Staff/Privacy Evidence Gap Register, Planning Only
Purpose
Define a read-only planning structure for organizing staff/privacy evidence gaps found outside the app, without storing notes, observations, approvals, decisions, evidence gaps, drafts, identities, database records, protected routes, APIs, or live workflow state.
Evidence gaps must be documented outside the app. This page provides static categories and example rows only; no notes, observations, evidence gaps, approvals, decisions, files, API routes, or workflow state are created.
Current Evidence Gap Boundary
Register status
read-only-evidence-gap-register-plan
Evidence gap storage status
not-stored
Observation storage status
not-stored
Note capture status
not-captured
PDF generation status
not-generated
Export status
not-generated
Approval status
not-recorded
Decision status
not-recorded
Implementation status
not-started
Live pilot decision
no-go
Intended Audience
Role labels only. No staff names, resident names, emails, direct contact details, or identity details are included.
Source Pages
| Route | Source purpose | Evidence contribution | Limitation | Status |
|---|---|---|---|---|
| /protected-preview/staff-privacy-dry-run-debrief-template/ | Dry-run debrief structure. | Outside-app debrief categories and after-debrief boundaries. | Does not store actual debrief notes, observations, evidence gaps, approvals, or decisions. | manual-reference-only / not-generated / not-recorded / not-stored |
| /protected-preview/staff-privacy-review-dry-run-checklist/ | Dry-run rehearsal checklist. | Simulated reviewer questions, safe answers, stop conditions, and observation categories. | Does not conduct a real review or record outcomes. | manual-reference-only / not-generated / not-recorded / not-stored |
| /protected-preview/review-packet-staff-handoff-notes/ | Non-technical handoff guidance. | What to send, what not to claim, safe answers, and after-meeting boundaries. | Does not send packet artifacts or record handoff outcomes. | manual-reference-only / not-generated / not-recorded / not-stored |
| /protected-preview/review-packet-visual-qa-checklist/ | Manual visual QA checklist. | Stale-reference checks, navigation checks, blocked-chip checks, and content exclusions. | Does not store QA findings or generate files. | manual-reference-only / not-generated / not-recorded / not-stored |
| /protected-preview/review-packet-manual-assembly-checklist/ | Manual assembly checklist. | Required packet pages, redaction checks, and sharing boundaries. | Does not assemble, export, or download a packet. | manual-reference-only / not-generated / not-recorded / not-stored |
| /protected-preview/staff-privacy-review-packet-summary/ | Concise review packet summary. | Meeting-ready summary of evidence, approvals, and unresolved decisions. | Does not record approvals or decisions. | manual-reference-only / not-generated / not-recorded / not-stored |
| /protected-preview/draft-pilot-evidence-package/ | Full planning evidence package. | Planning artifacts, unresolved gates, technical evidence, and privacy/staff questions. | Does not prove implementation readiness. | manual-reference-only / not-generated / not-recorded / not-stored |
| /protected-preview/staff-privacy-decision-record-template/ | Decision areas template. | Default unresolved/not-approved/no-go decision areas and checklist. | Does not record any decision. | manual-reference-only / not-generated / not-recorded / not-stored |
| /protected-preview/staff-privacy-review-walkthrough-script/ | Presentation walkthrough. | Route sequence, reviewer questions, objections, and safe answers. | Does not conduct an official review. | manual-reference-only / not-generated / not-recorded / not-stored |
/demo/
Product context only.
Limitation: Not a staff/privacy decision surface.
manual-reference-only/operator/
Technical appendix/reference only.
Limitation: Not core packet content and not a live admin surface.
manual-reference-only/protected-preview/draft-pilot-activation-readiness/
Activation readiness no-go review.
Limitation: Does not activate schema, routes, APIs, or workflows.
manual-reference-only/protected-preview/draft-pilot-implementation-plan/
Future implementation plan.
Limitation: Does not start implementation.
manual-reference-only/protected-preview/draft-pilot-architecture-package/
Architecture planning package.
Limitation: Does not create storage, routes, or APIs.
manual-reference-only/protected-preview/audit-logging-policy/
Audit policy planning.
Limitation: Does not write audit logs.
manual-reference-only/protected-preview/retention-deletion-policy/
Retention/deletion planning.
Limitation: Does not run retention or deletion jobs.
manual-reference-only/protected-preview/morning-sheet-visibility-policy/
Morning Sheet visibility planning.
Limitation: Does not place content on the Morning Sheet.
manual-reference-only/protected-preview/staff-review-procedure/
Staff review procedure planning.
Limitation: Does not create staff decisions.
manual-reference-only/protected-preview/pullup-pushup-draft-schema/
Draft schema planning.
