AI Doctrine: How Rōvn Uses AI
Status: July 2026 · aligned to canon generation 8.
TL;DR: Rōvn's AI is the labor layer, not the judge. The governing sentence is non-negotiable: AI compresses the work. Source systems prove the facts. Humans make every credentialing, privileging, hiring, and clinical decision. Agents operate under explicit authority, typed tools, budgets, and receipts. This doctrine is written to survive a hospital General Counsel reading it line by line.
1. The authority model
| Actor | Authority |
|---|---|
| Worker | Controls Passport sharing, corrections, disputes, preferences, and worker-agent authority |
| Source or issuer | Proves the fact within its legitimate authority |
| Organization | Authors its requirements and owns hire, credential, privilege, assignment, and coverage decisions |
| Named human | Makes and signs the regulated decision for the organization |
| Rōvn Trust Layer | Enforces permissions, tenant isolation, provenance, workflow, policy versions, disputes, and receipts |
| AI agents | Extract, chase, reconcile, monitor, explain, route, and prepare. They do not invent facts and do not make regulated decisions |
2. What agents may do
- detect risk and create or update Resolution Cases;
- request missing evidence and chase workers and organizations;
- extract and reconcile documents;
- perform allowed source checks and preserve the receipts;
- draft communications for human approval;
- prepare files, packets, and explanations of gaps;
- monitor expirations and changes and compute impact;
- prepare recommendations and version-bound external actions.
3. What agents may never do
- invent evidence, or mark uploaded evidence source-verified;
- independently hire, reject, credential, privilege, or take any adverse action;
- independently assign a worker to any work context;
- exceed consent or cross tenant boundaries;
- silently fall back to an unapproved model or tool;
- mutate regulated state outside typed domain commands and approval gates;
- use protected characteristics or hidden reliability scores anywhere. Ranking, where it exists, may use only job-relevant, explainable, human-authored requirements, and any agent-contact or ranking surface ships only after the published bias audit gate is met.
4. Three-party architecture
- Worker Agent: acts only for the worker under explicit consent and standing preferences.
- Organization Workforce Agent: operates only from organization-authored policy and delegated authority.
- Neutral Rōvn Trust Layer: enforces identity, consent, scope, policy, provenance, tenant isolation, human gates, disputes, and receipts.
The experience may feel like two agents coordinating. The legal and technical authority is deliberately asymmetric, and the trust layer sits between them.
5. The agent runtime
The agent control plane is designed around durable workflow cases and steps, typed tool calls, budgets and rate limits, model and prompt versioning, separation of duties, least-privilege credentials, PHI classification, approval tasks, idempotency and replay safety, dead-letter recovery, and complete trace records. Every agent action that matters produces a receipt: what the agent did, what evidence it used, whether human review is required or complete, and the audit reference.
6. Model providers, honestly stated
- The platform's agent runtime is model-agnostic. Anthropic-first is a routing choice, not a hard dependency.
- Document extraction structures fields; it never becomes the source of truth.
- PHI or regulated data may reach a provider only after the contractual, configuration, minimization, and logging gates are satisfied. No such real-data traffic exists today: the product operates on synthetic data behind a fail-closed real-data gate.
- This investor room's own agent is a separate, narrower system: Google Cloud Vertex AI running Gemini 2.5 Flash, grounded in the hash-pinned generation 8 canon, served same-origin. It answers diligence questions; it has no access to product data.
7. No specialist-model claim yet
Rōvn does not build a foundation model, and it claims no proprietary model accuracy advantage today. The intended compounding asset is the exception-resolution and outcome-labeled dataset that operating the workflow produces, plus specialist models trained on it later. That claim becomes real only with a held-out evaluation set, a raw frontier-model baseline, a measured Rōvn specialist result, and error analysis. Until that exists, the AI moat is prospective, and this room says so.
8. What every AI surface must show
- what the AI did;
- what evidence it used;
- whether human review is required or complete;
- a receipt or audit reference;
- a clear decision boundary.
If any surface drifts toward AI-decides framing, source-substitute framing, or human-removed framing, it is reverted before ship.