MetricsLed DEPLOY
MetricsLed DEPLOY is a secure cloud-based platform for recruiting, deploying, and managing field personnel, contractors and advisers. It centralises time, expenses, compliance, onboarding, logistics and invoicing, giving organisations real-time oversight and streamlined operational control across multiple projects and locations.
Features
- Cloud-based workforce deployment and management platform
- Real-time reporting and operational dashboards
- Secure remote access from any device
- Centralised onboarding and compliance management
- Time, attendance, and expense tracking
- Automated invoicing and payment processing
- Role-based access controls and permissions
- Data encryption and secure hosting
- Scalable to multiple projects and locations
- Integration with existing organisational systems
Benefits
- Streamline workforce deployment across multiple projects and locations
- Reduce administrative overhead through automation
- Gain real-time visibility of field operations
- Improve compliance management and audit readiness
- Accelerate onboarding of staff and contractors
- Simplify time, expenses, and invoicing processes
- Enable secure remote working and management
- Improve decision-making with accurate real-time data
- Scale operations quickly without additional infrastructure
- Increase operational efficiency and cost control
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 6 1 4 0 5 8 3 8 2 1 0 4 7 7
Contact
MetricsLed
Skotkonung Trading as MetricsLed
Telephone: +44(0) 33 0088 3933
Email: tenders@metricsled.com
About your service
- Service categories
-
Applications
Enterprise resource management
Financial
- Financial and Accounting Applications
- Accounts Payable Applications
- Accounts Receivable Applications
- Travel and Expense Management Applications
Human capital management
- Core Human Resources Applications
- Talent Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Maintenance is planned in advance (normally to take place between 8pm and 6am) and users are advised of disruption (normally with 48hr notice).
- System requirements
-
- Internet connection and browser
- Service is designed to work on a tablet/laptop/desktop
- Screens will render on a mobile device
User support
- Email or online ticketing support
- Yes
- Support response times
- The help desk is available 09:00 to 17:00 on UK business days. We respond to high priority issues within four working hours. Medium priority within one business day. Low priority as agreed with the Customer on receipt of a service request.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Support level is tailored to client needs and is normally set out in full in a service level agreement with the client. We provide single point of contact for technical support, finance and management. We provide a 24hr monitored single email address for all technical issues and run server monitoring on all client servers to flag connectivity and other issues. We can provide further details on request.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
We help users start using MetricsLed DEPLOY through a structured onboarding and implementation process designed to minimise disruption and enable rapid adoption.
Each customer is supported during setup to understand their operational model, governance requirements, and reporting needs. The service is configured before go-live to reflect agreed workflows, roles, permissions, data structures, financial processes, and dashboards.
We provide guided onboarding for different user roles, including administrators, managers, finance users, and field staff. This includes online training sessions, live walkthroughs, and access to clear user documentation covering core tasks such as onboarding, data entry, approvals, reporting, and communications. Where required, we support data migration and configuration of integrations with existing systems.
During early use, users receive responsive remote support to resolve queries, refine configurations, and optimise processes. Ongoing support and training are available as requirements change, ensuring users can confidently embed the service into day-to-day operations and scale usage over time. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
When a contract ends, users can extract their data in a structured and accessible format. The service provides tools to export data, including project records, financial data, monitoring and reporting information, and supporting documentation, using common file formats such as CSV and spreadsheet files. Documents and attachments can be downloaded in bulk to ensure a complete record is retained.
Where required, we support users through the off-boarding process by agreeing the scope of data to be extracted and assisting with exports to meet organisational or contractual requirements. API access can also be used to extract data programmatically. Following confirmation that data has been successfully transferred, access to the service is removed and data is securely deleted in line with contractual terms and data protection obligations. - End-of-contract process
-
We supports an orderly and transparent off-boarding process to ensure continuity, data security, and compliance with contractual and data protection requirements. Continued access to the service remains available until the agreed contract end date, allowing users to complete in-flight activities and final reporting.
