EvidenceGate
Documents
/
DOC-003
Saved, v1.0
Export
Save version
Engineering
Draft
In review
Approved
Hemnaath
Sai
Both
Evidence-centered services, model boundaries, deterministic quality gate, policy registry, review packet, and reliability behavior.
Markdown
H2
List
Use # headings, - lists, and plain text. Every save creates a revision.
# Evidence Graph and Platform Architecture ## Architectural thesis The Evidence Layer is the center of the platform. Models propose typed facts and retrieve context. Deterministic services establish quality results. Humans own material decisions. ## Runtime flow ### Intake boundary Authenticated portal and API requests create a tenant-scoped case. Files are malware-scanned, hashed, versioned, encrypted, and written to immutable object storage. Metadata is stored separately from document bytes. ### Document Intelligence The classifier selects an approved type or Unknown. OCR and extraction workers produce candidate facts. Clinical extraction is bounded to an explicit schema. Workers cannot update policy, execute a final disposition, or communicate externally. ### Evidence Graph The graph links case, document version, page, region, snippet, candidate fact, normalized fact, contradiction, rule input, rule result, finding, and human action. Nodes are immutable; corrections create superseding versions. ### Policy Intelligence Published policy sources are parsed into clause records. A human policy author converts relevant clauses into structured rules. A second reviewer approves the bundle after golden tests. RAG is tenant-filtered and version-pinned. Retrieval returns clauses and citations only. ### Quality Gate Deterministic services evaluate: - Required-document matrix. - Mandatory fields. - Identifier and demographic consistency. - Procedure, diagnosis, estimate, and chronology consistency. - Active insurer rule bundle. Unknown inputs produce Unknown or Needs review. They never become Pass through defaulting. ### Review Packet The packet service composes observed facts, deterministic findings, retrieved clauses, unknowns, evidence, and run metadata. Grounded summarization may improve readability but cannot introduce a finding that does not already exist in structured results. ## Service boundaries - Intake Service owns cases and file admission. - Document Service owns immutable versions and page assets. - Extraction Orchestrator owns bounded model jobs and retries. - Evidence Service owns provenance and fact versions. - Validation Service owns normalization and contradiction checks. - Policy Registry owns sources, clauses, and publication states. - Rule Engine owns deterministic execution. - Review Service owns packets, queues, overrides, and requests for evidence. - Audit Service receives append-only events from every service. ## Data stores - Object storage for encrypted original files and rendered pages. - PostgreSQL for operational state, rules, findings, and review actions. - Vector and lexical indexes for approved policy retrieval only. - Append-only audit store with retention controls. - Queue for idempotent asynchronous processing. ## Reliability behavior - Every job uses an idempotency key. - Partial extraction can proceed, but the packet displays missing pages and failed workers. - A rule-engine outage blocks rule results and routes the case to manual review. - A retrieval outage does not block deterministic checks. - A model outage preserves intake and queues extraction for retry. - Circuit breakers isolate tenant or provider failures. ## Security boundary All retrieval, storage, queues, logs, and caches are tenant-scoped. Protected health information is excluded from application logs. Model providers receive the minimum required page region under an approved data-processing configuration. ## Deployment baseline India-region services and storage are preferred for pilot data. Production requires private networking, managed keys, workload identity, backups, tested restoration, monitoring, and an incident runbook.