Salesforce Heroku
Heroku, a Salesforce company enables developers to focus on application code and data instead of managing servers or operations. Code with agility in open source: Ruby, Node.js, Java, PHP and more. Deploy and scale on demand. Extend apps with 100s of different add-ons. Includes EU Model Contract Clauses.
Features
- Fully managed container runtime environment
- Scale, dynamically scale up or down instantly to meet demand
- Buildpacks, open source supported and supplied or build your own
- Config, manage specific configurations separately from your source code
- Deploy, with Git. We'll handle compilation, dependencies, assets and executables
- Fork, creates a duplicate instance of your application immediately
- Extend, over 100 add-ons, integrated to Heroku.
- Region, US, Europe and APAC, EU Model Contract Clauses supported
- Data sync into Salesforce Sales, Service, & Marketing Clouds
- Open source, Ruby, Node.js, Python, Java, PHP, Scala, Clojure, .Net
Benefits
- Efficient, Developers can focus on the app, not the infrastructure
- Skills, prevalent in the market giving you greater choice
- Community, active to help you learn and share code
- Cost, cheaper than hosting and supporting your own environment
- Agile, create new apps, then deploy on demand
- Platform, API automate/extend with services in a programmatic manner
- Security, Virtual Private Cloud, SSO with OAuth SAML & GDPR
- Flexibility, listed here avoiding lengthy credit-card approvals
- Heroku, Connect pre-built integration to the best of Salesforce
- Speed, scales to millions, exploit the AWS underpinings
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 4 9 8 8 4 1 2 2 9 1 5 3 7 4
Contact
INSIGHT DIRECT (UK) LTD
Public Sector Tender Team
Telephone: 0344 846 3333
Email: pstenderteam@insight.com
About your service
- Service categories
-
PaaS
Application Development
- Development languages, environments, and tools
- Software construction components
- Business rules management
- Modelling and architecture
Service scope
- Service constraints
-
Usage Limits: Services and content are subject to usage limits, including, for example, the quantities specified in order forms.
A user’s password may not be shared with any other individual.
If you exceed a contractual usage limit, we may work with you to seek a reduction in your usage so that it conforms to that limit. If, notwithstanding our efforts, you are unable or unwilling to abide by a contractual usage limit, you will execute an order form for additional quantities of the applicable services or content promptly upon our request.
Full details are contained in our terms and conditions. - System requirements
-
- Heroku Dashboard - web based use any browser
- Heroku CLI - for Mac OSX, Windows, Debian/Ubuntu and standalone
- Heroku API - connect programatically
- Cloud deployment model
- Public cloud
User support
- Email or online ticketing support
- Yes
- Support response times
- Guaranteed 30 minute response time on urgent issues. Urgent support available 24x7. Within Business Hours receive deployment consultations, architectural guidance and best practices from Customer Solutions Architects.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
- Urgent support available 24x7. Within Business Hours receive deployment consultations, architectural guidance and best practices from Customer Solutions Architects.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Customer Solutions Architects proactively assist customers onboard to the service - providing guidance on initial access and setup and continue to provide white glove support on an ongoing basis.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Dependent on the service being consumed. Code should alway exist outside of Heroku and should already be available - if not it can be extracted from applications on Heroku. Data stored in data services can be extracted using standard tools for the service being used. Extraction for add-on services will vary.
- End-of-contract process
- Off-boarding from the service will be specific to the nature of the code and service as deployed. The customer therefore always has access to the code, and the data held within the PaaS offering. Typically most customers use the supported databases in conjunction with Heroku, and as such data exports and backups can be taken as required. Code can be saved to GitHub such that off-boarding from Heroku is predictable. Being open source based Heroku can make your data available via an industry standard and easily readable format to make it as easy as possible for you to migrate to another service if you wish to do so.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Using the web interface
- The Heroku Dashboard is the web user interface for Heroku’s core features and functionality. It provides UI support for things like creating/renaming/deleting apps, configuring add-ons, managing Heroku Teams, creating Heroku Pipelines, deploying your application, viewing and responding to application metrics, and accessing usage, invoices and billing information.
- Web interface accessibility standard
- WCAG 2.2 AA
- Web interface accessibility testing
- No public information available.
