Workpro Requests - FOI, EIR and DPA case management software
Workpro Requests case management system helps you to efficiently track, respond to and report FOI (Freedom of Information), EIR (Environmental Information Regulations), Data Protection Act (DPA) and SAR (Subject Access Requests) within one secure, user friendly system. GDPR compliant. UK based, ISO 27001 cloud hosting.
Features
- FOI, EIR, DPA, SAR, GDPR case types 'out-of-the-box'. Configurable features.
- Protect sensitive cases with user permissions. Allocate cases and tasks.
- Highly visible alerts ensure key dates and actions aren’t missed.
- All documentation stored and created within case record. Microsoft integration.
- Email and letter templates auto-populated with case data save time.
- Quick and advanced search to access relevant cases and documents.
- Comprehensive dashboards, case and task views to track casework.
- Built-in standard reports library and flexible report creation tools.
- Key system elements and permissions maintainable by authorised administrators.
- File management and GDPR compliance tools support data protection policies.
Benefits
- Manage all information requests from one secure online system
- Ensure consistency in request management and responses
- Improve correspondence and log all case documentation
- Track case activity with clear visibility of next steps
- Improve productivity, reducing time taken on cases
- Ensure request handling complies with legislation and policies
- A chronological audit trail guarantees full accountability and transparency.
- Monitor case status and team performance in real-time
- Produce management reports easily from the built-in standard reports library.
- Identify common request themes for FAQ publication and improvement initiatives.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 8 8 8 0 3 7 8 4 6 5 2 0 8 1
Contact
Workpro
Ken Naismith
Telephone: 0131 449 7071
Email: workpro@casltd.com
About your service
- Service categories
-
Applications
Customer relationship management
- Customer service
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- Much of Workpro’s functionality is accessed from a web browser. Workpro supports the following: current versions of Microsoft Edge and Google Chrome. Workpro also supports the creation of Microsoft Word documents, which can be edited and saved directly back into Workpro using the following: Microsoft Office 365. You may also require a PDF viewer tool. Any application capable of reading PDF documents can be supported (Adobe Acrobat / Microsoft Edge / Google Chrome). We offer an optional Workpro PDF editor module which allows you to save changes to PDF documents directly back to Workpro.
- System requirements
-
- Microsoft Edge; Google Chrome
- Microsoft Office 365
- PDF tool such as Adobe Acrobat
User support
- Email or online ticketing support
- Yes
- Support response times
- We aim to respond as soon as possible, with standard response commitments as follows: Priority 1 within 1 hour (system non-operational and affects more than 50% users). Priority 2 within 4 hours (system non-operational and affects minority of users). Priority 3 within 4 hours (identifiable fault but system still operational, minor faults and advice). Priority 4 within 8 hours (cosmetic issues which do not affect the operation of the system). Priority 5 within 5 working days (system enhancements, new and additional features). Standard working hours are Mon-Fri 9am-5pm GMT but out of hours support is available.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 A
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We operate an ITIL compliant support operation including manned help desk with backup technical resource as required. • 24/7/365 online support portal, for logging/monitoring issues, requests and billing Support is available by email/telephone through our helpdesk • Remote support can be carried out via dedicated link. • Workpro is an evolving product with one annual system upgrade • Standard Workpro application support hours are Mon-Fri 9-5, excluding Christmas and New Year. Our response times are based on 6 priorities: Priority 1 system non-operational and affects majority of (>50%) users with a target of resolve < 5 hours Mon-Fri. Priority 2 system non-operational and only affects minority (<50%) of users with a target of resolve in < 12 hours. Priority 3 identifiable fault but system still operational , minor faults and advice with a target to resolve in < 30 days. Priority 4 cosmetic issues which don't affect the operation of the system with a target to resolve in < 60 days. Priority 5 system enhancements, new and additional features with a target to negotiate resolution. Priority 6 requests for advice with a target to resolve in < 10 days.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
As standard, the Workpro Implementation Team will set up a client instance of Workpro on the Workpro Private or Public Cloud and will ensure client specific security settings are in place. Additional modules, customisation, support, integration and migration services can be purchased with Workpro.
While Workpro is designed to be intuitive and easy to use, we recommend training on the system to ensure that your organisation can use it to best advantage. Our Standard Training Package includes training for Users, Train the Trainer, System Administrators and Report Writers. This is delivered online in manageable chunks, with notes and recordings provided. A Workpro User Guide is supplied with the system and is accessible by a help link on screen. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- We would provide client data in the form of a spreadsheet when the contract ends. We would also transfer any stored documents to a client drive.
- End-of-contract process
-
3 month's notice is required, during which time service deprovisioning will be done.
Data and document extraction would be included in the price of the contract. - Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Workpro has a responsive design so it can be accessed from any mobile device. Workpro is a data-rich application and, therefore, we recommend accessing from a desktop.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- Workpro is a responsive web application, and is therefore accessible from any web-enabled device.
