commvita
Connected care platform
Organisational design

Reorganise the organisation without reorganising the record

How commvita implements organisational change; how it supports both a single neighbourhood provider and multiple neighbourhood providers — organisationally, through commissioning, and through shared incentives — and how the experience stays frictionless for citizens, patients and the workforce whichever design is chosen.

Live vs demonstrated: Live — real, API-backed platform logic (wired end-to-end today) Demonstrated — representative control surface with seeded data / illustrative UI mock-up

1What actually changes when an organisation changes

A reorganisation is rarely one change. It is usually five, arriving at different times and agreed by different people — and most systems bind them together, so moving one means re-implementing the rest. commvita holds them apart deliberately: an organisation can merge without anyone's record moving, and a contract can change hands without a clinician losing access to the person in front of them.

FIVE LAYERS — each can change without re-implementing the othersLegal entity & organisationTrusts, boards, providers, practices — held as organisations with ODS codesStructure & supervisionCare groups, teams, line management and clinical supervision as two separate linesPeople & accessRole, organisation scope, delegation and group membership — resolved at sign-inMoney & agreementContracts, pooled budgets, tariffs, delegated financial authorityThe experienceWhat a citizen, a patient and a member of staff actually meetCHANGES ON ITS OWN
Read it downward. A new provider is a change at layer one. A new care group is layer two. Neither requires the person's record, the neighbourhood team or the citizen's front door to be rebuilt. The experience layer is the one commvita works hardest to hold still.

2The instruments that make the change

Each layer has a configuration surface. None of them is a code change, and none requires a release.

Organisation and hierarchy

Layer 1–2 · Live

Structure — national, regional, system, network, provider, practice, team — is configured, not compiled. Care groups carry two independent lines: line management and clinical supervision. They are separate columns because in an integrated neighbourhood they routinely point at different organisations, and collapsing them is how a nurse ends up clinically supervised by their budget holder.

Where it lives /health-system-builder · /hierarchy-builder · /org-admin · GET /hierarchy/ · StaffHierarchyNode

People and access

Layer 3 · Live

A joiner is provisioned atomically — account, role, scope, care group, line manager and clinical supervisor in one call, rolled back cleanly on failure and written to the audit. Access is then resolved at sign-in from three sources: the person's own organisations, anything delegated to them, and any group they belong to.

Where it lives POST /auth/users/provision · /rbac-matrix · UserOrganisation · UserDelegation · UserGroup

Jurisdiction and law

Layer 1 · Live

Identifier formats, terminology, regulators, statutory clocks and financial values are read from a versioned, source-cited, effective-dated Jurisdiction Profile rather than hardcoded. Where a value is unconfigured, dependent behaviour fails safe to nothing — it never quietly adopts a neighbouring jurisdiction's answer.

Where it lives /jurisdiction-wizard · /jurisdiction-profile · /regulatory-engine

What each role sees

Layer 5 · Live

Navigation is narrowed by edition and role, and can be rebuilt per organisation. Two cautions, because both have caused real defects: edition scope is a packaging boundary, not a security one, and group membership grants organisation scope only, never a role.

Where it lives /menu-builder · edition_scope · effective_role() · effective_scope()
Why access is resolved and not copied. A merger normally means someone re-keying permissions for every affected member of staff, and that list is never quite right. Here a person's reach is computed from their organisations, delegations and groups each time they sign in, so changing the structure changes the access — with membership grants carrying an expiry and a re-attestation, and grant, re-attestation and lapse all written to a tamper-evident chain.

3Single or multiple neighbourhood providers

The neighbourhood question a commissioner actually has to answer is not technical: does one organisation hold the neighbourhood contract and subcontract delivery, or do several hold their own agreements and work as an alliance? commvita is built so that this is a commissioning decision, not a system decision — because the platform models the relationship between a person and the people helping them, rather than an org chart.

A · Single neighbourhood providerOne organisation holds the contract and subcontracts deliveryCommissionerLead providerholds the contractGPCommunitySocial careVoluntaryOne person · one record · one key workerNeighbourhoodCase · INTTeam · /nhrB · Multiple neighbourhood providersSeveral organisations each hold their own agreementCommissionerProvider 1own contractGPProvider 2own contractCommunityProvider 3own contractSocial careOne person · one record · one key workerNeighbourhoodCase · INTTeam · /nhrthe layer below the contract is identical in both designs
The contract layer differs; the care layer does not. In both designs a neighbourhood case carries one named key worker, a list of participating organisations, and a reference to the multidisciplinary team — so a person is never split into one case per provider. The team model is referenced rather than forked, so a neighbourhood has one team whichever way the contract is let.
Design dimensionSingle providerMultiple providers Where it is configuredStatus
Who holds the contractOne lead provider; others subcontract Each provider holds its own agreement Contract register · /icb-commissioningDemonstrated
Who employs the teamMostly one employer Several employers in one team Care group + supervision lines · /hierarchy-builderLive
Who can see the recordLead provider's scope Each organisation's own scope, plus delegation effective_scope() · /rbac-matrixLive
Who coordinates the personIdentical — one named key worker on one case NeighbourhoodCase · /neighbourhood-intelligenceLive
The multidisciplinary teamIdentical — one team per neighbourhood, roughly 30–50k population INTTeam · /intLive
The shared recordIdentical — one cross-organisation longitudinal record /nhr · /single-patient-recordLive
Non-NHS delivery staffIdentical — allocated to an organisation, never given an internal account CareProviderAllocation · /care-portalLive
Neighbourhood needIdentical — keyed on geography, never on identity AreaDeterminant (LSOA) · /deprivation-mappingLive
The load-bearing design choice. A neighbourhood case names its participating organisations as a list and its coordinator as one person. A model that instead gave each provider its own case would make the single-provider design look tidy and the multi-provider design incoherent — the person would appear three times, and no count of them would reconcile. Because the list is the model, adding or removing a provider is a change of data, not of schema.
Third-party delivery, without third-party access. Domiciliary and supported-living staff sign in to their own portal with their own credentials, and can only reach service users their organisation has been allocated — enforced server-side, not by hiding a menu. They are deliberately not internal platform accounts. That is what lets a neighbourhood include providers who are not part of the commissioning organisation at all, and lets one leave without an access review.