- API
- Yes
- What users can and can't do using the API
- The platform API empowers developers to automate, extend and combine Heroku with other services. You can use the platform API to programmatically create apps, provision add-ons and perform other tasks that could previously only be accomplished with Heroku toolbelt or dashboard.
- API automation tools
-
- Ansible
- Chef
- Terraform
- Puppet
- Other
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- Other
- Command line interface
- Yes
- Command line interface compatibility
-
- Linux or Unix
- Windows
- MacOS
- Using the command line interface
- The Heroku Command Line Interface (CLI), formerly known as the Heroku Toolbelt, is a tool for creating and managing Heroku apps from the command line / shell of various operating systems. All capabilities available in the API are available via the CLI.
Scaling
- Independence of resources
- Heroku provides both single and multi-tenant instances. Single tenant instances are dedicated only for single customer use and isolated from the risk of 'noisy neighbours'. As a platform Heroku serves many billions of requests on a monthly basis.
- Usage notifications
- No
Analytics
- Infrastructure or application metrics
- Yes
- Metrics types
-
- CPU
- HTTP request and response status
- Memory
- Network
- Number of active instances
- Other
- Other metrics
- Request Throughput
- Reporting types
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Reseller (no extras)
- Organisation whose services are being resold
- Salesforce Inc
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Other
- Other data at rest protection approach
-
Data is encrypted at rest by using AES-256, block-level storage encryption. Data encryption is implemented using the AWS EBS disk encryption feature. Encryption keys are fully managed by AWS and are not visible to Heroku or Heroku customers.
Heroku automatically encrypts data-at-rest at the disk level for most Heroku plans; however, for customers with advanced encryption needs, there is the BYOK feature for Heroku data add-ons. This feature allows customers to create and manage their own Customer Managed Key (CMK) and the ability to disable the CMK which makes all data encrypted by the key inaccessible. - Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Backup and recovery
- What’s backed up
-
- Configuration - application configuration and settings
- Data - data stored in Heroku managed data services
- Other - backup capabilities of add-ons vary by provider
- Backup controls
-
Heroku performs automatic backups of the platform, customer application configuration, and Heroku data services attached to applications. Customers can trigger additional backups on a manual or scheduled basis.
Every Heroku database on the Standard tier or higher comes with an automatic Continuous Protection mechanism that captures physical backups for disaster recovery. Heroku uses physical backups for continuous protection by persisting incremental snapshots or base backups of the file system, and write ahead log (WAL) files to external, reliable storage. Snapshots are taken on most databases while the database is fully available and makes a verbatim copy of the instance’s disk. - Datacentre setup
- Multiple datacentres with disaster recovery
- Scheduling backups
- Users schedule backups through a web interface
- Backup recovery
- Users can recover backups themselves, for example through a web interface
- Backup and recovery
- Yes
- RPO/RTO
- Yes
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
-
Each application on the Heroku platform runs within its own isolated environment and cannot interact with other applications or areas of the system. This restrictive operating environment is designed to prevent security and stability issues. These self-contained environments isolate processes, memory, and the file system using Linux containers (LXC), while host-based firewalls restrict applications from establishing local network connections.
Customer data is stored in separate access-controlled databases per application. Each database requires a unique username and password that is only valid for that specific database and is unique to a single application.
Availability and resilience
- Guaranteed availability
-
Salesforce makes commercially reasonable efforts to make the online Purchased Services available 24 hours a day, 7 days a week.
Applications deployed on the Heroku Services and Customer Data submitted to the Heroku Services, up to the last committed transaction, are automatically replicated on a near real-time basis at the database layer and are backed up as part of the deployment process on secure, access controlled, and redundant storage.
Service availability information is available from - https://status.salesforce.com/products/Heroku - Approach to resilience
-
The Heroku platform is designed for stability, scaling, and inherently mitigates common issues that lead to outages while maintaining recovery capabilities. The platform maintains redundancy to prevent single points of failure, is able to automatically replace failed components, and utilises multiple data centres designed for resiliency. In the case of an outage, the platform is deployed across multiple data centres using current system images and data is restored from backups. Heroku reviews platform issues to understand the root cause, impact to customers, and improve the platform and processes. In the event of an interruption of Heroku services, details are posted on the status page: https://status.heroku.com/.
