Skip to main content

Help us improve the Digital Marketplace - send your feedback

Tribal Education Limited

ebs by Tribal

Tribal’s ebs solution is the UK’s market leading Further Education Learner Management Information System (SMS/MIS/SIS), providing comprehensive functionality and efficient information management throughout the academic life of a learner. Tribal also provides a Data Management Service, including ILR submission, reporting and funding helpdesk, compliance, audit support and report writing.

Features

  • Curriculum planning, management and reporting
  • Enquiries, applications and enrolments management
  • Timetable and registers management
  • Learner Portal online prospectus, enquiries, applications and enrolments
  • Reporting solution with comprehensive set of reports
  • ILR management with powerful error checking
  • Integrated e-Portfolio solution
  • Integrated Business Intelligence dashboard for management KPI reporting
  • Additional Learner Support and fund management
  • On-demand access to funding, compliance and ebs product expertise

Benefits

  • Improved data quality with single-entry, validation and error checking
  • Improved efficiency of student transactions through integrated automated processes
  • Integrated process from curriculum to funding returns eliminates hassle
  • Fully integrated system with once-only data input
  • Greater efficiencies with Learner Portal and Agent staff portal
  • Comprehensive reporting facilities allow for improved management reporting
  • Simple automatic interfacing with third-party systems
  • Easy to use applications designed using familiar Microsoft technology
  • UK based Support, support portal and Dynamic user community
  • Brings additional capacity to small teams without the extra headcount

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at technology.bids@tribalgroup.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 9 6 3 9 9 5 5 1 7 4 1 1 0 4

Contact

Tribal Education Limited Fleur Brennan
Telephone: 0330 016 4000
Email: technology.bids@tribalgroup.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Education
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
• • Service downtime required for planned upgrades to the EBS software. Typically, 0.5 days max per release. Out of hours upgrades available at additional cost.
• Non-Production server availability runs between 6am – 9pm - (Production available 24/7)
System requirements
  • Access to the internet required to use the service
  • All major browsers can be used to access the service
  • Client machines to run Windows 11 or latest Mac OS

User support

Email or online ticketing support
Yes
Support response times
Response times are determined by the severity of the issue.
Critical incidents (P1) response time within 30 minutes during a working day
Major incidents (P2) response time within 1 working hour
Important incidents (P3) response time within 4 working hours
Minor incidents (P4) response within 8 working hours
Standard working hours are Monday to Friday, 9.00am to 5.30pm. Responses are not provided outside of these hours
Customers may provide an assessment of impact and urgency, used to support incident categorisation, prioritisation and triage.
Customers may request closure of a support ticket at any time. Escalation is available for support tickets
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
All services offered will be supported by a Service Level Agreement suitable to the customer and the service ordered.
- There are three levels of service available; Essential, Enhanced and Enterprise
- All support is included in the annual subscription and is not a separate cost
- depending on the level of support required, this will include a Service Delivery manager, Technical Project Coordinator and assigned Cloud Consultant.

If additional out of hours or onsite support is required then this option is available at additional cost.
Support available to third parties
No

Onboarding and offboarding

Getting started
The system is provided with a full suite of user documentation. During initiation of the project a full training plan will be scheduled and delivered according to the project timescales. Training if predominantly carried out on site. However, there are online training manuals and recorded training materials available as well.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
The underlying database containing all customer data would be provided to a customer-accessible destination prior to the contract ending.
End-of-contract process
We would work with the customer to define an exit plan which would involve extraction of data and completion of any outstanding services. The exact nature and cost of this exit plan will vary from customer to customer depending on their requirements.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Roles based access is a core part of the solution and guides many processes.

The solution's role group functionality enables all web portal content to be granted based upon fully configurable rules. All role groups are defined within the system with web portal access being dynamically calculated at login. The system can use either centralised or standalone authentication.

It is a responsive design, designed to work on any device. Built using standard HTML and javascript, it can be branded to fit the requirements of the institution/user.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
The web portal aims to be compatible with WCAG AA accessibility standards. The institution can customise the portal to ensure any styling that is used is accessible as well as using the programmed solutions. We test with a range of screen readers which all work within our web portal. In order to make our web screens perceivable we aim to provide text alternatives for any non-text content so that it can be changed to fit the user’s requirements. We aim to make all of our web functionality available from a keyboard so that it is operable by any user. To make our web content understandable we aim to make web pages operate in predictable ways by ensuring that common features work in the same way across the software. We try to help users to both avoid and correct any mistakes on the web pages by providing help text and useful error messaging.
API
Yes
What users can and can't do using the API
Users can interact with all core business processes using our API including, for example, a college's admissions process.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
The system is fully configurable, including fields, customer-specific screens and reports. Corporate branding can also be incorporated.

Scaling

Independence of resources
Tribal offers ebs via a public cloud provision through Microsoft Azure.
Our public cloud is a multi-tenanted solution, Tribal use a multi tier design and prevent 'noisy neighbour' performance issues through the use of auto-scaling as required to cope with user demand. As customer use grows dedicated resources can be assigned in order to maintain optimal performance.
We also offer an "essential" service which is available on a shared infrastructure platform.

