Proving what a partner is worth when the product sells itself
Know which decisions your partner ecosystem can actually support — before you make them.
Twenty-three digital health partnerships, fourteen supplying data, and no defensible way to value any of them. Demand already exceeded supply, so nothing a partner did to generate demand could be counted as value. The work rebuilt partner ROI around the four things that remain when acquisition is worthless.
at the start of the work
3 to a written specification
rights position
evidence behind them
ever been stated as a number
The argument
Before the evidenceTwenty-three digital health partnerships. Fourteen sending data, three to a written specification. The annual portfolio review stalled at the first question — what is each of these worth — and stayed stalled for two cycles.
Why the usual answer does not work
Both partner business cases in the estate counted the same thing: people the partner reached who went on to start treatment. That assumes demand is the constraint. Here supply is.
Where growth can come from instead
What the discovery found
The estate is sparse, not duplicative
The brief said rationalise. Six of fourteen journey stages are seen by more than one partner and two are seen by none. On a cost report the two look the same. The brief was written on that reading.
Four decisions of twenty-seven had evidence
Seventeen interviews produced twenty-seven decisions people said they make with partner data. No decision owner had ever specified what evidence would change their mind.
Eleven of fourteen feeds cannot be joined
Every partner emits its own subject identifier, two rotate, no agreement mentions stability. Nine decisions need a cross-partner view and all nine sit above that ceiling.
The two strongest fields are collected and never sent
Comorbidity is the eligibility gate here — BMI with a weight-related comorbidity is what qualifies someone. Two partners assess it and neither transmits it. Payer type is absent from every feed.
What was designed
| What it is | What it settled | |
|---|---|---|
| Three layers | What exists in the health system of record, what a partner can transmit, and what the affiliate builds afterwards | That patient master data and partner data are different objects. Collapsing them was the original error. |
| Receivable grain | What the affiliate can get is a property of the relationship, on three independent axes | The same element has a different grain from two partners who both hold it. |
| Assessment instrument | Interviews a prospective partner and maps their offer onto the catalogue before contracting | Whether a candidate adds evidence or duplicates it. |
| Conformance gateway | Four tests: contracted grain, received grain, usable grain, fitness for a named decision | A feed can pass the first three and fail the fourth. That is the normal case. |
| Confidence card | Attached to every published figure — grain, denominator, observability, bias, and what it cannot tell you | The care taken upstream survives into the room where the decision is made. |
Where the machine work went
capabilities built, six using a model. Everything else is deterministic rules, including the two pieces of logic the system most depends on.
declined. Six on governance or accountability rather than capability, and all six would have worked technically.
stages scored separately per activity. Most activities scored high on the first two stages and low on the last two.
What did not work
- The first workshop nearly failed. For the first hour they listed activities. Monitor partner performance. Improve adherence. I dropped the word decision and asked for the shape instead: who chooses, between what, by when, and what goes wrong if they choose badly.
- Three of eight functions never picked the work up. Neither could be served until data that nobody sends starts arriving.
- The largest single benefit rests on a number nobody measured — two to three days a month of one analyst’s time, reconstructed from artefacts. Measuring it properly was the first recommendation.
What it added up to
| Outcome | n | What it needs |
|---|---|---|
| Answerable once definitions were fixed | 6 | Nothing. Blocked on disagreement, not on data. |
| Needs a change to what partners send | 9 | A specification. The cheapest tranche. |
| Needs a change to linkage permissions | 5 | Contractual and consent. No engineering route. |
| Not answerable from partner data | 3 | Reassigned to primary research. |
| Not a decision | 4 | No owner, no moment of choosing, no cost of being wrong. |
The problem with proving partner value
FramingTwenty-three partnerships, and an annual review that had not been completed for two cycles.
The partnerships had accumulated across four years. Each was signed for a defensible reason. None was signed against a portfolio, and no two were structured the same way. Fourteen sent data back; three of those to a written specification. When the affiliate tried to run a portfolio review, it stalled at the first question and stayed stalled for two cycles.
Why the usual answer does not work here
The business cases in this estate were written as acquisition stories. The partner reaches people, some of those people start treatment, and you count them. Cost per initiation, share of new starts, incremental volume.
None of it applies to a product that is supply-constrained and demand-saturated. When more people want the medicine than can be supplied, a partner delivering initiations has moved demand around rather than created it. The patients they bring would have arrived through another route. Counting them produces a number that rises with partner spend and means nothing, and two of the partner business cases in the estate were built exactly that way.
The reframe. So demand was not available as a measure. Value has to be found in what happens after someone starts — how long they stay, what the service costs to run, what evidence the relationship generates, and what the affiliate learns that it could not learn otherwise. Five value classes, none of them acquisition.
The second complication: the partners want something too
Most of the fourteen are not passive suppliers. They want to be data partners in the full sense — sending data, receiving insight back, and building an analytics proposition of their own on the combined picture. Several asked for it explicitly during discovery. Three had it written into their agreements in terms nobody had operationalised.
Exchange has to be designed in both directions, because a partner with no reason to care about data quality will not maintain it. And the affiliate has to be deliberate about what it is helping a partner build, since insight returned to a partner operating across several manufacturers is a different proposition from insight returned to an exclusive service provider. Two of the twenty-three fall into the first category.
What the framework had to do
| Job | Why it comes here | |
|---|---|---|
| 1 | State each partner’s value in terms that survive a saturated market | Without this there is no basis for any portfolio decision, and the review stalls exactly where it stalled. |
| 2 | Separate strategic contribution from current performance | These are different axes and they were being collapsed into one score. A partner supplying scarce evidence badly is not the same as a partner supplying abundant evidence well, and the two need opposite responses. |
| 3 | Optimise the high performers rather than only rank them | Ranking produces a cut list. Most of the available value in this estate came from specification changes to partners the affiliate was already paying. |
| Artefact | What it is | What it settled |
|---|---|---|
| Partner value model | Five value classes, each with a counterfactual test and a measure | That a partner can be valued at all in a saturated market, and how |
| Data-to-insight chains | How each data category converts into a decision and then into value, with the market relevance of each | The question nobody had answered: what is this data actually for |
| Strategic × performance matrix | All 23 plotted on contribution against delivery, with a named action per quadrant | Which partners to deepen, fix, harvest or exit — and that the fix quadrant was the largest |
| Canonical data spine | Three layers, 187 catalogued elements, with receivable grain per relationship | That patient master data and partner data are different objects |
| Decision inventory | 27 decisions, owners named, evidence stated | What the estate is actually being asked to answer |
| Assessment instrument | An agentic intake that interviews a partner and returns a value profile | Whether a candidate adds value — before contracting |
| Conformance gateway | Four tests from contracted grain to decision fitness | That a feed can be valid, compliant and worthless |
| Partner value report | Generated per partner, per cycle, from the spine | The review that had stalled for two cycles |
Findings
Ordered by how much each constrains the restEleven. The first three make the others unavoidable, and F-01 is the reason the engagement changed shape in week two.
No decision owner had specified what evidence would change their mind
Seventeen interviews produced 27 decisions people said they make with partner data. Four had any evidence attached that the person could point to. The rest ran on relationship history, partner-supplied reports, or the fact that the partnership already existed.
This is upstream of every other finding. Without a specified evidence requirement there is nothing to put in a partner specification, and no basis for saying one dataset is worth more than another. It is also why the estate looks like sprawl from a finance report — undifferentiated cost is what an unprioritised portfolio looks like from outside.
Every partner emits its own subject identifier and none is guaranteed stable
Fourteen feeds, seven identifier schemes. Two rotate on re-registration. One is derived from an email address. None of the agreements mentions identifier stability, so none of the partners is obliged to maintain it and two had changed scheme without notification.
It removes any possibility of following a person across two partners, and it puts a ceiling on what the estate can answer that no amount of engineering will lift. Nine of the 27 decisions need a cross-partner view; all nine sit above that ceiling today.
Rights sit in prose across seven drafting patterns
What a partner may collect, what the affiliate may receive, at what grain, for which purpose, for how long, and whether anything may be combined with anything else — all of it in agreement text, phrased differently in every agreement.
Two consequences. No portfolio question can be answered without reading twenty-three documents, so nobody asks portfolio questions. And a proposed analysis cannot be checked against its rights position before it is commissioned, so the check happens afterwards, under time pressure, with an expectation already formed.
Two journey stages are unobserved by any partner
Tolerability and stop-reason. Both are captured somewhere in the estate and neither is captured usably: tolerability appears in P04 symptom logs from an engaged population and in P07 call notes as free text; stop-reason appears only in P07, unstructured, with no taxonomy.
These are the two highest-value evidence categories in this therapy area. The estate can measure that people stop. It cannot say why.
Device measurement stops when engagement stops, and engagement predicts the outcome
The P03 feed shows mean weight change improving over time. It does so partly because people who are not doing well stop weighing themselves. People who are not doing well stop weighing themselves, so the sample cleans itself over time.
This is informative censoring rather than ordinary missingness: the probability that a value is missing depends on the value. Nothing in the pipeline flags it, the number looks plausible, and it had already been used twice in internal reporting.
Funding route is absent from every feed and it conditions everything
Whether a person reached treatment through an NHS specialist service, a private clinic, an online provider or self-pay determines their cost exposure, their monitoring, their likely persistence and whether they appear in any given partner's data at all. No feed carries it.
Without it, every cross-partner comparison silently compares different populations, and every persistence figure is a weighted average of routes with very different economics.
Three functions run three different denominators
Commercial counts people who have a prescription event. Medical counts people with a confirmed first dose. Market access counts people present in the partner's cohort at period start. All three call the result “patients on treatment” and the three numbers differ by roughly a fifth.
Nobody is wrong. The definitions were each built for a legitimate purpose and none was written down, so the disagreement surfaces as a credibility problem in meetings rather than as a definitional one that could be settled.
Safety recognition sits with partner staff who were never trained for it
Four partner surfaces can receive content a patient writes. On three of them, a partner employee decides whether what they are reading is potentially reportable. That is a trained judgement, placed with people who have no obligation to hold it and no way to evidence that they exercised it.
The items judged not to be reportable leave no record anywhere, so the false-negative rate is not merely unknown — it is unknowable from inside the current design.
The reconciliation is one person and it appears in no system
Two to three days a month assembling the partner pack: pulling seven sources, resolving three denominators, checking the numbers against last month, and rebuilding anything a partner has changed. It is skilled work and the only place the whole estate is held in one view. It appears in no process document and no capacity plan.
Two funded arrangements never entered the partner register
The register is built from procurement, so a party enters when a purchase order is raised. Two arrangements — one grant-supported service and one co-developed content programme — generate no purchase order and appear nowhere.
Nothing published carries what it cannot tell you
Every figure that reaches a decision-maker arrives bare. No denominator, no observability window, no coverage, no known bias. The care taken upstream over grain and rights evaporates at the last step, which is the only step the decision-maker sees.
The ecosystem, and the spine that models it
Locked modelFive master layers, eight partner archetypes, one chain. Every table, dossier, benchmark and diagram in this document resolves to it, and nothing enters the catalogue that cannot be placed on it.
The three data layers, kept separate
Collapsing these was the affiliate's original error. A "patient master" inside a pharmaceutical affiliate is usually a category mistake — the affiliate holds neither the identity nor the right to hold it.
| Layer | What it is | Who holds it | What the affiliate can do with it |
|---|---|---|---|
| L1 Ecosystem master | What exists in the healthcare system of record: patient, HCP, organisation, site | NHS and professional-regulator reference sources; partners with a clinical relationship | Reference and validation only. Codes, vocabularies and status can be consumed; person-level records generally cannot. |
| L2 Partner-receivable | What a partner can lawfully transmit under this relationship, at a stated grain | The partner, bounded by the agreement | The working material. Everything the affiliate actually analyses starts here. |
| L3 Decision dataset | What the affiliate needs after joining, transforming, aggregating and enriching | The affiliate | The object a decision is made from. Derived, versioned, and carrying its own confidence record. |
Reading down that table produces the design constraint that shaped the product. The affiliate's analytical capability is bounded not by L1 or by what partners hold, but by L2 — and L2 is negotiated, not engineered. Changing it means changing an agreement, which is slow, which is why the assessment instrument sits at contracting rather than at integration.
Settling what the affiliate can actually reach
Two weeks of the discovery went on a question that sounds administrative and turned out to be structural: for each thing in the reference layer, is it something the affiliate can obtain, something a partner can obtain, or something nobody in this arrangement can obtain at all. The catalogue had been drafted without asking, and the draft treated national patient identity as a field the affiliate might one day populate.
Working through it with Privacy and with two partners produced the split below, and the split is the reason the model has two columns where most catalogues have one.
| Source | Class | What it establishes | What it does not give the affiliate |
|---|---|---|---|
| National patient demographic service | National service | The national record for patient demographics and the NHS number used to match a person to their health record | Access. PDS requires an NHS-facing organisation, a legitimate relationship and an approved use case. A partner with a clinical system may reach it; the affiliate does not. |
| National organisation directory | Reference data | Organisation and site codes, organisation roles, relationships, open/closed status, and practitioner-to-organisation relationships with active status | Clinical content. It is a directory, not a care record. |
| Professional regulator registers | Regulator register | Professional identity, registration number, registration status, profession and specialty where published | Employment, current place of work, or prescribing rights in a given service. Those come from the employer or the service configuration. |
| Clinical guidance body | Regulator guidance | Clinical eligibility criteria, measurement recommendations and the intervals at which measurements are clinically expected | Data-engineering thresholds. A clinical recommendation to measure annually is not a completeness target. |
| UK interoperability profile | Interoperability standard | Resource shapes, terminology bindings and identifier systems that make a feed interpretable without bespoke documentation | Any guarantee that a partner uses it. Two of fourteen feeds did. |
| Pharmacovigilance guidance | Regulator guidance | Obligations for handling and screening potential adverse reaction reports, including in digital media under the company’s management or sponsorship | Discretion about which partner surfaces are in scope. Sponsorship is the trigger, not control of the surface. |
The system of problems
Second-order effectsThey are four chains with a common origin, and reading them as a system is what stopped the work becoming a data-quality programme.
The human failure modes present here
| Mode | How it appears in this estate | Why it was reasonable at the time |
|---|---|---|
| Measurement error | Receipt of data counted as value. The estate is reported by volume of feeds and records, not by decisions served. | Volume is the only thing that was measurable without a decision inventory. |
| Data error | “We have the data” treated as “the data is usable”. Six of fourteen feeds are technically present and four are unusable for the question being asked of them. | The feeds are real, arrive on time and pass validation. Nothing about them looks wrong. |
| Ownership error | No single owner for the estate. Each partnership has a business owner; the portfolio has none. | Each partnership was individually justified and individually owned, which is correct until there are eleven. |
| Local optimisation | Partners optimise the metrics they report on, which they also define. | Nobody issued a specification, so partners reasonably reported what they could measure well. |
| Historical carry-over | The monthly pack retains four charts nobody uses, because removing one requires knowing who relies on it. | The pack grew by accretion and no forum ever owned its contents. |
| Change error | Onboarding a partner is treated as an integration event. It is a specification event with an integration afterwards. | Integration is the visible, hard, technical part. Specification looks like paperwork. |
The partner value model
Five classes, no acquisitionEach class carries a counterfactual test: what would have happened without this partner.
Three tiers, five classes
The five classes are the operating unit — each has its own counterfactual test and its own measure. They sit in three tiers, and the tier decides how a claim in it can be defended.
Direct economic value
Duration · Efficiency
Moves money in the current period. Defensible with a measurement and a comparator.
Knowledge and option value
Evidence · Intelligence
Buys the ability to answer something later, or to allocate better now. Real, and it cannot be defended with a single number.
Risk-adjusted value
Risk
Loss avoided. Visible only when it fails.
The tiers exist because the three are argued differently. A partner strong only in the second tier will lose a cost review against one strong in the first, regardless of which contributes more, unless the difference is named before the conversation starts.
| Class | What it is | Counterfactual test | Measure | Lands as | Partners |
|---|---|---|---|---|---|
| Duration | People stay on treatment longer because of something the partner does | Would this cohort have persisted at the same rate through another route? | Persistence at 12 / 26 / 52 weeks against a matched or historical comparator | Revenue, directly. The strongest claim available. | P01 P02 P04 P07 |
| Efficiency | Work the affiliate would otherwise do, done by the partner more cheaply or not needed at all | Would the affiliate have had to do this, and at what volume? | Contacts handled, HCP time released, fulfilment failures avoided | Cost displaced. Easy to measure, easy to over-claim. | P02 P07 |
| Evidence | Real-world evidence that supports access, guideline position or label | Could this evidence be generated another way, and at what lead time? | Evidence packs accepted; questions answerable that were not | Revenue protected or unlocked, on a long lag | P08 P03 P06 |
| Intelligence | Decision quality: who is being treated, where demand actually sits, where the journey fails | What would we have decided without this, and would it have been wrong? | Decisions made with traceable evidence; decisions reversed on new evidence | Better allocation. Real, and the hardest to put a figure on. | All 14 feeds |
| Risk | Safety detection, compliance posture, supply visibility | What is the exposure if this signal arrives late or not at all? | Detection timeliness; screening coverage; consistency | Loss avoided. Only visible when it fails. | P01 P04 P07 |
Where each partner archetype can generate value
| Archetype | Duration | Efficiency | Evidence | Intelligence | Risk | Where its value actually sits |
|---|---|---|---|---|---|---|
| P01 Telehealth | Strong | Moderate | Moderate | Strong | Strong | Intelligence on the private route, which the affiliate sees nowhere else |
| P02 Pharmacy | Strong | Strong | Moderate | Strong | Low | Duration. The refill interval is the most defensible persistence measure in the estate. |
| P03 Device | Moderate | Low | Strong | Moderate | Low | Evidence. Objective longitudinal measurement is scarce and this is the only source of it. |
| P04 Behaviour | Strong | Moderate | Moderate | Strong | Moderate | Duration, if the selection problem can be handled. Currently unprovable. |
| P05 Navigation | Low | Moderate | Low | Strong | Low | Intelligence. Demand geography and provision gaps, available nowhere else. |
| P06 HCP workflow | Moderate | Strong | Moderate | Strong | Moderate | Intelligence on clinical inertia. The most under-exploited relationship in the estate. |
| P07 Patient support | Strong | Strong | Moderate | Strong | Strong | All five. The smallest contract in the estate and the only source of stop reasons. |
| P08 RWE | Low | Low | Strong | Moderate | Low | Evidence, and only evidence. Correctly. |
What the data is actually for
Data to insight to valueThe question the affiliate could not answer, and the reason the catalogue had 187 elements and four in real use. Every chain below runs the same way: a data category, the insight it produces, the decision that insight moves, and the value class it lands in.
