How It Works

AI recommends. Rules protect. Patients decide.

Six-layer healthcare decision engine architecture diagram

Ensure Health's decision engine is built in six layers, ordered deliberately: safety and policy first, structured data second, low-cost AI third, the decision engine itself fourth, expensive frontier AI fifth, and the patient-facing action last. This ordering is the single most important architectural decision in the system — it's what allows us to say, credibly, that AI recommends, rules protect, and patients decide.

Architecture Overview

Layer 0
Safety & Policy
→
Layer 1
Structured Data
→
Layer 2
Low-Cost AI
→
Layer 3
Decision Engine
→
Layer 4
Frontier AI
→
Layer 5
Action — WellBee

The Layers

Layer 0 — Safety & Policy Engine
Permissions, consent, identity, escalation rules, and audit logging — enforced before any AI runs, not bolted on after.
Layer 1 — Structured Data
Patient, medication, coverage, and integration data normalized into a single internal model, using FHIR where appropriate.
Layer 2 — Low-Cost AI
Classification, entity extraction, summarization, and document parsing — using the cheapest model that clears the accuracy bar for the task.
Layer 3 — Decision Engine
The core. Ranks feasible pathways against need, cost, coverage, availability, location, and time — a legible, explainable ranking, not an opaque agent.
Layer 4 — Frontier AI
Used selectively, only where a task genuinely requires it: complex document synthesis, personalized explanations, administrative drafting.
Layer 5 — Action (WellBee)
The only layer with a member-visible surface. Every recommendation renders inside WellBee — the patient mobile app, and the only brand a member ever sees or downloads (getwellbee.com). Nothing happens without the member's approval. Ensure Health is the company behind the engine; WellBee is how members experience it.

A Real Example: Medication Pricing

When a member asks about a drug price, the engine runs a fixed-priority waterfall:

  1. Check the real-time adjudicated benefit price (via a PBM switch), because it correctly reflects deductible progress.
  2. If unavailable within 3 seconds, fall back to a cash/discount price.
  3. Compare both against generic and assistance-program alternatives.
  4. Surface the ranked, explained pathway — the member approves before anything happens.

See Pricing on the Employers page →

Why Not Just Use an Autonomous Agent?

A legible, constraint-ranked engine beats a general-purpose agent at this stage on four counts: explainability (a scored ranking shows its work), cost (selective model calls instead of default over-calling), regulatory posture (maps cleanly to FDA's Non-Device CDS criteria), and debuggability (any wrong recommendation traces to a specific data flag). More agentic techniques remain a future consideration once there's an outcome-labeled track record to evaluate them against.

Request a Demo