Gooroo (Capacity and Demand Planner)
Advanced planning software for NHS organisations, providing demand and capacity modelling to optimise elective care pathways. Helps reduce waiting times and improve resource allocation through predictive analytics.
Features
- Week-by-Week Activity & Capacity Planning
- Advanced Forecasting & Projection Modelling
- Patient-Level Simulation
- Scenario Planning & What-If Analysis
- Linked Elective Pathways
- Constant Capacity Planning Option
- Editable Assumptions & Profiles
- Web-Based Access (Horizon & Standard Licences)
- Automated Data Feeds & API Integration
- Visual Analytics & Collaborative Planning
Benefits
- Optimises elective care planning
- Reduces waiting times
- Improves resource allocation
- Enables accurate forecasting
- Supports scenario planning
- Enhances collaboration across teams
- Provides real-time visibility
- Reduces planning complexity
- Improves elective recovery performance
- Supports strategic decision-making
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 5 1 0 6 1 6 8 3 8 1 3 2 0 7
Contact
INSOURCE LIMITED
Gary Olah
Telephone: 02037274200
Email: info@insource.co.uk
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Healthcare
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- Our services are designed for flexibility and NHS compliance, but buyers should note the following constraints: Remote delivery is standard; on-site support is available by agreement. Integration depends on access to source systems and data feeds, which must be provided by the buyer. Performance may be impacted if local infrastructure does not meet minimum specifications. All services adhere to NHS information governance and security standards, which may influence deployment timelines.
- System requirements
-
- Workstation with Windows 11, Chrome Browser
- Windows Server 2019 or later for hosting application securely.
- Microsoft SQL Server 2019 database engine with appropriate licensing.
- IIS web server configured for secure application component delivery.
- .NET Framework.
- Minimum 64GB RAM for optimal performance and data processing speed.
- At least 1TB disk space for patient data and logs.
- Secure VPN access for remote administration and authorised clinical users.
- Multi-factor authentication enabled for all administrative and clinical user accounts.
- Daily encrypted backups configured for database and sensitive patient information.
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
-
Support requests are handled via our FogBugz ticketing system, monitored Monday–Friday, 09:00–17:00 (UK business hours), excluding UK bank holidays.
Response times follow the customer’s SLA and align with incident priority and business impact:
• Critical (system unavailable/severe impact): 1 business hour
• High (major functionality impaired): 4 business hours
• Medium (partial issue/workaround available): 1 business day
• Low (general query/minor issue): 2 business days
Requests submitted outside business hours are logged and queued for response at the next business day’s start.
Enhanced or extended-hours support, including evenings and weekends, is available by prior agreement under the customer’s SLA. - User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
The supplier provides four support levels: Standard Support, Enhanced Standard Support, Standard Support Plus, and Data as a Service (DaaS). Support is delivered Monday to Friday, 09:00–17:00 (UK business days). Out-of-hours support is available on a chargeable, ad-hoc basis. Planned maintenance is communicated in advance, and all services align with NHS information governance and security standards.
Standard Support is a fixed-price annual advice-and-guidance service for organisations with strong in-house technical capability. It is provided reactively via the supplier’s service portal and includes incident logging, diagnosis, guidance, workarounds, and notification of fixes and upgrades. A pre-requisite is that at least two client staff have completed supplier technical training, or the solution has been live and client-supported for at least two years.
Enhanced Standard Support is designed for teams that need additional supplier input and includes Standard Support plus a pre-purchased Time & Materials allowance for fixes, changes, and urgent support.
Standard Support Plus is for organisations that manage day-to-day operation but require regular supplier involvement. It adds scheduled proactive services such as configuration audits, managed upgrades, and application administration. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We provide a structured onboarding process to help users start using the service quickly and with minimal disruption.
We begin with a remote or onsite kick-off session to confirm scope, user and resource requirements, technical requirements, timelines, milestones, and reporting arrangements.
Following this, our team runs a discovery and setup phase to understand detailed data requirements, connect to organisation data sources, map data between organisation systems and the service, and configure any agreed business rules.
Once configuration is complete, we move into implementation and testing, supporting User Acceptance Testing (UAT) to confirm the service works as expected.
Training is provided where specified in the project scope and is delivered online or virtually. Where included, it covers how users, administrators, and managers use the system, including key workflows and reporting. We also offer train-the-trainer sessions so organisations can build internal capability and support their own users.
During go-live, our team works closely with the organisation to resolve issues quickly and ensure users can start using the service safely and effectively.
Our onboarding approach is collaborative, compliant with NHS standards, and tailored to each organisation’s needs. - Service documentation
- No
- End-of-contract data extraction
-
The service operates using a copy of the organisation’s source data, combined with supplier-owned data models, processing logic, and derived datasets that form part of the service. The organisation remains the owner of all data they have provided or entered into the service.
