Govern your organisation. The accountability record a board is inspected against — 116 modules on the Community base, sold to boards rather than clinicians, with no clinical workflow by design.
The Governance & Assurance Edition is commvita's answer to a question that has nothing to do with clinical software: can this organisation show that it is well run? It is bought by boards rather than by clinicians, it carries no clinical workflow by design, and it is the fastest of the three editions to put into service because nothing in it depends on clinical accreditation.
commvita ships three editions and they are additive — each one contains the one beneath it. There is no fourth, and no “modules” tier to negotiate.
The open platform base — identity and RBAC, the audit framework, the data fabric, the integration engine, and everything the NHS Federated Data Platform does. Self-hosted, open standards, no Palantir contract.
This document. The accountability record: board, risk, incident, information governance, AI governance, workforce competence and the statutory returns. Deliberately no clinical workflow.
The destination: the clinical record across primary care, social care, mental health, pharmacy, dentistry and community services, plus population health and analytics — and governance in full.
Most governance software is a filing cabinet with a workflow bolted on. The board papers live in one system, the risk register in a second, incidents in a third, policies in a fourth and training in a fifth — and the connections between them live in somebody's head, or in a spreadsheet, or nowhere. When an inspector asks how a particular incident changed a particular control, the answer is assembled by hand, from memory, under time pressure.
This edition is built on the opposite premise: the connections are the product. An event, a theme, a systemic issue, a risk and a board objective are one chain, and every step of it carries the evidence that justified the step.
Strip away the frameworks and an inspection — CQC, HIW, HIS, RQIA, HIQA or an internal audit committee — comes down to a handful of questions. Each one has a module that answers it, and the module holds the evidence rather than a claim about the evidence.
Ten groups, 116 modules, on top of the 139-module Community base. This table is generated from the product's own edition definition, so it cannot drift from what actually ships.
| Group | Modules | What it evidences |
|---|---|---|
| Board assurance | 9 | That the board saw it, decided it, and signed it |
| Risk & compliance | 10 | That risk is identified, controlled and traceable to policy |
| Incident management | 14 | That harm is reported, investigated proportionately and learned from |
| Information governance & privacy | 12 | That personal data is held lawfully and requests are answered on time |
| Data & AI governance | 7 | That algorithms are registered, assessed and reviewable by a human |
| Training, CPD & workforce assurance | 12 | That the people doing the work are competent and currently registered |
| Governance intelligence | 7 | That the policy estate and the safety record are actually understood |
| Audit & evidence | 10 | That the claims above can be produced on demand |
| Statutory reporting & annual returns | 7 | That the publications an organisation is judged on are produced |
| Statutory readiness & operational command | 11 | That the organisation can run in a crisis and prove it planned to |
| Ambulance | 1 | |
| Analytics | 2 | |
| Clinical | 1 | |
| Operations | 1 | |
| US-ACO | 3 | |
| Workforce | 9 | |
| Total | 116 | on top of the 139-module Community base |
A governance record is only worth what its integrity is worth. Board decisions, approval gates, policy sign-offs, information-governance access and the emergency loggist all write to append-only hash chains: each row stores the hash of the row before it, and the whole chain is re-verified by the server on every read.
Sign-off is a named human accepting accountability. Approvals route through commvita Sign and are bound to the thing being signed, so a signature ceremony cannot be replayed to close a second item. A policy approval, a board pack, a safety case, a jurisdiction go-live and a professional revalidation recommendation each refuse to complete without one.
A statutory duty counted in working days lands about a week later than the same number of calendar days. Software that types the deadline in produces breaches that are not breaches, and misses the ones that are.
An organisation's policies and its free-text safety record are the two largest bodies of writing it owns, and the two least often read. Seven capabilities work over them.
Every answer cites the document it came from. Retrieval is lexical, not semantic — commvita has no embedding provider, and the status endpoint says so, so nobody mistakes term matching for meaning. With no AI provider configured, the matching passages are returned verbatim rather than composed, because prose built from them without a model is invention.
Generated charts are bound to the source document version. Re-version the policy and the chart goes stale and stops claiming to be guidance — a sepsis flowchart drawn from a superseded policy is worse than none.
