Technical FAQ

Everything you need to evaluate the Enterprise Intelligence Platform

Explore platform-wide questions about architecture, interoperability, deployment, security, analytics, AI, and the EIP component ecosystem.

Platform-level guidance, all in one place

The EIP has dedicated documentation and product sites for its core components. This page focuses on evaluation-level questions about the platform as a whole.

01

Platform overview

How the EIP is structured, who it serves, and how its components work together.

What is the EIP and how is it structured?

The Enterprise Intelligence Platform is an interoperable ecosystem comprising Enterprise DHIS2, Analytics Platform, Super BI, Convo AI, and Dharma, with advanced security embedded throughout.

Components can be deployed together as a full platform or selected according to an organisation's infrastructure, data environment, and use case. Data enters through collection tools, point-of-care device connectivity, and direct system integrations; flows through the central analytics and warehousing layer; and is surfaced through embedded dashboards, conversational AI, and connected partner software.

Can components be deployed independently?

Yes. The platform is modular. Organisations can deploy Analytics Platform, Super BI, and Convo AI without BAO ConneX when device connectivity is not required, or without Dharma when field data collection is not needed.

Organisations already running DHIS2 or partner systems can add the Analytics Platform as an extension layer without replacing existing infrastructure.

Which open data exchange standards does EIP support?

EIP is built around HL7, FHIR, and OpenHIE, supporting interoperability with standards-compliant systems and existing national health information architecture.

Who is EIP designed for?

EIP serves technical and non-technical roles within the same deployment, including data scientists, programme managers, ministers, public health leaders, and community partners.

Internationally, it is designed for ministries, national public health programmes, UN organisations, and implementing partners. In the United States, it supports state and local public health departments, agencies, and community partners.

02

Enterprise DHIS2

Hosting, performance, security, identity, support, and deployment options.

What is Enterprise DHIS2?

Enterprise DHIS2 is BAO Systems' enterprise-grade DHIS2 hosting and managed service, available as a standalone product or as part of EIP. It adds high-performance analytics infrastructure, enterprise security, SSO, proactive monitoring, and premium support to a standard DHIS2 deployment.

How does Enterprise DHIS2 improve analytics performance?

Enterprise DHIS2 separates operational and analytics workloads, using PostgreSQL for transactional data and ClickHouse for analytics. BAO benchmarks show approximately 22× faster analytics query response times and around 5× faster analytics table generation compared with a standard PostgreSQL setup.

What security does Enterprise DHIS2 provide?

Security capabilities include a Web Application Firewall enforcing the OWASP Core Rule Set, continuous DAST scanning, proactive patching, real-time infrastructure monitoring, Infrastructure as Code, storage-volume encryption, SSL/TLS, and encrypted PostgreSQL connections.

What SSO options are supported?

Enterprise DHIS2 integrates with Microsoft Entra ID and Google Identity Platform. BAO Systems can also host a dedicated Keycloak instance when an organisation does not already have an identity provider.

What does the support model include?

Premium support includes priority response, a dedicated contact familiar with the deployment, proactive monitoring, quarterly reports, scheduled review meetings, an annual upgrade environment, compatibility reporting, and a structured upgrade test plan.

Can BAO host other ecosystem components?

Yes. BAO Systems can provide managed hosting for tools commonly used alongside DHIS2, including ODK, Keycloak, and Apache Superset.

Where can Enterprise DHIS2 be deployed?

The standard managed service runs on AWS. Enterprise DHIS2 can also be deployed in an organisation's own Azure, GCP, AWS, or on-premise environment to meet data sovereignty and infrastructure requirements.

03

BAO ConneX

Device connectivity, last-mile infrastructure, protocols, and data handling.

What is BAO ConneX?

BAO ConneX is the EIP device-connectivity component. It ingests data from point-of-care laboratory devices, IoT hardware, and cold-chain equipment, including in environments with limited or unreliable connectivity.

What devices and protocols does it support?

ConneX supports molecular diagnostic devices, laboratory analysers, refrigerators, temperature monitors, and other compatible IoT hardware. Supported protocols include PC1A, HL7, custom XML payloads, and FHIR through ConneX Bridge.

How does ConneX work in low-resource environments?

Connect Link gateways include embedded cellular connectivity across more than 200 countries and 500 networks, use a private APN, queue data locally, and can defer transmission until network conditions improve.

How does ConneX handle patient data and PII?

Data is separated at ingestion into operational data, such as telemetry and connectivity metrics, and diagnostic data, such as laboratory results and patient-linked information. Access controls are enforced at both UI and API levels.

What third-party connectivity integrations are supported?

EIP also integrates with Nexleaf and EHA GHM for device connectivity.

What is ConneX Bridge?

ConneX Bridge routes processed device data into downstream systems such as laboratory information systems, EHRs, and HMIS platforms including DHIS2.

What is the current deployment scale?

BAO Systems supports more than 2,000 point-of-care gateways across seven sub-Saharan African countries and more than 1,000 gateways in the United States.

04

Dharma

Mobile-first data collection for field operations, surveys, and programme monitoring.

