Sign in Create account
Witnessed events · In development

The second check is required.
Whether it happened is unknowable.

Insulin, heparin, chemotherapy, concentrated electrolytes — the drugs where a decimal point is the difference between a dose and an autopsy. The standard asks a second clinician to independently verify drug, dose, rate, route and patient. What gets recorded is a set of initials, which cannot distinguish a genuine independent check from a glance and a signature.

Two credentials · captured at the moment of verification · not reconstructed afterwards

Verification · sealed

● 2 of 2 signed

Heparin infusion — 1,200 units/hr

Pump setting confirmed against order

DL

D. Lang · administering

RN · TX-3310 · signed 14:22:04
MP

M. Prakash · verifying

RN · TX-7756 · signed 14:22:41

Sealed — both signatures verify

Editing anything breaks it visibly

Why the current double-check fails.

The clinicians are not cutting corners. The design of the check makes an honest one and a hollow one look identical on paper.

Confirmation bias defeats it

A second person shown someone else’s work tends to see what they expect. A truly independent check means calculating it separately, and nothing in the record shows whether that happened.

It is interrupted work

The verifier is pulled from their own patients. The check competes with everything else on the unit, and the fastest way through is initials.

Initials carry no time

A signature captured at the bedside and one added when charting catches up are indistinguishable afterwards.

What a real double-check seal looks like.

Both people sign the same record, at the moment it happens, each bound to their own credential. Neither can produce it alone.

At the pump

Both clinicians sign the same computed values

Drug, dose, rate, route, patient and the actual pump setting are sealed as one record. Not two sets of initials in adjacent boxes — one fact, signed twice.

At signing

The licence is captured, not asserted

Each signature carries the signer’s credential and role as part of the sealed content. A credential typed in later is not a credential.

Enforced

You cannot verify your own work

If both signatures resolve to the same credential the record refuses to seal. That refusal is the control, so it lives in the cryptography rather than in training.

Afterwards

Any edit breaks it, visibly

Change the dose, the rate or either name and the seal stops verifying. Not a flag someone has to notice — a broken record anyone can confirm independently.

Who this protects.

The nurse who checked properly

When an error is investigated, a sealed record they could not have altered is worth more than a colleague’s memory of a busy afternoon.

The safety officer

Double-check compliance becomes a measurable fact rather than an audit of initials, and gaps appear as broken seals.

The patient

The only reason any of this exists. A check that is provably independent is a check that actually caught something.

Where this actually stands.

We’d rather tell you plainly than let you find out on a call.

What exists today

  • The two-person seal is built and tested in our signing library
  • Self-witnessing is refused at the cryptographic layer, not by policy
  • Tamper-evidence and independent verification already run in our live review product
  • The signing key is published, so anyone can verify a sealed record without an account

What does not exist yet

  • A clinician-facing verification flow at the point of administration
  • Integration with any pump, eMAR or EHR
  • Per-signer keys — credentials are captured, but signing runs on a service key today
  • Any deployment in a live clinical setting

So this is a pilot conversation, not something you can buy this afternoon. If the problem is real where you work, that’s exactly who we want to build the first one with.

Talk to us about a pilot.

The founder reads every message and will tell you honestly whether this is ready for what you need.