Loading workspace…
no identity configured
Every requirement in bioskepsis-insights-user-requirements-v1.1.md, with the verdict the document’s own rules force. No requirement now carries the verdict BLOCKED. Each row carries both halves of its account, what is buildable and what is still held, and names the decisions that released it. A requirement answered the other way is DROPPED, and that is the one verdict nobody can go and change.
| ID | Verdict | Basis | What that means |
|---|---|---|---|
FR-DISC-01 | BUILD | stated | All of it: mechanism-of-action + indication as search inputs, an expert-to-mechanism/indication link built from the stated literature sources (OpenAlex primary, Semantic Scholar fallback, per 1.4), and a ranked result list. No open_questions entry is listed on this requirement. Still held. None of the requirement itself. Two boundaries the build must respect: (a) the ranking must be plain literature-relevance ordering from the source index - any composite or weighted expert score crosses into FR-FIT-01 and needs the unstated default weights of OQ-12, which rule 0.5 forbids inventing;... |
FR-DISC-02 | BUILD | stated | All of it, in the shape the answers of 17/09/2026 gave it. The expert a pharma user meets is an anonymous card carrying profession, country and topic, and no name, no employer and no question text (OQ-05). A contact request is recorded, passed to the expert, and the identity is revealed only on acceptance, with the acceptance stored as a consent record naming the company and the wording shown (OQ-42). The link between a card and a person stays inside the signal layer, which no service outside it may read. 'Sustained and specific enquiry' is the topic score of OQ-06, built from the number, recency and specificity of questions, with the top 1.4 percent of a disease area flagged until the validation study replaces the cut-off (NP-15). Research Workspace questions feed anonymous trends only, and reach a named card solely for an academic who switched on 'contactable by pharma' (OQ-07, NP-03, FD-02). The 12 researchers of the August 2026 note are excluded from every list, card and profile (OQ-33). The negative-publication verification this build already had is unchanged and is what evidences the claim. Still held. Nothing is held by a question. One operational bound stands and is not a gate: OncoSkepsis signals are shown only once a third hospital joins (NP-01, OQ-40), so a view with nothing releasable says so, naming the minimum, rather than showing an empty result. |
FR-DISC-03 | BUILD | stated | All of it. The therapeutic area stays a first-class dimension across search, trends and profiles, and the first release ships with oncology switched on, exactly as before. What the answer adds is the order and the condition for the rest: neurology, then metabolic disease, then infectious disease, by pipeline size, and each one starts when its own signal counts meet the OQ-14 and OQ-40 minimums rather than on a date (OQ-08). An area is therefore a row and a switch, and turning one on is an operational act with a stated precondition. Still held. Nothing. The condition on a second area is a threshold this build already enforces, not a question waiting for an answer. Released by OQ-08. |
FR-DISC-04 | BUILD | stated | All of it, and it is a negative requirement, which makes it cheap: the search query builder must emit no country or region predicate unless the user sets one, and geography must be an optional facet with an empty default. No open_questions entry is listed, and no number is needed. Still held. None. One boundary: if a geography facet is later fed from the OncoSkepsis signal layer (Section 5.3 item X-06, country of the contributing clinician), that path is gated by the minimum-count questions OQ-14 and OQ-40 and is still 'Proposed'. FR-DISC-04 itself only requires the absence of a default... |
FR-DISC-05 | BUILD | stated | All of it, as two halves the answer separates. Rules over public data suggest the type: a trial registry entry as principal investigator suggests trial investigator, a guideline, society or department-head role suggests clinical leader, and mainly laboratory papers suggest translational researcher. The customer's KOL lead then confirms or changes the suggestion, and the record holds who changed it and when (OQ-09). The suggestion is never the final word and the interface must not present it as one: the decision is the customer's, and the audit trail is what makes that true rather than claimed. Still held. Nothing. No per-type score cut-off is introduced, because the answer needs none: the rules are qualitative and the confirmation is a person's. Released by OQ-09. |
FR-DISC-06 | BUILD | research | All of it. The profession is a coded field on the expert record and a filter over it, and the vocabulary is now stated: doctors and scientists, plus pharmacists, nurse practitioners, physician assistants and clinical research staff, plus the tumour-board roles of molecular biologist, clinical geneticist, bioinformatician, oncology pharmacist and clinical trial coordinator (OQ-10). No physician-only predicate survives anywhere in ingest or search. Still held. Nothing. Released by OQ-10. |
FR-DISC-07 | PARTIAL | research | All of it as stated, on a non-numeric derivation. Basis is research ([R53], [R05]) and no open_questions entry is listed, so it is not gated by 0.3 or 0.4. Buildable: an influence-scope facet with the four stated values (local, regional, national, global) on expert results, derived from data that... Still held. None of the requirement is OQ-blocked, but one sub-part is blocked by rule 0.5 and has no open question covering it: any tier rule that needs a count cutoff - how many countries, centres, collaborators or citations make an expert 'national' rather than 'regional', or 'global' rather than 'national'... |
FR-FIT-01 | BUILD | stated | Basis is stated, so rule 0.3 does not apply. Buildable now: the fit-score structure itself, scoped per (customer molecule x expert), with the four named component slots that Dimitris Kyriacou stated (mechanism relevance, indication relevance, trial record, ability to enrol) as first-class,... Still held. Nothing. Both halves are answered. The trial record is source-agnostic: whichever public sources exist for each expert are used, and the source of every trial fact is stored with it (OQ-11). The ability-to-enrol input is the count of trials in which the expert appears as an investigator in ClinicalTrials.gov or the EU trial portal, labelled on the profile as a trial count and never as a measured enrolment figure, and no investigator or site performance database is licensed (FD-01). The weights are equal at launch, 25 each across mechanism, disease, trial record and enrolment, with every customer adjustment logged and presets published once the first customers have used the product (OQ-12, NP-14). Equal weights here are a decision with a date, which is what separates them from the placeholder rule 0.5 forbids. |
FR-FIT-02 | PARTIAL | research | Fully buildable. Basis is research, which rule 0.3 does not block, and FR-FIT-02 lists no open_questions, so rule 0.4 does not bite. The requirement is a transparency mechanism: it displays whichever inputs and contributions exist rather than deciding what they are, so it needs no threshold, weight... Still held. None. One sequencing note, not a gate: the breakdown can only render the components that exist, so until OQ-11 and OQ-12 are answered it will show the mechanism-relevance and indication-relevance contributions and mark trial record and ability to enrol as not yet computed, rather than showing a... |
FR-FIT-03 | BUILD | research | All of it, and the answer is more than a yes. Weights are presets per purpose, such as evidence generation or trial-site search, a customer may adjust a preset, and every change is logged with who made it and when (OQ-12). The product ships with equal weights of 25 across the four inputs, collects how customers adjust them, and EFEVRE publishes presets once the first customers have used it (NP-14). The audit log is the part that matters commercially: a fit score whose weights changed without a record is a number nobody can defend to a compliance reviewer. Still held. Nothing. Rule 0.5 is satisfied rather than bypassed: the launch weights are a stated decision of 17/09/2026, not a value this build chose for want of one. |
FR-FIT-04 | PARTIAL | research | Fully buildable. Basis is research, which rule 0.3 does not block, and FR-FIT-04 lists no open_questions. Every field the requirement asks for is named in the requirement text itself: the user, the date and the reason for each change, over two event kinds (a change to fit-score weights, and a... Still held. None. One caution rather than a gate: the requirement states no retention period, purge window or log-review frequency, so the build must not invent one (rule 0.5) - records are kept append-only with no expiry until someone states a retention rule. |
