People Alchemy LWP/ePortfolio
The Learning Workflow Platform/ePortfolio is used for induction/onboarding, developing managers and leaders, enabling learning transfer, training event wrapper, managing mentoring/coaching activities, nurturing aspiring talent, eportfolio and qualifications management, certification assessments, CPD recording, and many other learning and behavioural outcomes. Used in NHS/healthcare for Care Certificates, Preceptorships, Clinical Skills and more.
Features
- Configurable learning and performance pathways
- Pre-built pathways for induction, management and more
- ePortfolio for qualifications, evidence and reflective practice
- Competency assessment and certification management
- Observation in practice assessments
- Learning transfer and behaviour change tracking
- Learning and performance metrics for ROI and assurance
- Administration, reporting and audit trails
- Mobile access with SMS notifications
- Qualification assessment and verification functions
Benefits
- Reinforce learning transfer from training room to workplace
- Manage experiential and on-the-job learning activities
- Provide real-time visibility of learner progress and competence
- Embed learning directly into day-to-day work processes
- Involve line managers in coaching and team development
- Accelerate time to proficiency and role readiness
- Enable self-directed and reflective learning
- Simplify administration of assessments and verification
- Reduce time and effort spent managing learning programmes
- Enable structured coaching and mentoring interactions
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 4 7 5 3 8 9 5 2 0 1 3 1 6 6
Contact
PEOPLE ALCHEMY LTD
Frederick Paul Matthews
Telephone: 020 8720 7195
Email: hello@peoplealchemy.com
About your service
- Service categories
-
Applications
Enterprise resource management
Human capital management
- Talent Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
-
The service is subject to planned maintenance to deploy updates and improvements. Planned system updates are carried out weekly on Tuesday evenings and involve a short period of service unavailability.
Maintenance is scheduled outside normal UK working hours. End users are notified of the maintenance window via a header banner within the system. - System requirements
-
- Modern web browser (Chrome, Edge, Firefox or Safari)
- Internet connection with standard HTTPS access
- JavaScript enabled in the web browser
- Cookies enabled for authenticated sessions
- Access to Google-hosted CDNs including Google Fonts over HTTPS
- No local software installation required
User support
- Email or online ticketing support
- Yes
- Support response times
- During UK business hours, we aim to provide an initial response within four business hours. Urgent service issues are prioritised and responded to as quickly as possible during UK business hours.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
This service is delivered without formal tiered support levels.
All customers receive the same standard level of platform support as part of the People Alchemy Learning Workflow Platform/ePortfolio service. There is no additional cost for different support levels, as tiered support packages are not offered under this service.
Support is provided through a central support process during UK business hours. A named account manager is typically assigned as the primary commercial and relationship contact. A dedicated technical account manager or named cloud support engineer is not provided, although technical specialists are involved as required to resolve platform issues. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Users are supported through a structured implementation and onboarding process, with more intensive support provided during the early stages to ensure the service is set up effectively.
An experienced consultant guides initial configuration, setup, and adoption activities. Training for administrators is provided as required and is typically delivered remotely using online sessions. Comprehensive administrator documentation is provided to support ongoing use of the service.
On-site training is not normally provided but can be arranged by agreement where required. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
End users can extract their own user-generated content and learning programmes directly from the service using built-in PDF export functionality.
For organisational data, the supplier will agree with the customer how data should be extracted at the end of the contract, including the scope and format of the data to be provided. Data extracts can be supplied in agreed formats, and additional charges may apply for bespoke or non-standard formats.
Where required, the supplier can also provide, for an agreed fee, a time-limited data access account after contract termination. This allows the customer to continue accessing reports and exporting data directly from the system to support transition or audit requirements. - End-of-contract process
-
At contract end, the service remains available for normal use until the agreed exit date. During this period, end users can download their own user-generated content and learning programmes using built-in PDF export functionality.
An exit planning meeting is held with the customer to agree the exit timeline, responsibilities, data requirements, and any transition arrangements. The scope and format of any organisational data extracts are agreed with the customer.
After the exit date, access is removed for end users. Administrative access can be retained for an agreed period to support reporting and data extraction.
Buyer data is deleted or returned in line with GDPR requirements. Encrypted backups are retained for up to 12 months before secure deletion, in line with standard backup retention policies.
Included in the contract price
# End-user self-service PDF exports
# Standard exit planning and coordination
# Data deletion in line with GDPR
Additional costs may apply
# Extended post-contract administrative access
# Bespoke or non-standard data extracts
# Consultancy to support data migration or transition to another system
This process is defined in the People Alchemy Exit Plan - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Administrator documentation is provided online through a WordPress-based documentation site and accessed using standard web browsers.
