Panther
Panther Software Limited provides a cloud-based workforce management and services automation platform supporting organisations to manage workforce.
The service supports workflows including project setup, resource scheduling, vendor management, time and expense capture, payroll and billing integration, compliance, forecasting, and reporting. It is also suitable for safety-critical organisations and multi-project environments.
Features
- Real-time workforce scheduling and availability management
- Web and mobile time, attendance, expense capture
- Vendor management with multi-tier agency access controls
- Project, contract, and task management workflows
- Reporting dashboards and data exports
- Secure API integrations with HR and finance systems
- Compliance tracking for skills, training, certifications
- Cloud-hosted scalable infrastructure with high availability
Benefits
- Simplify supplier collaboration across first and second tier agencies
- Improve workforce utilisation and reduce manual scheduling effort
- Accelerate payroll and billing through automated data flows
- Increase compliance visibility and reduce operational risk
- Enable accurate forecasting of resource and project demand
- Reduce administrative overhead with integrated workflows
- Support remote teams with secure system access
- Improve decision making with real-time performance insights
- Scale operations without additional IT infrastructure
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
4 9 6 0 0 0 4 9 3 1 0 0 4 1 5
Contact
PANTHER SOFTWARE LIMITED
BidTeam Panther
Telephone: 0330 555 0154
Email: bidteam@panther-software.co.uk
About your service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Bullhorn, InTime, SAP, COINS ERP, UKG Pro Workforce Management, BambooHR, Microsoft Dynamics, Microsoft Business Central, Point of Rental (Syrinx), Sage and Xero, enabling secure data exchange, synchronised records and streamlined operational workflows across systems.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- The service requires reliable internet access and a modern supported web browser. Planned maintenance and upgrades are scheduled outside UK business hours where possible and may cause short periods of reduced availability, with advance notice provided. Some integrations depend on third-party system availability, APIs, and customer configuration. Data migration quality depends on the accuracy of source data supplied by the customer.
- System requirements
-
- Modern web browser such as Chrome, Edge, Firefox, Safari
- Reliable internet connection for continuous cloud access
- JavaScript and cookies enabled in browser settings
- Email access for notifications and password resets
- API access credentials for third-party system integrations
User support
- Email or online ticketing support
- Yes
- Support response times
-
Support is provided via email ticketing during working hours. All requests receive an automated acknowledgement, followed by human response based on priority.
Target response times are: Urgent incidents within 1 working hour, High within 2 working hours, Normal within 4 working hours, and Low within 1 working day.
Status updates are provided regularly based on incident severity.
Resolution is progressed using reasonable endeavours, with urgent issues prioritised for same-day workaround or fix where possible.
Response times may be longer outside standard working hours and at weekends, except for critical service outages. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes
- Support levels
-
Standard support is included within the subscription price and is provided via email ticketing. Customers do not pay extra for standard helpdesk support.
Incidents are prioritised into four levels:
Urgent (system unavailable), High (time-critical function unavailable), Normal (non-critical function unavailable), and Low (cosmetic or minor issues).
Target response times are:
Urgent within 1 working hour, High within 2 working hours, Normal within 4 working hours, and Low within 1 working day. Status updates and resolution targets are applied according to incident priority, with urgent incidents prioritised for same-day workaround or fix where possible.
Support is delivered by experienced technical support engineers with access to development and infrastructure teams for escalation where required. A dedicated Technical Account Manager is not included as standard but can be provided by agreement for larger or complex deployments as part of an enhanced support arrangement.
Support hours are standard business hours, with critical incidents prioritised outside hours where required. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Panther provides structured onboarding to support customers from initial setup through to live operation. This includes implementation planning, configuration of workflows and permissions, data migration where required, and validation of integrations with third-party systems.
Training is provided through a combination of remote sessions, role-based training workshops, and recorded materials tailored to administrative users, managers, and workforce users. Training can be delivered online and, where required, onsite as part of implementation services.
User documentation is provided covering system setup, daily operations, and administrative tasks, supported by in-application guidance and help prompts. Customers are also supported by dedicated implementation consultants during onboarding to ensure system configuration aligns with operational processes.
