Microsoft Power Platform Consultancy and Services
Microsoft Power Platform is increasingly critical to improving efficiency, visibility, and consistency. Low-code solutions must be designed with governance and security to ensure they are scalable, supportable, and trusted. We provide structured delivery combining technical expertise, information governance, and practical enablement to help organisations automate safely and empower users.
Features
- Governed Power Platform delivery aligned to NHS and Microsoft standards
- End-to-end Power Automate workflow design, deployment, governance, and training
- Secure system integration across Microsoft 365, Dataverse, Dynamics, NHS systems
- AI-assisted automation enabling smarter, context-aware, auditable operational decisions
- Power Apps development for web, mobile, and Microsoft Teams
- Role-based access controls and DLP policies enforcing NHS data protection
- Power BI dashboards providing real-time, trusted operational and clinical insight
- Robust data modelling supporting scalable, accurate, enterprise-grade NHS reporting
- Legacy system automation using RPA for structured and unstructured processes
- Full lifecycle delivery from discovery through deployment, assurance, adoption
Benefits
- Reduce manual effort by automating approvals, routing, and repetitive processes
- Improve productivity through faster workflows without bespoke development or coding
- Enable staff to access secure apps across web mobile Teams
- Provide real-time visibility through dashboards supporting informed operational decisions making
- Standardise processes with governed templates ensuring consistency safety and compliance
- Quickly adapt workflows as services change without disrupting live operations
- Reduce errors using validated data capture role-based access controls consistently
- Accelerate decision-making by surfacing trusted data when and where needed
- Safely scale automation across teams while maintaining governance and assurance
- Support confident adoption through training documentation and ongoing expert support
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 3 4 0 1 7 9 8 7 1 6 4 2 2 5
Contact
M8 SOLUTIONS LIMITED
Tracy Scriven
Telephone: 07925051060
Email: tracy@m8solutions.co.uk
About your service
- Service categories
-
Application Development and Deployment
AI platforms
AI life cycle
- AI Build Software
- Trustworthy AI Software
AI software services
- Personalize AI Software Services
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Dependent on agreed service delivery
- System requirements
- Active Microsoft 365 tenant
User support
- Email or online ticketing support
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- N/a
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- We support users in getting started through a combination of documentation, online training, and guided onboarding. Comprehensive user guides and step-by-step tutorials are provided, covering workflow creation, approvals, notifications, and reporting. These resources include screenshots, examples, and troubleshooting tips to enable users to self-learn efficiently. Online training sessions are offered, including recorded modules, demonstrating how to configure workflows, integrate with Microsoft 365 apps, and manage approvals. Authorised users can view these to build confidence in using the platform and applying customisation features. For larger deployments or specific organisational needs, we can provide guided onboarding sessions, either virtually or on-site, to help teams set up workflows, configure roles, and establish automation rules. These sessions include practical exercises to ensure users understand the system and can start automating processes quickly. Ongoing support is available through email and ticketing for any questions during the initial adoption period. This combination of self-service documentation, online training, and optional guided onboarding ensures users can rapidly adopt the service and maximise the benefits of workflow automation.
- Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
-
- Word Guides
- Video Guides
- End-of-contract data extraction
- At the end of the contract, users can either securely extract all their data in standard, machine-readable formats (CSV, Excel, or JSON) or they can continue using the automation unsupported by the supplier. This includes workflow configurations, task histories, approvals, notifications, and reporting data. Data extraction is managed via the web interface, with guidance provided in user documentation. For larger datasets or complex workflows, the supplier can assist with secure export or migration. Extracted data can be imported into other systems or retained for record-keeping and compliance purposes. All user data is removed from the platform after extraction, in line with GDPR and contractual obligations. This ensures organisations maintain control over their information and can transition smoothly to alternative solutions without data loss.
