A Identity and profilesOne account holds the person and the family members they look after, each profile with its own key.
B Keys held by the personRecord contents are sealed on the device before they synchronise.
C Consent and grantsAccess is given by wrapping the person's key for a named recipient; withdrawing it rotates the key.
D Exchange between partiesA relay that carries sealed material without being able to read what passes through it.
E Audit without contentEvery action is recorded; the log deliberately carries no medical content.
F Organisations and rolesClinics, staff, seats and their own domains, with patients linked only by their own consent.
One account does not mean one pool of data. Sign-in and the plan are shared. Anything crossing between applications is a separate permission, per category, off by default.