Search all 586 artefacts by title, document ID or content.
Printed on the standard letterhead. Page furniture, margins and repeating table headers come from the same stylesheet the PDF service uses.
Pensieve Labs
The operating system for hospitals
FRM-GL-509
v1.1.0 | 29 August 2026
Estimated completion time: 60 seconds. For hospitals that have reached the five-credential cap.
Why there is a cap. Five active credentials per hospital, enforced in the database. It is not a commercial limit and there is no charge to raise it. It exists so that the list of people who can read your workspace's documents stays a list somebody actually knows, and so that a departed employee's access is noticed.
POL-GL-500Section 1.3.You have two routes and both are quick. Replace a credential you no longer need: that is instant and needs no approval from
Pensieve Labs. Or ask for an additional one using this form.
| # | Field | Type | Required | Help text | Validation | Why it is needed |
|---|---|---|---|---|---|---|
| 1 | Hospital / workspace | prefilled | Yes | Prefilled from your credential | Read-only | Identifies the workspace the cap applies to |
| 2 | Requested by | prefilled | Yes | You must hold an active credential to submit this | Read-only | The request must come from inside the hospital, not from the new person |
| 3 | New user: full name | text | Yes | 2 to 100 characters | Access is granted to a person | |
| 4 | New user: work e-mail | Yes | Must be on the hospital's domain, or a domain you confirm belongs to the hospital group | Valid address | Domain determines whether auto-approval applies | |
| 5 | New user: role | select | Yes | Same list as FRM-GL-504 field 4 |
One value | Determines the documents surfaced |
| 6 | Route | radio | Yes | (a) Replace an existing credential (pick one below); (b) Request a sixth or further credential | One value | (a) is instant; (b) needs a decision |
| 7 | Credential to replace | select | Conditional | Required where route (a). Lists your five active credentials with the last access date | One value | The last-access date usually makes the choice obvious |
| 8 | Reason for an additional credential | textarea | Conditional | Required where route (b). One sentence is enough: for example, a second site, a separate finance reviewer, an external auditor engaged by you | ≤ 500 characters | It is the record of why the cap was raised, and it is what the quarterly access review reads |
| 9 | Duration needed | select | Yes | Permanent, Until a stated date | One value plus a date | A time-boxed credential is approved faster and expires without anybody having to remember |
| 10 | Authorised by | text | Yes | Name and designation of the person at the hospital authorising this | 2 to 150 characters | The hospital, not Pensieve Labs, decides who inside the hospital sees its documents |
Decision and service level.
| Route | Outcome | Timing |
|---|---|---|
| (a) Replace | Automatic. The replaced credential is revoked and NTC-GL-507 is sent to its holder |
Immediate |
| (b) Additional, time-boxed, on the hospital's own domain | Approved by the Trust Center admin | 4 business hours |
| (b) Additional, permanent, or on a domain outside the hospital's | Approved by the Founder | 1 Business Day |
| Refused | NTC-GL-506 with the ground and the alternative |
Same targets |
What raising the cap does not do. It does not change your Charges, does not require a Change Order, and
does not alter your Agreement. Every additional credential is reviewed at the next quarterly access review
(POL-GL-500 Section 4) and time-boxed credentials expire on their own.
External auditors and advisers. A credential for a person outside the hospital, such as an auditor, an
accreditation consultant, an IT adviser, is granted where the hospital authorises it in field 10, is
time-boxed by default, and is subject to NDA-GL-002. Pensieve Labs does not require a separate paper
NDA from the adviser.
Why both of these forms are public. This one source file carries two document identifiers, FRM-GL-504
and FRM-GL-509, and each is named on the closed public list at POL-GL-501 clause 1.5 on its own
recorded finding: FRM-GL-504 because it is the entry point to everything else, and FRM-GL-509 because
a form that asks for a credential cannot itself require one. A single frontmatter tier here
produces two register records, so each identifier is tested against clause 1.5 in its own right, and each
is counted separately in the register reconciliation that clause 1.5 requires at every review under
POL-GL-502. The list, and the finding recorded beside each row, are owned by POL-GL-501. Nothing in
these forms varies them.
| Topic | Document |
|---|---|
| Who gets access, refusal grounds, review and revocation | POL-GL-500 |
| Classification, the closed public list and the tier of these forms | POL-GL-501 |
| Trust Center terms of use | POL-GL-052 |
| Privacy Policy | POL-GL-053 |
| Click-through mutual NDA | NDA-GL-002 |
| Approval, refusal, revocation and cap e-mails | NTC-GL-505 to NTC-GL-508 |
| What is logged about your use | POL-GL-503 |
| Watermarking | POL-GL-510 |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.1.0 | 29 August 2026 | Trust Center Admin | Records the publication basis of both identifiers in this source file. FRM-GL-509 had been published at T_PUBLIC since first release, inside the FRM-GL-504 source file, without ever having been tested against POL-GL-501 clause 1.5, because one frontmatter tier here emits two register records. The amendment to POL-GL-501 clause 1.5 recorded in the same pass names FRM-GL-509 on the closed public list, and a new note at the foot of the FRM-GL-509 section states the finding recorded against each identifier and the control that each is tested and counted separately. POL-GL-501 is added to depends_on and to Related documents, and POL-GL-502, which the new note cites for the review at which the reconciliation is performed, is added to depends_on. The 1.0.0 row now carries its literal date rather than the current-version token, which a second row made wrong. No field, validation rule, route, decision target or approval authority changes. |
| 1.0.0 | 31 July 2026 | Trust Center Admin | First publication. Seven-field access request with a 40-second completion target, an explicit list of what is not asked for, and the four-business-hour decision target on its face; additional-credential form with an instant replace route, time-boxing by default, and hospital-side authorisation of every new credential. |