Synthetic, masked
MaxArc Global Health Impact Platform
Identity, Access, Approval & Immutable Audit Governance
Authorized access and human decision controls across every platform module.
A synthetic governance demonstration — not a production identity system, authorization server, credential store, or security certification. No real authentication, passwords, API keys, tokens, sessions, cookies, OAuth, OIDC, SAML, LDAP, MFA delivery, credential storage, or live identity-provider integration is implemented. Access requires an authorized role, valid purpose, and explicit least-privilege scope; requestors cannot approve their own requests; sensitive access requires second review; temporary access auto-expires; and every request, decision, delegation, revocation, override, and emergency event is auditable. AI is assistive only and never grants, approves, assigns, waives, activates, revokes, closes, or discloses.
Least-privilege
Minimum-necessary
Awaiting decision
Human-approved
No restricted info exposed
SoD / policy
Blocked or pending
Sensitive access
Auto-expires
Remain visible
Periodic
Flagged
Post-reviewed
Reviews done
Human review
Append-only
Reviewed
Present
Of 9
Roles, permissions & scope
Roles are least-privilege and minimum-necessary. Module access and data access are distinct; country, facility, program, organization, and record scopes are explicit. Conflicting roles are never silently assigned.
| Role | Module scope | Data scope / purpose | Controls |
|---|---|---|---|
| Fund Disbursement Initiator ROLE-FUND-INITIATOR |
fund-accountability | Country A, PRG-HIV purpose: program-financial-operations |
minimum-necessary conflicts: ROLE-FUND-AUTHORIZER |
| Fund Release Authorizer ROLE-FUND-AUTHORIZER · privileged |
fund-accountability | Country A, PRG-HIV purpose: program-financial-authorization |
minimum-necessary conflicts: ROLE-FUND-INITIATOR |
| Warehouse Dispatcher ROLE-WAREHOUSE-DISPATCHER |
stockpile-logistics | Country B, FAC-B-007 purpose: supply-chain-operations |
minimum-necessary conflicts: ROLE-WAREHOUSE-RECEIVER |
| Warehouse Receiver ROLE-WAREHOUSE-RECEIVER |
stockpile-logistics | Country B, FAC-B-007 purpose: supply-chain-receiving |
minimum-necessary conflicts: ROLE-WAREHOUSE-DISPATCHER |
| Laboratory Result Preparer ROLE-LAB-PREPARER |
lab-operations | Country A, DEP-LAB purpose: laboratory-operations |
minimum-necessary conflicts: ROLE-LAB-RELEASER |
| Laboratory Result Releaser ROLE-LAB-RELEASER · privileged |
lab-operations | Country A, DEP-LAB purpose: laboratory-result-release |
minimum-necessary conflicts: ROLE-LAB-PREPARER |
| Restricted Locator Requestor ROLE-LOCATOR-REQUESTOR |
restricted-patient-locator | Country A purpose: authorized-patient-continuity |
minimum-necessary conflicts: ROLE-LOCATOR-APPROVER |
| Restricted Locator Disclosure Approver ROLE-LOCATOR-APPROVER · privileged |
restricted-patient-locator | Country A purpose: authorized-disclosure-review |
minimum-necessary conflicts: ROLE-LOCATOR-REQUESTOR |
| Asset Custodian ROLE-ASSET-CUSTODIAN |
asset-management | Country B, FAC-B-007 purpose: asset-stewardship |
minimum-necessary conflicts: ROLE-ASSET-VERIFIER |
| Asset Verifier ROLE-ASSET-VERIFIER |
asset-management | Country B, FAC-B-007 purpose: asset-verification |
minimum-necessary conflicts: ROLE-ASSET-CUSTODIAN |
| Program Result Submitter ROLE-PROGRAM-SUBMITTER |
program-performance | Country A, PRG-TB purpose: program-reporting |
minimum-necessary conflicts: ROLE-PROGRAM-CERTIFIER |
| Program Result Certifier ROLE-PROGRAM-CERTIFIER · privileged |
program-performance | Country A, PRG-TB purpose: program-certification |
minimum-necessary conflicts: ROLE-PROGRAM-SUBMITTER |
| AI Intelligence Case Creator ROLE-AI-CASE-CREATOR |
ai-intelligence | Regional purpose: anomaly-triage |
minimum-necessary conflicts: ROLE-AI-CASE-CLOSER |
| AI Intelligence Case Closer ROLE-AI-CASE-CLOSER · privileged |
ai-intelligence | Regional purpose: case-disposition |
minimum-necessary conflicts: ROLE-AI-CASE-CREATOR |