At the end of the contract, we provide the organisation with an export of all data manually entered or uploaded by the organisation and any customer-owned reference or configuration data. This data is supplied in flat file formats such as CSV so it can be retained or imported into another system. Supplier-owned data structures, derived data, analytics outputs, and platform-specific datasets form part of our intellectual property and are not transferred as part of data extraction.
After data has been provided and confirmed, the service is decommissioned in line with NHS data protection and security requirements. - End-of-contract process
-
At the end of the contract, the service is moved into a controlled decommissioning process.
The supplier provides a Statement of Work (SoW) that documents the decommissioning activities, lists each supplier product, system, and database that will be decommissioned, and confirms the customer-owned data that will be extracted. This is reviewed with the organisation and an agreed decommissioning date is set. Before decommissioning, the organisation receives all data manually entered or uploaded by the organisation and any customer-owned reference or configuration data.
Once the agreed data has been provided, all supplier-hosted software, databases, and derived datasets associated with the service are securely removed. After decommissioning is complete, a formal sign-off is completed by both parties to confirm that data has been supplied, systems have been decommissioned, and the contract has been closed.
This ensures the service is exited in a controlled, auditable, and secure way.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- An API is available that provides access to the application processing logs. Only duly authorised users are able to activate this API.
- API documentation
- No
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- All data flows into the service, the flows of data through the service, and aspects of the user interface are all configurable. Customisation is enabled through the administration browser interface. Only duly authorised and trained users are able to operate the customisation capabilities of the service.
Scaling
- Independence of resources
- Our services are architected to ensure performance is not impacted by other users. Multi-tenancy is managed through workload prioritisation, preventing cross-customer interference. Capacity is monitored continuously.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Service usage and performance metrics are provided in line with the customer’s purchased support agreement and agreed reporting schedule.
Metrics are aligned to the customer’s contracted support model and governance requirements and may include:
• Ticket volumes and trends
• Request and incident categorisation (by type and priority)
• Response and resolution times
• SLA compliance and performance against targets
• Backlog levels and ageing
• User activity and support demand patterns
Reports are delivered in line with the customer’s purchased support agreement and agreed reporting schedule and are reviewed as part of ongoing service management and governance. - Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
- Azure automatically encrypts all data stored in Storage Accounts (Blobs, Files, Queues, Tables) using AES‑256 or FIPS‑140‑2 compliant ciphers.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export their data at any time during the contract. Standard CSV exports are provided. We provide comprehensive data dictionaries and documentation to support the process. For organisations requiring more complex migrations, optional assisted services are available for validation, reconciliation, and bespoke transformations. All exports comply with NHS Information Governance and GDPR requirements, ensuring data security and full auditability throughout the process.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
Where our service is deployed on buyer premises, we are unable to guarantee up time availability as we are dependent on the buyers infrastructure under which we have no control.
Where deployed to our cloud service, we rely on the MS Azure guaranteed availability of 99.9% measured monthly. This excludes planned maintenance windows, which can be scheduled outside core hours and are communicated in advance. Our infrastructure is built on resilient, NHS-compliant cloud platforms with redundancy and failover mechanisms to minimise downtime. Continuous monitoring and proactive alerts ensure issues are addressed before they impact service.
Our approach ensures NHS organisations can rely on consistent, secure, and high-performing services to support critical operations and statutory reporting. - Approach to resilience
-
Our services are designed with resilience at their core to ensure uninterrupted availability for NHS operations.
Where our services are deployed to buyer site, we are wholly dependent on the buyers infrastructure resilience.
For hosted deployments, we offer multiple levels of redundancy including high-availability zones and disaster recovery capabilities, automated failover continuity even in the event of hardware or network failure. We can also offer, Data replication across multiple nodes to prevent single points of failure.
Contracts can include continuous monitoring, proactive alerting, and capacity management to handle peak demand without degradation. In the unlikely event of a major incident, recovery procedures are tested regularly to ensure rapid restoration of service. - Outage reporting
-
For Data as a Service (DaaS) organisations, the supplier provides continuous monitoring of build processes, data flows, and application modules using the Management Information Console. Daily build logs, error logs, and performance trends are automatically reviewed to detect failures, slow-running processes, and data issues.
When a build failure or service issue is detected, it is automatically logged in the supplier’s online support system (FogBugz). A support ticket is created, assigned to the supplier’s support team, and an email notification is sent to the customer.
Critical incidents trigger immediate escalation to senior technical teams and, where applicable, the customer’s Technical Account Manager. Where issues cannot be resolved promptly, they are escalated to the customer with clear options and recommendations.
