CRBhub Coaching and Mentoring Management System
Match, manage, evaluate and report, with our secure and intuitive CRBhub coaching and mentoring management system. Delivering ROI and great outcomes for our customers' coaching and mentoring programmes since 2012.
Features
- Intelligent automatic matching of coachees to coaches
- Comprehensive self-service relationship management
- Evaluation questionnaires automatically triggered at defined points throughout the relationship
- Automated email prompts when action is due from a participant
- Activity recording and reporting for coaches / mentors
- Full oversight and control for system administrators
- Suite of real-time reports for system administrators
- Detailed CSV downloads of data for offline analysis
- Contextual help and signposting available throughout the system
Benefits
- Enables quick and optimal matching between coaches and coachees
- Provides the ability for parties to easily manage their relationships
- Dramatically reduces admin time by automating action prompts
- Allows administrators to demonstrate ROI on the system/programme
- Saves time by aggregating activity for administrative reporting
- Service is customisable and extensible to meet the organisation's requirements
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 5 1 6 3 1 9 5 0 4 5 5 2 1 1
Contact
CRB ASSOCIATES LTD
Corin Wakeford
Telephone: 01582 326414
Email: sales@crb-associates.com
About your service
- Service categories
-
Applications
Enterprise resource management
Human capital management
- Talent Management Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- System scope covers up to 10,000 users in a single pool of participants within the commissioning customer's organisation, unless otherwise agreed. Occasionally maintenance windows may need to be scheduled, which will be agreed with the customer in advance and scheduled out of UK office hours where possible.
- System requirements
- Modern, standards-compliant web browser
User support
- Email or online ticketing support
- Yes
- Support response times
- Guaranteed within 1 business day (UK business hours), but usually more quickly than this.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
- Unlimited support for system administrators via email, telephone or web helpdesk is included in the cost. Support for end users is not included as standard, but administrators may escalate end user queries if required. Support queries will be escalated by account managers to technical / hosting support or senior management if required.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- Training sessions for system administrators are provided via Teams. Online documentation including contextual help is also provided for both administrators and end users. System administrators may also request support / assistance via email, telephone or online helpdesk at any time.
- Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Administrators may download the majority of user and relationship data in CSV format at any time on demand. We undertake to provide any other required data for migration in CSV or other machine-readable format at the end of contract.
- End-of-contract process
- We work with the customer to ensure an orderly offboarding, aligning with the customer's schedule for migration where this is reasonably possible. All relevant data will be provided; any additional manipulation or extension of the service after the contract end date may incur additional cost.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Display format and tools (e.g. navigation) are optimised for the screen size currently in use, and some features (e.g. tabular reports) are naturally more suited to a larger screen size for display. But essentially, all available system functionality is accessible to a user whether they choose to use a mobile or a larger screen device.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service is accessed via a web interface, through any modern standards-compliant browser. The service interface is determined by the role of the accessing user, e.g. administrator, supplier user (e.g. coach), client user (e.g. coachee), although a user may hold multiple roles and may switch between the interfaces for these.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Testing by assistive technology users has allowed us to fine-tune certain elements of our interface, e.g. where JavaScript sliders are used, these are automatically rendered as accessible radio buttons for users who are using assistive technology.
- API
- No
- Customisation available
- Yes
- Description of customisation
- The system is designed to be highly customisable and extensible, to meet the requirements of a customer's coaching and mentoring programmes. Customisation and extensions of system scope may be commissioned at the point of implementation, and also throughout the duration of the licence term. Any proposed customisations will be scoped, specified and costed in advance, allowing the customer to make an informed decision on whether to proceed.
Scaling
- Independence of resources
- Customers' systems are segregated by virtual server, so resources are not able to be disproportionately utilised by a single customer.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The CRBhub system provides a full suite of reports, from management reporting dashboard-style summaries, to detailed tabular usage reports, aggregated trend reporting, and full CSV downloads for offline analysis by administrators.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users may export certain aspects of their data in PDF format, e.g. a relationship summary containing sessions, journal entries, private notes and evaluation responses. Administrative users may export reports in PDF and/or CSV format selectively, and may also download full user and relationship data in CSV format.
- Data export formats
-
- CSV
- Other
- Other data export formats
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.5% annual uptime guaranteed, excepting scheduled maintenance and problems with general internet connectivity which are outside of our control. Failure on our part to meet this service level will trigger a refund to the customer of £50 per day or part.
- Approach to resilience
- All datacentres are ISO-27001 certified, with the associated resiliance. Encrypted offsite backups are taken daily. Further information is available on request.
- Outage reporting
- Outages are reported to customers via email.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Administrator accounts as secured with multi-factor authentication. Support requires a separate login on our helpdesk system.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials and IASME Cyber Assurance (GDPR)
- Information security policies and processes
- Our security policies are company confidential, but are annually reviewed to ensure compliance with Cyber Essentials and IASME Cyber Assurance (GDPR) requirements.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- System components provided are those of the latest release, which have undergone rigorous manual testing. Updated components or changes made at the request of the customer are published only after similarly rigorous manual testing.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Firewall and intrusion detection services on our servers block and report exploitation attempts automatically. Vulnerability scans on the hosting surface are carried out quarterly. Threat information is provided by the software, which is kept regularly patched.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- We provide a firewall and intrusion detection services on our servers as standard, whereby exploitation attempts are blocked and reported automatically. This includes automated DDoS protection.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Users are encouraged to report incidents via web ticket, email or telephone. Our security policy includes a procedure for assessing and dealing with reported incidents, which begins with assessing the level of threat. Appropriate and proportionate measures are then taken, including restriction of access if a genuine exploitable threat has been identified.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 10%
- Between £500,001 and £1,000,000
- 15%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 20%
- Over £5,000,001
- 25%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- E9132e11-97f2-41da-b5d1-01ddfbad8e6d
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
- IASME Cyber Assurance (GDPR) Level 1
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
-