The Model Governance Record
A component of Closed-Loop Defensibility (CLD-SPEC-v1.0) — the file format carrying stages 2 to 5.
Clinical data has FHIR. Governance evidence has email threads. The MGR is an open, vendor-neutral JSON format for one model or agent's complete governed history — approval and baseline, monitoring entries, incidents, status transitions, the accountable human — portable between tools, auditable by anyone, yours rather than your vendor's.
The format
One MGR document per governed system. Four required blocks —
subject, accountability, approval
and the version marker — with monitoring, incidents, status history,
agent privileging (for systems that act) and optional hash-chain
integrity on top. The full JSON Schema:
mgr-v0.1.schema.json.
Reference implementations
A format nobody can emit from a deployment pipeline is a document, not a standard. Both reference implementations are open source, carry no runtime dependencies, and do the same three things: validate a record, build one, and seal or verify the hash chain over its dated entries.
| Package | Runtime | Install |
|---|---|---|
@healthcareai/mgr | Node, Deno, Bun, Cloudflare Workers, browser | npm i @healthcareai/mgr |
healthcareai-mgr | Python ≥ 3.10, standard library only | pip install healthcareai-mgr |
import { record, seal } from '@healthcareai/mgr';
const doc = record({
name: 'Sepsis early warning',
kind: 'predictive_model',
purpose: 'Flag deterioration risk on adult inpatients',
})
.ownedBy('A. Rivera', 'Chief Medical Information Officer')
.approved('2026-03-14', 'AI Oversight Committee',
{ metric: 'AUROC', value: 0.81, decay_threshold: 0.05 })
.monitored({ date: '2026-06-30', metric: 'AUROC', value: 0.79 })
.build(); // throws unless the record is complete
const sealed = await seal(doc); // adds integrity.head_hash Why two of them, held byte-identical
A record is only worth anything if it survives crossing an organisational boundary. A vendor emits one from a deployment pipeline — usually Python. A health system ingests it into whatever registry it keeps — often not Python. If the two disagree by a single byte about what a record serialises to, the receiving side computes a different hash and concludes the record was tampered with. That is the worst available failure for a format whose purpose is tamper-evidence, and it would be silent.
So the two are held compatible by test, not by intention: a suite
seals a record in each language, verifies it in the other, and asserts
both agree on which documents are invalid. Three specific divergences
had to be closed, and each would otherwise have broken verification
quietly — Python escapes non-ASCII where JavaScript does not, renders an
integral float as 1.0 where JavaScript renders 1,
and switches to exponential notation at a different magnitude
(1e+17 against 100000000000000000).
The integrity chain
Each dated entry is hashed together with its predecessor's digest, so altering, inserting, removing or reordering any entry changes every hash downstream of it:
head₀ = "genesis"
headₙ = sha256hex( headₙ₋₁ + "\n" + canonical(entryₙ) ) Verification returns three answers rather than two. A record whose
chain recomputes is true; one that does not is
false; and a record carrying no integrity block at all is
null — unverifiable. That third answer earns its place:
reporting an unsealed record as false would tell a surveyor
a record had been tampered with, when what actually happened is that
nobody sealed it.
Reference validator
Paste an MGR document below. This runs the published
@healthcareai/mgr package in your browser — the same code
path the SDK ships, not a re-implementation of it — so what you see here
is what your build pipeline will say. Nothing is transmitted.
For buyers: put it in the contract
Adoption is a procurement decision. The free Model Governance Rider is paste-ready contract language requiring a sealed, independently verifiable MGR at contracting and quarterly — one paragraph that turns governance claims into deliverables with a remedy.
For vendors: publish, seal, and let buyers verify
Publish your sealed MGR document at a public URL and give buyers one-click independent verification with the verify page and embeddable badge. Buyers check your record with the reference SDK, in their browser — the cheapest trust a vendor can offer, because it costs only honesty.
Licence and governance of the standard
MGR is published under CC BY 4.0: use it, implement it, extend it, commercially or otherwise, with attribution. Versioning is semantic; v0.x may change with notice, v1.0 will freeze required blocks. Proposals and implementations: write to the Institute. HAI-OS exports and imports MGR natively.
v0.1 is frozen, including its known gaps. Its schema
describes agent_privileging as required when
subject.kind is agent, but expresses no
conditional that enforces it. Both SDKs therefore report that case as a
warning and leave the document valid, rather than rejecting what the
published schema accepts — a standard that changes meaning under a fixed
version number is not a standard. It is carried to v0.2.
The format records what an organisation decided and observed. It carries no score, grade, ranking or pass/fail, and a complete MGR document describing a model that performs poorly is a good MGR document. Any consumer deriving a rating from these fields is doing something the format does not authorise.