Skip to main content

Help us improve the Digital Marketplace - send your feedback

INSOURCE LIMITED

Gooroo (Capacity and Demand Planner)

Advanced planning software for NHS organisations, providing demand and capacity modelling to optimise elective care pathways. Helps reduce waiting times and improve resource allocation through predictive analytics.

Features

  • Week-by-Week Activity & Capacity Planning
  • Advanced Forecasting & Projection Modelling
  • Patient-Level Simulation
  • Scenario Planning & What-If Analysis
  • Linked Elective Pathways
  • Constant Capacity Planning Option
  • Editable Assumptions & Profiles
  • Web-Based Access (Horizon & Standard Licences)
  • Automated Data Feeds & API Integration
  • Visual Analytics & Collaborative Planning

Benefits

  • Optimises elective care planning
  • Reduces waiting times
  • Improves resource allocation
  • Enables accurate forecasting
  • Supports scenario planning
  • Enhances collaboration across teams
  • Provides real-time visibility
  • Reduces planning complexity
  • Improves elective recovery performance
  • Supports strategic decision-making

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@insource.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 5 1 0 6 1 6 8 3 8 1 3 2 0 7

Contact

INSOURCE LIMITED Gary Olah
Telephone: 02037274200
Email: info@insource.co.uk

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Healthcare
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
Our services are designed for flexibility and NHS compliance, but buyers should note the following constraints: Remote delivery is standard; on-site support is available by agreement. Integration depends on access to source systems and data feeds, which must be provided by the buyer. Performance may be impacted if local infrastructure does not meet minimum specifications. All services adhere to NHS information governance and security standards, which may influence deployment timelines.
System requirements
  • Workstation with Windows 11, Chrome Browser
  • Windows Server 2019 or later for hosting application securely.
  • Microsoft SQL Server 2019 database engine with appropriate licensing.
  • IIS web server configured for secure application component delivery.
  • .NET Framework.
  • Minimum 64GB RAM for optimal performance and data processing speed.
  • At least 1TB disk space for patient data and logs.
  • Secure VPN access for remote administration and authorised clinical users.
  • Multi-factor authentication enabled for all administrative and clinical user accounts.
  • Daily encrypted backups configured for database and sensitive patient information.

User support

Email or online ticketing support
Yes, at extra cost
Support response times
Support requests are handled via our FogBugz ticketing system, monitored Monday–Friday, 09:00–17:00 (UK business hours), excluding UK bank holidays.
Response times follow the customer’s SLA and align with incident priority and business impact:
• Critical (system unavailable/severe impact): 1 business hour
• High (major functionality impaired): 4 business hours
• Medium (partial issue/workaround available): 1 business day
• Low (general query/minor issue): 2 business days
Requests submitted outside business hours are logged and queued for response at the next business day’s start.
Enhanced or extended-hours support, including evenings and weekends, is available by prior agreement under the customer’s SLA.
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
The supplier provides four support levels: Standard Support, Enhanced Standard Support, Standard Support Plus, and Data as a Service (DaaS). Support is delivered Monday to Friday, 09:00–17:00 (UK business days). Out-of-hours support is available on a chargeable, ad-hoc basis. Planned maintenance is communicated in advance, and all services align with NHS information governance and security standards.
Standard Support is a fixed-price annual advice-and-guidance service for organisations with strong in-house technical capability. It is provided reactively via the supplier’s service portal and includes incident logging, diagnosis, guidance, workarounds, and notification of fixes and upgrades. A pre-requisite is that at least two client staff have completed supplier technical training, or the solution has been live and client-supported for at least two years.
Enhanced Standard Support is designed for teams that need additional supplier input and includes Standard Support plus a pre-purchased Time & Materials allowance for fixes, changes, and urgent support.
Standard Support Plus is for organisations that manage day-to-day operation but require regular supplier involvement. It adds scheduled proactive services such as configuration audits, managed upgrades, and application administration.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide a structured onboarding process to help users start using the service quickly and with minimal disruption.

We begin with a remote or onsite kick-off session to confirm scope, user and resource requirements, technical requirements, timelines, milestones, and reporting arrangements.

Following this, our team runs a discovery and setup phase to understand detailed data requirements, connect to organisation data sources, map data between organisation systems and the service, and configure any agreed business rules.

Once configuration is complete, we move into implementation and testing, supporting User Acceptance Testing (UAT) to confirm the service works as expected.

Training is provided where specified in the project scope and is delivered online or virtually. Where included, it covers how users, administrators, and managers use the system, including key workflows and reporting. We also offer train-the-trainer sessions so organisations can build internal capability and support their own users.

During go-live, our team works closely with the organisation to resolve issues quickly and ensure users can start using the service safely and effectively.

