Softworks SaaS Workforce Management System
Workforce Management System for Healthcare, NHS, Care Homes, Public Sector and Commercial; Rostering. eRostering. Rota and Rotas. Scheduling. Time & Attendance and Clocking Machines. Annual Leave and Absence Management. HR Information System. Reports and Reporting. Management Dashboards.
Features
- Auto Rostering. eRostering. Scheduling Rotas.
- Real Time Reporting and Real Time Dynamic Management Dashboards
- Time and Attendance and Electronic Time Sheets
- API and Automated CSV Integrations with Third Party Software
- Payroll Exports and Integrations
- Annual Leave and Absence Management
- Apply for Overtime and Bank Shifts
- Configurable Real Time System Alerts to Staff and Managers
- Clocking Machines
- Mobile App to View, Request, Manage, Shifts, Holidays, HR Info
Benefits
- Save Admin Time and Money Preparing Rotas/Schedules/Timesheets
- Reduce Agency Staff Costs
- Raising Staff Engagement through Surveys and Mobile App
- Configurable Real Time System Alerts to Staff and Managers
- Configurable Holiday Rules preventing overbooking Holidays
- Business Pay Rules/Calculations Configured to produce Accurate Timesheets
- Configurable Annual Leave and Absence Policies and Rules
- Create and store Electronic Forms and Upload Staff Documents
- GDPR Compliant, ISO9001, ISO27001
- System is Scalable as Businesses Grow
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 1 5 0 8 7 5 5 4 0 5 9 8 7 9
Contact
Softworks Computing (UK) Ltd
<removed>
Telephone: <removed>
Email: <removed>@3405d643-a006-4469-9079-2d1c9be721a0.com
About your service
- Service categories
-
Application Development and Deployment
Application development
- Software construction components
- Business rules management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- Customers will be notified about planned maintenance in advance. Softworks will normally action such maintenance out of typical business hours. Support is not limited and extends to System and Hardware support.
- System requirements
-
- Access the Softworks system simply via a standard web browser
- Existing Security setups supported. Single Sign-On: Azure AD, OKTA, ADFS
User support
- Email or online ticketing support
- Yes
- Support response times
- Our Support Teams are available 8.00am to 6.30pm Monday to Friday. Incident response times (i.e. the time taken to acknowledge receipt of an incident) are determined by the severity of the problem when registered with Softworks. Critical: Immediate Call, 2 Hour Update. Urgent: Immediate Call, 4 Hour Update. High: Immediate Call, 24 Hour Update. Medium Non Business Critical: 4 Hour Response, Weekly Update. Low: 8 Hour Response, Weekly Update.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes
- Support levels
- Support levels provided determined by the support required. If hardware support outside of the warranty period is required on site, a daily rate of £1200 is charged. All remote support is provided free of charge and covered within the annual licenses charged for. Again, case by case and chargeable unless sanctioned free of charge/discounted, where other specialised onsite support is required for example IT or Engineers, Softworks would standardly charge a daily rate of £1200.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
-
Initially we would assign our planned implementation team to commence kick off meetings, scoping, design, configuration and system build. Having reviewed the requirements document, we understand what success will look like. Throughout the duration of the project, we will use project tracking tools to outline all stages of the project, agree all milestones, communication process and ensure we work together in making this a success. All supplementary documentation required will be provided by Softworks, such as risk registers, sample communication plans, scoping documents, training manuals, training videos and project success documents.
The Softworks project plan can be broken down into key milestones, these are outlined below.
Project initiation
Scoping
Desing
Development
Internal Testing
Delivery
Training
UAT
Go Live - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
Softworks application has several tools to extract data at the end of the contract, including:
Built in subject access request reports in the system
Reports which can be configured to export any required data in various formats
Softworks provide a backup of the database if required also
Softworks are happy to support any bespoke offboarding requirements as needed also - End-of-contract process
-
Softworks contracts are usually designed based on the number of users on the system.
Upon the contract ending, Softworks will contact the client to discuss renewal options. The contract includes all implementation, support, maintenance, hosting, backups and infrastructure.
