Integration adapters
Each adapter publishes an explicit contract and a defined source-unavailable behaviour.
Source unavailable behaviour: Use authorized snapshot where freshness is governed; if freshness cannot be established for a mandatory document → HOLD.
Source unavailable behaviour: Use last known schedule context; flag planning data as stale, do not block field execution.
Source unavailable behaviour: Permit validity that cannot be verified is treated as unverifiable → HOLD. No local approval substitute.
Source unavailable behaviour: Approved contingency verification only if organizationally permitted; otherwise mandatory control evidence unavailable → HOLD.
Source unavailable behaviour: Competency validity that cannot be verified for a mandatory activity role → HOLD.
Source unavailable behaviour: Fitness flag not confirmed → assignment cannot be counted toward workforce readiness. No clinical data is ever retrieved.
Source unavailable behaviour: Analytical only — never blocks field execution.
Unresolved reconciliations
Divergent versions are preserved in full and routed to the accountable authority.
Stale or unverifiable snapshots
Snapshot validity is a governed enterprise policy, not an invented time limit.
Degraded-mode matrix
- Analytical Analytics platform unavailable — field work continues unaffected.
- Blocking Mandatory permit validity unverifiable — HOLD.
- Degradable Connectivity unavailable — approved offline operational package.
- Blocking Critical control platform unavailable — approved contingency verification if organizationally permitted, otherwise HOLD.
- Blocking Mandatory critical-control evidence unavailable — HOLD.
Recovery sequence
Service availability is not operational recovery.
- 01Restore service
- 02Compare source versions
- 03Detect changes
- 04Reconcile offline events
- 05Resolve conflicts
- 06Verify evidence integrity
- 07VERIFIED