Core Workflows
How MOOSH works, end to end
The demo (see Demo Lab) includes ten scenarios (S1–S10). The stories below show the orchestrated loop: go-live, Decision Packs for the HRBP/EHS shared service, closed-loop risk work, privacy walls, employee policy help, and hazard triage that stays human.
Onboarding to go-live
Priya Raman · S1Baseline, privacy check, connect systems, first cohort
Priya works through the activation gates as organisation owner.
Company policies
She opens /onboarding/policies, uploads a synthetic WHS policy, and compares indexed vs processor-gated states.
Both DPIA sign-offs recorded
The organisation owner signs, then an independent reviewer signs separately.
Goes live
The organisation activates and lands straight on the dashboard.
What proves it worked: policy version/status, separate-corpus boundary, the six-step checklist, and the dashboard redirect on completion.
The full loop: signal to proof
Jess → Sarah → Tom → Sarah → Marcus · S3Jess — Employee
Completes a check-in; her answer first feeds only her own private view.
Sarah — Shared service
May receive a Decision Pack by email, or open the risk from the exception cockpit, and records why.
Tom — Fix owner
Completes the fix and attaches evidence that it was done.
Sarah — HR reviewer
Records the consultation, and checks the fix actually worked.
Marcus — Board member
Confirms the improvement shows up at board level too.
Jess — Workplace risks
Opens /me/workplace-risks and sees only consolidated risks, action status, and approved report access — never individual scores.
What proves it worked: one linked chain — signal, risk, fix, consultation and board record all connect; the employee risk view shows floor-safe aggregates only.
The privacy wall
Sarah → Dan → Jess · S4Sarah — HR reviewer
Sees a small team marked as protected — present, but clearly unavailable.
Switch to Dan — Manager
The protected notice disappears completely; a team he doesn't manage simply isn't found, not “denied.”
Switch to Jess — Employee
Only her own data is visible — no team or company-wide view at all.
What proves it worked: at no point does a headcount, a reason, or even the existence of a record leak to someone who shouldn't see it.
Private policy assistant
Jess McAllister · S9Jess — Employee
Opens /me/policy-assistant from My MOOSH or the Support hub.
Cited answer
Asks a sample question and receives an answer that names policy and version.
Controls
Clears history, tries the AI-down fallback, and uses Talk to a human.
What proves it worked: owner-only route guard, policy-version citation, honest fallback, and clear-history state — HR cannot read the chat.
Decision Pack orchestration
Priya · S10Exception cockpit
Dashboard shows Decision Packs, overdue controls, and review triggers for the shared service.
Email + pack
A decision_pack_ready email deep-links to the Logistics pack; Priya reviews cited drafts.
Approve
She approves; work materialises. Auto-applied standard controls appear with AUTO_STANDARD_CONTROL audit.
What proves it worked: human gate on non-standard packs, transactional email outbox, Tier-3 auto-apply informational path.
Hazard report to proof it was fixed
Public portal → Sarah → Irene → Priya → DavidAnonymous report portal
A hazard is reported with no name attached, given a reference number.
Sarah — HR reviewer
Sorts the report by urgency and decides where it should go.
Irene — Investigator
Opens a locked-down investigation, gathers statements, creates a fix.
Priya — Runs the organisation
Closes the case with a documented reason.
David — Compliance officer
Confirms the closed case is reflected in the standards-coverage record.
What proves it worked: the anonymous reference number, the full trail from report to fix, and approved evidence at the end — with the reporter's identity never entering the chain.