Skip to main content

Help us improve the Digital Marketplace - send your feedback

JOSKOS SOLUTIONS LIMITED

User Management & Account Provisioning - Lontra

LONTRA provides secure, automated user provisioning for Microsoft 365 and Google Workspace. It synchronises users records, standardises account creation, manages lifecycle changes, and reduces administrative workload. The service improves accuracy, strengthens compliance, and ensures users have the right access at the right time across all client systems.

Features

  • Automated user provisioning across Microsoft 365 and Google Workspace.
  • Real-time MIS data synchronisation for staff and pupils.
  • Automatic class, group, and timetable creation and updates.
  • Identity lifecycle management with instant leaver deactivation.
  • Hybrid cloud support for Azure AD and local AD.

Benefits

  • Reduces admin workload through complete automation of user management tasks.
  • Improves data accuracy with real-time MIS-to-cloud synchronisation.
  • Strengthens security by enforcing consistent permissions across all systems.
  • Accelerates onboarding and leaver processes across every school and Trust.
  • Enhances reliability with unified, Trust-wide identity oversight and control.

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@joskos.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 0 3 4 7 7 4 5 9 9 1 8 1 8 9

Contact

JOSKOS SOLUTIONS LIMITED Tom Singh
Telephone: 07950914002
Email: tenders@joskos.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Education
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes
What software services is the service an extension to
Lontra extends Microsoft 365, Azure AD, Google Workspace, and local Active Directory by automating identity, group, and timetable synchronisation from MIS platforms such as Arbor, Bromcom, SIMS, ScholarPack, and Integris. It also enhances SaaS tools including Jova, Sentry, and InCircle through consistent identity and access management.
Cloud deployment model
  • Public cloud
  • Hybrid cloud
Service constraints
Lontra requires access to the organisation’s MIS, Microsoft 365, Google Workspace, or Active Directory environment to enable synchronisation. Initial setup depends on the availability of API credentials and administrative permissions. Service updates and enhancements are deployed with minimal downtime during planned maintenance windows. Local AD integrations may require a lightweight connector. Some advanced features depend on MIS vendors’ API availability and rate limits.
System requirements
  • Access to MIS API credentials for data synchronisation.
  • Microsoft 365 or Google Workspace administrator permissions enabled.
  • Optional: Local Active Directory connector installed on server.
  • Stable internet connection for continuous synchronisation processes.
  • Valid organisational domain for email and username creation.
  • Approved API access to timetable and group data.
  • Modern browser for administration dashboard access.
  • Secure authentication configured for all integrations.
  • Appropriate role-based permissions for Trust-level oversight.
  • MIS platform configured to allow external data queries.

