Signet · Deliver

Three surfaces. One release chain.

Patients receive a one-use link to their own report. Employers receive an aggregate that never shows a group smaller than ten. Clinic write-back occurs only when the deployment’s completion path is bound and where licensed.

Patient

Opaque link; code by SMS or email

One-use link plus a code by SMS or email. No account. No identifier in the URL. No report before clinician release.

The patient document is the clinician-signed smart report bound to what was reviewed. Critical content never takes the automatic delivery path. Channels stay closed until release is accepted.

Employer

Aggregate at the privacy floor

Aggregates are computed server-side. The privacy floor k ≥ 10 is absolute — raiseable by the tenant, never lowerable. It is not a default. Complementary suppression hides a cell when the cell or its complement is below the floor. No individual result is representable here.

HR sees completion status only where that view is in scope. Clinical and data-quality holds collapse to the same employer status label. The employer surface is not a write target for clinical content.

Clinic

Only when the completion path is bound and licensed

Write-back to the clinic system only when the deployment’s completion path is bound and where licensed. Refused if unbound or unlicensed. Receipts cover intake, release and delivery.

Refusals

What Deliver refuses

  • Patient access before clinician release
  • Employer views for groups below k ≥ 10 (or the tenant’s higher floor), including complementary suppression
  • Clinic write-back when the deployment’s completion path is not bound, or where write-back is not licensed
  • Cross-portal session reuse — each portal is its own origin
  • Automatic patient delivery of critical content

Delivery partners: write to the partner team.

Prev · Compose · Next · Trust and residency · Signet · Partners