EE/COM/12100876/begin carries Tervisekassa’s
employer services for the companies that use Begin.
This page is Begin’s intermediation procedure, published under §5.4.6.1 of the
X-tee joining contract. It states on what basis Begin intermediates, how it
authenticates and authorises the people who use the services through Begin, and
how the resulting logs are archived and kept.
Last updated: 4 September 2026.
The basis for intermediating
Begin intermediates two Tervisekassa services, both in thekirst subsystem:
Tervisekassa has opened both to Begin’s subsystem. Each employer Begin acts for
grants Begin a mandate on eesti.ee — Volitused →
Tervisekassa alamplokk → Tööandja X-tee teenused, to registry code
12100876. Without that mandate Begin has no right to act for the employer,
and Tervisekassa returns nothing.
Every employer is also Begin’s client under Begin’s terms of service, accepted
when their workspace is created.
The employer a request concerns travels in the request itself. Begin reads it
from the employer’s own workspace record; no user of Begin can name another
company, and Begin never queries for an employer that has not connected the
integration.
Who may use the services through Begin
A person reaches these services only from inside their employer’s own Begin workspace, and only after passing four checks.- Identity. They sign in to Begin with a verified email address or phone number, by one-time code, or with a passkey.
- Membership. The sign-in resolves to one workspace. A person who is not a member of that workspace has no route to its data.
- Permission. Their role in that workspace must carry the Manage integrations permission, checked when connecting the integration, mapping certificate types, and sending the employer’s part.
- Employer identity. The company a request is made for comes from the workspace’s own record, never from anything the person types.
userId header.
Tervisekassa has required it since 15 September 2025. Begin refuses to send
when that code is missing from the person’s profile or fails its checksum, so
every submission names a real person.
An employer ends the intermediation by disconnecting the integration in Begin,
or by withdrawing the eesti.ee mandate. Disconnecting stops the queries — the
next scheduled query and every one after it. Deleting the workspace, or removing
the company registry code, stops them as well.
Logs of authentication and authorisation
Begin records every act that authorises a Tervisekassa query, in the workspace’s own audit log:- connecting and disconnecting the integration, and who did it;
- recording or withdrawing the eesti.ee mandate confirmation;
- changing which certificate type becomes which absence;
- sending the employer’s part — naming the person, the certificate and the figures sent.