Skip to main content

Help us improve the Digital Marketplace - send your feedback

e18 Innovation

Intelligent Automation / RPA Software (DWF Outsmart)

Digital Workforce Services’ Outsmart platform delivers intelligent automation software and services for healthcare organisations.

Outsmart enables NHS teams to design, orchestrate and scale RPA and AI across clinical and corporate workflows, improving productivity, patient pathways and operational efficiency, supported by extensive NHS delivery experience and proven live deployments.

Features

  • Vendor-agnostic automation orchestration across multiple RPA, BPA and AI technologies
  • Centralised governance and control of enterprise automation workloads
  • Real-time dashboards providing performance, throughput and exception reporting
  • Secure cloud-hosted platform with remote access and role-based permissions
  • Rapid deployment and scaling without customer-managed infrastructure
  • End-to-end automation lifecycle management from design to production
  • Supports complex NHS clinical and corporate workflows at scale
  • Built-in resilience, backup and disaster recovery for mission-critical operations
  • Configurable architecture supporting evolving automation strategies and technologies
  • Proven platform with extensive NHS production deployments and experienced teams

Benefits

  • Enable staff to automate repetitive tasks quickly and consistently
  • Free clinician time for patient care by reducing manual workload
  • Improve process visibility through real-time performance and exception insights
  • Standardise workflows to improve quality, safety and regulatory compliance
  • Accelerate service delivery without managing infrastructure or automation platforms
  • Support continuous improvement by identifying bottlenecks and optimisation opportunities
  • Enable secure remote management of automations across organisations and systems
  • Improve patient experience through faster, more reliable administrative processes
  • Simplify change management by configuring automations without complex redevelopment
  • Deliver benefits faster using proven NHS automation patterns and expertise

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at finance@e18-consulting.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

6 7 1 3 7 7 7 5 6 5 7 4 0 4 5

Contact

e18 Innovation Louise Wall
Telephone: 07979597396
Email: finance@e18-consulting.com

About your service

Service categories

Application Development and Deployment

Application platforms

  • Model driven application platforms
  • Robotic process automation
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Outsmart integrates with and extends automation platforms including Blue Prism, UiPath, Microsoft Power Automate, Robocorp and Flowable. It provides additional orchestration, governance, reporting and lifecycle management capabilities, while also operating as a standalone automation management platform independent of any single vendor technology.
Cloud deployment model
Public cloud
Service constraints
Outsmart is a managed cloud platform on Azure and requires agreed connectivity as part of onboarding (ICT Checklist and VPN form).
Customers also complete certain prerequisites in their own environment, such as installing required target applications/components and creating necessary accounts and access rights (with Digital Workforce support when possible).
Planned maintenance is managed via agreed service breaks; standard service breaks follow a monthly cycle, and non-standard breaks are communicated at least two weeks in advance. Incident SLAs apply to Digital Workforce time; customer/third-party time is excluded.
System requirements
  • Complete ICT Checklist and VPN form for connectivity
  • Provide secure network connectivity between customer and Outsmart
  • Install required target applications (e.g., ERP/CRM/Office)
  • Create AD and application-specific access rights for required users
  • Provide Digital Worker accounts, depending on the setup
  • Optional: enable domain joining, if required
  • Install components required for the business process
  • Provide test access to validate solutions in development.
  • Ensure target system availability during automation execution
  • Provide required solution documentation for handover/maintenance

User support

Email or online ticketing support
Yes
Support response times
Support requests submitted via email or the online ticketing system are acknowledged promptly during UK business hours. Initial response times are aligned to the priority level assigned to the ticket, with higher-priority issues responded to more quickly. Standard support is provided Monday to Friday, excluding UK public holidays. Tickets logged outside business hours or at weekends are queued and responded to on the next business day. Where enhanced support arrangements are agreed, extended hours or weekend response times can be provided. Users are kept informed of progress through regular status updates until resolution.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
No
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Digital Workforce provides multiple support levels for the Outsmart service.

Standard platform support is included at no additional cost. This covers management of the underlying cloud infrastructure and the Outsmart platform itself, including availability monitoring, platform maintenance, security updates and incident response related to the SaaS environment.

Optional enhanced support services (“Run Management”) are available at additional cost. Run Management provides operational support for specific automations, ensuring digital workers continue to operate effectively and deliver expected outcomes. Services may include proactive monitoring of automated processes, incident diagnosis and resolution against specified priority-based SLA’s, and ongoing optimisation to adapt automations to changing business requirements.

