Microsoft Power Platform Services
Akita’s Power Platform services help organisations streamline processes, build tailored low-code apps, automate workflows, integrate data, deliver real-time insights and provide ongoing support to improve efficiency and decision-making.
Features
- Low-code app creation with Power Apps
- Automated workflow orchestration with Power Automate
- Data visualisation dashboards with Power BI
- Custom portal and website building with Power Pages
- Centralised Dataverse data storage
- Consultancy, development & support services
- AI-powered enhancement tools
- Cross-platform mobile accessibility
- Real-time analytics capabilities
- Integration with Microsoft ecosystems (365, Dynamics)
Benefits
- Accelerates digital transformation through rapid low-code application delivery
- Automates manual processes to reduce operational costs and rework significantly
- Improves productivity with intuitive apps aligned to real workflows business
- Integrates data securely across Microsoft 365, Dynamics, and systems seamlessly
- Enables faster decisions using real-time insights and dashboards for leaders
- Delivers scalable solutions that grow with organisational complexity and demand
- Strengthens governance, security, and compliance across apps and data estates
- Empowers teams with secure mobile access to critical tools anywhere
- Streamlines collaboration by connecting workflows across systems
- Drives measurable ROI
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 4 1 2 9 0 5 2 9 6 4 8 1 1 7
Contact
AKITA SYSTEMS LIMITED
Akita
Telephone: 0330 058 8000
Email: info@akita.co.uk
About the service
- Service categories
-
Application Development and Deployment
Application platforms
- Model driven application platforms
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Power Platform extends Microsoft 365, Azure Active Directory, Business Cenrtal, and Dynamics 365 applications - or can standalone. It also integrates with Microsoft Teams, SharePoint, and Outlook to enhance collaboration, identity management, automation, and data connectivity across the Microsoft cloud.
- Cloud deployment model
- Public cloud
- Service constraints
- Power Platform operates on Microsoft’s cloud platform, so planned maintenance, release waves and security updates are controlled by Microsoft’s schedule. Customisations must align with supported APIs and update policies. Service performance depends on internet connectivity and supported browsers. Certain integrations or legacy on-premise components may require additional configuration. No offline deployment option is available.
- System requirements
-
- Modern browser such as Edge, Chrome or Safari.
- Stable internet connection for cloud access.
- Azure Active Directory accounts for authentication.
- Microsoft 365 licences for Outlook integration.
- Supported operating systems on user devices.
- Enabled cookies and JavaScript in browsers.
- Updated mobile OS for Dynamics mobile apps.
- API access permissions for integrations.
- Sufficient device memory for browser performance.
- Optional Power Platform licences for automation features.
User support
- Email or online ticketing support
- Yes
- Support response times
- We provide responses within one working hour for standard tickets. Critical issues receive immediate triage. Weekend and bank holiday responses follow our on-call schedule with longer response times depending on severity. All updates are provided through our ticketing portal and email notifications.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We provide Standard and Enhanced support levels. Standard includes ticketing, email support and one hour response within business hours. Enhanced adds extended hours coverage and priority routing. All support costs are published in our G Cloud rate card. A technical account manager or cloud support engineer is available under the Enhanced support level.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We help users get started through guided onboarding, user documentation and remote training. New environments can be provisioned with baseline configurations, sample data and security roles to support early adoption. Online training sessions cover navigation, record management, dashboards and core processes. We also provide role based training for administrators and customisers.
User documentation includes quick start guides, feature walkthroughs and links to Microsoft’s learning resources. Optional onsite training and floor walking can be arranged if required. Our support team assists with initial setup, access management and configuration tasks to help users become productive quickly. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Users can extract their data through the standard Dynamics 365 export tools, including Excel exports, data export services and the Dataverse API. Administrators can bulk export tables, records, attachments and audit logs using the export wizard or by connecting through Power Platform data connectors. Solution export can also be used to extract customisations and configuration components.
If required, we support structured data extraction using automated API scripts or scheduled exports to secure storage locations. Users retain full control of their environment during the extraction period. Once data is exported and confirmed, the environment can be deprovisioned in line with the buyer’s offboarding requirements. - End-of-contract process
-
At the end of the contract we provide guidance on data extraction, user access changes and environment closure. Users retain access to their Dynamics 365 environment for an agreed transition period to complete exports. Support for standard offboarding activities, including advice on extraction methods and confirming deprovisioning, is included in the contract price.
