Staff/Privacy Decision Record Template
Purpose
This template gives staff/privacy reviewers a static structure for deciding whether Renata may proceed toward a future pull-up/push-up draft pilot implementation.
It is not a decision capture surface. It creates no forms, approval controls, staff decision records, protected live routes, protected API routes, database reads, database writes, active migrations, drafts, accounts, identity records, or live workflows.
Current No-Go Status
Template status
read-only-template
Decision status
not-recorded
Implementation status
not-started
Live pilot decision
no-go
Approvals
not-recorded
Staff decisions
not-created
How To Use This Template
Use this page as a read-only checklist and discussion scaffold outside the app. Any actual decision record, approval, rejection, unresolved risk, or no-go note must be handled under an approved staff/privacy process outside this prototype.
Default state is unresolved, not-approved, requires-review, and no-go. No section implies approval.
Decision Section Cards
Primary print layout. These read-only decision cards are the main staff/privacy packet layout and do not collect approvals, record decisions, create staff actions, or store outcomes.
pilot-purpose
Define what the pilot is for, what problem it addresses, and what it must not become.
Default decision values: unresolved, not-approved, requires-review, no-go
Required approver role: program-lead
Required evidence: /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/account-workflow-gate-review/
Blocking questions: What resident-support problem should the pilot solve?; What outcomes would make the pilot inappropriate to continue?; How will staff explain that this is not discipline, scoring, or surveillance?
Prohibited shortcut: starting pilot implementation without a written purpose and no-surveillance boundary
access-boundary
Confirm Cloudflare Access remains an outer boundary with no identity claim exposure or storage.
Default decision values: unresolved, not-approved, requires-review, no-go
Required approver role: technical-owner
Required evidence: /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/access-claim-boundary/
Blocking questions: What proof shows Access claims are not returned, displayed, stored, logged, or mapped?; What route policy is required before protected live routes exist?
Prohibited shortcut: treating Cloudflare Access identity claims as app identity records
identity-and-actor-policy
Decide whether the pseudonymous actor model is sufficient and keep real names, emails, and claims out of app records.
Default decision values: unresolved, not-approved, requires-review, no-go
Required approver role: privacy-owner
Required evidence: /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/actor-reference-schema/
Blocking questions: Who can receive a pseudonymous actor reference?; How are actor references revoked or rotated?; What identity values remain prohibited in records and UI?
Prohibited shortcut: storing real identity values before identity and pseudonymous actor policies are approved
role-and-permission-policy
Decide who may draft, who may review, and who may see which future records.
Default decision values: unresolved, not-approved, requires-review, no-go
Required approver role: staff-review-lead
Required evidence: /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/account-role-mapping-schema/; /protected-preview/draft-pilot-read-runtime-plan/
Blocking questions: Which role can create draft content?; Which role can review draft metadata or content?; Which role can see Morning Sheet candidate metadata?
Prohibited shortcut: assigning live roles before role mapping and reviewer permission policies are approved
draft-content-policy
Decide what pull-ups and push-ups may contain and what content must be blocked.
Default decision values: unresolved, not-approved, requires-review, no-go
Required approver role: clinical-or-program-reviewer
Required evidence: /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/pullup-pushup-draft-schema/; /protected-preview/draft-pilot-write-endpoint-design/
Blocking questions: May any real draft body be stored?; What pull-up language is unsafe or punitive?; What push-up language is manipulative, ranking-like, or too personal?
Prohibited shortcut: collecting draft bodies before content, retention, deletion, and privacy policies are approved
staff-review-policy
Resolve review lanes, revision, block, private hold, escalation, and Morning Sheet consideration boundaries.
Default decision values: unresolved, not-approved, requires-review, no-go
Required approver role: staff-review-lead
Required evidence: /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/staff-review-procedure/; /protected-preview/draft-pilot-staff-review-write-design/
Blocking questions: Who may review drafts?; Which actions require escalation?; What review notes, if any, may exist?
Prohibited shortcut: creating staff decision records before reviewer, audit, and retention policies are approved
morning-sheet-visibility-policy
Resolve public visibility rules, private-only rules, and redaction rules.
Default decision values: unresolved, not-approved, requires-review, no-go
Required approver role: program-lead
Required evidence: /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/morning-sheet-visibility-policy/
Blocking questions: Is subject notification required before public visibility?; Is subject consent required before public visibility?; What content must remain private-only?
Prohibited shortcut: allowing public Morning Sheet placement before visibility and consent boundaries are approved
retention-and-deletion-policy
Resolve draft retention, private feedback retention, blocked content retention, and deletion procedure.
Default decision values: unresolved, not-approved, requires-review, no-go
Required approver role: privacy-owner
Required evidence: /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/retention-deletion-policy/
Blocking questions: What is the retention window for drafts?; What is the retention window for private feedback?; What deletion rights and exceptions apply?
Prohibited shortcut: storing draft bodies before retention and deletion policies are approved
audit-policy
Resolve minimal audit metadata and what audit logs must never contain.
