Glossary
Security glossary
Defines the access, identity and audit terms used across the governance section, with a short plain description for each entry.
This glossary defines the access, identity and audit terms the governance section uses. Each entry gives a short, plain description you can return to whenever a page uses a word you want to pin down.
How to read this page
The terms fall into three groups: how a person is known, how access is decided, and how the record of access is kept. Read a group in order the first time, then treat this page as a reference.
Identity terms
How Pensieve knows who is present, and the state of an account.
| Term | What it means |
|---|---|
| Identity | The single account that stands for one member of staff across every site. |
| Sign-in | The act of proving you hold an identity, on a workstation. |
| Session | The period between sign-in and sign-out during which the platform knows who is present. |
| PIN | A short personal code used to sign in quickly on an enrolled workstation. |
| Passkey | A key held on your device or a hardware key that signs you in. |
| Enrolled workstation | A machine registered once, so it carries a credential that pairs with a person's PIN. |
| Handover | The moment one person's session on a shared workstation closes as the next person's opens. |
| Account state | Whether an identity is active, suspended or closed; an active account is the one that holds a session. |
Access terms
How Pensieve decides, for each action, whether a person may take it.
| Term | What it means |
|---|---|
| Role | The kind of work a person does, one input to an access decision. |
| Relationship | The current care connection between a member of staff and a patient, established by admission and consent. |
| Permission | The right to take one particular action. |
| Authorisation | The decision, for every action, of whether a person may take it. |
| Patient lens | The narrowing applied at the record read path, so a person sees the records their role and the patient's admission entitle them to. |
| Consent | A patient's directive about their own record, held as a first-class entry. |
| Emergency access | A defined, time-boxed, logged path to a record for an urgent case, opened with a stated reason. |
| Site boundary | The line that keeps each site's records within the site, crossed only under defined conditions. |
Audit terms
How the record of access and change is kept, and how a reviewer reads it.
| Term | What it means |
|---|---|
| Audit entry | The record that one action happened: who acted, what they touched, and when. |
| Audit trail | The append-only sequence of audit entries for a site. |
| Access history | The audit entries for reads and changes to one patient's record. |
| Attribution | The property that every entry names the person who made it. |
| Reason for access | The basis recorded for each access: a current care relationship, or an emergency access with a stated reason. |
| Retention | How long an audit entry is held before it is archived. |
Terms often confused
How do a role and a permission differ?
A role is the kind of work a person does. A permission is the right to one particular action. Pensieve reaches a permission from the role and the relationship together.
How do consent and authorisation differ?
Consent is the patient's directive about their record. Authorisation is the platform's decision about a specific action. The patient lens brings consent into that decision at the read path.
How do the audit trail and the access history differ?
The audit trail is the whole append-only sequence for a site. The access history is the slice of it for one patient's record.
These terms recur across every governance page, so a firm hold on them makes the rest read plainly. Read how the authorisation model decides each access at the authorisation model, and how the audit trail records it at the audit trail.