Roadmap, priorities and delivery zones
What we build, in what order, and who builds it — with the arithmetic shown.
The ecosystem, becoming microservices
Everything Tracking Cube is today, and everything it is going to be. The further out a ring sits, the longer a clinic can keep working without it.
7 in use 2 in build 12 on the roadmap
What we are already carrying
Roughly 360 thousand lines of code across nine systems, a REDCap to PostgreSQL migration running PG-first with shadow compare, and an Australian privacy and security go-live obligation still open.
The estate, by size
What happens when something breaks
The rings are not a diagram convention. They are a statement about failure: how far out something sits is how long a clinic can keep working without it. That is the whole reason the estate is shaped this way, and it is worth settling before anything else.
The map from the opening, again. Select anything to take it offline.
So availability follows the rings, and so does the spend
High availability across the whole estate is roughly 2.5–3× the infrastructure bill. Ring by ring it is roughly 1.3×. We are not choosing to be less reliable — we are buying reliability where an outage reaches a clinician, and correctness-on-recovery everywhere else.
The engineering standard that makes Ring 1 safe to run cheaply — retries, dead-letter handling, idempotency, timeouts, correlation IDs — is already the contractual definition of done for every external package.
What one application actually costs
Every developer-month quoted anywhere is the build stage. That is what gets estimated, and it is less than half of what it takes to put an application in front of a clinician — the rest is ours, before it starts and long after it ships.
One application, end to end
— on the roadmap, commissioned out, and the most ordinary package on the list. Nothing about it is a special case.
Everything on the table, in both currencies
20 blocks — the systems we already run, the nine applications on the roadmap, and the supporting services none of them work without. Each one is priced the way the last chapter priced a single application: what it costs once to deliver across the whole lifecycle, and what it costs every year afterwards if it puts a new system into production.
What we can actually build
The capacity committed to all of it is one half-time full-stack developer, plus a technical lead whose time is architecture, contracts, review and acceptance — not build. That zero is not a rounding error; it is the design. A lead who is also the main implementer cannot review contractor deliverables, and unreviewed contractor work is the failure mode this whole model exists to prevent.
6 gross developer-months a year, less about 5 for run-the-business, leaves 1. Discretionary roadmap demand — the portfolio less the three blocks that are run-the-business — is 62 developer-months.
And that is build only
Four ways forward
Two zones, one decision rule
A capability stays internal if any of six things is true about it. It can be commissioned out only if all of five things are true. Nothing is assigned by preference or by who happens to be free.
36.5 developer-months stay inside · 44.5 can be commissioned.
Three blocks that split
Not everything is wholly one or the other. Three blocks divide — and the seam falls in the same place every time: authority over the system of record stays inside; the work that produces candidate data goes outside.
Every one of these seams is enforceable by IAM, not by trust: the external half never holds a credential that can write to the system of record.
Parallelism is the point
55% of the portfolio can be worked by
people who are not us, at the same time — but only if it is expressed as independently
deliverable components. Built as modules inside tc-api, that 55% would queue behind
the same review, the same release train and the same one and a half people.
tc-api-contracts — OpenAPI and versioned event schemas, merged before the
statement of work is signed. It is what lets three contractors work at once without coordinating
with each other: they coordinate with the contract.
The sequence
Ordering, not dates. Dates follow the resourcing decision.
One child's journey through the ecosystem
Eleven stages, each with the surface that serves it and the people standing at it. Select a person to follow them through.
Stages 1, 4, 8 and 10 are where external packages do the work. Stages 2, 5, 6, 7 and 9 are where the core decides. That is the same line as the seams, drawn on the journey instead of on the architecture — which is the point: the split is not an org chart, it is a property of the system.
What “done” looks like
One identity layer. One system of record holding identifiable clinical data behind one permission model. A ring of independently deployable services around it, several of them built by people who never had access to a production record. A warehouse serving outcomes to leadership without serving names. And a family who answered a questionnaire on their phone, whose answers landed on the same instrument the clinician is reading.Six decisions
None of these are engineering decisions. Each one changes what is possible in the next two years.