Skip to main content

Help us improve the Digital Marketplace - send your feedback

TRIBAL BUSINESS SOLUTIONS LIMITED

Tribal – Case Management System

Our feature rich, event driven Case Management system provides end-to-end participant management for employability and Health & Wellbeing programmes. It supports self-service participant access, configurable workflows, assessments, and dashboards, with automated milestone based reporting. This enables consistent service delivery, transparency, and measurable outcomes.

Features

  • Complete end-to-end configurable outcome focused case management system
  • Contract builder with deadlines/automations using a graphical workflow designer
  • Assessment and survey designer with version controlling
  • Unique search with recommendations speed-up planning and distance travelled
  • Full diary management with Outlook integration and automated reminders
  • Comms module with SMS, Email, Letters and Telephone
  • Create, share and arrange Dashboard widgets and Real-time reporting
  • PRaP pipeline and self-referral functionality with PRaP linking
  • Comprehensive auditing with GDPR functions
  • CRM and Vacancy Management

Benefits

  • Intuitive User Experience accelerates user adoption and training
  • Build flexible contracts with context aware deadlines and automation
  • Graphical participant journeys provide status, clarity and next step visibility
  • Build and share Dashboards to keep advisors informed of priorities
  • Clear diary management for Team Leaders, advisors and participants
  • Survey designer captures structured, actionable participant feedback
  • Automated communications keep your participants informed
  • Transparency with in-screen user auditing throughout
  • Secure data in an ISO27001 accredited environment, hosted within Azure

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bizdev@poweredbytribal.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 0 2 5 1 6 5 5 6 7 8 8 4 9 9

Contact

TRIBAL BUSINESS SOLUTIONS LIMITED Nathan Churchman
Telephone: 01245 975566
Email: bizdev@poweredbytribal.co.uk

About your service

Service categories

Applications

Content workflow and management

Content services

  • Enterprise Content Management Applications
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Services are deployed on Azure public cloud or windows-based systems only.
System requirements
  • Microsoft Windows Server OS based systems in vendor support
  • Microsoft SQL Database servers also in current vendor support
  • Antivirus technologies
  • Net Framework support
  • Firewalls & associated bypasses in filtering technologies to access system

User support

Email or online ticketing support
Yes
Support response times
Ticket based system this is aligned with our SLA’s the ticket system operates 8.30am to 5pm Monday-Thursday and 8.30am-4.30pm Friday.

No Ticket or support system is available at weekends.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
CMS Support offering:

- UK Service Desk (Phone, Email, Portal),

- Remote Support for end users,

- New User Onboarding and Leave Offboarding to the application,

- Online Ticketing Portal and Knowledge Base,

- Chargeable Onsite Support.
Support available to third parties
No

Onboarding and offboarding

Getting started
User Documentation is provided, additional online training is available at cost.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
Data can be extracted through csv export, or full DSAR pdf extraction.

Additional considerations such as database.

Additionally we can provide read-only licensing or bespoke data extraction at additional cost
End-of-contract process
If a customer chooses not to renew their contract, we will provide an open window up to 3 months from contract end for extraction of their data or to extend their contract on a read-only basis.

One data extraction has been completed, a formal notification of data deletion will be provided to the customer in line with data security and data protection requirements.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Chrome
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Slight interface differences - nothing major.
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
API is available for interaction however this would be additional cost/customisation. API is documented and can be shared as needed via Swagger.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Customisation is possible via a project-based methodology. Additional Feature requests, branding, customised API interaction.

Scaling

Independence of resources
Each customer has their own unique B2C tenant isolated platform for the application, data is segmented at the data plane into separate isolated database instances and database backends.

