Skip to content

Datasets

client.datasets lists the tenant’s datasets and registers new ones. A dataset is a customer-defined collection of records or files. It has one classification, one retention floor and one storage kind. Its root is a key domain of its own. Registering the first dataset needs the tenant’s backup key registration to be complete. Seald Healthcare refuses to create a dataset’s root key domain while nobody could recover it by break-glass recovery.

The calls

The samples use the allowed helper from Access decisions.

const datasets = await client.datasets.list();
// [{ name, classification, storage: { kind }, root, indexFields, subjectField, segmentFields, retentionFloor }, ...]
const sixYears = 6 * 365 * 24 * 60 * 60;
await allowed(await client.datasets.register({
name: 'encounters',
classification: 'phi',
storage: { kind: 'database' },
storageBinding: { database: { schema: 'clinical', table: 'encounters' } },
indexFields: ['visit_date'],
subjectField: 'mrn',
segmentFields: ['mrn', 'name', 'dob'],
retentionFloor: sixYears,
firstOwner: alice,
}));

The Dataset fields

FieldHolds
nameThe dataset’s name, unique in the tenant, such as encounters
classificationphi, pii, public or de-identified
storage.kindobject-storage, file-share or database
rootThe locator of the dataset’s root key domain
indexFieldsThe fields the SDK writes into every folder index under the dataset. They are searchable on the device
subjectFieldThe field the SDK tokenizes into the subject ref at save, such as mrn. Absent when the dataset has no subject
segmentFieldsFields with a segment key of their own, the HIPAA identifiers by default plus whatever the customer adds
retentionFloorSeconds an object must exist before anyone may delete it, whatever the tenant’s own policy says

register takes every Dataset field except root, which the Seald Healthcare Cloud assigns. In Swift and Kotlin, these fields form a DatasetRegistration. register also takes two more fields:

  • storageBinding tells the Seald Healthcare Cloud where the customer’s data lives. Its shape is particular to the storage kind.
  • firstOwner names the person who becomes the only domain owner of the new root key domain when it is created.

What the SDK does for you

  • Creates the dataset’s root key domain as part of registering it.
  • When the registering device’s person is the dataset’s firstOwner, creates the domain key in the same call. Makes the key recoverable by break-glass recovery.
  • Refuses register outright, before any call to the Seald Healthcare Cloud, while the tenant’s backup key registration is missing or still pending.
  • Tokenizes subjectField values at every save from then on. The field name is public. The values it holds never leave the device unhashed.

Decisions and errors you may see

Outcome or ErrorCodeWhenWhat to do
deny on registerThe caller does not hold the Owner or Admin role.Ask an Owner or Admin to register the dataset.
deny on registerThe backup key registration is not complete.Finish creating the backup key first.
not-foundfirstOwner names someone with no device certificate (card) in the tenant.Enroll and approve their device first.

Next