Platform, configuration and devices · C0840
Can one administrator change access policy, retention or alert settings alone?
In the pilot (v0.2.0, synthetic data)
Short answer
The pilot covers part of this. The rest is designed, not built. Pilot detail: Signed, versioned manifest; push needs two vendor operators; policy changes need dual control. Element Type Registry beyond capabilities not built. For reference, REQ-0109 (a top-priority requirement, all three tiers) says configuration changes affecting access policy, retention, tier, alert policy or code-alert definitions must require dual control and be versioned with rollback. Check: a single administrator cannot apply such a change; rollback restores the previous version and is audited.
This exists in the synthetic-data pilot only.
- Specification item
- REQ-0109
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- Can a clinic switch between the base, local, strict and sovereign privacy tiers? Designed
- Does AuroraMed support configuration simulation ("what-if") for access policies before activation? Designed
- Does AuroraMed provide a terminology management function (import, version pin, mapping, deprecation) with a release record per code-system update? Designed
- Does AuroraMed ship profile templates for US (HIPAA baseline), BR (LGPD), CO, CL, MX, PE and AR, each with values marked [verify] until counsel confirms? Designed
See it in context: Configuration, Element Type Registry and Jurisdiction Profiles · Search the help center · Ask a question