Activities requiring extended consultancy, such as large scale scripted exports, complex data transformation, migration into new systems or recreating integrations, are chargeable at published rates. Once offboarding is complete and confirmed by the buyer, the service is deactivated in line with Microsoft’s termination process. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- He mobile app provides streamlined access to core Dynamics features such as viewing records, updating activities and managing cases. Some advanced configuration, administration tasks and customisation features are only available on the desktop browser version. The mobile interface is optimised for touch input and quicker field updates but offers reduced screen layout options compared to desktop.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service provides a web based interface with role specific dashboards, navigation panels and customisable forms. Users can access records, workflows, reports and administration settings through a browser. The interface supports search, filtering and inline editing, with permissions controlling available features.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Dynamics 365 is designed and tested by Microsoft using assistive technologies including screen readers, keyboard navigation tools, high contrast modes and voice input. Accessibility reviews validate compatibility with Narrator, JAWS and NVDA. User testing ensures forms, buttons and navigation elements remain usable with alternative input methods and adaptive devices.
- API
- Yes
- What users can and can't do using the API
-
Users can use the Dynamics 365 Web API and Dataverse API to create, read, update and delete records, trigger workflows and integrate external systems. They can configure authentication through Azure Active Directory and automate processes by connecting to Power Platform tools. Users can also query data, manage entities and update field values programmatically.
Users cannot perform core administrative setup, change system level security roles or manage environment level settings through the API. Certain metadata changes, such as solution imports, require the admin interface. API usage is subject to Microsoft throttling limits and requires correct permissions to access specific data. - API documentation
- Yes
- API documentation formats
-
- HTML
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users can customise entities, fields, forms, views, dashboards and business process flows. They can also modify workflows, automation rules, security roles and page layouts. Custom branding, terminology and user interface elements can be adjusted to match organisational needs.
Customisation is completed through the Dynamics 365 admin centre and Power Platform tools. Users can add new tables, edit existing data structures, design automated flows, build custom apps and extend functionality using plugins or Power Automate. Solution packaging allows controlled deployment between environments.
Only users with the appropriate administrative or customiser permissions can make changes. End users can personalise dashboards, views and workspace layouts but cannot modify system level components.
Scaling
- Independence of resources
- Dynamics 365 runs on Microsoft’s multi tenant cloud platform, which allocates compute, storage and network resources independently for each environment. Microsoft monitors capacity and automatically scales underlying infrastructure to maintain performance. Throttling controls protect service stability by preventing any single tenant consuming excessive resources. This ensures one buyer’s activity cannot degrade another’s service.
Analytics
- Service usage metrics
- Yes
- Metrics types
- We provide metrics on user activity, licence usage, storage consumption, API calls, system performance and capacity. Administrators can view audit logs, environment health, failed operations and workflow performance. Metrics also show record volumes, mailbox throughput and integration activity to help monitor adoption and identify issues.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can export data using the standard Dynamics 365 export tools, including Excel export, advanced find export and data export service. Administrators can extract bulk records, attachments and audit data through the Dataverse API or Power Platform connectors. Solution export is available for configuration components. API based scripted exports can be used for large datasets or automated extraction.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XML
- Excel Open XML (XLSX)
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Excel Open XML
- JSON
- XML
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- Other
- Other protection within supplier network
- Data within the service is protected through encryption at rest using AES 256, strict role based access controls and logical separation of each tenant’s data. Microsoft’s private backbone network isolates internal traffic from the public internet. Continuous monitoring, threat detection, network segmentation and secure service boundaries prevent unauthorised access. All operations follow Microsoft’s security, auditing and compliance controls
Availability and resilience
- Guaranteed availability
- Dynamics 365 operates under Microsoft’s financially backed uptime SLA. The service is designed to provide high availability through redundant infrastructure and automated failover across Microsoft’s cloud platform. If Microsoft does not meet its stated monthly uptime commitments, service credits are applied to the buyer’s subscription in line with Microsoft’s SLA policy. Availability is monitored continuously and incidents are reported through the service health dashboard. This approach ensures buyers receive a consistent and reliable service with clear compensation mechanisms if availability falls below the guaranteed level.
- Approach to resilience
-
Dynamics 365 is delivered on Microsoft’s cloud platform, which is designed for high resilience through geographically distributed datacentres, redundant infrastructure and automated failover. Application components are replicated across multiple availability zones to maintain service continuity during hardware, network or facility level issues. Data is stored on resilient storage with built in redundancy and continuous monitoring.
