Security, privacy and audit requirements · C0879
Does AuroraMed enforce access as role AND relationship AND purpose AND context AND consent AND risk AND quota for every read, write, print and export?
In the pilot (v0.2.0, synthetic data)
Short answer
The security, privacy, consent, audit and access control part of the specification (REQ-2201) says the system must enforce access as role AND relationship AND purpose AND context AND consent AND risk AND quota for every read, write, print and export. The pilot covers part of this. The rest is designed, not built. Pilot detail: Role (tier) + scope class (panel/unit/dept) + assignment; no purpose/context/consent or central PDP. Acceptance check: denied request leaves audit record with decision trace.
This exists in the synthetic-data pilot only.
- Specification item
- REQ-2201
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- Does AuroraMed support RBAC, ABAC and ReBAC with a central policy decision point and local enforcement points? Pilot
- Does AuroraMed provide break-glass emergency access with reason code, time limit, notifications and mandatory review? Pilot
See it in context: Security, privacy, consent, audit and access control · Search the help center · Ask a question