HP Workforce Experience Platform (WXP)
HP Workforce Experience Platform (WXP) is a cloud-based, AI-enabled Digital Employee Experience (DEX) platform that helps organisations understand, manage, and improve how employees experience their technology. It gives IT teams deep visibility into the health, performance, and usability of devices, applications, and digital services used in modern, hybrid work environments.
Features
- Cloud-Native, OS-Agnostic and Scalable Architecture
- In-Band & Out-of-Band Remote Management
- Advanced Reporting, Dashboard and Experience Scoring
- Employee Sentiment & Pulse Surveys
- Deep Integration with Enterprise IT Ecosystems
- AI-Driven DEX Analytics
- Proactive & Automated Detection and Remediation
Benefits
- Automate Hardware and Software Asset Management
- Cut EUC-related Helpdesk Calls by up to 40%
- Shift from a Break-fix to Predictive (Fix-Before-Fail) Maintenance Model
- Lower Service and Carbon Costs with Analytic-driven Maintenance
- Improve Customer/User Experience and Perception of IT
- Automate ticket logging into your ITSM tool
- Prevent under/overprovisioning by right-sizing devices to workloads
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 0 3 2 1 4 1 1 2 5 6 3 0 9 2
Contact
DESK TOP PUBLISHING MICRO SYSTEMS LIMITED
Howard Hall
Telephone: 0113 276 0210
Email: tenders@dtpgroup.co.uk
About your service
- Service categories
-
Systems Infrastructure Software
Endpoint management
Output management
- Device Management
- Print Management
Client endpoint management
- Unified Endpoint Management
- PC Life-Cycle Management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
• Agent-based: Requires HP Insights agent installation (Windows, Mac, Android supported; no iOS agent)
• Internet-dependent: Continuous connectivity required for cloud platform communication
• HP peripheral monitoring: Advanced monitoring primarily for HP-branded printers/peripherals
• Remote-only delivery: On-site support incurs additional fees
• Feature maturity: Some advanced features (location-based analytics, real-time dashboards) are in development. - System requirements
-
- Windows: Windows 10 20H2 or later; Windows 11
- MacOS: Cataline 10.15 or later
- Chrome OS: HP Chromebook only; ChromeOS v76 or later
- Chrome OS: Requires Chrome Education or Enterprise Upgrade
- Mobile Devices: Android Version 9.0+; IOS Version 13.7+
- Desktop or Mobile Browser
- HP Insights Agent Deployment
- Network Connection
User support
- Email or online ticketing support
- Yes
- Support response times
- Within 1 working day.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
• We provide Standard HelpDesk Support FOC for the duration of service.
• Remote onboarding, deployment and support FoC for the duration of service.
• On-site onboarding, deployment and support at additional cost.
Would this be for example:
- Standard Helpdesk Support (included FOC - unlimited incidents)
- Remote deployment and/or support (FoC up to X days)
- On-site deployment and/or support (£x per day) - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
DTP provide multiple ways to support users starting our service including both onsite and remote training, documentation and a nominated technical resource who will help setup, deploy, and maintain the service throughout the service duration.
There is also online based training, and webinars that users can join throughout the service duration to learn more about upcoming releases and features. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Users can utilise the reporting and export features within the web-based portal to extract all data before the service ends.
- End-of-contract process
-
At the end of Contract, DTP can support and provide customer documentation for removing/unenrolling the WXP agent from all devices. The customer can request final reports from WXP, which DTP or the customer themselves can generate.
Customer data held within the WXP tenant will be permanently deleted after 90-days from contract termination. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
WXP is delivered as a cloud‑native, browser‑based platform providing:
• Device health and performance
• Application stability
• Security posture
• Employee sentiment and experience scores (DEX)
• Fleet trends and refresh insights - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
HP has conducted formal accessibility interface testing for HP Workforce Experience as part of its Section 508 conformance assessment, documented through a VPAT® 2.5 Accessibility Conformance Report (dated 24 March 2025).
Testing was carried out using HP’s proprietary accessibility test methodology and evaluated the user interface against the Revised Section 508 standards, incorporating WCAG 2.0 Level A and Level AA success criteria for web-based software and electronic support documentation.
The testing covered key interface areas, including:
• Non-text content (e.g. images and icons)
• Keyboard navigation and focus management
• Colour use, contrast, and text resizing
• Form labels, error identification, and instructions
• Page structure, headings, links, and reading order
• Interaction with assistive technologies, where applicable - API
- Yes
- What users can and can't do using the API
-
HP’s Workforce Experience Platform APIs are designed for insight, analytics, and integration, not direct device control.
What you can do:
Customers can programmatically read and query workforce and device experience data, including hardware and software inventory, device health, performance events (such as crashes), security posture, and aggregated employee sentiment. Using the WXP Query Language (WXPQL), teams can filter, analyze, and export data at scale. The APIs are intended to integrate WXP insights into other enterprise systems like ServiceNow, Power BI, or data platforms, helping break down data silos and enrich IT workflows. Access is secured via OAuth and role-based permissions, with defined daily rate limits.
What you can’t do:
The APIs do not provide low‑level device management or real‑time control. You cannot push arbitrary commands, replace MDM solutions, bypass role-based access controls, or stream unlimited real-time telemetry. Many remediation actions, AI recommendations, and dashboards remain platform-managed rather than API-driven. API access also requires a paid WXP subscription and an assigned Developer role. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
Buyers of HP’s Workforce Experience Platform (WXP) can customise the service, though the level of customisation depends on the plan and add‑ons purchased.
Customers can tailor dashboards, analytics and reports to focus on the KPIs that matter most to their organisation, such as device health, application performance, security and employee sentiment. WXP also allows configuration of custom alerts, automation rules and proactive remediations, helping IT teams control how issues are detected and resolved.
