Skip to main content

Help us improve the Digital Marketplace - send your feedback

SHAPECAST LIMITED

StrategyWorks SaaS Platform

StrategyWorks is a strategy and performance management application that manages objectives, programmes, projects, OKRs, KPIs, risks, issues and decisions.

StrategyWorks provides leadership and delivery teams with a clear view of progress, accountability, and outcomes through role based dashboards and secure access. It supports governance, portfolio oversight, and informed decision making.

Features

  • Web-based strategy lifecycle management platform
  • Structured management of strategic objectives and outcomes
  • Portfolio-level alignment of programmes and initiatives
  • Configurable governance and ownership management
  • Performance and outcome tracking across strategic portfolios
  • Visual dashboards for executive oversight and reporting
  • Full risk,issue and decision management across the strategy
  • Dependency and progress visibility across initiatives
  • Role-based access control and permissions
  • Configurable to organisational structures without custom development

Benefits

  • Improves visibility of strategic delivery across the organisation
  • Alignment between strategy, portfolios, and outcomes
  • Consistent governance and accountability
  • Reduced reliance on spreadsheets and documents
  • Enables evidence-based decision-making and prioritisation
  • Improves consistency of strategy execution and reporting
  • Ability to adapt the strategy as priorities change
  • Provides a single, clean source of strategy information
  • Reduces risk of underperforming or misaligned initiatives
  • Enables effective use of a cloud-based strategy management platform

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@shapecast.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

4 6 2 5 7 1 1 1 0 2 0 0 4 0 6

Contact

SHAPECAST LIMITED Will Barnett
Telephone: 020 3745 5211
Email: hello@shapecast.com

About your service

Service categories

Applications

Enterprise resource management

  • Enterprise performance management
  • Project and portfolio management
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
YYes. Buyers should be aware of the following constraints. Planned maintenance windows may result in short periods of service unavailability. Internet connectivity is required to access the service. The service is accessed via supported modern web browsers only. Configuration is limited to available platform features as part of the standard service. Integrations are limited to supported APIs and data formats. These constraints are typical for a cloud hosted SaaS service and are managed to minimise operational impact.
System requirements
  • Modern web browser supporting current HTML5 standards
  • Reliable internet connection
  • Screen resolution sufficient to display dashboards and reports

User support

Email or online ticketing support
Yes
Support response times
Shapecast aims to respond to email enquiries within 1 working day.

Responses are provided during UK business hours, Monday to Friday.
Weekend and UK public holiday enquiries are reviewed on the next working day.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Shapecast provides a single standard support level for StrategyWorks SaaS customers.

Standard support is provided via email and covers platform usage, configuration guidance, issue clarification, and follow-up questions related to the use of StrategyWorks. Support is available Monday to Friday during UK business hours.

Standard email support is included within the StrategyWorks subscription price. There are no additional charges for standard support.

Enhanced support options can be provided where required and are agreed and priced separately. These may include extended support hours, prioritised response times, or named specialist support.

A dedicated technical account manager or on-call cloud support engineer is not included as part of the standard service. Support is provided by experienced StrategyWorks platform specialists.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
StrategyWorks is designed to support straightforward onboarding using standard product features.

Buyers can get started by setting up their StrategyWorks environment, configuring core structures, and loading data using the platform interface and documentation provided. Standard onboarding materials include user guides, training resources, and documentation to support self service setup.

Optional onboarding support is available where required and may include remote guidance, training sessions, or assisted data loading. More extensive strategy design, integration, or change support can be provided separately as specialist cloud support services.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
When a contract ends, users can extract their data from StrategyWorks using built-in export functionality.

Data can be exported in commonly used, open formats (such as CSV) through the user interface, allowing organisations to retain strategy, portfolio, and performance information. Where required, data exports can also be supported via the API for structured datasets.

After contract termination, access to the service is removed in line with data retention and security policies.
End-of-contract process
At the end of the contract, customer access to StrategyWorks is disabled in line with agreed contract terms.

As part of the standard contract price, customers can export their data using the platform’s built in export functionality in open formats such as CSV. This enables customers to retain strategy, portfolio, and performance data for transition or record keeping purposes.

Customers may also request assisted data extraction, where Shapecast securely provides exported data on their behalf using agreed secure transfer methods.

