AnpherosAnpheros PlatformDevelopers

Consent and access model

Who sees what: project isolation, pairwise ids, grants, write ownership, provenance and what the patient sees about every application with access.

Rule: with the patient's consent an organisation sees the whole record — including what other clinics wrote — but can change or delete only what it wrote itself. Every version of every resource records the project that wrote it and the organisation on whose behalf it was written.

Who sees what

Writes and ownership

What the patient sees

/me/patients/{id}/grants lists every application with access, its scopes and expiry; …/access-log lists what each read or wrote — under the consent and with the project's own key. Revocation takes effect on the next request; the application cannot refresh back in.