Applications - Supply chain management
EPI-USE is a Certified SAP Gold Partner delivering SAP Public Cloud Business Suite for supply chain transformation. We provide SAP licences, implementation, and integration across logistics and transportation management, supply chain planning, and warehousing and inventory management, supported by automation, data migration, and managed services for UK public sector organisations.
Features
- Real-time analytics for SAP ERP, SuccessFactors, or combined landscapes
- Secure cloud access with role-based SAP authorisation controls
- Executive-ready dashboards for HR, finance, payroll, and operations
- Live data connectivity removing manual extracts and spreadsheets
- Cross-system reporting without complex data warehousing
- Drill-down analytics from strategic KPIs to transactions
- Embedded planning, forecasting, and scenario modelling
- Scalable architecture supporting future SAP solutions
- Rapid deployment using proven analytics accelerators
- Ongoing optimisation and insight support from EPI-USE experts
Benefits
- Access real-time insights without waiting for manual reports
- Quickly identify issues through automated alerts and live dashboards
- Drill into data instantly without technical or IT support
- Replace spreadsheets with trusted, single-source analytics
- Make faster decisions using up-to-date operational and workforce data
- Collaborate using shared dashboards across finance, HR, and leadership
- Manage performance proactively using trends and predictive insights
- Reduce reporting effort through automated, repeatable analytics processes
- Adapt dashboards quickly as business priorities change
- Plan confidently using integrated forecasting and scenario modelling
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 2 4 8 6 0 7 2 1 9 7 9 4 8 1
Contact
EPI-USE LIMITED
Kirsty Chatfield
Telephone: 07507 337795
Email: bdteam@epiuse.com
About your service
- Service categories
-
Applications
Supply chain management
- Logistics and transportation management
- Supply chain planning
- Warehousing and inventory management
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- The software and services are an extension to SAP and SuccessFactors solutions, designed to be used in conjunction with this software.
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- No specific ones to mention
- System requirements
-
- Public Cloud: Browser-based, no hardware required
- Pubilc Cloud: VPN sometimes required for technical user access
- Private Cloud: Hosting of SAP ERP required
- Network bandwidth recommended connection speed: 300-400 kbit/s
- Screen resolution XGA 1024x768 (high colour) or higher
User support
- Email or online ticketing support
- Yes
- Support response times
- EPI-USE's support service is provided Monday-Friday, 8am-6pm excluding bank holidays. Our response times are managed via Service Level Agreement based on ticket priority, to provide reassurance on response and resolution times. Please see Service Definition document for details. SAP product support is also available for any licenced products' bugs and this support is 24/7.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
The EPI-USE AMS Support Service provides a 2nd and 3rd line support model delivered by UK-based, certified consultants. Designed to work in partnership with our clients and SAP to ensure system stability while enabling continuous improvement. The service is SLA-backed, giving clients confidence in response times & resolution quality.
We provide full incident support, covering diagnosis, resolution, and root-cause analysis to minimise disruption and maintain business continuity. Our AMS service also includes the ability to deliver system changes, allowing organisations to evolve their landscape.
An Account Manager is provided to ensure proactive service delivery, conducting regular service reviews, analysis, and planning.
EPI-USE offers expert support for routine upgrades and enhancements provided by SAP, guiding clients through planning, testing, and deployment. For organisations running Payroll, we support with SAP supplied notes that provide legislative payroll alignment.
The EPI USE AMS service is designed to supplement the SAP provided support for bug fixes and upgrades included in licence costs, to give clients a comprehensive support service overall.
Our cost model is based on a single hourly rate for all services provided by AMS.
