Security, privacy and audit requirements · C0917
When is consent checked, and what happens offline?
Designed, not yet built
Short answer
REQ-4402 is a top-priority requirement for all three tiers: consent must be enforced at read time by the policy engine using the ledger consent state, with a local cached copy for offline use bounded by staleness limit (still an open decision). Not yet. It is designed in the specification and not built in the pilot. To verify it, the specification says offline consent cache older than limit forces conservative deny except emergency. Parts of it are explicitly marked as open in the specification.
This is designed, not built.
- Specification item
- REQ-4402
- Specification priority
- P0 (of P0 to P3)
- Tiers
- Small, Medium, Large
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- What does a patient's consent record contain? Designed
- How does consent work for children, guardians, proxies and representatives? Designed
- Are substance-use, psychotherapy and reproductive-health records handled separately? Designed
See it in context: Consent management · Search the help center · Ask a question