Appian Case Management for Public Sector
Appian unifies operations across healthcare, defence, policing, and social care using CMaaS. The platform modernises complex case management and service delivery, providing a secure "single view" of citizens and patients. It enables agile, multi-organisational collaboration and mobile fieldwork, ensuring efficient, compliant outcomes for safety, health, and social security administration. APP25GC15
Features
- Remote web and mobile access
- APIs supported for Appian SDK, RPA, Process Model Integration
- Data Fabric: Connects systems virtually without complex data migration
- Case Management: Dynamic case handling for complex government processes
- Real-Time Reporting: Interactive dashboards for instant operational visibility
- AI Process Automation: Orchestrate workflows with AI, RPA, and rules
- Defence Logistics: Secure management of personnel, equipment, and assets.
- Inter-Organisational Data: Secure data sharing between police, health, and care.
- Healthcare Operations: Patient journey tracking and clinical workflow orchestration.
- CMaaS architecture approach combined with extensible data schemas
Benefits
- Efficiency: The right data at the right time and place
- RAD: For quick, efficient development of applications, significantly reducing time
- Unify Data: Access a 360-degree view of data without migration.
- Quality: Standardise processes for consistent, compliant case outcomes
- Visibility: Real-time performance monitoring for informed decision making
- Operational efficiency: Automate manual tasks to significantly reduce processing time
- Agility: Rapidly adapt operations to changing legislative requirements.
- Security: Defence-grade security for sensitive operational data.
- Mobility: Empowers frontline staff with critical data anywhere.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 7 3 4 4 7 4 8 2 8 5 4 0 5 8
Contact
Appian Software International LLC
Peter Corpe
Telephone: 07748 105950
Email: peter.corpe@appian.com
About your service
- Service categories
-
Applications
Production and operations
- Other operations
Service industry and public sector operations
- Healthcare
- Education
- Public Order and Safety
- Police
- Defence
- Social Security Administration
- Adult Social Care
- Children's Social Care
- Other
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- None aside from any listed in the Appian Cloud subscription agreement.
- System requirements
-
- Users may access via supported web browser, or
- Native mobile application on supported devices.
User support
- Email or online ticketing support
- Yes
- Support response times
- With "Basic" ("Community") support, the response-time range is within two business hour for Priority 1 (critical) issues to within 72 business hours for Priority 4 (minor) issues. The term "business hours" refers to Appian's standard Product Support hours within Europe, which are 08:00 to 17:30, BST (British Summer Time), Monday through Friday, excluding Appian holidays. For "Enterprise" support, the response-time range is within 15 minutes for Priority 1 issues to within 6 hours for Priority 4 issues. A full accounting of response time by customer support levels and case priority can be provided upon request.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- Our comprehensive services deliver maintenance, support, and product updates to Appian customers, partners, and distributors. Specifically, we offer our customers four levels of customer support: Basic, Essential, Advanced, and Enterprise. Appian support is accessible via phone or e-mail, as well as over the web. Additionally, Appian provides a single portal for our clients and partners via the Appian Community portal, that delivers an integrated customer experience for knowledge management, discussion forums, Centre of Excellence documentation, product updates, software downloads, application and template downloads, logging support cases, licensing, documentation, and online training. Updates and new releases of the licensed software are included with Appian Product Support. In the United Kingdom, Appian Standard Product Support hours are 08:00 to 17:30, BST (British Summer Time), Monday through Friday, excluding Appian holidays. Advanced and Enterprise Support includes 24-hour assistance for critical issues. The Appian Product Support team operates in a “flat” organisational structure, whereby any engineer may assist any customer with any issue; and the Product Support engineer assigned to an issue at the time of help desk “ticket” creation retains ownership over the given case through to resolution/closeout. Available support services are detailed further here - https://appian.com/support/resources/support.html
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- Appian has automated processes to orchestrate the onboarding of new Appian Cloud customers. From a "get-started" perspective, Appian offers implementation, training, and post-implementation support services. Additionally, with Appian Cloud, all hosting, infrastructure, and system management tasks are managed by Appian; this includes activities around platform (but not application) administration, patch deployments, software upgrades (Appian software, operating system, and any other supporting applications), and backups.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Our customers can export data via Appian functionality and reports, including the business logic of their applications and the data stored in the relational database). Customers are responsible for exporting the necessary information prior to the termination date. Data is typically exported as CSV formatted files, further guidance and information is available on request subject to understanding the current environments in use, and what data has been loaded into the which systems etc.
