{
  "ok": true,
  "scope": "Identity governance, role-based access, approval workflow, separation-of-duties, and immutable-audit demonstration for the MaxArc Global Health Impact Platform. Governs authorized access and human decision controls across all existing platform modules WITHOUT real authentication, credentials, tokens, sessions, or live identity-provider integration.",
  "notice": "All data is synthetic and non-identifiable. No real names, real email addresses, passwords, hashes, tokens, credentials, secrets, patient identifiers, or precise locations are included. This is a synthetic governance demonstration, not a production identity system, authorization server, credential store, or security certification.",
  "authorizedReviewOnlyLabel": "FOR GLOBAL FUND / CCM / AUTHORIZED PARTNER REVIEW ONLY",
  "permittedUse": {
    "statement": "Materials are for authorized review only under minimum-necessary access; no anonymous or public access is implied. Access review does not grant ownership or commercial reuse rights.",
    "prohibits": [
      "unauthorized copying",
      "redistribution",
      "derivative or commercial use",
      "representation as formal approval or production certification",
      "representation as a production identity or authorization system"
    ],
    "excludes": [
      "real names",
      "real email addresses",
      "passwords, hashes, tokens, or credentials",
      "secrets",
      "patient identifiers",
      "precise location"
    ]
  },
  "summary": {
    "totalActors": 12,
    "activeActors": 10,
    "suspendedOrRevoked": 2,
    "privilegedActors": 4,
    "activeRoles": 23,
    "activePermissionSets": 22,
    "totalRequests": 9,
    "pendingRequests": 2,
    "approvedRequests": 3,
    "deniedRequests": 2,
    "blockedRequests": 2,
    "sodViolations": 4,
    "sodRules": 12,
    "secondReviewQueue": 4,
    "temporaryAccessNearingExpiration": 0,
    "temporaryAccessExpired": 1,
    "privilegedAccessReviews": 3,
    "overdueAccessReviews": 1,
    "accessReviewCompletion": 50,
    "emergencyAccessEvents": 1,
    "delegations": 2,
    "revokedDelegations": 1,
    "revocations": 2,
    "anomalousAccessSignals": 3,
    "totalRiskSignals": 6,
    "auditEvents": 7,
    "auditCompleteness": 86,
    "evidenceCompleteness": 80,
    "workflowTypesRepresented": 9,
    "byDecision": {
      "approved": 3,
      "blocked": 2,
      "pending": 2,
      "denied": 2
    },
    "byModule": {
      "fund-accountability": 4,
      "stockpile-logistics": 2,
      "lab-operations": 2,
      "restricted-patient-locator": 2,
      "authorized-review-room": 1,
      "asset-management": 1,
      "program-performance": 1
    },
    "boundaryReminder": {
      "impactDomain": "impact.maxarchealth.com",
      "impactPort": "3201",
      "medicalLibraryBoundary": "library.maxarchealth.com remains separate (port 3101, not used here)",
      "maxTraxEhrBoundary": "MaxTrax EHR remains separate; this is not a full EHR"
    }
  },
  "positioning": {
    "isSyntheticGovernanceDemonstration": true,
    "isNotProductionIdentitySystem": true,
    "isNotAuthorizationServer": true,
    "isNotCredentialStore": true,
    "isNotSecurityCertification": true,
    "noRealAuthentication": true,
    "noLiveIdentityProviderIntegration": true,
    "noProductionAccessEnforcement": true,
    "notAnEhr": true,
    "coversModules": [
      "fund-accountability",
      "stockpile-logistics",
      "lab-operations",
      "patient-continuity",
      "restricted-patient-locator",
      "asset-management",
      "program-performance",
      "ai-intelligence",
      "country-rollout",
      "authorized-review-room",
      "executive-review-packet"
    ]
  },
  "accessGovernancePosture": {
    "statement": "Access requires an authorized role, a valid purpose-of-use, an approved and explicit scope, and time-bounded authorization where applicable. Permissions are least-privilege and minimum-necessary. Module access and data access are distinct. Expired, revoked, suspended, and denied access remain visible and never expose restricted information.",
