⌘K

Health CompaniesGuide

Account, organization and access

Health Company sign-in, organization membership and the authorization chain.

On this page

Authentication

  • Managed authentication with email and password, and Google where enabled.
  • Email confirmation follows the platform's configured policy.
  • Password recovery uses a dedicated Health Company recovery route.
  • Returning members route to their authorized workspace; incomplete accounts route to onboarding.
  • Health Company and laboratory workspaces are separate; a Health Company account is never routed into laboratory setup.

Authorization chain

text
authenticated user
  → active organization membership
  → organization
  → Program / API client
  → environment
  → resource

Every step is verified server-side. Membership authorizes scoped workspace evidence; it never grants Partner API access or Production by itself.

  • Roles: administrator, developer and read-only member roles are held on the canonical membership.
  • Administrators and developers can issue Sandbox credentials and manage webhooks; testing-review requests require an administrator.
  • Members are visible in Settings. Invitations, role changes and removal are not self-service in the workspace today.

Related resources