Skip to main content

Help us improve the Digital Marketplace - send your feedback

PEOPLE ALCHEMY LTD

People Alchemy LWP/ePortfolio

The Learning Workflow Platform/ePortfolio is used for induction/onboarding, developing managers and leaders, enabling learning transfer, training event wrapper, managing mentoring/coaching activities, nurturing aspiring talent, eportfolio and qualifications management, certification assessments, CPD recording, and many other learning and behavioural outcomes. Used in NHS/healthcare for Care Certificates, Preceptorships, Clinical Skills and more.

Features

  • Configurable learning and performance pathways
  • Pre-built pathways for induction, management and more
  • ePortfolio for qualifications, evidence and reflective practice
  • Competency assessment and certification management
  • Observation in practice assessments
  • Learning transfer and behaviour change tracking
  • Learning and performance metrics for ROI and assurance
  • Administration, reporting and audit trails
  • Mobile access with SMS notifications
  • Qualification assessment and verification functions

Benefits

  • Reinforce learning transfer from training room to workplace
  • Manage experiential and on-the-job learning activities
  • Provide real-time visibility of learner progress and competence
  • Embed learning directly into day-to-day work processes
  • Involve line managers in coaching and team development
  • Accelerate time to proficiency and role readiness
  • Enable self-directed and reflective learning
  • Simplify administration of assessments and verification
  • Reduce time and effort spent managing learning programmes
  • Enable structured coaching and mentoring interactions

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@peoplealchemy.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 4 7 5 3 8 9 5 2 0 1 3 1 6 6

Contact

PEOPLE ALCHEMY LTD Frederick Paul Matthews
Telephone: 020 8720 7195
Email: hello@peoplealchemy.com

About your service

Service categories

Applications

Enterprise resource management

Human capital management

  • Talent Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
The service is subject to planned maintenance to deploy updates and improvements. Planned system updates are carried out weekly on Tuesday evenings and involve a short period of service unavailability.

Maintenance is scheduled outside normal UK working hours. End users are notified of the maintenance window via a header banner within the system.
System requirements
  • Modern web browser (Chrome, Edge, Firefox or Safari)
  • Internet connection with standard HTTPS access
  • JavaScript enabled in the web browser
  • Cookies enabled for authenticated sessions
  • Access to Google-hosted CDNs including Google Fonts over HTTPS
  • No local software installation required

User support

Email or online ticketing support
Yes
Support response times
During UK business hours, we aim to provide an initial response within four business hours. Urgent service issues are prioritised and responded to as quickly as possible during UK business hours.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
This service is delivered without formal tiered support levels.

All customers receive the same standard level of platform support as part of the People Alchemy Learning Workflow Platform/ePortfolio service. There is no additional cost for different support levels, as tiered support packages are not offered under this service.

Support is provided through a central support process during UK business hours. A named account manager is typically assigned as the primary commercial and relationship contact. A dedicated technical account manager or named cloud support engineer is not provided, although technical specialists are involved as required to resolve platform issues.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Users are supported through a structured implementation and onboarding process, with more intensive support provided during the early stages to ensure the service is set up effectively.

An experienced consultant guides initial configuration, setup, and adoption activities. Training for administrators is provided as required and is typically delivered remotely using online sessions. Comprehensive administrator documentation is provided to support ongoing use of the service.

On-site training is not normally provided but can be arranged by agreement where required.
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
End users can extract their own user-generated content and learning programmes directly from the service using built-in PDF export functionality.

For organisational data, the supplier will agree with the customer how data should be extracted at the end of the contract, including the scope and format of the data to be provided. Data extracts can be supplied in agreed formats, and additional charges may apply for bespoke or non-standard formats.

Where required, the supplier can also provide, for an agreed fee, a time-limited data access account after contract termination. This allows the customer to continue accessing reports and exporting data directly from the system to support transition or audit requirements.
End-of-contract process
At contract end, the service remains available for normal use until the agreed exit date. During this period, end users can download their own user-generated content and learning programmes using built-in PDF export functionality.

An exit planning meeting is held with the customer to agree the exit timeline, responsibilities, data requirements, and any transition arrangements. The scope and format of any organisational data extracts are agreed with the customer.

After the exit date, access is removed for end users. Administrative access can be retained for an agreed period to support reporting and data extraction.

Buyer data is deleted or returned in line with GDPR requirements. Encrypted backups are retained for up to 12 months before secure deletion, in line with standard backup retention policies.

Included in the contract price
# End-user self-service PDF exports
# Standard exit planning and coordination
# Data deletion in line with GDPR

Additional costs may apply
# Extended post-contract administrative access
# Bespoke or non-standard data extracts
# Consultancy to support data migration or transition to another system

This process is defined in the People Alchemy Exit Plan
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Administrator documentation is provided online through a WordPress-based documentation site and accessed using standard web browsers.