FR-FIT-05 | BUILD | research | Fully buildable. Basis is research, which rule 0.3 does not block, and FR-FIT-05 lists no open_questions. The requirement is explicitly for segments or archetypes 'that the customer defines', so the customer supplies the taxonomy and the build supplies only the container: create, rename and delete... Still held. None for the requirement as written. Two boundaries to respect: the five-dimension archetype model in the basis_detail [R02] (interaction time, recommendation ratings, academic or community setting, accessibility, ability to drive action) is cited evidence, not a stated BioSkepsis taxonomy, so it... |
FR-RISE-01 | BUILD | stated | All of it, on a definition that is now stated rather than inferred. A rising expert is a person with a sustained topic signal on a topic, with no limit on how many papers they have published on it (OQ-13). The flag therefore reads the OQ-06 topic score and nothing else: no career-stage filter, no publication-count filter, no years-since-first-paper window. The cut-off is the top 1.4 percent of topic scores within a disease area, held in configuration because the validation study of OQ-27 replaces it with a measured one (NP-15). Still held. Nothing. The 1.4 percent is a real bound with a real source, and it is deliberately interim: it comes from the August 2026 outside-read note, which measured that rate across conversations rather than across people, and the validation study replaces it rather than ratifies it. |
FR-RISE-02 | BUILD | research | All of it. The activity-over-time display was always buildable; what was missing was the judgement it leads to. A rising, steady or falling reading now comes from the topic score's movement, on the definition OQ-13 gives and the cut-off NP-15 sets, with the percentile held in configuration so the validation study can replace it without a code change. Still held. Nothing by a question. One constraint survives and is worth keeping in sight: the movement shown is the score's, so a change in the score's inputs is a change in the reading, and the interface should say which period it covers rather than implying a trajectory the data does not carry. |
FR-RISE-03 | PARTIAL | research | The whole requirement, because it is a negative constraint rather than a calculation: any rising-expert ranking must have at least one contributing input that is not a publication metric, and a ranking whose contributing-input set is publication metrics only must be refused or suppressed.... Still held. None. The guard is buildable and testable now, independently of how 'rising' is finally defined, though it only has a ranking to act on once FR-RISE-01/FR-RISE-02 are unblocked by OQ-13. What must not be built alongside it: any input weighting, which belongs to OQ-12 (fit-score weights) and OQ-13,... |
FR-TREND-01 | BUILD | stated | All of it. Every input it needed is now stated. The accelerating designation reads the OQ-06 topic score rather than a raw question count, so 'asked more and more often' is a movement in that score. A trend is shown only when at least 8 different people stand behind it, and every displayed count is rounded to the nearest 5 (OQ-14). Time is the ISO week of a question and nothing finer (OQ-43). Topics are coded with OncoTree, HGNC, HGVS with ClinGen Allele Registry IDs, and ChEMBL, with the code list version stored on every signal (OQ-44). Research Workspace questions feed these aggregates and never a named expert (OQ-07). Still held. Nothing. Two bounds travel with it rather than holding it: the 8-person minimum and the rounding apply in every view, export, alert and API answer, not only on screen, and the differencing check of NP-10 refuses an export or an API answer whose comparison could reveal a count the minimum was meant to hide. |
FR-TREND-02 | BUILD | stated | The whole requirement, built from the engine's own literature (OpenAlex primary, Semantic Scholar fallback per 1.4): group the studies bearing on a claim in a field and mark the claim contested when studies with opposing findings both exist, showing the graded citations on each side. Defining... Still held. None on the literature-derived path. Two constraints bound the implementation rather than blocking it: any disagreement ratio, effect-size gap or minimum number of disagreeing studies would be an invented threshold (rule 0.5), so only the presence-of-opposing-findings definition may be coded; and... |
FR-TREND-03 | PARTIAL | stated | The light view, which is what the answer leaves. Topics are marked where BioSkepsis answers found thin evidence or contested evidence, built from the two evidence flags the signal layer already carries (NP-07). That is a view over flags this product holds, and it needs nothing new from anybody. Still held. The gap finder itself, permanently rather than pending: OQ-15 puts it outside this product and not as an add-on either, so no gap-finder component, no gap-finder purchase path, and no research-gap prediction beyond the two flags. This entry stays PARTIAL rather than BUILD because the requirement as written asks for research gaps likely to become papers, and what is built is thinner than that on purpose. Still held by OQ-15. Nothing is defaulted in its place. |
FR-TREND-04 | BUILD | stated | The whole requirement on the public-evidence path: rank the mechanisms in a customer-supplied competitor or mechanism set by attention volume and by change across the periods already held, using public literature and trial activity (and congress activity only once FR-TREND-06 is unblocked). A... Still held. None as a ranked comparison. Constraints that bound it: no attention threshold, input weight or fixed comparison window may be hard-coded (rule 0.5) - the window must come from the retained data or from configuration; and if the attention measure is ever drawn from OncoSkepsis query signals it... |
FR-TREND-05 | BUILD | stated | All of it, under the two minimums and the anonymity the answers set. A field signal is shown when at least 8 distinct people stand behind it (OQ-14) and, where it comes from OncoSkepsis, at least 3 distinct institutions with the 5 percent dominance check (OQ-40, NP-12). Counts are rounded to the nearest 5. Nobody is named: a pharma user sees an anonymous card, and an identity is revealed only when the expert or clinician accepts a contact request, which is stored as a consent record naming the company and the wording shown (OQ-05, OQ-42). Still held. Nothing. Below either minimum there is nothing to show, and the view says so, naming the minimum rather than rendering an empty result that reads as a quiet field. |
FR-TREND-06 | BUILD | research | All of it, on the sources the answer names: congress abstracts come from OpenAlex and Crossref, which index the ASCO, ESMO and AACR supplements, and the licence status of every record is stored (OQ-16). No society abstract licence is bought, so abstract text is used only where the record's licence allows it, which is a per record decision the stored status makes checkable rather than assumed. Still held. Nothing. One consequence to build for rather than around: spot checks in September 2026 found ASCO and AACR abstracts with text in OpenAlex and ESMO abstracts without it, so coverage is uneven by society and the view must show what it has rather than implying a complete congress record. Released by OQ-16. |
FR-EVID-01 | BUILD | stated | All of it: an evidence-question surface inside Skepsis Insights that runs a BioSkepsis engine research run and returns the brief with every claim carrying its graded citation (tier, confidence, source identifier) visible next to the claim. Still held. None. The requirement lists no open_questions entry and needs no unstated number; the citation grading scale is produced by the engine, not chosen by this build. (OQ-01 release order and OQ-02 product naming are document-wide scope questions, not part gates on this requirement.) |
FR-EVID-02 | BUILD | stated | All of it: a hard integrity screen in the answer-assembly path that removes retracted sources and hijacked-journal sources before an answer is composed, and marks corrected sources with a visible correction flag on the answer. Still held. None. No open question and no unstated number: block/flag is a binary decision, not a threshold. Choosing the retraction and hijacked-journal reference lists is a source-selection decision (the engine already runs this screening per the stated basis), not a rule 0.5 number. |
FR-EVID-03 | BUILD | stated | Display and persistence of the engine-supplied Trust Index: the 0-100 score plus its six named facets (provenance, grounding, evidence strength, reproducibility, durability, reagent validity) shown on every evidence answer and stored with the answer record, so the score displayed is the score... Still held. None for the display requirement as written. But the six facet weights are stated nowhere in this file and no open question holds them, so under rule 0.5 Insights must not re-compute or re-weight the Trust Index itself - it reads score and facet values from the engine. Likewise no pass/fail cutoff,... |
