PC Provider ComplianceResearch front door
Discovery baseline · 31 August 2026

Research dossier: what Harrison needs, what exists, and what we should build.

One source-linked front door for the client process, 208-company market census, 127-repository GitHub campaign, the closest whole-case God source and the corrected self-hosted VPS direction.

208global companies/products
127GitHub repos screened
67deep system profiles
136live sitemap URLs checked
15preserved source files
18+research reports
Executive research synthesis · start here

The complete decision in one place.

This brief converges the client evidence, process video, company crawl, global competitor census, three GitHub campaigns and architecture review. The linked chapters and JSON datasets hold the underlying detail.

Bottom lineHarrison does not need a generic chatbot, a policy generator or a pile of loosely connected compliance tools. He needs one consultant-led application case workspace that preserves backstory, approved facts, responsible people, categories, evidence, plans, master-pack edition, form answers, gaps, approvals and post-submission events. The first proof should use five mature infrastructure libraries and keep the regulatory case authority custom.

1. What we actually researched

The discovery dossier combines fifteen preserved source files, Harrison’s 9 minute 25 second process walkthrough, two category master-pack editions, a 331-row document mapping register, 136 live Provider Compliance sitemap URLs, 208 companies and products, and 127 GitHub repositories screened across three technical domains plus the corrective God-source audit. Thirty companies received deeper workflow profiles. Thirty-seven repositories received deep mechanics profiles. The broader count of 67 deep system profiles is the combined 30-company and 37-repository analysis set.

The market work is deliberately split into breadth and depth. The 208-company directory is a global discovery census: every record carries geography, customer, delivery model, capabilities, public proof, confidence and relevance. Use the “30 deep workflow profiles” filter to see only the companies where we documented how the product works and what Harrison should learn. The market synthesis turns those records into seven market archetypes, ten feature-frequency findings, a top-25 learning shortlist and six areas of white space.

The technical work is also split into breadth and depth. The repository explorer contains 95 structured records with lane, purpose, mechanics, gaps, licence information and adoption verdict. The research now covers 43 regulated case/GRC/QMS/whole-case candidates, 44 document-automation candidates and 40 agent/workflow/memory candidates. The source datasets are public: regulated systems JSON, document factory JSON, agent workflow JSON and the corrected VPS architecture JSON.

208 companies30 company deep dives127 repos screened37 repo deep dives7 market archetypes10 feature findings19 research routesowned VPS direction

2. Where every research document lives

The research-pack register is the canonical index. It names every private working paper, explains its purpose and links to a public-safe readable ruling. The raw WhatsApp export, transcript, client applications, master ZIPs, personal data and private prompts remain withheld; the conclusions and evidence counts are published here.

Repository transparencyThe research site’s source currently lives inside the private sisodias/siso-agency repository, so there is no honest public source-repository URL for this front end yet. The public GitHub links below are the upstream projects evaluated by the research—not a fabricated “public repo” for this client dossier.

3. What Harrison’s process requires

The video shows a coherent regulated case process currently implemented through manual transfers between specialist Claude projects. Harrison begins with client answers, entity history, selected services, CVs, qualifications and other evidence. He proposes an organisation structure, tests whether responsibility is concentrated sensibly, sends it to the client and preserves the approved version. That structure then governs business plans, financial assumptions, workforce plans, recruitment plans, policies and application answers.

At each stage Harrison distinguishes three things: defects he can repair from existing evidence, reasonable proposals that still require confirmation, and facts or documents only the client can supply. That distinction is a core product feature. When funding, identity, responsible-person suitability, service scope or another material point is unknown, the system must create a gap with an owner and next action. It must not complete the sentence and quietly treat probability as fact.

The master-pack stage is not ordinary mail merge. The Category 1–4 ZIP contains 786 entries and the Category 1–5 ZIP contains 852. There are 282 normalised overlapping paths, and 173 same-path files differ. A job must pin an edition and checksum, determine inclusion from controlled rules, apply typed variables, preserve Word and workbook structure, produce review markings, run a pre/post token census, validate scope and terminology, scrub final metadata and emit an immutable manifest and delta log. The master-pack chapter explains the exact mechanics; the document research explains which libraries can execute them.

