Security & governance
What is enforced, what is recorded, and what is still incomplete
This page states the current posture of the platform without overstating it. Where a control is incomplete, it is labelled incomplete.
Controls
Control posture
Governance controls
| Control | State | Detail |
|---|---|---|
| Tenant boundary | Synthetic tenants only | Tenant identifiers are synthetic; no client tenant exists in this build |
| Identity separation | Enforced in schema | De-identified analytic tokens are held apart from identity crosswalks; analytic tables carry no direct identifiers |
| Role and purpose controls | INCOMPLETE | The review-context selector is a presentation control only. Server-enforced RBAC is not complete and must not be relied on |
| Approvals | Recorded, none granted | Approval records exist in the registry; no artifact has been approved |
| Audit | Server-side audit records | Model runs and governance reads are recorded server-side |
| Kill switches | Per-product, fail closed | Each analytic product executes only where its kill switch permits |
| Environment promotion | Blocked | Synthetic artifacts are permitted in local and test only; staging and production execution is refused |
| Refusal | Legitimate outcome | A refusal carries an explicit code and is never rendered as a generic error |
Safety
Hard safety boundaries
Boundaries that hold regardless of configuration
| Boundary | State |
|---|---|
| ECA member alerts | Never permitted |
| Automated denial of therapy | Disabled |
| Autonomous member contact | Disabled |
| Missing treated as negative | Prohibited — UNKNOWN remains UNKNOWN |
| Real PHI or production coefficients | Not present in this environment |
Server-enforced role-based access control is INCOMPLETE in this build. Access separation shown in the interface is a review presentation control and enforces no security boundary.