Maytas by Tribal
Comprehensive LMS supporting administration of apprenticeships and adult learning for training providers/colleges/councils/universities/employers. MAYTAS Hub is the e-portfolio enabling monitoring of evidence progress. An integrated solution managing learner data, programme performance, operational workflows, point-of-entry ILR/LLWR validation. Services include Funding and Compliance Advisory, ILR preparation/submission, funding reporting support, compliance/audit assistance, bespoke reporting.
Features
- Highly configurable, end-to-end learner management
- Real-time ILR and LLWR validation and automatic error checking
- Comprehensive ILR and LLWR management with audit-ready reporting tools
- Compliance alignment with DfE/ESFA, Ofsted, and accountability frameworks
- Integrated and mobile optimised e-Portfolio for stakeholder engagement
- Advanced reporting with dashboards and standard Power BI integration
- Secure & powerful OData API for seamless third-party system integration
- Automated funding calculations and off-the-job hours tracking
- Configurable workflows for apprenticeship and skills delivery
- Configurable onboarding and online data collection capabilities
Benefits
- Improved data quality with single-entry, validation and error checking
- Improved efficiency of student transactions through integrated automated processes
- Integrated process from curriculum to funding returns eliminates hassle
- Fully integrated system with once-only data input
- Greater efficiencies with Learner Portal and Agent staff portal
- Comprehensive reporting facilities allow for improved management reporting
- Simple automatic interfacing with third-party systems
- Easy to use applications designed using familiar Microsoft technology
- UK based Support, support portal and Dynamic user community
- Brings additional capacity without extra headcount and reduces turnover risks
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 1 6 9 5 3 8 5 6 7 9 7 6 9 6
Contact
Tribal Education Limited
Fleur Brennan
Telephone: 0330 016 4000
Email: technology.bids@tribalgroup.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Education
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
-
MAYTAS fits seamlessly into wider enterprise architectures thanks to its flexible and powerful integration capabilities.
Our full CRUD OData API layer, enables scalable, secure and highly configurable integrations with registration systems, CRMs, VLEs, marketing/onboarding tools and other organisational platforms.
MAYTAS also integrates with other Tribal products, including SITS and ebs. - Cloud deployment model
- Public cloud
- Service constraints
- MAYTAS currently offers a powerful and time-served Windows client that can be accessed online, providing seamless connectivity for users on Windows devices. Excitingly, our latest innovation, MAYTAS 6, will be a fully web-based, SaaS MIS solution, delivering the full power of MAYTAS directly through any browser, anywhere, anytime.
- System requirements
-
- Latest versions of Chrome, Safari and Edge
- Windows 10 with a minimum of 4GB memory
- Core Duo processor or equivalent
- Minimum screen resolution of 1024 x 768
User support
- Email or online ticketing support
- Yes
- Support response times
- Our response times to queries and incidents is based upon the severity of the incident in question. Critical faults (P1) are responded to within an hour. Major faults (P2) are responded to within two working hours. Important faults (P3) are responded to within four working hours. Minor faults (P4) are responded to within eight working hours. Our working hours are Monday-Friday 0830 to 1700 - therefore there would not be a response on weekends. Customers can provide us with an impact and urgency rating for any issues they raise which we use to help triage and assign priority.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Maytas offers a robust train-the-trainer support model, under which nominated customer representatives are designated as Maytas Superusers and provide first-line support. Superusers are responsible for responding to day-to-day user queries, troubleshooting routine issues, and delivering system training where appropriate, ensuring efficient resolution and continuity of service within the organisation.
The Support Team provides second-line support for issues that cannot be resolved by customer Superusers. In addition, Maytas maintains comprehensive online documentation and provides users with access to the Tribal Communities platform, where guidance, best-practice resources, and peer knowledge can be accessed at any time. Together, Maytas documentation and Tribal Communities form a central, always-available repository of support materials for administrators and end users, available 24/7.
In addition to standard support, Maytas offers a dedicated Customer Advisory service that provides proactive access to experienced specialists, acting as a trusted point of contact to help customers maximise the value of Maytas through advice on support options, system usage, enhancements, and roadmap alignment.
