The handover, acknowledged by name
Handover today is verbal plus a diary on a shared PC. When the question comes — “why wasn’t the DNACPR flag passed to the night shift?” — there is no record of who was told what. Baton makes the handover a record: every item acknowledged by the named person taking over, critical items blocking close-out until they are, and the whole shift sealed.
One board, one writer, and a door that will not close
The shift lead who opens the handover owns the board. Everybody else holds a view of it: a staff device asks — “add this”, “I have read that” — and the lead’s browser decides, stamps the request with the identity the channel proved, and publishes the result.
- A device can only ever acknowledge as itself. The name in the record is the one the transport authenticated, so a forged payload acknowledges for the forger and nobody else.
- A critical item blocks the close-out until everyone taking over has acknowledged it — one function decides, so the button, its explanation and the seal cannot drift apart.
- Still not read at 19:55? The lead can knock the people it is waiting on. A knock carries no payload, and the app says “a knock was sent” — never “they were notified”.
- Agency staff join for tonight with no account at all — the link and the room are the admission.
CRITICAL Mrs Iqbal, room 4 DNACPR in place as of this afternoon — form at the front of the folder. ✓ Nia 19:47 ⨯ Sam WATCH Mrs Patel Family visiting at 9. ✓ Nia 19:49 ✓ Sam 19:50 ────────────────────────────── Seal handover [ blocked ] One critical item has not been acknowledged by everyone taking over.
A receipt for the folder, over a record nobody can read
Why it is not a chat app
The product is the acknowledge-by-name workflow and the sealed close-out. A critical item literally blocks the shift from closing until the person taking over has tapped it, and the seal binds authors, acknowledgers and times into one chain. A message thread cannot do that — not because it lacks a feature, but because nothing in it decides anything.
Weakest point, stated
The incumbent care suites bundle a handover-notes feature the home already pays for. Baton wins on per-person receipts and ciphertext storage, and on nothing else — so the pitch has to be the evidence, not the notes.
And the encryption cuts back: a home that fumbles its key loses the very records the regulator requires. The key file is offered the moment a shift is sealed, and key recovery has to be a first-class feature rather than a footnote. It is on the platform roadmap and is not built yet; this page will not pretend otherwise.
What it costs
Commercial — per home, per month
One licence per home, not per carer: agency staff come and go, and a per-seat price on a rota that changes nightly would be a price on the wrong thing.
The part that matters, in the open
One function decides whether a handover may close, and a critical item nobody acknowledged is the thing that blocks it.
closeBlockedBecause() {
if (this.closedAt) return 'This handover is already closed.';
if (!this.items.length) return 'Nothing has been handed over yet.';
if (!this.staff.length) return 'Nobody has joined for the next shift yet.';
const open = this.unacknowledgedCritical();
Taken from this app's source, not written for the page. Built on the Messaging Platform SDK.