Overall, our AMS Support Service combines technical excellence, proactive management, and local expertise to deliver dependable, future-ready system support. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- EPI-USE provides implementation services to design and deploy your chosen technology to meet your needs. As part of the implementation, we provide knowledge transfer for future administrators, on how to manage and maintain the system/technology platform after go live. This is in addition to the online documentation provided by SAP for all of their platforms. For end-user training, as standard, we provide train-the-trainer sessions but, if requested, we can also provide end user training services and documentation. All our training is typically delivered online and not onsite although an onsite request can be considered. Implementation itself can be done via a number of methods – EPI-USE provides pre-configured and build-your-own options, with associated timelines and costs. We would work with you to determine the solution and implementation approach that best suits your business needs.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- SAP provides the tools to extract data from the solutions at any point. Clients can extract their own data when a contract ends and are not reliant on EPI-USE or SAP.
- End-of-contract process
- Prior to contract end, we would expect clients to extract their data to move to a new solution prior to the subscription end date. After the contract end date, SAP will remove system access and after a short period, will permanently erase the SAP SaaS solution purging all data, config and instances. EPI-USE can provide Archiving tools if required.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Where requested, EPI-USE documents have meaningful titles and a clear heading structure to support screen readers and easy navigation. Sentences and paragraphs are kept short. A minimum 12-point font size is used with 1.5 paragraph spacing and ample white space. All images have alt text with a clear description of the content of the image.
SAP documentation is provided online and typically follows similar standards.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service works on a browser on a phone or tablet the same as a desktop. For certain functionality, there are mobile applications available for iOS and Android.
- Service interface
- Yes
- User support accessibility
- EN 301 549
- Description of service interface
- SAP Business Suite including SuccessFactors provides configuration and administrator sections to their system, segmented from the end-user activity using Role Based Permissions. All interfaces are secure and encrypted.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
SAP is committed to delivering software solutions that are accessible to individuals with disabilities. This includes addressing Section 508 standards and W3C WAI WCAG 2.0, 2.1, and 2.2 (Level A and AA) guidelines, both of which are incorporated into the SAP accessibility standard, which is used for developing SAP products. While the solutions proposed implement a number of accessibility features, they are currently not fully optimised for accessibility.
Supported accessibility features are provided by SAP solutions in combination with third-party assistive technologies, such as the screen reader JAWS. JAWS and most other assistive technologies may require SAP and or customer furnished client-side software. Detailed VPATs addressing Section 508 of the Workforce Rehabilitation Act requirements and WCAG 2.0, 2.1, and 2.2 (Level A and AA) documents for many SAP applications are available
for review upon request. - API
- Yes
- What users can and can't do using the API
- The SuccessFactors API allows programmatic interaction with the platform but does not enable full system setup. Initial configuration of modules, data models, and security roles must be completed through the SuccessFactors admin interface. API setup primarily involves creating technical users, assigning API-enabled permissions, configuring authentication via OAuth, and selecting the appropriate API type, such as OData v2 or SFAPI. Once configured, the API can be used to create, read, update, and delete business data including employee records, job information, compensation, and learning data, while respecting existing workflows and validation rules. API Users can also perform batch operations and delta data integrations for efficiency. Limitations include the inability to modify core system configurations, such as data model structures, workflows, or role-based permissions. Certain objects may be read-only or partially writable, and API behavior can vary depending on the module and tenant configuration. Additional constraints include rate limits, payload size restrictions, and dependency on permissions assigned to the technical user, which may require middleware or the Integration Center for complex customisations.
- API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- SAP SaaS solutions can be 'configured' only and any customisation (e.g. coding) is carried out as extensions in the SAP BTP platform. This retains a 'clean core' for the suite applications with an adopt not adapt mindset, but gives flexibility to code if needed. For Private Cloud ERP, the solution is customisable. Configuration and customisation can be carried out by appropriately trained users.
