Public Administration & Healthcare

The population is everybody, and they did not choose you

A citizen cannot switch to another tax authority. A patient in an emergency department cannot shop around. Both sectors serve people who have no alternative, under rules written by somebody else, on systems that are older than most of the staff using them.

Where the requirements come from

Nobody here chose the identity requirements

In most industries identity is a design decision. Here it is largely a translation exercise: an obligation arrives, and something in the architecture has to answer it.

eIDAS 2.0 and the European Digital Identity Wallet

Public administration

Accepting a credential the citizen holds and you did not issue, and verifying it without calling the issuer for permission.

National electronic identity schemes

Public administration

Federating with a scheme you do not control, at the assurance level the service requires — and degrading gracefully for people who do not have one.

NIS2

Both

Multifactor authentication on systems in scope, access governance you can evidence, and incident timelines that assume you can answer who had access.

GDPR, and health data as a special category

Both

Purpose-bound access, consent that can be withdrawn, and a record of who read what — not only of who changed it.

Clinical governance and professional registers

Healthcare

Access tied to a current professional registration, which expires, is suspended, and is maintained by a body outside your organisation.

Public administration

You verify an identity you did not issue

The citizen arrives holding a credential from a national scheme, a bank, or a wallet on their phone. Your job is to decide what it entitles them to — not to re-establish who they are.

Assurance levels, not a single front door

Checking a bin collection date and filing a planning objection are not the same act. Binding the required assurance to the service, rather than to the portal, is what keeps low-stakes services usable.

Agencies that must federate, not merge

Each body has its own mandate, its own legal basis and its own systems. Federation lets a citizen move between them without any agency handing over control of its register.

The people without a digital identity

Every scheme has a population it does not reach. A service that only works for wallet holders excludes exactly the people most likely to depend on it, which is a design failure rather than an edge case.

Records that outlive the systems

Retention obligations measured in decades meet platforms replaced every seven years. Whatever proves who accessed what has to survive the tool that recorded it.

Healthcare

The one case where refusing access is the dangerous option

Everywhere else, denying uncertain access is the safe default. In a clinical setting it is not — which is why break-glass exists, and why it has to be designed rather than tolerated.

  1. 1

    The clinician needs the record now

    A patient who is not theirs, on a ward they do not normally cover, at three in the morning. Every second spent on identity is a second not spent on care.

  2. 2

    Access is granted, not requested

    The system does not queue an approval. It lets them in, immediately, because refusing is the outcome with the worst possible failure mode.

  3. 3

    And it is announced

    The event is recorded, flagged and routed to whoever reviews break-glass use, while the clinician is still on the ward.

  4. 4

    Somebody reads it afterwards

    The review is the control. It only works if the volume is small enough to be read, which means routine access must never need break-glass.

Clinicians move, workstations do not

A shift covers several wards and a dozen shared terminals. Sign-in has to be seconds, repeatable, and must not tempt anybody into leaving a session open for the next person.

Registration is the real entitlement

The right to see a record follows a professional registration held by an external body — one that expires and can be suspended. The entitlement has to follow it, not a copy of it made at onboarding.

Reading is the sensitive act

In most systems the audit trail cares about changes. Here, who read a record is the question that matters, and it is asked long after the fact.

How Monokee approaches it

The obligation becomes a flow you can show somebody

External credentials as steps

National schemes, wallets and verifiable credentials are nodes in the journey, so accepting a new one is a change to a diagram rather than a project inside every service.

Break-glass as a designed path

Immediate access, with its own recording, its own notification and its own review — drawn explicitly, so what happens at three in the morning is a decision somebody made in advance.

Evidence produced by the flow

Because each branch is versioned and each decision recorded, the answer to an auditor or a regulator is a report rather than a reconstruction.

Bring us the obligation with a date on it

These programmes almost always start from a regulation rather than an idea. Working from the deadline backwards is usually the honest way to plan them.

Talk to an expert