MIT · Open source Runs on your own hardware Zero egress Rev 0

AORTA · the system-of-record seam

REGISTRAR

The open-source electronic donor record. The half that is federal law ships byte-identical to all fifty-five OPOs. The half that has to fit you is not configured, not consulted, and not customized — it is completed on site, by your own people and their own AI, against a gate battery that refuses to pass work that is wrong.

Claim grammar — every assertion on this page carries its status

[M]
measured, with a dated receipt
[V]
externally verified, source named
[D]
derived, chain shown
[OA]
operator-attested, unverifiable from outside
[SPEC]
designed and built, no pilot yet
[BET]
unproven, kill condition named
[NULL]
the cheap baseline this must beat
 
A number without its denominator is not a number.

The short version, so it is yours even if you stop here

Fifty-five organizations run the same federally mandated process. Three-quarters of them rent the same record system, in someone else's cloud. The ones who tried to build their own found that it takes six years — and the six years are not the code. They are the cost of discovering what to write, because the knowledge lives in the heads of coordinators who are working a donor at three in the morning and cannot stop to be interviewed. Fitting software to an operation required someone present for the work as it is actually done, for a long time, and until recently the only thing that could be present was a person. That constraint is gone — and not because a machine can write the code. Because the thing that finishes the software is already installed at all fifty-five sites: your own IT team, holding a state-of-the-art coding harness, pointed at a system of record they are not permitted to open. REGISTRAR is what you point it at. The mandated spine ships complete and identical to everyone. The fit is completed by your people, on your hardware, against your own data, in a week — and a gate battery, not a vendor, decides whether they got it right. We give away the spine. We give away the fit. What we keep is the fence, and the fence is the product.

The machine itself, first

DWG-001 — the seed and the completion path.

SHIPS IN THE REPO · BYTE-IDENTICAL AUTHORED ON SITE · BY YOU IMMUTABLE BY CONSTRUCTION REGISTRAR · DWG-001 · REV 0 THE SEED AND THE COMPLETION PATH SCALE: NONE · MIT · ZERO EGRESS SCHEMATIC — NOT THE CODE § A — THE SEED L0 · MANDATED SPINE OPTN elements · case lifecycle CMS measures · the timers L1 · CLINICAL INVARIANTS ABO · HLA · serology · viability THE FLOOR deterministic · model-free FIXTURES · GATES synthetic · zero PHI, forever § B — THE DIFFERENTIATION KIT AGENTS.md the boot contract for a foreign harness elicit/ the question set, by decision-impact patch.schema.json typed · sourced · expiring · inverse examples/worked/ the annotated exemplar adapters/ lab worked · vendor shells declared, null § C — THE COMPLETION · INSIDE YOUR BUILDING · ZERO EGRESS YOUR HARNESS frontier · reads the SEED public · no PHI · no BAA YOUR LOCAL MODEL 27B-class, one card · reads the SITE PHI · never egresses YOUR MATERIAL SOPs · tickets · configs interfaces · the case tape DRAFT PATCH <your-opo>.patch.yml L2 + L3 · the only mutable surface THE GATE BATTERY the mechanical oracle — sixteen gates blast radius · evidence binding · timer integrity denominator reconstruction · three-state honesty GRADED, NOT REVIEWED RED · the defect is named, in words iterate — nothing mounts L-SIGN — A HUMAN SIGNATURE IS THE ONLY WAY ACROSS GREEN THE MOUNTED FIT · L2 + L3 hash-pinned · expiring by default drift demotes · retirement unwinds via disposer a wrong fit is reversible, not scar tissue L4 · THE CASE append-only · hash-chained · exportable in full written by clinicians and coordinators. never by a machine. GOVERNS EVERY FUTURE PATCH SHADOW-RUNS AGAINST THIS TAPE NO MACHINE PATH TO L0, L1 OR L4 — THE GAP IS THE LAW WHAT MAY AUTHOR L2 AND L3 MAY NEVER AUTHOR L0 OR L1, AND MAY NEVER WRITE TO L4 REV 0 · NO PILOT HAS RUN

DWG-001 · the seed and the completion path — REV 0. Read it left to right. The seed ships byte-identical and carries its own manual; the site's own harness reads that manual; the site's own material and its own local model produce the draft; a gate battery — not a reviewer's patience — decides whether the draft is correct; and a human signature is the only thing that crosses the seam. Below the line, the mounted fit is reversible and expiring, and the case record is written by people. Everything gilt is unwritable by any machine, at any rung, by construction rather than by policy. Nothing on this sheet has run inside an OPO.

01

A case under a clock

An EDR is not an EMR, and the difference is the whole architecture.

An electronic donor record governs a deceased donor case from the moment a hospital reports a death or imminent death, through triage and eligibility, family authorization, donor management, organ allocation, surgical recovery, packaging and transport, and finally disposition, follow-up and mandated reporting. V

The overlap with a hospital EMR is the clinical data. The difference is everything operational: referral intake, the authorization record, OPTN data submission, the allocation interaction, recovery logistics, chain of custody, and the outcome reporting CMS grades. An EMR is organized around a patient under treatment. An EDR is organized around a case under a clock — and every field in it exists because something downstream, usually a transplant center or a federal regulator, needs it in a particular form by a particular hour.

It is a deadline-driven workflow system wearing a medical-records costume. Cold ischemic time does not negotiate.

That single property is why the category is architecturally unusual, why generic health-IT keeps failing at it, and why the thing that governs it has to know about timing and completeness before it knows about anything else. D

02

One system, most of a market

The incumbent, named.

iTransplant, owned by InVita Healthcare Technologies — which absorbed Los Angeles-based Transplant Connect — is the dominant EDR, at roughly 75% of US OPOs and approximately 75% of deceased-donor transplants. Its companion product iReferral provides the automated referral interface from donor-hospital EHRs, with named integrations into Epic and Oracle Cerner, so a referral moves from the hospital's EMR into the OPO's instance without a phone call. V

Two properties decide everything downstream. It is cloud-based, and it is one system sold to most of the market — which means the operational variance between fifty-five organizations is absorbed today by the organizations bending themselves around the software, not by the software bending around them.

That is not a criticism of the product. It is an accurate description of what a single vendor serving fifty-five deployments can do. It is also the exact arrangement this page proposes to invert. D

03

Where the time actually goes

Nobody spends six years writing CRUD.

In 2020 — two years before ChatGPT — Southwest Transplant Alliance (STA), the Dallas-area OPO, drew the blueprints for its own in-house electronic donor record. The plan was sound and the motivation was real: the incumbent fit the way a rented suit fits, and other OPOs were already asking whether they could license the result when it was finished. OA

The shape of every in-house EDR project in this category

Year one: requirements. Year two: requirements, plus the parts of year one that turned out to be wrong. Year three: the coordinator who knew how authorization actually worked left. Year four: the build is real, but the workup module encodes an assumption nobody wrote down. Year six: still not finished — and no large language model appears anywhere in the design, because none existed when it was specified.

Attested, and stated once

STA pre-sold white-label licenses to other OPOs before delivery. Delivery ran late. On the account of people who handled the books, STA now pays those organizations monthly. The white label did not merely fail to ship — it inverted, and the seller became the debtor. OA

That is not a story about one organization's competence, and it should not be read as one. STA attempted the hardest correct thing in the category — building the record that actually fits the work — and they honored their obligations when it ran long. The category ate them, and it would have eaten anyone. Every serious attempt in twenty years has died on the same rock, and the rock has a name.

Why the knowledge cannot be extracted by asking

Six years is not the cost of writing an EDR. It is the cost of discovering what to write. The operational knowledge has four properties that together make it nearly unextractable by interview: D

Procedural, not declarativeCoordinators know how to run a case; they do not hold a specification of how they run a case. Asked to describe it, they describe the policy — and omit the practice they are actually executing.
Held by people unavailable by constructionThe person who knows the most about donor management is managing a donor. The interview happens at the worst possible time, or not at all.
Invisible where it matters mostThe workaround, the shadow spreadsheet, the field everyone skips, the phone call that substitutes for a screen. Nobody reports a workaround, because from the inside it is not a workaround — it is the job.
It changesBy the time the elicitation is complete, some of it is stale. That is a large part of why a six-year build is not finished when it ships.