Scaling
- Independence of resources
- SAP prevents one customer’s demand from impacting others through tenant isolation, enforced resource limits, and proactive capacity management. Each customer runs in an isolated system with controlled CPU, memory, background processing, and interface usage, preventing “noisy neighbour” effects. SAP continuously monitors usage, maintains spare capacity, and throttles abnormal workloads when needed. These technical controls are backed by contractual service-level agreements (SLAs), with service credits applied if availability targets are not met.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Service Metrics are provided in application and also via the support dashboards. Dashboards and reports are available within the customer community tools that detail service up time and planned outages. The SAP Trust Centre contains detailed information online about the current service status of all SAP cloud applications.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Reselling SAP licences. All services delivered directly by EPI-USE.
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Other
- Other data at rest protection approach
- We use AES 256 bit encryption for data at rest. We also offer optional additional chargeable services for BYOK, and HYOK encryption.
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- SAP provides tools, APIs and reports to allow customers to extract data both regularly if needed, and at contract end date.
- Data export formats
-
- CSV
- Other
- Other data export formats
- API (JSON, XML)
- Data import formats
-
- CSV
- Other
- Other data import formats
- API (JSON, XML)
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- SAP protects data within its network through layered security controls including network segmentation, encryption, strict access management, continuous monitoring, and independently audited security standards.
Availability and resilience
- Guaranteed availability
- SAP guarantee a 99.7% system availability percentage during each month for production versions, with the exception of regularly scheduled and emergency maintenance. Customers can request a refund on a pro-rated basis for any additional downtime, which is calculated monthly.
- Approach to resilience
- SAP servers are provisioned in a primary data centre, with data regularly copied to the failover data centre for resilience. SAP has a comprehensive BCP and DR approach, and there are slight variations by product, but typically the Enhanced Disaster Recovery provides customers with a time specific RTO of 24 hours, and RPO of no more than 4 hours.
- Outage reporting
- All outages are published on the web based SAP Trust Center which is available to all customers to review which gives outages, resolutions etc. This is also communicated by email to the nominated users at customers.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- For clarity; Public Key Authentication can be used for System/API integrations but not for user authentication into SuccessFactors, PSN can be used but this is Network restriction not user authentication into SuccessFactors, VPN can be used but this is Network restriction not user authentication into SuccessFactors
- Access restrictions in management interfaces and support channels
- Access to SuccessFactors is restricted via role-based permissions, segregation of duties, and identity management. Administrators assign roles in the RBP (Role-Based Permissions) framework, controlling who can view or modify employee data. Support access is limited through SAP’s secure support portal, with authenticated accounts and session tracking. For additional security, MFA, SSO, and IP/network restrictions can be enforced. Logging and audit trails ensure all administrative actions are monitored, helping prevent unauthorized access while maintaining compliance with data protection policies.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
- For clarity; Public Key Authentication can be used for System/API integrations but not for management authentication into SuccessFactors, PSN can be used but this is Network restriction not management authentication into SuccessFactors, VPN can be used but this is Network restriction not management authentication into SuccessFactors
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- SAP complies with ISO 27017 ISO 27018 BS10012
- Information security policies and processes
-
EPI-USE follows a set of globally agreed security policies and procedures and are Cyber Essentials certified. Details can be provided. For SAP, the head of SAP Global Security (Chief Security Officer; CSO) reports via the Security
Steering Committee to the SAP Executive Board and is responsible for the overall security strategy of SAP across lines of businesses. This includes besides others: corporate security, physical security, IT/Cloud security, cybersecurity and product security. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- All SAP processes and policies are defined following industry best practice standards. Most of those policies are internal and which is carried out annually and available to our customers.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- All SAP processes and policies are defined following industry best practice standards. Most of those policies are internal and which is carried out annually and available to our customers.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- All SAP processes and policies are defined following industry best practice standards. Most of those policies are internal and which is carried out annually and available to our customers.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- All SAP processes and policies are defined following industry best practice standards. Most of those policies are internal and which is carried out annually and available to our customers.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Other
- Other public sector networks
- Not directly, but is commonly securely integrated to all.
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1.5%
- Between £250,000 and £500,000
- 4%
- Between £500,001 and £1,000,000
- 7.5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 17.5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
-