SECURITY

Intelligence requires access. Trust requires restraint.

Arlie is being designed for an environment where clinical, operational and financial information can be highly sensitive. Security, privacy and controlled access are therefore part of the product architecture, not features added afterward.

DESIGN PRINCIPLE

Arlie should see what it needs.
Not everything it can.

Minimum necessary access

Connections should be limited to the information required for the management question Arlie is solving.

Controlled permissions

Access should reflect role, purpose and organizational boundaries rather than assuming every user should see every part of the practice.

Traceable activity

Important access and system actions should be attributable and reviewable rather than disappearing inside an opaque AI process.

DATA ARCHITECTURE

Connect to the practice.
Don't create another uncontrolled copy of it.

SOURCE SYSTEMS

Existing systems remain authoritative.

Arlie is designed to work with the systems already running the practice rather than becoming a replacement system of record.

ACCESS

Use only what the analysis requires.

The architecture should minimize unnecessary retrieval, exposure and persistence of sensitive information.

IDENTITY

Separate identity from analysis where possible.

Many management questions depend on patterns and relationships, not on exposing personally identifiable information throughout the reasoning process.

RETENTION

Keep data only for a defined purpose.

Retention policies should be deliberate, documented and appropriate to the information being processed.

AI GOVERNANCE

A recommendation should never become an unexplained command.

Evidence

Arlie should show the signals supporting a recommendation so management can understand why the issue was raised.

Reasoning

Recommendations should distinguish observations, plausible explanations and management judgment rather than presenting every inference as fact.

Human authority

Arlie advises management. People remain responsible for decisions, clinical judgment and actions affecting patients or the business.

Arlie is management intelligence โ€” not autonomous management and not autonomous clinical decision-making.
HEALTHCARE ENVIRONMENT

Built with healthcare obligations in mind.

Production deployments involving protected health information will require appropriate technical safeguards, access controls, contractual protections and operating procedures for the specific environment in which Arlie is deployed.

Encryption

Sensitive information should be protected in transit and at rest using appropriate modern encryption.

Authentication

Access to Arlie should require strong identity controls appropriate to the deployment environment.

Auditability

Security-relevant activity should be logged and available for appropriate review.

CURRENT STATUS

Private product preview.
Not a production deployment.

The current Arlie environment is for product development and demonstration. Production security, privacy and compliance claims will be made only for capabilities that have been implemented, validated and documented.
PRIVATE PRODUCT PREVIEW

See how Arlie thinks without pretending development is finished.

The preview demonstrates the management-intelligence model while the production architecture continues to be built and validated.