User support

Email or online ticketing support
Yes
Support response times
We respond to all questions through our service desk within standard business hours, typically within one working hour for priority issues and within four working hours for general enquiries. Weekend and bank holiday responses follow our out-of-hours arrangements, where urgent issues are monitored and addressed, and routine queries are handled on the next working day.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
We have tested our web chat and ticketing interface with common assistive technologies to ensure accessibility. Testing included NVDA and VoiceOver screen readers, keyboard-only navigation, high-contrast mode, and zoom and reflow checks for users with visual impairments. We also reviewed compatibility with speech-to-text tools and browser accessibility extensions. Internal accessibility champions provided feedback on focus order, form labels, and colour contrast. Automated WCAG 2.2 AA checks were completed, and we continue reviewing new features to maintain accessibility for users relying on assistive technologies.
Onsite support
Yes, at extra cost
Support levels
We provide three support levels: Standard, Enhanced, and Premium. Standard support is included within the service cost and provides access to our service desk during business hours, with response and resolution times aligned to our published SLAs. Enhanced support includes extended hours, priority handling, and faster response times for an additional monthly fee. Premium support provides full extended-hours coverage, proactive monitoring, and scheduled technical reviews.
All support requests are managed through our online ticketing system, email, or phone. Each customer is assigned a named technical account manager who oversees onboarding, configuration, and ongoing service performance. Cloud support engineers are available for escalations, integration support, and advanced troubleshooting.
Support costs are transparent and based on the level selected, with pricing provided in the accompanying rate card. We also offer optional onboarding and configuration packages for organisations requiring additional setup assistance or complex integrations.
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
We support users in getting started through a structured onboarding process that includes configuration workshops, access setup, and data validation. Each customer is assigned a technical account manager who guides them through initial configuration, synchronisation rules, and integration with Microsoft 365, Google Workspace, Active Directory, and their chosen MIS platform.
We provide online training sessions for administrators, covering user management, group configuration, timetable synchronisation, dashboard use, and audit features. Step-by-step documentation, video guides, and knowledge articles are available to support ongoing use. Optional onsite training can be arranged where needed.
Our onboarding team validates the first synchronisation cycle with the customer, ensures appropriate permissions are in place, and supports any adjustments during the early stages of deployment. We also offer follow-up check-ins and monitoring to ensure the service is fully embedded and operating as expected.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Users can extract all relevant data at the end of the contract through a structured offboarding process. Administrators can download synchronisation logs, configuration settings, audit records, and user or group data directly from the service interface in standard formats such as CSV, JSON, or PDF. If required, we can provide a full data export via secure transfer, including all current synchronisation mappings, system settings, and event histories.
We support customers throughout the extraction process to ensure that exported data is complete and meets their internal or regulatory requirements. Once extraction is confirmed, all customer data is securely removed from our systems in line with our data retention and deletion policy.
End-of-contract process
At the end of the contract, we provide a structured and fully supported offboarding process. Customers are notified in advance of contract expiry and given guidance on data extraction, system access, and transition planning. Data exports, including configuration settings, synchronisation mappings, audit logs, and user or group information, are included within the contract price and can be downloaded directly or provided securely on request.
Once the customer confirms successful extraction, access to the service is suspended and customer data is securely deleted in line with our retention and deletion policy. Deletion is performed at no additional cost.
If customers require extended access beyond the contract end date, assisted migration support, or bespoke reporting, these services can be arranged as additional chargeable options. We work with customers to ensure continuity and minimise disruption during any transition to an alternative solution.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
No
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service interface is a secure, web-based administration portal accessible through modern browsers. Administrators can view and manage synchronisation status, user records, groups, timetable data, audit logs, and system configuration. The interface provides dashboard reporting, manual sync controls, role-based access, and detailed event visibility. Changes made in the interface are reflected across connected systems according to configured rules.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We have tested the service interface with users who rely on assistive technologies to make sure it is easy to use and accessible. Testing included NVDA and VoiceOver screen readers, keyboard-only navigation, high-contrast settings, and zoom and reflow checks for users with visual impairments. We also checked compatibility with speech-to-text tools and common browser accessibility extensions.
Internal accessibility testers provided feedback on focus order, labels, buttons, and general usability.
API
No
Customisation available
No

Scaling

Independence of resources
We prevent one customer’s activity from affecting others by isolating workloads and scaling resources independently. Each organisation’s sync tasks, data processing, and API calls run in separate queues, so heavy usage in one tenant cannot slow another. The platform automatically scales compute and processing capacity during peak periods, and rate-limit controls stop any single tenant from consuming disproportionate resources. Monitoring alerts us to unusual load so we can adjust capacity quickly. This approach ensures stable, predictable performance for every customer regardless of demand elsewhere on the service.

Analytics

Service usage metrics
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Users can export their data at any time through the administration portal, where synchronisation logs, configuration settings, user and group records, and timetable mappings can be downloaded in standard formats. Exports are available as CSV, JSON, or PDF, depending on the data type. For full data extraction, administrators can request a complete export which is provided securely. All exports are self-service, with optional support available for organisations requiring assistance or complex migration requirements.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We guarantee a minimum availability of 99.9 percent for the Lontra service, excluding scheduled maintenance windows. Availability is monitored continuously and supported by a resilient cloud infrastructure with automated scaling and failover. Any planned maintenance is notified in advance and scheduled outside standard operating hours wherever possible.
Our SLA includes response and resolution times for incident categories, with priority issues addressed immediately and lower-impact issues handled within agreed timeframes. If availability falls below the guaranteed level in any calendar month, customers are eligible for service credits, applied as a percentage reduction on the following billing period.
We continually monitor system performance and uptime, with automated alerts and 24/7 infrastructure monitoring in place to maintain reliability for all users.
Approach to resilience
Available on request
Outage reporting
Due to the nature of the service we are providing, users would not be aware of an outage. If an outage became prolonged, we would notify our users by email

