MODULE M16 · AI ON REQUEST

Operational knowledge & AI assistance

On request, private AI supports searches, summaries and drafts with visible sources. Processing takes place on Oronela's own servers in Switzerland, without third-party AI.

On request, private AI helps with finding, summarising and preparing. It runs exclusively on Oronela servers in Switzerland; people review and decide.

  • Activate optional AI
  • Find knowledge with sources
  • Review suggestion professionally
Features and responsibility
Knowledge, when you want it.3D animation
In finalisation

The 18 modules form the feature catalogue; they are not a mandatory selection. You decide which areas your institution uses. AI is activated only on request. Clinical dependencies and finalisation are described on the module pages.

01 / IN DAILY USE

Tasks and responsibility.

You choose this module according to your institution's needs. The interfaces described are configured for the areas you select. AI support is available exclusively on request and processes data on Oronela's own servers in Switzerland.

Private assistance supports searching, summarising, dictating and preparing permitted professional actions. Internal SOPs and curated references have a source, validity and professional approval. Each person works in their own chat and agent area with their actual current permissions.

Resident-related assistance connects structured longitudinal data and original passages with traceable source coverage. The response distinguishes documented findings, operational knowledge, medical references and model inferences. Critical decisions are checked within the responsible professional process; an AI suggestion does not automatically become a clinical fact.

Information maintained by the module
AreaContent and meaning
Knowledge revisionSource, owner, approval, validity, language, permission, index version and withdrawal.
Assistance requestUser, purpose, resident context, sources actually used, model version, suggestion and decision.
Case overview tied to sourcesReviewed period, original passages, comparable episodes, current foundations and explicitly identified gaps.

02 / MODULE FUNCTIONAL SCOPE

What this module covers.

5 functional areas connect this module's tasks. The following sections explain their content, processing and responsibilities.

Knowledge ingestion, approvals and protected search

Approve operational knowledge once and find it again at the point of work with a valid source.

SOPs, manuals, forms and guidelines carry an owner, provenance, document and language revision, validity, approvers, access scope, content hash and successor. Document revision and index revision are separate.

Uploads, OCR, chunking and embeddings run privately with limited formats and resources and controlled quarantine. Tenants, source ACLs and permission changes are considered in the search and vector index.

ACL checks take place before retrieval to limit candidates and after retrieval immediately before context or answer approval using current permissions; search results, snippets, quotes and caches must not bypass protection.

Only knowledge revisions approved for the purpose and still valid may appear as currently applicable. Historical searches are explicitly labelled and separately authorised; withdrawn knowledge is promptly removed from active contexts.

Content from documents, OCR and external sources is treated as data. Embedded instructions to change system prompts, permissions, data or tools must not acquire authority.

Multilingual search finds permitted content across languages but shows the original language, actual source and translation status. Automatic translation does not create new professional approval.

The scope additionally includes curated medical references with licence, edition, freshness, clinical approval and withdrawal, as well as temporal and structured search. The complete permitted relevant source set must be reachable; a limited set of semantic matches must not appear as a complete history.

Responsibility
Knowledge authors work within their areas, designated professionals approve, and users require source permissions; the AI service account receives no cross-tenant reading authority.
Automation & AI
Metadata, duplicate and expiry suggestions and local semantic search simplify maintenance. The author or specialist team confirms validity and approval; linguistic similarity is not proof of accuracy. AI features require activation at your request. Processing remains on Oronela's own servers in Switzerland.

Local search, summary, dictation and drafting

Reduce writing and search effort while keeping statements, original data and responsibility traceable.

Assistance offers knowledge-based questions and answers, summaries of permitted record or process sections, dictation editing and draft tasks with a visible source or suggestion status. Access to resident context is explicit in each case.

Every request binds tenant, user and purpose, current policy, model, tokenizer and runtime revision, quantisation, parameters, prompt template and source revisions used; the previous resident's context is never carried over unintentionally.

The exact necessary inputs, supplied context, output and approval decision are retained in encrypted form under the protected evidence concept; operational logs do not contain unrestricted health data. Retention and deletion follow the approved concept.

Missing sources, contradictions, model or GPU errors, cancellation and timeouts have clear states. No invented source evidence, no silent switch to public AI and no automatic saving of a generated observation as fact.

Dictation retains the required original reference under control until defined processing or deletion; speaker and resident assignment must be checked before professional adoption. Units, numbers and negations must not be “corrected” unnoticed.

