Skip to content

Share an S3 dataset with an outside partner

Keep a research or imaging dataset in the customer’s own S3 bucket and share it with a person at an outside partner. The partner’s person holds a vendor seat in the tenant.

Who does each step:

StepWho
1. Register the datasetAn Owner or Admin
2. Add the partner and invite a seatAn Owner or Admin
3. Share the datasetA domain owner of the dataset

The samples use the allowed helper from Access decisions.

1. Register the dataset on S3

The Seald Healthcare Cloud holds the bucket binding and its AWS role. No device ever holds them.

await allowed(await client.datasets.register({
name: 'imaging', classification: 'phi', storage: { kind: 'object-storage' },
storageBinding: { s3: { bucket: 'example-health-imaging', prefix: 'sealdhealthcare/', region: 'us-east-1', role: 'arn:aws:iam::123456789012:role/sealdhealthcare-cloud' } },
indexFields: ['modality', 'study_date'], segmentFields: [], retentionFloor: sixYears, firstOwner: alice,
}));

firstOwner becomes the dataset’s first domain owner.

2. Add the partner as a vendor and invite a seat

vendors.record records the partner’s contract. people.invite with the vendorId invites one person as a seat.

VendorEntryDraft fieldWhat it sets
nameThe partner’s name.
contractThe contract’s reference, startsAt and endsAt. At its end, the seats are offboarded.
baaThe BAA’s terms, or null. Without a BAA in force, seats never reach PHI.
reachThe datasets and actions the seats may ever be given. Include imaging.
seatsHow many people may hold a seat at once.
signInWhere the seats sign in.
responsibleThe person answerable for the partner.
const vendor = await allowed(await client.vendors.record(draft));
if (vendor) await allowed(await client.people.invite([{ email: 'j.ortiz@partner.example', roles: ['employee'], vendorId: vendor.vendorId }]));

The person enrolls a device on the invitation. See Enroll a device.

3. Share the dataset with the seat

await allowed(await client.domains.share(imaging.root, { person: seat }));
Deny reasonWhen
vendorThe dataset is outside the vendor’s reach, or it holds PHI and no BAA is in force.

Next