Production data centers used to provide the Heroku Services have access system controls in place. These systems permit only authorised personnel to have access to secure areas. These facilities are designed to withstand adverse weather and other reasonably predictable natural conditions, are secured by around-the-clock guards, two-factor access screening, and escort-controlled access, and are also supported by on-site back-up generators in the event of a power failure. - Outage reporting
- Status website, RSS feed and X
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- Access to the Heroku Services requires a valid user ID and password combination, which are encrypted via SSL/TLS while in motion and passwords are stored using a one-way salted hash. Alternatively, Heroku supports Single Sign On (SSO) utilizing SAML 2.0 which uses Public Key Encryption and does not require Heroku to store a password. Following a successful authentication, a randomly generated credential is transmitted to the user’s browser or command line interface (CLI). All subsequent requests are authenticated with that credential.
- Access restrictions in management interfaces and support channels
- Management access to services is restricted to specific personnel - fine grained control over which systems they have access to is in-place. Strong security rotation policies are in place and access to maintain the platform is only completed from authorised machines over secure channels. Heroku Support personnel only have access to customer applications if the customer gives them permission to do so.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
-
Access restriction involves utilising the Kerberos security system. Authentication through Kerberos is mandatory for certain roles to perform administrative tasks.
There are no login credentials to access customer production data, rather they have separate login credentials to their interface accomplished through a proprietary login credentialing system. - Devices users manage the service through
- Directly from any device which may also be used for normal business (for example web browsing or viewing external email)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
-
ISO 27017,
ISO 27018,
SOC 1/2/3,
HDS Certificate,
PCI DSS,
UK Cyber Essentials,
Data Privacy Framework (DPF) Program,
CSA STAR. - Information security policies and processes
- Salesforce's information security policies are based on the ISO 27002 framework of best practices and are ISO 27001 certified. The EVP of Security has responsibility for the information security policies and ISMS. The Salesforce Security Steering Committee approves/authorizes all changes to the policies, the Statement of Applicability (SoA), the information security manual, and any separate policy statements. During the ISO 27001 audit process (as well as other audits such as SOX and SSAE 16 SOC 1), Senior Management for various departments are involved in verifying that policies and procedures are in place and adhered to. Policies are reviewed/approved at least annually.
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Changes to Salesforce products in pre-production and production environments and data centers, including changes to applications, information systems, network topologies, configurations, and data center facilities, must be managed by a documented change control process and approved change management system.
The Heroku Security team performs change management in line with the Salesforce change management standards which closely align with the ITIL framework. Change Management processes dictate that system changes and maintenance are documented in Salesforce’s internal ticketing system. Changes require approval, security impact and risk analysis and testing prior to deployment. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Salesforce includes threat modelling into its software development lifecycle to help ensure the risks associated with potential threats are mitigated as early as possible. Multiple threat intelligence sources are used to help understand the current and evolving threat landscape.
Vulnerability scans are performed on all Salesforce information systems and hosted applications. Patches are deployed in timeframes based on CVSS scores and risk level.
All vulnerabilities discovered during penetration tests are entered into the salesforce central ticketing system and are assigned an internal vulnerability ranking according on the OWASP risk rating framework based on likelihood and impact. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Salesforce Threat Intelligence and Detection team monitors the Salesforce services 24x7 for threats and unauthorized intrusions in collaboration with the Security Incident Response teams. Extensive logging and monitoring is conducted across all Salesforce Services and environments (at application, network and database layers). All suspicious activities are flagged and reported to Salesforce CSIRT for investigation, management, communication, and resolution of security events and incidents in line with the NIST Incident Response model.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Salesforce has a formal Incident Management Process that guides the Salesforce Computer Security Incident Response team in investigation, management, communication, and resolution activities.
Salesforce will promptly notify the customer in the event of any security breach of the Service resulting in an actual or reasonably suspected unauthorized disclosure of Customer Data. Notification may include phone contact by Salesforce support, email to customer's administrator and Security Contact and public posting on trust.salesforce.com.