FR-EVID-04 | BUILD | stated | All of it. The default export is a PDF carrying numbered claims, a full reference list with PMIDs and DOIs, and the search method that produced the answer. A direct push into Veeva Vault MedComms or PromoMats is an option the user chooses, with each claim linked to its reference (OQ-17). The immutable versioned snapshot this build already had is what the export renders, so an exported document is a version of the record rather than a fresh answer. Still held. Nothing. The PDF is built first and the Veeva connector second, which is sequencing rather than a gate. Released by OQ-17. |
FR-PROF-01 | BUILD | inference | All of it, confirmed on 18/09/2026 and shaped by OQ-05 and OQ-18. A pharma user first meets an anonymous card: profession, country and topic, with no name, no employer and no question text. The profile proper opens only after the expert accepts a contact request, and then carries name, affiliation, specialty, the topic signal summary, the fit score, papers and trials. Optional fields appear when available: country, congress talks, guideline and society roles, grants, KOL type and last-updated dates. Every profile carries a completion score the customer can see, which sorts and scores nothing (OQ-18, NP-06). The expert may sign in with ORCID to fill the optional fields, see the topics flagged for them, and withdraw entirely (NP-06, FD-03). The 12 researchers of the August 2026 note appear nowhere (OQ-33). Still held. Nothing. Two rules travel with the profile: a withdrawal deletes the expert's stored signals, recalculates the affected totals and re-applies the minimums (OQ-34, FD-03), and tumour-board membership appears only inside a revealed profile, never on a card, an export or an API answer that precedes an acceptance (NP-02). |
FR-PROF-02 | BUILD | stated | All of it. What a pharma user sees about a named expert is settled: the anonymous card until the expert accepts a contact request, and the revealed profile after (OQ-05). Signal-derived attributes on that profile obey the same minimums as everywhere else, 8 contributors and, for anything from OncoSkepsis, 3 institutions with the dominance check (OQ-14, OQ-40). Still held. Nothing. The link between a card and a real person stays inside the signal layer, and no service outside it may read that link: the reveal is a consent record, not a lookup. |
FR-PROF-03 | BUILD | research | All of it. OQ-18 names the core set that is required: name, affiliation, specialty, topic signal summary, fit score, papers and trials. Everything else is optional and shown when available. The completion score is visible to the customer and to the expert, and no scoring or sorting rule may read it (NP-06): it exists to motivate an expert to fill their profile, and a completion score that moved rank would be a ranking of who filled in a form. Still held. Nothing. Two exclusions are permanent rather than pending: no conflict-of-interest field, flag or note anywhere (NP-09), and no payment, claims or prescribing data (OQ-28). A field fed by a paid source would need its own decision, a written licence and a visible source label (NP-05); none is licensed at launch. |
FR-PROF-04 | BUILD | research | All of it. Trend data and the API data set refresh daily, expert profiles weekly, and every profile shows its last-updated time (OQ-19). The cadences are settings rather than literals, because the answer is a deployment decision and a site that needs a different one should not need a release. Still held. Nothing. Released by OQ-19. |
FR-PROF-05 | BUILD | research | All of it, on open identifiers: ORCID researcher IDs, OpenAlex author IDs and US NPI provider numbers, plus each customer's own CRM IDs held in a per-customer mapping table (OQ-20). Identity resolution is built on those, and EFEVRE licenses no doctor reference database, so there is no third-party identifier to reconcile and no licence term to honour on a field. Still held. Nothing. A paid identifier source later needs its own decision, a written licence and a source label on every field that uses it (NP-05). |
FR-PROF-06 | DROPPED | research | Digital opinion leaders are out of scope for this product (OQ-21). No social-media tracking, no digital-opinion-leader view, no platform connector and no verification that an online voice is a clinician. This is a decision rather than a delay: a 2026 study found the most influential voices about one drug were mostly non-medical accounts, and a 2024 study found follower counts unreliable for finding opinion leaders. A caller reaching for this is told the product does not do it, not that an answer is pending. Dropped by OQ-21. The answer went the other way, so nothing here is waiting on anybody and nothing arrives later. |
FR-NET-01 | BUILD | research | All of it that this document supports: co-authorship and shared-affiliation edges over the indexed literature, with the trial record now source-agnostic and each fact carrying the source that supplied it (OQ-11). Every requirement group is in the first release (OQ-01), so nothing waits on sequencing. Still held. Shared-trial edges remain unbuilt, and not because of a question: no requirement in this document names a trial data source for FR-NET. Inventing one would be a source decision nobody has taken. |
FR-NET-02 | BUILD | inference | All of it, confirmed on 18/09/2026. The shortest path runs over the co-authorship and shared-affiliation graph FR-NET-01 already builds, and the customer's own endpoints come from the engaged-expert file they upload (OQ-23), which is what supplies 'the company's existing contacts' without a CRM connection. Still held. Nothing. One honest bound on what a path means: it is a path through public co-authorship and affiliation, so it says two people have published together or shared an institution, and never that either would take an introduction. Released by OQ-23. |
FR-ALERT-01 | BUILD | research | All of it, on the channels the answer names: a weekly email digest per user, and alerts written into the customer's CRM as tasks, for Veeva Vault CRM, Salesforce Life Sciences Cloud and IQVIA OCE (OQ-22, OQ-26). Subscriptions were already buildable; what was missing was where an alert goes and how often, and both are now stated rather than chosen here. Still held. Nothing. Every alert carries the same suppression as the view it came from: the 8-person minimum, the 3-institution minimum with the dominance check, counts rounded to 5, and nobody named without an accepted contact request (OQ-14, OQ-40, OQ-05). An alert is a delivery channel, not an exemption. |
FR-ALERT-02 | BUILD | stated | All of it. The trigger is the OQ-06 topic score crossing the NP-15 cut-off, the top 1.4 percent within a disease area, rather than a question count nobody stated. Delivery is the weekly digest and the CRM task of OQ-22. What the alert may say is bounded by the same minimums as any other view, and it names no expert who has not accepted a contact request (OQ-05, OQ-14, OQ-42). Still held. Nothing. The cut-off is configuration, because the validation study of OQ-27 replaces it with a measured one, and an alert threshold that needed a release to change is a threshold nobody will tune. |
FR-PLAN-01 | BUILD | research | All of it, and it lists no open question at all. A user can create, name, save, edit and delete a target-expert list with a stated purpose, and add or remove experts; the three purpose examples in the requirement text (advisory board, speaker programme, trial-site search) are enumerated by the... Still held. Nothing. Three cautions that are constraints rather than gates: 0.5 - no maximum list size, member cap or seat limit may be invented (OQ-31 covers the seat model); the cross-customer isolation rule is ACC-01, which is basis inference plus OQ-04, so scope every list to one customer_id and do not... |
FR-PLAN-02 | BUILD | research | All of it, and it lists no open question. The documented need and the selection criteria can be captured, authored, timestamped and stored against a list before any expert is chosen for paid work, exactly as the EFPIA (2019 text) and PhRMA Codes require [R42, R44] - including the ordering rule,... Still held. Nothing inside FR-PLAN-02. Two adjacent things must be left out: the fair-market-value record belongs to COMP-04, whose basis is inference, so 0.3 forbids building that field now; and this domain record must stay separate from the general who-viewed-what access log in ACC-04, which is also... |
FR-PLAN-03 | BUILD | research | All of it, on the mechanism the answer chose: the customer uploads a file of engaged- expert IDs and meeting dates whenever they choose, and those experts are marked as already engaged in their lists (OQ-23). Matching uses the open identifiers and the per-customer CRM mapping table of OQ-20. A live CRM import is ruled out rather than postponed, so no read connection to a customer system is built for this. Still held. Nothing. The engagement status stays something the customer's own users set or upload, which keeps the record theirs: this product never infers that a meeting happened. |
