Partner Data Intelligence System · AI-assisted capture, assurance and insight from digital health partnerships · UK

Proving what a partner is worth when the product sells itself

Know which decisions your partner ecosystem can actually support — before you make them.

Twenty-three digital health partnerships, fourteen supplying data, and no defensible way to value any of them. Demand already exceeded supply, so nothing a partner did to generate demand could be counted as value. The work rebuilt partner ROI around the four things that remain when acquisition is worthless.

23
digital health partnerships
at the start of the work
14
supplying data;
3 to a written specification
2
with a machine-readable
rights position
4 / 27
decisions with traceable
evidence behind them
0
partners whose value had
ever been stated as a number
NoteClient context is anonymised and no organisation is identifiable. The method — research instruments, workshop design, frameworks and reasoning — is as used. Regulatory instruments and reference sources are real and UK-specific.
00

The argument

Before the evidence

Twenty-three digital health partnerships. Fourteen sending data, three to a written specification. The annual portfolio review stalled at the first question — what is each of these worth — and stayed stalled for two cycles.

Why the usual answer does not work

Both partner business cases in the estate counted the same thing: people the partner reached who went on to start treatment. That assumes demand is the constraint. Here supply is.

ACQUISITION Supply is the binding constraint. A partner delivering initiations moved demand between routes; it did not create it. The number rises with partner spend and means nothing. Two business cases in the estate were built this way. RULED OUT DURATION How long people stay Patient count is capped. Duration is the only volume lever left. STRONG counterfactual test applies EFFICIENCY What it saves us doing Work displaced from the affiliate. MEASURABLE counterfactual test applies EVIDENCE What it lets us prove Real-world evidence for access. LONG LAG counterfactual test applies INTELLIGENCE What it lets us see Segmentation, demand shape, where the journey fails. BROADEST counterfactual test applies RISK What it stops going wrong Detection timeliness, compliance posture. ONLY VISIBLE WHEN IT FAILS counterfactual test applies WHAT THE ESTATE CAN ACTUALLY SUPPORT Duration refill data strong; stop reason free text, one partner Efficiency contact volume good; reason unstructured Evidence objective outcome biased; comorbidity absent Intelligence geography good; payer and route absent Risk detection works; consistency unmeasured
scroll to pan →
The counterfactual test — what would have happened without this partner. Neither survived it.

Where growth can come from instead

WHERE GROWTH CAN COME FROM WHEN SUPPLY IS THE CONSTRAINT PATIENTS capped by supply × MONTHS ON TREATMENT open × DOSE REALISED partly open × PRICE fixed the two boxed terms are movable EXTEND DURATION Months on treatment Median duration is the single largest untapped term. NEEDS stop reason at the point of stopping tolerability in the first 8 weeks support exposure against persistence supply gap distinguished from a real stop 9 use cases REALISE DOSE Dose realised Patients stalled below target dose consume supply and deliver less benefit. NEEDS titration stage and date dose holds and reductions HCP escalation behaviour tolerability at each step 6 use cases ALLOCATE BETTER Same patients, better chosen Under constraint the question is not how many but which. NEEDS eligibility against treated funding route geography and provision segment-level persistence 11 use cases SPEND LESS Cost to serve Support and service cost per persistent patient. NEEDS contact volume and reason self-service deflection fulfilment failure rate HCP time released 7 use cases Patient count is set by supply. Price is set elsewhere. That leaves duration, dose realisation, allocation and cost to serve. All four sit downstream of the treatment decision, which is where partner data lives and where the field force does not.
scroll to pan →
Patient count is capped by supply and price is set elsewhere, which leaves duration, dose realisation, allocation and cost to serve. All four sit downstream of the treatment decision.

What the discovery found

The estate is sparse, not duplicative

The brief said rationalise. Six of fourteen journey stages are seen by more than one partner and two are seen by none. On a cost report the two look the same. The brief was written on that reading.

Four decisions of twenty-seven had evidence

Seventeen interviews produced twenty-seven decisions people said they make with partner data. No decision owner had ever specified what evidence would change their mind.

Eleven of fourteen feeds cannot be joined

Every partner emits its own subject identifier, two rotate, no agreement mentions stability. Nine decisions need a cross-partner view and all nine sit above that ceiling.

The two strongest fields are collected and never sent

Comorbidity is the eligibility gate here — BMI with a weight-related comorbidity is what qualifies someone. Two partners assess it and neither transmits it. Payer type is absent from every feed.

JOURNEY COVERAGE BY ARCHETYPE Discovery search, awareness Eligibility assessment, funding route Consultation clinical contact Prescription written Fulfilment dispensed, shipped Onboarding first dose Titration dose escalation Tolerability GI symptoms, burden Monitoring weight, measurement Behaviour nutrition, coaching HCP review follow-up, escalation Safety AE, signal Persistence still on treatment Stop + reason discontinuation P01 Telehealth / digital clinic ~ ~ ~ ~ ~ P02 Pharmacy / e-pharmacy ~ ~ P03 Remote monitoring / device ~ ~ ~ P04 Nutrition / behaviour / DTx ~ ~ ~ ~ ~ P05 Care navigation / HCP discovery ~ ~ P06 HCP workflow / clinical support ~ ~ ~ ~ ~ P07 Patient support service ~ ~ ~ ~ P08 Evidence / RWE partner agg agg agg agg agg agg agg agg agg agg agg agg agg agg The two ringed columns carry the highest-value evidence in this therapy area and the estate barely captures either. Tolerability is seen by three archetypes, two of them partially. Stop-reason is seen by one — P07 — because it is the only place a person asks. Four stages are covered by more than one partner; two by none. This is the argument against rationalising the estate on cost: the scarcest evidence sits with the least data-rich partner in it.
scroll to pan →
The finding that reordered the portfolio — ranked by volume the valuable partners are device and behaviour. The support service was the only place anyone asked a patient why they stopped. It had the smallest contract in the estate.

What was designed

What it is What it settled
Three layers What exists in the health system of record, what a partner can transmit, and what the affiliate builds afterwards That patient master data and partner data are different objects. Collapsing them was the original error.
Receivable grain What the affiliate can get is a property of the relationship, on three independent axes The same element has a different grain from two partners who both hold it.
Assessment instrument Interviews a prospective partner and maps their offer onto the catalogue before contracting Whether a candidate adds evidence or duplicates it.
Conformance gateway Four tests: contracted grain, received grain, usable grain, fitness for a named decision A feed can pass the first three and fail the fourth. That is the normal case.
Confidence card Attached to every published figure — grain, denominator, observability, bias, and what it cannot tell you The care taken upstream survives into the room where the decision is made.

Where the machine work went

11

capabilities built, six using a model. Everything else is deterministic rules, including the two pieces of logic the system most depends on.

8

declined. Six on governance or accountability rather than capability, and all six would have worked technically.

4

stages scored separately per activity. Most activities scored high on the first two stages and low on the last two.

What did not work

  • The first workshop nearly failed. For the first hour they listed activities. Monitor partner performance. Improve adherence. I dropped the word decision and asked for the shape instead: who chooses, between what, by when, and what goes wrong if they choose badly.
  • Three of eight functions never picked the work up. Neither could be served until data that nobody sends starts arriving.
  • The largest single benefit rests on a number nobody measured — two to three days a month of one analyst’s time, reconstructed from artefacts. Measuring it properly was the first recommendation.

What it added up to

Twenty-seven decisions, four outcomes
Outcome n What it needs
Answerable once definitions were fixed 6 Nothing. Blocked on disagreement, not on data.
Needs a change to what partners send 9 A specification. The cheapest tranche.
Needs a change to linkage permissions 5 Contractual and consent. No engineering route.
Not answerable from partner data 3 Reassigned to primary research.
Not a decision 4 No owner, no moment of choosing, no cost of being wrong.
The portfolio split four ways on strategic contribution against current delivery. Nine partners hold scarce evidence and deliver it badly, and every one of them is a cut candidate on cost.
01

The problem with proving partner value

Framing

Twenty-three partnerships, and an annual review that had not been completed for two cycles.

The partnerships had accumulated across four years. Each was signed for a defensible reason. None was signed against a portfolio, and no two were structured the same way. Fourteen sent data back; three of those to a written specification. When the affiliate tried to run a portfolio review, it stalled at the first question and stayed stalled for two cycles.

Why the usual answer does not work here

The business cases in this estate were written as acquisition stories. The partner reaches people, some of those people start treatment, and you count them. Cost per initiation, share of new starts, incremental volume.

None of it applies to a product that is supply-constrained and demand-saturated. When more people want the medicine than can be supplied, a partner delivering initiations has moved demand around rather than created it. The patients they bring would have arrived through another route. Counting them produces a number that rises with partner spend and means nothing, and two of the partner business cases in the estate were built exactly that way.

The reframe. So demand was not available as a measure. Value has to be found in what happens after someone starts — how long they stay, what the service costs to run, what evidence the relationship generates, and what the affiliate learns that it could not learn otherwise. Five value classes, none of them acquisition.

The second complication: the partners want something too

Most of the fourteen are not passive suppliers. They want to be data partners in the full sense — sending data, receiving insight back, and building an analytics proposition of their own on the combined picture. Several asked for it explicitly during discovery. Three had it written into their agreements in terms nobody had operationalised.

Exchange has to be designed in both directions, because a partner with no reason to care about data quality will not maintain it. And the affiliate has to be deliberate about what it is helping a partner build, since insight returned to a partner operating across several manufacturers is a different proposition from insight returned to an exclusive service provider. Two of the twenty-three fall into the first category.

What the framework had to do

Three jobs, in order
Job Why it comes here
1 State each partner’s value in terms that survive a saturated market Without this there is no basis for any portfolio decision, and the review stalls exactly where it stalled.
2 Separate strategic contribution from current performance These are different axes and they were being collapsed into one score. A partner supplying scarce evidence badly is not the same as a partner supplying abundant evidence well, and the two need opposite responses.
3 Optimise the high performers rather than only rank them Ranking produces a cut list. Most of the available value in this estate came from specification changes to partners the affiliate was already paying.
What the work produced
Artefact What it is What it settled
Partner value model Five value classes, each with a counterfactual test and a measure That a partner can be valued at all in a saturated market, and how
Data-to-insight chains How each data category converts into a decision and then into value, with the market relevance of each The question nobody had answered: what is this data actually for
Strategic × performance matrix All 23 plotted on contribution against delivery, with a named action per quadrant Which partners to deepen, fix, harvest or exit — and that the fix quadrant was the largest
Canonical data spine Three layers, 187 catalogued elements, with receivable grain per relationship That patient master data and partner data are different objects
Decision inventory 27 decisions, owners named, evidence stated What the estate is actually being asked to answer
Assessment instrument An agentic intake that interviews a partner and returns a value profile Whether a candidate adds value — before contracting
Conformance gateway Four tests from contracted grain to decision fitness That a feed can be valid, compliant and worthless
Partner value report Generated per partner, per cycle, from the spine The review that had stalled for two cycles
02

Findings

Ordered by how much each constrains the rest

Eleven. The first three make the others unavoidable, and F-01 is the reason the engagement changed shape in week two.

F-01

No decision owner had specified what evidence would change their mind

Seventeen interviews produced 27 decisions people said they make with partner data. Four had any evidence attached that the person could point to. The rest ran on relationship history, partner-supplied reports, or the fact that the partnership already existed.

This is upstream of every other finding. Without a specified evidence requirement there is nothing to put in a partner specification, and no basis for saying one dataset is worth more than another. It is also why the estate looks like sprawl from a finance report — undifferentiated cost is what an unprioritised portfolio looks like from outside.

Evidence27 decisions named across 14 interviews; 4 with traceable evidence. Four further “decisions” had no owner and no cost of being wrong, and were removed in W1. Observed
F-02

Every partner emits its own subject identifier and none is guaranteed stable

Fourteen feeds, seven identifier schemes. Two rotate on re-registration. One is derived from an email address. None of the agreements mentions identifier stability, so none of the partners is obliged to maintain it and two had changed scheme without notification.

It removes any possibility of following a person across two partners, and it puts a ceiling on what the estate can answer that no amount of engineering will lift. Nine of the 27 decisions need a cross-partner view; all nine sit above that ceiling today.

EvidenceIdentifier scheme profiled across 3 feeds directly and 4 from documentation. Two schemes observed to rotate. Zero agreements containing a stability clause. Observed
F-03

Rights sit in prose across seven drafting patterns

What a partner may collect, what the affiliate may receive, at what grain, for which purpose, for how long, and whether anything may be combined with anything else — all of it in agreement text, phrased differently in every agreement.

Two consequences. No portfolio question can be answered without reading twenty-three documents, so nobody asks portfolio questions. And a proposed analysis cannot be checked against its rights position before it is commissioned, so the check happens afterwards, under time pressure, with an expectation already formed.

Evidence23 agreements and 17 DPAs analysed; 7 distinct drafting patterns for the same underlying permission set. Zero structured rights fields in any system. Observed
F-04

Two journey stages are unobserved by any partner

Tolerability and stop-reason. Both are captured somewhere in the estate and neither is captured usably: tolerability appears in P04 symptom logs from an engaged population and in P07 call notes as free text; stop-reason appears only in P07, unstructured, with no taxonomy.

These are the two highest-value evidence categories in this therapy area. The estate can measure that people stop. It cannot say why.

EvidenceCoverage mapped across 8 archetypes and 14 stages in W2. Stop-reason present in 1 of 8; tolerability partial in 2 of 8. Observed
F-05

Device measurement stops when engagement stops, and engagement predicts the outcome

The P03 feed shows mean weight change improving over time. It does so partly because people who are not doing well stop weighing themselves. People who are not doing well stop weighing themselves, so the sample cleans itself over time.

This is informative censoring rather than ordinary missingness: the probability that a value is missing depends on the value. Nothing in the pipeline flags it, the number looks plausible, and it had already been used twice in internal reporting.

EvidenceP03 feed profiled over a 14-month window: measurement frequency declines sharply in the 6 weeks preceding permanent drop-off. Cross-referenced against P02 refill gaps for the subset where both exist. Observed Constructed
F-06

Funding route is absent from every feed and it conditions everything

Whether a person reached treatment through an NHS specialist service, a private clinic, an online provider or self-pay determines their cost exposure, their monitoring, their likely persistence and whether they appear in any given partner's data at all. No feed carries it.

Without it, every cross-partner comparison silently compares different populations, and every persistence figure is a weighted average of routes with very different economics.

EvidenceField-level review of 14 feeds: 0 carry funding route or an equivalent. Observed
F-07

Three functions run three different denominators

Commercial counts people who have a prescription event. Medical counts people with a confirmed first dose. Market access counts people present in the partner's cohort at period start. All three call the result “patients on treatment” and the three numbers differ by roughly a fifth.

Nobody is wrong. The definitions were each built for a legitimate purpose and none was written down, so the disagreement surfaces as a credibility problem in meetings rather than as a definitional one that could be settled.

EvidenceThree definitions reconstructed from reporting logic in W1 and confirmed against the monthly packs. Spread of approximately 18–22% depending on period. Observed Constructed
F-08

Safety recognition sits with partner staff who were never trained for it

Four partner surfaces can receive content a patient writes. On three of them, a partner employee decides whether what they are reading is potentially reportable. That is a trained judgement, placed with people who have no obligation to hold it and no way to evidence that they exercised it.

The items judged not to be reportable leave no record anywhere, so the false-negative rate is not merely unknown — it is unknowable from inside the current design.

Evidence4 patient-facing surfaces across P01, P04, P07. 3 rely on partner-side recognition. Screening cadence differs per surface with no documented rationale. Observed
F-09

The reconciliation is one person and it appears in no system

Two to three days a month assembling the partner pack: pulling seven sources, resolving three denominators, checking the numbers against last month, and rebuilding anything a partner has changed. It is skilled work and the only place the whole estate is held in one view. It appears in no process document and no capacity plan.

EvidenceReconstructed from artefact review of 14 monthly packs and confirmed in the walkthrough. Workload estimate from the analyst, not measured. Constructed
F-10

Two funded arrangements never entered the partner register

The register is built from procurement, so a party enters when a purchase order is raised. Two arrangements — one grant-supported service and one co-developed content programme — generate no purchase order and appear nowhere.

EvidenceRegister construction rule confirmed with Procurement; 2 arrangements identified through interview that appear in no register. Observed
F-11

Nothing published carries what it cannot tell you

Every figure that reaches a decision-maker arrives bare. No denominator, no observability window, no coverage, no known bias. The care taken upstream over grain and rights evaporates at the last step, which is the only step the decision-maker sees.

Evidence14 monthly packs and 4 steering decks reviewed; 0 carry denominator or coverage alongside a reported figure. Observed
03

The ecosystem, and the spine that models it

Locked model

Five master layers, eight partner archetypes, one chain. Every table, dossier, benchmark and diagram in this document resolves to it, and nothing enters the catalogue that cannot be placed on it.

THE SPINE — EVERY ARTEFACT RESOLVES TO THIS CHAIN Ecosystem master PDS · ODS · registers Partner archetype P01–P08 frozen Touchpoint where data is created Receivable grain 3 axes, per relationship Rights basis · purpose · linkage Quality fitness for the decision Decision named owner, named cost Outcome what actually changed Left of the break: authoritative, largely unreachable. Right of the break: a property of the commercial relationship, negotiated at contracting rather than solved at integration. A catalogue row that cannot name the decision it serves does not enter the catalogue. THE BREAK
scroll to pan →
Ecosystem referencePartner layerReceivable layerDecision layer
The break that matters — between the partner layer and the receivable layer. What exists at source and what arrives are different objects, and the difference is a property of the commercial relationship rather than of the healthcare system.

The three data layers, kept separate

Collapsing these was the affiliate's original error. A "patient master" inside a pharmaceutical affiliate is usually a category mistake — the affiliate holds neither the identity nor the right to hold it.

Three layers
Layer What it is Who holds it What the affiliate can do with it
L1 Ecosystem master What exists in the healthcare system of record: patient, HCP, organisation, site NHS and professional-regulator reference sources; partners with a clinical relationship Reference and validation only. Codes, vocabularies and status can be consumed; person-level records generally cannot.
L2 Partner-receivable What a partner can lawfully transmit under this relationship, at a stated grain The partner, bounded by the agreement The working material. Everything the affiliate actually analyses starts here.
L3 Decision dataset What the affiliate needs after joining, transforming, aggregating and enriching The affiliate The object a decision is made from. Derived, versioned, and carrying its own confidence record.

Reading down that table produces the design constraint that shaped the product. The affiliate's analytical capability is bounded not by L1 or by what partners hold, but by L2 — and L2 is negotiated, not engineered. Changing it means changing an agreement, which is slow, which is why the assessment instrument sits at contracting rather than at integration.

Settling what the affiliate can actually reach

Two weeks of the discovery went on a question that sounds administrative and turned out to be structural: for each thing in the reference layer, is it something the affiliate can obtain, something a partner can obtain, or something nobody in this arrangement can obtain at all. The catalogue had been drafted without asking, and the draft treated national patient identity as a field the affiliate might one day populate.

Working through it with Privacy and with two partners produced the split below, and the split is the reason the model has two columns where most catalogues have one.

What each reference layer establishes, and what it does not give this affiliate
Source Class What it establishes What it does not give the affiliate
National patient demographic service National service The national record for patient demographics and the NHS number used to match a person to their health record Access. PDS requires an NHS-facing organisation, a legitimate relationship and an approved use case. A partner with a clinical system may reach it; the affiliate does not.
National organisation directory Reference data Organisation and site codes, organisation roles, relationships, open/closed status, and practitioner-to-organisation relationships with active status Clinical content. It is a directory, not a care record.
Professional regulator registers Regulator register Professional identity, registration number, registration status, profession and specialty where published Employment, current place of work, or prescribing rights in a given service. Those come from the employer or the service configuration.
Clinical guidance body Regulator guidance Clinical eligibility criteria, measurement recommendations and the intervals at which measurements are clinically expected Data-engineering thresholds. A clinical recommendation to measure annually is not a completeness target.
UK interoperability profile Interoperability standard Resource shapes, terminology bindings and identifier systems that make a feed interpretable without bespoke documentation Any guarantee that a partner uses it. Two of fourteen feeds did.
Pharmacovigilance guidance Regulator guidance Obligations for handling and screening potential adverse reaction reports, including in digital media under the company’s management or sponsorship Discretion about which partner surfaces are in scope. Sponsorship is the trigger, not control of the surface.
The distinction in the last column is the one the catalogue enforces with two separate fields: where the data is authoritative, and the route by which the affiliate can lawfully receive it. Running that split across the catalogue resolved most of the patient identity layer to pseudonymous or aggregate, which is the honest picture and the more interesting design problem.
04

The system of problems

Second-order effects

They are four chains with a common origin, and reading them as a system is what stopped the work becoming a data-quality programme.

THE SYSTEM OF PROBLEMS — SECOND-ORDER EFFECTS MADE VISIBLE ROOT CAUSE OPERATIONAL HUMAN DATA BUSINESS No decision owner ever specified what evidence would change their mind Every dataset is equally defensible; none is prioritised Analyst rebuilds the same reconciliation monthly and cannot say why 187 elements, 4 in real use Investment continues without proof Partners define their own metrics because nobody issued a specification Fourteen feeds, seven definitions of an active patient Three functions quote three numbers in the same meeting No comparable denominator Renewal decided on relationship history Rights live in agreement prose, read at the point of use Analysis is gated by a legal read under time pressure Analysts stop asking; questions get shaped to what is easy to clear Purpose creep risk unmonitored Evidence pipeline runs at legal speed Safety recognition placed with untrained partner staff Recognition varies by partner and by shift Partner staff carry a judgement they were never trained for Unknown false- negative rate Regulatory exposure nobody can size Row one is the root of the other three. Specification, rights structure and safety recognition are all downstream of nobody having named a decision.
scroll to pan →
Why the origin matters — three of the four chains dissolve once decisions are specified. Specification, rights structure and denominator disagreement are all downstream of nobody having named what they were deciding. The fourth chain, safety recognition, is independent and would have needed fixing regardless.

The human failure modes present here

Mode How it appears in this estate Why it was reasonable at the time
Measurement error Receipt of data counted as value. The estate is reported by volume of feeds and records, not by decisions served. Volume is the only thing that was measurable without a decision inventory.
Data error “We have the data” treated as “the data is usable”. Six of fourteen feeds are technically present and four are unusable for the question being asked of them. The feeds are real, arrive on time and pass validation. Nothing about them looks wrong.
Ownership error No single owner for the estate. Each partnership has a business owner; the portfolio has none. Each partnership was individually justified and individually owned, which is correct until there are eleven.
Local optimisation Partners optimise the metrics they report on, which they also define. Nobody issued a specification, so partners reasonably reported what they could measure well.
Historical carry-over The monthly pack retains four charts nobody uses, because removing one requires knowing who relies on it. The pack grew by accretion and no forum ever owned its contents.
Change error Onboarding a partner is treated as an integration event. It is a specification event with an integration afterwards. Integration is the visible, hard, technical part. Specification looks like paperwork.
05

The partner value model

Five classes, no acquisition

Each class carries a counterfactual test: what would have happened without this partner.

Three tiers, five classes

The five classes are the operating unit — each has its own counterfactual test and its own measure. They sit in three tiers, and the tier decides how a claim in it can be defended.

Direct economic value

Duration · Efficiency

Moves money in the current period. Defensible with a measurement and a comparator.

Knowledge and option value

Evidence · Intelligence

Buys the ability to answer something later, or to allocate better now. Real, and it cannot be defended with a single number.

Risk-adjusted value

Risk

Loss avoided. Visible only when it fails.

The tiers exist because the three are argued differently. A partner strong only in the second tier will lose a cost review against one strong in the first, regardless of which contributes more, unless the difference is named before the conversation starts.

WHERE PARTNER VALUE CAN COME FROM WHEN DEMAND IS NOT THE CONSTRAINT ACQUISITION · RULED OUT Supply is the binding constraint. A partner delivering initiations has moved demand between routes, not created it. Volume rises with partner spend and means nothing. DURATION How long people stay patients × months, and the patient count is capped The only volume lever left under constraint REVENUE, DIRECT EFFICIENCY What it saves us doing work displaced from the affiliate to the partner Easy to measure, easy to over-claim COST DISPLACED EVIDENCE What it lets us prove real-world evidence for access and guideline position Long lag, high ceiling REVENUE PROTECTED INTELLIGENCE What it lets us see segmentation, demand shape, where the journey fails Hardest to put a figure on. Still real. BETTER ALLOCATION RISK What it stops going wrong detection timeliness, compliance posture Only visible when it fails LOSS AVOIDED Every claim in every class carries a counterfactual test: what would have happened without this partner? Two partner business cases in the estate claimed initiation volume. Both pass a volume test. Neither survives the counterfactual, because supply was the binding constraint either way.
scroll to pan →
Why duration sits first — in a chronic therapy at supply constraint, revenue is patients multiplied by months, and the patient count is capped by supply. Duration is the only volume lever left, and it is the one no partner in the estate was being measured on.
The five classes in full
Class What it is Counterfactual test Measure Lands as Partners
Duration People stay on treatment longer because of something the partner does Would this cohort have persisted at the same rate through another route? Persistence at 12 / 26 / 52 weeks against a matched or historical comparator Revenue, directly. The strongest claim available. P01 P02 P04 P07
Efficiency Work the affiliate would otherwise do, done by the partner more cheaply or not needed at all Would the affiliate have had to do this, and at what volume? Contacts handled, HCP time released, fulfilment failures avoided Cost displaced. Easy to measure, easy to over-claim. P02 P07
Evidence Real-world evidence that supports access, guideline position or label Could this evidence be generated another way, and at what lead time? Evidence packs accepted; questions answerable that were not Revenue protected or unlocked, on a long lag P08 P03 P06
Intelligence Decision quality: who is being treated, where demand actually sits, where the journey fails What would we have decided without this, and would it have been wrong? Decisions made with traceable evidence; decisions reversed on new evidence Better allocation. Real, and the hardest to put a figure on. All 14 feeds
Risk Safety detection, compliance posture, supply visibility What is the exposure if this signal arrives late or not at all? Detection timeliness; screening coverage; consistency Loss avoided. Only visible when it fails. P01 P04 P07
The counterfactual column is the discipline. Two partner business cases in the estate claimed initiation volume as value; both survive the volume test and neither survives the counterfactual, because those patients had another route and supply was the binding constraint either way.

