Skip to content

objects

client.objects opens records and files, saves new versions, creates objects and deletes them. Every call is one decision: allow, deny or challenge. Each decision records one access event.

open

open opens one object. It gets one decision and one access event. The plaintext is in the returned value. Under an offline lease, open returns the copy the offline lease covers.

open(ref: ObjectRef, options?: { action?: OpenAction }): Promise<Decided<Opened>>

Parameters

NameTypeDescription
refObjectRefThe locator, and the version if not the current one.
actionOpenAction, optional, default viewWhat the open is for: viewing, an access record, or downloading a file.

Returns: Decided<Opened>: on allow, the open record or file.

Records: View, Access Record or Download File, as the action option says.

Errors: locked, no-session, unreachable if the stored object cannot be fetched and no offline lease covers it, storage-unreachable, container-invalid, trust-failed.

openField

openField opens one field alone. It uses that field’s key and nothing else.

openField(ref: ObjectRef, field: string): Promise<Decided<OpenedField>>

Parameters

NameTypeDescription
refObjectRefThe locator, and the version if not the current one.
fieldstringThe field name.

Returns: Decided<OpenedField>: on allow, that one field’s value.

Records: View Field.

Errors: locked, no-session, unreachable, storage-unreachable, container-invalid, trust-failed.

save

save saves the next version of an object. It retries on its own if another save in the key domain lands first. If the object itself has a newer version, it returns BaseMoved.

save(locator: Locator, content: RecordContent | FileContent, options: SaveOptions): Promise<Decided<SaveOutcome> | Drafted>

Parameters

NameTypeDescription
locatorLocatorThe object to save a new version of.
contentRecordContent | FileContentThe plaintext to save.
optionsSaveOptionsThe version the edit was made from, and the subject identifier for a record. In Swift and Kotlin, baseVersion and subject are trailing labeled parameters instead.

Returns: Decided<SaveOutcome> \| Drafted. Check 'outcome' in result in TypeScript. In Swift and Kotlin, check the SaveResult<SaveOutcome> case. On allow, a Saved, or a BaseMoved with the choice if the base moved. If the Seald Healthcare Cloud is unreachable, a Drafted locked to the device key.

Records: Save.

Errors: locked, no-session, storage-unreachable, container-invalid.

create

create creates a new object in a folder. The Seald Healthcare Cloud assigns a random locator. The new object’s version is 1.

create(folder: Locator, content: RecordContent | FileContent, options?: CreateOptions): Promise<Decided<Saved> | Drafted>

Parameters

NameTypeDescription
folderLocatorThe folder the new object is created in.
contentRecordContent | FileContentThe plaintext to save.
optionsCreateOptions, optionalThe subject identifier for a record. In Swift and Kotlin, subject is a trailing labeled parameter instead.

Returns: Decided<Saved> \| Drafted.

Records: Save.

Errors: locked, no-session, storage-unreachable, container-invalid.

acceptPending

acceptPending makes an AI agent’s pending version current. It counts as the delegator’s own save. Only the delegator may call it.

acceptPending(ref: Required<ObjectRef>): Promise<Decided<Saved>>

Parameters

NameTypeDescription
refObjectRef, version requiredThe pending version to accept.

Returns: Decided<Saved>.

Records: Save.

Who may call it: Only the agent’s delegator.

Errors: locked, no-session, not-found.

rejectPending

rejectPending leaves the pending version out of use for good. It never becomes current.

rejectPending(ref: Required<ObjectRef>): Promise<Decided<{}>>

Parameters

NameTypeDescription
refObjectRef, version requiredThe pending version to reject.

Returns: Decided<{}>.

Records: One decision and one access event.

Who may call it: Only the agent’s delegator.

Errors: locked, no-session, not-found.

delete

delete retires a version, or every version of an object, into the recycle bin.

delete(ref: ObjectRef): Promise<Decided<{}>>

Parameters

NameTypeDescription
refObjectRefThe object, or one version of it, to retire. With no version named, it retires every version.

Returns: Decided<{}>.

Records: Delete.

Who may call it: A domain owner only. The SDK refuses it under a legal hold or the dataset’s retention floor.

Errors: locked, no-session.

