A permission study · 01

Data needs a purpose.

Age bandAssay groupOutcome bandReplicateReviewTeach

A field is not a blanket invitation.

Consent Finch
Local research sandbox

Research permissions / Workspace 01

Permission has
a perimeter.

Define who may use which fields, for what purpose,
and for how long. Then test the boundary.

The decision rule

Purpose ∩ Fields
∩ Recipient ∩ Term

All must match. Revocation takes priority.
Synthetic onlyNo dataset yet

Start empty, or load a clearly marked synthetic example. No participant data is collected.

01

Field × purpose

Draft scope

Give a fictional dataset
a defined scope.

Create a schema with four predefined fields.
No records, names, or health values are accepted.

03

Rehearse an access request

Local simulation
Requested fields

Decision awaiting request

Four matches.
No shortcuts.

A single grant must cover the entire request. Two partial permissions cannot be stitched together.

04

Revoke, without rewriting history

0 grants

Revocation blocks future checks against that grant. It cannot retrieve copies already downloaded. Other matching grants remain valid.

No grants yet. Your first authorization will appear here.

Audit timeline

Recorded on this device; export timestamps are UTC. This editable local trail is not tamper-proof evidence.

  1. No events recorded.

A portable permission vocabulary

Shared templates.
The same right to withdraw.

Consent Finch explores an application token for access to purpose templates and shared audit workspaces across research apps. The local sandbox needs no token. Holding one would never override a data subject’s withdrawal.

This prototype is not legal compliance certification or a real medical data exchange network.

Shared workspace / service boundary

SOON

Cross-application template access and shared audit workspaces are not connected. There is no token issuance, payment, wallet signing, or data exchange in this prototype.

Your local grants and audit are unchanged.