The documentation is written in clear, structured language and presented using standard web formats that support common accessibility features such as browser zoom, reflow, and screen reader access. Documentation can be accessed using keyboard navigation and does not rely on colour alone to convey meaning.
The documentation has not been formally tested against WCAG 2.2 accessibility standards. Accessibility testing to date has focused on the end-user service interface rather than administrative documentation.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
End-user screens are fully responsive and designed for use on smartphones and tablets.
Administration screens are optimised for desktop and laptop use and are not fully responsive on smaller devices. Administrative tasks are intended to be carried out on larger screens with a full keyboard and mouse for efficiency. - Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service is accessed through a secure, web-based user interface available via standard web browsers. End-user screens are responsive for use on desktop, tablet, and mobile devices. Administrative functions are accessed through the same web interface and are optimised for desktop and laptop use.
- Accessibility standards
- None or don’t know
- Description of accessibility
-
The end-user interface is designed to be accessible and usable with common assistive technologies. End-user screens are responsive and support keyboard navigation, screen readers, and other assistive tools. The end-user interface has been tested against WCAG 2.1 to level AA using an external accessibility specialist, and findings were reviewed to inform ongoing improvements.
The administrative interface has not been specifically designed or tested for WCAG accessibility standards. Some administrative functions may not be fully usable with assistive technologies.
The service has not yet been formally tested against WCAG 2.2. - Accessibility testing
-
Interface accessibility testing has been carried out on the end-user interface using an external accessibility specialist. Testing was undertaken against WCAG 2.1 to level AA and included evaluation using common assistive technologies and accessibility testing tools.
Findings from this testing were reviewed and used to inform accessibility improvements to the end-user interface.
The administrative interface has not been specifically designed or tested for use with assistive technologies.
The service has not yet been formally tested against WCAG 2.2. - API
- No
- Customisation available
- Yes
- Description of customisation
-
What can be customised
Users can customise learning and performance pathways, competencies and frameworks, assessments, workflows, roles and permissions, branding, notifications, and reporting structures. Customisation applies to how the service is configured and used, rather than changes to the underlying software.
How users can customise
Customisation is carried out through built-in administration tools within the service. Configuration changes are applied using the web-based administrative interface and do not require coding or changes to the core platform.
Who can customise
Customisation is performed by users with appropriate administrative permissions, such as system administrators or programme administrators, as defined by the customer.
Scaling
- Independence of resources
-
The service is delivered as a multi-tenant SaaS platform designed to support concurrent use by multiple customers. Capacity planning, monitoring, and scaling are managed by the supplier to ensure consistent performance across the service.
Workloads are managed centrally and resources are scaled to accommodate peak demand, preventing individual customers or user groups from adversely impacting others. Usage patterns are monitored to identify and address performance issues proactively.
Customers do not share data, configurations, or access rights, and one customer’s activity does not affect the availability or integrity of another customer’s service.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The service provides a range of administrative reports that present learning and performance metrics for programmes, pathways, competencies, and assessments.
Metrics are displayed on screen within the service and are primarily presented as tabular data, with supporting visual indicators such as progress bars to show completion and progress status. Reports provide visibility of learner progress, assessment outcomes, and programme participation.
Administrative users can export report data in Excel, CSV, or PDF formats for further analysis or local reporting. The service focuses on providing clear operational and progress metrics rather than predictive analytics or external business intelligence tooling. - Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- Other locations
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
End users can export their own user-generated content and learning programme information directly from the service using built-in PDF export functionality.
Users with administrative permissions can export organisational data from reports using PDF, Excel, or CSV formats, depending on the report and data type. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- MS Excel - XLSX
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- MS Excel - XLSX
- MS Word - DOCX
- MP3
- MP4
- JPG/JPEG
- PNG
- TXT
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is provided on a best-endeavours basis and no specific level of availability is contractually guaranteed as part of the standard service.
The service is not designed to support mission-critical or safety-critical operational processes. Temporary service unavailability may cause inconvenience to users but is not expected to prevent customers from continuing core business operations.
The standard service does not include a formal availability service level agreement (SLA), and no service credits or refunds are provided if availability targets are not met.
Where customers require defined availability commitments, SLAs can be agreed separately as part of a bespoke contractual arrangement. - Approach to resilience
-
The service is designed to be resilient through a combination of monitoring, containerised architecture, and managed cloud infrastructure.
