Search all 478 artefacts by title, document ID or content.
Printed on the standard letterhead. Page furniture, margins and repeating table headers come from the same stylesheet the PDF service uses.
Pensieve Labs
The operating system for hospitals
POL-GL-056
v1.0.0 | 01 August 2026
POL-GL-056 | Version 1.0.0 | Effective 01 August 2026 | Last Modified On 01 August 2026
This Policy states publicly how support is obtained from Pensieve Labs, who may obtain it, and how a
hospital forces something upwards when it is not moving fast enough. It is written for the person in the
hospital who has a problem at 02:00, and for the person evaluating Pensieve who wants to know
what happens after signature.
It is a policy, not a contract. Contractual severity definitions, response and restoration targets,
availability commitments and Service Credits are in the Service Level Agreement (SLA-GL-001), which
governs if this Policy and that Agreement ever appear to differ.
This Policy is published at the Public tier. It contains no exploitable detail and no named individual. The
named holders of each escalation level for a given hospital are recorded in SLA-GL-001 Schedule C for
that hospital, not here.
| Deployment model | How this Policy applies |
|---|---|
DM-1 Dedicated |
In full. |
DM-2 Shared |
In full. |
DM-3 Customer Cloud |
In full for the Platform. Actions inside the hospital's own cloud project are performed under the delegated-access terms of ADD-GL-009, and the hospital's own cloud provider support contract covers the infrastructure. |
DM-4 On-Premise |
In full for the Platform software. Pensieve cannot act on hardware, network or facilities it does not control; 9 states exactly what changes. |
Confusing these three costs a hospital hours in an incident. They are separate on purpose.
| Property | What it is | Use it for |
|---|---|---|
Support Center: [TO BE SUPPLIED] |
The operational channel. Tickets, ticket history, knowledge base, help articles, release notes, how-to documentation, supported browser and device matrix. | Anything that is not working, anything you do not know how to do, anything you want changed. |
Trust Center: https://trust.pensievelabs.org |
The document system of record. Contracts, policies, disclosures, security evidence, registers. | Getting a document, an answer to a security questionnaire, or the current version of a policy. |
Status page: Pensieve status page URL |
Live and historical availability of the Platform, by component and by deployment. | Checking whether an outage is yours alone or shared, before you raise a Ticket. |
1.1 The Support Center is the channel; the SLA is the commitment. Pensieve does not restate the Support
Center's contents in the Trust Center, and does not restate the SLA's commitments in the Support Center.
Where a Support Center article appears to promise something different from SLA-GL-001, SLA-GL-001
governs and Pensieve corrects the article. This mirrors SLA-GL-001 clause 12.1.
1.2 No support commitment is made anywhere except in SLA-GL-001. Statements made in a sales
conversation, a demonstration, a proposal deck or a Support Center article do not create a support
obligation.
| You are | You may raise | Where | What you get |
|---|---|---|---|
| A user at a Customer hospital | How-to questions, defect reports | Support Center | An answer, and a Ticket if it is a defect |
An Authorised Support Contact named in SLA-GL-001 Schedule C |
Anything, including a Severity 1 by telephone | Support Center, support e-mail, Severity 1 telephone | The full contractual response and escalation entitlement |
| A Customer's billing or finance contact | Invoices, credit notes, Service Credit claims | info@pensievelabs.org |
Handled under POL-GL-063 and the finance artefacts |
| A prospective customer, pre-contract | Product, security, commercial and evaluation questions | The Trust Center request form, or your named Pensieve contact | See 7 |
| A security researcher | A suspected vulnerability | info@pensievelabs.org |
Handled under POL-GL-059, not as a Ticket |
| A Data Principal (a patient, an employee, a website visitor) | A data-protection right or complaint | info@pensievelabs.org |
Handled under POL-GL-066, not as a Ticket |
| A law-enforcement or regulatory body | A demand for data | info@pensievelabs.org |
Handled under POL-GL-067, never through support |
| Anybody at all | A report that a published Pensieve document is wrong or stale | https://trust.pensievelabs.org feedback route |
Corrected or explained; tracked under POL-GL-502 |
2.1 Wrong-door rule. A request that arrives in the wrong channel is routed, not rejected. Pensieve
re-routes it, tells the sender where it went, and, where a statutory clock applies, as it does for a
Data Principal request under POL-GL-066, starts that clock from the original arrival, not from the
re-routing. Nobody loses a day because they used the wrong address.
