AI is entering hospitals through many doors at once: ambient documentation, chat assistants, coding tools, scheduling optimisers. Governing each one separately is slow and inconsistent. A single framework, applied to every model and agent, is faster for the hospital and clearer for clinicians.
Autonomy is a level, not a yes or no
We use five autonomy levels: observe, suggest, act with approval, act within limits and autonomous. In a hospital the right default is conservative. Clinical capabilities — work-ups, orders, discharge summaries — stay at suggest: the clinician decides and signs. Operational and financial actions — bed proposals, claim replies, reorders — can be prepared in full but still wait for a person to approve.
Autonomy by type of action
A conservative default for hospitals
| Action | Default level | Who decides |
|---|---|---|
| Early-warning score, critical-result routing | Observe | Nurse and treating doctor |
| Work-up list, order draft, discharge summary | Suggest | Treating doctor |
| Bed proposal, claim reply, pre-authorisation, reorder | Act with approval | Bed manager, finance, procurement |
| Reminder from an approved template | Act with approval | Patient experience lead |
| Any action changing a clinical record without a person | Not permitted | — |
Note: SCIKIQ default; each hospital sets its own limits with clinical governance.
Roles, masking and the record
An AI assistant is a new way to reach data, so it must obey the same access rules as every screen. In our demo, administrators manage beds, flow and money but do not open clinical records, finance users see diagnosis fields masked, and diagnosis questions from finance roles are refused by policy; every question, AI draft and agentic action is audited by user and role1. Health-data rules such as the HIPAA Privacy and Security Rules in the US apply to these features as to any system holding protected health information23.
- Inventory every AI capability, with an owner and an autonomy level.
- Validate before commit: the server re-checks every proposed action against role and record state.
- Confirm: nothing that changes a record commits without a person.
- Audit: keep every prompt, draft and action by user and role.
- Stop: keep the ability to switch any agent off.