Notes

FHIR scopes are the access boundary

A SMART scope names a resource and a permission. patient/Appointment.read is permission to read appointments for the patient in context. user/Appointment.read is permission to read appointments the signed-in user can see. system/Appointment.read is permission for a backend client, with no user in the session.

Lynx Labs requests the smallest set an engagement needs. A scheduling integration asks for schedule resources, and for patient demographics only when the workflow needs them. Write permission is requested only when the engagement writes. Broader scopes are not requested in advance of a defined need.

The EHR enforces the scopes the client organization approves. An integration cannot read or write past that grant. If the work changes, the scopes change with it, and the client approves the new set before it is used in production.