Platform · AI Copilot

AI that has to ask permission.

Every clinic system now claims AI. The question a clinic should actually ask is narrower: what is it allowed to read, what can it change without me, and what happens if it is wrong. This page answers those three first.

  • Permission-bound
  • Approval before writes
  • Identifiers masked
  • Every call audited
Copilot · a write waits for a yesSample

Dr AMove Patient B’s follow-up to next Thursday afternoon

  • Find patient1 match · S••••234A
  • List appointments20 Aug 10:30 follow-up
Reschedule appointmenthigh risk · needs approval
appointment
APT-4821
from
20 Aug 10:30
to
27 Aug 15:00

Questions are answered straight away. Anything that changes a record stops here, showing exactly what it would change, until a person decides. Either decision is logged.

The copilot

It works the clinic, not a chat window

The copilot is not a text box bolted onto the side. It reaches the same records your staff do — through the same permission checks — and it can act, once someone says yes.

Find and read

Search a patient, open an encounter, pull an invoice, read today’s queue, list appointments. Read-only questions are answered straight away.

Draft

A SOAP note from the consultation, a remark for a medical certificate, a summary of a patient’s history. Always as a draft, always editable, never saved on its own.

Act — after you approve

Book, reschedule or cancel an appointment; add someone to the queue; correct patient details; send a reminder. Anything that writes is held for a human yes.

It only sees what you see

Each tool re-checks the signed-in user’s own permissions. A front-desk account asking the copilot for clinical notes gets the same refusal it would get from the interface.

It stays inside your clinic

Every question it answers is limited to your clinic’s records. No wording of a request can reach another clinic’s data, because the system never hands it any.

Answers cite the record

When it tells you the last HbA1c, it tells you which encounter that came from — so you can check it in one click instead of trusting it.

The part that matters

What it is not allowed to do

These are not settings we hope you turn on. They are how the thing is built.

Approval

Writes need a human yes

Anything that would change a record does not happen on its own. It comes back as a proposal showing exactly what would change, and waits for a person to approve or reject it. That decision is recorded too.

Redaction

Identifiers are masked first

NRIC, phone numbers and account numbers are redacted before the request leaves for the model — S••••567G, not the real thing. The clinic still sees the full value; the model does not.

Audit

Every call is on the record

Who asked, what the AI looked up or proposed, what came back, and whether it was approved. The AI is in the same audit log as everything else.

Residency

Models are chosen on residency

Each AI model is recorded with where it runs and whether it is cleared for health information. Anything that touches patient data only uses models that are.

If you want to turn the copilot off for a role, or entirely, that is a permission — not a support request.

In the room

Dictation, in the doctor’s own words

The typing after each consultation is the time doctors most want back.

Speak, then edit

Dictate the consultation and it comes back structured into history, examination and plan — as a draft on screen, before anything is saved.

Your phrasing, not a house style

The write-up is tuned to each doctor, so the note reads like the doctor who dictated it rather than like a template.

Coding follows the note

ICD-10 and SNOMED candidates are suggested from what was written. Nothing is submitted on a suggestion alone — the doctor confirms.

Falls back gracefully

If dictation is unavailable, the encounter is an ordinary typed note. No part of the clinical workflow depends on the model answering.

Before they arrive

A front desk that answers at 11pm

Most patient WhatsApp messages are four questions: are you open, can I get an appointment, how much is it, do I need a referral. Those do not need a human at 11pm — but the fifth one does.

WhatsApp front desk · 23:41Sample

Patient · 23:41

Any slots tomorrow morning?

AI front desk · 23:41

Tomorrow 9:20am and 10:40am are open. Shall I take one?

Patient · 23:43

Can the doctor tell me what last week’s blood test means?

Hand off to a personEscalated to staff · thread attached

clinical question — agent has no clinical tools

It can book a slot. It cannot interpret a result: it has no access to the record, so it hands over.

It answers the routine four

Are you open, can I get an appointment, how much is it, do I need a referral: answered from your clinic’s own information, not from the open internet.

It can book, within limits

It can only offer the slots and services your clinic has set up. What it may book is your configuration, not its improvisation.

It hands over rather than guesses

Anything clinical, anything angry, anything it is unsure about goes to a human with the thread attached. Handing over is a tool it is expected to use, not a failure.

It cannot be talked out of its rules

Messages that try to trick it into ignoring its rules are caught on the way in, and its replies are checked on the way out.

It never invents a clinical answer

The agent has no clinical tools. It cannot read a diagnosis to a patient because it cannot reach one.

Everything it did is in the inbox

Staff see the AI’s replies in the same shared inbox as their own, attributed to the agent — not as a black box running somewhere else.

Paper in, data out

Documents you would otherwise retype

Paper that arrives at the counter is read into the right fields, and a person confirms it.

Identity documents

An NRIC or passport photographed at the counter is parsed into the registration form for the front desk to confirm.

Outside reports

Upload a discharge summary or an external report and the relevant history is surfaced into the encounter instead of retyped.

Insurance claim documents

Claim paperwork is extracted into the fields the payer expects, with the extraction shown next to the source for checking.

Always a draft

Extraction proposes; a person accepts. The pattern is the same everywhere the model touches a record.

How we know

It is tested like the rest of the system

Every change to the AI is checked against a fixed set of clinic situations before it reaches you, and the result decides whether it ships.

A fixed set of clinic situations

Each thing the AI does is checked against a set of real-world cases with known right answers, every time, rather than tried once by hand.

Marked against written criteria

Each answer is marked against written criteria and gets a pass, a score and notes, so if it gets worse, the score shows it.

Every change is traceable

Each version of the AI’s instructions is recorded with every answer it gives, so any change in behaviour can be traced back to the change that caused it.

You can see what it costs

Usage is tracked per clinic, so AI spend is a line you can see rather than a surprise attached to a subscription.

Questions

What clinics ask about the AI

Is our patient data used to train models?

No. Patient data is sent only to serve the request in front of you, identifiers are masked before it leaves, and it is not contributed to model training.

Can the AI change a record on its own?

No. Anything that writes is held as a proposed action with its exact arguments until a person approves it, and both the proposal and the decision are logged.

Can we switch it off?

Yes — per role or entirely. Copilot access is an ordinary permission, so the same screen that controls who can void an invoice controls who can use the AI.

What if it gets something wrong?

It drafts and proposes; a clinician decides. That is the design, not a disclaimer — which is also why every answer points at the record it came from.

Where does the model run?

Each AI model is recorded with where it runs and whether it is cleared for health information, and anything touching patient data only uses models that are. We will walk through the current setup on the call rather than print something here that changes.

Next step

See it against your own clinic day.

Thirty minutes, screen shared, using your workflow — your busiest hour, your payer mix, your claim types. We will tell you plainly if we are the wrong fit.

No slide deck. No obligation.