StrategyWorks SaaS Platform
StrategyWorks is a strategy and performance management application that manages objectives, programmes, projects, OKRs, KPIs, risks, issues and decisions.
StrategyWorks provides leadership and delivery teams with a clear view of progress, accountability, and outcomes through role based dashboards and secure access. It supports governance, portfolio oversight, and informed decision making.
Features
- Web-based strategy lifecycle management platform
- Structured management of strategic objectives and outcomes
- Portfolio-level alignment of programmes and initiatives
- Configurable governance and ownership management
- Performance and outcome tracking across strategic portfolios
- Visual dashboards for executive oversight and reporting
- Full risk,issue and decision management across the strategy
- Dependency and progress visibility across initiatives
- Role-based access control and permissions
- Configurable to organisational structures without custom development
Benefits
- Improves visibility of strategic delivery across the organisation
- Alignment between strategy, portfolios, and outcomes
- Consistent governance and accountability
- Reduced reliance on spreadsheets and documents
- Enables evidence-based decision-making and prioritisation
- Improves consistency of strategy execution and reporting
- Ability to adapt the strategy as priorities change
- Provides a single, clean source of strategy information
- Reduces risk of underperforming or misaligned initiatives
- Enables effective use of a cloud-based strategy management platform
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 6 2 5 7 1 1 1 0 2 0 0 4 0 6
Contact
SHAPECAST LIMITED
Will Barnett
Telephone: 020 3745 5211
Email: hello@shapecast.com
About your service
- Service categories
-
Applications
Enterprise resource management
- Enterprise performance management
- Project and portfolio management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- YYes. Buyers should be aware of the following constraints. Planned maintenance windows may result in short periods of service unavailability. Internet connectivity is required to access the service. The service is accessed via supported modern web browsers only. Configuration is limited to available platform features as part of the standard service. Integrations are limited to supported APIs and data formats. These constraints are typical for a cloud hosted SaaS service and are managed to minimise operational impact.
- System requirements
-
- Modern web browser supporting current HTML5 standards
- Reliable internet connection
- Screen resolution sufficient to display dashboards and reports
User support
- Email or online ticketing support
- Yes
- Support response times
-
Shapecast aims to respond to email enquiries within 1 working day.
Responses are provided during UK business hours, Monday to Friday.
Weekend and UK public holiday enquiries are reviewed on the next working day. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Shapecast provides a single standard support level for StrategyWorks SaaS customers.
Standard support is provided via email and covers platform usage, configuration guidance, issue clarification, and follow-up questions related to the use of StrategyWorks. Support is available Monday to Friday during UK business hours.
Standard email support is included within the StrategyWorks subscription price. There are no additional charges for standard support.
Enhanced support options can be provided where required and are agreed and priced separately. These may include extended support hours, prioritised response times, or named specialist support.
A dedicated technical account manager or on-call cloud support engineer is not included as part of the standard service. Support is provided by experienced StrategyWorks platform specialists. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
StrategyWorks is designed to support straightforward onboarding using standard product features.
Buyers can get started by setting up their StrategyWorks environment, configuring core structures, and loading data using the platform interface and documentation provided. Standard onboarding materials include user guides, training resources, and documentation to support self service setup.
Optional onboarding support is available where required and may include remote guidance, training sessions, or assisted data loading. More extensive strategy design, integration, or change support can be provided separately as specialist cloud support services. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
When a contract ends, users can extract their data from StrategyWorks using built-in export functionality.
Data can be exported in commonly used, open formats (such as CSV) through the user interface, allowing organisations to retain strategy, portfolio, and performance information. Where required, data exports can also be supported via the API for structured datasets.
After contract termination, access to the service is removed in line with data retention and security policies. - End-of-contract process
-
At the end of the contract, customer access to StrategyWorks is disabled in line with agreed contract terms.
As part of the standard contract price, customers can export their data using the platform’s built in export functionality in open formats such as CSV. This enables customers to retain strategy, portfolio, and performance data for transition or record keeping purposes.
Customers may also request assisted data extraction, where Shapecast securely provides exported data on their behalf using agreed secure transfer methods.
