State of the proof
What this is not
It is not Technology Strategy. Strategy decides what to invest in, in what order and at what cost; this expertise structures and builds what has been decided. Neither page borrows the other's vocabulary, and enterprise architecture sits here rather than there for exactly that reason.
It is not body-shopping. The forms include placement, but a placement is calibrated against a named gap and carries the practice with it — the mandate is a capability applied, not headcount supplied.
It is not a rewrite by default. Most estates that feel unmaintainable need boundaries, tests and a deployment path before they need replacing, and a rewrite proposed before those exist is a bet the collective will argue against.
Enterprise & solution architecture
Structuring what has been decided: domain boundaries, integration contracts, and the target state a roadmap is executed against. Technology Strategy decides; this structures.
Enterprise and solution architecture is the discipline that turns a decision into a structure other people can build against: domain boundaries, the contracts between them, and the target state a roadmap is executed toward.
The distinction from Technology Strategy is the one that matters commercially, and it is drawn the same way on both pages. Strategy decides — what is invested in, in what order, at what cost. Architecture structures what has been decided. A client who arrives with the decision already made needs this; a client still making it needs the Advisory offer.
The work produces boundaries with a rationale attached, integration contracts specific enough to build against, and a migration path from the estate that exists to the one that was decided. It names what will not be built, which is usually the more useful half: an architecture that forbids nothing constrains nothing.
It is bought when several teams have to build toward the same target and are currently interpreting it differently, when a merger puts two estates in one operating model, or when a platform decision has stalled between technology, product and operations. It is the wrong purchase for a single team on a single product, where the architecture is small enough to hold in a conversation and formalising it costs more than it returns.
Software engineering
Building and running the software itself, with the practice and the standards that let someone else maintain it.
Architecture is only real once it ships. This werk holds the target architecture, the integration surface and the engineering organization, and is measured on what runs rather than on what was specified.
Software and digital factory built and industrialized at AXA group level.
Carried inside the AXA factory mandate; no isolated case published.
Cloud & platform engineering
The platform the product teams deploy onto, and the paved road that makes the safe path the fast one.
The platform werk owns what everything else stands on. A migration that lands on an unpaved substrate produces the same delivery friction at a different address, with a cloud bill attached.
Five-nines target held on the PMU platform; SRE practice not published as a case.
Data engineering
The estate AI depends on: ingestion, modelling, lineage and the quality contracts downstream consumers rely on.
Data work earns its place when a number moves. This werk covers the strategy, the platform, the governance and the master data that a commercial promise depends on.
AXA · RAJA Group · Celio · BNP Paribas — FLOA
Data strategy carried at executive-committee level at Celio.
AI engineering
Getting models into production and keeping them there — serving, evaluation, monitoring and rollback.
A model is the smallest replaceable part of an AI product. Everything that decides whether it can be shipped, changed or trusted is engineering: where the call is made from, what context it is given, what it is allowed to do with the answer, how a regression is caught before a user meets it, and what a change costs in money and milliseconds.
This werk builds that layer. It assumes the model will be swapped — for a cheaper one, a newer one, a self-hosted one — and makes that swap a routine release rather than a rewrite.
On-Kare: every model call routed through a single governed provider, with a CI gate failing the build on any call made outside it.
Retrieval over a knowledge graph built from a 15,500-file engineering corpus.
Evaluation dimensions, rubrics and reference datasets specified per AI phase before implementation.
On-Kare: model, prompt hash and timestamp logged on every AI output for conformance audit.
Legacy modernization
Moving an estate that cannot be stopped, in increments each of which is independently valuable.
Legacy work is a cost and risk argument before it is a technology argument. The estate is expensive, slow to change and load-bearing, and the only acceptable exit is one that never takes the business offline.
Security & compliance
The posture, the controls and the evidence trail that turn a claimed certification into an audited one.
Security in this collective is an architecture discipline, not a scanning practice. The question it answers is whether a regulated system can prove what it did, to a regulator, months later.
