Search all 478 artefacts by title, document ID or content.
Printed on the legal letterhead. Page furniture, margins and repeating table headers come from the same stylesheet the PDF service uses.
Edsol Edtech Pvt. Ltd.
Pensieve Labs | Pensieve
POL-GL-060
v1.0.0 | 01 August 2026
POL-GL-060 | Version 1.0.0 | Effective 01 August 2026 | Last Modified On 01 August 2026
Three documents cover artificial intelligence in Pensieve, and they do different jobs. Reading
the wrong one produces the wrong answer.
| Document | Answers |
|---|---|
DIS-GL-027 AI/ML Feature Disclosure |
What exists. The dated inventory of every capability that uses a model, what data it sees, and the limitations |
POL-GL-132 AI Governance and Model Risk Policy |
How Pensieve governs it internally. Model inventory, approval, change control, risk assessment |
| This Policy | How it may be used: by hospital staff, by Pensieve personnel, and by the Platform itself |
Nothing here is restated from the other two. The feature inventory is not reproduced, because a copied inventory goes stale.
The governing commitment: every artificial-intelligence capability in
Pensieveis assistive. A person decides. The Platform does not.
This Policy binds Edsol Edtech Pvt. Ltd. personnel, every user of the Platform, and every capability of the
Platform, in all four deployment models. Where an artificial-intelligence capability is enabled, the AI and
Automated Processing Addendum (ADD-GL-006) is the contractual instrument and governs if it and this
Policy differ.
| Deployment model | Note |
|---|---|
DM-1, DM-2 |
In full. |
DM-3 |
In full. Inference location follows the deployment; DIS-GL-027 Section 6 states the per-model position. |
DM-4 |
In full for capability that runs in the deployment. A capability requiring an external model provider is unavailable in a disconnected DM-4 deployment and is not silently degraded: it is absent, and the hospital is told. |
These are the rules. Everything after this clause is detail.
1.1 A person decides. No output of an artificial-intelligence capability is, or becomes, a decision. Every consequential action (clinical, financial, employment-related or otherwise affecting a person) is taken by a named human being who is accountable for it and who can see what the capability suggested and what it drew on.
1.2 No clinical decision, ever. No capability diagnoses, triages, prescribes, doses, or determines
treatment. DIS-GL-028 is the boundary and it is not moved by this Policy, by an Order Form, by a
configuration, or by a request from a hospital. A hospital cannot opt into having the Platform make a
clinical decision.
1.3 It is always visible that a machine produced it. An output produced or materially shaped by a model is labelled as such at the point of use, with the capability, the model version and the time. Pensieve does not present machine-generated content as though a person wrote it, and no configuration removes the label.
1.4 The hospital's data trains nothing. Customer data is not used to train, fine-tune, evaluate or
improve any model, for that hospital or for anybody else. The commitment and its reasoning are in
DIS-GL-027 Section 4 and it is contractual in DPA-GL-001. This Policy adds one thing: no Pensieve employee
may seek a hospital's permission to relax it as part of a commercial negotiation.
1.5 Everything is auditable. Every invocation of a capability that touches personal data is logged
under DIS-GL-013: who, when, on what record, which capability, which model version. A suggestion that
influenced a decision can be reconstructed afterwards.
"Human in the loop" is meaningless unless it says who, and when.
| Class of capability | Required oversight | Enforced how |
|---|---|---|
| Produces text a clinician will sign: transcription, summarisation of the record | The clinician reads and signs. An unsigned output is not a clinical record and is visibly marked as a draft | The Platform will not treat an unsigned draft as a record |
| Suggests a code, a tariff or a claim line | A coder or billing user accepts, edits or rejects each suggestion. Bulk acceptance without review is not offered | No bulk-accept control exists |
| Ranks, sorts or highlights work: queues, exceptions, follow-ups | The user sees the whole list, not only the ranked subset, and can see why an item was highlighted | Unfiltered view always available |
| Forecasts or projects: demand, stock, cash | Treated as an input to a human plan. No automatic ordering, no automatic write-off | No autonomous transaction is generated |
| Searches the record in natural language | Returns only records the user is already permitted to see, under the same authorisation as any other read | Existing access control, unchanged |
2.1 No capability may be configured to act without a person, and Pensieve does not build an "auto-approve" control for any of the above. Where a hospital asks for one, the answer is no, and the reason is this clause.