2.2 The eight-contact limit is a support construct, not an access construct. The limit on Authorised
Support Contacts in SLA-GL-001 clause 12.6 governs who may escalate. It is unrelated to the Trust Center
credential limit in POL-GL-500 and unrelated to the number of hospital users of the Platform, which is
not capped.
Pensieve publishes this because a Ticket that contains these things is materially more likely to be fixed on first contact, and the hospital's own clock is the one that benefits.
3.1 A Ticket should carry: the hospital and site; the affected department and workflow; what was expected and what happened; the exact time it started; whether it affects one user, one department or everybody; the identifier of one affected record (never its clinical content); whether a workaround exists; and what changed recently on the hospital's side, if anything.
3.2 Never put patient data in a Ticket. Use record identifiers. Pensieve support personnel can retrieve
the record through the audited access path in DIS-GL-033; they should not receive clinical content by
e-mail. A Ticket found to contain patient data is redacted and the sender told.
3.3 Severity is claimed by the Customer and confirmed by Pensieve. The Customer states the Severity it
believes applies. Pensieve works the Ticket at the claimed Severity until it is agreed otherwise, and never
downgrades a Severity 1 without telling an Authorised Support Contact and recording the reason. The
catalogue of what counts as which Severity is SLA-GL-001 Schedule B.
3.4 The Severity 1 telephone line is for Severity 1. Using it for anything else is not a breach of anything, but it does not accelerate the other Ticket, and it degrades the line for the hospital that needs it next.
4.1 What escalation does. Escalation adds seniority and decision-making authority to a Ticket. It does
not add engineers Pensieve does not have, and Pensieve will not pretend otherwise (see 10).
What it does add is a named person who can authorise an out-of-cycle release, a rollback, a restore from
backup, a break-glass access under POL-GL-134, an on-site visit, or a commercial decision.
4.2 The ladder.
| Level | Role | Engaged automatically at | Also engaged on Customer request when | Authority added |
|---|---|---|---|---|
| E-1 | Support Engineer | On receipt of every Ticket | Not applicable | Triage, diagnosis, known-fix application, knowledge-base answer |
| E-2 | Duty Platform Engineer | Severity 1 at 30 minutes, Severity 2 at 4 hours | The response target in SLA-GL-001 clause 7 has been missed, at any Severity |
Production diagnosis, configuration change, hotfix preparation |
| E-3 | Engineering Lead | Severity 1 at 2 hours, Severity 2 at 1 business day | A Ticket has been open beyond twice its restoration target, or has been reopened twice | Out-of-cycle release, rollback, restore from backup, resource reallocation |
| E-4 | Head of Delivery / Incident Commander | Severity 1 at 4 hours, Severity 2 at 2 business days | Any Severity 1, immediately, on the Authorised Support Contact simply asking | Incident command, hospital-wide communication, on-site dispatch, invocation of POL-GL-112 |
| E-5 | Director |
Severity 1 at 8 hours, Severity 2 at 5 business days | The hospital's own executive has escalated, or a Ticket has become a commercial dispute | Commercial remedy, contractual decision, anything at all |
The named holder of each level for a given hospital, with direct telephone numbers, is SLA-GL-001
Schedule C.2. The times in the "engaged automatically" column are reproduced from that Schedule; where they
differ, the Schedule governs.
4.3 Escalation is a right, not a favour. An Authorised Support Contact may escalate to any level at any time by saying so, in the Ticket or by telephone. No justification is required and none will be asked for. Pensieve records the escalation in the Ticket, states who now owns it, and gives a next-update time.
4.4 Automatic escalation happens without the Customer asking. The Support Center applies the times in 4.2 mechanically. A hospital should never have to chase a Severity 1 to make it move; if it does, that is itself a defect in Pensieve's process and is reportable under 11.
4.5 Update cadence during an escalated Ticket. While a Severity 1 is open, Pensieve gives an update every 60 minutes to the Authorised Support Contacts and posts to the status page where the cause is shared across hospitals. For a Severity 2 the cadence is every business day. An update that says "no change, still investigating, next update at HH:MM" is a valid update; silence is not.
