Tribal – Case Management System
Our feature rich, event driven Case Management system provides end-to-end participant management for employability and Health & Wellbeing programmes. It supports self-service participant access, configurable workflows, assessments, and dashboards, with automated milestone based reporting. This enables consistent service delivery, transparency, and measurable outcomes.
Features
- Complete end-to-end configurable outcome focused case management system
- Contract builder with deadlines/automations using a graphical workflow designer
- Assessment and survey designer with version controlling
- Unique search with recommendations speed-up planning and distance travelled
- Full diary management with Outlook integration and automated reminders
- Comms module with SMS, Email, Letters and Telephone
- Create, share and arrange Dashboard widgets and Real-time reporting
- PRaP pipeline and self-referral functionality with PRaP linking
- Comprehensive auditing with GDPR functions
- CRM and Vacancy Management
Benefits
- Intuitive User Experience accelerates user adoption and training
- Build flexible contracts with context aware deadlines and automation
- Graphical participant journeys provide status, clarity and next step visibility
- Build and share Dashboards to keep advisors informed of priorities
- Clear diary management for Team Leaders, advisors and participants
- Survey designer captures structured, actionable participant feedback
- Automated communications keep your participants informed
- Transparency with in-screen user auditing throughout
- Secure data in an ISO27001 accredited environment, hosted within Azure
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 0 2 5 1 6 5 5 6 7 8 8 4 9 9
Contact
TRIBAL BUSINESS SOLUTIONS LIMITED
Nathan Churchman
Telephone: 01245 975566
Email: bizdev@poweredbytribal.co.uk
About your service
- Service categories
-
Applications
Content workflow and management
Content services
- Enterprise Content Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Services are deployed on Azure public cloud or windows-based systems only.
- System requirements
-
- Microsoft Windows Server OS based systems in vendor support
- Microsoft SQL Database servers also in current vendor support
- Antivirus technologies
- Net Framework support
- Firewalls & associated bypasses in filtering technologies to access system
User support
- Email or online ticketing support
- Yes
- Support response times
-
Ticket based system this is aligned with our SLA’s the ticket system operates 8.30am to 5pm Monday-Thursday and 8.30am-4.30pm Friday.
No Ticket or support system is available at weekends. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
CMS Support offering:
- UK Service Desk (Phone, Email, Portal),
- Remote Support for end users,
- New User Onboarding and Leave Offboarding to the application,
- Online Ticketing Portal and Knowledge Base,
- Chargeable Onsite Support. - Support available to third parties
- No
Onboarding and offboarding
- Getting started
- User Documentation is provided, additional online training is available at cost.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
-
Data can be extracted through csv export, or full DSAR pdf extraction.
Additional considerations such as database.
Additionally we can provide read-only licensing or bespoke data extraction at additional cost - End-of-contract process
-
If a customer chooses not to renew their contract, we will provide an open window up to 3 months from contract end for extraction of their data or to extend their contract on a read-only basis.
One data extraction has been completed, a formal notification of data deletion will be provided to the customer in line with data security and data protection requirements. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Slight interface differences - nothing major.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
- API is available for interaction however this would be additional cost/customisation. API is documented and can be shared as needed via Swagger.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Customisation is possible via a project-based methodology. Additional Feature requests, branding, customised API interaction.
Scaling
- Independence of resources
- Each customer has their own unique B2C tenant isolated platform for the application, data is segmented at the data plane into separate isolated database instances and database backends.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Service Level Agreements (response/resolve). This includes number of tickets logged, their priority, etc. Top categories of tickets logged.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- Yes
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Other
- Other data at rest protection approach
- All data stored in database is encrypted at rest via PMK within the Azure platform.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export data where permitted in the boundary of the contract via excel csv and pdf documents managed through the file system interface of the application.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
-
- .doc
- Docx
- Xlsx
- Xls
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- The CMS platform operates using latest TLS1.3 & support for TLS 1.2 ciphers and algorithms, CMS is protected by an L7 azure application gateway that uses the following settings via predefined GW policies which move with vendor changes and support, legacy protocols are not supported. Cipher Suites Enabled.