The final product is therefore one persistent case with one conversational front door and governed lanes for intake, organisation design, source documents, master-pack construction, application assembly, gap analysis, client review, declaration, external submission and Commission lifecycle. The database and event history are authoritative. The model can extract, propose, compare, draft and validate. Consultants and clients confirm facts and decisions. An authorised human owns the final declaration and submission.

4. What the 208-company market taught us

The “competitor market” is actually seven adjacent industries. Regulated provider operating suites such as Lumary, AlayaCare and WellSky manage clients, staff, scheduling, care and finance. Inspection and audit products such as Gatekeeper, Nomotix, Willow, AlwaysReady Care and Radar Healthcare map obligations, collect evidence and manage corrective actions. Policy consultancies sell templates and expert readiness. Enterprise GRC products such as AuditBoard, Diligent, MetricStream and ServiceNow manage controls, risk and assurance. eQMS and regulatory-submission platforms such as Qualio, Veeva Vault Quality, MasterControl, Rimsys and RegDesk control documents, change and submissions. Workforce products manage credentials, screening, training and expiries. Open-source infrastructure supplies case, document, rule and workflow primitives.

Common features are not the strategic answer. Evidence repositories, policy libraries, checklists, audits, gap actions, credentials and framework mappings are everywhere. They are table stakes. The uncommon capabilities are the ones Harrison’s process depends on: a structured applicant backstory; explicit consultant-versus-client ownership; claim-level links from an application answer to case evidence and regulatory authority; pinned form and master-pack editions; comprehension and declaration history; and continuity from application through information requests, audit, decision, renewal and variation.

The closest direct analogues are useful for different reasons. Gatekeeper demonstrates obligation-to-evidence-to-audit reporting. Nomotix demonstrates continuous aged-care and NDIS readiness. Willow demonstrates multi-framework AI positioning. CareDocs and Radar Healthcare show provider operations and inspection-readiness patterns. Qualio, Veeva and MasterControl show controlled content, review and change. None of the public evidence showed one product clearly joining applicant backstory, categories, people, finances, evidence, document edition, form claims, gap ownership, approvals and post-registration history. That integration is the product wedge.

Market verdictDo not build another policy library or generic AI writer. Build the missing case-and-evidence layer that can use policies, documents and compliance tools without surrendering applicant truth or human approval.

5. What GitHub can provide—and what it cannot

God-source correctionLegalise is the closest whole-system reference, because it begins with the complete governed client matter: documents, selected-source AI, citations, skills, named sign-off, append-only audit and verifiable export. It runs Postgres + pgvector, MinIO, Redis, Gotenberg, FastAPI and React on self-hosted infrastructure. It is explicitly an evaluation release with low adoption and production gaps, so the verdict is blueprint and synthetic spike, not live deployment. Read the full translation and limitations.

Lane one: regulated case, GRC and QMS. Forty-two credible candidates were structured and twelve received deep profiles. WKS Platform is the closest single case/workflow benchmark: Spring Boot, React and Camunda provide stages, tasks, timers, assignments and approvals. OpenQMS is the strongest regulated quality reference for controlled documents, deviations, CAPA, audits and change. Unicis is the strongest current open GRC reference. OPA is the strongest external rule-engine option. The best three-project benchmark is WKS + OpenQMS + OPA, but deploying all three would introduce overlapping authorities, Java/Camunda operations, licensing review and substantial integration before one Harrison case is proven. Verdict: learn and probe, not foundation.

Lane two: the document factory. Forty-four projects were screened and twelve profiled. python-docx is the best direct DOCX primitive because it exposes paragraphs, runs, tables, sections, headers and footers. openpyxl covers workbook and register manipulation. pypdf is the first probe for compatible Commission PDF forms. Pydantic types generation jobs, manifests, variables and validator results. Docling, OCRmyPDF, Gotenberg and qpdf are optional workers only when real fixtures prove the core four insufficient. Verdict: adopt the four primitives; keep edition selection, source precedence, inclusion, approval, census and finalisation custom.

