Skip to the guide
Jejak AI User guide
Go back to the product page

How to use Jejak AI.

This guide is in English, the same as the console it describes. Part 9, The informant app, is in Bahasa Melayu, for the parents and teachers it is written for.

1

Getting in

1.1Signing in

The Jejak AI clinic console is at https://app.jejak-app.my. It opens in a browser; there is nothing to install. There is also an installed build for macOS and Windows, built from the same source; see 1.1c below for what is different about it.

Sign in with a handle and a password. A handle is a short pseudonymous code such as MO-SUP1, never your name. The cloud system does not store staff names.

If sign-in fails you get one message. It is the same message whether the handle is wrong or the password is wrong. This stops someone guessing which handles exist.

A session expires after a set period. When it does, the console returns you to the sign-in screen and you sign in again.

1.1bIf you forget your password

Ask an admin to reset it. They set a new one and tell you what it is, in person or however you already talk to each other. Nothing is sent to you. The system has no email address, no phone number, and no name for any account.

An admin cannot reset their own password. They ask the other admin, and that is the reason a clinic should have two.

If you are the only admin and you are locked out, use the recovery code you were given when your account was created. It is a code like K7RM-4TQX-92HB-NDF3-WYP8, shown once on screen at that moment and never again, so it is on a piece of paper somewhere if anyone wrote it down. Sign-in takes it in place of a password once, you set a new password, and you are issued a new code on the spot.

Two things to know about that code before you need it:

  • It works once. Using it consumes it, and the replacement is shown once in the same way.
  • Anyone holding it can take the account. It is worth the same as the password. Keep it where you would keep a safe key, and if you find it has been used and it was not you, treat the account as compromised and have the other admin reset it.

Accounts created before August 2026 have no recovery code, because none existed then. An admin reset issues one.

1.1cOn an installed desktop console: the name vault on this computer

This section is for the macOS or Windows app, built and installed with tool/build_desktop.sh rather than opened in a browser. The browser console at https://app.jejak-app.my does not do any of this: it keeps names in the browser's own storage, with no passphrase and no lock.

Once you have signed in on a desktop install, you may see a second screen before the dashboard, asking about the names held on this one computer. How to tell which state you are in, and what each does:

  • Set a passphrase for this computer. This computer has never held a vault. Choose a passphrase now and type it a second time in the Passphrase again field below it. The two have to match, or Those do not match. appears and nothing is saved. The passphrase you set opens the vault on this computer from here on. Nothing is written to disk until the first name is saved.
  • Unlock names on this computer. A vault already exists on this computer. Enter the passphrase that was set for it; there is only one field here, since a wrong entry can simply be retried. A computer holding photographs and no names asks this, not the one above. Photographs are sealed under the same passphrase, and the names file is not written until somebody types a name, so a computer where paperwork was photographed and no child was ever named has a vault with nothing in its names file. Getting it wrong shows That passphrase does not open the vault. and asks again; there is no way past a wrong entry other than the right passphrase or Work with codes.
  • Work with codes. Skips the prompt for this sign-in only. Every screen shows the MRN instead of a name, exactly as it does when no vault is bound at all. Nothing about the clinical record changes: this is a display choice, not a data one. Photographs are the one exception: taking or viewing one needs the passphrase, so working with codes for the rest of this sign-in means photographs stay unavailable until you sign out and unlock. The prompt returns the next time you sign in, not only the next time the app is opened: signing out re-locks the vault, so a second clinician on the same computer is asked for the passphrase again rather than inheriting whatever the first clinician chose.

A forgotten passphrase costs everything held on that one computer. Every clinical record lives in the cloud under its MRN and never held a name, so a lost passphrase cannot lose a note, a score, or a diagnosis. There is no recovery for the old vault file.

Two things are in the vault, and they are not lost in the same way. The names come back with effort. Set a new passphrase and type them in again from your own referral letters. The photographs do not come back. Nothing else holds a copy, because keeping a child's picture on this computer instead of in the cloud is the point of the vault.

This vault is one computer, not the clinic. A name typed here is not visible on a colleague's machine, on the browser console, or on another installed copy, even in the same building.

If a machine that used to hold names suddenly asks to set a NEW passphrase after an update, do not assume the names are gone. The app moves an older vault to its current location once, the first time it starts after an update, before it asks for a passphrase. That move can fail if the app lacks permission to write, and when it does the app starts as if it had never held a vault. A failed move writes one diagnostic line to the Mac's own system log, findable in Console.app or with:

log show --predicate 'process == "Jejak"' --last 1h

The line names the error and the two paths involved. It never names a child.

1.1dHow you find out there is a new version

On the installed Mac console only. The browser console always serves the current version, so there is nothing to install and nothing to notice.

Three things point at an update, deliberately, because one was not enough:

  • A dialog a few seconds after you open the app, naming the version and waiting for a click. It only appears when there IS something. Nothing ever installs without it.
  • A dot beside Settings in the left sidebar, which stays there until you update. This is the one that survives closing the dialog.
  • A row at the very bottom of the sidebar reading "Update to 0.1.6", in place of the usual quiet version line. Clicking it brings the dialog back.

Nothing installs on its own. You are always asked, every time, and closing the dialog leaves you exactly where you were. Settings, My profile also has a Check for updates button if you would rather ask than wait.

Corrected 17 August 2026. Before that date this app checked for updates on a daily schedule and never once at launch, so a console opened and closed inside that window checked ZERO times. An installed copy sat on 0.1.4 with two newer versions published, showed nothing, and found the update the instant someone pressed the button by hand. If you are reading this on a build that still behaves that way, the button is the whole answer.

1.1eTelling the console what to call you

Settings > My profile > Your details. Three boxes: your full name, the name you would like to be called, and an email address. Save is a button, so nothing is written while you are half way through typing.

Set a preferred name and the dashboard greeting and the top bar both use it, straight away, without signing out.

All three stay on this computer. They are stored the way the theme and the collapsed rail are stored. They are never sent anywhere. Sign in on a second computer and you set them again there.

The email is stored for your own reference and nothing reads it. The console sends no mail of any kind.

1.2What your role can reach

Every account has exactly one of four roles. The first three are a ladder; the fourth is not on it.

Role Can do
Clinician The whole clinical loop: enrol, collect, score, read, write and sign notes
Supervisor Everything a clinician can, plus the Service view and the schools registry
Admin Everything a supervisor can, plus accounts, model configuration and agent telemetry
Preview Read the sandbox, ask Jeji, generate a document. Change nothing else, anywhere

Preview is not a junior clinician. It is a public account with a published password, so that somebody can look at the working console without being given one of their own. It reads invented patients only and the server refuses every write it makes. See 8.1c.

The left rail groups its rows into Clinic (Dashboard, Service view, Safety lane), Records (Patients, Enrol) and System (Settings, and Admin where your role allows it). The rail collapses to icons if you want the width back.

An Admin row appears for admins, and also for supervisors, who see it for the schools registry alone.

Two points about how that gate works:

  • Hiding a row is cosmetic. The rail hides doors it does not hold them shut. The server checks your role again on every request.
  • Some doors are visible to everyone and refuse at the server. Service view is one. Every role can click it. A clinician who does gets a panel saying the service view is for supervisors and admins.

1.3Sandbox and live

The system runs against two separate databases, and which one you reach is decided by the account you signed in as.

  • Sandbox holds invented patients, for demonstration, training and development. No child in it is real.
  • Live holds the real clinic record.

Every screen inside the console shows which one you are in, as a badge in the top bar, beside the clock. Sandbox is loud and yellow. Live is a quiet neutral chip.

Some things follow from this that are worth knowing up front:

  • An account belongs to one mode and cannot see the other. A sandbox session asking for a live child is answered as though that child does not exist, because in the database that session can reach, it does not.
  • The mode is fixed when the account is created. An admin can move an account to the other mode, and the move takes effect at that account's next sign-in. An admin cannot move their own account.
  • An account created before modes existed reads as sandbox. That is the safe direction to fail, and it is why every account provisioned to date is a sandbox account.

1.4The clock in the top bar

Beside the mode badge is a date and time. Tapping it expands a small control that moves the console's view of "now" forward or back, a week or four weeks at a time, with a Now button to return.

This is for looking at how a child's trajectory, the waiting list or the morning brief reads at another point in time, without waiting for that time to arrive. It is a view-only offset. Nothing you save is stamped with the shifted time: stored records keep their own absolute timestamps, and a note written while the clock is shifted still records the real instant it was written. The pill is highlighted whenever the clock is away from now, so a shifted view never looks like the present.

1.5What an admin sees in sandbox

The rail carries every row in section 1.2, Admin included, and the badge reads Sandbox.

The sandbox clinic holds invented children, among them MRN-TEST, the single record where development affordances are allowed to appear. The safety lane shows whatever the red-flag corpus has raised on their submissions. Service view opens and computes its measures from the records present rather than reading a stored figure, so an empty clinic gets a fully formed view of zeros rather than an error.

Under Admin you get five entries:

Entry State
Users & roles Working. Provisions accounts against the real server.
Schools registry Working for reading and creating against the canonical directory.
Audit log Not built. The screen says so. There is no backend behind it.
System config Working. Holds the clinic letterhead, the council provider and the model pins. The last two report unconfigured without model credentials; the letterhead works either way.
Agents Working, but reports nothing without model credentials.

1.6Telling whether the model-backed features are switched on

A Jejak AI deployment can run with or without credentials for a language model. You can read off the screens which one you are on.

Nothing clinical depends on the answer. Enrolment, informant collection, scoring, notes, the record and the Service view all work either way. In particular, SNAP-IV and PSC-17 are scored by ordinary code with fixed tests and never by a model, and that is a design rule rather than a current limitation.

What changes:

Where to look Credentials present Credentials absent
Admin, System config Lists the model catalogue and the pin for each lane Reports unconfigured
Admin, Agents Reports the calls the server has made Nothing to report
A child's record, case summary and draft Available Absent, not an error
Red-flag screening Runs both tiers Runs the clinician-graded phrase corpus alone, and records the second tier as unconfigured

Two of those are worth knowing. The generated documents are absent rather than a failed button: a deployment that cannot do the work does not advertise it. Screening records unconfigured rather than a clean pass, so a passage the corpus did not catch is never mistaken for a passage a model looked at and cleared.

Switching this on is a configuration change to the deployed service, not a change to the software.

On the current deployment, they are switched on. Checked 4 August 2026 against the running service: both vendor keys are configured, the council route is registered, and the model-backed lanes are live.


Next: 2. The clinic day.

2

A clinic day

This part is for clinicians. It covers what you see when you sign in, what has arrived since you last looked, how the waiting list is ordered and why, what the safety lane is for, and how to open a child's record.

2.0What has arrived since you last looked

Three things arrive in a clinic on their own: a parent or teacher completes a form, the screener raises a concern in a child's text, and a draft you asked for finishes. The console tells you about the first two on the rail and about all three on the child's row.

A number on a rail row is a number of CHILDREN, never of records. Five concerns raised about one child is one child, and the row says one. If you want the record count, open the destination and count the rows.

  • Patients carries the number of children with a form you have not seen.
  • Safety lane carries the number of children with a concern you have not seen.

No other row carries one. Settings has its own mark for a waiting app update. A mark on every row that ever has news stops the rail from meaning anything.

On the cohort lists, the child's own row says "new". A mark, not a number: the rail already told you whether there is anything, and you are about to open the record and see what it is.

How to tell what state you are in

  • No number on a row means one of two things and they look the same: there is nothing new, or the console has not been able to read the summary yet. It never means a read failed and was reported as "nothing". If a read fails the last number you were shown stays where it is rather than dropping to nothing.
  • Your first sign-in shows no numbers at all, on a clinic of any size. "New since you last looked" has no meaning before there is a last look, so the clock starts at your first sign-in and the feature begins working on your second. A number in the forties on day one would only teach you to ignore it.
  • The numbers are as old as your last refresh. They are not live. They update when you refresh and when you move between screens, and if you leave the console open for an hour they are an hour old.

What clears them

Opening the thing clears it, and only the thing you opened.

  • Arriving at Patients clears the Patients number. It does NOT clear the "new" marks on the rows, because arriving at a list is not reading the children on it, and those marks are how you find them.
  • Opening the Safety lane clears the Safety lane number, and likewise leaves the row marks alone.
  • Opening a child's record clears that child's mark and no other child's. It does not move either rail number.

Your marks are yours. They are stored per clinician in the cloud rather than on the machine, so the installed console and the browser agree about what you have seen, and a colleague signing in on the same machine sees their own.

2.1The dashboard

Dashboard is the first row in the rail and where signing in leaves you. It is a reading surface: nothing on it changes a record.

A greeting sentence sits at the top, then a row of cards.

A search box sits above the greeting. Type a child's code, or the name this device holds for them, and the matches appear underneath; tapping one opens that child's record. It reads the clinic list the first time you touch the box, so it works on the simple view as well as the detailed one, and it keeps working while the cards below are still loading. It lists the first six matches and says how many there are in total.

There is no chart on the dashboard. The trend charts you can trust are on a child's own record (section 5.4), drawn from that child's scores.

If you want to know how current the screen is, read the clock in the top bar. The brief is recomputed every time the screen is drawn.

Today's visits lists the appointments booked for today, in time order, taken from the appointment book. An empty list says so in words. Tapping a row opens that child.

Needs attention is two things stacked. First, how many work-ups are ready to review. Then the top few children on the waiting list, most urgent first, each one tappable. If the list is still being ranked it says so. If the ranking failed it says that. The two are different messages, and the still-ranking one has a small moving mark beside it. The failed one has no mark, so you can tell them apart without reading them.

Children waiting is the full waiting list in the same order.

Queue changes shows where the ranking moved a child: the position they held in a plain first-come queue, the position they hold now, and the reason.

Automatic checks carries one line each from the three checks the console runs for you. See section 2.4.

If no child has been enrolled yet, all of that is replaced by a single panel saying the clinic is empty, with the enrolment action on it. The cards are not rendered as empty shells, because a row of zeros looks like a broken read.

How to tell the console is still reading

Anywhere the console is waiting for something, you see the Jejak trail walking: the footprints light along the rising path and the endpoint fills as it gets there. Beside a button or a heading, where there is no room for that, it is a small turning ring instead. Either way, something moving means "still reading", never "finished" and never "broken".

It does not tell you how far along it is. Nothing fills up like a progress bar. (The bars on the informant forms are real: they count questions answered out of questions asked.)

When the answer arrives, the mark fades out as the content fades in. A screen sitting on the trail for longer than a few seconds means a slow connection. A read that has failed says so in words and offers a retry.

Moving between screens fades as well, both in the left rail and when you open a child, and nothing slides across the window any more. If you have reduced motion turned on for your machine you get none of it: screens change straight over and the waiting mark holds still.