| Readiness Assessor ROLE-READINESS-ASSESSOR |
country-rollout | Country B purpose: readiness-assessment |
minimum-necessary conflicts: ROLE-DEPLOYMENT-AUTHORIZER |
| Deployment Authorizer ROLE-DEPLOYMENT-AUTHORIZER · privileged |
country-rollout | Country B purpose: deployment-authorization |
minimum-necessary conflicts: ROLE-READINESS-ASSESSOR |
| Evidence-Package Author ROLE-EVIDENCE-AUTHOR |
authorized-review-room | Regional purpose: evidence-package-preparation |
minimum-necessary conflicts: ROLE-EVIDENCE-APPROVER |
| Evidence-Package Approver ROLE-EVIDENCE-APPROVER · privileged |
authorized-review-room | Regional purpose: evidence-package-approval |
minimum-necessary conflicts: ROLE-EVIDENCE-AUTHOR |
| Packet Generator ROLE-PACKET-GENERATOR |
executive-review-packet | Regional purpose: packet-generation |
minimum-necessary conflicts: ROLE-PACKET-EXPORT-AUTHORIZER |
| Packet Export Authorizer ROLE-PACKET-EXPORT-AUTHORIZER · privileged |
executive-review-packet | Regional purpose: export-authorization |
minimum-necessary conflicts: ROLE-PACKET-GENERATOR |
| Independent Auditor ROLE-AUDITOR · privileged |
fund-accountability, stockpile-logistics, lab-operations, patient-continuity, restricted-patient-locator, asset-management, program-performance, ai-intelligence, country-rollout, authorized-review-room, executive-review-packet | Regional purpose: independent-audit |
minimum-necessary |
| Funder Reviewer ROLE-FUNDER-REVIEWER |
authorized-review-room, executive-review-packet | Regional purpose: authorized-review |
minimum-necessary |
| CCM Member ROLE-CCM-MEMBER |
authorized-review-room, executive-review-packet | Country A purpose: authorized-review |
minimum-necessary |
Access requests & decisions
Every request identifies requestor, purpose, requested scope, approving role, and evidence. Requestors cannot approve their own requests. Denied requests never expose restricted information. Expired, revoked, suspended, blocked, and denied access remain visible.
| Request | Requestor role | Requested scope | Status |
|---|---|---|---|
| AR-001 Initiate HIV program disbursement request |
ROLE-FUND-INITIATOR by ACT-01 |
fund-accountability data: Country A, PRG-HIV |
approved SoD compliant |
| AR-002 Self-authorize the same disbursement the requestor initiated |
ROLE-FUND-AUTHORIZER by ACT-02 |
fund-accountability data: Country A, PRG-HIV |
blocked SoD violation 2nd review rule: SOD-SELF-APPROVAL |
| AR-003 Confirm receipt of a consignment this actor dispatched |
ROLE-WAREHOUSE-DISPATCHER by ACT-03 |
stockpile-logistics data: Country B, FAC-B-007 |
pending SoD violation 2nd review rule: SOD-DISPATCH-RECEIPT |
| AR-004 Release restricted results this actor prepared |
ROLE-LAB-PREPARER by ACT-05 |
lab-operations data: Country A, DEP-LAB |
blocked SoD violation 2nd review rule: SOD-LAB-PREPARE-RELEASE |
| AR-005 Restricted locator disclosure for authorized continuity |
ROLE-LOCATOR-REQUESTOR by ACT-07 |
restricted-patient-locator data: Country A |
denied SoD compliant 2nd review |
| AR-006 Read-only review of an authorized evidence package |
ROLE-CCM-MEMBER by ACT-11 |
authorized-review-room data: Country A |
approved SoD compliant |
| AR-007 Elevated access to all modules with all data scopes |
ROLE-FUNDER-REVIEWER by ACT-10 |
fund-accountability, stockpile-logistics, lab-operations, restricted-patient-locator data: Regional, all-records |
denied SoD compliant 2nd review |
| AR-008 Verify the same asset held in custody by this actor |
ROLE-ASSET-CUSTODIAN by ACT-12 |
asset-management data: Country B, FAC-B-007 |
pending SoD violation 2nd review rule: SOD-ASSET-CUSTODY-VERIFY |
| AR-009 Read-only audit review across modules |
ROLE-AUDITOR by ACT-09 |
fund-accountability, program-performance data: Regional |
approved SoD compliant |
Separation-of-duties rules
Violations remain blocked or pending, identify the violated rule, require reassignment or second review, remain auditable, and are never silently overridden.