Lane three: agents, durable workflow and memory. Forty repositories were verified and twelve profiled. LangGraph is the closest single agent framework for graph state, checkpoints and human interrupts. Temporal is the high-assurance reference for replayable long-running workflows. Langfuse is the strongest observability/evaluation companion; Promptfoo is useful for regression fixtures. Mem0 and Zep can hold derived preferences or reviewed lessons, but must never become applicant authority. OpenFGA and OPA are credible later controls for complex authorization and policy. Verdict: begin with explicit database state; add LangGraph only when real branching and resume complexity justify it, and add Temporal only when direct workers cannot reliably survive multi-day waits.

Use caseBest reference nowRatingReason
Whole AI-assisted case blueprintLegaliseGod source / spikeClosest complete loop and VPS stack; evaluation quality, single-workspace and requires full domain adaptation.
Generic case/BPMN benchmarkWKS PlatformProbeUseful stages/tasks/approvals reference; missing AI evidence, sign-off and provider domain authority.
External deterministic rulesOPADefer with triggerExcellent versioned decisions; unnecessary until validators outgrow application code.
DOCX transformationpython-docxAdoptDirect structural control with a small Python surface.
XLSX/register workopenpyxlAdoptFits the actual 331-row register and spreadsheet fixtures.
PDF form inspectionpypdfAdopt/probeSmallest first test; XFA, appearance and signature limits remain fixture-specific.
Typed contractsPydanticAdoptMakes case jobs, claims, gaps, manifests and validator outputs explicit.
Agent orchestrationLangGraphDefer with triggerUseful for proven branching/resume complexity, not the first source of truth.
Long-running durabilityTemporalDefer with triggerHigh assurance with meaningful operational cost.
Mixed document extractionDoclingProbe on failureAdd only when simple format-specific extraction fails measured fixtures.
Low-adoption turnkey compliance demosNoneRejectDo not outsource private case authority to an unproven full-stack claim.

6. The corrected implementation direction

Run one owned application on a VPS. PostgreSQL 16 + pgvector holds case state, full-text retrieval, embeddings, approvals and audit. MinIO or an encrypted mounted volume holds original evidence and generated artifacts. Redis or Valkey coordinates bounded workers. Gotenberg and LibreOffice handle conversion. FastAPI and React provide the domain API, consultant workspace and client portal. One audited model gateway routes to local Ollama or explicitly approved API models. This keeps storage, networking, backups, retention and model egress under operator control.

Use Legalise as the God-source specification for the matter/document/AI/citation/sign-off/audit/export loop. Rebuild that loop around Provider Compliance objects and stages rather than forking the legal vocabulary unchanged. python-docx, openpyxl, pypdf and Pydantic remain bounded document and contract primitives; Dify, n8n, Docling, Langfuse, OPA, OpenFGA and Keycloak are evidence-triggered sidecars, never the application authority.

SISO-owned code must still define the meaning-bearing layer: applicant backstory; case and person records; category and form versions; claim-to-evidence-to-requirement lineage; consultant/client gap ownership; approval and declaration events; deterministic regulatory validators; append-only business audit; deletion and restore; and the successful/incomplete evaluation fixtures. No repository can safely infer those semantics from Harrison’s files.

The next gate is not “build the full app.” It is one de-identified successful case and one incomplete case represented end to end. Each needs a pinned regulatory and form version, selected master-pack edition, structured backstory, evidence-linked claims, correct gap routing, approvals, document receipts, review and final output sets, submission/outcome history, cross-tenant leakage tests and a deletion/restore exercise. If that fixture passes, add user-facing workflow. If it exposes genuine branching, durability, authorization, evaluation or parsing limits, activate the relevant deferred repository using the triggers documented in the architecture decision.

Evidence still missingHarrison still needs to supply one complete successful case through outcome, one exact incomplete/paused case, the current Commission form packs used in practice, the authoritative instruction registry and the privacy/hosting/identity/retention decisions. Until then this is a research-backed build specification, not a production system or legal opinion.
01 · Product decision

One case workspace. One conversational front door. Several governed lanes.

The safe product preserves Harrison's judgement and client confirmation while moving durable state, evidence, approvals and version control out of chat memory.

Recommended

Consultant-led, evidence-backed application workspace

Propose, extract, compare, draft and validate—but abstain when material facts are missing and never submit without human approval.

