Design guidance
Clinical anti-patterns
Sets out workflow shapes that put clinical safety at risk, why they arise, and the safer alternative Pensieve supports in each case.
Some workflow shapes put clinical safety at risk. This page sets out the shapes that recur in hospital software, why each one arises, and the safer arrangement Pensieve supports in its place.
Verifying your own result
The shape
A single clinician enters a result and acts on it, so one person stands as both the source and the check.
This shape arises under staffing pressure on a busy shift. Pensieve holds entry and verification as separate capabilities. The clinician who verifies a result differs from the one who entered it, so a value is trusted once a second clinician confirms it. Read how the two roles divide in order verification.
Charting a dose early
The shape
A nurse records a dose as given before the medicine has been dispensed and received on the ward.
The shape arises from recording ahead to save a step. In Pensieve a dose becomes administerable once the medicine is dispensed and received in the ward, and the five rights are verified at the moment of administration. The order lifecycle keeps the operational steps in their real order, so the chart reflects the medicine in hand.
A standing bypass
The shape
A blanket setting waves dose, allergy and interaction checks through for a whole ward or role.
Repeated prompts feel like friction, and a standing bypass looks like relief. Pensieve clears one named check at a time, for one mapped reason, by a clinician who holds the permission. The reason stays with the action, so a reviewer sees the finding and the decision together. Read how overrides are captured in alerting and override.
Amending in place
The shape
A prior result or charge is edited so the earlier value disappears from view.
The shape arises from a wish for a tidy record. Pensieve adds a correction as a new version and keeps the prior entry, marked superseded. The record then reads as it stood at each moment, and a reviewer sees the change alongside the reason for it.
Ordering off-catalogue
The shape
An order is typed as free text, outside the hospital-approved catalogue.
The shape arises when an item feels missing from the list. Pensieve places every order from the catalogue the hospital maintains, and freezes a snapshot of the item as it stood at placement. A later catalogue change leaves the placed order as it was, so the history reads as the decision was made. Read how the catalogue is held in the catalogue.
Sharing a ward sign-in
The shape
Several staff act under one identity on a shared workstation through a shift.
Sign-in feels slow between patients, so one session gets shared. Pensieve gives each member of staff a quick sign-in with a PIN or a key, and each session stays their own. Every entry names the person who made it, even when many share one screen. Read how this holds in shared workstations.
The shapes and the safer paths
| Risky shape | Safer arrangement |
|---|---|
| One person enters and trusts a result | Entry and verification held by two different people |
| A dose charted before the medicine is in hand | A dose administerable once dispensed and received in the ward |
| A standing bypass of a safety check | One override per named check, with a mapped reason, retained |
| History amended in place | A correction added as a new version, the prior kept |
| An order typed outside the catalogue | An order placed from the catalogue and frozen as a snapshot |
| One sign-in shared on a ward screen | Each member of staff signed in as themselves |
The common thread
Each safer path keeps two things true. A second person or a recorded reason stands behind a risky action, and the record reads afterwards as it stood at the moment of the decision.
Read where each safety duty sits between the platform and the hospital in safety responsibility.