| Rule | Enforcement | Override / audit |
|---|---|---|
| Requestor cannot approve their own access request. SOD-SELF-APPROVAL |
blocked | never silently overridden auditable · e.g. AR-002 |
| Fund disbursement initiator cannot independently authorize release. SOD-FUND-INIT-AUTH |
blocked | never silently overridden auditable · e.g. AR-002 |
| Procurement creator cannot independently approve procurement. SOD-PROCUREMENT |
second-review | never silently overridden auditable |
| Warehouse dispatcher cannot independently confirm receipt. SOD-DISPATCH-RECEIPT |
pending | never silently overridden auditable · e.g. AR-003 |
| Laboratory result preparer cannot independently release restricted results. SOD-LAB-PREPARE-RELEASE |
blocked | never silently overridden auditable · e.g. AR-004 |
| Restricted-patient-locator requestor cannot independently approve disclosure. SOD-LOCATOR |
second-review | never silently overridden auditable · e.g. AR-005 |
| Asset custodian cannot independently verify the same asset where second review is required. SOD-ASSET-CUSTODY-VERIFY |
pending | never silently overridden auditable · e.g. AR-008 |
| Program-result submitter cannot independently certify the same result. SOD-PROGRAM-SUBMIT-CERTIFY |
second-review | never silently overridden auditable |
| AI intelligence case creator cannot independently close the case. SOD-AI-CREATE-CLOSE |
second-review | never silently overridden auditable |
| Readiness assessor cannot independently authorize deployment. SOD-READINESS-DEPLOY |
second-review | never silently overridden auditable |
| Evidence-package author cannot independently provide final approval. SOD-EVIDENCE-AUTHOR-APPROVE |
second-review | never silently overridden auditable |
| Packet generator cannot independently authorize export. SOD-PACKET-GENERATE-EXPORT |
second-review | never silently overridden auditable |
Approval workflows
Single, sequential, parallel, second-review, compliance, audit, emergency-post-review, expiration-review, and revocation-review workflows. Each approval record carries request, step, required role, assigned reviewer, decision, timestamp, reason, evidence, separation-of-duties status, and audit reference.
- single (AC-001 · AR-001)step 1: ROLE-FUND-AUTHORIZER → approved
- sequential (AC-002 · AR-009)step 1: ROLE-AUDITOR → recommended; step 2: ROLE-EVIDENCE-APPROVER → approved
- parallel (AC-003 · AR-006)step 1: ROLE-CCM-MEMBER → endorsed; step 1: ROLE-EVIDENCE-APPROVER → approved
- second-review (AC-004 · AR-002)step 1: ROLE-FUND-AUTHORIZER → blocked
- compliance (AC-005 · AR-005)step 1: ROLE-LOCATOR-APPROVER → denied
- audit (AC-006 · AR-009)step 1: ROLE-AUDITOR → reviewed
- emergency-post-review (AC-007 · EMG-001)step 1: ROLE-EVIDENCE-APPROVER → post-reviewed
- expiration-review (AC-008 · TMP-002)step 1: ROLE-EVIDENCE-APPROVER → expired-confirmed
- revocation-review (AC-009 · REV-001)step 1: ROLE-EVIDENCE-APPROVER → revocation-confirmed
Temporary access (auto-expires)
- TMP-001 — ACT-10 activeexpires 2026-08-15T00:00:00Z · auto-expires: yes
- TMP-002 — ACT-11 expiredexpires 2026-06-15T00:00:00Z · auto-expires: yes
Emergency break-glass (exceptional, post-reviewed)
- EMG-001 — Break-glass release of a time-critical laboratory result under documented exception post-reviewedexceptional: yes · time-limited: yes · documented: yes · audited: yes
Delegations (limited, attributable, revocable)
- DLG-001 — ACT-08 → ACT-11 activelimited: yes · revocable: yes · attributable: yes
- DLG-002 — ACT-02 → ACT-01 revokedlimited: yes · revocable: yes · attributable: yes
Access reviews (privileged & periodic)
- REVW-001 — fund-accountability privileged access completeprivileged · due 2026-06-01
- REVW-002 — restricted-patient-locator approvers overdueprivileged · due 2026-05-15
- REVW-003 — lab-operations releasers pendingperiodic · due 2026-07-15
- REVW-004 — executive-review-packet export authorizers completeprivileged · due 2026-06-10
Anomalous-access signals (human review required)
- self-approval-attempt — Actor attempted to approve their own fund request. highhuman review required: yes · autonomous action: no · open