As part of the service, users can export their data in standard, accessible formats. This includes structured data such as project records, financial information, monitoring and reporting data, and audit trails, as well as bulk download of documents and supporting evidence. We work with customers to agree the scope and timing of data extraction.
Standard off-boarding activities, including data export support, access removal, and secure deletion of customer data from the live service, are included in the contract price. Data is deleted in line with contractual terms and applicable data protection obligations once confirmation is received that exports have been completed.
Additional costs may apply if customers require optional services beyond standard off-boarding. These can include extended access beyond the contract term, bespoke data transformation, large-scale data migration into a replacement system, or consultancy support for complex exit arrangements. Any such services are agreed in advance. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Pages reformat depending on the size of the device screen. The product is primarily designed for desktop use and will work with Tablet and Phone devices.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure, web-based interface available on desktop, tablet, and mobile devices. Users interact with intuitive dashboards, configurable menus, and role-based views to manage workforce deployment, reporting, compliance, and administration efficiently, without specialist technical knowledge.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- We have worked with a cohort of users with a wide range of disabilities to test the usability of our system, both directly and when used alongside assistive technologies. Testing has included users who rely on screen readers, keyboard-only navigation, screen magnification, and alternative input methods. Feedback from these sessions has been used to refine navigation structures, form layouts, labelling, focus order, and error messaging to improve accessibility and ease of use. This iterative testing approach helps ensure the service can be used effectively by people with different access needs and supports inclusive access to programme management activities.
- API
- Yes
- What users can and can't do using the API
- Our solution provides an application programming interface (API) that enables secure integration with external systems. The API is used to exchange data with third-party services such as finance and enterprise resource planning (ERP) systems, portals, and other programme management tools. It supports controlled data access for activities including registration, data submission, reporting, and financial workflows. API access is governed by role-based permissions and security controls to ensure data is shared safely and appropriately in line with client requirements.
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
What can be customised:
Users can configure workflows, roles and permissions, reporting dashboards, data fields, approval processes, and integrations with existing systems.
How users can customise:
Customisation is completed through secure administrative settings, configurable templates, and role-based controls, without requiring code changes.
Who can customise:
Authorised administrators and system managers within the customer organisation can manage and apply customisations.
Scaling
- Independence of resources
- Our product is delivered as a cloud-based SaaS solution hosted on scalable infrastructure designed to manage variable demand across multiple users and programmes. Resources are allocated and scaled to maintain consistent performance as usage fluctuates, ensuring that activity by one customer does not degrade the service for others. The platform uses logical separation of customer data and workloads, with monitoring in place to identify and address performance issues proactively. Capacity management, availability monitoring, and regular performance testing are used to maintain service levels and ensure reliable access for all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Our solutions provide service usage and operational metrics to help organisations monitor activity, performance, and adoption. Metrics include user activity levels, workflow status, task and approval volumes, application and assessment throughput, and partner or supplier engagement. Financial metrics cover budget utilisation, claims, payments, variances, and cashflow forecasts. Monitoring and reporting metrics track indicator progress, data submission rates, and delivery status across projects and portfolios. These metrics are available through configurable dashboards and reports, enabling users to analyse trends, identify risks, and support operational and management decision-making.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
- In addition to physical protections provided by Microsoft Azure, data at rest is protected through strong encryption using industry-standard algorithms. Encryption keys are managed securely within the cloud environment, with access restricted to authorised systems and personnel only. Customer data is logically segregated to prevent unauthorised access between tenants. Access to stored data is controlled through role-based permissions and least-privilege principles, with all access logged and monitored. Regular security reviews and independent penetration testing are carried out to ensure controls remain effective and data stored within the platform remains protected.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users export their data using built-in export tools and, where required, via the service’s API. Structured data such as project records, financial data, monitoring and reporting information can be exported in common formats including CSV and spreadsheet files. Documents and supporting attachments can be downloaded in bulk to ensure a complete offline record. Exports can be carried out by authorised users with appropriate permissions, allowing organisations to retain full ownership and control of their data at all times.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- In addition to encryption in transit, data is protected through layered network security controls within the hosting environment. Firewalls and network access controls restrict traffic to authorised services and ports only. Role-based access controls and strong authentication reduce the risk of unauthorised access if credentials are compromised. Traffic is continuously monitored and logged to detect anomalous or malicious behaviour, with alerts enabling rapid response. The service undergoes regular independent penetration testing by accredited providers, and vulnerabilities are remediated promptly. These measures work together to protect data as it moves between buyer networks and the service.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Within our network, data is protected through a defence-in-depth security model. Customer data is logically segregated to prevent unauthorised access between tenants. Access to systems is restricted using role-based access controls and least-privilege principles, with administrative access tightly controlled and audited. Data is encrypted at rest within the hosting environment, and secure key management practices are applied. Network segmentation and firewalls limit lateral movement within the environment. Continuous monitoring and logging are in place to detect suspicious activity, and regular independent penetration testing is carried out to validate the effectiveness of internal security controls.
