Proxy & carer access
A second person watching someone else's data from somewhere else, unable to verify it, seeing it late, and often unable to do anything about it. The parent of a teenager with type 1 diabetes is the clearest case, and almost every design decision here follows from the delay.
Overview
Every other role in this system either holds the data or holds the patient. A follower holds neither. They see numbers produced by a device they do not control, about a body they cannot observe, delivered over a network that may be minutes behind — and they experience the consequences of all three as though they were watching in real time.
This creates a failure mode nothing else here has: acting confidently on information that has already stopped being true. A parent seeing 3.2 mmol/L and phoning urgently may be reacting to a reading their child corrected eight minutes ago.
This is about the interface of proxy access — what a follower sees, how late it is, what they may do, and what the subject knows. It is deliberately not about consent law, capacity assessment or data-sharing agreements, which are jurisdiction-specific and outside what this system can responsibly specify. See Contributing.
Distance is delay
The follower's view is always older than the subject's. Age and completeness are stated before any value.
Watching is not treating
A follower can see and can escalate to a human. They cannot dose, silence, or change a setting.
Nothing hidden from the subject
The person being watched can see who is watching, what they see, and what they have done — and can end it.
Anatomy
Ama's glucose
The alert that woke the follower is reconciled against what actually happened. Without this, the parent phones at 03:23 about a problem resolved four minutes earlier.
| Part | Rule |
|---|---|
| Lag | In the header, before any value. Both when the reading was taken and when it arrived — the difference between them is the follower's exposure. |
| Subject | Named on every screen. A follower may follow more than one person, and this is a wrong-patient surface — see Patient header. |
| Reconciliation | What has happened since the alert was sent. The single most valuable element on the page, and the one almost always missing. |
| Capability statement | What the follower can and cannot do, on the surface rather than in a help article. |
| Not monitoring | Propagated. A follower seeing nothing must know whether that is silence or absence — see Unattended operation. |
| Escalation route | What to actually do — contact the person, contact emergency services — rather than a screen that only worries them. |
Designing around the delay
A follower's screen states how old its data is, and how complete, before it states any value. A number presented as current when it is six minutes old invites action that is calibrated to the wrong moment — and unlike the subject, the follower has no way to look at the person and check.
- Two timestamps, always. When it was measured and when it arrived. One number conceals the lag entirely.
- Alerts are reconciled on arrival. "Alarmed at 03:17, responded at 03:19" turns a frightening notification into information.
- Never alert a follower before the subject. A parent learning of a low before their child has been told is both alarming and useless.
- The follower's delay is the escalation delay too. If the follower is the escalation path — see Unattended operation — the lag is part of the safety argument, and must be stated at setup rather than discovered.
- Loss of the follower's connection is stated on both sides. The subject must know when nobody is watching; the follower must know when they are seeing nothing rather than nothing happening.
What a follower may do
| May | May not |
|---|---|
| See current and historical values, with their lag | Give or change a dose |
| Receive alerts, reconciled | Silence or dismiss the subject's alarm |
| See device state — sensor, battery, mode | Change a setting, limit or mode |
| Contact the subject through the app | Act in the subject's name in any way the subject cannot see |
| Escalate to emergency services with the data to hand | Conceal that they viewed or acted |
The asymmetry is deliberate and it is not about trust. A follower is acting on delayed, unverifiable data about a body they cannot see; every action they take is taken with less information than the subject has. Alarm silencing is the sharpest case — a parent dismissing an alarm from another city removes the signal from the person who can actually do something about it.
Where a follower is genuinely the responsible carer for someone who cannot self-manage — a young child, an adult without capacity — the roles change and so does the interface. That device has a different specified user, not a more permissive follower mode. Treating it as a settings flag on the same product is how a parent-of-a-toddler capability ends up available on a teenager's account.
Nothing hidden from the subject
A person being monitored is entitled to know they are being monitored, by whom, and what that person can see. This is a design requirement independent of whatever consent was recorded when the account was set up — because arrangements outlive the circumstances that created them.
-
Kwame Boateng parentSees your glucose, trend and device state · alerted for lows · last looked 03:22
-
Diabetes team, St Bride's clinicalSees summaries for your appointments · not alerted · last looked 4 Aug
Who, what they see, whether they are alerted, and when they last looked — plus the ability to end it. "Last looked" is the element that makes the arrangement real rather than nominal.
- The list of followers is always reachable from the subject's device, never only from a web account they do not use.
- What each follower sees is stated in plain terms, not as permission names.
- Access is endable by the subject in one action, and ending it is not obstructed or delayed. Where the subject cannot end it — a child's device — that is stated plainly rather than hidden.
- Adding a follower is an act by the subject, confirmed on the subject's device. Never provisioned only from the follower's side.
- Access has a review point. Sharing set up during an illness or a school year should surface for confirmation rather than persisting indefinitely by default.