Salesforce.com is a member of the prestigious Forum of Incident Response and Security Teams (FIRST) and complies with the FIRST framework and best practices for incident response. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Separation between users
- Virtualisation technology used to keep applications and users sharing the same infrastructure apart
- Yes
- Who implements virtualisation
- Supplier
- Virtualisation technologies used
- Other
- Other virtualisation technology used
- Linux containers (LXC)
- How shared infrastructure is kept separate
- Each application on the Heroku platform runs within its own isolated environment and cannot interact with other applications or areas of the system. This restrictive operating environment is designed to prevent security and stability issues. These self-contained environments isolate processes, memory, and the file system using Linux containers (LXC), while host-based firewalls restrict applications from establishing local network connections. Infrastructure uses a fully virtualized hardware provided by AWS.
Energy efficiency
- Energy-efficient datacentres
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Customers can sign-up and use Heroku for free - lightweight 'free' dynos are available and most add-on services offer a free-tier to support testing of the service and capabilities.
- Link to free trial
- https://www.heroku.com/free
Discount
- Provide your minimum discount applicable to your baseline prices
- 0%
Formula for calculating price of your services
- Formula for calculating price of your services
-
Which of the core deployment models you intend to offer
- Public Cloud
- Private Cloud
Public Cloud - Formula for calculating price of your services
- Total Cost
- The Total Cost for a buyer's call off requirement in a Public Cloud Deployment
- =
- Baseline Pricing
- G-Cloud Digital Marketplace
- Baseline Pricing - Web link
- https://www.gov.uk/digital-marketplace
- -
- Minimum Discounting
- 0%
- +
- Onboarding Activity
- Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
- +
- Additional sources of cost
-
Unmanaged cloud activity can increase costs and risk for public sector buyers. Key drivers include data movement (inter‑region/zone egress, CDN origin fetches, Azure ExpressRoute metered egress, AWS NAT Gateway, Google Cloud Interconnect/NAT), storage and backup (snapshot sprawl, cold‑tier retrieval, Azure Archive rehydration, AWS Glacier tier fees, Google Coldline early deletion), compute/database inefficiencies (oversized instances, unattached disks/IPs, mis‑tuned autoscaling, misaligned reserved commitments), observability/serverless overhead (log ingestion/retention in Azure Log Analytics, AWS CloudWatch, Google Cloud Logging; serverless retries and event fan‑out), licensing/marketplace charges, and governance gaps (untagged resources, idle dev/test).
Insight mitigates these risks with egress‑aware architecture reviews, commitment management, tagging and lifecycle policies, budget alerts, and chargeback frameworks aligned to ISO 27001, Cyber Essentials and NCSC guidance. Changes are validated against performance, security and compliance requirements prior to implementation to avoid service disruption. Typical engagements reduce unmanaged cost growth by 20–30%, improving accountability through transparent reporting and showback/chargeback. Continuous optimisation ensures commitments track actual usage and observability and storage footprints remain controlled, helping buyers maintain predictable budgets, meet governance obligations and reinvest savings into priority services. - -
- Additional sources of cost reduction
-
Insight enables UK public sector organisations to achieve predictable, sustainable cloud cost reductions across Microsoft Azure, AWS and Google Cloud. As an Azure Expert MSP, AWS Premier Consulting Partner and Google Cloud Premier Partner, we apply proven methodologies aligned with recognised standards such as ISO 27001, Cyber Essentials and NCSC guidance.
Sources of cost reduction include:
Reserved Instance and Savings Plan optimisation to maximise discounts.
Rightsizing and workload alignment to eliminate overprovisioning.
Automated assessments and governance frameworks to detect inefficiencies early and enforce compliance.
Proprietary dashboards for real-time spend visibility and scheduled reviews for continuous optimisation.
Our approach combines automation with expert-led reviews, ensuring savings without service disruption or security compromise. Typical engagements deliver 20–30% cost reductions across multi-cloud environments. For example, Insight helped a UK government agency cut Azure costs by 28%, reinvesting savings into public-facing digital services.
Risk mitigation is central to our process: optimisation changes are validated against performance and compliance requirements before implementation. Buyers benefit from transparent reporting, predictable budgets and reinvestment opportunities, all delivered through a structured, repeatable methodology tailored to public sector needs.