- End-of-contract process
- Appian has automated processes to orchestrate the onboarding of new Appian Cloud customers and the offboarding of Appian Cloud customers that are discontinuing the service. These processes ensure that all involved parties within Appian are notified and also ensure that Appian Cloud sites are deployed and configured (or decommissioned) consistently. These processes further ensure each customer is notified well in advance regarding the expiration of its current Appian Cloud agreement, thereby allowing the customer sufficient time, should it decide not to renew the subscription agreement, to export its applications and data before its Appian Cloud site is shut down.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Alongside the browser availability on phones, users can also download the Appian Mobile application that allows them to access and use the solution in a similar, but more mobile-suited way for an even better user experience.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Service is accessed via a responsive, web-based graphical user interface (GUI) supporting all major evergreen browsers.
There are distinct interfaces based on the user's role:
1)End-User (Appian Sites): The primary, secure web portal for business users. Manages tasks, data, reports, and processes.
2) Developer (Appian Designer): A web-based, low-code IDE for developers to visually design, build, test, and deploy applications.
3) Administrator (Admin Console): A web-based console for admins to manage platform settings, security, users, and monitor system health.
End-user interfaces are also accessible via native iOS and Android mobile apps. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
The Appian Platform is designed and engineered for accessibility, adhering to global standards including WCAG 2.2 Level AA.
Appian (the platform vendor) conducts continuous and rigorous interface testing as part of its development lifecycle. This testing includes a "test-from-the-start" methodology using both automated and manual validation:
Automated Testing: Integrated into the development pipeline to catch common accessibility violations.
Manual Testing with Assistive Technology: Regular, in-depth testing is performed by accessibility experts using the most common assistive technologies, including: (1) Screen Readers: JAWS, NVDA (on Windows), and VoiceOver (on macOS/iOS). (2) Keyboard-Only Navigation: Ensuring all interface elements, controls, and workflows are fully operable without a mouse. (3) Screen Magnification: Testing with tools like ZoomText and OS-native magnifiers. (4)High-Contrast Modes: Verifying readability and usability when system high-contrast settings are enabled.
Appian also provides a public Voluntary Product Accessibility Template (VPAT) that fully documents its conformance with accessibility standards. - API
- Yes
- What users can and can't do using the API
- The Appian platform can be configured to create and expose application programming interfaces (APIs) via Simple Object Access Protocol (SOAP) or Representational State Transfer (RESTful). Appian can also consume APIs via SOAP and RESTful
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- The service is designed for flexibility, distinguishing between buyer-led configuration and supplier-led customisation. The buyer's trained administrators can perform routine configurations using the built-in, no-code Admin Console; this includes managing users, roles, teams, security, and customising business rules, drop-down lists, and branding. Deeper customisations – such as adding new data fields, altering core process steps, building custom interfaces, or creating new API integrations – are performed by Appian as a change request (unless contractually specified otherwise), typically managed via our G-Cloud Lot 3 (Cloud Support) service to ensure quality and platform stability.
Scaling
- Independence of resources
- Each customer site receives its own dedicated virtual infrastructure which is logically firewalled from that of other customers.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
System Resources: Real-time monitoring of CPU, memory (RAM), and disk utilisation trends.
User Activity: metrics on user login history, concurrent user sessions, and distinct active users.
Application Performance: Detailed logs and dashboards tracking interface response times, process execution speeds, and slow-running rules or queries.