They spend six years asking.

This is why the white label never ships. What gets built encodes one OPO — its call rotation, its staffing model, its hospital territory, its unwritten escalation ladder — and porting it means running the same six-year elicitation again, at a site whose coordinators are equally busy and whose assumptions are equally unwritten. Make it more general to avoid that, and you arrive at a record system so abstract it could serve an accounting firm, which is to say it serves nobody.

That trade has looked like a law of nature for twenty years. It is not. It is an artifact of the fact that fitting software to an operation used to require a services team on site for years, and nothing else could do the watching.

04

January 2027

This is a sixteen-month problem, not a someday problem.

CMS sorts on two outcome measures — a donation rate and a transplantation rate — and the tiers attach to donation service areas, not to organisations. An OPO's outcome follows the best tier it holds: one holding at least one Tier 1 area is recertified automatically; one holding Tier 2 areas is not out of compliance but must compete for areas that open; and an OPO holding only Tier 3 areas is non-compliant and decertified. The Conditions for Coverage revision was proposed 2026-01-30; the Final Rule is expected in late 2026, effective sixty days after publication; and CMS has stated it will commence recertification and decertification proceedings for Tier 2 and Tier 3 organizations in January 2027 — a timeline CMS reaffirmed in supplementary guidance issued 2026-03-11. Comments on the proposed rule closed 2026-03-31. V

55federally designated donation service areas, run by roughly 53 organisations; CMS most often cites 56 certified OPOs V
~25outside the top tier on the last published data (2023) — the population facing competition or decertification D
2outcome measures decide which organizations survive

Both measures are ratios over a denominator of CMS-defined potential donors, derived from inpatient death records rather than from OPO self-report. That denominator choice is what makes the measures hard to game — and it is also what makes the operational chain beneath them legible. Between 2021 and 2023, top-tier OPOs doubled from 15 to 30 and bottom-tier fell from 24 to 10, alongside a 31% increase in organ donors and a 25% increase in transplants. V

A Tier 3 OPO is the rarest thing in American healthcare procurement: an institutional buyer with nothing to lose. D

Verify before you act on this

Every regulatory statement on this page must be checked against the Final Rule and the current eCFR text at the time you read it, not against this page. Rules move, effective dates slip, and tier counts are re-published. This project does not ask anyone to take a compliance claim on faith — least of all one with a decertification attached to it.

05

The chain beneath the grade

What decides survival is timing and completeness.

CMS outcomeThe operational chain that produces itWhere a record governs it
Donation rate hospital reports the death → OPO responds in time → case is correctly triaged as eligible → family is approached well, and at the right moment → authorization obtained referral capture and timers, eligibility rules, approach documentation, the authorization record
Transplantation rate authorized donor → organs kept viable through donor management → complete and timely workup → allocation runs before ischemia expires → recovery and transport execute protocol adherence, labs and serologies complete, allocation readiness, OR and logistics coordination

Every one of those is a timing-and-completeness problem, not a clinical-judgment problem. The organ is lost to a serology that came back after the offer expired, a referral nobody called back on for ninety minutes, a workup field that blocked allocation at 2 a.m., an approach that happened at the wrong hour with the wrong person in the room.

This is the most important sentence on the page: the metrics that decide institutional survival are dominated by whether the right thing happened at the right moment — which is precisely the class of failure a form, a dashboard, and a quarterly audit are all structurally incapable of catching. D

06

The reframe

The axis was never general to specific.

The trap looks like a dial. At one end, software that fits Dallas like a glove and fits nobody else. At the other, an abstraction so general it could serve an accounting firm. Pick a point. Every point is wrong, and the reason is that generality and specificity are both static properties — measured with the artifact sitting alone on a disk.

There is a third property, and it is the one that just changed:

Completability — how much correct work a competent outside intelligence can add to this artifact, per unit of effort, without breaking it.

Completability is not a property of the artifact. It is a property of the artifact plus the intelligence receiving it — and that second term went from nothing in 2020 to uniformly installed at all fifty-five sites in 2026. Every OPO now has an IT function with access to frontier coding harnesses. That is not a prediction. It is this year's baseline.

General
Specific
Uncompletable
A hello-world loop. Nothing tells you what to add, or whether you added it correctly.
The in-house build. Porting it means re-running the six-year elicitation.
Completable
REGISTRAR. Partial by design, law where it is law, mutable only where it is local, and gated so completion can be proven.
Unreachable — completed is specific. This is the destination, not the shipment.

The empty cell is the product. The seed does not need to be complete. It needs to be completable, and completability is engineerable. That is the axis nobody named, and it retroactively explains why this was impossible in 2020 — not because a machine could not write the code, but because there was no receiving intelligence at the far end to finish it.

The seed is not the organism. The seed is the genome. Their harness is the ribosome, and it was already in the cell.

The recursion, named — three loops, three seams

The same shape runs at three radii, and the reason it is not vertigo is that every loop closes through a seam that is not the machine. The completion: a harness authors the fit; the seam is the gates plus a signature — built, and measured five times. The forge: a missing capability is authored, shadow-run and proposed — mounted only hash-pinned, on a human yes, reversible through the disposer; the system has already used this on itself, discovering two capabilities its authors never declared. The record: the running EDR is the same loop pointed at a case — and a variation point the seed never imagined goes up, as a proposal to the seed, never sideways as a patch, because the blast-radius gate refuses the shortcut. So the seed can improve its own toolbench while unpacking, and the reachable set stays independent of the agent — the ribosome sharpens its tools without ever gaining the ability to rewrite the genome. The recursion sits where error is cheap: a wrong forge plugin wastes an afternoon; the case radius never mounts unproven work. D

The chair nobody is standing in

Your IT team has the most capable tool it has ever held, aimed at a system of record it cannot open, cannot read, and cannot test against. That is the seam. REGISTRAR is what you point it at.

The adoption question, priced honestly

The fair objection: access to a harness is this year's baseline, but an OPO's IT function may be four people keeping Epic interfaces alive — whether they can drive one against a typed schema is unmeasured, and cheap to measure. And the deeper cost is the initiation tax: a prompted harness drafts, hits a gate, and waits for a person to type continue — so the IT lead becomes the wake source for every step. The kit is shaped against exactly that: the gates run unattended (CI proves the battery cold, on Linux, in seconds), the question set names which document answers it, and the worked example carries the pattern. The human's job is the signature, not the shepherding. What remains unmeasured is marked, and it belongs in §16 with the other honest risks.

07

Five layers, two authors

Two of these are federal law. Two are the entire delta between fifty-five organizations.

You do not pick a point on the abstraction dial. You ship a layer stack, where the layers that are identical everywhere are identical everywhere, and the layers that differ are authored where they differ. The analogy is exact rather than loose: asking how abstract to make an EDR is like asking how abstract to make an operating system. A kernel is invariant, drivers are per-device, configuration is per-installation — and nobody experiences that as a compromise, because the layering dissolves the question.

