GP Triage
GP Triage is a fully autonomous, AI-powered triage and booking platform for Primary Care. It collects patient requests, prioritises them based on urgency and type, and allocates them to the right team with booking options. This improves access, capacity, safety and the patient experience across GP practices, PCNs and ICBs.
Features
- Online clinical and admin request intake
- Automated priority and type categorisation
- Practice-defined capacity and resource management
- Intelligent automated booking and task routing
- Real-time clinician and admin workflow
- Bespoke, configurable triage pathways and rules
- Integrated booking with local calendars
- Audit logs and activity tracking
- Browser-based platform with role-based access control
- Real-time operational dashboards
Benefits
- Reduces telephone congestion by moving requests online
- Improves clinical prioritisation through structured presentation and automated urgency scoring
- Increases appointment utilisation via automated booking and routing
- Improves patient access with 24/7 online request capture
- Reduces administrative workload through intelligent allocation and worklists
- Improves safety by ensuring urgent cases are highlighted early
- Supports system-level coordination across practices, PCNs and ICBs
- Enhances reporting and auditability for governance and improvement
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 8 7 6 1 6 4 6 9 4 3 2 0 6 8
Contact
GP TRIAGE LTD
Hannan Chaudery
Telephone: 07447009616
Email: hannan.chaudery@gptriage.com
About your service
- Service categories
-
Applications
Customer relationship management
- Contact centre
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- GP Triage is a cloud-based browser application and requires standard internet connectivity and modern web browsers. Planned maintenance windows are communicated in advance and scheduled outside peak hours wherever possible. No specialist hardware is required. Customer configuration and onboarding activities are completed prior to go-live. Access to the service is role-based and requires authenticated user accounts.
- System requirements
-
- Modern web browser (Chrome, Edge, Safari, Firefox, etc.)
- Stable internet connection
- User login credentials
- Practice-defined capacity and user access control
- Electronic Health Record system for appointment booking (EMIS, SystmOne, etc.)
User support
- Email or online ticketing support
- Yes
- Support response times
- Support queries submitted via email or ticketing receive a response within 4 business hours (Mon–Fri, 08:00–18:00). High-priority service issues are acknowledged within 1 hour during business hours. Critical incidents affecting service availability are monitored and escalated 24/7. Non-urgent tickets received outside of business hours are processed the next business day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
GP Triage provides tiered support at no additional cost. Standard support is delivered via email, in-app ticketing, and telephone during business hours (09:00–17:00 GMT/BST, Monday–Friday), with responses handled by the Customer Support Team and the allocated Account Manager. Support includes issue triage, user guidance, configuration advice and general platform assistance. Outside standard hours, GP Triage monitors for platform outages and material service errors and provides 24-hour support for critical incidents which affect service availability or safety.
Tickets may be raised via email or in-app at any time. During support hours, GP Triage uses commercially reasonable efforts to respond within eight (8) hours via email and within three (3) hours via telephone. Platform availability targets are 99% monthly uptime, excluding planned maintenance or third-party outages.
Every customer is assigned an Account Manager who acts as the primary point of contact and escalation path. Technical and cloud support engineering is provided by GP Triage as needed to resolve platform-related issues. There are currently no paid support tiers, uplifted support packages, or separate Technical Account Management fees. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
GP Triage provides a structured, fully supported onboarding process designed to get practices live quickly and confidently. Each practice is assigned an onboarding lead who manages the entire setup and configuration process. Practices are invited to complete a short connectivity form, after which our team configures the local instance, appointment slot mappings, capacity rules, care navigation pathways and any specific local requirements.
Onboarding includes an online kickoff meeting where we review pathways, urgent/same-day/routine booking rules, patient flows, and staff roles. Practices are provided with an onboarding video to brief staff, plus written documentation on configuration, access, and operational use.
Once deployed to testing and then production, the practice completes live testing using a Spine-connected test patient, and our team verifies everything end-to-end before handover. Dashboard logins are issued to relevant staff, and practices receive a governance bundle for internal records. Support remains available after go-live via email/ticketing. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
-
- Video
- DOCX
- End-of-contract data extraction
- At contract end, the customer may request a full export of their data. GP Triage will provide all retained data in a commonly used, machine-readable format within an agreed timeframe. This export is delivered securely to the customer’s nominated contact via encrypted transfer. There are no proprietary formats or technical barriers to extraction, and no charge is applied for data extraction. Following successful handover, data is deleted in line with our retention and destruction policies, unless otherwise instructed for legal or clinical safety reasons.
- End-of-contract process
-
At the end of the contract, the customer may either renew or terminate the service. If the service is terminated, access to the GP Triage platform will cease at the contract end date.
