WritingEssay
On top of, not in charge of
Why the company that builds the applications must not own the layer beneath them.
No. 08 · June 2026 · 5 min read
There is a line in this design that decides everything, and it is easy to miss because it is a line of restraint rather than capability. The applications sit on top of the identity layer. They do not own it. KhaM Health builds the first applications, and it does not own the layer they stand on either.
The product a doctor sees is an application. A chamber workflow. A diagnostic center's upload screen. A pharmacist's verification check. A patient's wallet on a cheap phone. These are where a company competes on being good, and they should be as good as anyone can make them. But underneath them is the identity layer: the persistent identifier for every patient, doctor, clinic, lab, and pharmacy, and the credentials the issuers sign onto it. That layer is public-good infrastructure, and treating it as a company asset would poison the thing that makes it work.
The reason is trust, and trust here is structural, not promised. If the records are portable and the standards are open, a future government application could be built on the same identifiers without depending on KhaM Health at all. A competing clinical product in five years could read the same wallet, because the patient owns the wallet and the standard is public. The company cannot trap the record even if it wanted to, and that is the point.
A system the patient can leave is the only kind a patient can safely stay in.
This also changes the conversation a company can have with the state. The unwinnable version is trust this private company with the nation's health data. Nobody should say yes to that, and a careful state never will. The winnable version is different. The identity layer already runs on open standards. It already serves these patients and these doctors. The authorities already issue their own credentials onto it and hold their own keys. The state can formalize that arrangement without locking the country to anyone, including KhaM Health.
A company that owned the layer would have every incentive to make leaving expensive. A company that only builds on the layer has the opposite incentive: to make the applications so good that nobody wants to leave, while keeping the door open so they always could. The first is a trap dressed as a platform. The second is how infrastructure earns the right to be relied on.
So the restraint is not generosity. It is the condition that makes the whole thing trustworthy enough to become national. KhaM Health wins by building the best application on an open layer it does not control. Any other arrangement would win a smaller game and lose the one that matters.