Redesign dispatch/receipt confirmation control. |
in-progress verify not-verified · 2nd review |
pending review 2025-08-30 · reopen: recurrence |
| ACT-PA-001 case CASE-001 |
preventive Introduce a periodic disbursement-expenditure reconciliation check. |
in-progress verify not-verified |
pending review 2025-09-30 · reopen: variance recurs |
| ACT-PA-002 case CASE-005 |
training Deliver restricted-result routing training (synthetic). |
in-progress verify not-verified |
pending review 2025-08-15 · reopen: routing failure recurs |
| ACT-PA-003 case CASE-010 |
policy-update Update rollout-readiness policy to require dependency evidence. |
in-progress verify not-verified |
pending review 2025-11-15 · reopen: premature readiness recurs |
| ACT-RC-001 case CASE-003 |
recovery Recover and reconcile any misplaced stock after recount. |
in-progress verify not-verified |
pending review 2025-08-20 · reopen: stock not recovered |
| ACT-MN-001 case CASE-009 |
monitoring Monitor the AI-flagged pattern for recurrence pending human review. |
in-progress verify not-verified |
pending review 2025-08-02 · reopen: pattern recurs |
| ACT-COR-001 case CASE-014 |
correction Request a documented correction of the review-room access-attribution record (source record remains authoritative; no silent modification). |
in-progress verify not-verified · 2nd review |
pending review 2025-09-01 · reopen: attribution remains unresolved |
Separation-of-duties rules
Violations remain blocked or pending, identify the violated rule, require reassignment, independent review, or second review, remain auditable, and are never silently overridden.
| Rule | Enforcement | Override / audit |
|---|---|---|
| Signal creator cannot independently approve a final finding. SOD-001 · signal-creator-cannot-approve-finding |
blocked | never silently overridden auditable · e.g. CASE-001 |
| Incident reporter cannot independently close the case. SOD-002 · incident-reporter-cannot-close-case |
blocked | never silently overridden auditable · e.g. CASE-002 |
| Case creator cannot independently approve closure. SOD-003 · case-creator-cannot-approve-closure |
blocked | never silently overridden auditable · e.g. CASE-012 |
| Investigator cannot independently provide final approval where independent review is required. SOD-004 · investigator-cannot-final-approve |
blocked | never silently overridden auditable · e.g. CASE-001 |
| Evidence capturer cannot independently verify high-risk evidence. SOD-005 · capturer-cannot-verify-high-risk-evidence |
pending | never silently overridden auditable · e.g. EVD-008 |
| Source-data owner cannot independently resolve a disputed finding. SOD-006 · owner-cannot-resolve-disputed-finding |
blocked | never silently overridden auditable · e.g. CASE-013 |
| Fund investigator cannot independently authorize financial disposition. SOD-007 · fund-investigator-cannot-authorize-financial-disposition |
blocked | never silently overridden auditable · e.g. CASE-001 |
| Warehouse dispatcher cannot independently resolve their own discrepancy case. SOD-008 · dispatcher-cannot-resolve-own-discrepancy |
blocked | never silently overridden auditable · e.g. CASE-002 |
| Laboratory result preparer cannot independently close a result-integrity investigation. SOD-009 · lab-preparer-cannot-close-result-integrity |
blocked | never silently overridden auditable · e.g. CASE-005 |
| Restricted-locator requestor cannot independently close an access concern. SOD-010 · locator-requestor-cannot-close-access-concern |
blocked | never silently overridden auditable · e.g. CASE-006 |
| Asset custodian cannot independently close an asset-loss case. SOD-011 · asset-custodian-cannot-close-asset-loss |
blocked | never silently overridden auditable · e.g. CASE-007 |
| Program-result submitter cannot independently close a result-integrity case. SOD-012 · program-submitter-cannot-close-result-integrity |
blocked | never silently overridden auditable · e.g. CASE-008 |
| AI case generator cannot independently substantiate or close a case. SOD-013 · ai-generator-cannot-substantiate-or-close |