Default decision values: unresolved, not-approved, requires-review, no-go
Required approver role: technical-owner
Required evidence: /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/audit-logging-policy/
Blocking questions: What audit metadata is necessary and minimal?; Who can see audit metadata?; How do audit logs avoid reconstructing deleted sensitive drafts?
Prohibited shortcut: allowing writes before audit policy and audit visibility policy are approved
ai-use-policy
Decide whether AI is allowed at all for real drafts; default remains no AI processing of real drafts unless explicitly approved later.
Default decision values: unresolved, not-approved, requires-review, no-go
Required approver role: privacy-owner
Required evidence: /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/draft-pilot-write-endpoint-design/; /protected-preview/draft-pilot-staff-review-write-design/
Blocking questions: Is AI allowed for real draft content at all?; What explicit future policy would be required before AI processing?; How will staff prevent AI-generated staff decisions?
Prohibited shortcut: sending real drafts to AI or generating staff decisions with AI without explicit future policy
pilot-scope
Resolve group size, duration, participants, and support/incident procedure.
Default decision values: unresolved, not-approved, requires-review, no-go
Required approver role: program-lead
Required evidence: /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/draft-pilot-architecture-package/; /protected-preview/draft-pilot-implementation-plan/
Blocking questions: What is the smallest safe pilot group?; How long should the pilot run?; What support or incident procedure stops the pilot if harm appears?
Prohibited shortcut: launching resident-wide or without incident support and rollback procedure
go-no-go-decision
Record the final staff/privacy decision state; default is no-go / unresolved.
Default decision values: unresolved, not-approved, requires-review, no-go
Required approver role: program-lead
Required evidence: /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/draft-pilot-activation-readiness/
Blocking questions: Have all required approvals been recorded outside this app?; Have all technical and policy gates been satisfied?; Is the pilot still no-go?
Prohibited shortcut: treating this read-only template as a live approval record
Decision Sections Table (Secondary Appendix Reference)
Secondary appendix reference only. The stacked decision cards above are the primary print layout.
| Section | Purpose | Default decision | Approver | Required evidence | Blocking questions | Prohibited shortcut |
|---|---|---|---|---|---|---|
| pilot-purpose | Define what the pilot is for, what problem it addresses, and what it must not become. | unresolved not-approved requires-review no-go | program-lead | /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/account-workflow-gate-review/ | What resident-support problem should the pilot solve?; What outcomes would make the pilot inappropriate to continue?; How will staff explain that this is not discipline, scoring, or surveillance? | starting pilot implementation without a written purpose and no-surveillance boundary |
| access-boundary | Confirm Cloudflare Access remains an outer boundary with no identity claim exposure or storage. | unresolved not-approved requires-review no-go | technical-owner | /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/access-claim-boundary/ | What proof shows Access claims are not returned, displayed, stored, logged, or mapped?; What route policy is required before protected live routes exist? | treating Cloudflare Access identity claims as app identity records |
| identity-and-actor-policy | Decide whether the pseudonymous actor model is sufficient and keep real names, emails, and claims out of app records. | unresolved not-approved requires-review no-go | privacy-owner | /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/actor-reference-schema/ | Who can receive a pseudonymous actor reference?; How are actor references revoked or rotated?; What identity values remain prohibited in records and UI? | storing real identity values before identity and pseudonymous actor policies are approved |
| role-and-permission-policy | Decide who may draft, who may review, and who may see which future records. | unresolved not-approved requires-review no-go | staff-review-lead | /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/account-role-mapping-schema/; /protected-preview/draft-pilot-read-runtime-plan/ | Which role can create draft content?; Which role can review draft metadata or content?; Which role can see Morning Sheet candidate metadata? | assigning live roles before role mapping and reviewer permission policies are approved |
| draft-content-policy | Decide what pull-ups and push-ups may contain and what content must be blocked. | unresolved not-approved requires-review no-go | clinical-or-program-reviewer | /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/pullup-pushup-draft-schema/; /protected-preview/draft-pilot-write-endpoint-design/ | May any real draft body be stored?; What pull-up language is unsafe or punitive?; What push-up language is manipulative, ranking-like, or too personal? | collecting draft bodies before content, retention, deletion, and privacy policies are approved |
| staff-review-policy | Resolve review lanes, revision, block, private hold, escalation, and Morning Sheet consideration boundaries. | unresolved not-approved requires-review no-go | staff-review-lead | /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/staff-review-procedure/; /protected-preview/draft-pilot-staff-review-write-design/ | Who may review drafts?; Which actions require escalation?; What review notes, if any, may exist? | creating staff decision records before reviewer, audit, and retention policies are approved |
| morning-sheet-visibility-policy | Resolve public visibility rules, private-only rules, and redaction rules. | unresolved not-approved requires-review no-go | program-lead | /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/morning-sheet-visibility-policy/ | Is subject notification required before public visibility?; Is subject consent required before public visibility?; What content must remain private-only? | allowing public Morning Sheet placement before visibility and consent boundaries are approved |
