Totara Perform, Performance and Talent Management
BuildEmpire, a Totara Platinum Partner, delivers Totara Learn, Engage and Perform for the UK public sector. Trusted by NHS Trusts and public sector organisations, we provide secure, scalable platforms aligned to the latest Totara releases, with configurable and bespoke solutions tailored to public sector learning and performance needs.
Features
- Appraisals: Configurable performance review cycles
- Goals management: Set and track organisational goals
- Feedback tools: Continuous feedback and check-ins
- Competency frameworks: Manage skills and capability structures
- Evidence capture: Link learning to performance outcomes
- Reporting dashboards: Performance and capability insights
- Skills tracking: Identify skills gaps and development needs
- Workflow automation: Approvals and notifications
- SMART goals: AI-assisted SMART goal creation
- Coaching support: Enable coaching conversations
Benefits
- Better performance conversations: Support continuous improvement
- Clear priorities: Align goals to public sector outcomes
- Stronger capability: Address skills gaps proactively
- Evidence-based decisions: Link learning to performance
- Reduced admin: Automated workflows save time
- Consistent processes: Fair reviews across teams
- Improved retention: Support growth and progression
- Better workforce planning: Skills and capability insight
- Strong governance: Clear audit trails
- Measurable impact: Track outcomes confidently
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 1 7 0 1 5 6 2 4 9 5 2 5 6 0
Contact
BUILDEMPIRE LIMITED
Felicity Fiore
Telephone: 0161 641 2434
Email: commercial@buildempire.co.uk
About your service
- Service categories
-
Applications
Enterprise resource management
- Enterprise performance management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- The service extends Totara Learn as the core learning management system. It integrates social and collaborative learning capabilities formerly delivered through Totara Engage and can be further extended with Totara Perform for performance management, appraisals, feedback and coaching, providing a unified talent experience platform.
- Cloud deployment model
- Public cloud
- Service constraints
- Planned maintenance is scheduled in advance and designed to minimise disruption. The platform is accessed via a modern web browser and does not require specific hardware. Configuration options are agreed during onboarding to meet customer requirements.
- System requirements
- Entirely SaaS based, requires a working supported browser
User support
- Email or online ticketing support
- Yes
- Support response times
- Our support team is available Monday to Friday, 8:00am to 5:00pm (excluding UK Bank Holidays). During these hours, queries can be raised via email or our web portal and are prioritised based on severity. Initial response times range from approximately one hour for high-priority issues to up to 48 hours for lower-priority requests. Response times are measured during core support hours from the point a request is logged. Requests received outside core hours are responded to at the start of the next business day. Out-of-hours support can be provided by prior agreement, subject to additional charges.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Users can initiate real-time conversations with support staff via web chat during support hours, send messages, receive responses, and access relevant help resources. For complex queries, users may be directed to alternative support channels such as email or the support portal.
- Web chat accessibility testing
- N/A
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide responsive support designed to meet the needs of public sector organisations throughout the service lifecycle.
Standard Support is included within the subscription fee and provides access to email and web portal support during core business hours, alongside online guidance and resources for system administrators. Requests are prioritised by severity to ensure timely resolution.
Implementation and Onboarding Support is delivered by dedicated implementation specialists who work with customers to configure the platform, support data migration, and enable a successful go-live. This includes tailored implementation planning and deployment support.
Each customer is assigned a dedicated Implementation Specialist, Project Manager, and Customer Success contact, who act as the primary points of contact. They provide ongoing service oversight, regular reviews, and coordination of support activities, ensuring the platform continues to meet organisational needs.
Offboarding Support is available to support contract exit, including data export, reporting, and platform decommissioning activities.
All standard support and customer success management are included within the subscription cost, with no limits on support requests. Optional out-of-hours or enhanced support can be provided by agreement where required. - Support available to third parties
- No
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
We support customers through a structured onboarding and adoption process designed to ensure a smooth start and long-term success.
Following contract award, customers are supported by a dedicated implementation specialist and project manager who work collaboratively to understand organisational requirements and agree an implementation plan. This typically begins with an initial discovery workshop to confirm scope, configuration, data migration, and timelines.
Implementation specialists support system setup, configuration, and migration activities, while ensuring the platform is ready for go-live. Customers receive online training sessions for administrators and key users, with sessions recorded and supported by user documentation for ongoing reference. Training covers day-to-day administration, reporting, and platform usage.
Once live, customers are supported by a customer success contact who provides ongoing guidance, adoption support, and regular reviews to help maximise value from the service. Optional onsite training or workshops can be provided by agreement where required.
Throughout onboarding, users are guided on how to access support, raise queries, and make effective use of platform features, ensuring a confident and supported transition into live use. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
-
When a contract ends we ensure customers are able to fully extract the data they need.