Our onboarding approach is collaborative, compliant with NHS standards, and tailored to each organisation’s needs.
Service documentation
No
End-of-contract data extraction
The service operates using a copy of the organisation’s source data, combined with supplier-owned data models, processing logic, and derived datasets that form part of the service. The organisation remains the owner of all data they have provided or entered into the service.
At the end of the contract, we provide the organisation with an export of all data manually entered or uploaded by the organisation and any customer-owned reference or configuration data. This data is supplied in flat file formats such as CSV so it can be retained or imported into another system. Supplier-owned data structures, derived data, analytics outputs, and platform-specific datasets form part of our intellectual property and are not transferred as part of data extraction.
After data has been provided and confirmed, the service is decommissioned in line with NHS data protection and security requirements.
End-of-contract process
At the end of the contract, the service is moved into a controlled decommissioning process.
The supplier provides a Statement of Work (SoW) that documents the decommissioning activities, lists each supplier product, system, and database that will be decommissioned, and confirms the customer-owned data that will be extracted. This is reviewed with the organisation and an agreed decommissioning date is set. Before decommissioning, the organisation receives all data manually entered or uploaded by the organisation and any customer-owned reference or configuration data.
Once the agreed data has been provided, all supplier-hosted software, databases, and derived datasets associated with the service are securely removed. After decommissioning is complete, a formal sign-off is completed by both parties to confirm that data has been supplied, systems have been decommissioned, and the contract has been closed.
This ensures the service is exited in a controlled, auditable, and secure way.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
No
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
An API is available that provides access to the application processing logs. Only duly authorised users are able to activate this API.
API documentation
No
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
All data flows into the service, the flows of data through the service, and aspects of the user interface are all configurable. Customisation is enabled through the administration browser interface. Only duly authorised and trained users are able to operate the customisation capabilities of the service.

Scaling

Independence of resources
Our services are architected to ensure performance is not impacted by other users. Multi-tenancy is managed through workload prioritisation, preventing cross-customer interference. Capacity is monitored continuously.

Analytics

Service usage metrics
Yes
Metrics types
Service usage and performance metrics are provided in line with the customer’s purchased support agreement and agreed reporting schedule.
Metrics are aligned to the customer’s contracted support model and governance requirements and may include:
• Ticket volumes and trends
• Request and incident categorisation (by type and priority)
• Response and resolution times
• SLA compliance and performance against targets
• Backlog levels and ageing
• User activity and support demand patterns
Reports are delivered in line with the customer’s purchased support agreement and agreed reporting schedule and are reviewed as part of ongoing service management and governance.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
Azure automatically encrypts all data stored in Storage Accounts (Blobs, Files, Queues, Tables) using AES‑256 or FIPS‑140‑2 compliant ciphers.
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export their data at any time during the contract. Standard CSV exports are provided. We provide comprehensive data dictionaries and documentation to support the process. For organisations requiring more complex migrations, optional assisted services are available for validation, reconciliation, and bespoke transformations. All exports comply with NHS Information Governance and GDPR requirements, ensuring data security and full auditability throughout the process.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
Where our service is deployed on buyer premises, we are unable to guarantee up time availability as we are dependent on the buyers infrastructure under which we have no control.

Where deployed to our cloud service, we rely on the MS Azure guaranteed availability of 99.9% measured monthly. This excludes planned maintenance windows, which can be scheduled outside core hours and are communicated in advance. Our infrastructure is built on resilient, NHS-compliant cloud platforms with redundancy and failover mechanisms to minimise downtime. Continuous monitoring and proactive alerts ensure issues are addressed before they impact service.
Our approach ensures NHS organisations can rely on consistent, secure, and high-performing services to support critical operations and statutory reporting.
Approach to resilience
Our services are designed with resilience at their core to ensure uninterrupted availability for NHS operations.

Where our services are deployed to buyer site, we are wholly dependent on the buyers infrastructure resilience.

For hosted deployments, we offer multiple levels of redundancy including high-availability zones and disaster recovery capabilities, automated failover continuity even in the event of hardware or network failure. We can also offer, Data replication across multiple nodes to prevent single points of failure.

Contracts can include continuous monitoring, proactive alerting, and capacity management to handle peak demand without degradation. In the unlikely event of a major incident, recovery procedures are tested regularly to ensure rapid restoration of service.
Outage reporting
For Data as a Service (DaaS) organisations, the supplier provides continuous monitoring of build processes, data flows, and application modules using the Management Information Console. Daily build logs, error logs, and performance trends are automatically reviewed to detect failures, slow-running processes, and data issues.
When a build failure or service issue is detected, it is automatically logged in the supplier’s online support system (FogBugz). A support ticket is created, assigned to the supplier’s support team, and an email notification is sent to the customer.
Critical incidents trigger immediate escalation to senior technical teams and, where applicable, the customer’s Technical Account Manager. Where issues cannot be resolved promptly, they are escalated to the customer with clear options and recommendations.
For planned maintenance, including version upgrades and environment updates, customers are notified in advance.
There is no public status dashboard or external API. All outage reporting, alerts, and progress updates are delivered via email notifications and the support portal, providing a full audit trail of incidents, actions, and resolution.