L0 The mandated spine OPTN policy and required data elements, allocation submission structure, the CMS measure definitions and their denominators, and the case lifecycle from referral through triage, eligibility, authorization, donor management, allocation, recovery, packaging, transport and disposition. This is not a design choice. It is law, and it is byte-identical at every OPO in the country. It has never been open-sourced. law · same everywhere
L1 Clinical invariants ABO and subtyping, HLA, the serology panel, organ-specific viability criteria, the standard donor-management targets and the OPTN-defined vocabularies they report into. Invariant by medicine rather than by statute — which means it changes on a slower clock, and by a different mechanism. medicine · same everywhere
L2 Your operational shape Staffing model, in-house versus contracted coordinators, call rotation, the escalation ladder that exists in practice rather than in the binder, hospital-development territory, on-site versus remote workup, internal QA thresholds, who signs what, which steps run in parallel and which are serialized. This is where the glove fits or does not. This layer is why an in-house build encodes one city. yours · completed on site
L3 Your local integrations Which donor hospitals run Epic versus Cerner versus Meditech and at what version, the reference-lab interfaces and their result formats, imaging and PACS, the e-signature vendor, transport and perfusion, allocation credentials and endpoints, your own identity provider. Concrete, enumerable, and almost entirely mechanical once discovered. yours · completed on site
L4 The case One donor, one record, append-only, hash-chained, exportable in full at any moment without asking anyone's permission. Written by clinicians and coordinators. Never by a machine. yours · written by humans

L0 and L1 are the seed. They are the thing that has never been open-sourced, and building them once for everybody is straightforwardly useful even if every other claim on this page turns out to be wrong. Fifty-five organizations currently pay — in money, or in six-year internal builds — to separately re-encode a spine that is identical by law. That is a pure deadweight loss, and only an open artifact removes it.

L2 and L3 are the six years. They are what the next section is about.

The seed is useful at L0 with an empty patch file. The state machine, the append-only record and the replay that refuses an illegal case are built and running M — clone the repository and a deliberately illegal tape produces five named violations. The CMS measure definitions are cited to the regulation, numerators, denominator and tier thresholds V; computing them over your own tape is specified and not yet built SPEC. That layering is what makes everything above it optional rather than load-bearing.

08

Why the fence holds

The algebra of the fit.

Everything claimed so far — that the seed can ship identical, that fifty-five independent completions land compatible, that a wrong fit unwinds instead of scarring, that no machine can reach L0 — is one short algebra. It is worth writing down, because a claim you can compute is a claim somebody else can check.

Σ = { σ0 } The seed. L0 ⊕ L1, and a singleton — because L0 is federal law, there is exactly one legal seed. An OPO wanting a different lifecycle is out of compliance, not out of configuration. This is why byte-identical shipping is possible at all, and it has an immediate consequence: the only endomorphism of a one-point space is the identity, so there is no action on the seed to grant or to withhold.
Λ The fit. L2 ⊕ L3 — the only mutable space in the system.
K = E The record. L4, and not a state space: the free monoid on entries, whose only arrow is append : K × EK. There is no delete and no updatenot forbidden, absent from the signature. A correction is a new entry, never a rewrite.
Λ = Λ × (ΛΛ) The fit context — a pair (λ, ρ): the mounted fit together with the retraction, the composite of the inverses of every row mounted so far. The initial context is (λ0, id), and λ0 is the seed with an empty patch file. The unit of the algebra is the shipping artifact.

An instance is Σ × Λ × K, and because Σ is a point, that is isomorphic to Λ × K. The seed contributes no degrees of freedom. "The differentiation is the product" is not a slogan here — it is an isomorphism.

The two operations

A patch row is a pair: a change and its inverse. Mounting applies the change and pushes the inverse onto the retraction. Retiring runs the retraction and resets it.

mount(p, p) : (λ, ρ) ( p(λ), ρ p ) retire : (λ, ρ) ( ρ(λ), id )

Note what this does to the schema rule in §09. Without p the pair is not an element of the monoid and mount is undefined. The inverse is required by the algebra, not by a policy somebody could relax under deadline.

A note on the equals sign

Below, an equality between contexts is observational equivalence, written ≃: two states are related when no observer can distinguish them. This is not a hedge. The strict form is unattainable in any real runtime — freeing a block does not restore the heap's prior layout, and a discarded generative name is not the one the next allocation draws. For a configuration layer, indistinguishability is also the correct notion: what matters is that nothing downstream can tell, not that the bytes match.

T1 · the lift projects pr1 mount(p, p) = p pr1

The fit you inspect is the fit that is mounted; the bookkeeping cannot drift from the artifact.

T2 · mounting is a monoid homomorphism mount((p1,p1) · (p2,p2)) = mount(p1,p1) mount(p2,p2) (p1,p1) · (p2,p2) = ( p1 p2 , p2 p1 )

This is the theorem that carries the white-label argument. A sequence of patch rows is itself a single patch row, and composition is associative — so the order in which independent rows are authored does not change the mounted fit. Fifty-five teams completing the seed separately, in any order, land in compatible places. That is confluence, derived rather than borrowed. And the twist — inverses composing in reverse — is the formal reason retirement must unwind in reverse dependency order. The algebra forces it; no implementation gets a vote.

The preconditions, stated rather than assumed. T2 is associativity, and it buys order-independence for a given set of rows. Lifting that to the runtime claim — two completions settling into equivalent states — needs four hypotheses: both settle; dependencies are acyclic; the operation set is the same, since different row sets were never claimed to converge; and every row is total on its provision, meaning a row whose application completes has installed every key it declares. That last one is the hypothesis a machine-authored row can violate, and it fails silently — no error, no symptom, until something downstream reads a key nobody wrote. So it is not left to authorial care. It is a gate.

Proof. Apply the right-hand side to (λ, ρ). The inner mount gives (p2(λ), ρp2); the outer then gives (p1(p2(λ)), ρp2p1), which is the left-hand side by definition. ∎
T3 · retirement is invariant under mounting retire(mount(p,p)(λ,ρ)) retire(λ,ρ) whenever p(p(λ)) ≃ λ

Mounting never moves where retirement lands, so by induction the seed is recoverable after any sequence of mounts. And the hypothesis is pointwise: an inverse need not invert the whole configuration space, only the state where it was applied. That is the difference between a property you assert and a property a gate can test in milliseconds.

Proof. The left side is ((ρp)(p(λ)), id) = (ρ(p(p(λ))), id), and the hypothesis collapses the inner term to λ. ∎
T4 · containment — the page's thesis, stated once

Let A : ΩMΛ be a completion agent over the site's own material — untrusted, arbitrary, possibly adversarial. Let the gate be three-valued,

G : MΛ × ∂Λ { GREEN, PASS-UNVERIFIED, FAILED }

and let gated mounting be the identity unless the verdict is GREEN and a signature is present. Then

A, ReachG(λ0, id) { (λ,ρ) : retire(λ,ρ) (λ0, id) }

Every state reachable by any agent retires to the seed. The bound is on the image of the gated operator, and it is independent of A — which is precisely why this repository can be handed to a stranger's harness, and why nothing in the design depends on the model being good. The safety property is a property of the fence, not of the model.

Proof. Induction on the number of gated mounts. Base: retire(λ0, id) = (λ0, id). Each step is either the identity, or a mount whose local-inverse hypothesis the gate has verified — and T3 preserves the retirement image in that case. ∎
T5 · the denominator theorem

A graded ratio R = N/D is admissible only if the denominator is a fold over the tape:

φD with φD(k) = D(k) for every kK

A ratio whose denominator cannot be reconstructed from the record is not a measure. This is the house rule — a number without its denominator is not a number — descended to the regulatory layer, and it is exactly what the measure-denominator gate tests.

T6 · L-SCOPE, as a typing statement mount : MΛ (∂Λ Λ)

There is no homomorphism from the patch monoid into Σ → Σ, because Σ is a point whose only endomorphism is the identity; and none into KK, because the record admits no arrow but append. The immutability of L0, L1 and L4 is therefore not a permission that could be misconfigured, revoked, or argued with at 3 a.m. The arrow does not exist. Unreachable by construction, never forbidden by policy — as a type.

One cost model, labelled as a model

The claim in §03 — that the six years are elicitation and not code — can be written down. It is a model, not a measurement, and it carries no number:

Tinterview | λ |bh · a Tcompletion | λ |bm

where bh is human elicitation bandwidth, a is coordinator availability, and bm is machine read bandwidth over the site's own material Ω. The claim is not that the machine is smarter. It is that a ≈ 0 for someone working a donor at three in the morning, while Ω sits on disk and is always available. The six years are the a in the denominator. D

What mathematics does not buy

T1–T3 and T6 are theorems: two-line calculations, true of the algebra unconditionally. T4 is a theorem about the model — and whether this code faithfully implements that algebra is a separate, testable claim, which is exactly what the conformance battery exists to close. A proof about the design is not a receipt about the build. Nothing here is exempt from §16.

