See deterioration. Make the response clear.
Sentinel turns FHIR R4 observations into NEWS2 scores and governed alerts, keeping acknowledgements, clinical orders and audit evidence in one live workflow.
A dashboard is only as fast as the person looking at it.
Observations, alert state, clinical orders and acknowledgements are often split across systems or informal handoffs. Sentinel gives an entitled care team one explicit workflow: ingest, score, alert, acknowledge, order and acknowledge, with data age and missing NEWS2 parameters kept visible.
Alerting is not acting
A colour change alone does not show whether anyone took ownership. Sentinel records raised and acknowledged states for danger alerts and clinical orders.
Freshness is clinical context
An apparently normal score based on old observations is not the same as a current assessment. The live board surfaces when the latest observation was recorded.
Response needs verifiable evidence
Governed actions write PHI-lean audit records into a per-tenant hash chain, so later removal or alteration can be detected by chain verification.
Sense. Score. Act. Prove.
Four movements, one accountable workflow, from a FHIR observation to a governed alert, explicit acknowledgement and verifiable clinical order.
Observations arrive over FHIR R4
Hospital systems and device gateways can submit FHIR R4 Observation resources or Bundles through a clinic-scoped API key. Sentinel validates supported observations, deduplicates stable source IDs, records accepted readings, and reports anything it skips so partial coverage stays visible.
Deterministic NEWS2 scoring
Sentinel builds the latest encounter snapshot and calculates NEWS2, including the configured SpO2 scale, plus optional clinic hard thresholds. Missing NEWS2 parameters are surfaced rather than silently scored as zero. An optional AI narrative may explain an already-raised alert, but it cannot change the score, severity, or alert decision.
Governed alerts make response state explicit
A danger or critical breach raises an idempotent governed alert and updates the acuity-sorted live board. Team members can acknowledge alerts; authorised clinicians can issue clinical orders, and order acknowledgement is recorded separately. Automated calling is a disarmed, fail-safe integration point; it is not a live notification or order-capture channel.
Governed actions leave verifiable evidence
Observation records, alerts, clinical orders and acknowledgements run through governed actions with PHI-lean audit projections. Audit rows are hash-chained per tenant scope: removing or changing a row makes chain verification fail from that point forward.
You can’t act on what you can’t trust.
Sentinel keeps deterministic scoring separate from optional AI narrative. The narrative cannot alter NEWS2, severity or whether an alert is raised. Clinical orders require an authorised clinician, and their privileged audit entry must be committed before the order can be written.
Hash-chained provenance
Governed observation, alert, order and acknowledgement actions write PHI-lean rows into a sequential, tamper-evident audit chain.
Privileged clinical orders
Orders ride a fail-closed audit: the record is committed before the action. If the audit can't be written, the order doesn't happen.
PHI encrypted at rest
Sentinel vital values, patient references, alert detail, patient names and order text use AES-256-GCM field encryption at rest. Authorised server routes decrypt only for authenticated, tenant-scoped views.
Bounded scenario replay
Managers can run rate-limited what-if replays over a bounded historical window. Stored and returned results contain aggregate counts only, with truncation and baseline-fidelity caveats kept visible.