Platform for Research & Internal Systems Management · Johns Hopkins

P.R.I.S.M is your
lab manager.

Akshintala Lab & Johns HopkinsBuilt by Richu Ravikumar
Orchestrated intelligence

Look inside the brain

Not a chatbot on a tracker. A production multi-agent runtime: it perceives across four channels, routes to the right model, reasons over a permissioned memory, weighs what's worth surfacing, and turns intent into a reviewable proposal. A clock of scheduled jobs drives it while nobody is asking. Every write is gated. Nodes drawn dashed are built and waiting on a credential — we'd rather show you the machine than a flattering half of it.

PRISM's runtime, end to endFour channels — WhatsApp, the web app, the meeting bot, and photographs or PDFs read by vision — enter through a fail-closed PHI gate and a model router into the Orchestrator, which reasons with the Judge, an adversarial Reviewer, a permissioned memory vault, and a risk-tiered tool registry. Nothing writes without passing the confirm gate into the record, where document control, hash-chained signatures and the sourced, bitemporal fact graph live. A clock of scheduled jobs — the hourly proactivity sweep, reminders, drug-expiry escalation, the five-minute transcript poll, nightly memory consolidation, and the error watch — drives the runtime on its own. The record mirrors outward to email and to the lab's Google Drive. Nodes and connectors drawn dashed and marked NEXT are built but not switched on: the agent audit chain, OneDrive, and calendar sync.CHANNELSTHE RUNTIMETHE RECORDTHE CLOCKCONNECTED SYSTEMScorefaudio → textvisionevery inboundcleanplan · reasonproposalapprovedprev_hashhourly · nightly · */5m5xx → alertsendPRISM/<project>/WhatsApp1:1 · group · @prismWeb app⌘K reaches anythingMeeting botzoom · meetPhoto · PDFvision extractPHI gatefail-closedModel routergemini ⇄ openaiOrchestratorplan · reason · executeJudgeurgency · worth · confRevieweradversarial checkMemory vault4 classes · nightlyTool registryrisk-tiered · gatedConfirm gateyou approveThe recordpostgres · RLSDocument controldraft → activeSignatures21 CFR · hash-chainedAgent auditsaw → executedFact graphsource · conf · as_ofSweep6 monitors · hourlyRemindersbills · deadlines · grantsTranscript poll*/5 min · minutesDrug expiry4 · 3 · 2 · 1 monthsConsolidationnightly · pgvectorError watchsentry · 5xx + throwsEmail outdigests · minutesGoogle Drivedrive.file scopeOneDriveapp-only graphNEXTCalendargoogle · outlookNEXT
ChannelsWhatsApp, the app, a bot in your meeting, a photographPHI gatefail-closed, before any model reads a word of itOrchestratorplans, delegates to workers, reviews itselfThe clock12 scheduled jobs — it works while nobody is askingConfirm gatenothing reaches the record without youDashed · NEXTbuilt, not switched on — and we won't pretend otherwise
Automation Live

Twelve jobs run the lab’s clock.

It is working when nobody is asking it anything.

Hourly

The proactivity sweep

Six monitors read the lab, score what they find, and almost always decide it can wait.

Daily

Deadline sweep

Tasks, grants and abstracts — you hear about the date before it passes, not after.

Daily

Auto-retirement

A grant or a conference retires itself the day after its deadline. A new date brings it back.

Daily

Bills, chased

What is due or overdue gets an email, and a recurring bill materializes its own next occurrence.

Weekly

The trial

INTRO’s recruitment digest, drawn from REDCap. Drug-expiry alerts escalate at four, three, two and one month.

Every 5 min

Transcript poll

The finished meeting transcript is pulled the moment it is ready, and becomes the minutes.

1,964signals scored
1,932suppressed
32raised as a question
0acted on unasked

Measured in production, not asserted. It reads everything and interrupts almost never — and every interruption it did raise was a question, never a fait accompli. The jobs also watch themselves: all twelve report their own failure, so a scheduled job that starts returning 500 into the void raises an alert instead of vanishing.

Custom pipeline · live

Send a bot to the meeting you can't attend.

Ask in the app or over WhatsApp. PRISM sends a bot into the Zoom or Meet call, transcribes it on a GPU we run — the audio never reaches a transcription vendor, because we didn't hire one — pulls the finished transcript, extracts the summary, the decisions and the action items, files them, and emails them to you. The action items stop there and wait: an LLM reading a noisy multi-speaker room is not allowed to create a task in this system. You promote the ones that are right.

How PRISM's meeting bot worksYou ask PRISM — in the app or over WhatsApp — to send the bot to a meeting. PRISM dispatches it into the Zoom or Meet call, where it joins as PRISM Copilot and records. The audio is transcribed by Whisper large-v3-turbo on a GPU we run; it is never sent to a transcription vendor. A cron polls every five minutes for the finished transcript, extracts the minutes in a single strict-JSON call, and then files three things: the saved minutes, an email to whoever sent the bot, and action items that wait for a human to approve before they become tasks.ON HARDWARE WE RUN · NOTHING LEAVES THIS BOXaudio → text, on-device · no vendor, no uploadplatform + native idtranscriptcomplete?summary · decisions · action items01The ask“send the bot to my 3pm”02DispatchPOST /bots · id + passcode03It joinsas “PRISM Copilot”04It listenswhisper large-v3-turbo05The pollcron · every 5 minutes06The minutesstrict JSON · one callAction itemswait for a humanEmailed to youwhoever sent the botSaved minutessummary · decisions
Quality management Live

Every project runs its own QMS.

Protocols, SOPs, manuscripts and experiment records — versioned, risk-graded, approved and signed. Each project sets its own document types, its own lifecycle and its own approval chain.