- conflicting-role-assignment — Assignment would place dispatch and receipt with the same actor. highhuman review required: yes · autonomous action: no · open
- expired-access-active — Temporary access represented past its expiration — flagged for deactivation. mediumhuman review required: yes · autonomous action: no · resolved
- excessive-access-request — Request exceeded minimum-necessary scope. mediumhuman review required: yes · autonomous action: no · denied
- suspicious-emergency-access — Emergency break-glass access requires post-review confirmation. mediumhuman review required: yes · autonomous action: no · post-reviewed
- overdue-privileged-review — Privileged-access review is overdue for restricted-locator approvers. highhuman review required: yes · autonomous action: no · open
Immutable audit events (append-only)
- AUD-001 — access-request-approved approvedROLE-FUND-AUTHORIZER · fund-accountability · 2026-06-20T09:12:00Z · immutable: yes
- AUD-002 — self-approval-blocked blockedROLE-FUND-AUTHORIZER · fund-accountability · 2026-06-21T10:00:00Z · immutable: yes
- AUD-005 — disclosure-denied deniedROLE-LOCATOR-APPROVER · restricted-patient-locator · 2026-06-23T14:05:00Z · immutable: yes
- AUD-011 — emergency-access-granted granted-time-limitedROLE-LAB-RELEASER · lab-operations · 2026-06-30T17:30:00Z · immutable: yes
- AUD-011-C1 — audit-correction corrected correction of AUD-011ROLE-AUDITOR · lab-operations · 2026-07-01T09:00:00Z · immutable: yes
- AUD-014 — access-revoked revokedROLE-EVIDENCE-APPROVER · asset-management · 2026-06-18T12:00:00Z · immutable: yes
- AUD-019 — privileged-review-overdue overdueROLE-AUDITOR · restricted-patient-locator · 2026-05-16T00:00:00Z · immutable: yes
Audit events are append-only in this demonstration model; corrections require a new linked event; deletion is not represented as an allowed control; source-module audit records remain authoritative. This task does not implement a production cryptographic audit ledger.
Decisions by outcome
- approved 3
- blocked 2
- pending 2
- denied 2
Requests by module
- fund-accountability 4
- stockpile-logistics 2
- lab-operations 2
- restricted-patient-locator 2
- authorized-review-room 1
- asset-management 1
- program-performance 1
Module coverage
AI posture — assistive only, non-autonomous
AI assists with
- detect conflicting role assignments
- identify excessive or unusual access
- detect expired access still represented as active
- prioritize access reviews
- identify missing approvals or evidence
- detect self-approval attempts
- identify suspicious emergency-access patterns
- reconcile actor, role, organization, module, and scope records
- summarize audit history for authorized reviewers
- recommend access-review actions
AI must never
- autonomously grant access
- autonomously approve requests
- autonomously assign roles
- autonomously waive separation-of-duties rules
- autonomously activate emergency access
- autonomously revoke or suspend access
- autonomously alter audit history
- autonomously disclose restricted information
- autonomously close access reviews
- bypass evidence, human approval, minimum-necessary, expiration, revocation, or audit controls
AI is assistive only. It surfaces conflicts, excessive or unusual access, expired-but-active access, missing approvals or evidence, self-approval attempts, and suspicious emergency-access patterns for authorized human reviewers. Confidence is not proof; an anomaly is not a finding until a human reviews and decides. AI never makes access-control decisions.
Runtime boundary & linkage
- Impact runtime:
impact.maxarchealth.comon127.0.0.1:3201. - Governs access for fund accountability, stockpile & logistics, lab operations, patient continuity, restricted locator, asset management, program performance, AI intelligence, country rollout, the authorized review room, and the executive review packet & controlled download center — without coupling to MaxTrax EHR.
- Medical Library boundary remains separate at
library.maxarchealth.com(port3101) and is not used here. - MaxTrax EHR remains separate; this is not a full EHR and implements no real authentication or credentials.