Infrastructure Health: Availability status and alert logs for the underlying cloud infrastructure. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Other
- Other data at rest protection approach
- All storage is encrypted with a customer specific data encryption key, which is itself encrypted with a key encryption key.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Customers export data primarily through self-service Appian functionality, including out-of-the-box reports and record grids which allow immediate export to CSV or Excel formats. For automated or high-volume data extraction, users can configure standard Web APIs to expose data programmatically to external systems. Additionally, the application business logic, process models, and design objects can be exported as standard application packages (ZIP/XML) directly from the design environment.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- XML
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- XML
- JSON
- TXT
- XLSM
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Appian Cloud's service-level agreement (SLA) availability guarantees are based on the customer's subscribed support level, ranging from 99% to 99.99%. If, during customer's subscription, availability does not meet the SLA during a calendar month, Appian provides the customer with service credits in the form of a percentage of the applicable monthly service fee. These service credits range from ten percent to thirty percent of the monthly fee based on a combination of the problem severity level and the amount of time by which the guaranteed SLA has not been met. Further information is available on request.
- Approach to resilience
- Appian uses Amazon Web Services (AWS) as our Infrastructure-as-a-Service (IaaS) hosting partner for Appian Cloud. The customer chooses its preferred region, and all customer data inside an Appian Cloud instance is protected and not copied outside the customer’s designated region. AWS has state-of-the-art data centres spanning eight regions worldwide – specifically, in Asia Pacific (Sydney, Australia; Mumbai, India; Singapore; and Tokyo, Japan); in Canada; in Europe (Frankfurt, Germany; Ireland; London, United Kingdom; and Paris, France); in South America (Sao Paolo, Brazil); and in the United States (Northern California, Northern Virginia, Ohio, and Oregon). As our goal is to provide our Appian Cloud customers with a highly reliable and scalable architecture that affords them maximum uptime and zero data loss, customer production data is replicated across two availability zones within the client’s selected region. An availability zone is a completely separate data-centre location within a region (for example, if a customer chooses to have its solution hosted in Northern Virginia, that customer’s production data will be replicated across two entirely different and isolated data centres in Northern Virginia). Additional information is available on request.
- Outage reporting
- Notifications of outages would be sent to each customer's designated support point of contacts via e-mail.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- The platform provides the ability to create user groups, roles, and rule-based associations that can be used to designate access within the platform. Appian’s role-based security model controls access to data, documents, etc; each time a user requests access to a document or other content, the system verifies that user’s role with respect to the requested object. Each object has its own set of roles to which system administrators can assign users or groups. All objects have standard “administrator,” “editor,” “read only,” and “no access” roles, many objects also possess application-specific roles, providing additional functionality and flexibility.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Other
- Other security governance standards
- CyberEssentials, CyberEssentials+, Service Organisation Controls (SOC) 2 Type II, SOC 3, Payment Card Industry Data Security Standard (PCI DSS), HITRUST, HIPAA, C5, ISO 27001/27017/27018, ENS, SOC 1/ISAE 3402, Cloud Security Alliance (CSA) Security, Trust, and Assurance Registry (STAR), and many others
- Information security policies and processes
- Appian employs a full-time Information Security Officer and team responsible for defining and adhering to best practices-based information security policies and processes. This team works closely with our Appian Cloud team and Appian senior management to monitor the security and performance of our service, as well as coordinate periodic tests and reviews and work with third-party organisations that evaluate and certify the security and controls of our service. Appian Cloud has a comprehensive security and compliance program that meets numerous industry standards, detailed in our “Service Definition Document.” Appian undergoes frequent third-party audits to validate that controls are operating effectively to protect customer data.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- We use our software for the systematic proposal, review, justification, and implementation of cloud infrastructure changes. All changes are tracked using the Appian application and reviewed by a cloud architect/senior engineer. Appian pays special attention to the security and stability implications of the proposed change. Depending on the change, reviewers may request development environment testing. All requests are stored for audit purposes. Our plan and process are reviewed at least annually and documented as part of our security program review. Appian's hosting provider manages hardware changes. Sound practices are covered as part of the Service Organisation Controls (SOC) audit.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Appian performs regular vulnerability scanning against all Appian Cloud assets at least monthly. Appian performs risk assessments for identified security items and handles them in accordance with their overall impact. Appian makes our third-party penetration test report available to customers under nondisclosure agreement (NDA).