Following contract termination, customer data is retained for an agreed period to allow data extraction, after which it is securely deleted in line with data retention and security policies. - Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Yes, the mobile interface is responsive to the mobile device screen width available.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
-
StrategyWorks is accessed through a secure, web-based user interface via a standard web browser. The interface is designed for clarity and ease of use, with structured views for strategy, portfolios, objectives, initiatives, and performance information.
Users interact with the service through configurable dashboards, tables, and visual summaries that present strategic data, progress, and governance information. Navigation is role-based, ensuring users only see information relevant to their responsibilities.
The interface supports keyboard navigation, clear labelling, and consistent layouts to improve usability and accessibility. No local software installation is required. - Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
StrategyWorks user interfaces have been tested internally against recognised accessibility standards, including WCAG 2.1 AA.
Testing has focused on keyboard navigation, screen reader compatibility, colour contrast, focus indicators, and form usability.
Where third party components are used, supplier accessibility documentation is reviewed.
Accessibility considerations are included as part of ongoing platform updates and improvements. - API
- Yes
- What users can and can't do using the API
-
What users can do using the API
The StrategyWorks API allows authorised users to securely exchange data between StrategyWorks and other systems. Users can retrieve and update structured strategy data such as objectives, initiatives, performance measures, status updates, and ownership information. The API supports integration with reporting, portfolio, and data platforms.
How users can set up the service through the API
The API can be used to programmatically load or synchronise strategy-related data into an existing StrategyWorks environment. Core service setup, tenant creation, and initial configuration are performed through the platform interface rather than exclusively through the API.
How users can make changes through the API
Users can use the API to update supported data fields, refresh status information, and synchronise changes from external systems in line with configured permissions and data models.
API limitations
The API does not support full platform configuration, user management, or bespoke feature creation. All API usage is limited to documented endpoints, supported data structures, and role-based access controls. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
What can be customised
Users can customise strategy structures, objectives, outcomes, portfolios, governance workflows, dashboards, reporting views, roles, permissions, and data fields within the limits of the platform’s configuration options.
Users can also customise standard names and terms used throughout to support their own organisiation's terms used.
How users can customise
Customisation is completed through the StrategyWorks user interface using built-in configuration settings. No code changes or bespoke development are required. Optional API usage can support data synchronisation but not core configuration.
Who can customise
Customisation is restricted to authorised users with appropriate administrative or configuration permissions. Role-based access controls ensure only approved users can make changes.
Scaling
- Independence of resources
-
StrategyWorks is delivered as a multi tenant SaaS platform using scalable cloud infrastructure.
Resources are managed to ensure that demand from one customer does not impact the performance or availability experienced by others. Capacity is monitored and adjusted to support changes in demand across the user base.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
StrategyWorks captures platform interaction events related to strategy and portfolio data.
Interaction and usage data is maintained within the StrategyWorks data platform and integrated analytics tooling, and can be reported on upon request. These metrics are used to support service monitoring and improvement. - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- In-house
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
StrategyWorks stores customer strategy and performance data within the platform.
Customers can export their data using built in export functionality or via supported APIs.
Data export is supported at any time during the contract and following contract termination in line with agreed offboarding procedures.
Temporary access for assisted data extraction is removed once offboarding is complete. - Data export formats
-
- CSV
- Other
- Other data export formats
- .xlsx
- Data import formats
-
- CSV
- Other
- Other data import formats
- .xlsx
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
StrategyWorks is a cloud hosted software service operated on third party cloud infrastructure. Platform availability is supported through the resilience and availability features of the underlying cloud infrastructure.
While no fixed availability percentage is guaranteed as part of the standard service, StrategyWorks is designed for continuous operation and is monitored to ensure reliable access. Any service levels, response times, or service credits are defined contractually where required. - Approach to resilience
-
StrategyWorks is designed as a resilient, cloud-hosted Software as a Service platform.
The service is hosted on third-party cloud infrastructure that provides built-in resilience through redundant components, fault tolerance, and automated recovery mechanisms. Data is stored on resilient storage systems designed to withstand hardware failures without data loss.
The platform is monitored continuously to detect and respond to service issues. Planned maintenance and updates are managed to minimise disruption to users.