    "accessRequiresAuthorizedRolePurposeScope": true,
    "leastPrivilegeMinimumNecessary": true,
    "moduleAccessDistinctFromDataAccess": true,
    "scopesExplicit": true,
    "sensitiveAccessRequiresSecondReview": true,
    "conflictingRolesNotSilentlyAssigned": true,
    "requestorCannotApproveOwnRequest": true,
    "reviewersApproversAuditorsRequestorsSeparated": true,
    "temporaryAccessExpiresAutomatically": true,
    "expiredRevokedSuspendedDeniedRemainVisible": true,
    "delegatedAuthorityExplicitLimitedAttributableRevocable": true,
    "emergencyAccessExceptionalTimeLimitedDocumentedReviewedAudited": true,
    "deniedRequestsDoNotExposeRestrictedInformation": true,
    "privilegedAccessRequiresPeriodicReview": true,
    "noSilentDeletionOrRewriteOfAccessHistory": true,
    "everyDecisionAuditable": true
  },
  "separationOfDutiesPosture": {
    "statement": "Separation-of-duties rules keep requestors, approvers, reviewers, and auditors distinct where required. Violations remain blocked or pending, identify the violated rule, require reassignment or second review, remain auditable, and are never silently overridden.",
    "violationsRemainBlockedOrPending": true,
    "violationsIdentifyRule": true,
    "violationsRequireReassignmentOrSecondReview": true,
    "violationsRemainAuditable": true,
    "neverSilentlyOverridden": true
  },
  "approvalWorkflowPosture": {
    "statement": "Approval workflows span single, sequential, parallel, second-review, compliance, audit, emergency-post-review, expiration-review, and revocation-review types. Every approval record identifies request, step, required role, assigned reviewer, decision, timestamp, reason, evidence, separation-of-duties status, and audit reference.",
    "workflowTypes": [
      "single",
      "sequential",
      "parallel",
      "second-review",
      "compliance",
      "audit",
      "emergency-post-review",
      "expiration-review",
      "revocation-review"
    ]
  },
  "auditPosture": {
    "statement": "Audit events are append-only in this demonstration model. Historical events are not rewritten; corrections require a new linked event; deletion is not represented as an allowed control. Source-module audit records remain authoritative. This task does not implement a production cryptographic audit ledger.",
    "appendOnly": true,
    "historicalEventsNotRewritten": true,
    "correctionsRequireNewLinkedEvent": true,
    "deletionNotAnAllowedControl": true,
    "sourceModuleRecordsAuthoritative": true,
    "notProductionCryptographicLedger": true
  },
  "confidentialityPosture": {
    "statement": "Confidential governance materials are disclosed on a minimum-necessary basis to authorized roles only. No patient identity, precise location, credentials, secrets, or restricted operational data is included; all sample information is synthetic and non-identifiable.",
    "authorizedReviewOnly": true,
    "noAnonymousOrPublicAccess": true,
    "minimumNecessaryAccess": true,
    "noPatientIdentityLocationSecretsOrRestrictedOperationalData": true,
    "deniedRequestsDoNotExposeRestrictedInformation": true
  },
  "aiPosture": {
    "statement": "AI is assistive only. It surfaces conflicts, excessive or unusual access, expired-but-active access, missing approvals or evidence, self-approval attempts, and suspicious emergency-access patterns for authorized human reviewers. Confidence is not proof; an anomaly is not a finding until a human reviews and decides. AI never makes access-control decisions.",
    "assists": [
      "detect conflicting role assignments",
      "identify excessive or unusual access",
      "detect expired access still represented as active",
      "prioritize access reviews",
      "identify missing approvals or evidence",
      "detect self-approval attempts",
      "identify suspicious emergency-access patterns",
      "reconcile actor, role, organization, module, and scope records",
