GGO Systems

Chrysalis

Polaris, made entirely one team's own.

Chrysalis is a fully customised, white-label configuration of Polaris: the pathway app carries the clinical team's name and lettering, their approved documents, and nothing else. Behind it sits Cocoon, the operational shell, and an optional generator for authoring.

What the patient sees

Polaris, white-labelled

Every surgical pathway the team offers is an instance of one generic model: phases, steps, a standard track and an easy-read track on each. The team's identity is the only brand on the page; the suite's provenance appears once, in the footer.

Identity
The team's own name, mark, palette and lettering, applied through a brand kit, not a redesign.
Content
The current approved document for each procedure, reflected exactly; the guideline beats the leaflet when they disagree.
Readers
Anonymous by default. No account, no login, no tracker.
Hosting
UK regional configuration; migration to a licensee-controlled environment is a contractual right.

What the team sees

Cocoon

The operational control shell for the clinical team: what is published, against which source version, its readiness, and who signed for it. Cocoon makes no language-model calls and never will; it is a place to review, attest and release.

Identity
Clinicians and staff only, under their own names.
Readiness gate
A pathway cannot go live until every item shows its source, its version and its fidelity.
Sign-off
A warrant signed by a registered professional, attesting fidelity to an identified approved source.

Authoring · optional

Cocoon Advanced

An optional authoring toolchain that drafts pathway content from the team's approved documents with the help of a large-language model. It produces a candidate release with item-level provenance, and it can never publish: the candidate crosses into Cocoon only through the licensee's own importer, which recalculates every hash and writes its own receipt.

Where the model runs
In authoring only, outside the patient app and outside Cocoon.
Human review
Every candidate is reviewed and signed by the clinical team before it is released.
Detachable
A team that never wants it never installs it. Nothing in Polaris or Cocoon depends on it.

Beneath the line

Customisation reaches the surface. It never reaches these.

  • The patient app makes no large-language-model calls.
  • No patient accounts, logins or email capture.
  • No identity-graph or advertising trackers.
  • No clinical decision logic.
  • No frozen snapshots: the current approved document is the single source of truth.
  • No invented clinical figures; gaps are declared, not filled.

From candidate to signed release.

Chrysalis is the configuration where the governance chain is longest, because authoring can be assisted. Each link in the chain is recorded, and the chain fails closed.

Candidate provenance
A candidate release carries, for every item, its authorship, its supporting source and the authority it claims. The importer treats it as untrusted input.
Receipt
Only the licensee's importer can write the release receipt: release identifier, recalculated manifest SHA-256 and the validation that passed. Cocoon Advanced cannot self-assert it.
Reissue propagation
A reissued source document flags every item that reflected the old version for review, automatically.
Sign-off fails closed
Sign-off refuses a pathway with a missing authority, an absent or malformed receipt, or items assembled from different releases.
Fidelity, not approval
The signing professional attests that the rendering is faithful to the approved source; clinical approval stays with the document's own approvers and is cited.
Immutable archive
Each sign-off writes a named release with a SHA-256 digest into an archive that cannot be edited. The audit trail keeps every edit, author and timestamp.

One configuration. Yours would be another.

  • White-label Polaris with the team's own brand kit.
  • Cocoon for review, attestation and release.
  • Cocoon Advanced only if the team wants assisted authoring.