WAJD Learning

Module 2 of 2 · 50 minutes

Oversight that works: approval, permissions, logs and the right questions

By the end of this module you will be able to

  • Place a human approval step before the actions that matter
  • Tell a real review from a rubber stamp
  • Apply least privilege and separate identity to an agent
  • Explain the test of whether you can say why an agent did something
  • Ask a supplier and your organisation the questions that must be answered before go live
  • State where accountability sits when an agent acts

Work through it

1 interactive for this module, built on the WAJD Teach engine. Nothing moves until you ask it to, and every one has a written version if you would rather read it.

Watch: Emma and George talk it through

5 minutes. Captions are on, and the same conversation is written out in full below. The voices are computer generated.

Emma George, last time you scared me. This time give me the controls. If a supplier walks onto my ward with an agent tomorrow, what do I do?

George Start with one control, because it does most of the work. A person approves before the agent changes anything outside its own workings. Sending, booking, ordering, discharging, altering a record, changing a rota.

Emma And reading and drafting?

George Can run free. That's the dividing line. Preparing is cheap and reversible. Changing waits for a named human. The joint guidance asks for human approval of high-impact actions and ongoing oversight, not a check done once at set-up.

Emma Surely that's easy. I click approve.

George That's the trap. Picture one button that approves fourteen discharges, with no way to see what each one will do. That isn't a control, it's consent without understanding.

Emma So what does a proper one look like?

George It shows the specific action in plain words, with what you need to judge it. It gives you time. It lets you refuse without penalty, and it logs refusals as readily as approvals.

Emma Why does the refusals part matter?

George Because if nobody ever refuses anything, either the agent is perfect or nobody is looking. Only one of those is likely. A zero refusal rate is a warning, not a success.

Emma Fair. What else?

George Least privilege. Give it only the access the task needs, for as long as it needs it. Start read-only. Add the power to change something only where there's a reason, for the narrowest set of records. The guidance warns against broad access, especially to sensitive data, and against permissions set once and never reviewed.

Emma Can't it just use my login? That's what the demo did.

George It shouldn't. It acts under its own identity. Then the log shows what the agent did, you can withdraw its access without touching a person, and nobody's blamed for something software did in their name.

Emma Okay. Something goes wrong. What do I need?

George The ability to answer why did it do that within the hour. So a record of what it was asked, what it read, what it decided at each step, and what it changed, kept long enough and readable by the people who'll need it.

Emma How do I check that before we buy?

George Ask for the log during the demo. For the example they've just run. If the supplier can't show you one, you've learned something important.

Emma And if I need to stop it?

George You need a stop control that works at once, and a manual fallback that people can still do. A team that's forgotten the task has no fallback.

Emma I've heard of DCB0160, a hazard log, impact assessments. Do I need all that for a rota tool?

George Proportionately, yes. DCB0129 is for manufacturers and DCB0160 for organisations deploying, with a Clinical Safety Officer, a hazard log and a safety case. A data protection impact assessment where personal data's processed in a high-risk way. And if it's intended for a medical purpose it may be a medical device. You may not own those, but you should know who does.

Emma And when it nearly goes wrong?

George Report it as a near miss through your patient safety route. In England that's the national Learn from Patient Safety Events service. A near miss is the cheapest evidence you'll ever get that a control needs strengthening.

Emma Give me the seven questions I can take into the meeting.

George What can it read and what can it change. Who approves each action and what do they see. What's logged, for how long, can I read it. How do I stop it and what do we do then. Who's the Clinical Safety Officer and where's the hazard log. What happens to the data. And who is accountable when it's wrong.

Emma And the answer to that last one?

George It's never the agent. The Code still applies. Clause 19 asks you to reduce mistakes and allow for human factors and system failures. Decisions about people stay with people. If your account is the agent did it, nobody will accept it, and they shouldn't.

The written material

Approval before anything changes

The single most useful control is simple to state. A person approves before the agent does anything that changes something outside its own workings: sending a message, booking, ordering, discharging, altering a record, changing a rota. Reading, drafting and preparing can run freely. Changing waits for a human.

The joint guidance asks for human approval of high-impact actions and for continuous oversight rather than a check at set-up. An approval has to be designed, though, or it becomes theatre.

A real review versus a rubber stamp

An approval is only a control if the reviewer can tell what they are approving. One button that approves fourteen discharges, with no way to see what each will do, is consent without understanding.

A meaningful approval shows the specific action, in plain words, with the information needed to judge it. It gives the reviewer time. It gives them standing to refuse without penalty, and it records refusals as readily as approvals. If the refusal rate is zero, treat that as a warning, not a success: nobody is really looking.

Least privilege, and a separate identity

Give an agent only the access the task needs, for as long as it needs it. Start read-only. Add the ability to change something only where there is a reason, and for the narrowest set of records. The guidance warns specifically against broad or unrestricted access, especially to sensitive data and critical systems, and against permissions granted at set-up that nobody reviews.

An agent should act under its own identity, not a colleague's login. Then the log shows what the agent did, access can be withdrawn without disturbing a person, and nobody is blamed for something software did in their name.

Logs, and the test of why

After any incident the question will be: why did it do that? You should be able to answer within the hour. That needs a record of what the agent was asked, what it read, what it decided at each step and what it changed, kept for long enough to be useful and readable by the people who will need it.

Ask for the log in the demonstration, before purchase. If the supplier cannot show you one for the example they have just run, you have learned something important.

Add a stop control and a fallback. You need a way to pause the agent at once, and a tested manual process for when it is stopped or down. A team that has forgotten how to do the task by hand has no fallback.

Clinical safety, reporting, and the questions to ask

Three existing frameworks apply and you should know their names. NHS clinical risk management standards DCB0129, for manufacturers, and DCB0160, for organisations deploying a system, require a Clinical Safety Officer, a hazard log and a safety case. A data protection impact assessment is required where personal data is processed in a way likely to be high risk. And if the software is intended for a medical purpose it may be regulated as a medical device by the MHRA.

Report problems and near misses through your normal patient safety route, which in England means the national Learn from Patient Safety Events service. An agent that nearly did something wrong is the best evidence you will get that a control needs strengthening.

  • What can it read, and what can it change?
  • Who approves each action, and what do they see?
  • What is logged, for how long, and can I read it?
  • How do I stop it, and what do we do when it is stopped?
  • Who is the Clinical Safety Officer, and where is the hazard log?
  • What happens to the data, and is there a data protection impact assessment?
  • Who is accountable when it gets something wrong?

Knowledge check

The knowledge check and your certificate need a free account, so that your progress and results can be saved as evidence.

Create a free account Sign in

The learning itself stays free and open. You are reading all of it right now without an account.