Clinical patterns

Proxy & carer access

A second person watching someone else's data from somewhere else, unable to verify it, seeing it late, and often unable to do anything about it. The parent of a teenager with type 1 diabetes is the clearest case, and almost every design decision here follows from the delay.

Stable · v1.0 SteadyLine WCAG 2.2 AA IEC 62366-1

Overview

Every other role in this system either holds the data or holds the patient. A follower holds neither. They see numbers produced by a device they do not control, about a body they cannot observe, delivered over a network that may be minutes behind — and they experience the consequences of all three as though they were watching in real time.

This creates a failure mode nothing else here has: acting confidently on information that has already stopped being true. A parent seeing 3.2 mmol/L and phoning urgently may be reacting to a reading their child corrected eight minutes ago.

Scope of this page

This is about the interface of proxy access — what a follower sees, how late it is, what they may do, and what the subject knows. It is deliberately not about consent law, capacity assessment or data-sharing agreements, which are jurisdiction-specific and outside what this system can responsibly specify. See Contributing.

Distance is delay

The follower's view is always older than the subject's. Age and completeness are stated before any value.

Watching is not treating

A follower can see and can escalate to a human. They cannot dose, silence, or change a setting.

Nothing hidden from the subject

The person being watched can see who is watching, what they see, and what they have done — and can end it.

Anatomy

The follower's view leads with its own age

Ama's glucose

your view is 6 min behind
4.1mmol/L
falling · reading taken 03:16, received 03:22
Ama's device may have acted since. You are seeing what it knew at 03:16.
Ama's device alarmed at 03:17 and she responded at 03:19
You were alerted at 03:22 because the alarm had not been answered when the alert was sent.
You can see and be alerted. You cannot change Ama's device.

The alert that woke the follower is reconciled against what actually happened. Without this, the parent phones at 03:23 about a problem resolved four minutes earlier.

PartRule
Lag In the header, before any value. Both when the reading was taken and when it arrived — the difference between them is the follower's exposure.
Subject Named on every screen. A follower may follow more than one person, and this is a wrong-patient surface — see Patient header.
Reconciliation What has happened since the alert was sent. The single most valuable element on the page, and the one almost always missing.
Capability statement What the follower can and cannot do, on the surface rather than in a help article.
Not monitoring Propagated. A follower seeing nothing must know whether that is silence or absence — see Unattended operation.
Escalation route What to actually do — contact the person, contact emergency services — rather than a screen that only worries them.

Designing around the delay

The rule that carries the risk

A follower's screen states how old its data is, and how complete, before it states any value. A number presented as current when it is six minutes old invites action that is calibrated to the wrong moment — and unlike the subject, the follower has no way to look at the person and check.

What a follower may do

MayMay not
See current and historical values, with their lag Give or change a dose
Receive alerts, reconciled Silence or dismiss the subject's alarm
See device state — sensor, battery, mode Change a setting, limit or mode
Contact the subject through the app Act in the subject's name in any way the subject cannot see
Escalate to emergency services with the data to hand Conceal that they viewed or acted

The asymmetry is deliberate and it is not about trust. A follower is acting on delayed, unverifiable data about a body they cannot see; every action they take is taken with less information than the subject has. Alarm silencing is the sharpest case — a parent dismissing an alarm from another city removes the signal from the person who can actually do something about it.

The one exception worth designing

Where a follower is genuinely the responsible carer for someone who cannot self-manage — a young child, an adult without capacity — the roles change and so does the interface. That device has a different specified user, not a more permissive follower mode. Treating it as a settings flag on the same product is how a parent-of-a-toddler capability ends up available on a teenager's account.

Nothing hidden from the subject

A person being monitored is entitled to know they are being monitored, by whom, and what that person can see. This is a design requirement independent of whatever consent was recorded when the account was set up — because arrangements outlive the circumstances that created them.

The subject's view of their own followers
Who can see your data 2 people
  • Kwame Boateng parent
    Sees your glucose, trend and device state · alerted for lows · last looked 03:22
  • Diabetes team, St Bride's clinical
    Sees summaries for your appointments · not alerted · last looked 4 Aug

Who, what they see, whether they are alerted, and when they last looked — plus the ability to end it. "Last looked" is the element that makes the arrangement real rather than nominal.

States

StateRendering
Following, currentLag in the header, value, trend, device state.
Following, laggingLag becomes the headline once it exceeds a stated threshold; the value is demoted.
Subject not monitoringPropagated with its cause. Distinct from a follower connection problem, which is a different fact.
Follower disconnectedStated to the subject as well — "nobody is receiving your alerts".
Alert supersededReconciled: what the alert was, and what has happened since.
Sharing endedConfirmed to both parties. A follower who silently stops receiving data may believe no news is good news.

Do's and don'ts

Do

Your view is 6 min behind. 4.1 mmol/L, falling · taken 03:16, received 03:22

Lag before value, and both timestamps. The follower can calibrate how much to trust what they are seeing.

Don't

4.1 mmol/L

Presented as live. A parent acts immediately on a number that stopped being true before it arrived.

Do

Ama's device alarmed at 03:17 and she responded at 03:19. You were alerted at 03:22.

The alert reconciled against reality. This is the difference between an informed follower and a frightened one.

Don't

LOW GLUCOSE — Ama

A four-minute-old emergency with no resolution state. The phone call it triggers wakes someone who already dealt with it.

Do

You can see and be alerted. You cannot change Ama's device. If you are worried, call her — or call for help.

Capability stated on the surface, with what to do instead. No time wasted looking for a control that does not exist.

Don't

A remote carer silencing the alarm of the person who can actually act, on data six minutes old.

Do

Kwame Boateng · sees your glucose, trend and device state · alerted for lows · last looked 03:22 · Stop sharing

The subject knows who is watching, what they see, and when they last did — and can end it.

Don't

Sharing: On

A toggle with no names, no scope and no history. The subject cannot tell who is watching or what they can see.

Accessibility

Outcomes of use

What this contributes to, in the terms of Usability & context of use. These are attributes believed to contribute to an outcome; the outcome itself is settled by observing real use in a specified context, not by this page.

Clinical safety notes

Risk controls carried by this pattern

Trace these in your risk file (ISO 14971) and usability engineering file (IEC 62366-1).

NotJustAnyMed.Tech Design System · Proxy & carer access · v1.0 · draft for review
Reference applications named in this system are fictional; all people, values and timings shown are fabricated and illustrative.