Limitation: Does not store drafts.
manual-reference-onlyEvidence Gap Categories
Identity Policy
May app-level identity values ever be stored?
Evidence needed: Approved identity policy, no-identity exposure rules, and storage prohibition or allowance boundaries.
Owner role label: privacy-owner; blocker: blocks identity storage and account runtime
Prohibited shortcut: storing identity before policy approval
unresolved not-stored not-recordedAccess Boundary
What remains outside Cloudflare Access and what must never be returned?
Evidence needed: Cloudflare Access boundary evidence and response/header exclusion rules.
Owner role label: technical-owner; blocker: blocks protected runtime design
Prohibited shortcut: logging or displaying Access claims
unresolved not-stored not-recordedPseudonymous Actor Policy
How are pseudonymous actor references created, revoked, and rotated?
Evidence needed: Actor lifecycle, rotation, revocation, and no-real-identity mapping policy.
Owner role label: privacy-owner; blocker: blocks actor storage
Prohibited shortcut: creating actor records without policy
unresolved not-stored not-recordedRole Mapping Policy
Which roles may submit, review, or view draft pilot materials?
Evidence needed: Role mapping approval and least-privilege access evidence.
Owner role label: program-lead; blocker: blocks role assignment
Prohibited shortcut: assigning roles before approval
unresolved not-stored not-recordedDraft Content Policy
What may pull-up/push-up drafts contain?
Evidence needed: Draft content policy, prohibited content, private-only content, and storage limits.
Owner role label: staff-review-lead; blocker: blocks draft storage
Prohibited shortcut: collecting draft text before policy approval
unresolved not-stored not-recordedPull-Up Safety Policy
What pull-up content creates safety, privacy, or accountability risk?
Evidence needed: Pull-up safety criteria, examples, and block/revision thresholds.
Owner role label: clinical-or-program-reviewer; blocker: blocks pull-up submission design
Prohibited shortcut: launching pull-ups without safety policy
unresolved not-stored not-recordedPush-Up Recognition Policy
What recognition is appropriate and non-exposing?
Evidence needed: Push-up recognition criteria, consent/visibility rules, and private-only thresholds.
Owner role label: program-lead; blocker: blocks push-up submission design
Prohibited shortcut: publishing recognition without visibility policy
unresolved not-stored not-recordedSubject Consent And Notification
When must subjects be notified or asked for consent?
Evidence needed: Subject notification, consent, and opt-out policy evidence.
Owner role label: privacy-owner; blocker: blocks public visibility
Prohibited shortcut: making subject visibility decisions inside the app
unresolved not-stored not-recordedStaff Review Procedure
How should drafts move through review lanes?
Evidence needed: Review lane definitions, reviewer training, revision, private hold, block, and escalation rules.
Owner role label: staff-review-lead; blocker: blocks review queue design
Prohibited shortcut: adding approval/rejection controls
unresolved not-stored not-recordedReviewer Permission Policy
What reviewer role permissions are required?
Evidence needed: Reviewer permission matrix and separation-of-duty evidence.
Owner role label: staff-review-lead; blocker: blocks staff review runtime
Prohibited shortcut: broad staff access by default
unresolved not-stored not-recordedHarmful Content Escalation
What happens when harmful content appears?
Evidence needed: Escalation roles, support/incident process, and stop conditions.
Owner role label: clinical-or-program-reviewer; blocker: blocks draft collection
Prohibited shortcut: treating escalation as ordinary review
unresolved not-stored not-recordedMorning Sheet Visibility
What may ever be considered for Morning Sheet visibility?
Evidence needed: Visibility policy, consent rules, redaction policy, and staff review criteria.
Owner role label: program-lead; blocker: blocks Morning Sheet placement
Prohibited shortcut: automatic public placement
unresolved not-stored not-recordedRetention Policy
How long may draft metadata and body content exist?
Evidence needed: Retention windows for draft metadata, body content, blocked content, and private feedback.
Owner role label: privacy-owner; blocker: blocks storage schema
Prohibited shortcut: storing content before retention approval
unresolved not-stored not-recordedDeletion Policy
Who can request deletion and how is it handled?
Evidence needed: Deletion rights, workflow, confirmation, rollback limits, and non-retention rules.
Owner role label: privacy-owner; blocker: blocks draft storage
Prohibited shortcut: adding deletion later after collecting drafts
unresolved not-stored not-recordedAudit Policy
What minimal audit metadata is necessary?
Evidence needed: Audit event types, field boundaries, and no-content audit rules.
