Read-only deployment status
Mode and environment are stamped during deployment. The console reports their effective state and blockers but cannot switch mock, sandbox, or production traffic at runtime.
Manage facility registry mappings, review deployment-owned mode and readiness, govern evidence-backed releases, monitor delivery, recover eligible callbacks, and publish terminology releases without exposing patient payloads.
Mode and environment are stamped during deployment. The console reports their effective state and blockers but cannot switch mock, sandbox, or production traffic at runtime.
Super administrators maintain each tenant's HFR, HIP, and HIU identifiers and control registry verification. Tenants cannot enable modules, change stop controls, or edit ABDM-specific configuration.
Protected compliance evidence is bound to one exact build and environment. Release approval requires creator separation and two independent approvers. Expiry, revocation, or build drift fails closed.
Queues and ledgers expose identifiers, states, attempts, page coordinates, and failure codes only. Callback envelopes, ABHA identifiers, consent artefacts, keys, and clinical content remain protected.
Only eligible failed asynchronous callbacks can be replayed. Terminology releases are staged, validated, and activated as immutable versions.