Persistent emergency action

If this may be an emergency, open static guidance immediately — no API required.

Emergency help

Sante1 · Patient Command Center · local development

Patient Command Center

Trust & data control

Vos données, votre contrôle — your data, your choices.

This page is a local-dev skeleton only. It explains Sante1's intended patient trust model in plain language. There is no authentication, no real consent controls, no access history, and no health information collected or stored here today.

Demo only — policy preview, not legal advice

This skeleton summarizes direction from docs/architecture/patient-trust-model.md. It is not a privacy policy, not a consent flow, and does not certify regulatory compliance.

1. What Sante1 stores

Future coordination data — only what helps you navigate care over time.

Coming soon

Planned data categories (not collected in this skeleton)

When you use Sante1 with an account, the platform may store coordination facts you choose to keep: care episodes and workflow progress, your care team relationships, Emergency Health Passport snapshots you approve, language and notification preferences, and records of consent grants and revocations. Dashboards will show summaries — not raw clinical payloads by default.
  • Care episodes and timeline events — future
  • Care team and provider references — future
  • Passport snapshots you opt into — future
  • Consent and preference records — future

2. What Sante1 does not do without consent

Default is private to you.

Coming soon

Nothing silent, nothing bundled

Sante1 will not share your journey with providers, cache your passport offline for emergencies, send data to analytics programs, or grant family or household access unless you explicitly consent to each purpose separately. Local-dev demos use placeholder data only — no real sharing occurs today.
  • No provider sharing without consent
  • No offline passport cache without consent
  • No analytics / improvement use without opt-in
  • No family / household access without consent

3. Your Care Graph

One patient-controlled model — many views.

Coming soon

Projections, not separate silos

The Patient Command Center, Emergency Health Passport, My Care Team, and Care Episodes / Timeline are planned as projections of the same Care Graph — typed in @sante1/types as CareGraphProjection. You stay in control of what each view may show.

4. Emergency access

Different from everyday sharing — bounded and auditable.

Coming soon

Not a backdoor to your full record

Future emergency access covers only passport fields you pre-approved — not your entire intake or triage history. Access will be logged and visible to you when an account exists. Operational guidance (call 911) stays separate and always available offline.

Open Emergency help (static fallback)

5. Offline Emergency Passport control

Local snapshot, freshness, and delete.

Coming soon

Separate consent from navigation

Saving a passport snapshot on your device for offline emergencies will require its own consent. You will see freshness and staleness indicators, review reminders, and a clear control to delete local data. Encrypted on-device storage is planned — not implemented in this skeleton.

Open Emergency Passport skeleton

6. Sharing and revocation

QR codes, secure links, expiry — on your terms.

Coming soon

Future share controls (not available yet)

You will be able to generate time-limited secure links or QR codes, set expiry, revoke access instantly when online, and see who viewed shared summaries. Revocation stops new access; prior views remain in an audit history. No sharing controls exist in local-dev today.

7. Audit and transparency

Access history and explainable routing.

Coming soon

Future visibility (not available yet)

Sante1 plans a patient-facing access history — for example, when a provider viewed a shared summary — and plain-language explanations of why routing options were suggested (via routing decision factors). Sensitive actions will be auditable with actor, time, and purpose. This skeleton does not record or display access history.

8. Language and readability

Français et English — plain language first.

Coming soon

No legal jargon as the primary explanation

Trust copy, consent screens, and summaries will be readable in French and English from the start (Quebec-first). Rejecting optional uses will be as easy as accepting them — no dark patterns or bundled unrelated consents.
English — plannedFrançais — planned

Not implemented in this milestone

Authentication, consent APIs, passport storage, offline cache, QR sharing, provider notifications, and patient access history are documented for future steps only. See docs/architecture/patient-trust-model.md, docs/architecture/care-graph.md, and docs/architecture/emergency-health-passport-offline-contract.md in the repo.