Owner role label: technical-owner; blocker: blocks staff review writes
Prohibited shortcut: staff decisions without audit policy
unresolved not-stored not-recordedAudit Visibility
Who may see audit metadata?
Evidence needed: Audit visibility and redaction policy evidence.
Owner role label: privacy-owner; blocker: blocks audit UI planning
Prohibited shortcut: broad audit visibility
unresolved not-stored not-recordedAI Use Policy
May AI ever process real drafts?
Evidence needed: Explicit AI-use policy, data handling, opt-out, and prohibition boundaries.
Owner role label: privacy-owner; blocker: blocks AI features for real drafts
Prohibited shortcut: sending real drafts to AI
unresolved not-stored not-recordedSchema And Migration
What D1 schema package and rollback evidence would be approved?
Evidence needed: Schema review, local validation, active migration approval, and rollback evidence.
Owner role label: technical-owner; blocker: blocks active migrations
Prohibited shortcut: moving local draft SQL into active migrations
unresolved not-stored not-recordedProtected Read Runtime
What protected read surfaces must exist before writes?
Evidence needed: Protected read route policy, response policy, and no-identity response evidence.
Owner role label: technical-owner; blocker: blocks write endpoint implementation
Prohibited shortcut: creating writes before reads
unresolved not-stored not-recordedProtected Write Endpoints
What write endpoints may be allowed later?
Evidence needed: Write endpoint validation, rate limits, response boundaries, audit/retention dependencies.
Owner role label: technical-owner; blocker: blocks write APIs
Prohibited shortcut: creating POST/PATCH/DELETE handlers
unresolved not-stored not-recordedRollback And Incident Support
What support or incident process stops the pilot?
Evidence needed: Rollback plan, incident process, support owner roles, and harm stop conditions.
Owner role label: program-lead; blocker: blocks small pilot approval
Prohibited shortcut: launching without support/rollback
unresolved not-stored not-recordedSmall Pilot Scope
What is the smallest safe pilot group and duration?
Evidence needed: Pilot group size, duration, participant roles, support coverage, and exit criteria.
Owner role label: program-lead; blocker: blocks live pilot activation
Prohibited shortcut: resident-wide launch
unresolved not-stored not-recordedLanguage And Confusion Risk
What wording could imply surveillance, punishment, clinical claims, or launch readiness?
Evidence needed: Language review findings and rewrite guidance.
Owner role label: operator; blocker: blocks staff handoff readiness
Prohibited shortcut: using launch/approval wording
unresolved not-stored not-recordedDistribution And Sharing
How may review packet materials be shared?
Evidence needed: Distribution, redaction, audience, versioning, and no-sensitive-content evidence.
Owner role label: privacy-owner; blocker: blocks packet sharing
Prohibited shortcut: public posting or app-based email distribution
unresolved not-stored not-recordedStatic Evidence Gap Rows
| Gap | Category | Question | Evidence needed | Owner role | Status |
|---|---|---|---|---|---|
| gap-01-identity-storage | identity-policy | Whether app-level identity values may ever be stored. | Identity policy evidence and explicit storage boundary. | privacy-owner | unresolved / not-stored / blocks-implementation |
| gap-02-access-claims | access-boundary | Whether Cloudflare Access claims may ever be logged, displayed, mapped, or persisted. | Access claim boundary evidence and no-claim exposure rules. | technical-owner | unresolved / not-stored / blocks-implementation |
| gap-03-actor-lifecycle | pseudonymous-actor-policy | How pseudonymous actor references are created, revoked, and rotated. | Actor lifecycle policy and revocation/rotation evidence. | privacy-owner | unresolved / not-stored / blocks-implementation |
| gap-04-pullup-submitters | role-mapping-policy | Who may submit pull-ups. | Role mapping and submitter eligibility evidence. | program-lead | unresolved / not-stored / blocks-implementation |
| gap-05-pushup-submitters | role-mapping-policy | Who may submit push-ups. | Role mapping and submitter eligibility evidence. | program-lead | unresolved / not-stored / blocks-implementation |
| gap-06-pullup-subjects | draft-content-policy | Who may be the subject of a pull-up. | Subject eligibility and privacy policy evidence. | privacy-owner | unresolved / not-stored / blocks-implementation |
| gap-07-pushup-subjects | draft-content-policy | Who may be the subject of a push-up. | Subject eligibility and recognition policy evidence. | privacy-owner | unresolved / not-stored / blocks-implementation |
| gap-08-subject-notification | subject-consent-and-notification | Whether subject notification is required. | Notification policy and timing evidence. | privacy-owner | unresolved / not-stored / blocks-implementation |
| gap-09-subject-consent | subject-consent-and-notification | Whether subject consent is required before public visibility. | Consent policy and exception evidence. | privacy-owner | unresolved / not-stored / blocks-implementation |