The eleven chains, in order of what they are worth here
| # | Data category | The insight it produces | The decision it moves | Value class | Market relevance | State |
|---|---|---|---|---|---|---|
| 1 | Refill interval, stop event, stop reason | Where in the course people leave, and why. Stay-time by cohort, route and dose stage. | Where to put support; which partner to deepen; what the service must do at week 8 | Duration | Highest. In a chronic therapy at supply constraint, duration is the only growth lever available and the industry measures it badly. | Stop reason absent |
| 2 | Eligibility, funding route, channel, geography | Who is actually being treated against who is eligible. Where demand is unmet and where it is displaced. | Where to invest channel effort; which route to support; where provision is thin | Intelligence | High. Segmentation from real treated populations rather than from claims panels or survey proxies. | Funding route absent |
| 3 | Titration stage, dose holds, escalation timing | Where people stall below target dose, and whether stalling is tolerability or inertia | Where clinical education lands; what support content is needed and when | Duration Evidence | High. Under-dosing is a recognised and quantifiable value leak in titrated therapies. | Escalations only |
| 4 | GI symptom reports, burden, coping | What the first eight weeks feel like, and which experiences precede stopping | Support design; content; where a human contact is worth its cost | Duration | High. The dominant stop driver, and almost never captured structurally. | Free text only |
| 5 | Weight and body composition trajectory | Response shape over time, and the point at which trajectory predicts exit | When to intervene; what a realistic outcome curve looks like by segment | Evidence | High. Objective longitudinal outcome data is scarce and valuable to payers. | Attrition-biased |
| 6 | Support contact volume and reason | What is going wrong at scale, and what the service costs to run | Where self-service works; where partner support displaces affiliate cost | Efficiency | Moderate. Straightforward, immediately actionable, easy to over-claim. | Reason free text |
| 7 | HCP initiation and escalation behaviour | Clinical inertia by professional segment; who starts and who does not escalate | Where field and education effort should go | Intelligence | High. The most under-exploited data class in the estate and the closest to commercial decisions. | Not captured |
| 8 | Search, referral and provision geography | Where demand exists and where care is not available to meet it | Access strategy; where to support provision | Intelligence | Moderate. Demand signal rather than population, and useful precisely because it is early. | Available |
| 9 | Fulfilment failure, supply interruption | Whether a cohort-wide gap is behavioural or structural | Supply planning; whether a persistence dip is a real signal | Efficiency Risk | Moderate. Becomes critical during constraint, which is when it is most often missing. | Not distinguished |
| 10 | Patient-reported outcome, experience | Patient-valued outcomes beyond the clinical endpoint | Evidence packs; service design | Evidence | Moderate and rising. Increasingly expected in access conversations. | Aggregate only |
| 11 | Safety-relevant content across surfaces | Whether detection is consistent and timely across the estate | Screening cadence; where recognition sits | Risk | Non-negotiable. Not a value question but a licence-to-operate one. | Partner-side |
The pattern. Ranked by value, the top four are duration and segmentation. Ranked by what the estate can supply, they are geography, contact volume, engagement and aggregate outcomes.
Two worked examples
Stay-time
Refill intervals give the exit date, contact reasons give the why, and titration stage gives the point in the course. Together they produce a stay-time curve broken down by dose stage, funding route and support exposure — which is the single most commercially useful object the estate could produce, and it needs three fields that no partner currently sends.
The value is direct. In a chronic therapy where supply caps the patient count, a shift in median duration moves revenue with no change in demand at all. It is also the one thing the affiliate can influence, since the drivers are service and support rather than access.
What it needs: a stop-reason taxonomy at the point of contact; failed fulfilment distinguished from a patient-initiated gap; a denominator fixed at enrolment. All three are specification changes to partners already under contract.
Segmentation and demand
The affiliate segments on prescriber and on claims-derived proxies. Neither sees the private route, which is where a large share of treated patients in this therapy area actually sit, and neither sees eligibility — only people who reached treatment.
Partner data can produce a treated-population view with funding route, entry channel, geography, dose trajectory and duration attached. That supports demand shaping under constraint, which is a different exercise from demand generation and considerably more useful when supply is the binding limit.
What it needs: funding route on every initiation event, a controlled channel taxonomy issued by the affiliate rather than seven partner-defined ones, and outward-code geography. Two are specification changes; one needs a privacy determination already drafted.
How patient data becomes growth
Master use-case listRevenue in this therapy area is patients multiplied by months multiplied by dose realised. Supply caps the first term and the third is set elsewhere. That leaves two movable terms and a fourth lever — cost to serve — and partner data is the only instrument that reaches any of them.
Thirty-three use cases
Grouped by the lever each one moves. The state column is what the estate can support today.
| Use case | Data required | Insight produced | Who uses it | Value | State |
|---|---|---|---|---|---|
| EXTEND DURATION · the largest movable term | |||||
| Stay-time curve by cohort | refill interval, enrolment date, stop event | Median and distribution of months on treatment, by segment | Medical, Commercial | Direct revenue | Partial |
| Stop reasons, attributable | contact reason, stop event, titration stage | Why people leave, and at which point in the course | Medical, Digital | Direct revenue | Blocked |
| First-eight-week burden | symptom reports, contact volume, dose stage | What the hardest part of starting actually feels like | Digital, Medical | Direct revenue | Free text |
| Early-warning of exit | measurement frequency decline, contact pattern, refill gap | Which people are about to stop, while there is still time | Digital | Direct revenue | Needs L2 |
| Support exposure against persistence | programme enrolment, refill interval | Whether support changes duration, with selection stated | Medical | Direct revenue | Needs L2 |
| Route-level persistence | funding route, refill interval | Whether one access route holds people longer than another | Commercial, Market access | Direct revenue | Route absent |
| Supply gap vs behavioural gap | fulfilment failure, supply period marker, refill | Whether a persistence dip is real or an artefact of stock | Supply, Commercial | Avoids a wrong decision | Not distinguished |
| Restart rate | stop event, subsequent dispense | Whether stopping is permanent or an interruption | Medical | Direct revenue | Not captured |
| Plateau management | weight trajectory phase, contact reason | What happens when the curve flattens and people reassess | Medical, Digital | Direct revenue | Not derived |
| REALISE DOSE · supply consumed without benefit delivered | |||||
| Titration completion rate | titration stage, dates | How many reach target dose, and how long it takes | Medical | Efficacy per unit supplied | Partial |
| Where people stall | dose holds, reductions, escalation delay | The specific step at which escalation stops | Medical, Digital | Efficacy per unit supplied | Not captured |
| Stall cause split | dose holds, symptom reports, HCP escalation behaviour | Tolerability, patient choice, or clinical inertia | Medical | Targets the right intervention | Not captured |
| HCP escalation profile | prescriber ID, escalation events per course | Which prescribers escalate and which do not | Medical, Field | Directs education | Not captured |
| Dose-response by segment | dose stage, weight trajectory | What benefit each step actually delivers, in the real world | Medical, Market access | Evidence | Attrition-biased |
| Supply efficiency | dose realised, units dispensed | Benefit delivered per unit of constrained supply | Supply, Commercial | Allocation | Derivable |
| ALLOCATE BETTER · the same patients, better chosen | |||||
| Treated vs eligible | eligibility assessment, initiation | Who reaches treatment and who does not | Commercial, Market access | Allocation | Partial |
| Funding route mix | funding route on initiation | How much of the treated population sits outside the NHS route | Commercial | Allocation | Absent |
| Demand geography | search, referral, provision, dispensing location | Where demand exists and where care is available to meet it | Commercial, Access | Allocation | Available |
| Provision gap map | HCP and site directory, demand signal | Where there is no realistic route to treatment | Access, Medical | Allocation | Available |
| Channel economics | acquisition channel, persistence, cost to serve | Cost per persistent patient by route, not per initiation | Commercial | Allocation | Needs L2 |
| Segment persistence profile | segment attributes, refill interval | Which segments stay and which churn | Commercial | Allocation | Partial |
| Unmet need shape | eligibility, non-initiation, reasons | Who is eligible and never starts, and why | Market access | Access strategy | Not captured |
| Prescriber conversion | eligible patients seen, initiations | Conversion at the prescriber, not at the territory | Field, Medical | Allocation | Not captured |
| Waiting and friction | assessment date, consultation date, dispense date | Where the journey slows and by how much | Digital, Access | Allocation | Derivable |
| Competitive displacement | switch events, prior therapy | Movement in and out of the class | Commercial | Allocation | Not captured |
| Supply allocation model | demand geography, persistence, route | Where constrained supply produces the most benefit | Supply, Commercial | Allocation | Needs L2 |
| SPEND LESS · cost to serve per persistent patient | |||||
| Contact reason distribution | contact reason taxonomy | What goes wrong at scale, ranked | Digital, Patient services | Cost displaced | Free text |
| Self-service deflection | contact reason, content engagement | Which contacts a good answer online would have prevented | Digital | Cost displaced | Partial |
| Fulfilment failure cost | failed fulfilment, downstream contact | What a missed delivery costs in support and in persistence | Supply, Patient services | Cost displaced | Not distinguished |
| HCP time released | tool usage, query deflection | Professional time not spent on things the tool answers | Medical, Field | Cost displaced | Available |
| Support intensity by cohort | contact volume, segment, stage | Where a human contact is worth its cost and where it is not | Patient services | Cost displaced | Partial |
| GENERATE EVIDENCE · long lag, high ceiling | |||||
| Real-world outcome curves | weight trajectory, duration, denominator | Outcomes as they actually occur outside a trial | Market access, Medical | Access, reimbursement | Attrition-biased |
| Patient-valued outcomes | PRO instruments, experience | Outcomes patients care about, alongside clinical ones | Market access | Access | Aggregate only |
| State | Count | What it means |
|---|---|---|
| Available | 6 | Answerable now, once definitions are fixed. Start here. |
| Partial | 8 | A re-cut or an added field from a partner already sending data. |
| Blocked or absent | 19 | Fourteen need a specification change; five need linkage the estate does not have. |
Six of thirty-three are available today. The estate was assembled without a decision inventory.
The portfolio decision
Strategic contribution against deliveryTwo axes rather than one score. A partner supplying scarce evidence badly and a partner supplying abundant evidence well look identical on a single ranking, and they need opposite responses.
| Axis | Built from | Deliberately excluded |
|---|---|---|
| Strategic contribution | Uniqueness of the evidence within the estate · number of the nine carried decisions it serves · value class where it is strong · whether the coverage it provides exists anywhere else | Contract value. Relationship history. How much data arrives. |
| Current delivery | Fitness for the decisions it is meant to serve · quality across the six dimensions · grain against contracted grain · latency · whether a specification exists at all | Partner-reported activity metrics, since those measure the reporting rather than the delivery. |
What each quadrant gets
| Quadrant | n | Action | What is done first | What is deliberately not done |
|---|---|---|---|---|
| Deepen | 4 | Extend scope and co-design the next data element | Joint roadmap on the two elements each could add; longer contract term in exchange | No new commercial ask. These relationships are working and the risk is disturbing them. |
| Fix the specification | 9 | Change the grain, not the partner | Issue a specification from the catalogue at the next renewal; three of the nine agreed to it mid-term | No cutting. Every one of these would fail a cost review and every one holds something scarce. |
| Harvest | 4 | Automate ingestion, spend no relationship effort | Full gateway automation; remove from the review cycle entirely | No deepening. Additional attention here returns nothing. |
| Exit or make transactional | 6 | Convert to a simple purchase or end at renewal | Strip the data expectation from four; two proposed for exit | No remediation attempt. Fixing a partner with nothing unique to offer is the most common waste in these estates. |
What the matrix changed. The review that had stalled produced a decision in one session once the two axes were separated. The instinctive move — rank by cost, cut the tail — would have removed six of the nine partners holding scarce evidence and kept three of the four harvest partners on full relationship effort.
Stating a partner’s value
The assembly, workedNo monetary figure. A value position with a stated counterfactual can be defended. The two business cases in circulation were derived from a baseline nobody measured.
| Partner | Strongest value class | Counterfactual | Delivery today | Position |
|---|---|---|---|---|
| P02a Pharmacy | Duration · refill interval is the persistence backbone | Replaceable in principle by another dispensing partner, but not at this cohort completeness | Strong — full cohort, daily, stable identifier | Deepen |
| P07 Support | Duration Risk · the only structured route to stop reasons | Not replaceable without building the contact capability in-house | Poor — free text, monthly, no taxonomy | Fix the specification |
| P03 Device | Evidence · objective longitudinal measurement | Hard to replace; no other objective outcome source exists | Poor for its purpose — attrition-biased, no measurement method | Fix the specification |
| P08 RWE | Evidence · cohort outcomes with a stated denominator | Replaceable by other evidence providers on comparable terms | Strong — specified, denominated, on schedule | Deepen |
The business intelligence tools
Question-led intelligence · cohort designSeparate tools with separate jobs. One starts from something a person was asked and finds whichever evidence answers it — usually not a cohort. The other starts from a population somebody already knows they need, and tests whether partner data can carry it. Neither routes into the other.
Question-led intelligence
Ten questions of the kind an insight team receives. Each shows what the question becomes once it is made honest, the evidence it needs, what came out, and where it breaks. Three of ten are answerable from what partners send today.
You asked why. This estate can only tell you why among people who made contact before leaving — a reason mix among contactors, never a population rate. Reframed on that basis.
An exit date and a reason, attached to the same person
Supply gap patternReason for difficultyTreatment stage
Exits cluster between weeks eight and twelve, which is where most people move between dose steps. Among contactors, tolerability dominates before week twelve and cost after it.
Silent leavers are the majority and are absent from the reason data entirely.
Support is finite, so this is an allocation question rather than a targeting one. It needs groups that differ on how long they stay and have a driver you can change.
Segments that separate on duration and are modifiable
Refill regularityReason for difficultyProvision density
The erratic-refill group sits about twenty-one weeks below the regular one, and its dominant contact reason is tolerability. The slow-titration group separates almost as sharply and its driver is cost.
Two groups, similar spreads, opposite conclusions. Without the reason attached you would fund both.
This is a causal claim and needs a comparison group. There is not one, and no field would create it.
Exposure and outcome for the same people, plus an unexposed comparator
Programme engagementSupply gap pattern
Programme engagement sits with a different partner and no shared identifier
Not answerable. The comparison runs between people who chose support and people who did not, and that choice is the strongest signal in the data.
Selection, and no route around it here. Needs a randomised offer or a matched comparison on covariates nobody sends.
Under supply constraint this is about allocation rather than growth — which eligible groups are not reaching treatment.
Treated population against eligible population, by segment
Area contextProvision density
Payer type is absent from every feed
Partial. Geography gives a treated-population map with visible thinning in several areas. Payer cannot be added, so the map blends funded and self-funded groups that behave nothing alike.
Until payer arrives, underpenetrated cannot be told apart from funded elsewhere and therefore invisible.
Cost per initiation means nothing when supply is the constraint. The number worth having is cost per persistent patient.
Acquisition route, service consumption and duration, for the same people
Supply gap patternReason for difficulty
Supply route is not recorded as a fieldChannel taxonomies differ across seven partners
Not answerable. Route data sits with partners in incompatible vocabularies and none of it joins to dispensing.
Needs a common route vocabulary and a join. Worth naming because the reported figure today is the meaningless one.
Territory-level conversion averages this away. The unit has to be the prescriber panel.
Escalation events per patient-course, attributed to a prescriber
Treatment stage
Prescriber identity sits on the professional side with no join to the patient side
Not answerable, and it fails on a join rather than a gap. Both halves of the data exist.
The highest-value unanswered commercial question in the estate.
Straightforward to ask and biased to answer, in a knowable direction.
Objective longitudinal measurement against a stable denominator
Weight trajectoryTime on treatment
Partial. Measurement stops when people disengage and disengagement tracks the outcome, so the curve improves as the underlying picture worsens.
Informative censoring. Detectable here, correctable only with an exit signal from another partner.
A standard stratification, and the first thing a payer asks for.
Comorbidity at baseline, joined to trajectory and duration
Weight trajectory
Comorbidity burden is assessed by two partners at eligibility and transmitted by neither
Not answerable. One field, already collected, never sent.
One specification change to two existing agreements. No new collection, no new consent.
Run the required evidence against the coverage map rather than against partner proposals.
What each partner could supply, against what the open questions need
Reason for difficultySupply routePayer type
Answerable now. The three most-needed fields sit with two partners, and both are already under contract.
The estate does not need a new partner. It needs a specification for two it already pays.
Not an integration question. Identifier stability and permitted linkage are contractual.
Identifier scheme and rights position, per partner pair
Eleven of fourteen feeds have no route to a shared subject identifier
Every cross-partner question in this list fails here rather than on data availability.
No engineering moves a feed up a rung. Treating it as integration is how eighteen months get spent.
Cohort design
A scheme describes how a population could divide. A cohort is the one branch you decide to study. The tool is about whether the partner estate can support the group you have in mind.
What the data tags mean
Anchor
the starting populationAny population idea. Most of these are things that happened rather than things people are, which is what this estate holds.
Six rules for building a patient cohort
What the tool teaches, stated plainly.
From two partner feeds. Separates this population weakly — about three weeks of difference in how long people stay on treatment.
Ten-year bands from two feeds. Older bands stay on treatment longest, consistently.
The licensed weight-management indication. The broadest anchor available.
Assessed by two partners as part of eligibility. Transmitted by neither, so it cannot define a population here.
Anyone with continuous supply across the window.
First dispense in the window. The cleanest anchor in the estate.
Inferred from a supply gap, not observed as an event.
A dispense following a long gap, at the same partner.
No escalation across two expected intervals.
Not observed anywhere. Derived — and the derivation is the argument.
Everyone in a single partner’s book.
Who bears the cost, which shapes almost everything downstream.
Absent from every feed. Probably the strongest predictor available anywhere, and invisible.The eligibility gate. Without it a treated population cannot really be described at all.
Assessed by two partners during eligibility and transmitted by neither. One specification change would fix it.Changes indication, funding route, monitoring and how long people stay. Not one comorbidity among many.
Held at assessment by two partners. Not transmitted.The only demographic split any feed supports, and it behaves consistently — older bands stay longer.
Carried by two of fourteen feeds, so any split runs on a subset.Where people actually get the medicine. Nine routes exist and the estate sees six.
No feed records it as a field, though partners could.A composite of stage and recency. The most natural way to describe where someone is.
Derived, and inherits the gaps in treatment stage.Response shape over time, which is what most people mean by how someone is doing.
Measurement stops when engagement stops, and engagement tracks the outcome. The curve improves as the picture worsens.Area-level context joined at outward-code level. Describes places, not people.
Where people actually are in the schedule, which is rarely where anyone assumes.
Escalations are captured; holds and reductions are not. A stall and a slow start look identical.Where people are in the course.
Visible in the first three fills, before most people have left. Early enough to act on.
Determines whether support would help at all. Cost is not a support problem.
Free text from one partner, and only from people who made contact. Silent leavers are absent.A short gap is a recoverable moment. A long one usually is not.
Different barriers need different responses, and some need none from you.
Not captured anywhere. Would need to be collected at assessment.A self-funding person faces a monthly decision a reimbursed one does not.
Absent from every feed. Probably the strongest predictor available anywhere, and invisible.The obvious lever, and the hardest to evidence.
Sits with a different partner and no shared identifier. Needs a consent mechanism, not an integration.Support needs differ sharply by stage, and stage is knowable in advance.
Escalations are captured; holds and reductions are not. A stall and a slow start look identical.Each position implies a different intervention, which is what makes it designable.
Derived, and inherits the gaps in treatment stage.Route determines who can reach them and how.
No feed records it as a field, though partners could.Previously treated people need something different from the outset.
Prior exposure is asked at assessment and never transmitted.The first thing a payer asks about, and the first stratification any reviewer wants.
Assessed by two partners during eligibility and transmitted by neither. One specification change would fix it.A required subgroup in almost any submission in this area.