Identity and authentication

User authentication needed
Yes
User authentication
  • Username or password
  • Other
Other user authentication
Windows inherited security
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is strictly controlled through role-based permissions and multi-factor authentication. User rights are provisioned according to job requirements and reviewed regularly. Administrative privileges are granted only via separate accounts, used solely for authorised tasks. All login activities, including failed attempts and changes, are monitored and logged. Remote access is subject to additional safeguards, including VPN and device compliance checks. Support channels require identity verification before any action is taken. Password policies enforce complexity and periodic changes, and credentials are never shared. These measures ensure secure, least-privilege access across all environments.
Access restriction testing frequency
At least once a year
Management access authentication
  • Username or password
  • Other
Description of management access authentication
Windows inherited security

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber essentials Plus, DSP Toolkit
Information security policies and processes
We operate under a comprehensive Information Security Management System (ISMS) aligned with ISO 27001:2022 certification, ensuring best practice for confidentiality, integrity, and availability of information assets. Our policies cover all business functions, systems, networks, and physical environments supporting NHS services.
Key principles:

Protection against unauthorised disclosure, modification, or loss of data.
Compliance with NHS Information Governance, GDPR, and Data Security & Protection Toolkit.
Regular risk assessments and continuous improvement through audits and reviews.

Governance and reporting structure:

Overall responsibility rests with the ISMS Manager, supported by ISMS Representatives and the Data Protection Officer (DPO).
The COO approves the policy and oversees compliance.
All staff are required to report suspected breaches immediately via the IT helpdesk.

Policy enforcement:

Mandatory security awareness training for all employees.
Documented procedures for incident management, monitoring, and escalation.
Regular internal audits and external certification reviews to ensure adherence.

Our approach guarantees robust security controls, transparent governance, and proactive risk management to protect NHS data and maintain trust.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We follow a formal configuration and change management process. Changes are raised through a controlled Change Request process, assessed for operational and security impact before approval. Security reviews include vulnerability analysis, compliance checks, and risk mitigation planning. Approved changes are tested in a controlled environment prior to production release. Full audit trails are maintained, and rollback plans are documented for critical updates. This approach ensures integrity, security, and traceability across all service components.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We operate a proactive vulnerability management process aligned with ISO 27001 and NHS DSP Toolkit standards. Potential threats are assessed through continuous monitoring, automated vulnerability scans, and regular penetration testing. Critical vulnerabilities are prioritised and patched within 24 hours; high-risk issues within 72 hours, and all others within agreed SLAs. Patches are tested in a controlled environment before deployment to production. Our approach ensures rapid response, minimises risk, and maintains compliance with NHS information governance requirements.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We implement continuous protective monitoring to detect and respond to potential compromises. Our systems use real-time log analysis to identify suspicious activity across infrastructure and applications. When a potential compromise is detected, incidents are immediately escalated to our security team for investigation. All events are logged, and post-incident reviews are conducted to prevent recurrence. This proactive approach ensures rapid detection, minimises risk, and maintains compliance with NHS DSP Toolkit and ISO 27001 standards.
Incident management type
Supplier-defined controls
Incident management approach
We operate an ITIL-aligned incident management process. Pre-defined workflows cover common events such as system, data feed, and user access issues. Users log incidents via FogBugz, our 24/7 online support system for ticket submission. Issues detected through remote monitoring are automatically logged. All tickets are triaged during support hours, assigned a priority and SLA, and tracked in FogBugz, providing a full audit trail. System defects are managed in Jira using ITIL-aligned change and defect processes. Service reviews include FogBugz volumes, SLA performance, trends, and lessons learned to support continuous improvement.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
Health and Social Care Network (HSCN)

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0.0%
Between £250,000 and £500,000
0.5%
Between £500,001 and £1,000,000
1%
Between £1,000,001 and £2,500,000
1.5%
Between £2,500,001 and £5,000,000
2%
Over £5,000,001
3%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Citation ISO Certification Limited
ISO/IEC 27001 accreditation date
Wednesday 4 June 2025
What the ISO/IEC 27001 doesn’t cover
Insource Limited have not opted out of any clauses stated in the statement of applicability in ISO 27001.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Citation ISO Certification Limited
ISO 9001 accreditation date
Monday 27 November 2023
What the ISO 9001 doesn’t cover
Insource Limited have not opted out of any clauses stated in the statement of applicability in ISO 9001.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
81234f8d-9c22-4b55-9bf5-330cf1fa6290
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
2676e236-0779-4091-8d2e-57315271d601
Other security certifications
Yes
Any other security certifications
DSP Toolkit

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
    • Measures to engage users and communities and build relationships to increase community integration build trust and influence how the contract is delivered
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@insource.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.