Aurora design system
Version 2.0, expressed through iOS 26 Liquid Glass. Calm by default, exact under pressure — three registers over one token system. Every component below is the one the app actually uses.
Identity
The Aurora arch: two concentric bands rising from a shared baseline, closing into a rounded plus. Bridge span, aurora bands and medical cross in one mark — legible down to 20 pt in the navigation rail.
On the brand gradient, depth is carried by opacity — 55%, 78%, 100% — so the mark survives monochrome print and reversed placement without a second file.
Colour
Azure — primary
The 500/600 split is the most consequential accessibility decision in the palette. azure.500 is the brand colour and reaches only 3.9:1 on white — enough for graphics and large text, not for body copy. Aurora therefore uses 500 for fills and 600 for text and icons on light surfaces. They read as the same blue; only one is legally readable.
Ink — neutral
Status
Department identity — 14 categorical tokens
Chosen for hue and lightness separation, so pairs stay distinguishable under deuteranopia and protanopia and survive grayscale printing. Department colour is identity and wayfinding only — never clinical status — and is always paired with a text label.
Typography
SF Pro renders natively on Apple hardware; Inter is the metric-matched cross-platform fallback and General Sans carries the display roles. Sentence case everywhere — no Title Case buttons, no medical abbreviations in patient copy.
Liquid Glass materials
The glass rule. Any surface containing body text, a form control, a data table or a clinical value uses glass-3 or solid. The specular top edge is what makes glass read as a physical pane rather than a flat translucent rectangle — it is not optional at elevations 2 and 3. Legibility of a dose is not negotiable against an aesthetic.
Actions
Buttons name their outcome and keep the name through the flow: Book appointment → Appointment booked. Disabled controls stay focusable and explain themselves; loading preserves width so nothing shifts.
Inputs
ClinicalInput
It warns rather than blocks on an out-of-range entry, because a clinician may legitimately need to record an extreme value. Physiologically implausible values require explicit confirmation.
The evidence chart
Aurora's signature. Provenance renders as marker shape, not colour — a filled disc for a clinic measurement, a ring for a connected device, a dashed outline for a self-reported reading, a dashed diamond for a model estimate — so it survives grayscale printing, colour-vision deficiency and a bad screen. The curve is monotone cubic rather than a natural spline, because a natural spline overshoots between points, and in a clinical chart an overshoot draws a value the patient never had. A span touching an estimated point renders dashed along its whole length, so an estimate never blends into measured data.
Clinical components
Result rows
Every flag carries a left rule and an icon and a text label. Colour never works alone. Every value sits on a solid surface with tabular numerals and its reference range — a number without its range is not information.
Prescription item
Dose, strength and frequency are never abbreviated into ambiguity — "twice a day, after food", never "BD PC". The allergy banner is undismissable on clinical screens.
Department marks — all 32
Drawn as one coherent set rather than sourced individually, because they are the primary wayfinding device across thirty-two departments and have to read as siblings at 20 pt.
Emergency
The emergency surface is immutable: solid material, never glass, no motion, no network dependency, z-index 900 so it renders above sheets and modals. It cannot be A/B tested, feature-flagged, personalised, hidden or reordered. In this prototype 911 is displayed but never a live tel: link — a click-through demo dialling a real emergency service is a genuine incident.
States
When a test is done, the result will appear here — usually within 24 hours.
The connection dropped while fetching your reports. Nothing was lost — try again, or carry on and come back later.
Error copy follows one formula: what happened → why → what to do next → escape hatch. Never a stack trace, never a raw code; the trace ID lives in a copyable detail row for support.