
Agile Delivery of a Regulated Digital Therapeutic App
Let's Connect
Overview
What we built
A digital therapeutics company was shipping one validated release every nine months while competitors shipped monthly. We rebuilt its delivery around agile release trains that live inside its design controls and end audit-ready every six weeks.
In plain terms: the company makes a prescription app that treats behavioural-health conditions, so every change must be documented and validated the way a medical product demands. Its quality system assumed big, infrequent releases, which meant even small patient-experience fixes dragged a full manual paperwork and validation pass behind them. Improvements queued for months, engineers spent more time producing documentation than product, and rivals were shipping monthly while the company managed one release every nine months.
We did not ask the company to loosen its controls; we rebuilt delivery to run inside them. Requirements, risk items and test cases were linked in one traceability system, the build pipeline was rewired to generate validation evidence automatically, and documentation templates were mapped to sprint outputs, so each six-week release train ends audit-ready by construction. Release cadence improved from one validated release every 9 months to six-week validated release trains, and 47 patient-experience improvements shipped in the first year, up from 6 the year before.
The Problem
Nine-month regulated release cycles
The nine-month cycle was not a process preference, it was baked into the quality management system. The QMS assumed big-bang releases, so every change, however small, pulled a full manual documentation and validation pass behind it. There was no light path for a copy fix and no heavier path for a clinical change: everything paid the same toll.
The people costs compounded. Patient-experience fixes queued for months while the current release ground through validation, engineers spent more time on paperwork than on the product, and the roadmap became a story of what would not ship this cycle. In a category where competitors were shipping monthly, a nine-month cadence was a strategic problem wearing compliance clothing.
Full regression validation alone consumed 3 weeks of manual testing per release, and the documentation regulators reasonably require was assembled by hand at the end of each cycle rather than produced as the work happened. The result was a team that dreaded releases, because every one meant weeks of retrospective evidence-gathering.
Big-bang quality system
The quality management system assumed large, infrequent releases, so even a trivial change triggered the full manual documentation and validation pass designed for major ones.
Queued patient fixes
Patient-experience improvements waited months for the next release window, leaving known irritations live in a prescription app for the whole queue's duration.
Paperwork over product
Engineers spent more time assembling documentation and validation evidence by hand than building the therapeutic features the roadmap promised, and the imbalance grew with every release.
Manual regression burden
Every release closed with 3 weeks of manual regression testing, a fixed toll that made frequent releases arithmetically impossible under the old model.
What it was costing them
One validated release every nine months meant only a handful of chances a year to improve a prescription product patients used daily, while competitors iterated monthly. Engineering capacity drained into hand-built documentation, patient-experience fixes aged in a queue, and each release carried the accumulated risk of everything bundled into it, exactly the fragility big-bang releasing is supposed to avoid.
The Solution
Agile inside design controls
The founding decision was to treat the design controls as a constraint to build within, not an obstacle to argue with. We restructured delivery into agile release trains that live inside the company's quality framework, so compliance and cadence stopped being opposites. Each train runs six weeks and is expected to end audit-ready, not to become audit-ready afterwards.
Traceability became infrastructure. Requirements, risk items and test cases were linked in a single traceability system, so the chain from a requirement to its risk assessment to its passing test exists continuously instead of being reconstructed at release time. The CI pipeline was rebuilt to generate validation evidence automatically on every build, turning what had been a manual end-of-cycle effort into a byproduct of normal engineering.
Documentation templates were mapped to sprint outputs, so the artefacts the quality system requires are produced as the work happens, already in the shape auditors expect. The overnight automated regression suite replaced 3 weeks of manual testing, removing the last structural blocker to a six-week cadence and giving every train the same exit bar.
Key decisions
Agile inside design controls
Release trains were designed to satisfy the existing quality framework rather than bypass it, so regulatory confidence survived the change in cadence.
One traceability spine
Requirements, risk items and test cases live linked in a single system, making the compliance chain continuous instead of reassembled for each release.
Evidence generated, not assembled
The rebuilt CI pipeline produces validation evidence automatically on every build, so proof of quality accumulates continuously rather than being compiled at the end.
Templates mapped to sprints
Documentation templates were aligned to sprint outputs, so completing the work and completing the paperwork became the same activity rather than two competing ones.
Automate the regression toll
Full regression validation moved from 3 weeks of manual testing to an overnight automated suite, removing the fixed cost that had made frequent releases impossible.
Measurable Impact
What changed after launch
Release cadence improved from one validated release every 9 months to six-week validated release trains, and the product felt the difference immediately: 47 patient-experience improvements shipped in the first year, up from 6 the year before. Fixes that would once have queued for months now ride the next train to patients.
The compliance burden fell as the cadence rose. Per-release documentation effort was cut by roughly 60% through automated requirements-to-test traceability, and full regression validation dropped from 3 weeks of manual testing to an overnight automated suite. Engineers now spend their time on the therapeutic product, and audits start from evidence that already exists.
Release cadence
One validated release every 9 months
Validated release trains every six weeks
Patient improvements
6 patient-experience improvements shipped in a year
47 shipped in the first year on the new cadence
Documentation effort
Full manual pass assembled at each release
Cut by roughly 60% via automated traceability
Regression validation
3 weeks of manual testing per release
An overnight automated suite on every train
Headline results
Release cadence improved from one validated release every 9 months to six-week validated release trains
47 patient-experience improvements shipped in the first year, up from 6 the year before
Per-release documentation effort cut by roughly 60% through automated requirements-to-test traceability
Full regression validation reduced from 3 weeks of manual testing to an overnight automated suite
Tech & Tools Used
What powered the build
Every tool below earned its place in this engagement. Here is the part each one played.
Jira
Ran the six-week release trains, with sprint outputs structured so that closing work in the board also produced the delivery records the documentation templates expect.
Jama Connect
The single traceability system linking requirements, risk items and test cases, keeping the compliance chain continuous from stated intent through to passing evidence.
GitHub Actions
The rebuilt CI pipeline, generating validation evidence automatically on every build and packaging it for each release train's audit-ready close.
React Native
The framework behind the prescription behavioural-health app itself, letting patient-experience improvements reach patients from a single codebase on every train.
Node.js
Powered the backend services supporting the therapeutic app, updated inside the same release trains and covered by the same automatically generated evidence.
PostgreSQL
Stored the app's clinical and operational data, with schema changes flowing through the traceability system like any other risk-assessed change.
Cypress
Ran the automated regression suite that replaced weeks of manual testing, executing overnight so every train enters validation already exercised end to end.
SonarQube
Enforced code-quality gates inside the pipeline, adding static analysis results to the evidence pack each build generates for the quality team.
AWS ECS
Hosted the backend services and kept deployments repeatable, so each six-week train releases to production through the same validated, containerised path.
Ready to Build your Digital Therapeutics & Life Sciences Business with Agile Product Development
Ask Byte
Ask Byte
Typically replies instantly
just Now
Hi! I'm OrganByte's assistant. How can I help you today?
AI-generated content may be incorrect

