A safety
receipt layer is interposed between an electronic health
record (EHR)
system and
clinical decision support intervention (DSI) engines, including AI-assisted DSIs. For each DSI episode, the layer constructs a canonical clinical context envelope, evaluates a policy graph, and computes a permit outcome (permit, guarded permit, override, deny) that is enforced in a permit-before-action, fail-closed configuration. A time-of-check-to-time-of-use latch binds policy evaluation and any anchoring
precondition to rendering and EHR write-back so outputs cannot be finalized without an affirmative permit or recorded override. The layer emits a structured,
machine-verifiable safety
receipt encoding policy identifiers, the context envelope or a cryptographic digest of a canonicalized field
list, the permit outcome, requested and effective behavior
modes, and clinician response. Receipts are anchored in an
append-only verifiable log with maximum-merge-
delay signed heads and inclusion and consistency proofs, enabling
verification, role-based views, monitoring, and mappings to health IT transparency or certification requirements.