Identity & MFA
Keycloak-backed user administration and MFA controls. Signing re-verifies the password at the moment of decision.
A portable, self-hosted architecture for Saudi laboratories, with scoped identity and a clear conversation about operational readiness.
The reference architecture runs on customer-controlled hardware, without a cloud runtime dependency. Deployment inside the Kingdom is a hosting choice established with your organization.
Start with the controls that exist, then agree the operational prerequisites for your deployment.
Keycloak-backed user administration and MFA controls. Signing re-verifies the password at the moment of decision.
Working-site scope is resolved from the authenticated request. Governed changes validate their organization hierarchy.
An append-only mutation trail and separate approval history preserve changes. Patient record viewing is not audited today.
TLS termination, tested backup and restore, disaster recovery, monitoring and alerting must be established for the deployment. These are pilot prerequisites, not delivered infrastructure in the reference stack.
Designed to support ISO 15189 evidence. Not itself certified. Regulatory applicability and contractual requirements must be assessed for each deployment.
See the workflows, the quality gates, and the decisions behind every result.