Skip to main content
The care-circle walkthrough the README used to carry in full. Parts 2 to 4 are recorded against a running ./deploy.sh stack with SEED_DEMO_DATA on; part 1 is drawn, because what it shows is the authorization path and a drawing of that can be checked against user/care_circle.py while a recording cannot. The README carries three of the four scenes and links here for the fourth. SEED_DEMO_DATA defaults to on, so the ① → ② → ③ chain is walkable the moment ./deploy.sh finishes — signing in and browsing the seeded record need no key; the extraction in parts 2 and 3 and the questions in part 4 ride the one key configured above. 1 · Arrive. You sign in as you@mirobody.ai and find two records, not one. Yours: a year of self-tracked vitals and a lab panel from last November. mom@mirobody.ai has the same shape and is a different person, sharing their record with you view-only, and their weight is climbing, their nights are short and their HbA1c has crossed out of range. Same question, two answers, and only one of the two records is yours. Isolation you can see, not just read about.

How one person reaches another's health record: a request passes resolve_subject, which requires both memberships accepted and the subject's own health_access switch, and either returns access trimmed to the request or raises a 403How one person reaches another's health record: a request passes resolve_subject, which requires both memberships accepted and the subject's own health_access switch, and either returns access trimmed to the request or raises a 403

These four were a drawing until 1.4.4. Each is pinned by a test as a security property rather than a nicety, because the shipped code once contradicted all four at once (see the roadmap). A table can be diffed; a picture cannot. The switch is a column, not a promise: care_circle_members.health_access, NOT NULL DEFAULT 0, on your own row. Being invited into a circle shares nothing — the member decides, and no other person’s action can raise it. The check that reads it raises rather than returning a falsy value, so a route that forgets to look answers 403 instead of handing over a record. examples/06_care_circle_rules.py prints the whole decision table offline. 2 · ① Collect. demo/upload/ holds four files the seed deliberately leaves out, so uploading one is not a no-op — and they are four different formats, because a health record arrives as whatever the lab, the clinic and the family actually produce: Drop one on the Data page and the file is stored first, verbatim and traceable. That is all ① Collect does, and the split matters: what a lab said is one fact, what it means is another.

Dropping a lab-report PDF on the Data page; its analytes extracted, each linked to its source file

3 · ② Translate. Its analytes come out as readings a few seconds later, each one linking back to the file it was read off, and each one carrying a code:
The model reads the page; it does not get to invent the code. Resolution is a lookup against the shipped bundle, offline and deterministic, and it abstains rather than guessing when it has no answer. That code is what lets different files be read together. The csv comes from a different lab and names its analytes differently — Cholesterol, Total where the panel prints Total Cholesterol-TC — and both are 14647-2, so they are one series and not two. The unit is part of that identity rather than something smoothed over: cholesterol is 14647-2 in mmol/L and 2093-3 in mg/dL, and saying so is what stops a trend built from a mix of the two from being silently wrong. Reconciling those two codes into one comparable line is 1.5.0’s comparability key; on the device side the conversion already happens, and examples/02_standardize_a_reading.py turns 154.5 lb into 70.08 kg offline. 4 · ③ Agent. Ask how the cholesterol has moved. The agent finds every file that carries it, the csv’s other spelling included, and answers from what it read:
Three files, three vocabularies, one line, and the file each number came off named beside it. Ask the same question about the shared record and the answer is a different person’s.

Asking about your own panels; the agent charts both draws, cites the file each came from, and reads the trend

Asking the same question about the shared record; the agent answers from a record you can only view

That is the whole chain in one sitting: a file goes in, a coded reading comes out, and an agent answers over it — C · T · A, each stage visible on its own rather than asserted. Every value is generated; no file here describes a person, and the seed needs no network and no key. Set SEED_DEMO_DATA=false for a deployment that will hold real data. demo/README.md says what each file is and how to rebuild it; what the extraction pass does not yet do with those readings is in docs/roadmap.md rather than glossed over here.