GOSS Self-Service (CRM)
The low-code GOSS Self-Service Platform provides public sector clients Local/Central/Government/Authority/ Council/Police/NHS) with CRM-lite capabilities to build forms website portals, workflows, and online customer transactions all underpinned with AI interoperability. It enhances self and assisted-service for citizens, reduces organisational overhead, and supports optional integrations with AI and back-office systems.
Features
- Plug-in to existing websites. No need to replace CMS.
- Responsive WCAG accessible portal design accelerates desktop to mobile channel-shift.
- Task Manager: control panel for case management and job allocation.
- Web Forms, Process Mapping and Workflow, MyAccount, Self-Service, Assisted-Service.
- Utilise complex business process mapping (BPM) and transaction logic.
- Citizens can upload pictures for incident reporting.
- Process: Customer Experience Management, Personalised Content, Channel Shift Online.
- Electronic enquiry forms can be linked to intelligent workflow processes.
- Cloud Support Services available to achieve Digital Services/Customer Self-Service.
- Options: Payment Connectors, Authentication, Performance Dashboards, Case Management.
Benefits
- Significant savings available by providing end to end digital services.
- Business Transformation: proven return on investment (ROI) within months.
- Improved customer satisfaction encourages additional online self-service, further reducing costs.
- CRM-Light: Business Process Mapping logic enables efficient integrated transactions.
- Forms integrate easily: quicker back office integrations. AI/Chatbot integration.
- Customer Account self-service 24/7 from mobile devices/tablets/desktops.
- Secure Authentication services: Google, GOV.UK One Login, MyGovScot etc.
- Customer Service Agents assist citizen transition to Self-Service.
- Automatically update customers via emails/system updates throughout active transactions.
- England, Scotland, Wales, NI User Group Community shares best practice.
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 4 4 6 3 6 9 2 1 9 8 0 1 9 8
Contact
GOSS INTERACTIVE LIMITED
Simon Smith
Telephone: +44 844 880 3637
Email: bids@gossinteractive.com
About your service
- Service categories
-
Applications
Customer relationship management
- Digital commerce
- Customer service
- Contact centre
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
-
GOSS Content (Content Management System).
Other 3rd party CMS for websites and/or intranets. - Cloud deployment model
- Public cloud
- Service constraints
- Scheduled maintenance applied as per Service Definition. Scheduled maintenance will be agreed as required. Support available for GOSS-trained users.
- System requirements
-
- A modern supported and up-to-date browser i.e.
- Chrome
- Edge
- Firefox
- Safari
User support
- Email or online ticketing support
- Yes
- Support response times
- Support responses will vary in line with the software service purchased and the incident priority (based on severity/nature). UK-based Service Helpdesk open 8am to 6pm Monday to Friday excluding English Bank Holidays for emails and calls where applicable. Online ticketing available 24/7/365. Hosting monitoring provided 24/7/365. Please refer to detailed support SLAs in the GOSS Service Definition document.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support provided within the GOSS Cloud Software Service fee includes:
- Service monitoring and maintenance by a team of dedicated Network Support and Automation Engineers, maintaining and supporting the SaaS infrastructure 24/7/365.
- Application updates automatically applied or as required by new software releases and relevant to the software service/level chosen.
- Support provided to GOSS-trained users via a combination of (i) online 24/7/365 ticketing (ii) office hours email (iii) office hours Help Desk support. See Service Definition document for support levels/response. Incidents are allocated an issue-appropriate priority level and responded to accordingly by the UK-based Support Team.
- To ensure ongoing customer satisfaction, an Account Manager is allocated to each client and will be in regular contact, keeping you informed of client best practice examples and new service features.
- Support upgrades and additional support and consultancy from the GOSS Client Success Team can be provided based on a day rate or service expansion fee if required. GOSS Pricing/Service Definition Documents provide more details. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
A Project Manager and Account Manager are assigned, and will review any client requirements for specific configuration and support. A flexible delivery plan is agreed with the client which covers the deployment of the requested Cloud Service, together with any optional expansions (modules) and any known configuration requirements. An initial standard platform will be delivered and contain exemplar sample content (site configs, example forms etc), complemented by the free GOSS Community content such as forms. The onboarding deployment process commences, configuration begins, and a training consultation takes place to ensure an appropriate training programme is delivered for the range of client trainees. Clients are provided a selection of online training depending upon their specific needs.
