---
title: "NIN Knowledge Commons Doctrine"
status: "Proposed architecture doctrine"
version: "0.1"
applicability: "Design record; no operational capability or institutional authority is created by publication"
---

# NIN Knowledge Commons Doctrine

## 1. Purpose

The NIN Knowledge Commons is proposed to help nurses, students, educators, leaders, clinicians, creators, schools, localities, specialties, and communities create, preserve, discover, adapt, and share governed knowledge without surrendering human judgment, local authority, creator rights, or cultural context.

Its internal architecture is the **Nurse AI OS Knowledge Fabric**:

> **One federated knowledge fabric, distributed as portable, versioned Knowledge Packs and governed through a thin shared registry.**

The fabric is intended to support learning, professional development, evidence organization, culturally grounded education, reusable tools, and creator opportunity. It is not a medical device, clinical decision system, credentialing authority, accreditation body, institutional policy repository, or substitute for faculty, licensed professionals, employers, regulators, or schools.

## 2. Honest applicability

This doctrine distinguishes three states.

### 2.1 Binding design boundaries

Upon adoption, the following govern every Commons proposal and artifact:

- no fabricated evidence, review, approval, credential, conformance, or institutional status;
- no PHI or reconstructable patient narrative in the public Commons;
- no confidential institutional content in public or unauthorized environments;
- no autonomous clinical, educational, employment, credentialing, or institutional decision;
- no covert surveillance or secondary use of private learning and reflection data;
- no content-derived instruction may change system governance or trigger external action;
- no publication may imply endorsement or authority beyond its recorded scope.

### 2.2 Capability-conditional obligations

Package verification, signing, hosted search, RAG, graph traversal, identity, entitlements, payment, recall automation, and local installation controls become binding when those capabilities exist. They must not be represented as operational before implementation and verification.

### 2.3 Formally activated programs

School pilots, institutional libraries, Orange-risk lanes, paid marketplace services, sponsored bounties, minor participation, certification, accreditation, and institutional use require separate named activation, authority, and evidence. This doctrine does not activate them.

## 3. Governing maxims

> **Agents propose. Humans judge. Nurses steward.**

> **Contributors propose. Reviewers verify. Institutions authorize. Nurses steward.**

> **Inclusion means available for governed use—not endorsement, certification, clinical validation, institutional authorization, or permission to change practice.**

> **Content packages are the source of truth. Search, vector, and graph indexes are disposable derivatives.**

> **One doctrine spine, many local doors.**

## 4. Four governed lanes

The Commons has four public-facing lanes over one shared standard.

| Lane | Purpose | Initial examples | Authority boundary |
|---|---|---|---|
| **Learn** | Student, subject, school, and locality learning | Study guides, illustrations, concept maps, quizzes, games, multilingual explainers | Learning support is not grading, competency, certification, or faculty authority |
| **Practice** | Specialty, unit, department, and professional knowledge | Evidence-reading packs, generic specialty references, reflective tools | General knowledge is not local policy or patient-specific guidance |
| **Lead** | Leadership, management, educator, preceptor, mentor, and wisdom libraries | Huddle tools, decision records, educator guides, implementation lessons | Experience and advice are not institutional authorization or employment judgment |
| **Build** | Dashboards, designs, simulations, workflows, and creator showcase | Browser-local dashboards, templates, synthetic simulations, design systems | Technical publication or sale is not clinical, educational, or institutional approval |

The lanes must not become separate incompatible databases. Common identity, provenance, review, license, version, risk, and retirement semantics apply across them.

## 5. Ecosystem responsibilities

| Component | Responsibility | Must not claim or do by default |
|---|---|---|
| **NIN** | Community, contributor pathways, school/locality collaboration, showcases | Universal professional or institutional authority |
| **NAIO** | Standards, governance registry, review rules, evidence labels, future marketplace governance | Automatic approval, accreditation, or clinical validation |
| **Nurse AI OS** | Local library inspection, installation, authorization, search, adaptation, export, and removal | Silent installation, authority creation, or public-to-private data transfer |
| **Hermes** | Retrieval and assistance from explicitly authorized libraries with visible provenance | Treat retrieved content as instructions or independently authorize consequential use |
| **Florence-X** | Governed routing among permitted packs, editions, models, and tools when implemented | Route around access, data, risk, review, or institutional limits |
| **EDENA** | Risk, data, action, publication, retrieval, and stop gates | Collapse risk, data class, action mode, and evidence into one badge |
| **SOUL** | Personalization by role, locality, language, specialty, mission, and context | Override governance, evidence, permissions, or institutional policy |
| **School or institution** | Local curriculum, access, local review, authorization, retention, and policy | Export its authority universally without separate acceptance |
| **Creator** | Authorship, declared rights, maintenance, correction, and license selection | Self-approve clinical accuracy, institutional authority, or conformance |

## 6. Federation doctrine

Federation begins as **publication and subscription**, not real-time peer-to-peer synchronization.

