Skip to content

people

client.people manages the tenant’s people. It:

  • lists the tenant’s people and devices
  • reviews and answers enrollment requests
  • revokes devices and offboards people
  • changes roles for a person or a group

list

list returns every person in the tenant.

list(): Promise<TenantPerson[]>;

Returns: Every TenantPerson in the tenant.

Records: Nothing. Not a decision.

Errors: no-session, unreachable.

devices

devices returns device certificates (cards), for one person or for the whole tenant.

devices(person?: Person): Promise<Card[]>;
ParameterTypeDescription
personPerson, optionalOne person’s devices. When absent, every device in the tenant.

Returns: Every matching Card.

Records: Nothing. Not a decision.

Errors: no-session, unreachable.

enrollmentRequests

enrollmentRequests returns every enrollment request that waits on an approver.

enrollmentRequests(): Promise<EnrollmentRequestSummary[]>;

Returns: Every EnrollmentRequestSummary waiting on an approver.

Records: Nothing. Not a decision.

Errors: no-session, unreachable.

reviewEnrollment

reviewEnrollment opens a request for review and computes this device’s own comparison value. It then waits for the code. An Admin never reviews their own device.

reviewEnrollment(requestId: string): Promise<EnrollmentReview>;
ParameterTypeDescription
requestIdstringThe enrollment request to review.

Returns: An EnrollmentReview. Compare the code it computes against the one the new device’s person reads out, confirm who is asking, then call approve() or reject() on it.

Records: Nothing. Not a decision.

Who may call it: The Owner or Admin role, never for their own device’s request.

Errors: no-session, unreachable, not-found.

revoke

revoke revokes a device. It needs a fresh multi-factor sign-in. The device loses all access and its sessions end at once.

revoke(recipientId: RecipientId, reason: RevocationReason): Promise<Decided<{}>>;
ParameterTypeDescription
recipientIdRecipientIdThe device to revoke.
reasonRevocationReason"lost", "stolen" or "retired".

Returns: A Decided<{}>: allow once the card is revoked everywhere.

Records: Revoke. See Audit actions.

Who may call it: Anyone in the tenant with the Revoke action, but never for the device they are calling from.

Errors: no-session, unreachable, canceled, not-found.

offboard

offboard offboards a person and revokes everything at once. It lists the key domains that only the leaver owned, for break-glass recovery.

offboard(person: Person): Promise<Decided<{ ownerlessDomains: Locator[] }>>;
ParameterTypeDescription
personPersonThe person leaving the tenant.

Returns: A Decided carrying ownerlessDomains: the key domains that only this person owned, now waiting on break-glass recovery. In Swift and Kotlin the allow value is the list itself.

Records: Offboard. See Audit actions.

Errors: no-session, unreachable, not-found.

changeRole

changeRole gives or removes a role. A person cannot change their own role. A change to Owner or Admin carries the granter’s signature, after a fresh multi-factor sign-in.

changeRole(person: Person, role: Role, change: 'give' | 'remove'): Promise<Decided<{}>>;
ParameterTypeDescription
personPersonWhose role changes.
roleRoleThe role given or removed.
change"give" or "remove"Which direction.

Returns: A Decided<{}>.

Records: Change Role. See Audit actions.

Who may call it: The Owner or Admin role, never for their own role.

Errors: no-session, unreachable, canceled, not-found.

mapGroup

mapGroup maps an identity provider group to a role, as an Owner’s standing decision. The role is never Owner or Admin.

mapGroup(group: Group, role: Role): Promise<Decided<{}>>;
ParameterTypeDescription
groupGroupThe identity provider’s group.
roleRoleThe role every member gets while mapped. Never Owner or Admin.

Returns: A Decided<{}>.

Records: One decision and one access event.

Who may call it: The Owner role.

Errors: no-session, unreachable.

unmapGroup

unmapGroup removes a group’s mapping to a role.

unmapGroup(group: Group): Promise<Decided<{}>>;
ParameterTypeDescription
groupGroupThe mapping to remove.

Returns: A Decided<{}>.

Records: One decision and one access event.

Who may call it: The Owner role.

Errors: no-session, unreachable, not-found.

Types

RevocationReason

type RevocationReason = 'lost' | 'stolen' | 'retired';
ValueDescription
lostThe device is missing.
stolenThe device was taken.
retiredThe device was taken out of service in the ordinary course.

EnrollmentRequestSummary

interface EnrollmentRequestSummary {
requestId: string;
person: Person;
replaces?: RecipientId;
requestedAt: Date;
lapsesAt: Date;
}
FieldTypeDescription
requestIdstringIdentifies the request.
personPersonWho is asking.
replacesRecipientId, optionalThe card this device replaces, when it replaces a device rather than enrolling as a new one.
requestedAtdateWhen the request was made.
lapsesAtdateWhen it lapses unanswered.

EnrollmentReview

interface EnrollmentReview {
readonly requestId: string;
readonly person: Person;
readonly replaces?: RecipientId;
readonly code?: string;
waitForCode(): Promise<string>;
approve(): Promise<Decided<{}>>;
reject(): Promise<Decided<{}>>;
}
FieldTypeDescription
requestIdstringThe request being reviewed.
personPersonWho is asking.
replacesRecipientId, optionalThe card this device replaces, where it is a replacement.
codestring, optionalThe code this Client computed itself, once the new device has revealed its secret. The Seald Healthcare Cloud never supplies it.
waitForCode()functionResolves once code is available.
approve()functionApproves the request. Call it only after the approver compares the code and confirms who is asking. It needs a fresh multi-factor sign-in, then signs the exact request with this device key.
reject()functionRejects the request, after a code mismatch or an unconfirmed caller.

TenantPerson

interface TenantPerson {
person: Person;
roles: { role: Role; through?: Group }[];
organization: string;
devices: Card[];
agents: Card[];
}
FieldTypeDescription
personPersonThe person.
roleslist of role and optional groupEach role held, and the group it came through where mapped rather than given directly.
organizationstringThe person’s organization.
devicesCard[]This person’s own cards.
agentsCard[]The AI agents this person delegates to.