Held at assessment by two partners. Not transmitted.The objective outcome measure. Scarce, and valuable to payers.
Measurement stops when engagement stops, and engagement tracks the outcome. The curve improves as the picture worsens.Standard framing for a longitudinal cohort.
Derived, and inherits the gaps in treatment stage.Dose exposure is a prerequisite for any effectiveness claim.
Escalations are captured; holds and reductions are not. A stall and a slow start look identical.Any outcome comparison across payer types is comparing different populations.
Absent from every feed. Probably the strongest predictor available anywhere, and invisible.Circular if duration is also your outcome. Use as a frame, not a criterion.
Populations reached by different routes are not comparable.
No feed records it as a field, though partners could.Confounds every response curve if it is not controlled for.
Prior exposure is asked at assessment and never transmitted.Standard stratification for any outcome claim, and reviewers will expect it.
Carried by two of fourteen feeds, so any split runs on a subset.Early erratic refillers, tolerability-driven
Two criteria, both resolving to fields partners send. The dominant reason is modifiable, which is what makes it worth acting on.
Youngest band, low-provision areas
Identifiable and unactionable. No partner contacts this group and nothing in the definition can be changed. A finding, not a target.
High comorbidity burden, stalled below target
Comorbidity burden is assessed by two partners at eligibility and transmitted by neither. One specification change would make this buildable.
The question decides which dimensions matter. The data only decides whether you can have them.
In this estate behaviour separates people about seven times better than demographics do.
Discontinuation is not observed. It is inferred from absence, and your threshold is doing most of the work.
A split on age is a finding. A split on refill behaviour is a plan.
Each one you add narrows the population and adds a partner dependency. The third usually costs more than it returns.
Publish it. Do not build a programme around it.
Payer, route and clinical context
Three axes, one field eachI spent most of the first month treating these as one attribute. They are three, set by three different actors, and each predicts something the others do not. Getting this wrong is why the early segment work produced curves that averaged incompatible populations.
Clinical context, which was missing entirely
Comorbidity is the eligibility gate. Access to the weight-management indication turns on BMI together with a weight-related comorbidity, so a person’s comorbidity profile determines whether they qualify, under which route, and with what monitoring. The catalogue had 187 elements and none of them was comorbidity.
| Element | Grain | Source | Why it matters here | State |
|---|---|---|---|---|
| Comorbidity at assessment | pseudonym / snapshot / assessed population | Eligibility assessment | The eligibility gate. Without it a treated population is uninterpretable. | Absent |
| Coded comorbidity list | pseudonym / snapshot | Eligibility assessment | Coded rather than free text, or it cannot be counted | Absent |
| Comorbidity count | derived | Derived | A plausible persistence predictor nobody here has tested | Not derived |
| Type 2 diabetes status | pseudonym / snapshot | Eligibility assessment | Changes the indication, the funding route, the monitoring and the persistence pattern. Not one comorbidity among many. | Absent |
| Cardiovascular risk status | pseudonym / snapshot | Eligibility assessment | Increasingly central to the evidence conversation | Absent |
| Concomitant medication class | pseudonym / longitudinal | Eligibility assessment, pharmacy | Both a comorbidity proxy and a titration constraint | Absent |
| Contraindication flag | pseudonym / snapshot | Eligibility assessment | Safety-relevant and route-determining | Absent |
| Baseline HbA1c where diabetic | pseudonym / snapshot | Eligibility assessment | Baseline for the outcome that matters in the diabetic subgroup | Absent |
| Bariatric surgery history | pseudonym / snapshot | Eligibility assessment | Changes expected trajectory entirely | Absent |
| Prior GLP-1 exposure | pseudonym / snapshot | Eligibility assessment, pharmacy | A restart is a different clinical situation from a first course, and the estate cannot tell them apart | Absent |
| Other weight-management agents | pseudonym / longitudinal | Eligibility assessment | Confounds every response curve | Absent |
All eleven are held at source by the telehealth and HCP-workflow partners as part of an assessment they already perform. None is transmitted. A specification change to two existing agreements rather than a new collection, which puts it in the cheapest tranche of the programme.
Supply route, distinct from who pays
| Route | Regulatory frame | Clinical assessment before supply | Observed here |
|---|---|---|---|
| Community pharmacy, in person | Pharmacy regulation | Prescription-led | Partial |
| Distance-selling pharmacy | Pharmacy regulation, distance-selling requirements | Prescription-led, remote verification expected | Yes |
| Telehealth with integrated fulfilment | Provider and pharmacy regulation | Consultation-led, same organisation | Yes |
| Telehealth with separate pharmacy | Split across two regulated entities | Consultation-led, fulfilment elsewhere | Yes |
| Specialist weight-management service | NHS commissioning | Multidisciplinary | No |
| General practice | Primary care | Prescription-led | No |
| Medical aesthetics clinic | Provider regulation; assessment quality a live concern | Highly variable | No |
| Private endocrinology or bariatric | Provider regulation | Specialist | Partial |
| Outside the legitimate supply chain | None | None | No |
Aesthetics is the one I would single out. It is a material route in this therapy area in the UK, it sits in a different regulatory frame from a pharmacy or an online clinic, and no partner in the estate observes it. A manufacturer looking only at its partner estate cannot see a route by which its medicine reaches people.
A route field with no value for supply obtained outside the legitimate chain produces a dataset in which that population is invisible, and falsified product in this class is a documented problem.
Forecasting consumption
Cohort flowPartner data cannot forecast demand. It sees a partner’s cohort, not a market, and under supply constraint new starts are set by allocation rather than by appetite. What it can forecast is consumption per patient over time, which is the multiplier you apply to whatever patient count comes from elsewhere.
| Stage | What becomes possible | What it needs | Reachable |
|---|---|---|---|
| Now | Pooled titration-stage distribution and pack-mix projection, 8–12 weeks, no segmentation | The dispensing feed alone | Immediately |
| One change | Same, with contaminated windows excluded and split by funding route | Supply-event markers and funding route | Specification, two agreements |
| Two changes | Segment-level transition rates | Comorbidity and demographics | Specification, two agreements |
| Needs L2 | Support exposure and behaviour as covariates — whether intervention changes the curve | Cross-partner linkage | Consent design |
| External | Market-level rather than cohort-level forecasting | A market data source and a reweighting basis | Procurement decision |
The first three are reachable within a year. The fifth is not an analytics problem.
Two things I would insist on. The forecast carries a confidence card like any other decision-grade output, stating the cohort it was fitted on, the excluded windows and what it cannot tell you — which is anything about the reimbursed route. And payer mix enters as a scenario input rather than a parameter: three assumptions, three ranges, no single number. Coverage shifts are exogenous and nobody can time them, so producing one figure would be a false precision that the supply team would then plan against.
Benchmarks, other markets, and measuring growth
TransferA benchmark set built for one market is worth more than it looks, because most of what makes it hard to build is market-independent. What transfers and what does not follows a clean rule: the structure travels, the values do not.
| Layer | Transfers? | Why | What has to change |
|---|---|---|---|
| The value model — five classes | Fully | Duration, efficiency, evidence, intelligence and risk are properties of the commercial situation, not of a jurisdiction. | Nothing. The counterfactual test applies everywhere. |
| Growth lever structure | Fully | Patients × months × dose is arithmetic. Only which term is capped changes. | Where supply is not the constraint, acquisition comes back into scope and the weighting shifts. |
| Data catalogue structure | Fully | The domains, the three layers and the grain model describe how partner data behaves, not what any market holds. | Element definitions may need local clinical terms. |
| Decision inventory method | Fully | The decision card and the cost-of-being-wrong test are a facilitation technique. | The decisions themselves are local and must be re-elicited. This is not a copy exercise. |
| Grain and linkage model | Fully | The three axes and five rungs are structural. | Which rung is legally reachable differs sharply. Several markets permit routine linkage the UK does not. |
| Quality dimensions | Fully | Six standard dimensions plus fitness for decision. | Nothing. |
| Benchmark values | Not at all | Every threshold here is either a local operating target or derived from a UK-specific proxy. | All of them. Carrying a UK completeness target into another market is the most likely misuse of this work. |
| Reference sources | Not at all | National identity services, professional registers and organisation directories are national by definition. | Complete rebuild of Layer 1. The structure holds; every source is different. |
| Legal routes | Not at all | The four routes in the next section are UK. EU markets differ from each other, let alone from the UK. | Complete reassessment. Do not assume EU-wide uniformity either. |
| Partner archetypes | Partly | The eight roles exist in most developed markets. | Their prevalence differs enormously. Direct-to-consumer telehealth is dominant in some markets and marginal in others. |
Setting a benchmark in a market with no history
The first cycle in a new market has no baseline, which is the position the affiliate was in here. Four sources, in preference order, and the fourth is where most of these thresholds actually came from.
| Source | When to use it | Status it carries | Example |
|---|---|---|---|
| Published external data | Where a comparable published figure exists | Benchmark | Clinical measurement intervals, taken from guidance and cited to version |
| Cross-market internal | Where the same partner archetype operates in another affiliate | Derived | Feed latency norms for a dispensing partner; structure transfers, absolute value does not |
| Proxy from an adjacent setting | Where no direct figure exists but a comparable programme does | Derived from proxy | PRO completion, taken from published rates in comparable programmes and labelled as provisional |
| Risk-based operating target | Where nothing external exists — the common case | Operating target | Cohort coverage for a renewal decision, set at the point below which the analysis describes the partner’s best cases rather than its population |
Six of the nine benchmarks in this work are the fourth kind. They are defensible because the reasoning is written down, and they are not standards. An operating target presented as a standard is the misuse this table is meant to prevent.
Assessing growth once the benchmarks exist
| Question | Measured how | Guards against |
|---|---|---|
| Did duration move? | Median and distribution of months on treatment against a fixed denominator, split by route and by dose stage | A shift in cohort mix reading as a shift in behaviour. Splitting by route is what catches it. |
| Did dose realisation move? | Proportion reaching target dose and time to reach it | Improvement driven by a change in who is being started rather than how they are managed |
| Did allocation improve? | Share of treated population in segments with the highest duration and dose realisation | Volume growth in low-persistence segments reading as success |
| Did cost to serve move? | Support contacts and fulfilment failures per persistent patient, not per patient | A fall in contacts caused by people leaving rather than by things working |
| Did the evidence position move? | Questions answerable now that were not; evidence packs accepted | Activity counted as progress |
| Did the estate improve? | Use cases moving from blocked to partial to available; fitness verdicts passing | The catalogue growing while nothing becomes answerable |
How this is used inside the affiliate
Where it landsFive functions, five different objects, one spine underneath — and the honest position is that five of the eight took it up and three did not, at least not in the window.
| Function | What they open | What they do with it | Cadence | Adoption |
|---|---|---|---|---|
| Commercial · partnerships | Portfolio matrix and partner value report | Renewal and expansion decisions. The report replaces the review that had stalled. | Quarterly, and at each renewal | Took it up The stalled review was their problem and this solved it. |
| Medical | Decision datasets and confidence cards | Evidence questions; where support and education go | Continuous | Took it up Driven by the fitness verdicts, which told them which of their questions were answerable. |
| Market access | Evidence-class contributions and the RWE outputs | Payer conversations and evidence planning | Per submission cycle | Partial Used the outputs, did not engage with the catalogue. |
| Data and analytics | Catalogue, gateway, definition register | Runs it. Owns the integrity of the record and none of the decisions in it. | Daily | Took it up |
| Privacy and legal | Rights cockpit and the linkage ladder | Determinations, and the specification that goes into agreements | At contracting and on change | Took it up The structured rights position removed the interruptions they most disliked. |
| Patient safety | Surface inventory and screening cadence | Configures intake; assesses the queue | Per sweep | Partial Adopted the inventory, resisted moving recognition off partners until the volume argument was made twice. |
| Field and sales | Nothing directly | — | — | Did not land The HCP behaviour data that would serve them is the one class the estate does not capture. Nothing to give them yet. |
| Supply | Demand geography and persistence | Allocation and forecasting | Monthly | Did not land Interested, but the supply-event field does not exist, so the join they need cannot be made. |
Three of eight did not take it up, and two of those three are the ones I would most have wanted. Field and Supply both have a real use for this and neither can be served until a field that does not exist starts arriving. That is a sequencing consequence rather than an adoption failure, but it looks identical from the inside and it cost credibility in month four.
What drove adoption was the fitness verdict — a per-decision fit or blocked, visible to the person who owns the decision. People engaged with the catalogue because it started telling them their question could not be answered and why.
| Forum | Who | Decides | Frequency |
|---|---|---|---|
| Portfolio forum | Commercial, Digital, Medical, Data, Privacy | Quadrant assignments, exits, specifications, override review | Quarterly |
| Catalogue change | Data product, Privacy, decision owners | New elements, definition changes, denominator versions | Monthly |
| Fitness exceptions | Decision owner, data product | Whether a blocked publication proceeds, and on what stated ceiling | As needed, logged |
| Safety configuration | Patient safety, Digital, partner leads | Surface inventory and cadence | Quarterly and on any new surface |
Data sharing agreements in the UK
The landscape, and how to make an exchange compliantFour routes by which partner data can lawfully reach a pharmaceutical affiliate in the UK, the conditions attached to each, and the one route that is not available. Two independent tests apply and the second is the one most often missed.
Data protection, in the state it is now in
| Instrument | Status | What it requires here |
|---|---|---|
| UK GDPR · Article 6 | Law | A lawful basis for any processing of personal data. For a commercial affiliate this is realistically consent or legitimate interests, and legitimate interests needs a documented assessment. |
| UK GDPR · Article 9 | Law | Health data is special category and needs a separate Article 9 condition on top of the Article 6 basis. The two do not have to be linked and both must be identified before processing begins. |
| DPA 2018 · Schedule 1 | Law | Five of the ten Article 9 conditions require an additional Schedule 1 condition and, in several cases, an appropriate policy document in place at the time. |
| Data (Use and Access) Act 2025 | Law | Materially changes the position for this work. Scientific research now has a statutory definition that expressly includes privately funded and commercial research. Broad consent to an area of research is available. Further processing for research is treated as compatible with the original purpose. A transparency exemption applies where direct notification would take disproportionate effort, provided the notice is published. |
| Recognised legitimate interests · Art. 6(1)(ea) | Law | A new basis with no balancing test — and it does not cover commercial research. It is limited to a defined list including emergencies, safeguarding and crime prevention. Assuming it applies here would be a mistake, and it is an easy one to make. |
| ICO anonymisation guidance | Regulator guidance | Effective anonymisation puts data outside the scope of the legislation, and the bar is high. Identifiability sits on a spectrum; assess with the motivated-intruder test and watch for singling out and linkability. Pseudonymised data remains personal data. |
| DPA 2018 · s.171 | Law | Knowingly or recklessly re-identifying de-identified personal data is a criminal offence. |
| DPIA | Law | Required for high-risk processing, which large-scale special category data is. |
The route each part of this design actually relies on
| Design decision | Route | Why it holds | Residual risk |
|---|---|---|---|
| Affiliate receives aggregate or effectively anonymised data from most partners | R1 | Outside the scope of data protection law at the affiliate. Confidentiality discharged because the information is no longer confidential. | Small cohorts fail the motivated-intruder test. The catalogue carries a minimum cohort size and the gateway enforces it. |
| Pseudonymous subject-level data from two partners | R2 | Explicit consent, obtained by the partner, naming the affiliate and the purpose. | Withdrawable. Consent a partner obtained for its own service does not extend to the affiliate, and two agreements had assumed otherwise. |
| Real-world evidence work | R3 | Scientific research, now statutorily including commercial work, with Schedule 1 safeguards. | The safeguards are conditions, not documentation. Confidentiality still needs consent, statutory support or anonymisation. |
| Any cross-partner linkage | R4 | A trusted third party holds identifiers and returns outputs. The affiliate never holds identifiable data. | Slow to establish, and the outputs are fixed at specification time. This is why the linkage ladder places L3 where it does. |
| Rights position as structured values | — | Not a processing question. It is a record of determinations already made. | A structured field can look like a determination. Every value carries who confirmed it and when. |
| Safety content handling | Separate | Pharmacovigilance obligations sit outside this framework and cannot be contracted away. Anything received is handled through the established route. | Recognition sitting with partners was the real exposure, and moving it was a process change rather than a legal one. |
| Cross-partner probabilistic matching | None available | — | Removed from the design. See below. |
The part that was not lawful
The original architecture included probabilistic matching across partner datasets on quasi-identifiers — age band, outward postcode, initiation month — to construct a longitudinal cross-partner view. Technically it works. It was proposed twice and removed twice.
It manufactures a linkage no rights position permits. It defeats the anonymisation that most of the estate relies on for its lawful footing, because a dataset that can be linked to another is one where singling out becomes possible. And under section 171 of the Data Protection Act 2018, knowingly or recklessly re-identifying de-identified personal data is a criminal offence.
The second time it was proposed, it came with a technical argument about match confidence thresholds. The threshold is not the issue. The intent to re-identify is.
The rest of the regulatory frame
| Instrument | Applies to | What it constrains here |
|---|---|---|
| ABPI Code of Practice | All partner activity relating to the medicines | Third-party conduct is the company’s responsibility, including where the third party acts against instructions. Data collection must not be a vehicle for promotion. Transfers of value are disclosable, and data supplied in exchange for services is a transfer of value. |
| Advertising of prescription-only medicines | Any public-facing material | Prohibited to the public. Reaches partner surfaces where the affiliate’s material or funding is present. |
| Pharmacovigilance obligations | Digital media under the company’s management or sponsorship | Screening at a defined cadence. Anything received is reportable regardless of route, and no contract removes this. |
| Medical device regulation | Partner software that assesses, advises or monitors | Classification is the partner’s obligation as manufacturer and the affiliate’s dependency. An unclassified device inside a funded journey is a question the affiliate will be asked. |
| National data opt-out | Confidential patient information from health and care organisations in England, used for research and planning | Does not reach most of this estate, because most of it is private-sector service data rather than NHS-sourced. Where an NHS route is added, it does. |
| Competition law | Insight returned to partners who serve several manufacturers | Two of the twenty-three operate across manufacturers. What flows back to them was scoped deliberately, and the reciprocity design in the dossiers exists partly for this reason. |
| Risk | How it happens | Control |
|---|---|---|
| Purpose creep | Data received for service operation gets used for commercial analysis because it is sitting there | Permitted purposes as a structured field; the gateway blocks the use, not the ingestion |
| Consent that does not reach the affiliate | A partner’s consent covers its own service and is assumed to cover onward supply | Controller role and consent scope recorded per engagement, confirmed by Privacy, never inferred |
| Anonymisation that is not anonymous | A cohort small enough to single out, or a combination that becomes linkable | Minimum cohort size in the catalogue; identifiability reassessed when a new dataset arrives |
| Determination by default | A structured field gets populated by extraction and nobody confirms it | No rights value is written without a named human confirmation event. UNKNOWN is a permitted value; a default is not. |
| Drift into promotion | A data-collection instrument becomes a channel | Code review sits in the gate set for any patient-facing engagement, not only for material |
Counsel reviewed two points: the trusted third party route, and whether the research definition reached the commercial analysis. The answer on the second was narrower than the affiliate wanted.
How the work was run
MethodFive weeks of discovery running alongside six workshops, each ending on a decision rather than a discussion.