Where each partner archetype can generate value

Archetype against value class
Archetype Duration Efficiency Evidence Intelligence Risk Where its value actually sits
P01 Telehealth Strong Moderate Moderate Strong Strong Intelligence on the private route, which the affiliate sees nowhere else
P02 Pharmacy Strong Strong Moderate Strong Low Duration. The refill interval is the most defensible persistence measure in the estate.
P03 Device Moderate Low Strong Moderate Low Evidence. Objective longitudinal measurement is scarce and this is the only source of it.
P04 Behaviour Strong Moderate Moderate Strong Moderate Duration, if the selection problem can be handled. Currently unprovable.
P05 Navigation Low Moderate Low Strong Low Intelligence. Demand geography and provision gaps, available nowhere else.
P06 HCP workflow Moderate Strong Moderate Strong Moderate Intelligence on clinical inertia. The most under-exploited relationship in the estate.
P07 Patient support Strong Strong Moderate Strong Strong All five. The smallest contract in the estate and the only source of stop reasons.
P08 RWE Low Low Strong Moderate Low Evidence, and only evidence. Correctly.
06

What the data is actually for

Data to insight to value

The question the affiliate could not answer, and the reason the catalogue had 187 elements and four in real use. Every chain below runs the same way: a data category, the insight it produces, the decision that insight moves, and the value class it lands in.

HOW THE DATA BECOMES VALUE · ELEVEN CHAINS Bar width is the value at stake. The state column is what the estate can supply today. DATA CATEGORY INSIGHT IT PRODUCES DECISION IT MOVES VALUE AT STAKE Refill interval · stop event · stop reason Stay-time by cohort, route and dose stage Where support goes; which partner to deepen DURATION MOSTLY MISSING Eligibility · funding route · channel Who is treated vs who is eligible Channel investment; where provision is thin INTELLIGENCE ROUTE MISSING Titration stage · holds · escalation Where people stall below target dose Where clinical education lands DURATION PARTIAL Symptom reports · burden · coping What the first eight weeks feel like Support design; when a human is worth it DURATION FREE TEXT Weight · body composition trajectory Response shape, and when it predicts exit When to intervene; realistic outcome curves EVIDENCE BIASED HCP initiation · escalation behaviour Clinical inertia by professional segment Where field and education effort goes INTELLIGENCE NOT CAPTURED Contact volume · contact reason What goes wrong at scale, and what it costs Where self-service works EFFICIENCY REASON FREE TEXT Search · referral · provision geography Where demand exists without provision Access strategy INTELLIGENCE AVAILABLE Fulfilment failure · supply interruption Behavioural gap or structural gap Supply planning; reading a persistence dip EFFICIENCY NOT DISTINGUISHED Patient-reported outcome · experience Patient-valued outcomes beyond the endpoint Evidence packs; service design EVIDENCE AGGREGATE Safety content across surfaces Detection consistency and timeliness Screening cadence; where recognition sits RISK PARTNER-SIDE The ordering by value and the ordering by availability are almost inverted. The four widest bars are the four the estate supplies worst. Six of the eleven gaps close with a specification change to a partner already under contract. None needs a new partner.
scroll to pan →
Read the widths — the chains are drawn in proportion to what the estate can currently support, not to what matters. The two widest opportunities are the two the estate supplies worst.

The eleven chains, in order of what they are worth here

Data → insight → decision → value
# Data category The insight it produces The decision it moves Value class Market relevance State
1 Refill interval, stop event, stop reason Where in the course people leave, and why. Stay-time by cohort, route and dose stage. Where to put support; which partner to deepen; what the service must do at week 8 Duration Highest. In a chronic therapy at supply constraint, duration is the only growth lever available and the industry measures it badly. Stop reason absent
2 Eligibility, funding route, channel, geography Who is actually being treated against who is eligible. Where demand is unmet and where it is displaced. Where to invest channel effort; which route to support; where provision is thin Intelligence High. Segmentation from real treated populations rather than from claims panels or survey proxies. Funding route absent
3 Titration stage, dose holds, escalation timing Where people stall below target dose, and whether stalling is tolerability or inertia Where clinical education lands; what support content is needed and when Duration Evidence High. Under-dosing is a recognised and quantifiable value leak in titrated therapies. Escalations only
4 GI symptom reports, burden, coping What the first eight weeks feel like, and which experiences precede stopping Support design; content; where a human contact is worth its cost Duration High. The dominant stop driver, and almost never captured structurally. Free text only
5 Weight and body composition trajectory Response shape over time, and the point at which trajectory predicts exit When to intervene; what a realistic outcome curve looks like by segment Evidence High. Objective longitudinal outcome data is scarce and valuable to payers. Attrition-biased
6 Support contact volume and reason What is going wrong at scale, and what the service costs to run Where self-service works; where partner support displaces affiliate cost Efficiency Moderate. Straightforward, immediately actionable, easy to over-claim. Reason free text
7 HCP initiation and escalation behaviour Clinical inertia by professional segment; who starts and who does not escalate Where field and education effort should go Intelligence High. The most under-exploited data class in the estate and the closest to commercial decisions. Not captured
8 Search, referral and provision geography Where demand exists and where care is not available to meet it Access strategy; where to support provision Intelligence Moderate. Demand signal rather than population, and useful precisely because it is early. Available
9 Fulfilment failure, supply interruption Whether a cohort-wide gap is behavioural or structural Supply planning; whether a persistence dip is a real signal Efficiency Risk Moderate. Becomes critical during constraint, which is when it is most often missing. Not distinguished
10 Patient-reported outcome, experience Patient-valued outcomes beyond the clinical endpoint Evidence packs; service design Evidence Moderate and rising. Increasingly expected in access conversations. Aggregate only
11 Safety-relevant content across surfaces Whether detection is consistent and timely across the estate Screening cadence; where recognition sits Risk Non-negotiable. Not a value question but a licence-to-operate one. Partner-side

The pattern. Ranked by value, the top four are duration and segmentation. Ranked by what the estate can supply, they are geography, contact volume, engagement and aggregate outcomes.

Two worked examples

Stay-time

Refill intervals give the exit date, contact reasons give the why, and titration stage gives the point in the course. Together they produce a stay-time curve broken down by dose stage, funding route and support exposure — which is the single most commercially useful object the estate could produce, and it needs three fields that no partner currently sends.

The value is direct. In a chronic therapy where supply caps the patient count, a shift in median duration moves revenue with no change in demand at all. It is also the one thing the affiliate can influence, since the drivers are service and support rather than access.

What it needs: a stop-reason taxonomy at the point of contact; failed fulfilment distinguished from a patient-initiated gap; a denominator fixed at enrolment. All three are specification changes to partners already under contract.

Segmentation and demand

The affiliate segments on prescriber and on claims-derived proxies. Neither sees the private route, which is where a large share of treated patients in this therapy area actually sit, and neither sees eligibility — only people who reached treatment.

Partner data can produce a treated-population view with funding route, entry channel, geography, dose trajectory and duration attached. That supports demand shaping under constraint, which is a different exercise from demand generation and considerably more useful when supply is the binding limit.

What it needs: funding route on every initiation event, a controlled channel taxonomy issued by the affiliate rather than seven partner-defined ones, and outward-code geography. Two are specification changes; one needs a privacy determination already drafted.

07

How patient data becomes growth

Master use-case list

Revenue in this therapy area is patients multiplied by months multiplied by dose realised. Supply caps the first term and the third is set elsewhere. That leaves two movable terms and a fourth lever — cost to serve — and partner data is the only instrument that reaches any of them.

WHERE GROWTH CAN COME FROM WHEN SUPPLY IS THE CONSTRAINT PATIENTS capped by supply × MONTHS ON TREATMENT open × DOSE REALISED partly open × PRICE fixed the two boxed terms are movable EXTEND DURATION Months on treatment Median duration is the single largest untapped term. NEEDS stop reason at the point of stopping tolerability in the first 8 weeks support exposure against persistence supply gap distinguished from a real stop 9 use cases REALISE DOSE Dose realised Patients stalled below target dose consume supply and deliver less benefit. NEEDS titration stage and date dose holds and reductions HCP escalation behaviour tolerability at each step 6 use cases ALLOCATE BETTER Same patients, better chosen Under constraint the question is not how many but which. NEEDS eligibility against treated funding route geography and provision segment-level persistence 11 use cases SPEND LESS Cost to serve Support and service cost per persistent patient. NEEDS contact volume and reason self-service deflection fulfilment failure rate HCP time released 7 use cases Patient count is set by supply. Price is set elsewhere. That leaves duration, dose realisation, allocation and cost to serve. All four sit downstream of the treatment decision, which is where partner data lives and where the field force does not.
scroll to pan →
Why this framing rather than a funnel — a funnel puts acquisition at the top and everything else downstream of it. Under supply constraint acquisition is the part you cannot influence, and the value sits in duration, dose realisation and cost to serve.

Thirty-three use cases

Grouped by the lever each one moves. The state column is what the estate can support today.

Every use case, the data it needs, and whether the estate can supply it
Use case Data required Insight produced Who uses it Value State
EXTEND DURATION · the largest movable term
Stay-time curve by cohort refill interval, enrolment date, stop event Median and distribution of months on treatment, by segment Medical, Commercial Direct revenue Partial
Stop reasons, attributable contact reason, stop event, titration stage Why people leave, and at which point in the course Medical, Digital Direct revenue Blocked
First-eight-week burden symptom reports, contact volume, dose stage What the hardest part of starting actually feels like Digital, Medical Direct revenue Free text
Early-warning of exit measurement frequency decline, contact pattern, refill gap Which people are about to stop, while there is still time Digital Direct revenue Needs L2
Support exposure against persistence programme enrolment, refill interval Whether support changes duration, with selection stated Medical Direct revenue Needs L2
Route-level persistence funding route, refill interval Whether one access route holds people longer than another Commercial, Market access Direct revenue Route absent
Supply gap vs behavioural gap fulfilment failure, supply period marker, refill Whether a persistence dip is real or an artefact of stock Supply, Commercial Avoids a wrong decision Not distinguished
Restart rate stop event, subsequent dispense Whether stopping is permanent or an interruption Medical Direct revenue Not captured
Plateau management weight trajectory phase, contact reason What happens when the curve flattens and people reassess Medical, Digital Direct revenue Not derived
REALISE DOSE · supply consumed without benefit delivered
Titration completion rate titration stage, dates How many reach target dose, and how long it takes Medical Efficacy per unit supplied Partial
Where people stall dose holds, reductions, escalation delay The specific step at which escalation stops Medical, Digital Efficacy per unit supplied Not captured
Stall cause split dose holds, symptom reports, HCP escalation behaviour Tolerability, patient choice, or clinical inertia Medical Targets the right intervention Not captured
HCP escalation profile prescriber ID, escalation events per course Which prescribers escalate and which do not Medical, Field Directs education Not captured
Dose-response by segment dose stage, weight trajectory What benefit each step actually delivers, in the real world Medical, Market access Evidence Attrition-biased
Supply efficiency dose realised, units dispensed Benefit delivered per unit of constrained supply Supply, Commercial Allocation Derivable
ALLOCATE BETTER · the same patients, better chosen
Treated vs eligible eligibility assessment, initiation Who reaches treatment and who does not Commercial, Market access Allocation Partial
Funding route mix funding route on initiation How much of the treated population sits outside the NHS route Commercial Allocation Absent
Demand geography search, referral, provision, dispensing location Where demand exists and where care is available to meet it Commercial, Access Allocation Available
Provision gap map HCP and site directory, demand signal Where there is no realistic route to treatment Access, Medical Allocation Available
Channel economics acquisition channel, persistence, cost to serve Cost per persistent patient by route, not per initiation Commercial Allocation Needs L2
Segment persistence profile segment attributes, refill interval Which segments stay and which churn Commercial Allocation Partial
Unmet need shape eligibility, non-initiation, reasons Who is eligible and never starts, and why Market access Access strategy Not captured
Prescriber conversion eligible patients seen, initiations Conversion at the prescriber, not at the territory Field, Medical Allocation Not captured
Waiting and friction assessment date, consultation date, dispense date Where the journey slows and by how much Digital, Access Allocation Derivable
Competitive displacement switch events, prior therapy Movement in and out of the class Commercial Allocation Not captured
Supply allocation model demand geography, persistence, route Where constrained supply produces the most benefit Supply, Commercial Allocation Needs L2
SPEND LESS · cost to serve per persistent patient
Contact reason distribution contact reason taxonomy What goes wrong at scale, ranked Digital, Patient services Cost displaced Free text
Self-service deflection contact reason, content engagement Which contacts a good answer online would have prevented Digital Cost displaced Partial
Fulfilment failure cost failed fulfilment, downstream contact What a missed delivery costs in support and in persistence Supply, Patient services Cost displaced Not distinguished
HCP time released tool usage, query deflection Professional time not spent on things the tool answers Medical, Field Cost displaced Available
Support intensity by cohort contact volume, segment, stage Where a human contact is worth its cost and where it is not Patient services Cost displaced Partial
GENERATE EVIDENCE · long lag, high ceiling
Real-world outcome curves weight trajectory, duration, denominator Outcomes as they actually occur outside a trial Market access, Medical Access, reimbursement Attrition-biased
Patient-valued outcomes PRO instruments, experience Outcomes patients care about, alongside clinical ones Market access Access Aggregate only
Where the thirty-three land
State Count What it means
Available 6 Answerable now, once definitions are fixed. Start here.
Partial 8 A re-cut or an added field from a partner already sending data.
Blocked or absent 19 Fourteen need a specification change; five need linkage the estate does not have.

Six of thirty-three are available today. The estate was assembled without a decision inventory.

08

The portfolio decision

Strategic contribution against delivery

Two axes rather than one score. A partner supplying scarce evidence badly and a partner supplying abundant evidence well look identical on a single ranking, and they need opposite responses.

STRATEGIC CONTRIBUTION × CURRENT DELIVERY · ALL 23 Two axes, because they were being collapsed into one score and they need opposite responses. high low poor delivery strong delivery STRATEGIC CONTRIBUTION CURRENT DELIVERY FIX THE SPECIFICATION 9 partners · the largest quadrant Scarce evidence, badly supplied. These are the ones a cost-based review would cut first. DEEPEN 4 partners Scarce evidence, well supplied. Invest, extend scope, protect the relationship. EXIT OR MAKE TRANSACTIONAL 6 partners Little unique contribution, poorly delivered. Convert to a simple service or end. HARVEST 4 partners Abundant data, low uniqueness. Automate ingestion, spend no relationship effort. P07 P03 P06 P01a P04a P02b P01b P04b P05 P02a P08 P06b P03b V1 V2 V3 V4 V5 V6 H1 H2 H3 H4 Deepen Extend scope. Co-design the next data element. Longer term, more of the affiliate’s attention. Fix the specification Issue a specification. Change the grain, not the partner. Nine of twenty-three, and the largest pool of available value in the estate. Harvest Automate ingestion end to end. Zero relationship effort. Renew on autopilot while the data stays clean. Exit or make transactional Convert to a simple purchase with no data expectation, or end at renewal. The top-left quadrant is the finding. Nine partners hold scarce evidence and deliver it badly, and every one of them looks like a cut candidate on cost.
scroll to pan →
Fix the specification · 9Deepen · 4Harvest · 4Exit or make transactional · 6
The top-left quadrant is the argument — nine partners hold evidence the affiliate can get nowhere else and supply it badly. On any cost-based ranking they are the first cut, because they are small, cheap and produce nothing anyone reads.
Scoring behind the axes
Axis Built from Deliberately excluded
Strategic contribution Uniqueness of the evidence within the estate · number of the nine carried decisions it serves · value class where it is strong · whether the coverage it provides exists anywhere else Contract value. Relationship history. How much data arrives.
Current delivery Fitness for the decisions it is meant to serve · quality across the six dimensions · grain against contracted grain · latency · whether a specification exists at all Partner-reported activity metrics, since those measure the reporting rather than the delivery.

What each quadrant gets

Quadrant n Action What is done first What is deliberately not done
Deepen 4 Extend scope and co-design the next data element Joint roadmap on the two elements each could add; longer contract term in exchange No new commercial ask. These relationships are working and the risk is disturbing them.
Fix the specification 9 Change the grain, not the partner Issue a specification from the catalogue at the next renewal; three of the nine agreed to it mid-term No cutting. Every one of these would fail a cost review and every one holds something scarce.
Harvest 4 Automate ingestion, spend no relationship effort Full gateway automation; remove from the review cycle entirely No deepening. Additional attention here returns nothing.
Exit or make transactional 6 Convert to a simple purchase or end at renewal Strip the data expectation from four; two proposed for exit No remediation attempt. Fixing a partner with nothing unique to offer is the most common waste in these estates.

What the matrix changed. The review that had stalled produced a decision in one session once the two axes were separated. The instinctive move — rank by cost, cut the tail — would have removed six of the nine partners holding scarce evidence and kept three of the four harvest partners on full relationship effort.

09

Stating a partner’s value

The assembly, worked

No monetary figure. A value position with a stated counterfactual can be defended. The two business cases in circulation were derived from a baseline nobody measured.

HOW A PARTNER VALUE POSITION IS ASSEMBLED · WORKED FOR P07 ELEMENTS RECEIVED contact events contact reason enrolment support outcome INSIGHT PRODUCED stop reasons at the point of stopping first-8-week burden DECISIONS MOVED where support goes support content design partner deepening safety cadence VALUE CLASSES DURATION strong EFFICIENCY strong RISK strong INTELLIGENCE strong POSITION Strategic contribution: HIGH Current delivery: POOR Quadrant: FIX THE SPECIFICATION THE COUNTERFACTUAL, STATED Without this partner No structured source of stop reasons exists anywhere in the estate. The affiliate would be inferring reasons from absence, which is what it does today. Could it be replaced? Only by building the same capability in-house or requiring it of a larger partner. Both are slower and neither has the contact relationship. What is it worth? Stated as a duration position, not a revenue figure. Duration moves revenue under supply constraint, and the size of the move is measurable once the taxonomy exists. What would change the position? A stop-reason taxonomy and a fixed denominator. Two specification changes to a contract already in place. No monetary figure is stated. A value position with a counterfactual is defensible; a number derived from an unmeasurable baseline is not.
scroll to pan →
Why the smallest contract in the estate scores highest on contribution — it is the only place a person asks why someone stopped. Contribution is about scarcity within the estate, not about volume or spend.
The same assembly across four partners
Partner Strongest value class Counterfactual Delivery today Position
P02a Pharmacy Duration · refill interval is the persistence backbone Replaceable in principle by another dispensing partner, but not at this cohort completeness Strong — full cohort, daily, stable identifier Deepen
P07 Support Duration Risk · the only structured route to stop reasons Not replaceable without building the contact capability in-house Poor — free text, monthly, no taxonomy Fix the specification
P03 Device Evidence · objective longitudinal measurement Hard to replace; no other objective outcome source exists Poor for its purpose — attrition-biased, no measurement method Fix the specification
P08 RWE Evidence · cohort outcomes with a stated denominator Replaceable by other evidence providers on comparable terms Strong — specified, denominated, on schedule Deepen
P03 is the case that changed minds. It is described internally as the best data in the estate, it arrives constantly and it is clean. Its delivery scores poorly because it cannot support the decision it is used for, and no quality dashboard would ever have shown that.
10

The business intelligence tools

Question-led intelligence · cohort design

Separate tools with separate jobs. One starts from something a person was asked and finds whichever evidence answers it — usually not a cohort. The other starts from a population somebody already knows they need, and tests whether partner data can carry it. Neither routes into the other.

Question-led intelligence

Ten questions of the kind an insight team receives. Each shows what the question becomes once it is made honest, the evidence it needs, what came out, and where it breaks. Three of ten are answerable from what partners send today.

Patient
Commercial
HCP
Evidence
Partner
Data strategy
Tap a question. Three of ten are answerable from what partners send today.
Why are people leaving around week twelve?
Patient · Causal-adjacent
What it really is

You asked why. This estate can only tell you why among people who made contact before leaving — a reason mix among contactors, never a population rate. Reframed on that basis.

Evidence needed

An exit date and a reason, attached to the same person

Runs on

Supply gap patternReason for difficultyTreatment stage

What came out

Exits cluster between weeks eight and twelve, which is where most people move between dose steps. Among contactors, tolerability dominates before week twelve and cost after it.

Where it breaks

Silent leavers are the majority and are absent from the reason data entirely.

Which patients should we put support behind?
Patient · Allocation
What it really is

Support is finite, so this is an allocation question rather than a targeting one. It needs groups that differ on how long they stay and have a driver you can change.

Evidence needed

Segments that separate on duration and are modifiable

Runs on

Refill regularityReason for difficultyProvision density

What came out

The erratic-refill group sits about twenty-one weeks below the regular one, and its dominant contact reason is tolerability. The slow-titration group separates almost as sharply and its driver is cost.

Where it breaks

Two groups, similar spreads, opposite conclusions. Without the reason attached you would fund both.

Does behavioural support extend treatment?
Patient · Causal
What it really is

This is a causal claim and needs a comparison group. There is not one, and no field would create it.

Evidence needed

Exposure and outcome for the same people, plus an unexposed comparator

Runs on

Programme engagementSupply gap pattern

In the way

Programme engagement sits with a different partner and no shared identifier

What came out

Not answerable. The comparison runs between people who chose support and people who did not, and that choice is the strongest signal in the data.

Where it breaks

Selection, and no route around it here. Needs a randomised offer or a matched comparison on covariates nobody sends.

Which segments are underpenetrated?
Commercial · Descriptive
What it really is

Under supply constraint this is about allocation rather than growth — which eligible groups are not reaching treatment.

Evidence needed

Treated population against eligible population, by segment

Runs on

Area contextProvision density

In the way

Payer type is absent from every feed

What came out

Partial. Geography gives a treated-population map with visible thinning in several areas. Payer cannot be added, so the map blends funded and self-funded groups that behave nothing alike.

Where it breaks

Until payer arrives, underpenetrated cannot be told apart from funded elsewhere and therefore invisible.

What does it cost to keep a patient?
Commercial · Economics
What it really is

Cost per initiation means nothing when supply is the constraint. The number worth having is cost per persistent patient.

Evidence needed

Acquisition route, service consumption and duration, for the same people

Runs on

Supply gap patternReason for difficulty

In the way

Supply route is not recorded as a fieldChannel taxonomies differ across seven partners

What came out

Not answerable. Route data sits with partners in incompatible vocabularies and none of it joins to dispensing.

Where it breaks

Needs a common route vocabulary and a join. Worth naming because the reported figure today is the meaningless one.

Which prescribers are under-escalating?
HCP · Behavioural
What it really is

Territory-level conversion averages this away. The unit has to be the prescriber panel.

Evidence needed

Escalation events per patient-course, attributed to a prescriber

Runs on

Treatment stage

In the way

Prescriber identity sits on the professional side with no join to the patient side

What came out

Not answerable, and it fails on a join rather than a gap. Both halves of the data exist.

Where it breaks

The highest-value unanswered commercial question in the estate.

What happens to people after they start?
Evidence · Outcomes
What it really is

Straightforward to ask and biased to answer, in a knowable direction.

Evidence needed

Objective longitudinal measurement against a stable denominator

Runs on

Weight trajectoryTime on treatment

What came out

Partial. Measurement stops when people disengage and disengagement tracks the outcome, so the curve improves as the underlying picture worsens.

Where it breaks

Informative censoring. Detectable here, correctable only with an exit signal from another partner.

Do outcomes differ by comorbidity burden?
Evidence · Subgroup
What it really is

A standard stratification, and the first thing a payer asks for.

Evidence needed

Comorbidity at baseline, joined to trajectory and duration

Runs on

Weight trajectory

In the way

Comorbidity burden is assessed by two partners at eligibility and transmitted by neither

What came out

Not answerable. One field, already collected, never sent.