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Outside of planned maintenance, the CMS will be accessible 99.9% of the time during core business hours RTO = 1 working day, RPO = 1 hour
- Approach to resilience
-
CMS can be configured using high availability via Zonal protection, alongside this CMS also can have regional DR protection also in the event of a primary region being unavailable a failover will occur to a secondary region.
The above scenarios however are configurable based on customer requirements and noted that for resiliency and DR additional costs will be incurred for the additional infrastructure and management of HA and DR. - Outage reporting
- Currently this would be via an email alert/account manager contact in the event of an outage as well as providing outage details on proactive support tickets to key stakeholders.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Management interfaces are segmented via RBAC permissions within the system and different URL access for management blade operations.
Support is via an independent platform to the CMS application, this is secured via Login & 2fa to access the ticketing system – phone is an available option for communication also where users will be verified/validated before progressing to the ticket information. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Other
- Description of management access authentication
- IDP federation with Microsoft Entra & MFA 2 Factor is required for accessing any of the management pane operations by staff, alongside this conditional access is also applied to the staff accounts accessing management operations.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Certification covers software development and any deployment of the app for "the provision of employment training, support services... ..Criminal Justice and Social Care services (wellbeing, housing and workforce learning) and Employability, Skills and Health services (unemployment support and skill development) across the UK."
- Information security policies and processes
-
We maintain access/accreditation through our group company and have an Information Security Management System (ISMS) that is build on the requirements of ISO27001:2022 with all expected policies in place to cover off the Clauses of the standard and topic specific policies or procedures covering off all of the selected Annex A controls that have been implements as a result of risk assessment, best practice or legal requirements.
The Seetec Group Executive Board have assigned overall responsibility for Information Security within Seetec Group to the Executive Director, Commercial Contracts and Assurance.
The Executive Director, Commercial Contracts and Assurance have assigned day-to-day responsibility for ensuring the ISMS conforms to the requirements of ISO 27001:2022 to the Head of Information & Cyber Security, whose role is to regularly report on the performance of the ISMS to the Board.
Colleagues are informed via communication of policy and through exposure to the Internal Audit process that any non-conformance with the policies, procedures and controls may lead to the invocation of the Disciplinary procedure, contractual, legal or regulatory penalties and could also be detrimental to future contract wins. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
All changes are recorded in our change management system, each change is tied to the infrastructure or service components giving an overview of lifetime changes to the system chronologically all records remain for the lifetime of the object/service.
When changes are carried out this is approved in CAB by both technical representatives as well as senior business leadership prior to the change being implemented, alongside this a retrospective review of each change is carried out by the change manager to ensure consistency to changes as well as continued improvements to the change process. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- CMS platform operates a vulnerability management documented process scanned daily for vulnerabilities as well as alignment with CE+ requirements to patch high and critical security vulnerabilities within 14 days to code or infrastructure components - no alignment with recognised standards.
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
- The CMS platform is monitored by Microsoft defender for cloud as well as fed into our SIEM platform for monitoring and alert response. A dedicated security team operates managing these platforms responding to incidents as they occur, playbooks are used for incident type and approach and associated escalations and business interaction is carried out internally aswell as liaising with the customer on incidents.
- Incident management type
- Supplier-defined controls
- Incident management approach
-
End users can raise incidents by email, self-service portal, and telephone. These tickets are then triaged by the Service Desk team members to assign a priority based on the impact and urgency. Tickets are then worked on in date/priority order.
Common incidents/requests will have templated responses/processes to resolve.
Incident reports are provided via email. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 237a560a-ccf6-4fe5-be0d-f817cc6a9c00
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- Dd0ec8ab-a454-46a1-b3b3-dbe949709e16
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-