Enterprise Security
Identity, access and accountability
This page is maintained by ScribeMDPro to answer the access-control questions hospital IT and security teams ask during procurement. It states plainly what is active today and what is still planned.
Active today
Accounts authenticate with email and password or with Google. Sessions are managed by our authentication provider with automatic token refresh.
Clinic workspaces support owner, admin and clinician roles. Role changes and membership are controlled by owners and admins only.
Every record is protected by database-enforced access rules scoped to the signed-in user and their workspace, not by application code alone.
Administrative surfaces are gated by an explicit server-side role check and return aggregate data only — never transcripts, notes or patient content.
Workspace invitations are single-purpose, bound to the invited email address, and expire after 72 hours.
Document exports are recorded against the acting clinician so a workspace can reconstruct who exported what, and when.
Planned — not yet active
These capabilities are designed and prioritised but are not available today. Do not treat anything below as an implemented control during procurement.
- Single sign-on (SSO)
- Sign-in delegated to your hospital identity provider so accounts follow your existing joiner–mover–leaver process.
- SAML 2.0
- Enterprise SAML federation with your IdP, including domain-restricted sign-in.
- OAuth / OIDC for enterprise IdPs
- Standards-based federation for identity providers that prefer OIDC over SAML.
- SCIM provisioning
- Automated user creation, update and de-provisioning driven by your directory, so departures remove access immediately.
- Extended role-based access control
- Hospital admin, department admin, clinician, resident and medical student roles with department-scoped permissions.
- Session management console
- Administrator visibility of active sessions with the ability to revoke them and enforce session lifetime policy.
- Immutable audit logging
- Append-only records of login, export, recording, settings and administration events, retained for a configurable period and exportable for review.
If one of these is a hard requirement for your deployment, tell us during the security review — enterprise commitments influence sequencing.
Shared responsibility
- ScribeMDPro
- Platform security, access-control enforcement, secure handling of audio and transcripts in transit, dependency maintenance and incident response.
- Your organisation
- Managing who is invited to your workspace, enforcing your own device and password policy, removing departed staff, and ensuring clinicians review every note before it enters the medical record.
- Clinicians
- Reviewing and approving AI drafts, and avoiding patient-identifying content in support requests and feature feedback.
Related
See also the Trust Center, Security overview, Compliance and Backup & Disaster Recovery.
Bring your security questionnaire.
We answer directly, and we say 'not yet' where that is the honest answer.