A balanced briefing on the third-iteration pilot implementation, its current security and privacy controls, possible AMA-owned hosting models, and indicative development costs.
This note is intended to support an informed discussion with AMA Victoria. It does not ask AMA to approve a particular supplier, cloud provider or final architecture. It separates what the pilot already demonstrates from the governance and assurance decisions that remain outstanding.
At this stage, the immediate decision is whether AMA Victoria is willing to progress a controlled three-month pilot, subject to its normal review process and confirmation of an AMA-owned production environment.
The implementation contains a working public collection and administration model. It is designed to collect de-identified experiences about AHPRA regulatory processes, identify recurring themes and support evidence-based advocacy. It is not intended to determine the merits of an individual regulatory matter.
| Area | Current position |
|---|---|
| Organisational approval | To confirm AMA’s digital-project review and approval pathway is pending COO discussion. |
| Production ownership | To confirm The production account, domain, database and recovery access should be AMA-controlled. |
| Identity management | Pilot limitation Named individual accounts, MFA and fuller role separation remain required for broader use. |
| Recovery assurance | To complete Backup settings, recovery window and a non-production restore exercise must be documented. |
| Independent review | To arrange The supplied verification matrix should be run against the deployed environment, followed by a focused independent review. |
| Question | Response received | Practical interpretation |
|---|---|---|
| Digital-project approval | COO to be consulted on return from leave in September. | Do not treat the current technical build as organisational approval. |
| Where data is hosted | “Microsoft 365 environment”. | Clarify whether this means Microsoft 365 only, a mandatory Azure hosting/data-location requirement, or an Australian database requirement. |
| External managed hosting | AMA would prefer to own the hosting environment. | Cloudflare may be acceptable if the Cloudflare environment is owned and controlled by AMA; an AMA-owned Australian database is also a possible separate component. |
| AMA subdomain | Yes to an AMA-hosted environment. | AMA should control the domain/DNS and approve the final routing arrangement. |
| Administration and backup | Backup and limited administrator access are definitely required. | These become pilot go-live conditions, not optional enhancements. |
amavic.com.au delegated to Cloudflare nameservers and its public web response served through Cloudflare. The response also included cookies consistent with an Azure App Service origin. This makes an AMA-owned Cloudflare deployment path credible and may reduce setup effort, but it does not prove the existing Cloudflare account, origin, database, backups or logs are owned by AMA or suitable for this Monitor. Those matters require AMA confirmation.
AMA creates or controls the Cloudflare account and the amavic.com.au zone. The Worker, domain route, secrets, Turnstile, access controls and recovery arrangements sit inside that AMA-controlled environment.
Database choice: retain D1 for the lowest-disruption pilot path, or connect the Worker through Hyperdrive to an AMA-owned PostgreSQL/MySQL database in an Australian cloud region if country-specific database control is required. Hyperdrive is a separate database migration, not a D1 location setting.
Conditions: AMA account ownership, named administrators with MFA, documented recovery, WAF/rate limiting, and recorded decisions on D1 or external-database location, logs, backups and access.
The application is adapted to an Azure-hosted HTTP runtime, with an AMA-managed database and Microsoft identity/access controls where appropriate.
Advantages: closer alignment with existing Microsoft governance and potentially easier integration with AMA’s internal IT arrangements.
Trade-off: the Worker entry point, D1 database access, schema, secrets, rate limiting, backups and deployment process require migration and re-testing.
The production environment should not depend on a developer’s personal Cloudflare account, personal domain, personal email account or unmanaged backup. AMA should own the accounts, billing, DNS, secrets, database, backups and administrator recovery path. A developer may be granted limited implementation access, but should not be the sole person able to operate or recover the service.
The figures below are indicative Australian replacement costs for a project of this character. They are not a quote and exclude GST unless stated otherwise. They reflect the application, security controls, documentation, testing and handover—not merely the number of lines of code.
| Engagement | Indicative cost | What it normally includes |
|---|---|---|
| Prototype/basic functional version | $10k–$20k | Core pages, forms, database and basic administration, with limited operational hardening. |
| Senior independent developer | $20k–$45k | Current functional scope, security controls, documentation, testing and a practical handover. |
| Small specialist agency | $35k–$70k | Delivery management, implementation, QA, documentation and a more formal handover process. |
| Production hardening and independent review | +$10k–$25k | Named access, backup/recovery testing, deployment verification, security review and remediation. |
| Azure migration, if required | +$15k–$35k | HTTP-runtime adaptation, D1-to-managed-database migration, Azure configuration, data testing and re-verification. |
| Ongoing support | $4k–$12k/yr | Small support/maintenance allowance; actual cloud, domain, email and review costs are separate. |
AI has reduced the time needed for first drafts, boilerplate, documentation, test scaffolding and exploring alternative implementations. It has not removed the need for professional judgement or accountability.
For a project like this, AI may reduce raw coding time materially, but the overall professional cost is usually reduced less because testing, governance, deployment and assurance remain. A planning assumption of roughly 10–25% lower total delivery cost is more defensible than assuming a 50–80% reduction. This is an estimate, not a measured result for this project.
AI-assisted development is now normal in the market. Rates have not simply collapsed: specialist cloud, security, governance and integration skills remain valuable. Buyers increasingly seek milestone-based delivery, source-code ownership, documented handover, security testing and a clear support boundary.
The following questions can be taken to the COO or the relevant AMA technology/governance contact. They are intentionally practical and can be answered without committing AMA to an architecture prematurely.
| Stage | Outcome |
|---|---|
| 1. Organisational clarification | COO/AMA confirms approval pathway, ownership model, data requirements, administrator limits, backup expectations and retention. |
| 2. Hosting decision | Choose an AMA-controlled Cloudflare route with D1 or an AMA-owned Australian database, or approve an Azure migration if Microsoft hosting is required. |
| 3. Controlled deployment | Deploy into AMA-owned accounts; configure secrets, Turnstile, domain/DNS, access controls, WAF and backups. |
| 4. Validation | Run the security verification matrix, browser end-to-end checks, restore exercise and focused independent review. |
| 5. Pilot approval | Record residual risks, retention and incident contacts; open the three-month pilot with a defined review point. |
The current implementation is credible as a pilot. It demonstrates meaningful functionality and a stronger privacy/security baseline than a simple form or proof of concept.
It is not yet an AMA-approved production service. That status depends on organisational ownership, hosting confirmation, named access, backups, retention, deployed testing and assurance.
The lowest-risk commercial path is to avoid unnecessary rewriting. Public DNS evidence supports exploring an AMA-controlled Cloudflare route, but AMA must confirm ownership and governance. An external AMA-owned Australian database is possible if required; an Azure migration should be a deliberate governance decision, not an automatic response to Cloudflare use.
The technical description is based on the current third-iteration Worker, D1 schema, deployment guide, pilot operations procedure and security verification matrix. Public-domain infrastructure observations were checked on 23 August 2026 using DNS delegation and HTTPS response headers. Hosting/privacy context: Cloudflare D1 data location, Hyperdrive architecture and the OAIC’s personal information guidance. Market context was checked against: Hays, FY25/26 IT Contractor Rates Guide; Stack Overflow, 2025 Developer Survey — AI; and METR, Measuring the Impact of Early-2025 AI on Experienced Open-Source Developer Productivity.
This briefing is an implementation and planning summary, not legal advice, a privacy impact assessment, a penetration-test report or a formal assurance statement.