Run Management services are optional and can be applied on a per-automation basis for both RPA and BPA use cases. Pricing for each support level and service option is clearly defined in the accompanying pricing information.

Where enhanced support is procured, Digital Workforce can provide access to a cloud support engineer or technical account management function, proportionate to the scope and complexity of the services agreed.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Digital Workforce helps customers start using Outsmart through a guided onboarding and adoption journey that brings the service into operational use quickly and safely. We coordinate the onboarding plan, roles, and prerequisites, and provide clear guidance on what is needed from the customer side (for example, target application readiness and access setup) so that solutions can be validated end-to-end in the customer context.
Where customers are migrating an existing automation portfolio, we support an orderly transition by moving solutions into the development environment first and recommending testing prior to production release to confirm expected behaviour in the customer environment and configurations.
We also support adoption through documentation and knowledge transfer during handover to maintenance, using standard solution documentation templates (e.g., PDD and RPMD). After go-live, customers have ongoing access to support via the customer support portal (ITSM) and helpdesk email, with visibility of ticket progress and outcomes.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At the end of the contract, Digital Workforce will support the customer in extracting relevant solution and operational data from the Outsmart platform, in line with agreed exit arrangements. The scope and method of data extraction are determined during the offboarding process and may include documentation, configuration information, and other data necessary for transition. Following completion of the extraction and in accordance with contractual and regulatory requirements, Digital Workforce will securely delete customer data from the platform.
End-of-contract process
At the end of the contract, Digital Workforce will support the customer in transitioning from the Outsmart platform, including knowledge transfer and documentation as agreed. Offboarding activities are provided in line with the contract, and may include migration of solutions, extraction of relevant data, and transfer of operational knowledge. Additional cost services, such as extended support or bespoke data transformation, can be provided by separate agreement. Following completion of the offboarding process, Digital Workforce will securely delete customer data from the platform in accordance with contractual and regulatory requirements.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Users interact with Outsmart as a vendor-agnostic managed automation platform through the relevant automation tool interfaces used in their solutions within customer-specific development and production environments. Operationally, users engage Digital Workforce via the customer support portal (service portal) or by emailing the helpdesk to log incidents and service requests, and they can track status via the portal. Planned service breaks and other service communications are provided in advance through agreed channels, such as newsletter/email distribution.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Outsmart does not define a dedicated programme of interface testing specifically with assistive technologies (for example, formal screen-reader testing or WCAG certification) at the platform level. Instead, accessibility and usability assurance is managed at the solution level as part of the standard delivery lifecycle.
Each customer has a dedicated development environment where solutions are migrated and validated, and testing is recommended to confirm expected behaviour in the customer’s environment and technology configuration. In addition, solutions are progressed to production only through the Quality Acceptance and Handover process, which is designed to ensure solutions are thoroughly tested and perform as required before production use.
Where the customer has specific accessibility requirements (including assistive-technology users), these are captured during onboarding and incorporated into the solution validation activities in the development environment and the acceptance criteria for production handover.
API
No
Customisation available
Yes
Description of customisation
Customers can customise Outsmart by completing the customer-side activities prerequisites required to operate the managed platform within their own IT ecosystem. These customisations include domain joining (optional), creating Digital Worker accounts (depending on the setup), installing required components for the business process, installing target applications (for example Office, CRM, ERP, CBS), and creating the required access rights (for example AD accesses in the customer domain and application-specific accesses).
Customisation is completed as part of platform deployment and onboarding. Outsmart’s managed deployment also includes building the backend, configuring connectivity, setting up development and production virtual machines, installing and configuring the supported technology toolsets, orchestration tools, monitoring setup, and creating user accesses.
These customer-side activities are executed by the customer, with Digital Workforce supporting where possible. Any new solution introduced to the platform must pass a security review before it can be accepted into production, and some customisations may require additional effort to ensure compatibility with the platform and existing production solutions.

Scaling

Independence of resources
Outsmart is delivered as a multi-tenant cloud service with logical tenant separation to ensure customer workloads are isolated. The platform uses scalable cloud infrastructure, capacity management and workload controls to manage demand across tenants. Resource usage is monitored continuously, and service limits and safeguards are in place to prevent individual customers’ activity impacting others. Performance is supported through elastic scaling, proactive monitoring and operational controls, ensuring consistent service availability and reliability regardless of variations in demand from other users.

