Browse the handbook
This handbook defines how Kairos operates, who owns what, where authority sits, and how information, technology, clinical work, money, contracts, and intellectual property are governed.
Corporate Governance
Governance Principles & Rules of the Road
Establishes the fundamental principles under which Kairos operates.
Core principles
- Kairos business belongs to Kairos.
- Authority comes with accountability.
- Confidentiality does not mean concealment.
- Access is based on role and legitimate need.
- Material information must travel upward.
- Decisions affecting the company must be documented.
- No individual owns a client, project, study, system, dataset, or corporate relationship.
- Company interests take precedence over individual control of information.
- Regulatory and contractual restrictions must always be respected.
- When authority is unclear, escalate before acting.
Corporate Authority & Delegation
Defines who may make which decisions on behalf of Kairos.
Establish a formal Delegation of Authority covering
- Board
- CEO
- Executive leadership
- Clinical leadership
- Technology leadership
- Finance
- Business development
- Project/study leadership
- Employees and contractors
Specify authority for
- Signing contracts
- Pricing
- Hiring
- Termination
- Purchasing
- Vendor engagement
- Client commitments
- Study commitments
- Technology procurement
- Software subscriptions
- Financial expenditure
- Regulatory representations
- Access to sensitive systems
Principle: No one may commit Kairos beyond their delegated authority.
Corporate Records & Communications
Defines what constitutes an official Kairos record.
Company records include
- Kairos-domain email
- Contracts
- Proposals
- Client correspondence
- Study documentation
- Meeting decisions
- Financial records
- Technology documentation
- Source code
- Databases
- Company messaging
- Approved WhatsApp business communications
- Documents created while performing Kairos work
Material decisions made verbally, through WhatsApp, or through another informal channel must be appropriately captured in the corporate record.
Clinical & Regulatory Governance
Clinical Trial Governance
Establishes the distinction between:
Kairos leadership must have sufficient information to understand:
- What study Kairos is participating in
- Who the sponsor/client is
- What Kairos has contracted to do
- Who is responsible
- Major milestones
- Financial implications
- Operational status
- Material risks
- Regulatory obligations
Access to blinded data, PHI, PII, patient-level data, investigational information, or otherwise restricted study information remains role-based and governed by applicable regulations, agreements, protocols, and SOPs.
Confidentiality, Privacy & Information Classification
Create formal information classifications:
Restricted examples
- PHI/PII
- Blinded clinical data
- Passwords
- Security credentials
- Certain sponsor information
- Investigational information
- Highly sensitive financial or personnel information
Access should follow the minimum necessary / need-to-know principle.
Quality, Compliance & Escalation
Defines issues that must immediately be escalated.
Examples include
- Patient safety concerns
- Protocol deviations
- Data-integrity concerns
- Privacy breaches
- Security incidents
- Regulatory concerns
- Sponsor complaints
- Serious study delays
- Contract violations
- Suspected misconduct
- Financial irregularities
Kairos Rule: Bad news travels upward quickly.
No employee should conceal a material problem because they believe they can resolve it themselves.
Technology Governance
Technology Ownership
This should be unequivocal.
Technology created for Kairos using Kairos resources or within the scope of employment/contractual duties is governed by the applicable employment, contractor, IP, and development agreements and, where assigned to Kairos, is a Kairos corporate asset.
This may include
- Source code
- Applications
- Databases
- APIs
- Algorithms
- AI prompts
- AI workflows
- Agents
- Documentation
- Architecture
- Infrastructure configuration
- Deployment configuration
- Automation
- Analytics
- Internal tools
No production technology should depend exclusively upon one individual's personal account or personal infrastructure.
Source Code & Repository Governance
All official software must reside in company-controlled repositories.
Establish standards for
- GitHub organization ownership
- Repository administrators
- Branch protection
- Pull requests
- Code review
- Commit history
- Releases
- Production branches
- Archived repositories
- Backup
- Access removal after separation
Critical principle: No single developer should be the only person capable of accessing, understanding, deploying, or recovering a Kairos system.
Cloud & Infrastructure Governance
Create a central register of:
- Domains
- DNS
- Hosting
- Vercel/cloud infrastructure
- MongoDB/databases
- Storage
- Email infrastructure
- APIs
- Authentication systems
- Third-party integrations
- Monitoring systems
Each system should identify:
Credentials, Secrets & Access
Passwords and production credentials must never depend upon an individual's memory, personal email, or private password manager.
Govern
- API keys
- Database credentials
- OAuth credentials
- Cloud credentials
- GitHub access
- Domain registrar access
- Production secrets
- Encryption keys
- AI-provider keys
Require
- Company-controlled credential storage
- MFA where available
- Role-based access
- Periodic access review
- Immediate revocation when access is no longer required
- Credential rotation after material personnel changes
Software Development & Change Management
Define how software moves:
Not every change needs bureaucracy. The governance should be risk-based. Low-risk UI changes can move rapidly.
