Proposed system · Digital health · Federated trust · 2026

Citadel Immunization Passport

A proposed life-course immunisation record and minimum-disclosure credential service, designed around jurisdiction-owned FHIR records, clinician-governed decisions and bounded AI assistance.

Target architecture · Sponsor, clinical, regulatory and security approval required

Concept interface for Citadel showing a citizen immunisation timeline beside a clinician reconciliation workspace

Interactive system architecture / Citadel AIR

One governed record.
Four safe journeys.

Explore the proposed service in plain language or inspect the technical boundary behind every step.

Follow a service journeySource evidence → reviewed history
Clinical authoritySigned rules + authorised clinicianAI authorityProposal and explanation onlyPerson dataHeld inside the jurisdictionShared trustKeys, policy and status—not records

What it means / Authorised human review

Authorised human review

A trained reviewer compares the source with the proposal and accepts, corrects, rejects or marks it uncertain.

Proposed architecture visualisation. It processes no health data, makes no clinical decision and is not evidence of validation, regulatory approval or production deployment.

Build notes / reference implementation

Start with the safe core.
Add complexity only with evidence.

The first implementable slice is one jurisdiction, one accountable clinical owner, one schedule, one document class and language set, one registry integration and one care-continuity proof.

01
Experience and accessCitizen channels, clinical reconciliation and an offline verifier.

Build accessible React/Next.js channels with a server-rendered fallback, assisted service, paper QR and explicit guardianship. Place a standards-based gateway in front of every protected action.

Reference stackNext.js · OIDC · SMART-on-FHIR · paper/QR · offline verifier

02
Authoritative clinical coreA jurisdiction-owned FHIR record and deterministic schedule engine.

Start as a modular clinical service. Keep accepted vaccination events, source documents, provenance, consent, terminology and signed policy packages inside the local authority boundary.

Reference stackHAPI FHIR JPA · PostgreSQL · FHIR R4 · CQL/PlanDefinition/Library

03
Isolated AI evidence enclaveReviewable extraction and explanation, separated from clinical authority.

Use quarantined workers for OCR, terminology retrieval, conflict suggestions and grounded explanation. The model receives minimum context and returns typed candidates with source spans; it gets no clinical write, identity-merge or signing tool.

Reference stackPython/FastAPI workers · constrained model gateway · approved retrieval index

04
Federated trust and operationsSigned issuer trust first; a shared ledger only if governance proves it necessary.

Keep person data in each jurisdiction. Exchange FHIR summaries or small credentials through signed issuer directories and status material. Add permissioned QBFT only when independent authorities need joint write control—and never place personal data on it.

Reference stackOID4VCI/OID4VP · W3C VC 2.0 · KMS/HSM · signed status lists · optional Besu/QBFT

Release evidence before real-world use

  • Clinical safety case and deterministic rule traceability
  • DPIA, rights testing and minimum-disclosure verification
  • Independent security, key-recovery and supply-chain evidence
  • AI subgroup evaluation, prompt-injection testing and rollback
  • FHIR and credential interoperability across independent implementations
  • Accessible paper, assisted and offline journeys at parity

One record, governed locally

Citadel AIR is a proposed life-course immunisation record service for people whose evidence may be fragmented across clinics, documents and jurisdictions. The baseline design keeps each jurisdiction responsible for its own clinical record, policy and approvals instead of creating a global patient database or universal identifier.

People see a joined-up timeline and can share a minimum-disclosure proof. Clinicians see provenance, confidence and conflicts before accepting evidence into the authoritative record. A missing record is treated as missing evidence, not proof that a vaccination did not happen.

From fragmented evidence to a reviewed history

The service can accept records from connected providers and uploaded evidence. Optical character recognition and structured extraction may propose candidate events, while deterministic validation checks dates, products, doses and provenance. Low-confidence or conflicting evidence is routed to a qualified reviewer.

Only reviewed evidence becomes part of the jurisdiction-owned FHIR record. The person can see source and status, request a correction and continue through assisted, paper or offline routes where a digital journey is not appropriate.

Deterministic schedule, bounded AI

Clinical schedule decisions are produced by governed rules represented through FHIR PlanDefinition, Library and CQL resources. Generative AI may help extract evidence, suggest reconciliation matches and explain an already-grounded result, but it does not decide eligibility, change a schedule or write directly to the clinical record.

Every AI suggestion carries provenance, confidence and a route to human review. Prompt, model and policy versions form part of the operational evidence needed to investigate a result.

Federated trust without a global database

Approved issuers can create signed, minimum-disclosure credentials using OpenID for Verifiable Credential flows and W3C Verifiable Credentials. Verifiers check signatures, status and policy without receiving an entire clinical history.

Public-key infrastructure is the default trust layer. A permissioned Besu network with QBFT is an optional governance pattern only where independently accountable authorities need shared control of trust lists, policy versions or credential status. Personal health data, documents and clinical events remain off-chain and local.

Designed to remain correctable and inclusive

Personal clinical records must remain correctable even when audit evidence is retained. The design separates a person’s editable health record from tamper-evident operational logs, so accountability does not become permanent clinical error.

Accessibility, proxy access, consent, translation, assisted service and paper or offline verification are release requirements rather than later enhancements. No automated path should turn lack of data, language or device access into a clinical or administrative penalty.

Build from evidence, not assumptions

The first delivery slice should be intentionally narrow: one jurisdiction, one clinical owner, one governed schedule, one evidence type and language set, one provider integration and one minimum-disclosure proof. That slice should be assessed through clinical safety, data-protection, security, AI evaluation, FHIR interoperability, credential interoperability and service-access evidence.

This page is a target architecture derived from the supplied solution brief. It is not clinical validation, regulatory approval, a production deployment or a claim that the proposed components are already integrated.

Return to the indexAll projects