Datasets
client.datasets lists the tenant’s datasets and registers new ones. A dataset is a customer-defined collection of records or files. It has one classification, one retention floor and one storage kind. Its root is a key domain of its own. Registering the first dataset needs the tenant’s backup key registration to be complete. Seald Healthcare refuses to create a dataset’s root key domain while nobody could recover it by break-glass recovery.
The calls
The samples use the allowed helper from Access decisions.
const datasets = await client.datasets.list();// [{ name, classification, storage: { kind }, root, indexFields, subjectField, segmentFields, retentionFloor }, ...]
const sixYears = 6 * 365 * 24 * 60 * 60;await allowed(await client.datasets.register({ name: 'encounters', classification: 'phi', storage: { kind: 'database' }, storageBinding: { database: { schema: 'clinical', table: 'encounters' } }, indexFields: ['visit_date'], subjectField: 'mrn', segmentFields: ['mrn', 'name', 'dob'], retentionFloor: sixYears, firstOwner: alice,}));let datasets = try await client.datasets.list()
let sixYears: TimeInterval = 6 * 365 * 24 * 60 * 60_ = try await allowed(client.datasets.register(DatasetRegistration( name: "encounters", classification: .phi, storage: Dataset.Storage(kind: .database), indexFields: ["visit_date"], subjectField: "mrn", segmentFields: ["mrn", "name", "dob"], retentionFloor: sixYears, storageBinding: .database(DatabaseBinding(schema: "clinical", table: "encounters")), firstOwner: alice)))val datasets = client.datasets.list()
val sixYears = (6 * 365).daysallowed(client.datasets.register(DatasetRegistration( name = "encounters", classification = Classification.PHI, storage = Dataset.Storage(kind = Dataset.Kind.DATABASE), indexFields = listOf("visit_date"), subjectField = "mrn", segmentFields = listOf("mrn", "name", "dob"), retentionFloor = sixYears, storageBinding = StorageBinding.Database(DatabaseBinding(schema = "clinical", table = "encounters")), firstOwner = alice)))The Dataset fields
| Field | Holds |
|---|---|
name | The dataset’s name, unique in the tenant, such as encounters |
classification | phi, pii, public or de-identified |
storage.kind | object-storage, file-share or database |
root | The locator of the dataset’s root key domain |
indexFields | The fields the SDK writes into every folder index under the dataset. They are searchable on the device |
subjectField | The field the SDK tokenizes into the subject ref at save, such as mrn. Absent when the dataset has no subject |
segmentFields | Fields with a segment key of their own, the HIPAA identifiers by default plus whatever the customer adds |
retentionFloor | Seconds an object must exist before anyone may delete it, whatever the tenant’s own policy says |
register takes every Dataset field except root, which the Seald Healthcare Cloud assigns. In Swift and Kotlin, these fields form a DatasetRegistration. register also takes two more fields:
storageBindingtells the Seald Healthcare Cloud where the customer’s data lives. Its shape is particular to the storage kind.firstOwnernames the person who becomes the only domain owner of the new root key domain when it is created.
What the SDK does for you
- Creates the dataset’s root key domain as part of registering it.
- When the registering device’s person is the dataset’s
firstOwner, creates the domain key in the same call. Makes the key recoverable by break-glass recovery. - Refuses
registeroutright, before any call to the Seald Healthcare Cloud, while the tenant’s backup key registration is missing or stillpending. - Tokenizes
subjectFieldvalues at every save from then on. The field name is public. The values it holds never leave the device unhashed.
Decisions and errors you may see
Outcome or ErrorCode | When | What to do |
|---|---|---|
deny on register | The caller does not hold the Owner or Admin role. | Ask an Owner or Admin to register the dataset. |
deny on register | The backup key registration is not complete. | Finish creating the backup key first. |
not-found | firstOwner names someone with no device certificate (card) in the tenant. | Enroll and approve their device first. |