      "summarize audit history for authorized reviewers",
      "recommend access-review actions"
    ],
    "mustNot": [
      "autonomously grant access",
      "autonomously approve requests",
      "autonomously assign roles",
      "autonomously waive separation-of-duties rules",
      "autonomously activate emergency access",
      "autonomously revoke or suspend access",
      "autonomously alter audit history",
      "autonomously disclose restricted information",
      "autonomously close access reviews",
      "bypass evidence, human approval, minimum-necessary, expiration, revocation, or audit controls"
    ]
  },
  "humanControls": {
    "accessDecisionsRequireAuthorizedRole": true,
    "requestorCannotApproveOwnRequest": true,
    "sensitiveAccessRequiresSecondReview": true,
    "emergencyAccessRequiresPostReview": true,
    "privilegedAccessRequiresPeriodicReview": true,
    "revocationAndSuspensionRemainVisible": true,
    "auditHistoryAppendOnly": true
  },
  "boundary": {
    "impactDomain": "impact.maxarchealth.com",
    "impactPort": "3201",
    "medicalLibraryBoundary": "library.maxarchealth.com remains separate (port 3101, not used here)",
    "maxTraxEhrBoundary": "MaxTrax EHR remains separate; this is not a full EHR and implements no real authentication, credentials, or live identity-provider integration"
  },
  "modules": [
    {
      "id": "fund-accountability",
      "name": "Fund Accountability & Anti-Misuse"
    },
    {
      "id": "stockpile-logistics",
      "name": "Stockpile & Logistics (eLMIS-style)"
    },
    {
      "id": "lab-operations",
      "name": "Laboratory Operations (OpenLab-style)"
    },
    {
      "id": "patient-continuity",
      "name": "Patient Continuity & Follow-Up"
    },
    {
      "id": "restricted-patient-locator",
      "name": "Restricted Patient Locator & Authorized Search"
    },
    {
      "id": "asset-management",
      "name": "Asset Management & Equipment Accountability"
    },
    {
      "id": "program-performance",
      "name": "Program Performance & Results Accountability"
    },
    {
      "id": "ai-intelligence",
      "name": "Cross-Module AI Verification & Anomaly Intelligence"
    },
    {
      "id": "country-rollout",
      "name": "Country Rollout & Offline Readiness"
    },
    {
      "id": "authorized-review-room",
      "name": "Authorized Funder / CCM Review Room"
    },
    {
      "id": "executive-review-packet",
      "name": "Executive Review Packet & Controlled Download Center"
    }
  ],
  "policies": [
    {
      "id": "POL-LEAST-PRIV",
      "name": "Least-privilege & minimum-necessary",
      "reference": "MaxArc-IAG-POL-001"
    },
    {
      "id": "POL-SOD",
      "name": "Separation of duties",
      "reference": "MaxArc-IAG-POL-002"
    },
    {
      "id": "POL-EMERGENCY",
      "name": "Emergency break-glass access",
      "reference": "MaxArc-IAG-POL-003"
    },
    {
      "id": "POL-AUDIT",
      "name": "Append-only immutable audit",
      "reference": "MaxArc-IAG-POL-004"
    },
    {
      "id": "POL-PRIV-REVIEW",
      "name": "Privileged-access periodic review",
      "reference": "MaxArc-IAG-POL-005"
    }
  ],
  "routes": [
    "/identity-access-governance/actors",
    "/identity-access-governance/organizations",
    "/identity-access-governance/roles",
    "/identity-access-governance/permissions",
    "/identity-access-governance/access-requests",
    "/identity-access-governance/access-decisions",
    "/identity-access-governance/approval-chains",
    "/identity-access-governance/separation-of-duties",
    "/identity-access-governance/temporary-access",
    "/identity-access-governance/emergency-access",
    "/identity-access-governance/delegations",
    "/identity-access-governance/revocations",
    "/identity-access-governance/access-reviews",
    "/identity-access-governance/risk-signals",
    "/identity-access-governance/audit-events",
    "/identity-access-governance/evidence",
    "/identity-access-governance/summary",
    "/identity-access-governance-dashboard"
  ]
}