Themes carry their record references, so a count reconciles with the set behind it. Where a model is used, the references it returns are validated against the real corpus so it cannot invent an incident.
Both are advisory and read-only. commvita never rewrites a policy: which version survives a merger is an accountable human decision, and a test asserts the policy count is unchanged after a run.
Nothing in this edition requires the buyer to be a healthcare provider. The board, risk, policy, incident, information-governance, AI-governance and workforce-competence capabilities are the same shape in a housing association, a local authority, a charity or a professional body. The regulator, the inspection framework, the background-check scheme and the professional register are resolved per jurisdiction from a versioned, source-cited profile — and an unconfigured jurisdiction fails safe to a generic regulator rather than borrowing a neighbour's.
Why that matters commercially. It is the reason this edition has the shortest sales cycle of the three: no clinical accreditation to obtain, no clinical safety case to agree before go-live, and a far broader addressable market than a clinical system can reach.
Generated from services/web/src/editions.ts. Routes are the real
application routes.
| Board Management — portal, papers, committees, actions | /board-management | Shipped |
| Board Assurance Framework (BAF) | /board-assurance-framework | Shipped |
| Board Entity Governance | /board-entity-governance | Shipped |
| Register of Interests | /register-of-interests | Shipped |
| commvita Sign — e-signature & decision logging | /esign | Shipped |
| Governance & Delivery Visual Boards — risk bubble map, maturity radar, delivery Gantt | /governance-boards | Shipped |
| commvita Financial Recovery & SIP — recovery plans, savings schemes, approval gates and delivery assurance | /financial-recovery | Shipped |
| Quality Impact Assessment — impact of service change on quality of care, evidence, mitigation and panel review | /quality-impact-assessment | Shipped |
| Quality Improvement & Evidence Programme — problem, baseline, PDSA, Lean and Agile tests, evidence, benefits and organisational learning | /quality-improvement | Shipped |
| Corporate Risk Register | /corporate-risk | Shipped |
| Golden Thread — incident → theme → risk → objective | /golden-thread | Shipped |
| Policy-to-Process — policy as a gated process, authority matrix, N-of-M approvals, WORM audit | /policy-to-process | Shipped |
| Policy management — authoring, versioning, version-aware attestation | /policy-library | Shipped |
| Compliance Action Hub | /compliance-hub | Shipped |
| Regulatory & Commissioner Engine | /regulatory-engine | Shipped |
| Clinical Risk Management — DCB0129/0160 register & CSO sign-off | /clinical-risk | Shipped |
| Hazard Log — DCB0129 hazard identification & control | /hazard-log | Shipped |
| DCB0160 Workflow — change assessment for system modifications | /dcb0160 | Shipped |
| Safety Case Report — DCB0129/0160 safety case compilation | /safety-case-report | Shipped |
| Incident Reporting (PSIRF · LFPSE) | /incident-reporting | Shipped |
| Root Cause Analysis | /rca | Shipped |
| CAPA workflow | /capa | Shipped |
| Near-Miss Tracking | /near-miss | Shipped |
| Complaints Management | /complaints | Shipped |
| Duty of Candour | /duty-of-candour | Shipped |
| Freedom to Speak Up | /ftsu | Shipped |
| Mortality Review — MBRRACE · LeDeR · SHMI | /mortality-review | Shipped |
| LEARN Reporting — national patient-safety event submission | /learn-reporting | Shipped |
| CQC Notifications — statutory notification register | /cqc-notifications | Shipped |
| RIDDOR Reporting — HSE statutory reporting | /riddor | Shipped |
| Safety Walkrounds — board-to-ward assurance visits | /safety-walkrounds | Shipped |
| Patient Feedback (FFT) — responses, themes, CQC evidence pack | /patient-feedback | Shipped |
| Patient & Family Escalation (Rapid Review) — 24/7 worsening-condition escalation | /rapid-review | Shipped |
| IG Hub — DSPT, DPIA, breach, DSAR | /ig-hub | Shipped |