Analytics

Service usage metrics
Yes
Metrics types
Data can be exported via reports to various formats, including csv, and via the API.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Encryption of all physical media
  • Other
Other data at rest protection approach
Database instances will be encrypted including snapshots at rest using an industry standard. Once the data is encrypted, authentication of access and decryption of the data is handled transparently with a minimal impact on performance. Physical access is managed by Microsoft as appropriate as it is a public cloud offering.
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Data can be exported via reports to various formats, including csv, and via the API.
Data export formats
  • CSV
  • Other
Other data export formats
JSON/XML
Data import formats
  • CSV
  • Other
Other data import formats
JSON/XML

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
We offer a minimum 99.5% availability, assured by contractual commitments. Exact SLAs will vary from client to client and their desired uptime.
Approach to resilience
Public Cloud:
The public cloud provides the ability to place instances (servers) in multiple locations composed of Regions and Availability Zones. Availability Zones are distinct locations that are engineered to be insulated from failures in other Availability Zones and provide inexpensive, low-latency network connectivity to other Availability Zones in the same Region.

By deploying the web, application and database instances in separate Availability Zones, the solution is protected from failure of a single location. The region consists of more than one Availability Zone, is geographically dispersed, and is located in separate geographic areas.

Private cloud:
Available on request
Outage reporting
Service outages are reported through both our support portal and direct contact from the appropriate service delivery manager who is assigned to the client. The method of communication will be agreed with the specific client, but could include email alerts, direct phone calls to a specific support contact, etc.

Identity and authentication

User authentication needed
Yes
User authentication
Username or password
Access restrictions in management interfaces and support channels
Access in management interface and support channels is managed on a Role based Access Control system (RBAC) as with the rest of the system. In this way you can control which areas of the system and support users have access to.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Tribal has been an ISO27001 certified organisation since 2009 and all of our development and delivery services will be delivered from locations which are specifically ISO27001 certified. The accreditation process included a review of Tribal’s Information Security Management System (ISMS) and our overall policy for handling data including how it is collected, held and maintained.
We have local security forums for all of our offices, which feed into our central Information Security Governance forum which reports to the board. We have permanent Quality and Security Managers who form part of this board.
As well as our regular certification revalidation process (carried out by external evaluators) we regularly test our systems and processes with a series of internal audits to ensure that policies and processes are being followed.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
For our software solutions, Tribal has a structured Change Control process for managing requests for change and enhancements. All Requests for Changes (RFCs) are raised via the Service Desk and go through internal vetting by the respective support team before gaining authorisation from Tribal. Regular Change Advisory Boards meet to review Emergency and non-standard changes. Details of all changes are provided to the Service Manager to review and will obtain final approval from the Contracting Body before proceeding. The Contracting Body will be involved in the change Process at each stage and included in any post implementation review as required.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
As part of our ISO27001 processes we have a risk/vulnerability assessment procedure which will be undertaken on any new customer site and service.
Patches will be deployed depending on the severity of the problem and the level of testing required.
Information about potential threats is found based upon initial and recurring risks assessments, internal procedures and known threats highlighted by both the industry and users.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Our managed service includes the proactive monitoring of all services to identify potential compromises.
Based upon the nature of the compromise we would then respond to the agreed SLA.
The speed of the response will be determined by the severity of the incident.
Incident management type
Supplier-defined controls
Incident management approach
Our ISO27001 processes include a defined Incident Management process. All personnel are responsible for reporting incidents to the Information Governance Committee (IGC) or Security Forum representatives as quickly as possible. We have a formal Incident Report Form which staff use for recording the details of the incidents.
Security weaknesses will be recorded on a spreadsheet for tracking purposes. Any person can identify weaknesses, which will be managed by the Quality team in conjunction with the Security Forums and IGC as appropriate.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
LRQA
ISO/IEC 27001 accreditation date
Tuesday 2 May 2017
What the ISO/IEC 27001 doesn’t cover
Nothing relating to the proposed products/services. The certification applies to the secure development, implementation, hosting and support of all proposed services including ebs, Maytas, K2, Dynamics, Engage and Semestry. It covers all Tribal entities including Tribal Education Ltd at all Tribal office locations including within the UK.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
LRQA
ISO 9001 accreditation date
Tuesday 2 May 2017
What the ISO 9001 doesn’t cover
Nothing relating to the proposed products. It covers all quality processes relating to secure development, implementation, hosting and support of all proposed services including ebs, Maytas, K2, Dynamics, Engage and Semestry. It covers all Tribal entities including Tribal Education Ltd at all Tribal office locations including within the UK.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
E0426c22-3c8e-4eb9-adde-4865fa8d0e3e
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
Eea76e94-f3f4-47c7-9573-625a58f07ead
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Volunteering opportunities for staff
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at technology.bids@tribalgroup.com. Tell them what format you need. It will help if you say what assistive technology you use.