Private Cloud - Formula for calculating price of your services
- Total Cost
- The Total Cost for a buyer's call off requirement in a Private Cloud Deployment
- =
- Baseline Pricing
- G-Cloud Digital Marketplace
- -
- Minimum Discounting
- 0%
- +
- Onboarding Activity
- Onboarding costs may vary based on your specific requirements, please confirm with suppliers during the clarification process
- +
- Additional sources of cost
-
Unmanaged cloud activity can increase costs and risk for public sector buyers. Key drivers include data movement (inter‑region/zone egress, CDN origin fetches, Azure ExpressRoute metered egress, AWS NAT Gateway, Google Cloud Interconnect/NAT), storage and backup (snapshot sprawl, cold‑tier retrieval, Azure Archive rehydration, AWS Glacier tier fees, Google Coldline early deletion), compute/database inefficiencies (oversized instances, unattached disks/IPs, mis‑tuned autoscaling, misaligned reserved commitments), observability/serverless overhead (log ingestion/retention in Azure Log Analytics, AWS CloudWatch, Google Cloud Logging; serverless retries and event fan‑out), licensing/marketplace charges, and governance gaps (untagged resources, idle dev/test).
Insight mitigates these risks with egress‑aware architecture reviews, commitment management, tagging and lifecycle policies, budget alerts, and chargeback frameworks aligned to ISO 27001, Cyber Essentials and NCSC guidance. Changes are validated against performance, security and compliance requirements prior to implementation to avoid service disruption. Typical engagements reduce unmanaged cost growth by 20–30%, improving accountability through transparent reporting and showback/chargeback. Continuous optimisation ensures commitments track actual usage and observability and storage footprints remain controlled, helping buyers maintain predictable budgets, meet governance obligations and reinvest savings into priority services. - -
- Additional sources of cost reduction
-
Insight enables UK public sector organisations to achieve predictable, sustainable cloud cost reductions across Microsoft Azure, AWS and Google Cloud. As an Azure Expert MSP, AWS Premier Consulting Partner and Google Cloud Premier Partner, we apply proven methodologies aligned with recognised standards such as ISO 27001, Cyber Essentials and NCSC guidance.
Sources of cost reduction include:
Reserved Instance and Savings Plan optimisation to maximise discounts.
Rightsizing and workload alignment to eliminate overprovisioning.
Automated assessments and governance frameworks to detect inefficiencies early and enforce compliance.
Proprietary dashboards for real-time spend visibility and scheduled reviews for continuous optimisation.
Our approach combines automation with expert-led reviews, ensuring savings without service disruption or security compromise. Typical engagements deliver 20–30% cost reductions across multi-cloud environments. For example, Insight helped a UK government agency cut Azure costs by 28%, reinvesting savings into public-facing digital services.
Risk mitigation is central to our process: optimisation changes are validated against performance and compliance requirements before implementation. Buyers benefit from transparent reporting, predictable budgets and reinvestment opportunities, all delivered through a structured, repeatable methodology tailored to public sector needs.
Mandatory certifications
- Mandatory certifications
-
Are you are bidding to offer IaaS and/or PaaS as a reseller or are you in sole control of the infrastructure
ResellerCloud service suppliers you intend to resell with evidence
Organisation 1
Organisation name
AWSWebsite address/upload for organisation
Website addressWebsite address
https://partners.amazonaws.com/partners/001E000000UfalBIAR/Insight%20EnterprisesOrganisation 2
Organisation name
MicrosoftWebsite address/upload for organisation
Website addressWebsite address
https://marketplace.microsoft.com/en-us/partners/8bc78177-662b-440b-ae00-bbc5bf193536/overviewOrganisation 3
Organisation name
GoogleWebsite address/upload for organisation
Website addressWebsite address
https://cloud.google.com/find-a-partner/partner/insight-direct-uk-ltdOrganisation 4
Organisation name
SalesforceWebsite address/upload for organisation
UploadUpload
ProvidedISO 9001 certification
ProvidedISO 27001 certification
ProvidedISO 20000-1 certification
ProvidedAre you reliant on the Cloud Service Provider for some accreditations
Yes
Cyber Essentials
- Do you have a Cyber Essentials Plus certificate?
- Yes
- Cyber Essentials Plus certificate Number
- Cd8b1a78-44c7-4bb0-84d6-59a7506f3bba
Non-mandatory Standards and certifications
- ISO 28000:2022 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
-