System availability is monitored continuously, with automated checks performed at one-minute intervals. Additional monitoring is in place to track key operational indicators such as server load, application performance, and background processing queues, allowing issues to be identified and addressed promptly.
The service is deployed using containerised components, which supports rapid recovery and rebuild of application services in the event of a failure. This approach reduces recovery time and allows affected components to be restarted or replaced without rebuilding the entire environment.
The underlying datacentre infrastructure is provided by a third-party cloud hosting provider and is designed for resilience, including redundant power, networking, and physical security controls. Detailed information on datacentre resilience arrangements is available on request. - Outage reporting
-
If the service is unavailable, customers are notified directly via their nominated contact email address with information about the outage and progress updates.
If the service remains available but is operating in a degraded or impaired state, a notification banner is displayed within the service to inform users of the issue and provide updates as remediation progresses.
The service does not provide a public status dashboard and does not expose an API for outage or status notifications.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to management interfaces is controlled using multiple levels of administrative roles, allowing permissions to be granted based on specific responsibilities. Administrative access is restricted to authorised users and protected using strong authentication.
Support access is limited to users with appropriate administrative roles. Support requests are submitted via a dedicated email channel and are not available to end users. Requests are handled only for verified customer contacts by authorised internal staff.
Administrative access rights are reviewed and updated as roles or responsibilities change. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
-
Security governance is managed using a risk-based approach appropriate to the size and nature of the service. Security responsibilities are defined within the organisation and embedded into system design, development, and operational processes.
Controls include access management, encryption, monitoring, vulnerability management, and incident response procedures. The service is hosted within a managed cloud environment and supplier security controls are considered as part of ongoing risk management.
Security practices are informed by recognised guidance, including the UK Government Software Security Code of Practice and Cyber Essentials principles, and are reviewed periodically. - Information security policies and processes
-
Information security is managed through a set of documented policies and operational processes appropriate to the size and nature of the organisation. These cover access control, data protection, incident management, change management, backup and recovery, and secure system operation.
Security responsibilities are clearly assigned within the organisation, with oversight at senior management level. Security risks and incidents are escalated through defined reporting lines and reviewed as part of regular operational management.
Policies are implemented through technical controls, standard operating procedures, and controlled user access. Compliance is supported through system monitoring, logging, and regular review of access rights and configurations.
The service undergoes annual independent penetration testing, with findings reviewed and remediation actions tracked to completion where required.
Security practices are informed by recognised guidance, including Cyber Essentials requirements and the UK Government Software Security Code of Practice. Policies and processes are reviewed periodically and updated in response to changes in risk, technology, or regulatory expectations. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Service components are managed using version-controlled configuration and containerised deployments, allowing changes to be tracked throughout their lifecycle. Configuration changes are recorded and applied through controlled deployment processes.
Proposed changes are assessed for operational and security impact before deployment, including consideration of access control, data protection, and service availability. Changes are tested on a staging server prior to release and deployed to production in a controlled manner.
System updates and configuration changes are logged and reviewed, with monitoring in place to identify and respond to any issues arising from changes. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Potential threats are assessed through ongoing monitoring, periodic risk reviews, and independent annual penetration testing. Vulnerability information is obtained from vendor security advisories, operating system and software updates, and relevant security guidance.
Security patches are prioritised based on risk and are typically applied to a test environment first before deployment to the production service. Critical security updates are deployed as soon as practicable, with non-critical updates scheduled as part of regular maintenance.
Vulnerability remediation actions are tracked and reviewed as part of ongoing security management. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Protective monitoring is carried out through continuous system monitoring, including uptime checks, application health monitoring, and alerts on abnormal system behaviour such as unexpected load, errors, or queue backlogs.
Potential compromises are investigated promptly by the operations team. Where a security incident is suspected, access may be restricted, affected components isolated, and remedial actions taken in line with the incident response process.
Incidents are responded to as soon as practicable, with priority given to issues that present a security risk or service impact. - Incident management type
- Supplier-defined controls
- Incident management approach
-
The service operates defined incident management processes for common operational and security events. Incidents may be identified through system monitoring or reported by users via the support ticketing process.
Reported incidents are triaged and investigated by the operations team, with actions taken to contain, resolve, and prevent recurrence where appropriate. Customers are kept informed of significant incidents through direct communication, including email notifications where required.
Incident reports and post-incident summaries can be provided to customers on request. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- A free sandbox version provides full access to the application, including the ability to switch between user roles. It is intended for evaluation and configuration only and cannot be used for live production use. The sandbox is not time-limited.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 24d62446-e400-49de-ae30-34bb6ce8acd6
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-