πŸ₯ Clinical AI Assistant

AuthHub FGA

Live demonstration: FGA + AuthZEN + SCIM + Three-Clock Governance + Break-Glass + AI-Powered Clinical Decision Support

Minimal integration example. Production uses mTLS, multi-tenant isolation, Kafka event streaming, and enterprise IdP connectors.

0
API Calls
0ms
Avg Latency
0
AuthZ Decisions
0
Gov Events
Distributed System Trace
--:--:--SYS Awaiting first action...
Click "πŸ”„ Reset" to initialise the demo environment.

πŸ“– Demo Guide

β–Ό Show

What This Demonstrates

A clinical AI chatbot where every query passes through AuthHub's authorization engine. Access is controlled by FGA relationships, governed by three temporal clocks (event time, attestation time, execution time), and auditable in real-time.

The Three Clocks

Clock 1 (Event Time): When a structural identity event occurs (SCIM attribute change). Clock 2 (Attestation Time): When a human approver attests the delegation is still valid. Clock 3 (Execution Time): When the permission check actually runs β€” verifying conditions haven't drifted since attestation.

Flow

1Reset β€” Clear all state. Deny-by-default (no FGA tuple).
2Setup β€” Write FGA tuple + governance policy + SCIM user. Access granted.
3Chat β€” Ask AI. Per-message execution-time recheck via AuthZEN β†’ ALLOW β†’ DeepSeek responds.
4Org Change (Clock 1: Event Time) β€” Structural change detected. Governance suspends access immediately.
5Break-Glass (Lawful Continuation) β€” Not a clock. A bounded, supervised override with mandatory post-incident review. Time-limited (2 min), fully audited.
6Wait 2 min β€” Override auto-expires. Access reverts to DENIED. Suspension still active.
7Re-Attest (Clock 2: Attestation Time) β€” Data owner attests the delegation remains valid under new conditions. Permanent restore.
8Drift (Clock 3: Execution Time) β€” Environmental conditions changed since attestation. The attestation β€” valid when signed β€” no longer reflects reality. Re-suspended.
9Re-Attest again β€” Approve under the new environmental conditions.

Drift Thresholds (Two-Factor Model)

Drift threshold is NOT a single scalar. It decomposes into two independent concerns:

Per-Link Threshold
volatility_coefficient Γ— elapsed_since_attestation
Each delegation link has its own volatility β€” how fast ground truth moves in that domain. A GP federation (stable) vs a locum agency (volatile). Structural distance doesn't belong in this term.
Chain-Level Multiplier
chain_length β†’ re_attestation_cadence_multiplier
Longer chains force more aggressive re-attestation cadence, independent of any single link's volatility. Prevents mispricing risk on long, low-volatility chains.

Collapsing both into one scalar would quietly misprice risk on long, low-volatility chains β€” the product of many small risks compounds in ways a single threshold can't capture.

See Also

β†’ Common-Exposure Governance β€” When the thing that drifts isn't an individual subject but a shared condition (model provider, data processor) that multiple subjects depend on. Separates confirmed dependency (immediate suspension) from residual exposure (flagged for review).
Immutable Audit Trail
--:--:--SYSAwaiting actions...
πŸ™ Acknowledgements

The Three-Clock Governance model implemented in AuthHub was inspired by the work of the authorization community. The concepts of event time, attestation time, and execution time β€” and the insight that break-glass is a lawful-continuation branch rather than a clock in its own right β€” originate from collaborative discourse on temporal authorization boundaries.

πŸ“„ Read the original Three Clocks article on LinkedIn β†’

Special thanks to the following contributors whose thinking, feedback, and discussion shaped this implementation:

Ravi Shankar NRK Β· Kristina Vayo Β· Huck Huckaby Β· Greggory Don Butler Β· Brad Wolfe Β· Mark A.D Β· Christopher Gaither Β· Adriana Adria Β· Arvind SR Β· Dana Louw MBA Β· Arash Aghlara Β· Dasha Gorovenco-Gillespie Β· Adam S. Β· Rob Caswell Β· Custor 28 Β· Nikunj Dugar Β· Paul M. Β· Paul Roman Β· Grigori Korotkikh Β· Dani Danwin Β· Dan Lionello Β· Stephane Hoareau Β· Ilya Bubelo Β· Cyril Fautrai Β· Robert Hensley Β· Steve Tuthill Β· Michael Kozloff Β· Christof Schumann Β· Jennifer L. DiMotta Β· Sue Eze Β· Aaron Sempf Β· John Oluwafemi Jegede Β· Nick Mabe Β· Dr. Srinath Naidu Β· New Trend Computer Networks L.L.C Β· Virendra Vaishnav Β· Margaret Stokes Β· Jesper Jensen Β· Afsar Ahmed Β· Mohamed Adam Β· AurΓ©lie Jacquet Β· Anas Nuvy Β· Christopher Caruso Β· Lilian Crawford Β· James Stokes Β· S. Brady Alliy Β· Nalam Sriya Β· Jane Pollard Β· Digvijay Parmar Β· Rebecca Horrocks Β· Thierry Zedda Β· Swetha Gupta Β· AdeptiveAI Β· Akhilesh Warik Β· Nick Vejle Β· De Yu Chou