Governance
How clinical work is governed
Polarisk sells a clinician's signature at scale, so the governance around that signature is the product rather than a policy document behind it. This page sets out who may sign what, how registration is checked, where the legal boundaries sit, and which controls are evidenced rather than prevented.
The structure
Three parties, and the one people get wrong
Health surveillance involves three distinct legal roles. Getting the third one wrong is the most common and most consequential error in workplace health, because it is the one that turns a confidential clinical record into an employer's file.
Admission
Who may sign, and how that is checked
- A named register, recorded at admissionEvery clinician account is created against a specific register, GMC, NMC or HCPC, with the registration number stored on the record. The register and the number appear on the certificate and in the audit pack, so the claim is checkable by whoever reads it.
- Scope follows the registerNoise, vibration, respiratory and skin surveillance may lawfully be led by an occupational health nurse or other qualified OH professional. Programmes needing a doctor route to a doctor. Streams legally requiring an HSE Appointed Doctor are refused at the platform rather than downgraded.
- Clinicians set their own credentialsAn invited clinician accepts on their own link and sets their own password. Nobody else, including the inviting organisation and including us, ever holds it.
- Revocation bites immediatelyWithdrawing a clinician's access stops an already-issued session working, because the clinical gate checks live stored authority rather than the role claim inside the token. A revoked clinician cannot finish the case they had open.
- Attestation is recorded, and its absence is visibleWhere someone has attested to checking a clinician's registration against the public register, that attestation is on the record. Where nobody has, the account is flagged unverified and appears that way in the audit pack rather than looking identical to a checked one.
Stated, not hidden
The limit of the boundary
One control cannot be enforced in software while the employer onboards its own clinicians and distributes its own worker links, and we would rather you read it here than discover it later.
Whoever issues a credential holds it. An employer administrator who can invite a clinician can invite one it controls, and an employer that distributes worker links can use one. The role checks in the software are correct and they are not the point; the exposure is custody, not authorisation.
Because it cannot honestly be called prevented, it is made evidenced instead:
- Clinician provenanceEvery clinician account records who invited it, when, and whether anyone attested to checking the register. Self-onboarded and unattested accounts are marked.
- Answer provenanceEvery set of answers records the channel it arrived through and who issued the link, sealed into the signed record rather than reconstructed afterwards.
- An attestation routeA separate verification step lets an independent party confirm a clinician's registration, and the audit pack distinguishes verified from unverified.
In the loop
How a case actually moves
- Screening is deterministicResponses are scored against the published protocol for that programme. The same answers always produce the same triage, which is what makes the process auditable.
- Drafting never decidesA drafted assessment is a starting point for the clinician, and is labelled as one. No outcome is issued without a clinician actively signing it.
- Escalation is automatic, not discretionaryA positive screen routes onward by rule. This is the step that fails most often in manual programmes, where a concerning questionnaire is filed rather than escalated.
- Adverse findings raise the employer's duties tooWhere a finding triggers a review of controls for others doing the same work, or a possible RIDDOR report, that is surfaced with the outcome rather than left for the employer to know unprompted.
- The signature is bound to the recordThe signed outcome carries the clinician, their register, their number and the evidence trail behind the case. It is generated from the record rather than typed over it.
Standing rules
Rules we do not override
- No assessment is issued without a registered signatoryNot as a soft policy. No pilot closes and no price is quoted for clinical work until a named clinician on the relevant register has agreed to sign.
- Privacy and security work is never self-certifiedIndependent review is required. We know exactly how much this matters: two adversarial review passes on our own code each found a high-severity defect that a fully green test suite had approved.
- A test that cannot fail is treated as a defectOne of our own privacy regression tests was structurally incapable of failing and stayed green through 616 real violations. It was replaced with one that asks what an attacker could actually learn. We assert on what an attacker can do, never on the mechanism.
- Appointed-Doctor streams are refused, not adaptedAsbestos, lead, ionising radiation and compressed air require an HSE Appointed Doctor. We say so and point elsewhere.
Questions
Common questions
Can our HR team see why someone was found unfit?
No. Your organisation receives the fitness outcome and any recommended workplace adjustment. The clinical reasoning sits with the signing clinician, who holds it as an independent controller rather than as your processor, which means you cannot instruct its release. Every account that can open the clinical record is named on that record.
How do we know the clinician who signed is actually registered?
The certificate and the audit pack carry their register and registration number, which you can check against the public register yourself in under a minute. Where someone has attested to having done that check, the attestation is recorded. Where nobody has, the account shows as unverified rather than looking the same as a checked one.
What happens if a clinician's registration lapses mid-programme?
Their access is withdrawn, and withdrawal takes effect immediately rather than at the end of their session, because the clinical gate checks live stored authority rather than the claim inside an already-issued token. Records they have already signed remain valid as signed at the time, with the registration position as it stood recorded on them.
Is the AI making clinical decisions?
No. Screening is deterministic scoring against a published protocol, and any drafted assessment is explicitly a draft for a clinician to accept, change or reject. No outcome is issued without a clinician signing it. If a generative model is ever enabled it becomes a named sub-processor and clients are told before it is switched on.
For reviewers
Reviewing us for a DPO or an IT function?
The security page sets out the platform controls, the sub-processor position and the open items we do not yet close. Book a call if you need the underlying documentation.