The instruments
| Instrument | Who / what | Output | Decision it enabled |
|---|---|---|---|
| System walkthrough2 sessions, 71 and 54 minutes, screen-shared | Data engineering and Partner Operations, narrated by the analyst who runs the monthly reconciliation | Current-state data path with every actual handoff, including the four that appear in no documentation | Whether the problem was technology or process. It was process, in eleven of fourteen feeds. |
| Semi-structured interviews17 interviews across 6 functions | Commercial, Medical, Market Access, Privacy, Data, Patient Safety | Decision inventory, pain points, and the vocabulary conflicts between functions | Which decisions matter, who owns them, and where the same word means three things |
| Agreement-set analysis23 agreements, 17 DPAs, 9 partner terms | Contracts, data processing agreements, partner platform terms | Rights pattern matrix across seven drafting styles | Which rights language can become a structured control and which is irreducibly bespoke |
| Feed profiling5 live feeds, field by field | Dispensing, connected device, patient support, behaviour, HCP workflow | Field-level fill rates, type validity, cardinality, temporal coverage, subject continuity | Whether current feeds are usable, which is a different question from whether they are clean |
| Partner value reviewall 23, desk-based | Agreements, activity reports, steering material, invoices for scope only | Contribution and delivery position per partner | The portfolio matrix. This is where the counterfactual test was applied for the first time. |
| Artefact analysis~60 artefacts | Reconciliation spreadsheets, monthly partner reports, steering decks, service tickets, mailbox threads | Evidence trail of the actual operating process against the documented one | Where manual work and rework sit, and who absorbs them |
| Workshop sequence6 sessions over 5 weeks | Cross-functional, 6 to 11 participants per session | Ranked decision inventory, journey model, catalogue, allocation, checkpoint grid, product concept | What gets built, what stays human, and what is not worth doing |
The correction to the brief
The brief stated that the affiliate had a partner sprawl problem and needed to rationalise the estate. Profiling contradicted it in the first fortnight.
Overlap between partners is low. Mapping what the fourteen active feeds actually supply against the fourteen journey stages produced a coverage pattern with little redundancy — six stages are seen by more than one partner, and two are seen by none. The estate is sparse and uncoordinated rather than duplicated. On a finance report that looks the same and needs the opposite response.
Asked which decisions partner data currently informs, the seventeen interviews produced 27 named decisions and four that anyone could point to evidence for. The problem is not too many partners. No decision owner had specified what evidence would change their mind, which leaves every dataset equally defensible.
| Session | Question it had to settle | Frameworks used | Output | Decision it ended on |
|---|---|---|---|---|
| W1 Decisions11 participants, 3 hours | Which decisions could partner data change? | Decision-back mapping · forced ranking · cost-of-being-wrong scoring | Ranked inventory of 27 decisions with owners, current evidence and failure cost | The nine decisions the rest of the work would serve |
| W2 Journey8 participants, 3 hours | Where is data generated, and where does it disappear? | Journey mapping · service blueprinting · dark-data marking | 14-stage journey with touchpoints and coverage marked per archetype | That two journey stages are unobserved by any partner |
| W3 Catalogue9 participants, 2 sessions | What does good look like, for each decision? | Affinity clustering · benchmark families · fitness-for-decision test | 187 catalogued elements with grain, rights and benchmark | A benchmark per data family rather than one universal completeness target |
| W4 Machine work10 participants, 3 hours | Where should software do the work? | Staged function allocation · Crazy 8s · impact–risk plot | 34 candidate capabilities reduced to 11, with the filter recorded | The eight capabilities declined, and why |
| W5 Human line7 participants, 2.5 hours | What must remain human, and what could go wrong? | Pre-mortem · decision-rights grid · failure-mode walkthrough | Checkpoint grid and degraded-mode behaviour per capability | That recognition of safety-relevant content moves off partners |
| W6 Product9 participants, 3 hours | What finished thing expresses all of this? | Design Studio · storyboarding · concept critique | Two products on one spine, with the confidence card as the shared object | Not to build a platform |
W1 is the session that mattered and it nearly failed. The account is in the next section.
Workshop design
How the sessions were builtSix sessions across five weeks. The sequence matters more than any individual exercise: each one produced the input the next one needed, which also meant a failure early would have stopped everything after it. The first session nearly did.
Why six, and why in this order
Decisions first, because nothing downstream can be prioritised without them. The catalogue would otherwise be a field list, the allocation work would have no consequence attached, and the product would be designed against assumptions.
Journey second, before the catalogue. Designing the journey around available data reproduces the blind spots — you end up with a model of the service that matches the feeds rather than the care. So the journey was drawn from how the service actually runs, and data was attached afterwards. The two stages nobody could attach data to became a finding.
Catalogue third, because it needs both. Allocation fourth, because you cannot decide what a machine should do until you know which activities exist. The human line fifth, deliberately after allocation so the room was arguing about specific capabilities rather than about AI in general. Product last.
| Session | In the room | Deliberately not in the room | Exercises, in order | Ends on |
|---|---|---|---|---|
| W1 Decisions 11 people, 3 hours |
Decision owners from Commercial, Medical, Market Access, Patient Safety, Supply | Data and analytics. Their presence turns a decision conversation into a feasibility conversation within ten minutes. | Silent write · decision card completion · forced ranking by cost of being wrong · kill list | The nine decisions the rest of the work would serve |
| W2 Journey 8 people, 3 hours |
Medical, Digital, patient services, two people who take patient calls | Commercial. The journey gets drawn around the funnel if they are present. | Individual journey sketch · merge and argue · touchpoint marking · dark-stage identification | A 14-stage journey, with two stages nobody could evidence |
| W3 Catalogue 9 people, 2 sessions of 2.5 hours |
Data, Medical, Market Access, Privacy | Nobody excluded. This is the session that needs everyone who owns a field. | Affinity clustering from W2 touchpoints · benchmark families · fitness-for-decision test against W1 output | A benchmark per data family rather than one universal completeness target |
| W4 Allocation 10 people, 3 hours |
Cross-functional, including two people who do the reconciliation by hand | Vendors. Obvious, and it had been proposed. | Activity inventory · four-stage scoring · Crazy 8s on the top six · impact-risk plot | 34 candidates reduced to 11, with the filter recorded |
| W5 The human line 7 people, 2.5 hours |
Compliance, Privacy, Patient Safety, the analyst | Anyone who had championed a capability in W4. Authors defend. | Pre-mortem · failure-mode walkthrough per capability · decision-rights grid | Recognition of safety-relevant content moves off partners |
| W6 Product 9 people, 3 hours |
Mixed, including two from W1 who had not attended since | — | Design studio · storyboard the analyst’s week · concept critique · kill one idea | Not to build a platform |
W1, and the hour it took to work
The session was designed around a decision card — a fixed sentence with slots. It did not work for the first hour. Asked what decisions they make with partner data, the room produced activities: monitor partner performance, improve adherence, understand the patient journey. Each has an owner and a slide and none of them is a decision, because nothing happens differently depending on the answer.
I dropped the word decision and asked for the shape instead: who chooses, between what options, by when, and what goes wrong if they choose badly. Twenty-seven came out in ninety minutes having produced almost nothing in the first sixty.
The cost-of-being-wrong column was added mid-session for the same reason. Four items could not be given one, and on inspection none of them was a decision anybody makes.
The decision card, as used
| Field | A decision that survived | One that did not |
|---|---|---|
| The decision | Whether to renew a partner at contract end | “Monitor partner performance” |
| Who chooses | Business owner with Finance | — |
| Between what | Renew as-is · renew with a revised specification · do not renew | — |
| By when | Ninety days before expiry | — |
| Evidence used today | Relationship history, partner activity report | A monthly report |
| Evidence that would change it | Persistence contribution against a defensible denominator, quality trend, cost to serve | — |
| Cost of being wrong | A poor partner persists by inertia; a good one is lost for want of evidence | Cannot be stated |
| Verdict | Carried forward | Removed |
Why each framework, rather than which
| Session | Framework | Chosen against a specific failure |
|---|---|---|
| W1 | Silent write before discussion | The two most senior people in the room set the frame in the first three minutes otherwise. Everyone writes first, then reads out. |
| W1 | Forced ranking | Scoring lets everything be important. Ranking makes people trade, and the argument during the trade is the useful part. |
| W2 | Individual sketch before merge | A group journey map converges on the version of the service that management believes exists. Separate sketches surface the disagreement first. |
| W2 | Dark-stage marking | Rather than asking what data exists, asking where none does. Different question, and it produced the tolerability and stop-reason finding. |
| W3 | Affinity clustering | The room kept collapsing into two camps — clinical and commercial. Clustering on the artefacts rather than by discussion broke that. |
| W4 | Four-stage scoring | A single automate-or-not question produces binary answers to non-binary problems. Scoring the four stages separately is what surfaced the acquisition-and-analysis pattern. |
| W4 | Crazy 8s | Deliberately too fast to be careful. The point is volume, and the filtering happens afterwards with the criteria visible. |
| W5 | Pre-mortem | Asked directly, nobody will say what they think will fail. Asked to explain a failure that has already happened, everybody will. |
| W5 | Authors excluded | A capability defended by the person who proposed it does not get tested. |
| W6 | Kill one idea | A design session with no forced removal produces a superset. Requiring one death makes the room state its criteria. |
What the sessions produced, including what did not survive
| Filter applied | Removed | Examples |
|---|---|---|
| Needs linkage the estate does not have | 7 | Cross-partner journey analytics, unified patient view, cohort matching across partners |
| Redesign solves it better | 5 | Automated reconciliation across three denominators; automated assembly of charts nobody reads |
| The determination should not be automated | 4 | Safety classification, renewal recommendation, rights determination, fitness verdict |
| No data to support it | 3 | Predictive persistence scoring, partner performance prediction, churn propensity |
| Duplicate of another candidate | 4 | Three separate proposals that were all field mapping |
| Carried forward | 11 | — |
The pre-mortem, and what it changed
| Failure the room imagined | How likely they thought it was | What changed as a result |
|---|---|---|
| Everything gets blocked and people build a shadow spreadsheet | Very likely | A named, logged override on every block. The override became a feature rather than a leak. |
| The green light stops people looking | Likely | The confidence card states what a figure cannot tell you even when every check passes. |
| Partners refuse the specification | Likely for two of fourteen | Specification issued at contracting rather than retrofitted. Existing partners get it at renewal. |
| The catalogue is maintained for six months and then rots | Very likely | A custodian role, and the catalogue became the only route to a specification. |
| Confirmation load makes the analyst’s job worse | Possible | Measured deliberately. Confirmation on every mapping was kept anyway, for calibration. |
| Safety volume overwhelms reviewers once recognition moves | Likely | The surfacing capability was built to absorb it, with an exhaustive queue and a random tail sample. |
The partner population
Frozen — P01 to P08Eight archetypes, fixed once and used in every table, dossier, benchmark and diagram in this document. No ninth appears halfway through.
| ID | Archetype | What they do | Primary data value | In this estate |
|---|---|---|---|---|
| P01 | Telehealth / digital clinic | Remote consultation, eligibility assessment, prescribing, follow-up | Consultation, initiation, prescribing, persistence | 2 partners, both active feeds |
| P02 | Pharmacy / e-pharmacy | Dispensing, fulfilment, refill, access | Prescription, dispensing, refill interval | 2 partners, 1 active feed |
| P03 | Remote monitoring / connected device | Physiological measurement outside the clinic | Weight, body composition, device events | 1 partner, active feed |
| P04 | Nutrition / behaviour / DTx | Nutrition, behaviour change, adherence support | Engagement, behaviour, PRO and PREM | 2 partners, 1 active feed |
| P05 | Care navigation / HCP discovery | Helps people find appropriate professionals or services | HCP, specialty, site, geography, referral | 1 partner, no feed |
| P06 | HCP workflow / clinical support | Tools used by professionals for education, workflow or decision support | HCP identity, organisation, usage, workflow interaction | 1 partner, active feed |
| P07 | Patient support service | Onboarding, reminders, contact centre, persistence support | Contacts, questions, support interactions, safety-relevant content | 1 partner, active feed |
| P08 | Evidence / data / RWE partner | Aggregation, analytics, outcomes, evidence generation | Cohort outcomes, longitudinal evidence, utilisation | 1 partner, periodic outputs |
AI is not an archetype. It is a capability that appears inside several of these and inside the affiliate’s own product; giving it a row would place the same partner in two categories and break every downstream count. Connected devices sit in P03 and nowhere else, for the same reason.
Who is in the system
Flows, not an org chartTwelve groups touch a partner data flow. Two experience it as one thing — the patient at one end, the analyst at the other. Everyone in between sees a slice and assumes it is the whole.
| Group | What they need | Systems touched | Where it breaks for them |
|---|---|---|---|
| Patient | To understand who holds what about them, and where a problem goes | Partner app, clinic portal, pharmacy site | Consent language differs per partner. A person on three partner services has agreed to three different things and can describe none of them. |
| Health professional | A current picture at the point of contact | Clinical system, partner portal | Partner-generated data does not reach the clinical record. The professional is the one person who could act on it in the moment and is the one person who cannot see it. |
| Partner | A clear specification and a single point of contact | Own platform, SFTP or API endpoint | Receives requirements from four functions at different times. Two partners had never been told what the affiliate uses the data for. |
| Data engineering | A stable schema and a reason to trust the source | Warehouse, ingestion scripts, reconciliation sheets | Absorbs every upstream change silently. Schema drift is discovered when a report looks wrong, not when it happens. |
| Analyst | A denominator and a definition that holds still | Warehouse, spreadsheets, partner PDFs | Rebuilds the same reconciliation monthly. This is where the hidden work concentrates and it is invisible in every management view. |
| Commercial | To know which relationships to continue | Partner reports, steering decks | Partner-reported metrics, partner-defined, not comparable. Renewal runs on relationship history because nothing better exists. |
| Medical | Evidence that would survive scrutiny | Evidence repository, partner outputs | Most receivable data was collected for service operation rather than evidence, and cannot be retrofitted into it. |
| Market access | Outcomes and utilisation for payer conversations | Evidence packs, RWE outputs | Needs cohort-level outcomes with a defensible denominator. Receives engagement metrics. |
| Privacy | A settled controller position before data moves | DPIA register, agreement set | Consulted when a flow is proposed rather than when a partnership is agreed. By then the commercial expectation is fixed. |
| Patient safety | Every potentially reportable item, within the clock | Safety database, partner escalation mailboxes | Depends on partners recognising safety-relevant content. Recognition is a trained judgement placed with untrained parties. |
| Digital | To run and extend the partner estate | Partner platforms, integration layer | Holds the technical relationship and no authority over what is specified. |
| Procurement / Legal | Contract, standing, payment | Contract repository | Their trigger — the purchase order — became the de facto definition of a partner, which is how two funded arrangements never entered the register. |
The journey, and where each partner can see it
CoverageFourteen stages, designed in W2 from the affiliate’s own service reality rather than borrowed from a template. Data was attached afterwards, deliberately — designing the journey around available data reproduces the blind spots.
Stage by stage
| Stage | What happens | Data created | Held by | Reaches the affiliate? |
|---|---|---|---|---|
| 1 · Discovery | Person searches, encounters content, forms an intention | Search terms, content engagement, referral source | P01, P04, P05 | Aggregate only, and channel taxonomies differ per partner |
| 2 · Eligibility | Assessment against criteria; funding route determined | BMI, comorbidity, prior attempts, route (NHS / private / self-pay) | P01, P06 | Partially. Funding route is absent from every feed, and it conditions everything downstream. |
| 3 · Consultation | Clinical contact, remote or in person | Consultation event, outcome, prescriber | P01, P06 | Event only. No clinical content, correctly. |
| 4 · Prescription | Prescription written | Prescription event, product, dose, prescriber | P01, P02, P06 | Yes, from two archetypes, with conflicting timestamps |
| 5 · Fulfilment | Dispensed and delivered | Dispense event, quantity, delivery, failed fulfilment | P02 | Yes. The most reliable event in the estate. |
| 6 · Onboarding | First dose, device set-up, service enrolment | Enrolment, first-dose confirmation, app activation | P01, P04, P07 | Yes, but three different definitions of “started” |
| 7 · Titration | Dose escalation over weeks | Dose stage, escalation date, holds and reductions | P01, P02 (inferred), P06 | Partially. Holds and reductions are rarely captured, and they are the early signal. |
| 8 · Tolerability | GI symptoms, burden, coping | Symptom reports, severity, self-management | P04 partial, P07 | Sparse Mostly unstructured, in call notes and free text |
| 9 · Monitoring | Weight and measurement between contacts | Weight, body composition, measurement method | P03 | Yes, high frequency, subject to informative attrition |
| 10 · Behaviour | Nutrition, coaching, habit support | Engagement events, logs, programme progress | P04 | Yes, from an engaged population by definition |
| 11 · HCP review | Follow-up, escalation, dose decision | Review event, decision, referral | P01, P05, P06 | Partially, and not linked to the monitoring data that should inform it |
| 12 · Safety | Potentially reportable content arises | Reports, escalations, case references | P01, P04, P07 | Yes, at varying cadence set by whoever configured each surface |
| 13 · Persistence | Still on treatment, or not | Refill interval, continued engagement, contact | P01, P02, P07 | Yes, by three incompatible proxies |
| 14 · Stop + reason | Treatment ends | Stop event, reason, restart | P07 only | Dark One partner, unstructured, no reason taxonomy |
The finding the matrix produces. The instinct in the room was to prize the data-rich partners — P03 sends a measurement every few days, P04 sends thousands of engagement events a week. Neither can tell you why anyone stopped. P07 sends a few hundred call records a month, unstructured, from the smallest contract in the estate, and it is the only place in the system where a human being asks the question that the entire persistence problem turns on.
Current state
One data point, end to endFollowing a single weight reading from a connected scale to the number on a steering slide takes seven stages and crosses nine break-points. Six of the nine are specification failures rather than technical ones.
