Skip to content

Export an audit trail

Export the access events of a period as a signed evidence pack. An auditor verifies it offline, with no enrolled device.

Who can do this: a person entitled to Export. The pack is served to that person alone.

The samples use the allowed helper from Access decisions.

1. Export the pack

Choose one scope: the whole tenant, one or more datasets, or one patient.

const pack = await allowed(await client.evidence.export({ datasets: ['encounters'] }, { from, to }));
ScopeTypeScript
Whole tenant{ tenant: true }
Datasets{ datasets: ['encounters'] }
One patient, an accounting of disclosures{ subject: medicalRecordNumber }

2. Save the bytes

Hand the file to the auditor through your own channel.

if (pack) await writeFile(`evidence-${pack.packId}.sealdhealthcare`, await pack.bytes());

3. Verify the pack

The auditor calls verifyPack on the SDK, without a Client.

const verification = await sealdhealthcare.verifyPack(bytes);
if (!verification.verified) return render(verification.failure);
renderEvents(verification.events, verification.controlStatus);

failure names the first check that failed.

Next