BMC Helix ITSM
Today, customers need to be able to access technology support wherever they are and whatever they are doing. BMC Helix ITSM enables you to create world-class, omni-channel service experiences for your users, integrating self-service and empowering service agents to deliver the best possible human-led support. Tekwurx is a BMC Partner.
Features
- AI-Powered Service Desk: Automates ticket routing, categorisation, and resolution*
- Omni-channel Support: Email, chat, phone, self-service portals
- ITIL-Aligned: Best practices for incident, problem, change, asset management
- Self-Service Portal: Resolve issues, request services, and track progress
- Automated Workflows: Streamlines repetitive tasks and approvals with customisable workflows
- Integration: Connect third-party tools (e.g., Microsoft Teams, ServiceNow, Jira)
- Predictive Analytics: Uses data to predict and prevent IT issues
- Mobile Accessibility: Mobile apps for IT teams and end-users
- Asset Management: Tracks and manages IT assets throughout their lifecycle
- Customisable Dashboards: Provides real-time insights and KPIs
Benefits
- Improved Efficiency: Automates manual tasks, reducing resolution times and workloads
- Improved user satisfaction from omni-channel support and self-service
- AI and predictive analytics help prevent incidents before they occur
- Reduces operational costs by optimising IT processes and resource allocation
- Improved Compliance and Governance: Adherence to ITIL and regulatory standards
- Improved Scalability: Supports growing business needs and evolving IT environments
- Better Collaboration: Integrates with other tools, fostering cross-team collaboration
- Improved Decision-Making: Customisable dashboards and reports provide actionable insights
- Increased Productivity: Mobile and automation enable teams to work efficiently
- Future-Ready: Cloud-based architecture ensures flexibility and continuous innovation.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 1 4 7 7 8 5 5 5 4 5 2 9 1 7
Contact
TEKWURX LIMITED
Nik Dimmock
Telephone: +44 203 740 1905
Email: sales@tekwurx.com
About your service
- Service categories
-
Applications
Customer relationship management
- Customer service
- Contact centre
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- None
- System requirements
- Supported browser is required
User support
- Email or online ticketing support
- Yes
- Support response times
-
BMC provides support 24 hours a day, 7 days a week.
S1A (Critical) 24 hours a day, 7 days a week (including published holidays) 30 minutes
S1 (Critical) 24 hours a day, 7 days a week (including published holidays) 1 clock hour
S2 (High) Local business hours: 7:00 AM to 7:00 PM, Monday to Friday (excluding published holidays) 2 business hours
S3 (Medium) Local business hours: 7:00 AM to 7:00 PM, Monday to Friday (excluding published holidays) 4 business hours
S4 (Low) Local business hours: 7:00 AM to 7:00 PM, Monday to Friday (excluding published holidays) 12 business hours - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- No
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- Unknown
- Onsite support
- Yes, at extra cost
- Support levels
-
BMC provides support 24 hours a day, 7 days a week, as part of the subscription. Tekwurx offers extended support and BAU services that provide a more proactive approach to customer support. This is an additional cost and depends on the level of support required.
Severity 1 - Critical Service Impact
The issue critically affects the primary business service, major application, or mission-critical system. Characteristics of a Severity 1 issue include:
- Business service is not operational
- Production system crashes
- Data integrity at risk
- Production backup and recovery operations fail
Severity 2
Significant Service or Implementation Impact
The business service, major application, or system is seriously affected, or implementation is stopped. No acceptable workaround is available.
Severity 3 - Moderate Service Impact
The business service, major application, or system is moderately impacted; no data has been lost, and it is still functioning. The issue may be temporarily circumvented using an available workaround.
Severity 4 - No Service Impact
Non-critical issues, general questions, enhancement requests, or documentation issues
BMC & Tekwurx will assign a technical account manager to each customer. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
New customers work with the Tekwurx Account Management and PMO team to develop a statement of work for any required implementation services. Each project includes clearly defined deliverables, roles and escalation paths, ensuring full transparency on project progress.