Following contract termination, customer data is retained for an agreed period to allow data extraction, after which it is securely deleted in line with data retention and security policies.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Yes, the mobile interface is responsive to the mobile device screen width available.
Service interface
Yes
User support accessibility
WCAG 2.2 A
Description of service interface
StrategyWorks is accessed through a secure, web-based user interface via a standard web browser. The interface is designed for clarity and ease of use, with structured views for strategy, portfolios, objectives, initiatives, and performance information.

Users interact with the service through configurable dashboards, tables, and visual summaries that present strategic data, progress, and governance information. Navigation is role-based, ensuring users only see information relevant to their responsibilities.

The interface supports keyboard navigation, clear labelling, and consistent layouts to improve usability and accessibility. No local software installation is required.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
StrategyWorks user interfaces have been tested internally against recognised accessibility standards, including WCAG 2.1 AA.

Testing has focused on keyboard navigation, screen reader compatibility, colour contrast, focus indicators, and form usability.

Where third party components are used, supplier accessibility documentation is reviewed.

Accessibility considerations are included as part of ongoing platform updates and improvements.
API
Yes
What users can and can't do using the API
What users can do using the API

The StrategyWorks API allows authorised users to securely exchange data between StrategyWorks and other systems. Users can retrieve and update structured strategy data such as objectives, initiatives, performance measures, status updates, and ownership information. The API supports integration with reporting, portfolio, and data platforms.

How users can set up the service through the API

The API can be used to programmatically load or synchronise strategy-related data into an existing StrategyWorks environment. Core service setup, tenant creation, and initial configuration are performed through the platform interface rather than exclusively through the API.

How users can make changes through the API

Users can use the API to update supported data fields, refresh status information, and synchronise changes from external systems in line with configured permissions and data models.

API limitations

The API does not support full platform configuration, user management, or bespoke feature creation. All API usage is limited to documented endpoints, supported data structures, and role-based access controls.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
What can be customised
Users can customise strategy structures, objectives, outcomes, portfolios, governance workflows, dashboards, reporting views, roles, permissions, and data fields within the limits of the platform’s configuration options.

Users can also customise standard names and terms used throughout to support their own organisiation's terms used.

How users can customise
Customisation is completed through the StrategyWorks user interface using built-in configuration settings. No code changes or bespoke development are required. Optional API usage can support data synchronisation but not core configuration.

Who can customise
Customisation is restricted to authorised users with appropriate administrative or configuration permissions. Role-based access controls ensure only approved users can make changes.

Scaling

Independence of resources
StrategyWorks is delivered as a multi tenant SaaS platform using scalable cloud infrastructure.

Resources are managed to ensure that demand from one customer does not impact the performance or availability experienced by others. Capacity is monitored and adjusted to support changes in demand across the user base.

Analytics

Service usage metrics
Yes
Metrics types
StrategyWorks captures platform interaction events related to strategy and portfolio data.

Interaction and usage data is maintained within the StrategyWorks data platform and integrated analytics tooling, and can be reported on upon request. These metrics are used to support service monitoring and improvement.
Reporting types
  • Real-time dashboards
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least every 6 months
Penetration testing approach
In-house
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
StrategyWorks stores customer strategy and performance data within the platform.

Customers can export their data using built in export functionality or via supported APIs.

Data export is supported at any time during the contract and following contract termination in line with agreed offboarding procedures.

Temporary access for assisted data extraction is removed once offboarding is complete.
Data export formats
  • CSV
  • Other
Other data export formats
.xlsx
Data import formats
  • CSV
  • Other
Other data import formats
.xlsx

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
StrategyWorks is a cloud hosted software service operated on third party cloud infrastructure. Platform availability is supported through the resilience and availability features of the underlying cloud infrastructure.

While no fixed availability percentage is guaranteed as part of the standard service, StrategyWorks is designed for continuous operation and is monitored to ensure reliable access. Any service levels, response times, or service credits are defined contractually where required.
Approach to resilience
StrategyWorks is designed as a resilient, cloud-hosted Software as a Service platform.

The service is hosted on third-party cloud infrastructure that provides built-in resilience through redundant components, fault tolerance, and automated recovery mechanisms. Data is stored on resilient storage systems designed to withstand hardware failures without data loss.

The platform is monitored continuously to detect and respond to service issues. Planned maintenance and updates are managed to minimise disruption to users.