Included in the contract price: -
- Secure data export in a commonly used, machine-readable format
- Secure transfer of the exported data to the customer’s nominated contact
- Deletion of retained data in line with our data retention and destruction policies
There are no additional fees for data extraction or data return.
Additional costs may apply only where the customer requests optional services beyond the standard end-of-contract process (e.g. consultancy, custom data transformation, or extended platform access beyond the agreed termination date).
Where data originates from the clinical system (EMIS, SystmOne, etc.), no clinical record is deleted and standard clinical system access to historic entries remains unchanged. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is fully responsive and accessible via mobile browsers with no installation required. The mobile interface presents content in a simplified layout for smaller screens, but all core functionality remains available and aligned with the desktop experience.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service provides web-based interfaces for patients and clinical/admin users. Patients submit structured requests through an accessible online system. Clinical/admin users access configurable worklists, booking controls, dashboards, capacity tools, and audit logs. All interfaces are browser-based, responsive, and support role-based access control with activity tracking.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- GP Triage performs ongoing usability and accessibility testing with users who rely on assistive technology. Testing has included screen reader users (NVDA and VoiceOver) to validate page structure, form navigation and role/label semantics, as well as keyboard-only navigation to ensure full traversal without pointer devices. Contrast, focus indicators and text scaling are manually validated against WCAG AA criteria during development. Feedback from patients and administrative users is collected during onboarding pilots to identify accessibility barriers and inform improvements. Accessibility considerations form part of our routine QA and regression testing.
- API
- Yes
- What users can and can't do using the API
-
The API is used for secure integrations with external clinical systems and scheduling tools (for example calendar syncing and practice system integrations). Configuration and access are controlled by GP Triage and are not open for self-service or direct public use.
Users cannot set up the service directly through the API and cannot make configuration changes through the API. All configuration is managed through the GP Triage onboarding process.
API access is read/write depending on the integration and is limited to specific, authorised endpoints. There is no unsupported or open access. Buyer organisations cannot directly modify the service or bypass clinical or operational workflows through the API.
In summary, the API enables controlled system-to-system integrations rather than end-user customisation or setup. - API documentation
- Yes
- API documentation formats
-
- HTML
- Other
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Buyers can customise GP Triage at multiple levels to reflect local workflows, capacity, and service models. Customisable elements include - clinical pathways and outcomes (e.g. booking, divert, telephone), slot types and urgency mapping, appointment books, care navigation routes, question sets, interpreter requirements, and local service directories.
Customisation is completed during an onboarding and configuration process delivered by GP Triage with the buyer’s nominated leads (such as Practice Manager, GP Lead, or Digital Lead). Configuration options are agreed collaboratively, documented, and implemented by GP Triage to ensure alignment with safety, capacity, and governance requirements.
This configuration process requires no software development or code changes by the buyer. Onboarding and configuration are delivered as a professional service at a fixed cost in accordance with our pricing, with buyers able to purchase additional configuration services if their requirements change in future.
Authorised users can request further configuration changes via structured change control. No technical skills are required from the buyer.
Scaling
- Independence of resources
- GP Triage is delivered as a scalable cloud-hosted application. System capacity automatically adjusts based on usage, ensuring that a busy organisation does not slow down the service for others. Performance is continuously monitored to maintain responsiveness and uptime. This relates solely to the technical operation of the platform, not staffing or service desk capacity.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Metrics are available in real-time through the integrated analytics dashboard within the clinician portal. Data can be filtered, aggregated by time period, and exported on request. Metrics are view-only unless extracted on request.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users can request an export of their data at any time through our support channels. Data is provided in a secure, machine-readable format and transferred to the customer’s nominated contact via an encrypted method. There are no restrictions on data export and no additional fees for standard exports.
- Data export formats
-
- CSV
- Other
- Other data export formats
- JSON
- Data import formats
- Other
- Other data import formats
- Not applicable. No user data import required
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
GP Triage targets 99.9% platform availability, measured monthly, excluding planned maintenance windows.
Availability is monitored continuously and incidents affecting uptime are escalated immediately.
Planned maintenance is scheduled outside business hours where possible and communicated in advance.
GP Triage does not currently provide financial service credits; however, we operate a rapid escalation process for service-affecting incidents and keep customers informed throughout.
Service availability commitments are reviewed regularly as part of our product and infrastructure roadmap. - Approach to resilience
-
GP Triage is delivered using a modern, cloud-native architecture designed for resilience, performance and secure scaling.
Core infrastructure is hosted in UK datacentres with redundancy at multiple layers, including load balancing, automated failover, infrastructure monitoring and alerting. Application components are deployed with containerisation and orchestration to reduce single points of failure and support horizontal scaling during periods of higher demand.