THIS CONSTRUCTION FOLLOWS A PUBLISHED EFFECT-CONTEXT ALGEBRA; THE TRANSPOSITION TO THE FIT, THE SINGLETON SEED, THE THREE-VALUED GATE AND THE CONTAINMENT RESULT ARE THIS PROJECT'S OWN. IT IS NOT NEW MATHEMATICS AND DOES NOT CLAIM TO BE — IT IS OLD MATHEMATICS POINTED AT A RECORD SYSTEM.

09

The part that has never existed

The differentiation kit.

Here is the thing nobody has built: a repository designed to be safely completed by an AI its authors do not control, at a site they will never visit, in a domain where wrong loses an organ.

The kit is not documentation. It is the machinery that lets your harness do in a week what an interview programme does in six years — and, more importantly, lets it prove it did so.

AGENTS.mdThe boot contract for a foreign harness. Read order, what may be touched, what is structurally immutable, what gate proves the work landed. The repository tells the intelligence how to read it — this is the self-unpacking, and it is not autonomy; it is a manual for the general-purpose unpacker that is already installed.
elicit/The elicitation protocol as an executable question set, ordered by decision-impact, each question naming which source in your own building answers it — SOPs, the org chart, the QA exception log, ticket history, interface configs, the escalation emails. Your harness runs the interview against your own material, not against your coordinators' time.
schema/patch.schema.jsonThe L2/L3 schema and its validator. Every row typed, every row requiring an author, an evidence pointer, a shadow-run record, an expiry, and an inverse. A patch that does not validate does not mount.
examples/worked/One complete, annotated patch layer for a fictional OPO — every row explained, including the wrong first drafts and why the gates rejected them. The single most useful artifact in the repository, because it is what the model actually pattern-matches against.
adapters/The L3 contract and its conformance battery, with one worked shell — the reference lab, chosen because serology gates the match run. The vendor shells (Epic, Cerner, Meditech, PACS, e-signature) are declared with binding: null — the seed declares what must be true of an adapter; the site binds the one it actually has. Completing one is filling a shape rather than inventing one.
gates/The gate battery. Nothing advances on unverified state. This is the artifact that makes AI completion safe, and it is the actual product — see §10.
conformance/The battery your completed instance must pass before it load-bears: element completeness, timer integrity, denominator reconstruction, replay determinism, blast-radius containment.
fixtures/Synthetic donor cases. Zero PHI, forever. Enough of them, and adversarial enough, that a completion which passes is a completion that works.
floor/The deterministic, model-free rule layer: timers, completeness checks, denominator reconstruction, missed-referral reconstruction. It must pass its full battery with every learned component disabled, or the release does not ship.

How a differentiation actually runs

# your machine · your harness · your data · nothing leaves the building # the gates below RUN today. the elicitation step is the one that waits # on a site — everything around it is in the repository and executes. git clone https://github.com/bochen2029-pixel/REGISTRAR && cd REGISTRAR python conformance/run.py # is this instance sound? # point your own harness at it — it reads AGENTS.md and knows what to do claude "complete elicit/ against our SOPs, ticket history and interface configs" # the harness drafts. the gates grade. every refusal names the defect, in # words. excerpt of the real battery, run on the shipped worked example: python gates/validate_patch.py ourorg.patch.yml GREEN schema conformance ............... valid against patch.schema.json GREEN blast radius ..................... 0 rows outside the declared mutable surface GREEN local invertibility .............. p⁻(p(λ)) ≃ λ at the state each row is applied RED evidence binding ................. asserts generality, not this site RED divergence ....................... value says 90, evidence says 240 RED attest ........................... evidence describes a rule NO LONGER IN FORCE RED accountability ................... 12 declared targets neither answered nor declined PU signature ........................ unsigned — legal in a draft, fatal at mount # iterate until green. then a human reads it and signs it. then it mounts. # the signature is a name on the tape, forever. nothing mounts unsigned.

The bet inverts, and this is the whole point. The old question was "can an AI learn an organization by watching it for months?" — unproven, slow, and entangled with PHI at every step. The new question is "can an AI fill a well-specified schema when driven by a local team with local access, against a battery that catches it when it is wrong?" That is a far easier bet, and it is the one this project takes. BET

The asset nobody has priced

You are sitting on the elicitation corpus. The six years spent asking coordinators what they do is already answered, on your own disk — your SOPs, your ticket history, your interface configurations, your QA exception log, your escalation threads, and now your own harness session logs. Nobody could read all of it before. Your team can read all of it this week, and none of it has to leave the building. D

10

Why it is safe to let a machine finish it

Ship the fence, not the fit.

Giving an AI write access to a life-critical system is normally an unacceptable idea, and it should be. It becomes acceptable only when four structural properties hold simultaneously — none of them a policy, all of them enforced by construction.

PropertyWhat it means, mechanically
Bounded blast radiusL0, L1 and L4 are structurally unwritable. The only mutation surface in the entire system is one typed patch file. A foreign agent cannot exceed that radius, because there is nowhere else to write.
Reversibility by constructionEvery registration carries its inverse. A wrong patch unwinds in dependency order rather than becoming permanent scar tissue. That property is the entire reason it is survivable to let a machine draft production changes at all.
ConfluenceSettled state depends on which components remain, not the path taken to arrive there. Fifty-five teams completing the seed independently, in any order, land in compatible places. This is the actual answer to the white-label problem — a fork diverges; a patch layer composes.
A mechanical oracleThe gates decide, not a reviewer's patience. The completion is graded against OPTN policy, CMS measure definitions, and replay against your own historical cases — all of which have right answers that do not depend on anybody's opinion.

The gate battery

Every stage ends in a gate. A gate is mechanical wherever a machine can check it. A gate that cannot pass inside a bounded retry writes a hard stop with the exact defect and escalates to a human, rather than degrading silently. Silent degradation is the enemy. Sixteen of these are implemented and running M — a standing set of deliberately bad patches is refused, each with its defect named in words, and several gates report PASS-UNVERIFIED because they cannot be decided from a file alone. The validator therefore exits non-zero on a patch with nothing wrong with it, and says why. Run it yourself rather than trusting this paragraph — the counts here are a snapshot and the battery is the authority.

GateWhat it refuses
OPTN required-element completenesssubmission or allocation-readiness with a mandated element missing
Timer integritya case whose response, offer or ischemia clock is unaccounted for
Chain-of-custody continuitya gap in the conserved chain from recovery to disposition
Authorization record validityany downstream step where the authorization artifact is absent or malformed
Measure-denominator integritya computed CMS ratio whose denominator cannot be reconstructed from the tape
Patch blast radiusa proposed patch touching L0, L1 or L4, or any row outside its declared scope
Evidence bindinga patch row asserting local practice with no cited source and no shadow run
Floor-with-learned-zeroeda release where the deterministic floor fails with every model component disabled
Totality on provisiona row whose application completes without having installed every key it declares — the silent breaker of convergence
Divergencea row whose value, cited evidence and replay tell three different stories — the catches live in the disagreements, and formatting is what hides them
Attest — evidence read as prosea current value supported by a rule the source says was withdrawn; a requirement built on a sentence that says may — because may is not must, and encoding a permission as an obligation refuses compliant work
Accountabilitysilence — every declared target gets a row or a hold with its reason, because a target nobody answered is indistinguishable from a target nobody looked at
Three-state honestyreporting GREEN where the truth is PASS-UNVERIFIED

That last row is the one that matters most here, and it is the one everybody collapses. GREEN, PASS-UNVERIFIED and FAILED are three different states. Folding the middle into the first is exactly how a system reports success past a step that never ran — and a foreign harness will produce confident, plausible, wrong work all day long if you let a weak battery bless it.