Implementation support is provided by our in-house team of experienced, certified consultants. We offer a comprehensive suite of services, including consulting, implementation, training, communication strategy, and ongoing support. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Upon written request made within 60 days after the effective date of termination, BMC Helix will make the Customer Content available to Customer for retrieval in an industry-standard format
- End-of-contract process
- Upon expiration of the contract, all rights and Licenses will terminate, and the customer will make no further use of the Subscription Services. Upon written request made within 60 days after the effective date of termination, BMC Helix will make the Customer Content available to Customer for retrieval in an industry-standard format. After the 60-day period, BMC Helix shall have no obligation to maintain any Customer Content and will thereafter delete it.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The desktop and mobile interaction for users is very similar. It is not possible to administer or configure the application on the mobile platform
- Service interface
- No
- User support accessibility
- WCAG 2.2 AA
- API
- Yes
- What users can and can't do using the API
-
REST API - uses JSON to transmit data between a server and a web application.
C API - a set of functions and data structures.
Java API - a collection of classes, interfaces, and relationships that provide full client functionality in a style consistent with typical Java programming techniques. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- BMC Helix ITSM can be customised to suit a customer's particular requirements. This usually involves adding fields to a form and modifying the associated workflows. BMC provides a development environment that users with the necessary knowledge can use to customise the service.
Scaling
- Independence of resources
- BMC Helix services are delivered from a variety of cloud locations that seamlessly scale to meet performance requirements and consumption demands. Our typical availability SLA is 99.9%, unless otherwise contracted. BMC consistently achieves 99.98% average availability with real service credits for breaches
Analytics
- Service usage metrics
- Yes
- Metrics types
-
With BMC’s service status dashboard, you can monitor your production instance in real time—whether you’re at your desk or on the go. The intuitive, modern interface gives you a comprehensive overview of key metrics, including:
• Transaction volumes
• Active and historical license usage
• Application performance and usage
• Login response times
• Support metrics
• Application version details
• Broadcast messages - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- BMC Helix, EasyVista, Lansweeper, Barracuda
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Physical access control, complying with CSA CCM v4.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- The solution provides a comprehensive reporting solution which enables data to be extracted and exported to a variety of formats - e.g. CSV, XLS, DOC, PDF, RTF.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XML
- JDBC
- DOC
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JDBC
- JMS
- RDBMS
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
-
BMC Helix conducts rigorous performance testing to evaluate and ensure your subscription’s responsiveness, stability, and scalability under expected and peak usage conditions. BMC Helix services are delivered from multiple cloud locations that scale seamlessly to meet performance and consumption requirements. Our typical availability SLA is 99.9%, unless otherwise contracted. BMC consistently achieves 99.98% average availability with real service credits for breaches.
If the availability is less than the service commitment, the customer is eligible for a Service Credit. The Service Credit will be calculated by converting the difference between the Actual Availability and the Service Commitment into minutes, with any partial minutes counted as full minutes. These minutes will be converted to a monetary value and applied to the customer’s next transaction. - Approach to resilience
-
BMC's Helix services are hosted from various regional locations. Each customer's service location is dependent on various factors such as environment type, proximity of the customer to the data location, and customer sector (public versus private).
Customer environments are controlled, monitored, and managed by BMC SaaS Operations (BMC Cloud locations also include the underpinning application and infrastructure aspects of the service). Areas of focus include hosting, storage, network, application software, and the connectivity between the cloud and the customers' premises. Additionally, the service includes the management of standard operational activities such as data and system backup, and recovery. - Outage reporting
-
You will receive a system bulletin from the BMC SaaS Operations team if any of the following situations occur:
• A sudden downtime in the production environment because a service has stopped functioning
• An upcoming planned downtime for a BMC SaaS service (excluding those with a self-service option)
• Upcoming activities such as scheduled go-live announcements, month-end freeze reminders, and shutdown reminders
This notification may be addressed to a specific subgroup if the application is related to a particular set of users, or it may be sent as a global notification if application downtime (or another general announcement) has occurred. Announcements that address the BMC end-user community are critical and presented clearly and carefully.