Data is replicated across availability zones and backed up on a defined schedule. Backup integrity and restore procedures are tested regularly.
An internal incident management process is in place for platform events, supported by real-time observability and automated alerts.
Additional datacentre and network resilience details are available on request. - Outage reporting
-
GP Triage uses real-time infrastructure monitoring and alerting to detect service degradation or outages.
In the event of a confirmed outage, affected customers are notified directly via email and/or within the platform, depending on impact and urgency.
High-priority incidents affecting availability are escalated internally for rapid response and status updates are provided to customers until resolution.
GP Triage does not currently provide a public status dashboard or outage API. Additional reporting formats can be made available to buyers on request.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces (including administration panels) and support channels is restricted to authorised personnel using individual accounts with MFA and role-based permissions. Privileged actions are limited to specific roles and monitored. Support channels do not grant direct system access. Support staff require explicit authorisation to view or modify customer environments. No shared accounts are used, and access rights are reviewed periodically to ensure least-privilege. Administrative interfaces are not exposed publicly without authentication.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- GP Triage follows a structured security governance approach aligned to the UK Software Security Code of Practice. Security responsibilities are defined at management level, with regular review of risks, incidents, and improvement actions. We operate an ISMS-style framework covering access control, vulnerability management, supplier assurance, and incident response. Independent penetration testing is conducted annually and risk remediation is tracked. We are currently implementing ISO/IEC 27001:2022 as part of our formal ISMS programme. Security governance documentation and evidence can be provided on request.
- Information security policies and processes
-
We maintain a formal set of information security policies covering access control, acceptable use, data protection, incident response, vulnerability management, secure development, asset management, change management and business continuity. Policies are owned at management level and reviewed at least annually or following material changes.
We operate an ISMS-style governance approach aligned to ISO/IEC 27001:2022, with clear roles for data protection, clinical safety and security oversight. Security responsibilities are embedded within engineering, operations and product teams, and all staff undergo onboarding and periodic refresher training covering security, data protection and confidentiality.
Compliance is supported through technical controls (MFA, role-based access, least privilege, encryption at rest and in transit), code review processes, CI/CD pipeline checks, vulnerability scanning, penetration testing and incident management procedures.
Breaches, incidents and near-misses follow a defined escalation and reporting process. Policy conformance is monitored through internal checks, issue tracking and change management workflows.
We maintain documentation for data flows, data retention, DPIAs and clinical safety, aligned with NHS and ICO expectations. Policies and governance documentation are available to buyers on request. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Our configuration and change management approach is based on controlled source management, peer review and audited deployment workflows. All application and infrastructure components are tracked in version control with full lifetime history, enabling traceability, rollback and audit. Changes follow defined approval steps (Dev -> UAT -> Prod) and are assessed for potential security and service impact before deployment. Deployments are automated via CI/CD pipelines to ensure consistency, with access restricted under least-privilege principles. Security and dependency updates are prioritised, and changes to production are logged and monitored. All changes are scheduled and tested prior to release to minimise operational disruption.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We operate a continuous vulnerability management process covering application, infrastructure and dependency risks. Potential threats are assessed via routine dependency scanning, cloud platform alerts, scheduled penetration testing, and monitoring of vendor and NCSC advisories. Patches for high and critical issues are prioritised and deployed rapidly via our CI/CD pipeline, with lower-risk issues scheduled into regular releases. Information on emerging threats is sourced from cloud provider feeds, software vendor bulletins, OWASP, NVD/CVE databases, and NCSC advisories. All findings are triaged, tracked and verified through resolution.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We operate protective monitoring across application and infrastructure layers. Cloud-native logging and security telemetry are monitored for unusual behaviour, failed authentication patterns, privilege misuse and abuse indicators. Potential compromises are identified through automated alerts, threat intelligence feeds and periodic log review. On detection, incidents are triaged by severity, investigated, contained and remediated, with customer impact assessed and communications managed as required. High-severity incidents are actioned immediately, lower-severity events are managed within business hours. All incidents are tracked to closure and reviewed to identify root causes and implement improvements.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We maintain predefined incident response procedures for common security, availability and performance events. Incidents can be reported via our support dashboard or by email, which triggers a triage workflow and time-based escalation. Incident handling includes identification, containment, remediation, and post-incident review. Users are kept informed throughout via status updates and a final incident report summarising impact, root cause and corrective actions.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Health and Social Care Network (HSCN)
- Other
- Other public sector networks
- NHS Personal Demographics Service (PDS) via Spine-supported API connectivity.
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 3%
- Between £1,000,001 and £2,500,000
- 4%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 7%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Eabe0742-0285-46ac-b02d-acf9007d8c02
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-