Security, privacy and audit requirements · C0880
Does AuroraMed support RBAC, ABAC and ReBAC with a central policy decision point and local enforcement points?
In the pilot (v0.2.0, synthetic data)
Short answer
How would it be tested? The specification says policy decision under 50 ms p95 (still an open decision). That is the check for REQ-2202: the system must support RBAC, ABAC and ReBAC with a central policy decision point and local enforcement points. The pilot covers part of this. The rest is designed, not built. Where the code stands: Role (tier) + scope class (panel/unit/dept) + assignment; no purpose/context/consent or central PDP. Parts of it are explicitly marked as open in the specification.
This exists in the synthetic-data pilot only.
- Specification item
- REQ-2202
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- Does AuroraMed enforce access as role AND relationship AND purpose AND context AND consent AND risk AND quota for every read, write, print and export? Pilot
- Does AuroraMed provide break-glass emergency access with reason code, time limit, notifications and mandatory review? Pilot
- Does AuroraMed segment sensitive data into compartments with separate keys and policies (psychotherapy, SUD, HIV/STI, reproductive health, genetic, minors, VIP)? Designed
See it in context: Security, privacy, consent, audit and access control · Search the help center · Ask a question