User documentation includes: online context-sensitive help, a help website and training guides when training is provided.
The GOSS Client Success Team is available to provide a range of cloud support services to support a variety of projects, throughout the contract term.
Each Client’s online MyGOSS Account provides a range of relevant information on client infrastructure configuration, deployment pipeline, and will also include billing and monitoring information. - Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Training webinar session recordings
- End-of-contract data extraction
- As detailed in the online GOSS Client Service Manual, the secure offboarding data extract process will be agreed as part of the Client Exit Plan and agreed within the Client Call-Off Contract. GOSS can provide a data extract in a structured, commonly used and machine readable format. Once complete and after the agreed retention period, data will be destroyed in line with GOSS ISO 27001 information security policies.
- End-of-contract process
-
The GOSS Exit Plan will be implemented in accordance with the Call-Off Agreement and aligned with GOSS ISO 27001–compliant information security processes. Exit activities are managed through a structured Leaver Checklist and completed within the agreed termination period. These activities include secure data extraction and transfer, financial reconciliation, the controlled removal of access to support systems, updates to internal systems/records, and the secure decommissioning of servers and environments where applicable.
Whether exit occurs as a result of contract expiry, termination, or transition to an alternative supplier, continuity of service will be maintained throughout the notice period, as defined in the original contract. During this period, the service will continue to operate to agreed service levels, ensuring no unnecessary disruption to users or business operations.
All customer data will be securely held, transferred, returned, or destroyed in line with contractual requirements, data protection legislation, and information security policies. Knowledge transfer and the provision of relevant documentation will be completed as required to support a smooth and orderly transition. Costs, timescales, responsibilities, governance arrangements, and legal obligations associated with exit will be clearly defined, agreed, and communicated to ensure transparency and minimise risk for the buyer. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The websites, intranets or self/assisted-service portals managed using this service are responsively designed so that content including pages and electronic forms, will automatically resize appropriate to the device accessing the page, be this a desktop, tablet or mobile device, enabling end customers/citizens to view sites as required. All platforms are built mobile-first and have the GOSS PWA (Progressive Web App) expansion available as standard.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- GOSS Platform solutions are accessed via a suitable browser and used by clients to configure sites and citizen portals with content, forms & processes and integrations which together deliver end-to-end digital services. Staff and customers then use browser-based device responsive & accessible sites/intranet/portals to access content/digital services/account info as required. Actual site content will vary with the Platform selected.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
For all products, services and Themes, GOSS checks non-functional requirements (including performance, security and accessibility) at various stages of the software development lifecycle. This ranges from component-level performance and security testing through to larger solution-based performance and penetration testing.
Testing of markup validity (W3C compliance) and browser and device compatibility helps ensure interfaces are usable for assistive technology users and beyond. Where appropriate, and before building solutions, testing sessions can be run using interactive prototypes to review design usability, allowing users to click through designs to understand what is working and to explore alternative design approaches, including A/B testing.
GOSS ensures solution-managed websites are WCAG 2.2 AA compliant and verifies this using a range of recognised accessibility validators and testing tools. Given the wide range of commercially available assistive technologies, it is not feasible to test against every tool; instead, the approach is to meet international accessibility standards that assistive technologies themselves are designed to support.
GOSS Cloud Software Services include accessible site themes, portals and intranets tested to WCAG 2.2 AA. GOSS clients use a range of assistive technologies to access websites, intranets and portals delivered through the platform. - API
- Yes
- What users can and can't do using the API
- Access to elements of the GOSS Self-Service Platform is possible using the Platform’s API Server. The Server runs multiple Worker-Services, each of which has its own documented API. These services are called using JSON-RPC and have highly configurable security settings which combine internal/external flags, IP restrictions, API Keys and user defined access controls. Library content is available for use in forms using the iCMAPI Worker. The Forms Platform has access to the full range of Worker Services including the FormUtilities, Authentication, Email, Postcode Lookup and Case Management APIs. The services and solutions delivered using the Self-Service Platform can be queried, created and updated via dedicated APIs. These include the History Worker, which provides a flexible and extendable logging module for services, and the Workflow Worker Service, which provides the underlying technology for the GOSS Business Process Implementation. The Platform and associated Blockly editor can easily support the provision of appropriate AI calls and service delivery via low-code prompts and instructions.