Where it breaks

One specification change to two existing agreements. No new collection, no new consent.

Which partner holds what we are missing?
Partner · Partner selection
What it really is

Run the required evidence against the coverage map rather than against partner proposals.

Evidence needed

What each partner could supply, against what the open questions need

Runs on

Reason for difficultySupply routePayer type

What came out

Answerable now. The three most-needed fields sit with two partners, and both are already under contract.

Where it breaks

The estate does not need a new partner. It needs a specification for two it already pays.

What can we actually link?
Data strategy · Feasibility
What it really is

Not an integration question. Identifier stability and permitted linkage are contractual.

Evidence needed

Identifier scheme and rights position, per partner pair

In the way

Eleven of fourteen feeds have no route to a shared subject identifier

What came out

Every cross-partner question in this list fails here rather than on data availability.

Where it breaks

No engineering moves a feed up a rung. Treating it as integration is how eighteen months get spent.

Cohort design

A scheme describes how a population could divide. A cohort is the one branch you decide to study. The tool is about whether the partner estate can support the group you have in mind.

What the data tags mean

1

Anchor

the starting population

Any population idea. Most of these are things that happened rather than things people are, which is what this estate holds.

Six rules for building a patient cohort

What the tool teaches, stated plainly.

Population anchors
Clinical anchors
Treatment anchors
Journey anchors
Need anchors
Source anchors
Tap an anchor. Most of these are things that happened rather than things people are.
Male

From two partner feeds. Separates this population weakly — about three weeks of difference in how long people stay on treatment.

Aged 60+

Ten-year bands from two feeds. Older bands stay on treatment longest, consistently.

Obesity indication

The licensed weight-management indication. The broadest anchor available.

Type 2 diabetes

Assessed by two partners as part of eligibility. Transmitted by neither, so it cannot define a population here.

Currently on treatment

Anyone with continuous supply across the window.

Newly initiated

First dispense in the window. The cleanest anchor in the estate.

Discontinued treatment

Inferred from a supply gap, not observed as an event.

Define this firstYou never see a stop. You see an absence — and an absence contains stopping, switching, moving pharmacy and running out of stock. Where you put the gap threshold decides who is in this population, and moving it from 30 to 60 days changes the answer by about a third.
Restarted after a gap

A dispense following a long gap, at the same partner.

Define this firstOnly visible if they came back to the same place. Anyone who resumed elsewhere still looks like a permanent stop.
Stalled below target dose

No escalation across two expected intervals.

Define this firstThis is a state rather than an event, so membership changes month to month. Fix an as-of date or you are describing different people each time you run it.
High unmet need

Not observed anywhere. Derived — and the derivation is the argument.

Define this firstBefore this is a population, somebody has to say what unmet need means. Poor response, poor support and poor access are three different groups wearing one label.
Reached through one partner

Everyone in a single partner’s book.

Define this firstA partner population is not a patient population. Whatever selects people into that partner also selects them into anything you build on it.
Intent
Tap an intent to see which dimensions matter, and whether partners send them.
Directly relevant
Payer typeNot collected

Who bears the cost, which shapes almost everything downstream.

Absent from every feed. Probably the strongest predictor available anywhere, and invisible.
Comorbidity burdenNot collected

The eligibility gate. Without it a treated population cannot really be described at all.

Assessed by two partners during eligibility and transmitted by neither. One specification change would fix it.
Diabetes statusNot collected

Changes indication, funding route, monitoring and how long people stay. Not one comorbidity among many.

Held at assessment by two partners. Not transmitted.
Relevant
Age bandPartial

The only demographic split any feed supports, and it behaves consistently — older bands stay longer.

Carried by two of fourteen feeds, so any split runs on a subset.
Supply routeNot collected

Where people actually get the medicine. Nine routes exist and the estate sees six.

No feed records it as a field, though partners could.
Journey positionPartial

A composite of stage and recency. The most natural way to describe where someone is.

Derived, and inherits the gaps in treatment stage.
Weakly relevant
Weight trajectoryPartial

Response shape over time, which is what most people mean by how someone is doing.

Measurement stops when engagement stops, and engagement tracks the outcome. The curve improves as the picture worsens.
Area contextAvailable

Area-level context joined at outward-code level. Describes places, not people.

Treatment stagePartial

Where people actually are in the schedule, which is rarely where anyone assumes.

Escalations are captured; holds and reductions are not. A stall and a slow start look identical.
Time on treatmentAvailable

Where people are in the course.

Directly relevant
Refill regularityAvailable

Visible in the first three fills, before most people have left. Early enough to act on.

Reason for difficultyPartial

Determines whether support would help at all. Cost is not a support problem.

Free text from one partner, and only from people who made contact. Silent leavers are absent.
Relevant
Supply gap patternAvailable

A short gap is a recoverable moment. A long one usually is not.

Access barrierNot collected

Different barriers need different responses, and some need none from you.

Not captured anywhere. Would need to be collected at assessment.
Weakly relevant
Payer typeNot collected

A self-funding person faces a monthly decision a reimbursed one does not.

Absent from every feed. Probably the strongest predictor available anywhere, and invisible.
Programme engagementCannot be linked

The obvious lever, and the hardest to evidence.

Sits with a different partner and no shared identifier. Needs a consent mechanism, not an integration.
Treatment stagePartial

Support needs differ sharply by stage, and stage is knowable in advance.

Escalations are captured; holds and reductions are not. A stall and a slow start look identical.
Journey positionPartial

Each position implies a different intervention, which is what makes it designable.

Derived, and inherits the gaps in treatment stage.
Supply routeNot collected

Route determines who can reach them and how.

No feed records it as a field, though partners could.
Treatment historyNot collected

Previously treated people need something different from the outset.

Prior exposure is asked at assessment and never transmitted.
Directly relevant
Comorbidity burdenNot collected

The first thing a payer asks about, and the first stratification any reviewer wants.

Assessed by two partners during eligibility and transmitted by neither. One specification change would fix it.
Diabetes statusNot collected

A required subgroup in almost any submission in this area.

Held at assessment by two partners. Not transmitted.
Weight trajectoryPartial

The objective outcome measure. Scarce, and valuable to payers.

Measurement stops when engagement stops, and engagement tracks the outcome. The curve improves as the picture worsens.
Relevant
Journey positionPartial

Standard framing for a longitudinal cohort.

Derived, and inherits the gaps in treatment stage.
Treatment stagePartial

Dose exposure is a prerequisite for any effectiveness claim.

Escalations are captured; holds and reductions are not. A stall and a slow start look identical.
Weakly relevant
Payer typeNot collected

Any outcome comparison across payer types is comparing different populations.

Absent from every feed. Probably the strongest predictor available anywhere, and invisible.
Time on treatmentAvailable

Circular if duration is also your outcome. Use as a frame, not a criterion.

Supply routeNot collected

Populations reached by different routes are not comparable.

No feed records it as a field, though partners could.
Treatment historyNot collected

Confounds every response curve if it is not controlled for.

Prior exposure is asked at assessment and never transmitted.
Age bandPartial

Standard stratification for any outcome claim, and reviewers will expect it.

Carried by two of fourteen feeds, so any split runs on a subset.
Three worked cohorts
Early erratic refillers, tolerability-driven
Newly initiatedRefill regularity: ErraticReason: Tolerability
BreadthFocused
FeasibilityModerate–high
ReachabilityModerate
ActionabilityHigh
ConfidenceModerate–high

Two criteria, both resolving to fields partners send. The dominant reason is modifiable, which is what makes it worth acting on.

Youngest band, low-provision areas
Newly initiatedAge band: 18–29Provision density: Low
BreadthNarrow
FeasibilityModerate
ReachabilityLow
ActionabilityLow
ConfidenceModerate

Identifiable and unactionable. No partner contacts this group and nothing in the definition can be changed. A finding, not a target.

High comorbidity burden, stalled below target
Newly initiatedComorbidity burden: HighTreatment stage: Early titration
Breadth
FeasibilityNot supported
Reachability
Actionability
Confidence

Comorbidity burden is assessed by two partners at eligibility and transmitted by neither. One specification change would make this buildable.

What the data tags mean
AvailableA partner sends this today.
PartialIt arrives, but degraded — from some partners only, or in a form that loses something.
Not collectedNo partner sends it. Often held at source and never transmitted.
Cannot be linkedIt exists, on the wrong side of a join no two partners share.
Must be definedNot observed. You have to say what it means before it is anything.
Six rules for building a cohort
1
Start from a question, not from the data

The question decides which dimensions matter. The data only decides whether you can have them.

2
Anchor on what happened, not who they are

In this estate behaviour separates people about seven times better than demographics do.

3
Define an event before you use one

Discontinuation is not observed. It is inferred from absence, and your threshold is doing most of the work.

4
Segment on something you could change

A split on age is a finding. A split on refill behaviour is a plan.

5
Two criteria, rarely three

Each one you add narrows the population and adds a partner dependency. The third usually costs more than it returns.

6
A group you cannot reach is a finding, not a target

Publish it. Do not build a programme around it.

No population counts appear anywhere in either tool. Dividing an anchor evenly across branches produces numbers that look computed and are not. Breadth is judged on how hard each criterion cuts, and stated as a word with a reason.
11

Payer, route and clinical context

Three axes, one field each

I spent most of the first month treating these as one attribute. They are three, set by three different actors, and each predicts something the others do not. Getting this wrong is why the early segment work produced curves that averaged incompatible populations.

THREE AXES THAT WERE BEING TREATED AS ONE Who bears the cost, under which scheme it is authorised, and where the person physically collects it. Set by three different actors, predicting three different things. PAYER who bears the cost National health system unobserved Statutory / social insurance unobserved Regional budget holder unobserved Complementary insurance partial Full private insurance partial Employer scheme unobserved Out of pocket observed Co-payment / tiered unobserved Managed access unobserved FUNDING ROUTE the scheme it runs under Specialist service pathway unobserved Primary care pathway unobserved Private clinical pathway observed Insurance-authorised partial Employer programme unobserved Self-directed observed Pilot or managed entry unobserved SUPPLY ROUTE where they collect it Community pharmacy partial Distance-selling pharmacy observed Telehealth, integrated fulfilment observed Telehealth, separate pharmacy observed Specialist weight service unobserved General practice unobserved Medical aesthetics clinic unobserved Private endocrine / bariatric partial Outside the legitimate chain unobserved PAYER DETERMINES WHICH PARTNER SEES THE PATIENT — AND THIS ESTATE IS ALMOST ENTIRELY ONE PAYER TYPE Reimbursed patients move through specialist services and general practice. Self-funding patients move through telehealth, distance-selling pharmacy and aesthetics clinics. Fourteen of the estate’s feeds sit in the second group. Every transition rate, persistence curve and segment profile in this document is fitted on a privately funded, self-selecting cohort. If coverage expands, the treated population shifts toward a payer type the estate cannot observe at all. The affiliate is measuring the population least like where the volume is going. Coverage status is held per market as a dated, versioned value. This document states payer structure and does not assert any market’s current reimbursement position.
scroll to pan →
Observed by a partner in this estatePartially observedNot observed at all
On dating — payer archetypes are structural and stable, so they are named. Coverage positions move, so they are held as a dated value per market rather than written into the document. A model that hard-codes a reimbursement decision needs rewriting every quarter.

Clinical context, which was missing entirely

Comorbidity is the eligibility gate. Access to the weight-management indication turns on BMI together with a weight-related comorbidity, so a person’s comorbidity profile determines whether they qualify, under which route, and with what monitoring. The catalogue had 187 elements and none of them was comorbidity.

Clinical context · new Layer 2 domain
Element Grain Source Why it matters here State
Comorbidity at assessment pseudonym / snapshot / assessed population Eligibility assessment The eligibility gate. Without it a treated population is uninterpretable. Absent
Coded comorbidity list pseudonym / snapshot Eligibility assessment Coded rather than free text, or it cannot be counted Absent
Comorbidity count derived Derived A plausible persistence predictor nobody here has tested Not derived
Type 2 diabetes status pseudonym / snapshot Eligibility assessment Changes the indication, the funding route, the monitoring and the persistence pattern. Not one comorbidity among many. Absent
Cardiovascular risk status pseudonym / snapshot Eligibility assessment Increasingly central to the evidence conversation Absent
Concomitant medication class pseudonym / longitudinal Eligibility assessment, pharmacy Both a comorbidity proxy and a titration constraint Absent
Contraindication flag pseudonym / snapshot Eligibility assessment Safety-relevant and route-determining Absent
Baseline HbA1c where diabetic pseudonym / snapshot Eligibility assessment Baseline for the outcome that matters in the diabetic subgroup Absent
Bariatric surgery history pseudonym / snapshot Eligibility assessment Changes expected trajectory entirely Absent
Prior GLP-1 exposure pseudonym / snapshot Eligibility assessment, pharmacy A restart is a different clinical situation from a first course, and the estate cannot tell them apart Absent
Other weight-management agents pseudonym / longitudinal Eligibility assessment Confounds every response curve Absent

All eleven are held at source by the telehealth and HCP-workflow partners as part of an assessment they already perform. None is transmitted. A specification change to two existing agreements rather than a new collection, which puts it in the cheapest tranche of the programme.

Supply route, distinct from who pays

Nine routes, and what the estate sees
Route Regulatory frame Clinical assessment before supply Observed here
Community pharmacy, in person Pharmacy regulation Prescription-led Partial
Distance-selling pharmacy Pharmacy regulation, distance-selling requirements Prescription-led, remote verification expected Yes
Telehealth with integrated fulfilment Provider and pharmacy regulation Consultation-led, same organisation Yes
Telehealth with separate pharmacy Split across two regulated entities Consultation-led, fulfilment elsewhere Yes
Specialist weight-management service NHS commissioning Multidisciplinary No
General practice Primary care Prescription-led No
Medical aesthetics clinic Provider regulation; assessment quality a live concern Highly variable No
Private endocrinology or bariatric Provider regulation Specialist Partial
Outside the legitimate supply chain None None No

Aesthetics is the one I would single out. It is a material route in this therapy area in the UK, it sits in a different regulatory frame from a pharmacy or an online clinic, and no partner in the estate observes it. A manufacturer looking only at its partner estate cannot see a route by which its medicine reaches people.

A route field with no value for supply obtained outside the legitimate chain produces a dataset in which that population is invisible, and falsified product in this class is a documented problem.

Payer, funding route and supply route now sit as three separate fields with three separate controlled lists. That is one more field than anyone wanted and two more than the original design had,.
12

Forecasting consumption

Cohort flow

Partner data cannot forecast demand. It sees a partner’s cohort, not a market, and under supply constraint new starts are set by allocation rather than by appetite. What it can forecast is consumption per patient over time, which is the multiplier you apply to whatever patient count comes from elsewhere.

COHORT-FLOW MODEL · WHAT THE REFILL FEED CAN FORECAST Units = patients × dose intensity × persistence-weighted duration. The first term comes from market sources. The other two are what partner data measures, and most supply plans treat them as constants. PRE esc. STEP 1 pack strength 1 esc. STEP 2 pack strength 2 esc. STEP 3 pack strength 3 esc. STEP 4 pack strength 4 esc. MAINT pack strength 5 LAPSED gap beyond threshold RESTARTED re-entry at any step drop-out at every step · rate estimated per step from the refill history WHAT COMES OUT Patients per dose step per month the titration wave migrating from low to high strength over 16–20 weeks Units per pack strength the supply-planning number, 8 to 12 weeks ahead, from data already received Segment-differential forecasts a short-duration segment consumes a different pack mix, because it churns before maintenance Scenario ranges under payer mix three assumptions rather than one number, because coverage shifts are exogenous and untimeable THE FOUR WAYS IT BREAKS Supply interruption contaminates the history Rates fitted across a period with stockouts encode the stockout as behaviour, and the model then forecasts a recurrence of something Coverage The cohort is private-route and self-selecting. Applying its rates to a market count assumes a representativeness that does not hold, and Regime change New entrants, oral formulations and guidance changes all break stationarity. A cohort model assumes the rates hold. Small segments Wide intervals, and the cell-size suppression rule stops some segments being modelled at all. Survival models with competing risks and hierarchical partial pooling. Warranted here, and not what anyone means when they say AI.
scroll to pan →
Why dose intensity is the underrated term — in a titrated therapy with multiple pack strengths, a cohort that starts together moves up the ladder together, producing a wave of demand migrating from low strength to high over sixteen to twenty weeks. The refill feed already carries the titration-stage distribution, so the pack mix is forecastable now.
The pathway, staged by what it needs
Stage What becomes possible What it needs Reachable
Now Pooled titration-stage distribution and pack-mix projection, 8–12 weeks, no segmentation The dispensing feed alone Immediately
One change Same, with contaminated windows excluded and split by funding route Supply-event markers and funding route Specification, two agreements
Two changes Segment-level transition rates Comorbidity and demographics Specification, two agreements
Needs L2 Support exposure and behaviour as covariates — whether intervention changes the curve Cross-partner linkage Consent design
External Market-level rather than cohort-level forecasting A market data source and a reweighting basis Procurement decision

The first three are reachable within a year. The fifth is not an analytics problem.

Two things I would insist on. The forecast carries a confidence card like any other decision-grade output, stating the cohort it was fitted on, the excluded windows and what it cannot tell you — which is anything about the reimbursed route. And payer mix enters as a scenario input rather than a parameter: three assumptions, three ranges, no single number. Coverage shifts are exogenous and nobody can time them, so producing one figure would be a false precision that the supply team would then plan against.

13

Benchmarks, other markets, and measuring growth

Transfer

A benchmark set built for one market is worth more than it looks, because most of what makes it hard to build is market-independent. What transfers and what does not follows a clean rule: the structure travels, the values do not.

What transfers to another market, and what has to be rebuilt
Layer Transfers? Why What has to change
The value model — five classes Fully Duration, efficiency, evidence, intelligence and risk are properties of the commercial situation, not of a jurisdiction. Nothing. The counterfactual test applies everywhere.
Growth lever structure Fully Patients × months × dose is arithmetic. Only which term is capped changes. Where supply is not the constraint, acquisition comes back into scope and the weighting shifts.
Data catalogue structure Fully The domains, the three layers and the grain model describe how partner data behaves, not what any market holds. Element definitions may need local clinical terms.
Decision inventory method Fully The decision card and the cost-of-being-wrong test are a facilitation technique. The decisions themselves are local and must be re-elicited. This is not a copy exercise.
Grain and linkage model Fully The three axes and five rungs are structural. Which rung is legally reachable differs sharply. Several markets permit routine linkage the UK does not.
Quality dimensions Fully Six standard dimensions plus fitness for decision. Nothing.
Benchmark values Not at all Every threshold here is either a local operating target or derived from a UK-specific proxy. All of them. Carrying a UK completeness target into another market is the most likely misuse of this work.
Reference sources Not at all National identity services, professional registers and organisation directories are national by definition. Complete rebuild of Layer 1. The structure holds; every source is different.
Legal routes Not at all The four routes in the next section are UK. EU markets differ from each other, let alone from the UK. Complete reassessment. Do not assume EU-wide uniformity either.
Partner archetypes Partly The eight roles exist in most developed markets. Their prevalence differs enormously. Direct-to-consumer telehealth is dominant in some markets and marginal in others.

Setting a benchmark in a market with no history

The first cycle in a new market has no baseline, which is the position the affiliate was in here. Four sources, in preference order, and the fourth is where most of these thresholds actually came from.

Source When to use it Status it carries Example
Published external data Where a comparable published figure exists Benchmark Clinical measurement intervals, taken from guidance and cited to version
Cross-market internal Where the same partner archetype operates in another affiliate Derived Feed latency norms for a dispensing partner; structure transfers, absolute value does not
Proxy from an adjacent setting Where no direct figure exists but a comparable programme does Derived from proxy PRO completion, taken from published rates in comparable programmes and labelled as provisional
Risk-based operating target Where nothing external exists — the common case Operating target Cohort coverage for a renewal decision, set at the point below which the analysis describes the partner’s best cases rather than its population

Six of the nine benchmarks in this work are the fourth kind. They are defensible because the reasoning is written down, and they are not standards. An operating target presented as a standard is the misuse this table is meant to prevent.

Assessing growth once the benchmarks exist

The growth assessment, cycle on cycle
Question Measured how Guards against
Did duration move? Median and distribution of months on treatment against a fixed denominator, split by route and by dose stage A shift in cohort mix reading as a shift in behaviour. Splitting by route is what catches it.
Did dose realisation move? Proportion reaching target dose and time to reach it Improvement driven by a change in who is being started rather than how they are managed
Did allocation improve? Share of treated population in segments with the highest duration and dose realisation Volume growth in low-persistence segments reading as success
Did cost to serve move? Support contacts and fulfilment failures per persistent patient, not per patient A fall in contacts caused by people leaving rather than by things working
Did the evidence position move? Questions answerable now that were not; evidence packs accepted Activity counted as progress
Did the estate improve? Use cases moving from blocked to partial to available; fitness verdicts passing The catalogue growing while nothing becomes answerable
Every one of these is a ratio with a denominator that has to be fixed in advance.
14

How this is used inside the affiliate

Where it lands

Five functions, five different objects, one spine underneath — and the honest position is that five of the eight took it up and three did not, at least not in the window.

What each function takes from it
Function What they open What they do with it Cadence Adoption
Commercial · partnerships Portfolio matrix and partner value report Renewal and expansion decisions. The report replaces the review that had stalled. Quarterly, and at each renewal Took it up The stalled review was their problem and this solved it.
Medical Decision datasets and confidence cards Evidence questions; where support and education go Continuous Took it up Driven by the fitness verdicts, which told them which of their questions were answerable.
Market access Evidence-class contributions and the RWE outputs Payer conversations and evidence planning Per submission cycle Partial Used the outputs, did not engage with the catalogue.
Data and analytics Catalogue, gateway, definition register Runs it. Owns the integrity of the record and none of the decisions in it. Daily Took it up
Privacy and legal Rights cockpit and the linkage ladder Determinations, and the specification that goes into agreements At contracting and on change Took it up The structured rights position removed the interruptions they most disliked.
Patient safety Surface inventory and screening cadence Configures intake; assesses the queue Per sweep Partial Adopted the inventory, resisted moving recognition off partners until the volume argument was made twice.
Field and sales Nothing directly Did not land The HCP behaviour data that would serve them is the one class the estate does not capture. Nothing to give them yet.
Supply Demand geography and persistence Allocation and forecasting Monthly Did not land Interested, but the supply-event field does not exist, so the join they need cannot be made.

Three of eight did not take it up, and two of those three are the ones I would most have wanted. Field and Supply both have a real use for this and neither can be served until a field that does not exist starts arriving. That is a sequencing consequence rather than an adoption failure, but it looks identical from the inside and it cost credibility in month four.

What drove adoption was the fitness verdict — a per-decision fit or blocked, visible to the person who owns the decision. People engaged with the catalogue because it started telling them their question could not be answered and why.

Governance forums
Forum Who Decides Frequency
Portfolio forum Commercial, Digital, Medical, Data, Privacy Quadrant assignments, exits, specifications, override review Quarterly
Catalogue change Data product, Privacy, decision owners New elements, definition changes, denominator versions Monthly
Fitness exceptions Decision owner, data product Whether a blocked publication proceeds, and on what stated ceiling As needed, logged
Safety configuration Patient safety, Digital, partner leads Surface inventory and cadence Quarterly and on any new surface
15

Data sharing agreements in the UK

The landscape, and how to make an exchange compliant

Four routes by which partner data can lawfully reach a pharmaceutical affiliate in the UK, the conditions attached to each, and the one route that is not available. Two independent tests apply and the second is the one most often missed.

TWO TESTS, BOTH OF WHICH MUST PASS TEST 1 · DATA PROTECTION LAW UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. Health data needs BOTH an Article 6 basis AND an Article 9 condition. Five Article 9 conditions also require a Schedule 1 DPA 2018 condition and, in several cases, an appropriate policy document. TEST 2 · COMMON LAW DUTY OF CONFIDENTIALITY Separate from data protection law and frequently missed. Applies to information given in confidence in a clinical context. Satisfied by consent, by statutory support, or by the information no longer being confidential — that is, anonymised. A lawful basis under Test 1 does not discharge Test 2. + FOUR ROUTES THAT PASS BOTH · AND ONE THAT DOES NOT R1 EFFECTIVELY ANONYMISED Partner aggregates or anonymises before transmission. Affiliate is out of scope of data protection law entirely. Confidentiality discharged because the information is no longer confidential. CAUTION High bar. Motivated-intruder test; watch singling out and linkability. Small cohorts fail it. MOST OF THE ESTATE R2 EXPLICIT CONSENT The patient consents, specifically, naming the affiliate and the purpose. Article 9(2)(a) plus an Article 6 basis. Discharges confidentiality where the consent is informed. CAUTION Withdrawable. Consent obtained by a partner for its own purposes does not extend to the affiliate. 2 ENGAGEMENTS R3 SCIENTIFIC RESEARCH Research, statutorily defined to include commercial and privately funded work. Article 9(2)(j) with Schedule 1 safeguards. Broad consent to an area of research is available. CAUTION Safeguards are conditions, not paperwork. Confidentiality still needs consent, statutory support or anonymisation. THE RWE ROUTE R4 TRUSTED THIRD PARTY A third party holds identifiers and does the linkage. Affiliate receives outputs only. Affiliate never holds identifiable data. The third party carries the controller obligations for the linkage. CAUTION Slow to stand up, and the outputs are fixed at the point they are specified. THE L3 ROUTE R5 · PROBABILISTIC MATCHING ACROSS PARTNERS — NOT AVAILABLE Linking two partners’ pseudonymous datasets by matching quasi-identifiers would work technically. It manufactures a linkage no rights position permits, defeats the anonymisation the affiliate relies on for R1, and re-identifying de-identified personal data is a criminal offence under section 171 of the Data Protection Act 2018. This was proposed twice during the work and declined twice. It is the one place where the technically easy answer is the unlawful one.
scroll to pan →
The second test is the one that gets missed — a lawful basis under data protection law does not discharge the common law duty of confidentiality. They are independent, and information given to a clinician in a consultation is confidential regardless of what any privacy notice says.

