Levels
Each entry in the record can be rendered at up to four levels. A grant sets a ceiling per domain; the compiler renders each entry at or below it.
A level is a ceiling, never a licence. A recipient MUST hold a valid grant for every domain it reads, including at L0, and a recipient without one receives no record content and no category-presence information. There is no level a recipient reaches by authenticating alone.
What L1 removes
Personal names. Exact dates of birth (age bands are returned instead). Addresses below region. Phone numbers, email addresses, account and loyalty numbers. Employer and institution names.
Free text
Automatic redaction of free text is not reliable, so for free-text values the L1 rendering is a
string the person approved, held in rendering_overrides.L1. If none exists, the entry is not
returned at L1.
Keys that stop early
Not every key supports every level. The vocabulary states which. A coffee order has no L3. A medical alert returns no more than its category presence at L0, which is why L0 needs a grant of its own: knowing that a person has a medical alert is itself disclosure.
| Entry | L0 | L1 | L2 | L3 |
|---|---|---|---|---|
| Household | Includes minors | Partner and two children under 10 | Partner Sam; Ella (8), Noah (5) | Full names and dates of birth |
| Food allergy | Has a food allergy | Tree nuts, severe | Tree nuts, severe; carries an adrenaline pen | Plus the prescribing clinician |
| Coffee | Has a drink preference | Flat white, oat milk, extra shot | Same | Same |
| Mobility | Has an access need | Wheelchair user, needs step-free access | Plus chair dimensions | Plus a contact for assistance |