01

Access is tenant, role, event, and case scoped

Organization roles do not automatically grant private case access. Providers cannot browse requesters or other providers, finance receives cost-only context, and onsite access is event and shift limited.

02

Sensitive actions leave evidence

State changes, disclosures, exports, access changes, imports, corrections, and immutable operational actions belong in the audit trail. Corrections append superseding events.

03

Verify controls during procurement

Security documentation must distinguish product requirements, current implementation, deployment configuration, and independently verified controls. Contact the team for deployment-specific evidence.

Operational boundary

Keep decisions human and evidence explicit

Evencue records decisions made by authorized organizers and coordinates their event-specific consequences. It does not determine legal reasonableness, medical validity, entitlement, or venue certification. Provider and onsite views receive only the information required for their task.

Common questions

What teams usually ask

Is data tenant-scoped?

Tenant isolation is a product invariant and is covered by deterministic repository and route tests in the current workspace.

Does every administrator see private cases?

No. Global ownership and administration do not automatically grant case content; case-manager access is separately controlled.

How are audit corrections handled?

A correction appends a superseding event with actor, timestamp, and reason instead of silently rewriting history.