Every output has a history
A NIfTI volume, preview, structured label or segmentation is never treated as an isolated file. It points back to a pseudonymous source study, the transformation that created it, the relevant policy and the release in which it was approved.
Policy travels with the data
Commercial scope, retention, geography, exclusivity and security obligations belong to the programme record. Release controls evaluate those policies before access is granted rather than relying on filenames or institutional memory.
- Hospital authority and approved programme scope
- Pseudonymous study and series relationships
- Pipeline, ruleset and model versions
- Label source, reviewer and adjudication state
- Quality results, exclusions and unresolved limitations
- Release version, recipient, delivery and deletion state
Diligence without exposing identity
Enterprise review needs evidence of provenance and control, not patient identity. The platform produces aggregate distributions, manifests and audit records that support diligence while direct identifiers remain outside the release environment.
Questions, answered directly.
Does lineage include direct patient identity?+
External release lineage uses pseudonymous identifiers. Any authorized re-identification mapping remains under the appropriate hospital or controller process.
Can a release be reproduced?+
The goal is reproducibility from authorized source inputs using recorded pipeline, rules and model versions.
What happens when a dataset changes?+
A change creates a new release version with its own manifest, differences and approval evidence.
