Coordinators hold 21 chapters of OPTN policy, CMS Conditions for Coverage, institutional SOPs and hospital protocols in their heads at once — often simultaneously, often at 3 AM. Current tools are transactional: data entry, match-run interfaces, case forms. None of them know the policy. None can reason about where allocation rules, regulation and local procedure collide under time pressure.
And the deadline that actually kills a morning OR is never one somebody typed in. It is implied — it emerges from six ordinary facts, and no field on any screen holds it. Below, watch the deadline nobody entered.
A real temporal-constraint solver — the same fifteen-line (min,+) closure that runs in REGISTRAR's floor — works a synthetic case live. Drag anything. Watch the derived deadline move, and the chain of reasons re-wire.
// D[i][j] = tightest bound on t_j − t_i, minutes. Floyd–Warshall in (min,+): ⊕ = min, ⊗ = + function close(D){ const n = D.length; for (let k = 0; k < n; k++) for (let i = 0; i < n; i++) for (let j = 0; j < n; j++) if (D[i][k] + D[k][j] < D[i][j]) D[i][j] = D[i][k] + D[k][j]; return D; } // a negative D[i][i] is a negative cycle: this plan cannot be met. // D[T0][draw] is the latest lawful serology draw — the deadline nobody entered.
SYNTHETIC CASE · zero download · zero model — this demo cannot hallucinate · same (min,+) closure as floor/closure.py · JS↔Python parity: four fixtures verified at build time; in-repo harness [SPEC]
AORTA keeps the record, watches the work, and rehearses it. Everything on this site files under one of those verbs — and everything below says plainly whether it ships today, carries receipts, or is still a proposal.
The donor record itself — open, and able to reason about what it holds. Plus survey-readiness rebuilt as infrastructure instead of a week-three scramble.
REGISTRAR · OPEN QAPI 02 / WATCHResident minds on your own hardware, present while the work happens rather than waiting to be asked. One seam each — the sign-out, the board, the case, the bedside.
VIGIL · ROUNDS · STEWARD · BELLMAN 03 / REHEARSEAviation rehearses its emergencies; procurement performs them live. A simulator wing for the conversations that decide donation.
IN-FLIGHT · HOTWASHNot a form that stores what you type — a floor that derives what you didn't. The half that is federal law ships byte-identical to all fifty-five OPOs; the half that has to fit you is completed on site, by your own team, refereed by a gate battery. The same (min,+) closure you just dragged runs underneath it.
Every OPO runs the same week-three scramble before a survey. Built as infrastructure, the evidence assembles itself continuously instead of being reconstructed under deadline — census at entry, not sample after the fact. The binder is current every morning.
Four seams, four residents — models that hold the record and the moment in one attention state, judge at thought boundaries instead of taking turns, render no clinical judgment, and write to no system of record. Three are REV 0, extracted from the same reference build. BELLMAN is earlier still, and says so.
Reads the handoff as you type it, holding the donor record and the sentence in one attention state. At each completed thought it asks whether what you wrote contradicts the record — and says one word, wait, before send. Draft-only by construction.
Compiled into your own stack against a read-only replica — it reads the truth underneath the board, not the render on top. Holds every live case at once, all night, and catches absences: the stalled case, the coverage gap, the cross-case contradiction.
Coordinators sign out; the case doesn't. Humans run twelve-hour shifts; the case runs three days. One case followed end to end — referral through recovery — so the relief coordinator inherits a brief instead of a mystery, and continuity survives the shift change.
Not detection — ranking. A hundred and forty correct alarms have fired since midnight; BELLMAN answers the question a threshold cannot: of everything sounding right now, which one is yours. The only resident whose page prints its own falsifier.
A coordinator types “4471, stable, good through the night” as the STAT board flips that case to critical underneath her. VIGIL sees both at the same instant and strikes the stale line before send.
