Traceability by design: auditing every query at the source
Every federated query leaves a trail in the institution that holds the data. This is how we designed the audit log to be useful, not just mandatory.
An audit log nobody can read protects nobody. We designed ours to answer three questions: who, what and why.
AuditEvent resources
Every access generates a FHIR AuditEvent at the source node, including the declared purpose of the query.
Visible to the institution
The data custodian can review every external access in their own console, filter by purpose and export reports for the regulator.

