SAM People HRIS for Schools
SAMpeople is designed by education HR specialists for schools and trusts. It provides a single source of truth for staff data from recruitment to offboarding, with education-specific workflows, built-in compliance and reporting. Integrated with Arbor MIS and payroll systems, it supports consistent, scalable people management across schools and trusts.
Features
- End-to-end education recruitment from advert to onboarding
- Centralised employee records including contracts, roles and history
- Single Central Record and KCSIE safer recruitment tracking
- Absence, leave and TOIL management with staff self-service
- Performance, appraisal and HR case management workflows
- Payroll export or fully managed education payroll and pensions
- MAT and school-level reporting and workforce analytics
- Integration with Arbor MIS with automated read/write sync
- Policy distribution, document management and expiry alerts
- Scalable multi-school structure supporting growth and change
Benefits
- Reduces manual HR processes and spreadsheet dependency
- Improves data accuracy by removing duplicate data entry
- Supports safer recruitment and safeguarding compliance
- Provides a single source of truth for workforce data
- Enables consistent HR processes across schools and trusts
- Saves time across recruitment, HR administration and payroll
- Supports MAT growth without increasing HR headcount
- Improves staff experience through mobile self-service access
- Gives leaders visibility of workforce trends and risks
- Brings HR, payroll, and MIS data into one people system
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 6 9 4 8 5 4 8 3 1 1 5 3 0 0
Contact
ARBOR EDUCATION PARTNERS GROUP LTD
Phillippa De'Ath
Telephone: 0208 050 1028
Email: bids@arbor-education.com
About your service
- Service categories
-
Applications
Enterprise resource management
Human capital management
- Core Human Resources Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- The managed payroll bureau service operates in conjunction with SAMpeople HRIS, as payroll processing is based on employee and contractual data held within the HR system. Buyers procuring the payroll bureau service must therefore also have SAMpeople HRIS in place.
- System requirements
-
- Modern web browser with JavaScript enabled.
- Internet connection for secure cloud access.
- Payroll service is delivered in conjunction with SAMpeople HRIS
User support
- Email or online ticketing support
- Yes
- Support response times
-
Our standard SLA commitments include:
• Initial response within two working days, sooner for urgent issues
• Prioritisation and escalation based on impact and severity
• Transparent case tracking for Trust-level oversight
Our offices are open between 8.30am to 4.30pm Monday to Friday, excluding public and bank holidays. Our ticketing system is available 24/7/365. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- None has yet been done.
- Onsite support
- Yes, at extra cost
- Support levels
-
SAMpeople provides structured onboarding and ongoing support as part of its standard service model.
During implementation, customers are supported by a Customer Onboarding Partner, who leads system configuration, data validation, training coordination, and go-live preparation. This support is included within the initial setup costs.
Following go-live, customers are supported by a Customer Success Partner, who acts as the primary point of contact for the duration of the contract, providing service oversight and guidance on effective system use. This role is included within the annual subscription.
All users have access to the SAMpeople Hub, which provides user guides, help sheets, recorded training videos, and access to live webinars for administrators, line managers, and employees. Resources are updated regularly.
Ongoing support is delivered via the SAMpeople Hub ticketing system, email, and telephone during published support hours. Functional support, configuration guidance, and issue resolution are included.
For Multi-Academy Trusts, a mandatory Advanced Support Package is provided at £200 per school per year. This includes Trust-level coordination, onboarding support for additional schools, customer education and training, phased module roll-out, and ongoing Trust account management.
SAMpeople technical support is delivered through our central support teams. - Support available to third parties
- No
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
SAMpeople supports customers through a structured onboarding process designed to enable users to begin using the service efficiently and with confidence.
Implementation is led by a Customer Onboarding Partner, who coordinates system setup, data validation, configuration, and training. Onboarding is delivered remotely and tailored to the customer’s operational model, ensuring users are introduced to the system in a controlled and practical way.
Role-based training is provided for administrators, line managers, and employees. Training is delivered online through live remote sessions, supported by recorded training videos and written guidance. Key users are provided with access to a sandbox environment, allowing them to familiarise themselves with the system using dummy data prior to go-live.
