# onboard.pdhc — user manual

onboard.pdhc is where a **new supplier of health data is signed up**.

A supplier might be a clinic, a laboratory, or a company whose app or device
records measurements that patients take at home. Before any data can flow,
the two sides have to agree what will be sent, who is asking for it, and how
it will travel. This service is where that agreement is made and recorded.

> **Status, September 2026.** The service is live at
> [onboard.pdhc.se](https://onboard.pdhc.se) and both screens are built. A
> PDHC administrator signs in with their normal PDHC account; the supplier
> needs no account at all. A complete sign-up has not yet been run end to
> end with a real supplier, so treat the later steps as tested-but-new.

It is built around a **telephone call**. Two people — one at PDHC, one at the
supplier — have the same page open, and each fills in their own half while
they talk. It takes about twenty minutes.

## Why a call, and not a form

Because the things that go wrong are things a form cannot catch.

A supplier's legal name is not always what PDHC has written down. The number
of measurements in a plan can be counted two different ways. A web address can
be typed from memory and be almost right. Every one of those mistakes is
invisible at the time — the record looks complete, and the error only appears
weeks later when data arrives in the wrong shape, or under the wrong company.

So the design has one rule, and everything else follows from it:

> **Neither side can fill in the other's facts.**

Every item belongs to one party. The supplier enters their own details; PDHC
enters PDHC's. Each then has to confirm what the other wrote. Nothing counts
as agreed until both have done so — which means an agreement is something the
two people *did*, not something one of them typed while the other listened.

## What happens on the call

### You will get a link and a code

The administrator presses **Create the invitation**, and their screen shows
two things: a link to copy into an email, and a short code in large type.

The link arrives by email. The code is **read aloud on the telephone** and is
never written in the same email. Both are needed.

That is deliberate: an email going astray is then not enough for anyone to get
into the conversation. The page also stays shut unless the PDHC administrator
is actually there hosting the call, so an old link is not a door left open.

### You each fill in your own half

The supplier gives their legal company name, organisation number, who is
responsible for the connection, and a contact address. PDHC will read the
legal name back out loud before accepting it — that one is worth getting
exactly right, because it is the name the agreement is made with.

### You agree what will be sent

PDHC chooses a **care plan** that already exists, and the list of measurements
comes from it. They are not picked by hand. This matters: a hand-assembled
list can quietly disagree with the plan it claims to serve, and then the
supplier is asked for something the care never actually required.

The screen shows **how many measurements** the plan contains, in large type
next to the exact words to say. The number is read aloud and repeated back.
The supplier sees the same number on their own screen.

That check exists because it has gone wrong. One measurement can appear in a
plan several times — once as a goal, and again for each scheduled visit. Counted
naively, a plan with ten things to send can look like forty. Two people once
spent weeks at cross purposes over exactly that, each confident in a different
number. So the count is stated, out loud, by both.

Every measurement starts as **required**. If the supplier genuinely cannot
send one, it can be marked optional together, or removed from the agreement
altogether.

### You agree how the data travels

Either PDHC collects it from the supplier, or the supplier sends it in.
Whichever suits their system. If they are sending, they give the web address —
and again, **they** type it.

### Then it is agreed

When every line shows both ticks, the agreement is recorded and locked.

### The supplier gets an access key

The supplier presses **Show my access key** on their own screen, and it
appears there — **once**. There is deliberately no button for this on the
PDHC side.

Nobody at PDHC ever sees it. That is not a courtesy — it means PDHC cannot
lose or leak something it never held. If the supplier loses it before it is
saved, a replacement is issued; that is a normal thing to ask for and not a
problem.

### A test, then live

Before finishing, the connection is tested for real, in whichever direction
was agreed. If something on the supplier's side is not reachable from outside
yet, that is a common thing to discover and the sign-up simply waits until it
is ready.

## What each side sees

Both screens show the same agreement, as a list. Every line carries a badge
saying whose line it is — **you**, **PDHC**, or **both** — and two tick marks,
one per side. A line is settled when both ticks are green. Anything still
waiting shows a clock.

A row of steps across the top shows how far the call has got.

You cannot edit a line that belongs to the other side; there is no button to
do it. That is the design, not a permissions error.

## What you need to have ready

If you are the **supplier**:

- your legal company name, exactly as registered
- your organisation number
- the name and email of the person responsible for the connection
- somebody available who knows how your system sends or receives data

If you are the **PDHC administrator**: which care plan this is for, and which
organisation is ordering the data.

## If something goes wrong

| What happened | What to do |
|---|---|
| The supplier lost the access key | Issue a replacement. Do not start a new agreement. |
| The wrong legal name was agreed | Reopen and correct it. The agreement is kept. |
| The wrong care plan was chosen | Reopen and choose again — the measurement list is replaced. |
| The code was typed wrong five times | The page stops accepting it. Send a fresh invitation. |
| The supplier cannot open the link | Check the administrator is still hosting; the page closes when they leave. |

## A note on privacy

No patient data passes through this service. What is recorded here is an
agreement between two organisations: who will send what, to whom, and on what
basis. The measurements themselves travel elsewhere, once the agreement
exists.