2.2How the waiting list is ordered

The order is suggested, and it is suggested by a rule you can read rather than a model. Every child sits in one of three bands.

Band Who is in it
Urgent An active red flag, or a clinician escalation on a signed note
Elevated Aged 60 months or under: inside the early-intervention window, where being seen sooner carries outsized benefit
Routine Everyone else, ordered by how long they have waited

Within a band, longer waits come first, and younger children first where waits tie. On top of that, the trends check lifts any child whose scores are deteriorating into the urgent tier, just below an active red flag.

Three things about this are worth knowing:

  • Every placement carries a reason. The reason names what moved the child.
  • The clinician decides. The ranking is a suggestion about reading order. It books nobody and changes no record.
  • A child in active management has left the queue. The waiting list is for the registration phase only.

2.3The safety lane

Safety lane in the rail opens every open red flag across every child, grouped by child, most life-threatening first. A line above the queue gives the two numbers that matter together: how many flags are open, and how many children they are spread across. Those are not the same number, and a child can hold several.

The order is triage, not chronology. Categories rank in this order, worst first: suicidality, self-harm, safeguarding concern, harm to others, neglect. A child's place in the queue comes from their single worst open flag, so one child with a suicidality flag sits above a child with three neglect flags. Having more flags never moves a child up. Where two are equally serious, the more recent comes first, at both levels.

The dashboard's red band follows the same order, so the flag it shows you is the worst one open, not the newest.

Each child's block carries their code, a count when more than one flag is open for them, Open record, which goes straight to that child's Management tab, and Acknowledge all N when more than one flag is open for that child.

Each flag carries the category, a chip naming what raised it, and how long ago. Hover the mark beside the time for the exact date and time it was raised.

There are two things you can do with a flag, and both are on the card:

  • Acknowledge, or Acknowledge this one when the child has several open and you have only acted on this one. Either opens the acknowledgment box described below.
  • Why this was flagged opens the flag out, with the exact date and time and the layer that raised it. A flag a model raised opens on a tinted card headed by NAMI and names the model. A phrase match opens on a plainer bordered card. A flag a clinician coded opens with neither. This difference helps you see who or what raised it.

Flags come from screening the free text on an informant's submission against a phrase corpus a clinician graded, from a cloud model reading the same text, or from a clinician's own coded risk assessment.

Acknowledging

One box covers every open concern for one child. If three are open, you acknowledge all three once, with one account of what you did. Each concern is still recorded separately, and each one cites that same account, so the record never suggests you deliberated three times.

The box offers four steps:

  1. Contacted the caregiver
  2. Reviewed the safety plan
  3. Informed the supervisor
  4. Booked a review

They are recommended and none of them is required. There is no fit for all in mental health, so what you actually did goes in Your note, in your own words.

The one rule is that the record is never empty. Acknowledge stays dead until you have ticked at least one step or written at least one sentence, and a line under the box says so while it is dead.

Do not write a name, a phone number, an address or a school in the note. A note carrying one of those is refused and nothing is saved, so you can take it out and acknowledge again without retyping the rest.

What gets recorded. Each acknowledged concern gets its own entry on that child's Timeline tab, carrying the steps you ticked, your note, and the handle you signed in as. This works for a child who has never been seen in clinic, which matters because a red flag often fires while a child is still on the waiting list. Acknowledging does not close the concern and nothing on screen says it does: it records that you saw it and what you did about it.

Acknowledging from the red band on the dashboard works the same way, for the one flag that band is showing.

Flags by school

Under the tally, and above the children, sits a card that groups the same open flags by the school each child attends. A school appears only when three or more of its children have an open flag. One child with several open flags is one child, so a school never appears on the strength of one busy record.

The card says which school it is, its district, and how many of its children have an open flag out of how many are enrolled there. Both numbers, because three of four and three of forty are different situations.

This never leaves the clinic. It is the clinic's own caseload, on a screen where you can open every one of those children's records, so nothing is hidden and nothing is rounded. The suppression rule you have read about elsewhere in this manual applies to figures that get PUBLISHED, and none of these are.

Draft a summary for these N children starts one suggested summary per child, drafted from that child's own record. It tells you how many it will start before it starts anything, and it leaves out any child with nothing on file yet, because a draft built from an empty record can only report gaps. Each draft then appears in that child's own record when it is ready; the button does not wait for them, and each child succeeds or fails on their own.

Three states, and they mean different things:

  • A school listed: three or more of its children have an open flag right now.
  • No school has three or more children with an open flag. The check ran and found nothing. This is the ordinary state.
  • Could not check which schools these children attend. The check did not run. The queue below it is unaffected and still complete.

2.4What the three checks contribute

The Automatic checks card carries one line each. None of them acts.

Forms and work-ups watches the work-up: which forms have gone out, which are overdue, which submissions have arrived and been scored, and which children now have a complete enough picture to review. Its line is the only one scoped to a window, and it names that window on screen. Read it there rather than from this manual: the value has been changed once already.

"Issued 1 form" and "scored 3 submissions" are things that happened. "3 forms to chase" is a suggestion. It surfaces that three are overdue. Contacting the family is yours.

Trends reads the scores over time: children whose scores are worsening, children responding to titration, and children where your own recorded impression disagrees with what the instruments show. That last one is a discrepancy, and it is surfaced as a count for you to look at, never as a flag against you. This one reads a child's whole history, not a window.

Waiting list reports that it has ranked the waiting list, and points at the Queue changes card for the detail.

All three are computed when the page loads.

2.5Opening a child

Every row that names a child opens that child's record: the visits list, the needs-attention rows, the children waiting, the queue changes. Patients in the rail opens the same list as a full screen.

What you find there is part 5.

Patients is one table. One row per child. The children still waiting for a first appointment come first, in the triaged order, under a heading that says so, and everyone in active care follows under theirs. The columns are the child's code and name, age and sex, care phase, triage priority, concern, next visit, and how long they have waited.

The search box and the filter chips run over the whole clinic, never over the rows on screen. The box matches on the code and on the name this device holds. The chips narrow by care phase, by triage priority, and to children carrying an open safety flag; picking more than one narrows further, not wider. The line beside the card heading says how many children match out of how many the clinic holds.

Clicking a column heading sorts the whole list by it. Click it again to reverse it, and a third time to go back to the triaged order.

A long list arrives fifty rows at a time, with a Show more button under the last one. Searching still reaches a child whose row has not been drawn yet.

The rows scroll inside the card, and the column headings stay where they are. The search box, the filter chips and Show more stay put with them, so what is on screen at row forty is the same set of controls as at row one. On a window too narrow for every column, the table scrolls sideways inside its own card rather than moving the page, and the headings scroll with the columns they name.

Two columns are EMPTY for a child in active care, and that is the answer. Priority and Waiting both describe the queue for a first appointment. Triage answers who should be seen first, which is settled once a child is in care, and a child in care is no longer waiting, so neither column has a value rather than having a low one. Hover the question mark beside either heading and it says so.

Next visit is read for the rows on screen, so it fills in a moment after the rest of the row. None booked means nothing is in the appointment book for that child. Not known means that read failed.

When Patients cannot tell you something, it says so. Two things can go wrong there, and they look different on purpose.

If the page reads Could not load the clinic. with a Try again, the console could not fetch the children at all. That is not the same as an empty clinic, and the page will not say "No children enrolled yet." unless it genuinely got an answer and the answer was none. Tap Try again. If it keeps saying it, nothing on this page is current.

If the page still lists children but they sit under All children with no order, and the line above reads Could not work out who to see first., then the records loaded and the ranking did not. Every child is there and every record opens as usual. What is missing is the ordering, so the page will not tell you who is waiting and who is in active care until you tap Try again and it works. It drops those two headings rather than guessing, because a guess would put children in the wrong one. The priority and waiting columns come off with them, for the same reason.

If the line reads Could not check for open safety flags., the Concern column is not drawn at all. It is left out rather than showing every child as having nothing, which is an answer the page does not have.

2.6Two things on the dashboard that are not the dashboard

The clock in the top bar shifts the console's view of "now" forwards or back. It changes what these cards show; it changes nothing that is stored. See section 1.4.

Simple and detailed views. A toggle at the top right of the dashboard, beside Enrol patient, switches between the full brief described above and a compact summary. It reads "Simple view" when you are in the detailed one and "Detailed view" when you are in the simple one, so the label always names where tapping takes you. It is a display preference and switching it refetches nothing.

Both controls sit on the dashboard rather than in the top bar. That is how to tell them apart from the clock and the mode badge, which are console-wide and stay in the bar on every screen: anything in the top bar applies everywhere, anything in the page applies to the page you are on.


Next: 3. Enrolling a child.

3

Enrolling a child

This part is for clinicians. Enrolment is the one moment where a real child and a pseudonymous record meet, so it is worth understanding what crosses that line and what does not.

3.1Opening the form

Enrol is a row in the rail, under Records. The dashboard also offers it, and the empty-clinic panel puts it front and centre when no child has been enrolled yet.

3.2What you fill in

Seven things are required. The form tells you which are still missing rather than letting you submit and fail.

Age. Two ways to give it, and the choice matters. You can enter a date of birth, in which case the date stays on this machine and only the derived age in months is sent, or you can enter the age in months directly. Either way the record holds months and nothing finer. The screen shows the derived figure as you type, and the same age in years beside it, so you can check it: 108 and 18 look alike in a box and do not look alike as 9 years and 1 year 6 months.

Everywhere the console READS an age back to you it reads it in years and months, because that is how a clinician holds a child in mind. The record still stores the single number.

Sex. Female or male.

Referral source. School, Klinik Kesihatan, or Hospital.

Referral received. The date the referral arrived. This is what the waiting time is computed from, so it is worth getting right: the form shows the resulting wait in weeks beside the field. A date the form cannot read clears the value rather than keeping the last one it understood, so what you see and what gets sent never quietly disagree.

The child's name. Optional, and it stays on this device. See 3.3 for why.

Referral reason. Free text. It is scrubbed on this machine before anything leaves the room, and the form shows you a live Preview of exactly what will be stored as you type.

Consent. Which parties the consent covers, one or more of Caretaker, School, Self and Care Provider, plus an expiry date. This scope is enforced later: an informant outside it cannot be issued access, and a submission outside it is refused.

3.3The name field, and why it appears where it does

The name box sits above the referral reason. The reason is scrubbed against this child's name, and only the scrubbed text is ever stored. There is no second chance to redact it afterwards. The name has to be on screen before you write prose that might contain it.

The name is used for removal, never storage in the cloud. It is written to the clinic vault on this machine. The scrubber uses it to remove that child's name from anything you type about them. It matches the whole name and its parts, so a vault holding "Ahmad Zulhilmi bin Rahman" catches a note that says "Zulhilmi". Connectors like bin, binti and a/p are left alone.

Leaving it blank is allowed and costs you something specific. The scrubber still catches IC numbers, phone numbers, school patterns and honorific-prefixed names. A bare given name in your prose will not be caught.

Hiding names on screen does not stop redacting them on write. The show-names toggle is a display preference. The air gap is not.

On an installed desktop console (see part 1, "The name vault on this computer"), the vault can be locked when you submit. If it is, the child is enrolled exactly as normal and the cloud record is complete; only the name fails to reach this computer, and the screen tells you so directly: "Enrolled. The vault is locked, so the name did not save." Unlock the vault and set the name again from the child's profile.

A write can also fail for other reasons. That reads "Enrolled. The name did not save on this computer." The child is enrolled either way. Set the name again from the profile once the computer can write.

3.4What submitting creates, and what it never sends

The form says both, on screen, beside the fields. It creates:

  • a pseudonymous child record, with the MRN minted server-side in the form MRN-XXXX, only once you submit;
  • a consent scope for the parties you chose;
  • a waiting-list entry that derives its wait from the referral date.

It never sends:

  • name, IC, address, or school identity;
  • date of birth, only the derived age in months;
  • the raw referral note, only the scrubbed text.

The MRN is minted by the server rather than composed on your machine, so two clinics enrolling at the same moment cannot collide.

3.5After it is created

You get a confirmation with the new MRN and a summary of what was recorded, and two actions: open the child's profile, or enrol another.

One line on that screen surprises people, so it is worth knowing in advance:

Registered, awaiting first review. Informant registration opens after the first clinic review.

You cannot register a parent or teacher yet. A newly enrolled child is in the registration phase. Issuing informant access is a management-phase action. What moves the child into that phase is your first signed note on them. A draft does not count.

Part 4 covers what happens when that moment arrives.

3.6If something goes wrong

The form refuses to submit while anything required is missing and names what. An air-gap violation is refused by the server rather than stored, which you would only see if a forbidden field reached the request, and none of this screen's fields can produce one.


Next: 4. Informants.

4

Parents and teachers

This part is for clinicians. It covers registering the people who answer forms about a child, and the letter they walk out with.

Part 9 is the other half of this, written for the informant.

4.1When you can register one

Register an informant after you have signed a note on that child. Not before.

A child's first signed note is what the system treats as their first clinic review. This moves them from "enrolled, not yet seen in clinic" into active management. Registering an informant is a management-phase action.

  • A draft note does not open it. The child stays in the registration phase.
  • Retracting the note later does not close it again. The review happened.
  • The Add informant button is not on the profile until the child is in active management. It is absent, not present-and-failing.

If you expected the button and it is not there, the child likely has an unsigned note. Hover the ? on the "Enrolled, not yet seen in clinic" chip in the header to see what gate is closed and what opens it.

Once the child is in active management, Add informant appears on their profile and opens the ceremony.

4.2The ceremony, step by step

Step 1: who is this person to the child? Three groups:

Group Covers
Caretaker Parent, guardian, relative, or welfare officer
Care provider Doctor, psychologist, therapist, or other clinician
School Teacher, counsellor, or other school staff

Step 2: their specific role. Father, mother, sibling, grandparent, welfare officer, teacher, counsellor and so on. This matters more than it looks: a child's scores are kept in separate lanes per person, so a mother's ratings and a father's never merge into one series.

Step 3: review and issue. You confirm the child's MRN, the group, the subtype and the demographics, then issue.

Step 4: the registration is ready. You get a QR code, a handle and a claim code.

4.3What gets issued, and what it is not

Two things are minted, and they do different jobs.

A handle, like CTK-MERPATI-17. This is the informant's username. It is a group prefix (CTK, CPR, SCH), a word, and two digits.

The word is drawn from a closed list: landscape, infrastructure and birds like sungai, bukit, perahu, merpati. Floral and celestial words are excluded. The informant does not type a handle. The system offers one. Twenty words and two digits give 2000 combinations per group.

A claim code, like CLM-4T8N-W04. This is a one-time credential for setting up their account. It expires. It can be used once. It can be withdrawn by a supervisor or admin if a letter goes astray.

The screen shows both, plus a line that reads "Name / DOB: not included".

