USER GUIDE
Using CAELOMERE as one platform
This guide is for decision makers who need to understand the sandbox, not operate the internals. CAELOMERE is one platform with internal layers.
What CAELOMERE is
CAELOMERE controls action before consequence. It does not present Passport, Guardian, Sentinel, Governance or Business Intelligence as products you choose between. Those names describe stages of one journey.
How to start the sandbox
Open Sandbox, enter an organisation name and sector, then create the workspace. The existing /auth/demo-access route issues a demo-role token and an isolated tenant. No second demo backend is used.
Organisation and sector onboarding
Name and sector label the synthetic workspace so reviewers can see which prospect session they are in. They are not used to connect a live system.
Synthetic-data safety rules
This sandbox uses synthetic demonstration data only. Do not enter patient-identifiable information, classified material, live operational records, or other sensitive data. Demo workspaces are isolated and expire. No live external system is contacted.
How the joined workflow operates
- Who is asking? Passport. CAELOMERE records who or what is allowed to act, on which systems, and for how long.
- Is it allowed? Guardian. CAELOMERE decides whether a proposed action is permitted before anything consequential happens.
- What happened next? Sentinel. CAELOMERE records the operational outcome of a governed action.
- What evidence supports it? Governance, Assurance, Resilience & Enterprise Data. CAELOMERE keeps the governed evidence and data trail tenant-bound.
- What intelligence can be drawn? Business Intelligence. CAELOMERE turns governed information into intelligence. BI consumes only; it does not decide or execute.
How Passport authority is used
The sandbox registers a synthetic actor and issues a time-bounded Passport against a synthetic governed system. Authority is scoped: allowed actions, prohibited actions, systems, and expiry.
How Guardian decisions appear
Guardian evaluates the proposed action against the Passport. The fascia shows the decision the real engine returned. A missing spend limit or missing authority fails closed.
How Sentinel records operational outcomes
If Guardian permits the action, Sentinel records the operation against the same tenant. The sandbox does not execute a live consequential path.
How evidence and governance data is shown
The governance board view is tenant-bound. Evidence that is only mapped is not treated as certified.
How BI displays governed intelligence
Business Intelligence consumes governed tenant data only. It does not decide and does not execute.
How to review evidence
After the joined run, the sandbox shows the raw records returned by the backend. Treat them as receipts, not marketing claims.
How to submit feedback
Use the feedback form at the end of the sandbox. It posts to the existing /api/product-feedback route with the demo token.
What the sandbox does not do
- It does not accept patient-identifiable or classified data.
- It does not reach admin or internal routes.
- It does not trigger live NHS, EPR or production integrations.
- It does not perform consequential live execution.
- It does not store permanent secrets in the browser beyond a short-lived demo token.
- It does not let one demo tenant read another.
