Compassly
Compassly is an system for defining, assessing and reporting on the clinical competencies and preceptorship of healthcare professionals in a smartphone or web app, to help ensure the highest levels of skill for patient care. It allows passporting of competencies and collaborative competency libraries between different healthcare providers
Features
- Mobile and web application with consistent, simple interface across
- Configurable competency libraries shared across organisations with access controls
- Built with reusable components ensuring consistency and ease of use
- Rule-based engine mapping job competency requirements to roles automatically
- Evidence upload with documents photos and digitally signed competency records
- Biometric login on mobile devices ensuring security and ease
- Document reference library for learning material alongside competency requirements
- Powerful reporting through AWS QuickSight with standard and bespoke reports
- Active monitoring through app and email notifications configurable for users
- Work across multiple organisations with single login developing portable competencies
Benefits
- Save staff time eliminating paperwork with digital mobile assessment tools
- Motivate and retain staff focusing on professional development through competencies
- Ensure workforce competence across clinical environments promoting excellent patient safety
- Provide leaders real-time reporting and assurance of competency compliance
- Empower managers with simple team oversight and local administrative controls
- Customise competency assessments to match each workforce's specific different needs
- Collect secure consistent reliable evidence of competencies for regulators
- Deploy solution easily and quickly with simple QR code onboarding
- Eliminate wasted time repeating assessments with portable digital competency passports
- Develop and share workforce skills across different collaborating healthcare organisations
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 4 8 0 6 1 4 2 3 2 0 3 9 2 8
Contact
Tefogo Ltd
Compassly team
Telephone: 07928287535
Email: info@compassly.com
About your service
- Service categories
-
Applications
Enterprise resource management
Human capital management
- Core Human Resources Applications
- Talent Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Compassly requires internet connectivity (Wi-Fi or cellular) for full functionality, though limited offline access is available for mobile users. The application is designed for consistent cross-organisation use and is not available as a white-labelled solution. Jailbroken (iOS) and rooted (Android) devices are detected for security. Some features are mobile-optimised (biometric login, QR onboarding) whilst others are web-optimised (Business Intelligence dashboards, administrative functions). The service is designed primarily for healthcare competency and preceptorship / induction programme management but can be adapted for other regulated professions.
- System requirements
-
- Modern web browser, running current version
- Modern Operating System, maintaining current version
- Mobile devices with deployment from App Store / Google Play
- Not compatible with Microsoft Internet Explorer
- Internet access via Wi-Fi or cellular connectivity
User support
- Email or online ticketing support
- Yes
- Support response times
- Support is offered Monday-Friday, 9am - 5pm UK time. Support outside of these hours is provided on a best-endeavours basis. Premium support, such as on-site visits, may be provided but this is subject to contractual agreement and additional charges.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Basic ongoing support is included in the service subscription and not charged as a separate item.
Premium support may be applied depending on the agreed financial terms in the commercial contract.
Implementation support levels and costs are agreed separately as part of commercial terms. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Our implementation approach is built around the needs of the customer and their users, and this will be scoped and agreed pre-contract as an implementation package.
An implementation package can consist of any combination of on-site training, remote live training, access to pre-recorded training videos and published materials. Support information is also available within the Compassly application itself.
The implementation package will also cover configuration of Compassly ahead of implementation with users, and different levels of support for this phase are available too. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
End-of-contract data extraction can be agreed at the start of the contract upon request.
Our standard extraction provision is through flat file CSV extracts - as organisations can access this through the BI dashboard, they are able to download this data whenever they choose.
Individuals will be able to retain access to their competency passports and underlying competencies through their own personal login beyond the end of the contract.
We can also arrange for bespoke JSON extracts of the data for organisations. - End-of-contract process
-
Contract includes de-provisioning of active users, job descriptions and competencies, and confirmation of service close
Note that as users will retain their personal competency passports, the records that relate to them as individuals will be retained by them.
Any bespoke data migration activities would be subject to additional costs. - Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- There are minor differences between the mobile and desktop service - for example iOS/Android biometric login is not available on desktop services, and Business Intelligence dashboard functionality is limited on mobile applications.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- The service is accessed via a secure web-based or app-based user interface for end users and administrators. The interface allows users to perform day-to-day tasks and administrators to manage configuration and access.
