NHS Sovereign Federated Data Platform · 01 — Architecture

Federated coordination without unrestricted central control

Source integration, validation, canonicalisation, deterministic execution, operational products, security, audit and export remain separate and replaceable.

Complete layered route

Each layer has a declared responsibility and a replaceable interface

The platform does not become the clinical record merely because it consumes clinical and operational sources. Authority remains declared field by field and event by event.

L01
Source systems

EPR, PAS, referrals, waiting lists, ADT, theatres, beds, workforce, diagnostics, pharmacy and other authoritative systems.

L02
Connectors & integration

Approved extraction through FHIR R4, HL7, SQL, REST, queues, streams, CSV or controlled batch interfaces.

L03
Validation & standardisation

Structure, identity, dates, ranges, relationships and freshness are tested before versioned mappings are applied.

L04
Canonical operational data

Stable patient, organisation, location, practitioner, referral, pathway, appointment, admission and resource entities retain source links.

L05
Deterministic engine

Versioned pipelines, human-readable rules, checkpoints and idempotency controls calculate states and create governed tasks.

L06
Operational products

Dashboards, work queues, notifications, exports and reusable product packages operate against declared contracts.

L07
Federation

Local instances expose purpose-bound routes for trust, ICB, regional and national coordination while retaining local authority.

X
Cross-cutting controls

Identity, access, audit, provenance, security, accessibility, export, portability and governance apply across the full route.

Evidence-preserving data route

Source, canonical and derived states are never silently collapsed

1. Source envelope Organisation, source system, payload, source time, receipt time, schema and integrity evidence.
2. Validation result Named information, warning, review or blocking states. Failed input is retained.
3. Canonical record Governed operational entity with owner, version, temporal validity and source links.
4. Product state Exact rule and pipeline versions create a calculation, state, task or alert.
5. Evidence chain Actor, purpose, input, transformation, rule, result, human action, audit and export remain linked.

Federation model

Shared standards without centralised ownership

Federation is a controlled exchange between independently governed instances. It is not a single national database with unrestricted reach into every local record.

Level Authority Permitted coordination Boundary
Local / Trust Local controller and operating organisation Local pathways, queues, capacity and operational products Can continue independently if federation is unavailable
ICB Declared participating organisations and agreement Cross-provider coordination for an approved purpose Only registered datasets, routes, roles and retention
Regional Regional governance and product mandate Capacity, pathway and exception views across participating areas No automatic transfer of local operational authority
National Named national controller and product owner Approved aggregate, de-identified or specifically authorised products Purpose, lawful basis, fields, frequency and withdrawal are explicit

Connector boundary

Transport does not own product logic

  • Authenticate to one declared source.
  • Retrieve only the approved data scope.
  • Preserve the original payload and transport evidence.
  • Emit a typed source-record envelope.
  • Checkpoint progress, expose health and retain failures.
  • Keep mapping, RTT calculations and product rules outside the connector.

Product boundary

A product is a complete public contract

  • Declared source and canonical data requirements.
  • Versioned mappings, rules and pipeline stages.
  • Named roles, permissions and organisation scope.
  • Screens, queues, notifications and escalation behaviour.
  • Audit, provenance, export and retention behaviour.
  • Acceptance tests, limitations and replacement route.

No mandatory generative-AI layer

Pathway construction, operational calculations, routing, alerts, reconciliation, access decisions and audit are deterministic functions. Optional model products can be added or removed without changing the operational core. A prompt, hidden model state or probabilistic output cannot become the unrecorded basis of an operational decision.