Intranet, Employee Experience and Digital Workplace platforms
SaaS intranet, digital workplace / employee experience app / platform (eg Workvivo from Zoom, Flip, Blink, Haiilo, Staffbase, Humand, Sharepoint, Viva Engage...)
Features
- Internal Communications
- Employee Engagement
- Digital hub / application access
- Staff Networks / community
- Collaboration
- Frontline access / connection
Benefits
- Frontline and desk based internal communications
- Sharing news and updates
- Best practice sharing
- Onboarding new starters
- Embedding culture and values
- Leadership visibility
- Strategy engagement
- Operational efficiencies
- Knowledge sharing
- Policies and procedures engagement
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 8 6 1 0 5 3 0 1 5 5 8 0 2 7
Contact
WORK NETWORKS LIMITED
Nick Crawford
Telephone: 07985723655
Email: nick.crawford@worknetworks.co.uk
About your service
- Service categories
-
Applications
Collaborative
- Enterprise community
- Team collaboration
Conferencing and virtual event
- Web Conferencing Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Microsoft Office 365, Google Workspace, Workday, Oracle, SAP, Concur, other operational, HR, Finance SaaS apps etc
- Cloud deployment model
-
- Public cloud
- Hybrid cloud
- Service constraints
-
Our target availability uptime is 99.5% as per our SLA - actual uptime is currently 99.9998% in the last 3 years
- Workvivo continuously deploys updates/new features with a zero downtime approach
- If required, there is a maintenance window in the Support Policy for major updates that require downtime.
Customers are notified in advance (this has been required once in the last 4 years - System requirements
-
- All users require a software licence
- Accounts provisioned via csv or directory sync
- Can integrate with any IdP that supports SAML 2.0
- IOS / Android, tablet, browser and tv screen access
User support
- Email or online ticketing support
- Yes
- Support response times
- Under 1 hour (including weekends)
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- AI Agent built with Zendesk
- Onsite support
- Yes
- Support levels
- We provide core on site and online implementation support for tech, architecture, comms, training and leadership coaching, included with software licence costs. Additional support costs vary depending on deal size, but where possible is rolled into the software package (Gold, Silver etc, varying slightly across different software options)
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- We provide comprehensive onboarding and implementation services across, strategy, change management, technology, communications, architecture, launch planning and delivery, and post launch ongoing partnership and (data driven) customer success services
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
Customers are data owners and can request a full data download from their platform when the contract ends.
Where a customer has decided to cancel their account, their account enters an “inactive” state. If the customer decides to change their mind, it can be reactivated again within 30 days of becoming inactive. On request, we can forego this grace period altogether and permanently delete all data as required.
Note: You can choose to increase the retention period for your organization e.g. 60 / 90 / 180 days - End-of-contract process
-
Included in the price of the contract is platform access to all licenced users, core implementation services, and ongoing support. Where a customer has decided to cancel their account, their account enters an “inactive” state. If the customer decides to change their mind, it can be reactivated again within 30 days of becoming inactive. On request, we can forego this grace period altogether and permanently delete all data as required.
Note: You can choose to increase the retention period for your organization e.g. 60 / 90 / 180 days - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Services are optimised for 'mobile first' (eg frontline employees) access, delivering the same core features and functionality on mobile and desktop. Some admin and eg internal communicator / super user features have richer experience via browser, harnessing the larger screen real estate.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
-
Desktop
Web Browser via URL -
Desktop App (Windows, Mac & Linux)
Mobile
Native Mobile App on iOS & Android
Tablet
Native iPad Application
Web Browser (web application is fully responsive)
TV
Deployed via Web Browser on Smart TVs - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
1. We always keep the Web Content Accessibility Guidelines (WCAG) 2.2 at the core of our software development process to ensure inclusivity and accessibility for all users. We strive to meet Level A and AA aligning with WCAG 2.2 Version 2.5, reflected in our VPAT, addressing key accessibility barriers and ensuring our software is accessible to users with accessibility needs.
2. One of the core principles is to build inclusive software that caters not only to individuals with accessibility needs but also people who speak different languages, have different cultural backgrounds and different use cases. Our commitment to inclusivity drives us to create experiences that are accessible across various platforms, including web, mobile, TV, and email, ensuring accessible in the most convenient manner for every user whether based at the office, at home or anywhere.
3. We actively engage with our engineers, emphasising the importance of adopting best practices in accessible web development. This includes the use of semantic HTML, appropriate ARIA labels, and other critical considerations.
4. Engagement with our user community, is a priority for us. We regularly meet with users, including those with accessibility needs to gather feedback and identify opportunities for enhancement. - API
- Yes
- What users can and can't do using the API
-
Notification API Framework:
Surfacing 3rd party notifications
APIs and Webhooks:
Push / Pull content with 3rd party platformsDeep Linking:
Eg Application Launcher, Mega-Menu, Quick Links Widget, Pages
Standard integrations:
Eg Automated User Provisioning, Single Sign On
Productivity Suites:
Eg Google Workspace and Microsoft Office 365
Out of the box connectors:
Workday, YouTube, Jira, Confluence, Slack, Box, LinkedIn etc.
Zoom integrations:
Eg Quick Links to initiate a meeting, chat, call or access Zoom
Products
Embedded Content:
Embedded forms, pages, content from 3rd party platforms - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Admins can fully customise the platform eg Branding, Features (all modular, can be switched on / off), Content Areas, Communities, Structure, Permissions.
End users can customise experience, notifcations as allowed by admins.
