SDK
DocumentIndex
What the vault knows about a patient/exam/template (`docs/PROTOCOL.md §8`): keys, streams, clear metadata. Every field here is something the vault itself reads to route and authorize. The clinical content never appears on this model: it lives in the sealed object of each version, and a short sealed summary (name, title) lives in `encrypted_index`, which only a DEK holder opens. Exactly one `security_group_id` per document: sharing a patient with another team means copying it, never sharing its key.
class
Signature #
class DocumentIndex(*, document_id: str, workspace_id: str, resource: Literal['patients', 'exams', 'templates'], security_group_id: str, encrypted_keys: dict[str, EncryptedPayload], encrypted_index: EncryptedPayload | None = None, streams: dict[Literal['data', 'file'], DocumentStream] = {}, meta: dict[str, Any] = {}, created_at: str, created_by: str, updated_at: str, updated_by: str | None = None, is_archived: bool = False, is_deleted: bool = False) Bases: BaseModel
What the vault knows about a patient/exam/template (docs/PROTOCOL.md §8): keys, streams, clear metadata.
Every field here is something the vault itself reads to route and
authorize. The clinical content never appears on this model: it lives in
the sealed object of each version, and a short sealed summary (name,
title) lives in encrypted_index, which only a DEK holder opens.
Exactly one security_group_id per document: sharing a patient with
another team means copying it, never sharing its key.
Members #
document_id: str #
attribute
workspace_id: str #
attribute
resource: Literal['patients', 'exams', 'templates'] #
attribute
security_group_id: str #
attribute
encrypted_keys: dict[str, EncryptedPayload] #
attribute
encrypted_index: EncryptedPayload | None = None #
attribute
streams: dict[Literal['data', 'file'], DocumentStream] = {} #
attribute
meta: dict[str, Any] = {} #
attribute
created_at: str #
attribute
created_by: str #
attribute
updated_at: str #
attribute
updated_by: str | None = None #
attribute
is_archived: bool = False #
attribute
is_deleted: bool = False #
attribute
stream(name: StreamName = 'data') -> DocumentStream #
method
One stream's state; an empty stream when the vault sent none for `name`.
latest_version_id: str | None #
property
Shorthand for `stream("data").latest_version_id`.
versions: list[DocumentVersion] #
property
Shorthand for `stream("data").versions`.
pending_version_id: str | None #
property
Shorthand for `stream("data").pending_version_id`.