Skip to main content

Help us improve the Digital Marketplace - send your feedback

Invoka Consulting

Asana Licensing

Invoka Consulting provides access to Asana licences for public sector organisations. We support buyers in procuring the appropriate Asana subscription tier and user volumes, enabling teams to plan, track, and manage work effectively using Asana’s cloud-based work management platform.

Features

  • Project Management
  • Portfolio Management
  • Programme Management
  • Collaborative Work Management
  • Reporting
  • Task Management

Benefits

  • Simplified procurement of Asana licences through an approved supplier
  • Access to a leading cloud-based work management platform
  • Improved collaboration and visibility across teams and projects
  • Flexible licensing options to support organisational growth
  • Reduced administrative burden through centralised licence management
  • Assurance that buyers select the right Asana tier and package

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ben.flatman@invokaconsulting.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

5 5 4 0 3 8 8 8 6 2 3 4 9 6 3

Contact

Invoka Consulting Ben Flatman
Telephone: +44 (0) 207 264 2151
Email: ben.flatman@invokaconsulting.com

About your service

Service categories

Applications

Collaborative

  • Team collaboration
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Asana is a cloud only SaaS solution
System requirements
Web browser

User support

Email or online ticketing support
Yes, at extra cost
Support response times
Invoka aims to respond to questions within 2 hours. Tailored SLAs are available based on the organisation's requirements
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes, at an extra cost
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
We test our web chat functionality as part of our wider accessibility and usability assurance activities. This includes testing with assistive technologies such as screen readers (including NVDA and VoiceOver), keyboard-only navigation, and browser zoom and reflow at increased magnification.
Onsite support
Yes
Support levels
Invoka offers a standard level account management support for all customers, which includes email and phone support during UK working hours, with a 24hr response time. Additional levels of support, online ticketing, and reduced email and phone response times are all available at request and tailored to customer-specific requirements.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Asana provides a range of resources to help users get started quickly and effectively.

This includes:
• Online user documentation and help centre guidance
• In-platform templates and onboarding prompts
• Training materials, webinars, and learning resources
• Customer support services provided as part of the subscription

Invoka Consulting supports buyers with licence provisioning and access queries to ensure smooth onboarding onto the platform.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
When a contract ends, users can extract their data directly from Asana using built-in export and access tools.

This includes:
• Exporting project and task data into common formats such as CSV
• Downloading attachments stored within projects
• Using the Asana API to extract structured data programmatically
• Accessing account information prior to subscription expiry to support migration or archiving

These options enable buyers to retain and reuse their information outside the platform in line with exit requirements.
End-of-contract process
At the end of the contract term, the Asana subscription will expire unless renewed or extended by the buyer.

During the contract period, buyers have access to the Asana platform and the licensed features included within their selected subscription tier. This includes:
• Use of the cloud-hosted Asana service
• Access to product updates and platform availability
• Standard support services provided by Asana as part of the subscription

Before the contract ends, users can export or extract their data using Asana’s built-in tools and APIs.

Additional costs may apply if buyers choose to:
• Renew or upgrade their subscription tier
• Increase user numbers or add premium functionality
• Procure additional professional services such as implementation, training, or managed support (offered separately if required)

The core contract price covers licensing only, with optional add-ons available through separate agreement.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
  • MacOS
  • Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Asana provides a consistent experience across web, desktop, and mobile applications, allowing users to view tasks, collaborate, and track work from any device.

The desktop and web applications offer the full feature set, including advanced project configuration, reporting, admin controls, and integrations.

The mobile applications are optimised for on-the-go use, focusing on key activities such as viewing updates, completing tasks, commenting, and receiving notifications, with some advanced administration and configuration features limited compared to desktop.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Yes. Asana provides a web-based service interface accessed through a standard internet browser. The platform also offers dedicated desktop applications (Windows and macOS) and mobile apps (iOS and Android), allowing users to manage tasks, projects, and team collaboration through a consistent graphical user interface.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Asana is a cloud-based SaaS platform and Invoka does not modify the core user interface. Invoka has not conducted independent assistive technology usability testing of the Asana interface. Accessibility testing and improvements are managed by Asana as the software provider, and the platform supports common assistive technologies such as screen readers and keyboard navigation.
API
Yes
What users can and can't do using the API
Asana provides a public REST API that allows users to interact programmatically with the platform.

Users can use the API to create and manage projects, tasks, users, and workflows, and to retrieve structured work management data for integration and reporting purposes.

Service setup and ongoing changes, such as creating tasks, updating assignments, and managing project data, can be performed through authenticated API access.

Limitations include role-based permissions, rate limits, and some administrative or enterprise settings that must be configured through the web interface rather than via the API.
API documentation
Yes
API documentation formats
Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Asana is a configurable work management platform that buyers can tailor to their organisational workflows.

What can be customised
Buyers can customise:
• Projects, task structures, and templates
• Custom fields, statuses, and workflows
• Dashboards and reporting views
• Automations, rules, and notifications
• Integrations with third-party tools
• User roles, permissions, and access controls

How users can customise
Customisation is completed through Asana’s web-based no-code interface, with additional capabilities available via the API.

Who can customise
Customisation can be carried out by end users within their permissions, team administrators, and enterprise account administrators.

Scaling

Independence of resources
Asana is delivered as a multi-tenant cloud-based SaaS platform designed to operate at scale. The service is hosted on resilient infrastructure with capacity management, load balancing, and performance monitoring to ensure that demand from one customer does not adversely impact other customers.

