A Structured and Defensible
    Governance Framework

    OneCredential provides a consistent framework for managing healthcare industry representative credentials, access requirements and onsite activity.

    Scroll to explore

    Aligned to AS 5182

    OneCredential is the only Australian platform to formally align its credential governance framework with AS 5182, the Australian Standard for healthcare industry representative credentialing and access.

    • Consistent credential requirements
    • Risk-based access controls
    • Defined review and escalation pathways
    • Traceable credential and access decisions
    • Facility-specific governance settings

    AS 5182 provides guidance rather than mandatory requirements. Each facility retains authority over the requirements and access rules applied within its own environment.

    OneCredential provides the structure to apply those requirements consistently and demonstrate how decisions were made.

    A Dedicated Governance Layer

    Healthcare facilities already maintain established governance systems for employees, contractors and clinical personnel. Industry representatives often sit outside those systems and may be managed through local processes, manual checks and individual judgement. OneCredential provides a dedicated governance layer for this external workforce.

    • Credential requirements are defined consistently
    • Access rules can vary by facility and location
    • Exceptions follow structured review pathways
    • Decisions are recorded and available for review
    • Existing clinical and hospital systems remain separate

    Governance That Can Be Explained

    A defensible governance process is one in which decisions are made against defined requirements, recorded at the time of action and supported by a clear history. OneCredential records:

    • The requirement being assessed
    • The representative's credential status
    • The decision that was made
    • The user or system action involved
    • The date and time of the decision
    • Relevant approvals, exceptions and access activity

    Records Ready When Required

    OneCredential creates a searchable digital history of credential status, approvals, exceptions and access activity.

    Authorised users can review and export records showing:

    • Who attended each facility
    • When and where they checked in
    • The purpose of the visit
    • Which credentials were approved, outstanding or not accepted
    • Access decisions and approval activity
    • Relevant historical status and governance actions

    Standalone by Design

    OneCredential operates independently of hospital clinical, patient and internal operational systems.

    • No access to patient records
    • No integration with clinical workflows
    • No dependency on hospital identity systems
    • No local storage of representative credential documents
    • Facility access rules remain configurable by authorised users

    Our Governance Principles

    01

    Consistency

    Requirements and decisions are applied through defined processes.

    02

    Proportionality

    Controls are matched to the risk associated with the location and activity.

    03

    Privacy by Design

    Personal information is limited to what is required for the relevant purpose.

    04

    Accountability

    Decisions and actions are recorded and capable of review.

    05

    Facility Autonomy

    Each facility defines the requirements and access rules appropriate to its environment.

    Supported by Independent Standards

    OneCredential applies established security and governance controls across identity, documents, platform access and audit activity.

    • Data protected in transit using HTTPS and TLS
    • Documents, databases and backups encrypted at rest using AES-256
    • Private document storage within Australian AWS infrastructure
    • Authenticated access through AWS Cognito
    • Role-based access controls
    • Time-limited secure document links
    • Controlled audit records
    • Automated encrypted backups

    OneCredential has achieved SMB1001 certification, is recognised as an Australian Signals Directorate Cyber Security Business Partner and is progressing through ISO 9001 and ISO 27001 certification pathways.

    Informed by Healthcare and Industry Practice

    OneCredential engages with healthcare facilities, industry employers, professional groups and governance stakeholders to ensure the framework remains practical and relevant.

    Feedback from users, changes in recognised standards and emerging operational risks are considered as the platform develops.

    Sovereign Capability for Australian Healthcare

    OneCredential is an Australian-founded platform designed for Australian healthcare facilities, employers and representatives.

    Platform data is hosted within Australian AWS infrastructure, supporting local data residency and sovereign capability. Its digital-first model reduces reliance on paper records, duplicated document storage and manual administrative processes.

    Where physical credentials are provided, recycled materials are used for badges and lanyards to support a more sustainable operating model.

    OneCredential is establishing a dedicated grant program to support community-led initiatives that improve healthcare access in First Nations communities. Organisations adopting OneCredential contribute to a broader commitment to responsible, equitable and locally informed healthcare access.

    Learn more about the OneCredential
    governance framework