Free exploration · authored contracts only

Explore the system

Select a capability. The atlas keeps its topology while the chosen X-ray lens reveals a different kind of evidence. Nothing here is an arbitrary integration builder.

X-ray lens

Minimum payloads and active routes

Logical map of the Rivermark Demonstration NetworkTwenty separately authoritative synthetic capabilities connected through an interoperability layer. Active routes are shown only when both endpoints participate in the current context. The chosen lens separately emphasizes its relevant evidence. A complete table follows the map.
Payload route Every highlighted line is an invoked sender-to-receiver contract.
  • Registration message enters the exchange: community-app to iol, in selected contract view; both endpoints are in selected contract view.
  • Clinic request or artifact enters the exchange: clinic-ehr to iol, in selected contract view; both endpoints are in selected contract view.
  • Hospital requests a permitted shared summary: hospital-ehr to iol, in selected contract view; both endpoints are in selected contract view.
  • Laboratory receives an order or returns a result: laboratory to iol, in selected contract view; both endpoints are in selected contract view.
  • Pharmacy submits a minimum supply event: pharmacy to iol, in selected contract view; both endpoints are in selected contract view.
  • The sending system credential is checked: iol to authentication, in selected contract view; both endpoints are in selected contract view.
  • Worker, organization, location and service are related: iol to interlinking, in selected contract view; both endpoints are in selected contract view.
  • Identity evidence is evaluated: iol to entity-matching, in selected contract view; both endpoints are in selected contract view.
  • Purpose and disclosure policy are evaluated: iol to policy, in selected contract view; both endpoints are in selected contract view.
  • Local and enterprise identity links are queried: iol to client-registry, in selected contract view; both endpoints are in selected contract view.
  • Canonical facility status and endpoint are queried: iol to facility-registry, in selected contract view; both endpoints are in selected contract view.
  • Canonical worker role and status are queried: iol to health-worker-registry, in selected contract view; both endpoints are in selected contract view.
  • A versioned semantic mapping is requested: iol to terminology-service, in selected contract view; both endpoints are in selected contract view.
  • A fictional product identity is resolved: iol to product-catalogue, in selected contract view; both endpoints are in selected contract view.
  • A redacted operation event and derivation evidence are recorded: iol to audit-evidence, in selected contract view; both endpoints are in selected contract view.
  • A permitted normalized clinical subset is read or written: iol to shared-health-record, in selected contract view; both endpoints are in selected contract view.
  • A periodic minimized aggregate is exported: iol to hmis, in selected contract view; both endpoints are in selected contract view.
  • A minimum supply event changes represented stock: iol to lmis, in selected contract view; both endpoints are in selected contract view.
  • A separate fictional eligibility or claim state is exchanged: iol to finance-insurance, in selected contract view; both endpoints are in selected contract view.

Active station spine

Trust lens guardrail

This visualizes decisions and evidence.

It does not implement real identity proofing, authentication, encryption, authorization, consent enforcement, key management, legal compliance, or tamper-resistant audit storage. A successful technical check does not certify clinical appropriateness or good care.

Complete architecture, in document order

Text equivalent of the logical atlas. Each capability owns different facts.

All twenty logical capabilities in the Rivermark Demonstration Network
CapabilityRoleAuthoritative forExplicitly not authoritative for
Community apppoint of serviceCaptures a small synthetic registration artifact in a field workflow.
  • Its local workflow and locally asserted source artifact
  • Enterprise identity
  • Longitudinal clinical history
Clinic EHRpoint of serviceOwns Lumenbank Clinic local identity, encounter, order, and result workflow context.
  • Local patient identifier
  • Local order and encounter context
  • Enterprise identity
  • Complete longitudinal history
Hospital EHRpoint of servicePerforms a later permitted cross-town identity query and limited summary retrieval.
  • Eastbridge local workflow and local records
  • Other facilities’ source records
  • Exchange-wide policy
Laboratorypoint of serviceReceives a normalized order and asserts an immutable synthetic result.
  • Its source result, performer, and source version
  • Enterprise identity linkage
  • Whether downstream access is permitted
Pharmacypoint of serviceCreates a minimum dispense or supply event after resolving product identity.
  • Its local dispense workflow
  • Catalogue definition
  • LMIS stock balance
  • Full clinical history
Interoperability LayerinteroperabilityAuthenticates systems, invokes policy, validates, routes, mediates, orchestrates, logs, queues, and replays.
  • Operational routing evidence
  • Toy retry and replay state
  • Clinical truth
  • Enterprise identity
  • Longitudinal patient record
AuthenticationtrustReturns a clearly simulated sending-system credential outcome.
  • Toy credential validity outcome
  • Authorization
  • Clinical appropriateness
  • Worker status
InterlinkinginteroperabilityVerifies authored practitioner-role, organization, location, and service relationships.
  • The represented relationship view and its version
  • Underlying facility or worker facts
  • Authentication
Entity matchinginteroperabilityRepresents exact, possible, ambiguous, and no-match identity outcomes.
  • Toy match evidence and outcome
  • Clinical facts
  • Automatic truth in ambiguous cases
Client RegistryreferenceLinks retained local identifiers to one synthetic enterprise client identity.
  • Synthetic enterprise identity and linkage history
  • Clinical observations
  • Access policy
Facility RegistryreferenceReturns canonical facility identity, hierarchy, operational status, services, and endpoint.
  • Facility identity, hierarchy, status, services, endpoints, and versions
  • Patient records
  • Worker authentication
Worker RegistryreferenceReturns canonical synthetic worker identity, role, status, and facility relationship.
  • Worker identity, workforce role, status, relationships, and versions
  • Request authentication
  • Access grant
  • Clinical appropriateness
TerminologyreferenceValidates a tiny code set and governs versioned semantic mappings.
  • Represented code systems, value sets, concept maps, and mapping versions
  • Medical correctness
  • Patient data
  • Structural wire transformation
Product CataloguereferenceResolves a fictional local pack to a canonical fictional product identity.
  • Represented product definition and local product mapping
  • Stock quantity
  • Patient clinical chart
Shared Health RecordclinicalStores a normalized, operational, person-centric subset of shared clinical artifacts and versions.
  • The normalized shared subset and its version history
  • Everything in every source system
  • Warehouse aggregates
  • Stock or claims
HMISpopulationOwns a later periodic aggregate reporting fact without patient drill-through.
  • Represented aggregate report state
  • Patient-level clinical artifacts
  • SHR mutation
  • Automatic anonymity
LMISsupplyApplies an idempotent stock decrement and may issue a replenishment signal.
  • Represented stock, supply, and replenishment state
  • Product definition
  • Complete clinical chart
Finance & insurancefinanceOwns entirely fictional eligibility, claim, and finance states.
  • Toy eligibility and claim workflow state
  • Clinical record
  • Medical correctness
  • Real benefits or prices
PolicytrustEvaluates an authored requester, role, organization, purpose, category, time, and directive input.
  • Toy policy decision and obligations
  • Clinical appropriateness
  • Authentication
  • A universal consent model
Audit & provenanceevidenceKeeps separate evidence of security/operational events and artifact derivation.
  • Toy audit events and provenance records
  • Prevention
  • Clinical truth
  • Immutable or tamperproof storage