Detailed information about datacentre architecture, redundancy, and resilience measures is available to customers on request. - Outage reporting
-
StrategyWorks reports service outages through email notifications to affected customers and updates provided via the support ticketing system. Where appropriate, service status information is communicated directly to users to ensure transparency and timely awareness of incidents.
StrategyWorks does not provide a public status dashboard or outage reporting API.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
-
Shapecast restricts access to management interfaces and support activities to authorised staff only.
Access is controlled through role based permissions, multi factor authentication, and strong password policies, following least privilege principles. Access to secure environments requires explicit prior approval from senior management. Support requests are handled through agreed channels.
Access rights are reviewed periodically and removed promptly when no longer required. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Other
- Description of management access authentication
- Management access to protected environments is further restricted using zero trust access controls. Access is provided through identity based tunnels that require authentication and multi factor verification before connections are established.
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
-
StrategyWorks follows a security-by-design approach aligned with the Software Security Code of Practice. Security responsibilities are clearly defined, and secure development, access control, vulnerability management, and data protection are built into platform design and operation.
The service relies on secure third-party cloud infrastructure for physical security and resilience, while application-level security controls, monitoring, and access management are managed by the supplier. Security risks are reviewed regularly, and security considerations are incorporated into platform updates and operational processes.
Where appropriate, customers can request further security information to support assurance activities. - Information security policies and processes
-
StrategyWorks follows documented information security policies and processes aligned with recognised good practice for cloud-based software services.
Security governance is overseen by senior management, with clear responsibility for information security, data protection, and risk management. Policies cover areas including access control, data handling, secure development, incident management, and supplier management.
Security processes are embedded into day-to-day operations through role-based access controls, change management, regular reviews of permissions, and monitoring of service activity. Security considerations are included in platform updates and operational decisions.
Compliance with policies is supported through internal reviews, supplier assurance of third-party cloud infrastructure, and corrective actions where required. Security incidents or risks are reported through defined escalation and reporting procedures. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
StrategyWorks uses documented, supplier-defined configuration and change management processes to manage the service lifecycle.
Service components, configurations, and releases are tracked using version control and change records throughout their lifecycle. Changes to the platform are logged, reviewed, and approved before deployment, with rollback procedures in place where appropriate.
All proposed changes are assessed for potential security impact, including effects on data protection, access controls, and service availability. Security considerations are reviewed as part of the change approval process, and changes are tested prior to release to reduce risk to customers. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- StrategyWorks follows supplier-defined vulnerability management processes aligned with good practice for cloud-based SaaS services. Potential threats are assessed through regular review of platform components, dependencies, and configurations, with risks prioritised based on severity and impact. Security advisories from software vendors, dependency libraries, industry security sources, and the underlying cloud provider are monitored. Patches and updates are deployed in a timely manner according to risk, with critical vulnerabilities addressed as a priority. All changes are tested before deployment to reduce the risk of service disruption.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- StrategyWorks uses supplier-defined protective monitoring processes aligned with good practice for cloud-based SaaS services. Monitoring focuses on service availability, system health, authentication activity, and security-relevant events to help identify potential compromises or abnormal behaviour. Alerts and logs are reviewed to detect unauthorised access, unusual usage patterns, or service anomalies. When a potential compromise is identified, it is investigated promptly, access may be restricted if required, and corrective actions are taken to contain and resolve the issue. Incidents are assessed and responded to based on severity, with higher-risk events prioritised for immediate investigation and remediation.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
StrategyWorks follows documented, supplier-defined incident management processes aligned with good practice for cloud-based SaaS services.
Pre-defined processes are in place for common incident types, including service availability issues, access problems, and security-related events. These processes support consistent identification, assessment, containment, resolution, and review of incidents.
Users can report incidents through the email and online ticketing support system. Incidents are logged, tracked, and prioritised based on severity and impact.
Incident updates and outcomes are communicated to affected users through the support system, with incident reports provided where appropriate to support transparency and assurance. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Free trials are available by agreement with qualifying organisations for a fixed period, typically one to three months. Trials provide access to a fully functional service, with limited scope applied where appropriate, such as restricting the number of dashboards available.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12.5%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 50c8451a-db10-4aa3-87d8-04940426ff8d
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-