The Team Was the Infrastructure
How Wales built its COVID vaccination system.
In July 2020, with thousands already having died from COVID across the UK and a second wave expected before winter, the Welsh Government asked the seven health boards in Wales to start planning for the largest vaccination campaign Wales had ever attempted. What was known was the why: vaccination was our route out of the pandemic. What was not known was almost everything else: when the first vaccine would arrive, which would be approved, in what quantities, at what intervals, who would be prioritised, where vaccinations could be delivered, and how delivery would change as evidence, supply, and policy changed.
The broad requirement was to reach the population, prioritise correctly, schedule and accurately record immunisations in any setting, and use software flexible enough to absorb whatever changes the following week might bring.

Less than five months later, on 8 December 2020, the Welsh Immunisation System went live across the country as the first vaccines were administered. I was watching it being used and helping to troubleshoot in a leisure centre that had become the mass vaccination centre for Aneurin Bevan University Health Board. By May 2021, public data showed Wales among the leading countries in the world for first-dose coverage, ahead of many larger and wealthier nations. That achievement came from the vaccination programme as a whole.
The digital system helped programme delivery because people, relationships, judgement, and trust were already in place before the crisis arrived. The work was deeply technical, but it was also relational: within the software team, across Digital Health and Care Wales, and through the wider vaccination programme.
In the summer of 2020, a sub-group of the Welsh COVID vaccination board considered the options for getting software in place. The route judged to have the most chance of success was to use an existing team: Gill Davison and the colleagues she had been working with for over twenty years.
Gill was the product owner of CYPrIS, the Child and Young Person Information System, which underpinned the routine childhood immunisation programme in Wales. CYPrIS did the things any large-scale immunisation system has to do: identify cohorts, schedule appointments, record administration, and send recalls. Gill and her team had built it, run it, fixed it, and supported its users for years; they had been close to immunisation at scale long before COVID. Gill is by background a mathematician, with one of her first jobs at CERN, and brought the combination of technical, operational, and analytical judgement that the work required.
As the programme went on, the team built considerably more than had originally been scoped. Gill led well, and she knew the people in her team well.
There were two Gills in this story, within a much wider programme.
Gill Richardson, Deputy Chief Medical Officer for Vaccines and Senior Responsible Owner for the Wales COVID-19 vaccination programme, asked me to get involved in the digital side of the work. She was a great leader to work with: serious about our responsibility, clear about the programme’s direction, and careful not to micromanage the operational or technical detail.
Gill Davison led the software team. I worked alongside her, bringing a clinical and primary-care perspective into the digital work.
The gap we needed to keep as narrow as possible lay between the digital team and the people doing the vaccination work across Wales: the vaccination teams in the seven health boards, the people managing stock and pharmacy supply, and the Public Health Wales teams tracking cohorts, eligibility, and uptake. All of this sat within the direction and governance of the Welsh Government.
The work was developed through a mixture of formal programme structures and much less formal contact with the people using and supporting the system. There were operational meetings and tabletop exercises with the seven health boards. Gill and I often sat in on these together, with her deftly anticipating what the needs would be and checking carefully that what was being built would be compatible with what service teams were planning.
To be honest, the whole thing was built without a list of requirements coming from the business. They couldn’t provide one because the operational reality was shifting too fast. Instead, Gill formulated the requirements herself, drawing them directly from her interactions with the people who would do the work, and bringing them straight into the formal programme structures.
What I recognised in the way Gill worked was familiar to me as a GP. She was not simply responding to an upfront specification. In the language of organisational complexity, she was treating software discovery not as a complicated analysis of known facts, but as complex, emergent work. She was using continuity, pattern recognition, and deep domain knowledge to notice and formalise what would matter as a requirement before the business had even recognised it. Good general practice can work like that: the clinician hears something small and understands its significance because they know the patient, the context, and the history. Gill was doing something similar in a technical and operational domain.
I remember one day when Gill said she was wondering whether SMS appointment reminders might be useful. I suggested looking at GOV.UK Notify. The next day, she came back saying it would be an easy integration. A few days later, she had confirmed that Notify also provided a letter service. She proposed to the health boards that the entire back-end of communicating appointment information to citizens could be administered by her team. No one had previously considered that this might be a deliverable. The offer was taken up.