All users have access to the SAMpeople Hub, which provides a library of user guides, help sheets, recorded training materials, and access to live webinars. Resources are available on demand and updated to reflect system changes.
Following go-live, ongoing support is provided by the Customer Success Partner and central support team via the SAMpeople Hub ticketing system, email, and telephone, ensuring continued assistance as users embed the system into day-to-day operations. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
- Video
- End-of-contract data extraction
-
At the end of the contract, customers can extract their data directly from SAMpeople using standard system reporting and export tools. Data reports can be generated and exported in commonly used formats, including Excel, CSV, and PDF. Case records and supporting documentation can be printed or saved as PDF files for local retention.
Where an MIS integration is in place, relevant HR data may also have been written back to the MIS during service use, subject to the availability and scope of the integration.
Following contract termination, customer data is retained securely for up to two years in line with SAMpeople’s data retention policy, allowing customers to request additional extracts if required. After this period, data is securely deleted in accordance with contractual and data protection obligations. - End-of-contract process
-
At the end of the contract term, customers may either renew the service in line with the agreed contractual terms or allow the service to conclude. Customers are required to provide notice in accordance with the terms of their agreement.
Prior to contract end, customers can extract their data using standard reporting and export tools available within SAMpeople. Where required, guidance on data extraction and service exit is provided by the support team.
Following contract termination, customer data is retained securely for a defined period in line with SAMpeople’s data retention policy, after which it is permanently deleted in accordance with data protection requirements.
Pricing and additional costs:
The contract price includes access to the licensed SAMpeople services, standard support, and assistance with service exit and data extraction, provided all fees are up to date.
Any optional services procured during the contract term (such as additional licences, payroll services) are charged separately in accordance with the agreed pricing schedule. Additional support beyond the standard service scope may be subject to additional cost where applicable. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Onboarding and offboarding documentation is provided digitally through the SAMpeople Hub, which is accessible via a standard web browser. Documentation is available online and on demand, with no requirement for specialist software.
During onboarding, customers are provided with structured onboarding documentation, including guidance notes, checklists, and standard data templates used to support data preparation and migration. These templates are shared via the SAMpeople Hub and form part of the onboarding process led by the Customer Onboarding Partner.
Documentation is organised by stage of the service lifecycle and by user role, and can be viewed online or downloaded where appropriate. Access is controlled through role-based permissions to ensure users only see relevant content.
Offboarding documentation is also available via the SAMpeople Hub and provides guidance on service exit, data handling, and access removal in line with contractual and data protection requirements. Documentation is maintained centrally and updated as required.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
SAMpeople HRIS is primarily designed for use on desktop browsers, providing administrators with full access to configuration, reporting, and management functionality. The employee self-service portal, MySAM, is mobile-responsive and can be accessed via smartphones and tablets for common tasks such as viewing information, submitting requests, and signing documents.
SAMpeople Recruit follows a similar model. Administrative users access full recruitment functionality via desktop browsers, while the candidate portal is mobile-responsive, allowing candidates to search vacancies, submit applications, and track progress on mobile devices. - Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- SAMpeople provides a secure, browser-based service interface for administrators and users, including the MySAM employee self-service portal and the candidate interface for SAMpeople Recruit.
- Accessibility standards
- None or don’t know
- Description of accessibility
- SAMpeople is accessed via a secure, browser-based interface using role-based permissions. Administrators access full system functionality, including configuration, reporting, and compliance management. Line managers can view and manage information relating to their teams, including approvals and attendance. Employees access the MySAM self-service portal to view personal information, submit requests, and complete assigned actions. Recruitment administrators access SAMpeople Recruit via desktop browsers, while candidates access a mobile-responsive candidate portal. Users can only view or act on information permitted by their assigned role.
- Accessibility testing
-
SAMpeople has not undertaken formal, standalone interface testing sessions specifically with users of assistive technology. However, accessibility considerations are incorporated into system design and ongoing development, with the service delivered through standard, browser-based interfaces that rely on widely supported web technologies.