4.4The printed letter

Print registration letter produces an A4 page the family takes home. It is typeset as a letter from a hospital. It carries:

  • the clinic's own letterhead (see 4.6), a reference number and a date;
  • a title, PERMOHONAN KERJASAMA: PENILAIAN KANAK-KANAK, and four paragraphs saying what is being asked and why this reader specifically;
  • the child's name (see below), their MRN, and their age and sex;
  • the informant's handle, group and subtype;
  • the QR code and, beside it, the claim code as typeable text in a monospaced font, with the date it stops working;
  • an AKUAN KERAHSIAAN, the obligation not to pass the information on;
  • an issuer line at the foot.

The letter addresses the reader by their own role. A teacher's says "Sebagai guru kanak-kanak ini", a welfare officer's says "pegawai kebajikan". That substitution is what makes it read as a letter to a person rather than as a form, and it is why the same page works for a parent, a teacher and a welfare officer.

The typeable code exists for a specific person: a parent or older relative whose phone will not scan a QR, or whose letter has spent a week in a bag. The informant app's landing screen has always asked for a typed code; until 3 August 2026 nothing a clinic printed actually carried one.

The reference number is derived from the claim code, not counted. A reprint of the same letter carries the SAME reference. The console shows it beside the code on the child's Access letters card. A letter handed back at a counter can be matched without reading a live credential aloud. The reference is not the claim code itself. A reference can be copied into registers and read over the phone. A working one-time credential must not travel that way.

Before 21 August 2026 the letter carried LTR- and a timestamp instead. That string was built in the print handler, never stored, reset every time the screen was opened, and two clinicians printing in the same millisecond got the same one. It looked like a serial and was not one.

The letter names the child. The name is read from the local identity vault when you press print. A console whose vault is locked, or a clinician who has turned names off, prints the letter WITHOUT the name. The console tells you this before the print dialog opens.

The warning says what will happen. The console cannot tell four situations apart: no vault on this machine, a locked vault, names turned off, or no name stored for this child. It names the things you can act on instead.

The undertaking is on the paper only, for now. The letter states the obligation. Nothing yet records that the informant accepted it.

The language is chosen per print

A Bahasa Melayu / English switch sits above the print button. The clinician picks the language for the family in the room. It is not a saved setting. Malay is selected on arrival.

Reprint after switching if a letter has already been printed in the wrong language. The reference number does not change, so both sheets are the same letter.

The Malay is the product owner's wording. A care provider is a Pemberi Rawatan, never a Penyedia rawatan. Treat every string on this letter the same way.

The letter is the only artifact in this system that travels by hand between the clinic and the family. It carries no name. Identity travels with the person holding it.

4.5What the informant does next

Briefly, since part 9 covers it: they open the informant app, scan the QR or type the claim code, are offered a handle and choose a password. If they already have a handle from another child, they use it, and that one account then covers both children.

Guessing a claim code is throttled. Repeated failed attempts against codes for the same child are rate-limited with a Retry-After, so the codes cannot be enumerated. Verified against the running service on 3 August 2026: nine misses, then a refusal.

One thing to tell the family, because the app relies on it: the MRN shown on their phone must match the MRN printed on the letter. That check is what ties the pseudonymous account to the right child, and it is done by a person, not by the system, because the system deliberately has no name to check against.

4.5bThe recovery PIN

An informant sets a six-digit PIN when they first sign in. It is entered as six boxes, one digit each. There is no skip. An informant who skips has no way back into their account except a new letter and a new clinic visit. Anyone who enrolled before this existed is asked once, at their next sign-in.

The PIN is the second factor for getting back in. An informant who has forgotten their password opens the app, taps "Lupa kata laluan?" under the sign-in button, and enters the code from their letter, their PIN and a new password. The letter alone is not enough and the PIN alone is not enough, which is what makes a letter found on a bus useless.

They can do that even after the letter's registration date has passed. That date bounds registering, not recovering. What stops a letter working is the clinic withdrawing it.

A forgotten PIN is a phone call. A lost letter is a visit.

What happened What the clinic does What the informant loses
Forgot the password Nothing. They recover themselves with the letter and the PIN. Nothing.
Forgot the PIN Informants tab, the informant's menu, Clear PIN. Supervisor or admin only. Nothing. Same letter, same password. They set a new PIN at their next sign-in.
Lost the letter Withdraw it (4.7) and print a new one. Their way back in, until they are handed the new letter.

Withdrawing a CLAIMED letter locks the informant out. The console says so before you confirm. Do this for a letter that has gone to the wrong person. Do not do it for anything else. They cannot sign in and cannot recover until a new letter is printed and handed over.

The console does not show whether an informant has a PIN. Clearing a PIN that was never set is harmless and reports success. The action is safe to use without checking first.

Clear PIN appears only for an informant who has CLAIMED their letter. A PIN belongs to the account. An account is created when the letter is redeemed.

4.6The letterhead

The top of the letter is the clinic's own mark, name and address. Set these under Admin → System config.

  • The mark is a choice from a short list, not an uploaded image. Today the list is the Hospital Al-Sultan Abdullah UiTM lockup, the Hospital Selayang crest, and No mark.
  • The address is a block, not a line. Type the department, the street and the town on separate lines.
  • A clinic that has configured nothing prints the Hospital Al-Sultan Abdullah UiTM mark, name and full postal address. The mark and the name move together or not at all. A clinic that changes one must change both. Set the mark once, in Admin, before printing.

Any clinician can read the letterhead. Only an admin can change it. If the setting cannot be reached when you print, the letter prints with the default. A default letterhead beats no letter.

4.7Multiple informants, and withdrawing access

Two people in the same role stay separate. Two teachers rating the same child are two lanes, not one merged series.

A claim code can be withdrawn by a supervisor or admin before it is used. Record a reason. Withdrawing is stricter than issuing, which any clinician may do.

4.7aThe tab has two halves

The Informants tab opens on the registry. Registered shows who has access, what each has been asked for, and the access letters. What they sent is one tap away and holds two cards.

The two cards under "What they sent" are different records.

  • Questionnaires is a form somebody filled in, with anything they wrote alongside it shown under the form it came with.
  • Notes sent on their own is an informant writing to the clinic with no questionnaire involved. They can do that any day, without being asked. A note carries who wrote it and when. If it was written after 22 August 2026, it also shows which of the informant app's two boxes it came from: something that went well or something they're worried about. Older notes carry neither box.

A note this console cannot read says so. Under the notes there may be a line saying one more note is on file and could not be read here. The note was written by a newer version of the system. Updating usually brings it back.

Each segment counts what is ON the record, not what the group chips are showing. The number covers the questionnaires and the notes together. A segment with no number beside it has not finished reading yet, or one of the two reads failed.

4.8Taking a letter back

Open the child's record, go to Informants, choose Registered, and find Access letters at the bottom. Press Show letters.

You get one row per letter ever issued for this child, newest first, each showing its code and one of four states:

State What it means
Live Still works. Someone could redeem it today.
Used An informant already redeemed it. Nothing to withdraw.
Expired Past its 30 days. It stopped working on the date shown.
Withdrawn Someone took it back. The reason, if one was given, is shown under it.

Withdraw appears only on Live rows, and only if you are a supervisor or admin.

You are asked why. It is optional and it is kept on the record. Names typed here are removed on this machine before anything is sent.

Withdrawing does not remove an informant who has already redeemed a letter. That is a different action. A Used letter offers no Withdraw button.

When to reach for this: A letter handed to the wrong parent, left behind in a clinic room, photographed, or sent to an old address. A custody change where someone who should no longer have access is holding a working letter. Withdraw the letter and issue a new one.


Next: 5. The child record.

5

The child record

This part is for clinicians. It is the longest, because the child's profile is where most of the clinical work happens.

Every row that names a child opens it, from anywhere in the console.

5.1The header

The header carries the MRN, the age and the sex.

The age reads in years and months (age 8 years 2 months). The record stores a single number of months. Under a year it stays in months. A whole number of years drops the months: a child who has just turned two reads 2 years, never 2 years 0 months.

The header also carries a phase chip reading either "Enrolled, not yet seen in clinic" or "In active management". It decides which actions are available (see 4.1).

On a child who has not been seen yet the chip carries a ? mark. Hover it to see what is closed off and what opens it.

Names are shown here only if this device's vault holds one and the show-names toggle is on.

5.1bOpen safety concerns, above the tabs

A band sits above the tab row, on every one of the nine tabs. When a child has no open safety concern the band renders nothing at all. No empty box, no message.

It is amber. Red is kept for the safety lane itself.

It is deliberately quiet: no pop-up, no notification, no sound, no movement, and it never navigates on its own.

Each concern says when it was raised, as a sentence beginning "Raised". Times are shown in the clinic's own local clock.

A small chip on each concern says what raised it. The three it can say are "AI check", "Phrase list" and "Safety check".

A button reading "Review in the safety lane" takes the clinician there.

Acknowledging a concern in the safety lane and returning to the record updates the band, so it does not keep showing a concern that has been dealt with.

If the concerns cannot be read, the band says so rather than showing nothing: "Open safety concerns could not be read." It does not show an empty band, because an empty band means the child is clear.

5.2The nine tabs

Tab What it holds
Overview The referral, consent, counts, and the history review queue
Trajectory Scores over time, one line per rater
Notes Two segments: the composer, and the signed record, searchable
Assessments Scored instruments, computed live from submissions
Photos Photographed pages: a child's handwriting or drawings, read and confirmed
Timeline What has happened, most recent first. The raw access log is off by default
Informants Who is registered, and what they have sent: questionnaires, and notes written without one
Management Treatment plan, form assignments, and the suggested case summary and draft. No composer and no chart: those are the Notes and Trajectory tabs
Access The access ledger: who read or wrote what, when

There are nine tabs and they do not all fit. The row scrolls sideways. Access is the one most often out of view, so scroll the tab row right if you cannot see it.

The tab you are on is in the address bar, as ?tab=trajectory. Reloading comes back to it rather than to Overview. The address can be sent to a colleague to open the same tab of the same child. The code in the address is the child's MRN, never a name. A link with a tab name the app does not recognise opens Overview rather than failing.

5.3Notes

The tab shows the record, and writing is a button. Every signed note is on screen, newest first. Write note opens the composer in a dialog over the record. Pressing Correct on a signed note opens the same dialog with that note loaded.

Signing closes the composer. Signing offers Undo for five seconds at the foot of the window.

Every prose box opens to fill the window. A small arrow sits at the right end of each box's label. Press it to put that one box on the whole screen. Done closes it again. What you type expanded is the same text in the same field. There is no separate draft, nothing to save. Closing the editor puts the caret back where you left it. Escape closes it too.

The signed record has a search box. It filters what is already on screen, so it costs no read and works with the connection down. It matches on the note body, every heading of a first visit, the kind as it is labelled, the date as it is printed, and a retraction's reason. Words can be typed in any order: progress sleep finds a progress note about sleep.

The record shows a first visit in full. An intake note carries eight headings. The list prints every one you filled in, under the presenting complaint, in the order you worked through them. A heading you left blank prints nothing.

A long note is shut until you open it. The newest one is already open. Under a shut note you still see the first few lines and the headings it carries. Show the whole note opens that one. Show less shuts it again. A short note has no control and is always shown whole. While you are searching, every matching note is open.

The words you searched for are marked in the note. Every note the search returns marks your words wherever they appear: in the writing, under a heading, in the note's kind, in its date, in a retraction. A note that was retracted also prints why, and who did it, under the note itself.

It reads the stored, scrubbed copy of a note. A name that was scrubbed out is not in that copy, so searching for the child's name finds nothing. Searching for the word name also finds nothing. Search for what you wrote around it.

Four kinds, and the difference is functional rather than filing:

  • Intake note carries the headings a clerking actually has.
  • Progress note is the routine entry.
  • Working impression carries your structured read of where the child is heading: improving, steady or worsening.
  • Treatment plan carries directives, including which forms should be collected and how often.

A note is a draft until you sign it. Three things follow:

  1. A draft never reaches the cloud. It is yours until signed.
  2. Your first signed note moves the child into active management. This opens informant registration (4.1).
  3. A signed note is immutable. Editing one produces a new signed version and marks the old one superseded. Deleting one retracts it, with a reason. Nothing is overwritten in place.

Two structured fields, never parsed from your prose. A note carries a concern level (none, watch, high) and, on a working impression, an impression trend. Setting concern to high lifts the child in the triage queue. The system reads these fields. It never reads your sentences to guess what you meant.

Everything you type is scrubbed against this child's vault name before it is stored. This means the note body, each heading on a first visit, and the text of a correction. If this machine's vault holds no name for this child, a bare given name may get through. The IC, phone and school patterns still run either way.

5.3bPhotographing a page

You photograph a page: a child's handwritten note, or a drawing. On a desktop console you choose an image file. A desktop machine has no camera, so in clinic the picture is usually taken on a phone and moved across, or the console is opened on the phone itself, where the browser offers the camera.

Before anything is sent, you can paint rectangles over anything identifying: a name, a school badge, a hospital number. Those rectangles are burned into the picture itself, not laid over it, so what leaves the device has no name in it.

You must then tick a box confirming you have checked the image. The exact wording on screen is: I have checked this image. No name, IC, address, phone number or school name is visible. Nothing is sent until it is ticked.

Cropping or masking after ticking takes the tick back, because the picture has changed and the confirmation was about the old one.

The model then proposes a reading. It says what kind of page it is, how legible the photograph is, a transcript of any writing, and plain observations about the handwriting or the drawing. You confirm it line by line. Nothing is stored until you do. An observation the model could not make out says so on screen rather than being left off, because a missing line reads as a missing feature.

The reading also says whether the page depicts anything worth a look: violence between figures, injury, or anything sexualised. A drawing carries no writing, so nothing else screens one. Where something was seen you get one amber block above the observations, naming what is on the page in the model's own words and saying that saving it raises a safety flag. You read that before you save, so declining to save the page is still open to you. You cannot delete the observation itself. The two recorded ways past it are not saving the page, and acknowledging the flag afterwards in the Safety lane.

Where nothing was seen the reading says so in one line, and where it could not tell it says that instead. Those are different answers and they read differently. A page read before 31 August 2026 carries neither and shows no line at all, because nobody asked.

If the model cannot read the page it says so and gives four ways forward: take the photograph again, crop it and retry, keep it anyway with your own note about why it matters, or cancel. Keeping it with a note does not ask the model again. It has already said it cannot read the page, and a second attempt would produce a sentence someone might believe.

The photograph itself never leaves the device it was taken on. It is stored encrypted, under the same passphrase that opens the name vault on that computer (see 1.1c). Only the confirmed reading goes to the clinic's records.

So a colleague opening the same child on another machine sees the record and reads This photo is on another device where the picture would be.

