Operations
Runbook
A practical checklist for opening the hospital day, handing over active work, and triaging incidents without losing clinical, billing, or audit context.
Before queues start
Daily Opening
- Confirm API health, web availability, and required data stores before opening queues.
- Review emergency zone capacity, low-stock and expiry alerts, pending diagnostic verification, and unresolved feedback.
- Check sensitive audit activity after role, billing, patient merge, or service catalog changes.
Before ownership changes
Shift Handover
- Emergency: active cases, triage changes, handoffs, escalations, bed waits, and cases waiting without beds.
- Clinical: OPD queue, admitted patients, pending discharges, prescriptions, and outstanding diagnostic orders.
- Revenue and supply: unpaid invoices, pending insurance claims, unreceived purchase orders, low stock, and near-expiry batches.
- People operations: missing clock-outs, pending leave approvals, payroll exceptions, loans, and scheduled payroll runs.
Capture evidence before changing data.
For every incident, capture the user, role, route, patient/order/invoice identifier, timestamp, expected behavior, and observed behavior before adjusting permissions or records.
Access Surprise
Check role permissions first, then record scope, org scope, linked doctor/user ownership, and audit logs.
Realtime Failure
Verify JWT socket auth, notification preferences, MongoDB for chat, and Redis when multiple API workers are running.
Billing Mismatch
Compare service catalog pricing, module rates, invoice line items, payments, advances, refunds, voids, and audit events.
Diagnostic Visibility
Verify patient linkage, order status, verification state, storage availability, and export/download permissions.
Where to find active work.
Use these verified dashboard routes during handover, incident triage, and role training. Start with the module that owns the record, then cross-check billing, notifications, chat, and audit trails when the issue crosses teams.
Clinical Floor
Diagnostics & Supply
Revenue & Governance
Realtime & People
Technical Architecture
| Field | Type | Institutional Role |
|---|---|---|
| health_status | HTTP | API readiness checked through the health endpoint. |
| metrics_stream | Prometheus | Application and infrastructure metrics for triage. |
| error_tracking | Sentry | Optional API + web error tracking when SENTRY_DSN is configured (disabled by default locally). |
| audit_event | Record | Sensitive activity trail for role, billing, and patient changes. |
| socket_room | Socket.IO | Personal and group realtime channels for alerts and chat. |
Note: Sensitive fields use AES-256 field-level encryption where applicable.
Governance & Power
audit:viewreports:viewnotifications:viewchat:useRepository runbooks
- docs/info/DR-PLAYBOOK.md
- docs/info/OBSERVABILITY.md
- docs/info/ALERT-POLICY.md
- docs/info/SUPPORT-POLICY.md
- docs/info/GOVERNANCE.md
- docs/info/COMPLIANCE-PROGRAM.md