- End-of-contract process
- At the end of the contract, we work with the buyer to ensure an orderly transition to another supplier, in house or support is provided to extract all organisational data, including workflow configurations, task histories, approvals, notifications, and reporting data, in standard, machine-readable formats (CSV, Excel, JSON). Once data extraction is complete, all user and organisational data is securely deleted from the platform, in accordance with GDPR and contractual obligations. Access to the service is disabled, and any temporary accounts or third-party access are revoked to maintain security and confidentiality. The supplier provides guidance and documentation to assist with migration to alternative systems or archiving of data. Any outstanding support requests are resolved or handed over to the buyer prior to contract expiry. Optional offboarding assistance, including remote or on-site support, can be arranged for organisations with complex workflows or larger deployments. This structured end-of-contract process ensures data integrity, compliance, and security, allowing organisations to transition smoothly, retain full control over their information, and minimise operational disruption when the contract concludes.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service is fully functional on both desktop and mobile browsers. Mobile access supports workflow creation, approvals, notifications, and task management, optimised for smaller screens. Some advanced configuration and reporting features are easier to use on desktop, but all core workflow and automation functionality is available on mobile devices.
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
- Dependent on agreed service delivery
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Dependent on agreed service delivery
Scaling
- Independence of resources
- Dependent on agreed service delivery
Analytics
- Service usage metrics
- Yes
- Metrics types
- Dependent on agreed service delivery
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- IThink365
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Other
- Other data at rest protection approach
- Data at rest is protected using Microsoft 365’s built-in encryption (AES-256) across all storage media. Tenant data is logically segregated, with strict access controls, secure key management, and redundancy across data centres. Physical access is restricted and monitored by Microsoft, ensuring resilience and compliance with public sector security standards.
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Dependent on agreed service delivery
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Excel
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Other
- Other protection within supplier network
- Dependent on agreed service delivery
Availability and resilience
- Guaranteed availability
- The service is delivered as a cloud-hosted SaaS solution with guaranteed availability of 99.9% for the calendar month. Availability is measured across all core workflow automation functions, including flow execution, trigger processing, notifications, and approvals. We monitor service performance continuously and apply proactive maintenance, redundancy, and failover procedures to minimise downtime. Planned maintenance is scheduled outside business hours where possible, with advance notification to users. While we do not offer a formal SLA under the Ad Hoc Support model, we commit to promptly resolving any service interruptions. In the unlikely event that availability falls below the guaranteed level, affected organisations can request remediation, which may include service credits or support assistance to restore functionality. This approach ensures that automated workflows and approvals remain operational and reliable, supporting uninterrupted business processes for public sector organisations.
- Approach to resilience
- The service is designed for high resilience, leveraging Microsoft 365’s multi‑region, redundant data centre infrastructure. Flow definitions, run history, and organisational data are stored across multiple locations, ensuring continuity in the event of hardware failure or unplanned outages. Data is replicated in near real‑time to minimise risk of loss and maintain operational availability. Automatic failover mechanisms ensure that if one data centre experiences disruption, service operations continue seamlessly from alternate locations. Backup and recovery procedures are in place to restore data rapidly, with regular testing to confirm effectiveness. Planned maintenance is scheduled outside core business hours where possible, minimising user impact. The service also incorporates application-level resilience, including error handling, transaction logging, and retry mechanisms within workflows. Combined with Microsoft 365’s physical security, environmental controls, and monitoring, this ensures both data integrity and availability for all organisations. Details of the full resilience architecture, including specific datacentre configurations, are available on request to maintain security while demonstrating compliance with public sector standards.