What is Dharma?

Dharma is BAO Systems' cloud-based, mobile-first data collection tool for field surveys, emergency response, and programme monitoring. Non-technical teams can build forms without code, and collected data synchronises when connectivity becomes available.

What is the difference between Dharma and ODK?

Dharma and ODK are independent products. ODK is an open-source third-party tool supported through a native Analytics Platform connector. Dharma is a proprietary BAO Systems product and supports Apple iOS as well as other mobile deployment contexts.

05

Analytics Platform

Data pipelines, warehousing, connectors, analytics, and visualisation.

What is the Analytics Platform?

The Analytics Platform automates data movement from multiple source systems into a central data warehouse and supports analysis through SQL, Python, R, natural-language querying, and embedded BI tools.

It is built on open-source foundations including PostgreSQL, ClickHouse, and Apache Superset, and is released under the BSD-3 Clause licence.

What data sources are supported out of the box?

The platform includes 22+ no-code connectors covering DHIS2, ODK, CommCare, KoBoToolbox, Ona, iHRIS, FHIR, BAO ConneX, Nexleaf, EHA GHM, MySQL, PostgreSQL, Oracle, Microsoft SQL Server, Parquet, Moodle, CSV, and Excel.

Which BI and visualisation tools are supported?

Apache Superset is included. Power BI and Tableau are supported, along with any BI tool capable of connecting to a SQL data warehouse. Partner integrations include Esri, Fraym, PublishOne, Crosscut, and BroadReach Vantage.

Can non-technical users query data without SQL?

Yes. Users can ask questions in plain language. The platform generates and executes SQL, then returns the result as a table and visualisation. Python and R scripts can also be generated from natural-language prompts.

What does a typical deployment look like?

Deployment patterns vary according to the source systems, security model, hosting environment, and intended analytics workflows. Detailed examples and setup guidance are available in the Analytics Platform documentation.

06

Convo AI

Conversational access to data and personalised analytical experiences.

What is Convo AI?

Convo AI is a DHIS2 application that provides a conversational interface to Analytics Platform data. It resolves plain-language questions to the relevant data elements, organisational units, and time periods, generates SQL, and returns charts and plain-language interpretations.

What is the Data Feed?

The Data Feed is a personalised analytics surface within Convo AI. Administrators assign topics to user profiles, and the platform surfaces automatically generated analyses and visualisations in a mobile-friendly, scrollable feed.

Is Convo AI open source?

Convo AI is currently proprietary and is not included in the open-source AP release.

07

AI & language model integration

How the platform uses language models while protecting sensitive data.

Does patient data get sent to the language model?

No. The model receives metadata such as data-element names, indicator names, attributes, and data-warehouse table structures. Patient records, PII, diagnostic results, and raw data values are not sent to an external model provider.

Which providers are supported, and can we use our own API key?

Google Gemini and OpenAI are currently supported. Customers can supply their own API key in both managed and self-hosted deployments. Support for self-hosted language models is planned.

How are tracker and individual-level data queried?

The Analytics Platform creates one warehouse table per DHIS2 tracker programme. This allows generated SQL to join across programmes while preserving organisational-unit row-level security.

08

Super BI & DHIS2 integration

Embedded dashboards, row-level security, and multi-instance analytics.

What is Super BI?

Super BI is a DHIS2 application that embeds Apache Superset dashboards built on Analytics Platform data directly inside the DHIS2 interface. Data is served from the warehouse, avoiding extra analytics load on the DHIS2 instance.

Does Super BI support organisational-unit access control?

Yes. Super BI applies warehouse-level row security based on the authenticated DHIS2 user's organisational-unit assignments. A single dashboard can therefore return different data to different users.

Can AP connect to multiple DHIS2 instances?

Yes. One Analytics Platform deployment can ingest from multiple DHIS2 instances, including ministry, disease-surveillance, partner, and tracker systems, enabling cross-instance analysis in one warehouse.

09

Model Context Protocol

A standard interface between EIP data and compatible AI tools.

What is the MCP component of EIP?

The Model Context Protocol component connects Convo AI and other MCP-compatible AI tools directly to platform data through a standardised interface, reducing the need for bespoke integration whenever a new AI capability is introduced.

10

Deployment & open source

Hosting models, source availability, and technical documentation.

What deployment options are available?
BAO managed hostingBAO deploys, operates, monitors, and supports the platform.
Self-hosted cloudDeploy within your own AWS, Azure, or GCP account.
On-premiseDeploy in your own data centre for sovereignty or infrastructure requirements.
Is the Analytics Platform open source?

Yes. The Analytics Platform is released under the permissive BSD-3 Clause licence and is also available with commercial managed hosting and support. Convo AI is currently proprietary.

Where can I find the full technical documentation?

Analytics Platform installation, configuration, connector, and API guidance is available at the AP documentation site. Enterprise DHIS2 performance, security, support, and AI information is available on the Enterprise DHIS2 product site.

Still evaluating?

Talk through your architecture with our team

Tell us about your source systems, hosting requirements, users, and implementation context.

© 2026 BAO Systems