Who
An organization ID and a pseudonymous person ID. The crosswalk to real identity is stored apart.
Search public pages, research tools, and SAVRN solutions.
The SAVRN method
Nine steps, in order, from a permitted dataset to a controlled release.
A model is only as good as the record behind it and the test in front of it. These are the nine steps the SAVRN method sets between a permitted dataset and a model that qualified people are willing to use.
Five kinds of tools
A language model explains approved information and helps with workflow. It is never the source of a number, and it never makes a professional decision.
Approved reference content
Versioned, expert-reviewed content is retrieved for the task at hand. Each answer names the content it used and stays inside the approved scope.
Totals, trends and completeness
Totals, changes, trends and completeness are computed in tested code. A language model explains the numbers. It does not produce them.
Simple before complex
Work starts with statistical baselines a person can read. A more complex model is compared only when the data and the outcome justify it.
Video and images
Software finds candidate moments and proposes clips. A person confirms identity and meaning before anything is published.
Routing and approval
Alerts are routed, approvals requested, decisions logged and access enforced, whatever a model generates.
Nine steps
Each step produces something a reviewer can check: a task definition, an approved corpus, a test result, a shadow record, an approval.
Steps 1 to 4
Decide the question, then build a clean, permitted, time-true dataset with a held-out test group.
Separate reporting, forecasting, recommendation support and risk research. Define the prediction time, the population, the outcome and the action before choosing a model.
Filter records by purpose and rights. Remove duplicates, keep provenance and exclude labels that no qualified person confirmed.
Use only what was known before the decision. Later diagnoses, return dates and follow-up notes stay out of the inputs.
Hold out whole people and later time periods, and a separate site where one exists. One person's neighboring records never sit on both sides of the test.
Steps 5 to 7
Beat simple baselines, measure harm as well as accuracy, and run without affecting decisions.
Compare against the current workflow, approved rules and a plain statistical baseline. A complex model has to beat all three.
Report calibration, precision and recall, uncertainty, results by subgroup, the effect of missing data and the workload that false alerts create.
Generate outputs without changing any decision. Check that the system is reliable and that staff find the output worth acting on.
Steps 8 to 9
Show that acting on the output improves outcomes, then ship a locked, monitored version.
Whether acting on the output improves outcomes is a separate question. It needs its own prospective comparison.
Lock versions, require scientific and professional approval, watch for drift and keep a way back. Nothing learns from unreviewed production conversations.
Record fields
Every observation carries the same fields, so a record can be traced, checked and withdrawn.
An organization ID and a pseudonymous person ID. The crosswalk to real identity is stored apart.
An event ID, the source, the units and the version of the protocol or device.
The time of the event, the time it arrived, and the time it became available to the person deciding.
A quality status, with missing values marked as missing.
The purposes the record may be used for, and the permission behind each one.
org-17 · person p-4c2eReal identity held in a separate, restricted storesession log · coach app · minutes · protocol v3Source, units and version travel with the valuehappened 16:30 · arrived 16:42 · seen by the decision-maker 16:45The third time keeps later facts out of trainingcomplete · 1 field marked missingMissing is recorded as missing, never filled inservice: yes · research: no · model training: noEach purpose has its own permissionFour mistakes
The method is built to prevent four common mistakes. Three of them are documented in the published research.
Records from the same person are not independent, and few of them carry a confirmed outcome. The sample size that matters depends on the outcome, the number of events and the follow-up.
Bahr and Holme, British Journal of Sports Medicine, 2003A model trained on past choices can repeat past practice. The record has to hold the action and the outcome, and any recommendation has to be tested against the effects of selection and exposure.
Across 125 head-to-head comparisons at low risk of bias, machine learning showed no advantage over plain logistic regression in orthopedic sports medicine.
Lu et al, Journal of ISAKOS, 2026A review of 38 injury prediction studies found three with scores above 0.9 and called their clinical relevance questionable, because of wide prediction windows and broad injury definitions.
Leckey et al, British Journal of Sports Medicine, 2025Continue
The principle sets out what a record holds. A design case shows the record, the rules and the measures in one field.
A practical first conversation
Bring one decision your team makes often, the data you hold today and the outcome you would measure. We will map the record that connects them.
The model produces its output and nobody acts on it. Staff compare the output with what happened. It shows whether the system is reliable before it can affect a decision.
A test on people the model has never seen, from a different organization where one exists. A review of 204 sports injury prediction models found that none had been tested this way.
A model tested with information that arrived after the decision looks better than it is. Each example may only use what the decision-maker could have known at that moment.
No. Deleting a source record stops future use. It does not instantly remove that record's influence from a model that was already trained, so SAVRN tracks which datasets went into each model version.
In this method, a named scientific lead and the responsible professionals for the field approve it in writing. The approved version is locked, monitored and can be rolled back.