DDelvorDesign documentation Open application

Layer-Cake v1.8 · Architecture decisions ADR-0003–0010

One market composition.
Many participant businesses.

Delvor keeps the shared placement, gross market loss and each participant’s operating and accounting position connected—but never collapsed into one mutable record.

01Insured accountBP identity is researched; design values below are synthetic
02Many programmesSeparate purpose, period and governance
03Many layer cakesEach supports one or more lines of business
04Layers and participationsEvery bound participation has a contract
05Optional participant managementDelvor Private, external systems, or no market dependency
100/100Architecture checkpoint
217Current PostgreSQL tables
701Current foreign keys
98Consolidated active requirements
Current decisionProgramme → Coverages + LayerCakes → Layers → Participations → Contracts

Independent product planes

Market, Private or Both

This is an entitlement and lifecycle choice—not a cosmetic filter. Market and Private can be licensed, deployed and operated independently.

01

Market

Placement, shared contract collaboration and gross market claim facts. Bound messages route to the insurer’s own systems.

  • No Delvor participant books required
  • External delivery and acknowledgement
  • Shared truth only under explicit visibility
02

Private

Ordinary direct or imported business operated as participant-private SaaS.

  • No market participation required
  • Underwriting through reporting
  • ParticipantContext and legal-entity isolation
03

Both

Use both planes and choose the processing destination for each market contract.

  • Delvor Private or external route per contract
  • Shared composition beside My Position
  • Never one merged mutable record
Private native / external importParticipantManagedContract
PRIVATE
Delvor participant SaaSOperations → finance → analytics
Bound market contractShared and versioned
EXTERNAL_SYSTEM
Insurer in-house platformIntegration Hub delivery + response
Bound market contractShared and versioned
DELVOR_PRIVATE
ParticipantManagedContractOptional authorised hand-off

Shared market composition

Programme and layer-cake explorer

Select a synthetic programme and cake to inspect the market composition, shared gross-loss erosion and participant hand-off. No displayed value is asserted as a real BP insurance fact.

BP identity: RESEARCHEDProgrammes, cakes, lines, layers, carriers, shares, claims and contract IDs: SYNTHETIC DESIGN EXAMPLE

Public insured-company structure

The insured group, its legal entities and source-governed parent relationships are public-record identity evidence. Reviewed relationships may be used to construct the shared programme, select insured entities and organise local policies.

Shared gross placement

The market may see the primary and excess layers, deliberately shared terms, participant legal identities, signed shares, contract identifiers, signing evidence and gross claim erosion.

Private insurer treatment

After hand-off, each insurer privately manages its own signed share. Internal allocation, outward reinsurance, facultative or treaty cessions, retrocessions, retentions, recoveries and net results never appear in the shared layer cake.

Retention / ground-upIncreasing loss

MUI-001–MUI-020 · ADR-0009

A transaction-centred multiparty workspace

The policy is important, but it is not the universal parent of every collaboration. The primary interaction is a governed MarketTransactionWorkspace seen through an authorised role and perspective.

01

Context envelope

Subject, transaction, participant legal entity, contextual role, perspective, version/time and visibility travel together.

02

Transaction rooms

Placement, claim, settlement, endorsement, technical-accounting and reinsurance rooms bound the relevant facts and actions.

03

Agreement

Proposal → response → agreement records who offered what, who accepted it and which version became effective.

04

Obligations

Owner, beneficiary, dependency, due date, authority and evidence replace a single misleading workflow status.

05

Parallel state

Business, technical, signing, financial and settlement states progress independently and remain explainable.

06

Safe perspective

A perspective is an authorised projection of known facts—not impersonation and never access to another participant’s private book.

ML-001–ML-052 · ADR-0010

Multinational programme orchestration

Eligibility and programme design must be resolved for the exact legal entity, insurance class, jurisdiction, route, risk location and effective date. Unknown or high-risk outcomes go to legal/compliance review.

Programme and local solutions

Versioned master and local policies, local requirements, DIC/DIL correspondence, coverage comparison and claims coordination remain explicit.

Carrier roles

The licensed issuing carrier and beneficial insurer are separate roles. Fronts, captives and network partners are never flattened into one carrier field.

Derived risk transfer

Pool-first requirements and every cession, retrocession, collateral or alternative-risk leg are versioned and reconcile to exactly 100%.

Governed content

Rules carry source, licence, jurisdiction, class and effective dates. Appetite and legal reasoning remain participant-private.

