SDK

DocumentIndex

What the vault knows about a patient/exam/template (`docs/PROTOCOL.md §8`): keys, streams, clear metadata. Every field here is something the vault itself reads to route and authorize. The clinical content never appears on this model: it lives in the sealed object of each version, and a short sealed summary (name, title) lives in `encrypted_index`, which only a DEK holder opens. Exactly one `security_group_id` per document: sharing a patient with another team means copying it, never sharing its key.

On this page

class

Signature #

class DocumentIndex(*, document_id: str, workspace_id: str, resource: Literal['patients', 'exams', 'templates'], security_group_id: str, encrypted_keys: dict[str, EncryptedPayload], encrypted_index: EncryptedPayload | None = None, streams: dict[Literal['data', 'file'], DocumentStream] = {}, meta: dict[str, Any] = {}, created_at: str, created_by: str, updated_at: str, updated_by: str | None = None, is_archived: bool = False, is_deleted: bool = False)

Bases: BaseModel

What the vault knows about a patient/exam/template (docs/PROTOCOL.md §8): keys, streams, clear metadata.

Every field here is something the vault itself reads to route and authorize. The clinical content never appears on this model: it lives in the sealed object of each version, and a short sealed summary (name, title) lives in encrypted_index, which only a DEK holder opens.

Exactly one security_group_id per document: sharing a patient with another team means copying it, never sharing its key.

Members #

document_id: str #

attribute

workspace_id: str #

attribute

resource: Literal['patients', 'exams', 'templates'] #

attribute

security_group_id: str #

attribute

encrypted_keys: dict[str, EncryptedPayload] #

attribute

encrypted_index: EncryptedPayload | None = None #

attribute

streams: dict[Literal['data', 'file'], DocumentStream] = {} #

attribute

meta: dict[str, Any] = {} #

attribute

created_at: str #

attribute

created_by: str #

attribute

updated_at: str #

attribute

updated_by: str | None = None #

attribute

is_archived: bool = False #

attribute

is_deleted: bool = False #

attribute

stream(name: StreamName = 'data') -> DocumentStream #

method

One stream's state; an empty stream when the vault sent none for `name`.

latest_version_id: str | None #

property

Shorthand for `stream("data").latest_version_id`.

versions: list[DocumentVersion] #

property

Shorthand for `stream("data").versions`.

pending_version_id: str | None #

property

Shorthand for `stream("data").pending_version_id`.