Reverse Canvas worked example
Pharmacy Buyer AI Guardrails, a RealActivity educational resource
This example is fictional. "Veritas Rx Insight" is a composite invented for teaching. It does not describe any real company or product, and any resemblance is coincidental. The point is to show what a completed canvas looks like, including its gaps.
Vendor under review: Veritas Rx Insight (fictional). Pitched product: an AI assistant that predicts drug shortages and recommends purchase adjustments for a 400-bed community hospital.
1. Key Partnerships Confidence: medium
The product runs on a large general-purpose model rented from a major provider, hosted on a public cloud. The vendor confirmed both names when asked directly, but neither appears in the sales material. A signed BAA exists with the cloud host; the model provider's data terms were "available on request" and are still not in hand.
2. Key Activities Confidence: low
The team of 14 is mostly sales and integration. One validation study exists: a retrospective test on two health systems' purchase histories, run by the vendor itself. No independent validation, no published error rates, no description of the review process for model updates.
3. Key Resources: follow the data Confidence: medium
The pitch says "your data stays yours." The draft MSA says purchase histories may be used "to improve the service" in de-identified form, with no definition of de-identification and no exit clause for accumulated learning. The tuned model belongs to the vendor.
4. Value Proposition Confidence: low
Claimed: "up to 30 percent fewer stockouts." No baseline stated, no measurement window, no comparable site offered. In operational units the promise is undefined.
5. Customer Relationships Confidence: medium
Support is business-hours email with a 24-hour response target. There is no defined process for reporting a harmful or wrong recommendation, and the vendor has not yet handled one.
6. Channels Confidence: high
Direct sales today, with a GPO listing "in progress." Implementation, training, and updates are all owned by the vendor's integration team of three people.
7. Customer Segments: find yourself Confidence: high
The website lists eight verticals; hospital pharmacy is one. Two of the eleven current customers are hospitals. The roadmap leads with retail and distributor analytics. This hospital would be an early site, and its purchase data would be the most valuable thing it contributes.
8. Cost Structure Confidence: low
Seed-funded, 14 staff, renting expensive model capacity. Unit economics unknown. No continuity commitment exists if the company is acquired or shuts down.
9. Revenue Streams: follow the money Confidence: medium
Pilot is free for six months, then a per-facility subscription. The free pilot's terms grant the de-identified data rights in block 3. The pricing after year one is "to be discussed."
Blank and weak blocks, converted to the next questions:
- Blocks 2 and 4 are the weakest. Question one: "Share the validation study and the error rates by category, and name a comparable site we can speak with." Evidence: the study itself, not a summary slide.
- Block 3 question: "Strike or define the de-identified reuse clause, and state what happens to accumulated learning at exit." Evidence: revised MSA language.
- Block 8 question: "What continuity commitments can you make if the company is acquired or fails?" Evidence: escrow or continuity clause.
Risk category mapping
- Model and accuracy: unvalidated recommendations could quietly steer purchases. Primary risk.
- Data and privacy: purchase histories are not PHI, but reuse rights are undefined. Secondary risk.
- Operational and workflow: buyers may over-trust the recommendations once the tool feels routine.
- Compliance and regulatory: low direct exposure for this use case; confirm with compliance.
- Clinical and patient safety: indirect, through shortage decisions. Keep a human decision on every substitution.
Approval gate placement
This proposal sits at risk review. It should not advance to approve-and-scope until the block 2 and block 3 evidence arrives. If it advances, the pilot should have a defined baseline, a named owner, human sign-off on every recommendation, alert thresholds, and kill criteria agreed before launch.
Executive summary
Facts: rented model, cloud BAA signed, one self-run validation study, two hospital customers, free pilot with data-rights terms. Inferences: the hospital would be an early site and a data source; unit economics are likely unproven. Unknowns: error rates, de-identification method, exit terms, year-two pricing, continuity plan. The unknowns are the diligence agenda.
Compact AI formulary recommendation
- Approved indication and excluded uses: No approved indication yet. Consider only a restricted, non-patient-facing pilot for purchase-forecast review after validation evidence and data-rights terms are resolved. Exclude autonomous substitutions, direct inventory changes, patient-specific decisions, and any workflow that bypasses pharmacy buyer review.
- Exact product and model version: Veritas Rx Insight, version not documented. The underlying model provider, model version, update process, and hosted deployment terms must be named before pilot approval.
- Canvas findings: The strongest concern is incentive alignment: a free pilot paired with broad de-identified data reuse makes the hospital's purchase history a vendor resource. Hospital pharmacy is not the vendor's core segment, and exit terms are missing.
- Evidence gaps and local validation: Require the validation study, error rates by recommendation type, model-update policy, revised data reuse language, exit terms, and a local retrospective test against the hospital's last 12 months of shortage and purchasing decisions.
- Monitoring: Pharmacy purchasing director owns the pilot dashboard. Measures: stockout prediction accuracy, false positives, buyer overrides, recommendation acceptance rate, unresolved vendor tickets, and near-misses. Alert thresholds: any patient-safety near-miss, more than 10 percent high-impact false positives in a month, missing audit logs, or an unresolved data-rights issue.
- Reapproval or exit: Reapprove 90 days after pilot start and before any paid conversion. Renew only if local validation meets threshold and data terms are closed; restrict or revalidate after material model or workflow changes; suspend for patient-safety events or audit-log failure; retire if exit and continuity terms remain unresolved.