01 Review scope
What exists.
How it connects.
What is ready.
A technical review of the product builds, the enterprise dependencies around them, and the evidence behind the current status.
Scope boundary Meeting request supplied July 27, 2026. Claims in this review are separated from proposed design and owner-confirmation items.
02 Product landscape
Two products built.
Existing platform in secondary scope.
The architecture conversation starts by separating new product delivery from a focused change inside an existing application.
GroupLink Portal
Group administration modernization
- Modern React experience
- API and PostgreSQL coexistence layer
- Controlled bridge to DB2
BrokerLink Portal
ACA marketplace and regulated enrollment
- Broker, consumer, and admin surfaces
- CMS Marketplace and Hub clients
- Evidence-aware transaction design
ServiceLink Portal
ICHRA Phase 1 delivered in the existing ServiceLink Portal
- Existing platform and operating model
- One platform extended with the delivered Phase 1 capability
- Secondary scope in this technical review
- No new portal request
Evidence boundary GroupLink and BrokerLink reflect inspected programme and code records. ICHRA Phase 1 is recorded as delivered inside the existing ServiceLink Portal; it remains secondary scope here and does not imply a new portal.
03 GroupLink · current implementation
Modern experience.
Controlled coexistence.
Bidirectional IBM CDC deployment underway is the coexistence synchronization mechanism. DB2 remains authoritative as the system of record while dependent applications stay on the mainframe and the controlled PostgreSQL projection is introduced.
DB2 remains authoritative while CDC subscriptions and controlled write ownership are deployed in stages.
Claim boundary The bidirectional IBM CDC deployment is underway; this is not a claim that a live two-direction cutover is operating. DB2 remains authoritative, and subscription scope, write ownership, latency, recovery, and cutover controls stay governed by the HPS CDC design.
04 GroupLink · data + integration
Known path.
Unknowns made explicit.
IBM CDC is the evidenced coexistence path. SAML identity, DataPower mTLS APIs, MQ / ACE messaging, ExchangeLink services, and managed-file lanes are shown orthogonally so transport and authority do not blur together.
boundary portal + API + projection
Caller: React portal
Path: Spring Boot / DataPower
Auth: PingFederate SAML + mTLS
Payload: domain JSON
Source: DB2
Tool: IBM CDC
Target: PostgreSQL
Authority: DB2
Route: confirm
Schedule: confirm
Encryption: confirm
Owner: confirm
Correlation: confirm
Retention: confirm
Error path: confirm
Telemetry: confirm
Candidate domain sequence: employer / group → enrollment context → billing status → document references → audit events
Physical schema and endpoint inventory: confirm from the HPS design packDesign boundary Bidirectional IBM CDC deployment is underway while DB2 remains authoritative. API, message, file, and control lanes show the technical topology; exact production routes, payload versions, owners, and physical schema remain governed by the HPS design pack.
05 Enterprise payment boundary + GroupLink target
Keep the product clean.
Keep payment controlled.
Shared payment integration is in use as an enterprise dependency, not a GroupLink-owned gateway. GroupLink invokes the controlled tokenized enterprise path.
GroupLink payment route Caller: GroupLink · Path: shared enterprise payment integration · Auth: enterprise policy · Payload: tokenized payment request.
Source / proposal split The shared payment integration is in use. PaySafe / Fiserv retain the PCI boundary, DataPower applies enterprise policy, and ServiceLink performs binder / enrollment matching. The further target-state decomposition remains a proposed design, not committed scope.
06 BrokerLink / MarketLink · system architecture
A regulated workflow,
built as a system.
MarketLink is production-ready, and CMS UAT APIs exercised successfully. The system joins role-aware experiences, local controls, public API callsites, CMS Hub transport, document capture, and evidence context without collapsing their trust boundaries.
Corporate HPS GitLab · access is provisioned through HPS
Architecture review, not repository distributionImplementation boundary Architecture reflects inspected code, programme-owner delivery records, and UAT status. Production-ready remains distinct from CMS certification and audit closure: release evidence binding remains a separate gate, with no auditor certification claim.
07 BrokerLink / MarketLink · integration inventory
Plan discovery and EDE
take separate paths.