There were also many one-to-one conversations with vaccination teams, pharmacy and stock colleagues, Public Health Wales teams, business-change staff, service-desk colleagues, and GP practice users. I went out on site to see the software in use and brought back requirements based on what people were actually doing.
This narrowed the distance between the business and the IT: the people making software stayed close to the people making vaccination happen, and the work was funded as work to be done rather than as a project to be procured.
Tom Loosemore, who worked alongside Mike Bracken in the early days of the Government Digital Service, has condensed this point into four words on how public-sector digital should be paid for: fund teams, not projects. The contrast is between paying a stable team to do whatever the work requires as it evolves, and writing a project specification, procuring against it, and accepting that what you bought begins to go out of date the moment requirements move. Stable teams can absorb change. Project deliverables cannot. The principle is widely cited in public-sector digital, but is not always followed. In Wales in 2020, it was followed.
From a user’s point of view, the system was a web-based application that anyone with a managed device or Microsoft 365 authentication could log into to record a vaccination, anywhere. Behind that, the team had built a scheduling engine, a recall service, stock tracking, payment flows, and dashboards.
To vaccinate a country, the system had to do four things reliably: identify the right people, invite them at scale, record what happened wherever it happened, and give the programme enough visibility to manage stock, sites, cohorts, and uptake.
The first task was to identify.
The information teams identified cohorts centrally, drawing on national data and the prioritisation rules as they changed. This was not a static list. Priority groups changed. Eligibility changed. Dose intervals changed. The programme needed a system that could absorb central cohort identification and make it operational across seven health boards.
The second task was to invite.
The scheduling engine generated appointments by the thousand. You set up your clinic sessions, you had your cohort, you pressed a button, and the system populated the sessions. Invitations went out through GOV.UK Notify, the cross-government messaging platform built by GDS, in two forms: letters and SMS. By the time the programme was at scale, programme data showed millions of letters and many millions more text reminders had been sent.
The letters mattered as much as the SMS, particularly at the start. A letter on the doormat with the NHS logo was reassuring in a way that a text from an unknown number was not, especially during a period when scam messages were proliferating.
The third task was to record.
Most early vaccinations in Wales were given in mass vaccination centres, often repurposed leisure centres and stadiums. Other vaccinations took place in general practice, community pharmacy, care homes, and other settings. All needed to be recorded in the same system.

One cluster of GP practices in Cardiff decided to run a drive-in clinic in the car park behind Cardiff City Football Stadium. On the morning I visited, the temperature was just above freezing. People were coming up in their cars. The team was recording vaccinations on laptops over the same web application used in the mass centres. The system had been built to work in every setting.
The fourth task was to manage.
Behind the front end, dashboards gave the programme near real-time visibility. Vaccine stock was tracked at every site. My recollection from programme reporting is that Wales moved the vaccine from arrival in the country to administration much faster than the UK average, with wastage kept extremely low, including on short-dated stock. Vaccination is a clinical act, a logistical operation, a public-confidence exercise, a workforce challenge, and a records problem, all moving at the same time. The software could not deliver all of those aspects, but it could support or frustrate them.
When general practice was brought on board in January 2021, I recognised that practices were likely to be frustrated at being asked to use WIS rather than their familiar GP IT systems. Building payment claims directly into the software removed a layer of administrative burden. We even built searches to show practices the claims they had probably not yet made.
Mike Bracken founded the Government Digital Service in 2011 and articulated a sequence that broke with how the public sector had traditionally built digital services. Under the old approach, policy came first: a specification was written, a procurement was run, an external system was installed, and the people who would have to use it were introduced to it last. Bracken’s sequence reversed that order: start with the user need, then assess what is technically possible, and then sort out the policy at the end. The payment flow followed that sequence. The user need was easy claiming. The technical assessment was that we could build it that way. The policy work, including enabling legislation, moved quickly enough to allow it.
That part of the system was built for professionals trusted to behave like professionals, with audit trails as the backstop and flexibility to correct errors.