4.6 Escalating in the other direction. Pensieve escalates to the hospital when a Ticket is blocked on
the hospital: an unavailable contact, an unapproved change window, a third-party credential that has
expired. The hospital's escalation ladder is SLA-GL-001 Schedule C.4. A Ticket blocked on the hospital is
placed in a Customer Action Pending state, and the SLA clock is paused in accordance with SLA-GL-001
clause 7, with the pause recorded and visible in the Ticket.
| The thing | Goes to | Governed by |
|---|---|---|
| Invoice, credit note, refund, Service Credit claim | info@pensievelabs.org |
POL-GL-063, FIN-IN-003 |
| Price increase or renewal terms | Your named Pensieve contact, then E-5 | POL-GL-065 |
| A capability being withdrawn or deprecated | Support Center; escalation at E-3 | POL-GL-064 |
| A suspected personal-data breach | info@pensievelabs.org and the Severity 1 telephone |
POL-GL-112, DIS-GL-016 |
| A data-protection right or complaint | info@pensievelabs.org |
POL-GL-066 |
| A subprocessor objection | info@pensievelabs.org |
POL-GL-055 |
| A dispute the escalation ladder has not resolved | info@pensievelabs.org |
MSA-IN-001 dispute resolution |
5.1 A grievance is not a Ticket and a Ticket is not a grievance. A hospital that raises a service
problem as a grievance under POL-GL-066 will be answered, but it will be answered more slowly than the
same problem raised as a Ticket, because the grievance process is designed for a different purpose. This is
stated so that nobody chooses the slower route by accident.
6.1 The list of work that is chargeable rather than included: new build, bulk data work, restoration of
data a hospital user deleted, work caused by unnotified changes, re-integration after a third party changes
its interface, additional training cohorts, on-site attendance, unsupported browsers, is SLA-GL-001
clause 12.4. It is not restated here and it does not change.
6.2 The two-hour rule. Where a problem appears to originate on the hospital's side of the Platform
Boundary, Pensieve spends up to two hours per Incident helping to isolate it, free, before anything becomes
chargeable (SLA-GL-001 clause 12.3). Pensieve does not spend that time arguing about whose problem it is.
6.3 Third-party systems. Pensieve supports the Platform's side of every integration. It does not
support the third party's system, and it holds no credentials of its own for ABDM, NHCX, payment gateways,
insurers or laboratories; those are the hospital's, supplied under ADD-GL-007 and used on the hospital's
own authority. Responsibility is allocated in DIS-GL-026 for ABDM and NHCX and in ADD-GL-007 for
everything else. Pensieve will still take the Ticket, still diagnose it, and still tell the hospital
exactly what to say to the third party.
A prospective hospital is not left to wait for a sales cycle to answer a technical question.
7.1 Security, privacy, architecture and compliance questions are answered from the Trust Center. The
majority are already answered in a published document; the questionnaire master answers are QRE-GL-008.
7.2 A question the Trust Center does not answer is answered by e-mail within two business days, or, where the answer requires work, with a date by which it will be answered.
7.3 During a pilot under ADD-GL-013, support is provided as recorded in that agreement. A pilot does
not carry Service Credits.
7.4 Nothing in this clause is a commitment capable of being relied upon commercially; it is a statement of how Pensieve operates.
8.1 For the period after go-live recorded on the Order Form, Pensieve operates hypercare: a raised
support posture with a named engineer, a daily check-in, and shortened internal escalation triggers.
Hypercare is operated under RBK-GL-015 and exits against CRT-GL-008.
8.2 Hypercare does not change the contractual Severity definitions, response targets or Service
Credits in SLA-GL-001. It changes Pensieve's internal posture, not the hospital's entitlement. Saying
otherwise would be a promise that quietly expires.
For DM-1 and DM-2 this Policy applies without variation.