Detailed information about datacentre architecture, redundancy, and resilience measures is available to customers on request.
Outage reporting
StrategyWorks reports service outages through email notifications to affected customers and updates provided via the support ticketing system. Where appropriate, service status information is communicated directly to users to ensure transparency and timely awareness of incidents.

StrategyWorks does not provide a public status dashboard or outage reporting API.

Identity and authentication

User authentication needed
Yes
User authentication
Username or password
Access restrictions in management interfaces and support channels
Shapecast restricts access to management interfaces and support activities to authorised staff only.

Access is controlled through role based permissions, multi factor authentication, and strong password policies, following least privilege principles. Access to secure environments requires explicit prior approval from senior management. Support requests are handled through agreed channels.

Access rights are reviewed periodically and removed promptly when no longer required.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Other
Description of management access authentication
Management access to protected environments is further restricted using zero trust access controls. Access is provided through identity based tunnels that require authentication and multi factor verification before connections are established.

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
StrategyWorks follows a security-by-design approach aligned with the Software Security Code of Practice. Security responsibilities are clearly defined, and secure development, access control, vulnerability management, and data protection are built into platform design and operation.

The service relies on secure third-party cloud infrastructure for physical security and resilience, while application-level security controls, monitoring, and access management are managed by the supplier. Security risks are reviewed regularly, and security considerations are incorporated into platform updates and operational processes.

Where appropriate, customers can request further security information to support assurance activities.
Information security policies and processes
StrategyWorks follows documented information security policies and processes aligned with recognised good practice for cloud-based software services.

Security governance is overseen by senior management, with clear responsibility for information security, data protection, and risk management. Policies cover areas including access control, data handling, secure development, incident management, and supplier management.

Security processes are embedded into day-to-day operations through role-based access controls, change management, regular reviews of permissions, and monitoring of service activity. Security considerations are included in platform updates and operational decisions.

Compliance with policies is supported through internal reviews, supplier assurance of third-party cloud infrastructure, and corrective actions where required. Security incidents or risks are reported through defined escalation and reporting procedures.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
StrategyWorks uses documented, supplier-defined configuration and change management processes to manage the service lifecycle.

Service components, configurations, and releases are tracked using version control and change records throughout their lifecycle. Changes to the platform are logged, reviewed, and approved before deployment, with rollback procedures in place where appropriate.

All proposed changes are assessed for potential security impact, including effects on data protection, access controls, and service availability. Security considerations are reviewed as part of the change approval process, and changes are tested prior to release to reduce risk to customers.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
StrategyWorks follows supplier-defined vulnerability management processes aligned with good practice for cloud-based SaaS services. Potential threats are assessed through regular review of platform components, dependencies, and configurations, with risks prioritised based on severity and impact. Security advisories from software vendors, dependency libraries, industry security sources, and the underlying cloud provider are monitored. Patches and updates are deployed in a timely manner according to risk, with critical vulnerabilities addressed as a priority. All changes are tested before deployment to reduce the risk of service disruption.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
StrategyWorks uses supplier-defined protective monitoring processes aligned with good practice for cloud-based SaaS services. Monitoring focuses on service availability, system health, authentication activity, and security-relevant events to help identify potential compromises or abnormal behaviour. Alerts and logs are reviewed to detect unauthorised access, unusual usage patterns, or service anomalies. When a potential compromise is identified, it is investigated promptly, access may be restricted if required, and corrective actions are taken to contain and resolve the issue. Incidents are assessed and responded to based on severity, with higher-risk events prioritised for immediate investigation and remediation.
Incident management type
Supplier-defined controls
Incident management approach
StrategyWorks follows documented, supplier-defined incident management processes aligned with good practice for cloud-based SaaS services.

Pre-defined processes are in place for common incident types, including service availability issues, access problems, and security-related events. These processes support consistent identification, assessment, containment, resolution, and review of incidents.

Users can report incidents through the email and online ticketing support system. Incidents are logged, tracked, and prioritised based on severity and impact.

Incident updates and outcomes are communicated to affected users through the support system, with incident reports provided where appropriate to support transparency and assurance.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Free trials are available by agreement with qualifying organisations for a fixed period, typically one to three months. Trials provide access to a fully functional service, with limited scope applied where appropriate, such as restricting the number of dashboards available.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
7.5%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
12.5%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
50c8451a-db10-4aa3-87d8-04940426ff8d
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at hello@shapecast.com. Tell them what format you need. It will help if you say what assistive technology you use.