Every page on the list opens. Click one and you get the picture large enough to read it, then what you confirmed, then what the model proposed, in that order and in two clearly separate cards. Everything the model read is there, the handwriting and drawing observations included, which until 31 August 2026 you could only see while you were confirming the page. The address bar carries the page you have open, so a reload comes back to it and the link can be sent to a colleague. A page that was kept without a reading says that, rather than showing an empty one.

A confirmed transcript becomes part of the child's evidence, citable in a suggested summary like any other source.

When the child has an earlier page of the same kind, you also get a card headed "Compared with the page before". It names the day and time that earlier page was taken. It lists only the observations that read differently, one to a line, as the old value and then the new one. On screen that reads Reversed letters 9, now 3.

When the two pages read the same it says so in one line, carrying the date with it: None of the observations changed since the page taken on 31 Aug 06:43. Whether a child is getting worse is a question, and that is an answer to it.

Nothing appears at all on a child's first page, on a page you have not confirmed yet, or on a printed document. There is no empty card and no line explaining its absence.

No model is called to produce this card. Every value in it is one you confirmed yourself, which is why it is a plain card and not one marked as written by a model.

It stays quiet in three cases, so that it never reports a change that is not about the child. Where either page's value could not be read from the photograph, because a clearer photograph is not an improving child. Where the paper changed rather than the writing, which covers one page having printed lines and the other not, and one having a printed margin and the other not. And where a count is missing on either page, because a count nobody could read is not a count of none.

Body parts in a drawing are never compared. Counting them across two drawings is the scoring step this product does not do. Only pages of the same kind are compared, so a drawing is never read against a handwritten note.

If the system finds a name in the transcript and removes it, you are told. It means a name was visible in a picture you had confirmed showed none. The page had already gone to the reader by then.

5.4Assessments and the trajectory

The trajectory marks each treatment plan with a dashed vertical line labelled Plan. A plan signed before the child's first form has no week on this axis, so it sits at the left edge and says Plan before wk 1. Withdrawn and replaced plans are not marked. Only the plans that stand are marked.

What the current plan says is on the Management tab.

There are two charts now: SNAP-IV inattention and the PSC-17 total, one above the other. The second appears only when the child has PSC-17 forms on file. Both are on the same week axis. Week 5 is the same date on each. A treatment plan marks the same column on both.

Under the charts is a suggested reading. Nothing runs until you tap Generate. It says which way each rater's scores have moved and whether that changed around a treatment plan. Every statement carries the evidence it came from. It does not interpret what a change means, name a diagnosis or recommend anything.

Assessments shows the scored instruments. The subtitle reads: scored live from submissions. Nothing here is a stored number someone could have edited. The scores are recomputed from the submissions every time you look. Part 6 covers the instruments.

Trajectory plots those scores over time, one line per person, not per role. Two teachers rating the same child are two lines.

5.5The history review queue

This is on the Overview tab.

A structured history entry can arrive two ways: you enter it directly, in which case it is confirmed, or an agent proposes it from something already in the record, in which case it sits as proposed until you act.

A proposed entry has three possible fates: confirm, confirm with edits, or reject.

A proposed entry is not evidence. It is excluded from the evidence pack. No agent can ever cite something you have not accepted.

A line under the queue says whether the notes were read. The reading happens in the background after you sign. There are five things it can say:

  • "Checked the last note N minutes ago." It ran and finished.
  • "Checking the last note..." A reading is in flight.
  • "Could not check the last note." It ran and failed. Correct the note, which signs a new version and starts a fresh reading. Or enter the history directly.
  • "History checking is not switched on here." This deployment has no reading configured.
  • "Could not tell whether the last note was checked." A reading started and never reported back, or this screen could not reach the record of it. Treat it the same as a failure.

No line at all means there is nothing on record for this child. You will see this before the first note is signed and after any note signed before this line existed.

If the whole card is replaced by "Could not load suggested history." and a Try again button, the screen could not read the queue at all. Tap Try again.

5.6Risk assessment and mental state examination

Both are coded, not prose. A risk assessment records categories with levels. A mental state examination records structured findings.

A risk category above threshold raises a safety flag by itself. The narrative that accompanies it is screened with those categories already suppressed.

5.7The first visit

An intake note has a checklist showing what the record does and does not cover yet. It prompts, it does not block. The checklist says what is missing rather than refusing the note.

5.7bLinking a child to a school

Set school on the record header opens the directory. It has a search box at the top. Type part of a school's name, or its district, or its state. Every word you type has to match.

Typing gombak finds every school in that district whatever they are called.

Under the list is a count. Unfiltered it reads 940 schools. After a search it reads 104 of 940 schools. The second number tells you how much of the directory your search left behind.

The link stays in this clinic's local vault. It never reaches the cloud.

It is kept in the same encrypted file as the child's name. It needs the same passphrase and is unreadable without it. It survives closing the console.

How to tell it saved: Set a school, close the console fully, open it again and look at the same child. The header should name the school rather than offering Set school.

On the web console the link belongs to one browser on one machine. It does not follow you to another address for the same app. On the installed console it is in the clinic vault file.

The directory holds a few dozen invented but plausible schools, weighted to the Klang Valley. Every one of Selangor's nine districts has at least one. Outside Selangor the coverage is thin and a district may return nothing. The real Ministry register is a permissioned download; until it ships here, a school you need may simply not be listed.

5.8The access ledger

Access lists who read or wrote what, and when, including agent actions. It is a read surface with no controls.

A read row is one person opening this child's record, once. It carries their code, clinic, and the word READ. Opening the record fires a dozen requests behind the scenes and only one of them is logged, so a visit is a row rather than a page of them. Moving between tabs on a record you already have open does not add another; coming back to the child later does.

This is what a parent asking "who has looked at my child's record" is answered with. It is a different question from the one the code-based design answers. That design is about what leaves the clinic: the cloud holds no name, no IC and no school. This tab is about who inside the clinic looked, and only a log can answer it.

The manual said reads were logged before they were, and this section is where it said it. Reads were declared and never recorded until 31 August 2026, so until then the tab could say what had been written to a record and not who had opened it. Anything before that date carries no read rows, and it never will: a log cannot be back-filled.

There is no filter and no export yet. Reads are the most common row, so on a record that has been open for months the printed letters and the refusals sit further down. Everything is there, newest first.

5.8bAnswers waiting to be sent

The Access tab shows a Waiting to be sent card when an informant filled something in and the system would not accept it. Their answers are still on their phone.

How to tell. The card is only there when something is waiting or when the clinic could not check. Each row names what it was (SNAP-IV, or Note for a free-text note), who was sending it, and the day. One line says why it was refused: consent has lapsed, the channel is not on the consent form, or no consent is on file.

If the clinic cannot check. When the card reads Could not check just now. with a Try again button, the answer is unknown, not "nothing is waiting". Tap Try again. If it keeps saying it, the console cannot reach the clinic's records.

The Patients page shows the same thing from further away. A child with something waiting carries a small form waiting or note waiting chip on their row.

What clears it. Fix the reason, then the informant sends again. Renewing consent on its own does not clear it. The answers are still sitting on a phone until that person opens the app and sends them.

Dismiss closes a row you know will never arrive. It asks you to pick why from a short list. Use it when the informant is unreachable, when the answer is no longer needed, or when the same information reached you another way.

5.7aThe Timeline, and the rows it leaves out

Every read and write of this child's record is logged. Those log rows are off on this tab by default. The Access tab has all of them, unfiltered.

One thing happening lands two rows. A form arriving writes a log entry AND a row saying a form arrived. Showing both means you read each event twice.

A chip above the list says how many are hidden and turns them on.

5.8aTelling what a model wrote

A card whose content a model produced has a tinted header band with a small sparkle mark. That mark answers one question: who wrote these words. It has three states:

  • the sparkle, in green, means a model wrote it.
  • a cog, in grey, means fixed rules produced it and no model was involved. This covers every instrument score.
  • a shield, in amber, means a safety check held something back.

Hovering any of them says the same thing in words. Nothing you typed yourself carries a mark.

Some of those cards also carry a small character. It says which area of the work produced what is on the card: ELI heads the reading of a record, so ELI is on Suggested history and on the evidence-coverage figure of a draft. The character always sits BESIDE the sparkle.

Each character now carries its own name on a small plate across the bottom of the circle, wherever it is drawn large enough to read one. On the smallest ones the name is on hover instead.

If you would rather not have the animals, go to Settings > My profile > Agent characters. What was a character becomes the plain sparkle in the same circle. Suggested draft and Suggested case summary carry no character.

Generated text is shown formatted. Where a model writes a bold lead, a bullet or a numbered line, the console draws it that way. It renders only those three things and changes no word. A link is the one thing it will never render.

5.8cShow the work

A finished suggested case summary, draft or reading carries a "Show the work" button in its header. It opens what produced that card: which parts of the work ran, how each finished, how long it took, and every piece of the record the card cites.

It needs no admin account. The record of one run carries no child's details of any kind.

Where a card ran on the backup, it says so. A run that finished on the second route means the first one was refusing.

Cards with no run behind them have no button. Second read, Why this was flagged and Suggested history produce no run record on the service.

A run that cannot be read says so.

5.8dHow much has been checked for safety concerns

The Overview tab carries one line: how many of this child's notes and forms have been checked for safety concerns, how many raised one, and since when.

The date is the point. Where there is no honest figure, the line is absent rather than zero.

A zero WITH a date is different and is shown: "No notes or forms have been checked for safety concerns since 28 Aug" is a fact about this child.

5.9The suggested case summary and the suggested draft

Two sections on the Management tab: nothing runs until you tap Generate. Coming back to the tab shows the document you already generated.

Suggested case summary generates a summary from what is on the child's record: signed notes, scored instruments, what informants have written, confirmed history, coded risk assessments, mental state examinations, and what was observed on a photographed page. Each of those can be cited under a statement. Suggested draft generates the same thing at full depth, a seven-stage run. Both are a paid model call the server does not cache.

If this deployment has no council key configured, tapping Generate reports that generating a case summary or a draft is not set up on this server.

While a run is in progress, a stage checklist shows each stage as it lands. A grey dot means the stage has not started. A dot that breathes slowly means that stage is under way right now. A green dot names the model that served the stage and how many statements it contributed. A red dot names why it failed, in plain words. A run that outlives its time budget stops and says so.

Once a run is ready, every statement is one of three things: supported by cited evidence renders as plain text, only partly supported renders visibly weak and cannot be accepted until you have opened that evidence at least once, and a gap renders as something not established, never as a claim.

The sources sit under each statement as small chips, named the way you would name them: "Teacher, questionnaire score, 10 Jul". Tap one to read the excerpt itself. A chip carrying a number in brackets stands for that many excerpts from the same source.

A small glyph in front of a statement means a model wrote those words. You will see it on every generated statement and on nothing taken from the record. If you rewrite a statement, the glyph goes.

Accept, edit or remove each statement, then sign. Accept is the tinted button. Edit and remove are the quiet ones beside it.

5.9bHow to tell who produced something

Three different kinds of thing can sit on this record, and each says which kind it is.

  • A small sparkle beside a sentence means a model wrote it. You will see it on every statement in a suggested draft or case summary (5.9). Text you typed yourself carries no mark.
  • The same sparkle beside a suggested history fact (5.5) means something narrower. A model picked the details out of your note, but the line you are reading is put into words by the system from a fixed form. "Gestational age 34 weeks" is our phrasing. The 34 is what the model proposed, and the 34 is what you are being asked to check against the note.
  • Inside a safety flag, a small chip beside the SAFETY LANE tag says which kind of check raised it. "AI check" means a model made the call. "Phrase list" means a fixed, clinician-graded list of phrases did. A flag with no chip is one raised from a coded risk assessment.
  • The same small picture carries the same meaning everywhere in the console: a sparkle for a model, a gear for a step that runs no model, a shield for a safety check. Read the picture. It is the part that is the same everywhere.

5.10What the agents may and may not do here

  • Agents rank the queue, flag a risk, propose a history entry, draft a document.
  • Clinicians decide, diagnose and sign.
  • Every agent output carries a reason you can read.
  • Anything an agent generates about a child is bound to evidence. An unsupported statement renders as a gap card, never as a fact.
  • A number in a suggested statement is checked against the evidence it cites. If a figure does not appear in the material the statement points at, the whole statement becomes a gap card.
  • Scores are never produced by a model. They are ordinary code.

Two things on a signed note you can ask for:

  • Pull out birth and family history, on an intake note. It reads that note and proposes structured history facts for you to confirm or reject in Suggested history.
  • Check this note for risk, on any signed note. The safety lane reads that one note again and tells you what it found. It is not saved. Nothing goes on the record and no flag is raised.

If you ever see agent output that reads like a decision rather than a suggestion, that is a defect worth reporting.

5.11Asking Jeji

A control labelled "Ask Jeji" opens a panel. Its tooltip reads "Ask Jeji, the assistant".

Questions are typed in ordinary words. The box says "Ask a question. Type @ to name a patient." On a child's record it says "Ask about" followed by that child's code, ". Type @ to name someone else."

Typing @ names a child, so the clinician can ask about someone else without leaving the page. The panel can be told which child to focus on, and says "Asking about" with the child's code while it is doing so.

Sending is "Send (Enter)".

While it works it says "Jeji is working", and while it reads the record it says "Jeji is reading the record. One moment."

Other controls on the panel: "Start a new conversation", "Shrink to the side", and "Ask again".

When the record does not support an answer it says exactly that: "Nothing in the record supports an answer to that." It does not guess. A question about the clinic rather than one child, where the lookups ran and came back empty, says "Nothing in the clinic matches that" instead, and there is no "Ask again" under it: that is an answer, not a failure.

Jeji can also answer about the clinic as a whole. It can read the day's appointment book for the date the console is showing, count children by the things this clinic actually records, say how the caseload spreads across districts, and find a school by name and say how many of the clinic's children attend it. A question about a day always uses the date the console is on, so if the clock has been shifted for case review the answer follows the shift and agrees with the visits card beside it.

Under an answer are the sources it rests on. Each source shows a label naming what it is, for example "Teacher SNAP-IV" or "Clinical history", and the stored words themselves. Beside each source is a button that opens the tab that source lives on. The six it can say are "Open Notes", "Open Trajectory", "Open Informants", "Open Timeline", "Open Access" and "Open Overview". The button names the tab, so the clinician knows where they will land.

A source that a model proposed carries a line saying who proposed it, for example "ELI suggested this from a clinical note. A clinician confirmed it." A source no model proposed, such as a questionnaire score, carries no such line at all. So the absence of that line means a person put the fact there, not a model.

A line reading "What it looked at" with a number of steps shows what the panel read to answer.

Above that, a line reading "What it means to do". Jeji writes one or two sentences saying what it intends to look at, before it looks at anything. It is open while the turn is running, so there is something to read while the lookups happen, and closed once the answer arrives. It is intention rather than a finding: it can name something Jeji then does not read, and the step trail beside it is the record of what actually ran. Some turns carry none, and then no line appears at all.