Challenge, consequence, opportunity
| # | Challenge | Operational consequence | Human consequence | Data consequence | Where design intervenes |
|---|---|---|---|---|---|
| B1 | Partner defines the metric because no specification was issued | Seven definitions of an active patient | Analyst reverse-engineers each definition from sample data | No comparable denominator anywhere | Specification issued by the affiliate at contracting; definitions versioned in the catalogue |
| B2 | Partner aggregates before sending | Grain arrives below what the decision needs | Analyst requests re-cuts; partner obliges inconsistently | Subject-level questions unanswerable from a subject-level source | Contracted grain stated on three axes and tested on receipt |
| B3 | Schema changes without notice | Reports break, or worse, silently shift | Discovered when a number looks wrong, usually two cycles later | Trend discontinuities indistinguishable from real change | Conformance gateway holds the expected schema; drift is an event, not a discovery |
| B4 | No contract check at landing | Data lands whether or not the agreement permits its use | Privacy consulted after the fact | Purpose creep with no audit trail | Rights position as structured values, checked before publication |
| B5 | No key to join across partners | Each partner is analysed alone | Cross-journey questions get abandoned quietly | No longitudinal view of a person | Linkage ladder makes the constraint explicit and contractual |
| B6 | Reconciliation is unlogged manual labour | Two to three days a month, every month | One person holds knowledge nobody else has | Method changes when the person does | Automated mapping and conformance; the analyst confirms rather than assembles |
| B7 | Rights read from a PDF at point of use | Analysis waits on a legal read | Analysts shape questions to what clears quickly | The question asked is the easy one, not the right one | Structured rights position queried before the analysis is commissioned |
| B8 | Lineage stops at the warehouse | A published figure cannot be traced to its source events | Nobody can defend a number under challenge | Provenance lost at exactly the point it is needed | Lineage carried through to publication |
| B9 | The number arrives bare | Decision-makers read a figure without its limits | False confidence, and the wrong reading of persistence | Denominator and observability window invisible | Decision confidence card, attached at publication |
Official process against actual process
| Documented | Actual | What the gap tells us |
|---|---|---|
| Partner data is ingested to the warehouse via the standard pipeline | Three of fourteen feeds arrive as email attachments and are loaded by hand | The pipeline exists and was designed for a different class of source. Partner feeds were never in scope and nobody said so. |
| Data quality is monitored by the platform team | Quality is discovered by the analyst preparing the monthly pack | Monitoring watches infrastructure, not meaning. A feed can be up, on time and wrong. |
| Rights are governed by the data processing agreement | Rights are established by a Teams message to Privacy when a question arises | The agreement is real and unqueryable, so the operating control became an interruption. |
| Partner performance is reviewed quarterly | Two partners have not been reviewed since onboarding | Review requires a comparable measure. There isn’t one, so the meeting is about the relationship. |
| Safety-relevant content is escalated by the partner within the agreed period | One partner escalates weekly in a batch; one escalates when the account manager notices | “Within the agreed period” was never operationalised into a surface-level cadence. |
| Definitions are held in the data dictionary | The data dictionary covers internal sources only | Partner fields were treated as external and therefore nobody’s to define. |
Decision to evidence
The thesis, as a matrixTwenty-seven decisions came out of W1. Nine were carried forward. Each is traced back to the evidence that would move it, then to the data category, the touchpoint, the source and the grain that source can actually supply.
The evidence contract
Between a decision and any data sits an object nobody had written down. It states what evidence has to look like before it can answer that decision — the claim required, the population, the grain, the denominator, the coverage, how long people must be observable, what linkage it needs, what bias is tolerable, how recent it must be, which purposes the rights permit, and what would make the answer wrong.
Four of the twenty-seven decisions had anything resembling one. Writing the other twenty-three is what turned a field list into a catalogue: an element that appears in no contract does not enter, and a feed is judged against stated terms rather than against a general idea of quality.
| Decision | Owner | Current evidence | Missing evidence | Data category | Source | Min. linkage | Answerable? |
|---|---|---|---|---|---|---|---|
| Should this partner be renewed? | Business owner + Finance | Relationship history, partner activity report | Outcome contribution, cost-to-serve, quality trend | Persistence, outcomes, service ops | P01 P02 P07 P08 | L1 | After specification |
| Should this partner be expanded? | Digital + Commercial | Prescription and engagement volumes | A denominator, and evidence of incremental effect | Eligibility, initiation, persistence | P01 P02 | L1 | After specification |
| Does a new partner add anything? | Portfolio owner | The partner’s own proposal | Coverage overlap against the canonical catalogue | All categories | Assessment instrument | — | Yes, now |
| Is this feed usable for this question? | Data product | Manual inspection | A fitness-for-decision test | Quality metadata | Gateway | — | Yes, now |
| Can this data be used for this analysis? | Privacy + analyst | Contract read at point of use | Structured rights position | Rights metadata | Agreement set | — | Yes, now |
| Where is the journey under-supported? | Digital + Medical | Qualitative feedback, partner anecdote | Cross-partner coverage and drop-off by stage | Journey coverage | All | L2 | Needs consent design |
| Why do people stop? | Medical + Commercial | Partner speculation | Structured stop reason at the point of stopping | Discontinuation | P07, plus new capture | L1 | After specification |
| Does behaviour support change persistence? | Medical | Engagement volumes | Persistence outcome linked to exposure, controlled for selection | Behaviour, persistence | P04 + P02 | L2 | Needs consent design |
| Is safety-relevant content being detected? | Patient safety | Partner escalation counts | Consistent classification, timeliness, an audit trail | Safety | P01 P04 P07 | — | After specification |
| Outcome | Count | Examples | Why |
|---|---|---|---|
| Answerable from data already held | 6 | Fulfilment failure rate, refill interval distribution, contact volume by reason | Blocked only by definition disagreement, not by data. Fixed by fixing definitions. |
| Reassigned to primary research | 3 | Why people choose a private route; what the professional wants at review; where the service feels burdensome | Attitudinal questions that no operational feed will ever answer. Attempting them from partner data was the mistake being made. |
| Removed — not a decision | 4 | “Monitor partner performance”, “improve adherence” | No owner, no moment of choosing, no cost of being wrong. Activities dressed as decisions. |
| Deferred | 1 | Whether to build direct-to-patient capability | Depends on a strategic choice outside the scope of the work. |
Receivable grain, and the linkage ceiling
The constraint modelReceivable grain is the finest level the affiliate is entitled and able to receive from a given partner. It is a property of the relationship, not of the healthcare system — the same data element has a different receivable grain from each of two partners who both hold it.
| Feed | Identity | Temporal | Population | Fitness consequence |
|---|---|---|---|---|
| P01 telehealth | rotating token, resets on re-registration | longitudinal within an episode | self-selected, private route only | Cannot follow a person across two episodes. Persistence is per-episode, not per-person. |
| P02 dispensing | stable pseudonym, scheme unversioned | longitudinal subject | full partner cohort | The strongest feed in the estate. Refill interval is the most reliable persistence proxy available. |
| P03 device | stable pseudonym | longitudinal subject | self-selected and self-attriting | Finest identity grain, worst population scope. The feed most often called the best data in the estate. |
| P04 behaviour | stable pseudonym | longitudinal subject | engaged subset of an engaged population | Engagement measured on the engaged. Cannot support any claim about effect without a comparison group. |
| P06 HCP workflow | professional identifier, verifiable | repeated cross-section | full user base | Usable for HCP-side questions. Not joinable to any patient-side feed, correctly. |
| P07 support | stable pseudonym | event-level longitudinal | people who contacted, i.e. people with a problem | Strong selection toward difficulty, which is exactly what makes it the only source of stop reasons. |
| P08 RWE | aggregate only | repeated cross-section | defined cohort, denominator stated | Only feed with a stated denominator. Cannot be decomposed or joined. |
The ceiling. Eleven of fourteen feeds sit at L0. Nine of the twenty-seven decisions need L2 or above. No amount of engineering moves a feed up a rung — L2 requires a consent mechanism that does not exist, L3 requires a third party nobody has appointed, and L4 requires a governance arrangement that would take longer than the partnerships themselves. Naming this early stopped the affiliate commissioning a cross-partner analytics build that could not have worked.
The censoring problem, stated properly
The fix is not statistical in the first instance. It is a catalogue change: observability window, attrition reason and a denominator fixed at enrolment become required fields for any feed used in a longitudinal claim. Where attrition reason is genuinely unavailable, the feed carries a flag that prevents it being used alone for persistence, and the gateway enforces that rather than warning about it.
Where a resolution exists it comes from combining feeds — P02 refill gaps and P07 contact reasons both observe exits that P03 cannot see — which is a linkage question, which is L2, which is the ceiling. The honest position is that the affiliate can currently detect the bias and cannot correct it, and reporting that is better than reporting a corrected number nobody can defend.
Layer 1 — Ecosystem master
Reference, not receivableWhat exists in the healthcare system of record. The affiliate consumes codes, vocabularies and status from this layer and holds almost none of it at person level. Splitting authority from receivability is what makes that visible.
| Element | Authoritative source | Receivable by the affiliate | Why it is in the catalogue at all | Benchmark / control |
|---|---|---|---|---|
| PATIENT REFERENCE | ||||
| NHS number | PDS — national demographic record; the identifier used to match a person to their health record | Not receivable Partner may hold it under its own clinical relationship | Defines what a partner token is a substitute for, and why token stability matters | Syntactic validity at source; the affiliate never validates because it never receives |
| Name, date of birth, sex | PDS · GP record · partner registration | Not receivable Age band only, derived by the partner | Age band is the only demographic in any feed. Everything else is a modelling assumption. | Age band completeness ≥98% where eligibility is asserted operating target |
| Address, postcode | PDS · partner registration | Partial Outward code only, from 2 of 7 feeds | Geography for coverage analysis. Outward code is the finest grain the DPIA supported. | Valid outward code where present; no full postcode accepted |
| Registered GP practice | PDS · ODS · GP record | Not receivable | Marks the boundary of the affiliate’s visibility. Continuity of care sits outside the estate entirely. | n/a |
| Ethnicity | Clinical record where lawfully collected | Not receivable Aggregate only, and only for an approved research purpose | Named so that its absence is a stated position rather than an oversight | Not collected. Equity analysis runs on published population data, not partner feeds. |
| HCP REFERENCE | ||||
| Professional identifier | GMC · NMC · HCPC · GPhC registers | Receivable From P05 and P06 | The only person-level identity in the estate that is verifiable against a public source | 100% for onboarded professionals; verified at onboarding and re-checked weekly, operating target |
| Registration status | Regulator register | Receivable Derived at check time | Whether the professional can practise. Stale status is a live risk in a locator service. | Status current within 7 days of use operating target |
| Profession, role, specialty | Regulator register · ODS · employer | Receivable Controlled vocabulary | Routing and appropriateness. Specialty drives what P05 can safely surface. | 100% classified to controlled vocabulary; free text rejected at ingestion |
| Prescribing eligibility | Regulator status + service configuration | Partial Asserted by the partner, not verified | Whether an individual can act in a given service. The affiliate cannot verify it and says so. | Source and assertion date required; no inference from profession alone |
| ORGANISATION AND SITE | ||||
| Organisation code | ODS | Receivable | Stable join key across the NHS ecosystem, and the only truly reliable key in the whole model | 100% for in-scope organisations; refreshed against ODS on publication cycle |
| Site, address, geography | ODS | Receivable | Care navigation and coverage. Where care is actually delivered, as opposed to where the organisation is registered. | Current, valid; ODS code preferred over free-text address |
| Organisation role and relationships | ODS role vocabulary | Receivable | Parent, child, commissioning relationships. Prevents routing to the wrong entity. | Controlled vocabulary; effective dates and history retained |
| Open / closed / successor status | ODS | Receivable | Prevents referral into an entity that has closed. A live failure mode in directory services. | Checked on every refresh; closed entities suppressed rather than deleted |
| Practitioner-to-organisation relationship | ODS practitioner data | Receivable | A professional can hold several roles across several organisations, with different active status. Modelling one place of work is wrong. | Effective dates required; relationship history retained |
| CLINICAL REFERENCE | ||||
| Eligibility criteria | NICE guidance | Reference | Defines what “eligible” means before any partner asserts it | Guidance version and date recorded; criteria re-checked on guidance change |
| Measurement expectations | NICE guidance | Reference | Distinguishes a clinical recommendation from a data-engineering threshold. Annual clinical measurement is not an annual completeness target. | Clinical interval cited; engineering threshold stated separately and labelled |
| Terminology and coding | Recognised clinical terminologies | Reference | Whether a partner’s coded content is interpretable without bespoke documentation | Coded content required; 2 of 7 feeds currently comply |
| Resource shapes and identifiers | HL7 FHIR UK Core | Reference | Target shape for new feeds. Existing feeds are mapped to it rather than replaced. | New feeds conform; existing feeds carry a mapping with a stated loss profile |
Layer 2 — Partner-receivable
The working materialWhat each archetype can lawfully transmit under the relationship as it stands. One hundred and ten elements across twelve domains; forty-one are received today, and eleven of those are received in a form that cannot serve the decision they were acquired for.
| Element | Grain (identity / temporal / population) | Archetypes | Decision served | Rights position | Benchmark | State |
|---|---|---|---|---|---|---|
| CLINICAL CONTEXT · THE DOMAIN THAT WAS MISSING | ||||||
| Comorbidity at assessment | pseudonym / snapshot / assessed | P01 P06 | The eligibility gate; comparability of every cohort | Service operation | Coded, not free text | Absent |
| Comorbidity count | derived | derived | A plausible persistence predictor, untested here | Derived | Definition versioned | Not derived |
| Type 2 diabetes status | pseudonym / snapshot / assessed | P01 P06 | Changes indication, route, monitoring and persistence pattern | Service operation | Required on every initiation | Absent |
| Cardiovascular risk status | pseudonym / snapshot | P01 P06 | Increasingly central to the evidence conversation | Service operation | Coded where assessed | Absent |
| Concomitant medication class | pseudonym / longitudinal | P01 P02 P06 | Titration constraint and comorbidity proxy | Service operation | Class level, not product | Absent |
| Contraindication flag | pseudonym / snapshot | P01 P06 | Safety-relevant and route-determining | Service operation | Present on all assessed | Absent |
| Baseline HbA1c where diabetic | pseudonym / snapshot | P01 P06 | Baseline for the outcome that matters in that subgroup | Service operation | Where clinically taken | Absent |
| Prior GLP-1 exposure | pseudonym / snapshot | P01 P02 | A restart is a different clinical situation from a first course | Service operation | Required at assessment | Absent |
| Bariatric surgery history | pseudonym / snapshot | P01 | Changes expected trajectory entirely | Service operation | Required at assessment | Absent |
| Other weight-management agents | pseudonym / longitudinal | P01 | Confounds every response curve | Service operation | Class level | Absent |
| PAYER AND ROUTE · THREE FIELDS, NOT ONE | ||||||
| Payer type | pseudonym / snapshot | P01 P02 | Probably the strongest single persistence predictor available | Service operation | Controlled list of 9 archetypes | Absent |
| Coverage status | market-level, dated | reference | Whether that payer funds this indication, at a stated date | Reference | Versioned per market, effective-dated | Not held |
| Funding route | pseudonym / snapshot | P01 P06 | The scheme under which supply is authorised | Service operation | Controlled list of 7 | Absent |
| Supply route | pseudonym / event | P01 P02 | Where the medicine is physically obtained. Nine routes, six observed. | Service operation | Includes a value for outside the legitimate chain | Absent |
| Demographics | pseudonym / snapshot | P01 P02 | Sex and age band. With outward code, a quasi-identifier set. | Service operation | Band only; suppression below minimum cohort | Two feeds only |
| ELIGIBILITY AND ACCESS | ||||||
| Eligibility assessment outcome | pseudonym / event / partner cohort | P01 P06 | Who is in scope; where access friction sits | Service operation. Secondary use requires a purpose extension. | Definition versioned; ≥95% populated where a consultation follows target | Received |
| Funding route | pseudonym / snapshot / partner cohort | P01 P02 | Every cross-partner comparison; persistence economics | Service operation | Present on 100% of initiation events target | Absent from all feeds |
| Referral source / channel | pseudonym / event / partner cohort | P01 P04 P05 | Where access friction sits | Service operation | Controlled channel taxonomy issued by the affiliate | Received, 4 taxonomies |
| Prior weight-management attempt | pseudonym / snapshot / partner cohort | P01 | Cohort comparability | Service operation | Self-reported; provenance flag required | Not received |
| Wait time to first consultation | pseudonym / event / partner cohort | P01 | Where access friction sits | Service operation | Derived from two timestamps; both required | Derivable, not derived |
| TREATMENT PATH | ||||||
| Consultation event | token / event / self-selected | P01 P06 | Whether care happened; sequencing | Service operation. No clinical content received, by design. | Timestamp to the minute; outcome coded | Received |
| Prescription event | pseudonym / event / partner cohort | P01 P02 P06 | Initiation; drop-off between prescription and dispense | Service operation | Event ordering guaranteed; conflicting timestamps reconciled at source | Received, timestamps conflict |
| Dispense / fulfilment event | stable pseudonym / longitudinal / full cohort | P02 | Access friction; the persistence backbone | Service operation + agreed evidence use | Same-day or next-business-day receipt; 100% event capture | Received — strongest feed |
| Failed fulfilment | stable pseudonym / event / full cohort | P02 | Whether a gap is a stop or a supply problem | Service operation | Reason coded to a controlled list | Not distinguished from absence |
| Supply interruption | n/a — market-level | P02 P08 | Whether a cohort-wide gap is behavioural or structural | n/a | Recorded as a period marker against the cohort | Not captured |
| Titration stage and date | pseudonym / longitudinal / partner cohort | P01 P06 | Where support needs change | Service operation | Every change event captured with an effective date | Partial — escalations only |
| Dose hold or reduction | pseudonym / event / partner cohort | P01 P06 | The earliest tolerability signal available | Service operation | Reason coded; distinguished from a missed dose | Not captured |
| MEASUREMENT | ||||||
| Weight | stable pseudonym / longitudinal / self-selected | P03 | Response; monitoring sustainability | Service operation + agreed evidence use | Measurement method required on every value | Received |
| Measurement method | stable pseudonym / event / self-selected | P03 | Whether a value is comparable to another value | Service operation | Controlled list: clinic, connected device, self-reported, estimated | Not captured — all values treated alike |
| Body composition | stable pseudonym / longitudinal / self-selected | P03 | Quality of loss, not just quantity | Service operation | Device model and firmware recorded; calibration state where available | Received |
| Weight trajectory phase | derived | P03 + P02 | The decision-relevant variable. Cross-sectional weight is nearly useless. | Derived — inherits the strictest input | Definition versioned: loss, plateau, maintenance, regain | Not derived |
| Measurement recency | derived | P03 | Whether a monitoring claim is current | Derived | ≤48h for monitoring use target | Derivable |
| EXPERIENCE AND TOLERABILITY | ||||||
| GI symptom report | pseudonym / event / engaged subset | P04 P07 | Why people struggle; the dominant stop predictor | Service operation. Safety-relevant content routes separately. | Structured severity; distinguished from a reportable event at intake | Unstructured free text |
| Symptom burden / coping | pseudonym / event / engaged subset | P07 | Where support should be directed | Service operation | Coded to a support taxonomy | In call notes only |
| Patient-reported outcome | pseudonym / repeated cross-section / consenting subset | P04 P08 | Patient-valued outcome evidence | Evidence generation, where consented | Validated instrument; ≥70% completion at defined checkpoints derived from proxy | P08 only, aggregate |
| Service experience / PREM | pseudonym / event / respondents | P01 P04 P07 | Journey friction | Service improvement | Collected after a defined interaction; response rate stated with every result | Partial |
| ENGAGEMENT AND SUPPORT | ||||||
| Behaviour programme engagement | stable pseudonym / longitudinal / engaged subset | P04 | Whether support influences persistence | Service operation | “Meaningful engagement” defined once, by the affiliate, and versioned | Received, partner-defined |
| Support contact event | stable pseudonym / event / people with a problem | P07 | Where digital care needs a person | Service operation | Reason coded to a controlled list | Received, reason free text |
| Contact reason | stable pseudonym / event / people with a problem | P07 | What is actually going wrong, in the patient’s words | Service operation | Controlled taxonomy with a free-text tail | Free text only |
| PERSISTENCE AND EXIT | ||||||
| Refill interval | stable pseudonym / longitudinal / full cohort | P02 | The most defensible persistence proxy in the estate | Service operation + agreed evidence use | Gap threshold defined per product; denominator fixed at enrolment | Received |
| Stop event | pseudonym / event / varies | P02 P07 | Persistence, and everything downstream of it | Service operation | Distinguished from an observation gap | Inferred from absence |
| Stop reason | pseudonym / event / people who contacted | P07 | Why anyone stops. The scarcest evidence in the estate. | Service operation. Evidence use requires extension. | Controlled taxonomy: tolerability, cost, plateau, goal reached, supply, switched, other | Free text, one partner |
| Restart event | pseudonym / event / varies | P02 | Whether a stop was permanent | Service operation | Linked to the prior episode where the identifier permits | Not captured |
| Observability window | derived per feed | all | Whether any longitudinal claim is safe | Metadata | Stated per feed; attrition reason required where known | Not modelled |
| SAFETY | ||||||
| Potentially reportable content | pseudonym / event / all surfaces | P01 P04 P07 | Whether detection is working | Safety — separate lawful basis and route | All items reviewed under the applicable timeframe; recognition affiliate-side | Partner-side recognition |
| Screening event per surface | surface-level | P01 P04 P07 | Whether a surface is actually being watched | Safety | Cadence set by surface volume, not by whoever configured it | Cadence varies, no rationale |
| HCP-SIDE | ||||||
| Professional identity and organisation | verified identifier / snapshot / full user base | P05 P06 | Network coverage; appropriateness of routing | Service operation | Verified against the register; ODS code for organisation | Received |
| Initiation behaviour | identifier / longitudinal / full user base | P06 | Clinical inertia; where education lands | Service operation. Aggregate for any external use. | Denominator = eligible patients seen, not consultations | Not captured |
| Titration escalation behaviour | identifier / longitudinal / full user base | P06 | Whether under-dosing is a real pattern here | Service operation | Escalation events per patient-course | Not captured |
| Content and tool usage | identifier / event / full user base | P06 | Adoption and unmet need | Service operation | Event-level with source metadata | Received |
| GOVERNANCE METADATA | ||||||
| Subject identifier scheme | feed-level | all | Whether anything is joinable, and for how long | Metadata | Scheme documented and versioned; change is a notifiable event | Undocumented in 5 of 7 |
| Denominator definition | feed-level | all | Every rate in the document | Metadata | Definition, version, and the date it last changed | Absent everywhere |
| Rights position | feed-level, 7 structured fields | all | Whether an analysis may proceed | Metadata | Structured values, not prose. See §16. | Prose only |
| Source and timestamp | event-level | all | Trust and reconciliation | Metadata | 100% for governed events | Partial |
| Selection profile | feed-level | all | Whether two feeds may be compared | Metadata | Stated at onboarding; reviewed on material change | Not stated |
| Count | Comment | |
|---|---|---|
| Elements catalogued | 110 | Across ten domains and eight archetypes |
| Received today | 41 | Of which 11 are received at a grain that cannot serve the decision they were acquired for |
| Receivable without a contractual change | 23 | A specification and a re-cut. The largest tranche, and the cheapest. |
| Requires a contractual change | 19 | Chiefly stop reason, measurement method, funding route and identifier stability |
| Requires a linkage change (L2+) | 8 | Not reachable by specification. Consent design or a third party. |
| Not obtainable from this estate | 3 | Reassigned to primary research |
Layer 3 — Decision dataset
What the affiliate buildsDerived objects, one per decision, each with a fixed denominator, a stated observability window and a version. This is the layer the affiliate owns outright, and the only layer a decision is ever made from.