2.2 Named accountability. For each artificial-intelligence capability it enables, the hospital records
the role accountable for its outputs. For clinical-adjacent capability, that is the hospital's clinical
governance lead. The record lives with the enablement record under POL-GL-058 5.4.
Binding on every user of the Platform, in addition to ADD-GL-004 and ADD-GL-005.
3.1 Do not rely on an output as a clinical decision, or record one as though a clinician made it.
3.2 Do not disable, hide, crop or paraphrase away the machine-generated label at 1.3 when copying an output into another system or a printed document.
3.3 Do not copy patient data out of the Platform into an external artificial-intelligence tool: a public chatbot, a transcription service, a coding assistant. That is a disclosure of patient data to a third party under the hospital's own controllership, and it is outside everything Pensieve has assessed. Where a hospital wants such a capability, it should ask for it inside the Platform, where it is governed.
3.4 Do not use an output to make a decision about a person's employment, credit, insurance or access to care.
3.5 Do not attempt to make a capability produce content outside its purpose, or to extract training data, model weights or system instructions from it.
3.6 Do not present Platform-generated content to a patient as clinical advice.
4.1 Build a capability that takes a clinical decision, however configured, however requested, however priced.
4.2 Train on customer data (see 1.4).
4.3 Allow a model available to one hospital to see or learn from another hospital's data
(DIS-GL-027 Section 4).
4.4 Send personal data to a model provider that reserves a right to train on it. Where a third-party
provider is used, the position for each provider is in DIS-GL-027 Section 5 and the provider is a sub-processor
listed in DIS-GL-009, notified under POL-GL-055.
4.5 Publish an accuracy, sensitivity or specificity figure Pensieve has not measured, or imply clinical
validation that has not happened (DIS-GL-027 Section 9).
4.6 Enable an artificial-intelligence capability in a hospital's tenancy without the hospital enabling
it. Every such capability is opt-in and reversible (DIS-GL-027 Section 7).
4.7 Use an artificial-intelligence capability to make a decision about a hospital, a credit
decision, a support prioritisation that disadvantages it, a renewal price, without a person deciding.
POL-GL-065 3.8 is the related commitment on pricing.
4.8 Use a hospital's data, or a model derived from it, in Pensieve's own research or product development
without the ethics review that DIS-GL-027 Section 8 describes and, in most framings, participant consent.
Pensieve does not do this today at all.
5.1 A person about whom a decision is made is entitled to know that an artificial-intelligence capability was involved. Because of 1.1, the answer is always that a person decided and a capability assisted; the assistance is nonetheless disclosed.
5.2 Data-protection rights (access, correction, erasure, grievance) are exercised under POL-GL-053
and POL-GL-066. Where the individual is a patient, the hospital is the Data Fiduciary and the request is
made to the hospital; Pensieve assists it under DPA-GL-001.
5.3 Where a jurisdiction confers a specific right in relation to automated decision-making, that right is honoured in that jurisdiction. Pensieve's design position, that there is no solely automated decision producing a legal or similarly significant effect, means the right rarely bites, and Pensieve says so rather than claiming an exemption.
5.4 A person may complain about an artificial-intelligence capability directly to
info@pensievelabs.org, whether or not they are a Pensieve customer.
Each of these is a gate, and each produces a record. The internal mechanism is POL-GL-132; the gates are
published here so a hospital can ask for the evidence.
| Gate | Record produced |
|---|---|
| Purpose, limits and the human decision point are written down before development | Model inventory entry, POL-GL-132 |
| Data protection impact assessment where personal data is processed in a new way | REP-GL-020 |
| Record of Processing Activities updated | REG-GL-206 |
| Sub-processor assessed and notified where a third-party provider is used | REG-GL-212, DIS-GL-009, POL-GL-055 |
| Feature added to the public inventory before it is enabled for any hospital | DIS-GL-027 Section 2 |
| Security review, as for any release | POL-GL-118 |
| Clinical safety boundary re-checked | DIS-GL-028 |
6.1 The inventory is published before enablement, not after. A hospital should never find a capability
in the Platform that is not in DIS-GL-027.
