How it works
The people who actually know the workflow — a nurse manager, a department coordinator — describe the tool they need in plain English. A Brightrail engineer assigned to your institution makes it real on infrastructure that carries the security and compliance burden for them. Your people never touch code; your admins decide everything that matters, on the record.
Dozens of point-solution contracts — each with its own renewal, security review, and support queue — for software that's mostly the same app wearing different logos.
Every department has five tools they've begged IT for. IT has a two-year queue and better things to do than build a rounding checklist. That's triage, not failure.
So departments build it anyway — spreadsheets, personal databases — with sensitive data in places nobody audits. The real choice is vendor vs. ungoverned.
This platform is the third option: the speed of your own people describing what they need, with more governance than the vendors gave you — not less.
Step 1
Someone who knows the workflow describes the tool in plain English, in a workspace built for the conversation — no ticket queue, no spec documents. Every consequential choice — who sees what, what gets stored, what happens on deletion — is put to your people as an explicit decision card: options, consequences, one click. Recorded, exportable, written for a compliance reader.
Step 2
A Brightrail engineer assigned to your institution authors the tool on our healthcare foundation — the security architecture, access model, and compliance documentation are inherited, not reinvented per tool. One accountable author, vendor-grade change control: your team sees the tool running in a preview before it pilots and shapes it in conversation. Designated people on your side can keep proposing improvements in plain English at any time; Brightrail accepts them onto the build list, raises a decision to your admins, or declines with a reason on the record. Nothing merges, deploys, or reaches your staff without a named human's review.
Step 3
Every tool your institution runs lives in one application — one login for your staff, tools opening side by side, and an instance that is yours alone: no other institution shares it. We host, patch, secure, and operate it. Your IT department gets a governed portfolio — every tool visible, every tool with a named steward, every tool archivable in one click — instead of a sprawl of vendors or spreadsheets.
No tool reaches your staff in one leap. Every build moves through named stages your people can see, and the gate between each stage is a recorded sign-off by your people, not ours.
The requesting team works with a running preview on fake data and formally signs off before anything goes live.
Live for a named cohort — the tool's steward plus a handful of users — for a soak period. Pilot tools don't bill and don't count against your plan.
Going house-wide takes two names — an admin's decision with the steward's concurrence — with the pilot's real usage numbers as the evidence they read from.
Scrutiny scales with data sensitivity, the same proportionality logic as your own change advisory board — staged, recorded, and reversible. And because every gate is a recorded decision, each tool carries its own release history, exportable, next to its decision log.
Hand us your infection-control SOP and the platform drafts the operational rules it implies — each one carrying a verbatim excerpt of your own document as its citation. Your people approve each rule; only then does it run, and what runs is deterministic — currency lapses, expirations, overdue cadences — not an AI improvising. When a surveyor asks “show me the policy behind this practice,” the answer is a click.
The doctrine, in four words: rules fire, agents reason. The AI reads your policies, never your patients.
Every instance ships with a standard set of tools on from day one, plus a catalog your institution activates tool by tool — each one shaped to your programs through co-design, with your admins confirming every choice on the record. A catalog tool accelerates the build, never the sign-offs: it arrives pre-answered, never pre-approved.