Jeji may ask a question back. When a question genuinely means two different things, the panel shows "JEJI IS ASKING" above a question rather than an answer, and the typing box already has the caret. "How many students with depression" is the case this exists for: this clinic records no diagnosis, so the question could mean children whose own history records a prior psychiatric diagnosis, children with a family history, or children scoring above a cut-off. Jeji asks which.

It will never ask twice running. If the turn before it asked, it answers with what it has.

When Jeji cannot answer, it offers somewhere to go. Instead of stopping at "Jeji could not put an answer together", the panel may say what it could not do and then one thing it can, with a number: "I do not record diagnoses. Nine children scored above the cut-off. Which did you mean?" Every number in that sentence is checked against what the lookups actually returned before it is shown, so an offer that named a number nothing returned is dropped rather than printed. A turn with genuinely nothing to offer says plainly what it could not do, and that is correct rather than a fault.

While a source is still loading it says "Reading".

If a source cannot be found, it says "This source could not be read." followed by the source's id, so the clinician can chase it.


Next: 6. Scores and instruments.

6

Scores

This part is for clinicians. It covers the three instruments this system scores, what the numbers mean, and one guarantee that applies to all of them.

6.1The guarantee

No score in this system is produced by a language model, ever.

Every instrument is scored by ordinary code with fixed tests. The scoring functions are pure: same answers in, same score out, no network call, nothing random.

When you look at a SNAP-IV subscale total, the only question is whether the informant answered honestly.

The scores are also recomputed from the submissions every time you look, never read from a stored number.

6.2SNAP-IV

The Swanson 26-item rating scale, completed by a parent or a teacher. Items are rated 0 to 3.

Three subscales, each summed separately:

Subscale Items Mild Moderate Severe
Inattention 1 to 9 13 18 23
Hyperactivity / impulsivity 10 to 18 13 18 23
Opposition / defiance 19 to 26 8 14 19

A sum below the mild floor is reported as not clinically significant. That same floor doubles as the clinical target.

Each subscale reports its raw sum, its mean per item, its severity band, and whether it is above target. All four are shown rather than just the band. A sum of 13 and a sum of 22 are both "mild" and are not the same clinical picture.

A submission is rejected if it does not carry exactly 26 responses, or if any rating falls outside 0 to 3.

6.3PSC-17

The Pediatric Symptom Checklist, 17 items, completed by a parent. Items are rated 0 to 2.

Three subscales with published cut-offs:

Subscale Items Screens positive at
Internalizing 5 5
Attention 5 7
Externalizing 7 7

Each subscale reports its sum and whether it screened positive. A positive screen is a screen, not a diagnosis.

6.4What happened to the M-CHAT-R

It was here, scored and working, from 17 July until 14 August 2026. It was withdrawn for licensing of the electronic form, not clinical merit.

ADR-050 removed it: mchatscreen.com requires a licence agreement to distribute the instrument in any electronic format.

If you need an autism screen, use the paper M-CHAT-R. It is free to download from mchatscreen.com and free to use in your own clinic. Record the outcome in a clinical note.

No child lost anything. No M-CHAT-R had ever been submitted when it was removed.

6.5What happened to the SDQ

The Strengths and Difficulties Questionnaire was dropped, for electronic-use licensing reasons rather than clinical ones (ADR-009). It was never in the system at all.

6.6Reading a trajectory

Scores over time are plotted one line per person, not per role. Two teachers rating the same child are two lines.

Different raters disagree on SNAP-IV by more than a treatment effect typically moves it. Comparing one rater's baseline against another's latest can invent an improvement or hide one.

The trends check reads these lanes and reports what it sees: a worsening trajectory, or a response to titration. It reports. It does not diagnose.

How the lines are named. A single teacher is Teacher. Two teachers are Teacher 1 and Teacher 2, numbered in a fixed order. No handle or code ever appears on a line.

A line named (unregistered) is not a person you have not met. It is every form of that kind that arrived without a registered informant behind it, pooled into one line. It appears only when there is also an identified rater of the same kind. Read it as "forms we cannot attribute to anyone".

Point at anything to read it. Hovering a point names the rater, the week and the score: Teacher 1 · week 9 · 27/27. Pointing at a week with no form says so. This is the way to read an exact number off the chart.

What the marks mean. A filled or open dot on the plot is a score. A small open ring in the strip below the axis is a week with no form from that rater. It is absence, not a zero. The shaded band is at or below the clinical target. The dashed line across it is the cutoff. A gap in a line means nobody was measured in between.

The axis fits the record. It ends a week past the last form on file, not at a fixed twelve weeks.

The line under the chart is not typed by anyone. It carries the same mark every deterministic result in the console carries. It suggests. It does not diagnose.

The key above the chart is the reliable way to tell lines apart. Colour means the group, school or caretaker. Line style separates people inside a group.

Names are also printed at the end of each line, but only where the name is unambiguous. Pointing at a spot with several raters says how many raters are on it.

The axis is real time, shared by every line. Week 1 is the child's FIRST form, whoever sent it. A rater who joined in August starts in August, part-way along. Two points at the same x position were collected in the same week.

A week with two forms from the same rater shows the later one. Both are stored, and Assessments lists both.

6.7What a score does on its own

  • A red flag can be raised by screening the free text that accompanies a submission, or by a clinician's own coded risk assessment above threshold. Not by a subscale total.
  • A triage lift comes from an active red flag, the early-intervention age window, or your own signed escalation. Not from a subscale total.

A high score is information for a clinician. It does not, by itself, move a child up the queue or raise an alert.


Next: 7. Service view.

7

Service view

This part is for supervisors and admins. A clinician who opens it gets a panel saying so; that is the server refusing, shown honestly, not an error.

7.1What it is, and what it deliberately is not

Service view answers one question: how is this clinic doing? It is computed from your own clinic's records at the moment you open it. Nothing is stored, nothing is a snapshot from an earlier date, and nothing is entered by hand.

It is not a national dashboard. Country-level figures shown on an earlier version could only have been invented numbers for a single clinic. That was removed. What you see now is your catchment only.

It carries no MRN, on any figure, by construction. You cannot drill from a service number to a child here.

7.2Reading the figures

Every figure pairs its value with the denominator it came from, and that is the single most important thing about this screen.

A young clinic's records are sparse. "Median wait 83 days" means something quite different computed from four children than from four hundred, and a number shown without its denominator would let you forget which you were looking at. So the screen always says "computed from N of M".

Children in service. How many children the clinic is carrying.

In active management. How many have moved past registration, against how many could have.

Assessed this month. Likewise, with its denominator.

Median wait, in days. From referral received to first review. A child needs both dates to count, and both are optional in the record, so the number this is computed from is often smaller than the whole clinic. If nothing can be computed it renders as an honest empty state, never as zero. A clinic with no measurable waits has an unknown median, not a median of nought.

Wait trend. The median wait by month, over a trailing twelve months, so the axis stays readable as the clinic ages.

7.3The response distribution, and the number that keeps it honest

This is the SNAP-IV response measure, and it repays a careful read.

What is measured: the fall in a child's ADHD core total (items 1 to 18, inattention plus hyperactivity/impulsivity) from their first scorable submission to their latest, within their best-covered rater lane.

Opposition/defiance is deliberately excluded from that total. It responds to different treatment, and including it would let a child whose ODD score collapsed while their attention was unchanged register as a responder. They have not responded on this measure, and the figure must not say they have.

Four bands:

Band Meaning
Improved by 30% or more A responder, on the trial-standard relative definition. Exactly 30% counts.
Improved by under 30% Moving, not yet a responder
No change or worse Measured, and not improving
Excluded Could not be measured

Always read the excluded count. It is load-bearing, not a footnote. A child whose family stopped returning forms has no second submission and falls out of the scored set entirely, and the children doing worst are the likeliest to stop returning forms. Ignoring the excluded count therefore flatters your responder rate in a specific and predictable direction. Showing it is what keeps the rest of the row honest.

A child whose baseline was zero counts as excluded, not as "no change or worse". A percentage fall from zero is undefined, so such a child is unmeasurable rather than unimproved.

Retracted submissions do not move any figure here. A retraction is a clinician saying that data is not this child's, so it is excluded from the service numbers as well as the clinical ones.

7.3bThe referral map

The card Where children are referred from pairs a map with the same figures as a ranked list. The map answers whereabouts, the list answers how many, and you need both: a dot cannot be counted and a row has no position.

Nothing appears only on the map. Every school, every district and every count is in the list beside it. You can read the complete data from the list alone.

A mark is one school, and its size is how many children were referred from there. Size only. Not severity, not a score, not a blend of anything.

Read it as referrals RECEIVED, never as cases occurring. A school with an active counsellor refers more children and draws a bigger mark. That is not the same as more children there needing help, and answering the second question would need a population denominator this system does not hold.

A red mark means at least one child referred from that school is on the safety lane (has an open safety flag). It is a state a clinician recorded, not a number anything computed. Acknowledge the last open flag on that child and the red clears. A colour that never cleared would mark a school for a concern the team has already dealt with.

The line under the map states both scales in CHILDREN, never in intensity, and says how many schools are drawn.

It has two looks, and neither is broken

Sometimes the marks sit on a street map you can pan and zoom. Sometimes they sit on a plain diagram of the state with the largest sources named. Both are the map working.

The street map comes from Google, and it is the one part of this console that talks to anyone outside this service (ADR-062). When it cannot be reached, and there are ordinary reasons it cannot (a hospital network that blocks it, no connection, a key that expired), the diagram is what you get. It is drawn entirely from what this clinic already holds, so it always works, and it can label schools, which the street view cannot do without clutter.

You do not need to do anything when it looks like a diagram. It is working normally.

What it can and cannot see

The map reads the school links held on THIS device. They live in the vault on the machine you are sitting at. A child linked to a school on the desktop console will not appear on the map in a browser, and the other way round. School links never leave the machine by design.

A red mark is for your eyes and stays here. Nothing per school leaves the clinic: the share button in 7.4b publishes districts only, floored at five children, with no colour and no school.

7.4Why there is no small-cell suppression

The schools rollup suppresses cells below a threshold. This screen does not, and the difference is deliberate.

Service view is read by your own clinic's team, who already hold every record it summarises. Suppressing a cell of three would hide nothing from the person looking at it, while making their own service metrics wrong. The schools card is different: its cells resolve to a named school and are emitted upward out of the clinic, so it keeps its threshold. See 7.4b.

7.4bAlerts shared beyond this clinic

The card near the bottom shows what this clinic has published for other people to count: how many children have an open alert, by district and by school. Everything else on this screen stays inside the clinic. This is the one part that leaves it.

Nothing is shared until you press Share figures. Publishing is a deliberate act. The school links live in the vault on the machine you are sitting at, so an automatic share would change the published figure depending on which console opened this screen last.

The count is CHILDREN, never alerts. One child flagged five times is one child. Five records from one child would clear a threshold of five while pointing straight at that child.

A group of fewer than five children is not shared at all. Not shown as a small number, not shown as "fewer than 5". Absent.

Read the line under the button, especially when nothing was shared. It always names the denominator, because "nothing was shared" on its own tells you nothing you can act on. It reads like this:

Nothing reached five children, so nothing was shared. 7 children have an open alert, and 6 of them have no school on file.

That second sentence is the instruction: link those children to a school on their record (5.7b) and press it again.

If the vault is locked, the button refuses and says so. It does not publish an empty set. An empty share would replace what is already on the record, so a console with a shut vault would wipe figures that were correct.

What is sent is the district, the state and a number. No child code, no school code on the district rows, no category, and nothing about which children.

7.5An empty clinic

Service view never fails on a clinic with no records. It returns a fully formed view of zeros and honest empty states rather than an error, so an early clinic sees the shape of what it will eventually measure.


Next: 8. Administration.

8

Administration

This part is for admins. Admin in the rail holds six entries; a supervisor sees the section too, for the schools registry alone.

The heading above the pills names whichever destination is open, not the section. If it reads Users & roles, that is the screen you are on.

8.1Users and roles

Lists who has an account, and provisions new ones. No name is stored, for staff any more than for children.

Who has an account. A row per account: the handle, the role, whether it is a sandbox or a live account, and whether it has been retired. There is no name here and no route that could supply one.

The line under the table says how many accounts there are and how many of them cannot sign in, because the second number changes what the first one means.

Retiring an account. The answer to a clinician who leaves. Press Retire on their row, confirm, and they can no longer sign in. Press Put back to undo it.

Retiring is not deleting. The account, the handle and everything that names it stay exactly where they are, because an access-ledger entry saying MO-114 opened a chart is still an honest record after MO-114 has left, and deleting the account would leave that entry pointing at nothing.

A recovery code does not get a retired admin back in either. Recovering with the printed code refuses while the account is retired, and says so, and the code is not spent. Ask another admin to put the account back first.

It does not end a session that is already open, and the dialog says so. A retired clinician who is signed in at that moment keeps working until their session expires, up to ten hours. The change takes effect at their next sign-in, exactly like a mode change does, and for the same reason: the console proves who it is with a token that stands on its own, so the server never re-reads an account and the check costs nothing on every other request.

Three things it refuses:

  • Your own account. Ask another admin. An admin who retired themselves would keep a working session for the rest of the shift and then be unable to get back in.
  • The last admin who can still sign in. Create another admin first. A retired admin does not count towards that number, which is the point: with two admins where one is already retired, the other one is the last. The count is per clinic mode, because a sandbox admin cannot create or restore a live account, so sandbox admins are no help to a live partition that has run out.
  • Restoring an account in the other clinic mode. A sandbox admin may retire a live account, because taking access away is safe from either side, but only a live admin may give it back.

There is no way to delete an account or change its role. No such route exists in the system.

If the list cannot be read it says so and offers Try again. An empty list and a failed read are different things on this screen and always will be: an admin who takes a failed read for an empty clinic is about to create a handle that already exists.

Handle. An uppercase role prefix, a dash, then a code: MO-114, MO-ADMIN. The pattern is enforced, so a handle that looks like a person's name is refused.

Role. Clinician, supervisor, admin or preview. See 1.2 for what the first three reach, and 8.1c for what preview is.

Mode. Sandbox or live, and this cannot be changed by the account holder. A sandbox account sees invented patients only; a live account sees the real clinic record.

Two rules about mode that catch people out:

  • The mode is fixed at creation. You can move an account afterwards, and the move takes effect at that account's next sign-in, not immediately.
  • You cannot move your own account. An admin cannot promote themselves out of sandbox.

A password is set at creation. An empty or whitespace-only password is refused. A guessable credential stored in the cloud would be a security risk.

