Skip to main content

Help us improve the Digital Marketplace - send your feedback

CENTROCOL LIMITED

Myolla Case Management

Myolla-CM is a secure, cloud-based case and membership management system. It streamlines case handling, member engagement, and compliance reporting. Built for public sector efficiency, Myolla-CM enhances transparency, collaboration, and service delivery while meeting UK government digital and data security standards.

Features

  • End‑to‑end case tracking with custom statuses and full audit trail.
  • Automated workflows trigger actions, notifications, escalations, approvals seamlessly.
  • Centralised member records with import, export, custom field support.
  • Online member forms collect data directly into the secure platform.
  • Secure document storage and audit history.
  • Built‑in messaging supports emails and SMS communications to members.
  • Real‑time dashboards with filters, analytics, and exportable reports.
  • Advanced reporting tracks performance, compliance, activity, and case outcomes.
  • Enterprise security features include encryption, backups, and authentication controls.
  • GDPR‑aligned data handling with comprehensive logs and compliance safeguards.

Benefits

  • Track cases effortlessly from creation to resolution in real time.
  • Automate workflows to reduce admin time and manual input errors.
  • Access and update member records securely from any connected device.
  • Send updates via SMS or email directly from the platform.
  • Generate insightful reports instantly to support decisions and compliance checks.
  • Customise forms and fields to match your organisation’s needs.
  • Collaborate across teams with secure notes and status updates.
  • Store documents centrally for quick access and reduced duplication risks.
  • Stay compliant with GDPR through built-in audit and permissions control.

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@centrocol.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

8 8 7 3 2 1 9 7 2 5 4 2 2 0 4

Contact

CENTROCOL LIMITED David Young
Telephone: 07813127362
Email: tenders@centrocol.com

About the service

Service categories
  • Applications
    • Production and operations
      • Service industry and public sector operations
        • Healthcare
        • Education
        • Public Order and Safety
        • Police
        • Defence
        • Social Security Administration
        • Adult Social Care
        • Children's Social Care
        • Other
      • Other operations
        • Other operations
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Planned Maintenance: Myolla-CM schedules routine maintenance outside UK business hours with advance notice.

Browser Compatibility: Optimised for modern browsers (Chrome, Edge, Safari); legacy browsers not supported.

Internet Access Required: Service requires a stable internet connection for full functionality.

Customisation Requests: Subject to scope agreement and may involve additional lead time.
System requirements
  • Modern web browser required: Chrome, Edge, Safari or Firefox supported.
  • Stable internet connection needed for real-time updates and syncing.
  • JavaScript must be enabled for full platform functionality and performance.
  • No additional software licences required to access standard service features.
  • Email access recommended for receiving platform notifications and user updates.
  • Screen resolution 1280x720 or higher for optimal user experience.
  • Mobile access supported via responsive design, no app installation needed.
  • Pop-up blockers should be disabled for document preview functionality.
  • Single Sign-On available. flexible by organisation

User support

Email or online ticketing support
Yes
Support response times
We offer email and ticket-based support during UK business hours.
Standard Response Time: Within 4 business hours (Monday to Friday, 9am–5pm). Weekend and Bank Holidays: Responses may be slower, typically within 12 hours.

Priority Issues: Critical service issues are escalated for faster resolution.

Buyers can request enhanced SLAs or weekend support as part of onboarding.
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
AI chatbot
No
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
Use compliant webchat supplier, undertake our own accessibility testing with each merchant implementation with agreed assistive technology users.
Onsite support
Yes, at extra cost
Support levels
Myolla-CM provides three tiers of support to match client needs:

1. Standard Support (Included)
Email and ticket-based support (Mon–Fri, 9am–5pm UK time)
Response within 4 business hours
Platform updates and incident management
Access to knowledge base and onboarding guides
Cost: Included in subscription

2. Enhanced Support
All Standard Support features
Priority response (within 2 hours)
Quarterly service review and usage reporting
Access to feature roadmap consultations
Phone support
Cost: From £1000/month (based on organisation size)

3. Premium Support
All Enhanced Support features
Named Technical Account Manager (TAM)
Customised onboarding, training, and workflow support
Cost: Custom pricing (based on scope and SLA)
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We support new users with a structured onboarding process designed to ensure a smooth transition to Myolla-CM. Each client is assigned an onboarding lead who works closely with your team to understand your organisational structure, data requirements, and workflow needs.

The onboarding process typically includes:

Initial setup workshops to define case types, member fields, and user roles.

System labeling (field names etc.) can be customised to reflect an organisation's terminology.

Data import support, including secure migration of member records and case history.

Configuration assistance to customise forms, workflows, notifications, and branding.

User training sessions, delivered remotely or in person, tailored by role

Access to our support hub, with how-to guides, videos, and documentation.

Myolla-CM's interface is intuitive and designed for minimal training time. Most users can begin navigating the platform with confidence after a short orientation. For administrators and power users, we provide more in-depth configuration training and continued support as needed.

We also offer optional onboarding extras such as bulk form design, process reviews, and integration planning. Our goal is to get each organisation fully operational within a few weeks, depending on scope and readiness.

