Skip to main content

Help us improve the Digital Marketplace - send your feedback

M8 SOLUTIONS LIMITED

Microsoft Power Platform Consultancy and Services

Microsoft Power Platform is increasingly critical to improving efficiency, visibility, and consistency. Low-code solutions must be designed with governance and security to ensure they are scalable, supportable, and trusted. We provide structured delivery combining technical expertise, information governance, and practical enablement to help organisations automate safely and empower users.

Features

  • Governed Power Platform delivery aligned to NHS and Microsoft standards
  • End-to-end Power Automate workflow design, deployment, governance, and training
  • Secure system integration across Microsoft 365, Dataverse, Dynamics, NHS systems
  • AI-assisted automation enabling smarter, context-aware, auditable operational decisions
  • Power Apps development for web, mobile, and Microsoft Teams
  • Role-based access controls and DLP policies enforcing NHS data protection
  • Power BI dashboards providing real-time, trusted operational and clinical insight
  • Robust data modelling supporting scalable, accurate, enterprise-grade NHS reporting
  • Legacy system automation using RPA for structured and unstructured processes
  • Full lifecycle delivery from discovery through deployment, assurance, adoption

Benefits

  • Reduce manual effort by automating approvals, routing, and repetitive processes
  • Improve productivity through faster workflows without bespoke development or coding
  • Enable staff to access secure apps across web mobile Teams
  • Provide real-time visibility through dashboards supporting informed operational decisions making
  • Standardise processes with governed templates ensuring consistency safety and compliance
  • Quickly adapt workflows as services change without disrupting live operations
  • Reduce errors using validated data capture role-based access controls consistently
  • Accelerate decision-making by surfacing trusted data when and where needed
  • Safely scale automation across teams while maintaining governance and assurance
  • Support confident adoption through training documentation and ongoing expert support

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tracy@m8solutions.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 3 4 0 1 7 9 8 7 1 6 4 2 2 5

Contact

M8 SOLUTIONS LIMITED Tracy Scriven
Telephone: 07925051060
Email: tracy@m8solutions.co.uk

About your service

Service categories

Application Development and Deployment

AI platforms

AI life cycle

  • AI Build Software
  • Trustworthy AI Software

AI software services

  • Personalize AI Software Services
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Dependent on agreed service delivery
System requirements
Active Microsoft 365 tenant

User support

Email or online ticketing support
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
N/a
Support available to third parties
No

Onboarding and offboarding

Getting started
We support users in getting started through a combination of documentation, online training, and guided onboarding. Comprehensive user guides and step-by-step tutorials are provided, covering workflow creation, approvals, notifications, and reporting. These resources include screenshots, examples, and troubleshooting tips to enable users to self-learn efficiently. Online training sessions are offered, including recorded modules, demonstrating how to configure workflows, integrate with Microsoft 365 apps, and manage approvals. Authorised users can view these to build confidence in using the platform and applying customisation features. For larger deployments or specific organisational needs, we can provide guided onboarding sessions, either virtually or on-site, to help teams set up workflows, configure roles, and establish automation rules. These sessions include practical exercises to ensure users understand the system and can start automating processes quickly. Ongoing support is available through email and ticketing for any questions during the initial adoption period. This combination of self-service documentation, online training, and optional guided onboarding ensures users can rapidly adopt the service and maximise the benefits of workflow automation.
Service documentation
Yes
Documentation formats
  • PDF
  • Other
Other documentation formats
  • Word Guides
  • Video Guides
End-of-contract data extraction
At the end of the contract, users can either securely extract all their data in standard, machine-readable formats (CSV, Excel, or JSON) or they can continue using the automation unsupported by the supplier. This includes workflow configurations, task histories, approvals, notifications, and reporting data. Data extraction is managed via the web interface, with guidance provided in user documentation. For larger datasets or complex workflows, the supplier can assist with secure export or migration. Extracted data can be imported into other systems or retained for record-keeping and compliance purposes. All user data is removed from the platform after extraction, in line with GDPR and contractual obligations. This ensures organisations maintain control over their information and can transition smoothly to alternative solutions without data loss.
End-of-contract process
At the end of the contract, we work with the buyer to ensure an orderly transition to another supplier, in house or support is provided to extract all organisational data, including workflow configurations, task histories, approvals, notifications, and reporting data, in standard, machine-readable formats (CSV, Excel, JSON). Once data extraction is complete, all user and organisational data is securely deleted from the platform, in accordance with GDPR and contractual obligations. Access to the service is disabled, and any temporary accounts or third-party access are revoked to maintain security and confidentiality. The supplier provides guidance and documentation to assist with migration to alternative systems or archiving of data. Any outstanding support requests are resolved or handed over to the buyer prior to contract expiry. Optional offboarding assistance, including remote or on-site support, can be arranged for organisations with complex workflows or larger deployments. This structured end-of-contract process ensures data integrity, compliance, and security, allowing organisations to transition smoothly, retain full control over their information, and minimise operational disruption when the contract concludes.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is fully functional on both desktop and mobile browsers. Mobile access supports workflow creation, approvals, notifications, and task management, optimised for smaller screens. Some advanced configuration and reporting features are easier to use on desktop, but all core workflow and automation functionality is available on mobile devices.
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
Dependent on agreed service delivery
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • PDF
  • Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Dependent on agreed service delivery