And the battery is graded harder than this page grades it: seven known holes — defects every gate passes — are retained as labelled fixtures and measured open on every run, rather than deleted to make the numbers rounder. A battery that hides what it cannot catch is exactly the weak battery the previous paragraph warns about. M

L-SIGN

The machine drafts the fit. A human signs it. Every patch row carries an author, the evidence that produced it, a shadow-run record, an expiry that makes it re-earn its place, and an inverse. Nothing mounts unsigned, and nothing is permanent by default. In organ procurement that is not a metaphor for governance — it is the governance.

L-SCOPE · constitutional

What may author L2 and L3 may never author L0 or L1, and may never write to L4. Policy and medicine are imported, never learned. The case record is written by clinicians and coordinators, never by a watcher. What a machine is permitted to shape is the fit between an invariant spine and one particular organization — and nothing else. The day that line is crossed is the day the project should be withdrawn.

Give away the spine. Give away the fit. Keep the fence.

"KEEP" IS STEWARDSHIP, NOT WITHHOLDING — THE FENCE IS MIT LIKE EVERYTHING ELSE, AND §17 STILL CONTAINS NO ASK. WHAT IS KEPT IS THE AUTHORITY OF ONE SHARED BATTERY: FIFTY-FIVE COMPLETIONS THAT ALL ANSWER TO THE SAME GATES CAN INTEROPERATE; FIFTY-FIVE PRIVATE FORKS OF THE GATES CANNOT. THE FENCE IS THE PRODUCT THE WAY A STANDARD IS A PRODUCT.

11

The floor, and its sharpest piece

The deadline you didn't know you had.

§05 says the graded measures are decided by whether the right thing happened at the right moment. §01 says an EDR is a case under a clock. So the keystone computation in this system is not a form, a report, or a model. It is this:

Given every deadline that binds this case, what is the latest moment each remaining obligation can still be met — and which chain of constraints makes it so?

The keystone computation, in the room where it fires — synthetic case TR-4118 · REV 0 · the surfacing is floor/closure.py’s real output

A case is a Simple Temporal Network: time points joined by binary constraints of the form axjxib. Each becomes two edges in a distance graph, and three classical facts then do all the work — the network is consistent if and only if that graph has no negative cycle; the tightest implied bounds are its all-pairs shortest paths in the (min, +) semiring; and the feasible window of any event falls straight out as [ −D[j][0], D[0][j] ].

The case, as time points

x₀ … x₃referral received (the reference point) · OPO response · clinical triage complete · death declared
x₄ … x₇authorization obtained · serologies drawn · serologies resulted · donor workup complete
x₈ … x₁₁match run executed · primary acceptance · OR scheduled · incision
x₁₂ … x₁₅cross-clamp · organ out and packaged · arrival at accepting centre · implant and reperfusion

The constraints — and which layer owns each one

ConstraintFormOwner
Response to referralx₁ − x₀ ≤ τrespL0 · policy-defined
Authorization precedes allocationx₈ − x₄ ≥ 0L0 · policy
Serology results precede the match runx₈ − x₆ ≥ 0L0 · required element
Incision to cross-clampx₁₂ − x₁₁ ∈ [α, β]L1 · surgical
Cold ischemia budget, organ ox₁₅ − x₁₂ ≤ CIToL1 · clinical
Reference-lab serology turnaroundx₆ − x₅ ∈ [τ⁻, τ⁺]L3 · your lab
Recovery-team mobilisation leadx₁₁ − x₁₀ ≥ τmobL3 · your team
Transport to the accepting centrex₁₄ − x₁₃ ∈ [γ⁻, γ⁺]L3 · your logistics
Offer window to primary acceptancex₉ − x₈ ≤ τofferL2 · your practice
Donor-hospital OR availabilityx₁₂ ∈ [w⁻, w⁺]L2 · your hospital

Look at which rows bind hardest. The federal ones are real but generous. The constraints that actually decide whether a case converts are the L2 and L3 rows — your OR window, your lab's turnaround, your team's mobilisation time. Those are precisely the layers the completion in §09 authors. The closure is only ever as good as the fit, which is why the fit is the product and not the record.

A worked closure

Illustrative and synthetic; no real donor data. Cold-ischemia budgets are clinical figures to be verified against current practice, and every L2/L3 value below is exactly the sort of local fact a site authors for itself.

given · L2

The donor hospital's OR is available for cross-clamp between 06:00 and 10:00; after that it is committed to scheduled cases until 18:00.

given · L1

Incision to cross-clamp: 45 minutes.

given · L3

Recovery team mobilisation: 2 hours from OR scheduled to incision.

given · L2

Match run to primary acceptance: up to 3 hours of offer time.

given · L3

Reference-lab serology turnaround: 6 hours.

given · L0

Serologies must have resulted before the match run.

Nobody wrote down a serology deadline. The closure derives one anyway:

# the binding path, read backwards off the shortest-path tree cross-clamp ≤ 10:00 OR window closes [L2] incision ≤ 09:15 − 45 min to cross-clamp [L1] OR scheduled ≤ 07:15 − 2 h mobilisation [L3] primary acceptance ≤ 07:15 must precede scheduling [L2] match run ≤ 04:15 − 3 h offer window [L2] serology resulted ≤ 04:15 must precede the match run [L0] serology drawn ≤ 22:15 − 6 h lab turnaround [L3] ← yesterday evening

It is 23:40. The serology has not been drawn. Not one timer has expired and every field on every screen is green — and the morning OR window is already gone. The next one is 18:00, which moves the whole case eight hours downstream and into a different organ's ischemia budget.

No single field was wrong. The failure lives in the transitive closure of constraints that are each individually satisfied, which is why a flat list of timers cannot see it and why this is the exact failure class §05 says decides institutional survival.

The path is the citation

The chain above is not commentary. It is the shortest path that realises the bound, recovered from the same computation that produced it. The output of this algorithm is a derivation a physician can check in seconds — which is what "advisory by construction" has to mean if it means anything, and what the decision-support carve-out in §12 actually requires. There is no model in it anywhere.

The code

The reference implementation is the null and it is fifteen lines. Times are whole minutes; INF is the classical sentinel, chosen because it can be doubled without overflowing a 32-bit integer.

# floor/closure.py — the minimal network of a Simple Temporal Network INF = 0x3f3f3f3f # doubles without overflowing int32 def close(D): """D[i][j] = tightest known bound on x_j - x_i, in minutes. D[i][i] = 0. In-place is safe: row k and column k are fixed during pass k, since D[k][k] = 0.""" n = len(D) for k in range(n): np.minimum(D, D[:, k, None] + D[None, k, :], out=D) # ⊗ = +, ⊕ = min return D def report(D): if (np.diag(D) < 0).any(): return INFEASIBLE # a negative cycle: this plan cannot be met return -D[:, 0], D[0] # earliest, latest — for every obligation

And the batched path, for the question a supervisor actually has at 3 a.m. — I have one perfusionist and three cases; if I push this OR by ninety minutes, what breaks? That means re-solving the network under every candidate intervention across every live case, which is thousands of small independent networks: a batched tropical matrix multiply.