Pensieve is a small team. A hospital is entitled to know what that means before it depends on the Platform.
| What a hospital may reasonably ask | The honest answer today | Target |
|---|---|---|
| Is there a 24×7 staffed support desk? | No. There is a 24×7 on-call rota reachable on the Severity 1 telephone line. Severity 1 is answered at any hour; Severity 3 and 4 are worked in business hours. | Staffed desk when volume justifies it; no date committed |
| Is support follow-the-sun across time zones? | No. All support personnel are in a single time zone, disclosed in DIS-GL-033. |
Not planned |
| How many people can hold E-2? | More than one, and the rota is published internally. Key-person exposure is assessed in STM-GL-324. |
Not applicable |
| Is there a published first-response median? | Not yet. Pensieve has insufficient operating history to publish a meaningful median without misleading. | First publication in the Transparency Report (POL-GL-068) at Roadmap transparency report target |
| Is the Support Center knowledge base complete? | No. It is built out as capabilities ship, and gaps are answered by a person rather than an article. | None |
| Is support outsourced? | No. No third party answers a Pensieve Ticket. The subprocessor list is DIS-GL-009. |
None |
10.1 Pensieve does not offer a support tier it cannot staff. Where a hospital requires a staffed desk or a named dedicated engineer, that is a priced item on the Order Form and is only offered where Pensieve can actually deliver it.
Each statement below is auditable. Evidence is available to a Customer under DPA-GL-001 clause 15 and to
an assessor under ADD-GL-001 clause 15.
| # | Testable statement | Evidence |
|---|---|---|
| T-1 | Every Ticket receives an E-1 owner on receipt | Ticket audit trail, sampled monthly |
| T-2 | Automatic escalation fires at the times in 4.2 without human action | Support Center escalation configuration and fired-escalation log |
| T-3 | No Severity 1 is downgraded without a recorded reason and notice to an Authorised Support Contact | Ticket history, all Severity 1 Tickets, every month |
| T-4 | Severity 1 updates are issued at least every 60 minutes while open | Ticket update timestamps |
| T-5 | A misrouted request is re-routed within one business day and its original arrival time preserved | Cross-channel intake log |
| T-6 | No Ticket contains patient clinical content | Quarterly keyword sweep of Ticket bodies, with redaction record |
| T-7 | Clock pauses are recorded with a reason and are visible to the Customer | Ticket state history |
| T-8 | The Support Center contains no statement inconsistent with SLA-GL-001 |
Semi-annual review, recorded against POL-GL-502 |
11.1 Failure of T-2 or T-4 is treated as an internal incident, logged in REG-GL-203, because a
hospital finding out for itself that escalation did not fire is the worst way to discover it.
12.1 This Policy is reviewed annually and on any material change to SLA-GL-001, under POL-GL-502.
12.2 A change that reduces what a hospital gets, such as removing a channel, lengthening an escalation trigger, narrowing who may escalate, takes effect 60 days after notice to Customers. A change that adds or clarifies takes effect on publication.
12.3 This Policy never varies SLA-GL-001. A commitment appears in SLA-GL-001 or it does not exist.
| Document | Relationship |
|---|---|
SLA-GL-001 Service Level Agreement |
The contractual commitment. Source of truth for severities, targets, credits, contacts |
Support Center: [TO BE SUPPLIED] |
The operational channel. Source of truth for how-to content and the supported device matrix |
POL-GL-050 Terms of Service |
Incorporates this Policy by reference for Platform users |
POL-GL-059 Vulnerability Disclosure Policy |
Security reports, which never go through support |
POL-GL-066 Grievance Redressal Policy |
Data-protection complaints and the Grievance Officer |
POL-GL-067 Legal and Law Enforcement Request Policy |
Demands for data |
POL-GL-063 Refund, Credit and Service Credit Policy |
Money coming back |
POL-GL-064 Product End-of-Life and Deprecation Policy |
Withdrawal of a capability |
RBK-GL-015 Hypercare Runbook, CRT-GL-008 Hypercare Exit Certificate |
The post-go-live posture |
ADD-GL-008 On-Premise Supplement, ADD-GL-009 Delegated Cloud Access Agreement |
DM-4 and DM-3 variations |
DIS-GL-033 Remote Access and Support Model |
Where support personnel are, and how they reach a tenancy |
POL-GL-068 Transparency Report |
Where support statistics will first be published |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 2026-08-01 | Delivery | First published version. Establishes the three-property boundary, the audience routing table with a wrong-door rule that preserves statutory clocks, the five-level escalation ladder with automatic triggers and an unconditional customer right to escalate, DM-3 and DM-4 variants including clock suspension where Pensieve cannot act, an honest maturity table stating that there is no staffed 24×7 desk and no published response median, and eight testable statements with named evidence. |
POL-GL-056 v1.0.0 | Last Modified On 01 August 2026 | Review due
31 July 2027 | Published at https://trust.pensievelabs.org