Programme routeRisk locationEligibilityLocal solutionIssuer / beneficial insurer100% risk-transfer plan

Governed test oracle

Expected results for every researched insured

All 46 cases have a source-safe shared-market result, separate lead/follow operational and financial expectations, and a processable synthetic market fixture. Real insurer identities never imply a real placement.

46researched insured cases
230truth-scoped expected views
insured-object examples
5researched insurer identities

Loading governed expected results…

Target logical model

The missing middle is now explicit

The current physical model has contract Coverage, FinancialLayer and Participation, but not shared ProgrammeCoverage specifications, the LayerCake aggregate, its LOB/coverage associations, per-participation contract link or participant contract position.

operationalInsuredAccountparticipant entry point
1:N
insuranceRiskFinancingProgrammeshared programme identity
1:N
insurance · NEWProgrammeCoverageversioned protection specification
N:M
insurance · NEWLayerCakeversioned market tower
1:N
insurance · NEWFinancialLayerattachment + limit + basis
1:N
insuranceParticipationcarrier + role + shares
1:1 bound
insuranceInsuranceContractparticipant contract identity
hand-off
operational · NEWParticipantContractPositionprivate management anchor

LOB, coverage and objects

LayerCakeLineOfBusiness classifies the cake; LayerCakeCoverage links protection; LayerCakeInsuredObject gives a cake version many canonical objects. Contract Coverage implements, but does not replace, the shared specification.

Gross loss accumulation

LayerClaimAccumulation is a rebuildable shared projection over deliberately shared gross claim/occurrence facts, with currency, basis, as-of and known-at context.

Participant contract

A placement may exist before bind. Once BOUND, every participation must have one active contract relationship for the applicable effective period.

Private management

The bind event creates only the authorised participant’s private position. It never creates another participant’s reserve, payment, cession, journal or book.

Current migration 021

Implemented today

  • Programme → InsuranceContract → Coverage
  • Coverage → FinancialLayer
  • Layer → Participation → carrier Party
  • Exact attachment, limit and share measurements
  • No participant accounting on shared objects

Migrations 084–085

Implemented foundation

  • Programme → many ProgrammeCoverages + LayerCakes
  • Cake ↔ many lines of business + coverages
  • Many insured objects → one cake version
  • Cake → ordered layers → versioned participations
  • Order → written → signed → bound shares
  • Participation → bound participant contract
  • Explicit Delvor Private or external hand-off
  • Shared gross loss → layer erosion projection

Non-negotiable boundary

Four truths, one traceable journey

The hand-off is a lifecycle transition, not a transfer of database ownership. Shared facts remain shared; participant management starts through a referencing private position.

01

Shared market

Programme, programme coverage specifications, layer cake, LOB/coverage associations, layers, participation, contract, shared claim facts and gross layer erosion.

Never contains participant booking periods or ledgers.
02

Participant operational

Contract position, underwriting opinion, internal policy state, claim position, authority, workflow and private evidence.

Private by default under ParticipantContext.
03

Participant financial

Premium, commission, tax, reserves, payments, recoveries, cash, settlement, technical accounts and GL journals.

Created only by authorised participant commands.
04

Derived analytical

Loss runs, layer erosion projections, gross/ceded/net analysis, IBNR, IFRS 17, statutory and management reporting.

Rebuildable, source-lined and non-booking.
MarketplaceParticipation agreed and contract bound
explicit route
Delvor Private or external systemParticipant position only for DELVOR_PRIVATE
authorised consequences
Private booksNever created by market bind alone

Participant-scoped exchange

Integration Hub

One canonical envelope can be transformed into custom, Delvor JSON, Delvor XML or authoritative Lloyd’s-market messages. Exact Lloyd’s schemas remain unknown until supplied and licensed.

01

Freeze source cut

Authorised object versions, as-of/known-at, correlation and purpose.

02

Transform + validate

Versioned mapping and schema hash; JSON, XML, custom or Lloyd’s family.

03

Deliver

Append-only attempts, retries, acknowledgement and dead letter.

04

Capture response

Immutable participant-private evidence with signature, replay and schema controls.

Source-faithful

EXTERNAL_OBSERVED

A governed analytical snapshot of what the participant’s system returned. It is evidence-derived, not synthetic and not a Delvor business master.

What-if copy

SYNTHETIC_SCENARIO

An altered, anonymised or simulated derivative with every assumption and transformation lined back to the observed response.

Hard boundary

No automatic booking

Neither response interpretation nor scenario analysis can create reserves, payments, cessions, technical transactions or journals.

