PHASE 2 · SECURITY CONTROL PLANE

Identity and tenancy before clinical data.

Every sensitive portal will inherit the same security equation: identity + tenant + membership + entitlement + permission + resource scope.

Identity

ENFORCED

One MADOMIC OIDC identity across every portal and future standalone domain.

Tenant Context

ENFORCED

Every institutional request is revalidated against an active organization membership.

RBAC

ENFORCED

Roles are permission bundles; the default decision is deny.

Entitlements

ENFORCED

Subscription and feature access remain separate from organization permission.

Isolation

ENFORCED

Sensitive operational tenants target dedicated databases with opaque secret references.

Audit

ENFORCED

Sensitive activity is designed for append-only attribution and security review.