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
- We have worked extensively with a specialist IAAP assessor to test the accessibility standards of Compassly through the web and app interfaces.
- API
- No
- Customisation available
- Yes
- Description of customisation
-
Compassly allows for extensive customisation including job descriptions and rules, competency libraries, reference material and
some specific corporate terms. Reports can be customised through the business intelligence platform.
Much of this customisation can be done by local administrators, although some is reserved for support by system administrators.
Users are also able to customise elements of Compassly, either directly through the app (e.g. dark mode) or through its response to OS customisation (e.g. text size)
Scaling
- Independence of resources
- We host our server application on AWS cloud, which supports auto-scaling functionality depending on the load of the system. We can run multiple same type applications in parallel to process all the incoming requests and satisfy the demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
We provide service metrics on the key measures for Compassly, including new users joining, job descriptions assigned, competencies and stages of competencies completed, supervisory workload by supervisor.
Detailed metrics are available through the web reporting portal, and summary information for each user is available to Supervisors through the app. - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Users are able to export their data in CSV format, subject to organisation access permissions. This is through the BI dashboard.
Individual users can also download PDF certificates showing their achievements. - Data export formats
- CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
- Users can upload evidence of competency documentation (PDF, Image)
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We offer 99.5% availability for each month excluding scheduled maintenance periods which is completed outside of UK business hours.
Any refund policy will be subject to specifying in the commercial contract. - Approach to resilience
-
Our service is built on top of AWS cloud infrastructure that provides tools to build resilience applications, which includes (but is not limited to) multi availability zones within a region, load balancer to re-route traffic, auto-scaling to quickly add more instances to meet the traffic demand, database snapshot backups.
Further details on the AWS risk & compliance framework are available on request. - Outage reporting
- In case of unplanned outages, we notify primary contacts within the customer organisation by email. Users will also be informed by a status screen within the app.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Our system implements Role Based Access Control. We restrict access based on user’s roles and permissions. We have a granular way of granting access to different areas of the system based on permissions. We also restrict access to some features based on role seniority.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- We have aligned our internal governance processes to both the NHS DSP Toolkit and ISO27001 best practices, with ownership of security governance at the executive level.
- Information security policies and processes
-
We have based our information security policies on the template standards used by NHS Digital as part of the DSP Toolkit.
All policy compliance is monitored within our internal knowledge system as part of standard business processes and reporting. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
We have a backlog of all planned changes including features, bug fixes and improvements. It all then goes through project planning, product development and delivery to market. This way we can have a full history of all changes of the product and system.
Continuous Integration, Continuous Delivery and Test automation is in place to ensure repeatable, consistent and robust deployment. Changes are tested in staging environment before pushing to production and production deploy requires approval of authorised staff.
As part of the release pipeline changes are assessed for potential security impact. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
We constantly monitor and assess potential threads as part of our release lifecycle. We keep all the software and third party libraries up to date in order to prevent any potential security threads.
Our cloud provider AWS handles all the infrastructure related management, security patching, and updates.
We deploy a patch as part of our 2 week sprint release cycle but if there is anything serious we can deploy a backend patch in minutes and mobile app update up to 48 hours (subject to Apple Store and Google Play approval time). - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Potential compromises are identified based on multiple sources including logging and various monitoring tools. Our main goal is to prevent potential compromises before they becomes real, but in the case of a compromise we would start a thorough investigation to understand the scope and severity of the incident. All the serious incidents are escalated to CTO and reported to customers if needed.
Target resolution time for high severity incidents is up to 24 hours, although this is dependent on the nature of the incident. - Incident management type
- Supplier-defined controls
- Incident management approach
- Users can report incidents by email, but in case of emergency users can also call us directly. All incidents are recorded and assigned severity levels. Our response then depends on the severity level, for the lower level incidents we will then handle in the following development cycle, and for higher level we prioritise the issue and fix it immediately. All affected parties are notified upon resolution.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
-
We have two free trial options available:
- Access to a generic demo setup
- Setting up a specific pilot, with a small number of locations, users and competencies
Both are time-limited (typically 1-3 months)
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2%
- Between £500,001 and £1,000,000
- 3%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 7%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 207333e3-9a9f-4833-91b9-fc58feb0c242
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-