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
- We perform accessibility testing internally as part of our development process. Workpro contains an accessibility statement which is updated to reflect the latest findings of accessibility reviews and testing.
- API
- Yes
- What users can and can't do using the API
-
The Workpro API interface is designed for access by a client website and provides functionality to support the creation and updating of Workpro cases. Additionally, it allows users to upload one or more supporting pieces of documentation and associate them with a case. Workpro web services are typically hosted in one of two configurations: Within a separate application hosted inside a Workpro application or as a completely separate web site hosted in IIS.
Access to the services is normally limited by a firewall to specific source networks or addresses, to prevent unauthorised use. Other security mechanisms can be added depending on requirements. It is implemented as a set of web services. - API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Administration tools allow many aspects of the solution to be maintained by authorised users with the required access level and appropriate training. Authorised users can make changes for example to look-up lists, data categories, fields, document templates, targets, thresholds and alerts, user permissions and some file management and data retention activities.
The Workpro team are also available to support customisation should clients require or prefer it. We also provide integration (e.g. with your HR/Payroll system) and data migration services as required.
Scaling
- Independence of resources
- Each application has a separate application pool / database so that resource allocation can be profiled and allocated according to expected usage. Overall performance of the system is monitored by checking response times and resource usage. Where necessary, additional resources can be allocated.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
• Colour coded Ticket List shows priority and status
• Billing dashboard shows contracted hours used and how many remain
• Tickets raised, closed or currently open are listed.
If the Usage Based Licencing model is chosen, monthly user login reports determine how many users have logged in that month. An invoice will be produced based on that number. A user will be defined as a named individual and usage will be defined as the initial login for that named individual in a calendar month. - Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Physical access control, complying with another standard
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Data can be exported from reports to other applications and formats, e.g. Excel, Word, PDF.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Excel
- HTML
- XML
- JSON
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Excel
- XML
- JSON
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- We guarantee service availability of 99.9% within a calendar month. We have an optional mission critical service which offers a service credit for periods where the service isn't available during working hours.
- Approach to resilience
- Available on request.
- Outage reporting
- Email alerts are sent to our support team if the service isn't available.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Access restrictions in management interfaces and support channels
- Administrator accounts are not granted permissions to access case data within the system. Access to servers is via named accounts and is monitored.
- Access restriction testing frequency
- Less than once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
-
As an ISO 27001 certified organisation, Workpro has a fully documented ISMS (Information Security Management System) which includes the following policies: Information Security Standard, Information Backup Procedure, Logical Access Security Standard, Risk Assessment and Treatment Procedure, Physical Security Guidelines, Site Security Instructions, Data Protection Procedure, HR Security Guidelines. Copies of policies are available on request. The Chief Executive Officer is responsible for overseeing the high level co-ordination of Information Security Management within Workpro. Workpro has an Information Security Forum who meet regularly and are responsible for ensuring policies are followed, consisting of:
• Chief Technical Officer
• Infrastructure Manager
• Business Relationship Manager
• Quality Manager. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
Our change management process is included within the scope of our ISO9001 accreditation.
When a customer onboards their Workpro system is created using a standard configuration template. Changes to this are managed via a formal change control process with customers required to approve any changes to this configuration.
Core product changes are managed using an agile process. A specification for the core product is checked in to our source control system which describes the version at that revision.
Configuration changes are managed in the same way and deployed using an automated build for removing variability from deployments. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Workpro assign information processing assets to individual owners within the organisation, who are responsible for assessing risks and mitigation steps applicable to these assets. Systems are patched monthly and critical patches are applied within two weeks of notification.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- The Workpro environment is subject to constant ongoing monitoring by an industry standard tool which can report failures or other incidents to responsible staff. These monitors are run from a range of systems, including externally hosted servers. Any incident is subject to review, discussion and escalation with an experienced team in place to identify and address issues. Since reporting is real time, the response to any incident can be immediate.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Workpro has a documented incident reporting process that includes action steps to handle critical incidents, up to and including large scale business continuity issues. Workpro maintains a robust reporting system, accepting inputs from internal and external sources. Incidents are recorded in a formal database and are treated according to priority and impact. Failures that impact on user access or data can result in a formal report including details of actions taken, and any steps proposed to prevent or mitigate further incidents.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- Clients are given a login to a trial version. Report Builder is not included with this version. Access is usually for one month, but is negotiable.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA Limited
- ISO/IEC 27001 accreditation date
- Tuesday 17 December 2024
- What the ISO/IEC 27001 doesn’t cover
- N/a
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA Limited
- ISO 9001 accreditation date
- Friday 25 April 2025
- What the ISO 9001 doesn’t cover
- N/a
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 5b0d28b7-d836-4134-867d-58b89caafcc1
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- E919de2b-9bb6-4ee5-84ef-5814e755ba31
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Other measures to offer development opportunities for the target cohort(s) in the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-