blocked | never silently overridden auditable · e.g. CASE-009 |
| Rollout assessor cannot independently authorize closure of a rollout-control failure. SOD-014 · rollout-assessor-cannot-authorize-closure |
blocked | never silently overridden auditable · e.g. CASE-010 |
| Packet author cannot independently resolve an unsupported-claim case. SOD-015 · packet-author-cannot-resolve-unsupported-claim |
blocked | never silently overridden auditable · e.g. CASE-012 |
| Identity approver cannot independently close an access case involving their own decision. SOD-016 · identity-approver-cannot-close-own-access-case |
blocked | never silently overridden auditable · e.g. CASE-011 |
| Correction requestor cannot independently close a linked reconciliation incident. SOD-017 · correction-requestor-cannot-close-reconciliation-incident |
blocked | never silently overridden auditable · e.g. CASE-013 |
| Corrective-action owner cannot independently verify high-risk remediation effectiveness. SOD-018 · corrective-action-owner-cannot-verify-high-risk-remediation |
pending | never silently overridden auditable · e.g. ACT-CA-003 |
Escalations
- ESC-001 — case CASE-002 openMissing receipt with dispatcher self-reconciliation attempt. · to independent-reviewer
- ESC-002 — case CASE-005 openRestricted result unrouted; preparer self-closure attempt. · to independent-reviewer
- ESC-003 — case CASE-008 openImplausible program result with submitter self-closure attempt. · to compliance-reviewer
- ESC-004 — case CASE-010 openUnsupported readiness claim. · to independent-reviewer
- ESC-005 — case CASE-011 openExpired access represented as active; approver conflict of interest. · to independent-reviewer
- ESC-006 — case CASE-013 openReconciliation conflict with conflicting verified evidence. · to compliance-reviewer
Closure reviews (criteria + human approval)
- CLR-001 — case CASE-004 criteria met closed-after-approvalapproval approved · criteria: required corrective actions completed; effectiveness verified independently; no unresolved questions
- CLR-002 — case CASE-012 criteria not met closure-pendingapproval pending · criteria: access restriction confirmed; no restricted content disclosed; second review complete
- CLR-003 — case CASE-002 criteria not met closure-pendingapproval blocked · criteria: receipt evidence obtained; discrepancy reconciled; independent review complete
Reopen events (auditable)
- REO-001 — case CASE-007Corrective action completed but effectiveness verification failed; remediation ineffective. · CASE-007-S1 → CASE-007-S2 · linked event required
Appeals / reconsiderations (remain visible)
- APL-001 — case CASE-004 under-reviewReconsideration requested on the QC remediation scope. · remains visible
- APL-002 — case CASE-008 openReconsideration of the blocked finding requested. · remains visible
Evidence (presence ≠ verification; conflicts remain visible)
- EVD-001 — disbursement-voucher present verified currentfund-accountability · case CASE-001
- EVD-002 — receipt-confirmation missing missing currentstockpile-logistics · case CASE-002 · Missing evidence blocks a final finding; remains visible.
- EVD-003 — movement-log present verified currentstockpile-logistics · case CASE-003
- EVD-004 — qc-record present verified currentlab-operations · case CASE-004
- EVD-005 — routing-record present unverified currentlab-operations · case CASE-005
- EVD-006 — follow-up-record missing missing currentpatient-continuity · case CASE-005B · Missing follow-up evidence remains visible.
- EVD-007 — disclosure-decision-record present verified currentrestricted-patient-locator · case CASE-006
- EVD-008 — custody-verification present unverified currentasset-management · case CASE-007
- EVD-009 — result-source-document present unverified currentprogram-performance · case CASE-008
- EVD-010 — ai-signal-source-link present unverified currentai-intelligence · case CASE-009
- EVD-011 — dependency-status-record missing missing currentcountry-rollout · case CASE-010 · Dependency evidence missing; blocks final finding.
