Skip to content

Found a tenant

Founding a tenant enrolls its first device, then puts people, custodians and the first dataset in place, in a fixed order. A new tenant has no device and no device certificate (card). The first device enrolls with a one-use foundingToken in place of an approver. No later step needs the token. A re-founding, for a tenant that lost every device, uses the same call.

Each step below depends on the one before it:

  • An Admin cannot approve enrollments until the founding device exists.
  • Nobody can register a dataset until the backup key registration is complete.
  • Nobody can revoke a device or ask for a recovery until people hold roles.

The founding call

const client = await (
await sealdhealthcare.enroll({ hostname: 'records.example-health.com', tenantId, foundingToken })
).wait();

The founding order

  1. Enroll the founding device. The call above signs in, generates the device key and waits for a card. No approver exists yet. The token stands in for one, once.
  2. Enroll people and approve their devices. Bring alice, bob and carol in as people of the tenant. Review each device request from the founding device. See Approve an enrollment and People, devices and roles.
  3. Create the backup key. Name three to seven custodians and a quorum before registering any dataset. See Backup key and custodians.
  4. Register the first dataset. Do this only after the backup key registration is complete. See Datasets and, for a dataset on object storage, Datasets on S3.

What the SDK does for you

  • Signs the enrollment request with the founding token in place of an approver’s signature, once.
  • Verifies the returned card offline against the trust root built into the SDK before handing back a Client.
  • Refuses to register a dataset until a backup key registration exists and is complete.
  • Creates the dataset’s domain key when the registering person is the dataset’s first domain owner. Makes that key recoverable by break-glass recovery.

Decisions and errors you may see

Outcome or ErrorCodeWhenWhat to do
enrollment-lapsedThe founding token expired before the request completed.Ask for a new founding token and enroll again.
enrollment-rejectedThe request was withdrawn before it completed.Enroll again.
trust-failedThe returned card, or the identity authority behind it, failed its check against the trust root built into the SDK.Do not proceed. Contact support.
deny on datasets.registerThe backup key registration is still pending.Finish creating the backup key first.

Next