SS&C Blue Prism WorkHQ
The SS&C Blue Prism WorkHQ PaaS platform combines agent building, agent workflow, API connectors, Human-in-the-Loop and RPA in one service offering. The software (formerly known as Next Gen) transforms the way organisation manage operational and business processes. Deployed non-disruptively, it requires no replacement of systems, software development or system integration.
Features
- Frictionless Agentic Automation of IT & Business Process
- Infrastructure, Application and Process Agnostic
- Infinitely scalable cloud-based Operational Platform
- Agent Building Capability
- Agentic Workflow
- Hundreds of pre-built API Connectors
- Human-in-the-Loop form building
- Includes SS&C Blue Prism RPA functionality
- Integrated Agentic Orchestration, Scheduling and Management
- Extensible platform capabilities to incorporate future enhancements
Benefits
- Reduces operating costs
- Increased efficiency
- 100% accuracy & consistency
- Hyper accelerated digital transformation
- Brings together Agentic, API, Digital and Human workers
- Security, auditory and regulatory compliance (ISO27001/SOC2 Type II)
- Optimised shared digital resource
- Instantly scalable resource on demand
- Industry leading productivity that can execute 24x7x365
- Improved citizen outcomes
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 4 3 5 2 4 5 5 9 8 8 2 3 4 9
Contact
BLUE PRISM LIMITED
Mark Lockett
Telephone: 07917 588254
Email: mark.lockett@sscinc.com
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Model driven application platforms
- Robotic process automation
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- SS&C Blue Prism AI Gateway, SS&C Blue Prism Chorus (BPM)
- Cloud deployment model
- Public cloud
- Service constraints
- Requires access to LLMs via the SS&C Blue Prism AI Gateway - requires on-premise Runtime Resources (Digital Workers) to perform automated processes within the organisation's firewall. Currently hosted on Amazon Web Services.
- System requirements
-
- https://docs.blueprism.com/en-US/bundle/next-generation/page/architecture/architecture.htm
- Access to the SS&C AI Gateway recommended
- Access to a choice of LLMs recommended
User support
- Email or online ticketing support
- Yes
- Support response times
- P1 Issue Response 1hr P2 Issue Response 4hrs Mon-Fri only Enhanced (Business Critical) support with improved SLAs is available at extra cost
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- Production Maintenance and Support gives you peace of mind for all your important processes. You’ll benefit from response service level agreements (SLAs). Business-Critical Maintenance and Support is ideal if you’re automating business-critical processes and need 24x7 live support for high-priority issues. Enjoy a heightened response, target-resolution SLAs
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- There is a free University to learn how to build automated processes available https://university.blueprism.com/
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Through the export or by running a script
- End-of-contract process
- The service stops - if needed users should export their log files
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- Yes
- Compatible operating systems
- Windows
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- Using a web-browser
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
- User Interface tested to WCAG 2.2 A accessibility standard
- API
- Yes
- What users can and can't do using the API
- Please refer to https://docs.blueprism.com/en-US/bundle/next-generation/page/rest-api.htm
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users should build their own automated processes on the platform. Users should build their own Agents and Agent workflows.
Users should build their own forms to manage Human-in-the-Loop.
Scaling
- Independence of resources
- Each customer has a dedicated tenant
Analytics
- Service usage metrics
- Yes
- Metrics types
- The Analytics area allows users with the correct permissions to view and edit dashboards. Dashboards are a collection of tiles which provide a visual representation of information from various data sets.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- No
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- Using the export facilities or by running a script
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
-
- Json
- XML
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
- Any format
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.9% of scheduled uptime within the agreed availability window
- Approach to resilience
- As the platform is based on Amazon Web Services (AWS), it is already resilient, but for extra peace of mind customers can purchase a second AWS data centre to be configured as a high availability service.
- Outage reporting
- Public Dashboard and email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Access restrictions in management interfaces and support channels
- The platform allows for Role Based Access Control (RBAC)
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- SS&C Blue Prism operate an Information Security Management System as part of our ISO27001 certification
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Please refer to https://www.blueprism.com/blue-prism-security/
- Vulnerability management type
- Undisclosed
- Vulnerability management approach
- Security, privacy, and compliance are at the core of our development ethos. Our intelligent automation platform was designed using the latest in security standards and protocols, and we continue to enhance our methods and processes to keep you safe from the latest threats. The list of latest security updates can be found here https://portal.blueprism.com/security-updates
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
- Security, privacy, and compliance are at the core of our development ethos. Our intelligent automation platform was designed using the latest in security standards and protocols, and we continue to enhance our methods and processes to keep you safe from the latest threats. The list of latest security updates can be found here https://portal.blueprism.com/security-updates
- Incident management type
- Undisclosed
- Incident management approach
- Security, privacy, and compliance are at the core of our development ethos. Our intelligent automation platform was designed using the latest in security standards and protocols, and we continue to enhance our methods and processes to keep you safe from the latest threats. The list of latest security updates can be found here https://portal.blueprism.com/security-updates
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Police National Network (PNN)
- Joint Academic Network (JANET)
- Scottish Wide Area Network (SWAN)
- Health and Social Care Network (HSCN)
- Other
- Other public sector networks
- Any network given the correct permissions
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Friday 12 July 2024
- What the ISO/IEC 27001 doesn’t cover
- The Information security management systems (ISMS) for SS&C Blue Prism complies with the requirements of ISO/IEC:27001:2022, for the provision of information security of the central process of design, development, maintenance, support, hosting and delivery of Intelligent Automation software and services. This includes the interface and communication with SS&C supporting functions as per statement of applicability v10.1
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Volunteering opportunities for staff
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-