Vertical AI systems · Public reference implementation · Azure Dev validated

Healthcare AI Platform · Azure

An Azure-native safety and evaluation reference architecture combining a Python healthcare runtime, React Workbench, authenticated cloud execution, durable orchestration, persistent state and evidence, independent safety validation and structured observability.

MaturityPublic ARMIE AI engineering reference system · Phase complete
Confirmed baselinePython runtime + React Workbench + authenticated Azure Dev execution
Current validationDurable orchestration, Cosmos/ADLS persistence, identity, reliability and observability
Model planeOpenAI Platform · GPT 5.6 integration validated
Current engineering state

An authenticated, durable Azure runtime with validated model integration.

The Healthcare runtime executes through a React Workbench and authenticated Azure Dev path with Durable Functions orchestration, persistent operational state, evidence artifacts, structured observability and a validated OpenAI Platform GPT 5.6 path. The system remains a synthetic engineering reference implementation, not a production or clinical deployment.

Runtime statusAzure Dev runtime validated

Authentication, durable orchestration, Cosmos/ADLS persistence and Workbench integration are verified with synthetic data.

Cloud model planeOpenAI Platform · GPT 5.6 validated

The GPT 5.6 model path is connected to the OpenAI Platform and verified in the current Azure Dev runtime.

Evidence boundarySynthetic and non-clinical

Public evidence covers implemented engineering paths, synthetic data and repository-backed verification.

Why this exists

This project explores how a local healthcare reasoning pipeline can become an observable, authenticated, durable and cloud-operable AI system without moving core context, retrieval, validation or workflow semantics into a model vendor. It is a reference architecture for engineering patterns, not a healthcare chatbot, clinical product or source of medical advice.

Ownership principle. Model providers remain replaceable while healthcare context, retrieval, safety validation, persistence and workflow semantics remain owned by the ARMIE runtime.

System architecture

React Workbench operator and evaluation surface
↓
Microsoft Entra / MSAL authenticated user path
↓
Azure Functions + Easy Auth protected cloud boundary
↓
Azure Durable Functions recoverable workflow orchestration
↓
RunExecutionService stable business run semantics
↓
Healthcare Python Runtime context · retrieval · reasoning provider · independent safety validator
Cosmos DBoperational and business run state
ADLS Gen2evidence, traces and larger artifacts
Application Insights / structured traces execution observability
Durable Functions owns recoverable workflow execution.Cosmos DB owns operational/business truth.ADLS owns evidence/artifact truth.

Engineering evolution

Architecture prototype→Observable runtime→Local Workbench→Azure runtime→Persistent data plane→Entra authentication→Durable reliability→Model-plane architecture

Durable workflow & reliability

01Recoverable orchestration

Durable Functions coordinates long-running execution, bounded retry, timers, cancellation and replay/recovery.

02Terminal ownership

Cosmos-backed ETag/CAS concurrency prevents conflicting terminal outcomes.

03Idempotency

Stable business run_id and idempotency-key semantics prevent accidental duplicate workflow creation.

04Race-safe outcomes

Success, timeout and cancellation are competing terminal events; the Workbench preserves backend truth.

Persistent state & evidence

Cosmos DBQueryable operational and business run state

Run identity, lifecycle, requested/executed reasoning mode, validation and persistence status, orchestration correlation, attempts and terminal ownership.

ADLS Gen2Evidence, traces and larger run artifacts

Retrieved evidence, structured traces, result artifacts and evaluation/safety artifacts remain durable and auditable.

Function compute remains replaceable while operational state and evidence remain durable and auditable.

Identity & security architecture

Authenticated user→Workbench→Azure Functions / Easy Auth→Function Managed Identity→Azure services

Implemented Azure Dev boundaries include Microsoft Entra single-tenant identities, Easy Auth-protected run endpoints, a browser MSAL path for the Workbench, system-assigned Managed Identity and narrow Cosmos/ADLS data-plane access. The project uses synthetic/demo data only; no HIPAA, GDPR, PHI or other regulatory certification is claimed.

Safety & evaluation

Independent safety validation

Safety checks execute as an explicit boundary after reasoning rather than being delegated to the reasoning model.

Deterministic regression path

Rule-based reasoning provides repeatable CI and characterization behavior.

Evidence-aware execution

Retrieved evidence, reasoning provenance and execution traces remain inspectable.

Non-clinical evidence

Synthetic data and repository-backed scenarios support engineering evaluation, not clinical efficacy or safety benchmarking.

An operator and evaluation surface for the runtime.

The React/Vite Workbench is a projection of backend runtime truth, not a second implementation of healthcare business logic. It supports local FastAPI and authenticated Azure Dev backends, synchronous and Durable execution, run/orchestration identifiers, lifecycle projection, attempt and persistence state, cancellation control and explicit terminal outcomes.

Model provider strategy

ruleDeterministic baseline / CI
local_llmLocal Ollama / Qwen experimentation
openaiOpenAI Platform · GPT 5.6 integration validated
Cloud model-plane status. The GPT 5.6 model path is connected to the OpenAI Platform and has been validated in the current Azure Dev runtime.

Confirmed capabilities

Python runtime ownership

Healthcare context, retrieval, reasoning integration and validation remain in the ARMIE runtime.

React Workbench

Inspectable local and authenticated Azure Dev execution surface.

Azure Functions boundary

Serverless authenticated API/runtime boundary for synthetic Azure Dev execution.

Durable orchestration

Recoverable workflow execution with retry, timeout and cancellation semantics.

Persistent operational state

Cosmos DB stores queryable run and terminal-state truth.

Evidence / artifact persistence

ADLS Gen2 stores traces, evidence and larger run artifacts.

Identity & least privilege

Entra, Easy Auth and Managed Identity define user/service boundaries.

Distributed reliability

Idempotency, concurrency and terminal ownership are explicit system semantics.

Independent safety validation

Safety remains a separate validation boundary after reasoning.

Structured observability

Application Insights and structured traces expose runtime behavior.

Provider independence

Rule and local LLM paths remain available while the cloud provider remains replaceable.

Current scope and maturity

This is an ARMIE AI synthetic, non-clinical engineering reference system. Azure Dev infrastructure, authenticated execution, Durable Functions orchestration, Cosmos DB and ADLS persistence, Workbench integration, Managed Identity, structured observability and the OpenAI Platform GPT 5.6 path have been implemented and validated with synthetic data.

It is not a production healthcare deployment, hospital system, diagnostic or prescribing product, regulated medical device or compliance-certified application. No PHI processing, production SLA or clinical safety benchmark is claimed.

Related infrastructure

Vertical systems can share control patterns without becoming one claimed production platform.

Explore Construction Intelligence ↗