After go-live, customers transition to standard support services, with access to helpdesk support and ongoing assistance for configuration changes and new user onboarding. Additional training and change support can be provided as required to support organisational growth or process changes. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Customers can extract their data using built-in mass export tools within the service or via the secure REST API. Administrative users can generate bulk exports of key data sets including workers, assignments, projects, suppliers, timesheets, expenses, compliance records, and reference data in commonly used file formats such as CSV.
Exports can be run on demand and repeated as required prior to contract end to support migration planning and validation. Where customers have existing integrations, the API can also be used to extract structured data programmatically into replacement systems or data warehouses.
Panther can provide guidance on available export options and recommended data sets during offboarding, and professional services can be provided where customers require assistance with data extraction or transformation. - End-of-contract process
-
At contract end, customers are supported to complete data extraction using built-in mass export tools and/or the secure API as part of standard service access. This is included within the contract price and can be completed by customer administrators prior to service termination.
Once data extraction is complete and the contract has ended, the customer environment is securely decommissioned and live data is deleted from production systems in line with data protection and security policies. Where required by contract or regulation, encrypted backups may be retained for a defined period to meet legal, audit, or compliance obligations, after which they are securely deleted.
Standard offboarding activities and account closure are included in the service. Additional professional services, such as assisted data migration, bespoke export formats, data transformation, or extended retention beyond standard policies, may be provided at additional cost if requested by the customer. - Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The desktop and tablet interface provides full administrative functionality, including workforce planning, project management, reporting, configuration, and integrations, designed for users who require access to detailed operational data. The mobile experience is optimised for workforce users and focuses on core tasks such as viewing schedules, submitting timesheets, recording attendance, expenses, and completing required compliance actions. Some advanced configuration, reporting, and bulk data management functions are not available on mobile devices and are intended to be completed using the desktop or tablet interface.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The service is accessed through a secure, web-based user interface using standard browsers, with responsive layouts for desktop, tablet, and mobile devices. Administrative users access full workforce planning, project management, reporting, and configuration features via desktop and tablet interfaces designed for data-heavy workflows. Workforce users access mobile-optimised interfaces for viewing schedules, submitting timesheets, recording attendance and expenses, and completing compliance tasks. The interface supports role-based access, dashboards, and contextual navigation based on user permissions.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The service is accessed through standard web browsers and supports common assistive technologies such as screen readers, browser zoom, and keyboard navigation where supported by the user’s device and browser. An accessibility support plugin (accessiBe) is used to provide additional options including font size adjustments, contrast controls, and screen reader optimisation.
- Accessibility testing
-
Formal usability testing has not been conducted solely with specialist assistive technology user groups. However, accessibility is considered during interface design and testing, including use of browser-based accessibility tools, screen reader checks, keyboard-only navigation testing, and colour contrast reviews within supported browsers.
The service uses an accessibility support plugin (accessiBe), which provides automated scanning and remediation features such as screen reader optimisation, keyboard navigation support, contrast controls, and text presentation adjustments. These features have been reviewed and tested by customers, including Network Rail, as part of their internal accessibility and usability assessments. - API
- Yes
- What users can and can't do using the API
-
The service provides a secure REST API that allows customers and integration partners to automate data exchange with external systems such as HR, payroll, finance, recruitment, and vendor management platforms. Users can create, update, and retrieve core records including workers, assignments, timesheets, expenses, projects, suppliers, and reference data, subject to role-based permissions and API credentials.
The API can be used during onboarding to populate master data and keep records synchronised between systems, reducing manual data entry. Ongoing changes such as updating worker details, submitting timesheets, approving records, and exporting financial data can also be performed through supported endpoints.
Configuration of business rules, security roles, approval workflows, and system-wide settings must be performed through the administrative user interface and cannot be fully managed via the API. Some bulk or complex operational processes may also require UI-based management to maintain data integrity and governance.
API usage is subject to authentication, authorisation controls, and rate limiting to ensure platform stability and security. API documentation is provided to customers and partners to support integration development and testing. - API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Buyers can customise the service primarily through configuration rather than bespoke code. Configurable options include workflows, approval rules, project and contract structures, data fields, validation rules, compliance requirements, user roles, access permissions, dashboards, reports, and integration mappings.