| gap-10-block-before-storage | draft-content-policy | What draft content must be blocked before storage. | Blocked content criteria and pre-storage safety policy. | staff-review-lead | unresolved / not-stored / blocks-implementation |
| gap-11-private-only | draft-content-policy | What draft content may remain private-only. | Private-only policy and staff review lane evidence. | staff-review-lead | unresolved / not-stored / blocks-implementation |
| gap-12-real-draft-storage | retention-policy | Whether any real draft body may be stored. | Retention, deletion, privacy, audit, and draft content policy evidence. | privacy-owner | unresolved / not-stored / blocks-implementation |
| gap-13-reviewer-roles | staff-review-procedure | Who may review drafts. | Reviewer role policy and training evidence. | staff-review-lead | unresolved / not-stored / blocks-implementation |
| gap-14-reviewer-permissions | reviewer-permission-policy | What reviewer permissions are required. | Permission matrix and least-privilege evidence. | staff-review-lead | unresolved / not-stored / blocks-implementation |
| gap-15-harm-escalation | harmful-content-escalation | What harmful-content escalation procedure is required. | Escalation, incident, and support process evidence. | clinical-or-program-reviewer | unresolved / not-stored / blocks-implementation |
| gap-16-morning-sheet-eligible | morning-sheet-visibility | What content may be eligible for Morning Sheet consideration. | Visibility, review, redaction, consent, and staff policy evidence. | program-lead | unresolved / not-stored / blocks-implementation |
| gap-17-visibility-policy-owner | morning-sheet-visibility | Who can approve Morning Sheet visibility policy outside the app. | Role-label approval boundary and outside-app approval process. | program-lead | unresolved / not-stored / blocks-implementation |
| gap-18-draft-metadata-retention | retention-policy | What retention window applies to draft metadata. | Metadata retention window and deletion policy evidence. | privacy-owner | unresolved / not-stored / blocks-implementation |
| gap-19-draft-body-retention | retention-policy | What retention window applies to draft body content. | Draft body retention window and private feedback policy evidence. | privacy-owner | unresolved / not-stored / blocks-implementation |
| gap-20-deletion-rights | deletion-policy | What deletion rights exist. | Deletion rights, requester roles, and deletion procedure evidence. | privacy-owner | unresolved / not-stored / blocks-implementation |
| gap-21-minimal-audit | audit-policy | What audit metadata is necessary and minimal. | Audit event type and field boundary evidence. | technical-owner | unresolved / not-stored / blocks-implementation |
| gap-22-audit-visibility | audit-visibility | Who may see audit metadata. | Audit visibility, redaction, and access policy evidence. | privacy-owner | unresolved / not-stored / blocks-implementation |
| gap-23-ai-real-drafts | ai-use-policy | Whether AI may ever process real drafts. | Explicit AI-use policy and prohibition/approval evidence. | privacy-owner | unresolved / not-stored / blocks-implementation |
| gap-24-d1-schema-package | schema-and-migration | What D1 schema package would be approved. | Schema review package, local-only draft review, and table boundary evidence. | technical-owner | unresolved / not-stored / blocks-implementation |
| gap-25-migration-rollback | schema-and-migration | What migration and rollback evidence is required. | Local validation, rollback plan, and active migration approval evidence. | technical-owner | unresolved / not-stored / blocks-implementation |
| gap-26-read-before-write | protected-read-runtime | What protected read surfaces must exist before writes. | Protected read runtime and response policy evidence. | technical-owner | unresolved / not-stored / blocks-implementation |
| gap-27-write-endpoints-later | protected-write-endpoints | What protected write endpoints are allowed later. | Endpoint validation, audit, retention, role, and response policy evidence. | technical-owner | unresolved / not-stored / blocks-implementation |
| gap-28-support-incident | rollback-and-incident-support | What support or incident process is required. | Support, incident, rollback, and stop-condition evidence. | program-lead | unresolved / not-stored / blocks-implementation |
| gap-29-smallest-safe-scope | small-pilot-scope | What the smallest safe pilot scope could be. | Small pilot group, duration, support, and exit criteria evidence. | program-lead | unresolved / not-stored / blocks-implementation |
| gap-30-language-risk | language-and-confusion-risk | What language risks could imply surveillance, punishment, clinical claims, or launch readiness. | Visual QA, handoff, and wording review evidence. | operator | unresolved / not-stored / blocks-implementation |
Required Evidence By Category
identity-policy
identity policy evidence
required-before-implementation not-storedaccess-boundary
access boundary evidence
required-before-implementation not-storedpseudonymous-actor-policy
pseudonymous actor policy evidence
required-before-implementation not-storedrole-mapping-policy
role mapping policy evidence
required-before-implementation not-storeddraft-content-policy
draft content policy evidence
required-before-implementation not-storedpull-up-safety-policy