FR-PLAN-04 | BUILD | research | All of it. Insights are captured through one fixed category list, the same for every customer: evidence gap, guideline or practice change, clinical-trial interest, safety question, access or reimbursement issue, and other (NP-08). There is no free-text box anywhere in insight capture (OQ-24), and an agency account keeps each client's notes inside that client's workspace (OQ-04). Still held. Nothing. The safety category opens the customer's own safety reporting page, whose link is held in their account settings, and no side-effect content is stored here (NP-08). That is the whole of this product's role in pharmacovigilance, deliberately. |
FR-PLAN-05 | BUILD | research | All of it. A short checklist can be shown at the point of insight capture, with items taken from the stated source definition rather than invented: R23 defines an insight as a deeper understanding of the reason behind a trend that shows whether action is warranted, which yields the two checklist... Still held. No functional part. OQ-01 is the only listed open question and governs release order, not content. Three constraints: 0.5 - no score, weight or pass threshold may be invented, so nothing like 'three of four boxes means actionable' and the checklist must not gate saving; the exact checklist wording... Released by OQ-01. |
FR-PLAN-06 | DROPPED | research | The requirement asked for adverse events to be detected in free-text insights. There is no free text to detect them in: insight capture is pick-lists only (OQ-24), and the fixed category list carries a safety item that opens the customer's own safety reporting page while this product stores no side-effect content (NP-08). The requirement is replaced rather than deferred, which is why a caller is told no instead of later. SEC-06 carries what remains of the obligation. Dropped by OQ-24. The answer went the other way, so nothing here is waiting on anybody and nothing arrives later. |
FR-INT-01 | BUILD | inference | All of it, confirmed by the answer that names the formats: CSV and Excel for lists and tables, PDF for profiles and evidence answers, and JSON through the API (OQ-25). The export action exists on expert lists, profiles and trend views. Still held. Nothing, and one rule is part of the requirement rather than a caveat: every one of the four paths applies the suppression the views apply, and the differencing check of NP-10 refuses an export whose comparison could reveal a hidden count. A commercial user's export carries public-source fields only, never signals, fit scores or evidence answers, and every export is logged with user, time and content (NP-11). |
FR-INT-02 | BUILD | research | All of it. The API data set refreshes daily, which is the cadence OQ-19 states, and the cadence is configuration rather than a literal. Every requirement group is in the first release (OQ-01). Still held. Nothing. An API answer is subject to the differencing check like an export: it is refused when a comparison could reveal a count the minimums hide (NP-10). |
FR-INT-03 | BUILD | research | All of it, against the three systems the answer names: Veeva Vault CRM, Salesforce Life Sciences Cloud and IQVIA OCE, all in the first release (OQ-26, OQ-01). Read access serves expert matching; write access delivers the alert tasks of OQ-22. Still held. Nothing. What crosses into a customer's CRM obeys the same suppression as everything else, and an alert task naming an expert requires the same accepted contact request a screen does. |
FR-INT-04 | BUILD | inference | All of it, confirmed on 18/09/2026: single sign-on through SAML 2.0 or OpenID Connect, with identity-provider metadata configured per customer. This product's own identity instance already speaks OpenID Connect, so a customer's provider is a configuration of that rather than a second authentication path in this codebase. Still held. Nothing. Just-in-time provisioning stays bounded by ACC-01: a user arriving through a customer's provider joins that customer's account and no other. Released by OQ-01, the confirmation of 18/09/2026. |
FR-INT-05 | BUILD | research | All of it, and at launch it has nothing to do, which is the point: the answers license no outside data. Identity resolution runs on ORCID, OpenAlex and NPI, which are free to use, plus each customer's own CRM IDs (OQ-20), and no doctor reference database is licensed; FD-01 decides the same for enrolment data. What this requirement builds is the source register: every field carries a source label, shown on the profile and in exports, and a paid source added later needs its own decision and a written licence before a single field may use it (NP-05). Still held. Nothing. |
FR-MEAS-01 | BUILD | stated | All of it, on the design the answer gives. A cohort of flagged people is held and reported on every quarter, against matched BioSkepsis users and against a publication-based ranking. A live expert score updates quarterly; after 12 months a flagged person is given an assigned score, and each quarter after that the report shows whether the live score sits above or below it (OQ-27). This is the study that replaces the interim 1.4 percent cut-off of NP-15 with a measured one. Still held. Nothing. The comparison group and the outcome are stated in the answer rather than chosen here, which is what rule 0.5 was protecting. Released by OQ-27. |
FR-MEAS-02 | BUILD | inference | All of it, confirmed on 18/09/2026: per customer, the lead time between the date this product flagged an expert on a topic and the date of that expert's first indexed publication on it. The flag date is already recorded and the publication date comes from the indexed literature, so the measurement needs no new source. Still held. Nothing. Two honesty constraints belong to the number rather than beside it: a lead time exists only for an expert who did publish, so the report says how many flagged experts have not, and a median over a survivor set is a different claim from a median over the cohort. This is the same measurement the OQ-27 study formalises, and it is the number that evidences the product's central claim. Released by the confirmation of 18/09/2026. |
FR-MEAS-03 | PARTIAL | research | All of it. Basis is research ([R18] survey of 1,023 MSL professionals; MAPS guidance [R20], [R21] separating activity from impact metrics), the requirement lists no open_questions entry, and it needs no invented number: both metric families are counts and records over data the product already... Still held. None under rules 0.3, 0.4 and 0.5. Two conservative limits still apply: rule 0.5 forbids attaching any KPI target, benchmark or threshold to these metrics, since no target is stated in the file, so the report must present bare counts rather than a rating or a red/amber/green judgement; and the... |
FR-MEAS-04 | BUILD | inference | All of it, confirmed on 18/09/2026: per expert, the scientific topics on which company engagement took place. The engagement records come from the customer's own uploaded file (OQ-23) and the topics from this product's coded vocabulary, so nothing here needs a source it does not have. Still held. Nothing, and the requirement's own exclusion stands as written: no prescribing data and no sales data, which OQ-28 makes a product-wide rule rather than a local one. |
X-01 | BUILD | inference | The cancer type named in a question, coded with OncoTree, whose code list version is stored on every signal (OQ-44). Still held. Nothing. Shown only above both minimums: 8 distinct contributing people (OQ-14) and 3 distinct institutions with the 5 percent dominance check (OQ-40, NP-12), with counts rounded to the nearest 5 and the differencing check refusing an export or API answer whose comparison could reveal a hidden count (NP-10). |
X-02 | BUILD | inference | The gene named in a question, as an HGNC symbol (OQ-44), confirmed on 18/09/2026. Still held. Nothing. Shown only above both minimums: 8 distinct contributing people (OQ-14) and 3 distinct institutions with the 5 percent dominance check (OQ-40, NP-12), with counts rounded to the nearest 5 and the differencing check refusing an export or API answer whose comparison could reveal a hidden count (NP-10). |
X-03 | BUILD | inference | The tumour variant named in a question, in HGVS notation with a ClinGen Allele Registry ID (OQ-44). A variant-level signal is shown only above both minimums and rolls up to the gene otherwise (OQ-41), which is the whole of the re-identification control here. Still held. Nothing. Shown only above both minimums: 8 distinct contributing people (OQ-14) and 3 distinct institutions with the 5 percent dominance check (OQ-40, NP-12), with counts rounded to the nearest 5 and the differencing check refusing an export or API answer whose comparison could reveal a hidden count (NP-10). |