The response language follows the user's language; original clinical entries remain unchanged. Translations or simplified explanations require the specified professional validation before binding use.

Responsibility
Professional and operational users act according to context and purpose, professional reviewers according to the target action, and model operations receives only the necessary technical view. Auditors receive separately authorised evidence access.
Automation & AI
Local Qwen assistance creates drafts; recording dictation can start the appropriate draft process. A person confirms the actual content; decisions with a significant clinical impact remain outside an unapproved intended purpose. AI features require activation at your request. Processing remains on Oronela's own servers in Switzerland.

Safe AI tools, approvals and evaluation

Move from a request in natural language to verifiable, prefilled professional actions and approve model changes under control.

A versioned tool catalogue defines the permitted domain command, schema, purpose, permissions, risk class, human confirmation, side effects, idempotency and preview. Model text cannot trigger unrestricted SQL, shell commands or arbitrary network access.

Suggestion, user confirmation and actual execution are separate. Authorisation, competence, source revisions and domain rules are checked again at execution; confirmation is bound to specific parameters and revisions.

Permitted low-risk automation runs only through a pre-approved deterministic workflow rule with a narrow scope. Medication or fasting orders, role assignments, exceptions to shift rules and audit changes are not decided autonomously by the language model.

Every model, prompt, retrieval and tool revision has a purpose, evaluation case set, representative approved languages, attack and error classes, independent assessment and release decision. Model weights do not have conventional code coverage.

A failed evaluation blocks the new revision; withdrawing or switching off assistance leaves the domain core, audit and permissions intact. Domain commands already executed are not undone by rolling back a model.

Users can correct an accepted draft; feedback for improvement is purpose-limited. There is no silent training with resident or employee data or export to public providers.

PAI-002/004/009/012–For personal agents: the scope of approval and delegation is limited and revocable. Current user permissions are the upper limit, not a blanket instruction for every technically possible action. Clinical suggestions require their approved purpose; a question alone documents neither medication administration nor a new prescription.

The clinical case function is activated by the approved function profile. Free text, model classification or switching to a general chat mode must not activate unapproved resident-specific therapy assistance.

Responsibility
Professional users confirm only their own permitted actions; independent clinical and security leads approve tools and models. System and GPU administrators do not automatically gain clinical approval authority.
Automation & AI
Examples: prefill a task draft, permitted appointment request or annual leave preference, each with the original request, parameters and confirmation. Appointment confirmation and leave approval remain with the responsible module and its rules. AI features require activation at your request. Processing remains on Oronela's own servers in Switzerland.

Personal AI chat and agent within the user context

Every employee receives their own assistance area, whose capabilities match their current permissions.

Conversations and requests are maintained separately for each person. Care, kitchen, HR and administration access their respective permitted sources and tools. A technical AI account with broader access does not extend the requesting person's permissions.

Each task binds the user, institution, purpose and visible domain context. With multiple resident windows, sources, drafts and subsequent tool responses remain assigned to the correct resident. Transfer to another case requires explicit review.

Stored chats, personal assistant preferences and derived reminders are protected and managed according to approved retention periods. Colleagues or HR receive no blanket access to personal conversations. A chat does not silently become the sole clinical record or a training dataset.

Revoked permissions or a context change affect ongoing searches, streaming, saved answers and memories. An old conversation must not provide a back door into a record that is now restricted. Permissions and sources are checked again before output and every tool action.

The agent can, for example, prepare a leave preference, a permitted appointment request or a draft task. Preview, confirmation and execution remain separate steps. A question alone does not authorise dispatch, medication administration, a signature or a binding assignment.

Search and tool steps are bounded and can be resumed in a controlled way. Errors in the local model or GPU are visible; there is no silent switch to a public AI provider. The manual domain function remains available.

Responsibility
Each person uses their own assistant within their current scope of tasks. Critical approvals remain with the responsible professionals.
Automation & AI
The agent works through the same professional commands and checks as the user interface. Approved sources, proposal, decision and effect remain traceable. AI features require activation at your request. Processing remains on Oronela's own servers in Switzerland.
Connection & offline use
Private inference requires the local services. Without an available connection, no binding agent action is confirmed.

Source-bound progress and case assistance

The assistant compiles the documented history and makes sources, gaps and limits of comparison visible.

Search combines structured observations, actual care delivered, free text, orders and authorised documents. Time-based queries and complete page traversal supplement semantic search. A few similar results do not justify claiming that the entire record has been reviewed.