Data protection, in the state it is now in

What applies, and what changed recently
Instrument Status What it requires here
UK GDPR · Article 6 Law A lawful basis for any processing of personal data. For a commercial affiliate this is realistically consent or legitimate interests, and legitimate interests needs a documented assessment.
UK GDPR · Article 9 Law Health data is special category and needs a separate Article 9 condition on top of the Article 6 basis. The two do not have to be linked and both must be identified before processing begins.
DPA 2018 · Schedule 1 Law Five of the ten Article 9 conditions require an additional Schedule 1 condition and, in several cases, an appropriate policy document in place at the time.
Data (Use and Access) Act 2025 Law Materially changes the position for this work. Scientific research now has a statutory definition that expressly includes privately funded and commercial research. Broad consent to an area of research is available. Further processing for research is treated as compatible with the original purpose. A transparency exemption applies where direct notification would take disproportionate effort, provided the notice is published.
Recognised legitimate interests · Art. 6(1)(ea) Law A new basis with no balancing test — and it does not cover commercial research. It is limited to a defined list including emergencies, safeguarding and crime prevention. Assuming it applies here would be a mistake, and it is an easy one to make.
ICO anonymisation guidance Regulator guidance Effective anonymisation puts data outside the scope of the legislation, and the bar is high. Identifiability sits on a spectrum; assess with the motivated-intruder test and watch for singling out and linkability. Pseudonymised data remains personal data.
DPA 2018 · s.171 Law Knowingly or recklessly re-identifying de-identified personal data is a criminal offence.
DPIA Law Required for high-risk processing, which large-scale special category data is.
The transparency point deserves attention because it is counter-intuitive. Under the 2025 Act, re-using personal data for scientific research without individually notifying people is available where notification would involve disproportionate effort — provided the notice is published and rights are protected in other ways. That is a real widening, and it is not a general licence.

The route each part of this design actually relies on

Design decision against legal route
Design decision Route Why it holds Residual risk
Affiliate receives aggregate or effectively anonymised data from most partners R1 Outside the scope of data protection law at the affiliate. Confidentiality discharged because the information is no longer confidential. Small cohorts fail the motivated-intruder test. The catalogue carries a minimum cohort size and the gateway enforces it.
Pseudonymous subject-level data from two partners R2 Explicit consent, obtained by the partner, naming the affiliate and the purpose. Withdrawable. Consent a partner obtained for its own service does not extend to the affiliate, and two agreements had assumed otherwise.
Real-world evidence work R3 Scientific research, now statutorily including commercial work, with Schedule 1 safeguards. The safeguards are conditions, not documentation. Confidentiality still needs consent, statutory support or anonymisation.
Any cross-partner linkage R4 A trusted third party holds identifiers and returns outputs. The affiliate never holds identifiable data. Slow to establish, and the outputs are fixed at specification time. This is why the linkage ladder places L3 where it does.
Rights position as structured values Not a processing question. It is a record of determinations already made. A structured field can look like a determination. Every value carries who confirmed it and when.
Safety content handling Separate Pharmacovigilance obligations sit outside this framework and cannot be contracted away. Anything received is handled through the established route. Recognition sitting with partners was the real exposure, and moving it was a process change rather than a legal one.
Cross-partner probabilistic matching None available Removed from the design. See below.

The part that was not lawful

The original architecture included probabilistic matching across partner datasets on quasi-identifiers — age band, outward postcode, initiation month — to construct a longitudinal cross-partner view. Technically it works. It was proposed twice and removed twice.

It manufactures a linkage no rights position permits. It defeats the anonymisation that most of the estate relies on for its lawful footing, because a dataset that can be linked to another is one where singling out becomes possible. And under section 171 of the Data Protection Act 2018, knowingly or recklessly re-identifying de-identified personal data is a criminal offence.

The second time it was proposed, it came with a technical argument about match confidence thresholds. The threshold is not the issue. The intent to re-identify is.

The rest of the regulatory frame

Instrument Applies to What it constrains here
ABPI Code of Practice All partner activity relating to the medicines Third-party conduct is the company’s responsibility, including where the third party acts against instructions. Data collection must not be a vehicle for promotion. Transfers of value are disclosable, and data supplied in exchange for services is a transfer of value.
Advertising of prescription-only medicines Any public-facing material Prohibited to the public. Reaches partner surfaces where the affiliate’s material or funding is present.
Pharmacovigilance obligations Digital media under the company’s management or sponsorship Screening at a defined cadence. Anything received is reportable regardless of route, and no contract removes this.
Medical device regulation Partner software that assesses, advises or monitors Classification is the partner’s obligation as manufacturer and the affiliate’s dependency. An unclassified device inside a funded journey is a question the affiliate will be asked.
National data opt-out Confidential patient information from health and care organisations in England, used for research and planning Does not reach most of this estate, because most of it is private-sector service data rather than NHS-sourced. Where an NHS route is added, it does.
Competition law Insight returned to partners who serve several manufacturers Two of the twenty-three operate across manufacturers. What flows back to them was scoped deliberately, and the reciprocity design in the dossiers exists partly for this reason.
The five things most likely to go wrong, and what stops each
Risk How it happens Control
Purpose creep Data received for service operation gets used for commercial analysis because it is sitting there Permitted purposes as a structured field; the gateway blocks the use, not the ingestion
Consent that does not reach the affiliate A partner’s consent covers its own service and is assumed to cover onward supply Controller role and consent scope recorded per engagement, confirmed by Privacy, never inferred
Anonymisation that is not anonymous A cohort small enough to single out, or a combination that becomes linkable Minimum cohort size in the catalogue; identifiability reassessed when a new dataset arrives
Determination by default A structured field gets populated by extraction and nobody confirms it No rights value is written without a named human confirmation event. UNKNOWN is a permitted value; a default is not.
Drift into promotion A data-collection instrument becomes a channel Code review sits in the gate set for any patient-facing engagement, not only for material

Counsel reviewed two points: the trusted third party route, and whether the research definition reached the commercial analysis. The answer on the second was narrower than the affiliate wanted.

16

How the work was run

Method

Five weeks of discovery running alongside six workshops, each ending on a decision rather than a discussion.

The instruments

Research design — what was run, and the decision each enabled
Instrument Who / what Output Decision it enabled
System walkthrough2 sessions, 71 and 54 minutes, screen-shared Data engineering and Partner Operations, narrated by the analyst who runs the monthly reconciliation Current-state data path with every actual handoff, including the four that appear in no documentation Whether the problem was technology or process. It was process, in eleven of fourteen feeds.
Semi-structured interviews17 interviews across 6 functions Commercial, Medical, Market Access, Privacy, Data, Patient Safety Decision inventory, pain points, and the vocabulary conflicts between functions Which decisions matter, who owns them, and where the same word means three things
Agreement-set analysis23 agreements, 17 DPAs, 9 partner terms Contracts, data processing agreements, partner platform terms Rights pattern matrix across seven drafting styles Which rights language can become a structured control and which is irreducibly bespoke
Feed profiling5 live feeds, field by field Dispensing, connected device, patient support, behaviour, HCP workflow Field-level fill rates, type validity, cardinality, temporal coverage, subject continuity Whether current feeds are usable, which is a different question from whether they are clean
Partner value reviewall 23, desk-based Agreements, activity reports, steering material, invoices for scope only Contribution and delivery position per partner The portfolio matrix. This is where the counterfactual test was applied for the first time.
Artefact analysis~60 artefacts Reconciliation spreadsheets, monthly partner reports, steering decks, service tickets, mailbox threads Evidence trail of the actual operating process against the documented one Where manual work and rework sit, and who absorbs them
Workshop sequence6 sessions over 5 weeks Cross-functional, 6 to 11 participants per session Ranked decision inventory, journey model, catalogue, allocation, checkpoint grid, product concept What gets built, what stays human, and what is not worth doing

The correction to the brief

The brief stated that the affiliate had a partner sprawl problem and needed to rationalise the estate. Profiling contradicted it in the first fortnight.

Overlap between partners is low. Mapping what the fourteen active feeds actually supply against the fourteen journey stages produced a coverage pattern with little redundancy — six stages are seen by more than one partner, and two are seen by none. The estate is sparse and uncoordinated rather than duplicated. On a finance report that looks the same and needs the opposite response.

Asked which decisions partner data currently informs, the seventeen interviews produced 27 named decisions and four that anyone could point to evidence for. The problem is not too many partners. No decision owner had specified what evidence would change their mind, which leaves every dataset equally defensible.

This changed the engagement. A rationalisation exercise would have cut six of the nine partners supplying the scarcest evidence in the estate, because all nine are small, none is expensive, and none produces a report anybody reads.
Workshop sequence
Session Question it had to settle Frameworks used Output Decision it ended on
W1 Decisions11 participants, 3 hours Which decisions could partner data change? Decision-back mapping · forced ranking · cost-of-being-wrong scoring Ranked inventory of 27 decisions with owners, current evidence and failure cost The nine decisions the rest of the work would serve
W2 Journey8 participants, 3 hours Where is data generated, and where does it disappear? Journey mapping · service blueprinting · dark-data marking 14-stage journey with touchpoints and coverage marked per archetype That two journey stages are unobserved by any partner
W3 Catalogue9 participants, 2 sessions What does good look like, for each decision? Affinity clustering · benchmark families · fitness-for-decision test 187 catalogued elements with grain, rights and benchmark A benchmark per data family rather than one universal completeness target
W4 Machine work10 participants, 3 hours Where should software do the work? Staged function allocation · Crazy 8s · impact–risk plot 34 candidate capabilities reduced to 11, with the filter recorded The eight capabilities declined, and why
W5 Human line7 participants, 2.5 hours What must remain human, and what could go wrong? Pre-mortem · decision-rights grid · failure-mode walkthrough Checkpoint grid and degraded-mode behaviour per capability That recognition of safety-relevant content moves off partners
W6 Product9 participants, 3 hours What finished thing expresses all of this? Design Studio · storyboarding · concept critique Two products on one spine, with the confidence card as the shared object Not to build a platform

W1 is the session that mattered and it nearly failed. The account is in the next section.

17

Workshop design

How the sessions were built

Six sessions across five weeks. The sequence matters more than any individual exercise: each one produced the input the next one needed, which also meant a failure early would have stopped everything after it. The first session nearly did.

Why six, and why in this order

Decisions first, because nothing downstream can be prioritised without them. The catalogue would otherwise be a field list, the allocation work would have no consequence attached, and the product would be designed against assumptions.

Journey second, before the catalogue. Designing the journey around available data reproduces the blind spots — you end up with a model of the service that matches the feeds rather than the care. So the journey was drawn from how the service actually runs, and data was attached afterwards. The two stages nobody could attach data to became a finding.

Catalogue third, because it needs both. Allocation fourth, because you cannot decide what a machine should do until you know which activities exist. The human line fifth, deliberately after allocation so the room was arguing about specific capabilities rather than about AI in general. Product last.

The sequence, with the room and the reasoning
Session In the room Deliberately not in the room Exercises, in order Ends on
W1 Decisions
11 people, 3 hours
Decision owners from Commercial, Medical, Market Access, Patient Safety, Supply Data and analytics. Their presence turns a decision conversation into a feasibility conversation within ten minutes. Silent write · decision card completion · forced ranking by cost of being wrong · kill list The nine decisions the rest of the work would serve
W2 Journey
8 people, 3 hours
Medical, Digital, patient services, two people who take patient calls Commercial. The journey gets drawn around the funnel if they are present. Individual journey sketch · merge and argue · touchpoint marking · dark-stage identification A 14-stage journey, with two stages nobody could evidence
W3 Catalogue
9 people, 2 sessions of 2.5 hours
Data, Medical, Market Access, Privacy Nobody excluded. This is the session that needs everyone who owns a field. Affinity clustering from W2 touchpoints · benchmark families · fitness-for-decision test against W1 output A benchmark per data family rather than one universal completeness target
W4 Allocation
10 people, 3 hours
Cross-functional, including two people who do the reconciliation by hand Vendors. Obvious, and it had been proposed. Activity inventory · four-stage scoring · Crazy 8s on the top six · impact-risk plot 34 candidates reduced to 11, with the filter recorded
W5 The human line
7 people, 2.5 hours
Compliance, Privacy, Patient Safety, the analyst Anyone who had championed a capability in W4. Authors defend. Pre-mortem · failure-mode walkthrough per capability · decision-rights grid Recognition of safety-relevant content moves off partners
W6 Product
9 people, 3 hours
Mixed, including two from W1 who had not attended since Design studio · storyboard the analyst’s week · concept critique · kill one idea Not to build a platform

W1, and the hour it took to work

The session was designed around a decision card — a fixed sentence with slots. It did not work for the first hour. Asked what decisions they make with partner data, the room produced activities: monitor partner performance, improve adherence, understand the patient journey. Each has an owner and a slide and none of them is a decision, because nothing happens differently depending on the answer.

I dropped the word decision and asked for the shape instead: who chooses, between what options, by when, and what goes wrong if they choose badly. Twenty-seven came out in ninety minutes having produced almost nothing in the first sixty.

The cost-of-being-wrong column was added mid-session for the same reason. Four items could not be given one, and on inspection none of them was a decision anybody makes.

The decision card, as used

Field A decision that survived One that did not
The decision Whether to renew a partner at contract end “Monitor partner performance”
Who chooses Business owner with Finance
Between what Renew as-is · renew with a revised specification · do not renew
By when Ninety days before expiry
Evidence used today Relationship history, partner activity report A monthly report
Evidence that would change it Persistence contribution against a defensible denominator, quality trend, cost to serve
Cost of being wrong A poor partner persists by inertia; a good one is lost for want of evidence Cannot be stated
Verdict Carried forward Removed

Why each framework, rather than which

Session Framework Chosen against a specific failure
W1 Silent write before discussion The two most senior people in the room set the frame in the first three minutes otherwise. Everyone writes first, then reads out.
W1 Forced ranking Scoring lets everything be important. Ranking makes people trade, and the argument during the trade is the useful part.
W2 Individual sketch before merge A group journey map converges on the version of the service that management believes exists. Separate sketches surface the disagreement first.
W2 Dark-stage marking Rather than asking what data exists, asking where none does. Different question, and it produced the tolerability and stop-reason finding.
W3 Affinity clustering The room kept collapsing into two camps — clinical and commercial. Clustering on the artefacts rather than by discussion broke that.
W4 Four-stage scoring A single automate-or-not question produces binary answers to non-binary problems. Scoring the four stages separately is what surfaced the acquisition-and-analysis pattern.
W4 Crazy 8s Deliberately too fast to be careful. The point is volume, and the filtering happens afterwards with the criteria visible.
W5 Pre-mortem Asked directly, nobody will say what they think will fail. Asked to explain a failure that has already happened, everybody will.
W5 Authors excluded A capability defended by the person who proposed it does not get tested.
W6 Kill one idea A design session with no forced removal produces a superset. Requiring one death makes the room state its criteria.

What the sessions produced, including what did not survive

34 candidates to 11, with the filter recorded
Filter applied Removed Examples
Needs linkage the estate does not have 7 Cross-partner journey analytics, unified patient view, cohort matching across partners
Redesign solves it better 5 Automated reconciliation across three denominators; automated assembly of charts nobody reads
The determination should not be automated 4 Safety classification, renewal recommendation, rights determination, fitness verdict
No data to support it 3 Predictive persistence scoring, partner performance prediction, churn propensity
Duplicate of another candidate 4 Three separate proposals that were all field mapping
Carried forward 11

The pre-mortem, and what it changed

Failure the room imagined How likely they thought it was What changed as a result
Everything gets blocked and people build a shadow spreadsheet Very likely A named, logged override on every block. The override became a feature rather than a leak.
The green light stops people looking Likely The confidence card states what a figure cannot tell you even when every check passes.
Partners refuse the specification Likely for two of fourteen Specification issued at contracting rather than retrofitted. Existing partners get it at renewal.
The catalogue is maintained for six months and then rots Very likely A custodian role, and the catalogue became the only route to a specification.
Confirmation load makes the analyst’s job worse Possible Measured deliberately. Confirmation on every mapping was kept anyway, for calibration.
Safety volume overwhelms reviewers once recognition moves Likely The surfacing capability was built to absorb it, with an exhaustive queue and a random tail sample.
18

The partner population

Frozen — P01 to P08

Eight archetypes, fixed once and used in every table, dossier, benchmark and diagram in this document. No ninth appears halfway through.

Canonical archetypes
ID Archetype What they do Primary data value In this estate
P01 Telehealth / digital clinic Remote consultation, eligibility assessment, prescribing, follow-up Consultation, initiation, prescribing, persistence 2 partners, both active feeds
P02 Pharmacy / e-pharmacy Dispensing, fulfilment, refill, access Prescription, dispensing, refill interval 2 partners, 1 active feed
P03 Remote monitoring / connected device Physiological measurement outside the clinic Weight, body composition, device events 1 partner, active feed
P04 Nutrition / behaviour / DTx Nutrition, behaviour change, adherence support Engagement, behaviour, PRO and PREM 2 partners, 1 active feed
P05 Care navigation / HCP discovery Helps people find appropriate professionals or services HCP, specialty, site, geography, referral 1 partner, no feed
P06 HCP workflow / clinical support Tools used by professionals for education, workflow or decision support HCP identity, organisation, usage, workflow interaction 1 partner, active feed
P07 Patient support service Onboarding, reminders, contact centre, persistence support Contacts, questions, support interactions, safety-relevant content 1 partner, active feed
P08 Evidence / data / RWE partner Aggregation, analytics, outcomes, evidence generation Cohort outcomes, longitudinal evidence, utilisation 1 partner, periodic outputs

AI is not an archetype. It is a capability that appears inside several of these and inside the affiliate’s own product; giving it a row would place the same partner in two categories and break every downstream count. Connected devices sit in P03 and nowhere else, for the same reason.

Where public precedent for an archetype exists only in another jurisdiction — direct-to-consumer telehealth arrangements are largely a US pattern — it is used as an illustration of the archetype and marked as such. It is not treated as UK evidence, and the regulatory frame throughout is UK.
19

Who is in the system

Flows, not an org chart

Twelve groups touch a partner data flow. Two experience it as one thing — the patient at one end, the analyst at the other. Everyone in between sees a slice and assumes it is the whole.

Stakeholder analysis
Group What they need Systems touched Where it breaks for them
Patient To understand who holds what about them, and where a problem goes Partner app, clinic portal, pharmacy site Consent language differs per partner. A person on three partner services has agreed to three different things and can describe none of them.
Health professional A current picture at the point of contact Clinical system, partner portal Partner-generated data does not reach the clinical record. The professional is the one person who could act on it in the moment and is the one person who cannot see it.
Partner A clear specification and a single point of contact Own platform, SFTP or API endpoint Receives requirements from four functions at different times. Two partners had never been told what the affiliate uses the data for.
Data engineering A stable schema and a reason to trust the source Warehouse, ingestion scripts, reconciliation sheets Absorbs every upstream change silently. Schema drift is discovered when a report looks wrong, not when it happens.
Analyst A denominator and a definition that holds still Warehouse, spreadsheets, partner PDFs Rebuilds the same reconciliation monthly. This is where the hidden work concentrates and it is invisible in every management view.
Commercial To know which relationships to continue Partner reports, steering decks Partner-reported metrics, partner-defined, not comparable. Renewal runs on relationship history because nothing better exists.
Medical Evidence that would survive scrutiny Evidence repository, partner outputs Most receivable data was collected for service operation rather than evidence, and cannot be retrofitted into it.
Market access Outcomes and utilisation for payer conversations Evidence packs, RWE outputs Needs cohort-level outcomes with a defensible denominator. Receives engagement metrics.
Privacy A settled controller position before data moves DPIA register, agreement set Consulted when a flow is proposed rather than when a partnership is agreed. By then the commercial expectation is fixed.
Patient safety Every potentially reportable item, within the clock Safety database, partner escalation mailboxes Depends on partners recognising safety-relevant content. Recognition is a trained judgement placed with untrained parties.
Digital To run and extend the partner estate Partner platforms, integration layer Holds the technical relationship and no authority over what is specified.
Procurement / Legal Contract, standing, payment Contract repository Their trigger — the purchase order — became the de facto definition of a partner, which is how two funded arrangements never entered the register.
20

The journey, and where each partner can see it

Coverage

Fourteen stages, designed in W2 from the affiliate’s own service reality rather than borrowed from a template. Data was attached afterwards, deliberately — designing the journey around available data reproduces the blind spots.

JOURNEY COVERAGE BY ARCHETYPE Discovery search, awareness Eligibility assessment, funding route Consultation clinical contact Prescription written Fulfilment dispensed, shipped Onboarding first dose Titration dose escalation Tolerability GI symptoms, burden Monitoring weight, measurement Behaviour nutrition, coaching HCP review follow-up, escalation Safety AE, signal Persistence still on treatment Stop + reason discontinuation P01 Telehealth / digital clinic ~ ~ ~ ~ ~ P02 Pharmacy / e-pharmacy ~ ~ P03 Remote monitoring / device ~ ~ ~ P04 Nutrition / behaviour / DTx ~ ~ ~ ~ ~ P05 Care navigation / HCP discovery ~ ~ P06 HCP workflow / clinical support ~ ~ ~ ~ ~ P07 Patient support service ~ ~ ~ ~ P08 Evidence / RWE partner agg agg agg agg agg agg agg agg agg agg agg agg agg agg The two ringed columns carry the highest-value evidence in this therapy area and the estate barely captures either. Tolerability is seen by three archetypes, two of them partially. Stop-reason is seen by one — P07 — because it is the only place a person asks. Four stages are covered by more than one partner; two by none. This is the argument against rationalising the estate on cost: the scarcest evidence sits with the least data-rich partner in it.
scroll to pan →
Full — event-level, reliablePartial — proxy or incompleteAggregate onlyNo dataDark column
Read the columns, not the rows — the row pattern shows what each partner is for. The column pattern shows what the estate can answer, and it is the column pattern that reorders the portfolio.

Stage by stage

The fourteen stages, what is generated, and who holds it
Stage What happens Data created Held by Reaches the affiliate?
1 · Discovery Person searches, encounters content, forms an intention Search terms, content engagement, referral source P01, P04, P05 Aggregate only, and channel taxonomies differ per partner
2 · Eligibility Assessment against criteria; funding route determined BMI, comorbidity, prior attempts, route (NHS / private / self-pay) P01, P06 Partially. Funding route is absent from every feed, and it conditions everything downstream.
3 · Consultation Clinical contact, remote or in person Consultation event, outcome, prescriber P01, P06 Event only. No clinical content, correctly.
4 · Prescription Prescription written Prescription event, product, dose, prescriber P01, P02, P06 Yes, from two archetypes, with conflicting timestamps
5 · Fulfilment Dispensed and delivered Dispense event, quantity, delivery, failed fulfilment P02 Yes. The most reliable event in the estate.
6 · Onboarding First dose, device set-up, service enrolment Enrolment, first-dose confirmation, app activation P01, P04, P07 Yes, but three different definitions of “started”
7 · Titration Dose escalation over weeks Dose stage, escalation date, holds and reductions P01, P02 (inferred), P06 Partially. Holds and reductions are rarely captured, and they are the early signal.
8 · Tolerability GI symptoms, burden, coping Symptom reports, severity, self-management P04 partial, P07 Sparse Mostly unstructured, in call notes and free text
9 · Monitoring Weight and measurement between contacts Weight, body composition, measurement method P03 Yes, high frequency, subject to informative attrition
10 · Behaviour Nutrition, coaching, habit support Engagement events, logs, programme progress P04 Yes, from an engaged population by definition
11 · HCP review Follow-up, escalation, dose decision Review event, decision, referral P01, P05, P06 Partially, and not linked to the monitoring data that should inform it
12 · Safety Potentially reportable content arises Reports, escalations, case references P01, P04, P07 Yes, at varying cadence set by whoever configured each surface
13 · Persistence Still on treatment, or not Refill interval, continued engagement, contact P01, P02, P07 Yes, by three incompatible proxies
14 · Stop + reason Treatment ends Stop event, reason, restart P07 only Dark One partner, unstructured, no reason taxonomy

The finding the matrix produces. The instinct in the room was to prize the data-rich partners — P03 sends a measurement every few days, P04 sends thousands of engagement events a week. Neither can tell you why anyone stopped. P07 sends a few hundred call records a month, unstructured, from the smallest contract in the estate, and it is the only place in the system where a human being asks the question that the entire persistence problem turns on.