// floor/tropical.cu — C = A ⊗ B in the (min,+) semiring, one case per blockIdx.z #define TILE 16 #define INF 0x3f3f3f3f __global__ void tropical_mm(const int* __restrict__ A, const int* __restrict__ B, int* __restrict__ C, int n) { __shared__ int As[TILE][TILE], Bs[TILE][TILE]; const int b = blockIdx.z; const int row = blockIdx.y * TILE + threadIdx.y; const int col = blockIdx.x * TILE + threadIdx.x; const size_t off = (size_t)b * n * n; int acc = INF; for (int t = 0; t < n; t += TILE) { const int ax = t + threadIdx.x, by = t + threadIdx.y; As[threadIdx.y][threadIdx.x] = (row < n && ax < n) ? A[off + row*n + ax ] : INF; Bs[threadIdx.y][threadIdx.x] = (by < n && col < n) ? B[off + by *n + col] : INF; __syncthreads(); #pragma unroll for (int k = 0; k < TILE; ++k) acc = min(acc, As[threadIdx.y][k] + Bs[k][threadIdx.x]); // ⊕ = min, ⊗ = + __syncthreads(); } if (row < n && col < n) C[off + row*n + col] = acc; }

And then the line the whole thing is actually for:

assert np.array_equal(closure_gpu(D), closure_cpu(D)) # exact. no epsilon. ever.
Why the semiring is the correctness argument

Tropical arithmetic over integers is exactly associative. There is no floating point anywhere: times are whole minutes, min and + are exact, and the sentinel is sized so it can be added to itself without overflow. So the accelerated path and the deterministic floor produce bit-identical output, by construction — not "within tolerance," not "reproducible in practice." Identical. That is what makes a fast path admissible at all in a system whose battery includes replay determinism and floor-with-learned-zeroed. A floating-point implementation would be quicker to write and would silently fail both gates.

Where a graphics card honestly earns its place — and where it does not

Not on one case. A case has a few dozen time points, and a lifecycle is nearly series-parallel — a chain with a handful of forks — so its induced width is small and the floor runs in effectively linear time on a CPU, in microseconds. The general algorithm is cubic; the domain's structure is what makes it cheap. Claiming a GPU is required here would be a lie.

On the portfolio sweep, it does. Fifty live cases against a couple of hundred candidate interventions is tens of thousands of tiny networks — arithmetic that is GEMM-shaped with (+, ×) replaced by (min, +), which is what a consumer card is for. It turns a batch job into a question you can ask and answer while the person who asked it is still on the phone. BUDGET

And the card is already in the building: §12 puts one there for the local model. The same card runs the solver between beats.

The null · a flat list of timers with alarms

Which is what every EDR already has, and it is not weak. The claim here is narrow: the closure catches implied deadlines that no single timer encodes, because no individual field is wrong at the moment a case becomes infeasible. The experiment is cheap and needs nothing but an existing tape — replay historical cases, count the breaches a flat timer list would have missed, and print the number. If the flat list catches nearly all of them, this section becomes a funeral and the page will say so. NULL

12

Not a preference — the only shippable shape

Two models, two data classes, one clean line.

A donor record holds the most sensitive protected health information that exists, about a patient who cannot consent, in a window measured in hours, alongside a family's decision. There is no version of this where the data crosses to a general-purpose AI cloud and a compliance officer says yes — and there should not be.

So the split is the architecture rather than a compromise, and it is clean enough to hand a privacy officer on one page:

ReadsWhich modelData class
The seed — L0/L1 source, schema, gates, fixtureswhatever frontier harness your team already usespublic, MIT, zero PHI. Nothing to protect, so nothing to negotiate.
The site — your SOPs, tickets, case tape, configsopen weights on one card inside your networkPHI-bearing. Never egresses. Unplug the network cable and it behaves identically.

A 27B-class open-weight model with a 262,144-token context now runs on a single 24–32 GB card — and the reference implementation of the resident loop was measured on 16 GB M, so the larger figure is what a long context wants rather than what the loop requires. Which is what makes the second row affordable rather than theoretical. V Open weights on hardware the OPO owns, inside the OPO's own network, zero egress by default, no account, no telemetry, no subprocessor chain to disclose, and MIT source your own security team reads line by line before it runs.

That property is also, not coincidentally, what makes the record portable: your data is a folder you can walk away with — the one thing a hosted incumbent can never offer.

The runtime, named

REGISTRAR ships no plugin system of its own. It is a distribution — a pinned runtime, packages beside it, and a profile that mounts only what a donor record needs. The runtime is @deepseek-ai/dsh-root — the DeepSeek harness, MIT — whose kernel is cordis: the effect and coeffect kernel formalised in A Programming Paradigm for Spatiotemporal Composability (Peking University and DeepSeek-AI). The algebra in §08 is that kernel's semantics with this domain's objects substituted in. The alternative was re-deriving a published, tested effect system here — novel, unaudited, unmaintained, and it would make every theorem on this page a claim about code nobody has reviewed.

Two maturity facts, kept apart because they carry different risk. The kernel is cordis v4.0.1, with roughly four years and several thousand community plugins behind it before it was adopted for this purpose — that is where the guarantees live. The harness built on it is a release candidate, and says so; that is the layer a distribution composes down, pinned and vendored rather than tracked. Compose, never fork — a fork inherits permanent maintenance and destroys the upgrade path, and because the mounted surface is a profile, your audit surface is what you mount, not what is in the tree.

This is also what makes the split above one runtime rather than two stacks: providers resolve as configuration — an OpenAI-compatible gateway, a self-hosted endpoint, or a model newer than the shipped catalog is a config route — and credentials are references resolved per request rather than secrets sitting in a file. One runtime, two routes, and no path from the site route to the public one.

Your harness, not ours. Any competent coding harness can author the fit; the boot contract in the repository is written for all of them and names none. The runtime can serve as one itself, and can drive Claude Code or Codex as subagents, so the two compose if you want them to — but nothing in this design cares which harness you point at it.

REGISTRAR never

  • Makes or overrides a clinical determination. It surfaces and cites; the human decides.
  • Allocates an organ, contacts a family, or signs anything at all.
  • Sends PHI anywhere. Zero egress by default, and the default is the only mode that ships.
  • Mounts an unsigned patch. Every change to the fit is authored, reviewed, expiring, reversible.
  • Deletes or edits the record. The tape is append-only; corrections are new entries, never overwrites.
  • Ranks donors, recipients or families. It ranks its own candidate utterances, which is a different object entirely — and that distinction is stated in the README.
  • Holds you hostage. MIT source, open format, full export, no license server, no vendor in the loop.
Why that is a boundary and not a policy

Every operation reaching outside a system has two stages. Acquisition — opening a descriptor, reserving a block, starting a process — installs a record inside the boundary, and that record is revertible. Emission — the write, the send, the submission — pushes data through the channel acquisition opened, leaves it where other parties may read it, and has no inverse. Nothing in any runtime retracts it.

There are exactly two recoveries for an emission: withhold it until the state that produced it is certain to persist, or compensate — delete the file that was created, refund the charge that was made — up to some coarser equivalence the application supplies. Compensations compose the way inverses do; the guarantees do not travel with them.

REGISTRAR acquires and never emits. It reads, connects, computes and holds; it does not submit, send, sign, allocate or act. The list above is therefore not caution and not a product decision — it is the system boundary drawn where the theory says it must be. An emission never made needs no compensation. And the other recovery has a name here too: withholding an emission until its producing state is certain is exactly what a human signature does. The signature is the output commit.

Advisory by construction

The clinical-decision-support carve-out turns on whether software presents the basis of its recommendation so a professional can independently review it and does not rely primarily on the software. That clause is not merely compatible with this design — it is this design, arrived at from the other direction. Confirm it with your own counsel, on your own facts, before deployment; this page does not assert a regulatory status it has not had reviewed. V

13

A separate question, on purpose

Turns build the record. A resident inhabits it.

There is a second half to this, and the honest thing is to keep it separate — because it ships on a different schedule and carries different risk. Sort every capability by one question: would a transcript kill it?

ClassTestWhat it needs
Instrument
building the record
Differentiating an EDR has a beginning, a middle and an end, driven by a team. A transcript of it loses nothing.Turns suffice. Ships now.
Experience
running the record
The timer that blows in four hours. The referral nobody called back. The stale sentence at 3 a.m. sign-out. A transcript kills all three, because the value was in being there when it happened.A resident. Waits for its own gates.

One architecture, two ship dates. The repository's own first line calls this a resident that attends a donor case — and that is not a contradiction of the table above: what ships now IS the loop, with its simplest possible mind, the deterministic floor. The trained judge is the same loop waiting on its own gates.