Minimum service levels are defined within SLAs. Support requests can be raised by Superusers via the Maytas self-service platform, managed in line with agreed service levels, including formal escalation procedures. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- The system comes complete with a comprehensive suite of user documentation. At project kick-off, a tailored training plan will be scheduled and delivered in line with your project timeline. While training is primarily conducted online, increasing awareness and availability, our focused and tailored training sessions are delivered to empower your team to quickly master the system and maximise its capabilities from day one. Users also have access to online manuals and recorded sessions, ensuring flexible, self-paced learning. On-site training for hands-on guidance is also available.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- The underlying database containing all customer data would be provided to a customer-accessible destination prior to the contract ending.
- End-of-contract process
- We would work with the customer to define an exit plan which would involve extraction of data and completion of any outstanding services. The exact nature and cost of this exit plan will vary from customer to customer depending on their requirements.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile solution is device responsive and can be used on tablet or smartphone.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
-
The MAYTAS OData API provides a secure, scalable and highly flexible integration layer designed to streamline data exchange across your systems. Authentication is managed through industry-standard JWT Bearer tokens, ensuring secure, controlled access at all times. Administrators can easily create API client credentials within the Integration platform, configuring client IDs, scopes and secret expiry settings. These credentials are then used to obtain an access token from the identity server, with each token valid for one hour.
Once authenticated, users can interact with the API through their preferred middleware, benefiting from the power and adaptability of the OData protocol. The API supports full read/write functionality across GET, POST, PATCH and DELETE, enabling efficient data retrieval, updates and synchronisation. By exposing selected MAYTAS tables, the API ensures that integrations remain both robust and governed.
The OData layer provides strong advantages, including predictable query patterns, reduced development effort, and the ability to shape, filter and expand data with ease. This makes integrations faster to build, simpler to maintain and highly responsive to organisational needs. The MAYTAS OData API ultimately delivers a modern, flexible and secure foundation for maximising data connectivity and operational efficiency across your platform ecosystem. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
The system is fully configurable, including fields, customer-specific screens and reports.
MAYTAS is a fully configurable platform designed for training providers, colleges, councils, universities and employers. It adapts to your organisational needs whilst ensuring compliance and connectivity.
Key Features:
• Flexible Workflows and Roles – Configure user roles, permissions, and workflows to fit your organisational structure.
• Full Schema Control – Create your own custom fields and surface to users to capture all required information.
• Createand Publish Screens – Create your own custom screens and publish to other users (permission controlled) ensuring they reflect exactly the information you require.
• Customisable Data and Reporting – Tailor data fields, reporting templates, and dashboards to meet compliance and business requirements.
• Seamless Integrations – Connect with finance, HR, and learning platforms through robust API integrations.
• Personalised Branding – Apply your logos, colour schemes, and terminology for a consistent brand experience.
• Compliance Alignment – Ensure processes and reporting meet industry and regulatory standards.
With MAYTAS, you can get a tailored solution that grows with your business and delivers a personalised user experience.
Scaling
- Independence of resources
-
Tribal offers Maytas via a public cloud provision through Microsoft Azure.
Our public cloud is a multi-tenanted solution, Tribal use a multi tier design and prevent 'noisy neighbour' performance issues through the use of auto-scaling to cope with user demand. As customer use grows dedicated resources can be assigned in order to maintain optimal performance.
We also offer an "essential" option which is on shared infrastructure.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Tribal Cloud incorporates an application to provide alerts to relevant teams when issues arise or thresholds are exceeded. It is a SaaS-based automated IT performance platform. As it is SaaS-based no processing is done on the monitored node, consequently, it has a minimal performance overhead.
It can monitor any Tribal Cloud service as part of our managed service - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Encryption of all physical media
- Other
- Other data at rest protection approach
- Database instances will be encrypted including snapshots at rest using the industry standard AES-256 (SQL TDE). Once the data is encrypted, authentication of access and decryption of the data is handled transparently with a minimal impact on performance. Physical access is managed by Microsoft as appropriate as it is a public cloud offering.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Users can generate the ILR batch files required for monthly submission to the DfE to claim funding for training delivery. The file includes individual learning records in XML format and can be submitted through the DfE’s designated channels. The export process also includes a comprehensive error log allowing correction of issues prior to submission.
