Skip to content

What is in scope for the review, what is deliberately excluded, and the confidentiality terms of this build.

Updated Jun 9, 2026

Scope, NDA, and watermarking

This page defines what is in scope for the EY review, what is out of scope, and how this build of the docs site is protected.

In scope

The review covers the documentation set exposed in this build. Specifically:

  • Architecture - C4 L1 system context, C4 L2 container views per capability, C4 L3 component views where they exist, dynamic process flows, the deployment landscape view, and the auth / events / access-control overview pages.
  • Domain - the business ontology, the InFORM-aligned domain language, the glossary of terms with their invariants and caveats, and the alignment of Olly concepts to industry-standard insurance concepts.
  • Process coverage - the InFORM-aligned coverage map that calls out which insurance value-chain processes are implemented, partially implemented, or out of scope. This is the primary artefact for the use-case completeness dimension.
  • Designs - the design records covering significant architectural decisions (auth model, PII walls, event topology, ontology projection, notifications, and others).
  • Get-started and platform overview pages linked from the home page - useful for orienting yourself in the system before going deep.

If you cannot find something you need for the review against the seven dimensions, please raise it through the contact channel below rather than inferring from absence.

Out of scope

The following are deliberately excluded from this build and from the engagement:

  • Source code of any service. The review is on the architecture and the docs, not on implementation correctness.
  • Database schemas at column granularity. Table-level structure and the domain ontology are in scope; column-level DDL is not.
  • Triage algorithm internals. The triage service is described at the container and integration level. The clinical decision logic, pathway authoring, and LLM prompt engineering inside the triage service are out of scope for this engagement.
  • Infrastructure topology beyond what is shown in the deployment view: specific hostnames, IPs, secrets, certificates, and the operational runbooks are excluded.
  • Partner contracts. Where the architecture depends on an external partner (brokers, underwriters, claims handlers, payment processors, NHS data sources), the integration is in scope but the underlying commercial contracts are not.

If a finding requires access to material that sits in one of these excluded areas, please file the finding with the limitation noted and we will arrange a focused follow-up where appropriate.

NDA and confidentiality

The content of this build is confidential to Olly and to EY under the NDA executed for this engagement.

  • Do not share screenshots, URLs, exports, or quotes from this build outside the EY review team.
  • Do not store copies of pages outside the systems agreed in the NDA.
  • The review deliverable (the finding register and executive summary) may reference page URLs from this build, but should not embed verbatim screenshots in any document that leaves the engagement.

Watermarking

Every page in this build is watermarked with:

  • The engagement date (the date this build was generated for EY).
  • A page identifier unique to this build and to the page.

The watermarks appear on screen and persist in screenshots and PDF exports. A leaked screenshot is traceable back to this build and to the page it came from. This is not a trust signal directed at EY; it is a control we run on every confidential build, including internal ones.

If you find a page where the watermark is unreadable, broken, or missing, please flag it through the contact channel so we can fix the build rather than continue without it.

Contact channel

For any access issue, missing artefact, clarification question, or scope dispute during the review, please use:

architecture-review@olly.uk

This mailbox is monitored by the Olly architecture team during UK business hours and routed to a named owner for this engagement. For urgent or out-of-hours matters, use the escalation path agreed in the engagement letter.


Ready to start? See the Recommended Reading Order.

Olly Health Insurance Platform