- Outage reporting
- The service reports outages through multiple channels to ensure users are informed promptly. Public dashboard: Displays current service status, including any outages or planned maintenance, accessible via the web. Email alerts: Registered users receive notifications for service disruptions, maintenance windows, and incident resolutions. API: Available for integration with organisational monitoring tools, providing real-time status updates programmatically. Incident reports include start and end times, affected components, and any mitigation steps taken. Users can monitor service health proactively and plan work around any disruptions. Post-incident summaries are provided to support review and compliance requirements. This multi-channel approach ensures transparency, timely communication, and minimises operational impact for public sector organisations.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is strictly controlled using role-based access controls and multi-factor authentication. Only authorised personnel, such as administrators or support staff, can access workflow configuration, system settings, or customer data. Support channel access (email or ticketing) is restricted to verified users, and all requests are logged for auditing. Sensitive actions, such as configuration changes or data extraction, require elevated permissions. Periodic reviews ensure access remains appropriate, with immediate revocation for departing staff or changes in role. This approach ensures that both operational and support activities are secure, auditable, and limited to authorised personnel only.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
- The service follows Microsoft 365’s comprehensive information security policies and processes, aligned with ISO 27001 and public sector security standards. These cover access control, data protection, incident management, change management, and monitoring. Reporting structure: Security responsibilities are defined across organisational and technical teams. A designated Security Officer oversees compliance, reporting directly to senior management. All incidents are logged, escalated, and reviewed according to severity, with documented mitigation steps. Policy enforcement: Access is controlled using role-based permissions and multi-factor authentication. Users are required to follow security best practices, while administrative and operational activity is monitored through audit logs. Regular training ensures staff understand and adhere to policies. Security reviews, internal audits, and automated monitoring help maintain compliance. Incident response: Any suspected breaches trigger immediate investigation and reporting, following a formal escalation process. Lessons learned are applied to update policies, configurations, and controls. This structured approach ensures that the service maintains data confidentiality, integrity, and availability, while providing public sector organisations with clear visibility of security governance and adherence to recognised standards.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- The service follows formal configuration and change management processes aligned with recognised standards (CSA CCM v4.0, SSAE-18/ISAE 3402). All components, including workflows, APIs, integrations, and infrastructure, are tracked through their lifecycle with version control and documented histories. Proposed changes are assessed for security and operational impact, tested in a controlled environment, and approved by authorised personnel. Audit logs and monitoring tools track all changes, ensuring compliance and transparency. This approach maintains service stability, security, and reliability, allowing updates, enhancements, and patches to be deployed safely while providing public sector organisations with a fully auditable and controlled change process.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- The service follows a structured vulnerability management process aligned with recognised standards (CSA CCM v4.0, SSAE-18/ISAE 3402). Potential threats are assessed through automated scans, internal security reviews, and threat intelligence from Microsoft Security, CERT-UK, and other recognised sources. Risks are prioritised by severity and impact on workflows, data, and integrations. Security patches are tested in a controlled environment and deployed promptly, with critical vulnerabilities addressed as quickly as possible. Continuous monitoring and audit logs ensure emerging threats are identified and remediated, maintaining service security, operational continuity, and compliance for public sector organisations.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Identifying compromises: Continuous monitoring of workflows, APIs, system logs, and network activity detects anomalies, suspicious behaviour, or potential security breaches. Automated alerts and threat intelligence feeds from Microsoft Security and CERT-UK support rapid identification of risks. Responding to incidents: Once a potential compromise is detected, incidents are escalated according to severity. Investigation and containment measures are initiated immediately, including isolating affected components and applying mitigation steps. Response time: Critical incidents are addressed as quickly as possible, with formal incident reporting and post-incident review. Lessons learned inform updates to security controls and procedures.
- Incident management type
- Supplier-defined controls
- Incident management approach
- The service has defined incident management processes aligned with recognised standards. Pre-defined procedures cover common events, including service outages, security breaches, and workflow failures. Users report incidents via email or the online ticketing portal, with prioritisation based on severity. Incidents are logged, investigated, and escalated as needed, with containment and mitigation measures applied promptly. Users receive updates throughout the resolution process, including incident summaries and post-incident reports detailing causes, actions taken, and lessons learned. Continuous review ensures procedures are improved over time, maintaining operational continuity, transparency, and compliance while protecting public sector data and service reliability.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- None of the criteria
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- D2995467-44e9-4934-a970-bb8b35e0ed39
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-