Softworks notify the client several months in advance of upcoming renewals
Assuming the client renews, this service will continue uninterrupted
If the client decides to end the contract at this point we would support the client in getting any required data - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Softworks documentation is all provided to the client upon commencement of the project
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- While the core functionality of Softworks remains consistent across both platforms, there are some key differences in how they are managed and secured to provide the best experience for your team. Both our webserver and mobile app allow for client branding as standard, so the UI/UX can follow your specific guidelines. For both platforms, you don't have to manage two different sets of permissions. We use granular user profiles that you define, which dictate exactly what a user can see or do. Mobile devices are often personal (BYOD), no access to any additional data from the user's phone is permitted.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Access to service interfaces, for both users and providers, is strictly limited to authenticated and authorized individuals. You can configure user accounts to ensure every action is linked back to a specific person. Access can be restricted depending on the network being used i.e externally or internally. IP Whitelisting also available. Access to specific system functions can be limited by a Least Privelege Modal, using unique accounts and Two-Factor Authentication (2FA) where available. For technical integrations, we provide a SOAP API interface that handles data inputs and outputs securely.Compliance with OWASP Top 10 and NIST frameworks.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Access our workforce management solution through a fully web-based interface or our mobile application,. Users typically log in via a standard web browser, and we ensure that all traffic transiting the network is adequately protected against eavesdropping via HTTPS and TLS 1.2 encryption
- Accessibility testing
- Our applications undergo rigorous security testing, including weekly automated vulnerability scans and annual penetration tests conducted by CREST-certified third parties. During our Product Delivery Lifecycle, every change or new development is reviewed against the NIST and OWASP Top 10 security frameworks to ensure the interface is hardened against threats. During the implementation phase, we work with clients to ensure the web and mobile interfaces follow their specific branding guidelines. When we update our applications, we log these changes in our VSO system and specifically review how they might impact the confidentiality, integrity, and availability (CIA) of the system, as well as GDPR requirements. We perform automated vulnerability scanning on our applications and infrastructure on a weekly and monthly basis using tools like AppCheck NG. We integrate security checks directly into our UI Path testing system. Firewalls are equipped with Intrusion Detection (IDS), Data Loss Prevention (DLP), and virus detection to monitor and protect against network-based attacks.
- API
- Yes
- What users can and can't do using the API
-
Setting Up the Service
Authentication. All APIs and integrations are strictly authenticated before a connection can be established. With API endpoints for general monitoring or information, you have the option to disable these if not required for specific setups.
Making Changes
You can use our web-based APIs to populate the system with your data,. This is particularly useful for:
• Data Inputs and Outputs: Moving information into or out of the Softworks environment automatically.
• System Population: Using the API as a primary method for feeding data into the platform, alongside other options like CSV imports or manual entry.
• Monitoring: Accessing system information or monitoring status through dedicated endpoints.
Limitations to Consider
There are some limitations and security boundaries you should be aware of:
• Authentication Requirements: Authentication is required to access the system or functionality via the API.
• Administrative Control: Restricting the API's footprint. Unnecessary endpoints can be disabled minimising your attack surface.
• Configuration Scope: In addition to data API data movements, more granular administrative tasks—such as building complex user profiles to define which specific fields can be read or written—are typically managed directly within the application's user profile settings rather than through the API itself. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
What can be customised:
• Branding and UI/UX: Both webserver and mobile app.
• defining granular user access profiles individually to control exactly what staff can see and do down to specific data fields.
• Flexibility to choose authentication mechanisms, such as ADFS, OKTA, Azure AD, or Google Auth. Configurable password complexity
• customisable timeout periods for logouts. Set up real-time alerts for system administrators regarding unsuccessful login attempts.
• Data Retention: Through our "right to be forgotten" module, defining specific retention periods for terminated employee data.
• Custom banner messages to your users on the login interface to share important updates or policy reminders.
How users can customise:
• Major UI and branding customizations are typically discussed and established during the initial implementation.
• built-in tools for administrators to build user profiles, group access by role or region, adjust security settings.
