Skip to content

evidence

client.evidence exports an evidence pack over a period and scope. It also makes the refs a customer compares against a pack. To verify a pack offline without enrollment, use verifyPack on Seald Healthcare, not evidence.

export

export exports an evidence pack for a person entitled to Export. For a subject scope, the SDK tokenizes the customer’s identifier for each epoch the period spans. The Seald Healthcare Cloud never sees the identifier.

export(scope: ExportScope, period: { from: Date; to: Date }): Promise<Decided<ExportedPack>>;
ParameterTypeDescription
scopeExportScopeThe whole tenant, a set of datasets, or one subject.
period{ from, to }The period the pack covers.

Returns: A Decided<ExportedPack>.

Records: Export. See Audit actions.

Who may call it: A person entitled to the Export action.

Errors: no-session, unreachable.

subjectRef

subjectRef makes a ref for a candidate identifier. The customer compares it with the ref in the pack, on its own side. The two refs are equal only for the same subject.

subjectRef(identifier: string, epoch: number): Promise<Ref>;
ParameterTypeDescription
identifierstringThe customer’s own identifier for the subject, such as a medical record number. The SDK never sends it to the Seald Healthcare Cloud.
epochnumberThe epoch the pack’s event falls in.

Returns: A Ref for the identifier at that epoch, to compare with the one in the pack.

Records: Nothing. Not a decision.

Errors: no-session.

personRef

personRef makes a ref for a candidate person, to compare with a ref in the pack.

personRef(person: Person, epoch: number): Promise<Ref>;
ParameterTypeDescription
personPersonThe candidate to resolve.
epochnumberThe epoch the pack’s event falls in.

Returns: A Ref for the person at that epoch, to compare with the actor or subject ref in the pack.

Records: Nothing. Not a decision.

Errors: no-session.

epochs

epochs lists the epochs a period spans.

epochs(period: { from: Date; to: Date }): Promise<number[]>;
ParameterTypeDescription
period{ from, to }The period to list epochs for.

Returns: Every epoch the period spans, to resolve a ref against each.

Records: Nothing. Not a decision.

Errors: no-session, unreachable.

Types

ExportScope

type ExportScope = { tenant: true } | { datasets: string[] } | { subject: string };
CasePayloadDescription
tenantnoneEvery event in the tenant.
datasetsdatasetsEvery event on the named datasets.
subjectsubjectEvery event naming this subject: an accounting of disclosures. The SDK tokenizes the identifier on the device per epoch. The Seald Healthcare Cloud never sees the identifier.

ExportedPack

interface ExportedPack {
packId: string;
eventId: EventId;
events: number;
bytes(): Promise<Bytes>;
}
FieldTypeDescription
packIdstringIdentifies the pack.
eventIdEventIdThe access event of this export.
eventsnumberHow many events the pack holds.
bytes()functionThe archive, in the evidence pack format. The SDK has sent the exporter’s manifest over it.

Ref

A keyed one-way ref and the epoch of the key that made it.

interface Ref {
ref: string;
epoch: number;
}
FieldTypeDescription
refstringThe one-way ref.
epochnumberThe epoch of the key that made it.

PackEvent

interface PackEvent {
id: EventId;
at: Date;
actor: Ref;
organization: string;
device: RecipientId;
action: string;
locator?: Locator;
version?: number;
subject?: Ref;
classification?: Classification;
policyVersion: string;
outcome: Outcome;
reason?: DenyReason;
riskScore: number;
offline: boolean;
hash: string;
}
FieldTypeDescription
idEventIdIdentifies the event.
atdateWhen it happened.
actorRefThe device’s person, as a ref.
organizationstringThe actor’s organization.
deviceRecipientIdThe device that made the call.
actionstringThe action recorded, from Audit actions.
locatorLocator, optionalThe object or key domain, where the event names one.
versionnumber, optionalThe version, where the event names one.
subjectRef, optionalThe record’s subject, as a ref, where the event names one.
classificationClassification, optionalThe object’s classification, where the event names one.
policyVersionstringThe policy version in effect when the decision was made.
outcomeOutcome"allow", "deny" or "challenge".
reasonDenyReason, optionalPresent on a deny outcome.
riskScorenumberThe risk score the decision carried.
offlinebooleanWhether the decision was made under an offline lease.
hashstringThe event’s own hash, chained for verification.

PackVerification

interface PackVerification {
verified: boolean;
failure?: {
check: 'chain' | 'checkpoint' | 'identity-authority' | 'card' | 'manifest' | 'pack-manifest' | 'policy-version';
detail: string;
};
tenantId: TenantId;
period: { from: Date; to: Date };
scope: 'tenant' | 'datasets' | 'subject';
events: PackEvent[];
policyVersions: PolicyVersion[];
checkpoints: { at: Date; authority: string; eventId: EventId }[];
controlStatus: { [control: string]: unknown };
}
FieldTypeDescription
verifiedbooleanWhether every check passed.
failure{ check, detail }, optionalThe first failure, in the order the checks run.
tenantIdTenantIdThe pack’s tenant.
period{ from, to }The period the pack covers.
scope"tenant", "datasets" or "subject"The pack’s scope.
eventsPackEvent[]Every event in the pack.
policyVersionsPolicyVersion[]The policy versions in effect over the period.
checkpointslist of at, authority and event idEach timestamp authority checkpoint over the chain.
controlStatusmap of control to statusThe control status for the period.

verifyPack produces a PackVerification offline, with no enrollment and no key. It is on Seald Healthcare.