Authorised administrative users can apply many configuration changes directly through the service interface using built-in administration tools. These changes take effect without software deployment or service downtime.
Where customers require additional functionality not available through existing configuration, Panther may deliver enhancements through controlled product development. These enhancements are added to the core platform as configurable features, rather than creating customer-specific code branches, ensuring ongoing support, security updates, and compatibility with future releases.
Scaling
- Independence of resources
- The service uses a clustered database architecture (Galera cluster) to distribute database load and provide high availability, ensuring that increased demand from one customer does not degrade performance for others. Application services are deployed on scalable cloud infrastructure, allowing capacity to be increased as usage grows. Performance and capacity are continuously monitored by Panther administrators with proactive scaling where required. The platform has been proven in production to support deployments scheduling over 40,000 workforce assignments per week, demonstrating its ability to operate at scale while maintaining consistent performance.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service records application-level usage metrics including user login history, session activity, and audit logs of key actions such as record creation, updates, approvals, and submissions. These logs support security monitoring, operational support, and investigation of data changes where required. Activity data can be filtered by user, date, and functional area to support issue resolution and compliance review. Infrastructure performance and availability metrics are monitored by Panther administrators only and are not exposed to customers.
- Reporting types
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Administrative users can export data using self-service mass export tools within the service. These tools allow bulk download of key data sets including workers, assignments, projects, suppliers, timesheets, expenses, compliance records, and reference data in common file formats such as CSV. Exports can be filtered by date range, project, or status and run on demand as required. For automated or ongoing data transfer, the secure REST API can also be used to extract structured data into external systems or data stores.
- Data export formats
-
- CSV
- Other
- Other data export formats
- API / Json
- Data import formats
-
- CSV
- Other
- Other data import formats
- Via API
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
The service is designed for high availability and is monitored continuously. Availability is measured monthly. If unscheduled downtime exceeds 24 hours in any calendar month, customers are entitled to service credits. For each hour (or part thereof) of unscheduled downtime above 24 hours, the customer receives a credit equal to 1% of the monthly subscription fee, up to a maximum of 100% of the monthly fee for that month.
Service credits are applied to the next month’s invoice, or refunded within 30 days if the contract has ended. This credit mechanism is the sole and exclusive remedy for service unavailability under the subscription agreement.
Downtime caused by third-party software, customer systems, or third-party hosting providers is excluded from service credit calculations. Planned maintenance is scheduled outside of core operating hours where possible and does not count as unscheduled downtime.
Helpdesk support is provided throughout the subscription term via email support, with incidents triaged and responded to according to severity. - Approach to resilience
-
The service is hosted on Microsoft Azure using resilient cloud infrastructure designed for high availability and fault tolerance. Platform components are deployed across redundant compute and network resources to reduce the impact of individual component failures. Database services use clustered architecture (Galera cluster) with replication across nodes, enabling continued operation if a single node becomes unavailable.
Regular automated backups are performed and stored securely to support data recovery in the event of data corruption or system failure. Infrastructure and application performance are continuously monitored by Panther administrators, with automated alerts and operational procedures to respond to incidents and capacity issues.
Azure datacentres provide resilient physical facilities, including redundant power, cooling, and network connectivity, and are independently certified to recognised security and resilience standards. Disaster recovery procedures and restoration processes are tested as part of operational governance and incident management.
Capacity planning and scaling processes are used to ensure the service can accommodate increases in demand without degradation of performance. Detailed architecture and resilience information can be provided to buyers on request where required for assurance purposes. - Outage reporting
-
Service availability and incidents are communicated to customers through a public service status dashboard, which provides real-time and historical information about platform availability, planned maintenance, and active incidents. Customers can view current service status without logging into the application.
In addition, email notifications are sent to nominated customer contacts when significant service incidents occur, including updates on investigation progress and service restoration. Planned maintenance windows are also communicated in advance via email and reflected on the status dashboard.
Internally, infrastructure and application monitoring tools generate automated alerts to Panther support teams, enabling rapid detection and response to service issues. Customers may also report issues through support channels, which are logged and managed through incident management processes.