Ongoing support continues post-launch, ensuring a successful rollout and adoption across your team.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
  • Other
Other documentation formats
How to videos (MP4 or similar)
Documentation accessibility standard
WCAG 2.2 AA
End-of-contract data extraction
Custom data extraction support is available upon request. All data extraction requests are processed securely, in line with GDPR and information governance policies. Myolla-CM provides guidance and assistance throughout the offboarding process to ensure a smooth and compliant transition.
End-of-contract process
At the end of the contract, Myolla-CM follows a secure and transparent offboarding process:

Notice & Confirmation: We confirm contract end dates and offboarding preferences with the client.

Data Access & Export: Users retain access for 30 days post-contract to report and export all data using built-in reporting. We assist with exports if needed.

Account Closure: After data extraction, all user access is revoked and data is securely destroyed, following GDPR and retention policies.

Included in Contract Price:

Access to self-service reporting and data export tools.
Secure storage of data for 30 days post-contract
Final export of customer dataset

Additional Costs (if required):

Extended data retention beyond 30 days
Assisted migration or integration support to another platform

We ensure all client data is handled with care and provide documentation to support a compliant and stress-free contract closeout.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Myolla-CM has been designed to work on mobile devices.

Differences Between Mobile and Desktop Service:

Myolla-CM uses a responsive web design, ensuring smooth access via browsers on smartphones and tablets—no app download required.

All features, including case updates, member lookups, and messaging, are available.

Some admin functions (e.g., advanced reporting or configuration settings) are best viewed on desktop for full usability.

The mobile experience is optimised for quick access, case updates, and field use.
Service interface
Yes
Description of service interface
Myolla-CM provides a user-friendly web-based service interface.

It is accessible via modern browsers on desktop and mobile devices. The interface supports secure login, role-based views, and access to all features including case management, member records, messaging, reporting, and administration tools.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We regularly conduct formal interface testing with users of assistive technology.

During onboarding, we collaborate closely with each organisation to test the platform with agreed user groups, including those using assistive tools. This ensures that accessibility needs are addressed in real-world environments and allows us to make tailored adjustments where required. We are committed to ongoing improvement and welcome user feedback to enhance accessibility for all.
User support accessibility
WCAG 2.2 AA
API
No
Customisation available
Yes
Description of customisation
What Can Be Customised:
Reference data including: Case types, categories, and workflows
Member data fields and segmentation
Notifications (email/SMS) and escalation rules
User roles, permissions, and access levels
Branding: logos
Reports, dashboards, and export formats
Online Forms

How Users Can Customise:
Via the admin interface.
Through guided onboarding with our support team
By submitting configuration requests (for more complex needs)

Who Can Customise:
Platform administrators and users with customisation permissions
Myolla support team (for advanced or restricted changes)

Scaling

Independence of resources
Myolla-CM is built on a scalable cloud infrastructure using load balancing to ensure consistent performance across all clients. Each organisation operates within logically isolated databases, which means user data is kept completely separate from that of other organisations.

We use multi-tenant architecture with auto-scaling, which guarantees that heavy usage by one organisation does not degrade the experience for others. Performance is actively monitored, and we allocate additional resources automatically as needed to maintain service levels.

This approach ensures every user benefits from high availability, reliability, and consistent performance - regardless of demand elsewhere on the platform.

Analytics

Service usage metrics
Yes
Metrics types
Myolla-CM can provide service usage metrics such as active users, logins, and key case management actions (case creation, updates, closures, assignments). Audit logs capture user actions for transparency and compliance. Service performance metrics include response times, error rates, and uptime monitoring. Volume metrics such as storage used and communication volumes (emails/SMS) are also available.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
Data sanitisation process
Yes
Data sanitisation type
Data Erasure
Equipment disposal approach
In-house destruction process

Data importing and exporting

Data export approach
Data Export Approach

Users can export their data from Myolla using built-in tools available to administrators. Exports are self-service, secure, and can be performed at any time. Exports include:

Myolla-CM provides a flexible reporting interface which includes the ability to export all report results to CSV

Audit logs and activity histories upon request

Advanced exports can be provided on request (additional cost).
Data export formats
CSV
Data import formats
  • CSV
  • ODF
  • Other

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Myolla-CM aim to provide 99.9% availability as part of its standard service level agreement (SLA), excluding scheduled maintenance. This equates to less than 9 hours of unplanned downtime annually.

Service Level Commitments:
Target Uptime: 99.9% monthly uptime
Monitoring: 24/7 system monitoring and automated alerts
Scheduled Maintenance: Performed outside UK business hours with prior notice.
Approach to resilience
Approach to Resilience

Myolla-CM is architected for high availability and fault tolerance across all service layers. Our cloud infrastructure is provided by Microsoft Azure, allowing Myolla-CM to leverage the resilience of the public cloud.
Outage reporting
Myolla-CM reports service outages through the following channels:

Email Alerts: Affected clients receive immediate notifications about outages, status updates, and resolution progress.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Strict access controls across all administrative interfaces and support channels to ensure data security and compliance:
Management Interfaces:
Only authorised users can access admin features based on their assigned permissions.

Audit Logging: All actions within admin panels are recorded and monitored.

Least Privilege Principle: Users are granted only the access necessary for their responsibilities.

Support Channels:Authenticated Support Requests: Only verified organisation contacts can request support involving sensitive data.

Access Approval Workflow: Temporary support access is granted only with client consent.

Secure Communication: Support interactions are conducted through encrypted channels and logged.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users receive audit information on a regular basis
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Software Security Code of Practice
Yes
Security governance certified
No
Security governance approach
Myolla-CM complies with the Software Security Code of Practice and ISO/IEC 27001 by embedding security across its development and operational processes. We follow secure-by-design principles, conduct regular threat modelling, code reviews, and use automated testing and vulnerability scanning tools. Role-based access controls, multi-factor authentication, and secure session management protect user access.

Our ISO 27001-aligned Information Security Management System governs access control, risk management, incident response, and business continuity. Staff receive regular security training, and policies are continuously reviewed.

Regular audits and improvement cycles ensure we maintain high security and compliance standards, meeting UK government expectations for cloud-based software services.
Information security policies and processes
Myolla-CM follows strict information security policies aligned with ISO/IEC 27001 and UK government best practices. Key components include:

Core Policies:
Data Protection and Privacy (GDPR-aligned)
Access Control and User Management
Incident Response and Breach Notification
Secure Development and Change Management
Business Continuity and Disaster Recovery
Third-Party Risk Management

Governance and Reporting Structure:
A Designated Security Lead oversees policy implementation and compliance.
Security responsibilities are embedded into all teams, including development, support, and operations.
Regular security audits and risk assessments are conducted.
Staff undergo mandatory security awareness and data protection training.
Incidents or breaches are escalated to senior management and, if required, reported to regulators and affected clients.

Enforcement and Review:
Policies are reviewed at least annually or following significant incidents/changes.
Compliance is enforced through automated controls, audits, and disciplinary procedures if necessary.
Clients are notified of relevant policy updates that may affect their data or service usage.

Our goal is to ensure a proactive and accountable security posture across the entire organisation.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Myolla-CM uses a structured change management process aligned with CSA CCM and SSAE-18 standards.

All components are tracked via version control. Changes undergo formal review, with security assessments for all updates. High-risk changes are approved by technical and security leads. Changes are staged across development, testing, and production environments. Rollback plans are in place for critical updates, and post-deployment monitoring ensures issues are quickly identified. This approach ensures security, traceability, and stability throughout the service lifecycle while minimising operational risk.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Myolla-CM uses a proactive vulnerability management process aligned with CSA CCM and SSAE-18 standards. Threats are assessed using automated vulnerability scans, internal reviews, and severity ratings based on risk and impact. Critical vulnerabilities are patched within 24–72 hours of the fix being available, while others follow a risk-based deployment schedule. Emergency patches can be applied immediately with rollback plans. Threat intelligence is sourced from the NCSC, NIST CVE database, vendor advisories, and independent security audits. This ensures fast detection and resolution of risks, maintaining the security and integrity of the service environment.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Myolla-CM uses real-time monitoring tools and log analysis to detect potential compromises, such as unusual login activity, privilege escalations, or data access anomalies. Alerts are triggered through automated systems and reviewed by our security team. When a potential compromise is identified, we initiate a defined incident response process that includes containment, investigation, and remediation. Critical incidents are triaged and acted on within 1 hour, with full resolution efforts continuing until closure. Impacted clients are notified promptly, and post-incident reviews are conducted to prevent recurrence. This proactive approach ensures quick detection and response to threats, maintaining service integrity and client trust.
Incident management type
Supplier-defined controls
Post-quantum cryptography secure
No
Incident management approach
Myolla-CM maintains a structured incident management process with pre-defined procedures for common events such as service disruption, unauthorised access, and data loss. Users can report incidents through our support channels, where each is logged, triaged, and escalated based on severity. Our team investigates, mitigates, and resolves incidents while maintaining communication with affected clients. For significant incidents, we issue a formal incident report outlining the cause, impact, actions taken, and preventive measures. Reports are typically provided within five business days of resolution. This ensures transparency, accountability, and continual improvement of service reliability and security.

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
8%
Between £1,000,001 and £2,500,000
10%
Between £2,500,001 and £5,000,000
12%
Over £5,000,001
15%

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
No

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

  • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
  • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
  • Ensuring new workers are informed of their right to join a trade union
  • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
  • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
  • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors

Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

  • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering

Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

  • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
  • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
Mission: Make Britain a clean energy superpower

To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

  • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
Mission: Break down barriers to opportunity

By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

Policy Outcome 6: Employment and training: For those who face barriers to employment

  • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
  • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
  • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce

Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

  • Understanding of the issues affecting the development of new skills by target cohort
  • Understanding of issues relating to entering the contract workforce
Mission: Build an NHS fit for the future

That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

  • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@centrocol.com. Tell them what format you need. It will help if you say what assistive technology you use.