Executable UAT hubThe local Configuration workbench now lists certified custom and Delvor JSON/XML contracts, keeps Lloyd's schema/version source-gated, queues idempotent hash-only dispatches and displays retry, dead-letter, quarantine, external-observation and synthetic-scenario evidence without booking consequences. Open Configuration.
London Market follow-up · planned UAT-098The 28 August handover adds a dated interface/source catalogue, retrievable private message evidence, frozen mapping/replay dependencies and operator exception handling. These are planned gaps, not completed live integrations. A non-booking CDR mapping demonstrator is the first candidate; full field review, licences, sandbox access and conformance remain outstanding. Lloyd's strategy statement confirms the transition away from Blueprint Two; it does not certify any Delvor interface.

Operating platform

Domain ownership

Each environment owns its decisions while tracing to the same authorised market composition.

UW

Underwriting

Submission, assessment, quote, referral, negotiation, placement, bind and participant contract hand-off.

CL

Claims

Shared event/occurrence/claim identity; private claim position, reserves, payments and recoveries.

TA

Technical accounting

Premium, tax, commission, claim and cash movements linked to participant contract positions.

RI

Reinsurance

Participant-private outward programmes, cessions and recoveries without relabelling gross business.

AC

Actuarial

Selected-account development, frozen source-lined datasets and Chain Ladder, Bornhuetter-Ferguson and Expected Loss Ratio IBNR comparisons with uncertainty ranges. A recommendation is immutable and independently approved or rejected; only a separately authorised claims command can append the linked reserve movement.

GL

General ledger

Participant/legal-entity books, deterministic postings, trial balance, close and reconciliation.

RG

Reporting and open-source BI

IFRS 17, NAIC/RBC, ISO/Verisk, Solvency UK and management reporting over frozen cuts. Apache Superset is the preferred self-hosted BI layer over curated read-only PostgreSQL products; Delvor retains commands, ParticipantContext authority and canonical truth.

PF

Platform controls

Identity, context, RLS, workflow, evidence, commands, audit, outbox/inbox and lineage.

Claims experience

Portfolio first, one claim in focus

The claims handler starts with attention, exposure and next action. Opening a claim preserves context while separating investigation from consequential reserve, payment and recovery commands.

01

Portfolio workbench

Search and filter the selected account’s claims; show open positions, work attention, non-zero reserves and source-safe status without substituting another account.

02

Focused workspace

Summary, timeline, coverage, financials, market/layers, recoveries, parties, evidence, tasks/approvals and audit/lineage remain available around one active claim.

03

Guided process

FNOL, open/triage, decision, reserve, payment, recovery and closure appear one stage at a time with authority, idempotency and optimistic version controls.

04

Truth boundaries

Shared gross claim and layer erosion, participant operations, participant financial books and derived claims analysis are composed for navigation but never merged.

05

Researched event history

Recognisable evidenced losses such as BP’s Deepwater Horizon / Macondo, Texas City, Toledo and Whiting events appear in account context without falsely asserting an insurance claim amount, coverage response or layer result.

06

Governed loss run

Every researched insured has an account-scoped, permission-aware private loss run with explicit as-of and known-at valuation. Booked reserve, payment and recovery measures are shown by currency; gross, ceded and net remain NULL until all governed inputs exist.

07

Financial development

Deterministic synthetic UAT snapshots exercise paid, case-reserve and incurred development at 0, 3 and 6 months for every researched insured and legal-entity context. They are visibly synthetic derived analysis, never researched claims or participant books; production triangles require reproducible booked source snapshots.

08

Gross, ceded and net

A visibly synthetic 20% ceded sensitivity reconciles gross exactly to ceded plus net at every development point. It exercises analysis without filling the governed cession share, asserting real reinsurance terms or posting any participant book.

09

Actuarial booking hand-off

Claims receives a permission-aware queue of derived reserve recommendations without access to the actuarial workbench. Independent approval still has no booking effect; an authorised claims user must open the claim where needed and explicitly append the exact participant-financial reserve movement.

10

Large-loss and catastrophe review

Every researched insured receives the same account-scoped review. Labelled shared synthetic occurrences can explain layer erosion, but large-loss classification remains UNKNOWN until a participant threshold exists and catastrophe accumulation remains UNKNOWN until governed footprint/object matching exists. Neither signal books a value or exposes private claim finances.

11

Private media evidence

Images and video remain in encrypted object storage while immutable PostgreSQL metadata retains hash, provenance, classification, retention and legal hold. Evidence is participant-private by default; sharing to the market requires a separate immutable decision and never publishes the participant claim book.

