Open stain opened 1 year ago
I expect each TRE could have different polices for the acceptability of provenance information. One TRE could accept a securely encoded assertion that a researcher is "safe", from there home TRE. But another TRE could only accept a securely encoded assertion of the researcher identity, from there home TRE, but then use locally held information (with its own provenance chain) to assess if the researcher is "safe".
It appears that SAIL's policy is to recheck all information passed to them.
The Sign-Off phase references a Agreement policy data document but does not yet specify what this should include or even if it should have a public URL.
Agreement Data
The Agreement data relevant to a Researcher will specify: