The Smart Health Hub

SHN Admin

Issue tier-based magic-link invitations.

Sprint 8 v1.2 LOCKED invitation-management. Sandbox-grade through June 9 Delaware Prior Auth Lab; production-grade Q3 2026. Authorized issuers per CTO Demo Access Reframe Sprint 8 v1.2 §3.1 Option (b) tier-based authority. MSE UX layer; substrate-side wire-contract via Integration Engineer.

5-tier RBAC invitation matrix

TierAudienceSandbox surface scopeAuthorized issuer
Tier 1Sovereign + State Medicaid + GovernorsFull sandbox + UC22 + multi-role demoCEO + CSO
Tier 2Provider org CIOs / leadershipProvider Enterprise AccountCOO + Network Coordinator + EPL
Tier 3Payer counterpartsPayer Enterprise AccountCOO + Network Coordinator + EPL
Tier 4Standards (HL7 + FHIR + DaVinci PAS)UC22 + FHIR/DaVinci profile mappingCSO + Julia Skapik
Tier 5Press / BriefingRead-only walkthroughCSO + ML

CEO retains override authority + revocation authority on any invitation. All invitations logged to substrate-event audit chain via Step 6 endpoint per ADR-022.

Issuance flow

  1. Authorized issuer selects tier + enters invitee email + organization context
  2. Substrate-side validates issuer authority + generates magic-link token (cryptographically random; HMAC-SHA256; 14-day expiry)
  3. Email template rendered with Brand Guide v1 application + tier-specific copy + magic-link URL
  4. SES outbound delivery with smarthealthhub.net DKIM/SPF/DMARC + reputation monitoring
  5. Substrate-event-record emitted per ADR-022 (issuance event + tier + invitee + issuer + audit-trail anchor)
  6. Invitation acceptance → magic-link landing page at smarthealthhub.net/signin/callback?token=... → tier-scoped Enterprise Account UX provisioned
  7. Per-invitee session expiry: 30 days post-acceptance (sandbox-grade); revocation at session-blacklist trigger