X-04 | BUILD | inference | The drug, drug class or mechanism named in a question, coded with ChEMBL (OQ-44). ChEMBL is CC BY-SA 3.0, so anything derived from it that this product shares travels under the same licence. Still held. Nothing. Shown only above both minimums: 8 distinct contributing people (OQ-14) and 3 distinct institutions with the 5 percent dominance check (OQ-40, NP-12), with counts rounded to the nearest 5 and the differencing check refusing an export or API answer whose comparison could reveal a hidden count (NP-10). |
X-05 | BUILD | inference | The question type, from the six OncoSkepsis functions: tumour-board case, variant interpretation, tumour-board brief, country-specific literature, reimbursement dossier and clinical-trial search (OQ-45, NP-13). Still held. Nothing. Shown only above both minimums: 8 distinct contributing people (OQ-14) and 3 distinct institutions with the 5 percent dominance check (OQ-40, NP-12), with counts rounded to the nearest 5 and the differencing check refusing an export or API answer whose comparison could reveal a hidden count (NP-10). |
X-06 | BUILD | inference | The country of the contributing clinician, which is what makes a country facet possible without a named person behind it. Still held. Nothing. Shown only above both minimums: 8 distinct contributing people (OQ-14) and 3 distinct institutions with the 5 percent dominance check (OQ-40, NP-12), with counts rounded to the nearest 5 and the differencing check refusing an export or API answer whose comparison could reveal a hidden count (NP-10). |
X-07 | BUILD | inference | The time of a question as an ISO week, and no exact timestamp anywhere in the signal layer (OQ-43). A week is the finest granularity this product will ever hold. Still held. Nothing. Shown only above both minimums: 8 distinct contributing people (OQ-14) and 3 distinct institutions with the 5 percent dominance check (OQ-40, NP-12), with counts rounded to the nearest 5 and the differencing check refusing an export or API answer whose comparison could reveal a hidden count (NP-10). Released by OQ-43. |
X-08 | BUILD | inference | The contributing clinician's professional role, from the list OQ-10 states, confirmed on 18/09/2026. Still held. Nothing. Shown only above both minimums: 8 distinct contributing people (OQ-14) and 3 distinct institutions with the 5 percent dominance check (OQ-40, NP-12), with counts rounded to the nearest 5 and the differencing check refusing an export or API answer whose comparison could reveal a hidden count (NP-10). |
X-09 | BUILD | inference | The evidence status of the answer, as contested evidence or thin evidence, confirmed on 18/09/2026. These two flags are what the research-gap view is built from (NP-07), which is why the field exists at all. Still held. Nothing. Shown only above both minimums: 8 distinct contributing people (OQ-14) and 3 distinct institutions with the 5 percent dominance check (OQ-40, NP-12), with counts rounded to the nearest 5 and the differencing check refusing an export or API answer whose comparison could reveal a hidden count (NP-10). |
X-10 | BUILD | inference | The counts themselves: questions, distinct contributing clinicians and distinct contributing institutions, which are what the two minimums are measured against. Still held. Nothing. Shown only above both minimums: 8 distinct contributing people (OQ-14) and 3 distinct institutions with the 5 percent dominance check (OQ-40, NP-12), with counts rounded to the nearest 5 and the differencing check refusing an export or API answer whose comparison could reveal a hidden count (NP-10). |
X-11 | BUILD | inference | The change in question counts between two periods, confirmed on 18/09/2026 and governed by NP-10. Comparing two tables can reveal a small number even when each table separately meets the threshold, so the differencing check stands in front of every export and API answer, and an in-app view shows a warning instead. Still held. Nothing. Shown only above both minimums: 8 distinct contributing people (OQ-14) and 3 distinct institutions with the 5 percent dominance check (OQ-40, NP-12), with counts rounded to the nearest 5 and the differencing check refusing an export or API answer whose comparison could reveal a hidden count (NP-10). |
X-12 | BUILD | inference | The sustained-enquiry indicator for a clinician, reaching a pharma user as an anonymous card and never a name. An identity is revealed only when that clinician accepts a specific contact request, and the acceptance is stored as a consent record holding the time, the wording shown and the company named (OQ-05, OQ-42). Still held. Nothing. Shown only above both minimums: 8 distinct contributing people (OQ-14) and 3 distinct institutions with the 5 percent dominance check (OQ-40, NP-12), with counts rounded to the nearest 5 and the differencing check refusing an export or API answer whose comparison could reveal a hidden count (NP-10). |
X-13 | BUILD | inference | Tumour-board membership, which appears only inside the profile that opens after a clinician accepts a contact request, and never on a card, in a list, in an export or in an API answer that precedes an acceptance (OQ-46, NP-02). Still held. Nothing. Shown only above both minimums: 8 distinct contributing people (OQ-14) and 3 distinct institutions with the 5 percent dominance check (OQ-40, NP-12), with counts rounded to the nearest 5 and the differencing check refusing an export or API answer whose comparison could reveal a hidden count (NP-10). |
X-14 | BUILD | inference | Reimbursement-dossier requests, as group counts by drug and country and never per hospital (OQ-45). Still held. Nothing. Shown only above both minimums: 8 distinct contributing people (OQ-14) and 3 distinct institutions with the 5 percent dominance check (OQ-40, NP-12), with counts rounded to the nearest 5 and the differencing check refusing an export or API answer whose comparison could reveal a hidden count (NP-10). |
X-15 | BUILD | inference | Clinical-trial search activity, as group counts by cancer type and country (OQ-45). The search that produces it is built inside OncoSkepsis on ClinicalTrials.gov and the EU trial portal (NP-13). Still held. Nothing. Shown only above both minimums: 8 distinct contributing people (OQ-14) and 3 distinct institutions with the 5 percent dominance check (OQ-40, NP-12), with counts rounded to the nearest 5 and the differencing check refusing an export or API answer whose comparison could reveal a hidden count (NP-10). |
NEVER-01 | PARTIAL | stated | All of it. Basis is stated (no patient data leaves the institution). No open_questions. The '18 identifier types' figure comes from the cited HIPAA de-identification standard [R79] and serves explicitly as a checklist, so it is a sourced figure rather than an invented number under rule 0.5. Still held. None. |
NEVER-02 | PARTIAL | stated | All of it. Basis is stated (no patient data leaves the institution), no open_questions, no number. The prohibition on patient clinical details reaching Insights is directly stated and is reinforced by GDPR Recital 35 [R65] and the CJEU 2024 ruling on pharmacy order data [R71]. Still held. None. One caveat to carry into the code review rather than a gate: the basis_detail says the enumerated list (age, sex, stage, treatment history, test results, sequencing files, pathology reports, case notes, board decisions) is the document author's reading, so treat that list as a non-exhaustive... |
NEVER-03 | BUILD | inference | All of it, confirmed by OQ-40: no institution name and no tumour-board name is attached to any clinical signal. What reaches this product is a count of distinct institutions, which is what the 3-institution minimum and the dominance check are measured against. Still held. Nothing. A count is not a name, and the dominance check exists precisely so that a count cannot be read back as one. |
NEVER-04 | PARTIAL | stated | All of it. Basis is stated (pharma users never see clinical activity; Insights receives only aggregated derived signals; also stated facts 5.1.6 and 5.1.9). No open_questions, no number. This is the strongest stated prohibition in the group and is the right foundation for the guards that the... Still held. None. |
NEVER-05 | PARTIAL | stated | The forward-looking half, which does not depend on OQ-34: a mandatory current-consent check before any signal_event is created, so no signal exists for a clinician who never opted in and no NEW signal is created after a withdrawal. Basis is stated (clinicians opt in explicitly and can withdraw),... Still held. The retroactive half. OQ-34 has not decided whether signals a clinician already contributed must be deleted from Skepsis Insights or only excluded from new aggregations, so the withdrawal handler must not yet act on already-stored signals or already-delivered aggregates. Build the consent gate,... Still held by OQ-34. Nothing is defaulted in its place. |
NEVER-06 | BUILD | research | All of it, confirmed by OQ-47: patient data EFEVRE processes on behalf of a hospital never reaches this product or the signal layer. EFEVRE is a processor for that data and a controller only for the consented signal layer, and Article 28(10) is the reason the distinction has teeth: a processor that sets its own purposes becomes a controller. Still held. Nothing. Released by OQ-47. |
