Chemical Exposure Pipeline
How a Chemical Exposure request flows through the Quantum State Engine.
Chemical Exposure does not use the seven-stage pipeline that powers the other modules. It runs a dedicated, safety-first flow that begins with a disclaimer acknowledgment gate, validates a structured input model, applies safety and scope intercepts, normalizes dose, computes a probabilistic confidence allocation, and emits a strict four-key public payload. For the standard flow used by every other module, see the QSE Pipeline.
Pipeline Overview
Each stage validates its inputs and produces well-defined outputs. If any stage fails validation, or the request is out of scope, the system returns a sealed Unknown or precondition response rather than fabricating data.
Pipeline Stages
Disclaimer Acknowledgment Gate
Verifies the caller has accepted the current disclaimer version
- •Authenticated request required (anonymous calls fail closed with 403)
- •Caller must present an acknowledgment of the latest active disclaimer version
- •Stale or missing acknowledgment is rejected with HTTP 428 Precondition Required
- •Disclaimer text and version are returned with every successful response
Structured Input Validation
Validates the four core exposure inputs before any scoring
- •Substance identity resolved against the registry, with broader recognition of common household, OTC, pesticide, cosmetic, and environmental substances by everyday name
- •Unrecognized or ambiguous substances fall through to the safety intercepts rather than being guessed
- •Dose or concentration with unit and dose basis (per event vs per day)
- •Exposure route (oral, dermal, inhalation, other)
- •Duration and duration unit; missing dimensions force the Unknown branch
Safety & Scope Intercepts
Routes crisis, out-of-scope, and ambiguous inputs to sealed Unknown outputs
- •Crisis-precedence patterns return safety-first sealed responses (always served, never rate limited)
- •Out-of-scope and unknown-substance queries return sealed Unknown rather than guessing
- •Forbidden-key allowlist prevents raw input or registry metadata from leaking into the response
- •Intercept kind is recorded in admin diagnostics, never in the public payload
Dose Normalization & Trace Detection
Converts dose to a consistent base and flags negligible exposures
- •All units normalized to a common base (mg) for comparison
- •Per-event vs per-day dose basis preserved through scoring
- •Trace doses (below 1/1000th of the per-tier reference dose) are flagged as negligible
- •Trace flag short-circuits dose contribution to the lowest tier and blocks Likely / Yes escalations
Confidence Allocation
Computes the relative-exposure label across the five-state lattice
- •Scores dose, route, duration, and their interaction independently
- •Interaction term applied only when dose and duration share sign (no spurious amplification)
- •Trace path caps positive route contribution at 0 and zeroes the interaction term
- •Free-text scenario and additional-context fields can shift the allocation by at most one interior step and cannot reach Yes or No on their own. Details that change the structured inputs themselves (effective dose, route, or duration, for example PPE that prevents skin contact) flow through dose normalization instead and can move the outcome by more than one step
- •Probabilistic allocation across: No, Not Likely, Unknown, Likely, Yes
QA & Endpoint Gating
Reserves strong labels for fully-specified, well-supported scenarios
- •Any missing dimension forces the Unknown branch before strong labels can fire
- •"No" is reserved for trace dose + short duration + all four inputs present
- •Insufficient endpoint signal demotes a model "No" to "Not Likely"
- •Safety gates run after any context-driven shift, so the final output may still be constrained regardless of optional context
- •Validator coverage and near-violation telemetry recorded for admin review
Public Payload Serializer
Emits a strict, allowlisted public response
- •Public payload contains exactly four keys: final_label, template_fragment_id, disclaimer_text, disclaimer_version
- •No rationale, factor breakdown, raw model output, or registry metadata is exposed
- •Allowlist enforced at the response builder so additions cannot leak by accident
- •Admin diagnostics, raw input, and validator output remain in admin-only columns
Public Payload Contract
Every successful Chemical Exposure response contains exactly these four fields. No other keys are ever emitted on the public path.
final_label— one of: No, Not Likely, Unknown, Likely, Yes.template_fragment_id— identifier of the registered explanation fragment.disclaimer_text— full text of the active disclaimer.disclaimer_version— integer version of the disclaimer the response is pinned to.
Label Semantics
No
Reserved for clearly negligible, fully-specified scenarios: trace dose, short duration, and all four inputs present.
Not Likely
Inputs are complete enough to lean low, but conditions do not meet the strict bar required for "No".
Unknown
Inputs are missing, ambiguous, or out of scope. The system explicitly declines to lean either direction.
Likely / Yes
Reserved for fully-specified inputs with meaningful relative exposure under the modeled conditions. Trace doses cannot reach these labels.
Fail-Closed Behavior
On Success
All gates pass and the request is in scope. The caller receives the sealed four-key public payload pinned to the current disclaimer version.
On Insufficient Input
Missing or ambiguous inputs return a sealed Unknown response. The system never fabricates a label to fill in for missing dimensions.
On Gate Failure
Anonymous callers receive HTTP 403. Authenticated callers without a current disclaimer acknowledgment receive HTTP 428 with no analysis performed.
Key Principles
Consent-Gated
No response is produced until the caller acknowledges the current disclaimer version.
Allowlisted Output
The public payload is locked to four fields. Internal reasoning and raw inputs never exit the edge.
Safety-First Intercepts
Crisis and out-of-scope queries are routed to sealed responses before any scoring runs.
Probabilistic, Not Predictive
Confidence is allocated across five labels rather than asserting a single outcome.