The documentation is written in clear, structured language and presented using standard web formats that support common accessibility features such as browser zoom, reflow, and screen reader access. Documentation can be accessed using keyboard navigation and does not rely on colour alone to convey meaning.

The documentation has not been formally tested against WCAG 2.2 accessibility standards. Accessibility testing to date has focused on the end-user service interface rather than administrative documentation.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
End-user screens are fully responsive and designed for use on smartphones and tablets.

Administration screens are optimised for desktop and laptop use and are not fully responsive on smaller devices. Administrative tasks are intended to be carried out on larger screens with a full keyboard and mouse for efficiency.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
The service is accessed through a secure, web-based user interface available via standard web browsers. End-user screens are responsive for use on desktop, tablet, and mobile devices. Administrative functions are accessed through the same web interface and are optimised for desktop and laptop use.
Accessibility standards
None or don’t know
Description of accessibility
The end-user interface is designed to be accessible and usable with common assistive technologies. End-user screens are responsive and support keyboard navigation, screen readers, and other assistive tools. The end-user interface has been tested against WCAG 2.1 to level AA using an external accessibility specialist, and findings were reviewed to inform ongoing improvements.

The administrative interface has not been specifically designed or tested for WCAG accessibility standards. Some administrative functions may not be fully usable with assistive technologies.

The service has not yet been formally tested against WCAG 2.2.
Accessibility testing
Interface accessibility testing has been carried out on the end-user interface using an external accessibility specialist. Testing was undertaken against WCAG 2.1 to level AA and included evaluation using common assistive technologies and accessibility testing tools.

Findings from this testing were reviewed and used to inform accessibility improvements to the end-user interface.

The administrative interface has not been specifically designed or tested for use with assistive technologies.

The service has not yet been formally tested against WCAG 2.2.
API
No
Customisation available
Yes
Description of customisation
What can be customised
Users can customise learning and performance pathways, competencies and frameworks, assessments, workflows, roles and permissions, branding, notifications, and reporting structures. Customisation applies to how the service is configured and used, rather than changes to the underlying software.

How users can customise
Customisation is carried out through built-in administration tools within the service. Configuration changes are applied using the web-based administrative interface and do not require coding or changes to the core platform.

Who can customise
Customisation is performed by users with appropriate administrative permissions, such as system administrators or programme administrators, as defined by the customer.

Scaling

Independence of resources
The service is delivered as a multi-tenant SaaS platform designed to support concurrent use by multiple customers. Capacity planning, monitoring, and scaling are managed by the supplier to ensure consistent performance across the service.

Workloads are managed centrally and resources are scaled to accommodate peak demand, preventing individual customers or user groups from adversely impacting others. Usage patterns are monitored to identify and address performance issues proactively.

Customers do not share data, configurations, or access rights, and one customer’s activity does not affect the availability or integrity of another customer’s service.

Analytics

Service usage metrics
Yes
Metrics types
The service provides a range of administrative reports that present learning and performance metrics for programmes, pathways, competencies, and assessments.

Metrics are displayed on screen within the service and are primarily presented as tabular data, with supporting visual indicators such as progress bars to show completion and progress status. Reports provide visibility of learner progress, assessment outcomes, and programme participation.

Administrative users can export report data in Excel, CSV, or PDF formats for further analysis or local reporting. The service focuses on providing clear operational and progress metrics rather than predictive analytics or external business intelligence tooling.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • Other locations
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
End users can export their own user-generated content and learning programme information directly from the service using built-in PDF export functionality.

Users with administrative permissions can export organisational data from reports using PDF, Excel, or CSV formats, depending on the report and data type.
Data export formats
  • CSV
  • Other
Other data export formats
  • MS Excel - XLSX
  • PDF
Data import formats
  • CSV
  • Other
Other data import formats
  • MS Excel - XLSX
  • MS Word - DOCX
  • PDF
  • MP3
  • MP4
  • JPG/JPEG
  • PNG
  • TXT

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The service is provided on a best-endeavours basis and no specific level of availability is contractually guaranteed as part of the standard service.

The service is not designed to support mission-critical or safety-critical operational processes. Temporary service unavailability may cause inconvenience to users but is not expected to prevent customers from continuing core business operations.

The standard service does not include a formal availability service level agreement (SLA), and no service credits or refunds are provided if availability targets are not met.

Where customers require defined availability commitments, SLAs can be agreed separately as part of a bespoke contractual arrangement.
Approach to resilience
The service is designed to be resilient through a combination of monitoring, containerised architecture, and managed cloud infrastructure.