On-Kare: fail-closed consent guards, AES-256-GCM field encryption, HMAC-chained audit trail across 12 compliance frameworks.
On-Kare: tenant-scoped reads, cache-key isolation and role gating enforced by CI ratchets.
Five-nines availability held on a betting platform where downtime is lost stakes.
Delivery management
Getting a result out of several teams and vendors at once: sequencing, environments, release and the measures that say whether delivery is improving. Product delivery ships one team's increment; this holds the estate's.
Delivery management is the engineering function that gets a result out of more than one team at a time. Where a single squad can be run on its own cadence, an estate cannot: the constraint moves to the seams — who releases into which environment, in what order, against whose dependency, and what happens when two vendors both believe they are unblocked.
The distinction from Product delivery is the one that matters commercially, and it is drawn the same way on both pages. Product delivery turns a decided scope into a shipped increment on a cadence one team can hold. Delivery management holds the cadence across teams, vendors and environments that do not report to each other. A client whose single squad ships unpredictably needs the first; a client whose programme has four suppliers and no one holding the release train needs this.
The work is the mechanics of that: a release and environment model that people can actually follow, dependency sequencing against reality rather than plan, and delivery measures — lead time, change failure rate, restore time — reported the same way by every team so that “delivery is improving” is a number rather than an opinion.
What is handed over is a delivery model the organisation runs without the operator: named owners for the release train and the environments, the measures still being collected, and the escalation path that replaces the person who used to be it.
It is not a programme management office, and it is not a reporting layer added above teams that are already blocked. Where the constraint is that nobody has decided what to build, that is a Product or an Advisory problem, and adding delivery governance on top of an undecided scope makes the drift visible without making it stop.
How it is bought
Any expertise can be bought in six forms: fixed price, time and materials, short placement, long placement, permanent placement or named seat. Each specialty carries the forms that suit it.
Questions
- How is a replatforming kept safe?
- In stages, with availability validated at each cut. The PMU betting platform left the mainframe for AWS while holding a 99.995% target, which is a delivery outcome rather than a slide. A single switchover would have been faster to plan and impossible to defend.
- What is the architectural bias?
- Composable over monolithic, event-driven where state is contended, headless where the front end changes faster than the core. Derichebourg's end-of-life-vehicle platform moved off a monolith onto microservices and conversion rose 18%. legrand.fr was rebuilt on a headless Drupal front office with an Adyen omnichannel payment gateway, run with 30 FTE.
- Does the collective write code?
- It engineers and ships. The mandate is accountable to a system running in production, not to an architecture document handed to a party that did not help shape it.
- At what scale has this been held?
- 250 engineers across five business units at AXA, 120 FTE on the Carrefour replatforming, 30 on Legrand, 15 reorganized into autonomous squads at Satelia. The mandate covers the organization that ships, not only the design it ships to.
- Which clouds has the collective delivered on?
- AWS at PMU and at Societe Generale, where the BU MassMarketing estate left owned datacenters and total cost of ownership fell 37% on cloud-based and API-based application patterns. And a secure European cloud at Satelia, chosen because a cardiovascular telemonitoring platform entering the EU market carries data residency and medical-device constraints that decide the substrate for you.
- Is platform engineering the same as cloud migration?
- No. Migration moves an estate once. Platform engineering builds the paved road that keeps every team after you from rebuilding the same pipeline — which is what was industrialized at AXA as a group software and digital factory, and what made a 2.5-month time-to-market possible on the product that ran on it.
- What is honestly not proven here?
- Infrastructure as code, Kubernetes and GitOps are declared. They are standard components of the mandates above and no published case isolates them, so they are listed as declared rather than implied. A buyer who needs a Kubernetes platform built from zero should ask what has been run, and will get a straight answer.
- What does a data mandate deliver first?