21

Current state

One data point, end to end

Following a single weight reading from a connected scale to the number on a steering slide takes seven stages and crosses nine break-points. Six of the nine are specification failures rather than technical ones.

CURRENT STATE — ONE PARTNER DATA POINT, END TO END Generate P03 scale reading, P02 dispense, P07 call Capture partner platform writes its own record Transform partner aggregates to its own definition Transmit SFTP drop, API pull, PDF attachment Land warehouse staging, no contract check Reconcile analyst joins by hand against 3 definitions Publish monthly deck, number without provenance PATIENT / HCP PARTNER FRONTSTAGE PARTNER BACKSTAGE TRANSPORT AFFILIATE SYSTEMS HUMAN WORK GOVERNANCE measurement or interaction app / clinic / call partner record created partner schema, partner IDs aggregation to partner definition SFTP · API · PDF (3 routes, 14 feeds) staging tables per feed warehouse, no canonical key manual join, manual QC deck assembled by hand no published lineage rights read from PDF at point of use no confidence record attached B1 B2 B3 B4 B5 B6 B7 B8 B9 B1 partner defines the metric B2 grain lost at aggregation B3 silent schema drift B4 no contract check on landing B5 no cross-partner key B6 reconciliation invisible B7 rights read under pressure B8 lineage stops at the warehouse B9 no confidence record Nine break-points. Six are specification failures, two are governance, one is human workload.
scroll to pan →
Patient and HCPPartnerTransportAffiliate systemsHuman workGovernance
Where the lane matters — the human work lane exists in no process document and absorbs every failure in the four lanes above it. It is one analyst, and the estate scales by adding partners to the top of the diagram.

Challenge, consequence, opportunity

Each break-point traced through
# Challenge Operational consequence Human consequence Data consequence Where design intervenes
B1 Partner defines the metric because no specification was issued Seven definitions of an active patient Analyst reverse-engineers each definition from sample data No comparable denominator anywhere Specification issued by the affiliate at contracting; definitions versioned in the catalogue
B2 Partner aggregates before sending Grain arrives below what the decision needs Analyst requests re-cuts; partner obliges inconsistently Subject-level questions unanswerable from a subject-level source Contracted grain stated on three axes and tested on receipt
B3 Schema changes without notice Reports break, or worse, silently shift Discovered when a number looks wrong, usually two cycles later Trend discontinuities indistinguishable from real change Conformance gateway holds the expected schema; drift is an event, not a discovery
B4 No contract check at landing Data lands whether or not the agreement permits its use Privacy consulted after the fact Purpose creep with no audit trail Rights position as structured values, checked before publication
B5 No key to join across partners Each partner is analysed alone Cross-journey questions get abandoned quietly No longitudinal view of a person Linkage ladder makes the constraint explicit and contractual
B6 Reconciliation is unlogged manual labour Two to three days a month, every month One person holds knowledge nobody else has Method changes when the person does Automated mapping and conformance; the analyst confirms rather than assembles
B7 Rights read from a PDF at point of use Analysis waits on a legal read Analysts shape questions to what clears quickly The question asked is the easy one, not the right one Structured rights position queried before the analysis is commissioned
B8 Lineage stops at the warehouse A published figure cannot be traced to its source events Nobody can defend a number under challenge Provenance lost at exactly the point it is needed Lineage carried through to publication
B9 The number arrives bare Decision-makers read a figure without its limits False confidence, and the wrong reading of persistence Denominator and observability window invisible Decision confidence card, attached at publication

Official process against actual process

Documented Actual What the gap tells us
Partner data is ingested to the warehouse via the standard pipeline Three of fourteen feeds arrive as email attachments and are loaded by hand The pipeline exists and was designed for a different class of source. Partner feeds were never in scope and nobody said so.
Data quality is monitored by the platform team Quality is discovered by the analyst preparing the monthly pack Monitoring watches infrastructure, not meaning. A feed can be up, on time and wrong.
Rights are governed by the data processing agreement Rights are established by a Teams message to Privacy when a question arises The agreement is real and unqueryable, so the operating control became an interruption.
Partner performance is reviewed quarterly Two partners have not been reviewed since onboarding Review requires a comparable measure. There isn’t one, so the meeting is about the relationship.
Safety-relevant content is escalated by the partner within the agreed period One partner escalates weekly in a batch; one escalates when the account manager notices “Within the agreed period” was never operationalised into a surface-level cadence.
Definitions are held in the data dictionary The data dictionary covers internal sources only Partner fields were treated as external and therefore nobody’s to define.
None of these gaps is a compliance failure and none was hidden. Each is a reasonable local response to a missing specification, which is why more rigour at each desk would not have fixed any of them.
22

Decision to evidence

The thesis, as a matrix

Twenty-seven decisions came out of W1. Nine were carried forward. Each is traced back to the evidence that would move it, then to the data category, the touchpoint, the source and the grain that source can actually supply.

The evidence contract

Between a decision and any data sits an object nobody had written down. It states what evidence has to look like before it can answer that decision — the claim required, the population, the grain, the denominator, the coverage, how long people must be observable, what linkage it needs, what bias is tolerable, how recent it must be, which purposes the rights permit, and what would make the answer wrong.

Four of the twenty-seven decisions had anything resembling one. Writing the other twenty-three is what turned a field list into a catalogue: an element that appears in no contract does not enter, and a feed is judged against stated terms rather than against a general idea of quality.

THE OBJECT THAT WAS MISSING A NAME DECISION who chooses, between what, by when EVIDENCE CONTRACT the terms evidence must meet to answer that decision AVAILABLE EVIDENCE what the estate actually holds FITNESS does the evidence satisfy the terms CONFIDENCE what the figure cannot tell you HUMAN DECISION a person chooses THE ELEVEN TERMS Written once per decision, before any data is looked at. A feed satisfies a contract or it does not. Required claim What must be shown to be true Population Who the claim is about Grain Identity, time and scope needed Denominator Fixed, versioned, stated in advance Coverage What share of the population is needed Observability How long people must be visible Linkage Which rung the claim requires Acceptable bias What distortion can be tolerated Recency How old the evidence may be Rights Permitted purposes for this use Invalidating conditions What would make the answer wrong Twenty-seven decisions were inventoried and four had anything resembling a contract behind them. Writing the other twenty-three is what turned a field list into a catalogue: an element that appears in no contract does not enter, and a feed is judged against the terms rather than against a general idea of quality. The contract is written before the data is looked at. Written afterwards, it describes what you happen to have.
scroll to pan →
Order matters — the contract is written before the data is looked at. Written afterwards, it describes what you happen to have.
The nine decisions the work serves
Decision Owner Current evidence Missing evidence Data category Source Min. linkage Answerable?
Should this partner be renewed? Business owner + Finance Relationship history, partner activity report Outcome contribution, cost-to-serve, quality trend Persistence, outcomes, service ops P01 P02 P07 P08 L1 After specification
Should this partner be expanded? Digital + Commercial Prescription and engagement volumes A denominator, and evidence of incremental effect Eligibility, initiation, persistence P01 P02 L1 After specification
Does a new partner add anything? Portfolio owner The partner’s own proposal Coverage overlap against the canonical catalogue All categories Assessment instrument Yes, now
Is this feed usable for this question? Data product Manual inspection A fitness-for-decision test Quality metadata Gateway Yes, now
Can this data be used for this analysis? Privacy + analyst Contract read at point of use Structured rights position Rights metadata Agreement set Yes, now
Where is the journey under-supported? Digital + Medical Qualitative feedback, partner anecdote Cross-partner coverage and drop-off by stage Journey coverage All L2 Needs consent design
Why do people stop? Medical + Commercial Partner speculation Structured stop reason at the point of stopping Discontinuation P07, plus new capture L1 After specification
Does behaviour support change persistence? Medical Engagement volumes Persistence outcome linked to exposure, controlled for selection Behaviour, persistence P04 + P02 L2 Needs consent design
Is safety-relevant content being detected? Patient safety Partner escalation counts Consistent classification, timeliness, an audit trail Safety P01 P04 P07 After specification
What happened to the other eighteen
Outcome Count Examples Why
Answerable from data already held 6 Fulfilment failure rate, refill interval distribution, contact volume by reason Blocked only by definition disagreement, not by data. Fixed by fixing definitions.
Reassigned to primary research 3 Why people choose a private route; what the professional wants at review; where the service feels burdensome Attitudinal questions that no operational feed will ever answer. Attempting them from partner data was the mistake being made.
Removed — not a decision 4 “Monitor partner performance”, “improve adherence” No owner, no moment of choosing, no cost of being wrong. Activities dressed as decisions.
Deferred 1 Whether to build direct-to-patient capability Depends on a strategic choice outside the scope of the work.
The removed four are worth dwelling on. Each had a slide, a metric and an owner. None had a moment at which someone chooses between options with different consequences, which is what a decision is. Three of the eleven partner reports existed to serve them.
23

Receivable grain, and the linkage ceiling

The constraint model

Receivable grain is the finest level the affiliate is entitled and able to receive from a given partner. It is a property of the relationship, not of the healthcare system — the same data element has a different receivable grain from each of two partners who both hold it.

GRAIN IS THREE INDEPENDENT AXES, NOT ONE VALUE A feed takes one position on each. Decision fitness is a region in this space. Two feeds can both be “pseudonymous” and only one of them answer the question. IDENTITY RESOLUTION identifiable stable pseudonym rotating token anonymous event aggregate only finest TEMPORAL STRUCTURE longitudinal subject repeated cross-section single snapshot period aggregate point estimate finest POPULATION SCOPE full eligible cohort full partner cohort sampled self-selected unknown denominator finest P02 dispensing P03 device P08 RWE output P07 support calls P03 is the finest feed on identity and the worst on population scope. It is the one most often described internally as the best data in the estate.
scroll to pan →
Why three axes rather than one field — the eight grain values in common use collapse three independent dimensions. P08 is aggregate on identity and longitudinal on time; P07 is stable-pseudonymous and self-selected. A single grain field cannot express either, and the catalogue would silently misdescribe both.
Grain, per feed, on all three axes
Feed Identity Temporal Population Fitness consequence
P01 telehealth rotating token, resets on re-registration longitudinal within an episode self-selected, private route only Cannot follow a person across two episodes. Persistence is per-episode, not per-person.
P02 dispensing stable pseudonym, scheme unversioned longitudinal subject full partner cohort The strongest feed in the estate. Refill interval is the most reliable persistence proxy available.
P03 device stable pseudonym longitudinal subject self-selected and self-attriting Finest identity grain, worst population scope. The feed most often called the best data in the estate.
P04 behaviour stable pseudonym longitudinal subject engaged subset of an engaged population Engagement measured on the engaged. Cannot support any claim about effect without a comparison group.
P06 HCP workflow professional identifier, verifiable repeated cross-section full user base Usable for HCP-side questions. Not joinable to any patient-side feed, correctly.
P07 support stable pseudonym event-level longitudinal people who contacted, i.e. people with a problem Strong selection toward difficulty, which is exactly what makes it the only source of stop reasons.
P08 RWE aggregate only repeated cross-section defined cohort, denominator stated Only feed with a stated denominator. Cannot be decomposed or joined.
THE LINKAGE LADDER Which decisions are answerable at all depends on this. It is fixed at contracting, not discovered at analysis. L4 Approved identifier linkage A governed arrangement permits a common identifier. GOVERNANCE Named lawful basis, DPIA, oversight, narrow purpose. UNLOCKS Full longitudinal view. Rare, slow, usually the wrong first ask. 0 today L3 Trusted third party A separate body holds the keys and performs the join. GOVERNANCE TTP agreement, approved purpose, output-only disclosure. UNLOCKS Cross-partner outcomes; affiliate never holds identifiers. 0 today L2 Patient-mediated The person consents to join their own records across services. GOVERNANCE Consent capture, withdrawal handling, a patient-held key. UNLOCKS Cross-partner journey, consenting subset only. 0 today L1 Stable within partner One subject recognisable over time inside one partner. GOVERNANCE Contractual stability clause + scheme versioning. UNLOCKS Persistence and trajectory for that partner's population. 3 of 14 feeds L0 No linkage Partner-specific token, no route out. GOVERNANCE None available. UNLOCKS Cohort comparison inside one partner. 11 of 14 feeds Nine of the 27 decisions need L2 or above. None of the estate is there, and no amount of engineering moves a feed up a rung.
scroll to pan →
How the ladder is used — every decision carries a minimum rung; every partner carries a current rung. The gap between them is the partnership design agenda, and it is a contractual and consent conversation rather than an integration one.

The ceiling. Eleven of fourteen feeds sit at L0. Nine of the twenty-seven decisions need L2 or above. No amount of engineering moves a feed up a rung — L2 requires a consent mechanism that does not exist, L3 requires a third party nobody has appointed, and L4 requires a governance arrangement that would take longer than the partnerships themselves. Naming this early stopped the affiliate commissioning a cross-partner analytics build that could not have worked.

The censoring problem, stated properly

INFORMATIVE CENSORING — WHY P03 CANNOT ANSWER A PERSISTENCE QUESTION baseline loss weeks on treatment still weighing themselves stopped weighing themselves · reason unrecorded What the feed shows Mean weight change improves month on month. What is happening People doing badly stop measuring. The sample cleans itself. Why it is not ordinary missingness The probability a value is missing depends on the value. What the catalogue must carry Observability window, attrition reason, denominator fixed at enrolment. What resolves it P02 refill gaps and P07 contact reasons supply the exit P03 cannot see. The general rule: wherever the act of generating data is itself the behaviour under study, absence is evidence and must be modelled rather than dropped. Applies to P03 and P04 directly, and to any engagement-derived persistence measure.
scroll to pan →
Why it survived undetected — the resulting number improves over time, which is the direction everyone expects, and it passes every ordinary quality test. Completeness is high among the records present. Validity is fine. Timeliness is fine. The failure is in who is present, and no dimension in a standard quality framework asks that.

The fix is not statistical in the first instance. It is a catalogue change: observability window, attrition reason and a denominator fixed at enrolment become required fields for any feed used in a longitudinal claim. Where attrition reason is genuinely unavailable, the feed carries a flag that prevents it being used alone for persistence, and the gateway enforces that rather than warning about it.

Where a resolution exists it comes from combining feeds — P02 refill gaps and P07 contact reasons both observe exits that P03 cannot see — which is a linkage question, which is L2, which is the ceiling. The honest position is that the affiliate can currently detect the bias and cannot correct it, and reporting that is better than reporting a corrected number nobody can defend.

24

Layer 1 — Ecosystem master

Reference, not receivable

What exists in the healthcare system of record. The affiliate consumes codes, vocabularies and status from this layer and holds almost none of it at person level. Splitting authority from receivability is what makes that visible.

Layer 1 — 18 elements. Authority and receivability are separate columns.
Element Authoritative source Receivable by the affiliate Why it is in the catalogue at all Benchmark / control
PATIENT REFERENCE
NHS number PDS — national demographic record; the identifier used to match a person to their health record Not receivable Partner may hold it under its own clinical relationship Defines what a partner token is a substitute for, and why token stability matters Syntactic validity at source; the affiliate never validates because it never receives
Name, date of birth, sex PDS · GP record · partner registration Not receivable Age band only, derived by the partner Age band is the only demographic in any feed. Everything else is a modelling assumption. Age band completeness ≥98% where eligibility is asserted operating target
Address, postcode PDS · partner registration Partial Outward code only, from 2 of 7 feeds Geography for coverage analysis. Outward code is the finest grain the DPIA supported. Valid outward code where present; no full postcode accepted
Registered GP practice PDS · ODS · GP record Not receivable Marks the boundary of the affiliate’s visibility. Continuity of care sits outside the estate entirely. n/a
Ethnicity Clinical record where lawfully collected Not receivable Aggregate only, and only for an approved research purpose Named so that its absence is a stated position rather than an oversight Not collected. Equity analysis runs on published population data, not partner feeds.
HCP REFERENCE
Professional identifier GMC · NMC · HCPC · GPhC registers Receivable From P05 and P06 The only person-level identity in the estate that is verifiable against a public source 100% for onboarded professionals; verified at onboarding and re-checked weekly, operating target
Registration status Regulator register Receivable Derived at check time Whether the professional can practise. Stale status is a live risk in a locator service. Status current within 7 days of use operating target
Profession, role, specialty Regulator register · ODS · employer Receivable Controlled vocabulary Routing and appropriateness. Specialty drives what P05 can safely surface. 100% classified to controlled vocabulary; free text rejected at ingestion
Prescribing eligibility Regulator status + service configuration Partial Asserted by the partner, not verified Whether an individual can act in a given service. The affiliate cannot verify it and says so. Source and assertion date required; no inference from profession alone
ORGANISATION AND SITE
Organisation code ODS Receivable Stable join key across the NHS ecosystem, and the only truly reliable key in the whole model 100% for in-scope organisations; refreshed against ODS on publication cycle
Site, address, geography ODS Receivable Care navigation and coverage. Where care is actually delivered, as opposed to where the organisation is registered. Current, valid; ODS code preferred over free-text address
Organisation role and relationships ODS role vocabulary Receivable Parent, child, commissioning relationships. Prevents routing to the wrong entity. Controlled vocabulary; effective dates and history retained
Open / closed / successor status ODS Receivable Prevents referral into an entity that has closed. A live failure mode in directory services. Checked on every refresh; closed entities suppressed rather than deleted
Practitioner-to-organisation relationship ODS practitioner data Receivable A professional can hold several roles across several organisations, with different active status. Modelling one place of work is wrong. Effective dates required; relationship history retained
CLINICAL REFERENCE
Eligibility criteria NICE guidance Reference Defines what “eligible” means before any partner asserts it Guidance version and date recorded; criteria re-checked on guidance change
Measurement expectations NICE guidance Reference Distinguishes a clinical recommendation from a data-engineering threshold. Annual clinical measurement is not an annual completeness target. Clinical interval cited; engineering threshold stated separately and labelled
Terminology and coding Recognised clinical terminologies Reference Whether a partner’s coded content is interpretable without bespoke documentation Coded content required; 2 of 7 feeds currently comply
Resource shapes and identifiers HL7 FHIR UK Core Reference Target shape for new feeds. Existing feeds are mapped to it rather than replaced. New feeds conform; existing feeds carry a mapping with a stated loss profile
Reading the third column down is the point of the table. Almost the entire patient reference layer is not receivable, and the HCP and organisation layers largely are. That asymmetry shaped the product: the strongest identity spine available to this affiliate is professional and organisational, not patient, and P05 and P06 are the archetypes that benefit.
25

Layer 2 — Partner-receivable

The working material

What each archetype can lawfully transmit under the relationship as it stands. One hundred and ten elements across twelve domains; forty-one are received today, and eleven of those are received in a form that cannot serve the decision they were acquired for.

Layer 2 — 55 of 110 elements shown; the full set follows the same structure. State reflects the estate at the start of the work.
Element Grain (identity / temporal / population) Archetypes Decision served Rights position Benchmark State
CLINICAL CONTEXT · THE DOMAIN THAT WAS MISSING
Comorbidity at assessment pseudonym / snapshot / assessed P01 P06 The eligibility gate; comparability of every cohort Service operation Coded, not free text Absent
Comorbidity count derived derived A plausible persistence predictor, untested here Derived Definition versioned Not derived
Type 2 diabetes status pseudonym / snapshot / assessed P01 P06 Changes indication, route, monitoring and persistence pattern Service operation Required on every initiation Absent
Cardiovascular risk status pseudonym / snapshot P01 P06 Increasingly central to the evidence conversation Service operation Coded where assessed Absent
Concomitant medication class pseudonym / longitudinal P01 P02 P06 Titration constraint and comorbidity proxy Service operation Class level, not product Absent
Contraindication flag pseudonym / snapshot P01 P06 Safety-relevant and route-determining Service operation Present on all assessed Absent
Baseline HbA1c where diabetic pseudonym / snapshot P01 P06 Baseline for the outcome that matters in that subgroup Service operation Where clinically taken Absent
Prior GLP-1 exposure pseudonym / snapshot P01 P02 A restart is a different clinical situation from a first course Service operation Required at assessment Absent
Bariatric surgery history pseudonym / snapshot P01 Changes expected trajectory entirely Service operation Required at assessment Absent
Other weight-management agents pseudonym / longitudinal P01 Confounds every response curve Service operation Class level Absent
PAYER AND ROUTE · THREE FIELDS, NOT ONE
Payer type pseudonym / snapshot P01 P02 Probably the strongest single persistence predictor available Service operation Controlled list of 9 archetypes Absent
Coverage status market-level, dated reference Whether that payer funds this indication, at a stated date Reference Versioned per market, effective-dated Not held
Funding route pseudonym / snapshot P01 P06 The scheme under which supply is authorised Service operation Controlled list of 7 Absent
Supply route pseudonym / event P01 P02 Where the medicine is physically obtained. Nine routes, six observed. Service operation Includes a value for outside the legitimate chain Absent
Demographics pseudonym / snapshot P01 P02 Sex and age band. With outward code, a quasi-identifier set. Service operation Band only; suppression below minimum cohort Two feeds only
ELIGIBILITY AND ACCESS
Eligibility assessment outcome pseudonym / event / partner cohort P01 P06 Who is in scope; where access friction sits Service operation. Secondary use requires a purpose extension. Definition versioned; ≥95% populated where a consultation follows target Received
Funding route pseudonym / snapshot / partner cohort P01 P02 Every cross-partner comparison; persistence economics Service operation Present on 100% of initiation events target Absent from all feeds
Referral source / channel pseudonym / event / partner cohort P01 P04 P05 Where access friction sits Service operation Controlled channel taxonomy issued by the affiliate Received, 4 taxonomies
Prior weight-management attempt pseudonym / snapshot / partner cohort P01 Cohort comparability Service operation Self-reported; provenance flag required Not received
Wait time to first consultation pseudonym / event / partner cohort P01 Where access friction sits Service operation Derived from two timestamps; both required Derivable, not derived
TREATMENT PATH
Consultation event token / event / self-selected P01 P06 Whether care happened; sequencing Service operation. No clinical content received, by design. Timestamp to the minute; outcome coded Received
Prescription event pseudonym / event / partner cohort P01 P02 P06 Initiation; drop-off between prescription and dispense Service operation Event ordering guaranteed; conflicting timestamps reconciled at source Received, timestamps conflict
Dispense / fulfilment event stable pseudonym / longitudinal / full cohort P02 Access friction; the persistence backbone Service operation + agreed evidence use Same-day or next-business-day receipt; 100% event capture Received — strongest feed
Failed fulfilment stable pseudonym / event / full cohort P02 Whether a gap is a stop or a supply problem Service operation Reason coded to a controlled list Not distinguished from absence
Supply interruption n/a — market-level P02 P08 Whether a cohort-wide gap is behavioural or structural n/a Recorded as a period marker against the cohort Not captured
Titration stage and date pseudonym / longitudinal / partner cohort P01 P06 Where support needs change Service operation Every change event captured with an effective date Partial — escalations only
Dose hold or reduction pseudonym / event / partner cohort P01 P06 The earliest tolerability signal available Service operation Reason coded; distinguished from a missed dose Not captured
MEASUREMENT
Weight stable pseudonym / longitudinal / self-selected P03 Response; monitoring sustainability Service operation + agreed evidence use Measurement method required on every value Received
Measurement method stable pseudonym / event / self-selected P03 Whether a value is comparable to another value Service operation Controlled list: clinic, connected device, self-reported, estimated Not captured — all values treated alike
Body composition stable pseudonym / longitudinal / self-selected P03 Quality of loss, not just quantity Service operation Device model and firmware recorded; calibration state where available Received
Weight trajectory phase derived P03 + P02 The decision-relevant variable. Cross-sectional weight is nearly useless. Derived — inherits the strictest input Definition versioned: loss, plateau, maintenance, regain Not derived
Measurement recency derived P03 Whether a monitoring claim is current Derived ≤48h for monitoring use target Derivable
EXPERIENCE AND TOLERABILITY
GI symptom report pseudonym / event / engaged subset P04 P07 Why people struggle; the dominant stop predictor Service operation. Safety-relevant content routes separately. Structured severity; distinguished from a reportable event at intake Unstructured free text
Symptom burden / coping pseudonym / event / engaged subset P07 Where support should be directed Service operation Coded to a support taxonomy In call notes only
Patient-reported outcome pseudonym / repeated cross-section / consenting subset P04 P08 Patient-valued outcome evidence Evidence generation, where consented Validated instrument; ≥70% completion at defined checkpoints derived from proxy P08 only, aggregate
Service experience / PREM pseudonym / event / respondents P01 P04 P07 Journey friction Service improvement Collected after a defined interaction; response rate stated with every result Partial
ENGAGEMENT AND SUPPORT
Behaviour programme engagement stable pseudonym / longitudinal / engaged subset P04 Whether support influences persistence Service operation “Meaningful engagement” defined once, by the affiliate, and versioned Received, partner-defined
Support contact event stable pseudonym / event / people with a problem P07 Where digital care needs a person Service operation Reason coded to a controlled list Received, reason free text
Contact reason stable pseudonym / event / people with a problem P07 What is actually going wrong, in the patient’s words Service operation Controlled taxonomy with a free-text tail Free text only
PERSISTENCE AND EXIT
Refill interval stable pseudonym / longitudinal / full cohort P02 The most defensible persistence proxy in the estate Service operation + agreed evidence use Gap threshold defined per product; denominator fixed at enrolment Received
Stop event pseudonym / event / varies P02 P07 Persistence, and everything downstream of it Service operation Distinguished from an observation gap Inferred from absence
Stop reason pseudonym / event / people who contacted P07 Why anyone stops. The scarcest evidence in the estate. Service operation. Evidence use requires extension. Controlled taxonomy: tolerability, cost, plateau, goal reached, supply, switched, other Free text, one partner
Restart event pseudonym / event / varies P02 Whether a stop was permanent Service operation Linked to the prior episode where the identifier permits Not captured
Observability window derived per feed all Whether any longitudinal claim is safe Metadata Stated per feed; attrition reason required where known Not modelled
SAFETY
Potentially reportable content pseudonym / event / all surfaces P01 P04 P07 Whether detection is working Safety — separate lawful basis and route All items reviewed under the applicable timeframe; recognition affiliate-side Partner-side recognition
Screening event per surface surface-level P01 P04 P07 Whether a surface is actually being watched Safety Cadence set by surface volume, not by whoever configured it Cadence varies, no rationale
HCP-SIDE
Professional identity and organisation verified identifier / snapshot / full user base P05 P06 Network coverage; appropriateness of routing Service operation Verified against the register; ODS code for organisation Received
Initiation behaviour identifier / longitudinal / full user base P06 Clinical inertia; where education lands Service operation. Aggregate for any external use. Denominator = eligible patients seen, not consultations Not captured
Titration escalation behaviour identifier / longitudinal / full user base P06 Whether under-dosing is a real pattern here Service operation Escalation events per patient-course Not captured
Content and tool usage identifier / event / full user base P06 Adoption and unmet need Service operation Event-level with source metadata Received
GOVERNANCE METADATA
Subject identifier scheme feed-level all Whether anything is joinable, and for how long Metadata Scheme documented and versioned; change is a notifiable event Undocumented in 5 of 7
Denominator definition feed-level all Every rate in the document Metadata Definition, version, and the date it last changed Absent everywhere
Rights position feed-level, 7 structured fields all Whether an analysis may proceed Metadata Structured values, not prose. See §16. Prose only
Source and timestamp event-level all Trust and reconciliation Metadata 100% for governed events Partial
Selection profile feed-level all Whether two feeds may be compared Metadata Stated at onboarding; reviewed on material change Not stated
Layer 2 in summary
Count Comment
Elements catalogued 110 Across ten domains and eight archetypes
Received today 41 Of which 11 are received at a grain that cannot serve the decision they were acquired for
Receivable without a contractual change 23 A specification and a re-cut. The largest tranche, and the cheapest.
Requires a contractual change 19 Chiefly stop reason, measurement method, funding route and identifier stability
Requires a linkage change (L2+) 8 Not reachable by specification. Consent design or a third party.
Not obtainable from this estate 3 Reassigned to primary research
26

Layer 3 — Decision dataset

What the affiliate builds

Derived objects, one per decision, each with a fixed denominator, a stated observability window and a version. This is the layer the affiliate owns outright, and the only layer a decision is ever made from.

