Skip to main content

Help us improve the Digital Marketplace - send your feedback

Tefogo Ltd

Compassly

Compassly is an system for defining, assessing and reporting on the clinical competencies and preceptorship of healthcare professionals in a smartphone or web app, to help ensure the highest levels of skill for patient care. It allows passporting of competencies and collaborative competency libraries between different healthcare providers

Features

  • Mobile and web application with consistent, simple interface across
  • Configurable competency libraries shared across organisations with access controls
  • Built with reusable components ensuring consistency and ease of use
  • Rule-based engine mapping job competency requirements to roles automatically
  • Evidence upload with documents photos and digitally signed competency records
  • Biometric login on mobile devices ensuring security and ease
  • Document reference library for learning material alongside competency requirements
  • Powerful reporting through AWS QuickSight with standard and bespoke reports
  • Active monitoring through app and email notifications configurable for users
  • Work across multiple organisations with single login developing portable competencies

Benefits

  • Save staff time eliminating paperwork with digital mobile assessment tools
  • Motivate and retain staff focusing on professional development through competencies
  • Ensure workforce competence across clinical environments promoting excellent patient safety
  • Provide leaders real-time reporting and assurance of competency compliance
  • Empower managers with simple team oversight and local administrative controls
  • Customise competency assessments to match each workforce's specific different needs
  • Collect secure consistent reliable evidence of competencies for regulators
  • Deploy solution easily and quickly with simple QR code onboarding
  • Eliminate wasted time repeating assessments with portable digital competency passports
  • Develop and share workforce skills across different collaborating healthcare organisations

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@compassly.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 4 8 0 6 1 4 2 3 2 0 3 9 2 8

Contact

Tefogo Ltd Compassly team
Telephone: 07928287535
Email: info@compassly.com

About your service

Service categories

Applications

Enterprise resource management

Human capital management

  • Core Human Resources Applications
  • Talent Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Compassly requires internet connectivity (Wi-Fi or cellular) for full functionality, though limited offline access is available for mobile users. The application is designed for consistent cross-organisation use and is not available as a white-labelled solution. Jailbroken (iOS) and rooted (Android) devices are detected for security. Some features are mobile-optimised (biometric login, QR onboarding) whilst others are web-optimised (Business Intelligence dashboards, administrative functions). The service is designed primarily for healthcare competency and preceptorship / induction programme management but can be adapted for other regulated professions.
System requirements
  • Modern web browser, running current version
  • Modern Operating System, maintaining current version
  • Mobile devices with deployment from App Store / Google Play
  • Not compatible with Microsoft Internet Explorer
  • Internet access via Wi-Fi or cellular connectivity

User support

Email or online ticketing support
Yes
Support response times
Support is offered Monday-Friday, 9am - 5pm UK time. Support outside of these hours is provided on a best-endeavours basis. Premium support, such as on-site visits, may be provided but this is subject to contractual agreement and additional charges.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Basic ongoing support is included in the service subscription and not charged as a separate item.
Premium support may be applied depending on the agreed financial terms in the commercial contract.
Implementation support levels and costs are agreed separately as part of commercial terms.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Our implementation approach is built around the needs of the customer and their users, and this will be scoped and agreed pre-contract as an implementation package.

An implementation package can consist of any combination of on-site training, remote live training, access to pre-recorded training videos and published materials. Support information is also available within the Compassly application itself.

The implementation package will also cover configuration of Compassly ahead of implementation with users, and different levels of support for this phase are available too.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
End-of-contract data extraction can be agreed at the start of the contract upon request.
Our standard extraction provision is through flat file CSV extracts - as organisations can access this through the BI dashboard, they are able to download this data whenever they choose.
Individuals will be able to retain access to their competency passports and underlying competencies through their own personal login beyond the end of the contract.
We can also arrange for bespoke JSON extracts of the data for organisations.
End-of-contract process
Contract includes de-provisioning of active users, job descriptions and competencies, and confirmation of service close
Note that as users will retain their personal competency passports, the records that relate to them as individuals will be retained by them.
Any bespoke data migration activities would be subject to additional costs.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
There are minor differences between the mobile and desktop service - for example iOS/Android biometric login is not available on desktop services, and Business Intelligence dashboard functionality is limited on mobile applications.
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
The service is accessed via a secure web-based or app-based user interface for end users and administrators. The interface allows users to perform day-to-day tasks and administrators to manage configuration and access.
Accessibility standards
WCAG 2.2 A
Accessibility testing
We have worked extensively with a specialist IAAP assessor to test the accessibility standards of Compassly through the web and app interfaces.
API
No
Customisation available
Yes
Description of customisation
Compassly allows for extensive customisation including job descriptions and rules, competency libraries, reference material and
some specific corporate terms. Reports can be customised through the business intelligence platform.
Much of this customisation can be done by local administrators, although some is reserved for support by system administrators.
Users are also able to customise elements of Compassly, either directly through the app (e.g. dark mode) or through its response to OS customisation (e.g. text size)