- API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- MyAccount self/assisted-service portal content can be edited such as forms, processes, (case types, tasks and workflow for case management) and end-to-end transactional services including End Point Integrations. Customisations are performed using various Self-Service Platform tools such as the drag and drop forms designer, the process and workflow engine, and End Point creator (API server) which, when combined, can create effective online end-to-end transactional services. These are then accessed via the citizen's MyAccount for customer self-service and assisted-service. Users with appropriate permission can edit the above features. Administrators can control which users and user groups can access and edit different parts of the Platform, based on granular access permission settings. Please see the service definition for more information.
Scaling
- Independence of resources
- The infrastructure allows us to seamlessly increase resources for a particular service or expand the resilience and capacity by adding more virtual machines to the environment. Tenants of the platform are fully segregated using logical security controls, dedicated private networks and dedicated resource reservations. Each individual server and service is carefully calibrated to achieve optimum efficiency and performance. Services are scaled to meet client transactional volumetric requirements and anticipated growth, in line with the suggested fair usage policy, as detailed in the Service Definition Document.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Monthly uptime availability performance reports. Google Analytics statistics/metrics provided within application. Software includes management reporting function, logs etc. Qualitative and quantitative Client-Service dashboards are configurable.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- HTML, XML, CSV, BPMN2.0, JSON (for case management)
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- HTML
- XML
- BPMN 2.0 XML
- JSON (for case management)
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- HTML, XML
- BPMN 2.0 (for processes only Forms)
- Media files into Media Library
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection between networks
- We aim to implement the Transport Layer Security protocol (TLS version 1.2 or above) to protect data in transit for all services and service access. We also apply certificate and TLS hardening best practices wherever necessary. Where HTTPS cannot be used, such as some connections between our service and 3rd party suppliers (or your own systems) we implement IPSec VPN gateways. IPSec VPN gateways are also used for non-http based integrations. GOSS can work with individual clients to ascertain and meet protection needs, based on their individual security/service requirements. Please note additional GOSS Cloud Support fees may be applicable.
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- Data flows and storage from different clients are segregated from one another, flowing across dedicated networks and stored in dedicated locations for each client using security best practices recommended by the cloud provider. All traffic and storage will be kept within the cloud provider’s secure networks and not traverse the internet unencrypted. Any data that is stored outside of the cloud provider, such as offsite backups, are encrypted with industry standard encryption methods such as GPG.
Availability and resilience
- Guaranteed availability
- 99.95% site availability. 24/7/365 hosting support. See GOSS Terms and Conditions for service credit schedule relating to site availability.
- Approach to resilience
-
The GOSS Cloud Services platform is powered by a number of public cloud providers, including Amazon Web Services (AWS) and Google Cloud Platform (GCP) using UK only data centres, ensuring a cloud-agnostic, secure, and highly available service for our clients. This multi-provider approach allows us to deliver resilient infrastructure with robust redundancy, failover, and disaster recovery capabilities.
Detailed information on our approach to service delivery, setup, high-availability architecture, and resilience measures is available upon request and is documented in the online Client Services Manual provided to all clients. This approach aligns with the NCSC’s 2nd cloud security principle, ‘Asset protection and resilience’, ensuring continuity of service even in the event of infrastructure or service disruptions. - Outage reporting
- GOSS Incident ticketing system is used.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Other
- Other user authentication
- 2-factor authentication for site registration and configurable for site access. 3rd party (i.e. Google, social media, etc) via GOSS Expansions. Anonymous citizen use is possible where designed and allowed by you. VPN Expansion is available. See Pricing/Service Definition for more details.
- Access restrictions in management interfaces and support channels
-
Management Interfaces are controlled by a powerful and granular user management system. System Administrator can configure a range of users with access to various parts of the service as required.
