WORKSTATION AGENT
Workstation Agent — Overview
1 of 12A secure local bridge between Mediloop web applications and trusted workstation hardware, applications and legacy systems.
SecureLocal BridgeDevice AccessOffline CapableAuto Update
What is the Workstation Agent?
A lightweight local service running on a clinician workstation that gives Mediloop controlled access to resources a browser cannot reach directly.
USB / HID devices — microphones, foot pedals, scanners
Serial / COM devices — analyzers, monitors and pumps
Smart card readers and secure tokens
Vendor SDKs and native drivers
Local applications and scoped file-system access
Legacy systems and proprietary protocols
Local-first security
The Agent does not persist clinical data by default. Access is explicit, scoped and auditable.
Architecture overview
Mediloop Web Application
Browser requests device access, sends commands and receives data.
WebSocket /
gRPC (TLS)
gRPC (TLS)
Workstation Agent
Device discovery & management
Secure communication server
Data routing & transformation
Local processing (optional)
Logging & diagnostics
USB / HID Devices
Serial / COM Devices
Smart Card Readers
Local Applications
File System
Legacy Systems
Secure Bridge
End-to-end encrypted channel between browser and Agent.
Device Discovery
Automatically enumerate local devices and resources.
Multi-Protocol
HID, Serial, TCP/IP, WebSocket, gRPC and vendor APIs.
Permission & Consent
Granular resource-level access and user consent.
Offline Operation
Continue safe local operations during network outage.
Auto Updates
Signed updates with rollback protection.
Diagnostics & Logs
Health monitoring, logs and troubleshooting tools.
Multiple Sessions
Serve multiple authorized Mediloop apps simultaneously.
Lightweight & Safe
Minimal footprint; no arbitrary local access.
How it works
1Install & Pair — install the signed Agent and pair it to your Mediloop tenant
2Discover Resources — enumerate approved local devices, drivers and applications
3Request Access — web app asks for a specific resource and purpose
4Secure Communication — mTLS / TLS channel is established
5Stream Data & Commands — bidirectional data, commands and events
6Return Results — results are returned to the web application in real time
System requirements
CPUDual core or higher
Memory2 GB RAM minimum
Disk200 MB free space
NetworkOutbound HTTPS 443
PrivilegesStandard user rights
Multiple connector support
Dictation & Speech
Medical Imaging
Laboratory & LIS
Card & Identity Services
Custom local adapters