Safe Use and Limitations
Apply MARCUS within its current non-PHI boundary and review every important output against the underlying evidence.
MARCUS helps clinicians find and synthesize information from an institutional document library. It is not an emergency service, diagnostic system, clinician replacement, medical record, or patient-facing advice tool.
Current data boundary: MARCUS supports an institutional non-PHI workspace. PHI use is not available in this lane. Do not upload, type, paste, connect, or transmit patient identifiers, patient-specific clinical facts, credentials, secrets, or other prohibited data.
Audience and Availability
This page applies to everyone who signs in to MARCUS, administers a workspace, imports sources, reviews output, or receives shared material.
The boundary and review duties on this page apply even when a feature, integration, export, or sharing option is available in the interface. A visible control is not permission to use prohibited information.
What MARCUS Is Appropriate For
Use MARCUS for non-PHI work with approved institutional or reference documents, such as:
- finding a section in an approved protocol
- comparing two current policy documents
- summarizing a guideline with citations
- identifying topics covered or missing across a project
- preparing a draft educational outline from approved sources
- locating the document language behind a general clinical-process question
Example question:
Which sections of the current postoperative pathway describe reassessment timing, and where do the approved sources differ?
The question is about source content and contains no patient information.
What Must Stay Out of MARCUS
Do not enter or import:
- names, dates of birth, medical-record numbers, addresses, contact details, or other patient identifiers
- patient histories, examination findings, laboratory values, images, medications, diagnoses, treatment details, or other patient-specific facts
- clinical notes, handoffs, consult messages, or screenshots that contain patient information
- credentials, access tokens, passwords, private keys, connection strings, or recovery codes
- confidential material that your organization has not approved for this workspace
- content from an external service merely because a connector can technically reach it
De-identifying a sentence informally is not enough if the remaining facts could identify a person. When uncertain, keep the material out of MARCUS and use your approved institutional workflow.
The Required Review Path
Citation trace
How a citation leads back to the original source
Each visible reference can be followed from the answer to the passage and source information MARCUS used for display.
Statement in the answer
A reference marker appears beside the relevant part of the response.
Citation number
The marker connects that part of the answer to a source entry.
Displayed passage
MARCUS opens the passage associated with the reference when its identity is clear.
Original source
The clinician can review the source title, section, and page when available.
Inspect source
For every important output:
- Read the answer as a draft synthesis.
- Open each citation supporting an important claim.
- Compare the displayed excerpt with the exact stored passage when available.
- Confirm the source title, section, page, date, version, and institutional approval status.
- Look for relevant conflicts, exceptions, and missing sources.
- Apply clinical judgment and any patient-specific context outside MARCUS in an approved system.
- Follow the authoritative source and local governance when the synthesis and source differ.
Never let a polished answer replace source review.
What MARCUS Cannot Guarantee
MARCUS output may be incomplete, inaccurate, outdated, or inapplicable. Its usefulness depends on:
- whether the right source was included
- whether the source was current and approved
- whether text extraction preserved the relevant content
- whether the project scope matched the question
- whether search found the most useful passages
- whether the answer represented those passages faithfully
- whether conflicting or qualifying evidence was found
A citation shows where support came from. It does not prove that the source is correct, current, complete, or applicable.
A coverage or support cue is a navigation aid. It is not a calibrated probability that the answer is true.
When MARCUS Should Decline to Answer
If the indexed sources do not provide enough support, MARCUS is designed to return a no-evidence response rather than fill the gap by inference. A typical message states that it could not find enough evidence in the indexed documents to answer reliably.
That response is useful information. It may mean:
- the relevant source is missing
- the source is not ready
- the question is outside the project scope
- the wording does not match the source well
- the evidence genuinely does not answer the question
Do not turn an evidence gap into a confident answer by repeatedly rephrasing until MARCUS produces one. Investigate the library and the question.
Handle Conflicts and Uncertainty
When sources disagree:
- Open the cited passages from each source.
- Compare dates, versions, issuing bodies, intended populations, and scope.
- Check whether one source has been superseded.
- Preserve the disagreement in any summary.
- Ask the responsible clinical or policy owner to resolve the conflict.
MARCUS shows source metadata and passage-support information, but it cannot ratify which policy governs your organization.
Understand Access and Privacy Boundaries
MARCUS uses authenticated sessions and checks the active organization and project for protected actions. Those controls support workspace separation, but they do not change the non-PHI boundary.
Also remember:
- conversations are organizational workspace content, not reliably private notes
- authorized administrators may have access to activity and question-level records
- a public answer share is viewable by anyone who receives the link
- copied text and exports leave the original MARCUS access boundary
- retention and administrative access depend on organizational agreements and configuration
Do not claim that a deployment is HIPAA compliant, SOC 2 certified, or approved for a particular institutional use based only on the interface or these docs. Use the current approved trust and contracting materials for those determinations.
Before Sharing or Exporting
Review the complete artifact, including:
- question text
- answer text
- citation labels
- source titles
- reviewer notes
- task and bookmark labels
- filenames
- exported metadata
Use only an authorized institutional channel. Choose the smallest audience and shortest useful duration. Revoke a public link when it is no longer needed.
If Prohibited Information Was Entered
- Stop adding or sharing the content.
- Revoke any public share link.
- Follow your organization's privacy or security incident procedure immediately.
- Contact the authorized workspace administrator or support path without repeating the prohibited information.
- Do not paste the same content into a bug report, email, or support message.
Do not assume deletion alone completes an incident response. Your organization decides the required containment, reporting, and follow-up.
Expected Result and How to Verify It
A safe MARCUS workflow ends with a source-supported draft that a clinician can independently verify, with no prohibited data in the workspace.
Before using an output, confirm:
- the active organization and project were correct
- the source set was appropriate and current
- important claims have reviewable citations
- the exact source text supports the wording used
- conflicts and evidence gaps are visible
- the output is clearly identified as generated synthesis where needed
- clinical application and patient-specific reasoning occurred outside MARCUS
Common Risk Signals
Failure path
How MARCUS handles an incomplete step
An interrupted source or answer should remain visibly incomplete rather than being presented as successful.
Work begins
MARCUS starts preparing a source or answering a question.
Problem detected
A connection, source, search, or generation step does not finish.
InterruptedNot complete
MARCUS keeps the item out of the successful or ready state.
Needs attentionReview the message
The visible state explains what can be checked or changed next.
Correct and retry
The clinician can retry after the underlying issue is resolved.
Retry path
| Signal | Safe response |
|---|---|
| The answer has no citations | Do not act on it; inspect the library and retry only after finding the cause |
| A citation does not support the claim | Follow the source text, report the mismatch, and do not reuse the unsupported claim |
| Only an old or draft source appears | Find the current approved source or escalate to its owner |
| Sources conflict | Preserve the disagreement and request governance review |
| The question requires patient-specific facts | Stop and use an approved clinical system instead |
| A generated page looks authoritative but lacks source review | Treat it as a draft navigation aid |
| A share link contains inappropriate information | Revoke it and follow the incident process |
| A feature appears to promise security or compliance | Verify the approved deployment documentation rather than inferring from the interface |
Continue Reading
- Previous: Collaboration and Administration
- Next: Troubleshooting
- Related: Evidence Grounding, Security Model, Privacy, Terms, and Acceptable Use