Identity and authentication

User authentication needed
No
Access restrictions in management interfaces and support channels
We restrict access to management interfaces and support channels using layered controls. Administrative consoles are limited to approved IP ranges, VPN connections or trusted network locations. Access is authenticated using SSO or federated identities, supported by MFA for all privileged accounts. Role-based access controls ensure users only see the functions and data required for their role. ACLs are applied across systems, APIs and support tools to prevent unauthorised access. All activity within management interfaces is logged and monitored, and support channels require verified user authentication before any changes, queries or actions are carried out.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
No audit information available
Access to supplier activity audit information
You control when users can access audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We operate a comprehensive Information Security Management System (ISMS) aligned to ISO 27001, which provides the framework for all our security policies, controls and operational processes. Our ISMS is formally certified and audited through both annual surveillance audits by our certification body and regular internal audits led by an independent third-party security consultant.

Our policies cover core areas including access control, data classification and handling, asset management, secure configuration, supplier management, business continuity, incident response, vulnerability management, change control, and staff security screening. These policies define mandatory requirements for all staff and contractors, supported by role-based training and regular compliance checks.

Operationally, our processes include risk assessment and treatment, secure system administration, logging and monitoring, patch and update management, backup and recovery routines, and formal procedures for onboarding, offboarding, and privilege management. All processes follow recognised good practice and are reviewed on a scheduled basis to ensure they remain effective.

We use a security-by-design approach for service delivery, embedding controls throughout the lifecycle from planning through to ongoing operation. Governance is overseen by senior leadership, with risks, incidents, and audit findings tracked through our ISMS improvement cycle to maintain continuous alignment with ISO 27001 requirements.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We use a controlled configuration and change-management process aligned to our internal ISO-based service standards. All service components are tracked throughout their lifecycle in our configuration repository, including version, ownership, change history and deployment status. Any proposed change is logged, risk-assessed and approved through our change-control workflow. As part of this, we explicitly assess potential security impacts, including dependency changes, access implications and data-handling risks. Security-related changes follow an enhanced review and require sign-off from our technical leads. All approved changes are tested in a controlled environment before release to ensure stability and protect service integrity.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We have a Vulnerability Management process that implements the following: Receives information about zero day threats from the National Cyber Security Center; subscribe to newsletters from vendors and used products, in contact with special interest groups; Technical vulnerabilities are handled either using the Incident management process or the Change management process; Patches are tested following the Installation of software on operational systems.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
All devices run our monitoring agent, which continuously checks performance, security status, and early signs of failure. Any anomaly is automatically reported to our service desk, where it is triaged and prioritised. We operate an internal four-hour SLA for initiating remedial action, ensuring issues are addressed promptly. The severity of each incident is assessed as soon as it is detected so that high-priority or service-affecting problems receive an immediate response. This approach allows us to resolve risks early, reduce downtime, and maintain stable, reliable service for users across the estate.
Incident management type
Supplier-defined controls
Incident management approach
We operate a defined Incident Management Process with standard workflows for common events, enabling quick triage and resolution. Users report incidents through our service desk via phone, email, or the ticketing portal, where issues are logged and prioritised. Our engineers gather relevant system logs and evidence, apply a fix, patch, or workaround, and document all actions taken. Each incident is reviewed to determine whether improvements or control changes are needed to prevent recurrence. We provide incident reports on request or for major incidents, summarising root cause, impact, actions taken, and recommended preventative measures. Periodic trend reviews ensure continual improvement.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
2%
Between £250,000 and £500,000
4%
Between £500,001 and £1,000,000
6%
Between £1,000,001 and £2,500,000
8%
Between £2,500,001 and £5,000,000
10%
Over £5,000,001
12%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Citation ISO Certification Limited
ISO/IEC 27001 accreditation date
Thursday 28 March 2024
What the ISO/IEC 27001 doesn’t cover
We are fully covered by ISO27001:2022 and includes all aspects of information security
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Centre for Assessment
ISO 9001 accreditation date
Friday 28 February 2003
What the ISO 9001 doesn’t cover
We are fully covered by ISO 9001:2015
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
6c1e4683-a09c-4f3a-9565-5e0d03893e08
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
6ecf48af-af04-49be-bd9e-3df16ca6910c
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@joskos.com. Tell them what format you need. It will help if you say what assistive technology you use.