HARROW.
A payer's record of itself lives in fragments, spread across other people's systems.
Claims history sits with one vendor, eligibility with another, prior years with a TPA whose contract has ended. Each extract is partial, each schema different, and where they overlap they disagree. HARROW is the record the payer owns: it reconciles those fragments inside a boundary the payer or its sponsor controls, over the systems already running, and where the sources disagree it says so rather than choosing for you. Every value carries the evidence that produced it.
Human judgment. Deterministic machine. No model in between.
The lost record, in eight frames.
Where the fragments live, how the layer reconciles them, and what a value looks like when it can prove where it came from.
Every reconciliation reduces to three questions.
Is this the same patient? Do these records conflict? Which source is more reliable?
The refinery answers each one with evidence, and records the honest fourth outcome: where the evidence is insufficient, the answer is insufficient evidence, not a guess.
Is this the same patient?
Matches are made by named rules over declared keys and crosswalks, and every match names the rule that made it. Low-confidence matches are quarantined for human review. Nothing is silently merged.
Do these records conflict?
Disagreement is shown, not smoothed. Competing values stay side by side with the sources that carried them, and a defined contradiction is a recorded finding, not noise to average away.
Which source is more reliable?
Reliability is a judgment about your own sources, and the machine does not make it for you. Where sources disagree, every competing value stays on the record beside the source and the row that carried it, and the finding routes to the people who own that call. What the machine guarantees is that the disagreement reaches them intact.
The result is one envelope, one verification algorithm, and one reconciled record in which every competing value is preserved beside the others, with nothing resolved silently.
The answer is evidence, not an assertion.
Every value in the reconciled record walks back to the rule that produced it, the raw source bytes it came from, and a hash over those bytes. Where no rule can decide between sources, the record carries the disagreement instead of an answer. The walk works in both directions: from a value down to the row it started as, or from a source file up to every value it touched.
And the chain recomputes. Re-run the reconciliation on the same declared inputs and the same values, the same receipts, and the same hashes come back, byte for byte. A reviewer does not have to take the record's word for anything; they can re-derive it.
One finding from a synthetic exhibit: three sources describing one member, disagreeing on one field, with no winner invented.
Nothing migrated. Nothing replaced. Nothing turned off.
Our differentiator isn't the engine: it's where we sit and what we unlock.
Vendor outputs enter the layer as evidence. Nothing displaces them, nothing corrects them in place, and the systems that produced them keep running exactly as they do today. They simply perform better on reconciled data.
Deployment sits inside a boundary the payer or its sponsor controls. The layer refuses to take custody of the data: it operates where the data already lives, and what leaves the boundary is evidence, on the owner's terms.
Enabling payers to meet their own obligations. The record a payer is asked to produce, for a regulator, a sponsor, or its own teams, becomes a record it can produce itself, from its own boundary, with the evidence attached.
The machine decides structure; people decide everything else. Unresolved exceptions route to human review with the machine evidence preserved beside them, never overwritten by the reviewer's call.
Deterministic outputs, built to be checked.
Receipts
Subject-first: each receipt names its subject, the competing values, the sources that carried them, and one of four evidence states: SUPPORTS, DOES_NOT_SUPPORT, INSUFFICIENT_EVIDENCE, NOT_ASSESSED. The fourth state means what it says: outside the run's declared scope, and marked so.
Evidence memo
A fixed PDF document stating what was reconciled, under which declared sources and rules, with findings and their receipts. Deterministic: the same inputs produce the same bytes, so the memo a reviewer holds is one they can re-derive.
Universe workbook
An XLSX carrying every row in scope, including quarantined and refused rows. Coverage totals keep the hard rows in the denominator: a clean result can never be produced by dropping them out of it.
Replay and verification
Every run emits a replay manifest: pinned versions and hashed inputs. Re-running reproduces the result hashes exactly, and tampering with one input file makes verification fail naming that file.
Screens and checks ship as packs the layer can emit over the reconciled record; each pack declares its scope and states what it did not assess.
The layer proves where a value came from and which rule produced it. It does not certify a value as clinically true, does not judge medical necessity, does not predict any audit outcome, and does not compute a compliance verdict. Where the evidence is insufficient, it says so instead of answering.
The fragments already exist. The vendors already run. What is missing is the record the payer owns.