Market
Placement, shared contract collaboration and gross market claim facts. Bound messages route to the insurer’s own systems.
- No Delvor participant books required
- External delivery and acknowledgement
- Shared truth only under explicit visibility
Layer-Cake v1.8 · Architecture decisions ADR-0003–0010
Delvor keeps the shared placement, gross market loss and each participant’s operating and accounting position connected—but never collapsed into one mutable record.
Shared market composition
Select a synthetic programme and cake to inspect the market composition, shared gross-loss erosion and participant hand-off. No displayed value is asserted as a real BP insurance fact.
The insured group, its legal entities and source-governed parent relationships are public-record identity evidence. Reviewed relationships may be used to construct the shared programme, select insured entities and organise local policies.
The market may see the primary and excess layers, deliberately shared terms, participant legal identities, signed shares, contract identifiers, signing evidence and gross claim erosion.
After hand-off, each insurer privately manages its own signed share. Internal allocation, outward reinsurance, facultative or treaty cessions, retrocessions, retentions, recoveries and net results never appear in the shared layer cake.
MUI-001–MUI-020 · ADR-0009
The policy is important, but it is not the universal parent of every collaboration. The primary interaction is a governed MarketTransactionWorkspace seen through an authorised role and perspective.
Subject, transaction, participant legal entity, contextual role, perspective, version/time and visibility travel together.
Placement, claim, settlement, endorsement, technical-accounting and reinsurance rooms bound the relevant facts and actions.
Proposal → response → agreement records who offered what, who accepted it and which version became effective.
Owner, beneficiary, dependency, due date, authority and evidence replace a single misleading workflow status.
Business, technical, signing, financial and settlement states progress independently and remain explainable.
A perspective is an authorised projection of known facts—not impersonation and never access to another participant’s private book.
ML-001–ML-052 · ADR-0010
Eligibility and programme design must be resolved for the exact legal entity, insurance class, jurisdiction, route, risk location and effective date. Unknown or high-risk outcomes go to legal/compliance review.
Versioned master and local policies, local requirements, DIC/DIL correspondence, coverage comparison and claims coordination remain explicit.
The licensed issuing carrier and beneficial insurer are separate roles. Fronts, captives and network partners are never flattened into one carrier field.
Pool-first requirements and every cession, retrocession, collateral or alternative-risk leg are versioned and reconcile to exactly 100%.
Rules carry source, licence, jurisdiction, class and effective dates. Appetite and legal reasoning remain participant-private.
Governed test oracle
All 46 cases have a source-safe shared-market result, separate lead/follow operational and financial expectations, and a processable synthetic market fixture. Real insurer identities never imply a real placement.
Loading governed expected results…
Download expected-results.jsonDeterministically loaded into PostgreSQL by migration 082 for demo/API use.
Target logical model
The current physical model has contract Coverage, FinancialLayer and Participation, but not shared ProgrammeCoverage specifications, the LayerCake aggregate, its LOB/coverage associations, per-participation contract link or participant contract position.
LayerCakeLineOfBusiness classifies the cake; LayerCakeCoverage links protection; LayerCakeInsuredObject gives a cake version many canonical objects. Contract Coverage implements, but does not replace, the shared specification.
LayerClaimAccumulation is a rebuildable shared projection over deliberately shared gross claim/occurrence facts, with currency, basis, as-of and known-at context.
A placement may exist before bind. Once BOUND, every participation must have one active contract relationship for the applicable effective period.
The bind event creates only the authorised participant’s private position. It never creates another participant’s reserve, payment, cession, journal or book.
Current migration 021
Migrations 084–085
Non-negotiable boundary
The hand-off is a lifecycle transition, not a transfer of database ownership. Shared facts remain shared; participant management starts through a referencing private position.
Programme, programme coverage specifications, layer cake, LOB/coverage associations, layers, participation, contract, shared claim facts and gross layer erosion.
Never contains participant booking periods or ledgers.Contract position, underwriting opinion, internal policy state, claim position, authority, workflow and private evidence.
Private by default under ParticipantContext.Premium, commission, tax, reserves, payments, recoveries, cash, settlement, technical accounts and GL journals.
Created only by authorised participant commands.Loss runs, layer erosion projections, gross/ceded/net analysis, IBNR, IFRS 17, statutory and management reporting.
