Watch OpenAdapt prove a write—or stop before the wrong one
This is one immutable workflow recorded, compiled, qualified, and executed by OpenAdapt Flow 1.22.0. Every result below links to the exact retained report, independent result check, media, and SHA-256 digest.
All application data is synthetic. The workflow outcomes come from 18 governed executions against OpenAdapt MockMed synthetic reference. No customer data, credentials, or billing records are connected.
VERIFIED
The workflow ran and every required check proved the intended business result.
HALTED
OpenAdapt stopped without claiming success because a required safety or result check could not be proven.
Independent result check
Success is checked outside the screen that performed the write, so the interface cannot certify itself.
Measured campaign results
3 trials for each normal and fault condition, bound to the exact application, browser, viewport, runtime, and source commit in the evidence pack.
Switch between the source demonstration, a successful replay, and a deliberate ambiguity case. These are the exact videos retained by the evidence pack.
Source recording
The synthetic reference task is performed once through OpenAdapt’s recorder. It retains the input events, frames, timing, and exact target evidence used by the compiler.
1 · The demonstration became an inspectable workflow
The graph below is generated from the exact compiled bundle—not reconstructed for this page. Expand any step to see its targeting, identity, postcondition, and effect contracts; Stop rules isolates its explicit refusal paths.
no plaintext PHIlinear programcompiler 1.22.0certified: clinical-writeParameters: note:string
ViewFollow the normal execution path and expand any step.
identity gate
identity gate
identity gate
identity gate
irreversibleidentity gateeffect check
Halts here: halts if the system-of-record effect is not confirmed
Workflow path complete
How to read this: each step shows how it re-finds its target (resolution ladder), whether it confirms it is acting on the right record (identity gate), what real system-of-record change it checks (effect), and where it will stop rather than guess (halt point). This is the same compiled program used by this campaign. Its reports record zero model calls. Screen checks in this evidence pack come from retained before/after evidence and explicit qualification.
Why the raw recording contains pointer coordinates: they remain as capture provenance. Replay resolves the compiled structural target first, then the image and landmark fallbacks shown in the expanded step; it does not blindly click the recorded point.
Certification checks the compiled bundle before it can be deployed. The Standard execution profile independently requires the runtime protections that must hold on every governed run.
2 · Qualification tested the normal path and five ways it must refuse
A fault test passes when OpenAdapt produces the expected HALTED outcome before an uncertain or unverified write. Every condition below ran three times.
What that means: The result is checked through an API, database, audit feed, or other system interface independent of the screen that performed the write. Tier 1 is the strongest; Tier 4 is the weakest.
Normal qualified run3/3 passed
Writes to the intended synthetic record, then proves the saved value through the independent source of truth.
Identity check failed for step 'step_000' (click 'Open'): a target was found positionally (rung 'template', confidence 1.00) but its surrounding text does not match the recorded target's — expected '<structured identity template>', observed 'Taylor DuplicateKnee pain referralHigh' (coverage 0.00) — refusing to act; run aborted
Record changed after checking3/3 passed
Rechecks immediately before the write and stops if the record changed after the earlier observation.
Identity check failed for step 'step_000' (click 'Open'): a target was found positionally (rung 'structural', confidence 1.00) but its surrounding text does not match the recorded target's — expected '<structured identity template>', observed 'Changed IdentityKnee pain referralHigh' (coverage 0.00) — refusing to act; run aborted
Success proof is too weak3/3 passed
Does not accept an on-screen success message as sufficient proof of the saved business state.
System-of-record effect verification HALTED step 'step_005' (click 'Save Encounter'): field_equals refuted against the rest system of record and could not be reconciled (escalated) — [rest] field_equals: field 'note' is '', expected 'Synthetic follow-up in two weeks' (the system of record contradicts the declared outcome) -- no compensator available for an irreversible refuted effect -- durably halt and escalate — run aborted
Success proof is missing3/3 passed
Does not report success when the required independent verifier is unavailable.
System-of-record effect verification HALTED step 'step_005' (click 'Save Encounter'): record_written refuted against the rest system of record and could not be reconciled (escalated) — [rest] record_written: 0 records match the target selector, expected 1 (missing / phantom / rejected write -- the screen may show success but nothing landed) -- no compensator available for an irreversible refuted effect -- durably halt and escalate — run aborted
3 · VERIFIED describes proof, not merely a finished script
Execution completion and trusted outcome are separate. The normal case is VERIFIED only because authorization, identity, runtime checks, and the independent business-state check all passed.
Independent result check: GET /api/db is independent of browser pixels and the runtime report; target state is held in the local MockMed fault server.
Try it with your own workflow
The public pack is immutable so every visitor can inspect the same evidence. Your workspace is where recording, qualification, runs, evidence, and governed repair become interactive.