Apps · Baton

The handover, acknowledged by name

Handover today is verbal plus a diary on a shared PC. When the question comes — “why wasn’t the DNACPR flag passed to the night shift?” — there is no record of who was told what. Baton makes the handover a record: every item acknowledged by the named person taking over, critical items blocking close-out until they are, and the whole shift sealed.

by name every acknowledgement stamped with the identity the channel authenticated, never a name in the message
all not “somebody” a critical item needs every person taking over — “one of them was told” is the answer that fails an inspection
0 readable bytes on our servers resident detail is encrypted in the browser; the key never leaves the home
1 receipt per shift counts and who took over — printable for the folder, with no resident detail in it
How it works

One board, one writer, and a door that will not close

The shift lead who opens the handover owns the board. Everybody else holds a view of it: a staff device asks — “add this”, “I have read that” — and the lead’s browser decides, stamps the request with the identity the channel proved, and publishes the result.

  • A device can only ever acknowledge as itself. The name in the record is the one the transport authenticated, so a forged payload acknowledges for the forger and nobody else.
  • A critical item blocks the close-out until everyone taking over has acknowledged it — one function decides, so the button, its explanation and the seal cannot drift apart.
  • Still not read at 19:55? The lead can knock the people it is waiting on. A knock carries no payload, and the app says “a knock was sent” — never “they were notified”.
  • Agency staff join for tonight with no account at all — the link and the room are the admission.
Willow Court · day → night19:45
CRITICAL  Mrs Iqbal, room 4
  DNACPR in place as of this
  afternoon — form at the front
  of the folder.
  ✓ Nia 19:47   ⨯ Sam

WATCH     Mrs Patel
  Family visiting at 9.
  ✓ Nia 19:49  ✓ Sam 19:50

──────────────────────────────
  Seal handover   [ blocked ]
  One critical item has not been
  acknowledged by everyone
  taking over.
Closing out

A receipt for the folder, over a record nobody can read

Sealone tap, two destinations
The boarditems, residents, who wrote what and who acknowledged it — encrypted in the lead’s browser and stored as ciphertext
The receiptthe hash of that board, the shift, the counts and who took over — signed into an append-only chain that verifies without us
The keya separate download. The home keeps it as it keeps its notes

Why it is not a chat app

The product is the acknowledge-by-name workflow and the sealed close-out. A critical item literally blocks the shift from closing until the person taking over has tapped it, and the seal binds authors, acknowledgers and times into one chain. A message thread cannot do that — not because it lacks a feature, but because nothing in it decides anything.

Weakest point, stated

The incumbent care suites bundle a handover-notes feature the home already pays for. Baton wins on per-person receipts and ciphertext storage, and on nothing else — so the pitch has to be the evidence, not the notes.

And the encryption cuts back: a home that fumbles its key loses the very records the regulator requires. The key file is offered the moment a shift is sealed, and key recovery has to be a first-class feature rather than a footnote. It is on the platform roadmap and is not built yet; this page will not pretend otherwise.

Pricing

What it costs

Commercial — per home, per month

One licence per home, not per carer: agency staff come and go, and a per-seat price on a rota that changes nightly would be a price on the wrong thing.

How it's built

The part that matters, in the open

One function decides whether a handover may close, and a critical item nobody acknowledged is the thing that blocks it.

js/baton-core.js
closeBlockedBecause() {
    if (this.closedAt) return 'This handover is already closed.';
    if (!this.items.length) return 'Nothing has been handed over yet.';
    if (!this.staff.length) return 'Nobody has joined for the next shift yet.';
    const open = this.unacknowledgedCritical();

Taken from this app's source, not written for the page. Built on the Messaging Platform SDK.