NEVER-07 | BUILD | inference | All of it, confirmed by OQ-38: the clinician's own words never enter the signal layer. What is stored is coded labels and a machine-written summary built from those labels and the topic of the answer, generated inside the institution boundary, with the inputs to each summary logged (NP-04). Still held. Nothing. The log is what makes this checkable rather than promised: a summary whose inputs are recorded can be shown to contain nothing a clinician typed. |
XFER-01 | BUILD | research | All of it. Basis is research (GDPR Art 7(4)/Recital 43 [R65], EDPB 2020 consent guidance [R66]) and the requirement lists no open_questions. The decline path is additionally backed by stated fact 5.1.7 (a clinician who declines keeps full clinical use). No number is needed. Still held. None. |
XFER-02 | BUILD | research | All of it, including the stated acceptance criterion. Basis is research (GDPR Art 7(3) [R65], EDPB 2020 guidance [R66]); no open_questions; the symmetry rule (as easy as giving) needs no invented number. Still held. None. Note this covers the withdrawal ACTION only; what happens to already-delivered aggregates is NEVER-05/OQ-34 territory, not XFER-02. |
XFER-03 | BUILD | stated | All of it. The consent screen can now say what it has to, because the answers fix what is recorded: coded labels plus a machine-written topic summary, never a clinician's typed words (OQ-38); no free-text question box exists at all (OQ-39); the ISO week and no timestamp (OQ-43); and a name reaching a pharma user only through the clinician's own acceptance of a contact request (OQ-05, OQ-42). Still held. Nothing. A consent screen is only as honest as the list behind it, which is why this requirement could not be built while any of those four answers was missing. |
XFER-04 | BUILD | inference | All of it, confirmed by OQ-48, which decides it the other way from the requirement's own expectation: the hospital licence informs the hospital about the signal layer, and the clinician's own consent record is the only thing that gates signal creation. There is no licence-level switch. Still held. Nothing. The reasoning is worth keeping: consent must be a real choice without pressure, and a hospital-level switch would put the employer between the clinician and that choice. Released by OQ-48. |
XFER-05 | BUILD | inference | All of it, confirmed on 18/09/2026 and narrowed to the structured fields. OQ-39 removed the free-text question box from OncoSkepsis, so there is no prose to scan: what remains is a check on the coded fields before a signal is created. Still held. Nothing. The narrowing matters: a free-text scanner in a product with no free text would be security theatre, and would imply a protection that nothing exercises. Released by the confirmation of 18/09/2026, OQ-39. |
XFER-06 | BUILD | inference | All of it, confirmed by OQ-38 and OQ-44: the signal carries coded items in the stated vocabularies, with the code list version recorded, plus a one-line machine summary written from the coded fields and the topic of the answer returned to the clinician, never from words a clinician typed (NP-04). The summary is generated inside the institution boundary and the inputs used for each one are logged. Still held. Nothing. |
XFER-07 | BUILD | inference | All of it, confirmed by OQ-39 and OQ-47. OncoSkepsis runs in EFEVRE's cloud under the institutional licence, and clinicians enter only structured fields, so no patient details reach it. EFEVRE is a processor for that clinical use and a controller only for the signal layer, which is where the institution boundary sits. Still held. Nothing. The boundary is a legal shape the architecture has to match: separate stores, separate access control, a processor contract per hospital and a consent record per clinician. |
XFER-08 | BUILD | research | All of it. Basis is research (WP29 2014 pseudonymisation guidance [R67], draft EU 2026 guidance on anonymous-for-recipient-but-not-for-controller [R69]) plus the stated fact that EFEVRE operates both the signal layer and Skepsis Insights. No open_questions, and no number is required: the... Still held. None. A concrete retention PERIOD would be an invented number under rule 0.5, but XFER-08 does not ask for one; it asks only for the personal-data classification to hold while the data is kept. |
XFER-09 | BUILD | inference | All of it, confirmed by OQ-40, which supplies both numbers: an OncoSkepsis signal is shown only when at least 3 institutions stand behind it and no single institution dominates, where dominance is the count minus the two largest institutional contributions falling under 5 percent of the largest (NP-12). The 8-person minimum of OQ-14 applies on top. Still held. Nothing. p is held in configuration, so a site that needs a stricter rule sets one rather than patching a literal. |
XFER-10 | BUILD | research | All of it, on the strength NP-10 chose: a comparison that could reveal a hidden count blocks the export or the API answer outright, and an in-app view shows a warning instead. The check runs before every export and every API answer rather than at the point the data is stored. Still held. Nothing. The asymmetry is deliberate: an export leaves the building and cannot be recalled, while an in-app view is read by a signed-in user whose access is logged. |
XFER-11 | BUILD | inference | All of it, confirmed by OQ-41: a variant-level signal is shown only above both minimums, and rolls up to the gene automatically otherwise. The roll-up is the behaviour rather than a fallback, so a rare variant becomes a gene-level count rather than disappearing. Still held. Nothing. Released by OQ-41. |
XFER-12 | BUILD | inference | All of it, confirmed by OQ-40. The institution minimum applies in every view, export, alert and API answer, and NP-01 adds the launch consequence: until a third hospital joins, nothing from OncoSkepsis is releasable, and the view says so. Still held. Nothing. |
XFER-13 | BUILD | inference | All of it, confirmed on 18/09/2026, and it is the load-bearing one. The signal layer delivers to this product through a one-way interface, and this product's services have no read access to the stored coded OncoSkepsis signals. ADR 0002 records the shape that implements it: a signal service that neither product owns, which OncoSkepsis writes to and this product reads from, holding no credential for any clinical store. Still held. Nothing. Until the confirmation this was an inference the architecture already relied on, which is the uncomfortable kind: a design resting on a requirement nobody had agreed. Released by the confirmation of 18/09/2026, OQ-47. |
XFER-14 | BUILD | stated | All of it, including the acceptance criterion. Basis is stated (Dimitris Kyriacou stated clinicians never see Skepsis Insights; also stated fact 5.1.9). No open_questions, no number. Both halves are buildable: the read-access denial and the no-display rule. Still held. None. |
XFER-15 | BUILD | research | All of it, and it is a prohibition rather than a feature: patient data EFEVRE processes for a hospital is never used for this product or for the signal layer. OQ-47 gives it its legal footing, since a processor that sets its own purposes becomes a controller for that processing. Still held. Nothing. The architecture is what enforces it: this product cannot reach a clinical store, and the boundary refuses at startup a configuration that would let it try. Released by OQ-47. |
XFER-16 | BUILD | inference | All of it, confirmed by OQ-42 and OQ-46: a clinician is anonymous until they accept a specific contact request, the acceptance is stored with its time, wording and the company named, and tumour-board membership appears only inside the profile that acceptance opens (NP-02). Still held. Nothing. |
XFER-17 | BUILD | research | All of it. OQ-36 names who does the legal work, and OQ-37 sets the sequence: Greece starts, and each further country joins only after a recorded legal sign-off for that country. A country flag per tumour board carries that state, and a country stays off until the sign-off exists. Still held. Nothing. The reason the sequence exists is worth keeping in sight: Article 9(4) lets each member state add its own conditions for health and genetic data, so national rules differ and one assessment does not cover the next country. |
DATA-01 | BUILD | stated | The whole requirement. Both directions of the visibility ban are stated and carry no open question: a pharma user can never be shown an individual clinician's or researcher's own activity, and OncoSkepsis / the Research Workspace can never show Insights content to clinicians or researchers.... Still held. None. No part of DATA-01 depends on an unanswered open question and no numeric value is needed. |