12

Explainable reruns and overrides

Rule results and authorised overrides are separate immutable, bitemporal derived records with input/result identities and explicit supersession. The original UNKNOWN result remains visible beside the explained review override; neither record books a claim value.

Source safetyA researched loss event is not automatically an insurance claim. Unsupported coverage, liability, wording, claim amount, layer result, party, diary and financial facts remain UNKNOWN; synthetic UAT inputs never become researched facts.

Flexible, but governed

Custom fields that can become product concepts

Authorised customers can extend any registered business-record type. Values remain typed, versioned and schema-bound; recurrent use may open a product-governance case, never silently change the canonical model.

01

Define locally

Choose text, code, money, percentage, measurement, reference, structured or media value and its applicability.

02

Capture safely

Store under registered versioned JSON or a governed sidecar; immutable rows are never patched.

03

Observe recurrence

Aggregate permission-safe counts by record type, LOB, coverage and jurisdiction—without copying private values.

04

Promote deliberately

Domain, privacy, licensing and compatibility review publishes a future product/configuration version.

LOB-aware forms

Core + standard + local

Product/version, LOB, coverage, jurisdiction and effective date determine the visible sections. Users never have to edit raw JSON.

Claims evidence

Images and video

Encrypted object storage holds binaries; relational metadata holds hash, scan, provenance, security, retention and legal hold. Private by default.

Concept centralisation

Official code, finer meaning

An ISO/Verisk code retains issuer and version while a local sprinkler subtype maps as narrower. Exact licensed codes remain source-gated.

AI assistance

Suggest, explain, confirm

AI can extract, map, deduplicate and cross-populate proposals. It cannot silently alter authoritative, shared, financial, posted or filed truth.

Promotion lifecycleLocal draftLocal approvedCandidateDomain reviewStandard approvedProduct version
Executable UAT workbenchThe local application now exposes registered record types, the source-gated concept/code-set registry, ParticipantContext-isolated recurrence evidence, deterministic narrower-than mapping and append-only promotion decisions. Open Configuration.

Insurer SaaS tenancy

Enter as the insurer, then work its private book

Company identity is a security boundary, not a cosmetic filter. XL Insurance Company SE and the reusable HDI Global SE isolation fixture have source-linked identities; deployment, policies and amounts remain explicitly synthetic UAT unless separately evidenced.

01

Select participant company

Choose the insurer first, then an authorised persona and legal-entity context. Changing company issues a new participant-bound session token.

02

Private-native policies

Operate ordinary primary policies without requiring a shared-market programme, layer cake or market placement.

03

Market hand-off

Where the insurer participates in a market placement, accept a source reference into the isolated private operating book without copying or mutating the shared market contract. The executable HDI/BP example is explicitly synthetic UAT and reconciles shared consequence as reference-only.

04

External import

Process policies received from in-house systems through governed integration, provenance and reconciliation controls.

Isolation and provenanceInsurerID evidence may establish an identity candidate; it does not prove Delvor adoption, a real placement or a real private policy. Cross-participant policy, claim, reinsurance, finance and analytical access is denied and tested.
UAT-096 acceptedSupported-browser evidence proves XL Private-only and Delvor Market/Private operation. Two fresh 112-migration rebuilds, 154 repository tests, health checks and live tenant isolation tests pass. Inspect the machine-readable design status.

Governed change

Architecture decisions and remaining gates

The layer-cake, operating-mode and signing foundations now exist in migrations 084–085 and the local browser. Governed write APIs and the full principal journey remain release-gated.

Accepted · 27 Aug 2026

ADR-0003 — Programme layer cakes

Introduces shared composition, bound participation contracts and the private-position boundary.

Accepted · 27 Aug 2026

ADR-0004 — Independent operating modes

Market, Private and Both become independently deployable, with an explicit processing route per market contract.

Accepted · 27 Aug 2026

ADR-0005 — Integration Hub and analytical shadow

Defines message contracts, delivery/response evidence, externally observed snapshots and synthetic scenarios.

Accepted · 27 Aug 2026

ADR-0006 — Governed market signing

Separates order, written, signed and economic shares and requires accepted signing evidence before bound contract hand-off.

Accepted · 27 Aug 2026

ADR-0007 — Insurance ledger / ERP boundary

Delvor owns insurance subledgers and participant accounting; corporate ERP capabilities remain integrated through governed adapters.

Accepted · 27 Aug 2026

ADR-0008 — Governed extensibility

Defines typed local fields, LOB-aware forms, claims media, concept mappings, deliberate promotion and confirmable AI proposals.