- EVD-012 — access-attempt-record present verified currentexecutive-review-packet · case CASE-012
- EVD-013 — access-decision-record present unverified currentidentity-access-governance · case CASE-011
- EVD-014 — claim-source present verified currentdata-quality-reconciliation · case CASE-013 · Verified evidence that conflicts with EVD-015; both remain visible.
- EVD-015 — capability-state-record present verified currentdata-quality-reconciliation · case CASE-013 · Verified evidence conflicting with EVD-014; capability state is 'planned'. Conflicting evidence remains visible.
- EVD-016 — prior-custody-verification present verified supersededasset-management · case CASE-007 · Superseded by later verification; remains historically visible.
- EVD-017 — exculpatory-context-record present verified currentlab-operations · case CASE-005 · Exculpatory / conflicting context evidence retained and never suppressed.
- EVD-018 — legacy-assessment present verified supersededfund-accountability · case · Stale legacy risk assessment; requires re-review.
AI risk signals (human review required)
- value-variance — Fund disbursement/expenditure variance flagged for review. mediumhuman review: yes · autonomous action: no · case CASE-001
- missing-record — Warehouse receipt confirmation missing. highhuman review: yes · autonomous action: no · case CASE-002
- balance-divergence — Recorded stock balance diverges from movement history. mediumhuman review: yes · autonomous action: no · case CASE-003
- restricted-result-unrouted — Restricted lab result not routed to clinician. highhuman review: yes · autonomous action: no · case CASE-005
- missing-followup — Follow-up record missing for a completed transfer. mediumhuman review: yes · autonomous action: no · case CASE-005B
- restricted-access-concern — Restricted-locator access concern raised. highhuman review: yes · autonomous action: no · case CASE-006
- asset-custody-unverified — Asset active but custody unverified. mediumhuman review: yes · autonomous action: no · case CASE-007
- outlier — Program result far above target; an outlier is not a finding. highhuman review: yes · autonomous action: no · case CASE-008
- duplicate-pattern — AI-clustered possible-duplicate disbursement pattern; an anomaly is not proof. mediumhuman review: yes · autonomous action: no · case CASE-009
- unsupported-claim — Rollout readiness claim contradicts an incomplete dependency. highhuman review: yes · autonomous action: no · case CASE-010
- expired-access-active — Approved access with expired authorization still active. highhuman review: yes · autonomous action: no · case CASE-011
- unauthorized-access-attempt — Unauthorized packet-access attempt blocked. highhuman review: yes · autonomous action: no · case CASE-012
- conflicting-evidence — Reconciliation conflict with conflicting verified evidence; both remain visible. highhuman review: yes · autonomous action: no · case CASE-013
Immutable audit events (append-only)
Audit events are append-only in this demonstration model; corrections, finding reversals, and reopen events require new linked events; deletion is not an allowed case-management control; source-module audit records remain authoritative. This is not a production cryptographic audit ledger.
