commvita
Connected care platform
EPRR & Resilience

Running an incident, keeping services going — one spine from first alert to stood-down

A demo reference for commvita's Emergency Preparedness, Resilience & Response module — the incident-management spine that carries an event through Gold/Silver/Bronze command, a one-tap escalation ladder, JESIP & METHANE, a running loggist and business-continuity activation — every decision landing in an append-only, hash-verified log.

Live vs demonstrated: Live — real, API-backed platform logic (wired end-to-end today) Demonstrated — representative control surface with seeded data / illustrative UI mock-up

Three things the spine has to do

EPRR is not a document folder — it is a live operating surface. Coordinate the response, structure the communication, and keep the critical functions running while it all happens. commvita does all three in one place at /eprr.

Coordinate the response

Gold / Silver / Bronze command · who's-on-call · escalation

A command dashboard with the system-pressure OPEL tile, open actions and the on-call rota, plus a one-tap escalation ladder — every step recording who / when / why to an immutable decision log. Declare a Major Incident and hand off cleanly.

Where in commvita /eprr · Coordination · /eprr · Incidents & Escalation · /major-incident

Structure the communication

JESIP · METHANE · loggist · multi-channel dispatch

The JESIP five-principles joint-decision log and a METHANE message builder that composes and records the structured major-incident message. Dispatch via SMS / WhatsApp / Microsoft Teams — every message logged to the incident's running loggist.

Where in commvita /eprr · JESIP & METHANE · /eprr · Comms & Loggist · /sms/send

Keep services running

Business continuity · RTO/RPO · assurance

A critical-function RTO/RPO register you can activate against a live incident — the activation written to the loggist. Plus a jurisdiction-aware core-standards self-assessment, plans library and exercise programme.

Where in commvita /eprr · Business Continuity · /eprr · Assurance · /eprr/bcp

1 Coordinate — command, on-call & one-tap escalation

Every incident opens on a coordination surface: who holds command, what the system pressure is, what actions are open — and a single control to escalate up the chain, recording the decision as it happens.

1

Gold / Silver / Bronze command dashboard

Strategic (Gold), tactical (Silver) and operational (Bronze) command are shown side by side with the current holder, the who's-on-call rota and the live system-pressure OPEL tile — so the room knows who owns the decision the moment it is needed.

/eprr · CoordinationGold/Silver/BronzeEPRROnCallRota
2

One-tap escalation ladder

A single control walks the incident up the ladder — Duty officer → Manager on-call → Director/Exec on-call → Bronze → Silver → Gold. Each escalation captures who escalated, when, and why against the incident.

/eprr/escalation-ladder/eprr/escalationsEPRREscalationEvent
3

Recorded to an append-only decision log

Every escalation event is written to an append-only record — EPRREscalationEvent — so the rationale for going up a tier can never be quietly rewritten after the fact. Declaring a Major Incident hands off to /major-incident.

EPRREscalationEvent (append-only)/major-incident
4

On-call & command — click-to-contact

The rota carries the tier, the person and their preferred channel, with click-to-contact — and links the integrated OPEL assessment from On-Call Manager so operational pressure and command are on one view.

/eprr · On-Call & Command/oncall-manager/eprr/rota
EPRR Hub / Coordination Silver commander
OPEL 3
System pressure — OPEL 3
Acute · CHS · MH contributing · NHS 111 standalone · assessed 10:00
Gold — strategic
Dr A. Fenwick
Director on-call · stood up 09:48
Silver — tactical
J. Marsh
Ops manager · holding now
Bronze — operational
Site team
Ward & flow leads
One-tap escalation ladder
Duty officer Manager on-call Director / Exec on-call Bronze Silver Gold
Each step records who / when / why to the append-only decision log.
Open actions
7 · 2 overdue
On-call now
K. Osei · preferred: Teams
Escalate to Gold Declare Major Incident
Representative UI — illustrative
Escalation is a recorded decision, not a phone call. The one-tap ladder writes who escalated, when and why to an append-only EPRREscalationEvent log — so a post-incident review, board or regulator can reconstruct exactly how command moved through the tiers. There is no route to edit or delete an escalation after it is logged.

2 Communicate — JESIP, METHANE & the loggist

A response fails on communication before it fails on anything else. The spine structures the joint decisions, composes the standard major-incident message, and logs every dispatch to a single running record.

JESIP five-principles joint-decision log

Each joint decision is recorded against the five JESIP principles — co-locate · communicate · co-ordinate · jointly understand risk · shared situational awareness — giving a defensible record of multi-agency working.

/eprr/jesip/eprr/jesip-principlesEPRRJesipDecision

METHANE message builder

A structured builder composes and records the METHANE message — Major incident declared? · Exact location · Type · Hazards · Access · Number of casualties · Emergency services — then hands it to Comms for dispatch, so nothing is improvised under pressure.

/eprr/methaneEPRRMethaneMessageMETHANE · CSCATTT

Multi-channel dispatch — every message logged

Dispatch via text (SMS) / WhatsApp / Microsoft Teams; every dispatch is written to the incident. In the demo, comms transport is queued and logged; production routes SMS/WhatsApp via /sms/send and Teams via webhook.

/eprr/comms-dispatchEPRRCommsDispatchSMS Gateway · Comms CRM

Running loggist — decision / action / info

A chronological loggist records decision, action and information entries with owner and status — the single source of truth for what happened and when.