Scaling

Independence of resources
We host our server application on AWS cloud, which supports auto-scaling functionality depending on the load of the system. We can run multiple same type applications in parallel to process all the incoming requests and satisfy the demand.

Analytics

Service usage metrics
Yes
Metrics types
We provide service metrics on the key measures for Compassly, including new users joining, job descriptions assigned, competencies and stages of competencies completed, supervisory workload by supervisor.
Detailed metrics are available through the web reporting portal, and summary information for each user is available to Supervisors through the app.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
In-house destruction process
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Users are able to export their data in CSV format, subject to organisation access permissions. This is through the BI dashboard.
Individual users can also download PDF certificates showing their achievements.
Data export formats
CSV
Data import formats
  • CSV
  • Other
Other data import formats
Users can upload evidence of competency documentation (PDF, Image)

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We offer 99.5% availability for each month excluding scheduled maintenance periods which is completed outside of UK business hours.
Any refund policy will be subject to specifying in the commercial contract.
Approach to resilience
Our service is built on top of AWS cloud infrastructure that provides tools to build resilience applications, which includes (but is not limited to) multi availability zones within a region, load balancer to re-route traffic, auto-scaling to quickly add more instances to meet the traffic demand, database snapshot backups.
Further details on the AWS risk & compliance framework are available on request.
Outage reporting
In case of unplanned outages, we notify primary contacts within the customer organisation by email. Users will also be informed by a status screen within the app.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Our system implements Role Based Access Control. We restrict access based on user’s roles and permissions. We have a granular way of granting access to different areas of the system based on permissions. We also restrict access to some features based on role seniority.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
We have aligned our internal governance processes to both the NHS DSP Toolkit and ISO27001 best practices, with ownership of security governance at the executive level.
Information security policies and processes
We have based our information security policies on the template standards used by NHS Digital as part of the DSP Toolkit.
All policy compliance is monitored within our internal knowledge system as part of standard business processes and reporting.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We have a backlog of all planned changes including features, bug fixes and improvements. It all then goes through project planning, product development and delivery to market. This way we can have a full history of all changes of the product and system.

Continuous Integration, Continuous Delivery and Test automation is in place to ensure repeatable, consistent and robust deployment. Changes are tested in staging environment before pushing to production and production deploy requires approval of authorised staff.

As part of the release pipeline changes are assessed for potential security impact.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We constantly monitor and assess potential threads as part of our release lifecycle. We keep all the software and third party libraries up to date in order to prevent any potential security threads.

Our cloud provider AWS handles all the infrastructure related management, security patching, and updates.

We deploy a patch as part of our 2 week sprint release cycle but if there is anything serious we can deploy a backend patch in minutes and mobile app update up to 48 hours (subject to Apple Store and Google Play approval time).
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Potential compromises are identified based on multiple sources including logging and various monitoring tools. Our main goal is to prevent potential compromises before they becomes real, but in the case of a compromise we would start a thorough investigation to understand the scope and severity of the incident. All the serious incidents are escalated to CTO and reported to customers if needed.

Target resolution time for high severity incidents is up to 24 hours, although this is dependent on the nature of the incident.
Incident management type
Supplier-defined controls
Incident management approach
Users can report incidents by email, but in case of emergency users can also call us directly. All incidents are recorded and assigned severity levels. Our response then depends on the severity level, for the lower level incidents we will then handle in the following development cycle, and for higher level we prioritise the issue and fix it immediately. All affected parties are notified upon resolution.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
We have two free trial options available:
- Access to a generic demo setup
- Setting up a specific pilot, with a small number of locations, users and competencies
Both are time-limited (typically 1-3 months)

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
2%
Between £500,001 and £1,000,000
3%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
7%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
207333e3-9a9f-4833-91b9-fc58feb0c242
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@compassly.com. Tell them what format you need. It will help if you say what assistive technology you use.