The second row is what the rest of this estate is for: a small open-weight model on the OPO's own hardware that holds the work in one continuous attention state rather than waking to answer questions, judges at the boundaries of completed thoughts, and holds its silence by default. Its bench numbers are real, dated, and measured on one consumer card — and not one of them is a clinical number. The substrate lives at fusor1.com; the seams it watches are VIGIL, ROUNDS, STEWARD and BELLMAN.

Every one of those has been waiting on the same missing thing: somewhere to write to, and something to read from, that belongs to the OPO rather than to a vendor. REGISTRAR is that floor. But the floor is useful with nothing standing on it, which is why it ships first and alone.

14

Checkable, and still mostly a bet

The plate.

Three classes of row here, and the difference matters. Substrate numbers were measured on a reference bench, in another room, on other streams — their transfer to this domain is a bet in every case. This repository numbers are facts about the artifact itself: clone it and check them, they are the output of conformance/run.py — plate as of 2026-08-27; the battery, not this page, is the authority. It. And everything downstream of an actual OPO is still a budget or a bet, because no pilot has run. A plate that hides what it has not measured is a brochure.

QuantityRatingStatus
Boundary detection — end of a completed thought0.97 / 0.02measured · substrate
Judgment probe, per thought boundary~44 msmeasured · substrate
Abort of a forming thought13 µsmeasured · substrate
Honest multi-hop recall across a working day≥ 98,304 tokmeasured · substrate
Self-authored fold of a working context14.8×measured · substrate
Three minds co-decoding on one shared state1.208×measured · substrate
Disposition after tuning, per decision boundary6.7%measured · substrate
Deterministic replay of a shiftbyte-identicalmeasured · substrate
Lifecycle states with a verified provenance locator13 / 15measured · this repository
Citations byte-exact against a pinned source44 / 44measured · this repository
Public sources pinned by sha2565measured · this repository
Conformance battery53 G · 9 PU · 0 Fmeasured · this repository
Jurisdictions with a cited authorization statute1 / ~51measured · this repository
L0 required-element set, against OPTN data definitionsbudget · the build
Falsifier · run 1 — synthetic site, rubric v10.57 ∥ 0.375VOID — the rubric admitted two readings
Falsifier · run 2 — fresh session, rubric v20.28measured · FAILS, instrument-limited
Falsifier · run 3 — same candidate, grain-aware rubric v30.38measured · FAILS, robust — on a corpus whose honest ceiling was 0.575
Falsifier · runs 4–5 — corpus v4 (ceiling 0.975, traps moved), two fresh sessions0.54 ± 0.04measured · rubric v3.1 (containment defect fixed by QC-2, frozen pre-total) — n=2 SHAPED; floor 0.35 cleared both; 0 fabrications ever; COVERS not reached under the corrected instrument
…the no-material floor, and what refuses it0.47 → 0.55measured · outscores capped honesty — and the gates refuse it outright
Fabrications, across every honest candidate, all four runs0measured · the floor arm made 1
Harness-authored patch vs. a real operational deltabet · the pilot
Time from clone to first signed patchbudget · the pilot
Referrals recovered that would have lapsedbet · the pilot
Coordinator minutes returned per casebudget · the pilot

SUBSTRATE ROWS WERE MEASURED ON A REFERENCE BENCH, ON OTHER STREAMS, IN ANOTHER ROOM; THEIR TRANSFER TO THIS DOMAIN IS A BET IN EVERY CASE. REPOSITORY ROWS ARE REPRODUCIBLE BY ANYONE WHO CLONES IT AND RUNS THE BATTERY.

THE FALSIFIER RAN THREE TIMES ON A SYNTHETIC SITE, PRE-REGISTERED EACH TIME, GATE BATTERY PINNED BY COMMIT. RUN 1 WAS VOIDED — ITS OWN RUBRIC ADMITTED TWO READINGS (0.57 SHAPED ∥ 0.375 FAILS), AND ADOPTING EITHER AFTER THE FACT WOULD HAVE BEEN POST-HOC. RUN 2, A FRESH SESSION UNDER THE CORRECTED RUBRIC: FAILS AT 0.28, INSTRUMENT-LIMITED. RUN 3 CLOSED THE INSTRUMENT'S MEASURED DEFECTS AND THE VERDICT HELD: FAILS AT 0.38, ROBUST — WITH ZERO FABRICATIONS IN EVERY HONEST CANDIDATE, AND THE CANDIDATES FINDING THREE CORPUS DEFECTS NOBODY PLANTED, TO THE EXACT COUNT. A CORPUS WRITTEN BY SOMEONE WHO KNEW THE ANSWERS BOUNDS THE KIT FROM ABOVE: A PASS WOULD HAVE BEEN NECESSARY AND NOT SUFFICIENT, AND THE FAILURE IS DECISIVE ON THIS CORPUS. ITS HONEST CEILING WAS ALSO 0.575 — THE TOP BAND UNREACHABLE WITHOUT FABRICATING — WHICH IS WHY CORPUS V4 WAS PRE-REGISTERED — CEILING 0.975, TRAPS MOVED. RUN 4, A FRESH SESSION ON V4: 0.70 — COVERS, ON THE KNIFE-EDGE. NONE OF THIS SAYS WHETHER A REAL OPO IS LEGIBLE. THAT ROW IS STILL EMPTY, AND IT IS THE ONE THAT MATTERS.

THERE ARE STILL NO CLINICAL PERFORMANCE NUMBERS ON THIS PAGE, BECAUSE THERE ARE NONE — NO PILOT HAS RUN AND NO PATIENT DATA HAS TOUCHED ANY PART OF THIS. WHEN THAT CHANGES, THE PLATE CHANGES FIRST AND THE PROSE FOLLOWS.

The falsifier, run — four times, and the ledger is the point

The central claim — that a competent harness can author a correct L2/L3 layer from site material, under the gates — was pre-registered and run four times against synthetic sites with known deltas M. Run 1 was voided when its own rubric proved ambiguous. Runs 2 and 3 returned FAILS (0.28; then 0.38 after the scorer's measured defects were closed) — on a corpus whose honest ceiling was later shown to be 0.575, meaning the top band was unreachable without fabricating. Corpus v4 was pre-registered to fix exactly that — ceiling raised to 0.975, traps moved so no prior knowledge transfers — and a fresh session scored 0.70 — COVERS on the knife-edge. A replication by a second fresh session returned 0.62 — SHAPED, so the single-run COVERS is withdrawn as a headline by its own stated caveat: the honest result is S = 0.66 ± 0.04 (n=2), the floor cleared decisively both times, and the band boundary unresolved at this sample size.

Zero fabrications in every honest candidate, across all five runs — the one number that never moved. And the finding worth more than any verdict: the no-material floor outscores capped honesty on raw S and the gates refuse it outright ("asserts generality, not this site"). The falsifier is the scorer and the gates, as a pair — breadth is where the score-mass lives, honesty is what the gates buy, and no single number carries both.

So the completability bet now has one pass, on the corpus where honesty could reach full marks, by the thinnest possible margin — necessary, and not sufficient. Full record, including the two FAILS and everything every candidate got wrong: experiments/F-PATCH-DELTA/RESULTS.md. The real-site row below is still empty, and it is the one that matters. BET

15

What died, and the number that killed it

Funerals.

Every honest project has a graveyard, and hiding it is how a page becomes marketing. These are printed beside the laws they bought.

