A demo reference for commvita's Emergency Preparedness, Resilience & Response module — the incident-management spine that carries an event through Gold/Silver/Bronze command, a one-tap escalation ladder, JESIP & METHANE, a running loggist and business-continuity activation — every decision landing in an append-only, hash-verified log.
EPRR is not a document folder — it is a live operating surface. Coordinate the response, structure the communication, and keep the critical functions running while it all happens. commvita does all three in one place at /eprr.
A command dashboard with the system-pressure OPEL tile, open actions and the on-call rota, plus a one-tap escalation ladder — every step recording who / when / why to an immutable decision log. Declare a Major Incident and hand off cleanly.
The JESIP five-principles joint-decision log and a METHANE message builder that composes and records the structured major-incident message. Dispatch via SMS / WhatsApp / Microsoft Teams — every message logged to the incident's running loggist.
A critical-function RTO/RPO register you can activate against a live incident — the activation written to the loggist. Plus a jurisdiction-aware core-standards self-assessment, plans library and exercise programme.
Every incident opens on a coordination surface: who holds command, what the system pressure is, what actions are open — and a single control to escalate up the chain, recording the decision as it happens.
Strategic (Gold), tactical (Silver) and operational (Bronze) command are shown side by side with the current holder, the who's-on-call rota and the live system-pressure OPEL tile — so the room knows who owns the decision the moment it is needed.
A single control walks the incident up the ladder — Duty officer → Manager on-call → Director/Exec on-call → Bronze → Silver → Gold. Each escalation captures who escalated, when, and why against the incident.
Every escalation event is written to an append-only record — EPRREscalationEvent — so the rationale for going up a tier can never be quietly rewritten after the fact. Declaring a Major Incident hands off to /major-incident.
The rota carries the tier, the person and their preferred channel, with click-to-contact — and links the integrated OPEL assessment from On-Call Manager so operational pressure and command are on one view.
A response fails on communication before it fails on anything else. The spine structures the joint decisions, composes the standard major-incident message, and logs every dispatch to a single running record.
Each joint decision is recorded against the five JESIP principles — co-locate · communicate · co-ordinate · jointly understand risk · shared situational awareness — giving a defensible record of multi-agency working.
A structured builder composes and records the METHANE message — Major incident declared? · Exact location · Type · Hazards · Access · Number of casualties · Emergency services — then hands it to Comms for dispatch, so nothing is improvised under pressure.
Dispatch via text (SMS) / WhatsApp / Microsoft Teams; every dispatch is written to the incident. In the demo, comms transport is queued and logged; production routes SMS/WhatsApp via /sms/send and Teams via webhook.
A chronological loggist records decision, action and information entries with owner and status — the single source of truth for what happened and when.
While the incident is being run, the critical functions still have to work. The BCP register makes the recovery targets explicit and lets you activate a plan against the live incident, with the activation written to the loggist.
Each critical function carries its Recovery Time Objective and Recovery Point Objective — so "how long can this be down, and how much data can we lose" is answered in advance, not argued mid-incident.
One control activates the plan for a function against the current incident — /eprr/bcp/{id}/activate — and the activation is written straight to the incident loggist so the response and the continuity decision are on one timeline.
A core-standards self-assessment, plans library and exercise programme — with the framing resolved per jurisdiction (see below), so the assurance evidence always speaks the right language for the deployment.
| Critical function | RTO | RPO | Status | |
|---|---|---|---|---|
| EPR / clinical record | 1 hr | 15 min | degraded | Activate BCP |
| Pathology / lab results | 4 hr | 1 hr | at risk | Activate BCP |
| Telephony / switchboard | 30 min | 0 | running | Activate BCP |
EPRR is enabled for every jurisdiction, but the assurance language is resolved to fit the deployment — and it never borrows the wrong nation's branding.
England, Scotland and Wales each get their own NHS-nation resilience framing — the resolver _eprr_framework never applies "NHS England" to the wrong nation.
Crown Dependencies (Guernsey · Isle of Man), Gibraltar, the Caribbean (Jamaica · Antigua · Montserrat), Kenya and Oman get neutral best-practice framing with no NHS branding.
An unknown or unmapped jurisdiction fails safe to generic framing — never to another jurisdiction's NHS branding. The module stays enabled; only the language adapts.
| Capability | Tab / Route | Model / API | Standard | Status |
|---|---|---|---|---|
| Command & system pressure | Coordination · /eprr | OPEL tile · open actions · rota | Gold/Silver/Bronze command | ● Live |
| One-tap escalation ladder | Incidents & Escalation · /eprr/escalations | EPRREscalationEvent (append-only) · /eprr/escalation-ladder | who / when / why decision log | ● Live |
| Declare Major Incident | /major-incident | EPRRIncident · handoff | METHANE · CSCATTT | ● Live |
| On-call & command rota | On-Call & Command · /eprr/rota | EPRROnCallRota · /oncall-manager | tier · preferred channel | ● Live |
| JESIP joint-decision log | JESIP & METHANE · /eprr/jesip | EPRRJesipDecision · /eprr/jesip-principles | JESIP five principles | ● Live |
| METHANE message builder | JESIP & METHANE · /eprr/methane | EPRRMethaneMessage | METHANE structured message | ● Live |
| Running loggist | Comms & Loggist · /eprr/log | EPRRLogEntry | decision / action / info | ● Live |
| Multi-channel comms dispatch | Comms & Loggist · /eprr/comms-dispatch | EPRRCommsDispatch · /sms/send · Teams webhook | SMS · WhatsApp · Teams | ◍ Demonstrated |
| Business-continuity register | Business Continuity · /eprr/bcp | EPRRBCPEntry · RTO / RPO | ISO 22301 concepts | ● Live |
| Activate BCP against incident | /eprr/bcp/{id}/activate | writes to loggist | continuity activation | ● Live |
| Assurance & framework resolver | Assurance · /eprr/framework | EPRRPlan · _eprr_framework | jurisdiction-aware · fail-safe | ● Live |
Status key. ● Live — API-backed today: /eprr/ plus the append-only escalation decision log. ◍ Demonstrated — comms dispatch transport (SMS / WhatsApp / Teams) is queued and logged in the demo; production routes SMS/WhatsApp via /sms/send and Teams via webhook.