Skip to content
Launching in Atlanta · Early access is open
GovernanceFor partners, advisors, and investors

The guarantees are fixed.The routing and the people are configurable.

Families never see this vocabulary. They see who is coming and that the person showed up. This page is the mechanism underneath: the rules every booking runs on, and the record they leave behind.

OlliDoc.it is pre-launch. None of this is running yet — each part is labelled as first to ship or designed.

Why rules, not judgment

Non-medical home care reduces to four facts.

Clinical care asks whether a decision was right — contested, and a matter of judgment. Non-medical care asks something narrower, and each part resolves to a fact. That is what lets a system enforce it with rules it will not override, instead of policies someone has to remember under pressure.

01

Identity

Is this the verified person?

02

Location

Were they at the service address?

03

Time

When did they arrive, and when did they leave?

04

Scope

Did they do the agreed thing — and only that?

The charter · designed

Twelve rules.

None can be switched off by a family, a partner, or our own schedulers. That is what makes them guarantees rather than defaults.

Work · protects caregivers
Visits · protects families and caregivers in the room
Data · protects everyone’s information

Work

Protects caregivers

  1. 01

    Pay is never used to rank caregivers or break a tie.

    No bidding, no undercutting. The family chooses on fit, availability, distance, and prior visits.

  2. 02

    Terms are shown before acceptance and do not change after it.

  3. 03

    Declining a request costs a caregiver nothing.

  4. 04

    A caregiver can ask why and get the logged answer.

    The record is written at the moment of the decision, not reconstructed on request.

Visits

Protects families and caregivers in the room

  1. 05

    A lapsed or unverified caregiver cannot be dispatched.

    Scheduling pressure cannot override it. Only renewal and a named review can.

  2. 06

    Arrival and departure are location-confirmed at both ends.

  3. 07

    A caregiver can end a visit that feels unsafe. The scheduled pay stands.

  4. 08

    Every concern reaches a person, and every outcome is recorded.

Data

Protects everyone’s information

  1. 09

    Nothing is permitted until it is explicitly allowed.

  2. 10

    A named human approves every movement of money and every release of personal data.

    Who approves is configurable. That a human approves is not.

  3. 11

    Records are appended, never overwritten. A correction sits beside the original.

  4. 12

    Two isolation layers must fail, not one.

Who decides

The family chooses. The record explains.

The platform shows which caregivers are eligible and available, with a dated verification state. The family chooses. OlliDoc.it does not score caregivers to decide on a family’s behalf — a platform that ranks workers by quality is directing their work.

A caregiver who was not chosen can still ask why, and gets the logged answer rather than a support macro. It is the structural answer to the lack of recourse workers report on gig platforms.

decision record
$ OlliDoc.it record --request=4471 --requested-by=caregiver
Illustrative record showing the format. OlliDoc.it is pre-launch.

Tamper-evidence· designed

Don’t take our word for it. Break it.

“You can trust the record” is exactly what an untrustworthy record would say. So change the rate on a booking after the fact, and watch what happens to every entry that follows.

chain intact
entryactionprevhash
0x41booked · Tue 10:00–14:00 · $24.00/hr00000000badd361d
0x42arrived 10:04 · location confirmedbadd361d105129f8
0x43tasks recorded · meal, reminder105129f88f26220f
0x44left 14:00 · location confirmed8f26220f18ed65e9
0x45record shared with family18ed65e91b0c95b0
Each record carries the hash of the one before it.

Illustrates the designed structure with a simplified hash. The Merkle-chained trail is on the roadmap; at launch the log is append-only.

The record

Using a record and proving one are different jobs.

Most platforms offer one of these. A partner who has to answer for what happened needs all three.

Use it

The visit record

Families and caregivers read the same record of every visit — arrival, departure, tasks, notes, corrections.

first to ship

Prove it

Verification

A signed digest and a proof that a given entry is unaltered — what you hand someone who asks whether the record could have changed.

designed

Keep it

Export

Into a partner’s own reporting tools. The export is itself written to the record.

designed

Status

Most platforms wrote their governance after they got sued.

We wrote ours before we wrote the product. Which means being exact about what ships first and what is designed behind it — a governance page that blurs the two is the thing this page exists to argue against.

First to ship

  • Verified identity and a dated verification state for every caregiver
  • Location-confirmed check-in and check-out on every visit
  • A plain-language visit record shared with the family
  • Rules that make a lapsed caregiver undispatchable
  • An append-only record of each booking’s terms, changes, and outcome

Designed · later phases

  • Default-deny access, with a named human decision on money movement and data sharing
  • Cryptographically tamper-evident records that can be independently verified
  • Export of the record into a partner’s own reporting tools
  • A caregiver record that other employers can choose to honor

Architecture

Designed by Netminder42.

The access model, the record, the human-approval gates, and the rules every booking operates under.