Skip to the main content
Evora

Organizations · Companies

Companies

Most employers do not want health records. They want to know a requirement is satisfied, and they are stuck collecting documents to prove it, documents they must then secure, retain and eventually lose.

Sector tooling in build

The person's record is live today. The console for this sector is not.

Employment does not give an employer medical-record access.

How this works now

Not a caricature, this is the ordinary version of it, and it repeats every year.

  • A note, a form or a screening result is emailed to a manager or an HR inbox and lives there indefinitely.
  • Sensitive documents are held far beyond the moment they were needed, because nobody owns deleting them.
  • The same employee is asked again at the next role, the next site or the next annual cycle.
  • The employee has no record of who inside the company read what, or when.

What EVORA puts in its place

Each step is one decision, made by the person whose record it is.

  1. 01

    The company states a requirement

    A named question with a reason: a fitness-for-duty confirmation, a vaccination status where the law requires it, a hearing or vision check for a specific role.

  2. 02

    The request reaches the person, not their manager

    The employee sees who asked, what was asked, why, and what would satisfy it. They can approve part of it, all of it, or decline and say why.

  3. 03

    The answer is a status wherever a status is enough

    Met, met with accommodation, not met, expires on a date. No findings, no values, no documents, which is almost always all the requirement actually needed.

  4. 04

    Documents, only by exception

    Where a document is genuinely required, it is shared narrowly and with an end date, to a named reviewer rather than a shared inbox.

  5. 05

    Occupational health stays separate from management

    A verified occupational-health clinician may read what they were granted. Managers and HR see the status only, and the separation is enforced by the grant, not by policy language.

  6. 06

    Leaving closes the door

    When employment ends, access ends. The employee keeps the record and the full history of every view the company made.

Roles and limits

Who may see what.

Being on a roster, a payroll or a staff list is context. It is never access.

Illustrative role limits. Anything in the granted column requires the person's scoped, expiring permission, and every view is written to their access history.
RoleSees without askingOnly if the person grants itNever sees
Line managerAssigns work and needs to know availability.Whether the person may perform the role, and any accommodation stated in plain language.Nothing further, a manager is not an appropriate recipient of clinical detail.Diagnoses, medications, test results or documents.
HR administratorTracks that requirements are satisfied.Requirement statuses with issue and expiry dates.A specific document only where a status genuinely cannot answer the requirement.Browsing access to any employee's record.
Occupational health clinicianAssesses fitness for a specific role.Nothing by default; a verified clinical role still requires a grant.The areas relevant to the assessment, for its duration, with findings written back to the person.The record after the assessment window closes.
Safety or compliance officerDemonstrates the organization meets its obligations.Aggregate completion, how many requirements are met, pending or expired.An individual document only for a named investigation the person is told about.Named health detail for routine reporting.

What this page will hold

Written down first so you can hold us to it.

  • An employer console with sites, teams, roles and requirement sets
  • Status-only requirement replies with expiry and re-ask scheduling
  • A strict separation between occupational-health access and management visibility
  • Aggregate completion reporting that contains no individual health detail
  • Automatic access closure when employment or a role assignment ends