Microsoft SharePoint Online Service
Akita provides Microsoft SharePoint Online as a managed SaaS service. We support configuration, security, permissions, information architecture, and ongoing operation to help buyers collaborate securely, manage content effectively, and maintain reliable access to SharePoint Online across their organisation.
Features
- Cloud-hosted document storage with version control
- Role-based access and permission management
- Real-time document co-authoring
- Secure sharing with internal and external users
- Integrated search across sites and libraries
- Built-in retention and compliance policies
- Audit logs and activity reporting
- Microsoft 365 integration including Teams and Outlook
- Browser-based access with no local installation
- Automatic platform updates and security patching
Benefits
- Collaborate on documents simultaneously without file conflicts
- Access files securely from any location
- Reduce email attachments and duplication
- Improve document governance and compliance
- Find information quickly using structured search
- Control access without IT intervention
- Support hybrid and remote working models
- Streamline internal communication and knowledge sharing
- Reduce on-premise infrastructure and maintenance
- Keep systems current without manual upgrades
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 2 4 2 4 0 6 6 3 6 4 9 3 5 9
Contact
AKITA SYSTEMS LIMITED
Akita
Telephone: 0330 058 8000
Email: info@akita.co.uk
About the service
- Service categories
-
Applications
Content workflow and management
- Document
Content services
- Enterprise Content Management Applications
- Content Sharing and Collaboration Applications
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Integrated Employee Workspaces
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Microsoft 365 services including Microsoft Teams, OneDrive for Business, Outlook and Power Platform. SharePoint Online integrates with these services to support collaboration, document management, communication and workflow automation, while remaining usable as a standalone content management platform.
- Cloud deployment model
- Public cloud
- Service constraints
- The service is delivered as a Microsoft multi-tenant SaaS platform and is subject to Microsoft planned maintenance and update schedules. Internet connectivity is required for access. Functionality and integrations depend on supported Microsoft 365 licences and configurations. Customisation is limited to platform-supported features. Support is provided remotely and is dependent on buyer environment and user configuration
- System requirements
-
- Supported web browser and internet connection
- Microsoft 365 or SharePoint Online licence
- User accounts managed through Microsoft Entra ID
- Modern device running supported operating system
- TLS-encrypted network connectivity
- Role-based permissions configured by administrators
- Email service for notifications and alerts
- Supported mobile or desktop operating system
- Multi-factor authentication enabled where required
- Administrator access for configuration and governance
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is provided during UK business hours, Monday to Friday, with responses prioritised based on incident severity. Out-of-hours, weekend and bank holiday support is available for contracted customers under agreed support arrangements. Requests raised outside business hours are triaged and responded to in line with incident severity and the agreed support model.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Akita provides remote support for SharePoint Online delivered as a SaaS service. Standard support includes email, ticketing and phone support during UK business hours, with responses prioritised by incident severity. Support covers user access issues, configuration guidance, incident investigation and liaison with Microsoft where required.
Enhanced support options can be agreed at call-off and may include extended hours support, faster response targets, proactive service reviews and named technical contacts. Costs for enhanced support are defined per customer based on scope, service hours and response requirements.
Akita provides access to experienced cloud support engineers with Microsoft 365 expertise. Where agreed, a named technical account manager can be assigned to coordinate support activity, provide service oversight and act as the primary escalation point.
Out-of-hours and extended support is available for contracted customers based on agreed service arrangements and incident severity. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Akita helps users start using SharePoint Online through a structured onboarding approach. This includes initial configuration guidance, user setup and access controls aligned to buyer requirements. Online user documentation and Microsoft-provided guidance are made available to support self-service learning.
Akita provides remote onboarding sessions to introduce users to core features such as document management, collaboration and permissions. Where required, tailored training sessions can be delivered to administrators, site owners and end users. Onsite training can be provided by agreement and at additional cost.
Ongoing support and guidance is available through Akita’s support channels, helping users adopt the service effectively and align it with their working practices. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
When the contract ends, users can extract their data directly from SharePoint Online using standard Microsoft-supported tools and interfaces. Data can be downloaded through the SharePoint web interface, synchronised to local storage, or exported using Microsoft 365 administration tools and APIs. Document libraries, files, metadata and version history can be retained and transferred in commonly used formats.
Akita supports buyers by providing guidance on data extraction options, access controls and export processes. Where required, Akita can assist with planning and executing data exports, including validation that data has been successfully retrieved. Data extraction is performed in line with Microsoft security controls and buyer governance requirements, ensuring continued access to information prior to service termination. - End-of-contract process
-
At the end of the contract, the service is transitioned in line with the agreed off-boarding process. Buyer access to SharePoint Online remains available until the contract end date, allowing time for data extraction and transition planning. Akita supports an orderly exit by providing guidance on data export, access management and service closure.
