A working example, not a demo
The gate, running on your own Mac.
One command installs Harness Desk: your records, MedGemma running locally through Ollama, and the same Fidelity Gate this site runs, checking every answer before you see it. Nothing here calls a cloud model. It drafts; a clinician decides.
curl -fsSL https://harnesshealth.ai/dl/install.sh | shmacOS 14+. Installs Node 24 and Ollama for you if you don't have them (no admin password). First run pulls MedGemma 4B, about 3.3 GB, once. Opens at http://127.0.0.1:3760 — that address never leaves your Mac.
What it does.
Five real behaviors, not a feature list — the same code the tests run against (desk/test.mjs, desk/test-edges.mjs).
Keeps a local record
Allergies, medications, conditions and documents in a SQLite file on your disk (~/.harness-desk). Searchable, deletable, never uploaded.
Drafts from MedGemma, locally
Answers your question from your own records, using MedGemma via Ollama on this Mac. No API key, no account, no cloud model.
Checks every answer against your records
The same Fidelity Gate the website runs: a dropped safety line, a changed dose, or an invented number triggers an automatic retry. Still fails and it is labelled NOT VERIFIED, with your own source lines shown instead.
Never waits on a model for a red flag
Chest pain, stroke signs, overdose, self-harm — triage is deterministic and fires before any model call.
Gives a clinician the last word
Approve, needs changes, or decline — each decision hash-chained to the one before it, so an edit after the fact is detectable.
What it does not do: it does not diagnose. The fidelity gate is a word match against your own records, not a reading — a “checked” answer can still be wrong in meaning. A clinician decides.
Why a signature company ships a local app.
HarnessHealth's actual product is the attested signature that a MedGemma (or any model's) output needs before it reaches a decision — see how that wires in. Harness Desk is the smallest real version of that pattern: draft, gate, human review — one person, their own machine, no infrastructure. It is not a product pilot. It is the fastest way to see whether the pattern is real before a real conversation about one.
Straight answers
Is this the same thing a pilot gets?
No — this is a smaller, single-user reference implementation: one person, their own records, running on their own machine. A pilot wires a real MedGemma (or other) application to a named, NPI-verified physician’s signature at scale. This page is where you can see the draft-until-attested pattern work, in under two minutes, before talking about a pilot.
How a pilot works →What if I do not have Node or Ollama installed?
The installer gets them for you, without an administrator password: a private Node 24 copy if your system Node is missing or too old, and the Ollama app into ~/Applications if it is not already there. Then it pulls MedGemma 4B (about 3.3 GB, once) and opens the app in your browser.
Does anything leave my Mac?
No. The model runs locally via Ollama. The record store is a local file. The one network call the installer itself makes is to download the program and the model weights — after that, asking a question makes no outbound request.
Is this a diagnosis tool?
No. It explains what your own records say and refuses to answer about anything they do not cover. A clinician reads the record, not the model. See the Review tab, and read Google’s own caveats about MedGemma.
What MedGemma’s maker says →Ready for more than your own Mac?
Same pattern, wired to a named, NPI-verified physician and a receipt anyone can verify.