| retention-and-deletion-policy | Resolve draft retention, private feedback retention, blocked content retention, and deletion procedure. | unresolved not-approved requires-review no-go | privacy-owner | /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/retention-deletion-policy/ | What is the retention window for drafts?; What is the retention window for private feedback?; What deletion rights and exceptions apply? | storing draft bodies before retention and deletion policies are approved |
| audit-policy | Resolve minimal audit metadata and what audit logs must never contain. | unresolved not-approved requires-review no-go | technical-owner | /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/audit-logging-policy/ | What audit metadata is necessary and minimal?; Who can see audit metadata?; How do audit logs avoid reconstructing deleted sensitive drafts? | allowing writes before audit policy and audit visibility policy are approved |
| ai-use-policy | Decide whether AI is allowed at all for real drafts; default remains no AI processing of real drafts unless explicitly approved later. | unresolved not-approved requires-review no-go | privacy-owner | /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/draft-pilot-write-endpoint-design/; /protected-preview/draft-pilot-staff-review-write-design/ | Is AI allowed for real draft content at all?; What explicit future policy would be required before AI processing?; How will staff prevent AI-generated staff decisions? | sending real drafts to AI or generating staff decisions with AI without explicit future policy |
| pilot-scope | Resolve group size, duration, participants, and support/incident procedure. | unresolved not-approved requires-review no-go | program-lead | /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/draft-pilot-architecture-package/; /protected-preview/draft-pilot-implementation-plan/ | What is the smallest safe pilot group?; How long should the pilot run?; What support or incident procedure stops the pilot if harm appears? | launching resident-wide or without incident support and rollback procedure |
| go-no-go-decision | Record the final staff/privacy decision state; default is no-go / unresolved. | unresolved not-approved requires-review no-go | program-lead | /protected-preview/draft-pilot-evidence-package/; /protected-preview/draft-pilot-activation-readiness/; /protected-preview/draft-pilot-activation-readiness/ | Have all required approvals been recorded outside this app?; Have all technical and policy gates been satisfied?; Is the pilot still no-go? | treating this read-only template as a live approval record |
Required Approver Roles
Role labels only. No staff names, real names, or emails are included.
Default Decision Values
Go/No-Go Checklist
| Checklist item | Default status |
|---|---|
| access boundary approved | not-approved |
| identity policy approved | not-approved |
| pseudonymous actor policy approved | not-approved |
| role mapping policy approved | not-approved |
| draft content policy approved | not-approved |
| pull-up safety policy approved | not-approved |
| push-up recognition policy approved | not-approved |
| staff review procedure approved | not-approved |
| reviewer permission policy approved | not-approved |
| Morning Sheet visibility policy approved | not-approved |
| retention policy approved | not-approved |
| deletion policy approved | not-approved |
| audit policy approved | not-approved |
| escalation policy approved | not-approved |
| AI-use policy resolved | not-approved |
| technical schema reviewed | not-approved |
| migration plan reviewed | not-approved |
| rollback plan approved | not-approved |
| support/incident procedure defined | not-approved |
| small pilot group approved | not-approved |
Prohibited Approvals
This template cannot approve the following outcomes.
Evidence References
- /protected-preview/draft-pilot-evidence-package/
- /protected-preview/draft-pilot-activation-readiness/
- /protected-preview/draft-pilot-staff-review-write-design/
- /protected-preview/draft-pilot-write-endpoint-design/
- /protected-preview/draft-pilot-read-runtime-plan/
- /protected-preview/draft-pilot-architecture-package/
- /protected-preview/staff-privacy-review/
- /protected-preview/staff-review-procedure/
- /protected-preview/morning-sheet-visibility-policy/
- /protected-preview/retention-deletion-policy/
- /protected-preview/audit-logging-policy/
Unresolved Questions
Approval Gates
- staff workflow approval
- privacy approval
- identity policy approval
- pseudonymous actor policy approval
- role mapping policy approval
- draft content policy approval
- pull-up safety policy approval
- push-up recognition policy approval
- staff review procedure approval
- reviewer permission policy approval
- Morning Sheet visibility policy approval
- retention policy approval
- deletion policy approval
- audit policy approval
- escalation policy approval
- AI-use policy decision
- technical schema review
- migration review
- rollback plan approval
- small pilot approval
What Remains Blocked
Next Planning Phase
Phase 10.21 — Staff/Privacy Review Packet Handoff Freeze, Planning Only
The decision-record template is now part of the current staff/privacy review packet path with print style boundaries, manual assembly, visual QA, staff handoff, dry-run, debrief, evidence gap register, and evidence gap review sequence planned. The next planning phase may freeze packet route order, review status, and handoff instructions as a no-go review artifact while keeping approvals, decisions, protected APIs, protected live routes, reads, writes, storage, and workflow activation blocked.
Boundaries: no export generation; no download artifacts; no approval recording; no live pilot; no protected live routes; no protected API routes; no database reads; no database writes; no active migrations; no draft storage; no account storage; no actor storage; no identity capture; no staff decisions; no Morning Sheet placement; no tracking; no analytics; no scoring.
recommended-next