Integrations and safe changes
Integrations
Section titled “Integrations”| Integration | Use | Boundary |
|---|---|---|
| Privy | Session and optional attribution | Service key authorizes M2M routes |
| PostgreSQL/Drizzle | Metadata, drafts, audit, queues | Protected clinical data |
| R2 | Encrypted originals | Decrypt only after scope check |
| pg-boss | Extraction, dead letter, submission | Workers only when enabled |
| Nebius | Structured extraction | De-identification is not a guarantee |
| RheumAI audit proxy | Grade or submit for review | Cannot approve or register |
| Clinician agent | Inventory and extraction for one clinician | Cannot approve or submit |
| Tenki | Playwright microVM | Requires explicit config and outbound access |
| BIOBADAMEX | crdA–crdE form | Map does not cover every control |
Configuration names
Section titled “Configuration names”Names only, never values:
BIOBADAMEX_QUEUE_ENABLEDBIOBADAMEX_REGISTRY_SUBMIT_ENABLEDNEBIUS_API_KEY,NEBIUS_BASE_URL- M2M intake key and optional
BIOBADAMEX_INGEST_MEDIC_ID BIOBADAMEX_AUDIT_API_KEY- clinician-agent key and configured
onBehalfOfclinician - R2 variables and encryption master key
- Tenki token, image, and workspace
- registry base URL and credentials
Never copy values into files, docs, commands, logs, or PRs.
Invariants
Section titled “Invariants”- Check owner before R2 decryption.
- Keep
agentRecordimmutable. - Recompute DAS-28 and missing fields after correction.
- Never convert
unknownto zero orfalsegenerally. - Keep approval separate from submission.
- Recheck ownership, state, missing fields, confirmation, and flag at submission.
- Use payload map version.
- Do not equate idpac/summary with field-level read-back.
- Keep study data separate from clinical workflow.
- Documentation never authorizes deploy, migration, or external write.
Change and test map
Section titled “Change and test map”| Change | Files | Minimum verification |
|---|---|---|
| Intake | intake/uploads | intake, batch, upload tests |
| Extraction | extract/config | extractor, failure, schema tests |
| Tri-state/completeness | registry package | full registry suite |
| Review/correction | drafts + UI | draft, preview tests, web typecheck |
| Queue | queue/jobs | jobs, dead letter, lifecycle |
| Map/worker | map/resolver/filler/driver | registry and worker suites; bundle |
| Submission | submit + Tenki | mocks only; never live submit |
| Audit/agents | audit/agent | fail-closed keys, scope, no external mutation |
Observed validation
Section titled “Observed validation”pnpm --filter @pokta/biobadamex-registry testpnpm --filter @pokta/biobadamex-registry-worker testpnpm --filter @pokta/api test -- <focused files>pnpm exec turbo run typecheck --forceAt the documented commit: registry 190 tests, worker 41, focused API 156, and forced typecheck 12 tasks all passed. No migrations, deployments, clinical queries, or registry writes ran.
Risks that must remain visible
Section titled “Risks that must remain visible”- Plaintext clinical text in extraction queue payload.
- Best-effort de-identification.
- Approval checklist mainly client-side.
- Best-effort nonfatal field filling.
- Incomplete and ambiguous external map.
- No field-by-field read-back.
- No registry-submit-specific retry policy.
- Pending clinician-facing descriptions in pipeline config.