| Confidential-Information Governance Spine | /ig-spine | Shipped |
| Legitimate Relationship Log | /legitimate-access-log | Shipped |
| Data Sharing Partnership Agreements | /dspa-manager | Shipped |
| IG Training Compliance | /ig-training-compliance | Shipped |
| Supplier IG Assurance | /supplier-ig-assurance | Shipped |
| FOI workflow — request, statutory clock, exemptions, review | /ig-records | Shipped |
| Records management — retention & disposal schedules | /ig-records | Shipped |
| Information Asset Register + Art.30 ROPA | /ig-records | Shipped |
| Patient Data Control — Art.30 data flows, ABAC policy, National Data Opt-Out | /ig-data-control | Shipped |
| Shared Care Opt-Out Registry — FHIR Consent, emergency override governance | /shcr-opt-out | Shipped |
| Federated Governance — cross-org data sharing agreements & steward registry | /federated-governance | Shipped |
| AI Governance — ATRS register, AIA, bias, Art.22 overrides | /ai-governance | Shipped |
| AI Integration Hub — governed provider config & audit | /ai-integration-hub | Shipped |
| Data Transparency Register | /data-transparency | Shipped |
| Data lineage — source & transformation tracking | /ig-records | Shipped |
| Microsoft Purview integration (optional, removable) | /ig-records | Shipped |
| Clinical Studies — research IG, DSA register, re-identification risk, extract ledger | /clinical-studies | Shipped |
| Federated Cohort Discovery — GDPR Art.89, k≥5 suppression | /cohort-discovery | Shipped |
| commvita Learn — learning management & course catalogue | /learn | Shipped |
| Mandatory Training compliance — statutory & role-based | /mandatory-training | Shipped |
| CPD record & Training Passport — hours, evidence, export | /learn | Shipped |
| Accreditations register — NMC · GMC · HCPC, expiry & manager verification | /learn | Shipped |
| Competency frameworks & supervisor sign-off | /learn | Shipped |
| Appraisal & professional revalidation — signature-backed sign-off, Well-Led evidence | /appraisal | Shipped |
| eAssessment — scored knowledge checks with attempt history | /learn | Shipped |
| commvita Learn Mobile — offline learning delivery | /mobile-learn | Shipped |
| Staff Portal — personal governance (training, interests, approvals, signatures) | /staff-portal | Shipped |
| Staff Hierarchy Builder — accountability & clinical supervision | /hierarchy-builder | Shipped |
| IG training compliance — DSPT Criterion 7 | /ig-training-compliance | Shipped |
| Staff Wellbeing — PERMA+, staff survey, psychological safety (figures are seeded) | /staff-wellbeing | Shipped |
| Ask the corpus — cited answers from your own policies and SOPs | /governance-intelligence | Shipped |
| Policy → interactive flowchart — version-bound, approved by a named person | /governance-intelligence | Shipped |
| Safety thematic analysis — patterns across the free-text safety record | /governance-intelligence | Shipped |
| PFD (Regulation 28) register — coroner concerns, statutory 56-day clock | /governance-intelligence | Shipped |
| Policy estate audit — duplication, overdue review, missing ownership | /governance-intelligence | Shipped |
| Merger harmonisation — conflicts and gaps between two estates | /governance-intelligence | Shipped |
| Process Quality Baseline — cycle time, handoffs, rework and coded-vs-free-text, measured over time | /process-quality | Shipped |
| Clinical Audit | /clinical-audit | Shipped |
| Regulatory Assessment (CQC SAF / multi-jurisdiction) | /regulatory-assessment | Shipped |
| Assurance Dashboard — deployment rings | /assurance | Shipped |
| HIMSS Maturity Cockpit | /himss-assessment | Shipped |
| Cyber Assessment (Cyber Essentials · ISO 27001) | /cyber-assessment | Shipped |
| Data Security Architecture | /security-architecture | Shipped |
| Real-Time Security Console — SOC, Art.9 monitoring, GDPR Art.33 ICO countdown | /security-console | Shipped |
| DTAC Compliance — the NHS supplier gate | /dtac | Shipped |
| ShCR Maturity Scorecard | /shcr-maturity | Shipped |
| PRSB Compliance Dashboard — Core Information Standard completeness | /prsb-compliance | Shipped |
