Search all 478 artefacts by title, document ID or content.
Policy | Family 2, Legal & Contractual
Pensieve is not sold per seat, per user or per transaction. A hospital adds departments, users and workflows without asking and without repricing (POL-GL-065). That model only works if a small number of consumption patterns are constrained, because they are the patterns that degrade the Platform for the hospital…
This document is the source of truth for: marketing:/legal/fair-use, trust:/legal/fair-use, trust:/documents/POL-GL-057, rate-limit-classes, fair-use-thresholds
Those surfaces render this text from here. They do not keep their own copy, so they cannot drift from it.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
POL-GL-057 | Version 1.0.0 | Effective 01 August 2026 | Last Modified On 01 August 2026
Pensieve is not sold per seat, per user or per transaction. A hospital adds departments, users
and workflows without asking and without repricing (POL-GL-065 2.2). That model only works
if a small number of consumption patterns are constrained, because they are the patterns that degrade the
Platform for the hospital itself, or, on a shared deployment, for somebody else's hospital.
This Policy states what those patterns are, what limits apply, what happens when a limit is reached, and what Pensieve will and will not do about sustained excess.
The governing commitment: Pensieve rate-limits before it throttles, throttles before it suspends, notifies before it does any of them, and never applies a limit that would prevent clinical care.
| Deployment model | How this Policy applies |
|---|---|
DM-1 Dedicated |
In full. Limits protect the hospital's own dedicated capacity and are set from its own profile. |
DM-2 Shared |
In full, and most strictly. Limits here also protect other tenants; the isolation controls are in DIS-GL-032. |
DM-3 Customer Cloud |
Application-level limits apply. Capacity is the hospital's own cloud spend, so Pensieve advises rather than constrains, except where a pattern threatens the Platform's own stability. |
DM-4 On-Premise |
Application-level limits apply as configured at deployment. Hardware capacity is the hospital's under ADD-GL-008; Pensieve's limits protect the software, not the server room. |
Stated first, because it is the only part that matters clinically.
1.1 Pensieve does not apply a rate limit, throttle or suspension that prevents:
1.1.1 registration or admission of a patient;
1.1.2 recording, retrieval or display of a clinical record for a patient currently receiving care;
1.1.3 an order, a result, a dispensing action or an administration record;
1.1.4 a discharge; or
1.1.5 access by a clinician to information they need at the point of care.
1.2 Where a hospital's own consumption is degrading these paths, Pensieve's response is to add capacity
and then talk about it, not to limit the path. POL-GL-126 governs the capacity response.
1.3 Suspension for non-payment is governed by MSA-IN-001 and is not this Policy. Even there, the
suspension terms preserve read access to clinical records. The position is in MSA-IN-001 and
WPR-GL-400, not here.
| Kind | What it constrains | Applied at | Typical response when reached |
|---|---|---|---|
| Rate limit | Requests per unit of time, per identity and per source | The edge, before any work is done | HTTP 429 with a Retry-After header; the caller slows down |
| Concurrency limit | Simultaneous long-running operations: bulk exports, large reports, migrations | The job scheduler | The job is queued, not rejected, with a stated position |
| Fair-use threshold | Sustained consumption over a month, against the profile on the Order Form | Billing and capacity review | A conversation, then 5; never an automatic charge |
2.1 A rate limit is a protection, not a commercial device. Pensieve does not set a rate limit in order to sell a higher tier.
2.2 The numeric limits in force are published in the Support Center at
[TO BE SUPPLIED], per capability and per interface, and are versioned. They are published
there rather than here because they change with capacity and a stale number in a policy is a trap.
Limits are set per class of caller, not per hospital, so that one integration cannot exhaust the budget of a clinician at a workstation.
| Class | Who or what | Limit basis | Note |
|---|---|---|---|
| Interactive | A logged-in human using the Platform | Generous, per user session | Never reached in normal clinical use. Reaching it indicates automation driving the interface. See 4.3 |
| Integration | A machine identity using the published application programming interfaces | Per credential, per endpoint class | The intended path for volume. Limits are stated in the interface documentation |
| Bulk | Exports, migrations, large report generation | Concurrency, not rate | Queued and run; see 6 |
| Inbound third-party | A third-party system calling in under the hospital's own credentials | Per credential | Pensieve protects itself from a misbehaving third party without blaming the hospital |
| Anonymous | Unauthenticated requests to public endpoints | Strict, per source | Includes login attempts; the authentication-specific controls are in POL-GL-115 |
3.1 Limits are per identity and per source, as recorded in ADD-GL-001 clause 12. A single misbehaving
integration does not consume a hospital's whole budget.
3.2 Burst is allowed. Limits are configured with a burst allowance so that a legitimate spike (a shift change, a camp, a mass-casualty intake) is absorbed rather than rejected. A hospital does not need to warn Pensieve before a busy day, though for a planned event of unusual scale 7 is faster than discovering the ceiling.
These are addressed under the Acceptable Use Policy (ADD-GL-004) as well as here, and Pensieve may apply
an immediate limit without notice because the harm is immediate.
4.1 Automated traffic that degrades the Platform for other users or, on DM-2, for another tenant.
4.2 Scraping the user interface for bulk extraction. A full export is free and available on request
under WPR-GL-400; there is no reason to improvise one, and the improvised version is slower.
4.3 Driving the user interface with an automation tool to evade an interface rate limit.
4.4 Credential sharing that makes per-identity limiting meaningless. Pensieve does not cap named users,
so there is no commercial reason to share a credential and several security reasons not to
(POL-GL-115).
4.5 Load or penetration testing against a production tenancy without prior written agreement. Pensieve will agree a test window; it will not distinguish an unannounced test from an attack.