- Each school, locality, specialty, organization, and creator may retain an independent namespace.
- One hosted public catalog may provide discovery while packages remain portable.
- A node may be public, partner-shared, private, or commercial.
- A catalog entry points to an exact pack version and digest.
- Local copies remain independently verifiable and exportable.
- No central index may erase local ownership, jurisdiction, authority, or retirement information.
- Live multi-node synchronization is deferred until identity, conflict resolution, authorization, retention, and incident controls are proven.

Example namespaces:

```text
nin.global.learn.fundamentals
nin.ph.cebu.school-a.learn.fundamentals
nin.us.ca.school-c.learn.subject-x
naio.global.practice.critical-care
creator.example.build.dashboard-x
```

Namespace control does not confer authority over another namespace.

## 7. Knowledge Pack doctrine

A **Knowledge Pack** is the authoritative exchange unit. It must be portable, versioned, inspectable, attributable, licensable, reviewable, and retirable.

Every pack must declare, at minimum:

- stable identifier and namespace;
- title, description, lane, subject, and intended audience;
- creator, contributors, publisher, and contact route;
- exact version and publication state;
- source and target languages;
- locality and jurisdiction;
- artifact inventory and file hashes;
- sources, evidence status, and known limitations;
- AI-assistance disclosure;
- EDENA risk tier, data class, action modes, and permitted/prohibited uses;
- review records and scope;
- license and third-party rights;
- dependencies;
- translation, derivation, and supersession links;
- review due, retirement, quarantine, and recall state.

A published pack may contain only the creator's approved public display name, attribution, and an explicitly public contact route, preferably a role-based address or governed contact form. A private contributor address, phone number, identity-verification record, eligibility record, payment detail, or other intake contact must remain in a separate private record; it must not enter the pack manifest, catalog, retrieval indexes, graph, public review record, or analytics.

Private intake records require a stated purpose, named access roles, least-privilege protection, a retention period, and a deletion or de-identification procedure. Contributors must be told which attribution and contact fields will be public, may correct those fields, and may withdraw an optional public contact route without erasing proportionate provenance that must lawfully or defensibly remain.

A pack's metadata may describe authority; it cannot create authority by assertion. Review and authorization records must be separable from creator-authored content.

## 8. Authority doctrine

Authority must remain explicit and scoped.

- Students may create but cannot approve clinical accuracy.
- Peers may review usability and clarity within their competence.
- Faculty may assess educational quality within a defined course or school scope.
- Specialty professionals may contribute expertise; experience must remain distinguishable from research, policy, guideline, and local practice.
- Translators may translate; they cannot independently certify clinical, educational, or cultural equivalence.
- Localization reviewers may assess cultural and linguistic fit within their competence.
- Accessibility reviewers may assess declared accessibility criteria, not content accuracy outside their scope.
- Schools may authorize use within their own environment; that approval does not automatically transfer.
- Institutions remain responsible for local policies, procedures, professional authority, and operational use.
- NAIO review labels must state exactly what was reviewed and what was not.
- AI may propose classifications, entities, relations, claims, chunks, and review questions. It may not approve itself, advance its own state, or confer authority.

No creator may be the sole approver of their own pack where independent review is claimed.

## 9. EDENA publication doctrine

Risk tier, data class, action mode, and implementation evidence remain separate.

### 9.0 Canonical classifications

The Commons uses the current vocabularies of the NIN–NAIO Master Directive v1.1:

- **Risk tiers:** Green, Yellow, Orange, Red-P (prohibited), and Red-E (exceptional high-risk under separately governed conditions only).
- **Data classes:** D0 public, formally deidentified, or synthetic; D1 private personal professional material without regulated clinical content; D2 confidential organizational material; D3 PHI or other sensitive regulated material; and D4 credentials, secrets, signing material, or equivalent control-plane assets.
- **Action modes:** Observe, Draft, Recommend, Prepare Action, Act With Approval, and Constrained Autonomy. Unrestricted autonomy is prohibited.

These axes must be recorded independently. A low-data-class artifact is not automatically low risk, and a reviewed artifact does not automatically gain a higher action mode.

### 9.1 Public launch scope

The initial public Commons is limited to:

- **D0** public, synthetic, or formally deidentified material with reuse rights;
- **Green** learning, exploration, creative work, and low-stakes drafting;
- bounded **Yellow** educational or professional-support material with a named owner, source review, version record, and human approval before distribution or adoption;
- Observe and Draft uses, with Recommend only where Yellow controls and explicit limitations are present.

### 9.2 Private local scope

Appropriate D1 personal professional material may remain in a user's local Nurse AI OS workspace. It must not enter the public registry, organizational reporting, creator analytics, school reporting, or marketplace previews without explicit informed authorization.