Microsoft’s global backbone network isolates internal traffic and provides resilient routing. Security, capacity and performance are actively monitored, with automated systems able to scale resources and recover services quickly. Detailed architectural resilience information is available on request in line with Microsoft’s published documentation and compliance commitments. - Outage reporting
- Outages are reported through the Microsoft Service Health Dashboard, which provides real time status updates for Dynamics 365. Administrators receive service notifications through the Microsoft 365 message centre and can configure email alerts for incident updates. API access to service health information is also available for integration with monitoring tools.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- Users authenticate through Azure Active Directory using secure OAuth based sign in. Authentication supports username and password, multifactor authentication and passwordless options such as authenticator apps or Windows Hello. Organisations can enable identity federation with their existing provider to allow single sign on. Conditional access policies can enforce MFA, device compliance and location based controls. Access tokens are issued securely and refreshed automatically.
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted through role based access controls in Azure Active Directory, ensuring only authorised administrators can view or modify settings. Privileged roles require MFA and can be limited through conditional access policies. Support channels are restricted to verified contacts and authenticated users. Our support team accesses customer environments only with approved permissions, and all actions are logged and monitored.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
- Management access is authenticated through Azure Active Directory using secure OAuth sign in. Administrators authenticate with username and password plus multifactor authentication or passwordless options where enabled. Organisations can use identity federation to provide single sign on and enforce conditional access policies such as device compliance or location controls. Privileged roles require elevated permissions managed through Azure AD.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Security policies aligned to ISO 27001 and Cyber Essentials Plus
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Configuration items and service components are tracked throughout their lifecycle using Microsoft’s configuration management databases and automated inventory systems. All changes follow Microsoft’s documented change management process, including classification, security assessment, validation and approval before deployment. Updates are tested in controlled environments and reviewed for potential security, performance or availability impacts. Only authorised personnel can implement changes and all activity is logged, monitored and audited to maintain service integrity.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We use Microsoft’s continuous vulnerability management processes, which include automated scanning, threat intelligence monitoring and security assessments across all service components. Potential threats are evaluated through Microsoft’s Security Response Center, global threat intelligence feeds and industry vulnerability disclosures. Patches and updates are prioritised based on severity and deployed through Microsoft’s controlled release pipelines, often within hours for critical issues. All activity is monitored and audited to maintain service security.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We use Microsoft’s protective monitoring systems, which continuously analyse logs, network activity and authentication patterns to identify potential compromises. Alerts are generated through automated threat detection tools, including anomaly detection and behavioural analytics. When a potential compromise is detected, Microsoft’s security teams investigate immediately and apply containment actions. Critical incidents receive rapid response, often within minutes, with remediation, patching or service isolation applied as needed. Buyers are informed through service health notifications where relevant.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We follow Microsoft’s incident management processes, which include predefined procedures for common events such as service degradation, security alerts and platform outages. Incidents are logged, assessed and prioritised through Microsoft’s global operations centre. Users can report incidents through our support desk or ticketing system. Incident updates and resolutions are communicated via the Microsoft Service Health Dashboard and email notifications. Formal incident reports can be provided on request, including root cause analysis for major issues.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- British Assessment Bureau (UKAS accredited)
- ISO/IEC 27001 accreditation date
- Friday 18 January 2019
- What the ISO/IEC 27001 doesn’t cover
- The ISO/IEC 27001 certification does not cover customer-owned systems or infrastructure not managed by Akita Systems Limited, physical security controls at customer premises, end-user devices not under Akita management, or non-IT business activities outside the defined scope of IT support, cloud services, and hosted and recovery services.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- British Assessment Bureau (UKAS accredited)
- ISO 9001 accreditation date
- Thursday 23 April 2015
- What the ISO 9001 doesn’t cover
- The ISO 9001:2015 certification does not cover activities outside the defined scope of IT service delivery, including non-IT business operations, customer-owned systems or processes not managed by Akita Systems Limited, services delivered entirely by third parties outside Akita’s quality management system, and physical site operations at customer premises where Akita does not have operational control.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 56073cca-376a-486b-a991-0f76b99f23b2
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- Cc55b424-1c83-4f89-8550-44e6b24ec430
- Other security certifications
- No
Social value
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement