Polarisk

Governance

How clinical work is governed

Polarisk sells a clinician's signature at scale, so the governance around that signature is the product rather than a policy document behind it. This page sets out who may sign what, how registration is checked, where the legal boundaries sit, and which controls are evidenced rather than prevented.

Controller, processor and independent controller Three parties. The employer is the controller and decides that surveillance happens. Polarisk is the processor and acts only on documented instruction. The signing clinician is an independent controller for the clinical record. The fitness outcome passes from the clinician to the employer. The clinical detail does not, and cannot be instructed. CONTROLLER The employer Decides scope and acts on outcomes PROCESSOR Polarisk Acts only on documented instruction INDEPENDENT CONTROLLER The signing clinician Holds the clinical record FITNESS OUTCOME Fit, fit with adjustments, or not fit, plus any adjustment CLINICAL DETAIL Answers, symptoms and reasoning. Not disclosed, and not the employer's to instruct.
Fig. 1 The three legal roles, and the boundary that matters. The employer receives a fitness outcome. The clinical record sits with the signing clinician as an independent controller, so it is not the employer's to request.

The structure

Three parties, and the one people get wrong

Health surveillance involves three distinct legal roles. Getting the third one wrong is the most common and most consequential error in workplace health, because it is the one that turns a confidential clinical record into an employer's file.

Why the third row matters. Because the clinician is an independent controller rather than the employer's processor, the employer cannot instruct disclosure of the clinical detail behind an outcome. The platform is built so it cannot be made to try. That is a structural property, not a setting.

Admission

Who may sign, and how that is checked

  • A named register, recorded at admissionEvery clinician account is created against a specific register, GMC, NMC or HCPC, with the registration number stored on the record. The register and the number appear on the certificate and in the audit pack, so the claim is checkable by whoever reads it.
  • Scope follows the registerNoise, vibration, respiratory and skin surveillance may lawfully be led by an occupational health nurse or other qualified OH professional. Programmes needing a doctor route to a doctor. Streams legally requiring an HSE Appointed Doctor are refused at the platform rather than downgraded.
  • Clinicians set their own credentialsAn invited clinician accepts on their own link and sets their own password. Nobody else, including the inviting organisation and including us, ever holds it.
  • Revocation bites immediatelyWithdrawing a clinician's access stops an already-issued session working, because the clinical gate checks live stored authority rather than the role claim inside the token. A revoked clinician cannot finish the case they had open.
  • Attestation is recorded, and its absence is visibleWhere someone has attested to checking a clinician's registration against the public register, that attestation is on the record. Where nobody has, the account is flagged unverified and appears that way in the audit pack rather than looking identical to a checked one.

Stated, not hidden

The limit of the boundary

One control cannot be enforced in software while the employer onboards its own clinicians and distributes its own worker links, and we would rather you read it here than discover it later.

Whoever issues a credential holds it. An employer administrator who can invite a clinician can invite one it controls, and an employer that distributes worker links can use one. The role checks in the software are correct and they are not the point; the exposure is custody, not authorisation.

Because it cannot honestly be called prevented, it is made evidenced instead:

  • Clinician provenanceEvery clinician account records who invited it, when, and whether anyone attested to checking the register. Self-onboarded and unattested accounts are marked.
  • Answer provenanceEvery set of answers records the channel it arrived through and who issued the link, sealed into the signed record rather than reconstructed afterwards.
  • An attestation routeA separate verification step lets an independent party confirm a clinician's registration, and the audit pack distinguishes verified from unverified.
The structural fix, and when it lands. Clinician credentials issued by Polarisk rather than by the employer, and worker links delivered directly to workers, remove the custody problem entirely. Both need a messaging channel that does not exist yet, and both are on the list before any pilot at scale. Until then the position is evidence, and we describe it as evidence.

In the loop

How a case actually moves

  • Screening is deterministicResponses are scored against the published protocol for that programme. The same answers always produce the same triage, which is what makes the process auditable.
  • Drafting never decidesA drafted assessment is a starting point for the clinician, and is labelled as one. No outcome is issued without a clinician actively signing it.
  • Escalation is automatic, not discretionaryA positive screen routes onward by rule. This is the step that fails most often in manual programmes, where a concerning questionnaire is filed rather than escalated.
  • Adverse findings raise the employer's duties tooWhere a finding triggers a review of controls for others doing the same work, or a possible RIDDOR report, that is surfaced with the outcome rather than left for the employer to know unprompted.
  • The signature is bound to the recordThe signed outcome carries the clinician, their register, their number and the evidence trail behind the case. It is generated from the record rather than typed over it.
The Polarisk clinician workspace, showing the queue of cases awaiting clinical review and sign-off.
Fig. 5 The clinician's queue. Cases are triaged against the programme protocol and drafted for review; nothing is issued until a registered clinician signs it under their own name and registration number. Demo organisation and generated data.

Standing rules

Rules we do not override

  • No assessment is issued without a registered signatoryNot as a soft policy. No pilot closes and no price is quoted for clinical work until a named clinician on the relevant register has agreed to sign.
  • Privacy and security work is never self-certifiedIndependent review is required. We know exactly how much this matters: two adversarial review passes on our own code each found a high-severity defect that a fully green test suite had approved.
  • A test that cannot fail is treated as a defectOne of our own privacy regression tests was structurally incapable of failing and stayed green through 616 real violations. It was replaced with one that asks what an attacker could actually learn. We assert on what an attacker can do, never on the mechanism.
  • Appointed-Doctor streams are refused, not adaptedAsbestos, lead, ionising radiation and compressed air require an HSE Appointed Doctor. We say so and point elsewhere.

The security and data protection position →

Questions

Common questions

Can our HR team see why someone was found unfit?

No. Your organisation receives the fitness outcome and any recommended workplace adjustment. The clinical reasoning sits with the signing clinician, who holds it as an independent controller rather than as your processor, which means you cannot instruct its release. Every account that can open the clinical record is named on that record.

How do we know the clinician who signed is actually registered?

The certificate and the audit pack carry their register and registration number, which you can check against the public register yourself in under a minute. Where someone has attested to having done that check, the attestation is recorded. Where nobody has, the account shows as unverified rather than looking the same as a checked one.

What happens if a clinician's registration lapses mid-programme?

Their access is withdrawn, and withdrawal takes effect immediately rather than at the end of their session, because the clinical gate checks live stored authority rather than the claim inside an already-issued token. Records they have already signed remain valid as signed at the time, with the registration position as it stood recorded on them.

Is the AI making clinical decisions?

No. Screening is deterministic scoring against a published protocol, and any drafted assessment is explicitly a draft for a clinician to accept, change or reject. No outcome is issued without a clinician signing it. If a generative model is ever enabled it becomes a named sub-processor and clients are told before it is switched on.

For reviewers

Reviewing us for a DPO or an IT function?

The security page sets out the platform controls, the sub-processor position and the open items we do not yet close. Book a call if you need the underlying documentation.