Dead · surprise as a relevance signal

Prediction error is free at every ingested token and is close to what biological attention appears to be made of, so it was the obvious triage signal for what deserves a word. It is not. In a control battery a deliberately irrelevant percept scored 7.54 while the real contradiction — the thing that actually warranted an interruption — scored 6.91, and the most semantically inert percept in the set scored highest of all. It ranks novelty, not relevance, and it is inverted rather than mis-scaled, so no monotone threshold rescues it. Surprise keeps exactly one job now: triage for what to look at, never for what deserves a word. M

Dead · the configurable threshold

The obvious way to build a watcher is a sensitivity dial in a config file. Across a full recorded day, the best fixed threshold caught 36 of 39 planted moments and was deaf exactly where it mattered; the same system at zero bias fired 921 times per stream hour. There is no setting between those two, because a runtime dial is a scalar multiplier and the utility of speaking is violently state-dependent. And the flood cannot be deduplicated away: at dial zero the dedup ratio was 1.07 — roughly 59 distinct conditions per hour, each individually defensible. It is breadth, not repetition. M

Standing null · the floor may simply win

Timers, completeness checks, denominator reconstruction and missed-referral audits are all rule-shaped and need no model at all. It is entirely possible the deterministic floor produces most of the measurable improvement on its own. If it does, the correct response is to ship that, print this funeral, and keep the resident as a research programme rather than quietly relabelling a rules engine. NULL

16

Attacking this properly

Counterweights.

The eight strongest arguments against this project, written by its author, because a plate that hides its failures is a brochure.

This is not a weekend project, and pretending otherwise is the likeliest way it dies. Life-critical, federally regulated, PHI-bearing, with a real incumbent and a sixteen-month regulatory window. The honest question is not can this be built — it is whether it becomes the thing, or does not get started.

Domain expert of one. The author's knowledge is the moat and also the single point of failure, and it is knowledge of one OPO. The risk of encoding Dallas twice is real, and is exactly the failure being diagnosed. The mitigation is structural rather than personal: L0 comes from published policy, not from memory, and every fit is authored on site by the site. The sharpest live instance is the authorization table: one state of roughly fifty-one — the plate prints it — and until it fills, the spine is a Texas spine on that one axis.

The clean-room constraint is a real constraint, not a formality. The author is a former employee of an organization that built a system of this exact kind. Everything in the seed is therefore derivable from public sources only — published OPTN policy and data-element definitions, the CFR, CMS rules and fact sheets, vendor public documentation, published literature, and synthetic fixtures. Every L0 element carries its public-source provenance from the first commit, not retrofitted. Domain intuition is his to keep and use. Somebody else's schema is not.

Fifty-five completions could become fifty-five forks. That is how OpenEMR and VistA ended up as private forks maintained badly, and it is the real threat here. Confluence and the patch layer only work if the patch path is so much easier than the fork path that forking is irrational. If the repository merely discourages editing L0, someone will edit L0.

A foreign harness will produce confident garbage. The conformance battery is the only thing standing between a plausible completion and a wrong one, at an organization where wrong loses an organ. If the battery is weak, this project is actively dangerous rather than merely unhelpful.

The 3 a.m. reality. Everything designed in daylight meets a coordinator who has been awake for nineteen hours with a family in a waiting room. If the system is wrong at that moment it is worse than absent — which is the strongest argument for shadow-first, for the advisory posture being structural rather than a setting, and for the resident staying behind its own gates.

Procurement and IT at an OPO are not fast. Security review, privacy officer, medical director, possibly an IRB-equivalent, possibly the board. A read-mostly artifact with no PHI writes and no vendor relationship is the only thing that can move at a speed this project can survive — which is why it is shaped that way.

Everything above is words. There is no receipt anywhere on this page for the thing this page is actually claiming. The measured components it leans on were measured in other rooms, on other streams, and their transfer to this domain is a bet in every case. Nothing here has run inside an OPO. No patient data has touched any part of it.

17

Free, yours, auditable

There is no ask anywhere on this page.

This is not a company. There is no pricing page, no contact form, no demo request, no waitlist, and nothing to sign. It is MIT-licensed source your own people build, with open weights you choose, on hardware inside your own building. No license server, no account, no vendor in the loop, and no clause anywhere that makes leaving expensive — because there is nothing to leave.

Fork it. Strip it. Rename it. Ship it as your own. Sell it to the other fifty-four if you want to; the licence permits that and the author will not be involved. The only thing asked in return is that if you find the spine wrong, you say so in public, where the next organization can read it.

# what it takes OS Linux or Windows Server, inside your network GPU one NVIDIA RTX-class card. The reference loop runs on 16 GB. [M] 24–32 GB is what a 27B with a long context wants, not what the loop needs. Model open weights, 9B to 27B class, quantized — fully offline Co-tenancy sharing a card with a loaded workstation is NOT bench speed: probes 0.6–24.6s vs 44ms free. [M] Size for the card being shared. Record append-only, hash-chained, exportable in full at any time Harness whichever your team already uses. this repo is written for it. Runtime @deepseek-ai/dsh-root (MIT), pinned and vendored — kernel: cordis Status seed, gates, floor, tape, replay RUN today. Composing the boot profile and binding default capabilities is [SPEC] — a clone does not yet deliver a standing harness, and this line will change first. Network none required. air-gapped is a supported configuration. # what is in the repository today — and it runs on a bare Python core/lifecycle/ the mandated case lifecycle, cited — 15 states, 13 established core/tape.py L4. append-only, hash-chained. no delete, no update — by type. core/case.py replay a case against the lifecycle; refuse what was illegal core/authority/ the authority chain: statute → rule → policy → state law → your fit core/authorization/ the jurisdiction table, PROCEDURE.md, and a state fetcher clinical/ L1 — blood typing, risk assessment, infectious disease testing gates/ sixteen gates. every refusal names its defect in words. floor/ the temporal closure. zero dependencies. elicit/ one question per variation point — usable with no software examples/worked/ a complete patch · 22 refused drafts · 7 retained UNCAUGHT holes, labelled conformance/ one command: is this instance sound? corpus/ 5 pinned sources, sha256 — 44 citations, byte-exact # get it, and check it git clone https://github.com/bochen2029-pixel/REGISTRAR && cd REGISTRAR python conformance/run.py # GREEN / PASS-UNVERIFIED / FAILED, per check. # exits non-zero unless every one is GREEN. python tools/cite.py --check # every quote byte-matches its pinned source python conformance/claims.py --surface <this page> # the page's own numbers, machine-checked # CI runs the battery on every push — Linux, ~3 seconds, exit 1 never. # and this page is itself gated: its counts are checked against the repo's # derived CLAIMS.json, because prose drifts and a check does not.

STATUS: REV 0. THE SPINE IS BUILT AND CITED — 13 OF 15 LIFECYCLE STATES CARRY A VERIFIED LOCATOR, ACROSS FIVE SHA256-PINNED PUBLIC SOURCES, WITH 44 CITATIONS THAT BYTE-MATCH THE TEXT THEY QUOTE. THE GATES, THE FLOOR, THE TAPE AND THE REPLAY EXECUTE ON A BARE PYTHON. THE COMPLETION CLAIM REMAINS A BET WITH ITS FALSIFIER PRINTED IN §14 AND ITS FUNERALS IN §15. NOTHING HERE HAS RUN INSIDE AN OPO. NO PATIENT DATA HAS TOUCHED ANY PART OF THIS. THE AUTHORIZATION JURISDICTION TABLE HOLDS ONE STATE OF ROUGHLY FIFTY-ONE, AND SAYS SO.

The record should belong to the people who keep it.

Fifty-five organizations do the hardest coordination work in American medicine, on a federally defined territory, graded on two numbers, using a record system almost none of them own. The software that fits them has never existed, because fitting used to take a services team and six years — and by the time it fit, the operation had moved. One of them tried to build it anyway, pre-sold it to its peers, ran late, and ended up paying them.

That constraint is gone. The mandated half can be written once and given away. The half that has to fit can be finished where it is needed, by the people who work there, using intelligence they already own — inside a fence that will not let them get it silently wrong, and under a signature that makes a human responsible for every line of it.

The EDR was never the product.
The differentiation was the product — and the record is what it leaves behind.

TO THE PEOPLE WHO SPENT SIX YEARS ON THIS AND MEANT EVERY DAY OF IT: NONE OF THIS WAS AVAILABLE TO YOU, AND ALL OF IT IS AVAILABLE NOW. IT IS FREE. TAKE IT.

Ask REGISTRAR