Named access
Administrator, storekeeper, doctor, nurse, therapist, staff and managed operation permissions.
AFIYORA describes controls that are verified, separates desktop safeguards from planned cloud architecture, and does not display compliance badges without evidence.
Access, data handling, backup and recovery must be reviewed in the deployment context.
These controls are available within the current desktop product scope and remain subject to correct customer deployment and administration.
Administrator, storekeeper, doctor, nurse, therapist, staff and managed operation permissions.
Named staff authentication with failed-login throttling and responsible-user attribution.
Automatic backups, export, validated import, database-integrity and checksum validation.
Restore preview and a safety snapshot before the selected backup is imported.
Batch, item, adjustment, asset and user activity remain available for operational review.
The desktop local server is designed for the clinic network, not direct public-internet exposure.
The future SaaS architecture is not presented as operational or certified until implementation and evidence are complete.
Planned separation between organizations and controlled support access.
Planned module activation, limits, roles, access review and joiner-mover-leaver workflows.
Planned operational audit, system status, background job and security-alert context.

Planned AFIYORA agents are scoped by permission and workflow. Sensitive actions require human review, and the full decision path remains attributable.
Agentic capabilities require product controls that make context, authority, review and intervention visible to clinic teams.
Each assistant has a defined role, data scope and permitted action set.
People can inspect the information and proposal before approval.
Professional and consequential actions remain under responsible control.
Teams can measure quality, handle exceptions and stop automation safely.
AFIYORA does not claim HIPAA, GDPR, DHA, DoH, MOHAP, NABIDH, Malaffi, ISO, SOC 2, PCI, FHIR or HL7 certification or integration without verified evidence.
Language, currency, tax, consent templates or country profiles can support localization, but do not establish legal or clinical compliance by themselves.
Share the deployment model, user roles, network boundary, backup expectations and integration requirements. We will respond with evidence-backed scope and clearly identified gaps.