Support is provided to GOSS-trained users as listed in the GOSS Support System. Any system config is subject to the GOSS ISO certified Change Control procedure which requires sign-off by system admin as defined in the GOSS Service Manual. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
- Other
- Description of management access authentication
- 2fa can be configured to be used on any site/portal.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials and Cyber Essentials Plus
- Information security policies and processes
-
GOSS is certified to ISO 27001 (Information Security Management) and Cyber Essentials Plus. All staff receive induction, regular training, and assessments on relevant ISO policies and processes, as defined in the GOSS Quality & Information Security Manual. The Compliance Manager, reporting to the CEO, oversees implementation, ongoing training, and compliance with all ISO policies and processes. Internal and external audits are conducted regularly to verify ongoing adherence.
Staff access the secured intranet for key documents, including the Quality & Information Security Manual, Information Asset List, Statement of Applicability, and the Disaster Recovery/Business Continuity Plans.
The Information Security Manual (ISMS) defines the company Security Policy and outlines responsibilities for risk management, asset management, HR security, physical/environmental security, access control, operational control, and business continuity. Senior Management are updated on ISO issues and ensure relevant information is communicated across teams.
All staff are responsible for complying with ISO policies in their daily activities, ensuring the organisation maintains robust information security standards. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Changes follow the ISO 9001:2015 Change Control process, with security risks and impacts assessed for major releases/updates/fixes. Subversion/GitLab logs all components, enabling full rollback and an audit trail of user, date, and reason. Code changes are comparable across templates, stylesheets, JavaScript, and application code. Urgent security fixes may be deployed as required. Staged automated deployments run across environments, with customer-specific changes scheduled separately. GitLab tooling is used for Code Reviews and Merge Request management. Working group approval is required for Product changes before release. Bespoke changes require documented Change Requests, risk assessments, rollback plans, and approval before CI/CD pipeline release.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- ISO 27001:2022 process: regularly monitor/scan servers/computers/network for vulnerabilities. Should any be found it is policy to assess for severity, impact and urgency, and mitigate the issues as required. All are managed and maintained within a risk log. Constant monitoring across all major security bulletins ensures that our Development/Network Engineers are immediately notified should problems arise. Actively review OWASP news feeds to learn, adapt to, implement latest security standards in all GOSS products and services. Network Engineers monitor security bulletins from relevant vendors and organisations such as CERT UK, CISA (US CERT), Cisco, Red Hat, Rocky Linux, Microsoft and VMware.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- ISO 27001:2022 process following industry best practice: Network Engineers monitor security bulletins from relevant vendors and organisations such as CERT UK, CISA (US CERT), Cisco, Red Hat, Microsoft and VMware and take positive action where required in line with the GOSS ISO Security Manual. A centralised site availability monitoring system is used to automatically alert engineers in and out of hours, depending on the impact and the severity of the event. An event will automatically get escalated if an on-call engineer does not investigate within a certain period of time as per our Incident Management Policy and SLA.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The GOSS ISO27001 Security Manual details the Incident Management Policy for the management/reporting of security incidents. The objective is to minimise the damage from security incidents and to monitor and learn from such issues. The process for incident management covers software, hosting or client support related issues including documented call-out procedure and escalation procedure. Support process defines incident priorities and response/resolution timescales. Support service varies with Software Service Level chosen: client incident reporting via 24/7/365 online ticketing system, email or phone during stated helpdesk hours. Incident reports and updates are provided via the GOSS online ticketing and reporting system.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0.5%
- Between £2,500,001 and £5,000,000
- 1%
- Over £5,000,001
- 1.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus ISOQAR (for UKAS)
- ISO/IEC 27001 accreditation date
- Tuesday 22 April 2025
- What the ISO/IEC 27001 doesn’t cover
- Nothing. Please note that 3rd-party hosting service provision is covered by the 3rd party's own ISO 27001 certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Independent European Certification Ltd
- ISO 9001 accreditation date
- Saturday 16 March 2024
- What the ISO 9001 doesn’t cover
- Nothing. Please note that 3rd-party hosting service provision is covered by the 3rd party's own ISO 9001 certification.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Df385545-6c6d-4931-9542-bd8d2b2323ca
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- C6f65ed6-ca71-4f50-acd3-790373aa111e
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-