4Commissioning and shared incentives

Commissioners are not a fixed map — boards have already merged, and the Cabinet statement of 31 July 2026 signals an intent to align integrated care board boundaries with the new strategic authorities by the end of the Parliament. Any design that assumes a stable commissioning geography is wrong within a year, which is why the map is held as sourced, effective-dated configuration rather than as structure. Beyond that, shared incentives fail for a dull reason: each partner reports against its own contract, on its own cycle, using its own numerator. The instruments below are separate on purpose — an agreement, a pooled budget, a price and a delegated authority are genuinely different things — but they are measured against one set of outcomes.

Contract registerNHS Standard Contract · CQUIN/icb-commissioningPooled budgetSection 75 · cost-sharing ratio/icb-commissioningPriceScheme → rate → local price/nhs-payment-systemDelegated authoritySoRD / SFI · role × decision × limit/policy-to-processMeasured against one set of outcomes, not four sets of returnsTotal cost of care · quality measures · outcome and equity movement · partner-attributed outcomesResource Impact Score — where to deploy nextStart · Scale · Redesign · Stop · Shift, each with a stated confidence · /outcome-intelligence
Four instruments, one measurement. Total cost of care, quality measures and outcome movement are read across the neighbourhood rather than per provider, and voluntary and community activity can be counted in through a partner-agnostic contract, so capacity outside the statutory sector is not invisible to the incentive.
01

Agreement — the contract register

NHS Standard Contract lifecycle, CQUIN performance, and procurement routed through the Provider Selection Regime under the Procurement Act 2023. This is where a change of provider is actually recorded.

/icb-commissioningGET /icb-commissioning/Demonstrated
02

Pooled budget — Section 75

Pooled budget agreements with local-authority partners, each carrying its cost-sharing ratio and annual review date. This is the mechanism a multi-provider neighbourhood uses to share gain and share risk, and commvita records it as the agreement it is.

Section 75, NHS Act 2006Demonstrated
03

Price — scheme, rate, local price

An effective-dated payment scheme holds national rates, locally agreed prices and recorded activity costs. Money is held in pence as whole numbers, so a price never drifts by a rounding error between two providers reading the same rate.

/nhs-payment-systemGET /tariff/Live
04

Delegated authority — and who may approve across an organisational boundary

The scheme of reservation and delegation and the standing financial instructions are held as an effective-dated matrix of role × decision × limit × instrument. An approval gate can be assigned to a role, a named individual, or a whole team or care group — which is what allows a partner organisation's manager to hold a real approval in a shared process. Gates can require several approvers of whom a quorum must agree, escalate on a service-level breach, and be signature-backed.

/policy-to-processGET /p2p/teamsP2PAuthorityRowLive
05

Measurement — one set of outcomes

Total cost of care against benchmark, quality measures, and outcome, equity and value movement across the population, ending in a ranked recommendation of where to deploy next. Small numbers are suppressed, and social value is labelled as an estimate rather than presented as a measured saving.

/tcoc-dashboard/quality-measure-tracker/outcome-intelligenceDemonstrated
What commvita does not claim here. There is no gain-share or risk-share calculator in the platform — no module computes a partner's share of a saving and no figure in this document should be read as one. What exists is the agreement (with its cost-sharing ratio), the cost and outcome measurement either side of it, and the delegated authority to act on the result. The arithmetic of an incentive scheme remains a commissioning decision, taken by people, and commvita records it rather than making it.

5Frictionless, whatever the design

The point of holding the layers apart is that the bottom four can be redrawn without the fifth moving. A citizen should not be able to tell, from using the service, whether the neighbourhood is run by one provider or five.

The citizen

One front door, whoever is delivering

One portal for appointments, medication, messages, care plan and record. A family member or carer can be granted proxy access — relationship, level and expiry recorded and revocable. Communication needs, accessible formats and reasonable adjustments are declared once, by the person, and carried by every outbound letter.