4.6 Any use prohibited by ADD-GL-005 (Use Case Restrictions), which is a different question from
volume and is dealt with there.
5.1 What "excess" means. The Order Form records the hospital's profile: beds, sites, expected transaction volume, integration count, retention period. Sustained consumption materially above that profile, for two consecutive monthly periods, is excess. A single busy month is not excess.
5.2 What Pensieve does, in order.
5.2.1 Tells the hospital, with the data, and asks whether the pattern is intended. In practice this resolves most cases, because most excess is a misconfigured integration retrying in a loop.
5.2.2 Where it is a defect on Pensieve's side, Pensieve fixes it and nothing else happens.
5.2.3 Where it is a defect on the hospital's side, Pensieve helps isolate it under the two-hour rule in
SLA-GL-001 clause 12.3.
5.2.4 Where the pattern is intended and permanent, it is a commercial conversation at the next
renewal, under POL-GL-065. It is not a mid-term repricing, and Pensieve does not issue a larger invoice
in place of a conversation (POL-GL-065 2.5.3).
5.3 Throttling. Pensieve may throttle a specific class of traffic where excess is degrading service and the hospital has not acted after notice. Throttling is applied to the narrowest class that fixes the problem, never to clinical paths under 1, and is lifted as soon as the cause is resolved.
5.4 Notice. Except where an immediate limit is necessary to protect the Platform or another tenant,
Pensieve gives ten (10) Business Days' notice before applying a throttle, stating the traffic class, the
data, the threshold and what would remove it. The notice instrument is NTC-GL-012.
5.5 Storage and retention. Storage growth is not throttled. Where retained data materially exceeds
Deal retention days, the position is handled under POL-GL-111 and the Order Form, not by limiting
writes.
6.1 Bulk exports, migrations and large reports are queued rather than rejected, with a visible position and an estimated start.
6.2 Where a bulk operation would degrade interactive use, Pensieve schedules it outside the hospital's peak window rather than refusing it. The hospital's peak window is recorded at onboarding.
6.3 A complete export for exit purposes is never throttled, queued behind other work, or delayed for
capacity reasons. WPR-GL-400 governs, and it takes precedence over this Policy. A supplier that slows an
export on the way out is not a supplier a hospital should have chosen.
7.1 A hospital that expects an unusual load, a migration, a mass registration drive, a health camp, a new site coming live, tells Pensieve through the Support Center. Pensieve raises the relevant limits for the window, at no charge, and confirms in writing.
7.2 A permanent increase for a genuine operational reason is made at no charge where capacity allows.
Where it requires materially more infrastructure, POL-GL-065 governs and the change lands at renewal.
7.3 Pensieve does not charge an overage fee. There is no metered surcharge in the three-part tariff.
8.1 Every limited response carries a machine-readable reason and, where applicable, a Retry-After
value. Silent dropping is not used.
8.2 A hospital may see its own consumption against its limits in the Platform. It does not have to ask Pensieve for the number that is being applied to it.
8.3 Rate-limit rejections attributable to Pensieve's own configuration error are excluded from
availability measurement in the hospital's favour, under SLA-GL-001 clause 4; that is, they count as
downtime, not as a legitimate limit.
8.4 A change that lowers a published limit is notified thirty (30) days in advance. A change that raises one takes effect immediately.
| # | Testable statement | Evidence |
|---|---|---|
| T-1 | No rate limit, throttle or suspension has been applied to a path listed in 1.1 | Limit configuration review against the clinical path inventory, quarterly |
| T-2 | Every throttle applied outside an emergency was preceded by 10 Business Days' notice | Throttle log against the notice log |
| T-3 | Published limits in the Support Center match the limits actually configured | Configuration export compared to published values, quarterly |
| T-4 | Every limited response carried a reason code | Edge log sampling |
| T-5 | No exit export was queued, throttled or delayed for capacity | Offboarding records against the job scheduler log |
| T-6 | No overage charge was raised on any invoice | Invoice line review, every cycle |
10.1 Reviewed annually under POL-GL-502, and after any capacity incident recorded in REG-GL-203.
10.2 This Policy does not vary SLA-GL-001, ADD-GL-004 or the Order Form.
| Document | Relationship |
|---|---|
POL-GL-050 Terms of Service, clause 5.8 |
Incorporates this Policy |
ADD-GL-004 Acceptable Use Policy, clause 7 |
The conduct rules this Policy enforces technically |
ADD-GL-005 Use Case Restrictions |
What the Platform may be used for, as distinct from how much |
ADD-GL-001 Security Addendum, clause 12 |
Rate limiting as a security control |
SLA-GL-001 Service Level Agreement |
Availability measurement, the two-hour isolation rule, chargeable work |
POL-GL-126 Capacity Management Policy |
How Pensieve adds capacity rather than limiting demand |
DIS-GL-030 Uptime, Performance and Capacity Disclosure |
What the Platform is engineered to sustain |
DIS-GL-032 Multi-Tenancy Isolation Disclosure |
Why DM-2 limits are stricter |
WPR-GL-400 Exit and Data Portability Commitment |
Exports are never limited |
POL-GL-065 Price Change and Renewal Policy |
Where a permanent volume change is handled |
Support Center: [TO BE SUPPLIED] |
The current numeric limits |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 2026-08-01 | Engineering | First published version. Opens with the clinical paths that are never limited, defines three limit kinds and five caller classes, keeps numeric limits in the Support Center so they cannot go stale, sets a notice-before-throttle rule with a ten-business-day period, states that exit exports are never throttled, confirms that no overage charge exists, and lists six testable statements. |
POL-GL-057 v1.0.0 | Last Modified On 01 August 2026 | Review due
31 July 2027 | Published at https://trust.pensievelabs.org