Two inspected code snapshots contain overlapping but divergent clients. The topology shows integration families; the matrix keeps source ref, method, local callsite, schema maturity, and live-proof state separate.
domain services Marketplace / Census / RCL clients · Hub contract layer · carrier stub
REL/SIT POSTPlan search/plans/search → /api/quotes · app-wired
REL/SIT GETCounty-by-ZIP/counties/by/zip/{ZIP} → /api/quotes/counties
REL/SIT GETCrosswalk/crosswalk → renewal communications
REL/SIT POSTSLCSP/households/slcsp · client method present / no application callsite located
RJ74Hub connectivityREST both refs · SOAP path only in SIT
RJ139 / RJ140Identity scope configH139 / H140 harness IDs are separate identifiers
SESApplication lifecyclewrappers present · major steps lack application callsites
V4 SOAPEligibility + enrollmenteligibility SIT only · enrollment both refs · schema maturity differs
REL GET | SIT POSTDMI / SVIsame paths · divergent methods · wrapper-only
REL JSON | SIT MULTIPARTDSRS uploaddocument contract diverges · no application callsite
IESPolicy + redirectget-policy and redirect methods diverge by ref
EBPEvent processing/ebs/v1/events · wrapper / runtime proof pending
RESTUS Censusgeocoder / geography match
SODACMS RCLproducer registration by NPN
AGENTCMS IDM-Okta + RCL / NIPROIDC config · RCL app-wired · NIPR service scaffold uncalled
CONSUMERRIDP-RBA / GetRecordconsumer route → identity record seam · config + live proof open
SMTPCommunicationsconfiguration + delivery proof required
DOC/OCRDocument Capture / OCRimplemented per programme owner record · release artifact binding remains separate
PLAN DATAProvider + formulary linksfields returned by Marketplace; no provider API client
X12 834Carrier adapter / 834 transport“Would SFTP / POST” transport seam
Proof boundary Release 7e1e013 and SIT 5200de0 are divergent source snapshots, not one deployable implementation. CMS UAT APIs exercised successfully at programme level; binding each release artifact to its source ref remains a separate gate. No standalone provider-network API client was found: provider directory, formulary, SBC, brochure, and issuer links arrive in Marketplace plan data. MarketLink does not process payment, and its carrier transport is not connected.
08 BrokerLink / MarketLink · transaction + trust
Successful UAT path.
Trust made visible.
CMS UAT APIs exercised successfully across the required workflow. This orthogonal view separates identity, application, eligibility, plan, enrollment, documents, transport, and evidence so a programme outcome is not confused with one source snapshot.
CORRCorrelation IDrequest → responseAUTHActor + authoritywho acted, under what roleAUDITAuditable event recordwhat changed, whenEVIDCase artifactproof for reviewIdentity establishes the actor and proofing state before regulated data is changed.
STATUS · UAT EXERCISED · RELEASE ARTIFACT BINDING TRACKED SEPARATELYSequence boundary The programme records successful CMS UAT API exercise. The required workflow with wrapper-level support remains mapped by source ref; this diagram inventories support and trust boundaries rather than serving as the auditor certification packet. Broker / agent authentication and licensing follow the separate CMS IDM-Okta + RCL / NIPR path. Carrier / 834 delivery remains a separate stubbed boundary.
09 BrokerLink / MarketLink · delivery + audit status
Production-ready product.
Audit package still gated.
MarketLink is production-ready and CMS UAT APIs exercised successfully. The next assurance gate still depends on clean, reviewable transaction artifacts—not on the calendar alone.
traceability rows mapped
review candidate
pending captures
source pending
export-ready
Elevate Consult appears as the intended auditor, but contract status is contradictory across inspected documents. Independent auditor not confirmed.
Readiness boundary Counts reflect the generated July 27 review artifacts. The 21 / 21 value is traceability coverage, while production-ready and successful CMS UAT exercise are delivery states. Export readiness and independent certification are separate; there is no auditor certification claim. Failures remain remediation evidence until a clean rerun is captured.
10 BrokerLink / MarketLink · network + deployment
From the network edge
to the evidence gate.
The inspected deployment and service artifacts define a full control path. They do not yet bind the running environment to an exact release SHA, configuration, and certificate set.
Topology boundary Code and runbooks establish the control design. A signed environment → repository / ref / SHA / SBOM / configuration manifest is still required to prove the exact running topology.
11 HPS current estate · end-to-end data flow
The products sit inside
a larger operating system.
Digital channels cross shared identity, API, messaging, file, data, payment, document, and communications layers. The modernization products overlay this estate; they do not erase it.
Identity at entry · API policy at the edge · service / message / file exchange in the middle · authoritative data and operating outputs at the right
Current-state boundary Source-backed from the April 2026 Wipro Links architecture and modernization kickoff. GroupLink and BrokerLink are shown as transformation overlays, not labels from the source diagram.
12 Portfolio · initiative horizon
The platform work
is already compounding.
The next wave applies the same engineering pattern to claims, contact center, data access, documents, and reconciliation—each at its recorded delivery gate.
Modernize the platform. Infuse AI across it.
Register boundary Portfolio status is sourced from the governed August 5, 2026 register. Meeting updates should be reconciled back into that source before any status is upgraded.