Access Mosaic Social Care Case Management and Finance System
Mosaic is designed for adults, children’s case management and associated finance services. It simplifies the recording and monitoring of pathways, saves time, reduces paperwork and minimises risk. Mosaic incorporates information on an individual, their immediate family and finances, providing you with a single view of a person and their environment.
Features
- Mosaic Children's Social Care Case Management
- Mosaic Adults Social Care Case Management
- Information at your fingertips for effective decisions and timely interventions
- Supports your digital by default strategy using web portals
- Statutory returns
- eLearning
- Integration with Synergy Education Management System
- Integration with Core+ Youth Services
Benefits
- Take the administrative burden away from complex management
- Ensure best practice and meet statutory requirements
- Have more time to focus on individuals and improving outcomes
- Get holistic view of every aspect of a client’s life
- Make better decisions with accurate information at point of care
- Respond to court requirements easily
- Collaborate more easily with families and other agencies
- Get the insight to prioritise workloads
- Team Workload view promotes transparent ways of working
- Improve data quality and accuracy
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 3 8 8 8 7 9 5 4 3 7 6 6 3 7
Contact
ACCESS UK LTD
Stacey Graham
Telephone: 01206322575
Email: buyer.enablement@theaccessgroup.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Adult Social Care
- Children's Social Care
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- All end user and citizen facing components of the solution are fully browser based and need nothing installed on the client device other than the browser itself.
- System requirements
-
- End-user facing elements of the solution are accessed via web-browser
- Supported by, Windows, macOS, iOS and Android
- No additional software or plug-ins are required on client devices
- There are no additional licensing implications
User support
- Email or online ticketing support
- Yes
- Support response times
- Access has developed a range of support plans. Our online Knowledge base and Community service plans are available to all our clients. We have made significant investment in our client support tools. The Success portal provides around the clock access to log incidents, browse articles and videos to find solutions. Our Support teams are available M-F 08:30-18:00, excluding English public holidays. On these plans P1 cases are responded to in 30 minutes. For P1 incidents for hosted customers, Service Hours are 07:00 to 22:00, seven days a week including English public holidays. Please refer to Access for further details.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- N/A
- Onsite support
- Yes, at extra cost
- Support levels
-
As a Standard Plan customer you benefit from faster response times and can access our support teams via telephone and live chat, as well as through our Customer Success portal. To help your team be more productive, you are provided with continued access to our e-learning content as well as a programme of Success webinars, designed to keep you up to date with new features and share best-practice advice and guidance. Our Premier Plan enables your team to achieve more and improve productivity through an ongoing relationship with your own designated Customer Success Manager. Your Customer Success Manager will get to understand how you’re using the technology and will advise you on how to get more from it. Our Premier+ Plan provides the highest level of dedicated support to maximise your technology investment. Building on the Premier Plan benefits, you receive more frequent consultations with your designated Customer Success Manager and also benefit from a Lead Technical Support Engineer who prioritises your complex and business-critical issues, ensuring rapid resolution when it matters most.
Costs for each plan are contained within the pricing document. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
Access works closely with customers throughout the implementation process. A project plan and PID documentation will be provided.
The following onsite/remote system training is provided:
• Mosaic Familiarisation
• Workshop Preparation
• Finance Familiarisation
• System Administration
• Workflow and Template Manager
• Train the Trainer
• Portals (where applicable)
• Mosaic Reporting
• Go-Live Guidance
Access also provide access to our online library of Mosaic user guides which contains our guides relating to system administration and configuration, workflow configuration, form design and building and system properties. The library also contains up to date information on any new functionality which has been created within a new version. As new versions of our software are released, our guidance is updated and new guidance produced to highlight and explain any new functionality.
Another option to consider in addition to the training offered by Access, is the use of eLearning, to support Mosaic training. This is used by a number of customers, either to support system implementations or business as usual training. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Access provides a data schema for each version of Mosaic and this is available to customers to allow the extraction of data into a required format. If the customer prefers; they can commission Access to extract the data into .csv files as a chargeable service.
- End-of-contract process
- Access's approach to decommissioning is to work with the Authority to meet its objectives and ensure any move to a new supplier is smooth and simple. Data is provided to the customer in the agreed format. Any technical involvement in script writing from Access is normally chargeable however advice and support can be provided until the contract end date. The data is deleted securely when the customer has agreed all data has been provided and drives holding the data are securely cleansed. Access can provide an Exit Management Plan to highlight the steps involved in decommissioning the Mosaic application.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Access Group's onboarding and offboarding documentation is accessible through the Customer Success Portal (https://access-support.force.com/Support/s/), which provides 24/7 online access to comprehensive resources including a knowledge base with FAQs, product guides, e-learning content, on-demand webinar recordings, feature release updates, and training materials that can answer most day-to-day user questions. All users can register for portal access regardless of their Success Plan level (Essential, Standard, or Premier), with additional support available through online case submission for all customers, telephone support for Standard and Premier customers, and dedicated resources like Customer Success Managers and Lead Technical Support Engineers for Premier customers, ensuring documentation and guidance is readily available throughout the entire customer lifecycle from initial onboarding through ongoing system use and any eventual offboarding scenarios.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- When used on Windows, iOS and Android smartphones and tablets, Mosaic forms are drawn in a way that is responsive to the device size. Native finger-friendly device functions such as date pickers are used by default.
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
-
Mosaic provides and out of the box set of generic APIs that can be used to provide third party systems bi-directional access to Mosaic.