Where it lives /portal · /concierge · PatientCommNeed · DCB1605 Live

The patient

One identity, one record, across every provider

A master patient index resolves a person across sources and identifier schemes rather than creating a record per organisation. Every clinical surface carries the identity banner, and a build gate fails if any page reaches a record by a raw link instead of the canonical person-first route — so the person, not the case, is the object of the system.

Where it lives /empi · /nhr · Whole Person Record · npm run check:person-first Live

The workforce

One list of what needs me today

One personal home gathers open actions from eight modules — compliance actions, case tasks, board actions, incident actions, approval gates, broadcasts awaiting acknowledgement, unread mandatory policies and appraisal steps — worst-first, each opening its own module. Frontline staff get a smaller surface: one-tap capture that works offline.

Where it lives /workflow-hub · GET /my-actions · /care-portal Live
The architectural companion to this document. Everything above assumes organisations stay separate legal entities and keep their own records. How that is joined up without dissolving it — identity, record, query and governance, each federating on its own terms — is set out in Send the question, not the data (commvita-federated-architecture-blueprint.html).
Simplification is one reversible switch. The end-user simplification programme — task-first home, collapsed navigation, merged menu sections, an honest data-source indicator — sits behind a single flag with one seam in the code. Turning it off restores the previous behaviour exactly, and a read error fails back to the classic experience rather than to a half-migrated one. An organisation adopting commvita during a reorganisation can therefore change the experience without that being a one-way door.

6The honest edges

commvita records the change; it does not make it. Novating a contract, transferring employment and consulting a workforce are legal and human processes. The platform holds the resulting structure, agreement and authority, and keeps the record continuous across the change.

Parts of the commissioning surface are seeded. Contract values, pooled-budget agreements and efficiency programmes are representative demonstration data. The structures, access resolution, neighbourhood case model, delegated authority and personal action list are live and API-backed — every row above says which.

Editions are a packaging boundary, not a security one. Authorisation is role-based throughout; a scoped user who types a URL meets exactly the same role check as anyone else.

The Community Edition is not free. It is £1 per instance, with optional paid support, and carries the platform base — identity, access, audit, data fabric — deliberately without the clinical record or clinical workflow.

7Where every claim in this document lives

CapabilityRouteAPI / modelStatus
Care groups, line management, clinical supervision
Staff Hierarchy Builder
/hierarchy-builderGET /hierarchy/ · StaffHierarchyNodeLive
Atomic joiner provisioning
User Setup Wizard
/hierarchy-builder · /user-managementPOST /auth/users/provisionLive
Organisation scope, delegation, groups
RBAC & scope
/rbac-matrix · /rbacUserOrganisation · UserDelegation · UserGroupLive
Access resolved at sign-in
RBAC
effective_role() · effective_scope()Live
Jurisdiction configuration
Jurisdiction Wizard & Profile
/jurisdiction-wizard · /jurisdiction-profileGET /jurisdiction-profile/Live
Neighbourhood multidisciplinary team
Integrated Neighbourhood Teams
/intGET /int/ · INTTeam · INTMemberLive
Cross-partner case, key worker, participating orgs
Neighbourhood Intelligence
/neighbourhood-intelligenceGET /neighbourhood/ · NeighbourhoodCaseLive
Neighbourhood need keyed on geography
Neighbourhood Intelligence
/neighbourhood-intelligence · /deprivation-mappingAreaDeterminant (LSOA)Live
External provider staff, isolated auth
Care Worker Portal
/care-portalPOST /provider-portal/login · CareProviderAllocationLive
Contract register, CQUIN, procurement
ICB Commissioning
/icb-commissioningGET /icb-commissioning/Demonstrated
Section 75 pooled budgets
ICB Commissioning
/icb-commissioningcost-sharing ratio per agreementDemonstrated
Payment scheme, rates, local prices
NHS Payment System
/nhs-payment-systemGET /tariff/ · TariffScheme · TariffRate · TariffLocalPriceLive
Delegated financial authority
Policy-to-Process
/policy-to-processGET /p2p/authority · P2PAuthorityRowLive
Approval by team or care group
Policy-to-Process
/policy-to-processGET /p2p/teamsLive
Total cost of care against benchmark
TCOC Dashboard
/tcoc-dashboardDemonstrated
Outcome, equity and value; where to deploy next
Outcome Intelligence
/outcome-intelligenceGET /outcome-intelligence/Demonstrated
Citizen front door and proxy access
Patient Portal
/portalGET /portal/Live
Accessible formats and reasonable adjustments
Communication Needs
/portal · /elective-experience-standardsGET /comm-needs/ · PatientCommNeedLive
One identity across providers
EMPI Hub
/empiGET /empi/Live
One personal action list across modules
commvita MyDay
/workflow-hubGET /my-actionsLive
NHS Standard ContractSection 75, NHS Act 2006Procurement Act 2023 · Provider Selection RegimeCare Act 2014Accessible Information Standard DCB1605Non-SaMD organisational & commissioning surfaceCommunity Edition — £1 per instance (optional support)
© 2026 Commvita Digital Health Solutions Ltd. All rights reserved.