Analytics

Service usage metrics
Yes
Metrics types
Service Level Agreements (response/resolve). This includes number of tickets logged, their priority, etc. Top categories of tickets logged.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CHECK service provider
Protecting data at rest
Other
Other data at rest protection approach
All data stored in database is encrypted at rest via PMK within the Azure platform.
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can export data where permitted in the boundary of the contract via excel csv and pdf documents managed through the file system interface of the application.
Data export formats
  • CSV
  • Other
Other data export formats
PDF
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • PDF
  • .doc
  • Docx
  • Xlsx
  • Xls

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
The CMS platform operates using latest TLS1.3 & support for TLS 1.2 ciphers and algorithms, CMS is protected by an L7 azure application gateway that uses the following settings via predefined GW policies which move with vendor changes and support, legacy protocols are not supported. Cipher Suites Enabled.
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Outside of planned maintenance, the CMS will be accessible 99.9% of the time during core business hours RTO = 1 working day, RPO = 1 hour
Approach to resilience
CMS can be configured using high availability via Zonal protection, alongside this CMS also can have regional DR protection also in the event of a primary region being unavailable a failover will occur to a secondary region.

The above scenarios however are configurable based on customer requirements and noted that for resiliency and DR additional costs will be incurred for the additional infrastructure and management of HA and DR.
Outage reporting
Currently this would be via an email alert/account manager contact in the event of an outage as well as providing outage details on proactive support tickets to key stakeholders.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Management interfaces are segmented via RBAC permissions within the system and different URL access for management blade operations.

Support is via an independent platform to the CMS application, this is secured via Login & 2fa to access the ticketing system – phone is an available option for communication also where users will be verified/validated before progressing to the ticket information.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Other
Description of management access authentication
IDP federation with Microsoft Entra & MFA 2 Factor is required for accessing any of the management pane operations by staff, alongside this conditional access is also applied to the staff accounts accessing management operations.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Certification covers software development and any deployment of the app for "the provision of employment training, support services... ..Criminal Justice and Social Care services (wellbeing, housing and workforce learning) and Employability, Skills and Health services (unemployment support and skill development) across the UK."
Information security policies and processes
We maintain access/accreditation through our group company and have an Information Security Management System (ISMS) that is build on the requirements of ISO27001:2022 with all expected policies in place to cover off the Clauses of the standard and topic specific policies or procedures covering off all of the selected Annex A controls that have been implements as a result of risk assessment, best practice or legal requirements.

The Seetec Group Executive Board have assigned overall responsibility for Information Security within Seetec Group to the Executive Director, Commercial Contracts and Assurance.

The Executive Director, Commercial Contracts and Assurance have assigned day-to-day responsibility for ensuring the ISMS conforms to the requirements of ISO 27001:2022 to the Head of Information & Cyber Security, whose role is to regularly report on the performance of the ISMS to the Board.

Colleagues are informed via communication of policy and through exposure to the Internal Audit process that any non-conformance with the policies, procedures and controls may lead to the invocation of the Disciplinary procedure, contractual, legal or regulatory penalties and could also be detrimental to future contract wins.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All changes are recorded in our change management system, each change is tied to the infrastructure or service components giving an overview of lifetime changes to the system chronologically all records remain for the lifetime of the object/service.

When changes are carried out this is approved in CAB by both technical representatives as well as senior business leadership prior to the change being implemented, alongside this a retrospective review of each change is carried out by the change manager to ensure consistency to changes as well as continued improvements to the change process.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
CMS platform operates a vulnerability management documented process scanned daily for vulnerabilities as well as alignment with CE+ requirements to patch high and critical security vulnerabilities within 14 days to code or infrastructure components - no alignment with recognised standards.
Protective monitoring type
Undisclosed
Protective monitoring approach
The CMS platform is monitored by Microsoft defender for cloud as well as fed into our SIEM platform for monitoring and alert response. A dedicated security team operates managing these platforms responding to incidents as they occur, playbooks are used for incident type and approach and associated escalations and business interaction is carried out internally aswell as liaising with the customer on incidents.
Incident management type
Supplier-defined controls
Incident management approach
End users can raise incidents by email, self-service portal, and telephone. These tickets are then triaged by the Service Desk team members to assign a priority based on the impact and urgency. Tickets are then worked on in date/priority order.

Common incidents/requests will have templated responses/processes to resolve.

Incident reports are provided via email.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
237a560a-ccf6-4fe5-be0d-f817cc6a9c00
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
Dd0ec8ab-a454-46a1-b3b3-dbe949709e16
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at bizdev@poweredbytribal.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.