The operating model
Institutional system
A purpose-built operational system engineered around a public institution’s mandate — its authority, structure, records and accountability. The mandate shapes the system model; the institution is never reorganized to fit a product.
RelatedOperating platform · System of record · ImplementationDemonstrated at Institutional Systems →
Operating platform
A platform an organization runs on, not an application it runs alongside: structure, people, workflows, records and reporting operating through one governed model. In CREA-KO’s public model, continON is the operating platform.
RelatedConfigurable platform · System of recordDemonstrated at continON →
Configurable platform
A platform shaped to the organization through configuration — processes, forms, rules, documents, reports — rather than rebuilt through custom code each time operations change. Adaptation stays inside the governed model instead of spawning disconnected applications.
RelatedOperating platform · Selective modernizationDemonstrated at continON Platform Foundation →
System of record
The system holding the authoritative version of an operational fact — the place where separate domains agree on what is true. Without one, each application keeps its own version of the truth and the organization reconciles by hand.
RelatedRecord · Evidence lineageDemonstrated at Enterprise Resource Planning →
Position & assignment
The separation that keeps an organization’s shape while its people change: the position persists, an assignment places a person in it for a period, and responsibility attaches to the authorized assignment — never to a name alone, never to an empty seat.
RelatedIdentity & access · Institutional memoryDemonstrated at Workforce Management →
Control, custody & coordination
Data sovereignty
Who controls the environment a system runs in — the data, documents, identities, records, backups and logs. Custody is allocated deliberately in how the system is engineered and contracted, not left to a vendor’s defaults.
RelatedClient-controlled infrastructure · Controlled deploymentDemonstrated at Data Sovereignty →
Client-controlled infrastructure
Deployment environments where administrative control remains with the organization — its own infrastructure where the mandate requires it, other controlled environments where appropriate. The deployment varies; the allocation of control does not.
RelatedData sovereignty · Controlled deploymentDemonstrated at continON Deployment Options →
Controlled deployment
Deployment treated as a governed transition, not a file transfer: the environment understood first, boundaries defined, validation inside a controlled zone, an approved gate — and responsibility continuing after go-live.
RelatedImplementation · Business continuityDemonstrated at Controlled Deployment →
Identity & access
The engineering that decides who may act — in which role, under which conditions, on which resource — and keeps an accountable record of that decision. Access follows organizational responsibility instead of accumulating around accounts.
RelatedLeast privilege · Auditability · Position & assignmentDemonstrated at Identity & Access →
Least privilege
Access granted at the smallest scope a responsibility needs, and no wider — then reviewed against what the responsibility still requires, so access does not quietly outlive its purpose.
RelatedIdentity & access · Segregation of dutiesDemonstrated at Access & Auditability →
Segregation of duties
Duties that should check one another kept in different hands, so no single account can both take an action and approve it. A structural control, engineered into roles and workflows rather than requested as good behavior.
RelatedLeast privilege · AuditabilityDemonstrated at Access & Auditability →
Auditability
The ability to reconstruct governed action afterwards — who acted, under what authority, on what basis — from durable records rather than memory. It is engineered into how actions are recorded, not added as reporting later.
RelatedRecord · Evidence lineage · Segregation of dutiesDemonstrated at Access & Auditability →
Bounded coordination
Coordination across independent authorities without merging them: information moves only through defined exchange points, an exception returns to the authority that owns it, and a shared picture of status emerges without any domain giving up its records or its say.
RelatedMulti-agency environment · CustodyDemonstrated at Multi-Agency Environments →
Multi-agency environment
An operating context where several institutions work toward one objective while each remains answerable to its own mandate and its own law. The engineering answer is bounded coordination, not a shared pile of data.
RelatedBounded coordination · Institutional systemDemonstrated at Multi-Agency Operations →
Work, records & evidence
Workflow
The governed movement of work: routed, assigned, reviewed and decided under rules, with responsibility explicit at every step rather than improvised between inboxes.
RelatedCase management · RecordDemonstrated at Workflow & Case Management →
Case management
Work organized around a persistent record that accumulates its entire history. States change, responsibility changes hands, exceptions branch and return — the record remains, and the history grows.
RelatedWorkflow · RecordDemonstrated at Workflow & Case Management →
Record
More than content: the context, version, responsibility, relationships, access and retention held together so that what happened stays provable and understandable. Content alone is not the record.
RelatedRetention · Auditability · Case managementDemonstrated at Documents & Records →
Retention
How long a record must remain available and understandable — governed deliberately across its life rather than decided by whichever disk it happens to sit on.
RelatedRecord · Institutional memoryDemonstrated at Documents & Records →
Evidence lineage
The traceable path from a reported figure back through its measure and definition to the source records it came from — so a number can be interrogated and defended, not just displayed.
RelatedSystem of record · AuditabilityDemonstrated at Reporting & Business Intelligence →
Custody
Who holds an item — and who is accountable for it — at every point of movement: receipt, stock, movement, handoff, distribution and reconciliation. The custody line stays continuous even when the work does not go to plan.
RelatedRecord · Bounded coordinationDemonstrated at Supply Chain Management →
Continuity & evolution
Business continuity
Prepared capability that keeps critical functions operating through disruption: documented, rehearsed where agreed, restored to a governed state, and improved by review. Not a promise that nothing fails.
RelatedControlled deployment · Lifecycle responsibilityDemonstrated at Business Continuity →
Institutional memory
What the organization keeps as people, leadership and technology change: records and their meaning, responsibility and its history, working knowledge. Systems are engineered so this memory survives every transition, including their own replacement.
RelatedRetention · System evolution · Position & assignmentDemonstrated at Long-Term System Evolution →
Selective modernization
Modernizing what constrains the organization while keeping what still works: new capability enters alongside systems in service, connected through defined boundaries, and transition happens deliberately — not as a leap from old to new.
RelatedIntegration · System evolutionDemonstrated at Integration & Modernization →
Integration
Connection under defined interfaces: systems exchanging selected information without surrendering ownership, blurring responsibility, or quietly widening what each may touch.
RelatedSelective modernization · Data sovereigntyDemonstrated at Integration & Modernization →
Lifecycle responsibility
The delivery model in which deployment is a milestone, not an exit: operation, maintenance, adaptation and controlled enhancement continue under named responsibility, with knowledge kept usable by the client throughout.
RelatedBusiness continuity · System evolutionDemonstrated at Support, Maintenance & Evolution →
System evolution
A system changing across generations without the institution losing its memory: established, kept dependable, adapted as the organization changes, selectively modernized, and carried onward through documentation, training and controlled releases.
RelatedSelective modernization · Institutional memory · Lifecycle responsibilityDemonstrated at Long-Term System Evolution →
Implementation
The work that makes a system real inside an organization: introduced around how the institution actually works, people trained, procedures established, and support holding the result afterwards. A system nobody can run has not been implemented.
RelatedControlled deployment · Lifecycle responsibilityDemonstrated at Institutional Programs →