/eprr · Comms & Loggist/eprr/logEPRRLogEntry
EPRR Hub / JESIP & METHANE / METHANE message builder loggist
Yes — declared 09:41 by Gold
Ring road / Junction 7 · grid SU 412 987
Multi-vehicle RTC · mass casualty
Fuel spill · unstable vehicles
RVP north approach · south road closed
≈ 14 · P1 ×3 · P2 ×6 · P3 ×5
Ambulance · Fire · Police on scene · HART requested
Record & hand to Comms Save draft
METHANE recorded & handed to Comms — dispatched via Teams + SMS · written to the incident loggist. logged
Representative UI — illustrative

3 Keep services running — business continuity

While the incident is being run, the critical functions still have to work. The BCP register makes the recovery targets explicit and lets you activate a plan against the live incident, with the activation written to the loggist.

1

Critical-function RTO/RPO register

Each critical function carries its Recovery Time Objective and Recovery Point Objective — so "how long can this be down, and how much data can we lose" is answered in advance, not argued mid-incident.

/eprr · Business ContinuityEPRRBCPEntryRTO / RPO
2

Activate a BCP against a live incident

One control activates the plan for a function against the current incident — /eprr/bcp/{id}/activate — and the activation is written straight to the incident loggist so the response and the continuity decision are on one timeline.

/eprr/bcp/{id}/activateEPRRLogEntry
3

Assurance — jurisdiction-aware self-assessment

A core-standards self-assessment, plans library and exercise programme — with the framing resolved per jurisdiction (see below), so the assurance evidence always speaks the right language for the deployment.

/eprr · Assurance/eprr/frameworkEPRRPlan
EPRR Hub / Business Continuity — critical functions Silver commander
Critical functionRTORPOStatus
EPR / clinical record1 hr15 min degraded Activate BCP
Pathology / lab results4 hr1 hr at risk Activate BCP
Telephony / switchboard30 min0 running Activate BCP
BCP activated — EPR / clinical record · downtime proforma in use · written to incident loggist. /eprr/bcp/{id}/activate
Escalation decision log — latest row
Silver → Gold 09 Jul 2026 · 09:48 J. Marsh · EPR degraded beyond RTO — strategic decision required chain verified ✓
Representative UI — illustrative

4 Jurisdiction-aware framing — fail-safe to generic

EPRR is enabled for every jurisdiction, but the assurance language is resolved to fit the deployment — and it never borrows the wrong nation's branding.

NHS-nation framing — the right nation only

England, Scotland and Wales each get their own NHS-nation resilience framing — the resolver _eprr_framework never applies "NHS England" to the wrong nation.

/eprr/frameworkNHS England EPRR Core Standards concepts

Neutral best-practice framing — no NHS branding

Crown Dependencies (Guernsey · Isle of Man), Gibraltar, the Caribbean (Jamaica · Antigua · Montserrat), Kenya and Oman get neutral best-practice framing with no NHS branding.

jurisdiction-aware resolver

Fail-safe — generic, never NHS England

An unknown or unmapped jurisdiction fails safe to generic framing — never to another jurisdiction's NHS branding. The module stays enabled; only the language adapts.

fail-safe → genericJESIP · CSCATTT · Gold/Silver/Bronze (universal)

Where it lives in commvita

Coordinatecommand · OPEL → Escalateone-tap ladder → CommunicateJESIP · METHANE · dispatch → Continueactivate BCP → Immutable decision log
CapabilityTab / RouteModel / APIStandardStatus
Command & system pressureCoordination · /eprrOPEL tile · open actions · rotaGold/Silver/Bronze command● Live
One-tap escalation ladderIncidents & Escalation · /eprr/escalationsEPRREscalationEvent (append-only) · /eprr/escalation-ladderwho / when / why decision log● Live
Declare Major Incident/major-incidentEPRRIncident · handoffMETHANE · CSCATTT● Live
On-call & command rotaOn-Call & Command · /eprr/rotaEPRROnCallRota · /oncall-managertier · preferred channel● Live
JESIP joint-decision logJESIP & METHANE · /eprr/jesipEPRRJesipDecision · /eprr/jesip-principlesJESIP five principles● Live
METHANE message builderJESIP & METHANE · /eprr/methaneEPRRMethaneMessageMETHANE structured message● Live
Running loggistComms & Loggist · /eprr/logEPRRLogEntrydecision / action / info● Live
Multi-channel comms dispatchComms & Loggist · /eprr/comms-dispatchEPRRCommsDispatch · /sms/send · Teams webhookSMS · WhatsApp · Teams◍ Demonstrated
Business-continuity registerBusiness Continuity · /eprr/bcpEPRRBCPEntry · RTO / RPOISO 22301 concepts● Live
Activate BCP against incident/eprr/bcp/{id}/activatewrites to loggistcontinuity activation● Live
Assurance & framework resolverAssurance · /eprr/frameworkEPRRPlan · _eprr_frameworkjurisdiction-aware · fail-safe● Live

Status key. ● Live — API-backed today: /eprr/ plus the append-only escalation decision log. ◍ Demonstrated — comms dispatch transport (SMS / WhatsApp / Teams) is queued and logged in the demo; production routes SMS/WhatsApp via /sms/send and Teams via webhook.

© 2026 Commvita Digital Health Solutions Ltd. All rights reserved. NHS England EPRR Core Standards conceptsJESIPMETHANECSCATTT Gold / Silver / Bronze commandISO 22301 business continuity conceptsNon-SaMD EPRR control surface