The nine decision datasets
Dataset Grain Denominator, fixed at Observability Inputs Known bias Confidence ceiling
Persistence at 12 / 26 / 52 weeks subject-period first dispense event 26 weeks; 14% exit the feed before week 26 P02 refill · P01 episode · P07 contact Private route over-represented; NHS route absent from the estate L1 — per partner only. No cross-partner persistence.
Initiation funnel event-cohort eligibility assessment completed 8 weeks from assessment P01 · P02 · P06 Only assessed people appear. Eligible-but-never-assessed is invisible. Timestamps conflict between P01 and P02; ordering is reconstructed
Discontinuation reasons event stop event confirmed n/a — cross-sectional P07 only, once a taxonomy exists Only people who contacted. Silent stoppers are the majority and are absent. Cannot be generalised. Reported as a reason mix among contactors, never as a population rate.
Journey coverage stage-partner all active partners quarterly snapshot All feeds + catalogue None material Full. This one is about the estate, not about people.
Partner contribution partner-period partners with an active feed quarterly All feeds + service ops Confounded with partner population differences; not a like-for-like ranking Comparative only within archetype, never across
Monitoring sustainability subject-period device activation 52 weeks P03 Informative censoring — see §12 Detection only. The bias is visible and not correctable within this estate.
Behaviour exposure subject-period programme enrolment programme length P04 + P02 Engagement measured on the engaged. No comparison group exists. Cannot support an effect claim. Reported as association with the limitation stated.
Safety detection performance surface-period all patient-facing surfaces monthly P01 · P04 · P07 False negatives leave no record; the rate is unknowable from inside Timeliness and consistency only, never sensitivity
HCP engagement and behaviour professional-period professionals with a verified identity quarterly P05 · P06 Users of the tool, not all professionals seeing these patients Full within the tool’s user base
Every one of these carries a confidence ceiling as a stored property, not a caveat someone remembers to add. The ceiling is what the confidence card renders, and it is why the card can be populated automatically at publication rather than written by hand.
27

Benchmarks and data quality

Seven dimensions, and the one that matters

There is no universal completeness percentage. Each data family takes the benchmark that fits it, and everything carries a provenance status so a reader can tell a published standard from an operating target somebody set in a workshop.

Quality dimensions, tests and thresholds
Dimension What it asks Example test Threshold Owner Failure behaviour
Completeness Is the field populated where it should be? Fill rate by field, conditioned on the event type Per-field, set by decision requirement Data product Publish with the fill rate stated, or suppress the derived measure
Validity Does the value conform to its type and vocabulary? Type, range, controlled-list membership, impossible dates 100% for governed events Data engineering Reject the record, notify the partner, do not silently coerce
Consistency Do related values agree, within and across records? Event ordering; prescription before dispense; dose within schedule 100% on ordering; exceptions logged Data engineering Quarantine the affected subject-series, not the whole feed
Timeliness Does it arrive in time to be useful? Latency from event to receipt, by feed <24h for operational; ≤48h for monitoring operating target Data product Publish with a staleness marker rather than withhold
Uniqueness Is one thing represented once? Duplicate subject-events; duplicate professional records Duplicate rate <0.5% operating target Data product Deduplicate with a rule, log the rule version
Accuracy Does it correspond to the world? Reconciliation against an independent source where one exists Reconciles within tolerance where a source exists; stated as unverifiable where not Analyst State as unverifiable rather than assume
Fitness for the decision Can this support the decision it is being used for? Grain, denominator, observability, coverage and bias against the decision’s requirement Binary — fit or not fit, per decision Decision owner Block publication for that decision only. The feed may remain fit for others.

The seventh dimension is the one the case turns on, and it is the only one that is not a property of the data. It is a relation between the data and a named decision, which means the gateway that tests it has to hold the decision inventory rather than a schema registry. A feed passing the first six and failing the seventh is the normal case, not an edge case.

Benchmarks, with provenance
Benchmark Value Status Derivation What it protects
Professional registration currency Status verified within 7 days of use Operating target Set by the risk of surfacing a professional who cannot practise. No published numeric standard exists. A locator service directing a patient to a lapsed registration
Organisation code currency Refreshed each publication cycle against the reference source Reference practice The reference source publishes on a known cycle; the affiliate follows it. Referral into a closed entity
Clinical measurement interval Per current clinical guidance for the condition Published guidance Cited to the guidance version and date. Explicitly not converted into a completeness target. Confusing a clinical expectation with a data expectation
Monitoring recency ≤48 hours for a monitoring claim Operating target Set by the decision requirement in W3, not by any external standard A monitoring dashboard describing last month
Feed latency <24 hours, operational feeds Operating target Operational requirement agreed with the decision owners Decisions made on stale operational data
Cohort coverage for renewal ≥80% of the partner’s active population Operating target Risk-based. Below this, a renewal analysis describes a subset the partner has selected. A renewal decision made on the partner’s best cases
Identity match rate ≥98% within a feed, across a period Operating target Risk-based, set against the longitudinal claim being made Silent cohort churn read as persistence
PRO completion ≥70% at defined checkpoints Derived from proxy Taken from published completion rates in comparable programme settings; to be replaced with a measured rate Outcome claims from a highly self-selected respondent group
Safety screening cadence Set by surface volume, reviewed quarterly Regulator guidance Guidance requires screening of digital media under the company’s management or sponsorship at a defined frequency; the frequency is the affiliate’s to set defensibly. A weekly sweep on a surface with daily traffic
Six of nine are operating targets set in a workshop, and they are labelled as such throughout. An operating target is a defensible position with a stated rationale; presenting one as a standard is the failure mode this table exists to prevent.
28

Partner dossiers

Eight, one structure

Every dossier carries the same thirty-one fields. Two of them do the most work: what the affiliate can reasonably know from this partner, and what it cannot know from this partner alone.

P01  ·  Telehealth / digital clinic 2 partners · both active

Field Value
Role in the journey Discovery through consultation, prescription, review and follow-up. Owns the clinical relationship for the private route.
Primary user Patient, with a prescribing professional in the loop
Receivable grain Rotating token / longitudinal within an episode / self-selected private-route population
Identifier model Token resets on re-registration. Two episodes by the same person are two subjects.
Patient master dependency None. The partner holds identity; the affiliate receives a token.
HCP master dependency High. Prescriber identity is verifiable and is the strongest link to Layer 1.
Transmission API pull, nightly
Longitudinal capability Within an episode only. This is the single biggest limitation in the estate.
Decision contribution Initiation funnel; access friction; per-episode persistence
Safety relevance High — patient-facing free text at three points in the flow
Privacy sensitivity High — clinical context, even where only events are transmitted
Quality risks Timestamp conflicts with P02 on the same prescription; episode boundaries undocumented
Selection profile Self-selected, digitally confident, private-pay. Systematically excludes the NHS specialist route.
Denominator Consultations completed, partner-defined. Does not distinguish first from repeat.
Observability window Episode length; median 19 weeks. Exit is indistinguishable from episode end.
Reciprocal need Clinical content, patient materials, and early sight of supply position

What the affiliate can reasonably know

Whether someone reached treatment through this route, how long it took, and what happened inside one episode.

What it cannot know from this partner alone

Whether the same person came back, what happened after the episode ended, or anything about the NHS route.

P02  ·  Pharmacy / e-pharmacy 2 partners · 1 active feed

Field Value
Role in the journey Fulfilment, refill, access. The most operationally reliable point in the whole journey.
Primary user Patient; pharmacist in the loop
Receivable grain Stable pseudonym / longitudinal subject / full partner cohort
Identifier model Stable, but the scheme is unversioned and has changed once without notice
Patient master dependency None
HCP master dependency Low — prescriber identifier present but not verified
Transmission SFTP, daily
Longitudinal capability Strong. The backbone of every persistence measure in the estate.
Decision contribution Persistence; access friction; the only credible stop signal
Safety relevance Moderate — dispensing queries occasionally contain reportable content
Privacy sensitivity High — dispensing implies diagnosis
Quality risks Failed fulfilment is not distinguished from a patient-initiated gap. A supply interruption looks like a stop.
Selection profile Full cohort of this partner’s patients. The least biased feed in the estate.
Denominator Patients with at least one dispense. Clean, and the one the affiliate adopted as canonical.
Observability window Continuous while registered; churn to another pharmacy is invisible
Reciprocal need Supply forecasting, patient counselling material, device training content

What the affiliate can reasonably know

Whether treatment was collected, at what interval, and when the interval broke.

What it cannot know from this partner alone

Whether a broken interval means stopping, switching pharmacy, or a supply problem.

P03  ·  Remote monitoring / connected device 1 partner · active

Field Value
Role in the journey Measurement between clinical contacts
Primary user Patient
Receivable grain Stable pseudonym / longitudinal subject / self-selected and self-attriting
Identifier model Stable device-account pseudonym; one account may serve a household
Patient master dependency None
HCP master dependency None
Transmission API, near real-time
Longitudinal capability High frequency, subject to informative attrition — see §12
Decision contribution Monitoring sustainability. Not persistence, despite being used for it twice.
Safety relevance Low — no free text
Privacy sensitivity High — biometric time series is highly identifying in combination
Quality risks Measurement method absent; household sharing undetected; attrition correlates with outcome
Selection profile People who acquired and retained a device. The most selected population in the estate.
Denominator Devices activated. Not people, and not people on treatment.
Observability window Until the device goes quiet. Median 31 weeks, heavily right-skewed.
Reciprocal need Clinical interpretation guidance and co-branded onboarding content

What the affiliate can reasonably know

Weight trajectory, at high frequency, for people still engaged with measuring.

What it cannot know from this partner alone

Anything about the people who stopped — which is the group the persistence question is about.

P04  ·  Nutrition / behaviour / DTx 2 partners · 1 active feed

Field Value
Role in the journey Onboarding, behaviour support, adherence, tolerability coping
Primary user Patient
Receivable grain Stable pseudonym / longitudinal subject / engaged subset of an engaged population
Identifier model Stable app-account pseudonym
Patient master dependency None
HCP master dependency None
Transmission API, weekly batch
Longitudinal capability Strong within the programme; nothing after disengagement
Decision contribution Association between support exposure and persistence, with the selection limitation stated
Safety relevance High — symptom logging and free-text journalling
Privacy sensitivity High — dietary and behavioural data, and symptom content
Quality risks “Engagement” is partner-defined and has been redefined once; no restatement of history
Selection profile Doubly selected — people who downloaded, and people still using
Denominator Active users in the period, partner-defined
Observability window Until app abandonment; no exit signal
Reciprocal need Clinically reviewed nutrition content and tolerability guidance

What the affiliate can reasonably know

What supported people do, and what they report while they are being supported.

What it cannot know from this partner alone

Whether the support caused anything. There is no comparison group and no route to one.

P05  ·  Care navigation / HCP discovery 1 partner · no feed

Field Value
Role in the journey Discovery and routing to appropriate care
Primary user Patient, searching
Receivable grain Anonymous event / cross-section / all searchers
Identifier model None. Session-level only, by design.
Patient master dependency None
HCP master dependency Very high — this partner is entirely built on Layer 1 professional and organisation data
Transmission No feed today. Reporting by monthly PDF.
Longitudinal capability None, and none is appropriate
Decision contribution Network coverage; geographic access gaps; demand signal by area
Safety relevance Low
Privacy sensitivity Low — no personal data received
Quality risks Directory staleness. Closed sites and lapsed registrations are the live risk.
Selection profile People who search online. A demand signal, not a population.
Denominator Searches, not people
Observability window n/a
Reciprocal need Verified service capability data and up-to-date site information

What the affiliate can reasonably know

Where demand is, where provision is, and where the two do not meet.

What it cannot know from this partner alone

Anything about individuals, and whether a search led to care.

P06  ·  HCP workflow / clinical support 1 partner · active

Field Value
Role in the journey Professional-side education, workflow and decision support
Primary user Health professional
Receivable grain Verified professional identifier / repeated cross-section / full user base
Identifier model Regulator identifier, verifiable against a public register. The only verifiable identity in the estate.
Patient master dependency None
HCP master dependency Very high, and reciprocally useful
Transmission API, weekly
Longitudinal capability Strong for the professional; none for the patient
Decision contribution Adoption; unmet need; and, once captured, clinical inertia
Safety relevance Moderate — professional queries occasionally contain case detail
Privacy sensitivity Moderate — professional rather than patient data, still personal
Quality risks Organisation affiliation stale; a professional may hold several active roles
Selection profile Professionals who adopted the tool. Not the professionals who most need it.
Denominator Registered users. Not professionals seeing these patients.
Observability window Continuous while registered
Reciprocal need Clinical content, guideline updates, case material

What the affiliate can reasonably know

What professionals using this tool look at, and what they cannot find.

What it cannot know from this partner alone

What professionals not using this tool do, which is most of them.

P07  ·  Patient support service 1 partner · active

Field Value
Role in the journey Onboarding, titration support, tolerability coaching, persistence, exit
Primary user Patient, with a trained support agent
Receivable grain Stable pseudonym / event-level longitudinal / people who made contact
Identifier model Stable service pseudonym
Patient master dependency None
HCP master dependency Low
Transmission Monthly extract, mixed structured and free text
Longitudinal capability Contact-level, across the whole treatment course
Decision contribution The only source of stop reasons and structured tolerability in the estate
Safety relevance Very high — direct patient contact, free text, and the highest yield of reportable content
Privacy sensitivity Very high — symptom and personal circumstance detail in call notes
Quality risks Reason captured as free text; agent-to-agent variation in what gets recorded
Selection profile People who contacted, i.e. people with a problem. Strong selection toward difficulty — which is precisely why it holds the exit data.
Denominator Enrolled in the support programme
Observability window Enrolment to last contact; no closure event
Reciprocal need Clinical escalation pathways, training, and current tolerability guidance

What the affiliate can reasonably know

Why people struggle and, uniquely in this estate, why they stop.

What it cannot know from this partner alone

Anything about the people who never called, who are the majority and who stop silently.

P08  ·  Evidence / data / RWE partner 1 partner · periodic outputs

Field Value
Role in the journey Aggregation, outcomes, utilisation and evidence generation
Primary user Affiliate Medical and Market Access
Receivable grain Aggregate only / repeated cross-section / defined cohort with a stated denominator
Identifier model None received. Linkage performed by the partner under its own governance.
Patient master dependency High at source, none at the affiliate
HCP master dependency Moderate at source
Transmission Scheduled analytical output, quarterly
Longitudinal capability Yes, at cohort level. The only genuine longitudinal outcome view available.
Decision contribution Outcome evidence for access conversations
Safety relevance Low — aggregate
Privacy sensitivity Low at the affiliate; high at source
Quality risks Cannot be decomposed, verified or re-cut. The affiliate takes the output on trust.
Selection profile Defined by the partner’s own data sources; stated, which is more than any other feed manages
Denominator Stated with every output. The only feed that does this.
Observability window As specified per output
Reciprocal need Research questions, clinical input, protocol review

What the affiliate can reasonably know

Cohort-level outcomes with a denominator you can quote.

What it cannot know from this partner alone

Anything at subject level, and anything you did not specify before the analysis ran.

Reading the last pair across all eight. Each partner’s blind spot is covered by another partner. Almost none of those pairings can be made, because they need linkage at L2 and the estate sits at L0.

29

Human factors

The work system, not the interface

One analyst holds the only complete view of the estate, assembles it by hand every month, and appears in no system, no capacity plan and no management report. That is the work system this design had to change.

The analyst’s work system, examined
Property What it looks like today Design consequence
Workload Two to three days a month of assembly, concentrated in the four days before the pack is due, on top of a full analytical role Automating assembly is worth more than any model in the portfolio. It is also the least interesting part of the programme to talk about, which is why it had not been done.
Memory demand Seven identifier schemes, three denominators and eleven partner quirks held in one head and in a personal spreadsheet Externalise into the catalogue. The knowledge is not written down anywhere the organisation can reach.
Interruption profile Reconciliation is done in fragments between other work; a full pass is never uninterrupted Every step must be resumable and must leave a record of where it got to. Batch processes that must complete in one run fail here.
Search cost Locating the current definition of a partner metric means finding the last email in which it was explained A definition register with versions, reachable from the figure that uses it.
Error recovery A wrong number is discovered when someone downstream queries it, typically two cycles later Checks move upstream to arrival. Recovery becomes quarantine and re-run rather than retraction.
Accountability The analyst is accountable for a number assembled from seven sources they do not control Fitness verdicts carry a named decision owner. The analyst becomes accountable for the process, not for the partners’ data.
Situation awareness Downstream readers see a figure with no denominator, coverage or bias The confidence card. The single largest human-factors change in the design.
Degraded operation When a feed fails, the pack is produced anyway with a footnote nobody reads Explicit degraded modes with visible markers, and blocked publication where the figure cannot be defended.

The concepts that earned their place

Concept Where it applies here The design decision it produced
Ironies of automation Automating the clean 80% of mapping leaves the analyst only the ambiguous cases, cold, with no warm-up on the easy ones Confirmation is required on every mapping, not only the uncertain ones. The easy confirmations keep the analyst calibrated and cost seconds.
Automation bias A green conformance light will stop people looking. The gateway is most dangerous where it is most reassuring. The card states what the figure cannot tell you even when every check passed. Reassurance is never the terminal output.
Trust calibration Two feeds pass identical checks and one is unfit. Uniform presentation would teach uniform trust. Fitness is per decision and rendered per decision. The same feed shows fit for one question and blocked for another, on the same screen.
Situation awareness Persistence figures were being read without denominators for eighteen months, correctly and to the wrong conclusion Denominator and observability window are mandatory card fields, and a missing value renders as UNKNOWN at full weight.
Skill, rule and knowledge Mapping a field is rule-based. Judging fitness is knowledge-based. Both had been treated as clerical. The split runs straight down the allocation matrix — machines take the rule-based work, people keep the knowledge-based work.
Informative attrition P03’s missingness is a behaviour, not a gap Observability window and attrition reason became required catalogue fields, and the gateway blocks solo persistence use of P03.
30

Function allocation

Thirty-one activities, four stages each

Automation applies independently to information acquisition, information analysis, decision selection and action implementation. Scoring the four separately produces a different answer from asking whether a task should be automated.

FUNCTION ALLOCATION — FOUR STAGES SCORED SEPARATELY Degree of automation, 0 (all human) to 4 (fully automated), assessed independently per stage. Reading across a row shows the shape of the allocation, not a single verdict. INFORMATION ACQUISITION INFORMATION ANALYSIS DECISION SELECTION ACTION IMPLEMENTATION DISPOSITION Ingest and land a feed 3 3 0 0 ASSIST Validate schema and types 4 4 0 0 ASSIST Detect schema drift 4 4 0 0 ASSIST Map partner fields to canonical 3 3 1 0 ASSIST Extract rights terms from an agreement 3 3 0 0 ASSIST Confirm a rights value 0 0 1 0 AUGMENT Reconcile denominators 2 3 1 0 AUGMENT Resolve subject identity within a feed 4 4 1 0 ASSIST Resolve identity across feeds 0 0 0 0 PRESERVE Score a feed against benchmark 4 4 2 1 AUGMENT Judge fitness for a decision 2 2 1 0 AUGMENT Summarise partner evidence 3 3 0 0 ASSIST Detect anomaly in a feed 4 4 1 0 ASSIST Draft a remediation request 2 2 1 1 AUGMENT Send a remediation request 0 0 0 1 ASSIST Surface possible safety content 4 4 1 0 ASSIST Classify safety relevance 2 1 0 0 ASSIST Escalate a safety item 1 1 0 1 ASSIST Recommend renewal 3 3 1 0 ASSIST Decide renewal 0 0 0 0 PRESERVE Approve a new partner 0 0 0 0 PRESERVE Change a rights position 0 0 0 0 PRESERVE Assemble a decision confidence card 4 4 2 3 AUGMENT Publish a figure 2 2 1 2 AUGMENT Define a denominator 0 0 0 0 PRESERVE Interview a prospective partner 3 2 1 1 AUGMENT Map a partner offer to the catalogue 3 3 1 0 ASSIST Detect coverage overlap 4 4 2 0 AUGMENT Set a screening cadence 2 2 1 0 AUGMENT Investigate an attrition pattern 3 3 1 0 ASSIST Interpret a persistence figure 1 1 0 0 ASSIST The dominant pattern is high on the two left columns and low on the two right. That is the correct shape for regulated work, and it is invisible to any framework that asks only whether AI should do a task. Seven activities score zero across all four stages. None of them scores zero because a model would perform badly.
scroll to pan →
Acquisition and analysisDecision and actionAutomateAssistAugmentPreserve
The shape is the finding — high on the left pair, low on the right pair, across almost the whole estate. Machines gathered and analysed. People chose and acted. Seven activities score zero everywhere, and none of them scores zero because a model would perform badly at it.
Dimensions each activity was scored against
Dimension Question Effect on the score
Reversibility Can the outcome be undone before it reaches anyone outside? Irreversible caps decision and action at zero regardless of model performance.
Named-person requirement Does a rule or an accountability structure require an identified human? Ends the analysis for that stage.
Failure asymmetry What does a false negative cost against a false positive? Strong asymmetry pushes toward assist with a low threshold, never toward automate.
Judgement content Is it recognition or interpretation? Recognition can be assisted. Interpretation is preserved.
Data readiness Does the record needed to do this exist yet? Absent data defers rather than declines. Six activities sit behind the catalogue work.
Consequence What happens downstream if this is wrong? High consequence with low frequency is the worst automation candidate in the set. There are three.
Process integrity Is the current process the right one? Where no, the activity goes to redesign and no capability is specified for it.

