WORKSTATION AGENT
Workstation Agent — Pairing & Trust
5 of 12Establish zero-trust machine identity, user authentication, certificate-based trust and revocable tenant binding.
Zero TrustMutual AuthenticationTenant BoundCertificate BasedRevocable
Pairing & trust flow (high level)
1
Generate Code
Agent generates a short-lived pairing code.
2
Register in Portal
User enters code or scans QR.
3
Authenticate User
SSO / MFA establishes user identity.
4
Authorize Machine
Organization approves this device.
5
Issue Identity
Machine certificate is issued.
6
Establish Trust
Mutual TLS channel is established.
7
Bind & Scope
Machine is bound to tenant and resources.
8
Ready
Agent is trusted and ready.
All communications are encrypted with mTLS. The Agent can only access resources explicitly permitted by your organization.
Identities & trust model
User Identity
Who is using the Agent (SSO/MFA).
Machine Identity
X.509 identity bound to the workstation.
Connector Authorization
Which connectors may run.
Resource Permissions
Which devices, apps, files or systems may be accessed.
Machine identity details
Issued asX.509 client certificate
Stored inOS secure store / Keychain
Identifierworkstation-id (UUID v4)
Valid for90 days configurable
RotationAutomatic before expiration
RevocationImmediate via portal or API
Trust anchorMediloop Root CA (pinned)
Pairing methods
Code EntryQR Code
Agent displays one-time code
User logs into Mediloop Portal
User enters code or scans QR
Machine is authorized and trusted
Code expires in 5 minutes and is single-use.
Trust state
Trusted
Agent is connected and authorized.
Expiring soon
Certificate will rotate automatically.
Not trusted
Revoked, expired or not authorized.
Unknown
Agent not registered or unreachable.
Certificate lifecycle
Issued by Mediloop CA
Active for Agent authentication
Rotated before expiry
Revoked immediately when invalid
Re-authentication
User session expires
Agent requests portal re-auth
User authenticates via SSO/MFA
Session token renewed
Active connections continue
Revocation & unpairing
Revoke from Portal invalidates certificate
Unpair removes machine from tenant
Agent loses access instantly
All actions are audited
Lost / stolen workstation
Revoke machine certificate immediately
Change local OS credentials
Re-install and pair again if recovered
The Agent stores no patient data by default.
Administrator policies
Require MFA for pairing
Restrict pairing to trusted networks
Auto-expire machine certificates
Limit connectors per workstation
Enforce resource-level permissions
Block unmanaged workstations