Build

Durable case authority

  • Structured applicant backstory
  • Claim → evidence → requirement links
  • Consultant/client gap ownership
  • Versioned approvals and outputs
Avoid

Opaque general memory

  • Prior cases used as current facts
  • Incomplete answers becoming defaults
  • Static guidance outranking current forms
  • Silent filling of material blanks
02 · What the programme learned

Seven findings govern the build.

These are the points every agent should absorb before proposing architecture, prompts or automation.

01

Case context is product data.

No two applications are identical. Entity history, service choices, people, funding, geography, prior matters and the reason for applying must be explicit, versioned and evidence-linked.

02

Successful cases are fixtures, not memory.

Use proven end-to-end applications for evaluation, sequencing and quality patterns only after outcome evidence is attached. Never copy their facts or prose into a new applicant.

03

Incomplete cases are negative tests.

They are valuable for pause-and-ask, blocker routing and gap classification. Their unfinished answers must never seed defaults.

04

The master packs are versioned products.

Category 1–4 and 1–5 editions differ materially. Edition selection, inclusion rules, variables, transformations and validation need explicit manifests and deterministic receipts.

05

Regulatory authority outranks internal guidance.

The supplied guides are useful maps, but current legislation, Commission guidance and the exact current form pack control external requirements.

06

Human ownership is a safety feature.

Organisation-specific answers, client comprehension, consultant review and immutable approval history are core system behaviour—not friction to automate away.

07

The market gap is traceability.

Competitors sell consulting, documents and audit support. Few expose a durable workspace connecting backstory, evidence, decisions, approvals and regulatory versions.

03 · Current process reconstructed

The workflow is already coherent. The hand-offs are fragile.

The 9:25 process walkthrough and supplied operating instructions converge on this stage model.

  1. 01

    Intake + backstory

    Entity, history, categories, services, people, evidence, constraints and unanswered questions.

  2. 02

    Organisation design

    Propose role allocation, test suitability/concentration, then record explicit approval.

  3. 03

    Business viability

    Business plan, financial model, ramp, workforce and recruitment plan.

  4. 04

    Master-pack build

    Select the confirmed edition; populate, scope, brand, validate and create a Build Report.

  5. 05

    Application assembly

    Answer exact current form questions and link every material claim to evidence and authority.

  6. 06

    Gap routing

    Separate consultant-resolvable work from facts, decisions or documents only the client can provide.

  7. 07

    Review + finalisation

    Client review set, tracked decisions, mechanical finalisation and immutable final outputs.

  8. 08

    Submission lifecycle

    Receipt, Commission correspondence, outcome, renewal, variation and change-in-circumstance events.

04 · Knowledge architecture

Do not put everything in “memory.”

Every retrievable object needs a named source class and authority level.

Highest external authority

Regulatory authority

Current Act, Rules, Commission and Department guidance, and exact form packs with effective dates.

regulatory_authority
Workflow authority

Instructions

Versioned lane behaviour, source precedence, hard gates, delivery states and supersession history.

instructions
Reusable assets

Master templates

Pack editions, registers, variables, inclusion rules, transformations and validation contracts.

master_templates
Reviewed practice

Policy memory

Client-free standing rulings, defect patterns, methods and lessons promoted through human review.

policy_memory
Tenant + case scoped

Case facts

Current applicant intake, evidence, approved org chart, financial model and confirmed answers.

case_facts
Tenant + case scoped

Case history

Backstory, decisions, contradictions, assumptions, approvals, exclusions and state transitions.

case_history
Testing only

Evaluation fixtures

Frozen successful, incomplete and adversarial cases with expected outcomes and proof.

evaluation_fixtures
Orientation only

External research

Competitors, GitHub candidates, public company research and discovery observations.

external_research
05 · Master-pack evidence

Two editions, not one folder with extras.

The ZIP central directories and control registers establish a concrete versioning problem.