Analytics

Service usage metrics
Yes
Metrics types
Outsmart provides service metrics through regular service reporting. Reports are delivered monthly or quarterly (depending on event volume) and include analysis of opened incidents and service requests, plus an SLA report for the period; additional detailed data can be included to extend context.
For Enterprise plan customers, Outsmart can also track monthly business value KPIs for selected solutions, such as solution success rate, average end-to-end handling time, number of human interactions, length of manual tasks, and number of business exceptions (with thresholds agreed per solution).
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
Outsmart stores customer data in Microsoft Azure, where encryption at rest is provided by Azure services using symmetric encryption as data is written to storage, with key management controls supported through Azure Key Vault. Azure Storage services support server-side encryption at rest by default using service-managed keys and support customer-managed keys in Azure Key Vault where required. Outsmart’s security management follows ISO/IEC 27001:2022 requirements, confirmed by certification, and new solutions are subject to Security Review prior to production acceptance.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
At the end of the contract, Digital Workforce will support the customer in extracting relevant solution and operational data from the Outsmart platform, in line with agreed exit arrangements. The scope and method of data extraction are determined during the offboarding process and may include documentation, configuration information, and other data necessary for transition. Data extraction is managed securely and in accordance with contractual and regulatory requirements.
Data export formats
Other
Data import formats
Other

Data-in-transit protection

Data protection between buyer and supplier networks
IPsec or TLS VPN gateway
Data protection within supplier network
Other
Other protection within supplier network
Outsmart protects data within the service network through controlled connectivity and security governance. Connectivity between Outsmart and the customer environment is established during onboarding using Digital Workforce’s ICT Checklist and VPN form, ensuring the correct network solution and secure connectivity are implemented. Outsmart’s security management follows ISO/IEC 27001:2022 requirements, confirmed by certification, and new solutions must pass a Security Review before being accepted into production.

Availability and resilience

Guaranteed availability
Outsmart provides the following service levels (SLAs), with availability and support delivered through the agreed service management model:
• Platform availability SLA: Outsmart platform availability is 99.8%, measured as 24/7 availability excluding downtime that has been planned and agreed.
• Incident resolution SLA: Incident resolution times are defined by solution priority. P1 is <2 hours (every day) and P3 is <24 hours on weekdays (P3 applies to RPA Run Management).
• Service request response SLA: Digital Workforce responds to service requests within 48 hours on weekdays.
Planned downtime includes planned service maintenance (including service breaks) and solution/process downtime requested or approved by the customer. Customers are informed of non-standard planned breaks at least two weeks in advance. If guaranteed availability levels are not met, any financial remedies (such as service credits or refunds, if applicable) are handled strictly in line with the agreed contract terms.
Approach to resilience
Outsmart is delivered as a managed cloud platform built on Microsoft Azure, leveraging the resilience and high availability features of hyperscale cloud infrastructure. The platform is available 24/7, excluding planned and agreed downtime, and is supported by service management processes aligned with ISO/IEC 27001:2022 standards.
Resilience is achieved using customer-specific development and production environments, capacity management, and incident management SLAs. The underlying Azure datacentres provide geographic redundancy, robust physical security, and continuous monitoring. Platform deployment and service management processes include secure connectivity, regular maintenance, and proactive incident response to minimize service disruption.
Further technical details regarding datacentre architecture and specific resilience measures are available upon request.
Outage reporting
Outsmart reports outages through its managed service operations model rather than through a public status dashboard or an Outsmart platform API. The service is monitored, and incidents are handled through the agreed incident management process (ticketing). Customers can contact the helpdesk by email or via the customer support portal (service portal), and they can follow the status of service requests and incidents through the portal.
For planned outages (for example, scheduled service breaks and maintenance), Outsmart communicates in advance via agreed channels. Standard service breaks follow a monthly schedule, and customers are informed of non-standard planned service breaks at least two weeks in advance via the service newsletter/email distribution list. Outsmart does not provide a public outage dashboard or a platform outage-reporting API; outage communication and status follow-up are provided via service communications and the service portal/helpdesk interface.