DATA-02 | BUILD | stated | All of it, and the answer makes the architecture explicit rather than only the rule. The separation stays enforced by construction: separate stores, separate services, a startup check that refuses a clinical or research database URL or role, and a per- request refusal of a clinical service account. What OQ-05 settles is the individual- level question that used to hold half of this: nothing individual crosses. A pharma user meets an anonymous card, the link between card and person stays inside the signal layer, and no service outside it may read that link. An identity is revealed only by the expert's own acceptance of a contact request (OQ-42), which is a consent record rather than a data flow. Still held. Nothing. OQ-47 adds the legal shape the architecture has to match: EFEVRE is a processor for each hospital's clinical use and a controller only for the signal layer, so the two stores stay separate with separate access control, per hospital contracts and per clinician consent. |
DATA-03 | BUILD | stated | All of it. The dashboard receives aggregated signals, and the two numbers that define 'aggregated' are now stated: at least 8 distinct people behind anything shown, with displayed counts rounded to the nearest 5 (OQ-14), and at least 3 distinct institutions with the 5 percent dominance check for anything from OncoSkepsis (OQ-40, NP-12). The thresholds apply in every view, export, alert and API answer, and the differencing check refuses an output whose comparison could reveal a count they hide (NP-10). Still held. Nothing. Individual-level data does not cross at all, which OQ-05 settles: the anonymous card is what a pharma user sees, and a name arrives only through the expert's own acceptance. |
DATA-04 | PARTIAL | stated | The whole requirement. The consent mechanism, its timing (consent before any signal is created or passed) and the three disclosure headings (what is recorded, what is not recorded, what is shared with pharmaceutical customers) are all stated, and DATA-04 carries no open question. Still held. None under rules 0.3, 0.4 and 0.5. One adjacency, explicitly not a 0.4 gate on DATA-04: the item-by-item wording shown on that screen is governed by XFER-03, which does carry OQ-05, OQ-38 and OQ-42, so build the screen, its versioning and the three headings now and let XFER-03 supply the final item... |
DATA-05 | BUILD | stated | All of it. The signal layer records the scientific question and its field, and nothing else: coded items in stated vocabularies, a machine summary built only from those and the answer's topic, and an ISO week (OQ-38, OQ-43, OQ-44). OncoSkepsis has no free-text question box for patient detail to arrive in (OQ-39), and the identifier check runs over the structured fields before a signal is created (XFER-05). Still held. Nothing. This requirement used to be blocked by the absence of a stated content list, which is exactly what made it unenforceable: a prohibition with no inventory behind it is a sentence rather than a control. |
DATA-06 | BUILD | stated | All of it, including the retroactive half that used to be held. A withdrawal deletes the contributor's stored signal events, recalculates every affected aggregate, and re-applies the suppression rules to every affected view, so a total that falls below 8 contributors or 3 institutions without them stops being shown (OQ-34). An expert may also withdraw entirely from the claim-your-profile page, which removes them from every list, card, trend and future processing, and the withdrawal is recorded with its time and the wording shown, because it is an objection under Article 21 (FD-03). Still held. Nothing. |
DATA-07 | BUILD | stated | All of it. Research Workspace questions feed anonymous group trends and nothing else, under a clear privacy notice with an opt-out shown inside the Research Workspace itself (OQ-07). Every signal is tagged with the surface that produced it, and a signal tagged Research Workspace may enter trend aggregates only. An academic who switches on 'contactable by pharma' may receive a contact request, and even then appears exactly as a clinician does: an anonymous card until they accept (NP-03, FD-02). Still held. Nothing in this build. One dependency sits outside it: the notice and the opt-out control live in the Research Workspace, and the lawful basis is a legitimate interest whose balancing test the external data protection officer confirms (OQ-36). |
DATA-08 | PARTIAL | research | The whole requirement. Basis is research, which rule 0.3 does not block, and no open question is attached. Buildable now: a data-classification attribute on every dataset and column group where pseudonymised is classified as personal data; a guard that prevents any UI label, export header, API... Still held. None. The rule is categorical, so no re-identification-risk score, retention period or other numeric value is needed - and none may be invented (rule 0.5). |
DATA-09 | BUILD | research | All of it that this product owns: the Article 14 register, the notice record per expert, the one-month due date the requirement itself states, and the send path. The external data protection officer owns the notice's legal substance and the legitimate-interest assessment behind it (OQ-36), which is an ownership answer rather than a gate on the machinery. Still held. Nothing. Sending to real experts waits on the officer's sign-off of the wording, which is a deployment precondition recorded in the register rather than a missing feature. Released by OQ-36. |
DATA-10 | PARTIAL | research | The whole requirement. Basis is research and no open question is attached. Buildable now: an objection intake path, an objection record per expert, a recorded validity decision, a processing-stop flag that by default removes that expert from discovery, scoring, saved lists, exports, alerts and API... Still held. None. One scope guard: no objection-review deadline or response-time SLA may be coded, because no such number is stated anywhere in the file (rule 0.5) - so the stop must take effect immediately and synchronously on a valid objection rather than being queued against an invented deadline. |
DATA-11 | BUILD | research | All of it that is this build's to hold: the assessment record, its version history and the link from each processing purpose to the assessment that covers it. Its substance, its balancing conclusion and its approval belong to the external data protection officer (OQ-36), who owns the legitimate-interest assessment for the Research Workspace signals in particular. Still held. Nothing. Released by OQ-36. |
DATA-12 | BUILD | inference | All of it, confirmed by OQ-36, which names the owner: the external data protection officer leads the data protection impact assessment, with lawyers engaged for specific opinions on the AI Act, the European Health Data Space Regulation and Greek law. This build holds the assessment record and the release gate that the assessment must be complete before real expert data is processed. Still held. Nothing. The assessment's content is the officer's work rather than this build's, and the gate in front of real data is what makes that ownership visible. Released by OQ-36. |
ACC-01 | BUILD | inference | All of it, confirmed by OQ-04, which also settles the shape. An external Medical Affairs agency holds one account containing a separate workspace per drug-company client, and inside that account a workspace shows its lists, notes, weights and exports only to the agency staff assigned to it. A Medical Affairs team inside a drug company holds its own account for that company. The seat model is a yearly fee per named user with add-on modules charged separately, so an account holds named users with a licence record each, and module entitlements sit at account level (OQ-31). Still held. Nothing. The isolation is per workspace as well as per account, which is stricter than the requirement's own wording and is what an agency's clients will ask about. |
ACC-02 | BUILD | research | All of it. Commercial users may hold logins, in a separate view that keeps consented signals and medical content out (OQ-35). Every user carries a role, and the filter is applied to the data rather than to the screen: a commercial role sees no signal- derived field, no fit score and no evidence answer, anywhere, including through the API. Still held. Nothing. The same rule governs export: a commercial user exports fields built from public sources only, such as papers, trials, congress roles and affiliations, and every export is logged with user, time and content (NP-11). |
ACC-03 | BUILD | inference | All of it, confirmed on 18/09/2026: a customer administrator adds users, removes users and assigns roles. The role vocabulary it assigns is this product's own five, which the answers settle: KOL lead, field medical lead, Medical Science Liaison, commercial and administrator (OQ-03, OQ-35). Still held. Nothing. An administrator's reach stops at their own account, and inside an agency account at the workspaces they administer (OQ-04, ACC-01). |