The service is regularly used by a diverse user base across schools and Trusts, including users with varying accessibility needs, and feedback is captured through support interactions and user engagement. Where accessibility issues are identified, they are reviewed and addressed as part of continuous improvement. - API
- Yes
- What users can and can't do using the API
- SAMpeople provides limited, secure APIs to support approved integrations with specific systems. These APIs are not publicly exposed and are not available for general customer or third-party use.
- API documentation
- No
- API sandbox or test environment
- No
- Customisation available
- No
Scaling
- Independence of resources
-
SAMpeople is delivered as a multi-tenant SaaS platform hosted within the Microsoft Azure public cloud. The underlying infrastructure is monitored 24/7/365 and configured to scale automatically to meet demand. Resources are allocated dynamically to ensure performance is maintained during peak usage periods.
Customer data is logically segregated within the platform, and system capacity is managed centrally to prevent individual customer activity from adversely impacting others. Service availability and performance are continuously monitored, with proactive management to ensure consistent and reliable access for all users.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
SAMpeople provides service performance and operational metrics. Service availability is monitored in real time, with current and historical status published via an online status page. Support activity is measured against agreed SLA response times, with performance tracked through the support system. During onboarding, service and delivery KPIs may be agreed where appropriate.
In addition, SAMpeople provides audit reporting showing user activity, including user identity, date, and time stamps for key actions, subject to role-based permissions. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
-
Users can export their data directly from SAMpeople using built-in reporting and export tools. Standard reports can be generated and exported in commonly used formats, including Excel, CSV, and PDF. Case records and supporting documentation can be printed or saved as PDF files.
Data exports can be performed at any time during the contract term by authorised users, subject to role-based permissions. Guidance on exporting data is available through user documentation and support resources. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- Data import formats
-
- CSV
- Other
- Other data import formats
- Excel
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
SAMpeople is delivered via a centrally hosted, UK-based cloud infrastructure and is designed to provide a level of availability consistent with comparable SaaS services used in the education sector.
While SAMpeople does not provide a contractual guarantee of uptime or network response times, the service is actively monitored on a 24/7 basis. Reasonable endeavours are used to maintain service availability and to investigate and resolve incidents that impact access.
Service availability is monitored continuously, and historical availability is tracked via an online service status page. Planned maintenance is managed centrally and communicated in advance where possible.
The service does not include a service credit or financial refund mechanism linked specifically to availability levels. Support incidents are managed in line with published support processes and response targets. - Approach to resilience
-
SAMpeople is delivered as a cloud-based SaaS service hosted within the Microsoft Azure public cloud, using UK-based data centres. The service is designed with resilience in mind, leveraging Azure’s underlying infrastructure, which includes redundancy across compute, storage, and network components.
The platform is monitored continuously, with automated alerting and incident management processes in place to detect and respond to service issues. Data is stored securely and backed up in line with defined backup and retention policies to support service recovery.
Capacity is managed centrally, and the cloud infrastructure supports scaling to maintain service availability during periods of increased demand. Further detail on data centre resilience and architecture can be provided on request. - Outage reporting
-
SAMpeople reports outages through multiple channels:
Public dashboard: Service availability and incidents are published on our public status page: http://status.feps.co.uk/.
Email alerts: For unplanned outages or significant incidents, email notifications are issued to keep customers informed and to provide progress updates through to resolution.
Customer support portal notifications: Updates are also posted via the SAMpeople Hub help centre to support incident communication and query management.
In-application notifications: Where relevant, in-product messages (such as pop-ups or banners) may be displayed to advise users of service disruption or feature-specific issues.
For planned maintenance, customers are notified in advance where possible. In emergency situations where advance notice cannot be provided, customers are notified at the earliest opportunity via the channels above.
API: No outage reporting API is provided.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
-
Access to management interfaces and support channels within SAMpeople is controlled through unique, individual user accounts. Shared accounts are not permitted, ensuring accountability and allowing access to be revoked promptly when required.
Role-based permissions are applied to restrict what users can view or action within the system and within support channels, ensuring access aligns with job responsibilities. Support requests submitted via the SAMpeople Hub are associated with authenticated user accounts, providing a clear audit trail.
User access can be amended or removed by authorised administrators, supporting secure access management throughout the service lifecycle. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
SAMpeople follows formal information security policies and processes aligned with its ISO/IEC 27001 information security management framework.