Initially we would inform them they have a certain amount of time to extract their data themselves should they wish. System administrators have access to all user data held in the system and can extract by their preferred method. They are also able to run any number of system reports and export these from the LMS as a comprehensive record of all system data. - End-of-contract process
-
Upon the completion of the Initial Contract Term, you have the option to extend for an additional period. BuildEmpire will work with you to provide a quote for the subsequent term.
We are committed to facilitating a smooth exit process for customers who request to leave our service. Upon confirmation of a customer's decision to leave, we will send Off-Boarding correspondence via email. This will include details of the products not being renewed, the cessation date of access, steps involved in the Off-Boarding process, and contact information for a designated individual within BuildEmpire for any inquiries.
Our standard off-boarding procedure does not incur any costs for customers. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile experience is optimised for learning, collaboration, and content consumption, including course access, progress tracking, and notifications. The desktop service provides the full administrative and configuration functionality, including advanced reporting, system configuration, and user management.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed through a secure, web-based interface available via modern browsers. It provides a role-based user experience for learners, managers, and administrators, with configurable dashboards, intuitive navigation, and integrated reporting. The interface supports responsive access across devices and can be branded and configured to meet organisational requirements.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Accessibility for the platform is assured through a combination of platform-level accessibility assessment and controlled service configuration.
Totara, as the core platform provider, has undertaken structured accessibility assessment and publishes detailed accessibility documentation and an Accessibility Conformance Report (ACR). This work covers platform support for assistive technologies, including keyboard navigation, screen readers, and accessible interaction patterns, and informs ongoing improvements across releases.
BuildEmpire aligns service delivery to this accessibility framework by deploying and configuring the platform in line with published accessibility guidance. This includes the use of accessible themes and layouts, adherence to supported accessibility features, and guidance to customers on creating accessible learning content and user experiences within the platform. - API
- Yes
- What users can and can't do using the API
-
Our service provides REST-based APIs that allow customers to integrate the platform with other systems and automate key processes.
Using the API, users can programmatically manage users, enrolments, course data, learning records, and synchronise data with external systems such as HR, identity management, and reporting tools. APIs can be used to support initial configuration activities, including user provisioning and data import, as well as ongoing updates such as role changes, enrolments, and status updates.
The API supports secure authentication and follows documented standards to ensure reliable integration. Changes made via the API are subject to the same permission controls and validation rules as changes made through the user interface.
Advanced system configuration, user interface customisation, and some administrative settings are not available via the API and must be managed through the platform’s administrative interface. API usage is intended to complement, not replace, standard platform administration and is designed for integration and automation rather than full system setup. - API documentation
- Yes
- API documentation formats
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
The platform can be customised to reflect organisational structure, branding, and ways of working.
Customers can configure the platform using built-in administrative tools. This includes custom branding and themes, dashboards, learning catalogues, roles and permissions, learning pathways, programmes, certifications, workflows, notifications, and reports. Administrators can tailor user experiences for learners, managers, and administrators without requiring code changes, enabling organisations to adapt the platform as needs evolve.
Configuration can be managed by authorised customer administrators through the service interface and applied across departments, teams, or tenant structures where required.
Where additional flexibility is needed, BuildEmpire provides bespoke development and integration services. This may include custom plugins, workflows, reports, integrations with external systems, or user interface enhancements. Bespoke work is delivered by BuildEmpire’s specialist development team and agreed through structured implementation or change processes.
This combination of self-service configuration and optional bespoke development ensures the service can be adapted to complex public sector requirements while remaining secure and supportable.
Scaling
- Independence of resources
- The service is delivered on a modern, scalable cloud platform designed to provide a consistent experience for all users. Capacity is planned and managed to support growth and peak usage, ensuring reliable performance across organisations. The platform is continuously monitored and maintained to deliver a stable, high-quality service, allowing users to work confidently without being impacted by changes in demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Administrators can access metrics covering user activity, course enrolments, completions, progress, certifications, compliance status, and learning outcomes. Usage data can be viewed at organisational, departmental, or user level to support monitoring and reporting requirements. Reports can be scheduled, filtered, and exported to support internal governance, audits, and management reporting.
The service also provides visibility of platform usage trends, including active users, content engagement, and participation over time. Metrics can be used to identify adoption levels, skills development, and areas requiring intervention.
Access to metrics is role-based, ensuring that only authorised users can view or manage reporting data. - Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Totara
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Totara is GDPR compliant and has the ability for an individual user to export all data linked to them. The format of each item of exported data is equivalent to its storage method in the application's database (e.g. course names/completion dates, or numerical values that represent status). Totara also provides capabilities for export in the application (e.g. Report Builder, Record of Learning). This approach can be useful for an individual wanting, for example, to take their completion data (courses, competencies, certifications) with them to a new employer.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
BuildEmpire commits to a minimum monthly availability of 99.9% for the Service.
