Inspiration

Every clinic visit ends with a plan: start a medicine, send a test, check blood pressure twice a day, come back in three weeks. Then the patient walks out, and nobody follows the plan home.

Results arrive days later in scattered messages. A reading that never comes goes unnoticed. A patient who cannot reach the lab, or cannot find the medicine, quietly stops treatment. A worrying symptom can sit in the same queue as a routine question. The doctor has no reliable view of what is still open, and the patient has no one to ask between visits.

As a cardiologist, I see this gap every week. Sanad (Arabic for "support, the one you lean on") is built to close it: the doctor decides, and Sanad follows through.

Who it is for

  • Doctors who manage follow-up between visits and need to know, at a glance, who is in danger, who is waiting for a decision and who has gone quiet.
  • Patients who are trying to carry out instructions at home and need clear reminders, simple answers and practical help.
  • Clinics that want follow-up to be accountable, recorded and safe, not dependent on someone remembering to check a chat.

What it does

For the doctor

  • Speak or type the plan. A voice note, text, prescription photo or PDF on Telegram becomes a plan on one confirmation card: medicines, tests, monitoring, visits and tasks.
  • Grounded, never guessed. Every field on the card points back to the doctor's own words. If something is unclear, it becomes a question on the card. Doses and durations are never invented.
  • Confirm once, track everything. After confirmation, every request carries a deadline and a review time. Missing timings are proposed on the same card for the doctor to accept.
  • One dashboard. Patients grouped by what needs attention (urgent, waiting on the doctor, patient late, due today), a patient card with the latest readings and a chart, and the full record with every document beside what was read from it.
  • Act from the page. Reply to questions, resolve reviews, amend an order with the old version kept in history, or remove a patient, which stops all contact.
  • No daily noise. Unresolved work moves into one weekly summary instead of repeated alerts.

For the patient

  • Joins safely. An invitation QR code, clear consent terms naming every service that handles their data, and the doctor's confirmation of the intended person before anything is shared.
  • Knows what to do. The plan in plain English, reminders at the times they choose and never in quiet hours, with pause, snooze and stop.
  • Gets answers. Questions are answered from the accepted plan and doctor-reviewed explanations; anything else goes to the doctor, and a dose is never changed by Sanad.
  • Gets help. When a lab is too far or a medicine is out of stock, the Resolver suggests real nearby places, without booking, pricing or swapping medicines.
  • Is checked on. Starting a medicine is one report, and a separate day-three check asks whether anything is in the way.

For the administrator

Doctor accounts are approved, rejected (with a reason) or suspended from a separate page, without any access to clinical records.

Safe by design

  • Danger comes first. A deterministic safety kernel screens every readable message and caption before any agent runs. "Chest pain now" gets fixed safety guidance at once and an urgent report to the doctor, on a path that never waits for a model.
  • Every patient sentence is checked. A validator confirms each generated sentence is backed by the accepted plan or an approved explanation; unsupported content becomes a question for the doctor.
  • Honest results. Two independent readers must agree on at least half the rows of a document before a card is built; otherwise nothing is recorded and the patient is told plainly. Received, complete and reviewed stay separate states, and silence never counts as done.
  • Privacy built in. Every record belongs to one doctor, a QR code alone reveals nothing, sign-in links are single use and short lived, browser actions are protected against forgery, and only synthetic patients are used.

Reliable under failure

  • Nothing half saved. Each change, its audit event and its outgoing message commit in one DynamoDB transaction.
  • No stale or duplicate messages. Workers are fenced, delivery rechecks consent, access and current orders right before sending, and replayed updates are processed once.
  • Work survives restarts. Incoming messages are saved before they are acknowledged, and every deadline, follow-up and review lives on its own durable clock driven by a minute tick.

How we built it

Agents that stay in their lane (Strands)

Sanad runs six Strands agents on Amazon Bedrock with Amazon Nova:

  • Scribe turns the doctor's dictation into a plan (two extractions, merged and grounded).
  • Concierge talks with the patient from the accepted plan and approved explanations.
  • Coordinator words each follow-up request.
  • Resolver helps with practical barriers using a map search.
  • Evidence Reader reads photos and PDFs.
  • Liaison reports danger, completed requests and unresolved work to the doctor.

Each agent has one responsibility, only its own scoped tools, a tool budget and a typed proposal as output. Conversations live in fenced sessions that cannot overwrite newer state. None of the agents can change a record: a deterministic Steward validates identity, permission and version, and is the only code that commits a change.

Architecture on AWS

Telegram and the web pages are only doors into the same records. A container on AWS Lambda receives webhook and browser traffic, saves work before acknowledging it, and processes it with workers. DynamoDB (single table) holds records, deadlines and the outbox; private S3 holds media. EventBridge fires a signed minute tick through a private relay to return to due work. Amazon Nova Lite does the reasoning and Nova Micro the classification; Gemini handles speech, vision and independent cross-checks.

How we worked

The product was built in small, reviewed slices, each with a written specification, its own tests and an independent review before it was accepted. Models were chosen by measurement on real synthetic cases, and the rejected ones are recorded with their reasons. The result: more than 7,500 hermetic tests, about 4,700 repeated against DynamoDB Local, about 400 browser checks on the real pages, and live smoke checks on every deployment (model access, health, signed tick, webhook, tenant isolation, enrollment, sessions and cost).

Challenges we ran into

  • Numbers in speech. Speech models misheard clinical numbers and terms. Instead of trusting a transcript, the card asks the doctor whenever a value cannot be grounded.
  • Photos that lie. Two readers often disagree on a noisy lab photo. The agreement rule and honest refusal replaced "best guess" extraction.
  • Proposal versus decision. Letting a model shape records directly would be impossible to test or trust. Putting every write behind the deterministic Steward made the system testable and safe.
  • Durable follow-up on serverless. Reminders and reviews had to survive restarts and retries, which led to the atomic outbox, fenced workers and the minute tick.
  • Scope under time. We kept the product complete for three roles and kept unfinished ideas out of the submission rather than half-shipping them.

Accomplishments that we're proud of

  • A complete, working product for doctors, patients and administrators on Telegram and the web.
  • A danger path that never depends on a model, and a check on every sentence sent to a patient.
  • Follow-up that is accountable: every request has an owner, a deadline and a visible state until it is resolved.
  • A deployment that is tested live on every release.

What we learned

Useful agents are bounded agents. The value of Strands for us was not letting a model do everything, but giving each agent a narrow job, scoped tools and structured output, so deterministic code could stay the source of truth. In healthcare, that separation is what turns an impressive demo into something a doctor could trust.

What's next

  • Clinical policy and consent review with clinicians before any real patient.
  • Arabic conversation for patients in Egypt and the region.
  • A pilot with clinics, measuring missed results, late responses and time saved for doctors.

Try it

Built With

Share this project:

Updates

Submission history