• choose of feeding data into the system: APIs, CSV file imports, manual entry.
• submit Change Requests to our developers to include in a future patch.
Who can customise:
• Your designated administrators
• Softworks Projects/Support Teams assisting your administrators to define complex user profiles/implementing branding.
• line managers able to manage certain access rights for staff.
Scaling
- Independence of resources
- Softworks application is deployed as a single tenant application with a specific environment set up built for that client, ensuring it scales to meet your organisations specific requirements. We complete extensive stress testing on our application also
Analytics
- Service usage metrics
- Yes
- Metrics types
- Softworks can provide reports and usage information in relation to engagement through the Softworks mobile app for end users
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
Softworks provide built in subject access request reports for users
Softworks also have a suite of reporting tools available for extraction of data
Softworks also provide backups of the database as required
Softworks do also have API's for data extraction - Data export formats
-
- CSV
- Other
- Other data export formats
-
- API
- Database backups
- Data import formats
-
- CSV
- Other
- Other data import formats
- API
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Softworks support a guaranteed availability of 99.9% for all users excluding planned outages,
This is reported monthly across all clients - Approach to resilience
-
Softworks use state of the art data centres who are certified.
Our environments follow a specific build however are customised upon client request
We use state of the art monitoring tools to measure all usage and ensure resilience levels are maintained
We will set up a failover redundancy to a secondary data centre - Outage reporting
- Softworks use email alerts to all clients to report any outages
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
Softworks is designed as an application where every user has specific access and authorisation levels which are completely configurable
In this, every screen can be defined for read and write access.
We can utilise MFA/ 2FA, SSO or AD if required. If using Softworks default application, we have in place password compliance rules, such as frequency of change, minimum password length, complexity, special characters and the use of 2FA - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Softworks have full ISMS reporting
We provide annual refresher training on our policies
We have all areas of our processes documented
We have a documented training process
We use an internal LMS system to ensure training is up to date - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Softworks are both ISO 9001 and ISO 27001 certified.
Any product changes are stored in Devops and assessed for risk. We develop in line with NIST and OWASP best practices
We run automated vulnerability scanning on our application to assess any potential risks prior to release
For major releases, pen testing is done with a CREST certified third party
Every change is version controlled, tracked, tested and audited - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Softworks are both ISO 9001 and ISO 27001 certified.
Any product changes are stored in Devops and assessed for risk. We develop in line with NIST and OWASP best practices
We run automated vulnerability scanning on our application to assess any potential risks prior to release
For major releases, pen testing is done with a CREST certified third party
Every change is version controlled, tracked, tested and audited
Patches are deployed monthly, unless a major vulnerability is discovered at which point is is an immediate release - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Softworks are both ISO 9001 and ISO 27001 certified.
Any product changes are stored in Devops and assessed for risk. We develop in line with NIST and OWASP best practices
We run automated vulnerability scanning on our application to assess any potential risks prior to release
For major releases, pen testing is done with a CREST certified third party
Every change is version controlled, tracked, tested and audited
Softworks use Darktrace for monitoring of abnormal activity also - Incident management type
- Supplier-defined controls
- Incident management approach
-
We have pre defined processes to flag any incidents through our SLAs.
Users are notified or incidents via email and where required, direct phone call
Incident reports are provided through detailed root cause and remediation plans - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Amtivo (Ireland)
- ISO/IEC 27001 accreditation date
- Monday 11 August 2025
- What the ISO/IEC 27001 doesn’t cover
-
The Information Security Management System of Softworks Ltd covers the design,
development, delivery, maintenance, and support of its workforce management solutions,
offered as on-premise or hosted (SaaS) for clients. This scope includes all relevant information
assets, processes, and technologies within Softworks Group and applies to its staff globally. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Amtivo (Ireland)
- ISO 9001 accreditation date
- Friday 13 June 2025
- What the ISO 9001 doesn’t cover
-
The scope of Softworks' Quality Management System applies to all
products and services offered by our organisation including design,
development, testing, implementation, training and post-implementation
activities such as customer support, change management and
maintenance. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
- Plans for positive actions with community groups.
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-