P.R.I.S.M is your
lab manager.
Look inside the brain
Not a chatbot on a tracker. A production multi-agent runtime: it perceives across four channels, routes to the right model, reasons over a permissioned memory, weighs what's worth surfacing, and turns intent into a reviewable proposal. A clock of scheduled jobs drives it while nobody is asking. Every write is gated. Nodes drawn dashed are built and waiting on a credential — we'd rather show you the machine than a flattering half of it.
Twelve jobs run the lab’s clock.
It is working when nobody is asking it anything.
The proactivity sweep
Six monitors read the lab, score what they find, and almost always decide it can wait.
Deadline sweep
Tasks, grants and abstracts — you hear about the date before it passes, not after.
Auto-retirement
A grant or a conference retires itself the day after its deadline. A new date brings it back.
Bills, chased
What is due or overdue gets an email, and a recurring bill materializes its own next occurrence.
The trial
INTRO’s recruitment digest, drawn from REDCap. Drug-expiry alerts escalate at four, three, two and one month.
Transcript poll
The finished meeting transcript is pulled the moment it is ready, and becomes the minutes.
Measured in production, not asserted. It reads everything and interrupts almost never — and every interruption it did raise was a question, never a fait accompli. The jobs also watch themselves: all twelve report their own failure, so a scheduled job that starts returning 500 into the void raises an alert instead of vanishing.
Send a bot to the meeting you can't attend.
Ask in the app or over WhatsApp. PRISM sends a bot into the Zoom or Meet call, transcribes it on a GPU we run — the audio never reaches a transcription vendor, because we didn't hire one — pulls the finished transcript, extracts the summary, the decisions and the action items, files them, and emails them to you. The action items stop there and wait: an LLM reading a noisy multi-speaker room is not allowed to create a task in this system. You promote the ones that are right.
Every project runs its own QMS.
Protocols, SOPs, manuscripts and experiment records — versioned, risk-graded, approved and signed. Each project sets its own document types, its own lifecycle and its own approval chain.
Draft → Approved → Active → Superseded
Each document type carries its own lifecycle — and each project decides which document types it has.
Nothing is ever deleted
A new version supersedes the current one, and the file it replaces moves to Old drafts.
The grade sets the chain
A protocol is graded first, and the grade decides how heavy its approval chain is. You see the chain before you click, not after.
21 CFR Part 11
Printed name, timestamp, meaning — hash-chained to the signature before it.
Competency, per version
A major revision assigns retraining. A typo correction does not — a QMS that cries wolf is one the lab learns to ignore.
Raised, routed, signed closed
A departure from protocol is recorded and reviewed, and the last signature IS the closure. There is no separate close button.
Enforced, not asserted. A version is immutable by database trigger: its content hash, its label and its date cannot change. Once it is approved, its risk grade freezes too — that grade is what the signatures were given under, and re-grading the protocol next year cannot rewrite what this year’s signatures meant.
Everything lands in the lab’s own Drive.
Filed where a person would have filed it — and PRISM only ever sees what it put there.
<Project>/<Doc type>/protocols · SOPs · manuscripts · experiment recordsOld drafts/the version it replaced — moved, never deleted
Bills/2026-07/receipts and card statements, by the month they were handed inMeetings/2026-07/meeting audio, by month
- Scoped credential
It can only see the files it made
PRISM holds a drive.file credential, so the lab’s existing Drive is invisible to it. That is not a policy we promise to keep — it is the only scope it was granted.
- The record
Drive holds the file. PRISM holds the record.
Drive purges its own revision history after about thirty days. The version, the hash, the approval and the signature live in the database, which does not.
- Reach
No reader needs a Google account
Files stream back out through PRISM, under PRISM’s permissions — so what someone may open is decided in one place, not in a share dialog.
Good morning — 3 things need you
It lives where the lab already talks.
Photograph an RFA. Say “add this meeting.” Forward a receipt. PRISM reads the thread, understands what you mean, and hands back a proposal — right inside WhatsApp. No app to open.
It answers only when it is addressed.
Only to numbers it knows — and only ever with what that person is permitted to see.
- Photograph a bill, or a card statement. It reads the vendor, the amount and the date, and files it under the right month.
- “Send me July’s Excel.” The Hopkins reimbursement workbook arrives in the conversation, as a file.
- “Send a bot to my Zoom.” It joins the call, transcribes on a GPU we run, and emails you the minutes.
- Send a protocol PDF. It becomes a new version on the lab’s Drive. The file it replaces moves to Old drafts.
- “What’s the latest protocol?” It returns the approved version, who signed it, and the file itself.
- Send an RFA. It extracts the funder, the deadline and the cap, and proposes the grant.
- “What needs me today?” That person’s tasks, approvals and deadlines. Nobody else’s.
- “Archive the ACG conference.” It checks with you first, then archives it.
Everything the lab runs on
The AI Lab Manager
Proactive: it acts before you ask, drafts the work, and asks before it commits.
Quality & Documents
Protocols, SOPs, manuscripts — versioned, approved, and auditable.
Grants & Bills
Every deadline and receipt, held and chased, in JHU's own format.
The meeting bot
It joins the call, transcribes on our own GPU, and emails you the minutes.
Ambient WhatsApp
Send a photo, or say “add this meeting.” It understands the thread.
The clock
Twelve scheduled jobs: reminders, digests, expiry escalation, nightly recall.
Your second brain
It remembers every decision, and why — so the lab never loses the thread.
Connectors
Drive, OneDrive and your calendar — built, waiting on a credential. We'll say so until they're on.
QMS & Documents
Controlled documents, risk-graded approval chains, 21 CFR signatures, training records and deviations — configured per project.
Finance
A photograph of a receipt becomes a filed expense, and a month becomes the Hopkins reimbursement workbook.
INTRO trial
Recruitment drawn from REDCap, drug inventory held, and expiry escalated at four, three, two and one month.
Literature
PubMed and the FDA’s eCFR, with every citation verified against the corpus it was retrieved from — deterministically, not by asking the model again.
Team & projects
Each member says what they are working on, and the people who need to know can see who is carrying what.
Reliability
2,976 automated tests gate every release. After it ships, a crash — or a scheduled job failing quietly — raises an alert instead of vanishing.
Provenance, not black boxes
The guarantees aren't marketing — they're enforced in code, tested, and structural. Here's how, exactly.
- The confirm gate
No unapproved write reaches the database
An architecture test forbids any module from holding an LLM call and a DB write together. Every write is a proposal, re-authorized at confirm time.
- Prompt-injection defense
Tool output is untrusted data, never instructions
External content is fenced as UNTRUSTED before the model sees it, per OWASP LLM01.
- Data-origin pinning
WhatsApp content never reaches a training provider
Sensitive origins are pinned to a non-training model and fail closed — no silent fallback.
- Tamper-evident audit
Hash-chained 21 CFR signatures
Every approval carries a printed name, a timestamp, and a meaning — chained so any later edit is made visible.
Run the lab like it's 2026.
Invitation-only, for the Akshintala Lab and the people it works with.