Lifecycle

Draft → Approved → Active → Superseded

Each document type carries its own lifecycle — and each project decides which document types it has.

Versions

Nothing is ever deleted

A new version supersedes the current one, and the file it replaces moves to Old drafts.

Risk grade

The grade sets the chain

A protocol is graded first, and the grade decides how heavy its approval chain is. You see the chain before you click, not after.

Signature

21 CFR Part 11

Printed name, timestamp, meaning — hash-chained to the signature before it.

Training

Competency, per version

A major revision assigns retraining. A typo correction does not — a QMS that cries wolf is one the lab learns to ignore.

Deviations

Raised, routed, signed closed

A departure from protocol is recorded and reviewed, and the last signature IS the closure. There is no separate close button.

Enforced, not asserted. A version is immutable by database trigger: its content hash, its label and its date cannot change. Once it is approved, its risk grade freezes too — that grade is what the signatures were given under, and re-grading the protocol next year cannot rewrite what this year’s signatures meant.

The data room Live

Everything lands in the lab’s own Drive.

Filed where a person would have filed it — and PRISM only ever sees what it put there.

PRISM/
  • <Project>/<Doc type>/protocols · SOPs · manuscripts · experiment records
    • Old drafts/the version it replaced — moved, never deleted
  • Bills/2026-07/receipts and card statements, by the month they were handed in
  • Meetings/2026-07/meeting audio, by month
  • Scoped credential

    It can only see the files it made

    PRISM holds a drive.file credential, so the lab’s existing Drive is invisible to it. That is not a policy we promise to keep — it is the only scope it was granted.

  • The record

    Drive holds the file. PRISM holds the record.

    Drive purges its own revision history after about thirty days. The version, the hash, the approval and the signature live in the database, which does not.

  • Reach

    No reader needs a Google account

    Files stream back out through PRISM, under PRISM’s permissions — so what someone may open is decided in one place, not in a share dialog.

prism-lab.online⌘K
P.R.I.S.M

Good morning — 3 things need you

Grants · due ≤ 14d
2
Docs awaiting sign-off
5
Bills to file
4
Meetings this week
6
PRISM · Copilot⌘B
YouAdd the endoscopy invoice to the R01 budget.
PRISMOlympus, $4,212.50 — approve to file it?
The platform

Everything the lab runs on

01

The AI Lab Manager

Proactive: it acts before you ask, drafts the work, and asks before it commits.

02

Quality & Documents

Protocols, SOPs, manuscripts — versioned, approved, and auditable.

03

Grants & Bills

Every deadline and receipt, held and chased, in JHU's own format.

04

The meeting bot

It joins the call, transcribes on our own GPU, and emails you the minutes.

05

Ambient WhatsApp

Send a photo, or say “add this meeting.” It understands the thread.

06

The clock

Twelve scheduled jobs: reminders, digests, expiry escalation, nightly recall.

07

Your second brain

It remembers every decision, and why — so the lab never loses the thread.

08

Connectors

Drive, OneDrive and your calendar — built, waiting on a credential. We'll say so until they're on.

09

QMS & Documents

Controlled documents, risk-graded approval chains, 21 CFR signatures, training records and deviations — configured per project.

10

Finance

A photograph of a receipt becomes a filed expense, and a month becomes the Hopkins reimbursement workbook.

11

INTRO trial

Recruitment drawn from REDCap, drug inventory held, and expiry escalated at four, three, two and one month.

12

Literature

PubMed and the FDA’s eCFR, with every citation verified against the corpus it was retrieved from — deterministically, not by asking the model again.

13

Team & projects

Each member says what they are working on, and the people who need to know can see who is carrying what.

14

Reliability

2,976 automated tests gate every release. After it ships, a crash — or a scheduled job failing quietly — raises an alert instead of vanishing.

Security & engineering

Provenance, not black boxes

The guarantees aren't marketing — they're enforced in code, tested, and structural. Here's how, exactly.

  • The confirm gate

    No unapproved write reaches the database

    An architecture test forbids any module from holding an LLM call and a DB write together. Every write is a proposal, re-authorized at confirm time.

  • Prompt-injection defense

    Tool output is untrusted data, never instructions

    External content is fenced as UNTRUSTED before the model sees it, per OWASP LLM01.

  • Data-origin pinning

    WhatsApp content never reaches a training provider

    Sensitive origins are pinned to a non-training model and fail closed — no silent fallback.

  • Tamper-evident audit

    Hash-chained 21 CFR signatures

    Every approval carries a printed name, a timestamp, and a meaning — chained so any later edit is made visible.

Confirm gate · TOCTOU-safe

Six checks before a write executes

Each confirm is an independent request that re-verifies everything.

propose → ownership re-check → role re-derive from session → MFA step-up (AAL2) if high-risk → atomic CLAIM (no double-run) → execute with re-auth → append to hash chain
Isolation · Postgres RLS

Every row scoped to a workspace

Row-Level Security guards direct access; service-role writes run only server-side.

select * from document where workspace_id = auth.workspace() -- RLS: cross-workspace read → 0 rows
Signatures · hash chain

decisionHash links each approval

The signature triple is inside the hash; tampering breaks every link after it.

hash = sha256( prev_hash ∥ step ∥ role ∥ user ∥ decision ∥ name ∥ time ∥ meaning )
Model routing · fail-closed

The right brain for the job

Gemini by default; OpenAI for sensitive origins. If the required provider is unavailable, it refuses.

if origin == "whatsapp": require(nonTrainingProvider) # or refuse

Run the lab like it's 2026.

Invitation-only, for the Akshintala Lab and the people it works with.

Sign in →Request accessDownload for Windows or Android