| Dataset | Grain | Denominator, fixed at | Observability | Inputs | Known bias | Confidence ceiling |
|---|---|---|---|---|---|---|
| Persistence at 12 / 26 / 52 weeks | subject-period | first dispense event | 26 weeks; 14% exit the feed before week 26 | P02 refill · P01 episode · P07 contact | Private route over-represented; NHS route absent from the estate | L1 — per partner only. No cross-partner persistence. |
| Initiation funnel | event-cohort | eligibility assessment completed | 8 weeks from assessment | P01 · P02 · P06 | Only assessed people appear. Eligible-but-never-assessed is invisible. | Timestamps conflict between P01 and P02; ordering is reconstructed |
| Discontinuation reasons | event | stop event confirmed | n/a — cross-sectional | P07 only, once a taxonomy exists | Only people who contacted. Silent stoppers are the majority and are absent. | Cannot be generalised. Reported as a reason mix among contactors, never as a population rate. |
| Journey coverage | stage-partner | all active partners | quarterly snapshot | All feeds + catalogue | None material | Full. This one is about the estate, not about people. |
| Partner contribution | partner-period | partners with an active feed | quarterly | All feeds + service ops | Confounded with partner population differences; not a like-for-like ranking | Comparative only within archetype, never across |
| Monitoring sustainability | subject-period | device activation | 52 weeks | P03 | Informative censoring — see §12 | Detection only. The bias is visible and not correctable within this estate. |
| Behaviour exposure | subject-period | programme enrolment | programme length | P04 + P02 | Engagement measured on the engaged. No comparison group exists. | Cannot support an effect claim. Reported as association with the limitation stated. |
| Safety detection performance | surface-period | all patient-facing surfaces | monthly | P01 · P04 · P07 | False negatives leave no record; the rate is unknowable from inside | Timeliness and consistency only, never sensitivity |
| HCP engagement and behaviour | professional-period | professionals with a verified identity | quarterly | P05 · P06 | Users of the tool, not all professionals seeing these patients | Full within the tool’s user base |
Benchmarks and data quality
Seven dimensions, and the one that mattersThere is no universal completeness percentage. Each data family takes the benchmark that fits it, and everything carries a provenance status so a reader can tell a published standard from an operating target somebody set in a workshop.
| Dimension | What it asks | Example test | Threshold | Owner | Failure behaviour |
|---|---|---|---|---|---|
| Completeness | Is the field populated where it should be? | Fill rate by field, conditioned on the event type | Per-field, set by decision requirement | Data product | Publish with the fill rate stated, or suppress the derived measure |
| Validity | Does the value conform to its type and vocabulary? | Type, range, controlled-list membership, impossible dates | 100% for governed events | Data engineering | Reject the record, notify the partner, do not silently coerce |
| Consistency | Do related values agree, within and across records? | Event ordering; prescription before dispense; dose within schedule | 100% on ordering; exceptions logged | Data engineering | Quarantine the affected subject-series, not the whole feed |
| Timeliness | Does it arrive in time to be useful? | Latency from event to receipt, by feed | <24h for operational; ≤48h for monitoring operating target | Data product | Publish with a staleness marker rather than withhold |
| Uniqueness | Is one thing represented once? | Duplicate subject-events; duplicate professional records | Duplicate rate <0.5% operating target | Data product | Deduplicate with a rule, log the rule version |
| Accuracy | Does it correspond to the world? | Reconciliation against an independent source where one exists | Reconciles within tolerance where a source exists; stated as unverifiable where not | Analyst | State as unverifiable rather than assume |
| Fitness for the decision | Can this support the decision it is being used for? | Grain, denominator, observability, coverage and bias against the decision’s requirement | Binary — fit or not fit, per decision | Decision owner | Block publication for that decision only. The feed may remain fit for others. |
The seventh dimension is the one the case turns on, and it is the only one that is not a property of the data. It is a relation between the data and a named decision, which means the gateway that tests it has to hold the decision inventory rather than a schema registry. A feed passing the first six and failing the seventh is the normal case, not an edge case.
| Benchmark | Value | Status | Derivation | What it protects |
|---|---|---|---|---|
| Professional registration currency | Status verified within 7 days of use | Operating target | Set by the risk of surfacing a professional who cannot practise. No published numeric standard exists. | A locator service directing a patient to a lapsed registration |
| Organisation code currency | Refreshed each publication cycle against the reference source | Reference practice | The reference source publishes on a known cycle; the affiliate follows it. | Referral into a closed entity |
| Clinical measurement interval | Per current clinical guidance for the condition | Published guidance | Cited to the guidance version and date. Explicitly not converted into a completeness target. | Confusing a clinical expectation with a data expectation |
| Monitoring recency | ≤48 hours for a monitoring claim | Operating target | Set by the decision requirement in W3, not by any external standard | A monitoring dashboard describing last month |
| Feed latency | <24 hours, operational feeds | Operating target | Operational requirement agreed with the decision owners | Decisions made on stale operational data |
| Cohort coverage for renewal | ≥80% of the partner’s active population | Operating target | Risk-based. Below this, a renewal analysis describes a subset the partner has selected. | A renewal decision made on the partner’s best cases |
| Identity match rate | ≥98% within a feed, across a period | Operating target | Risk-based, set against the longitudinal claim being made | Silent cohort churn read as persistence |
| PRO completion | ≥70% at defined checkpoints | Derived from proxy | Taken from published completion rates in comparable programme settings; to be replaced with a measured rate | Outcome claims from a highly self-selected respondent group |
| Safety screening cadence | Set by surface volume, reviewed quarterly | Regulator guidance | Guidance requires screening of digital media under the company’s management or sponsorship at a defined frequency; the frequency is the affiliate’s to set defensibly. | A weekly sweep on a surface with daily traffic |
Partner dossiers
Eight, one structureEvery dossier carries the same thirty-one fields. Two of them do the most work: what the affiliate can reasonably know from this partner, and what it cannot know from this partner alone.
P01 · Telehealth / digital clinic 2 partners · both active
| Field | Value |
|---|---|
| Role in the journey | Discovery through consultation, prescription, review and follow-up. Owns the clinical relationship for the private route. |
| Primary user | Patient, with a prescribing professional in the loop |
| Receivable grain | Rotating token / longitudinal within an episode / self-selected private-route population |
| Identifier model | Token resets on re-registration. Two episodes by the same person are two subjects. |
| Patient master dependency | None. The partner holds identity; the affiliate receives a token. |
| HCP master dependency | High. Prescriber identity is verifiable and is the strongest link to Layer 1. |
| Transmission | API pull, nightly |
| Longitudinal capability | Within an episode only. This is the single biggest limitation in the estate. |
| Decision contribution | Initiation funnel; access friction; per-episode persistence |
| Safety relevance | High — patient-facing free text at three points in the flow |
| Privacy sensitivity | High — clinical context, even where only events are transmitted |
| Quality risks | Timestamp conflicts with P02 on the same prescription; episode boundaries undocumented |
| Selection profile | Self-selected, digitally confident, private-pay. Systematically excludes the NHS specialist route. |
| Denominator | Consultations completed, partner-defined. Does not distinguish first from repeat. |
| Observability window | Episode length; median 19 weeks. Exit is indistinguishable from episode end. |
| Reciprocal need | Clinical content, patient materials, and early sight of supply position |
What the affiliate can reasonably know
Whether someone reached treatment through this route, how long it took, and what happened inside one episode.
What it cannot know from this partner alone
Whether the same person came back, what happened after the episode ended, or anything about the NHS route.
P02 · Pharmacy / e-pharmacy 2 partners · 1 active feed
| Field | Value |
|---|---|
| Role in the journey | Fulfilment, refill, access. The most operationally reliable point in the whole journey. |
| Primary user | Patient; pharmacist in the loop |
| Receivable grain | Stable pseudonym / longitudinal subject / full partner cohort |
| Identifier model | Stable, but the scheme is unversioned and has changed once without notice |
| Patient master dependency | None |
| HCP master dependency | Low — prescriber identifier present but not verified |
| Transmission | SFTP, daily |
| Longitudinal capability | Strong. The backbone of every persistence measure in the estate. |
| Decision contribution | Persistence; access friction; the only credible stop signal |
| Safety relevance | Moderate — dispensing queries occasionally contain reportable content |
| Privacy sensitivity | High — dispensing implies diagnosis |
| Quality risks | Failed fulfilment is not distinguished from a patient-initiated gap. A supply interruption looks like a stop. |
| Selection profile | Full cohort of this partner’s patients. The least biased feed in the estate. |
| Denominator | Patients with at least one dispense. Clean, and the one the affiliate adopted as canonical. |
| Observability window | Continuous while registered; churn to another pharmacy is invisible |
| Reciprocal need | Supply forecasting, patient counselling material, device training content |
What the affiliate can reasonably know
Whether treatment was collected, at what interval, and when the interval broke.
What it cannot know from this partner alone
Whether a broken interval means stopping, switching pharmacy, or a supply problem.
P03 · Remote monitoring / connected device 1 partner · active
| Field | Value |
|---|---|
| Role in the journey | Measurement between clinical contacts |
| Primary user | Patient |
| Receivable grain | Stable pseudonym / longitudinal subject / self-selected and self-attriting |
| Identifier model | Stable device-account pseudonym; one account may serve a household |
| Patient master dependency | None |
| HCP master dependency | None |
| Transmission | API, near real-time |
| Longitudinal capability | High frequency, subject to informative attrition — see §12 |
| Decision contribution | Monitoring sustainability. Not persistence, despite being used for it twice. |
| Safety relevance | Low — no free text |
| Privacy sensitivity | High — biometric time series is highly identifying in combination |
| Quality risks | Measurement method absent; household sharing undetected; attrition correlates with outcome |
| Selection profile | People who acquired and retained a device. The most selected population in the estate. |
| Denominator | Devices activated. Not people, and not people on treatment. |
| Observability window | Until the device goes quiet. Median 31 weeks, heavily right-skewed. |
| Reciprocal need | Clinical interpretation guidance and co-branded onboarding content |
What the affiliate can reasonably know
Weight trajectory, at high frequency, for people still engaged with measuring.
What it cannot know from this partner alone
Anything about the people who stopped — which is the group the persistence question is about.
P04 · Nutrition / behaviour / DTx 2 partners · 1 active feed
| Field | Value |
|---|---|
| Role in the journey | Onboarding, behaviour support, adherence, tolerability coping |
| Primary user | Patient |
| Receivable grain | Stable pseudonym / longitudinal subject / engaged subset of an engaged population |
| Identifier model | Stable app-account pseudonym |
| Patient master dependency | None |
| HCP master dependency | None |
| Transmission | API, weekly batch |
| Longitudinal capability | Strong within the programme; nothing after disengagement |
| Decision contribution | Association between support exposure and persistence, with the selection limitation stated |
| Safety relevance | High — symptom logging and free-text journalling |
| Privacy sensitivity | High — dietary and behavioural data, and symptom content |
| Quality risks | “Engagement” is partner-defined and has been redefined once; no restatement of history |
| Selection profile | Doubly selected — people who downloaded, and people still using |
| Denominator | Active users in the period, partner-defined |
| Observability window | Until app abandonment; no exit signal |
| Reciprocal need | Clinically reviewed nutrition content and tolerability guidance |
What the affiliate can reasonably know
What supported people do, and what they report while they are being supported.
What it cannot know from this partner alone
Whether the support caused anything. There is no comparison group and no route to one.
P05 · Care navigation / HCP discovery 1 partner · no feed
| Field | Value |
|---|---|
| Role in the journey | Discovery and routing to appropriate care |
| Primary user | Patient, searching |
| Receivable grain | Anonymous event / cross-section / all searchers |
| Identifier model | None. Session-level only, by design. |
| Patient master dependency | None |
| HCP master dependency | Very high — this partner is entirely built on Layer 1 professional and organisation data |
| Transmission | No feed today. Reporting by monthly PDF. |
| Longitudinal capability | None, and none is appropriate |
| Decision contribution | Network coverage; geographic access gaps; demand signal by area |
| Safety relevance | Low |
| Privacy sensitivity | Low — no personal data received |
| Quality risks | Directory staleness. Closed sites and lapsed registrations are the live risk. |
| Selection profile | People who search online. A demand signal, not a population. |
| Denominator | Searches, not people |
| Observability window | n/a |
| Reciprocal need | Verified service capability data and up-to-date site information |
What the affiliate can reasonably know
Where demand is, where provision is, and where the two do not meet.
What it cannot know from this partner alone
Anything about individuals, and whether a search led to care.
P06 · HCP workflow / clinical support 1 partner · active
| Field | Value |
|---|---|
| Role in the journey | Professional-side education, workflow and decision support |
| Primary user | Health professional |
| Receivable grain | Verified professional identifier / repeated cross-section / full user base |
| Identifier model | Regulator identifier, verifiable against a public register. The only verifiable identity in the estate. |
| Patient master dependency | None |
| HCP master dependency | Very high, and reciprocally useful |
| Transmission | API, weekly |
| Longitudinal capability | Strong for the professional; none for the patient |
| Decision contribution | Adoption; unmet need; and, once captured, clinical inertia |
| Safety relevance | Moderate — professional queries occasionally contain case detail |
| Privacy sensitivity | Moderate — professional rather than patient data, still personal |
| Quality risks | Organisation affiliation stale; a professional may hold several active roles |
| Selection profile | Professionals who adopted the tool. Not the professionals who most need it. |
| Denominator | Registered users. Not professionals seeing these patients. |
| Observability window | Continuous while registered |
| Reciprocal need | Clinical content, guideline updates, case material |
What the affiliate can reasonably know
What professionals using this tool look at, and what they cannot find.
What it cannot know from this partner alone
What professionals not using this tool do, which is most of them.
P07 · Patient support service 1 partner · active
| Field | Value |
|---|---|
| Role in the journey | Onboarding, titration support, tolerability coaching, persistence, exit |
| Primary user | Patient, with a trained support agent |
| Receivable grain | Stable pseudonym / event-level longitudinal / people who made contact |
| Identifier model | Stable service pseudonym |
| Patient master dependency | None |
| HCP master dependency | Low |
| Transmission | Monthly extract, mixed structured and free text |
| Longitudinal capability | Contact-level, across the whole treatment course |
| Decision contribution | The only source of stop reasons and structured tolerability in the estate |
| Safety relevance | Very high — direct patient contact, free text, and the highest yield of reportable content |
| Privacy sensitivity | Very high — symptom and personal circumstance detail in call notes |
| Quality risks | Reason captured as free text; agent-to-agent variation in what gets recorded |
| Selection profile | People who contacted, i.e. people with a problem. Strong selection toward difficulty — which is precisely why it holds the exit data. |
| Denominator | Enrolled in the support programme |
| Observability window | Enrolment to last contact; no closure event |
| Reciprocal need | Clinical escalation pathways, training, and current tolerability guidance |
What the affiliate can reasonably know
Why people struggle and, uniquely in this estate, why they stop.
What it cannot know from this partner alone
Anything about the people who never called, who are the majority and who stop silently.
P08 · Evidence / data / RWE partner 1 partner · periodic outputs
| Field | Value |
|---|---|
| Role in the journey | Aggregation, outcomes, utilisation and evidence generation |
| Primary user | Affiliate Medical and Market Access |
| Receivable grain | Aggregate only / repeated cross-section / defined cohort with a stated denominator |
| Identifier model | None received. Linkage performed by the partner under its own governance. |
| Patient master dependency | High at source, none at the affiliate |
| HCP master dependency | Moderate at source |
| Transmission | Scheduled analytical output, quarterly |
| Longitudinal capability | Yes, at cohort level. The only genuine longitudinal outcome view available. |
| Decision contribution | Outcome evidence for access conversations |
| Safety relevance | Low — aggregate |
| Privacy sensitivity | Low at the affiliate; high at source |
| Quality risks | Cannot be decomposed, verified or re-cut. The affiliate takes the output on trust. |
| Selection profile | Defined by the partner’s own data sources; stated, which is more than any other feed manages |
| Denominator | Stated with every output. The only feed that does this. |
| Observability window | As specified per output |
| Reciprocal need | Research questions, clinical input, protocol review |
What the affiliate can reasonably know
Cohort-level outcomes with a denominator you can quote.
