how i work: Personalised careers guidance, advice and support
how i work is a cloud-based, gamified learning platform that uses adaptive activities to help young people understand their strengths, needs and working preferences, generating personalised, research-backed support insights and dashboards to enable educators, parents and careers advisers to provide tailored, effective support.
Features
- Online, cloud-based delivery
- Adaptive learning activities personalised in real time to user responses
- Gamified multi-zone learning journey with progress tracking
- Secure user authentication and role-based access controls
- Personalised digital support cards generated from assessment data
- Real-time dashboards for authorised teachers, parents and advisers
- Accessibility-aware interface designed for diverse cognitive and sensory needs
- GDPR-compliant data storage with consent-based information sharing
Benefits
- Build learner self-understanding to improve daily learning and working strategies
- Enable personalised support decisions using clear, evidence-based learner insights
- Reduce time spent guessing adjustments through structured, actionable guidance
- upport consistent approaches across teachers, parents and careers advisers
- Improve engagement through motivating, gamified learning activities
- Quickly identify strengths and support needs to inform next-step planning
- Share permission-based insights securely across education and support teams
- mprove transition planning between education, training and employment settings
- Help learners develop strategies that work reliably across different environments
- Increase confidence in support decisions using research-backed recommendations
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 4 1 1 2 3 6 2 1 2 5 4 8 3 0
Contact
DAMGEO LTD
Damien Caldwell
Telephone: 07809401589
Email: damien.caldwell@damgeo.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Education
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- How i work is a browser-based SaaS service and requires a modern web browser and internet connection. Planned maintenance and updates are carried out periodically and may result in brief service unavailability, typically outside standard working hours. The service is accessed online and does not support offline use.
- System requirements
-
- Users require a modern, standards compliant web browser
- Users require an internet connection
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- Within 2 hours between 09:00 to 17:00 Monday to Friday and within 24 hours at all other times, including weekends and bank holidays.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- EN 301 549
- Web chat accessibility testing
-
To test the accessibility of our web chat functionality, we carried out structured testing with users who rely on assistive technologies. We recruited participants using a range of tools, including screen readers and keyboard-only navigation, to reflect real-world usage.
We developed task-based test scenarios covering key web chat functions such as starting a conversation, reading messages, sending responses and ending sessions. Testing took place in a supportive environment where participants used their own assistive technologies alongside the web chat interface.
Participants were guided through each task and encouraged to work at their own pace while we observed interactions, noted usability challenges and captured direct feedback. Following task completion, we gathered additional insights through short interviews and structured feedback sessions.
Test findings were analysed to identify accessibility and usability issues, including focus management, readability and interaction flow. Improvements were prioritised and implemented iteratively, with changes retested where appropriate. All findings, actions taken and recommendations were documented to inform ongoing accessibility improvements and future development. - Onsite support
- Yes, at extra cost
- Support levels
-
Basic Support Level:
Cost: Included in the base subscription fee.
Features: Standard email support during business hours, typically with responses within 24-48 hours. Access to a knowledge base and community forums for self-service assistance.
Technical Account Manager/Cloud Support Engineer: Not provided at this level.
Advanced Support Level:
Cost: Additional 20% of the subscription fee.
Features: Priority email and phone support during extended business hours, usually with responses within 12-24 hours. Access to a dedicated support portal with enhanced resources and documentation.
Technical Account Manager/Cloud Support Engineer: Assigned technical account manager for proactive assistance and guidance.
Enterprise Support Level:
Cost: Additional 40% of the subscription fee.
Features: 24/7 phone and email support with guaranteed response times, such as 1 hour for critical issues. Access to a dedicated support hotline. Quarterly business reviews, personalised support escalation paths, on-site training, and priority access to new features.
Technical Account Manager/Cloud Support Engineer: Dedicated cloud support engineer available for immediate assistance and proactive support. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
We support users to start using how i work through a structured and flexible onboarding approach designed to suit different roles and learning preferences.
Organisations receive guided onboarding, which may include facilitated online or onsite sessions delivered by experienced members of our team. These sessions introduce the service, explain core features and focus on practical use within the organisation’s context.
Users are supported by self-paced online guidance, including clear walkthroughs and in-platform prompts that help them understand how to navigate the service and complete activities confidently. Supporting adults, such as teachers, parents and advisers, are shown how to interpret dashboards and use insights appropriately.
Clear, concise user documentation is available within the platform, providing step-by-step guidance and reference materials that can be accessed at any time. This documentation is written in plain language and designed to be accessible and easy to follow.
This combination of guided onboarding, self-service learning and accessible documentation ensures users can quickly begin using the service effectively and build confidence over time. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, customers can export their data using built-in self-service tools within the how i work platform. Authorised users can access a data export function from the account or administrative settings area.
Users can select the relevant data sets and time periods and export data in commonly used formats such as CSV or Excel, supporting reuse in other systems or local storage. Exports are generated on demand and made available for secure download.
Where required, support is available to assist customers with the data extraction process and to answer any questions about exported content or formats. Data remains accessible for export during the contract term, enabling customers to plan and complete extraction in line with their offboarding requirements.
This approach ensures customers retain control of their data and can transition smoothly to alternative services or storage solutions at the end of the contract. - End-of-contract process
- There are no additional costs at the end of a contract, unless the client requests and agrees to additional services.
- Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- There are no differences
- Service interface
- No
- User support accessibility
- EN 301 549
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- How i work is delivered as a managed SaaS service designed to support multiple users without performance impact. The service uses scalable cloud infrastructure and load management to ensure demand from one customer does not affect others. Capacity is monitored continuously and adjusted as required to maintain consistent performance. Updates and changes are planned to minimise disruption, and resilience measures are in place to reduce the risk of service degradation during periods of increased usage.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides usage and engagement metrics through secure dashboards for authorised users. Metrics include user activity levels, progress through learning activities, completion status, frequency of use and engagement over time. Supporting adults can view aggregated insights to understand participation and identify where additional support may be helpful. Metrics are presented visually to support interpretation and decision-making and are accessible within the platform without the need for additional tools. Data is permission-based and aligned with the user’s role.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- In-house destruction process
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Authorised users can export their data at any time using self-service tools within the how i work platform. Data export is accessed through account or administrative settings, where users can select relevant data sets and apply filters such as date ranges. Data can be exported in commonly used formats, including CSV and Excel, and is generated automatically for secure download. The export process is designed to be simple and accessible for users with varying technical experience. Support is available to assist with data export if required.
- Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
How i work is provided as a managed SaaS service with a guaranteed availability of 99.9% per calendar month, excluding planned maintenance. Availability is measured at the service level and monitored continuously.
Planned maintenance is scheduled outside standard working hours wherever possible and communicated in advance. If availability falls below the guaranteed level in any calendar month, customers may be eligible for a service credit in accordance with the service level agreement. Service credits are applied to future invoices and represent the customer’s sole remedy for availability-related service failures. - Approach to resilience
-
How i work is designed as a resilient, cloud-hosted SaaS service. The underlying hosting environment is configured to reduce single points of failure and support continued service availability in the event of component or infrastructure issues.
The service is hosted in professionally managed data centres with resilient power, cooling and network connectivity, including backup power and redundant network paths. Data is protected through regular backups and replication, with recovery mechanisms in place to support service continuity.
The service is monitored continuously, with automated alerts and response processes to identify and address incidents promptly. Resilience controls are reviewed and tested periodically to ensure ongoing effectiveness and to support reliable operation under varying demand or failure scenarios. - Outage reporting
-
Any service outages or disruptions are communicated to users promptly and transparently. Service status information is made available through a publicly accessible status page, which provides updates on current incidents, service availability and historical status information.
Where appropriate, users are also notified of outages via email. Notifications include a summary of the issue, confirmation that it is being investigated or resolved, and follow-up communication once the issue is resolved. Users can subscribe to receive service status notifications to stay informed about relevant updates.
This approach ensures users have timely access to accurate information during service disruptions and supports clear, proactive communication.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- We restrict access to management interfaces and support channels through strict access controls, employing role-based permissions and multi-factor authentication. Only authorised personnel with a legitimate need should have access to sensitive functions and data. Access to management interfaces is limited to designated administrators, while support channels are accessed through authenticated accounts with restricted privileges. Regular audits and reviews ensure compliance with access policies and identify any unauthorised access attempts for immediate remediation.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- No
- Security governance approach
- Security governance is managed through documented policies, defined responsibilities and regular review of security controls. We follow recognised best practice, including the Software Security Code of Practice, and apply security-by-design principles across development and operations. Access to systems and data is role-based and reviewed periodically. The service is monitored for security events, with processes in place for incident response, patching and vulnerability management. Security risks are assessed as part of change management and ongoing service operation, with improvements implemented where required.
- Information security policies and processes
- We follow documented information security policies and processes covering areas such as data protection, access control, encryption, incident management and secure system use. Responsibilities for information security are clearly defined, with oversight provided by senior staff. Access to systems and data is controlled and monitored, and security events are logged and reviewed. Staff receive appropriate security awareness guidance as part of their role. Policies and procedures are reviewed periodically and updated where required to reflect changes in risk, technology or regulatory requirements.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Configuration and change management processes are used to track service components throughout their lifecycle. We document and maintain service components and configurations under version control to provide visibility of changes over time. Proposed changes are assessed for operational and security impact before implementation, including consideration of potential risks to data, access controls and service availability. Changes are tested and reviewed prior to release and are implemented in a controlled manner to minimise disruption. Security considerations form part of the change assessment and approval process.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We operate an ongoing vulnerability management process to identify and address potential security risks. Potential threats are assessed through a combination of regular security reviews, automated vulnerability scanning and monitoring of the service environment. Identified vulnerabilities are assessed and prioritised based on severity and potential impact. Patches and fixes are applied in a timely manner, with higher-risk issues addressed as a priority. Information about emerging threats is obtained from trusted sources, including security advisories, software vendor notifications and recognised industry guidance.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring is used to identify potential security incidents within the service. System activity and logs are monitored to detect unusual or suspicious behaviour that may indicate a compromise. When a potential issue is identified, an incident response process is followed to assess impact, contain the issue and apply appropriate remediation. Actions may include restricting access, investigating affected components and implementing corrective measures. Incidents are reviewed and addressed promptly, with response times prioritised based on severity to minimise risk and service impact.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We follow defined incident management processes, including pre-defined procedures for common incident types. Users can report incidents through a designated support contact or service desk. Reported incidents are logged, assessed and prioritised, then assigned for investigation and resolution. Following resolution, we promptly provide incident summaries, detailing the nature of the issue, actions taken and any follow-up measures. Common incidents follow standard response workflows, while more complex incidents are investigated in detail to support service improvement. Our transparent approach ensures timely communication and fosters trust in our ability to manage and mitigate incidents effectively.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 7%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 12%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-