The platform is engineered to maintain consistent availability and performance across users, supported by Asana’s operational resilience and scalability practices.

Analytics

Service usage metrics
Yes
Metrics types
Asana provides usage metrics through administrative dashboards and account management tools. Administrators can view information such as user activity, project usage, automation consumption, storage, and subscription limits. Metrics support governance and operational oversight and can be exported where required.
Reporting types
  • API access
  • Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Asana

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Users can export their data from Asana using the platform’s built-in export functionality and APIs.

This includes:
• Exporting project and task data into open formats such as CSV
• Downloading attachments stored within the platform
• Using the Asana API to extract data programmatically for integration or migration purposes

These options allow buyers to retrieve and retain their information in standard, reusable formats at any time.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Asana is delivered as a cloud-based SaaS platform with availability targets and service commitments provided by the software vendor.

Availability and uptime commitments are defined within Asana’s subscription terms and service level documentation. Where service levels are not met, remedies and service credits (where applicable) are handled in accordance with Asana’s published SLA and contractual provisions.

Invoka Consulting provides licensing supply and subscription management, while the underlying platform availability and associated service credits are governed directly by Asana as the service operator.
Approach to resilience
Asana is designed as a resilient, cloud-hosted SaaS platform operating on hyperscale infrastructure with high availability and fault tolerance.

The service is hosted across multiple datacentre locations with redundancy, load balancing, and continuous monitoring to reduce the risk of single points of failure. Data is protected through replication and backup processes to support service continuity.

Asana’s infrastructure provider ensures physical and environmental resilience of datacentres, including power, network, and security controls aligned with recognised standards.

Further technical resilience details can be provided on request.
Outage reporting
Asana reports service outages and operational status through a combination of public and direct communication channels.

This includes:
• A public service status dashboard providing real-time availability and incident updates
• Email notifications to customers where appropriate during significant disruptions
• Updates through Asana support channels and incident communications

Asana does not typically provide outage reporting via an API, but status information is publicly accessible through its dashboard.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Asana restricts access to management interfaces and support channels through role-based access control and authenticated administrative permissions.

Administrative functions such as user management, security settings, integrations, and billing controls are limited to authorised administrators within the customer account. Enterprise plans provide enhanced governance features, including single sign-on integration and granular permission controls.

Support access is controlled through authenticated customer support channels, ensuring that only approved users can raise requests or receive account-specific assistance.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Asana’s security governance also aligns with recognised assurance frameworks such as:
• SOC 2 Type II
• ISO/IEC 27018 (protection of personal data in cloud services)
• GDPR-aligned privacy and security controls
Information security policies and processes
Asana maintains documented information security policies and processes covering areas such as access control, data protection, vulnerability management, incident response, and secure software development.

Security governance is overseen by a dedicated security leadership function with defined reporting lines and accountability for compliance across the organisation. Policies are communicated internally and supported through mandatory training, role-based controls, and ongoing monitoring.

Asana ensures policies are followed through regular security reviews, independent assurance activities, automated enforcement controls, and continuous improvement processes aligned with recognised industry standards.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Asana operates formal configuration and change management processes to ensure the platform remains secure, reliable, and consistently managed throughout its lifecycle.

Service components, including infrastructure, application releases, and configuration items, are tracked through controlled environments using version control, deployment pipelines, and operational monitoring.

Changes are subject to documented review and approval processes, including assessment of potential security impacts. Security considerations such as access control, vulnerability testing, and compliance checks are incorporated into the change lifecycle before deployment to production.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Asana maintains an active vulnerability management process to identify, assess, and remediate security risks across the service.

Threats are assessed through continuous monitoring, automated vulnerability scanning, regular penetration testing, and review of platform components. Findings are prioritised based on severity and potential customer impact.

Security patches and updates are deployed within defined remediation timelines, with critical vulnerabilities addressed as a priority. Patching is supported through controlled release processes to ensure service stability.

Asana sources threat intelligence from security research communities, vulnerability disclosure programmes, cloud provider alerts, and recognised advisory sources such as CVE databases.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Asana operates protective monitoring processes to detect and respond to potential security incidents across the service.

Potential compromises are identified through continuous security monitoring, centralised logging, automated alerting, and detection controls across platform infrastructure and application activity.

When suspicious activity is detected, Asana follows defined incident response procedures, including investigation, containment, remediation, and customer communication where required.

Incidents are prioritised based on severity, with critical security events responded to promptly through established escalation and security operations processes.
Incident management type
Supplier-defined controls
Incident management approach
Asana operates defined incident management processes to ensure security and service events are handled effectively.

The service maintains pre-defined response procedures for common incidents such as service disruption, suspicious activity, and security vulnerabilities, supported by escalation and investigation workflows.

Users can report incidents through Asana’s customer support channels and helpdesk. Service status and major incidents are communicated through the public status dashboard and direct customer notifications where appropriate.

Post-incident reports and updates are provided to customers as required, in line with the severity of the event and contractual support terms.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Asana provides a free version and trial access for evaluation. The free version includes core task and project management features for individuals and small teams. Advanced functionality such as higher limits, enterprise security controls, automation, reporting, and governance features is only available on paid plans. Trials are time-limited.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
20%
Over £5,000,001
35%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
E82c0e92-11d8-4d03-8717-b389475c5a00
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Measures to involve local stakeholders and/or users in design (e.g. in the design of services, systems, products or buildings)
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at ben.flatman@invokaconsulting.com. Tell them what format you need. It will help if you say what assistive technology you use.