Clinical patterns

Safety configuration

One person, on a screen nobody design-reviewed, changing the behaviour of every alarm for every patient in a deployment — while the clinicians affected are never told it happened. This is the highest-consequence interface in a clinical product and it is almost always the least designed one.

Stable · v1.0 QuietWard ISO 14971 IEC 62366-1

Overview

This system already names the clinical systems administrator as a specified user whose "errors here affect every clinician silently" — see Usability & context of use — and has admitted in writing that administration screens receive a fraction of the attention the clinical ones do. This page is that debt being paid.

The reasoning is uncomfortable and simple. A clinician making a mistake harms one patient. An administrator making a mistake in a threshold, an escalation chain or a suppression rule harms every patient the rule touches, for as long as nobody notices — and because the consequence is a change in what does not happen, nobody notices for a long time.

This is a clinical surface

It does not look like one. It has forms, tables and a save button, and it is usually built by whoever had capacity. But a screen that decides which alarms reach which clinicians is making the same class of decision as the screen that displays them, at a thousand times the scale. It gets the same design rigour, the same risk controls, and the same review as any bedside screen — or the controls on the bedside screens are decorative.

Blast radius first

Before anything else, the screen states how many patients, which wards, and for how long this change would apply.

Simulated before saved

No clinical rule takes effect until it has been run against real recent data and the author has seen exactly what it would have done.

Visible at the bedside

A change is announced where its effects land, with its author and time. Configuration that only exists in a console is configuration nobody can question.

Blast radius

The single most useful thing this screen can do is refuse to let someone edit a rule without knowing its reach. Scope is stated before the fields, not discovered at the confirmation step.

Scope stated before the controls
Edit rule · transient desaturation Draft — not in force
This rule currently affects 214 patients across 9 wards
Adult inpatient monitoring, all beds. Not applied in critical care, theatres or the emergency department.
In force since 2 Jun 2026 · authored by A. Fenn · v11

Medium and low priority only. High-priority and technical alarms are never held — see Suppression.

Changed from 90%. This widens the rule.

PartRule
Reach Required, above the fields. Patient count, ward list, and the care settings explicitly excluded. A number the author has to read before they can type.
Draft state Editing never touches the live rule. A console that writes to production as you type has no safe way to be interrupted.
Direction of change Each edited field says whether it widens or narrows the rule. "Changed from 90%" is a fact; "this widens the rule" is the meaning.
Standing prohibitions Restated inline, at the field. The administrator should not have to remember that high-priority alarms are unsuppressable — the form should say so where they are typing.
Save Disabled until previewed, with the reason in the label rather than in a tooltip — see Button.
Provenance Current version, author and date in force, so the person editing knows whose decision they are changing.

Simulated before saved

The rule that carries the risk

A change to a clinical rule is run against a stated period of real recent data before it can be saved, and the author is shown exactly which signals it would have removed, delayed or newly raised — including any that were later acknowledged as clinically significant. Configuration reviewed only as parameters is configuration nobody has understood. "Hold for 60 seconds instead of 30" is unreadable as a risk; "this would have delayed 412 alarms, 3 of which preceded a rapid response call" is not.

What the change would have done
Preview · 7–14 Aug 2026 · 214 patients replayed against recorded monitoring data
Alarms delayed
412
up from 180 under the current rule
Delayed and self-resolved
386
the intended saving
Delayed and did not resolve
26
raised 60 s later than they are today
3 of the delayed alarms preceded a rapid response call
Bed 12 (9 Aug), bed 3 (11 Aug), bed 21 (13 Aug). Under this rule each would have been raised 60 seconds later than it was.

Who may change what

Not every configuration change carries the same consequence, and treating them uniformly means either obstructing trivial edits or waving through catastrophic ones.

ClassExamplesRequired
Presentational Ward display names, sort order of a list, density. One authorised user. Logged.
Operational Escalation chains, who is on call, contact routing. One authorised user, preview of the resulting chain, logged and announced.
Clinical rule Thresholds, hold periods, grouping windows, which priorities a rule may touch. Preview against real data, plus a second approver. Announced at the bedside. Never effective the instant it is saved.
Prohibited Suppressing high-priority or technical alarms; disabling an announced risk control; retrospective application to a firing alarm. Not offered. These are not permissions — the capability does not exist. See Contributing.
Why a second approver, and why only here

Two-person authorisation is expensive and it is routinely applied to the wrong things — the irreversible-looking action rather than the wide-reaching one. Deleting a ward is dramatic and recoverable from backup. Widening a suppression rule by two percentage points is undramatic and affects two hundred people continuously until someone notices. The second approver belongs where the blast radius is, not where the drama is.

Visible at the bedside

The people who experience a configuration change are not the people who made it, and in most products they are never told it happened. A ward that suddenly gets quieter is indistinguishable from a ward where the monitoring broke.

Announced where the effects land
Alarm rules changed at 14:20
Transient desaturation alarms are now held for 60 seconds instead of 30 before being raised. Applies to this ward.
A. Fenn, clinical systems · approved by M. Okonjo · rules v12

Advisory priority, in clinical language, naming both people. It is dismissible — this is information, not an alarm — but it persists in the ward's change record.

Getting back

SituationBehaviour
Revert a change One action to the previous version, from the rule's own history. Rollback is itself announced at the bedside — an unannounced reversal is a second unexplained change.
Emergency stop A single control that disables all suppression and raises everything, available without the two-person process. Making the safe direction hard is how people end up leaving a bad rule running.
Version history Every version readable with its author, approver, preview result and period in force. The record must answer "what were the rules at 03:40 last Tuesday" — the question an incident review actually asks.
Unsaved draft Preserved and clearly marked as not in force. An administrator interrupted mid-edit must not return to ambiguity about what is live.
Conflicting edit Refused, with the other author named. Two people editing alarm rules from different assumptions is a hazard, not a merge problem.

Do's and don'ts

Do
This rule affects 214 patients across 9 wards

Reach stated before the fields. The author reads the consequence before they touch a control.

Don't

A field name, a unit nobody thinks in, and no indication that this number governs two hundred people's monitoring.

Do

Preview: would have delayed 412 alarms, 26 of which did not self-resolve, and 3 preceded a rapid response call.

The change expressed as what it would have done to real patients. This is the sentence that stops a bad rule.

Don't

Hold period: 30 s → 60 s. Save?

A diff of parameters. Correct, complete, and impossible to assess — the reviewer has no way to know whether doubling it is safe.

Do
Alarm rules changed 14:20 by A. Fenn, approved by M. Okonjo

Announced where the effects land, with named people. The ward can ask someone about it.

Don't

(configuration updated silently)

The ward gets quieter and nobody knows why. The most likely response is a fault report, and the second most likely is nothing at all.

Do

Save is disabled with the reason in the label. The gate is visible rather than discovered on submit.

Don't

An optional safety step, positioned as the lesser action. It will be skipped, most often by the person most confident they do not need it.

Accessibility

Outcomes of use

What this contributes to, in the terms of Usability & context of use. These are attributes believed to contribute to an outcome; the outcome itself is settled by observing real use in a specified context, not by this page.

Clinical safety notes

Risk controls carried by this pattern

Trace these in your risk file (ISO 14971) and usability engineering file (IEC 62366-1).

NotJustAnyMed.Tech Design System · Safety configuration · v1.0 · draft for review
Reference applications named in this system are fictional; all patient data, rules, names and alarm volumes shown are fabricated and illustrative.