pull-up safety policy evidence
required-before-implementation not-storedpush-up-recognition-policy
push-up recognition policy evidence
required-before-implementation not-storedsubject-consent-and-notification
subject consent/notification evidence
required-before-implementation not-storedstaff-review-procedure
staff review procedure evidence
required-before-implementation not-storedreviewer-permission-policy
reviewer permission evidence
required-before-implementation not-storedharmful-content-escalation
harmful-content escalation evidence
required-before-implementation not-storedmorning-sheet-visibility
Morning Sheet visibility evidence
required-before-implementation not-storedretention-policy
retention/deletion evidence
required-before-implementation not-storeddeletion-policy
retention/deletion evidence
required-before-implementation not-storedaudit-policy
audit policy evidence
required-before-implementation not-storedaudit-visibility
audit visibility evidence
required-before-implementation not-storedai-use-policy
AI-use policy evidence
required-before-implementation not-storedschema-and-migration
D1 schema review evidence; local migration validation evidence; active migration approval evidence; rollback evidence
required-before-implementation not-storedprotected-read-runtime
protected read route policy evidence; protected API response policy evidence
required-before-implementation not-storedprotected-write-endpoints
protected write endpoint policy evidence
required-before-implementation not-storedrollback-and-incident-support
support/incident evidence; rollback evidence
required-before-implementation not-storedsmall-pilot-scope
small pilot approval evidence
required-before-implementation not-storedlanguage-and-confusion-risk
language and confusion risk review evidence
required-before-implementation not-storeddistribution-and-sharing
distribution and sharing policy evidence
required-before-implementation not-storedOwner Role Labels
Outside-App Documentation Guidance
- document real debrief notes outside the app
- do not store evidence gaps in the app
- do not store observations in the app
- do not store approvals in the app
- do not store decisions in the app
- do not copy resident, staff, identity, draft, clinical, legal, medical, or trauma details into the app
- summarize gaps as policy/technical questions only
- convert outside-app findings into future planning prompts only after review
- keep implementation no-go until approvals and technical gates are complete
What Not To Document
Conversion Rules For Future Planning Phases
- each evidence gap may become a future planning phase only after outside-app review
- no gap row becomes implementation authorization
- no gap row becomes an approval record
- no gap row becomes a staff decision
- no gap row becomes a live task record
- future phases must remain planning-only until explicit implementation approval
- technical gaps require policy approval before schema/API work
- privacy gaps require privacy-owner review before any storage planning
- staff workflow gaps require staff-review-lead review before any review queue design
- AI-use gaps must remain blocked until explicit AI-use policy exists
- Morning Sheet visibility gaps must remain blocked until visibility, consent, and review policy are approved
Stop Conditions
- evidence gap page is interpreted as a live register
- reviewer believes gaps are being stored in the app
- reviewer believes approval has been recorded
- reviewer believes implementation may begin
- reviewer asks to enter real names, emails, draft content, staff notes, or sensitive details
- any page implies live workflow, live draft collection, protected APIs, protected live routes, database reads, or database writes
- any page implies tracking, scoring, participation analytics, discipline, compliance, surveillance, or clinical validation
- any owner role is replaced by a real person name or email
- any collection surface, entry control, selection control, long-text entry control, action control, export/download control, note-entry surface, or persistence control appears
What Remains Blocked
Recommended Next Phase
Phase 10.21 — Staff/Privacy Review Packet Handoff Freeze, Planning Only
The evidence gap register plan now feeds a read-only evidence gap review sequence with categories, owner role labels, source pages, static unresolved rows, outside-app documentation rules, conversion rules, and stop conditions without storing gaps, observations, notes, approvals, decisions, protected APIs, protected live routes, reads, writes, or live workflows. The next planning phase may freeze packet route order, review status, and handoff instructions as a no-go review artifact while keeping approvals, decisions, protected APIs, protected live routes, reads, writes, storage, and workflow activation blocked.
Boundaries: no live register; no note capture; no observation storage; no evidence-gap storage; no approval recording; no decision storage; no protected live routes; no protected API routes; no database reads; no database writes; no active migrations; no draft storage; no account storage; no actor storage; no identity capture; no staff decisions; no Morning Sheet placement; no tracking; no analytics; no scoring.
recommended-next