| Quality & Performance Report (DCEOE) — the monthly board report; ND carries its reason | /quality-performance-report | Shipped |
| Automated QPR Reporting — IAPT QPR (NHS Digital DS v2.0), CQC/NICE KPI pack, PCN/ARRS utilisation | /qpr-reporting | Shipped |
| OPEL submission — the daily NHS England operational pressures return | /opel-submission | Shipped |
| Quality Account — the statutory annual quality publication | /quality-account | Shipped |
| Annual Plan Hub — SMART outcomes, quarterly milestones, live RAG | /annual-plans | Shipped |
| Net Zero & Sustainability — Scope 1/2/3 and the CNZAP annual return | /net-zero | Shipped |
| AI Transformation Advisor — executive decision support, human-in-the-loop | /ai-transformation-advisor | Shipped |
| EPRR Hub — Civil Contingencies Act 2004, business continuity, on-call, WORM loggist | /eprr | Shipped |
| Major Incident — METHANE, JESIP joint decision, CSCATTT, Gold/Silver/Bronze, casualty tracking | /major-incident | Shipped |
| On-Call Manager — OPEL assessment, escalation, duty log, handover | /oncall-manager | Shipped |
| Safe Staffing / CHPPD — NQB safe staffing, professional judgement, board return | /safe-staffing | Shipped |
| Bank & Agency Cascade — bank-first cascade, agency control, WTD compliance | /bank-agency | Shipped |
| Shift Priority Board — shift-aware priority actions & handover | /shift-priority | Shipped |
| Handover Clock — 15-minute handover standard, breach & delay reasons | /handover-clock | Shipped |
| Jurisdiction Profile — versioned, sourced, signed-off jurisdictional variance | /jurisdiction-profile | Shipped |
| Firearms Certificate Management — evidence-grade decision log (per-jurisdiction regime) | /firearms-certification | Shipped |
| 21st Century Cures Act — ONC information blocking (US) | /cures-act | Shipped |
| EHDS Compliance — EU Reg. 2024/2987 | /ehds | Shipped |
| HEMS Coordination | /hems | Shipped |
| Benchmarking | /benchmarking | Shipped |
| ICS Finance | /ics-finance | Shipped |
| Community Nursing Activity (KF25/KF26) | /community-nursing-activity | Shipped |
| Elective Experience Standards | /elective-experience-standards | Shipped |
| CMS Conditions of Participation | /cms-cop | Shipped |
| CMS Interoperability | /cms-interoperability | Shipped |
| No Surprises Act | /no-surprises-act | Shipped |
| Dynamic Scheduling | /dynamic-scheduling | Shipped |
| ESR Integration | /esr-integration | Shipped |
| HR & Finance | /hr-finance | Shipped |
| Job Planning & PA Management | /job-planning | Shipped |
| NHS Pension & Job Planning | /nhs-pension | Shipped |
| Rostering | /rostering | Shipped |
| Staff Directory | /staff-directory | Shipped |
| Staff Org Management | /staff-org-management | Shipped |
| Workforce Heatmaps & Skill-Mix | /workforce-visuals | Shipped |
This edition needs the Community platform base underneath it. It is a standalone commercial product, not a stepping stone — it shares no modules with Community or Population — but it runs on the Community foundation of identity, RBAC, audit and data fabric.
Some figures on some surfaces are seeded. Where that is true the module says so rather than the document: the Staff Wellbeing dashboard, for example, is a designed control surface whose figures are illustrative until its data is wired. The Quality & Performance Report goes further and refuses to invent: an indicator it cannot compute is returned as unavailable with the reason and the module that would have to be wired, so the report doubles as the platform's own gap register.
Assurance is derived from coverage. A domain more than a third unavailable cannot report full assurance. That is enforced in the code rather than left to the narrative, and it means the product will sometimes tell a board something less comfortable than a competitor would.
Non-SaMD. Nothing in this edition diagnoses, treats, or makes a clinical decision. The clinical-safety modules (DCB0129/0160 hazard log, clinical risk, safety case) are the governance record of clinical safety work, not a clinical device.