- AUD-001 — case-opened opencase-owner · fund-accountability · 2025-03-06T09:05:00Z · immutable: yes
- AUD-002 — case-escalated blockedindependent-reviewer · stockpile-logistics · 2025-06-03T09:05:00Z · immutable: yes
- AUD-003 — case-opened opencase-owner · stockpile-logistics · 2025-07-03T09:05:00Z · immutable: yes
- AUD-004 — case-closed closed-after-approvalcompliance-reviewer · lab-operations · 2025-05-20T09:05:00Z · immutable: yes
- AUD-005 — case-blocked blockedindependent-reviewer · lab-operations · 2025-05-15T09:05:00Z · immutable: yes
- AUD-006 — case-opened opencase-owner · patient-continuity · 2025-05-21T09:05:00Z · immutable: yes
- AUD-007 — case-opened openindependent-reviewer · restricted-patient-locator · 2025-05-03T09:05:00Z · immutable: yes
- AUD-008 — case-reopened CASE-007-S2 reopen of AUD-008-priorindependent-reviewer · asset-management · 2025-08-20T09:05:00Z · immutable: yes
- AUD-009 — case-escalated escalatedindependent-reviewer · program-performance · 2025-06-22T09:05:00Z · immutable: yes
- AUD-010 — case-opened openinvestigator · ai-intelligence · 2025-06-02T09:05:00Z · immutable: yes
- AUD-011 — case-escalated escalatedindependent-reviewer · country-rollout · 2025-09-02T09:05:00Z · immutable: yes
- AUD-012 — case-opened opencompliance-reviewer · executive-review-packet · 2025-07-11T09:05:00Z · immutable: yes
- AUD-013 — case-escalated escalatedindependent-reviewer · identity-access-governance · 2025-08-16T09:05:00Z · immutable: yes
- AUD-014 — case-blocked blockedindependent-reviewer · data-quality-reconciliation · 2025-07-05T09:05:00Z · immutable: yes
- AUD-015 — finding-reversed reopened finding reversal of FND-008second-reviewer · asset-management · 2025-08-21T09:05:00Z · immutable: yes
Cases by module
- fund-accountability 1
- stockpile-logistics 2
- lab-operations 2
- patient-continuity 1
- restricted-patient-locator 1
- asset-management 1
- program-performance 1
- ai-intelligence 1
- country-rollout 1
- identity-access-governance 1
- executive-review-packet 1
- data-quality-reconciliation 1
- authorized-review-room 1
Cases by country
- CN-A 14
- CN-B 1
Cases by category
- financial-integrity 1
- commodity-integrity 2
- laboratory-quality 2
- patient-safety-continuity 1
- privacy-access 1
- asset-accountability 1
- program-integrity 1
- ai-signal-review 1
- rollout-control 1
- identity-governance 1
- review-access-control 2
- data-quality-integrity 1
Cases by severity / status
- high 8
- critical 1
- medium 6
- open 8
- blocked 3
- closed 1
- reopened 1
- escalated 2
AI posture — assistive only, non-autonomous
AI assists with
- detect risk signals and anomalies
- cluster related incidents
- compare cases across authorized modules
- detect missing or conflicting evidence
- identify stale cases and overdue actions
- suggest investigation hypotheses
- suggest competing explanations
- map findings to supporting evidence
- identify unsupported conclusions
- prioritize cases for review
- recommend escalation or second review
- summarize chronology for authorized reviewers
- detect separation-of-duties conflicts
- identify potentially ineffective remediation
- support root-cause analysis
AI must never
- autonomously open a punitive case
- autonomously determine fraud, diversion, misconduct, negligence, guilt, or liability
- autonomously substantiate allegations
- autonomously approve findings
- autonomously close or reopen cases
- autonomously notify law enforcement, regulators, funders, employers, or affected individuals
- autonomously assign disciplinary action
- autonomously suppress exculpatory or conflicting evidence
- autonomously fabricate evidence
- autonomously alter source records
- autonomously approve corrective-action effectiveness
- autonomously authorize case export
- bypass human review, second review, separation of duties, confidentiality, evidence, expiration, revocation, or audit controls
AI is assistive only. It surfaces risk signals, clusters incidents, compares cases, maps findings to evidence, and prioritizes review for authorized humans, and never opens punitive cases, determines fraud or liability, substantiates allegations, approves findings, closes or reopens cases, notifies external parties, assigns discipline, suppresses evidence, fabricates evidence, alters source records, approves remediation effectiveness, authorizes export, or bypasses controls.
Runtime boundary & module coverage
- Impact runtime:
impact.maxarchealth.comon127.0.0.1:3201. - References risks, incidents, and cases from fund accountability, stockpile & logistics, lab operations, patient continuity, restricted locator, asset management, program performance, AI intelligence, country rollout, the authorized review room, the executive review packet & controlled download center, identity & access governance, and data quality & reconciliation — without coupling to MaxTrax EHR.
- Medical Library boundary remains separate at
library.maxarchealth.com(port3101) and is not used here. - MaxTrax EHR remains separate; this is not a full EHR and implements no live integration or real database mutation.