Types

ObjectKind

type ObjectKind = 'record' | 'file';
ValueMeaning
recordStructured fields, such as an encounter.
fileBytes with a name and a media type, such as a DICOM study.

ObjectRef

interface ObjectRef {
locator: Locator;
version?: number;
}
FieldTypeDescription
locatorLocatorThe object’s opaque id, the same across versions.
versionnumber, optionalThe current version unless the person chose an earlier one.

FieldValue

A record field’s value: what the customer’s row or document holds.

type FieldValue = string | number | boolean | null | FieldValue[] | { [field: string]: FieldValue };

Any JSON-shaped value: a string, a number, a boolean, null, an array of field values, or a nested object of field values.

RecordContent

interface RecordContent {
kind: 'record';
name: string;
fields: { [field: string]: FieldValue };
}
FieldTypeDescription
kind'record'The tag that makes this a RecordContent.
namestringThe record’s name, such as Visit note.
fields{ [field: string]: FieldValue }The record’s fields, by name.

FileContent

interface FileContent {
kind: 'file';
name: string;
type: string;
bytes: Bytes | ReadableStream<Bytes>;
size?: number;
}
FieldTypeDescription
kind'file'The tag that makes this a FileContent.
namestringThe file’s name.
typestringA media type.
bytesBytes | ReadableStream<Bytes>The file’s content, in memory or streamed.
sizenumber, optionalThe file’s size in bytes, where known ahead of streaming.

ObjectContent

type ObjectContent = RecordContent | FileContent;

What save and create take: a RecordContent or a FileContent. In Swift, wrap the value in .record(...) or .file(...). In Kotlin, RecordContent and FileContent implement ObjectContent directly. Pass either one as is.

SaveOptions

interface SaveOptions {
baseVersion: number;
subject?: string;
}
FieldTypeDescription
baseVersionnumberThe version the edit was made from.
subjectstring, optionalThe customer’s own identifier for the subject, such as a medical record number. The SDK tokenizes it into the subject ref under the tenant’s tokenization key. It never sends the identifier. For a record, if subject is absent, the SDK uses the dataset’s subject field.

CreateOptions

interface CreateOptions {
subject?: string;
}
FieldTypeDescription
subjectstring, optionalThe customer’s own identifier for the subject.

Saved

interface Saved {
kind: 'saved';
locator: Locator;
version: number;
pending: boolean;
}
FieldTypeDescription
kind'saved'The tag that makes this a Saved.
locatorLocatorThe object’s locator.
versionnumberThe version just saved.
pendingbooleanAn AI agent’s version, written but not current until its delegator calls acceptPending.

BaseMoved

The version the edit was made from is no longer current. The SDK encrypts nothing until the person chooses.

interface BaseMoved {
kind: 'base-moved';
currentVersion: number;
saveAnyway(): Promise<Saved>;
abandon(): void;
}
FieldTypeDescription
kind'base-moved'The tag that makes this a BaseMoved.
currentVersionnumberThe version that is now current.
saveAnyway() => Promise<Saved>Saves as the next version anyway. The saved object and its access event record the version it was made from.
abandon() => voidSaves nothing. Your application may open the current version and carry the changes over.

Drafted

The Seald Healthcare Cloud is unreachable. The SDK keeps the edit as a draft, locked to the device key, until the Seald Healthcare Cloud is back.

interface Drafted {
kind: 'draft';
draftId: string;
}
FieldTypeDescription
kind'draft'The tag that makes this a Drafted.
draftIdstringThe draft’s id, for offline.discardDraft or shown among offline.drafts().

SaveOutcome

type SaveOutcome = Saved | BaseMoved;

The allow payload of save: either the save went through as Saved, or the base moved and BaseMoved asks the person to choose.

SaveResult

What save and create return in Swift and Kotlin: a decision once the Seald Healthcare Cloud answers, or a draft while it is unreachable. TypeScript returns the union Decided<...> | Drafted. Check 'outcome' in result.

// inline in TypeScript:
Decided<SaveOutcome> | Drafted

OpenAction

type OpenAction = 'view' | 'access-record' | 'download-file';
ValueMeaning
viewAn ordinary open, for viewing.
access-recordAn open to give the record’s subject a copy.
download-fileAn open to download the file.

