The Workforce Side

The workforce side of the same spine.

A staffing plan is a promise to the bedside, and the data behind it is people's work lives. Nightingale OS runs both sides on one spine: staffing operations derived from the shift records the hospital already publishes — and a worker-data boundary that treats worker data as the workers', with a frozen purpose allowlist and a privacy floor the software cannot talk its way past.

Staffing Operations

Built from the records you already publish.

The staffing operations surface runs on shift records, acuity data, and published staffing plans — not on an integration project. No EHR integration required.

Hours per patient day, tied to outcomes

The staffing-outcome link correlates staffing levels with patient outcomes, and the outcome correlator keeps that calibration honest — staffing decisions with their evidence attached, not staffing decisions with a vibe attached.

Staffing mix and skill match

The staffing-mix and skill-mix-matcher surfaces show the composition of every shift — who is actually on the floor, by role and competency — and the acuity-based staffing surface weighs the mix against the patients actually there.

Acuity-fit assignment

The acuity-fit weaver and patient-acuity assignment surface connect measured patient acuity to assignment, with the fit between experience and acuity made explicit rather than absorbed into tradition.

Surge, with the waiver line drawn

Surge staffing ratios evaluate flexing options against the state's real rules — and in no-waiver jurisdictions the software refuses to treat a waiver as available (SURGE_001, surgeStaffingRatios.js). The line is drawn in code, not in a policy binder.

Worker Data Governance

Worker data is the workers'.

Analytics about workers are where hospital software goes to misbehave — wellness dashboards becoming surveillance, "engagement scores" becoming discipline. Nightingale OS draws the boundary in code: manager-facing worker aggregates pass through a governance gate with a frozen allowlist of purposes and a privacy floor, and uses outside the allowlist are refused with a citation to the Worker Bill of Rights.

4 allowed purposes
frozen allowlist — new purposes require labor + ethics co-sign
flockBoundaryGate.js ALLOWED_MANAGER_PURPOSES: workforce-planning, education-coverage, retention-research, accreditation-evidence (verified 2026-09-25). Any other purpose is refused FLOCK_BOUND_001.
k ≥ 5
the privacy floor for manager aggregates
K_FLOOR = 5 with ℓ-diversity ≥ 2 and t-closeness ≤ 0.2 (flockBoundaryGate.js exports, verified 2026-09-25). Smaller groups are suppressed, not approximated.
Individual rows, refused
aggregates only, and never re-identified
The gate refuses manager requests for individual worker rows and cross-worker queries (REFUSAL_MANAGER_INDIVIDUAL_ROW, REFUSAL_CROSS_STAFF_QUERY) — an aggregate that re-identifies is not an aggregate.
116 Flock bundles
78 surfaced to the client today
Feature-catalogue family "Flock (worker governance)": 116 bundles, 78 client-surfaced (catalogue snapshot, verified 2026-09-28).

The four purposes, verbatim. workforce-planning — aggregate shift-trade demand patterns; education-coverage — aggregate microlearning completion per unit; retention-research — aggregate staff-survey engagement; accreditation-evidence — aggregate competency completion for Magnet/Pathway packages. Each carries an explicit never-to-identify constraint in the source. Purposes beyond the four are refused until labor and ethics co-sign the addition.

Status Honesty

What's surfaced, and what isn't yet.

The same honesty the product applies to its own surfaces applies here. Of the staffing-and-scheduling family, the catalogue counts 112 bundles with 99 surfaced to the client — and the gaps are named, not rounded away.

pbj-loader — UNSURFACED

The CMS Payroll-Based Journal staffing-mix loader is built and ingests PBJ data, but has no client screen yet — so it is not presented here as one.

workforce-forecast — UNWIRED

The workforce forecast service exists in the codebase but is not wired to a surface. When it ships, it ships with its receipt.

contract-labor-optimizer — UNSURFACED

Contract-labor optimization logic is built but not client-surfaced. The rest of the family — assignment, acuity, surge, mix — is surfaced and shown in product demos.

One spine for the plan and the people in it.

Staffing operations, the compliance wedge, and the worker-data boundary are part of Nightingale OS — the evidence layer for governed hospital AI, built, led, and owned by nurses.

Runs on shift records the hospital already publishes and its own acuity data. No EHR integration required.