Availability and resilience
- Guaranteed availability
-
Our product is delivered as a cloud-based SaaS service hosted on Microsoft Azure and is designed to provide high availability and resilience for users operating across multiple locations and time zones. The service is engineered to achieve a minimum of 99.9% availability, excluding planned maintenance, in line with the underlying cloud infrastructure service levels.
Availability is supported through the use of resilient cloud architecture, including redundant components, automated failover, and scalable resources that adapt to demand. The platform is continuously monitored to detect performance or availability issues, allowing rapid investigation and remediation where required. Maintenance activities that may affect availability are planned and scheduled in advance wherever possible to minimise disruption to users.
The service is used to support mission-critical programme management activities, including finance, grant management, and reporting, often in challenging operational environments. As such, resilience and reliability are core design principles. Regular testing, capacity planning, and security monitoring are carried out to maintain service stability as usage scales.
Where customers have specific availability or operational requirements, these can be discussed during onboarding and reflected in agreed service arrangements, ensuring the platform continues to meet user needs throughout the contract term. - Approach to resilience
-
Our solution is designed for resilience at both the application and infrastructure layers to ensure continuity of service and data integrity. The platform is hosted on Microsoft Azure, which provides a resilient datacentre setup with geographically distributed facilities, built-in redundancy, and high availability design. Core infrastructure components are replicated and designed to tolerate hardware or component failure without service interruption.
At the application level, our product uses a scalable, cloud-native architecture that can adapt to changes in demand and recover quickly from faults. Continuous monitoring and alerting are in place to detect issues early, and automated recovery mechanisms are used where possible. Regular backup processes protect customer data and support recovery in the event of data loss or corruption.
Capacity planning, routine testing, and independent security assessments help ensure the service remains stable and resilient as usage grows. Further details of the datacentre architecture and resilience measures are available on request for customers who require deeper assurance. - Outage reporting
-
Our solution reports outages and service issues primarily through email notifications and in-system alerts. Users are informed in advance of planned maintenance or planned outages, with notifications explaining the nature of the work, expected impact, and anticipated duration. Where service degradation or unplanned issues are identified, alerts are issued to keep users informed and to provide updates as the situation is investigated and resolved.
In-system alerts are visible to logged-in users and are used to communicate operational notices relevant to their use of the platform. Email alerts ensure key contacts are notified even if they are not actively using the service at the time.
The service does not currently provide a public status dashboard or outage reporting API. However, availability is continuously monitored internally, and issues are addressed proactively. This platform has experienced minimal outages over more than nine years of operation, reflecting the stability of the platform and its underlying cloud infrastructure.