Creating an admin shows a recovery code once. Write it down before you close the screen. It is stored only as a digest, so no screen anywhere can show it again. It is that admin's only way back in if there is no other admin to reset their password. Creating a clinician or a supervisor shows no code. Clinicians and supervisors have an admin to ask if they forget their password. Spare credentials on paper for everyone would create too many ways into the system.

A warning appears here when this clinic has only one admin account. One forgotten password and nobody can create an account, move a mode, or reset anyone. Create a second admin and the warning goes.

8.1bResetting a password

Type the handle and the new password, and tell the person what it is yourself. Nothing is sent to them.

You cannot reset your own password. An admin doing this is signed in, so they are not locked out, and allowing it would mean anyone who found an unlocked console could take that account permanently.

Resetting an admin's password issues them a new recovery code, shown once like the first. The old one stops working: an admin whose password had to be reset may have lost the paper too, and those are usually the same afternoon.

Every reset is recorded: which account, when, and who did it. A reset that used a recovery code instead of an admin is recorded as such, which is the one entry worth reading. It means somebody held that account's paper code, and this system cannot tell the locked-out admin from a person who found the drawer.

8.1cThe preview account

A public, read-only account so somebody can look at the working console without being given one of their own. Its credentials are published: the handle preview and the password preview.

Create it from the same form. Pick Preview as the role and the handle and the mode fill themselves in, because a preview account may only ever hold that one handle and may only ever be a sandbox account. Set the password yourself. No recovery code is shown, because it is not an admin.

What somebody signed in as it can do. Read everything the sandbox holds, ask Jeji questions, and run the council to generate a case summary or a formulation. This shows how the agents work.

What it cannot do. Change anything else, anywhere. Not enrol a child, write a note, record a risk assessment or a mental state examination, add history, sign a document, replace consent, issue a QR code or an access letter, book an appointment, acknowledge a safety flag, or reach any admin screen. The refusal is in the server, not in the console, so it holds whether or not a button was hidden.

The buttons are still there and they will fail. A console with hidden write buttons reads as broken to someone who has never seen the working one. Hiding a button does not stop a request. On most screens the failure shows as that screen's ordinary error rather than a message about preview.

A bar across the top says so, on every screen, and cannot be dismissed. It says the account is a preview, that the patients are invented, and that nothing is saved. A visitor who arrived from a published password has no other way of knowing any of the three.

Two visitors do not share anything they make. Each sign-in gets its own conversation with Jeji and sees only the documents it generated itself, plus everything the clinic already had. A visitor who reloads and signs in again starts a fresh conversation; there is no way to get an old one back, because there is no per-visitor account to attach it to.

Signing in twice makes two visitors, including two tabs of your own. The separation is per SIGN-IN, not per person, so a second tab signed in with the same published password is a stranger as far as the server is concerned. Asking that tab about a conversation the first one started is refused, and the refusal is the separation working rather than a fault. It is worth knowing before you chase one: a tool that signs in again to check on a running answer will be told the conversation belongs to somebody else.

It cannot be a live account. The form will not offer it and the server refuses it. The published password is only acceptable because the sandbox holds no real child.

A wrong password does not lock anybody out. The preview handle is not throttled after repeated failures. There is no secret to protect. Throttling it would let any stranger stop every visitor signing in for fifteen minutes.

8.2Schools registry

Admins manage it; supervisors can read it. Adding a school runs a duplicate check first and an admin confirms every entry. Nothing is created automatically: a suggestion is offered, a person accepts it.

The directory shows forty schools at a time with numbered pages, and the search box above it matches a name, a district, a state or a code.

Opening a school. Tap any row. You get its code, district, state, setting, pupil and teacher counts, and its coordinate, with a button to open the location in Google Maps and one to send it on WhatsApp. Only the school and where it is ever leave the clinic that way. Nothing about a child can: this screen is reached from the directory, which has no child in scope at all.

Correcting a school. Press Edit. Everything except the code can be changed: the name, the district, the state, the coordinate and the two headcounts. The code cannot, because it is what a clinic vault's child-to-school link points at, and changing it would break every one of those links invisibly. Leave both coordinate boxes empty if the location is not known; one on its own is refused.

Withdrawing a school. Press Withdraw. It stops being offered when linking a child, and its row stays in the directory marked Withdrawn. Press Put back to undo it.

There is no way to delete a school. Which children attend which school lives in the clinic vault and never reaches the server. The server side cannot know whether removing a row would leave a child pointing at a school that is gone. A child already linked to a withdrawn school keeps showing it by name. A deleted school would show as blank, which looks the same as a locked vault.

8.3System config

Five settings live here.

Clinic letterhead. The mark, name and address printed at the top of every registration letter. Covered in 4.6. The address box takes three lines and prints them as typed. The mark is picked from a short list rather than uploaded. Change all of it before any letter goes to a family unless you are at the pilot site: the default names Hospital Al-Sultan Abdullah UiTM, and its crest sits above that name.

Monthly limit for AI drafting. How many drafting runs a month may hold, and therefore when drafting stops. Three lines say how much of this month has gone: sandbox, live, and both together.

Two numbers, and they move together. Both are checked on every run, so raising the sandbox limit on its own changes nothing at all: the total still refuses at the old number. The screen says so, and the server refuses a total set below the sandbox limit rather than saving a setting that would never apply.

The live limit is shown and cannot be changed here. It guards spending against real records, and moving it takes a new build. Raising the total does not loosen it.

The count is runs STARTED. It is not the cost figure on the Agents screen, which is an estimate and enforces nothing. If drafting has stopped, this is the screen that says why, and raising the limit takes effect on the next run with no redeploy. "Back to 400 / 550" returns both to whatever the running build shipped with.

How the agents reach Google. Which doors the agents use to reach Google, in order, and what happens when one cannot answer. This choice happens first: it decides how the vendor below is reached, not which vendor answers. A door this deployment holds no credentials for is shown but not selectable. Offering a choice that silently does nothing is worse than not offering it. A door cannot appear twice in the chain.

The chain is up to three doors deep (ADR-053), and the build ships with all three set: the challenge credits first, then this project's own Google Cloud account, then the API key. Both Google Cloud doors authenticate as the same service account, so one identity failure takes out both at once; the API key is the only door that needs no Google Cloud identity, which is why the third slot is there. The card shows one empty slot past the end of the chain and no more, so the chain can never be left with a hole in the middle. Choosing Nothing after this in a slot ends the chain there and clears everything below it.

Read the "Serving now" line, not just the first slot. It names the first door that has not been observed failing. A door that has failed is marked not answering beside its slot. A chain answering from its last door looks the same as one answering from its first, and the two spend money from different accounts. Absence of a marker means no failure has been observed since the server last restarted, not that a door is healthy.

When every door in the chain has failed, the line says Nothing is answering and names no door at all. The markers stay, so the card still says which doors were tried.

The screen states plainly that requests run in Google's wider pool, not only in the region this clinic's other data lives in. That line is not a setting; it is a fact about where a request goes once it leaves this system, and it stays true regardless of which door is first.

Council provider. Which vendor answers when a document is generated, and which one takes over if the first cannot. A provider this deployment holds no key for is shown but not selectable, because offering a choice that silently does nothing is worse than not offering it. A provider cannot fall back to itself.

Model pins. Which model runs each lane. Each pin has a floor compiled into the software and an optional override you set here. The floor is never removed: an override that stops working falls back to it and the lane keeps running.

Read the warnings on this screen precisely. The screen can tell you that an override you set has been withdrawn from the vendor's list. It cannot tell you that a model is deprecated and still answering. It says nothing about a stale floor when no override is set. Checking the vendor's model page before a release is a human job that this screen does not do for you.

8.4Agents

A report on what the model-backed lanes have done. It is a read surface: it reports consequences of the settings above and writes nothing itself.

The screen states when it was read, separate from the window it reports on. A line above the bands reads, for example, "This window: 1 Aug to 8 Aug. Read at 8 Aug 14:32." so a report that looks current is never mistaken for one just refreshed: the window can be old news even when the read time is this minute. The read time is on your own clock, so you can hold it against the clock on the wall: press Refresh and it should read the minute you are in. The two window dates in front of it are not; they are the server's own calendar days, which is what the server counted.

Below that header sit four tabs, each answering a different question about the same window. Only one panel is mounted at a time.

Runs answers "what happened, run by run, and stage by stage". It opens first. The flow diagram draws the pipeline's fixed wiring first and fills in with one run's numbers second. Below the diagram sits the list of runs in the window; tap one to fill the diagram in. With no runs recorded, JEJI appears above the short line that says so. This is the only place JEJI appears on this screen. JEJI never sits beside a score, a suggestion, or anything the model wrote. A hover mark beside JEJI tells you that JEJI is the guide rather than one of the agents.

Health answers "is each vendor answering, and what is this costing". Covered below (provider health and cost).

Each agent answers "what areas does the system look after, and which lanes fall under each". The model-backed lanes are grouped under the character whose domain covers them: ELI, NAMI, PIPIT, and one group with no character yet, titled "Making sense of the case". A character heading uses product vocabulary beside the build vocabulary, not instead of it. Every lane still carries its own name and its own agent, deterministic step, or guardrail mark (see "How the pipeline is wired" below). The character tells you which domain a set of lanes belongs to. A group with no character shows no mascot and no placeholder circle.

One provenance mark (5.9b) sits above the whole tab rather than beside every card. The tab reads "Everything below is a call to a model. Steps with no model in them are not counted in these numbers; the Runs tab draws those." Everything on this tab is a model call, so marking each card separately would repeat the same fact many times.

Calls answers "show me the raw call log". Every call in the window, newest first, paginated rather than loaded all at once.

Provider health shows which vendor answered, how often, and when it last succeeded or failed, within a window. For Gemini specifically, the row splits further into which DOOR answered: the doors set on the "How the agents reach Google" card each get their own line under the vendor, using the same answering, degraded, refusing or not-used wording. DeepSeek has no door split, because a door is a Gemini-only concept; a vendor that has no second door does not grow an empty row.

One gap in that split: if every one of Gemini's replies in the window failed our own parsing rather than Google's answering, the door split can show nothing at all for Gemini even though the vendor's own reply count is not zero. When that happens the screen says so directly, next to the count of replies that did not fit. Check Calls below instead, where each row carries the real door that produced it.

How to tell which door served any one call. Open a run and look at a stage's row, or open Calls. Each carries which door answered it, alongside the model and the vendor. A call recorded before doors existed, or a DeepSeek call, reads as "Not recorded" rather than guessing: the screen never assumes a call went through the API key just because that was the only door that existed when the record was written. If every recent attempt for a vendor reads "Not recorded", that tells you the records are old, not that the door is unknown or broken.

Note the wording throughout: a failure was observed. The failing set lives in server memory and resets when the service restarts. Absence of a warning means "nothing observed since the last restart", not "this lane is healthy". A false reassurance would be worse than silence.

Costs shown here are estimates, derived from a hand-maintained price table stamped with the date it was last checked. They are never a bill. A model missing from that table prices as unknown, never as free.

How the pipeline is wired is a permanent diagram, not a report on any one run. Every row is one of three kinds, told apart by shape and tag: a circle tagged AI agent is a model call, a square tagged Deterministic step runs no model at all, and a diamond tagged Guardrail can refuse a result but never rewrite it. A guardrail refusing something is what it is there to do. A handful of rows carry a small character token, the same cast as the Each agent tab. The shape and tag beside each row is the signal; the character is additional. One row goes further: the Safety check carries its own hover mark for KURA, because KURA is the one character with no group on the Each agent tab. A guardrail makes no model call, so it has no lane there. The other characters have no mark here; their group heading on that tab already carries the same sentence.

With no run picked, the diagram shows the architecture alone: what exists and in what order, nothing about whether it is working. Pick a run from Runs below it and every AI agent row fills in with what that run actually did: the model that served the stage, how long it took, how many attempts it made, and a tag reading Override when an admin's pin served the call rather than the shipped default. Once a run is filled in, tap anywhere on the diagram to open a Timeline: a millisecond-scale replay of that run's calls, laid out on a real time axis. A row reading "No call recorded" means telemetry for that stage was not written, not that the stage never ran; stage completion itself is answered on the child's own record, never here (5.9 covers where that shows).

Neither the diagram nor the Timeline can show a run in flight. This screen reads no run status. What it has is a set of calls that were recorded. Telemetry is written fire-and-forget, with a failed write swallowed rather than retried. A lane with no call in it means no record was kept. It does not mean "this stage did not run" or "this stage is running now". The Timeline in particular is a replay of one already-finished run, not a live view. Open it mid-run and it shows only the calls that had already landed, with nothing marking whether more are still coming.

This screen needs an admin account, and one thing on it no longer does. The list of runs, the cost figures and the window above them are all admin only. What ONE run did is not: since 28 August 2026 any clinician can read it (ADR-066), and they reach it from the card it explains rather than from here. See 5.8c, "Show the work".

The split is deliberate. This screen reports which vendor processed how much clinical text across the whole clinic and at what cost, which is a governance question. One run answers "why does this card say that", which is a clinical one. The record of a single run carries no child's details of any kind, which is the fact that made widening it cheap.

Tap a run to select it; its start time, attempt and failure counts, and its estimated cost are all that show before you do.

Once you select a run, the panel re-reads it on its own every few seconds, which is how new calls appear without your pressing anything, never because the screen knows the run is still going. It stops re-reading on its own once several minutes have passed with nothing new arriving, and there is no spinner or any other mark to tell "this run is finished" apart from "this run has simply gone quiet for now", both look identical, for the reason above: nothing here carries a run status. If you want a fresh read at any point, tap the run again.

8.4bOperating the sponsored account

Verifying the sponsored route, proving how much of the challenge credits have been spent, and checking nobody else is spending them are three operator tasks rather than three things an administrator does in the console. They moved to part 11 on 28 August 2026, with the rest of the sponsored-project operations.

They moved because this part is published. docs/manual/ parts 1 to 9 are rendered onto the public site at build time, and those three sections name the sponsored project, a service account address and a billing account id. Part 11 is not published and is where every other runbook of that kind already lives.

See docs/manual/11-mirroring-to-a-second-gcp-project.md.

8.4cSeeing which account served a run, without leaving the child

You no longer have to open Agents to answer "which provider answered". As an admin, every stage in a suggested document's checklist carries a second line naming the account that served it: Google Cloud (challenge credits), Google Cloud (our account), API key or DeepSeek.

Where to look:

  • While a run is generating, the checklist is already on screen under the card, unhidden. Lines fill in as each stage lands, so this reads as a live log without anything to press.
  • After it finishes, open How this was made under the document.

Only an admin sees this line. A clinician sees the same checklist without it, deliberately: which Google project answered is not something they can act on, and the account names are operator vocabulary.

