White-label operating layer

Your organization owns the experience. The platform preserves the rules.

Brand identity resolves through the hierarchy and follows the patient or staff member across every approved touchpoint—without allowing custom branding to weaken accessibility, authorization, or security signals.

OPERATING LAYERLIVE PRODUCT MAP
01Groupbrand foundation
02Regiondelegated override
03Cliniclocal identity
RECOVEROPERATEGOVERN

Brand inheritance

Deterministic, versioned, and governed.

Each field can inherit, override, or clear according to policy. The effective identity is resolved as platform default → franchise profile → region override → clinic override.

01

Platform default

Safe fallback, security signals, and governed attribution

02

Franchise / group profile

Primary identity, legal name, assets, colours, links, contact, and policy

03

Regional override

Delegated variation for a geography or operating unit

04

Clinic override

Local name, contact, hours, directions, help, and delivery identity

Where the brand appears

Identity continuity beyond the login screen.

The approved logo, name, tagline, colours, contact details, help channels, language, and attribution follow each relevant surface.

Workforce

Authenticated chrome, profile, help, and clinic context

Patient

Offer, confirmation, preferences, opt-in, forms, feedback, response, and error states

Communications

SMS, email, templates, sender identity, links, reminders, and notices

Documents

Forms, generated artifacts, calendar invitations, and downloads

Public

Approved widgets, custom domain, help pages, and contact presentation

Support

Clinic identity, hours, phone, email, website, directions, and help request

Domains and communications

A brand is also a delivery system.

Custom domains, sender identities, email providers, templates, support routes, and attribution require verification, health, fallback, audit, and ownership—not just a text field.

  1. 01

    Configure

    Create the group brand and delegate allowed regional or clinic overrides.

  2. 02

    Upload safely

    Managed assets are inspected, sanitized, scanned, versioned, and delivered as derived clean media.

  3. 03

    Preview

    Review staff, patient, document, email, and error-state presentation in English and French.

  4. 04

    Verify

    Prove custom-domain ownership and sender configuration before activation.

  5. 05

    Approve

    High-risk changes can require reason, role, review, and immutable history.

  6. 06

    Deliver and monitor

    Resolve the effective brand per resource, preserve fallback, and surface domain/sender health.

Non-negotiable guardrails

White-label without an unsafe blank cheque.

Tenant colours are constrained semantic inputs, not arbitrary code. Unknown patient links fall back to a neutral clinic identity rather than the software vendor. Required platform attribution remains governed by contract and plan.

ACCESSIBILITY

Contrast and focus remain safe

Unsafe colour combinations fall back to accessible tokens, with reduced-motion and semantic states preserved.

AUTHORIZATION

Hostname is not identity

Custom-domain resolution never replaces authenticated tenant and resource authorization.

PATIENT TRUST

Help points to the clinic

Patient error and unavailable states use configured clinic contact and hours, never an unrelated software-company support route.

DELIVERABILITY

No sender spoofing

Unverified domains cannot become active From addresses; approved platform fallback remains explicit.

Evidence-led product tour

See the system in action.

Captured from the working product with synthetic demonstration data. Use the thumbnails like an ecommerce product gallery; every view explains what to notice and the documentation that governs it.

Full topic drill-down

What this part of the product covers.

Each topic connects the public promise to a real screen and the relevant product evidence. Detailed technical records remain available during an appropriate private review.

01

Deterministic inheritance

Effective identity resolves platform → group → region → clinic with explicit inherit, override and clear semantics.

Product evidence: Product specification §9.17 · White-label verification record
02

Every relevant surface

Staff chrome, patient journeys, messages, documents, calendar artifacts, help and errors use the resolved identity.

Product evidence: Product specification §9.17
03

Managed assets

Uploads require type, size, sanitation, inspection, scan and clean derived delivery evidence.

Product evidence: Product specification §9.17 · Security record
04

Domains and senders

Ownership, certificates, sender verification, fallback and health gates precede activation.

Product evidence: White-label verification record · Production acceptance pack
05

Non-negotiable trust

Brand customization cannot weaken contrast, focus, authorization or security signals.

Product evidence: Product specification §9.17 · Security record

A serious operating review

See the product as a system—not a collection of screens.

Bring your organization structure, cancellation economics, integration landscape, branding requirements, and diligence questions. We will map the operating boundary and the evidence available today.

Live demoRequest a private reviewTrust architecture