Rebuildable, source-lined and non-booking.Participant-scoped exchange
One canonical envelope can be transformed into custom, Delvor JSON, Delvor XML or authoritative Lloyd’s-market messages. Exact Lloyd’s schemas remain unknown until supplied and licensed.
Authorised object versions, as-of/known-at, correlation and purpose.
Versioned mapping and schema hash; JSON, XML, custom or Lloyd’s family.
Append-only attempts, retries, acknowledgement and dead letter.
Immutable participant-private evidence with signature, replay and schema controls.
Source-faithful
A governed analytical snapshot of what the participant’s system returned. It is evidence-derived, not synthetic and not a Delvor business master.
What-if copy
An altered, anonymised or simulated derivative with every assumption and transformation lined back to the observed response.
Hard boundary
Neither response interpretation nor scenario analysis can create reserves, payments, cessions, technical transactions or journals.
Operating platform
Each environment owns its decisions while tracing to the same authorised market composition.
Submission, assessment, quote, referral, negotiation, placement, bind and participant contract hand-off.
Shared event/occurrence/claim identity; private claim position, reserves, payments and recoveries.
Premium, tax, commission, claim and cash movements linked to participant contract positions.
Participant-private outward programmes, cessions and recoveries without relabelling gross business.
Selected-account development, frozen source-lined datasets and Chain Ladder, Bornhuetter-Ferguson and Expected Loss Ratio IBNR comparisons with uncertainty ranges. A recommendation is immutable and independently approved or rejected; only a separately authorised claims command can append the linked reserve movement.
Participant/legal-entity books, deterministic postings, trial balance, close and reconciliation.
IFRS 17, NAIC/RBC, ISO/Verisk, Solvency UK and management reporting over frozen cuts. Apache Superset is the preferred self-hosted BI layer over curated read-only PostgreSQL products; Delvor retains commands, ParticipantContext authority and canonical truth.
Identity, context, RLS, workflow, evidence, commands, audit, outbox/inbox and lineage.
Claims experience
The claims handler starts with attention, exposure and next action. Opening a claim preserves context while separating investigation from consequential reserve, payment and recovery commands.
Search and filter the selected account’s claims; show open positions, work attention, non-zero reserves and source-safe status without substituting another account.
Summary, timeline, coverage, financials, market/layers, recoveries, parties, evidence, tasks/approvals and audit/lineage remain available around one active claim.
FNOL, open/triage, decision, reserve, payment, recovery and closure appear one stage at a time with authority, idempotency and optimistic version controls.
Shared gross claim and layer erosion, participant operations, participant financial books and derived claims analysis are composed for navigation but never merged.
Recognisable evidenced losses such as BP’s Deepwater Horizon / Macondo, Texas City, Toledo and Whiting events appear in account context without falsely asserting an insurance claim amount, coverage response or layer result.
Every researched insured has an account-scoped, permission-aware private loss run with explicit as-of and known-at valuation. Booked reserve, payment and recovery measures are shown by currency; gross, ceded and net remain NULL until all governed inputs exist.
Deterministic synthetic UAT snapshots exercise paid, case-reserve and incurred development at 0, 3 and 6 months for every researched insured and legal-entity context. They are visibly synthetic derived analysis, never researched claims or participant books; production triangles require reproducible booked source snapshots.
A visibly synthetic 20% ceded sensitivity reconciles gross exactly to ceded plus net at every development point. It exercises analysis without filling the governed cession share, asserting real reinsurance terms or posting any participant book.
Claims receives a permission-aware queue of derived reserve recommendations without access to the actuarial workbench. Independent approval still has no booking effect; an authorised claims user must open the claim where needed and explicitly append the exact participant-financial reserve movement.
Every researched insured receives the same account-scoped review. Labelled shared synthetic occurrences can explain layer erosion, but large-loss classification remains UNKNOWN until a participant threshold exists and catastrophe accumulation remains UNKNOWN until governed footprint/object matching exists. Neither signal books a value or exposes private claim finances.
Images and video remain in encrypted object storage while immutable PostgreSQL metadata retains hash, provenance, classification, retention and legal hold. Evidence is participant-private by default; sharing to the market requires a separate immutable decision and never publishes the participant claim book.
Rule results and authorised overrides are separate immutable, bitemporal derived records with input/result identities and explicit supersession. The original UNKNOWN result remains visible beside the explained review override; neither record books a claim value.