786Category 1–4 ZIP entries
852Category 1–5 ZIP entries
282normalised overlapping paths
173changed same-path files

Required bundle controls

  • Stable edition ID and source checksum
  • Canonical register and controlled vocabulary
  • Explicit inclusion and category rules
  • Variable schema with source and required state
  • Pre/post transformation token census
  • DOCX/XLSX structural validation
  • Category, jurisdiction and terminology gates
  • Output manifest, delta log and finalisation event
Open reconciliation: README versus variable counts, 31 versus 33 input fields, inconsistent clinical labels, referenced-but-absent control artifacts, legacy codes and macOS sidecar content.
06 · Company and market

A broad consultancy with an unclaimed software wedge.

The public company spans aged care, NDIS, ISO and business growth. Its current funnel remains consultation-led and quote-led.

Aged care

Registration + readiness

Application support, policies, governance, documentation, audit preparation and ongoing advice.

Official service page ↗
NDIS

Registration + systems

Registration support, policy setup, Practice Standards alignment and audit readiness.

Official service page ↗
ISO

Management systems

Gap analysis, implementation and audit preparation for ISO 9001, 27001 and 45001.

Official service page ↗
Live crawl136 / 136sitemap URLs returned
Current-site defect6pages contained “Aged Care Act 1997”
Current wording0pages contained literal “Aged Care Act 2024”
Trust surfaces3old Act, 1+ counters, wrong map target

Direct market references

Explore all 208 →

Competitor statistics and success rates are self-claims unless independently verified. Their presence here is market orientation, not endorsement.

07 · GitHub and SISO landscape

Borrow infrastructure patterns. Keep case authority custom.

Three independent lanes plus the corrective whole-case audit screened 127 repositories across governed cases, document automation and durable agents. Legalise is the closest God-source blueprint; no repository is production-ready for Harrison unchanged.

ReuseResearch and internal worker infrastructure

Foundry for external research; Runtime and Project OS for internal agent operations.

ProbeEvidence, parsing and privacy patterns

Evidence Engines contracts, pypdf, Docling and measured PII middleware.

DeferWorkflow platforms and CRM hosts

Temporal, LangGraph and SISOCRM only after simpler state and tenancy gates fail.

RejectLow-adoption turnkey claims

Do not outsource case authority or private application data to unproven PDF/compliance services.

GitHub search boundary and additional probes

Searches covered tenant-isolated compliance workspaces, claim/evidence provenance, immutable audit logs, approval workflows, DOCX/XLSX transformations, PDF form filling, regulatory source versioning, PII redaction, aged care and NDIS compliance.

Additional pattern-only candidates include replayable RAG, evidence-ledger hashing, CloakLLM and Wirken. Repository self-claims remain unverified until source and deployment probes run.

08 · Minimum safe architecture

The smallest system that preserves trust.

Custom where meaning and authority live; reusable where infrastructure is generic.

Missing inputUnsupported claimStale authorityWrong categoryEvidence expiryContradictionClient blockerConsultant taskCross-tenant leakageUnapproved finalisation
09 · Risks and immediate corrections

Fix trust surfaces before selling the system.

These are verified discovery findings or explicit decision gates—not a legal opinion.

RiskWhy it mattersResponse
Old legislative references

Six sitemap pages still contain “Aged Care Act 1997.”

Correct and reconcile all live/indexed content.
Broken public proof

Metrics render as 1+ and the Sydney map target points to Karachi.

Repair before using the site as product proof.
Source-pack drift

Internal mappings and asserted rules cannot outrank current official forms.

Freeze, version and reconcile against exact packs.
Client data exposure

Applications contain identity, screening, qualification and financial material.

Tenant isolation, least privilege, encryption, retention and deletion controls.
Hidden assumptions

Financial or operational blanks can become unsupported claims.

Record proposed values and require explicit confirmation.
Case contamination

Reusable memory currently contains active-case names and unrelated downloads.

Namespace, quarantine and enforce clean-slate retrieval.
10 · Research pack library

One front door, with the deeper evidence labelled.

Public-safe summaries are available here. Private working papers and source evidence remain in the controlled project workspace.

Smallest high-value next move

Ingest one proven success and one honest failure.

De-identify and preserve one application from intake through Commission outcome, plus one incomplete case with its exact blocker. Use them to prove the case schema, gap routing, source precedence and evaluation harness before building a polished client portal.

Open agent handoff