- Follower actions appear in the subject's own record — see Clinician override on attribution.
States
| State | Rendering |
|---|---|
| Following, current | Lag in the header, value, trend, device state. |
| Following, lagging | Lag becomes the headline once it exceeds a stated threshold; the value is demoted. |
| Subject not monitoring | Propagated with its cause. Distinct from a follower connection problem, which is a different fact. |
| Follower disconnected | Stated to the subject as well — "nobody is receiving your alerts". |
| Alert superseded | Reconciled: what the alert was, and what has happened since. |
| Sharing ended | Confirmed to both parties. A follower who silently stops receiving data may believe no news is good news. |
Do's and don'ts
Your view is 6 min behind. 4.1 mmol/L, falling · taken 03:16, received 03:22
Lag before value, and both timestamps. The follower can calibrate how much to trust what they are seeing.
4.1 mmol/L ↓
Presented as live. A parent acts immediately on a number that stopped being true before it arrived.
Ama's device alarmed at 03:17 and she responded at 03:19. You were alerted at 03:22.
The alert reconciled against reality. This is the difference between an informed follower and a frightened one.
LOW GLUCOSE — Ama
A four-minute-old emergency with no resolution state. The phone call it triggers wakes someone who already dealt with it.
You can see and be alerted. You cannot change Ama's device. If you are worried, call her — or call for help.
Capability stated on the surface, with what to do instead. No time wasted looking for a control that does not exist.
A remote carer silencing the alarm of the person who can actually act, on data six minutes old.
Kwame Boateng · sees your glucose, trend and device state · alerted for lows · last looked 03:22 · Stop sharing
The subject knows who is watching, what they see, and when they last did — and can end it.
Sharing: On
A toggle with no names, no scope and no history. The subject cannot tell who is watching or what they can see.
Accessibility
- Lag is in the accessible name of the value — "4.1 millimoles per litre, your view is 6 minutes behind". A follower using a screen reader must not receive the number without its age.
- The subject is named in every alert. A follower may follow more than one person, and an alert announcing only a value is a wrong-patient hazard.
- Reconciliation is text, not a struck-through or faded alert.
- Follower alerts are assertive; lag notices are polite.
- The follower list uses real list semantics so its size is announced, with each follower's scope in the item's accessible name.
- "Stop sharing" is a plainly labelled button, never a toggle whose state is conveyed by position or colour alone.
- Targets ≥ 44 px on the alert path — this interface is used on a phone, in the dark, by someone who has just been woken.
- No timed dismissal (SC 2.2.1), and no flashing (SC 2.3.1).
Outcomes of use
What this contributes to, in the terms of Usability & context of use. These are attributes believed to contribute to an outcome; the outcome itself is settled by observing real use in a specified context, not by this page.
- Effectiveness — the follower's action matches the subject's actual current state, and escalation happens when it is still needed. Both over-reaction and missed escalation are failures of the same design property.
- Efficiency — a follower who can tell in one glance whether to act. The expendable resource is the subject's autonomy: every unnecessary phone call spends it.
- Satisfaction — for the follower, sleep and reduced anxiety. For the subject, not feeling surveilled. These pull against each other, and the visibility rules are how the tension is held rather than resolved in the watcher's favour.
Clinical safety notes
Trace these in your risk file (ISO 14971) and usability engineering file (IEC 62366-1).
- Lag stated before any value, with both timestamps. Mitigates: action calibrated to a moment that has passed.
- Alerts reconciled against subsequent events. Mitigates: escalation to a resolved event, and the alert fatigue that follows it.
- Follower never alerted before the subject. Mitigates: a carer responding to something the person has not been told about.
- Followers cannot dose, silence or configure. Mitigates: an action taken on delayed, unverifiable data — most sharply, an alarm silenced remotely for a person who could have acted on it.
- Subject named on every follower screen. Mitigates: wrong-subject action where a follower follows more than one person.
- Not-monitoring propagated to the follower. Mitigates: absence of data read as absence of problems.
- Loss of follower connection stated to both parties. Mitigates: a subject believing they are watched and a follower believing all is quiet.
- Followers, their scope and their last access visible to the subject. Mitigates: monitoring arrangements outliving the circumstances that justified them.
- Sharing endable by the subject in one action. Mitigates: coercive or stale monitoring the subject cannot exit.
- Carer-of-a-dependent is a different specified user, not a permission level. Mitigates: capabilities designed for a young child's carer becoming available on an autonomous adult's account.
Related
- Unattended operation & degraded modes — the escalation path this role sits at the end of.
- Therapy recommendation — the actions a follower may not take.
- Sign in / sign out — attribution, and separating reading from acting.
- Patient header — subject identity on a multi-subject surface.
- Lay & patient-facing design — the register both sides of this pattern are written in.
- SteadyLine — the reference application.