Accepted · 27 Aug 2026

ADR-0009 — Multiparty workspace

Defines contextual roles, perspectives, rooms, obligations and multidimensional state around a market transaction.

Accepted · 27 Aug 2026

ADR-0010 — Multinational orchestration

Defines governed eligibility, local solutions, carrier roles and explicit derived risk-transfer chains.

Inspect machine-readable decisions
UAT-097Release resilienceBackup/restore, upgrade/rollback, diagnostics, support bundle and ERP adapter
UAT-098Hardening and scaleSecurity, data-quality, performance, recovery, media and AI-isolation gates
UAT-099–100Acceptance and releaseAll 67 scenarios, defect closure, packaging and machine-readable completion report

Research-backed consolidated backlog

98 requirements and 67 acceptance scenarios

CA-001–CA-025, MUI-001–MUI-020, ML-001–ML-052 and owner requirement REQ-EXT-001 deepen UAT-090–100. Research inputs define product requirements, not legal advice, procurement validation or completion evidence.

Covered foundations55 of 25Acceptance depth remains traceable
Partial depth gaps1818 of 25Mapped into UAT-090–098
New backlog22 of 25Extension marketplace and ERP adapter
90

Market transaction

Composition, signing, transaction workspace, contextual roles, obligations, documents and principal journey.

91–92

Product, multinational and claims

Eligibility, local solutions, product/rating versions, DIC/DIL, claims intelligence and catastrophe accumulation.

93–94

Finance and risk transfer

Billing, tax, cash exceptions, parallel books, captives, collateral, ART and treaty mechanics.

95–97

Authority and coexistence

Roles, perspectives, delegated authority, account-scoped portal access, source/version impact, configuration, rule governance, migration and ERP reject/replay.

98

Standards and scale

Privacy, licensed content, market messages, resilience, stewardship and repeatable peak benchmarks.

99–100

67-scenario acceptance

Execute T-01–T-13, UI-T01–UI-T12 and ML-T01–ML-T42; close high defects and publish traceability.

Deferred · FUT-DOC-001Schedules, invoices, debit/credit notes, account-current and collateral notices are listed for post-UAT-100 document production. They are not included in the 98/67 active totals.
Deferred · FUT-GCI-001After UAT-100 and separate authorisation, model the read-only InsurerID/BrokerID provider contracts and create a future InsuredID project for a reproducibly selected 10,000-group corporate-structure corpus. Selection, licensing, funding and ownership gates remain open; nothing is added to this release.
Public

Corporate structure

Source-governed groups, exact legal entities and typed historical relationships with evidence, review state and explicit unknowns.

Shared

Market placement

Only deliberately shared programme, layer, participation, contract and gross-claim facts—not inferred from the corporate graph.

Private

Participant risk financing

Retention, cession, retrocession, recovery and net position remain ParticipantContext/RLS-private and cannot be discovered through the public graph.

Implementation readiness

Delivery position

Architecture completion and application completion are deliberately separate.

Architecture100 / 100100%Complete, with ADR-0003–0010 controlled extensions
UAT delivery95 / 10095%UAT-095 governed analysis and multiparty commands are complete
Operating modesFoundation built2 of 3Decision + migration/API → browser acceptance
Next implementation sequence
  1. Continue UAT-097 recovery and ERP integration: isolated PostgreSQL logical restore passes 289 relation/sequence content comparisons with the source unchanged; retained backups, cross-store recovery, restored permissions and upgrade/rollback remain open.
  2. Complete standards, resilience and scale controls through UAT-098.
  3. Execute the 67 baseline scenarios plus ten operational scenarios: 77 total, with persistent expected-versus-actual evidence and named human business-role sign-off.
  4. Close UAT-100 traceability and hardening; retain FUT-DOC-001 as deferred document production.
Approved operational acceptance · planned, not implementedOPS-001–010 cover daily role work, independent business acceptance, migration/cutover, insurer onboarding and exit, correspondence, payment fraud controls, operational ownership, trusted BI definitions, long-lived claims and safe demo isolation. Reviewer assignments and task-time targets remain open. Automated tests cannot supply human sign-off. Local UAT readiness is separate from production approval; subscription billing and self-service purchasing remain later decisions.

Living layer cake and explainable numbers

The Market structure workspace now includes a loss explorer: enter a synthetic gross loss, watch attachment, consumption and exhaustion, and open “Explain this number” for the formula, inputs and fixture references. No posting or private-book calculation occurs.

The first slice supports exact single-currency bands. Historical replay, saved scenarios, broader financial explanations, reconciliation triage and evidence-aware assistance are planned extensions, not completed features.

Open the market workspace