Chrysalis
Polaris, made entirely one team's own.
Chrysalis is a fully customised, white-label configuration of Polaris: the pathway app carries the clinical team's name and lettering, their approved documents, and nothing else. Behind it sits Cocoon, the operational shell, and an optional generator for authoring.
What the patient sees
Polaris, white-labelled
Every surgical pathway the team offers is an instance of one generic model: phases, steps, a standard track and an easy-read track on each. The team's identity is the only brand on the page; the suite's provenance appears once, in the footer.
- Identity
- The team's own name, mark, palette and lettering, applied through a brand kit, not a redesign.
- Content
- The current approved document for each procedure, reflected exactly; the guideline beats the leaflet when they disagree.
- Readers
- Anonymous by default. No account, no login, no tracker.
- Hosting
- UK regional configuration; migration to a licensee-controlled environment is a contractual right.
What the team sees
Cocoon
The operational control shell for the clinical team: what is published, against which source version, its readiness, and who signed for it. Cocoon makes no language-model calls and never will; it is a place to review, attest and release.
- Identity
- Clinicians and staff only, under their own names.
- Readiness gate
- A pathway cannot go live until every item shows its source, its version and its fidelity.
- Sign-off
- A warrant signed by a registered professional, attesting fidelity to an identified approved source.
Authoring · optional
Cocoon Advanced
An optional authoring toolchain that drafts pathway content from the team's approved documents with the help of a large-language model. It produces a candidate release with item-level provenance, and it can never publish: the candidate crosses into Cocoon only through the licensee's own importer, which recalculates every hash and writes its own receipt.
- Where the model runs
- In authoring only, outside the patient app and outside Cocoon.
- Human review
- Every candidate is reviewed and signed by the clinical team before it is released.
- Detachable
- A team that never wants it never installs it. Nothing in Polaris or Cocoon depends on it.
Beneath the line
Customisation reaches the surface. It never reaches these.
- The patient app makes no large-language-model calls.
- No patient accounts, logins or email capture.
- No identity-graph or advertising trackers.
- No clinical decision logic.
- No frozen snapshots: the current approved document is the single source of truth.
- No invented clinical figures; gaps are declared, not filled.
From candidate to signed release.
Chrysalis is the configuration where the governance chain is longest, because authoring can be assisted. Each link in the chain is recorded, and the chain fails closed.
- Candidate provenance
- A candidate release carries, for every item, its authorship, its supporting source and the authority it claims. The importer treats it as untrusted input.
- Receipt
- Only the licensee's importer can write the release receipt: release identifier, recalculated manifest SHA-256 and the validation that passed. Cocoon Advanced cannot self-assert it.
- Reissue propagation
- A reissued source document flags every item that reflected the old version for review, automatically.
- Sign-off fails closed
- Sign-off refuses a pathway with a missing authority, an absent or malformed receipt, or items assembled from different releases.
- Fidelity, not approval
- The signing professional attests that the rendering is faithful to the approved source; clinical approval stays with the document's own approvers and is cited.
- Immutable archive
- Each sign-off writes a named release with a SHA-256 digest into an archive that cannot be edited. The audit trail keeps every edit, author and timestamp.
One configuration. Yours would be another.
- White-label Polaris with the team's own brand kit.
- Cocoon for review, attestation and release.
- Cocoon Advanced only if the team wants assisted authoring.