Redesign — the four that needed no capability at all

Activity Was Became Why it is redesign rather than automation
Denominator reconciliation Three functions each computing their own, monthly, and disagreeing One canonical denominator, defined once, versioned, with the two others retired Automating three wrong reconciliations produces three wrong answers faster.
Safety recognition Partner staff deciding whether content is potentially reportable Partners forward everything on a defined cadence; recognition returns to trained affiliate staff The judgement was in the wrong place. No model changes that; moving it does.
Partner onboarding Four functions specifying separately, at different times One specification issued at contracting, from the catalogue The sequence was wrong, not the effort.
The monthly pack Assembled by hand, containing four charts nobody uses Generated from the decision datasets; anything without a decision owner removed Automating the assembly of unused charts is the most expensive way to keep them.
The denominator work delivered more than every capability in the portfolio combined, and required no model. It is listed first deliberately — a document where the machine work is the headline would have inverted this.
31

The capability portfolio

Eleven built

Thirty-four candidates from W4, reduced to eleven. All are assistive or deterministic, all produce output a person acts on, and none makes a determination that leaves the organisation.

The models, and everything that is not a model

Six models in a system of thirty-one automated steps. Everything else is rules. The rules carry the weight and the models are the cheap part. Every proposal the affiliate had received before this one had it the other way round.

WHERE THE MODELS ARE, AND WHAT EACH ONE ACTUALLY DOES Six models. Everything else in the system is deterministic. Every model output is confirmed by a person before it becomes a fact. ONBOARD INGEST INTERPRET PUBLISH M1 AGENTIC INTERVIEW MODEL Conducts the partner assessment, branching on every answer HOW Language model + question tree HUMAN Partnership lead reviews the full transcript IF GONE Reverts to the static form it replaced. Slower, still works. M2 OFFER MAPPING MODEL Maps what a partner says they hold onto the canonical catalogue HOW Retrieval over the catalogue + classification HUMAN Data product confirms every mapping IF GONE Mapping done by hand against the catalogue, as before. D1 SCHEMA & TYPE CHECKS RULES Deterministic validation against the registered contract HOW Rules. No model. HUMAN Nothing until it fails IF GONE n/a — this is the floor the whole system stands on. M3 DRIFT DETECTION MODEL Compares arriving structure and distribution to the baseline HOW Statistical tests + a model for distributional shift HUMAN Data engineering decides whether to accept IF GONE Structural drift still caught by rules. Distributional drift goes unseen. M4 FIELD MAPPING MODEL Proposes partner field to canonical element, with sample values HOW Few-shot classification over confirmed prior mappings HUMAN Data product confirms every mapping, including obvious ones IF GONE The analyst’s spreadsheet. The pre-existing state. M5 RIGHTS EXTRACTION MODEL Proposes the seven rights values from an agreement, quoting the clause HOW Extraction with span citation HUMAN Privacy confirms or corrects every single value IF GONE Eleven agreements read by hand. Slow, and it is what happens now. D2 BENCHMARK & FITNESS RULES Scores against benchmark; tests grain, denominator and coverage per decision HOW Rules over stored properties. No model. HUMAN Decision owner issues the fitness verdict IF GONE n/a — deterministic, and the most important logic in the system. M6 SAFETY SURFACING MODEL Orders an exhaustive queue by likelihood of safety relevance HOW Classification + ranking, with a random tail sample HUMAN Trained reviewer assesses every item regardless of rank IF GONE Queue reverts to chronological. Coverage never changes. D3 CARD ASSEMBLY RULES Renders the confidence card from stored properties HOW Template over the record. No model. HUMAN Reads it. Cannot remove a field. IF GONE n/a — publication is blocked without a card. M7 EVIDENCE SUMMARY MODEL Summarises partner evidence with a link back to every source claim HOW Summarisation with citation HUMAN Reader follows the links for anything that matters IF GONE Read the sources. Slower and no less correct. D4 VALUE ASSEMBLY RULES Builds the partner value position from the five classes and the counterfactual HOW Rules + stored evidence. No model. HUMAN Portfolio owner decides the quadrant IF GONE n/a — the assembly is logic, not inference.
scroll to pan →
OnboardIngestInterpretPublishSolid border · modelDashed · deterministic rules
Read the bottom line of each card — what happens if the model is removed. Every one degrades to a manual process that already exists, and none degrades to silence. That property is what allowed a model onto the safety path. Patient Safety tested for it rather than for accuracy.
The six models, stated plainly
Model Technique Trained or grounded on Confirmed by Wrong output costs
M1 Agentic interview Language model driving a branching question tree, with catalogue retrieval The canonical catalogue and prior sessions Partnership lead reads the transcript A poor follow-up question. The transcript is visible and the partner can correct the mapping live.
M2 Offer mapping Retrieval over the catalogue plus classification 187 catalogued elements with definitions Data product confirms every mapping Caught at confirmation. Mis-mapping a novel element is the realistic failure and it surfaces immediately.
M3 Drift detection Statistical tests plus a model for distributional shift The registered contract and 12 months of feed history Data engineering decides whether to accept A false positive costs a review. A false negative is the state before the system existed.
M4 Field mapping Few-shot classification over confirmed prior mappings Every confirmed mapping in the estate, growing Data product confirms every mapping, including the obvious ones Caught at confirmation. Confirming the easy ones is deliberate — it keeps the reviewer calibrated.
M5 Rights extraction Extraction with span citation The agreement set and the seven-field vocabulary Privacy confirms or corrects every value Caught at confirmation. The quoted clause is what makes confirmation fast enough to actually happen.
M6 Safety surfacing Classification and ranking over an exhaustive queue Reviewer decisions, reviewed quarterly, never applied automatically Trained reviewer assesses every item regardless of rank A missed item sits lower in a queue that is still read end to end. A random tail sample runs every sweep.
M7 Evidence summary Summarisation with citation Partner-supplied evidence documents Reader follows the links for anything material A misleading summary. Every claim carries a link and reviewers are told to follow them.
Five of the eleven capabilities in the portfolio use no model at all. Benchmark scoring, fitness assessment, card assembly, value assembly and structural validation are rules over stored properties — and they include the two pieces of logic the whole system depends on.
The eleven
Capability Stage What it does What the person does When it is wrong Value Risk
Schema and type conformance acquisition Deterministic validation against the expected shape Nothing until it fails Rejects a valid record; the partner is notified and it is re-sent High Low
Drift detection acquisition Compares arriving structure to the registered contract Reviews the diff, decides whether to accept Fires on a benign change; costs a review High Low
Field mapping to canonical analysis Proposes a mapping from partner field to catalogue element, with the evidence Confirms every mapping, including the obvious ones Caught at confirmation; the obvious cases are what keep the reviewer calibrated High Medium
Rights extraction analysis Proposes values for the seven rights fields from an agreement, quoting the source clause Privacy confirms or corrects every value Caught at confirmation. The quoted clause is what makes confirmation fast enough to happen. High Medium
Benchmark scoring analysis Scores a feed against the benchmark family for each data type Reads the score; decides on exceptions Deterministic. A wrong threshold is a configuration error, not a model error. High Low
Coverage overlap detection analysis Maps a candidate partner’s offer against the estate and shows what is new Portfolio owner decides Over-states novelty; the assessment output shows the working High Low
Anomaly detection in a feed analysis Flags distributional shifts that no schema check catches Investigates False positive costs an investigation; false negative is the pre-existing state Medium Low
Evidence summarisation analysis Summarises partner-supplied evidence with links back to the source Reads the source for anything that matters Summary misleads; every claim carries a link and reviewers are told to follow them Medium Medium
Safety content surfacing acquisition Orders partner-forwarded content by likelihood of being safety-relevant Trained reviewer assesses every item; order changes, coverage does not A missed item sits lower in an exhaustive queue, never outside it. A random tail sample runs every sweep. High High — controls in §22
Assessment interview acquisition Conducts the structured partner interview, branching on answers Reviews the transcript and the derived profile Asks a poor follow-up; the transcript is visible and the profile is confirmed High Low
Confidence card assembly analysis Populates the card from the record at publication Reads it; may not remove a field Cannot be wrong independently — it renders stored values. A wrong value is wrong upstream. High Low
32

The declined set

Eight, with the reasoning

Most of what was asked for.

Predictive partner scoring

The most requested capability in discovery and the first to fail. It needs a common outcome measure across partners; there is none, and the linkage ceiling means there cannot be one at L0. Partner-reported metrics describe the reporting rather than the performance, so a model trained on them learns the reporting. Deferred until L2 exists, at which point it may still be the wrong idea.

Automated renewal recommendation

A recommendation is a decision in everything but name — once a system produces one, the human role becomes ratification, and ratification under time pressure is not review. The gateway assembles the evidence pack instead and recommends nothing.

Automated safety classification

Deciding whether content is potentially reportable is exactly the judgement the current design gets wrong by placing it with partners. The judgement fails because the person making it is untrained. A model would not be trained either. Surfacing and ordering are automated; the determination is not.

Cross-partner identity resolution

Probabilistic matching on quasi-identifiers would work technically and would manufacture linkage the rights position does not permit. It also creates re-identification risk in a dataset assembled specifically to avoid it. Declined on governance rather than feasibility.

Patient-facing conversational support

Proposed as an adherence capability inside partner apps. Sits close enough to the medical-device boundary that it needed a classification assessment nobody had run, and it lives at the highest-consequence point in the journey. Adding a safety intake route to those same surfaces delivered the reachable part.

Synthetic data generation to fill gaps

Proposed to fill the tolerability and stop-reason gaps. Synthetic records would carry the shape of evidence without the content, and nothing downstream could distinguish them from real ones. The gaps are real findings and are reported as gaps.

Automated rights determination

The model proposes the values. Privacy confirms them. A wrong lawful basis is not corrected by deleting the data afterwards, and the accountability for the determination has to sit with a person who can be asked why.

An agentic partner-monitoring platform

The opening hypothesis: a system that continuously watches every partner, ingests their data, scores them and recommends action. It presumes a complete register, a rights position permitting ingestion, comparable metrics and a defined action space. None of the four existed.

The pattern in the eight. Six were declined on governance or accountability rather than on capability, and every one of those six would have worked technically. Only two were declined because the data does not support them. Six of eight would have worked technically.

33

Human checkpoints

Nine, each with a basis

Justified against evidence rather than caution. Three exist because accountability requires a person who can be asked why; four because the error cannot be withdrawn; two because the people doing the work asked, and their reasoning held.

Checkpoint Level Why it stays human Basis
Rights determination Always human A wrong lawful basis is not corrected by deleting the data. Accountability has to rest with someone who can explain the determination. Privacy, W5: “I can defend a judgement. I cannot defend a field that was populated for me.”
Fitness verdict for a decision Always human It is a relation between data and a decision only the decision owner fully holds. The gateway can compute the inputs; it cannot hold the intent. W1 — four “decisions” dissolved on inspection. A machine would have scored all four.
Safety relevance determination Always human Trained judgement inside an established process. Nothing in this design reaches past the intake boundary. Patient Safety, W5, and the existing process definition
Denominator definition Always human A definitional choice with consequences across every rate the organisation publishes. It is a decision, not a calculation. F-07 — three functions, three reasonable definitions, an 18–22% spread
Partner approval or termination Always human Irreversible, externally visible, contractually consequential Standard practice, confirmed in W5
External communication to a partner Human approval Machine drafts; a person sends. A remediation request in the wrong tone damages a relationship the affiliate cannot easily replace. W5 — raised by Partner Operations, unprompted
Field mapping confirmation Human approval, every item Not because mapping is hard, but because confirming the easy ones keeps the reviewer calibrated for the hard ones Ironies of automation. The design cost is seconds per item.
Publication of a figure Human approval The last point at which anyone can ask whether this number should exist F-11 — nothing published carried its limits
Overriding a blocked publication Human approval, named, logged Blocks must be overridable or people route around the system. The override is the record. W5 pre-mortem: an unoverridable block produces a shadow spreadsheet within a quarter
One checkpoint was removed rather than added. Partner-side recognition of safety-relevant content had functioned as an informal human control; it was a regulated judgement placed with untrained parties who had no way to evidence exercising it. Removing it and requiring undifferentiated forwarding moved substantially more volume to affiliate reviewers, which the surfacing capability absorbs.
34

Human–AI interaction

The loop, and what happens when it fails

One loop serves both products. The property that made it acceptable to the safety and privacy functions is that every failure mode returns the system to the state that preceded it, never to silence.

THE LOOP — WHAT THE MACHINE DOES, WHAT THE PERSON DOES, AND WHAT HAPPENS WHEN IT FAILS 1 · ARRIVAL feed lands, or a partner completes the assessment instrument 2 · MACHINE CHECKS schema, types, ordering, drift, benchmark, coverage — deterministic 3 · MACHINE PROPOSES field mapping, rights values, fitness verdict per decision, with the source shown 4 · BANDING clear · needs a look · blocked. Every item still reaches a person. 5 · HUMAN CONFIRMS data product confirms mapping; Privacy confirms every rights value; decision owner confirms fitness 6 · PUBLICATION figure released with a confidence card populated automatically from the record HUMAN OVERRIDE any proposed value can be changed; the change is the record, with a reason FEEDBACK confirmed and overridden values return as labelled examples, reviewed quarterly DEGRADED MODES — every failure returns the system to the previous state, never to silence Model unavailable Proposals stop. Deterministic checks continue. Queue reverts to manual. Confidence collapses Everything enters “needs a look”. Slower, not less complete. Partner changes schema Feed quarantined at staging; the last good publication stands, marked stale. Rights value cannot be determined Written as UNKNOWN, never defaulted. Dependent decisions blocked. Confidence card cannot be populated Publication blocked. No figure has ever left without one. Sampling finds systematic error Proposals suspended; checks and review continue, unranked.
scroll to pan →
The override path is the record — a confirmed value and an overridden value are stored identically, with who and why. Override rates became a monitored measure.
Per capability: what the machine knows, what the person sees
Capability Machine knows Machine does Person sees At low confidence Failure behaviour
Field mapping Catalogue definitions, prior confirmed mappings, the partner’s own field names and sample values Proposes a target element and a grain Proposal, the sample values it reasoned from, and the prior mapping if one exists Proposes nothing and says so, rather than guessing Mapping halts; deterministic checks continue; the analyst maps by hand as before
Rights extraction The agreement text and the seven-field vocabulary Proposes a value per field with the source clause quoted Every proposed value beside its clause Marks UNKNOWN — never a default Field written as UNKNOWN; every dependent decision blocked
Safety surfacing Forwarded content, surface metadata, prior reviewer decisions Orders an exhaustive queue by likelihood Item, surface, timestamp, original text, position and the stated reason Everything enters the middle band Queue reverts to chronological. Coverage never changes.
Benchmark scoring Feed profile, benchmark family, decision requirement Computes and compares Score, threshold, and which decision the threshold came from n/a — deterministic Scoring unavailable; last good score shown with a staleness marker
Coverage overlap The canonical catalogue and the current estate Maps a candidate offer and shows what is new Overlap map with the reasoning Marks the element as unclassifiable and asks Falls back to manual comparison against the catalogue
Assessment interview The catalogue, the question tree, prior answers Conducts the interview, branching on answers Full transcript and the derived profile Escalates to a human interviewer Reverts to the static questionnaire the interview replaced
Confidence card Every stored property of the dataset Renders The card Renders UNKNOWN at full weight Publication blocked

The sampling control

A model that is consistently wrong in one direction is indistinguishable, from the reviewer’s seat, from a model that is right — because the reviewer only sees what the model surfaced first. A fixed proportion of the bottom band is drawn every sweep and reviewed ahead of the rest. It is the only way to detect the failure from inside the process, and it is cheap.

35

The Partner Data Assessment Instrument

Product one

An agentic intake that interviews a prospective partner and returns a decision pack. It replaced a nineteen-question static form that took four weeks to complete and produced answers nobody could compare.

Why an interview rather than a form
Problem with the form What the interview does
The useful follow-up question depends entirely on the previous answer. A form asks all of them or none. Branches. A partner who says “we hold weight measurements” is then asked how the measurement was taken, whether the method is recorded, and whether the account can be shared — three questions no other partner would receive.
Partners answer in their own vocabulary; the affiliate cannot compare answers across partners. Maps every answer to the canonical catalogue as it goes, and shows the partner the mapping so they can correct it.
A partner cannot tell what a good answer looks like, so answers optimise for sounding capable. States the benchmark for each element before asking, which changes the answer from a claim to a measurement.
The form asks what data exists. It never asks what is transmissible. Asks the receivable-grain questions explicitly, on all three axes, and asks about identifier stability, which no partner had ever been asked before.
Four weeks of email, then a spreadsheet nobody revisits. A session, a transcript, a derived profile, a coverage map and a draft confidence card.
What it asks, in order
Block The questions Why here
1 · Business shape Archetype, journey stages touched, primary user, service model Determines everything that follows. A wrong archetype produces a wrong question tree.
2 · What is generated What the service creates as a by-product of doing its job Deliberately separated from what is transmissible. Partners conflate the two, and the gap is informative.
3 · Receivable grain Finest transmissible grain on identity, temporal structure and population scope, per element The core of the instrument. Three axes, asked separately, in the partner’s own terms and mapped afterwards.
4 · Identifier model Scheme, stability over time, reset conditions, whether the same subject is recognisable across datasets Nobody had ever asked. Two partners discovered their own answer during the session.
5 · Denominator Who counts as a subject, when they enter, when they leave, and whether the definition has changed The single most common source of incomparability in the estate
6 · Selection and observability Who is in this population and who is not; how long a subject stays visible; why they leave Where informative attrition is caught, before contracting rather than eighteen months later
7 · Rights Purpose, basis, onward transfer, linkage, retention, secondary use Proposed by extraction from the draft agreement where one exists; confirmed here
8 · Operations Transmission route, cadence, change notification, support model What the gateway will need
9 · Reciprocity What the partner needs from the affiliate A one-directional model produces agreements partners have no reason to honour well
What it returns
Output Contents Who uses it
Coverage map The candidate’s journey coverage against the existing estate, with new, overlapping and absent marked Portfolio owner — the “does this add anything” decision
Grain profile Three-axis position per offered element, with the fitness consequence for each affected decision Data product and the decision owners
Linkage assessment Current rung, and what would move it up one Legal, Privacy, and the partnership lead
Draft rights position Seven structured fields, proposed, with source clauses Privacy, who confirms every value
Specification What the affiliate requires this partner to send, generated from the catalogue Goes into the agreement, not into an email afterwards
Draft confidence card What any figure derived from this partner will be able to say, and what it will not The decision owner, before signature
Transcript The full session Everyone. It is the evidence that the profile is not invented.
The draft confidence card at onboarding is the piece that changed behaviour. Showing a decision owner, before signing, exactly what a figure from this partner will be unable to tell them turns a data conversation into a decision conversation — and it killed one candidate partnership outright.
36

The Conformance Gateway

Product two

Everything an existing partner sends passes through four tests in order. The first three are properties of the data. The fourth is a relation between the data and a named decision, and it is the one that fails.

THE CONFORMANCE FUNNEL — VALID IS NOT FIT Four tests in order. A feed can pass the first three and fail the one that names a decision owner. CONTRACTED GRAIN what the agreement permits longitudinal pseudonymous subject-level RECEIVED GRAIN what actually arrives monthly anonymous aggregate change USABLE GRAIN what survives the six quality tests aggregate · 61% coverage · 9-day latency DECISION-FIT GRAIN what this decision requires subject-level · ≥80% coverage · ≤48h VERDICT  technically valid · contractually acceptable · NOT FIT for the persistence decision. The first three tests are properties of the data; the fourth is a relation between the data and a named decision.
scroll to pan →
The worked example is the normal case — a feed arriving inside its contract, passing every quality dimension, and unable to support the question it was acquired to answer. Ordinary data-quality tooling reports this feed as green.
The pipeline, stage by stage
Stage What it does What it enforces On failure Measure
Landing Receives, records arrival, computes a fingerprint Nothing yet — arrival is always recorded, including malformed arrivals Records the arrival and the failure. A feed that fails at the door is a fact, not an absence. Arrivals against expected schedule
Structural validation Schema, types, controlled vocabularies, event ordering The registered contract Rejects the record, notifies the partner, never coerces silently Rejection rate by feed and by field
Drift detection Compares arriving structure and distribution to the registered baseline Change is an event, not a discovery Quarantines at staging; the last good publication stands with a staleness marker Time from drift to detection
Canonical mapping Maps partner fields to catalogue elements One vocabulary Unmapped fields land in a holding area and are reported, not dropped Unmapped field count; time to resolve
Rights check Compares the intended use against the structured rights position Purpose, grain, linkage and retention Blocks the use, not the ingestion. The data may be lawful for a different purpose. Blocked uses, and how many were resolved by a rights change
Benchmark and quality Six dimensions against the benchmark family for each data type Thresholds set by decision requirement Publishes with the measured value stated rather than withholding Pass rate by dimension
Fitness assessment Compares grain, denominator, observability, coverage and known bias against each decision’s requirement Fitness per decision, not per feed Blocks that decision only. The feed remains fit for others. Fit and unfit counts per decision
Publication Releases with a populated confidence card No card, no publication Blocked, with a named override path Publications; overrides; override reasons

Ingestion into the existing estate

Step What is implemented Measure attached
Land Immutable arrival store, one object per arrival, fingerprinted Arrival completeness against schedule; time to land
Validate Contract-driven validation at the boundary, not in the warehouse Rejection rate; false-rejection rate from partner disputes
Map Canonical mapping with confirmed lineage per field Unmapped fields; mapping changes per period
Reconcile Canonical denominator applied; the two retired definitions retained as views for one transition period Variance between old and new definitions, reported until the views are removed
Enrich Reference data joined from Layer 1 — organisation codes, professional status Reference join rate; stale reference rate
Publish Decision datasets built, versioned, and released with a card Publication latency; card completeness; blocked publications
37

Features

What a user encounters
Feature list
Feature User Problem it solves What was built The human’s part Type
Guided partner interview Partnership lead, partner Four weeks of email producing incomparable answers Branching agentic session with live mapping shown to the partner Reviews the transcript; can take over at any point AI
Coverage map Portfolio owner No way to see whether a candidate adds anything Journey-by-archetype map with new, overlapping and absent marked Decides Product
Grain profile card Data product, decision owner Grain discussed in one word, meaning three things Three-axis profile per element, with fitness consequences Confirms Product
Rights cockpit Privacy, analyst Rights unreadable without opening eleven agreements Seven structured fields per engagement, queryable, with source clauses Confirms every value AI + product
Specification generator Partnership lead, Legal Partners define their own metrics because nobody specified Requirements generated from the catalogue for the agreement Reviews and negotiates Product
Arrival monitor Data engineering Feed failures discovered two cycles later Arrival tracking against schedule with fingerprinting Investigates exceptions Configuration
Drift alert Data engineering, data product Silent schema change Structural and distributional comparison against a registered baseline Decides whether to accept AI + rules
Mapping workbench Data product Manual mapping held in one person’s spreadsheet Proposed mappings with sample values and prior decisions Confirms every mapping AI
Fitness board Decision owner A feed reported as green while being useless Fit or blocked per decision, with the failing criterion named Sets the requirement; issues the verdict Product
Decision confidence card Every reader of every figure Figures published bare Auto-populated component attached at publication Reads it; cannot remove a field Product
Safety review queue Patient safety reviewer Cadence set by whoever configured the surface; recognition by partners Exhaustive queue, ordered, with a random tail sample Assesses every item AI
Definition register Analyst, everyone The current definition lives in the last email that explained it Versioned definitions, reachable from any figure that uses them Owns and versions Product
Evidence pack assembly Business owner, Finance Renewal on relationship history Assembles everything known about a partner into one reviewable pack Decides. The pack recommends nothing. AI + product
Override log Everyone Blocks get routed around and nobody knows Named, reasoned, logged override on any block Provides the reason Configuration
38

Capabilities

What the system can do underneath
Capability list — separate from features, with what breaks without each
Capability Serves Depends on What breaks without it
Canonical catalogue Everything Nothing — it is the root There is no vocabulary, so nothing can be compared, specified or mapped
Receivable grain model Grain profile, fitness board, assessment Catalogue Grain gets discussed in one word and the catalogue misdescribes half the estate
Linkage state per partner Fitness board, coverage map Catalogue, agreements Cross-partner questions get commissioned and quietly abandoned
Structured rights position Rights cockpit, gateway rights check Agreement set, controlled vocabulary Every analysis waits on a legal read and the portfolio question stays unanswerable
Decision inventory Fitness board, card, catalogue prioritisation W1 output, maintained Fitness has nothing to be assessed against and the catalogue reverts to a field list
Denominator register Every rate, the card Canonical definitions Three functions quote three numbers and nobody can say which is right
Observability model Card, fitness board Feed profiling Longitudinal claims are made from feeds that cannot support them
Contract registry Drift detection, validation Catalogue, onboarding Drift is undetectable because there is no baseline to compare against
Quality engine Gateway stages 5 and 6 Contract registry, benchmarks Quality is discovered by the analyst preparing the pack
Fitness engine Fitness board, publication block Decision inventory, quality engine, grain model Feeds are reported green and used wrongly
Lineage Card, audit, dispute resolution All pipeline stages emitting events A published number cannot be defended when challenged
Confidence card renderer Publication Every capability above it The care taken upstream evaporates at the last step
Extraction and mapping models Mapping workbench, rights cockpit Catalogue, agreement set, confirmed examples The work is done by hand, which is the pre-existing state and is survivable
Surfacing model Safety review queue Surface inventory, reviewer decisions Queue reverts to chronological. Coverage is unaffected.
Feedback store Model improvement Confirmations and overrides Models stop improving. Nothing else breaks.
Reading the last column down separates the two kinds of capability. The first twelve are load-bearing — remove one and something becomes impossible. The last three are efficiency; remove them and the work returns to how it was done before, which is slower and still correct. Only the last three involve a model.
39

Information model

Seventeen entities, one owner each

Ownership was the contested part. Every attribute resolves to exactly one function, and ownership is a named individual rather than a function, because a function cannot be asked what it decided and why.