What it cannot know from this partner alone
Anything at subject level, and anything you did not specify before the analysis ran.
Reading the last pair across all eight. Each partner’s blind spot is covered by another partner. Almost none of those pairings can be made, because they need linkage at L2 and the estate sits at L0.
Human factors
The work system, not the interfaceOne analyst holds the only complete view of the estate, assembles it by hand every month, and appears in no system, no capacity plan and no management report. That is the work system this design had to change.
| Property | What it looks like today | Design consequence |
|---|---|---|
| Workload | Two to three days a month of assembly, concentrated in the four days before the pack is due, on top of a full analytical role | Automating assembly is worth more than any model in the portfolio. It is also the least interesting part of the programme to talk about, which is why it had not been done. |
| Memory demand | Seven identifier schemes, three denominators and eleven partner quirks held in one head and in a personal spreadsheet | Externalise into the catalogue. The knowledge is not written down anywhere the organisation can reach. |
| Interruption profile | Reconciliation is done in fragments between other work; a full pass is never uninterrupted | Every step must be resumable and must leave a record of where it got to. Batch processes that must complete in one run fail here. |
| Search cost | Locating the current definition of a partner metric means finding the last email in which it was explained | A definition register with versions, reachable from the figure that uses it. |
| Error recovery | A wrong number is discovered when someone downstream queries it, typically two cycles later | Checks move upstream to arrival. Recovery becomes quarantine and re-run rather than retraction. |
| Accountability | The analyst is accountable for a number assembled from seven sources they do not control | Fitness verdicts carry a named decision owner. The analyst becomes accountable for the process, not for the partners’ data. |
| Situation awareness | Downstream readers see a figure with no denominator, coverage or bias | The confidence card. The single largest human-factors change in the design. |
| Degraded operation | When a feed fails, the pack is produced anyway with a footnote nobody reads | Explicit degraded modes with visible markers, and blocked publication where the figure cannot be defended. |
The concepts that earned their place
| Concept | Where it applies here | The design decision it produced |
|---|---|---|
| Ironies of automation | Automating the clean 80% of mapping leaves the analyst only the ambiguous cases, cold, with no warm-up on the easy ones | Confirmation is required on every mapping, not only the uncertain ones. The easy confirmations keep the analyst calibrated and cost seconds. |
| Automation bias | A green conformance light will stop people looking. The gateway is most dangerous where it is most reassuring. | The card states what the figure cannot tell you even when every check passed. Reassurance is never the terminal output. |
| Trust calibration | Two feeds pass identical checks and one is unfit. Uniform presentation would teach uniform trust. | Fitness is per decision and rendered per decision. The same feed shows fit for one question and blocked for another, on the same screen. |
| Situation awareness | Persistence figures were being read without denominators for eighteen months, correctly and to the wrong conclusion | Denominator and observability window are mandatory card fields, and a missing value renders as UNKNOWN at full weight. |
| Skill, rule and knowledge | Mapping a field is rule-based. Judging fitness is knowledge-based. Both had been treated as clerical. | The split runs straight down the allocation matrix — machines take the rule-based work, people keep the knowledge-based work. |
| Informative attrition | P03’s missingness is a behaviour, not a gap | Observability window and attrition reason became required catalogue fields, and the gateway blocks solo persistence use of P03. |
Function allocation
Thirty-one activities, four stages eachAutomation applies independently to information acquisition, information analysis, decision selection and action implementation. Scoring the four separately produces a different answer from asking whether a task should be automated.
| Dimension | Question | Effect on the score |
|---|---|---|
| Reversibility | Can the outcome be undone before it reaches anyone outside? | Irreversible caps decision and action at zero regardless of model performance. |
| Named-person requirement | Does a rule or an accountability structure require an identified human? | Ends the analysis for that stage. |
| Failure asymmetry | What does a false negative cost against a false positive? | Strong asymmetry pushes toward assist with a low threshold, never toward automate. |
| Judgement content | Is it recognition or interpretation? | Recognition can be assisted. Interpretation is preserved. |
| Data readiness | Does the record needed to do this exist yet? | Absent data defers rather than declines. Six activities sit behind the catalogue work. |
| Consequence | What happens downstream if this is wrong? | High consequence with low frequency is the worst automation candidate in the set. There are three. |
| Process integrity | Is the current process the right one? | Where no, the activity goes to redesign and no capability is specified for it. |
Redesign — the four that needed no capability at all
| Activity | Was | Became | Why it is redesign rather than automation |
|---|---|---|---|
| Denominator reconciliation | Three functions each computing their own, monthly, and disagreeing | One canonical denominator, defined once, versioned, with the two others retired | Automating three wrong reconciliations produces three wrong answers faster. |
| Safety recognition | Partner staff deciding whether content is potentially reportable | Partners forward everything on a defined cadence; recognition returns to trained affiliate staff | The judgement was in the wrong place. No model changes that; moving it does. |
| Partner onboarding | Four functions specifying separately, at different times | One specification issued at contracting, from the catalogue | The sequence was wrong, not the effort. |
| The monthly pack | Assembled by hand, containing four charts nobody uses | Generated from the decision datasets; anything without a decision owner removed | Automating the assembly of unused charts is the most expensive way to keep them. |
The capability portfolio
Eleven builtThirty-four candidates from W4, reduced to eleven. All are assistive or deterministic, all produce output a person acts on, and none makes a determination that leaves the organisation.
The models, and everything that is not a model
Six models in a system of thirty-one automated steps. Everything else is rules. The rules carry the weight and the models are the cheap part. Every proposal the affiliate had received before this one had it the other way round.
| Model | Technique | Trained or grounded on | Confirmed by | Wrong output costs |
|---|---|---|---|---|
| M1 Agentic interview | Language model driving a branching question tree, with catalogue retrieval | The canonical catalogue and prior sessions | Partnership lead reads the transcript | A poor follow-up question. The transcript is visible and the partner can correct the mapping live. |
| M2 Offer mapping | Retrieval over the catalogue plus classification | 187 catalogued elements with definitions | Data product confirms every mapping | Caught at confirmation. Mis-mapping a novel element is the realistic failure and it surfaces immediately. |
| M3 Drift detection | Statistical tests plus a model for distributional shift | The registered contract and 12 months of feed history | Data engineering decides whether to accept | A false positive costs a review. A false negative is the state before the system existed. |
| M4 Field mapping | Few-shot classification over confirmed prior mappings | Every confirmed mapping in the estate, growing | Data product confirms every mapping, including the obvious ones | Caught at confirmation. Confirming the easy ones is deliberate — it keeps the reviewer calibrated. |
| M5 Rights extraction | Extraction with span citation | The agreement set and the seven-field vocabulary | Privacy confirms or corrects every value | Caught at confirmation. The quoted clause is what makes confirmation fast enough to actually happen. |
| M6 Safety surfacing | Classification and ranking over an exhaustive queue | Reviewer decisions, reviewed quarterly, never applied automatically | Trained reviewer assesses every item regardless of rank | A missed item sits lower in a queue that is still read end to end. A random tail sample runs every sweep. |
| M7 Evidence summary | Summarisation with citation | Partner-supplied evidence documents | Reader follows the links for anything material | A misleading summary. Every claim carries a link and reviewers are told to follow them. |
| Capability | Stage | What it does | What the person does | When it is wrong | Value | Risk |
|---|---|---|---|---|---|---|
| Schema and type conformance | acquisition | Deterministic validation against the expected shape | Nothing until it fails | Rejects a valid record; the partner is notified and it is re-sent | High | Low |
| Drift detection | acquisition | Compares arriving structure to the registered contract | Reviews the diff, decides whether to accept | Fires on a benign change; costs a review | High | Low |
| Field mapping to canonical | analysis | Proposes a mapping from partner field to catalogue element, with the evidence | Confirms every mapping, including the obvious ones | Caught at confirmation; the obvious cases are what keep the reviewer calibrated | High | Medium |
| Rights extraction | analysis | Proposes values for the seven rights fields from an agreement, quoting the source clause | Privacy confirms or corrects every value | Caught at confirmation. The quoted clause is what makes confirmation fast enough to happen. | High | Medium |
| Benchmark scoring | analysis | Scores a feed against the benchmark family for each data type | Reads the score; decides on exceptions | Deterministic. A wrong threshold is a configuration error, not a model error. | High | Low |
| Coverage overlap detection | analysis | Maps a candidate partner’s offer against the estate and shows what is new | Portfolio owner decides | Over-states novelty; the assessment output shows the working | High | Low |
| Anomaly detection in a feed | analysis | Flags distributional shifts that no schema check catches | Investigates | False positive costs an investigation; false negative is the pre-existing state | Medium | Low |
| Evidence summarisation | analysis | Summarises partner-supplied evidence with links back to the source | Reads the source for anything that matters | Summary misleads; every claim carries a link and reviewers are told to follow them | Medium | Medium |
| Safety content surfacing | acquisition | Orders partner-forwarded content by likelihood of being safety-relevant | Trained reviewer assesses every item; order changes, coverage does not | A missed item sits lower in an exhaustive queue, never outside it. A random tail sample runs every sweep. | High | High — controls in §22 |
| Assessment interview | acquisition | Conducts the structured partner interview, branching on answers | Reviews the transcript and the derived profile | Asks a poor follow-up; the transcript is visible and the profile is confirmed | High | Low |
| Confidence card assembly | analysis | Populates the card from the record at publication | Reads it; may not remove a field | Cannot be wrong independently — it renders stored values. A wrong value is wrong upstream. | High | Low |
The declined set
Eight, with the reasoningMost of what was asked for.
Predictive partner scoring
The most requested capability in discovery and the first to fail. It needs a common outcome measure across partners; there is none, and the linkage ceiling means there cannot be one at L0. Partner-reported metrics describe the reporting rather than the performance, so a model trained on them learns the reporting. Deferred until L2 exists, at which point it may still be the wrong idea.
Automated renewal recommendation
A recommendation is a decision in everything but name — once a system produces one, the human role becomes ratification, and ratification under time pressure is not review. The gateway assembles the evidence pack instead and recommends nothing.
Automated safety classification
Deciding whether content is potentially reportable is exactly the judgement the current design gets wrong by placing it with partners. The judgement fails because the person making it is untrained. A model would not be trained either. Surfacing and ordering are automated; the determination is not.
Cross-partner identity resolution
Probabilistic matching on quasi-identifiers would work technically and would manufacture linkage the rights position does not permit. It also creates re-identification risk in a dataset assembled specifically to avoid it. Declined on governance rather than feasibility.
Patient-facing conversational support
Proposed as an adherence capability inside partner apps. Sits close enough to the medical-device boundary that it needed a classification assessment nobody had run, and it lives at the highest-consequence point in the journey. Adding a safety intake route to those same surfaces delivered the reachable part.
Synthetic data generation to fill gaps
Proposed to fill the tolerability and stop-reason gaps. Synthetic records would carry the shape of evidence without the content, and nothing downstream could distinguish them from real ones. The gaps are real findings and are reported as gaps.
Automated rights determination
The model proposes the values. Privacy confirms them. A wrong lawful basis is not corrected by deleting the data afterwards, and the accountability for the determination has to sit with a person who can be asked why.
An agentic partner-monitoring platform
The opening hypothesis: a system that continuously watches every partner, ingests their data, scores them and recommends action. It presumes a complete register, a rights position permitting ingestion, comparable metrics and a defined action space. None of the four existed.
The pattern in the eight. Six were declined on governance or accountability rather than on capability, and every one of those six would have worked technically. Only two were declined because the data does not support them. Six of eight would have worked technically.
Human checkpoints
Nine, each with a basisJustified against evidence rather than caution. Three exist because accountability requires a person who can be asked why; four because the error cannot be withdrawn; two because the people doing the work asked, and their reasoning held.
| Checkpoint | Level | Why it stays human | Basis |
|---|---|---|---|
| Rights determination | Always human | A wrong lawful basis is not corrected by deleting the data. Accountability has to rest with someone who can explain the determination. | Privacy, W5: “I can defend a judgement. I cannot defend a field that was populated for me.” |
| Fitness verdict for a decision | Always human | It is a relation between data and a decision only the decision owner fully holds. The gateway can compute the inputs; it cannot hold the intent. | W1 — four “decisions” dissolved on inspection. A machine would have scored all four. |
| Safety relevance determination | Always human | Trained judgement inside an established process. Nothing in this design reaches past the intake boundary. | Patient Safety, W5, and the existing process definition |
| Denominator definition | Always human | A definitional choice with consequences across every rate the organisation publishes. It is a decision, not a calculation. | F-07 — three functions, three reasonable definitions, an 18–22% spread |
| Partner approval or termination | Always human | Irreversible, externally visible, contractually consequential | Standard practice, confirmed in W5 |
| External communication to a partner | Human approval | Machine drafts; a person sends. A remediation request in the wrong tone damages a relationship the affiliate cannot easily replace. | W5 — raised by Partner Operations, unprompted |
| Field mapping confirmation | Human approval, every item | Not because mapping is hard, but because confirming the easy ones keeps the reviewer calibrated for the hard ones | Ironies of automation. The design cost is seconds per item. |
| Publication of a figure | Human approval | The last point at which anyone can ask whether this number should exist | F-11 — nothing published carried its limits |
| Overriding a blocked publication | Human approval, named, logged | Blocks must be overridable or people route around the system. The override is the record. | W5 pre-mortem: an unoverridable block produces a shadow spreadsheet within a quarter |
Human–AI interaction
The loop, and what happens when it failsOne loop serves both products. The property that made it acceptable to the safety and privacy functions is that every failure mode returns the system to the state that preceded it, never to silence.
| Capability | Machine knows | Machine does | Person sees | At low confidence | Failure behaviour |
|---|---|---|---|---|---|
| Field mapping | Catalogue definitions, prior confirmed mappings, the partner’s own field names and sample values | Proposes a target element and a grain | Proposal, the sample values it reasoned from, and the prior mapping if one exists | Proposes nothing and says so, rather than guessing | Mapping halts; deterministic checks continue; the analyst maps by hand as before |
| Rights extraction | The agreement text and the seven-field vocabulary | Proposes a value per field with the source clause quoted | Every proposed value beside its clause | Marks UNKNOWN — never a default | Field written as UNKNOWN; every dependent decision blocked |
| Safety surfacing | Forwarded content, surface metadata, prior reviewer decisions | Orders an exhaustive queue by likelihood | Item, surface, timestamp, original text, position and the stated reason | Everything enters the middle band | Queue reverts to chronological. Coverage never changes. |
| Benchmark scoring | Feed profile, benchmark family, decision requirement | Computes and compares | Score, threshold, and which decision the threshold came from | n/a — deterministic | Scoring unavailable; last good score shown with a staleness marker |
| Coverage overlap | The canonical catalogue and the current estate | Maps a candidate offer and shows what is new | Overlap map with the reasoning | Marks the element as unclassifiable and asks | Falls back to manual comparison against the catalogue |
| Assessment interview | The catalogue, the question tree, prior answers | Conducts the interview, branching on answers | Full transcript and the derived profile | Escalates to a human interviewer | Reverts to the static questionnaire the interview replaced |
| Confidence card | Every stored property of the dataset | Renders | The card | Renders UNKNOWN at full weight | Publication blocked |
The sampling control
A model that is consistently wrong in one direction is indistinguishable, from the reviewer’s seat, from a model that is right — because the reviewer only sees what the model surfaced first. A fixed proportion of the bottom band is drawn every sweep and reviewed ahead of the rest. It is the only way to detect the failure from inside the process, and it is cheap.
The Partner Data Assessment Instrument
Product oneAn agentic intake that interviews a prospective partner and returns a decision pack. It replaced a nineteen-question static form that took four weeks to complete and produced answers nobody could compare.
| Problem with the form | What the interview does |
|---|---|
| The useful follow-up question depends entirely on the previous answer. A form asks all of them or none. | Branches. A partner who says “we hold weight measurements” is then asked how the measurement was taken, whether the method is recorded, and whether the account can be shared — three questions no other partner would receive. |
| Partners answer in their own vocabulary; the affiliate cannot compare answers across partners. | Maps every answer to the canonical catalogue as it goes, and shows the partner the mapping so they can correct it. |
| A partner cannot tell what a good answer looks like, so answers optimise for sounding capable. | States the benchmark for each element before asking, which changes the answer from a claim to a measurement. |
| The form asks what data exists. It never asks what is transmissible. | Asks the receivable-grain questions explicitly, on all three axes, and asks about identifier stability, which no partner had ever been asked before. |
| Four weeks of email, then a spreadsheet nobody revisits. | A session, a transcript, a derived profile, a coverage map and a draft confidence card. |
| Block | The questions | Why here |
|---|---|---|
| 1 · Business shape | Archetype, journey stages touched, primary user, service model | Determines everything that follows. A wrong archetype produces a wrong question tree. |
| 2 · What is generated | What the service creates as a by-product of doing its job | Deliberately separated from what is transmissible. Partners conflate the two, and the gap is informative. |
| 3 · Receivable grain | Finest transmissible grain on identity, temporal structure and population scope, per element | The core of the instrument. Three axes, asked separately, in the partner’s own terms and mapped afterwards. |
| 4 · Identifier model | Scheme, stability over time, reset conditions, whether the same subject is recognisable across datasets | Nobody had ever asked. Two partners discovered their own answer during the session. |
| 5 · Denominator | Who counts as a subject, when they enter, when they leave, and whether the definition has changed | The single most common source of incomparability in the estate |
| 6 · Selection and observability | Who is in this population and who is not; how long a subject stays visible; why they leave | Where informative attrition is caught, before contracting rather than eighteen months later |
| 7 · Rights | Purpose, basis, onward transfer, linkage, retention, secondary use | Proposed by extraction from the draft agreement where one exists; confirmed here |
| 8 · Operations | Transmission route, cadence, change notification, support model | What the gateway will need |
| 9 · Reciprocity | What the partner needs from the affiliate | A one-directional model produces agreements partners have no reason to honour well |
| Output | Contents | Who uses it |
|---|---|---|
| Coverage map | The candidate’s journey coverage against the existing estate, with new, overlapping and absent marked | Portfolio owner — the “does this add anything” decision |
| Grain profile | Three-axis position per offered element, with the fitness consequence for each affected decision | Data product and the decision owners |
| Linkage assessment | Current rung, and what would move it up one | Legal, Privacy, and the partnership lead |
| Draft rights position | Seven structured fields, proposed, with source clauses | Privacy, who confirms every value |
| Specification | What the affiliate requires this partner to send, generated from the catalogue | Goes into the agreement, not into an email afterwards |
| Draft confidence card | What any figure derived from this partner will be able to say, and what it will not | The decision owner, before signature |
| Transcript | The full session | Everyone. It is the evidence that the profile is not invented. |
The Conformance Gateway
Product twoEverything an existing partner sends passes through four tests in order. The first three are properties of the data. The fourth is a relation between the data and a named decision, and it is the one that fails.