Scaling

Independence of resources
Dependent on agreed service delivery

Analytics

Service usage metrics
Yes
Metrics types
Dependent on agreed service delivery
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
IThink365

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Other
Other data at rest protection approach
Data at rest is protected using Microsoft 365’s built-in encryption (AES-256) across all storage media. Tenant data is logically segregated, with strict access controls, secure key management, and redundancy across data centres. Physical access is restricted and monitored by Microsoft, ensuring resilience and compliance with public sector security standards.
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Dependent on agreed service delivery
Data export formats
  • CSV
  • Other
Other data export formats
  • Excel
  • JSON
Data import formats
  • CSV
  • Other
Other data import formats
  • Excel
  • JSON

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
Dependent on agreed service delivery

Availability and resilience

Guaranteed availability
The service is delivered as a cloud-hosted SaaS solution with guaranteed availability of 99.9% for the calendar month. Availability is measured across all core workflow automation functions, including flow execution, trigger processing, notifications, and approvals. We monitor service performance continuously and apply proactive maintenance, redundancy, and failover procedures to minimise downtime. Planned maintenance is scheduled outside business hours where possible, with advance notification to users. While we do not offer a formal SLA under the Ad Hoc Support model, we commit to promptly resolving any service interruptions. In the unlikely event that availability falls below the guaranteed level, affected organisations can request remediation, which may include service credits or support assistance to restore functionality. This approach ensures that automated workflows and approvals remain operational and reliable, supporting uninterrupted business processes for public sector organisations.
Approach to resilience
The service is designed for high resilience, leveraging Microsoft 365’s multi‑region, redundant data centre infrastructure. Flow definitions, run history, and organisational data are stored across multiple locations, ensuring continuity in the event of hardware failure or unplanned outages. Data is replicated in near real‑time to minimise risk of loss and maintain operational availability. Automatic failover mechanisms ensure that if one data centre experiences disruption, service operations continue seamlessly from alternate locations. Backup and recovery procedures are in place to restore data rapidly, with regular testing to confirm effectiveness. Planned maintenance is scheduled outside core business hours where possible, minimising user impact. The service also incorporates application-level resilience, including error handling, transaction logging, and retry mechanisms within workflows. Combined with Microsoft 365’s physical security, environmental controls, and monitoring, this ensures both data integrity and availability for all organisations. Details of the full resilience architecture, including specific datacentre configurations, are available on request to maintain security while demonstrating compliance with public sector standards.
Outage reporting
The service reports outages through multiple channels to ensure users are informed promptly. Public dashboard: Displays current service status, including any outages or planned maintenance, accessible via the web. Email alerts: Registered users receive notifications for service disruptions, maintenance windows, and incident resolutions. API: Available for integration with organisational monitoring tools, providing real-time status updates programmatically. Incident reports include start and end times, affected components, and any mitigation steps taken. Users can monitor service health proactively and plan work around any disruptions. Post-incident summaries are provided to support review and compliance requirements. This multi-channel approach ensures transparency, timely communication, and minimises operational impact for public sector organisations.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is strictly controlled using role-based access controls and multi-factor authentication. Only authorised personnel, such as administrators or support staff, can access workflow configuration, system settings, or customer data. Support channel access (email or ticketing) is restricted to verified users, and all requests are logged for auditing. Sensitive actions, such as configuration changes or data extraction, require elevated permissions. Periodic reviews ensure access remains appropriate, with immediate revocation for departing staff or changes in role. This approach ensures that both operational and support activities are secure, auditable, and limited to authorised personnel only.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Limited access network (for example PSN)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