Mosaic has a number of SOAP and REST APIs. They offer the ability to create and search for people, retrieve demographic, budget information, care timetables, organisations and workers, send and receive alerts as well as providing an integration point for workflow and e-forms. Users set up the service by making calls to the APIs that allow creations. They make changes by calling APIs that identify the record to be updated then submit their changes via the APIs that permit updates.
There are no particular limitations on how users can set up and use the APIs other than calls made must obviously pass appropriate authentication and the business rules that the APIs enforce. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
-
All the Mosaic workflows and forms are fully configurable to meet any specific local requirements to ensure that the system reflects local best practice. If any changes to Mosaic’s standard configuration are needed, our consultants will work closely with you during the implementation of the system to define and input these changes.
Mosaic has been designed to maximise the flexibility for our customers to manage, edit, add to or amend code tables with little to no intervention from Access. We provide all customers with the ability to locally configure reference data (code) tables where the worker has the appropriate system permissions without our involvement.
With every new installation of Mosaic, there is a full suite of forms in the Customer Led Configuration (CLC) designed to meet the requirements of business processes. These forms are all available and accessed via the Template Manager Tool and are all fully configurable by system administrators.
Mosaic’s Template Manager Tool allows sites to edit, amend and delete SC forms or to create their own forms for use within the system. The template manager tool contains a version control system so previous versions of forms are stored and amended if required.
Scaling
- Independence of resources
- All systems are scaled to operate at peak demand. Allocation of resource through a combination of monitoring, auto-scaling and resource isolation are designed to minimise any impact of other customers, or the so-called 'noisy-neighbour' effect. In the unlikely event of any system reaching pre-defined thresholds or KPI's systems where performance is impacted for a specific platform, resources are re-allocated to ensure that this is rectified.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Service metrics are provided in the form of call lists which users can filter on calls outstanding either by call reference, created date range, call status, name of reporter, assignee and summary. Customers can log in to the online support portal to view this information as and when required at no additional cost.
Service measurements are used internally to monitor performance accordingly.
Reporting of SLA performance and KPIs can also be provided. - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
-
Access provides access to the Mosaic database allowing data to be extracted and interrogated via industry standard third party reporting and business intelligence tools. Supporting documents (Entity Relationship Diagrams and Data Dictionary are provided to support).
All reports run via the Mosaic Report Repository can be exported to Microsoft Excel and saved in the desired format. Where a specific format is required for a return submission, Access provides this in addition to tables to allow data validation prior to submission. - Data export formats
- CSV
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- XML
- JPEG
- XLS
- DOC
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- The threshold for application availability in any month is 99.8%, measured on a 24 hours per day, 365 days per year basis, excluding planned or previously agreed downtime for Maintenance.
- Approach to resilience
- The solution has been designed to cater for a range of disasters. All customer databases are mirrored on secondary servers. This means if the production database fails, users can be switched onto the mirror system whilst any repair or recovery work is carried out. More detailed information available on request.
- Outage reporting
- Access utilises industry standard monitoring solutions which immediately alert our teams to a service outage. Contact with customers is made via telephone or email to agree contacts. Users can also subscribe to email alerts giving updates on scheduled maintenance and outages.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- We operate role profile based Access Control - based on least privilege access. This applies to all our services.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- All controls included within Annex A of the ISO27001:2013 standard. Statement Of Applicability (SOA) available on request.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- All change management is undertaken in line with ISO27001:2013 using JIRA for audit purposes.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Access uses multiple defense layers including Layer7 Firewalls, IDS/IPS, behavioral analytics, and phishing protection. Palo Alto Firewalls inspect traffic using App-ID technology with WildFire threat detection. Weekly automated vulnerability scans via Tenable IO and Nessus supplement 24/7/365 monitoring through a Hybrid CSOC with managed detection providers.
Critical security patches deploy within 72 hours based on CVE scores and mitigations. Non-critical OS patches apply within one month, first to non-production then production environments. Anti-virus signatures update hourly.
Threat intelligence sources include vendor repositories, internet-based feeds, WildFire cloud sandboxing, Cortex XDR behavioral monitoring, Palo Alto threat feeds, and managed security service providers. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We have traffic monitoring and content based alerting on changes to the site and/or traffic flows implemented at infrastructure level. We keep daily historical reports from servers which provide the facility to identify when changes occurred. We proactively monitor third party suppliers vulnerability reporting and security fix availability. We patch any vulnerabilities found in a timescale appropriate for their level of severity. Our infrastructure response is within 1 hour in the SLA period 8am-8pm Monday – Friday.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- We operate a robust incident management process in line with ISO27001:2013 Staff are encouraged to report all incidents using a pre-defined process using a form available on our Company Collaborate site Incident reports will be provided following forensics and closure.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 6%
- Between £500,001 and £1,000,000
- 12%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 18%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus ISOQAR
- ISO/IEC 27001 accreditation date
- Saturday 4 January 2014
- What the ISO/IEC 27001 doesn’t cover
- Nothing is excluded from the standard certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- BSI
- ISO 9001 accreditation date
- Friday 1 September 2023
- What the ISO 9001 doesn’t cover
- The scope covers the design, integration, maintenance and hosting of managed information systems and software applications, consultancy, user training and support for the Health, Education, Social Care and Local authorities. Excluding all other products that fall outside of this scope.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 88f162a5-ea3c-4f9a-83d5-42769c7d8459
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- You do not have a current and valid Cyber Essentials Plus certificate, or will not have in place within 12 months of the date of award but have an IASME certified equivalent.
- Other security certifications
- Yes
- Any other security certifications
-
- ISO 42001
- ISO 27701
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-