Post-incident communication and root cause summaries can be provided to customers where required as part of service reviews or contractual reporting.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Username or password
- Other
- Other user authentication
- Microsoft SSO
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted to authorised staff only, based on defined roles and least-privilege principles. Logical access controls are used to prevent unauthorised access to systems and information, and permissions are approved, reviewed and removed when no longer required. Administrative access is limited to the IT team and protected by strong authentication. Support channels (including the service desk) are used as controlled entry points for requests and incident reporting, ensuring audit trails are maintained. Access controls and permissions are reviewed through internal audits and management reviews as part of our ISMS.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Dedicated link (for example VPN)
- Other
- Description of management access authentication
- Microsoft SSO
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Panther operates an information security management system aligned with ISO 27001, covering governance, risk management, access control, incident management, supplier management, and business continuity. Security policies are documented, reviewed regularly, and communicated to all staff as part of mandatory training and onboarding processes.
Security responsibilities are defined within management roles, with incidents and risks escalated through formal reporting and review processes. Security events are logged, investigated, and managed through incident response procedures, including root cause analysis and corrective actions where required.
Access to systems and customer data is controlled using role-based permissions and least-privilege principles. Changes to production systems follow controlled change management processes with peer review and testing prior to deployment.
Supplier and hosting providers are assessed against security requirements, and contractual controls are maintained for data protection and confidentiality. Compliance with policies is monitored through internal reviews, operational controls, and management oversight, with corrective actions tracked to completion.
Information security risks are reviewed as part of regular management review cycles to ensure continuous improvement of controls and processes. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Service components are tracked through version control, deployment pipelines, and environment inventories, providing traceability of changes throughout their lifecycle. All changes are logged, reviewed, and approved before deployment, with separation between development, testing, and production environments. Changes are assessed for operational and security impact, including access control, data handling, and dependency risks, in line with information security policies. Testing is completed prior to release, and rollback procedures are in place where required. Emergency changes follow controlled processes with retrospective review to ensure risks are identified and corrective actions applied.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We assess potential threats using vendor threat intelligence and security alerts from CrowdStrike, Mimecast and Microsoft, which are reviewed regularly and escalated via our incident management process. Vulnerabilities are ranked by severity and prioritised, with high-severity issues patched first and any exceptions formally logged. Company laptops and mobile devices are configured for automatic OS, antivirus and application updates, which users cannot disable. Third-party software is patched periodically, and immediately where zero-day exploits are identified. This ensures rapid deployment of critical patches and continuous risk reduction across our services.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We identify potential compromises through continuous endpoint, email and cloud monitoring using security tooling and automated alerts, combined with log review and user reports. Alerts indicating suspicious activity are triaged promptly and assessed for severity and potential impact. Where a compromise is suspected, affected accounts or devices are isolated, credentials are reset, and forensic investigation is initiated in line with our incident management procedures. Incidents are escalated to management as required, with actions tracked to resolution. High-severity incidents are responded to immediately, with containment actions typically initiated the same day.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We have processes for common information security events and incidents, with clear criteria for when events are treated as incidents. Users report incidents as soon as possible via the Panther Service Desk, which acts as the single point of contact and ensures an audit trail is captured. Incidents are prioritised, investigated and managed by the IT team, with initial assessment by the CTO and Head of IT. Investigations are initiated immediately and, where possible, within 24 hours, with containment, forensic analysis and corrective actions tracked to closure. Incident reports and lessons learned are documented and reviewed through ISMS management review.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Peers Quality Assurance Limited
- ISO/IEC 27001 accreditation date
- Tuesday 19 March 2024
- What the ISO/IEC 27001 doesn’t cover
-
The ISO/IEC 27001 certification applies to the information security management system covering the provision and operation of the Panther and Signal SaaS recruitment platforms, as defined in the Statement of Applicability.
Activities outside the scope include customer-managed devices, local IT environments, customer network infrastructure, and any third-party systems or integrations not operated or controlled by Panther Software Limited. Security of data once exported from the service and stored within customer-managed environments is also outside the scope of certification.
Physical security controls of third-party cloud datacentres are covered through supplier assurance and contractual arrangements with cloud service providers, rather than direct certification of those facilities under Panther’s own ISO certificate.
Any customer-developed customisations, third-party plugins, or external reporting tools not hosted or managed by Panther are also outside the certified scope. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-