Flexible, but governed
Authorised customers can extend any registered business-record type. Values remain typed, versioned and schema-bound; recurrent use may open a product-governance case, never silently change the canonical model.
Choose text, code, money, percentage, measurement, reference, structured or media value and its applicability.
Store under registered versioned JSON or a governed sidecar; immutable rows are never patched.
Aggregate permission-safe counts by record type, LOB, coverage and jurisdiction—without copying private values.
Domain, privacy, licensing and compatibility review publishes a future product/configuration version.
LOB-aware forms
Product/version, LOB, coverage, jurisdiction and effective date determine the visible sections. Users never have to edit raw JSON.
Claims evidence
Encrypted object storage holds binaries; relational metadata holds hash, scan, provenance, security, retention and legal hold. Private by default.
Concept centralisation
An ISO/Verisk code retains issuer and version while a local sprinkler subtype maps as narrower. Exact licensed codes remain source-gated.
AI assistance
AI can extract, map, deduplicate and cross-populate proposals. It cannot silently alter authoritative, shared, financial, posted or filed truth.
Insurer SaaS tenancy
Company identity is a security boundary, not a cosmetic filter. XL Insurance Company SE and the reusable HDI Global SE isolation fixture have source-linked identities; deployment, policies and amounts remain explicitly synthetic UAT unless separately evidenced.
Choose the insurer first, then an authorised persona and legal-entity context. Changing company issues a new participant-bound session token.
Operate ordinary primary policies without requiring a shared-market programme, layer cake or market placement.
Where the insurer participates in a market placement, accept a source reference into the isolated private operating book without copying or mutating the shared market contract. The executable HDI/BP example is explicitly synthetic UAT and reconciles shared consequence as reference-only.
Process policies received from in-house systems through governed integration, provenance and reconciliation controls.
Governed change
The layer-cake, operating-mode and signing foundations now exist in migrations 084–085 and the local browser. Governed write APIs and the full principal journey remain release-gated.
Introduces shared composition, bound participation contracts and the private-position boundary.
Market, Private and Both become independently deployable, with an explicit processing route per market contract.
Defines message contracts, delivery/response evidence, externally observed snapshots and synthetic scenarios.
Separates order, written, signed and economic shares and requires accepted signing evidence before bound contract hand-off.
Delvor owns insurance subledgers and participant accounting; corporate ERP capabilities remain integrated through governed adapters.
Defines typed local fields, LOB-aware forms, claims media, concept mappings, deliberate promotion and confirmable AI proposals.
Defines contextual roles, perspectives, rooms, obligations and multidimensional state around a market transaction.
Defines governed eligibility, local solutions, carrier roles and explicit derived risk-transfer chains.
Inspect machine-readable decisionsResearch-backed consolidated backlog
CA-001–CA-025, MUI-001–MUI-020, ML-001–ML-052 and owner requirement REQ-EXT-001 deepen UAT-090–100. Research inputs define product requirements, not legal advice, procurement validation or completion evidence.
Composition, signing, transaction workspace, contextual roles, obligations, documents and principal journey.
Eligibility, local solutions, product/rating versions, DIC/DIL, claims intelligence and catastrophe accumulation.
Billing, tax, cash exceptions, parallel books, captives, collateral, ART and treaty mechanics.
Roles, perspectives, delegated authority, account-scoped portal access, source/version impact, configuration, rule governance, migration and ERP reject/replay.
Privacy, licensed content, market messages, resilience, stewardship and repeatable peak benchmarks.
Execute T-01–T-13, UI-T01–UI-T12 and ML-T01–ML-T42; close high defects and publish traceability.
Source-governed groups, exact legal entities and typed historical relationships with evidence, review state and explicit unknowns.
Only deliberately shared programme, layer, participation, contract and gross-claim facts—not inferred from the corporate graph.
Retention, cession, retrocession, recovery and net position remain ParticipantContext/RLS-private and cannot be discovered through the public graph.
Implementation readiness
Architecture completion and application completion are deliberately separate.
The Market structure workspace now includes a loss explorer: enter a synthetic gross loss, watch attachment, consumption and exhaustion, and open “Explain this number” for the formula, inputs and fixture references. No posting or private-book calculation occurs.
The first slice supports exact single-currency bands. Historical replay, saved scenarios, broader financial explanations, reconciliation triage and evidence-aware assistance are planned extensions, not completed features.
Open the market workspace