Identity and authentication

User authentication needed
Yes
User authentication
Other
Other user authentication
Users access the Outsmart service through customer specific environments where authentication is handled by the identity and access controls of the platform technologies provided as part of the service. User accounts and required access permissions are created during platform deployment as part of onboarding. Access to the customer support portal is restricted to named, approved users. Depending on the customer’s configuration and environment, authentication may be integrated with the customer’s existing identity management systems. Further technical details on authentication options and configurations are available on request.
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is restricted through role-based access controls and user authentication. Permissions are assigned based on job role and least-privilege principles to ensure users can only access authorised functions and data. Administrative access is limited to designated users and protected using multi-factor authentication. Support channel access is controlled through authenticated accounts, with ticket visibility restricted to authorised users. Access rights are reviewed regularly and updated promptly when roles change, or access is no longer required.
Access restriction testing frequency
At least once a year
Management access authentication
Other
Description of management access authentication
Users access the Outsmart service through customer specific environments where authentication is handled by the identity and access controls of the platform technologies provided as part of the service. User accounts and required access permissions are created during platform deployment as part of onboarding. Access to the customer support portal is restricted to named, approved users. Depending on the customer’s configuration and environment, authentication may be integrated with the customer’s existing identity management systems. Further technical details on authentication options and configurations are available on request.

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Digital Workforce operates a formal information security management framework aligned to ISO/IEC 27001. This includes documented policies and processes covering information security governance, risk management, access control, incident management, secure development, supplier management, data protection and business continuity.
Information security is overseen by a named board-level executive with overall accountability for the security of all services. Day-to-day security management is supported by defined operational roles responsible for implementing controls, monitoring compliance and managing risks.
Policies are communicated to staff through onboarding, training and regular awareness activities. Compliance is enforced through role-based access controls, technical safeguards, monitoring, internal reviews and incident reporting processes. Security incidents are logged, investigated and managed in line with defined escalation and response procedures. Policies and controls are reviewed regularly to ensure they remain effective, reflect changes to the threat landscape and support continuous improvement in the security of the Outsmart service.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Outsmart follows defined configuration and change management processes to control service changes throughout their lifecycle. Service components, configurations and dependencies are tracked using configuration records and version control systems. Changes are proposed, reviewed, tested and approved before release, with segregation of duties applied where appropriate. Security impact is assessed as part of the change review process, including consideration of data protection, access controls and potential risks. Approved changes are deployed through controlled release processes, and post-change monitoring is used to confirm service stability and security.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Digital Workforce operates a defined vulnerability management process to identify, assess and remediate security risks affecting the Outsmart service. Potential threats are assessed using vulnerability scanning, penetration testing, security monitoring and risk assessment activities. Vulnerabilities are prioritised based on severity, exploitability and potential impact. High-risk issues are addressed promptly through tested patches or mitigations deployed via controlled change management processes, while lower-risk issues are resolved through planned updates. Threat intelligence is sourced from cloud provider advisories, software vendors, industry security bulletins and recognised vulnerability databases.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Outsmart uses defined protective monitoring processes to detect and respond to security events. Potential compromises are identified through centralised logging, security alerts, automated monitoring and anomaly detection across the service environment. Alerts are reviewed by authorised personnel to assess severity and impact. Suspected incidents are investigated, contained and escalated in line with incident response procedures. High-severity security incidents are responded to promptly, with actions taken to mitigate risk, restore service and prevent recurrence. Monitoring and response activities are reviewed regularly to support continuous improvement of the service’s security posture.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Digital Workforce operates defined incident management processes for Outsmart. Users report incidents via the Support Portal (ticketing system) or by emailing the helpdesk and can follow ticket status through the portal. Incidents are prioritised and managed to resolution under the agreed service levels, with progress updates provided through the ticketing process. For Priority 1 incidents, submission triggers immediate escalation to the on-duty Digital Workforce staff to ensure rapid response. Where appropriate, incident outcomes and corrective actions are communicated through agreed service communications.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Kiwa Sertifiointi Oy
ISO/IEC 27001 accreditation date
Monday 23 June 2025
What the ISO/IEC 27001 doesn’t cover
We hold the ISO/IEC 27001 certification for our Information Security Management System, with the scope defined and audited in accordance with the standard. The certification covers all information security controls assessed as applicable within that scope, as documented in the Statement of Applicability. An area of exclusion relates to our internal R&D AI project team - this is mostly excluded.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at finance@e18-consulting.com. Tell them what format you need. It will help if you say what assistive technology you use.