Time Keeper
Time Keeper is a cloud-based timesheet and time recording service that helps organisations capture, approve and report staff and contractor time. It supports tracking across projects, programmes and operational activities, providing auditable records and reporting to support accountability and compliance.
Features
- Time recording against projects, programmes and operational activities
- Configurable approval workflows with delegation and audit trails
- Support for hybrid, remote, office and field working
- Mobile-responsive access for desktop, tablet and mobile devices
- Role-based access control aligned to organisational permissions
- Bulk time entry with recurring templates and calendars
- Timer-based and manual time entry options
- Reporting dashboards with export and integration capabilities
- Audit logging of time entries, approvals and changes
- Configurable task catalogues without custom code development
Benefits
- Improve accountability and transparency across time recording activities
- Adapt workflows to organisational processes without custom development
- Support audit, compliance and freedom of information reporting requirements
- Monitor hybrid, remote and flexible working arrangements effectively
- Reduce security and operational risk using existing cloud controls
- Deploy quickly within existing organisational cloud environments
- Reduce maintenance effort by avoiding custom code dependencies
- Support data residency requirements aligned to UK public sector needs
- Improve visibility of resource utilisation for planning and forecasting
- Enable faster management reporting and informed decision making
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 0 3 4 3 1 0 4 1 1 0 9 4 8 9
Contact
ULTRA DYNAMIX LTD
Muhammad Umer Ishtiaq
Telephone: +61 424060800
Email: umer.ishtiaq@ultradynamix.com
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Model driven application platforms
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Microsoft Power Apps and Microsoft Dataverse
- Cloud deployment model
- Public cloud
- Service constraints
- The service requires appropriate Microsoft Power Apps and Dataverse licences and sufficient environment capacity. Supported browsers include Edge, Chrome, Firefox and Safari (latest versions). Support is provided 9am to 5pm GMT, Monday to Friday, excluding UK public holidays. Planned maintenance is communicated at least seven days in advance and scheduled outside standard business hours where possible. Configuration limits may apply based on the selected service tier.
- System requirements
-
- Microsoft Power Apps licence appropriate to user and usage volumes
- Microsoft Dataverse environment with sufficient database capacity
- Modern web browser supporting current HTML5 standards
- Internet connectivity for secure cloud service access
- Organisational Microsoft identity for user authentication and access control
- Administrator permissions to install managed solution packages
- Sufficient API request capacity for expected user activity
- Mobile device running supported iOS or Android operating system
- Power BI licence required for advanced analytics and custom reports
- Secure organisational network configuration allowing outbound cloud connections
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is available 9am to 5pm GMT, Monday to Friday, excluding UK public holidays. Response targets are: Critical incidents within 4 hours, High priority within 8 hours, Normal priority within 24 hours, and Low priority within 48 hours. Requests received outside business hours are responded to the next business day.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
All service tiers include standard support at no additional cost.
STANDARD SUPPORT (All tiers):
Email support and telephone support are available 9am to 5pm GMT, Monday to Friday, excluding UK public holidays. Response targets are: Critical incidents within 4 hours, High priority within 8 hours, Normal priority within 24 hours, and Low priority within 48 hours. Standard support includes access to online documentation, software updates and bug fixes.
PREMIUM SUPPORT (Optional):
Available for £995 per month. Includes all standard support features, prioritised email responses, and quarterly service review calls.
DEDICATED ACCOUNT MANAGER (Optional):
Available for £500 per month. Provides a named account manager, monthly service review meetings, and support with configuration changes.
TECHNICAL ACCOUNT MANAGER / CLOUD SUPPORT ENGINEER (Optional):
Not provided as standard. Available for £500 per month and includes access to a dedicated technical resource for larger implementations.
ONSITE SUPPORT (Optional):
Available at additional cost. Implementation workshops and training sessions are charged at £1,200 per day plus travel expenses, with a minimum two-day engagement. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Users are supported through a structured onboarding process. This includes access to online user guides and setup documentation, remote onboarding sessions to help administrators configure the service, and optional training sessions for end users. Additional onsite training can be provided at extra cost where required.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- At the end of the contract, authorised users can extract their data using built-in export functionality. Data can be exported in common, open formats suitable for archiving or import into other systems. Support is available to assist with data extraction if required.
- End-of-contract process
-
At the end of the contract, access to the service is scheduled for closure in line with agreed notice periods. Users can export their data using standard export functionality during the contract term and up to contract end. After confirmation, customer data is securely deleted in accordance with data retention policies.