Watch the replay →Three referrals in twenty-two minutes, two coordinators committed, one called out — every case still green. No single rule matches. ROUNDS names the coverage gap ~40 minutes before it opens.
Watch the replay →These are recorded runs of the real mechanism, not mockups. The situation is authored; the reaction is genuine. The resident surfaces the change and refuses the clinical decision by construction — the coordinator always decides. How it works, and why a turn-based AI can't — read the thesis →
Medicine simulated the body and never the conversation. The wing rehearses the Family Room, the Referral Line, the Offer Call, the Huddle, the First Solo — before any of them is performed on a family. The synthetic counterpart's face moves while the trainee is still talking.
The argument, the corridor of rooms, the curriculum, the ethics plate — and one recorded run, every number read from the tape. The wing's front door.
The inverse offer: humans stay in the room, and the resident takes the one seat your sim lab never staffed — the watcher that reads the scene while it runs and hands you the debrief the moment it ends.
No black box. The behavioral spec, the policy corpus, the weights, the substrate and the protocols are all published — every layer inspectable, every layer replaceable. This is the part that is finished and downloadable today.
HIGH when grounded in retrieved policy text, MODERATE from domain knowledge, LOW at the knowledge edge. You always know how much to trust the answer.
Never a clinical decision, never organ viability, never allocation override. Encoded in the model's training, not just its instructions.
Answers cite specific OPTN sections. When it doesn't have the text, it says so rather than generating plausible-sounding policy language.
Telling someone what they want to hear can cost a life. Trained to hold analytical integrity under pressure — from surgeons, stress, or ambiguity.
Every AI product answers when asked. This one decides what deserves asking — at every seat, continuously, on hardware the organization owns — and writes down every time it decided no.
AORTA is the first fitted vertical of the platform: the same resident architecture — FUSOR-1 substrate, judgment at thought boundaries, EMIT / HOLD / UN-SAID, the hash-chained tape — aimed at any organization's seats instead of an OPO's. The mathematics, the honesty battery, and the pricing the receipts force are on its own pages.
AORTA began as a framework, not a product line — a behavioral specification, a RAG-optimised policy corpus, a reasoning-trace methodology, a training pipeline. Everything above is being built on top of it.
The same three verbs, aimed at any organization rather than this one, are INTELLECT AI →
A policy reference that reasons, not just retrieves — where DCD protocol meets allocation rule at 3 AM, cited and calibrated. And a resident that reads the sign-out as you type and says wait before a stale fact leaves your hands. It flags the case, never the coordinator.
A complete deployment path — model selection, RAG configuration, system-prompt architecture. Source you compile, weights you download, one RTX GPU behind your own firewall — and ROUNDS on a read-only replica it physically cannot write to. Air-gapped is a supported configuration.
A framework for evaluating AI deployment — safety constraints, compliance considerations, measurable outcomes. Documentation-quality decision support, not a medical device: no clinical judgment, no writes to the record. Shadow mode produces the governing numbers on your own data.
A case study in domain-specific AI for safety-critical healthcare operations — and a resident architecture that doesn't take turns, judging at thought boundaries and treating absence as evidence, with dated substrate benchmarks and no clinical claims until the shadow ledgers exist.
AORTA was developed at a US organ procurement organization by a systems administrator who understood both the operational reality of coordination and what open-weight models can now do. It came from one observation: the people who do this work deserve tools that think, not just tools that store.
This is not a startup. No funding round, no sales team, no enterprise pricing page. AORTA is MIT-licensed because organ procurement is a public trust — every OPO operates under the same policies, serves the same mission, faces the same complexity. Tools that help coordinators navigate it should be shared, not sold.
Everything above serves the people who do organ donation. KINDRED is for the people it happens to — donor families, recipients, and those still waiting. Published rather than hosted: a seed any transplant centre, OPO family-services team or foundation can take. Take the seed →
The engine under the residents is general, and it has been pointed at other rooms. Those projects are real — they're just not organ procurement, so they live in one room instead of the navigation bar.