Other
Other security governance standards
Cyber Essentials Plus
Information security policies and processes
The service follows Microsoft 365’s comprehensive information security policies and processes, aligned with ISO 27001 and public sector security standards. These cover access control, data protection, incident management, change management, and monitoring. Reporting structure: Security responsibilities are defined across organisational and technical teams. A designated Security Officer oversees compliance, reporting directly to senior management. All incidents are logged, escalated, and reviewed according to severity, with documented mitigation steps. Policy enforcement: Access is controlled using role-based permissions and multi-factor authentication. Users are required to follow security best practices, while administrative and operational activity is monitored through audit logs. Regular training ensures staff understand and adhere to policies. Security reviews, internal audits, and automated monitoring help maintain compliance. Incident response: Any suspected breaches trigger immediate investigation and reporting, following a formal escalation process. Lessons learned are applied to update policies, configurations, and controls. This structured approach ensures that the service maintains data confidentiality, integrity, and availability, while providing public sector organisations with clear visibility of security governance and adherence to recognised standards.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
The service follows formal configuration and change management processes aligned with recognised standards (CSA CCM v4.0, SSAE-18/ISAE 3402). All components, including workflows, APIs, integrations, and infrastructure, are tracked through their lifecycle with version control and documented histories. Proposed changes are assessed for security and operational impact, tested in a controlled environment, and approved by authorised personnel. Audit logs and monitoring tools track all changes, ensuring compliance and transparency. This approach maintains service stability, security, and reliability, allowing updates, enhancements, and patches to be deployed safely while providing public sector organisations with a fully auditable and controlled change process.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
The service follows a structured vulnerability management process aligned with recognised standards (CSA CCM v4.0, SSAE-18/ISAE 3402). Potential threats are assessed through automated scans, internal security reviews, and threat intelligence from Microsoft Security, CERT-UK, and other recognised sources. Risks are prioritised by severity and impact on workflows, data, and integrations. Security patches are tested in a controlled environment and deployed promptly, with critical vulnerabilities addressed as quickly as possible. Continuous monitoring and audit logs ensure emerging threats are identified and remediated, maintaining service security, operational continuity, and compliance for public sector organisations.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Identifying compromises: Continuous monitoring of workflows, APIs, system logs, and network activity detects anomalies, suspicious behaviour, or potential security breaches. Automated alerts and threat intelligence feeds from Microsoft Security and CERT-UK support rapid identification of risks. Responding to incidents: Once a potential compromise is detected, incidents are escalated according to severity. Investigation and containment measures are initiated immediately, including isolating affected components and applying mitigation steps. Response time: Critical incidents are addressed as quickly as possible, with formal incident reporting and post-incident review. Lessons learned inform updates to security controls and procedures.
Incident management type
Supplier-defined controls
Incident management approach
The service has defined incident management processes aligned with recognised standards. Pre-defined procedures cover common events, including service outages, security breaches, and workflow failures. Users report incidents via email or the online ticketing portal, with prioritisation based on severity. Incidents are logged, investigated, and escalated as needed, with containment and mitigation measures applied promptly. Users receive updates throughout the resolution process, including incident summaries and post-incident reports detailing causes, actions taken, and lessons learned. Continuous review ensures procedures are improved over time, maintaining operational continuity, transparency, and compliance while protecting public sector data and service reliability.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
None of the criteria
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
D2995467-44e9-4934-a970-bb8b35e0ed39
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tracy@m8solutions.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.