Back to home
back to forum
Engineering

Designing an AI scribe that cannot act on its own

The guardrails in Medi, my ambient scribe prototype, and why they come first.

AIElectronArchitecture
POST #001

Medi is a prototype ambient scribe that sits next to eClinicalWorks. It is not production software and it is not presented as compliant. The design question I cared about most was how to make sure the model never acts on its own.

A gate, not a suggestion

Nothing leaves draft until a person approves it. The check lives in the runtime, so a UI bug cannot skip it.

Show your sources

Every drafted line links back to the transcript spans it came from. Reviewers check evidence instead of trusting the model.

Keep less data

Audio stays on the device and is purged after 12 hours. The drafting server is stateless, so it has nothing to leak later.

Write the decisions down

The project has 38 passing tests and architecture decision records. When I change a guardrail, the reason is written next to it.

Thread locked · this board is currently read-only.