Skip to main content

Help us improve the Digital Marketplace - send your feedback

KOCHO GROUP LIMITED

ALIRA - Unified Entra Identity and Access Management Portal

Kocho’s Alira Access Portal is a cloud-native, end-user-centric SaaS solution built to augment Microsoft Entra ID. It centralises and standardises all application access into one interface and experience, enabling self-service requests, automated approvals, real-time access reporting, and licence management to improve security, compliance, and operational efficiency.

Features

  • Unified portal integrates with Microsoft Entra for access management.
  • Self-service access requests reduce reliance on IT helpdesk tickets.
  • Automated approvals and JML workflows manage user lifecycle efficiently.
  • Licence tools assign, monitor, and reclaim software licences easily.
  • Real-time reporting and audits support governance and compliance needs.
  • Centralised view of user access entitlements in one interface.
  • Supports Entra Access Packages and PIM for privileged access.
  • Manages Azure, AWS, GCP admin roles in one platform.
  • Fully customisable interface with corporate branding and colour options.
  • Enforces Entra SSO and conditional access for secure authentication.

Benefits

  • Reduces helpdesk workload by automating access and provisioning tasks.
  • Speeds up onboarding with instant access to required resources.
  • Improves productivity by reducing delays in application access.
  • Minimises shadow IT by centralising approved application access.
  • Strengthens compliance through consistent access policy enforcement.
  • Cuts licence waste by reclaiming unused or misallocated licences.
  • Frees IT staff for strategic, high-value business initiatives.
  • Enhances user satisfaction with fast, self-service access tools.
  • Increases Entra ROI by improving adoption and reducing overhead.
  • Delivers audit trails for transparency and regulatory compliance reporting.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at G-Cloud@kocho.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 2 3 3 1 4 3 3 6 5 0 8 6 9 2

Contact

KOCHO GROUP LIMITED Steve Marshall
Telephone: 07967388226
Email: G-Cloud@kocho.co.uk

About your service

Service categories

Applications

Content workflow and management

Enterprise portals and digital workspaces

  • Multi-Audience Portals
  • Integrated Employee Workspaces
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes
What software services is the service an extension to
Entra IdAM
Cloud deployment model
  • Public cloud
  • Private cloud
Service constraints
Works with Entra ID / M365 Only
System requirements
Definied organisational units in Entra

User support

Email or online ticketing support
Yes
Support response times
24/7
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
N/A
Web chat accessibility testing
N/A
Onsite support
Yes, at extra cost
Support levels
P1 - Response up to 4 hours, Resolution within 4 hours P2- Response up to 6 hours, Resolution within 1-day P3 - Response up to 24 hours, Resolution within 3-days P4 - Resolution within 5-days Technical Account Manager will be appointed
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Kocho would implement the solution and provide training, support for IT, and provide user documentation.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
Kocho will work with organisation to either export data or agree on deletion.
End-of-contract process
Login privileges will be removed and Kocho will provide guidance on how to clean up their Entra tenant.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Online and via email

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
None
Service interface
No
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
The API enables the same functionality to be actioned within Entra ID
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Customise the branding and UI Choose what users can see/access Toogle settings for app behaviour

Scaling

Independence of resources
Autoscaling and brut force protection via Microsoft Azure service

Analytics

Service usage metrics
Yes
Metrics types
Uptime availability
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Other
Other data at rest protection approach
Encryption
Data sanitisation process
No
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data export approach
N/A
Data export formats
  • CSV
  • ODF
Data import formats
  • CSV
  • ODF

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Country Geofencing
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
Data encryption at rest and in-transit. Azure Secret Manager

Availability and resilience

Guaranteed availability
99.9%
Approach to resilience
Containerisation with autoscaling and microservices architecture.
Outage reporting
Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
Role Based Access
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • ISO/IEC 27001
  • Other
Other security governance standards
Cyber Essentials Plus
Information security policies and processes
ISO27001 and Cyber Essentials Plus
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Assessed and managed via Azure DevOps
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Managed via Microsoft Defender and Sentinel. In-house SOC team to identity and resolve vulnerabilities
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
In-house SOC team, using Defender and Sentinel
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Ervice Desk with pre-agreed SLAs and reporting processes. Can be bespoke and 24/7/365.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Provided for a defined subset of users. Please contact us for additional information.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
2.5%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
7.5%
Over £5,000,001
10%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
Thursday 25 May 2023
What the ISO/IEC 27001 doesn’t cover
Our certification covers all areas as detailed in the associated Statement of Applicability.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
British Assessment Bureau
ISO 9001 accreditation date
Tuesday 30 September 2025
What the ISO 9001 doesn’t cover
The scope does not include the professional services teams as it concerns a QMS for the SOC team, the managed service desk and the service delivery managers.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
C3418dff-f6ac-411c-84ab-a2a4d176f33a
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
E4bcca11-f5b6-41e3-82ca-05b84e497db4
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at G-Cloud@kocho.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.