The reviewed period, sources reached and missing areas are reported as coverage. An interrupted import, missing access or cancelled search is explained as a gap. “Not documented” remains separate from an explicitly negative clinical finding.

The presentation distinguishes the current record, earlier comparable episodes, resident-specific foundations valid today, clinical interpretation and next permitted steps. Earlier interventions and documented effects name the date, source and revision; missing evidence of effects remains identifiable.

Operational knowledge, curated medical reference sources, resident records and knowledge learned by the model are labelled separately. Each statement cites the source that actually supports it. General model knowledge is neither a current guideline nor a new medical order.

A medication used earlier or a history documented at the time does not produce a treatment decision today. Missing current observations lead to queries or a limited response. The approved urgent escalation route must not wait for a lengthy historical analysis.

Clinical assistance functions are activated only for an explicitly approved intended purpose. Source, context and output checks also apply before a professionally usable presentation. Unchecked streaming output is not presented as an approved treatment recommendation.

Responsibility
Authorised professionals review the source-bound compilation. Diagnostics, therapy and clinical approvals remain in their respective professional processes.
Automation & AI
AI helps locate and bring together evidenced information. It does not invent observations, confirm effects or issue an independent prescription. AI features require activation at your request. Processing remains on Oronela's own servers in Switzerland.
Connection & offline use
Analysis requires current permitted sources and the private model operation. With incomplete data, the statement is explicitly limited.

03 / PRACTICAL EXAMPLE

A professional searches for earlier comparable episodes

  1. They select the resident and the approved purpose of the request.

  2. The assistant searches permitted structured events and documents within the relevant period.

  3. The overview separately shows original passages, interventions at the time, documented effects and currently valid foundations.

  4. The professional reviews the sources and decides on a permitted query or action in the authoritative module.

A missing entry does not prove a negative finding. Earlier therapy and model knowledge do not create a new prescription; missing sources visibly limit the answer.

SYSTEM WORKFLOW / Typical workflow

Typical workflow

  1. 01

    The question is asked in the current permissions context; only permitted, valid sources are used.

  2. 02

    Our own AI infrastructure creates a response or draft with sources and recognisable uncertainty.

  3. 03

    The person reviews the suggestion and personally confirms each action with professional consequences.

View the domain workflow in 3D
M16 WORKFLOWResident · Care · Doctor
Illustrative workflow model
01Permitted sources
INFORMATIONPermitted professional context
02Private assistance
Question · Permissions · Valid sourcesReady for handover

The question is asked in the current permissions context; only permitted, valid sources are used.

Our own AI processes permitted sources; humans confirm actions with professional effect.
What information is passed on?
  1. 01 → 02
    Permitted professional context

    Question · Permissions · Valid sources

  2. 02 → 03
    AI draft with sources

    Suggestion · Evidence · Uncertainty

DATA EXCHANGE / MODULE CONNECTIONS

Interfaces in context.

M16 is at the centre. The connections show which modules can provide or receive information when selected and configured for your institution. Choose a connection to see its data scope.

M16 CONNECTIONSExchange across modules
Versioned module contracts
M16This module
INFORMATIONConfirmed domain draft
M02Approved domain context
Permitted record information and confirmed drafts.Ready for handover

Permitted record information and confirmed drafts. A draft becomes professionally effective only through human confirmation.

The connections show domain data relationships. Specific API contracts and partner connections are versioned and approved separately.
Exchange
Permitted record information and confirmed drafts.
Professional rule
A draft takes professional effect only through human confirmation.
Exchange
Permitted personnel and planning information.
Professional rule
The assistance uses the same authorised professional commands.

The module requirements define the exchange of domain information. Each module manages its own data; other modules use approved, versioned contracts. Permissions, tenant, revision and acknowledgement are preserved throughout.

READ MORE / Connected modules

Linked modules

SOURCES & DEVELOPMENT STATUS

Functional scope. Current status.

This module, selectable according to need, is part of Oronela in finalisation. Functions, responsibilities and interfaces form the fixed scope. Finalisation combines professional acceptance reviews with feedback from care institutions: real needs determine the final improvements.

Comparison with the module requirements, implementation plan and current Oronela system codebase: 1 October 2026. Product requirements M16-01–M16-05 · M16-A–E. The following areas are explained on this page:

Sources in the product repository
  • Umsetzungsplan/Module/M16_KI_und_Wissen.md
  • Umsetzungsplan/Erweiterungen/10_Persoenlicher_KI_Agent_und_Bewohnerwissen.md
Next moduleM17 · Integration & data exchange