The platform is available 24*7, ensuring accessibility to users at any time. However, periodic maintenance, scheduled in advance, results in brief downtime, lasting only a few minutes. These maintenance activities are planned to occur outside of our customer's regular business hours, minimising disruption to users, and advance notification is provided to all customers to ensure seamless transition and minimal impact on operations. - Approach to resilience
- Our service is designed with resilience in mind, hosted in modern cloud environments with accredited providers. Our hosting architecture ensures scalability and robustness. Detailed information on our datacenter setup is available upon request.
- Outage reporting
- We utilise a public dashboard for outage reporting and also send email alerts to affected customers, providing updates on resolution progress.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
We enforce strict access control measures to safeguard our management interfaces and support channels:
- Users are granted access rights and permissions strictly based on their job roles, ensuring they have access only to necessary assets and systems.
- Regular reviews of user access rights are conducted to verify that permissions remain appropriate and in line with job responsibilities.
- Privileged accounts are selectively assigned to individuals requiring them for administrative tasks, minimising potential security risks.
- Management systems incorporate secure logon and authentication mechanisms, such as 2FA (Two-Factor Authentication), to enhance protection against unauthorised access attempts. - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 6 months and 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Our Information Security Management System is anchored in the ISO 27001 framework, ensuring robust cybersecurity and privacy measures. A suite of comprehensive policies outlines information security processes, roles, and responsibilities for all stakeholders.
New team members undergo thorough security training, refreshed annually to ensure continuous awareness and compliance. Oversight is provided by the Senior Management Team, responsible for policy implementation and continuous monitoring. Departmental leaders enforce policy adherence within their teams, ensuring compliance among their staff. Additionally, all employees are responsible for identifying and reporting any non-conformances to the Data Protection Officer.
Biannual audits of the ISMS validate its ongoing effectiveness, providing insights for refinement as needed.
Through these measures, we demonstrate a steadfast commitment to information security, safeguarding our organisation, our clients, and their stakeholders against potential threats. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Our robust change management processes rigorously assess all changes for potential functional and security impacts. Utilising task tracking software ensures adherence to protocols and enables thorough auditing. Prior to deployment to the testing environment, all code changes undergo review by a separate team member. Testing occurs in an isolated environment before deployment to the live environment. Throughout the process, we maintain full transparency and communication with our clients, ensuring they are informed every step of the way.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Our vulnerability management process includes continuous risk assessments through our ISO-27001 ISMS processes. We swiftly address potential threats:
- High-risk vulnerabilities are promptly mitigated upon identification.
- Development and deployment of fixes occur as soon as practicable.
- We maintain subscriptions to industry-leading sources for threat intelligence. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
We ensure the security of our platform environments through vigilant protective monitoring:
- Potential compromises are identified through firewall services monitored by our database partner, AWS. Suspicious activities trigger immediate reports for investigation.
- Our support team conducts regular reviews of client platforms and access event logs. Additionally, clients have access to event logs to monitor changes to platform data.
- Reports of suspicious activity undergo immediate investigation using our ISO 27001 security incident processes. All incidents are thoroughly assessed, resolved, and promptly communicated to clients. - Incident management type
- Supplier-defined controls
- Incident management approach
-
We maintain structured incident management processes to swiftly and effectively address events:
- Our Information Security Management System includes a documented Incident management procedure, enabling systematic handling of all events.
- Users have multiple channels to report incidents, either via email or through the customer's project portal.
- Incidents are diligently recorded in the customer's communication log and undergo thorough investigation. Root cause analysis is conducted, and corrective actions are identified and tracked until completion.
- Incident reports are communicated to customers through the project portal as appropriate, ensuring transparency and timely updates. - Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Available upon request, our demonstration portal allows users to explore platform functionality, including site navigation, course catalogue browsing, and reporting. Contact commercial@buildempire.co.uk for access.
- Link to free trial
- https://buildempire.co.uk/book-demo/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Approachable Certification
- ISO/IEC 27001 accreditation date
- Saturday 12 October 2024
- What the ISO/IEC 27001 doesn’t cover
- Our ISO/IEC 27001 certification does not cover customer-managed environments, end-user devices, or physical premises not operated or controlled by BuildEmpire. Physical security controls are applied proportionately and are limited to the scope of our remote-first operating model and the third-party data centres and cloud infrastructure we use.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 3ef295e4-4b24-43f4-a18f-ddff0afe923f
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 20304a0b-8ceb-49db-a50e-e2f0ebe9ec4e
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-