Changes requiring stronger review and testing
- Patient information
- Clinical calculations
- Authentication
- Permissions
- Financial information
- Production databases
- Security
- Regulatory workflows
AI Governance
Kairos should establish this now rather than later.
AI systems must have defined
- Purpose
- Approved models/providers
- Data-access boundaries
- Human oversight
- Logging
- Validation expectations
- Cost controls
- Security requirements
- PHI/PII restrictions
- Model-change procedures
Fundamental rule: AI output is not automatically truth.
Where an AI system influences clinical, regulatory, financial, or other material decisions, appropriate verification and human oversight are required.
Data Governance
Every important dataset should have:
- Business owner
- Technical owner
- Source of truth
- Access rules
- Backup policy
- Retention policy
- Recovery procedure
- Data-quality expectations
Production data should never exist solely on someone's laptop.
Cybersecurity & Incident Management
Establish minimum requirements for:
- MFA
- Device security
- Encryption
- Access control
- Backups
- Logging
- Vulnerability management
- Security updates
- Phishing
- Lost devices
- Credential compromise
- Incident reporting
Employees must report suspected compromise immediately.
Do not investigate or quietly fix a significant security incident without notifying the appropriate company authority.
Intellectual Property
Intellectual Property Ownership
Clearly govern:
- Software
- Algorithms
- Documentation
- Clinical technology
- Processes
- Designs
- Databases
- AI workflows
- Training materials
- Brands
- Domain names
- Inventions
IP ownership must be established contractually with employees, consultants, partners, and developers.
No ambiguity should exist about whether technology developed for Kairos belongs to an individual or to the company.
Third-Party & Open-Source Technology
Maintain visibility into:
- Open-source libraries
- Commercial software
- APIs
- AI models
- SaaS services
- Cloud services
- Third-party datasets
Licensing obligations must be respected.
Developers should not introduce technology carrying unacceptable licensing, security, privacy, or commercial restrictions.
Commercial Governance
Client & Business Development Governance
Client relationships are corporate relationships.
Maintain a corporate pipeline containing:
No business opportunity should reside exclusively inside someone's personal contacts, inbox, or memory.
Contracts & Commitments
Maintain a central contract register.
For every agreement:
Only authorized personnel may execute agreements.
Vendor & Third-Party Governance
Before material vendors receive access to Kairos information or systems, establish:
- Business purpose
- Contract
- Confidentiality
- Data access
- Security requirements
- Financial terms
- Responsible Kairos owner
- Termination process
Vendor access must be removed when no longer required.
Financial Governance
Financial Authority
Define authorization thresholds for:
- Purchases
- Contracts
- Reimbursements
- Hiring
- Consulting
- Technology
- Travel
- Vendor payments
- Capital expenditure
No individual should simultaneously initiate, approve, and reconcile a material financial transaction where reasonable segregation is possible.
Revenue, Billing & Collections
Every commercial engagement should connect:
Management should have visibility into:
- Contract value
- Amount invoiced
- Amount collected
- Outstanding receivables
- Aging
- Expected collections
People & Accountability
Roles, Responsibilities & Accountability
Every significant role should have:
- Defined responsibilities
- Reporting relationship
- Decision authority
- Expected deliverables
- Performance measures
- Escalation responsibilities
Seniority does not eliminate accountability.
Joining, Role Changes & Separation
Joining
Provision only required access.
Role Change
Review access when responsibilities change.
Separation — immediately address
- GitHub
- Cloud
- Databases
- Credentials
- Applications
- Documents
- Company equipment
- Client relationships
Conduct a formal knowledge transfer before departure whenever possible.
Business Continuity & Key-Person Risk
Kairos should be capable of continuing operations if any single individual becomes unexpectedly unavailable.
For every critical function:
The company should never have to say:
“Only that person knows how this works.”
Management Operating System
Management Visibility
Leadership should have a concise view of:
The purpose is visibility—not micromanagement.
Decision & Escalation Framework
Every important matter should ultimately answer:
- Who owns it?
- Who decides?
- Who needs to know?
- Where is the decision recorded?
- When must it be escalated?
If those five questions cannot be answered, governance is incomplete.
The Kairos Standard
Kairos should remain entrepreneurial, fast, and innovative.
Corporate governance should not create bureaucracy for its own sake.
Its purpose is to ensure that the company can move quickly without becoming dependent upon individual people, undocumented decisions, inaccessible information, or uncontrolled systems.
And above all:
If Kairos owns the responsibility, Kairos must have the governance necessary to fulfill that responsibility.