Requirements - Documentation
-
D02 - Open Publication
Documentation should be published 'open by default' and exceptions handled according to policy i.e. sensitivity etc.
Requirement description
This requirement is concerned with ensuring that architecture documentation is discoverable, accessible and shared by default across NHS England unless there is a legitimate reason to restrict access.
Restrictions should be based on recognised policy requirements such as information sensitivity, security classification, commercial confidentiality, personal data, or other approved governance controls. Documentation should not be restricted simply because sharing has not been considered.
The objective is to improve transparency, collaboration, reuse, knowledge sharing and architectural consistency across teams and services.
In simple terms:
Architecture documentation should be openly accessible wherever possible, with any restrictions clearly justified and managed according to policy.
Scoring rubric table – D02 Open by Default Documentation
| Score | What it looks like | Typical evidence | Key gaps / risks |
|---|---|---|---|
| 0 | No evidence of an open-by-default approach. Documentation is inaccessible, isolated or restricted without justification. |
Architecture documents held in private locations. No documented sharing approach. No justification for access restrictions. |
Significant service risk. Knowledge remains siloed and architectural decisions cannot be easily reviewed, reused or challenged. |
| 1 | Limited sharing of documentation. Access decisions appear ad hoc and there is little evidence that openness has been actively considered. |
Some shared documentation. Inconsistent permissions. Informal access arrangements. Limited policy awareness. |
High-risk gaps. Important documentation may be hidden unnecessarily and access arrangements may be inconsistent. |
| 2 | Some documentation is openly published and there is evidence that access restrictions are considered, but application is inconsistent. |
Partially shared repositories. Some documented access controls. Basic classification or sensitivity considerations. Inconsistent publication practices. |
Significant notable gaps. Teams may struggle to locate architecture information and restriction decisions may not be traceable. |
| 3 | Much of the architecture documentation is openly available and restrictions are generally based on recognised policy requirements. |
Architecture repositories with broad access. Document classification information. Evidence of policy-based access decisions. Documented exceptions. Shared architecture artefacts. |
Notable gaps remain. Some documentation may be unnecessarily restricted, inconsistently classified or difficult to discover. |
| 4 | Most architecture documentation follows an open-by-default approach. Exceptions are documented, reviewed and supported by policy justification. |
Clearly accessible architecture repositories. Document classification and handling guidance. Exception records. Policy-aligned access controls. Evidence of regular review of restrictions. |
Minor gaps only. Remaining access limitations are justified and present limited risk. |
| 5 | Comprehensive and exemplar implementation of open-by-default principles. Knowledge sharing is embedded within architecture governance and delivery practices. |
Widely accessible architecture documentation. Well-governed classification processes. Clear exception management. Evidence of active reuse and knowledge sharing. Regular review of restricted content. Architecture information routinely used across teams and programmes. |
Minimal or no significant gaps. Documentation is highly discoverable, appropriately protected and actively supports collaboration and reuse. |
What assessors should look for
- Accessibility – Is architecture documentation broadly accessible to those who need it?
- Open-by-default behaviour – Is openness treated as the default publishing approach?
- Policy-based exceptions – Are restrictions based on recognised policy requirements rather than convenience or habit?
- Classification and handling – Is sensitive information identified and managed appropriately?
- Discoverability – Can stakeholders easily find relevant architecture documentation?
- Governance – Are restricted documents subject to review and oversight?
What separates a 3 from a 4 or 5
A score of 3 generally indicates that most documentation is shared appropriately and there is evidence of policy-based access decisions, but inconsistencies remain in publication practices, discoverability or exception management.
A score of 4 requires a consistent open-by-default approach, with documented and justified exceptions, clear governance and evidence that access controls are aligned with policy requirements.
A score of 5 requires openness and knowledge sharing to be embedded within architecture practices. Documentation is routinely discoverable, actively reused and restrictions are regularly reviewed to ensure they remain justified.
Updated: 04 September 2026 (SAF Version 1.1)