Skip to content

Trust

Trust is built into the work.

Koltra is designed for operations where permissions, data handling, human judgment, and accountability are part of the workflow.

Illustrative operating record

Record · Riverside Family Medicine · 09/02retained 30 days
08:12Move appointment · Elm Streetsame-week ruleFinished
08:13Handoff · on-call nurseaccepted 08:26Handed off
10:47Referral status · Harbor Viewread onlyFinished
12:03Chest pain mentioned · Northgatenurse · 12:04Handed off
13:55New patient · Northgateintake at deskHeld

The system should know what it may do, leave evidence of what it did, and govern how it changes.

The standard the system is built to, at operation and deployment scope. Stated as obligations, not current capability.

Operation scope

What must hold while the work runs.

Scoped accessIdentity, permissions, and approved actions follow the workflow rather than relying on broad system access.
Bounded dataThe operation loads the context it needs, with retention and deletion requirements defined for the deployment. Our policy: Customer conversations are not used to train models unless you explicitly opt in.
Attributable actionsTool calls, handoffs, outcomes, and failures remain attached to the run that produced them.
Human authorityJudgment, exceptions, and approvals stay with the people responsible for them.

Deployment scope

What must hold as the system changes.

Configuration inheritanceDeployment configuration narrows what a product may do for one customer. It never silently widens a boundary the product declared.
Tenant separationCustomers and workspaces stay strictly separated: data, numbers, knowledge, permissions, and records.
Learning boundaryWhat a deployment learns stays local to it. Promotion into shared capability is an explicit, recorded decision.
Governed changeChanges are tested against the evidence, versioned, released under declared authority, and reversible.

Accountability has a data model.

The operating standard is written as obligations rather than benefits, because a benefit cannot be checked. Every Koltra workflow is built to leave one record per run, with a name on it: what it was for, the steps and tool calls it took, where a person entered, how it ended, and what it cost.

That record is what an operations or security review can hold onto. A failed run leaves the same quality of evidence as a completed one, and the failure itself is part of the record: where the run stopped, and what it was waiting on.

Healthcare boundary

HIPAA requirements shape the system from the start.

Koltra has executed business associate agreements with major infrastructure vendors expected to handle protected health information, including AWS. Healthcare product work and the shared platform are being built for HIPAA-governed deployments. PHI enters production only after the customer business associate agreement, deployment data flow, relevant providers, safeguards, and customer controls are approved.

Where the human boundary sits.

Each product or explored context needs its own explicit human boundary.

Healthcare

Clinical judgment stays with care teams. The product carries scheduling, information collection, and coordination, and hands off with the state intact.

Healthcare
Managed IT

Diagnosis stays with the technician. The exploratory MSP model considers intake, context assembly, ticket enrichment, routing and customer communication; it is not an announced product.

Managed IT
Every product

Exceptions, approvals, and anything ambiguous stop the run and bring a person in, with the conversation and context attached.

working state

A person arrives with the state, not with a transcript.

What was said. Useful to read; insufficient to continue the work. A person arrives with the working state and the reason for the handoff.

stateworking state
Permitted context assembled for the declared job
01
Declared request and policy boundary recorded
02
Approved system and next action identified
03
Named person receives the current state and reason for handoff
04

Authorized person · receives the working state

Common questions.

What data does a Koltra product access?The context the workflow needs and no more. Scoped identity, permissions, and approved actions follow the workflow, and retention and deletion requirements are defined per deployment.
How does Koltra approach HIPAA?Major infrastructure vendors expected to handle protected health information, including AWS, are covered by executed business associate agreements. PHI enters production only after the customer business associate agreement, deployment data flow, relevant providers, safeguards, and customer controls are approved.
Can a deployment be inspected?Inspection is the point of the record. Completion, failure, latency, quality, and cost stay visible per run, never blended into an average.

Have a security or compliance question?

Tell us what the workflow handles and which requirements govern the deployment.