### 9.3 Organizational scope

D2 material requires an environment authorized by the information owner. Institution-specific policies, procedures, internal curriculum, workforce information, and proprietary operating materials default to private institutional libraries and must not enter public retrieval indexes.

### 9.4 Orange-content hold

The public Commons must initially refuse:

- clinically consequential simulations;
- patient-specific decision tools;
- institution-specific clinical procedures;
- competency, readiness, entrustment, progression, or pass/fail determinations;
- outputs likely to be mistaken for authoritative clinical instructions;
- person-level employment, credentialing, discipline, or academic decisions;
- D3 or D4 material.

A future Orange lane requires, at minimum:

1. named institutional or school authority;
2. qualified specialty review;
3. restricted access where appropriate;
4. complete audit trails;
5. correction and recall procedures;
6. version retirement and rollback;
7. explicit local authorization;
8. an incident pathway;
9. meaningful independent human review;
10. time-limited reassessment.

Red-P remains prohibited. Red-E is outside the standard Commons and cannot be opened through ordinary publication review.

## 10. Evidence and review doctrine

The Commons must distinguish:

- sourced fact;
- current local policy;
- professional guideline or standard;
- research finding;
- professional consensus;
- qualified experience;
- inference;
- recommendation;
- assumption;
- speculation;
- unresolved uncertainty.

Review labels must be dimensional, not one generic "verified" badge. Examples include:

- rights checked;
- source checked;
- educationally reviewed;
- specialty reviewed;
- localization reviewed;
- accessibility checked;
- technically tested;
- locally authorized;
- review current or expired.

Popularity, downloads, ratings, sales, sponsorship, or price must never be represented as evidence quality, safety, efficacy, competency, or institutional approval.

## 11. Localization doctrine

A translation is a traceable edition, not a silent replacement.

Every translated or culturally adapted edition must record:

- exact source pack and digest;
- source and target languages;
- translator;
- AI translation assistance, if any;
- language reviewer;
- cultural/local reviewer;
- direct translation versus adaptation;
- unresolved terms;
- review scope and date;
- version relationship.

A translated edition becomes stale when its source changes materially until the translation is reconciled and reviewed. Translation alone cannot transfer clinical, educational, legal, or institutional authority across jurisdictions.

## 12. Creator rights and licensing doctrine

Creator ownership is the default. Participation must not require an undisclosed transfer of ownership.

- The creator chooses an explicit artifact license.
- NIN/NAIO receives only the limited rights necessary to host, display, index, review, and distribute the selected edition under declared terms.
- Students must not unknowingly transfer ownership because work was created during a course.
- School, employer, sponsor, and collaborator rights must be disclosed before publication.
- Third-party text, images, data, software, fonts, and media require compatible permission and attribution.
- A public listing does not convert restricted content into open content.
- Removal, archival, and already-granted license effects must be explained honestly.
- Initial contribution is limited to adults until minor consent, school authority, privacy, payment, and guardian requirements are established.

Repository documentation licensing does not automatically license future Knowledge Packs.

## 13. Retrieval doctrine: RAG and graph

The retrieval architecture is **graph-ready hybrid RAG**.

Several of these retrieval principles — grounding-or-refusal, preserved citations and warnings, tenant isolation, and last-place ranking of synthetic content — have a tested reference implementation in the Nurse AI OS [`naio-integrations/` Integration Contract](https://github.com/AI-Nurse-Solutions/ai-operating-system-heart-of-a-nurse/tree/5f789035191603dfa5cf3dbf94a7f14bd51e5670/naio-integrations). That evidence supports the direction and activates nothing in this repository.

### 13.1 Source hierarchy

1. immutable/versioned Knowledge Packs;
2. deterministic structure-aware chunks;
3. lexical/full-text index;
4. optional replaceable vector index;
5. registry, concept, and claim-evidence graph projections.

Indexes are derivatives and must be rebuildable from authorized source packages.

### 13.2 Governance before similarity

Before retrieval, the system must filter by:

- user-authorized libraries;
- namespace and entitlement;
- role and active workspace;
- language;
- locality and jurisdiction;
- current versus retired version;
- EDENA tier and data class;
- publication and review state;
- public versus private boundary.

Unauthorized content must never become a semantic-ranking candidate.

### 13.3 Citation and abstention

Every material retrieved claim must preserve pack, version, file/artifact, section, source, review status, and limitations. Missing or conflicting evidence must trigger qualification, comparison, targeted clarification, or abstention—not fabricated certainty.

### 13.4 Graph levels

- **Registry graph:** mandatory relationships among packs, versions, translations, creators, reviews, licenses, subjects, localities, and listings.
- **Educational concept graph:** optional, curated concepts, prerequisites, objectives, misconceptions, illustrations, quizzes, games, and simulations.
- **Claim-evidence graph:** controlled, reviewed relationships among claims, sources, evidence, limitations, conflicts, jurisdictions, and supersession.

