Governance
Two data estates, one learner
Every statement below is stated as a design requirement for the platform. No legal compliance is claimed or verified; controller and processor roles are to be agreed with each institution.
Learner-controlled development data
The adaptive profile, practice history, reflections and portable summary belong to the learner and persist across sponsors with explicit consent.
- • Export in a portable format — design requirement
- • Correction workflow — design requirement
- • Deletion, including after sponsorship ends — design requirement
Institution-controlled assessment records
Formal assessment decisions, progression records and accreditation evidence remain the institution's record and are not portable by the learner.
- • Role-based institutional access (director, assessor, administrator)
- • Audit trail on every assessment view and change
- • Learners may view and challenge their own records
Consent lifecycle
Consent is renewed at graduation and at every sponsor change; it is granular, revocable and never bundled with continued access to the personal profile.
- • No dark patterns; discontinuation is presented equally
- • No sale of data and no unrelated reuse — design requirement
- • No training on identifiable learner data without explicit opt-in
Control matrix
| Data category | Controls it | Institutional visibility | Status |
|---|---|---|---|
| Personal development data (practice, adaptive activity, reflection) | Learner | No access to item-level data | Design requirement |
| Formal assessment records | Institution | Full access, role-based | Learner may view and request correction |
| Authorised portable summary | Learner authorises each recipient | Only if authorised | Time-bound authorisation |
| Cohort analytics | Institution | De-identified, minimum cohort size | Suppression below threshold |
| Patient-identifiable data | Not applicable | Never stored | Simulation uses fictional cases only |
Clinical governance
Named author role, independent clinical review, review dates, source standards, versioning and an escalation route for disputed content.
Controller / processor
Roles are to be agreed institution by institution. The platform makes no assertion about which party is controller for any given dataset.
Data residency
Regional cloud residency is a partnered capability, not yet an implemented feature.
Strategic terms such as clinical governance and controller/processor are defined in tooltips throughout the platform.