# EyeHealthIntel Clinical — Partner engineering onboarding

Sandbox only, synthetic data only, non-diagnostic. Every analysis returns NOT_ASSESSABLE.

1. **Access** — receive an invitation to a sandbox organisation; sign in at `/clinical`.
2. **Credentials** — create a sandbox API key in the Partner Portal. It is shown once; store it in your secret manager. Keys are scoped and rate-limited; revoke and rotate freely.
3. **Explore** — open `/clinical/demo` for the synthetic workflow, sample FHIR bundle and webhook simulator.
4. **Integrate** — follow `api-quickstart.md` and the OpenAPI description at `/api/public/v1/clinical/openapi.json`.
5. **Webhooks** — register an HTTPS endpoint; verify `ehi-signature` (HMAC-SHA256 over `t.body`, 300 s tolerance) and de-duplicate on `ehi-event-id`.
6. **FHIR** — import `DiagnosticReport`, `Observation`, `DocumentReference`, `Device`, `Provenance` into a *test* EHR. There is no conclusion and no coded finding by design.
7. **Display rules** — show NOT_ASSESSABLE as "no analysis available". Never present Research or Traditional content (the API never emits it).
8. **Go-live gate** — real data requires a signed DPA, an approved pilot protocol and EyeHealthIntel enabling a non-sandbox environment. This is a human decision, never automatic.

Support: support@eyehealthintel.com · Security: security@eyehealthintel.com