The contract price includes standard support and access to data export features. Additional assistance with data extraction, extended access periods, or bespoke transition support can be provided at additional cost if required. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service provides the same core functionality on mobile and desktop. On mobile devices, the user interface is optimised for smaller screens with simplified layouts and touch-friendly controls. Reporting dashboards and configuration activities are easier to use on desktop due to screen size.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a web-based user interface using a modern browser. It provides role-based screens for users, approvers and administrators to record time, submit approvals and view reports. The interface is responsive and adapts to desktop, tablet and mobile devices.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- The service interface has been tested using common assistive technologies including screen readers, keyboard-only navigation and browser accessibility tools. Testing focuses on ensuring content is readable, controls are accessible, and key workflows can be completed without a mouse. Accessibility feedback is incorporated into ongoing interface improvements.
- API
- No
- Customisation available
- Yes
- Description of customisation
- The service can be customised through built-in configuration options rather than bespoke development. Administrators can set up time recording structures, tasks, approval workflows, roles, permissions and reporting views to match organisational processes. Individual users can adjust personal preferences, such as default views, within the access permissions assigned to them.
Scaling
- Independence of resources
- The service is delivered using a scalable cloud architecture that allocates resources dynamically based on demand. Usage is managed to ensure fair performance across customers, with monitoring in place to identify and address any contention. This approach helps ensure one customer’s usage does not adversely affect others.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides usage metrics including numbers of active users, time entries submitted, approvals completed, and activity volumes over time. Reporting also supports visibility of usage by team, project or time period to help organisations monitor adoption and operational usage.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Authorised users can export their data directly from the service using built-in export options. Data can be downloaded in common file formats for reporting, archiving, or transfer to other systems. Support can be provided to assist with exports where required.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is provided with a target availability of 99.9% per calendar month, excluding planned maintenance. Planned maintenance windows are communicated in advance and scheduled outside standard business hours where possible.
If the monthly availability target is not met, customers may request a service credit applied to their next billing period. Service credits are calculated on a pro-rata basis, depending on the level of availability achieved. Credits are the sole and exclusive remedy for failure to meet availability targets. - Approach to resilience
- The service is designed for resilience using a cloud-based architecture that supports redundancy and automated recovery. It is hosted on managed datacentre infrastructure with built-in power, network and hardware resilience. Regular monitoring and backup processes are in place to detect issues and restore service where required. Further details on resilience arrangements can be provided on request.
- Outage reporting
- Service outages and significant incidents are communicated to customers by email. Updates are provided during an incident and once service is restored. There is no public status dashboard or outage reporting API.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces is restricted using role-based permissions so that only authorised administrators can perform configuration and administrative tasks. Support channels are limited to named contacts approved by the customer, and access is authenticated before support actions are taken. Administrative and support activities are logged to support accountability and audit requirements.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Security governance is overseen by a senior individual with organisational authority and is supported by documented security policies and procedures. The approach includes regular risk assessment, secure development practices, access control, monitoring, and periodic security testing. Security considerations are reviewed as part of ongoing service management and change processes.
- Information security policies and processes
- The organisation follows documented information security policies covering access control, data protection, incident management and secure change management. Policies are approved and overseen by a senior individual with organisational authority. Compliance is supported through role-based access controls, staff awareness, regular reviews and security testing. Adherence to policies is monitored as part of routine service management and operational reporting.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Service components are tracked throughout their lifecycle using internal configuration records that identify environments, versions and dependencies. Changes are logged, reviewed and approved by authorised personnel before deployment.
Each change is assessed for potential security and operational impact, including access control, data handling and service availability. Where relevant, changes are tested in a controlled environment prior to release, and rollback options are considered to minimise risk. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Potential threats are assessed through a combination of monitoring, periodic security testing and review of changes to the service environment. Identified vulnerabilities are evaluated based on risk, likelihood and potential impact to confidentiality, integrity and availability.
Security patches and updates are prioritised according to severity. Critical patches are applied as soon as practicable, with lower-risk updates scheduled through the standard change management process and deployed following testing.
Information about potential threats is obtained from cloud platform security advisories, trusted industry sources, vulnerability disclosures and results from external penetration testing and internal reviews. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Protective monitoring approach
Describe your protective monitoring processes.
Include:
how you identify potential compromises
how you respond when you find a potential compromise
how quickly you respond to incidents - Incident management type
- Supplier-defined controls
- Incident management approach
-
The organisation follows documented incident management procedures, including predefined processes for common service and security events. Incidents are categorised by severity and managed in line with agreed response targets.
Users can report incidents through the service support channels, including email or the support ticketing process. Reported incidents are logged, assessed and tracked through to resolution.
For significant incidents, customers are kept informed during the incident and provided with a summary once resolved. Incident reports include details of impact, actions taken and any corrective measures identified. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
-