Over one weekend, one of our business-change team and I recorded short demos for GP practices: a video for receptionists, a video for vaccinators, and a video for record viewing. There was a known irritation in the workflow: a vaccinator had to select themselves from a list every time they recorded a vaccination. That would slow things down once GP practices were delivering at volume. I had recorded a workaround.
Just as I was about to upload the video, Gill messaged to say the team had fixed the problem in the release going live that night. You could now default a vaccinator per session. I added a note to the video before practices picked it up the next morning. From spotting an issue to recording its workaround to having it fixed in the live system to documenting the fix took less than a day.
Alongside all of this sat a Facebook group I had set up when I first joined Digital Health and Care Wales as a low-friction channel for GP IT users. It had 100 members at the start of COVID and rapidly grew. That was where I posted demos, fielded queries, and heard the truth.
I had led the primary care response to COVID for our organisation in the first part of the pandemic. Through that work, our users had come to trust the organisation as honest, competent, and reliable. That mattered when WIS was implemented. There were ups and downs, and we did stumble at times. The existing relationships helped me and the team recover.
Our national data architecture was solid. Because we retained control of the data, we could run queries to show individual practices exactly which patients in their cohorts still needed to be scheduled. But scaling the workflow was where we hit the fragmentation of the system. While WIS successfully managed the scheduling and backend for the seven large health boards, we didn’t manage to build localised scheduling for the 400 individual GP practices across Wales. Consequently, practices had to schedule vaccinations using their own booking systems, creating an immediate need for their local records to be updated.
To bridge this, we produced data feeds to push this information out to external systems. How our partners handled those feeds made all the difference. The NHS COVID Pass integration went smoothly because that team was aligned and ready to consume our data feed. By contrast, one of our primary care system suppliers told us in February 2021 that the integration to ingest our data feed into their system would be ready in three weeks; it didn’t go live until August. The data was ready, but because our external supplier couldn’t give the work the priority we needed, the lack of timely integration became a heavy administrative burden for the 400 practices on the frontline: a stark reminder that public infrastructure remains vulnerable to the priorities of external commercial partners.
The decision to build with an existing team was driven by coordination cost, domain knowledge, and trust. Wales could keep the work in-house because Gill Davison’s team was already there, trusted, and close to the work.
The WIS team had responsibility for developing and adapting the digital product while staying close to the users and operational teams whose work the product had to support. It could draw on shared infrastructure and expertise around it: GOV.UK Notify, cohort identification, business change, the service desk, pharmacy and stock processes, and programme governance. In Matthew Skelton and Manuel Pais’s language, this was close to a stream-aligned team supported by platform services: a team organised around an outcome, drawing on shared capabilities rather than rebuilding everything itself.
In October 2021, Grant Davies, Head of Planning and Performance for the Aneurin Bevan Mass Vaccination Programme, described WIS to the DHCW Board as “a complete game changer” and “critical to the success” of the Welsh mass vaccination programme. He spoke not only about the product but also about how it adapted and evolved in response to user needs and feedback through many in-flight changes, as the vaccination programme moved through initial doses, second doses, boosters, and third doses.
Some work is hard because it is technically demanding, logistically difficult, or large in scale. Expert teams can analyse it, break it down, and determine what good delivery looks like. Other work is harder because the nature of the problem is uncertain; understanding the problem is itself part of the work. The first kind of work is complicated; the second is complex. While the final software engine the team built was a structured, technically complicated system, the process of discovering what to build was fundamentally complex. Recognising what kind of problem you are dealing with is itself the work. The WIS team succeeded because they had the relational capability to navigate the complex human environment of a crisis and translate it into a stable, functioning service.
Public systems need durable internal capability, close to the work, before the crisis arrives: teams that understand the domain, know their users, own the consequences of what they build, and are trusted to deliver.
Wales built its vaccination system on years of accumulated capability. The campaign succeeded because many parts of the system worked together. The software team’s contribution was one of the conditions that made the wider story possible.
The team was infrastructure: technical, operational, and relational.
This essay was in part based on a talk that Gene Kim invited me to give at DevOpsEurope22. You can watch the start of that here or click through the link to sign up for free and see the whole thing.
Also grateful to Leighton Andrews for inviting me to speak about this innovation to his students at Cardiff Business School.