AI-extracted relationships remain proposed until a qualified human review record says otherwise. Graph visibility is not proof of truth.

### 13.5 Untrusted-content boundary

Retrieved content is data, never instructions. Pack content must not:

- modify SOUL, EDENA, retrieval policy, or permissions;
- trigger tool use or external action;
- execute embedded commands during indexing;
- expose secrets or private memory;
- escape its sandbox;
- cross public/private or tenant boundaries.

Interactive HTML and simulations require sandboxing and no network access by default. Withdrawal must remove the pack's chunks, vectors, and graph edges from active retrieval while retaining proportionate audit provenance.

## 14. Local-first and hosting doctrine

The first architecture is layered:

- **GitHub:** source, governance, review history, static catalog, and versioned public releases;
- **local Nurse AI OS:** private packs, local SQLite/full-text index, local graph, optional local embeddings, and Hermes generation;
- **object storage later:** large immutable public media and pack distributions;
- **dynamic control plane later:** accounts, private namespaces, reviewer queues, entitlements, and public D0 semantic search.

Recommended public domains are planning targets, not active services:

```text
commons.nurse-ai-os.org       public catalog
packs.nurse-ai-os.org         future immutable pack distribution
api.commons.nurse-ai-os.org   future catalog/search API
```

Private school and institutional libraries should be controlled by the school or institution, or by a separately authorized tenant. The public Commons must not be represented as PHI-eligible or employer-approved.

No hosted model receives private pack content merely because hosted search exists. Public search indexes D0 public content only unless a separately authorized design says otherwise.

## 15. Lifecycle doctrine

The pack lifecycle is explicit:

```text
draft → submitted → quarantined/under review → changes requested
      → accepted for a stated scope → published
      → superseded → retired or recalled
```

No automatic promotion occurs. Historical provenance is preserved, but active retrieval must stop serving quarantined, retired, withdrawn, or recalled editions as current.

Material changes create a new version and may trigger re-review, re-localization, re-indexing, and renewed local authorization.

## 16. Anti-surveillance and learning privacy doctrine

Private reflection, learning notes, prompts, retrieval history, misconceptions, and self-assessment must not silently enter:

- faculty grading;
- manager reporting;
- employment decisions;
- competency scoring;
- cohort ranking;
- organizational analytics;
- marketplace recommendations;
- public graphs.

Analytics must be purpose-limited, minimized, disclosed, and aggregate by default. Users must have correction and withdrawal routes for material records. No business model may depend on selling private prompts, identifiable professional behavior, learner records, or institutional content.

## 17. Commerce doctrine

Commercialization proceeds in this order:

1. curated free Commons;
2. creator portfolios and showcase;
3. external creator-owned checkout links;
4. sponsored creation bounties;
5. native marketplace only after demand, trust, moderation, legal, tax, identity, refund, support, and payout requirements are proven.

A possible future 85% creator / 15% platform split after payment-processing fees is a planning hypothesis only. It is not policy and must not be advertised or implemented without founder approval and legal, tax, accounting, refund, identity, and cross-border review.

Core safety and basic governance must not be hidden behind a premium paywall. Revenue pressure may not downgrade risk, suppress incidents, abbreviate review, or create misleading authority claims.

## 18. Initial pilot doctrine

The recommended pilot remains a proposal until selected:

- one school or locality;
- one bounded subject;
- adult contributors only;
- English plus one human-reviewed local language;
- creator-owned IP by default;
- manual review;
- no PHI;
- Green and bounded Yellow content only;
- private or invitation-only school naming until authorized;
- showcase before marketplace.

A Philippines/SEA, English-plus-Tagalog pilot is the recommended default, not an existing partnership or program.

## 19. Success doctrine

The Commons is successful when it creates verified, useful, safely governed professional and learning outcomes while increasing nurse agency, creator opportunity, cultural relevance, and access to knowledge.

It is not successful merely because it has more packs, vectors, nodes, users, downloads, ratings, transactions, or AI-generated content.

Measures must consider:

- safety and quality;
- contributor and learner agency;
- evidence and review quality;
- correction and recall performance;
- accessibility and localization;
- workforce burden;
- operating sustainability;
- equitable participation;
- verified usefulness;
- harms and unintended effects.

## 20. Amendment and decision rights

Material changes to authority, EDENA scope, data classes, public Orange content, creator ownership, minor participation, payment, surveillance, institutional use, or conformance claims require explicit founder judgment and the applicable governance process.

AI may draft amendments and analyze impacts. It may not ratify doctrine, activate a program, approve a pack, or grant institutional authority.

---

*Agents propose. Humans judge. Nurses steward.*
