Roadmap, priorities and delivery zones

What we build, in what order, and who builds it — with the arithmetic shown.

Leadership teamSeptember 2026Engineering lead
Scroll, or use the arrow keys
The whole picture, first

The ecosystem, becoming microservices

Everything Tracking Cube is today, and everything it is going to be. The further out a ring sits, the longer a clinic can keep working without it.

7 in use 2 in build 12 on the roadmap

Select anything on the map to see what it is.
Drag the map sideways to see all of it.
Where we start

What we are already carrying

Roughly 360 thousand lines of code across nine systems, a REDCap to PostgreSQL migration running PG-first with shadow compare, and an Australian privacy and security go-live obligation still open.

The estate, by size

The immediate risk is not capacity. It is concentration — backend, infrastructure and frontend knowledge each sit with one person.
What the rings mean

What happens when something breaks

The rings are not a diagram convention. They are a statement about failure: how far out something sits is how long a clinic can keep working without it. That is the whole reason the estate is shaped this way, and it is worth settling before anything else.

The map from the opening, again. Select anything to take it offline.

Drag the map sideways to see all of it.
The set of things that can stop a clinic is deliberately small — and it is the set we own.

So availability follows the rings, and so does the spend

High availability across the whole estate is roughly 2.5–3× the infrastructure bill. Ring by ring it is roughly 1.3×. We are not choosing to be less reliable — we are buying reliability where an outage reaches a clinician, and correctness-on-recovery everywhere else.

The engineering standard that makes Ring 1 safe to run cheaply — retries, dead-letter handling, idempotency, timeouts, correlation IDs — is already the contractual definition of done for every external package.

What the estimates left out

What one application actually costs

Every developer-month quoted anywhere is the build stage. That is what gets estimated, and it is less than half of what it takes to put an application in front of a clinician — the rest is ours, before it starts and long after it ships.

One application, end to end

— on the roadmap, commissioned out, and the most ordinary package on the list. Nothing about it is a special case.

The whole board

Everything on the table, in both currencies

20 blocks — the systems we already run, the nine applications on the roadmap, and the supporting services none of them work without. Each one is priced the way the last chapter priced a single application: what it costs once to deliver across the whole lifecycle, and what it costs every year afterwards if it puts a new system into production.

The arithmetic

What we can actually build

The capacity committed to all of it is one half-time full-stack developer, plus a technical lead whose time is architecture, contracts, review and acceptance — not build. That zero is not a rounding error; it is the design. A lead who is also the main implementer cannot review contractor deliverables, and unreviewed contractor work is the failure mode this whole model exists to prevent.

6 gross developer-months a year, less about 5 for run-the-business, leaves 1. Discretionary roadmap demand — the portfolio less the three blocks that are run-the-business — is 62 developer-months.

And that is build only

At today's capacity the roadmap is not slow. It has not started, and on this trajectory it does not start. 62 developer-months against one a year is not a schedule — it is a statement that the plan and the resourcing describe two different companies.

Four ways forward

Contractors are necessary but not sufficient. Around 45% of the portfolio cannot leave the building at any price — so external capacity alone leaves that 45% exactly where it is today.
Who builds what

Two zones, one decision rule

A capability stays internal if any of six things is true about it. It can be commissioned out only if all of five things are true. Nothing is assigned by preference or by who happens to be free.

36.5 developer-months stay inside · 44.5 can be commissioned.

Three blocks that split

Not everything is wholly one or the other. Three blocks divide — and the seam falls in the same place every time: authority over the system of record stays inside; the work that produces candidate data goes outside.

Every one of these seams is enforceable by IAM, not by trust: the external half never holds a credential that can write to the system of record.

Why services, and why contracts

Parallelism is the point

55% of the portfolio can be worked by people who are not us, at the same time — but only if it is expressed as independently deliverable components. Built as modules inside tc-api, that 55% would queue behind the same review, the same release train and the same one and a half people.

The microservice boundary is not an infrastructure preference. It is the mechanism that converts money into parallel delivery — and, as the rings already showed, the thing that keeps one failure from becoming all of them.

tc-api-contracts — OpenAPI and versioned event schemas, merged before the statement of work is signed. It is what lets three contractors work at once without coordinating with each other: they coordinate with the contract.

The sequence

Ordering, not dates. Dates follow the resourcing decision.

When it is all built

One child's journey through the ecosystem

Eleven stages, each with the surface that serves it and the people standing at it. Select a person to follow them through.

Served by the internal core Served by a commissioned service Split across the seam

Stages 1, 4, 8 and 10 are where external packages do the work. Stages 2, 5, 6, 7 and 9 are where the core decides. That is the same line as the seams, drawn on the journey instead of on the architecture — which is the point: the split is not an org chart, it is a property of the system.

What “done” looks like

One identity layer. One system of record holding identifiable clinical data behind one permission model. A ring of independently deployable services around it, several of them built by people who never had access to a production record. A warehouse serving outcomes to leadership without serving names. And a family who answered a questionnaire on their phone, whose answers landed on the same instrument the clinician is reading.
What we need from you

Six decisions

None of these are engineering decisions. Each one changes what is possible in the next two years.