9 The Literature III: Platform and Ecosystem Landscapes
Validation happens inside something. This chapter surveys the somethings: the commercial validated platforms, the open-source component ecosystems, and the practitioner reports that fill the space between them.
9.1 The incumbent tier
The default answer to “where should regulated analysis run” remains the commercial validated platform — historically SAS’s Life Science Analytics Framework in many large organizations, and, on the R side, Posit’s enterprise stack of Workbench, Package Manager, and Connect. The product in this tier is not primarily software; it is the vendor’s accountability: their validation package, their audit responses, their support channel. That is what the subscription buys, and it explains both the tier’s durability and its price.
The honest limitation is structural: a closed platform is a single negotiation. If its roadmap, pricing, or hosting model diverges from your needs, your options are migration or accommodation. For large organizations the trade is often right. For small ones, it is a subscription sized for someone else’s problems.
9.2 The open component tier
At the other pole sit the ecosystems this book has already cited. The pharmaverse network curates roughly fifty packages spanning the chain — admiral for ADaM derivations, metacore and metatools for metadata-driven development, rtables, tern, rlistings, Tplyr, and tfrmt for tables, teal, siera, and autoslider for interactive review, cards and cardx for analysis-results data, logrx, covtracer, and the riskmetric family for validation-adjacent needs, pharmaverseadam and pharmaversesdtm for synthetic data, pkglite and xportr for submission packaging, and whirl for pipeline execution with log validation. The Insights Engineering NEST family contributes the rtables/tern/rlistings/teal/formatters stack, the scda synthetic-data package, and — importantly for later chapters — the TLG Catalog as a product in its own right.
Two facts about this tier matter more than any feature list. First, its own governance is candid: the pharmaverse FAQ’s plain “No” to GxP assurance (Chapter 5). Second, its timeline: the NEST project’s public history runs from a 2017 proof of concept through 2020’s internal validation for a regulatory computing environment to supporting the first R-based FDA submission in 2022 — a reminder that even the best-funded open stack took half a decade from idea to regulated use, with the surrounding factory never open-sourced.
9.3 The practitioner tier
Between the poles, a thin but growing literature of practitioner reports documents what small organizations actually build. The most detailed recent example this book draws on (and contributes to) is a PHUSE report on replacing a vendor-hosted single Shiny server with a composed Docker platform: twenty-one services on one host — fourteen Shiny review applications, an R API, five Python services, one reverse proxy — with one encrypted entry point, a shared authentication module verifying the partner’s signed tokens locally, all data access through one API, pipeline-only deployment with a thirteen-point health check and one-command rollback, and one-page decision records for every significant choice. The paper is explicit about its boundary — internal exploratory review, not a validated system — and distills compose-vs-buy rules that this book will generalize in Part IV.
9.4 The empty cell
Lay the three tiers on a grid of capability against accountability: the incumbent has accountability without composability; the ecosystem has composability without accountability; the practitioner reports show the composition working but stopping self-consciously at the GxP line. Nobody occupies the fourth cell — a composed system that generates its own accountability, open-source parts wrapped in a trust layer that ships evidence with every output. That empty cell is the thesis of this book, stated as a market observation.
The test. When a vendor or ecosystem pitch reaches you, place it on that grid in one sentence: “Who is accountable when this fails, and what do they hand me as proof?” Answers that require a sales call to interpret belong to the first two tiers. The fourth cell answers in artifacts, before you ask.