Scaling
- Independence of resources
-
Performance Testing
- QA and Infrastructure Teams maintain a ‘Performance Platform’ that replicates the ‘Production Platform’ to run various load tests and stress tests at scale
- Performance Tests involve both protocol-level and browser-level load tests against our performance environment.
The product provides the ability to simulate user traffic from 12 geographic regions
- These are conducted in line with any major new features being released.
- Major Performance and Stress Tests are also conducted on a regular basis
Analytics
- Service usage metrics
- Yes
- Metrics types
- User activation / onboarding metrics, activity, content engagement, platform access (mobile / browser), activity by geography, function, employee insights, advanced analytics tools,
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Workvivo by Zoom, Flip, Blink, Haiilo, Staffbase, Humand, Simpplr, Microsoft
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with another standard
- Other
- Other data at rest protection approach
-
All data encrypted at rest with 256-bit AES encryption
and in-transit, including all backups, snapshots and
replicas. - Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Admins can request data export from the support team, plus some exports are self service from within the admin panel.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
-
Our target availability uptime is 99.5% as per our SLA - actual uptime (eg Workvivo) is currently 99.9998% in the last 3 years
- Workvivo continuously deploys updates/new features with a zero downtime approach
- If required, there is a maintenance window in the Support Policy for major updates that require downtime.
Customers are notified in advance (this has been required once in the last 4 years
- Customers have visibility to system uptime via our Status Dashboard - Approach to resilience
- SOC2 and other infosec information is available to customers on request.
- Outage reporting
- Public dashboards, email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is strictly restricted to authorised users. Administrative access is role-based and granted on a least-privilege basis. Multi-factor authentication is enforced for all administrative and support accounts. Access is approved by management, logged, and reviewed regularly, with immediate removal upon role change or termination. Support access to customer environments is controlled, time-limited where appropriate, and performed only for legitimate support purposes, ensuring customer data is protected at all times.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We operate a formal Information Security Management framework designed to protect the confidentiality, integrity, and availability of client, partner, and company data. Our policies and processes are aligned with recognised best practice, including the principles of ISO/IEC 27001 and the UK GDPR.
Governance and Policy Framework
We maintain documented information security policies covering:
• Information security governance and risk management
• Data protection and privacy
• Access control and user management
• Acceptable use of systems and devices
• Incident management and breach response
• Business continuity and disaster recovery
Policies are reviewed at least annually and updated in response to regulatory, technical, or business changes.
Access Control and Identity Management
• Access to systems and client data is granted on a least-privilege basis.
• User access is role-based and approved by management.
• Multi-factor authentication (MFA) is enforced on all critical systems, including cloud platforms and email.
• Access rights are reviewed regularly and immediately revoked upon role change or leaver events.
Supplier and Cloud Security
• We partner with reputable software vendors and cloud providers that demonstrate strong security controls and compliance standards.
• Supplier security is considered as part of onboarding and ongoing relationship management. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- We follow controlled configuration and change management processes to ensure system stability, security, and traceability. Standard configurations are documented and maintained for all core systems and cloud platforms. Changes are risk-assessed, approved, tested where appropriate, and implemented in a controlled manner. All changes are logged and reviewed, with rollback plans in place for material changes. Access to make configuration changes is restricted to authorised personnel and follows the principle of least privilege.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We manage vulnerabilities in line with Cyber Essentials principles. Potential threats are assessed through regular review of system software, configurations, and exposure to known vulnerabilities, with risk determined by severity and impact. Security updates and patches are applied promptly, with critical updates installed within 14 days, or sooner where practicable. We obtain vulnerability information from trusted sources including software and cloud service providers, the National Cyber Security Centre (NCSC), CERT advisories, and recognised security bulletins. This ensures known vulnerabilities are identified and addressed in a timely and controlled manner.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We operate protective monitoring processes to detect and respond to potential security compromises. Monitoring includes review of security alerts, system logs, and activity within cloud platforms and endpoint protection tools to identify suspicious or unauthorised behaviour. Potential compromises are assessed promptly and escalated in line with our incident response process. Where an incident is confirmed, containment and remediation actions are taken without undue delay, including access restriction, system updates, and investigation. Security incidents are responded to as soon as practicable, with priority given to high-risk or confirmed compromises.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We operate a defined incident management process to ensure security and service incidents are handled consistently and effectively. Pre-defined procedures are in place for common events such as account compromise, malware alerts, and service disruption. Users report incidents via designated internal channels or by contacting the service desk. All incidents are logged, assessed, and prioritised based on impact and risk. Where required, incident reports are produced detailing the nature of the incident, actions taken, outcomes, and any preventative measures implemented.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Demos, branded demos, limited timescale trials can all be provided and delivered upon request
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 25%
- Over £5,000,001
- 30%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Certification Europe Ltd
- ISO/IEC 27001 accreditation date
- Tuesday 7 February 2023
- What the ISO/IEC 27001 doesn’t cover
-
Any systems, departments, services or business functions outside the defined scope of the certified ISMS — e.g., corporate functions or tools not included in the Workvivo service boundary. 
• Security aspects not required by ISO 27001 itself, such as specific privacy laws (e.g., GDPR) — those require separate compliance measures. 
• Controls or operational details beyond the standard’s requirements (for example, real-time threat detection or incident response playbooks are good practice but not mandated).
• Anything outside the version/period of the current certification (e.g., new features added after audit cut-off).  - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Cc081bfb-89a1-4a47-8168-87bf8841b3f7
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Ensuring new workers are informed of their right to join a trade union
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- How the supplier will work with NGOs, trade unions or other businesses to address modern slavery risk
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Plans for engaging a diverse range of businesses in engagement activities prior to appointing subcontractors (including activities prior to award of the main contract and during the contract term)
-