Two readings that are NOT the same thing, and the screen keeps them apart:

  • A stage with no line at all has not answered yet. It has no record, so there is nothing to name.
  • "Account not recorded" means the stage answered but the document predates this field. Documents generated before 19 August 2026 all read this way, and will keep reading this way: it is a fact about the record, not a fault, and regenerating produces a document that names its accounts.

What this does not replace. It reports the account that SERVED each stage, which is one line per stage. It does not show the attempts underneath: a door that refused before another answered appears nowhere here. That is the Agents tab's job, and the Open agents control on the card header goes straight to it.

Read it against the failover rate, not on its own. One stage naming DeepSeek is the failover working. Every stage naming DeepSeek, run after run, means the primary is failing and nobody has been told, which is exactly the state register entry A97 describes going unnoticed for a day.

8.5Audit log

Not built. The screen says so. There is no backend behind it yet, and it is listed here so you know its absence is known rather than a fault in your deployment.

The per-child access ledger (5.8) does exist and is unrelated to this.

8.5bSafety check

This was called the Privacy check until 30 August 2026, when it grew from one check into five. The redaction check is unchanged and is now the first tab.

What it is for. The system produces work: it redacts a note, screens a passage for danger signals, drafts a sentence from evidence, and ranks a waiting list. Automated tests prove each of those does what it was written to do. They cannot tell you how often what it was written to do is enough. This screen is how a person finds out, one piece of output at a time.

Two ways to use it, and most tabs offer both

Check a note shows you something the system already produced about a real child, and asks you to grade it.

Try your own gives you the field the real thing is entered in, runs the system on whatever you write, and shows you what came back.

They answer different questions and both are worth asking. The first measures how the system is doing on the actual record. The second is the one you reach for when you want to go looking for a failure, and it is the only one that works on a check nothing has been through yet. It is also the one that finds a problem BEFORE a child's data is involved, which is the difference between a fix and a deletion.

A switch above the card moves between them. It appears only on the tabs that have both.

How the grading half works

How it works, in every lane. You are shown one item, told what the system concluded about it, and asked one question. Two answers, and neither one is the highlighted button. This is a measurement. A screen that leans toward "all clear" would spoil it. Saying it went wrong opens two sets of chips: what was wrong, and why you think it happened. Not sure, show me another records nothing at all. Use it freely. An item you skip has not been checked, so it comes back.

There is nowhere to type in any lane. In the redaction lane, if you find a name that got through, that name is in the cloud. A text box would be where someone could copy it into a second place. The other lanes keep the same shape. Every answer is a chip from a fixed list. The record keeps who checked, when, which item by its exact document path, the verdict and the categories. It never keeps the item or what you found in it.

The tabs

Redaction. One informant note exactly as the cloud holds it, with the redactions drawn as small dark chips, and a line saying what the redaction reports removing. Is anything here still identifying?

Danger signals. One passage the red-flag screening read, and what it concluded, including the passages it said nothing about. That last part is the point: this is the only tab that can show you something the system MISSED rather than something it got wrong, so its chips carry both directions. It also tells you how many graded phrases the screening had to work with, because a clear result over a small list is a weaker statement than a clear one over a large list.

ELI drafts. One drafted sentence, the grade the council gave it, and the evidence it cites underneath. Does that evidence really say this? A citation the document does not carry is shown as a named gap rather than left out. A sentence resting on evidence that was never stored is worth catching. Signed documents are never shown here. A signature is over a fixed thing, so a finding against one would be something nobody can act on.

NAMI triage. One waiting child, the reason given for their place in the queue, and the facts that place was worked out from. Is this child in the right place? Every waiting child appears, not only the ones the queue moved, so you can also say that somebody should have been moved and was not.

A tab you cannot see is a check this deployment cannot run. The tabs are drawn from what the server can actually serve. A lane with nothing behind it is absent rather than present and empty.

The numbers at the top

Checks made, how many found something, and the miss rate, per tab. Each tab keeps its own count and its own rate; they are separate measurements of separate things and are never added together.

One item is one mark. A note with four identifiers where one survives counts as one miss, not a quarter of one. The rate stays blank until there are ten checks in that tab. A percentage over two of them says nothing. The count is checks rather than distinct items, so checking the same one twice counts twice.

The count of items is printed with the count of children beside it, and the second number is the one that bounds what the check can tell you. Two hundred drafted sentences across seven children is a measurement of seven children.

Under the numbers, a line saying when this tab was last looked at and whether that was this week, then one line per person who has checked.

The weekly round is a state, not a schedule. Nothing here runs a job or sends a reminder. The line tells you which tabs are still owed a look this week.

When you find something. The row in the log carries the document path. In the redaction lane that is the thing to delete, and deleting it is a separate deliberate action outside the console, not a button here. In the other lanes it is how a reader gets back to what was judged.

Sandbox and live. The items you read are the ones in the mode you are signed in to, and the log lives beside them. The redaction tab is sandbox only. Its finding on a fail is a document to delete. Live records are never deleted. A live redaction finding would file a permanent note that a real child's identifier is in the cloud and nobody may remove it. The other tabs run in both modes. None of their findings has a deletion attached.

How the Try your own half works

The field is the real one. On the redaction and danger-signal tabs it is the box an informant writes in, with the same prompt. A test entered somewhere that does not look like the real entry point is testing something other than the thing people use.

It opens with something already in it. Press the button once and see what the check does before deciding what to try. Change it to whatever you want to test.

Nothing is kept unless you send it. Running the check stores nothing. No child's record is touched either way. Run it as often as you like.

There is no button saying the output was fine. This half is not a measurement. A count of the runs you were happy with would only record how hard you looked. If it looks right, change the input and run it again.

When it does not look right, pick whichever categories fit and write what is wrong in your own words. Send it. Your words are what matters. The categories say what kind of fault it is; your sentence says what the fault was.

What you wrote and what came back are sent with it. A developer can run the exact same thing again. It also means the note you type here is stored. This half is sandbox only, on every tab. Nothing you type can reach the live database.

Two tabs have no Try your own half, and it is about cost rather than readiness. An ELI draft is written from a child's whole record over several minutes, so it is graded here rather than run here. Image analysis has nothing behind it yet.

8.5cSafety report

Everything anyone has sent from a Try your own run, newest first. It is for developers rather than for clinic work: nothing on it is about a child.

Each row leads with what the tester wrote, then the categories they picked, who they were and which build they were running. Opening the row shows the exact input and exactly what came back, so the case can be run again.

Mark handled when it is dealt with. The row stays in the record. It leaves the default view, which shows open ones. Nothing here is ever deleted.

There are counts and no percentages. How many are open, how many are handled, how many in total. A share would measure the people working on the list rather than the system. Reading it beside the miss rate on the tab before would put two very different numbers side by side.

8.6What administration cannot do

Worth stating, because the boundary is unusual:

  • An admin cannot read a child's name. Nobody can, through the console. Names live in the local vault on a clinic device and never reach the cloud, so there is no admin screen that could show one.
  • An admin cannot move their own account between modes, and cannot retire it either.
  • An admin cannot delete anything. Not an account, not a school. Both have a way to be taken out of use that keeps the record: retiring, and withdrawing.
  • An admin cannot make an agent decide anything. The model settings choose which model drafts and audits. They do not change what an agent is permitted to do, which is fixed: suggest, flag, rank, draft.
  • An admin cannot email a family, and no future admin screen will. There is no family address in the cloud to send to. Contact details live in the clinic's local vault, which is the whole point of the system, and putting one in the cloud so a screen could mail it would undo that. A clinic that needs to reach families does it from the vault, on the clinic's own machine, where the details already are.

Next: 9. The informant app.

9

The informant app

Bahagian ini untuk ibu bapa, penjaga dan guru. Ia ditulis dalam Bahasa Melayu dahulu, sama seperti aplikasi itu sendiri, dengan terjemahan Inggeris selepas setiap bahagian.

This part is for parents, caretakers and teachers. It is written in Bahasa Melayu first, as the app itself is, with English following each section.


9.1Apa itu aplikasi ini / What this app is

Aplikasi ini ada di https://form.jejak-app.my. Ia dibuka dalam pelayar telefon; tiada apa-apa untuk dipasang. Anda boleh menambahnya ke skrin utama telefon supaya ia mempunyai ikon dan namanya sendiri.

Buka pautan daripada klinik dahulu, sekali sahaja. Selepas itu telefon anda sudah tahu klinik mana, jadi anda boleh membuka aplikasi ini terus.

Anda menjawab borang tentang seorang kanak-kanak yang anda kenali. Klinik menggunakan jawapan anda untuk memahami keadaan kanak-kanak itu dari semasa ke semasa.

Aplikasi ini tidak pernah mengetahui nama kanak-kanak itu. Ia hanya mengetahui satu kod, seperti MRN-4T8N.

The app is at https://form.jejak-app.my. It opens in your phone's browser; there is nothing to install, and you can add it to your home screen so it has its own icon and name.

Open the clinic's link once first. After that your phone knows which clinic you belong to, so you can open the app directly.

You answer forms about a child you know. The clinic uses your answers to understand how that child is doing over time.

The app never learns the child's name. It knows only a code, like MRN-4T8N.

9.2Kali pertama / The first time

Klinik memberi anda sekeping surat. Pada surat itu ada satu kod QR dan satu kod tuntutan bertulis, seperti CLM-4T8N-W04.

  1. Imbas kod QR dengan kamera telefon. Jika kamera tidak dapat mengimbasnya, buka aplikasi dan taip kod tuntutan itu di bawah "Saya ada surat".
  2. Periksa kod kanak-kanak pada telefon anda sama dengan kod pada surat. Langkah ini penting: ia yang memastikan jawapan anda difailkan kepada kanak-kanak yang betul. Sistem tidak dapat memeriksanya untuk anda, kerana ia memang tidak menyimpan nama sesiapa.
  3. Aplikasi menawarkan anda satu nama pengguna, seperti CTK-MERPATI-17. Anda tidak menciptanya sendiri. Pilih satu, kemudian tetapkan kata laluan.
  4. Simpan nama pengguna itu. Anda akan menggunakannya semula.

Kod tuntutan hanya boleh digunakan sekali, dan ia luput selepas satu tempoh. Jika ia sudah digunakan atau luput, minta klinik mengeluarkan yang baharu.

Jika anda terlupa nama pengguna anda, telefon yang sama biasanya sudah mengisinya untuk anda pada skrin log masuk. Jika tidak, tanya klinik. Mereka boleh melihatnya. Semasa anda log masuk, nama pengguna itu juga tertera di bahagian atas skrin utama.

The clinic gives you a letter. On it are a QR code and a written claim code, like CLM-4T8N-W04.

  1. Scan the QR with your phone's camera. If it will not scan, open the app and type the claim code under "I have a letter".
  2. Check that the child's code on your phone matches the code on the letter. This step matters: it is what files your answers against the right child. The system cannot check it for you, because it deliberately holds nobody's name.
  3. The app offers you a username, like CTK-MERPATI-17. You do not invent one. Pick one, then set a password.
  4. Keep that username. You will use it again.

A claim code works once and expires after a period. If it has been used or has expired, ask the clinic to issue a new one.

If you forget your username, the same phone usually fills it in for you on the sign-in screen. If not, ask the clinic; they can look it up. While you are signed in it also shows at the top of the main screen.

9.3Jika anda sudah ada nama pengguna / If you already have a username

Gunakan nama pengguna yang sama. Satu akaun boleh meliputi lebih daripada seorang kanak-kanak, contohnya dua adik-beradik di klinik yang sama.

Pada skrin, pilih "Saya sudah ada akaun" dan log masuk seperti biasa.

Use the same username. One account can cover more than one child, for example two siblings at the same clinic.

On screen, choose "I already have an account" and sign in.

9.3aSelepas anda log masuk / After you sign in

Di bahagian atas skrin, sentiasa kelihatan pada mana-mana tab: nama kanak-kanak itu seperti yang anda simpan pada peranti ini, kod klinik untuknya (MRN), dan nama pengguna anda sendiri. Nama itu tidak pernah keluar dari peranti anda; kod itu yang digunakan oleh klinik.

Di bahagian bawah ada tiga tab:

  • Nota ialah dua kotak menulis.
  • Tugasan ialah borang yang klinik hantar kepada anda.
  • Hantaran ialah senarai semua yang anda sudah hantar.

Jika ada borang yang belum sampai ke klinik, pemberitahuannya kekal di bahagian atas pada mana-mana tab, supaya ia tidak tersembunyi di belakang tab yang anda tidak buka.

Dua kotak nota. Yang di atas, Sesuatu yang baik, untuk apa-apa yang anda gembira lihat pada anak itu. Yang di bawah, Sesuatu yang anda risaukan, untuk apa-apa yang anda ingin klinik tahu. Kedua-duanya dihantar berasingan, masing-masing dengan butang hantarnya sendiri. Anda tidak perlu menulis perkara yang baik dahulu sebelum melaporkan sesuatu yang mendesak.

Perkara kecil pun dikira. Anak yang menyiapkan kerja sekolah sendiri, atau yang tidur lebih awal, ialah maklumat yang berguna kepada doktor sama seperti sesuatu yang tidak kena.

Selepas menghantar. Kotak itu kosong semula dan satu baris hijau memberitahu nota anda sudah sampai ke klinik. Baris itu kekal sehingga anda mula menaip nota berikutnya, jadi anda tidak perlu tergesa-gesa membacanya. Jika baris itu tidak muncul, jangan anggap ia sudah dihantar.

Tugasan. Senarai itu dibaca semula setiap kali anda kembali ke aplikasi. Jika klinik baru sahaja memberitahu anda ada borang menunggu dan senarai itu masih kosong, tekan Semak semula di bawahnya. Anda tidak perlu log keluar.

Hantaran. Setiap nota dan setiap borang yang anda hantar disenarai di sini, yang terbaharu di atas. Nota ditunjukkan seperti yang tersimpan di klinik, jadi jika aplikasi memadamkan nama semasa anda menaip, versi yang anda baca di sini ialah versi yang doktor baca.

Setiap nota disenarai dengan nama kotak tempat anda menaipnya, jadi anda boleh menyemak semula minggu-minggu yang baik dan minggu-minggu yang merisaukan. Nota yang dihantar sebelum ada dua kotak hanya tertulis Nota: pada masa itu klinik tidak menyimpan yang mana satu.

Senarai ini datang dari klinik, bukan dari telefon anda. Jadi ia masih ada walaupun anda tukar telefon atau memadam data pelayar. Nota yang dihantar sebelum kemas kini 22 Ogos 2026 tidak disenarai: klinik tidak menyimpan siapa yang menghantarnya, jadi ia tidak boleh ditunjukkan kepada sesiapa.

At the top of the screen, on every tab: the child's name as you saved it on this device, the clinic's code for them (the MRN), and your own username. The name never leaves your device; the code is what the clinic uses.