| Question | The honest answer today | Target |
|---|---|---|
| Has any capability been clinically validated? | No. None is a medical device, none makes a clinical decision, and no validation study has been performed. | Not applicable while 1.2 holds |
| Are accuracy figures published? | No. Pensieve has not measured them at a scale that would make publication honest. | Published per capability once measured; no date committed |
| Is bias testing published? | No. DIS-GL-027 Section 9.5 states the position. |
With the accuracy figures |
| Has any third party assessed these capabilities? | No independent assessment has been performed. | Included in the scope of the first independent security assessment at Roadmap pentest target |
| Is there an AI ethics committee? | No. Pensieve is too small for one to be more than a formality. Decisions are made by the Director against POL-GL-132, and recorded. |
External review when headcount justifies it |
| Is any capability certified under an AI standard? | No. Pensieve holds no certifications of any kind. | None |
| # | Testable statement | Evidence |
|---|---|---|
| T-1 | Every capability using a model appears in DIS-GL-027 with a date preceding its first enablement |
Inventory against feature-flag history |
| T-2 | Every model-generated output carries a label with capability, model version and time | Interface review and rendered-output sampling, each release |
| T-3 | No bulk-accept or auto-approve control exists for any suggestion class in 2 | Interface inventory review |
| T-4 | No customer data appears in any training, fine-tuning or evaluation dataset | Dataset provenance records; pipeline configuration |
| T-5 | Every invocation touching personal data is logged with user, record, capability and model version | Audit log sampling under DIS-GL-013 |
| T-6 | Every enabled capability has a named accountable role recorded at the hospital | Enablement records, 100% |
| T-7 | No published material states an accuracy figure that is not in a measurement record | Annual review of marketing and Trust Center content |
8.1 Failure of T-1, T-3 or T-4 is a serious internal incident, logged in REG-GL-203 and reported to the
affected hospitals.
9.1 Reviewed semi-annually under POL-GL-502, in step with POL-GL-132, because this area moves
faster than the annual cycle.
9.2 A change that would weaken 1.1, 1.2 or 1.4 is not a policy change; it would be a change to what Pensieve is, and would be notified to every Customer sixty (60) days in advance with the reasoning published.
| Document | Relationship |
|---|---|
DIS-GL-027 AI/ML Feature Disclosure |
The dated inventory, the third-party providers, the limitations |
POL-GL-132 AI Governance and Model Risk Policy |
Internal governance, model inventory, change control |
ADD-GL-006 AI and Automated Processing Addendum |
The contractual instrument where a capability is enabled |
DIS-GL-028 Clinical Safety Boundary Statement |
The boundary this Policy will not move |
ADD-GL-004 Acceptable Use Policy, ADD-GL-005 Use Case Restrictions |
The wider conduct rules |
DPA-GL-001 Data Processing Agreement |
The contractual no-training commitment |
POL-GL-055 Sub-Processor Notification and Objection Terms |
Model providers as sub-processors |
POL-GL-058 Beta and Early Access Terms |
Where a capability is pre-release |
POL-GL-053 Privacy Policy, POL-GL-066 Grievance Redressal Policy |
Individual rights and complaints |
REP-GL-020 DPIA Template and Exemplar, REG-GL-206 Record of Processing Activities |
The pre-ship gates |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 2026-08-01 | Founder / Pensieve Labs | First published version. Separates rules of use from the feature disclosure and the internal governance policy; states five rules with a person always deciding; makes human oversight concrete per capability class and records that no auto-approve control exists; forbids employees from negotiating away the no-training commitment; lists what Pensieve will not build; states honestly that nothing is clinically validated, no accuracy or bias figures are published and no independent assessment has occurred; and lists seven testable statements. |
POL-GL-060 v1.0.0 | Last Modified On 01 August 2026 | Review due
31 January 2027 | Published at https://trust.pensievelabs.org