Standard contract pricing includes access to the service for the agreed term, remote support during the notice period and reasonable assistance with exit queries. Data remains accessible to the buyer throughout this period.
Additional support, such as extended access beyond the contract term, assisted data migration to alternative platforms, bespoke reporting or onsite support, can be provided by agreement and at additional cost. All exit activities are carried out in line with security, data protection and contractual requirements. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
The mobile service provides access to documents, sites and basic collaboration features through mobile browsers and supported apps. Desktop access offers full configuration, administration and advanced content management features. Some complex site design, administration and bulk management tasks are only available via the desktop interface.
This is accurate, clear, and within 100 words. - Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- He service is accessed through a web-based interface using supported browsers and Microsoft mobile applications. Users interact with document libraries, lists, pages and collaboration tools through configurable sites and menus. Administrators manage settings, permissions, compliance and governance through Microsoft 365 and SharePoint administration portals.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- SharePoint Online accessibility is designed and tested by Microsoft in line with WCAG 2.2 AA requirements. Microsoft undertakes regular accessibility testing using assistive technologies such as screen readers, keyboard navigation and high-contrast modes. Akita supports buyers by configuring the service using platform accessibility features and by following Microsoft accessibility guidance when enabling and managing SharePoint sites. Any accessibility issues identified by users are logged and escalated through standard support processes.
- API
- Yes
- What users can and can't do using the API
-
SharePoint Online provides APIs through Microsoft Graph and SharePoint REST services. Users can authenticate via Microsoft Entra ID and use APIs to automate site creation, manage document libraries, apply permissions, manage metadata, and integrate SharePoint with other applications and workflows. APIs can also be used to retrieve content, update files, and monitor usage.
Users cannot bypass Microsoft security controls, licensing requirements or platform governance through the API. Core platform architecture, service limits and tenant-level restrictions are managed by Microsoft and cannot be altered. API usage is subject to Microsoft throttling, permission scopes and service limits. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Users can customise SharePoint Online within Microsoft-supported boundaries. Customisable elements include site structures, document libraries, lists, metadata, permissions, retention policies and page layouts. Users can also configure workflows and automation using Microsoft Power Platform tools.
Customisation is carried out through the SharePoint web interface, Microsoft 365 administration portals and supported configuration tools. No unsupported code changes or platform modifications are required. Changes take effect in line with tenant governance and security policies.
Customisation is typically performed by authorised administrators, site owners or power users with delegated permissions. Akita supports buyers by providing configuration guidance, governance design and best-practice recommendations where required.
Scaling
- Independence of resources
- SharePoint Online is delivered as a Microsoft-managed, multi-tenant SaaS platform designed to operate at scale. Microsoft allocates compute, storage and network resources dynamically to manage demand across tenants and maintain service performance. Built-in service limits, throttling controls and monitoring are used to prevent individual tenant activity from impacting others. Microsoft service level management and resilience controls are applied across the platform to ensure consistent availability and performance for all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- SharePoint Online provides usage and activity metrics including storage consumption, document access and edits, sharing activity, site usage and user engagement. Metrics are available at tenant and site level to support governance, auditing, capacity planning and ongoing service management.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Microsoft
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users export data from SharePoint Online using Microsoft-supported tools and interfaces. Data can be exported through the SharePoint web interface, synchronised to local storage, or retrieved using Microsoft 365 administration tools and APIs. Exports can be performed at site, library or file level, with metadata and version history retained where supported.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- DOCX, XLSX and PPTX
- Data import formats
-
- CSV
- Other
- Other data import formats
- DOCX, XLSX, PPTX and PD
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
SharePoint Online is provided with a financially backed availability SLA from Microsoft. Microsoft commits to a monthly uptime percentage of at least 99.9% for the service. Availability is measured across the tenant and service components in line with Microsoft’s published SLA definitions.
If Microsoft fails to meet the availability commitment, service credits may be applied in accordance with the Microsoft Online Services SLA. Any applicable credits are calculated by Microsoft and applied to the buyer’s service charges. Akita supports buyers by managing service incidents, liaising with Microsoft where required and assisting with SLA reporting and service credit requests.
Availability is dependent on factors including planned maintenance, customer network connectivity and correct service configuration. - Approach to resilience
-
SharePoint Online is designed to deliver a resilient, highly available collaboration platform underpinned by Microsoft’s global cloud infrastructure. As a Microsoft-managed, multi-tenant SaaS service, SharePoint Online operates across multiple geographically distributed data centres, providing built-in redundancy and automatic failover to reduce the impact of service disruption.
Microsoft continuously monitors the platform and applies service-level resilience controls to maintain availability and performance at scale. Data is protected through automated backups, versioning, and configurable retention policies, supporting recovery from accidental deletion or corruption. Built-in throttling, capacity management, and security controls prevent excessive activity within a single tenant from affecting the wider service.