System availability is monitored continuously, with automated checks performed at one-minute intervals. Additional monitoring is in place to track key operational indicators such as server load, application performance, and background processing queues, allowing issues to be identified and addressed promptly.

The service is deployed using containerised components, which supports rapid recovery and rebuild of application services in the event of a failure. This approach reduces recovery time and allows affected components to be restarted or replaced without rebuilding the entire environment.

The underlying datacentre infrastructure is provided by a third-party cloud hosting provider and is designed for resilience, including redundant power, networking, and physical security controls. Detailed information on datacentre resilience arrangements is available on request.
Outage reporting
If the service is unavailable, customers are notified directly via their nominated contact email address with information about the outage and progress updates.

If the service remains available but is operating in a degraded or impaired state, a notification banner is displayed within the service to inform users of the issue and provide updates as remediation progresses.

The service does not provide a public status dashboard and does not expose an API for outage or status notifications.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces is controlled using multiple levels of administrative roles, allowing permissions to be granted based on specific responsibilities. Administrative access is restricted to authorised users and protected using strong authentication.

Support access is limited to users with appropriate administrative roles. Support requests are submitted via a dedicated email channel and are not available to end users. Requests are handled only for verified customer contacts by authorised internal staff.

Administrative access rights are reviewed and updated as roles or responsibilities change.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Between 6 months and 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
Between 6 months and 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
Security governance is managed using a risk-based approach appropriate to the size and nature of the service. Security responsibilities are defined within the organisation and embedded into system design, development, and operational processes.

Controls include access management, encryption, monitoring, vulnerability management, and incident response procedures. The service is hosted within a managed cloud environment and supplier security controls are considered as part of ongoing risk management.

Security practices are informed by recognised guidance, including the UK Government Software Security Code of Practice and Cyber Essentials principles, and are reviewed periodically.
Information security policies and processes
Information security is managed through a set of documented policies and operational processes appropriate to the size and nature of the organisation. These cover access control, data protection, incident management, change management, backup and recovery, and secure system operation.

Security responsibilities are clearly assigned within the organisation, with oversight at senior management level. Security risks and incidents are escalated through defined reporting lines and reviewed as part of regular operational management.

Policies are implemented through technical controls, standard operating procedures, and controlled user access. Compliance is supported through system monitoring, logging, and regular review of access rights and configurations.

The service undergoes annual independent penetration testing, with findings reviewed and remediation actions tracked to completion where required.

Security practices are informed by recognised guidance, including Cyber Essentials requirements and the UK Government Software Security Code of Practice. Policies and processes are reviewed periodically and updated in response to changes in risk, technology, or regulatory expectations.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Service components are managed using version-controlled configuration and containerised deployments, allowing changes to be tracked throughout their lifecycle. Configuration changes are recorded and applied through controlled deployment processes.

Proposed changes are assessed for operational and security impact before deployment, including consideration of access control, data protection, and service availability. Changes are tested on a staging server prior to release and deployed to production in a controlled manner.

System updates and configuration changes are logged and reviewed, with monitoring in place to identify and respond to any issues arising from changes.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Potential threats are assessed through ongoing monitoring, periodic risk reviews, and independent annual penetration testing. Vulnerability information is obtained from vendor security advisories, operating system and software updates, and relevant security guidance.

Security patches are prioritised based on risk and are typically applied to a test environment first before deployment to the production service. Critical security updates are deployed as soon as practicable, with non-critical updates scheduled as part of regular maintenance.

Vulnerability remediation actions are tracked and reviewed as part of ongoing security management.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring is carried out through continuous system monitoring, including uptime checks, application health monitoring, and alerts on abnormal system behaviour such as unexpected load, errors, or queue backlogs.

Potential compromises are investigated promptly by the operations team. Where a security incident is suspected, access may be restricted, affected components isolated, and remedial actions taken in line with the incident response process.

Incidents are responded to as soon as practicable, with priority given to issues that present a security risk or service impact.
Incident management type
Supplier-defined controls
Incident management approach
The service operates defined incident management processes for common operational and security events. Incidents may be identified through system monitoring or reported by users via the support ticketing process.

Reported incidents are triaged and investigated by the operations team, with actions taken to contain, resolve, and prevent recurrence where appropriate. Customers are kept informed of significant incidents through direct communication, including email notifications where required.

Incident reports and post-incident summaries can be provided to customers on request.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
A free sandbox version provides full access to the application, including the ability to switch between user roles. It is intended for evaluation and configuration only and cannot be used for live production use. The sandbox is not time-limited.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
25%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
24d62446-e400-49de-ae30-34bb6ce8acd6
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@peoplealchemy.com. Tell them what format you need. It will help if you say what assistive technology you use.