For planned maintenance, including version upgrades and environment updates, customers are notified in advance.
There is no public status dashboard or external API. All outage reporting, alerts, and progress updates are delivered via email notifications and the support portal, providing a full audit trail of incidents, actions, and resolution.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Username or password
- Other
- Other user authentication
- Windows inherited security
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is strictly controlled through role-based permissions and multi-factor authentication. User rights are provisioned according to job requirements and reviewed regularly. Administrative privileges are granted only via separate accounts, used solely for authorised tasks. All login activities, including failed attempts and changes, are monitored and logged. Remote access is subject to additional safeguards, including VPN and device compliance checks. Support channels require identity verification before any action is taken. Password policies enforce complexity and periodic changes, and credentials are never shared. These measures ensure secure, least-privilege access across all environments.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Username or password
- Other
- Description of management access authentication
- Windows inherited security
Audit information for users
- Access to user activity audit information
- You control when users can access audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber essentials Plus, DSP Toolkit
- Information security policies and processes
-
We operate under a comprehensive Information Security Management System (ISMS) aligned with ISO 27001:2022 certification, ensuring best practice for confidentiality, integrity, and availability of information assets. Our policies cover all business functions, systems, networks, and physical environments supporting NHS services.
Key principles:
Protection against unauthorised disclosure, modification, or loss of data.
Compliance with NHS Information Governance, GDPR, and Data Security & Protection Toolkit.
Regular risk assessments and continuous improvement through audits and reviews.
Governance and reporting structure:
Overall responsibility rests with the ISMS Manager, supported by ISMS Representatives and the Data Protection Officer (DPO).
The COO approves the policy and oversees compliance.
All staff are required to report suspected breaches immediately via the IT helpdesk.
Policy enforcement:
Mandatory security awareness training for all employees.
Documented procedures for incident management, monitoring, and escalation.
Regular internal audits and external certification reviews to ensure adherence.
Our approach guarantees robust security controls, transparent governance, and proactive risk management to protect NHS data and maintain trust. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We follow a formal configuration and change management process. Changes are raised through a controlled Change Request process, assessed for operational and security impact before approval. Security reviews include vulnerability analysis, compliance checks, and risk mitigation planning. Approved changes are tested in a controlled environment prior to production release. Full audit trails are maintained, and rollback plans are documented for critical updates. This approach ensures integrity, security, and traceability across all service components.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We operate a proactive vulnerability management process aligned with ISO 27001 and NHS DSP Toolkit standards. Potential threats are assessed through continuous monitoring, automated vulnerability scans, and regular penetration testing. Critical vulnerabilities are prioritised and patched within 24 hours; high-risk issues within 72 hours, and all others within agreed SLAs. Patches are tested in a controlled environment before deployment to production. Our approach ensures rapid response, minimises risk, and maintains compliance with NHS information governance requirements.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We implement continuous protective monitoring to detect and respond to potential compromises. Our systems use real-time log analysis to identify suspicious activity across infrastructure and applications. When a potential compromise is detected, incidents are immediately escalated to our security team for investigation. All events are logged, and post-incident reviews are conducted to prevent recurrence. This proactive approach ensures rapid detection, minimises risk, and maintains compliance with NHS DSP Toolkit and ISO 27001 standards.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We operate an ITIL-aligned incident management process. Pre-defined workflows cover common events such as system, data feed, and user access issues. Users log incidents via FogBugz, our 24/7 online support system for ticket submission. Issues detected through remote monitoring are automatically logged. All tickets are triaged during support hours, assigned a priority and SLA, and tracked in FogBugz, providing a full audit trail. System defects are managed in Jira using ITIL-aligned change and defect processes. Service reviews include FogBugz volumes, SLA performance, trends, and lessons learned to support continuous improvement.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0.0%
- Between £250,000 and £500,000
- 0.5%
- Between £500,001 and £1,000,000
- 1%
- Between £1,000,001 and £2,500,000
- 1.5%
- Between £2,500,001 and £5,000,000
- 2%
- Over £5,000,001
- 3%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO Certification Limited
- ISO/IEC 27001 accreditation date
- Wednesday 4 June 2025
- What the ISO/IEC 27001 doesn’t cover
- Insource Limited have not opted out of any clauses stated in the statement of applicability in ISO 27001.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation ISO Certification Limited
- ISO 9001 accreditation date
- Monday 27 November 2023
- What the ISO 9001 doesn’t cover
- Insource Limited have not opted out of any clauses stated in the statement of applicability in ISO 9001.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 81234f8d-9c22-4b55-9bf5-330cf1fa6290
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 2676e236-0779-4091-8d2e-57315271d601
- Other security certifications
- Yes
- Any other security certifications
- DSP Toolkit
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
- Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
- Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-