The platform supports third‑party integrations (for example with ITSM tools and endpoint management platforms), enabling WXP to fit into existing IT ecosystems rather than replacing them. Buyers can also configure employee sentiment surveys, customise support and help experiences (such as routing users to a company helpdesk), and choose between self‑managed or partner‑managed deployment models.
However, WXP remains a cloud SaaS platform, so customers cannot change the underlying architecture or core AI models. Advanced customisation options increase with higher‑tier plans and optional add‑ons.
Scaling
- Independence of resources
- WXP is built on AWS infrastructure designed for enterprise scale, currently supporting 48 million endpoints and processing 1.9TB of new data daily. The platform runs on 1,000+ server instances with 200+ microservices, using Lambda and Medallion architectures that combine batched and real-time processing for elastic scalability during demand spikes.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Real time analytics and reporting is available to provide customers with service information such as:
- Number of registered devices by type
- Number of active licences and full licence details
- Number and identity of registered Admin users and roles/privileges - Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Hewlett Packard Inc.
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Users export data by utilising the export button features within the web-based portal or by using the reporting capability.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Xlsx
- Data import formats
-
- CSV
- Other
- Other data import formats
- Xlsx
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- WXP operates under the HP Workforce Experience Platform Service Level Agreement. Platform uptime targets are typically >99.5% availability, with API uptime targeting 99.9%.
- Approach to resilience
- WXP is hosted in two AWS regions for geographic redundancy. The architecture uses over 300 EMR jobs, 200+ microservices, and Lambda/Medallion architectures providing both real-time and batch processing redundancy. The platform includes automated failover capabilities and 24x7x365 monitoring.
- Outage reporting
-
HP informs customers about Workforce Experience Platform (WXP) outages through multiple channels:
Status Page – A public portal shows real-time service health, incidents, and outages.
Pulse Notifications – Admins can send pop-up alerts to end users’ Windows devices for scheduled maintenance or unexpected issues.
Configurable Alerts – IT admins receive email and in-product notifications for incidents, which can also be extended to users.
Device-Level Pop-Ups – Notifications appear directly on enrolled devices for service-related events.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Role Based Access / Principle of Minimum Privilege.
Granular permissions structure by role. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We operate a formal information security management framework aligned with ISO/IEC 27001, for which we hold independent certification. Our policies and processes are designed to protect the confidentiality, integrity and availability of data throughout the provision of our Infrastructure Software as a Service offering.
Key policies include Information Security, Risk Management, Access Control, Secure Configuration, Incident Management, Business Continuity, Supplier Security and Data Protection. Policies are reviewed at least annually and following material changes.
Information security risks are identified and assessed through regular risk assessments covering infrastructure, applications and supporting services. Controls are implemented proportionately and tracked through a documented risk treatment plan.
Access to systems is role-based, authorised and logged, with least-privilege principles and strong authentication enforced. Infrastructure is securely configured, regularly patched and monitored, with endpoint and network protections implemented in line with Cyber Essentials.
Security incidents are managed through a documented incident response process. All staff receive mandatory information security and data protection training. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Changes to services and features follow secure software development practices, including security risk reviews prior to launch. Developer access to production environments is via explicit access system requests, which are subject to stringent review and authorisation.
Teams set bespoke change management standards underpinned by standard guidelines.
All production environment changes are reviewed, tested and approved. Stages include design, documentation, implementation (including rollback procedures), testing (non-production environment), peer to peer review (business impact/technical rigour/code), final approval by authorised party.
Emergency changes follow incident response procedures. Exceptions to change management processes are documented and escalated to management. - Vulnerability management type
- Undisclosed
- Vulnerability management approach
-
HP Security performs vulnerability scans on the host operating system, web applications, and databases in the cloud-hosted environment. Identified vulnerabilities are monitored and evaluated. Countermeasures are designed and implemented to neutralise known/newly identified vulnerabilities.
HP Security monitors newsfeeds/vendor sites for patches and receives vulnerability intelligence via trusted industry sources. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
HP deploys monitoring devices to collect information on unauthorised intrusion attempts, usage abuse, and network/application bandwidth-usage. Devices monitor:
• Port scanning attacks
• Usage (CPU, processes, disk utilization, swap rates, software-error generated losses)
• Application metrics
• Unauthorized connection attempts
HP Security controls are reviewed by independent external auditors during audits for our ISO 27001 and Cyber Essentials Plus compliance. - Incident management type
- Supplier-defined controls
- Incident management approach
-
HP adopts a three-phased approach to manage incidents:
1. Activation and Notification Phase
2. Recovery Phase
3. Reconstitution Phase
To ensure the effectiveness of the Incident Management plan, HP conducts incident response testing, providing effective coverage for the discovery of defects and failure modes as well as testing the systems for potential customer impact.
The Incident Response Test Plan is executed annually. It includes multiple scenarios, potential vectors of attack, the inclusion of the customer role in reporting and coordination, and varying reporting/detection channels. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
DTP can offer a no obligation PoC for 60-days.
It provides the Pro version of the WXP solution for a maximum of 500 seats.
DTP assign a technical resource to support the implementation and deployment of WXP, with jointly agreed success criteria that are measured throughout the PoC.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Peers Quality Assurance Limited (UKAS accreditation No. 9940)
- ISO/IEC 27001 accreditation date
- Thursday 9 October 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Peers Quality Assurance Limited (UKAS accreditation No. 9940)
- ISO 9001 accreditation date
- Tuesday 29 July 2025
- What the ISO 9001 doesn’t cover
- N/A
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 480de455-649d-4dc0-a2d7-4d5daa55b930
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Working conditions which promote an inclusive working environment and promote retention and progression
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-