Skip to main content

ktayl IS β€” Architecture at a Glance

If you read one page to understand ktayl, read this. It is the whole business-application architecture on a single screen: who uses it, the insurance value chain, the legacy core it wraps, the shared platforms (Data Β· AI Β· Documents), and the foundations everything runs on β€” plus a reading path into the detailed docs. Depth lives elsewhere; this is the mental model.

:::note One insurer, one IS β€” and a separate product ktayl-solution is a fictional commercial-lines (IARD / large-risk) insurer; everything here is its information system. Retrieva is a separate product (RNCP cert / DORA) that only runs on this platform β€” it is not a ktayl business app and appears nowhere below. :::

:::info Status legend (what's live vs not) β€” verified against the running cluster 2026-09-30 🟒 live in prod Β· πŸ”΅ live on dev only Β· 🟑 partial (some pieces live) Β· βšͺ planned (not built yet). Only the tagged domains/platforms actually run; untagged arrows are the value-chain pipeline, not a status claim. The authoritative box-by-box status is the table under the picture. :::

The one picture​

Read it top-down: people β†’ the apps they touch β†’ the insurance value chain (the business) β†’ the legacy core that one domain wraps β†’ the shared Data/AI/Document platforms β†’ the foundations.

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
PEOPLE β”‚ Underwriters Β· Claims handlers Β· Brokers β”‚
β”‚ Finance Β· Compliance Β· Ops β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ browser-first, SSO (Authentik + MFA)
CHANNELS / APPS β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
(how work gets done) β”‚ Web apps Β· Underwriter/Claims workbench β”‚
β”‚ Broker portal Β· Digital workplace (M365-alt)β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ every call: OIDC Β· RBAC Β· audit
══════════════ BUSINESS VALUE CHAIN (the insurer itself β€” Track A) ══════════════
DISTRIBUTION ─► UNDERWRITING ─► POLICY ADMIN ─► CLAIMS ─► BILLING ─► REINSURANCE
βšͺ #13 πŸ”΅ #12 🟒 #6 🟒 #11 βšͺ #14 βšͺ #22
broker/CRM workbench contracts FNOL→ premium treaty/
submissions rating/quote endorsements settle finance cessions
feeds UW β–² βšͺ RISK ENGINEERING #21 (risk survey β†’ prevention) spans the chain β—† βšͺ INTERNATIONAL PROGRAMMES #23 (master/local Β· DIC/DIL)
β”‚ β”‚
β”‚ β”‚ (Claims is delivered by wrapping a legacy)
══════════════ LEGACY SPINE β€” one deliberate initiative (Track C) β€” LIVE on dev+prod ══════════════
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ GlobalCore (System of Record) β”‚ MySQL* Β· Java Β· SOAP Β· batch
β”‚ FROZEN Β· OUTSIDE k8s β”‚ holds the CLAIMS domain
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ *simulated Oracle-era legacy (ADR-002)
ACL wraps it: │ SOAP→JSON (writes) · Debezium binlog→NATS JetStream (CDC)
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ ktayl-claims (#11) = the ACL β”‚ modern Claims, built AS the wrap β€” LIVE
β”‚ + CQRS read-model (CNPG) β”‚ reads = projection; writes = SOAP (ADR-008)
β”‚ + Angular adjuster workbench β”‚ nginx BFF β†’ internal ACL (ADR-009)
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚ clean domain events on NATS (never raw legacy access)
══════════════ SHARED PLATFORMS (serve every domain β€” transversal) ══════════════
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ DATA / ACTUARIAL β”‚ AI / AUTOMATION β”‚ ENTERPRISE DOCUMENT PLATFORMβ”‚
β”‚ #5 β”‚ #4 Β· #18 Β· #19 β”‚ #24 β”‚
│ warehouse · BI │ RAG (docs) + SQL-tools │ parse→chunk→metadata→embed │
β”‚ semantic/metrics β”‚ (data) Β· Copilot (last) β”‚ β†’vector DB Β· GED Β· e-sign β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
also transversal: 🟑 INTEGRATION (#25 Β· API-GW/events/ETL) Β· βšͺ MDM (#20 Β· golden records) Β· 🟑 COMPLIANCE (#15 Β· AML/sanctions/obligations) Β· βšͺ ITSM (#16 Β· GLPI/CMDB)
══════════════ FOUNDATIONS (live) + GOVERNANCE (continuous β€” Track B) ══════════════
k3s Β· GitOps (ArgoCD/Kargo) Β· IaC (OpenTofu) Β· Observability (OTel/Prom/Grafana/Tempo)
Identity (Authentik) Β· Secrets (Vault/ESO) Β· Supply-chain (cosign/SBOM/Trivy)
GOVERNANCE gate every domain clears: regulatory impact Β· AI-Act tier Β· NFR + security + resilience

What's live vs planned​

The single source of truth for the picture above β€” every box, with its verified status (checked against the running cluster on 2026-09-30, not the roadmap). 🟒 prod Β· πŸ”΅ dev only Β· 🟑 partial Β· βšͺ planned.