- Usually governance, not a platform. At Adeo the supplier and referencing data model was rebuilt to run at marketplace scale, and that — not a new warehouse — is what cut referencing lead time from 124 days to 15 and let 7,000 suppliers on.
- Is master data a data problem or a supply chain problem?
- Both, which is why it sits here. At Chantelle, order orchestration and stock allocation were re-engineered across every sales channel, and on-time-in-full delivery moved from 85% to 98%. The data model was the mechanism; the promise to the customer was the outcome.
- How does data connect to the AI werk?
- It precedes it. A model on an ungoverned estate produces confident output from unverified input, which launders a data problem into a decision. AI mandates therefore start on the platform and the lineage — the group big-data estate at AXA was industrialized before the products that ran on it were built.
- What is declared rather than proven?
- Analytics engineering, streaming and data mesh. They are in scope and no published case carries them, so they are listed as declared. The proven ground is strategy, platform, governance and master data.
- How is this different from the AI werk?
- The AI werk decides which model belongs behind which decision and proves it is worth putting there. AI engineering builds the system that call lives in: the gateway, the retrieval path, the evaluation gate, the cost budget and the release mechanics. One chooses the intelligence, the other makes it operable by a team that did not write it.
- Why insist on a single model gateway?
- Because governance is only enforceable at a chokepoint. Masking, routing, quotas and lineage are each trivial to implement once and impossible to enforce across scattered call sites, so the gateway is the difference between a policy and a claim.
- What state is the proof in?
- The data-platform and lifecycle lines are proven in client mandates — BNP Paribas FLOA and AXA — and the conversational lines at Orange Business and Peetchr. The gateway, retrieval and evaluation lines currently live inside the On-Kare venture rather than a client case, so they read HELD rather than PROVEN.
- What does a legacy mandate actually move?
- The applications and their economics together. At PMU the total cost of ownership of the replatformed betting applications fell 87% and change lead time fell 41%, while the availability target held.
- What is declared rather than proven here?
- COBOL and 4GL modernization, batch-to-event migration, legacy data migration and green-screen UX are in scope for a mandate and no published case carries them. They are listed as declared rather than dropped, because the estate that needs them is the estate this werk exists for.
- Why is a legacy estate a board problem?
- Because it prices every other decision. A fixed-cost mainframe sets the floor under the IT budget, and long lead times set the ceiling on how fast the business can answer a competitor. At PMU both moved in the same mandate: cost of ownership down 87%, change lead time down 41%.
- Does modernization mean rewriting?
- Rarely, and never by default. Adeo's gain came from decommissioning rather than rebuilding — dismantling legacy systems released EUR 9.5M. The 7R decision is made per application against its remaining life, not per estate against a slogan.
- Where is the real proof?
- In a trading-platform audit and redesign with regulatory alignment at VERMEG, in a medtech telemonitoring platform migrated onto secure European infrastructure for EU market entry, and inside the On-Kare venture, where consent guards fail closed and every sensitive field is encrypted at rest.
- What is out of scope?
- Penetration testing, SIEM operations and identity platform builds. They are listed as declared so a buyer knows to bring a specialist rather than discovering the gap mid-mandate.
- What does a regulated architecture have to prove?
- That it can reconstruct what it did. VERMEG's core trading-platform interfaces were audited and redesigned with regulatory alignment inside a capital-markets vendor, where the interface is the control surface a regulator reads. Satelia's telemonitoring platform was migrated onto secure European infrastructure because data residency was a market-entry condition, not a preference.
- What does fail-closed mean in practice?
- That a missing decorator denies access rather than granting it. On the On-Kare platform, a controller touching patient data without an explicit consent declaration returns a refusal at runtime — the absence of a rule is treated as a denial, which is the only posture that survives an audit.
- Who should not hire this werk?
- An organization that needs a SOC stood up, a penetration-test programme run, or an identity platform built. Those are declared scope with no published proof, and the right answer is a specialist firm plus this collective on the architecture.