Onboarding an external agent
Technical integration is the easy half. These have to be true first, and the platform will not connect a practice until the blocking ones are.
#The channel checklist
| Requirement | Blocking |
|---|---|
| Channel partner agreement executed | yes |
| BAA chain recorded - who is the Business Associate, who is the subcontractor | yes |
| Application registered with the partner platform | yes |
| Contract cassettes recorded from the partner sandbox | yes |
| Partner security review complete | no |
Ticking a box you have not done
Marking "cassettes recorded" without recording them buys a channel that fails at its first real call, against a practice that believed it was connected. The live adapter refuses to start without them anyway.
#Then, per practice
A partner agreement grants nothing on its own. Each practice authorises separately:
- The practice records a consent reference - its own paper, not the partner's.
- The practice names the scopes it grants. A channel gets what the practice granted and nothing else.
- The connection is checked on every call, not cached at connection time.
- The practice can revoke unilaterally, without the partner agreeing and without leaving the platform.
#Contract prerequisites for the model side
- No training on our data, in writing.
- A deletion attestation.
- Named sub-processors, with notice before one is added.
- A BAA covering the actual data flow, not a generic one.
#Canary first
A new channel starts on canary practices with a lower external autonomy ceiling. It is widened after the contract suite has run against recorded cassettes and the first live calls have been reviewed by a person.