If downtime is required due to an approved change request, a system bulletin is sent a few days before and on the same day as the change request’s fulfilment. The bulletin also explains that the scheduled downtime is due to an approved change request.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
-
BMC’s access controls include specialised security controls that provide role-based, secure application access. BMC’s scalable cloud-based solutions secure our customers' solutions across the Software Development Lifecycle (SDLC) — from code development to pre-production testing and production. Key features of this layer include:
• Application security that protect data from unauthorised access
• Role-based access
• Encrypted credentials
• A logical, multi-tiered access control construct
• Static Application Security Testing, including the use of Open Web Application Security Project (OWASP)
• Dynamic Application Security Testing, including authentication tests, client-side attack tests, command execution tests, information disclosure tests, and logical attack tests - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
BMC understands that the confidentiality, integrity and availability of your operational information are vital to your organisation. BMC uses a multi-layered approach to protect your data by continuously monitoring and improving applications, systems, and processes. The BMC Security Operations Centre (SOC) and Network Operations Centre (NOC) teams operate 24 hours a day, 7 days a week, 365 days a year to ensure the continuous, secure operation of your service.
The NOC makes extensive use of BMC’s world-class monitoring and automation solutions. All customer environments are monitored 24 hours a day, 7 days a week. The NOC frequently resolves potential incidents before they impact customers.
Should your service be impacted, automated root cause analysis data is provided via the BMC TrueSight Operations Management solution and extensive automations using BMC Atrium Orchestrator dramatically reduce the Mean Time to Repair (MTTR).
BMC’s security strategy includes the following layers:
• Governance
• Physical
• Perimeter
• Network
• Endpoint
• Application
• Data
More details here: https://docs.bmc.com/xwiki/bin/view/Helix-Common-Services/Other/BMC-Helix-Subscriber-Information/helixsubscriber/Security/Security-overview/ - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
BMC oversees change processes through its Change Advisory Board (CAB), which includes BMC SaaS Operations representatives. The CAB assesses the risk and impact of all proposed changes to your system.
Every change requires a Request for Change (RFC)—a formal proposal that outlines:
• Details of the change
• Steps for execution
• A back-out plan
This ensures structured, low-risk updates to your system. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
BMC welcomes input on potential vulnerabilities from all sources. The team follows a formal vulnerability disclosure process regardless of the source.
Based on the severity, the vulnerability is routed through senior management, remediated by the relevant development team, and communicated to affected customers.
The incident management procedure covers emergency incidents, escalation, and public vulnerability disclosure. BMC’s practices include procedures for documenting the incident in detail and producing a report for future reference or management attention.
- Assess impact.
Determine what fix is required.
- Maintain communication.
- Document and communicate the fix. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Identifying a problem before it impacts service is critical to outage avoidance. BMC has extensive monitoring capabilities in place to proactively monitor performance for the production instances through use of its own tools. These tools include:
• BMC Helix Operations Management
• BMC Helix Log Analytics
• BMC Helix Continuous Optimization
• BMC Helix Service Monitoring with AIOps
• BMC PATROL Agent for BMC Helix Operations Management
• BMC Helix Discovery
• BMC Helix Intelligent Integrations
• BMC Helix Dashboards
• BMC Helix Developer Tools
• BMC Helix Intelligent Automation
• BMC TrueSight Synthetic Monitor
• BMC TrueSight Orchestration Platform - Incident management type
- Supplier-defined controls
- Incident management approach
-
BMC’s incident management procedure enables a swift response to any potential incident. This procedure covers emergency incidents, escalation, and public vulnerability disclosure. BMC’s practices include procedures for documenting the incident in detail and producing a report for future reference or management attention.
- Assess impact.
- Determine what fix is required.
- Maintain communication.
- Document and communicate the fix. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- 30-day trial licence
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 20b11a27-f6fe-4761-bc64-cca8b0888d47
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Activities to cascade good practice on fair working conditions throughout the supply chain
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
- How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
- How to ensure business decisions re: price/cost, short lead times, payment timescales do not create modern slavery risks in the supply chain
- Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
- Activities to reconnect people with the environment and increase awareness of ways to protect and enhance it
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-