ACC-04 | BUILD | inference | All of it, confirmed by NP-11, which names what it must cover: every export is logged with the user, the time and the content, and a commercial user's exports are filtered to public-source fields before that log is written. Still held. Nothing by a question. One value stays unstated and unneeded: no log retention period or review cadence is invented here, because none is stated and the audit log's own retention is a deployment decision recorded elsewhere. Released by NP-11. |
COMP-01 | BUILD | research | All of it, as a deny-by-default rule with nothing left to decide. No payment data, no claims data and no prescribing data enters this product, so US Open Payments, European payment registers, insurance claims and prescribing feeds are excluded from every profile, score and export (OQ-28). Still held. Nothing. The rule is easier to keep than it was to write: there is no ingestion path to guard, because none is built. Released by OQ-28. |
COMP-02 | BUILD | research | All of it. Basis is research (GDPR Article 22, R37) and the requirement lists no open_questions entry. No threshold, weight, window, price or limit is needed, so rule 0.5 is clean. Still held. None. The basis_detail caveat - that applying Article 22 to consultant selection is the research agent's reading and has not been confirmed by a regulator - is a legal-scope note, not an open_questions entry, and does not change basis from research. OQ-36 (who performs the legal assessments) is... |
COMP-03 | DROPPED | research | The requirement was to show publicly disclosed industry payments. OQ-28 removes payment data from this product entirely, so there is nothing to show and nothing pending. The reasoning is on the record: US government guidance of 2020 warns against choosing paid speakers by past or expected sales, and a product that surfaced payment history beside a fit score would be building exactly that selection. NP-09 goes further in the same direction: no conflict-of-interest field, flag or note anywhere. Dropped by OQ-28. The answer went the other way, so nothing here is waiting on anybody and nothing arrives later. |
COMP-04 | BUILD | inference | All of it, confirmed on 18/09/2026 with one thing settled that the requirement left open: the customer enters the fair market value. This product calculates none, proposes none and holds no rate table. The documented need and the selection criteria already exist as append-only revisions under FR-PLAN-02, so this requirement ties those two and the customer's own fair market value record to a planned engagement. Still held. Nothing. The narrowing is the substance: a product that proposed a payment amount would be making a recommendation about a transfer of value, which is the customer's decision and their record to defend to a code reviewer. Released by the confirmation of 18/09/2026. |
COMP-05 | BUILD | research | All of it. Basis is research (EU AI Act Article 50 transparency obligations, applicable from 2 August 2026 per R49 - a date stated in the file, and already past as of 17 September 2026), and no open_questions entry is listed. No numeric value is needed. Still held. None. The basis_detail caveat that Article 50's exact scope for BSI has not been checked by a lawyer is a note, not an open_questions gate - and it argues for disclosing on all AI output rather than for deferring the disclosure. |
COMP-06 | BUILD | research | All of it that this build owns: the assessment record and the link from each processing purpose to it. OQ-36 names who carries out the legal work: an external data protection officer leads, with lawyers engaged for specific opinions on the AI Act, the European Health Data Space Regulation and Greek law. Still held. Nothing. The conclusion of an assessment is the officer's to write, which is an ownership answer rather than a gate on the machinery that holds it. Released by OQ-36. |
SEC-01 | BUILD | research | All of it that a build can carry. OQ-29 sets the path: SOC 2 Type I now, and a Type II report completed before the first pharma contract. What that asks of this codebase is evidence kept from the start, so the Type II observation period can begin without rework: access logs, change records and the security policies themselves. Still held. Nothing. The audit dates and the report itself are EFEVRE's to schedule, and no claim of certification may appear in the product or its materials before a report exists. |
SEC-02 | BUILD | research | All of it that a build can carry, on the same answer as SEC-01: the evidence an information security management system needs is produced from the start rather than assembled in front of an audit (OQ-29). Still held. Nothing. The certification timeline and the scope statement are EFEVRE's decisions, taken against the first pharma contract rather than against a date. Released by OQ-29. |
SEC-03 | PARTIAL | research | All of it. A maintained answer bank for standard vendor security questionnaires: one row per question with the answer text, a pointer to the supporting evidence, an owner and a last-reviewed date, plus an export so a completed questionnaire can be returned to a pharma customer's procurement team.... Still held. None. One caution rather than a gate: the 627-questions / 21-categories / 128-questions figures come from a SIG licensee's 2025 summary and the file states they were not checked against Shared Assessments directly (0.7, 0.8), so they must not be hardcoded as schema constraints, completeness checks... |
SEC-04 | PARTIAL | research | All of it, and this is the strongest build candidate in the group. Two halves, both fully specified: (a) a server-side guard that refuses any request reaching stored signal data unless the session was authenticated with a second factor, applied at the data-access layer rather than only at the login... Still held. None of the mechanism. Under rule 0.5 no numbers may be baked in: no MFA session lifetime or re-prompt interval, no failed-attempt lockout threshold, no access-log retention period, and no fixed review cadence. Log review therefore ships as an on-demand operator action with a recorded reviewer and... |
SEC-05 | BUILD | inference | All of it, confirmed by OQ-30, which fixes the territory: EU data centres. A deployment names its own region within that, the status route reports what it names, and the availability target is 99.5 percent per calendar quarter. Still held. Nothing. A deployment may still be misconfigured, which is why the region is reported rather than assumed: a residency claim nobody can check is worth nothing to a procurement reader. Released by OQ-30. |
SEC-06 | BUILD | inference | All of it, confirmed by OQ-24 and NP-08, which also shrink it to almost nothing. Insight capture is pick-lists only, so no free text can carry a side-effect report into this product. The safety category opens the customer's own safety reporting page, whose link is held in their account settings, and no side-effect content is stored here. Still held. Nothing. What remains of the obligation is the routing link and the absence of free text, and both are cheap to keep because neither is a detector that can be wrong. |
NFR-01 | BUILD | research | All of it. The intervals are stated: trend data and the API data set refresh daily, expert profiles weekly (OQ-19), and both are settings rather than literals so a deployment can differ without a release. Still held. Nothing. Released by OQ-19. |
NFR-02 | BUILD | inference | All of it, confirmed on 18/09/2026: every expert signal and every field trend carries the type of evidence behind it, whether publications, trials, congress abstracts or aggregated query signals. The types are ones this product already holds, so the requirement is a field and a display rather than a new source. Still held. Nothing. This is the requirement that stops a question-derived signal reading like a publication record, which is the single most misreadable thing the product shows. Released by the confirmation of 18/09/2026. |
NFR-03 | BUILD | inference | All of it, confirmed by OQ-14, which supplies the number it needed: at least 8 distinct people behind anything shown, with counts rounded to the nearest 5, in every view, export, alert and API answer. Still held. Nothing. NP-01 adds an operational consequence rather than a gate: OncoSkepsis signals stay hidden until a third hospital joins, so an empty OncoSkepsis view names the minimum instead of implying a quiet field. |
NFR-04 | BUILD | inference | All of it, confirmed by OQ-30, which states both targets: 99.5 percent availability per calendar quarter, and the page-speed thresholds of main content within 2.5 seconds and input response within 200 milliseconds, measured at the 75th percentile of page loads. Still held. Nothing. The targets are measured rather than asserted, and the percentile matters: a mean would hide exactly the slow quarter of loads the threshold exists to catch. Released by OQ-30. |
NFR-05 | BUILD | research | All of it. One responsive web application serving phone, tablet and computer, with every screen usable from 400 pixels of width upward, and no separate phone app (OQ-32). The answer is grounded: about 60 percent of Medical Science Liaison interactions with experts are in person, and MSLs now hold their own logins (OQ-03). Still held. Nothing. |