Access controls
Users sign in to their organization’s workspace. Their roles determine whether they can change settings, handle live conversations or approve actions.
Security, privacy & governance
Set who can access your workspace, which actions Korenact can take and when staff approval is required. Your facility must review the hosting, data handling and service agreements before going live.
Plan a healthcare pilotControls in the product
Users sign in to their organization’s workspace. Their roles determine whether they can change settings, handle live conversations or approve actions.
Choose the information a workflow can use and the actions it can take. An action cannot run without the required permission.
Appointment lookups and changes require verified contact details. Verification answers are masked in saved conversations and kept out of optional language processing.
Staff can review recorded permissions, approvals and action results, including failures and uncertain outcomes.
Rules are checked before an action runs. When staff approval is required, Korenact checks it again before proceeding.
Requests that need attention go to your staff queue with the allowed conversation details. Your team monitors the queue and decides when to respond.
Scheduling connections use authorized accounts. Credentials stay on the server; administrators manage only the approved connection settings in the workspace.
You can record a conversation retention target. Automatic deletion does not cover all records, so your deployment still needs an enforced retention process.
If you want to host on your own infrastructure, review the access, storage, recovery and service agreements that setup needs.
Review conversation results and connection health. Failed or uncertain actions are recorded separately from confirmed changes.
Operating your deployment
Product controls are part of the setup. Your team also needs to manage user access, connected services and staff follow-up.
Read the privacy policyYour deployment operator is responsible for secure connections, storage protection, backups, credential rotation and infrastructure access.
Confirm where connected services process data, what they may use it for, how long they keep it and which agreements apply.
Assign staff to review exceptions, investigate uncertain results and respond to privacy or security requests. A request in the queue still needs someone to accept and handle it.
Before using patient data
Korenact does not claim HIPAA, SOC 2 or HITRUST certification. Single sign-on, multi-factor authentication, automated deletion across all records and a published service-level agreement are not included in this release.
Before handling regulated or confidential information, review security, privacy and contractual requirements. Confirm that the required agreements and controls are in place.
To report a security concern, request a private follow-up. Share a brief description first; do not include passwords, credentials or another person’s private information.
Discuss a pilot
Bring your questions about user access, patient information, hosting and staff responsibilities.