FurtherAction

type FurtherAction = 'copy' | 'print' | 'download-file' | 'access-record';
ValueMeaning
copyCopying what is open.
printPrinting what is open.
download-fileDownloading the open file.
access-recordGiving the record’s subject a copy of what is open.

Times

When an object was created and when a version was saved. TypeScript writes it inline as { created: Date; saved: Date } on OpenedBase and on the folders page’s Entry.

times: { created: Date; saved: Date };
FieldTypeDescription
createdDateWhen the object was created.
savedDateWhen this version was saved.

OpenedBase

The fields and methods every open shares, whether a record or a file.

interface OpenedBase {
locator: Locator;
version: number;
kind: ObjectKind;
name: string;
type: string;
size: number;
times: { created: Date; saved: Date };
baseVersion?: number;
pending: boolean;
writer: RecipientId;
epoch: number;
offline: boolean;
request(action: FurtherAction): Promise<Decided<{}>>;
close(): void;
}
FieldTypeDescription
locatorLocatorThe object’s locator.
versionnumberThe version that was opened.
kindObjectKindWhether this is a record or a file.
namestringThe object’s name, fixed when it was saved. Storage cannot change it.
typestringThe object’s media type, fixed when it was saved.
sizenumberThe object’s size, fixed when it was saved.
times{ created, saved }When the object was created and when this version was saved, fixed when it was saved.
baseVersionnumber, optionalThe version this one was saved from, where it is not the first.
pendingbooleanAn AI agent’s version, written but not current until its delegator accepts it.
writerRecipientIdThe device that saved this version.
epochnumberThe key domain epoch that protects this version.
offlinebooleanTrue under an offline lease. The decision was made when the offline lease was granted.
request(action: FurtherAction) => Promise<Decided<{}>>A further action on what is open, such as Copy or Print from the surface. It gets its own decision and access event. On allow, your application carries it out with the plaintext it already holds.
close() => voidDiscards the plaintext and every key of this open.

OpenedRecord

interface OpenedRecord extends OpenedBase {
kind: 'record';
fields: { [field: string]: FieldValue };
masked: { field: string; reason: DenyReason; text: string }[];
}
FieldTypeDescription
kind'record'The tag that makes this an OpenedRecord.
fields{ [field: string]: FieldValue }The record’s fields.
masked{ field, reason, text }[]Fields the policies denied even though the object opened. Your application shows them masked, with the reason.

OpenedFile

interface OpenedFile extends OpenedBase {
kind: 'file';
bytes(): Promise<Bytes>;
stream(): ReadableStream<Bytes>;
}
FieldTypeDescription
kind'file'The tag that makes this an OpenedFile.
bytes() => Promise<Bytes>The whole file, in memory.
stream() => ReadableStream<Bytes>The file, streamed.

Opened

type Opened = OpenedRecord | OpenedFile;

The allow payload of open: either an OpenedRecord or an OpenedFile, told apart by kind. In every language an Opened is itself an OpenedBase. opened.version, opened.request(...) and opened.close() work whichever kind it is. The members of one kind go through its case: in Swift case .record(let record): record.fields, in Kotlin is Opened.Record -> opened.record.fields and is Opened.File -> opened.file.stream().

OpenedField

interface OpenedField {
locator: Locator;
version: number;
field: string;
value: FieldValue;
close(): void;
}
FieldTypeDescription
locatorLocatorThe object the field belongs to.
versionnumberThe version that was opened.
fieldstringThe field name.
valueFieldValueThe field’s plaintext value.
close() => voidDiscards the plaintext and every key of this open.

Objects

interface Objects {
open(ref: ObjectRef, options?: { action?: OpenAction }): Promise<Decided<Opened>>;
openField(ref: ObjectRef, field: string): Promise<Decided<OpenedField>>;
save(locator: Locator, content: RecordContent | FileContent, options: SaveOptions): Promise<Decided<SaveOutcome> | Drafted>;
create(folder: Locator, content: RecordContent | FileContent, options?: CreateOptions): Promise<Decided<Saved> | Drafted>;
acceptPending(ref: Required<ObjectRef>): Promise<Decided<Saved>>;
rejectPending(ref: Required<ObjectRef>): Promise<Decided<{}>>;
delete(ref: ObjectRef): Promise<Decided<{}>>;
}

Objects groups the seven methods above into the namespace client.objects.