Information security governance is overseen by senior management, with defined responsibilities for information security and data protection. Policies are supported by documented operational procedures and are embedded into day-to-day service delivery.
Core policies include an Information Security Policy, Data Protection and Privacy policies, an Incident Management Policy, and a Business Continuity Policy. These set out how information is protected, how incidents are identified and managed, and how service continuity is maintained in the event of disruption.
Compliance with policies is supported through staff training, role-based access controls, and established incident reporting and escalation processes. Security incidents are logged, investigated, and managed in line with documented procedures, with appropriate reporting where required.
Policies and processes are reviewed regularly to ensure they remain effective and aligned with organisational risk and regulatory requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
SAMpeople uses a structured configuration and change management approach aligned with its development and security processes.
Service components and changes are tracked throughout their lifecycle using standard development and change control tools. Changes are assessed prior to implementation to understand technical, operational, and security impact. Where relevant, changes are reviewed by senior technical staff and the Data Protection Officer.
All development and testing is carried out in non-production environments that are isolated from the live service. Changes are tested before release and deployed using controlled processes to minimise risk. Post-release reviews are carried out to confirm stability and effectiveness. - Vulnerability management type
- Undisclosed
- Vulnerability management approach
-
SAMpeople manages vulnerabilities through a structured monitoring and response process. The service is hosted in a secure cloud environment and is monitored continuously using third-party security tooling and platform controls. Potential threats are identified through system monitoring, vendor security notifications, and guidance from trusted sources, including regular updates from the National Cyber Security Centre (NCSC).
Identified vulnerabilities are assessed for risk and impact and escalated to senior leadership and the Data Protection Officer where appropriate. Patches and mitigations are prioritised based on severity, with critical issues addressed promptly. All actions are logged and reviewed as part of ongoing security management. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
SAMpeople uses protective monitoring to identify and respond to potential security incidents. The service is monitored continuously using third-party security monitoring tools and cloud platform controls, which alert on unusual activity or potential compromises.
When a potential compromise is identified, it is assessed by the Data Protection Manager and escalated to senior leadership where appropriate. Incidents are logged and managed in line with documented incident management procedures.
Response times are prioritised based on severity, with critical incidents responded to within two hours and urgent incidents within four hours, ensuring timely investigation and mitigation. - Incident management type
- Supplier-defined controls
- Incident management approach
-
SAMpeople operates a defined incident management process covering common service and security events. Incidents are logged, tracked, and managed through our secure service desk and internal DevOps tracking tools.
Users report incidents via the SAMpeople Hub ticketing system or by contacting the support team. Incidents are assessed, prioritised, and managed in line with documented procedures.
Service status and incident updates are published via the public status page (http://status.feps.co.uk/) and communicated to customers through the Help Centre and email as appropriate. Incident reports and updates are provided throughout resolution until closure. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- A sandbox is available for trial purposes that gives full access to a demo version of SAMpeople, with dummy data loaded. This is available for SAMpeople customers and potential customers. Access is limited when given to non-customers/potential customers.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO Certification Limited
- ISO/IEC 27001 accreditation date
- Tuesday 24 March 2020
- What the ISO/IEC 27001 doesn’t cover
- Our ISO 27001:2013 certification is comprehensive, covering the entirety of our information security management system across all offices and systems. We do not exclude any internal business systems or geographic locations from this scope, ensuring that every aspect of our operations meets this international benchmark for data security. While our certification specifically validates our internal management processes and the security of platforms, it is important to note that it does not extend to the independent internal infrastructure of the schools we serve or third-party hardware managed locally by clients.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Citation ISO Certification Limited
- ISO 9001 accreditation date
- Tuesday 10 January 2023
- What the ISO 9001 doesn’t cover
- Our ISO 9001:2015 certification is an internationally recognised gold standard that ensures our quality management systems are measurably effective and subject to independent annual audits. We added this certification specifically to provide assurance for our customer services, ensuring that our internal processes for supporting schools and trusts meet rigorous quality benchmarks.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Eaa86dd2-b784-4b53-bee1-76f80b5f6903
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of issues relating to entering the contract workforce
-