Read-only by default.
Why we read from systems of record but don't write back — and how that single architectural choice makes compliance the floor.
The first design decision in MD, BIZ, and EDU is the same: we read. We don't write.
This sounds like a limitation. It's a feature. Three reasons.
1. Compliance gets easier when you don't change anything
Read-only access has a fundamentally different risk profile from write access. Auditors care less. Legal cares less. Vendor security reviews go faster. Your buyer's IT team can say yes without rewriting their data governance policy.
2. Trust gets easier when accountability stays put
If a clinician acts on context we surface, the clinician is still the one who acted. If we wrote to the record, we'd be in the chain of accountability. We're not. The person doing the work stays in charge.
3. Integration gets easier when the contract is one-way
Two-way sync is a maintenance nightmare. One-way reads with a clear scope are tractable. We can integrate with new systems in days, not quarters.
What this is not
This isn't a permanent constraint. There are workflows where writing back makes sense — and where we'll do it under explicit contract, with explicit consent, and with full audit trails. But the default is read. Always.
That's why we say compliance is the floor, not the pitch.