| Stage | What it does | What it enforces | On failure | Measure |
|---|---|---|---|---|
| Landing | Receives, records arrival, computes a fingerprint | Nothing yet — arrival is always recorded, including malformed arrivals | Records the arrival and the failure. A feed that fails at the door is a fact, not an absence. | Arrivals against expected schedule |
| Structural validation | Schema, types, controlled vocabularies, event ordering | The registered contract | Rejects the record, notifies the partner, never coerces silently | Rejection rate by feed and by field |
| Drift detection | Compares arriving structure and distribution to the registered baseline | Change is an event, not a discovery | Quarantines at staging; the last good publication stands with a staleness marker | Time from drift to detection |
| Canonical mapping | Maps partner fields to catalogue elements | One vocabulary | Unmapped fields land in a holding area and are reported, not dropped | Unmapped field count; time to resolve |
| Rights check | Compares the intended use against the structured rights position | Purpose, grain, linkage and retention | Blocks the use, not the ingestion. The data may be lawful for a different purpose. | Blocked uses, and how many were resolved by a rights change |
| Benchmark and quality | Six dimensions against the benchmark family for each data type | Thresholds set by decision requirement | Publishes with the measured value stated rather than withholding | Pass rate by dimension |
| Fitness assessment | Compares grain, denominator, observability, coverage and known bias against each decision’s requirement | Fitness per decision, not per feed | Blocks that decision only. The feed remains fit for others. | Fit and unfit counts per decision |
| Publication | Releases with a populated confidence card | No card, no publication | Blocked, with a named override path | Publications; overrides; override reasons |
Ingestion into the existing estate
| Step | What is implemented | Measure attached |
|---|---|---|
| Land | Immutable arrival store, one object per arrival, fingerprinted | Arrival completeness against schedule; time to land |
| Validate | Contract-driven validation at the boundary, not in the warehouse | Rejection rate; false-rejection rate from partner disputes |
| Map | Canonical mapping with confirmed lineage per field | Unmapped fields; mapping changes per period |
| Reconcile | Canonical denominator applied; the two retired definitions retained as views for one transition period | Variance between old and new definitions, reported until the views are removed |
| Enrich | Reference data joined from Layer 1 — organisation codes, professional status | Reference join rate; stale reference rate |
| Publish | Decision datasets built, versioned, and released with a card | Publication latency; card completeness; blocked publications |
Features
What a user encounters| Feature | User | Problem it solves | What was built | The human’s part | Type |
|---|---|---|---|---|---|
| Guided partner interview | Partnership lead, partner | Four weeks of email producing incomparable answers | Branching agentic session with live mapping shown to the partner | Reviews the transcript; can take over at any point | AI |
| Coverage map | Portfolio owner | No way to see whether a candidate adds anything | Journey-by-archetype map with new, overlapping and absent marked | Decides | Product |
| Grain profile card | Data product, decision owner | Grain discussed in one word, meaning three things | Three-axis profile per element, with fitness consequences | Confirms | Product |
| Rights cockpit | Privacy, analyst | Rights unreadable without opening eleven agreements | Seven structured fields per engagement, queryable, with source clauses | Confirms every value | AI + product |
| Specification generator | Partnership lead, Legal | Partners define their own metrics because nobody specified | Requirements generated from the catalogue for the agreement | Reviews and negotiates | Product |
| Arrival monitor | Data engineering | Feed failures discovered two cycles later | Arrival tracking against schedule with fingerprinting | Investigates exceptions | Configuration |
| Drift alert | Data engineering, data product | Silent schema change | Structural and distributional comparison against a registered baseline | Decides whether to accept | AI + rules |
| Mapping workbench | Data product | Manual mapping held in one person’s spreadsheet | Proposed mappings with sample values and prior decisions | Confirms every mapping | AI |
| Fitness board | Decision owner | A feed reported as green while being useless | Fit or blocked per decision, with the failing criterion named | Sets the requirement; issues the verdict | Product |
| Decision confidence card | Every reader of every figure | Figures published bare | Auto-populated component attached at publication | Reads it; cannot remove a field | Product |
| Safety review queue | Patient safety reviewer | Cadence set by whoever configured the surface; recognition by partners | Exhaustive queue, ordered, with a random tail sample | Assesses every item | AI |
| Definition register | Analyst, everyone | The current definition lives in the last email that explained it | Versioned definitions, reachable from any figure that uses them | Owns and versions | Product |
| Evidence pack assembly | Business owner, Finance | Renewal on relationship history | Assembles everything known about a partner into one reviewable pack | Decides. The pack recommends nothing. | AI + product |
| Override log | Everyone | Blocks get routed around and nobody knows | Named, reasoned, logged override on any block | Provides the reason | Configuration |
Capabilities
What the system can do underneath| Capability | Serves | Depends on | What breaks without it |
|---|---|---|---|
| Canonical catalogue | Everything | Nothing — it is the root | There is no vocabulary, so nothing can be compared, specified or mapped |
| Receivable grain model | Grain profile, fitness board, assessment | Catalogue | Grain gets discussed in one word and the catalogue misdescribes half the estate |
| Linkage state per partner | Fitness board, coverage map | Catalogue, agreements | Cross-partner questions get commissioned and quietly abandoned |
| Structured rights position | Rights cockpit, gateway rights check | Agreement set, controlled vocabulary | Every analysis waits on a legal read and the portfolio question stays unanswerable |
| Decision inventory | Fitness board, card, catalogue prioritisation | W1 output, maintained | Fitness has nothing to be assessed against and the catalogue reverts to a field list |
| Denominator register | Every rate, the card | Canonical definitions | Three functions quote three numbers and nobody can say which is right |
| Observability model | Card, fitness board | Feed profiling | Longitudinal claims are made from feeds that cannot support them |
| Contract registry | Drift detection, validation | Catalogue, onboarding | Drift is undetectable because there is no baseline to compare against |
| Quality engine | Gateway stages 5 and 6 | Contract registry, benchmarks | Quality is discovered by the analyst preparing the pack |
| Fitness engine | Fitness board, publication block | Decision inventory, quality engine, grain model | Feeds are reported green and used wrongly |
| Lineage | Card, audit, dispute resolution | All pipeline stages emitting events | A published number cannot be defended when challenged |
| Confidence card renderer | Publication | Every capability above it | The care taken upstream evaporates at the last step |
| Extraction and mapping models | Mapping workbench, rights cockpit | Catalogue, agreement set, confirmed examples | The work is done by hand, which is the pre-existing state and is survivable |
| Surfacing model | Safety review queue | Surface inventory, reviewer decisions | Queue reverts to chronological. Coverage is unaffected. |
| Feedback store | Model improvement | Confirmations and overrides | Models stop improving. Nothing else breaks. |
Information model
Seventeen entities, one owner eachOwnership was the contested part. Every attribute resolves to exactly one function, and ownership is a named individual rather than a function, because a function cannot be asked what it decided and why.
The confidence card, rendered
Future state
The same data point, again| # | Was | Now | Residual |
|---|---|---|---|
| B1 | Partner defines the metric | Specification issued from the catalogue at contracting; definitions versioned | Legacy agreements carry old definitions until renewal |
| B2 | Aggregation destroys the grain | Contracted grain stated on three axes and tested at arrival | Two partners cannot supply finer grain without a platform change of their own |
| B3 | Silent schema drift | Registered contract; drift is an event with a named reviewer | Distributional drift is harder than structural and will produce false positives for a while |
| B4 | No contract check at landing | Rights checked from structured values before publication | Rights extraction is assistive; every value still needs a human confirmation |
| B5 | No cross-partner key | Linkage state explicit per partner; unsupported joins refused rather than warned | The ceiling itself is unchanged. This makes it visible, not solvable. |
| B6 | Reconciliation invisible | Canonical denominator, automated assembly, analyst confirms | The confirmation load is real and was deliberately not minimised |
| B7 | Rights read under pressure | Queryable before an analysis is commissioned | Novel purposes still need a determination, and should |
| B8 | Lineage stops at the warehouse | Carried to publication | Two feeds arriving by attachment have lineage that starts at the mailbox |
| B9 | The number arrives bare | No card, no publication | None. This one is closed. |
Operating model
Who decides what| Decision | Decides | Consulted | Escalates to |
|---|---|---|---|
| Whether an arrangement is a partnership at all | Portfolio owner | Legal, the proposing function | Digital leadership where the archetype is contested |
| Archetype classification | Portfolio owner | Data product | Portfolio forum |
| Whether a candidate adds coverage | Portfolio owner | Decision owners affected | Digital leadership |
| The specification issued to a partner | Data product | Decision owners, Legal, Privacy | Portfolio forum |
| Contracted grain | Data product with Legal | Partner, decision owners | Portfolio forum |
| Rights position values | Privacy | Legal, engagement owner | Data protection lead |
| Linkage rung and any move up it | Privacy with Legal | Decision owners who need it | Data protection lead |
| Canonical denominator | Data product | Commercial, Medical, Market access — all three | Portfolio forum. This one was escalated, and settling it took two sessions. |
| Whether a mapping is correct | Data product | — | Data product lead |
| Fitness for a decision | The decision owner | Data product | Portfolio forum |
| Whether a figure is published | The decision owner | Data product | Portfolio forum |
| Overriding a publication block | Named individual, logged with a reason | — | Reviewed monthly at the portfolio forum |
| Screening cadence per surface | Patient safety | Partner, on feasibility | Existing pharmacovigilance chain |
| Whether safety content is reportable | Patient safety | — | Existing pharmacovigilance chain |
| Partner suspension or termination | Portfolio forum | Legal, Commercial, engagement owner | Affiliate leadership |
| Changes to any model | Owning function of the affected process | Patient safety where the safety path is touched | Portfolio forum |
What was deliberately not centralised
- The partner relationship. Stays with the engagement owner. A central function fielding every partner conversation becomes the bottleneck the redesign removed.
- Fitness verdicts. Stay with decision owners. Centralising them would separate the verdict from the intent it is a verdict about.
- Rights determination. Stays with Privacy. The register displays the position; it does not decide it.
- Whether a partnership is commercially worth having. Stays with Commercial. Governance sets whether it may proceed, not whether it is a good idea.
Measurement
What would show it worked| Level | Measure | Baseline | What it detects |
|---|---|---|---|
| Product | Catalogue elements with a named decision | 0 of 187 | Whether the catalogue is a decision instrument or a field list |
| Product | Feeds with a registered contract | 0 of 14 | Whether drift is detectable at all |
| Product | Rights positions held as structured values | 0 of 23 | Whether a portfolio rights question can be answered |
| Product | Figures published with a card | 0 | The closing measure on F-11 |
| Behaviour | Analyses checked against rights before commissioning | Unmeasured — the check happened afterwards | Whether the shift from retrospective to prospective actually happened |
| Behaviour | Mapping override rate | n/a | Model quality, and whether reviewers are still reading. A rate at zero is a warning, not a success. |
| Behaviour | Publication blocks overridden, with reasons | n/a | Whether the blocks are calibrated or are being routed around |
| Behaviour | Decisions citing a card in the meeting record | 0 | The only measure that shows the human-factors work landed |
| Operational | Analyst days per month on assembly | 2–3 days constructed | The workload finding. Measured properly from month one, having been estimated in discovery. |
| Operational | Time from schema drift to detection | 2 cycles, typical | Whether silent failure has stopped being silent |
| Operational | Feeds fit for their intended decision | 4 of 14 at the outset | The headline operational measure |
| Operational | Time from arrival to publication | Monthly cycle | Whether the pipeline runs at data speed or at meeting speed |
| Business | Decisions with traceable evidence | 4 of 27 | The measure the whole programme exists to move |
| Business | Partner renewals decided on evidence | 0 | Whether renewal has stopped running on relationship history |
| Business | Journey stages with usable coverage | 4 of 14 | Whether the estate is being shaped or accumulated |
| Strategic | Ability to answer a persistence question defensibly | Not possible | The single question the affiliate most needs and could not answer |
The working system
Six screensWhat the analyst, the partnership lead and the data team actually sit in front of. Each screen shows one task in progress rather than a feature list, and every model output in them is a proposal a person confirms.
One system, four layers
Four jobs, in sequence: build the evidence estate, protect its quality, use it, and keep it alive. The screens below sit in those layers rather than beside each other.
Layer 3 · Question desk
An analyst pastes what they were asked. The system decomposes it, narrows it to what the estate can support, names the evidence and drafts the answer. Nothing publishes without a person confirming.
Two questions in one. Why they leave is causal; what to do is allocation. Different evidence, separated below.
Unit: the person, from first dispense. Outcome: time to exit, right-censored. Denominator: enrolled at first dispense, v2 — fixed before counting.
| Required claim | Exit concentrates at an identifiable point, with an attributable reason |
| Population | Initiated in window, any route |
| Grain | Person-level, longitudinal, full partner cohort |
| Denominator | Enrolled at first dispense · v2 · fixed |
| Coverage | ≥90% of the initiating cohort |
| Observability | ≥26 weeks per person |
| Linkage | L1 sufficient for timing · L2 required for reason |
| Acceptable bias | Contactor selection tolerable if stated; silent leavers must not be imputed |
| Rights | Service operation · secondary analysis permitted |
| Invalidates it | A supply interruption inside the window that is not marked |
Exit concentrates between weeks eight and twelve, where most people move between dose steps. Among contactors, tolerability dominates before week twelve and cost after it.
Support belongs before week eight rather than at the point of exit. The two exit groups need different responses, and one is not a support problem at all.
| Grain | Stable pseudonym · longitudinal · full partner cohort |
| Observability | 26 weeks · 14% exit the feed before then |
| Known bias | Reasons only from people who made contact |
| Linkage | L1 · within one partner |
| Cannot tell you | Why the majority who left silently did so, or whether they restarted elsewhere |
Layer 3 · Cohort architect
Separate tool, separate job. Somebody already knows they need a group; the question is whether partner data can carry one. The critique panel argues with the design while it is still open.
| Dimension | Relevance to intent | Partner data | In design |
|---|---|---|---|
| Refill regularity | directly relevant | live | level 1 |
| Reason for difficulty | directly relevant | partial | level 2 |
| Supply gap pattern | relevant | live | — |
| Payer type | relevant | absent | — |
| Age band | weakly relevant | partial | — |
Retain · Reason for difficulty
Tied to the stated intent. Without it you have a group that leaves early and no way to know whether support would help.
Test separately · Refill regularity
May work better as a second-level split than an entry criterion. Erratic refilling could be the outcome rather than a selector.
Show both waysBlocked · Payer type
Would separate cost leavers from tolerability leavers. No partner sends it.
Open specificationLayer 1 · Partner assessment
Mid-session with a candidate partner. The interview branches on each answer, maps what they describe onto the catalogue as it goes, and shows the partner the mapping so they can correct it.
First — when a measurement arrives, do you record how it was taken? Clinic scale, connected device, or the patient typing a number in?
We store the source device ID. If it came from the app manually there’s a flag, but we don’t surface either in the export today.
L2.MEASUREMENT.method · identity: stable pseudonym · temporal: longitudinal · scope: self-selected
Held at source, not transmitted. This is a specification change, not a new collection. Serves D-05 monitoring sustainability and D-07 response shape.
Only that they stopped. We’d see the device go quiet.
Layer 1 · Partner portfolio
The review that had stalled for two cycles. Positions are computed from the catalogue rather than scored by hand, and the quadrant carries an action rather than a rank.
| Partner | Unique contribution | Failing | Change needed | Owner |
|---|---|---|---|---|
| P07 Patient support | Only structured route to stop reasons | taxonomy | Specification | M. Doyle |
| P03 Remote monitoring | Objective longitudinal measurement | attrition reason | Specification | M. Doyle |
| P06 HCP workflow | Professional-side behaviour | no patient join | Linkage L2 | — |
| 01a Telehealth | Private-route visibility | timestamps | Specification | R. Bell |
02a moved to Deepen
Denominator fixed. Fitness now passes for three decisions.
Two candidates assessed
One declined on 88% coverage overlap with an existing partner.
Layer 2 · Conformance gateway
Feed health across the estate. The column that matters is the last one — a feed can pass every quality dimension and still be unfit for the decision it was acquired for.
| Feed | Arrival | Schema | Drift | Rights | Quality | Contract | State |
|---|---|---|---|---|---|---|---|
| P02a dispensing | on time | pass | none | 7/7 | 6/6 | 4 fit | publishing |
| P03 device | continuous | pass | none | 7/7 | 6/6 | 1 fit · 2 blocked | partial |
| P07 support | monthly | pass | none | 5/7 | 5/6 | 1 fit · 2 blocked | partial |
| P04a behaviour | weekly | 3 fields | 2d ago | 7/7 | 5/6 | blocked | quarantined |
| P01a telehealth | nightly | pass | none | 6/7 | 6/6 | 2 fit | publishing |
| P06 HCP workflow | weekly | pass | none | 7/7 | 6/6 | 2 fit | publishing |
| P08 RWE | quarterly | n/a | n/a | 7/7 | stated | 1 fit | publishing |
| P05 navigation | — | — | — | n/a | — | — | no feed |
Every quality dimension passes
Completeness 98% · validity 100% · consistency 99% · timeliness continuous · uniqueness 0.1% · accuracy unverifiable.
Two contracts unsatisfied
D-01 persistence requires an acceptable-bias term this feed cannot meet: attrition correlates with the outcome and no attrition reason is captured.
D-03 stop analysis requires a reason the feed does not carry at all.
Satisfies D-07 response shape, whose contract tolerates the same bias.
Layer 4 · Evidence watch
The quiet one. Nobody goes back to check whether a blocked question has become answerable. This watches for the moment a question becomes answerable, and for the moment a published figure stops being safe.
Is a persistence dip real, or a stock artefact?
The pharmacy partner began sending supply-interruption markers last month. Two periods previously read as demand softening resolve as stock gaps.
Three published figures should be revisited.
Re-run the threeWhere is provision thinnest?
Reference data refreshed. Two areas previously below the reporting floor now clear it.
Behaviour programme engagement
The partner changed its engagement definition and did not restate history. Any trend spanning the change is uninterpretable.
Two dashboards affected, both marked.
| Question | Blocked on | Cycles | Status |
|---|---|---|---|
| Do outcomes differ by comorbidity? | Comorbidity burden | 1 | specification drafted |
| Cost per persistent patient | Supply route · channel vocabulary | 3 | no owner |
| Which prescribers under-escalate? | Patient–prescriber join | 4 | needs linkage |
| Does support extend treatment? | Selection, not data | — | not solvable here |
Two of the four waiting questions have sat unowned for three cycles or more. Neither is a data problem. Both need somebody to make a contractual decision.
What it is built on
No new platform. A thin application layer over what the affiliate already runs, with the catalogue as the only new system of record.
| Layer | What it is | Build or reuse | Why |
|---|---|---|---|
| Arrival store | Immutable object store, one object per arrival, fingerprinted | Reuse | Arrival is a fact and must survive a failed load. |
| Warehouse | The existing analytical warehouse | Reuse | Replacing it was proposed and declined. Nothing about the problem is a warehouse problem. |
| Orchestration | Existing scheduling and pipeline tooling | Reuse | Gateway stages run as ordinary pipeline steps. |
| Catalogue and spine | Metadata store holding elements, grain, rights, decisions, denominators, fitness | Build | Nothing existing holds a rights position as structured values or a fitness verdict per decision. |
| Rules engine | Deterministic checks, benchmark scoring, fitness logic | Build, small | The most important logic in the system, and none of it is a model. |
| Model services | Six models behind a confirmation step | Integrate | Swappable. Each degrades to the manual process that preceded it. |
| Application | Six screens | Build | Deliberately small. The value is in the spine. |
| Identity and access | Existing enterprise identity | Reuse | Named accountability needs named users, which already exist. |