This approach ensures users receive clear, timely communication about planned activities and any service issues, while avoiding unnecessary complexity for a platform used across diverse and often bandwidth-constrained operational environments.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access controls and least-privilege principles. Administrative and support access is limited to authorised staff whose roles require it, with permissions reviewed regularly. Strong authentication, including multi-factor authentication, is used for privileged access. Management activities are logged and monitored to provide an audit trail of actions taken within the service. Support requests are handled through controlled service desk channels, ensuring that only verified customer contacts can raise or receive information about incidents, configuration changes, or sensitive operational issues.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
MetricsLed follows formal information security policies and processes aligned with its ISO/IEC 27001–certified Information Security Management System (ISMS). These policies cover areas including access control, data protection, incident management, risk management, supplier security, business continuity, and secure system development and operation.
Information security governance is overseen by senior management, with clear accountability for maintaining and enforcing security controls across the organisation. Defined roles and responsibilities ensure that security risks are identified, assessed, and managed consistently. Security risks are reviewed regularly, and controls are updated to reflect changes in threats, technology, or business operations.
Policies are communicated to staff through onboarding, training, and ongoing awareness activities to ensure they are understood and followed. Compliance is reinforced through documented procedures, role-based access controls, logging, and monitoring. Security incidents and suspected breaches are reported through a defined incident management process, with escalation paths and corrective actions clearly set out.
Regular internal audits, management reviews, and independent external audits are used to verify compliance with policies and the effectiveness of controls. This structured approach ensures information security policies are embedded in day-to-day operations and continuously improved. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management is governed by documented processes aligned with ISO 9001 and ISO/IEC 27001. Service components are identified, versioned, and tracked through their lifecycle using controlled repositories and change records. Proposed changes are logged, reviewed, and approved before implementation. Each change is assessed for potential operational and security impact, including risks to data confidentiality, integrity, and availability. Changes are tested in controlled environments prior to release, with approvals required before deployment to live systems. All changes are auditable, and post-implementation reviews are carried out where appropriate to ensure controls remain effective.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Vulnerability management is governed by processes aligned with ISO/IEC 27001. Potential threats are assessed using risk-based analysis that considers likelihood, impact, and exposure to service availability and data security. Information on vulnerabilities is sourced from cloud provider security advisories, software vendor notifications, industry alerts, and findings from independent penetration testing. Identified vulnerabilities are prioritised according to severity and risk. Security patches and mitigations are deployed promptly, with critical patches applied as soon as practicable following testing, and lower-risk updates scheduled through controlled change management processes to minimise service disruption.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is used to identify potential compromises through continuous logging and monitoring of system activity, access events, and operational alerts within the hosting environment. Logs are reviewed to detect anomalous behaviour, unauthorised access attempts, or indicators of compromise. When a potential security incident is identified, it is assessed and handled through a defined incident management process, with escalation to appropriate technical and management staff. Responses are prioritised based on severity, with critical incidents investigated and contained as soon as practicable. Corrective actions and lessons learned are recorded to strengthen controls and reduce future risk.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Incident management for ML Project follows predefined processes for common security and operational events, aligned with our ISO/IEC 27001–certified information security management system. Users can report incidents through established service desk channels, ensuring issues are logged, prioritised, and tracked consistently. Incidents are assessed based on severity and impact, with clear escalation paths for technical and management response. Where required, incident updates and resolutions are communicated through the service desk, and formal incident reports are provided for significant events. These reports include details of the issue, actions taken, and any corrective or preventative measures implemented.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- UKAS
- ISO/IEC 27001 accreditation date
- Tuesday 26 September 2017
- What the ISO/IEC 27001 doesn’t cover
- All services described are fully inside the scope of our ISO 27001: 2022 certification
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- UKAS
- ISO 9001 accreditation date
- Tuesday 26 September 2017
- What the ISO 9001 doesn’t cover
- All services described are fully inside the scope of our ISO 9001: 2015 certification
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 24d3d62d-8824-42aa-a936-eb21d59d1e30
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 937fdce0-9508-4091-af56-07f0da7676fc
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
- Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder
- Ensuring accessibility to contracting and subcontracting opportunities for disabled business owners and employees
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-