BoxStatusNote
Policy Admin #6🟒 prodthe first live core system (dev+prod)
Claims #11 β€” ACL + Debezium CDC + CQRS read-model + adjuster workbench🟒 prodthe legacy-spine wrap, live end-to-end (dev+prod)
Underwriting #12πŸ”΅ devintakeβ†’ratingβ†’quoteβ†’bind + workbench UI live on dev; prod promotion pending
Distribution / CRM #13 Β· Billing #14 Β· Reinsurance #22βšͺ plannedscaffold / no app yet
Data / Actuarial #5🟑 partialMetabase BI + CNPG live (Slice 1); warehouse / semantic layer / actuarial planned
AI / Automation #4 Β· #18 Β· #19🟒 prodLiteLLM Β· Langfuse Β· Qdrant Β· RAG Β· LangGraph/CrewAI agents β€” mature
Enterprise Document #24🟑 partiale-sign + storage + RAG ingest live (Docuseal/Nextcloud); records-mgmt DMS planned
Integration #25🟑 partialNATS / Temporal / n8n engines live; API + event catalogue + BPM/approvals planned
MDM #20βšͺ plannedgolden records parked β€” the keystone gap for cross-domain (customer) analytics
Risk Engineering #21βšͺ plannedscaffold; risk survey β†’ prevention recommendations β†’ feeds underwriting (the P1 insurability pivot)
International Programmes #23βšͺ plannedscaffold (ktayl-ip-portal backlog); master/local policies Β· DIC/DIL Β· PO↔SO premium/claims flows
Compliance & Enterprise Risk #15🟑 partialobligations register (doc) + DORA pattern proven via Retrieva; AML/sanctions screening planned
ITSM #16βšͺ plannedscaffold; GLPI (ITIL v4) + CMDB β€” not yet live
Foundations β€” k3s Β· GitOps (ArgoCD/Kargo) Β· Observability Β· Identity Β· Secrets Β· Supply-chain🟒 prodmature

Reading the value chain honestly: it is live at both ends (Policy + Claims in prod) with the operational middle (Underwriting on dev; Pricing/Billing planned) still in progress β€” not a fully running end-to-end insurer yet.

The three tracks (why nothing is scattered)​

Every item on the roadmap is in exactly one of three parallel tracks β€” this is the organising idea:

TrackWhat it isContains
A β€” Business buildthe insurance value chain, built domain by domainDistribution #13 β†’ Underwriting #12 β†’ Policy Admin #6 (live) β†’ Claims #11 (live) β†’ Billing #14 β†’ Reinsurance #22 Β· + Risk Engineering #21 Β· International Programmes #23 (value-chain) Β· Compliance #15 (governance-adjacent) Β· ITSM #16 (enterprise-IT)
B β€” Governancethe gate every Track-A build clears (not a phase)regulatory impact Β· AI-Act tier Β· NFR/security/resilience by design
C β€” Modernization labthe legacy-wrap muscle, feeding real integration skill into AGlobalCore (legacy core) + the ktayl-claims ACL + GenApp M1–M4

Foundations (platform #3, AI #4, digital workplace #10) are live and underpin all three.

How every domain is built (one repeatable recipe)​

1. FDE playbook β†’ understand the domain (process, users, pain, data, KPIs)
2. BMAD spec+stories β†’ the implementation contract
3. Thin end-to-end slice β†’ (uses Track-C wrap patterns when it touches the legacy)
4. Governance gate β†’ Track-B: regulatory impact + AI-Act tier + NFR/security/resilience
5. Deploy (GAP wrapper chart) β†’ iterate

So the docs aren't a pile of apps β€” they're one architecture, three tracks, one recipe per domain.

Reading path (where to go next)​

You want to understand…Read
What to build next / the tracks🧭 IS Build Roadmap
The functional target (12 domains + 4 layers) + the legacy spineπŸ› EA Blueprint
Every app, its stack + statusBusiness Applications Catalog
The legacy-core wrap (GlobalCore + MySQL + Claims β€” LIVE)*Legacy-Core Modernization
How AI is applied (RAG vs SQL-tools, the copilot)AI-First Operating Model
Regulation & compliance-by-designRegulatory Operating Model
A worked domain (deep-dive)Underwriting FDE Playbook Β· Policy Service Β· Legacy-Core Modernization / Claims

One-line takeaway: ktayl is a greenfield-modern insurer whose value chain is live at both ends β€” Policy #6 and Claims #11 in prod β€” with the operational middle (Underwriting on dev; Pricing/Billing planned) still in progress, all built domain-by-domain on a mature k8s platform, with one deliberate legacy spine (Claims via GlobalCore/MySQL, simulated) β€” live end-to-end to prove real enterprise modernization β€” all clearing a continuous governance gate.