Along the bottom are three tabs:

  • Nota is the two writing boxes.
  • Tugasan is the forms the clinic has sent you.
  • Hantaran is everything you have sent.

If a form has not reached the clinic, its notice stays at the top on every tab, so it cannot hide behind a tab you did not open.

Two note boxes. The top one, Something that went well, is for anything you were glad to see in the child. The one below, Something you're worried about, is for anything you want the clinic to know. They send separately, each with its own send button. You never have to write something good first before reporting something urgent.

Small things count. A child finishing their homework on their own or settling earlier at night is as useful to the doctor as something that went wrong.

After you send. The box empties and a green line tells you your note reached the clinic. That line stays until you start typing the next note. There is no rush to read it. If it does not appear, the note was not sent.

Tasks. The list re-reads every time you return to the app. If the clinic just told you a form is waiting and the list is empty, press Check again underneath it. You do not need to sign out.

Hantaran. Every note and every form you have sent is listed here, newest first. A note is shown as the clinic holds it. If the app removed a name while you were typing, the version you read here is what the doctor reads.

Each note is listed under the name of the box you typed it in. You can look back over your good weeks and worried weeks. A note sent before there were two boxes just says Note; the clinic did not record which box at the time.

This list comes from the clinic, not your phone. It survives changing phone or clearing browser data. Notes sent before the 22 August 2026 update are not listed. The clinic did not record who sent them, so they cannot be shown to anyone.

9.4Mengisi borang / Filling in a form

Borang ditunjukkan satu soalan pada satu masa. Jawab mengikut apa yang anda lihat sendiri, bukan apa yang anda fikir klinik mahu dengar.

Beberapa borang mempunyai ruang untuk anda menulis dengan perkataan sendiri. Tulislah. Ruang itu berguna.

Seekor burung kecil di sisi sesetengah ayat. Kadangkala anda akan nampak JEJI, burung kecil aplikasi ini, di sisi satu ayat pendek: di skrin memasukkan kod, pada dua langkah pertama persediaan akaun, di skrin memilih borang, di atas borang itu sendiri, di skrin selepas anda menghantar borang, dan di skrin menulis nota kepada klinik. Ayat yang ada JEJI di sisinya ialah aplikasi ini sendiri bercakap dengan anda, menerangkan skrin itu. Soalan-soalan borang tidak pernah mempunyai JEJI di sisinya. Itulah caranya anda tahu soalan itu daripada klinik, bukan daripada aplikasi.

Apa yang berlaku kepada perkataan anda. Sebelum apa-apa dihantar, telefon anda membuang butiran pengenalan daripada teks: nama, nombor kad pengenalan, nombor telefon (telefon bimbit dan talian tetap), nama sekolah. Yang tinggal ialah maksud klinikalnya. Skrin menunjukkan kepada anda versi yang akan disimpan, sebelum anda menghantarnya.

A form is shown one question at a time. Answer from what you have seen yourself, not what you think the clinic wants to hear.

Some forms have space to write in your own words. Do use it; that space is valuable.

If you have a lot to say, make the box bigger. A small arrow sits at the right end of the writing box. Press it and the box fills the screen. You are not typing a paragraph through three lines. Selesai closes it. Your words stay the same either way. The notice about what was removed stays on screen while you write.

A small bird beside some lines. Sometimes you will see JEJI, this app's small bird, beside a short line of text: on the code-entry screen, on the first two steps of setting up your account, on the screen where you pick a form, above the form itself, on the screen after you send a form, and on the screen for writing a note to the clinic. A line with JEJI beside it is the app itself talking to you, explaining that screen. Form questions never have JEJI beside them. That tells you a question came from the clinic, not the app.

What happens to your words. Before anything is sent, your phone removes identifying details from the text: names, IC numbers, phone numbers (mobile and landline), school names. What remains is the clinical meaning. The screen shows you the version that will be kept, before you send it.

How to tell whether it removed what you expected: read that preview. It is labelled as what the cloud keeps, and it is literally what is sent. If you ever see something in that preview that should not be there, delete it from your text before sending and tell the clinic.

9.4aDiari ubat / The medication diary

Diari ubat ialah semakan mingguan pendek semasa dos ubat sedang dilaraskan.

Ia tinggal dalam telefon anda dan tidak dihantar ke klinik. Ini berbeza daripada borang: borang pergi ke klinik, diari tidak. Jadi bawa telefon anda ke temu janji dan tunjukkan kepada doktor. Jika ada kesan sampingan yang merisaukan anda, hubungi klinik, jangan tunggu temu janji dan jangan bergantung pada diari untuk memberitahu mereka.

Nama pertama anak anda boleh ditulis di skrin itu, sama seperti diari kertas. Nama itu juga tidak pernah keluar dari telefon.

The medication diary is a short weekly check while a dose is being adjusted.

It stays on your phone and is not sent to the clinic. This is different from a form: forms go to the clinic, the diary does not. So bring your phone to the appointment and show it to the doctor. If a side effect worries you, contact the clinic rather than waiting for the appointment, and do not rely on the diary to tell them.

You can write your child's first name on that screen, exactly as on a paper diary. That name never leaves the phone either.

9.5Tanpa talian / Without a connection

Aplikasi ini terbuka walaupun tiada talian. Borang yang anda isi tanpa talian disimpan pada telefon dan dihantar secara automatik apabila talian kembali.

Anda boleh keluar dari skrin borang itu tanpa risau. Selagi ada borang yang menunggu, satu kad di halaman utama menyenaraikannya dan memberitahu tarikh ia diisi, dengan butang untuk cuba hantar sekarang. Kad itu hilang dengan sendirinya sebaik sahaja borang tersebut sampai ke klinik.

Tetapi apa-apa yang memerlukan jawapan daripada pelayan, seperti log masuk atau menuntut kod, memerlukan talian.

Kadang-kadang klinik belum dapat membenarkan sesuatu borang dihantar buat masa ini, dan keadaan itu boleh berubah kemudian. Borang itu kekal tersimpan dengan selamat pada telefon anda, dan aplikasi memberitahu anda untuk bercakap dengan klinik dahulu. Selepas itu, anda boleh cuba hantar semula borang yang sama di tempat mesej itu muncul.

Ada juga borang yang ditolak terus dan tidak akan diterima, misalnya kerana borang itu datang daripada pihak yang bukan sebahagian daripada rawatan kanak-kanak itu. Borang jenis ini tidak dihantar semula, dan aplikasi akan memberitahu anda begitu, bukan membiarkan anda menyangka ia masih dalam perjalanan.

The app opens even with no signal. A form you fill in offline is held on your phone and sent automatically once the connection comes back.

You can leave that form's screen without worrying. For as long as a form is waiting, a card on the home page lists it with the day it was filled in and a button to try sending now. The card goes away on its own once the form reaches the clinic.

Anything needing an answer from the server, such as signing in or claiming a code, needs a connection.

Sometimes the clinic has not allowed a form through yet. That can change later. The form stays saved on your phone. The app tells you to speak to the clinic first. After that, you can try sending the same form again from where you saw this message.

Some forms are refused outright and will never be accepted. For example, the form came from someone outside the child's care. A refused form is not resent. The app tells you this rather than letting you think it is still on its way.

Cara mengetahui mesej mana yang anda lihat: kadangkala mesej ini memenuhi keseluruhan skrin, dan kadangkala muncul sebagai nota pendek berhampiran bahagian atas halaman; walau apa pun bentuknya, apa yang tertulis itulah yang memberitahu anda mesej yang mana. Satu mesej yang menyatakan borang disimpan pada telefon ini dan akan dihantar apabila talian kembali hanya menunggu talian, dan tidak memerlukan apa-apa daripada anda. Satu mesej yang menyatakan borang belum sampai lagi, dengan jawapan anda kekal pada telefon, sedang menunggu klinik; bercakaplah dengan mereka, kemudian cuba hantar semula di tempat anda melihat mesej itu. Satu mesej yang menyatakan borang tidak diterima, tanpa apa-apa untuk dicuba semula, bermakna sistem klinik telah menolaknya untuk selama-lamanya. Satu mesej yang menyatakan telefon itu sendiri tidak dapat menyimpan salinan borang bermakna borang itu tiada di awan dan tiada pada telefon; jawapan anda masih di skrin, jadi cuba hantar semula, dan jika ia masih gagal, kosongkan sedikit ruang telefon dahulu. Jika tiada satu pun mesej ini muncul semasa anda menghantar borang, perhatikan mesej yang menyatakan ia telah sampai ke klinik; itulah yang mengesahkan ia berjaya dihantar.

How to tell which you are looking at: these messages sometimes fill the whole screen and sometimes appear as a short note near the top. What it says tells you which one you are looking at. One saying the form is saved on this device and will send once you are back online is waiting for a connection only; it needs nothing from you. One saying the form has not gone through yet, with your answers on the phone, is waiting on the clinic; speak to them, then try sending it again from where you saw the message. One saying the form was not accepted, with nothing to retry, means the clinic's system has refused it for good. One saying the phone itself could not keep a copy means the form is in neither the cloud nor the phone. Your answers are still on screen; try again, and if it still fails, free up space on the phone first. If none of these appear when you send a form, watch for the message that says it reached the clinic. That confirms it went through.

Jika anda log masuk dan mengisi borang yang diberikan oleh klinik kepada anda, borang itu akan hilang daripada senarai tugasan anda sebaik sahaja ia berjaya dihantar, jadi aplikasi tidak akan meminta anda mengisinya sekali lagi.

If you are signed in and fill a form the clinic assigned you, it drops off your task list once it goes through. The app will not ask you to fill it in again.

9.6Privasi anda, dan privasi kanak-kanak itu / Your privacy, and the child's

Beberapa perkara yang benar tentang sistem ini, dan patut anda ketahui:

  • Nama kanak-kanak itu tidak pernah sampai ke internet. Ia tinggal di klinik sahaja.
  • Nama pengguna anda bukan nama anda. Ia dipilih daripada satu senarai perkataan tetap, iaitu perkataan tentang tempat, binaan dan burung. Tiada siapa boleh meneka siapa anda daripadanya.
  • Surat itu tidak menyebut nama sesiapa. Jika ia hilang, ia tidak memberitahu penemunya tentang mana-mana kanak-kanak.
  • Jawapan anda diasingkan daripada jawapan orang lain. Jika seorang ibu dan seorang bapa mengisi borang yang sama, kedua-duanya kekal berasingan.

A few things that are true of this system, and worth knowing:

  • The child's name never reaches the internet. It stays at the clinic.
  • Your username is not your name. It comes from a fixed word list of places, structures and birds. Nobody can guess who you are from it.
  • The letter names nobody. If it is lost, whoever finds it learns nothing about any child.
  • Your answers are kept separate from others. If a mother and a father both complete the same form, the two stay distinct.

9.7Bahasa / Language

Aplikasi ini dalam Bahasa Melayu secara lalai, dengan butang untuk bertukar ke Bahasa Inggeris. Butang itu ada pada halaman utama, senarai tugasan, nota dan diari, dan bahasa yang anda pilih kekal sehingga anda menukarnya semula. Skrin borang yang dihantar oleh klinik tiada butang itu, jadi pilih bahasa anda sebelum membuka borang.

Satu perkara yang perlu diketahui: soalan-soalan borang klinikal itu sendiri dalam Bahasa Inggeris buat masa ini, termasuk butang jawapannya ("Not at all", "Just a little", dan seterusnya). Ia tidak diterjemahkan secara automatik: terjemahannya mesti disahkan oleh seorang klinisian, kerana menukar perkataan dalam satu instrumen yang telah disahkan boleh menukar maksudnya. Nama borang seperti SNAP-IV dan PSC-17 kekal sama dalam kedua-dua bahasa.

Cara mengetahuinya: buka mana-mana borang. Jika soalan pertama dalam Bahasa Melayu, terjemahan itu sudah sampai.

The app is in Bahasa Melayu by default, with a button to switch to English. That button is on the home page, the task list, the notes screen and the diary. The language you choose stays until you change it. The screen for a form the clinic sent has no button, so choose your language before you open a form.

One thing to know: the clinical form questions are in English for now, and so are their answer buttons ("Not at all", "Just a little", and so on). They are not auto-translated. A clinician must confirm the wording, because changing the words in a validated instrument can change what it measures. Form names like SNAP-IV and PSC-17 stay the same in both languages.

How to tell: open any form. If the first question is in Malay, the translation has arrived.

9.8Jika ada masalah / If something goes wrong

  • Kod tidak diterima. Skrin itu ada butang Masukkan kod semula, yang membawa anda terus kembali ke kotak kod. Periksa ejaannya dahulu; satu huruf silap adalah sebab yang paling biasa. Jika ia masih gagal, kod itu mungkin sudah digunakan, luput, atau ditarik balik oleh klinik. Hubungi klinik.
  • Log masuk gagal. Skrin itu memberitahu apa yang berlaku: kotak yang kosong, nama pengguna atau kata laluan yang salah, atau klinik yang tidak dapat dihubungi. Yang ketiga bermakna talian anda, bukan kata laluan anda.
  • Terlalu banyak percubaan. Aplikasi akan meminta anda menunggu sebentar. Ini melindungi kanak-kanak lain, bukan menghukum anda.
  • Anda lupa nama pengguna. Hubungi klinik.
  • Aplikasi memberitahu ada versi baharu. Satu kotak kecil muncul di bawah skrin: Versi baharu sudah sedia, dengan Muat semula dan Nanti. Aplikasi tidak akan memuat semula dengan sendirinya, jadi anda tidak akan kehilangan apa-apa yang sedang ditaip. Tekan Muat semula apabila anda sudah bersedia. Jika anda tekan Nanti, ia tidak akan bertanya lagi kali ini, dan versi baharu itu tetap ada apabila anda buka aplikasi kemudian.
  • Klinik meminta versi yang anda guna. Nombornya ada di bahagian paling bawah skrin pertama, sebelum anda log masuk.
  • A code is not accepted. That screen has an Enter the code again button which takes you back to the code box. Check the spelling first; one wrong character is the commonest cause. If it still fails, the code may have been used, expired, or withdrawn by the clinic. Contact them.
  • Sign-in fails. The screen says which of three things happened: a box you left empty, a username or password the clinic refused, or the clinic being unreachable. The third one is your connection, not your password or username.
  • Too many attempts. The app asks you to wait a little. This protects other children.
  • You forgot your username. Contact the clinic.
  • The app says a newer version is ready. A small box appears at the bottom of the screen with Reload and Not now. The app never reloads itself, so nothing you are typing is lost. Press Reload when you are ready. Pressing Not now stops it asking this time. The newer version is still there next time you open the app.
  • The clinic asks which version you are on. The number is at the very bottom of the first screen, before you sign in.

That is the last part written for parents, caretakers and teachers. Part 10, Releasing the desktop build, is not about using the app at all; it is a runbook for whoever cuts a desktop release.