Tenancy and scope
A facility is the tenant, and it carries its jurisdiction. Isolation is a property of the data layer rather than a rule that route handlers are trusted to follow, so a new endpoint cannot accidentally be the one that leaks.
- Facility and jurisdiction on every clinical row, applied by a shared mixin
- Scope enforced as a dependency every clinical request passes through
- Cross-facility read, list and search denied where the query is built
- Role permissions per clinical role, on top of the facility scope
- Multi-tenant means multi-jurisdiction — adapters are selected from the tenant