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Appian performs daily reviews of event/incident alerts at the infrastructure level. Unusual or suspicious activity is investigated and escalated as necessary. Customers have access to application and application server logs including security logs, which can be reviewed or downloaded via the web interface. See https://appian.com/blog/2021/monitoring-appian-with-appian--tackling-security-alert-fatigue-w.html for a blog description of Appian's security practices and tooling.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Appian uses an online form for incident reporting (available through Appian Forum) and the Appian platform for managing incidents, and we use Forum for customer communication. The steps we follow in addressing any reported incident are: 1) verifying the source; 2) verifying the incident; 3) notifying other parties as appropriate; 4) form incident response team; 5) gather evidence; and 6) contain, eradicate, and recover from the incident. Appian’s Information Security Officer is responsible for monitoring security incident status until it has been resolved and normal business operations have been safely restored. The response required depends on the type of incident.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Appian Community Edition is a free, full-featured cloud environment for learning, experiment, and prototyping. It includes full platform access (Low-code Designer, Data Fabric, and Automation tools) but is restricted to non-production use, excluding SLAs, backups, and support. Access is not time-limited, provided the environment remains active through regular login.
- Link to free trial
- https://community.appian.com/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Coalfire Systems, Inc
- ISO/IEC 27001 accreditation date
- Friday 4 April 2025
- What the ISO/IEC 27001 doesn’t cover
-
4 April 2025 most recent accreditation (Accredited since 1 May 2019)
Appian Cloud has earned ISO/IEC 27001:2022 certification through Coalfire, an independent cybersecurity assessor. This internationally recognised certification demonstrates Appian Cloud’s achievement of a high level of security maturity and robust management, operational, and technical controls in place to manage or eliminate security risks and enable customers to trust that their confidential data is protected. Physical security (which is outsourced to AWS data centers) and Physical Media Transfers are not covered. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Coalfire Systems, Inc
- ISO 9001 accreditation date
- Wednesday 30 April 2025
- What the ISO 9001 doesn’t cover
-
30 April 2025 - most recent accreditation (Accredited since 6 June 2023)
Appian Engineering ISO 9001 certification covers the entire Engineering Software Development LifeCycle (SDLC) and the associated Quality Management System (QMS). All engineering activities which are part of Appian Cloud development and deployment are included in the scope. Appian packaged vertical solutions, Appian Process Mining capabilities and AWS data centers used to host Appian Cloud are outside the scope. - Quality management systems (QMS)
- Yes
- CSA STAR certification
- Yes
- CSA STAR accreditation date
- Friday 7 March 2025
- CSA STAR certification level
- Level 1: CSA STAR Self-Assessment
- What the CSA STAR doesn’t cover
-
07/03/2025 most recent update (CSA STAR listed since 30/05/2018)
The CSA STAR certification covers our entire Appian Cloud service offering. Physical security (which is outsourced to AWS data centers) and Physical Media Transfers are not covered. - PCI certification
- Yes
- Who accredited the PCI DSS certification
- Payment Card Industry (PCI)
- PCI DSS accreditation date
- Friday 21 November 2025
- What the PCI DSS doesn’t cover
-
21 November 2025 - most recent accreditation (Accredited since 18 December 2017)
The PCI DSS certification applies to the Appian Cloud service which hosts bespoke customer defined business applications that may process credit card transactions as a component of their solution. All Cardholder Data storage, processing, and transmission processes are the customer responsibility and not part of the services offered within the Appian Cloud service. Physical security (which is outsourced to AWS data centers) and Physical Media Transfers are not covered as well. - Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- C8c12e85-19ad-47f4-afb5-6ec7eb3df2a4
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 38d18183-01d1-45e1-9bf1-5e821372e525
- Other security certifications
- Yes
- Any other security certifications
-
- Service Organisation Controls (SOC) 1 Type II/ISAE 3402
- Service Organisation Controls (SOC) 2 Type II
- Service Organisation Controls (SOC) 3
- Federal Risk and Authorisation Management Programme (FedRAMP)
- Defense Information Security Agency (DISA) Level 2
- Government of Canada (GC) Protected B
- Health Information Trust Alliance (HITRUST)
- Pharmaceutical and Life Sciences Validation and Good Practice Standards (GxP)
- Information Security Registered Assessor Program (IRAP)
- Cloud Computing Compliance Criteria Catalogue (C5)
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
-