Updates, security patches, and feature enhancements are applied centrally by Microsoft, removing the need for customer-led maintenance and reducing operational risk. Akita supports this resilience with configuration best practice, user guidance, and responsive support, helping organisations maintain reliable access to SharePoint and continuity of collaboration. - Outage reporting
-
SharePoint Online reports service status and outages through Microsoft’s service health capabilities. A public service health dashboard is available to provide visibility of current incidents, advisories and planned maintenance. Administrators can also view detailed service health information through the Microsoft 365 admin centre.
Outage notifications and service advisories can be delivered by email to nominated administrators. Service status information is also available via Microsoft APIs for monitoring and integration where required. Akita monitors service health information and supports buyers by interpreting incident updates, providing guidance and managing escalations during service disruptions.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted through role-based access controls and authenticated user accounts. Administrative access is limited to authorised personnel using Microsoft Entra ID with enforced permissions and, where required, multi-factor authentication. Support systems restrict access based on user roles, ensuring only approved administrators and support staff can view or manage service configurations. Access rights are reviewed regularly and adjusted in line with role changes or service requirements.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Akita follows a formal information security management framework aligned to ISO/IEC 27001. Information security policies cover areas including access control, data protection, incident management, risk management, supplier security and business continuity. Policies are approved at board level and apply across all services.
Responsibility for information security sits with a board-level director, supported by senior management and operational teams. Clear reporting lines are in place to escalate security risks, incidents and compliance issues. Security incidents are recorded, investigated and reviewed, with corrective actions tracked to completion.
Compliance with information security policies is ensured through mandatory staff training, role-based access controls and documented procedures. Policies and controls are reviewed regularly and updated to reflect changes in risk, technology and regulatory requirements. Internal audits and management reviews are used to monitor effectiveness and drive continual improvement. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Akita follows formal configuration and change management processes aligned with ISO/IEC 27001. Service components and configurations are documented and tracked throughout their lifecycle. Changes are logged, assessed and approved prior to implementation, with records maintained for audit purposes.
All changes are reviewed for potential security impact, including access, data protection and service availability considerations. Where required, changes are tested and validated before deployment. Emergency changes follow controlled processes with retrospective review to ensure continued compliance. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Akita’s vulnerability management process identifies, assesses, and reduces security risk across customer environments through monitoring, threat intelligence, and structured remediation.
Vulnerabilities are identified using automated scanning tools, vendor advisories, and intelligence from Microsoft and trusted security partners. Findings are assessed by severity, exploitability, and business impact to ensure prioritisation. Where Akita delivers managed services, remediation actions such as patching, configuration changes, and mitigation controls are implemented in line with agreed service scopes and change management.
Critical vulnerabilities are escalated promptly with clear guidance on risk and required actions. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Akita operates protective monitoring processes aligned with ISO/IEC 27001. Potential security compromises are identified through log monitoring, alerting and incident reporting across supported systems and services. Alerts are reviewed by authorised personnel and assessed for severity and impact.
When a potential compromise is identified, incidents are logged, investigated and escalated in line with the incident management process. Containment and remediation actions are taken promptly, with response times prioritised based on risk and service impact. Lessons learned are reviewed to prevent recurrence and improve controls. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Akita operates defined incident management processes aligned with recognised standards. Pre-defined procedures exist for common security and service incidents, ensuring consistent handling and escalation. Users report incidents through phone, email or the support ticketing system.
Incidents are logged, prioritised and managed based on severity and impact. Updates are provided to affected users during investigation and resolution. Post-incident reports can be provided on request, outlining the incident, actions taken and any preventative measures implemented. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- British Assessment Bureau (UKAS accredited)
- ISO/IEC 27001 accreditation date
- Friday 18 January 2019
- What the ISO/IEC 27001 doesn’t cover
- The ISO/IEC 27001 certification does not cover customer-owned systems or infrastructure not managed by Akita Systems Limited, physical security controls at customer premises, end-user devices not under Akita management, or non-IT business activities outside the defined scope of IT support, cloud services, and hosted and recovery services.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- British Assessment Bureau (UKAS accredited)
- ISO 9001 accreditation date
- Thursday 23 April 2015
- What the ISO 9001 doesn’t cover
- The ISO 9001:2015 certification does not cover activities outside the defined scope of IT service delivery, including non-IT business operations, customer-owned systems or processes not managed by Akita Systems Limited, services delivered entirely by third parties outside Akita’s quality management system, and physical site operations at customer premises where Akita does not have operational control.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 56073cca-376a-486b-a991-0f76b99f23b2
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- Cc55b424-1c83-4f89-8550-44e6b24ec430
- Other security certifications
- No
Social value
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement