NHS Sovereign Federated Data Platform · 01 — Architecture
Federated coordination without unrestricted central control
Source integration, validation, canonicalisation, deterministic execution, operational products, security, audit and export remain separate and replaceable.
Complete layered route
Each layer has a declared responsibility and a replaceable interface
The platform does not become the clinical record merely because it consumes clinical and operational sources. Authority remains declared field by field and event by event.
EPR, PAS, referrals, waiting lists, ADT, theatres, beds, workforce, diagnostics, pharmacy and other authoritative systems.
Approved extraction through FHIR R4, HL7, SQL, REST, queues, streams, CSV or controlled batch interfaces.
Structure, identity, dates, ranges, relationships and freshness are tested before versioned mappings are applied.
Stable patient, organisation, location, practitioner, referral, pathway, appointment, admission and resource entities retain source links.
Versioned pipelines, human-readable rules, checkpoints and idempotency controls calculate states and create governed tasks.
Dashboards, work queues, notifications, exports and reusable product packages operate against declared contracts.
Local instances expose purpose-bound routes for trust, ICB, regional and national coordination while retaining local authority.
Identity, access, audit, provenance, security, accessibility, export, portability and governance apply across the full route.
Evidence-preserving data route
Source, canonical and derived states are never silently collapsed
Federation model
Shared standards without centralised ownership
Federation is a controlled exchange between independently governed instances. It is not a single national database with unrestricted reach into every local record.
| Level | Authority | Permitted coordination | Boundary |
|---|---|---|---|
| Local / Trust | Local controller and operating organisation | Local pathways, queues, capacity and operational products | Can continue independently if federation is unavailable |
| ICB | Declared participating organisations and agreement | Cross-provider coordination for an approved purpose | Only registered datasets, routes, roles and retention |
| Regional | Regional governance and product mandate | Capacity, pathway and exception views across participating areas | No automatic transfer of local operational authority |
| National | Named national controller and product owner | Approved aggregate, de-identified or specifically authorised products | Purpose, lawful basis, fields, frequency and withdrawal are explicit |
Connector boundary
Transport does not own product logic
- Authenticate to one declared source.
- Retrieve only the approved data scope.
- Preserve the original payload and transport evidence.
- Emit a typed source-record envelope.
- Checkpoint progress, expose health and retain failures.
- Keep mapping, RTT calculations and product rules outside the connector.
Product boundary
A product is a complete public contract
- Declared source and canonical data requirements.
- Versioned mappings, rules and pipeline stages.
- Named roles, permissions and organisation scope.
- Screens, queues, notifications and escalation behaviour.
- Audit, provenance, export and retention behaviour.
- Acceptance tests, limitations and replacement route.
No mandatory generative-AI layer
Pathway construction, operational calculations, routing, alerts, reconciliation, access decisions and audit are deterministic functions. Optional model products can be added or removed without changing the operational core. A prompt, hidden model state or probabilistic output cannot become the unrecorded basis of an operational decision.