MAYTAS supports the export of LLWR batch files (XML) for Welsh specific submissions.
MAYTAS enables users to export data to a variety of formats including .csv and .xlsx formats. - Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- We offer a minimum 99.5% availability, assured by contractual commitments. Exact SLAs will vary from client to client and their desired uptime.
- Approach to resilience
- Our service offers the cost and efficiency advantages that virtualisation brings along with centralised management and control, built in redundancy features like clustering, and a unified set of orchestration tools. The environment is backed by both our 100% Network Uptime Guarantee and our One-Hour Hardware Replacement Guarantee, supported by hundreds of Microsoft Certified experts to create a customised Virtualisation environment base.
- Outage reporting
- Service outages are reported through both our support portal and direct contact from the appropriate service delivery manager who is assigned to the client. The method of communication will be agreed with the specific client, but could include email alerts, direct phone calls etc.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Access in management interface and support channels is managed on a Role based Access Control system (RBAC) as with the rest of the system. In this way you can control which areas of the system and support users have access to.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Tribal has been an ISO27001 certified organisation since 2009 and all of our development and delivery services will be delivered from locations which are specifically ISO27001 certified. The accreditation process included a review of Tribal’s Information Security Management System (ISMS) and our overall policy for handling data including how it is collected, held and maintained.
We have local security forums for all of our offices, which feed into our central Information Security Governance forum which reports to the board. We have permanent Quality and Security Managers who form part of this board.
As well as our regular certification revalidation process (carried out by external evaluators) we regularly test our systems and processes with a series of internal audits to ensure that policies and processes are being followed. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- For our software solutions, Tribal has a structured Change Control process for managing requests for change and enhancements. All Requests for Changes (RFCs) are raised via the Service Desk and go through internal vetting by the respective support team before gaining authorisation from Tribal. Regular Change Advisory Boards meet to review Emergency and non-standard changes. Details of all changes are provided to the Service Manager to review and will obtain final approval from the Contracting Body before proceeding. The Contracting Body will be involved in the change Process at each stage and included in any post implementation review as required.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
As part of our ISO27001 processes we have a risk/vulnerability assessment procedure which will be undertaken on any new customer site and service.
Patches will be deployed depending on the severity of the problem and the level of testing required.
Information about potential threats is found based upon initial and recurring risks assessments, internal procedures and known threats highlighted by both the industry and users. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Our managed service includes the proactive monitoring of all services to identify potential compromises.
Based upon the nature of the compromise we would then respond to the agreed SLA.
The speed of the response will be determined by the severity of the incident. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Our ISO27001 processes include a defined Incident Management process. All personnel are responsible for reporting incidents to the Information Governance Committee (IGC) or Security Forum representatives as quickly as possible. We have a formal Incident Report Form which staff use for recording the details of the incidents.
Security weaknesses will be recorded on a spreadsheet for tracking purposes. Any person can identify weaknesses, which will be managed by the Quality team in conjunction with the Security Forums and IGC as appropriate. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA
- ISO/IEC 27001 accreditation date
- Tuesday 2 May 2017
- What the ISO/IEC 27001 doesn’t cover
- Nothing relating to the proposed products/services. The certification applies to the secure development, implementation, hosting and support of all proposed services including ebs, Maytas, K2, Dynamics, Engage and Semestry. It covers all Tribal entities including Tribal Education Ltd at all Tribal office locations including within the UK.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA
- ISO 9001 accreditation date
- Tuesday 2 May 2017
- What the ISO 9001 doesn’t cover
- Nothing relating to the proposed products. It covers all quality processes relating to secure development, implementation, hosting and support of all proposed services including ebs, Maytas, K2, Dynamics, Engage and Semestry. It covers all Tribal entities including Tribal Education Ltd at all Tribal office locations including within the UK.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E0426c22-3c8e-4eb9-adde-4865fa8d0e3e
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Eea76e94-f3f4-47c7-9573-625a58f07ead
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Volunteering opportunities for staff
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-