TARGET INFORMATION MODEL · COLOUR IS THE OWNING FUNCTION · NO FACT HAS TWO OWNERS PARTNER partner_id · PK legal_entity · archetype P01-P08 linkage_rung · owner Partnership lead PARTNER PRODUCT product_id · partner_id service · journey_stages[] Partnership lead AGREEMENT agreement_id · partner_id effective · expiry · scope Legal RIGHTS POSITION engagement_id · PK basis · purposes[] · grain linkage · retention · transfer Privacy FEED feed_id · partner_id transport · cadence contract_version Data engineering DATA ELEMENT element_id · PK · layer domain · definition · version authoritative_source Data product RECEIVABLE GRAIN feed_id · element_id identity · temporal · scope stability · verified_at Data product DENOMINATOR denom_id · definition entry_rule · version Data product TOUCHPOINT touchpoint_id · stage actor · creates[] Service design JOURNEY STAGE stage_id · 1.14 order · description Service design DECISION decision_id · PK owner · cost_of_error min_linkage · evidence_req Decision owner DECISION DATASET dataset_id · decision_id denom_id · observability confidence_ceiling · version Data product QUALITY RESULT feed_id · dimension value · threshold · passed measured_at Data product FITNESS VERDICT dataset_id · feed_id fit · failing_criterion verdict_by · at Decision owner CONFIDENCE CARD dataset_id · rendered_at all fields derived cannot_tell_you System · derived SAFETY SURFACE surface_id · partner_id cadence · intake_route last_swept Patient safety REVIEW EVENT review_id · object_ref reviewer · decision rationale · at Reviewing function OVERRIDE override_id · block_ref by · reason · at Reviewing function THE OWNERSHIP RULE No fact has two owners. Split ownership of a single fact is where these registers rot. Every attribute above resolves to exactly one function. No function writes into another’s entity. Privacy owns rights values; Data product owns grain; the decision owner owns the fitness verdict. Reads are unrestricted. The card is the only derived entity. It has no owner because it holds no independent value — every field renders from an entity above it. Ownership is a named individual, not a function. A function cannot be asked what it decided and why. The re-audit framing made this non-negotiable.
scroll to pan →
Partnership & engineeringLegal & service designPrivacy & data productDecision ownerPatient safetyReviewing function
Why the card has no owner — it holds no independent value. Every field renders from an entity above it, which is what allows it to be populated automatically and what makes it impossible to soften by hand.

The confidence card, rendered

DECISION CONFIDENCE CARD — THE COMPONENT BOTH PRODUCTS WRITE TO PERSISTENCE AT 26 WEEKS · P02 REFILL-BASED 58% of the enrolled denominator · period to 31 March GRAIN stable pseudonym · longitudinal subject · full partner cohort DENOMINATOR enrolled at first dispense, fixed at enrolment · definition v2 OBSERVABILITY 26 weeks · 14% exit the feed before week 26 COVERAGE 81% of this partner’s active population LATENCY 4 days from dispense event to receipt LINKAGE L1 · within-partner only, no cross-partner view KNOWN BIAS private route only · NHS specialist route absent from the estate QUALITY 6 of 6 dimensions pass · fitness: FIT for this decision CANNOT TELL YOU  why anyone stopped, or whether they restarted elsewhere Every field is a stored property Nothing here is written by hand. Grain, denominator, observability and bias are catalogue and dataset fields, rendered. A missing value renders as UNKNOWN At full weight, in the same position. An omitted row reads as an absent problem, which is the failure this prevents. Fitness is per decision The same feed shows FIT here and BLOCKED on the persistence-across-journey question. Uniform presentation would teach uniform trust. The last line is mandatory Every card states what the figure cannot support. A card that only ever reassures is decoration. It is the shared object The assessment instrument drafts it at onboarding; the gateway populates it at publication. Nothing else is written by both. Publication is blocked without it Not a warning. No figure has left the gateway without a card.
scroll to pan →
The last line is mandatory — every card states what the figure cannot support. A card that never says what a figure cannot support is decoration.
40

Future state

The same data point, again
FUTURE STATE · SAME DATA POINT, SAME SIX STAGES Generate Transmit to spec Validate & map Test fitness Publish Decide PATIENT / HCP PARTNER GATEWAY AFFILIATE GOVERNANCE measurement or interaction AUTO captured to the issued specification AUTO transmitted at contracted grain AUTO schema, drift, canonical mapping ASSIST 6 quality dimensions + fitness per decision ASSIST mapping confirmed by data product HUMAN fitness verdict by the decision owner HUMAN dataset built, card populated AUTO decision taken with the card in hand HUMAN rights checked from structured values AUTO lineage complete to source event AUTO override logged with a reason HUMAN CONFIDENCE CARD ATTACHED HERE TODAY  Nine break-points across the same six stages. Recognition sits with partners, rights are read from a PDF at the point of use, reconciliation is two to three days of one analyst’s month, and the figure arrives bare. Four human steps remain and all four are decisions rather than assembly. The analyst confirms and adjudicates instead of collecting.
scroll to pan →
AutomatedMachine-assisted, human confirmsHuman
Four human steps, all of them decisions — mapping confirmation, fitness verdict, the decision itself, and the override. Assembly, reconciliation and rights lookup have gone. The analyst adjudicates rather than collects, which is a different job and a better one.
Break-point by break-point
# Was Now Residual
B1 Partner defines the metric Specification issued from the catalogue at contracting; definitions versioned Legacy agreements carry old definitions until renewal
B2 Aggregation destroys the grain Contracted grain stated on three axes and tested at arrival Two partners cannot supply finer grain without a platform change of their own
B3 Silent schema drift Registered contract; drift is an event with a named reviewer Distributional drift is harder than structural and will produce false positives for a while
B4 No contract check at landing Rights checked from structured values before publication Rights extraction is assistive; every value still needs a human confirmation
B5 No cross-partner key Linkage state explicit per partner; unsupported joins refused rather than warned The ceiling itself is unchanged. This makes it visible, not solvable.
B6 Reconciliation invisible Canonical denominator, automated assembly, analyst confirms The confirmation load is real and was deliberately not minimised
B7 Rights read under pressure Queryable before an analysis is commissioned Novel purposes still need a determination, and should
B8 Lineage stops at the warehouse Carried to publication Two feeds arriving by attachment have lineage that starts at the mailbox
B9 The number arrives bare No card, no publication None. This one is closed.
41

Operating model

Who decides what
Decision rights
Decision Decides Consulted Escalates to
Whether an arrangement is a partnership at all Portfolio owner Legal, the proposing function Digital leadership where the archetype is contested
Archetype classification Portfolio owner Data product Portfolio forum
Whether a candidate adds coverage Portfolio owner Decision owners affected Digital leadership
The specification issued to a partner Data product Decision owners, Legal, Privacy Portfolio forum
Contracted grain Data product with Legal Partner, decision owners Portfolio forum
Rights position values Privacy Legal, engagement owner Data protection lead
Linkage rung and any move up it Privacy with Legal Decision owners who need it Data protection lead
Canonical denominator Data product Commercial, Medical, Market access — all three Portfolio forum. This one was escalated, and settling it took two sessions.
Whether a mapping is correct Data product Data product lead
Fitness for a decision The decision owner Data product Portfolio forum
Whether a figure is published The decision owner Data product Portfolio forum
Overriding a publication block Named individual, logged with a reason Reviewed monthly at the portfolio forum
Screening cadence per surface Patient safety Partner, on feasibility Existing pharmacovigilance chain
Whether safety content is reportable Patient safety Existing pharmacovigilance chain
Partner suspension or termination Portfolio forum Legal, Commercial, engagement owner Affiliate leadership
Changes to any model Owning function of the affected process Patient safety where the safety path is touched Portfolio forum

What was deliberately not centralised

  • The partner relationship. Stays with the engagement owner. A central function fielding every partner conversation becomes the bottleneck the redesign removed.
  • Fitness verdicts. Stay with decision owners. Centralising them would separate the verdict from the intent it is a verdict about.
  • Rights determination. Stays with Privacy. The register displays the position; it does not decide it.
  • Whether a partnership is commercially worth having. Stays with Commercial. Governance sets whether it may proceed, not whether it is a good idea.
One new role: a catalogue custodian in Data product, accountable for the integrity of the record and for none of the decisions recorded in it. The distinction held under questioning, which was the test.
42

Measurement

What would show it worked
Product → behaviour → operational → business → strategic
Level Measure Baseline What it detects
Product Catalogue elements with a named decision 0 of 187 Whether the catalogue is a decision instrument or a field list
Product Feeds with a registered contract 0 of 14 Whether drift is detectable at all
Product Rights positions held as structured values 0 of 23 Whether a portfolio rights question can be answered
Product Figures published with a card 0 The closing measure on F-11
Behaviour Analyses checked against rights before commissioning Unmeasured — the check happened afterwards Whether the shift from retrospective to prospective actually happened
Behaviour Mapping override rate n/a Model quality, and whether reviewers are still reading. A rate at zero is a warning, not a success.
Behaviour Publication blocks overridden, with reasons n/a Whether the blocks are calibrated or are being routed around
Behaviour Decisions citing a card in the meeting record 0 The only measure that shows the human-factors work landed
Operational Analyst days per month on assembly 2–3 days constructed The workload finding. Measured properly from month one, having been estimated in discovery.
Operational Time from schema drift to detection 2 cycles, typical Whether silent failure has stopped being silent
Operational Feeds fit for their intended decision 4 of 14 at the outset The headline operational measure
Operational Time from arrival to publication Monthly cycle Whether the pipeline runs at data speed or at meeting speed
Business Decisions with traceable evidence 4 of 27 The measure the whole programme exists to move
Business Partner renewals decided on evidence 0 Whether renewal has stopped running on relationship history
Business Journey stages with usable coverage 4 of 14 Whether the estate is being shaped or accumulated
Strategic Ability to answer a persistence question defensibly Not possible The single question the affiliate most needs and could not answer
Three baselines are unmeasured and reported as such rather than estimated. A measure introduced mid-programme with an invented starting point is a constructed number wearing the clothes of a measured one, and it fails at the first challenge.
43

The working system

Six screens

What the analyst, the partnership lead and the data team actually sit in front of. Each screen shows one task in progress rather than a feature list, and every model output in them is a proposal a person confirms.

One system, four layers

Four jobs, in sequence: build the evidence estate, protect its quality, use it, and keep it alive. The screens below sit in those layers rather than beside each other.

ONE SYSTEM, FOUR LAYERS 1 BUILD THE ESTATE Partner Assessment Interviews a candidate, maps what they hold onto the catalogue, and states what a figure from them will not be able to tell you. RUNS before contracting every output carries a confidence card 2 PROTECT THE QUALITY Conformance Gateway Four tests per feed, ending in whether the evidence satisfies the contract for a named decision. RUNS every arrival every output carries a confidence card 3 USE THE EVIDENCE Question Desk · Cohort Architect Turns a question into an answer with its limits attached, or builds a population and tests whether the estate can carry it. RUNS daily every output carries a confidence card 4 KEEP IT ALIVE Evidence Watch Notices when a blocked question becomes answerable, and when a published figure stops being safe. RUNS every cycle every output carries a confidence card Four screens, one spine. The catalogue is the only new system of record; everything else runs on infrastructure the affiliate already has.
scroll to pan →
The catalogue is the only new system of record. Layer 4 is the one that compounds — blocked questions do not stay blocked, and without it nobody goes back to check.

Layer 3 · Question desk

An analyst pastes what they were asked. The system decomposes it, narrows it to what the estate can support, names the evidence and drafts the answer. Nothing publishes without a person confirming.

Work Question desk Q-2841ReassignSave draftConfirm & publishWhy are we losing patients in the first three months?
ThreadEvidenceMethodLineageHistory
Why are we losing so many patients in the first three months, and can we do anything about it?
A. OKAFOR · COMMERCIAL · 09:14
Decomposition

Two questions in one. Why they leave is causal; what to do is allocation. Different evidence, separated below.

Unit: the person, from first dispense. Outcome: time to exit, right-censored. Denominator: enrolled at first dispense, v2 — fixed before counting.

Question narrowedThe estate can only answer why for people who contacted support before leaving. That is a reason mix among contactors, not a population rate. Reporting it as the latter would be the most misleading output available here.
Evidence contract · generated from the decision, before any data is read
Required claimExit concentrates at an identifiable point, with an attributable reason
PopulationInitiated in window, any route
GrainPerson-level, longitudinal, full partner cohort
DenominatorEnrolled at first dispense · v2 · fixed
Coverage≥90% of the initiating cohort
Observability≥26 weeks per person
LinkageL1 sufficient for timing · L2 required for reason
Acceptable biasContactor selection tolerable if stated; silent leavers must not be imputed
RightsService operation · secondary analysis permitted
Invalidates itA supply interruption inside the window that is not marked
Contract satisfied in partNine of ten terms met. Linkage for reason sits at L1 where the contract asks for L2, which is why the answer below is scoped to contactors rather than to the cohort.
Drafted answer · not published

Exit concentrates between weeks eight and twelve, where most people move between dose steps. Among contactors, tolerability dominates before week twelve and cost after it.

Support belongs before week eight rather than at the point of exit. The two exit groups need different responses, and one is not a support problem at all.

Confidence card · auto-attached at publication
GrainStable pseudonym · longitudinal · full partner cohort
Observability26 weeks · 14% exit the feed before then
Known biasReasons only from people who made contact
LinkageL1 · within one partner
Cannot tell youWhy the majority who left silently did so, or whether they restarted elsewhere
Ask a follow-up, or type /rerun to change the gap threshold…Send
Evidence required
Supply gap patternlive
Refill regularitylive
Reason for difficultypartial
Payer typeabsent
Blocking the causal halfPayer type would separate the cost leavers from the tolerability leavers. No feed carries it. Specification drafted for two agreements.
Method log
Cohort assembled1,180
Notes coded to taxonomy1,086
Uncoded, shown separately94
Selection check rundone
Related
Q-2790 stop reasonspartial
Q-2612 support effectblocked
Draft readyPublication blocked · awaiting decision ownerRights check passed · service operationQ-2841 · edited 2 min ago · M5 rights extraction v4

Layer 3 · Cohort architect

Separate tool, separate job. Somebody already knows they need a group; the question is whether partner data can carry one. The critique panel argues with the design while it is still open.

Work Cohorts Draft-114CompareDuplicateFreeze definitionEarly erratic refillers, tolerability-driven
DesignEvaluationFeasibilityVersions
AnchorNewly initiated
IntentDesign
Criteria2of 4 max
BreadthFocused
Dimensions, ranked against intent
DimensionRelevance to intentPartner dataIn design
Refill regularity directly relevantlivelevel 1
Reason for difficulty directly relevantpartiallevel 2
Supply gap pattern relevantlive
Payer type relevantabsent
Age band weakly relevantpartial
Scheme · one branch selected
Newly initiated
Refill regularity
RegularVariableErratic
Reason for difficulty
TolerabilityCostPlateauPractical
Scheme, not yet a cohortTwo of two levels chosen. The definition below is complete and can be frozen.
Evaluation
BreadthFocused
Data feasibilityModerate–high
ReachabilityModerate
ActionabilityHigh
ConfidenceModerate–high
Design critique
Retain · Reason for difficulty

Tied to the stated intent. Without it you have a group that leaves early and no way to know whether support would help.

Test separately · Refill regularity

May work better as a second-level split than an entry criterion. Erratic refilling could be the outcome rather than a selector.

Show both ways
Blocked · Payer type

Would separate cost leavers from tolerability leavers. No partner sends it.

Open specification
Definition complete2 criteria · both resolve to fields in the catalogue1 recommended dimension unavailableDraft-114 · v3 · autosaved

Layer 1 · Partner assessment

Mid-session with a candidate partner. The interview branches on each answer, maps what they describe onto the catalogue as it goes, and shows the partner the mapping so they can correct it.

Partners Assessments Candidate P-24PauseTake overGenerate decision packRemote monitoring candidate · session 1 of 1
SessionMappingCoverageRightsTranscript
BLOCK 3 OF 9RECEIVABLE GRAIN 18 min elapsed · 14 of 22 elements mapped
You said you hold weight measurements. Three questions about what you could actually send us.

First — when a measurement arrives, do you record how it was taken? Clinic scale, connected device, or the patient typing a number in?
Partner · K. Reyes

We store the source device ID. If it came from the app manually there’s a flag, but we don’t surface either in the export today.

Mapped → catalogue

L2.MEASUREMENT.method  ·  identity: stable pseudonym  ·  temporal: longitudinal  ·  scope: self-selected

Held at source, not transmitted. This is a specification change, not a new collection. Serves D-05 monitoring sustainability and D-07 response shape.

That’s a change to what you send rather than what you collect. Second: if someone stops sending measurements, do you know why, or only that they stopped?
Partner · K. Reyes

Only that they stopped. We’d see the device go quiet.

Gap flagged → L2.EXIT.attrition_reasonInformative attrition risk. Measurement stops when engagement stops and engagement tracks the outcome, so any persistence figure from this feed alone would improve as the picture worsens. Fitness verdict will read BLOCKED for D-01 persistence until resolved.
Interviewer may interject at any point…Send
Live profile
ArchetypeP03 remote monitoring
Elements offered14
Mapped12
Unmapped2
Journey stages3 of 14
Linkage rungL1
Coverage against the estate
Monitoring
88% overlap with an existing partner
Body composition
new to the estate
Exit reason
not offered
Draft confidence card
Shown to the decision owner before signatureAny figure from this partner will not be able to tell you why measurement stopped, or whether the person stopped treatment.
Agentic session · M1 interview v7Transcript recording1 gap flaggedP-24 · block 3/9 · 18:04

Layer 1 · Partner portfolio

The review that had stalled for two cycles. Positions are computed from the catalogue rather than scored by hand, and the quadrant carries an action rather than a rank.

Partners Portfolio Current cycleExport packCycle historyOpen reviewStrategic contribution × current delivery
MatrixListCoverageChangesOverrides
Partnerships2314 with feeds
Fix quadrant9largest pool
Proposed exit6
Feeds at L011of 14
Fix the specification · 9Deepen · 4Exit or transactional · 6Harvest · 4P07P03P0601a04a02b01b04bP0502aP0806b03bV1V2V3V4V5V6H1H2H3H4
Scarce evidence, poorly delivered Scarce evidence, well delivered Abundant, low uniqueness Neither
Fix quadrant · ordered by what it would take
PartnerUnique contributionFailingChange neededOwner
P07 Patient supportOnly structured route to stop reasonstaxonomySpecificationM. Doyle
P03 Remote monitoringObjective longitudinal measurementattrition reasonSpecificationM. Doyle
P06 HCP workflowProfessional-side behaviourno patient joinLinkage L2
01a TelehealthPrivate-route visibilitytimestampsSpecificationR. Bell
Changed this cycle
02a moved to Deepen

Denominator fixed. Fitness now passes for three decisions.

Two candidates assessed

One declined on 88% coverage overlap with an existing partner.

Blocked publications
Blocked this cycle4
Overridden1
Override loggedSteering deadline. P03 persistence figure published with the ceiling stated. Reason recorded against S. Iyer.
Action per quadrant
Deepen4
Fix specification9
Harvest4
Exit6
Positions computed from catalogueLast refresh 04:121 override pending monthly reviewCycle Q-current · 23 partners

Layer 2 · Conformance gateway

Feed health across the estate. The column that matters is the last one — a feed can pass every quality dimension and still be unfit for the decision it was acquired for.

Data Feeds AllFilterContract registry2 quarantinedFeed conformance · 14 active
FeedsDriftRightsQualityFitness
Arriving on schedule12of 14
Quarantined1
Fit for all decisions4
Blocked publications4
FeedArrivalSchemaDriftRightsQualityContractState
P02a dispensingon timepassnone7/76/64 fitpublishing
P03 devicecontinuouspassnone7/76/61 fit · 2 blockedpartial
P07 supportmonthlypassnone5/75/61 fit · 2 blockedpartial
P04a behaviourweekly3 fields2d ago7/75/6blockedquarantined
P01a telehealthnightlypassnone6/76/62 fitpublishing
P06 HCP workflowweeklypassnone7/76/62 fitpublishing
P08 RWEquarterlyn/an/a7/7stated1 fitpublishing
P05 navigationn/ano feed
P04a · drift detected, feed quarantinedThree fields changed shape without notification. engagement_score moved from a 0–100 scale to a five-point band; two fields added. Last good publication stands, marked stale. Remediation request drafted — awaiting a person to send it.
P03 · selected
Every quality dimension passes

Completeness 98% · validity 100% · consistency 99% · timeliness continuous · uniqueness 0.1% · accuracy unverifiable.

Two contracts unsatisfied

D-01 persistence requires an acceptable-bias term this feed cannot meet: attrition correlates with the outcome and no attrition reason is captured.

D-03 stop analysis requires a reason the feed does not carry at all.

Satisfies D-07 response shape, whose contract tolerates the same bias.

Quality is not fitnessSix dimensions green, one red. A quality dashboard reports this feed as healthy because quality is a property of the data. Whether it satisfies a contract is a property of the pairing.
Pipeline
Landok
Validateok
Map to canonicalok
Rights checkok
Fitness2 blocked
Publishpartial
1 feed quarantinedDrift detection M3 · last run 06:00Rights engine deterministic14 feeds · 187 catalogued elements

Layer 4 · Evidence watch

The quiet one. Nobody goes back to check whether a blocked question has become answerable. This watches for the moment a question becomes answerable, and for the moment a published figure stops being safe.

Work Evidence watchSubscribeRe-run 3 figuresWhat changed this cycle
ChangesWaitingRetiredRules
Newly answerable
Is a persistence dip real, or a stock artefact?

The pharmacy partner began sending supply-interruption markers last month. Two periods previously read as demand softening resolve as stock gaps.

Three published figures should be revisited.

Re-run the three
Where is provision thinnest?

Reference data refreshed. Two areas previously below the reporting floor now clear it.

Newly blocked
Behaviour programme engagement

The partner changed its engagement definition and did not restate history. Any trend spanning the change is uninterpretable.

Two dashboards affected, both marked.

Still waiting
QuestionBlocked onCyclesStatus
Do outcomes differ by comorbidity?Comorbidity burden1specification drafted
Cost per persistent patientSupply route · channel vocabulary3no owner
Which prescribers under-escalate?Patient–prescriber join4needs linkage
Does support extend treatment?Selection, not datanot solvable here
What the watch monitors
New fields arrivingon
Definition changeson
Reference data refreshon
Rights position changeson
Linkage rung changeson
Assessment

Two of the four waiting questions have sat unowned for three cycles or more. Neither is a data problem. Both need somebody to make a contractual decision.

Retired this cycle
Q-2455 channel mixsuperseded
Q-2301 device uptakeno owner, 6 cycles
2 newly answerable1 newly blocked · 2 dashboards marked4 questions waitingCycle close · next scan in 6 days

What it is built on

No new platform. A thin application layer over what the affiliate already runs, with the catalogue as the only new system of record.

Architecture
Layer What it is Build or reuse Why
Arrival store Immutable object store, one object per arrival, fingerprinted Reuse Arrival is a fact and must survive a failed load.
Warehouse The existing analytical warehouse Reuse Replacing it was proposed and declined. Nothing about the problem is a warehouse problem.
Orchestration Existing scheduling and pipeline tooling Reuse Gateway stages run as ordinary pipeline steps.
Catalogue and spine Metadata store holding elements, grain, rights, decisions, denominators, fitness Build Nothing existing holds a rights position as structured values or a fitness verdict per decision.
Rules engine Deterministic checks, benchmark scoring, fitness logic Build, small The most important logic in the system, and none of it is a model.
Model services Six models behind a confirmation step Integrate Swappable. Each degrades to the manual process that preceded it.
Application Six screens Build Deliberately small. The value is in the spine.
Identity and access Existing enterprise identity Reuse Named accountability needs named users, which already exist.
Two of the eight are new and one of those is small. The affiliate had been offered a partner-data platform twice, and both proposals failed because the missing thing was never infrastructure.