User Management & Account Provisioning - Lontra
LONTRA provides secure, automated user provisioning for Microsoft 365 and Google Workspace. It synchronises users records, standardises account creation, manages lifecycle changes, and reduces administrative workload. The service improves accuracy, strengthens compliance, and ensures users have the right access at the right time across all client systems.
Features
- Automated user provisioning across Microsoft 365 and Google Workspace.
- Real-time MIS data synchronisation for staff and pupils.
- Automatic class, group, and timetable creation and updates.
- Identity lifecycle management with instant leaver deactivation.
- Hybrid cloud support for Azure AD and local AD.
Benefits
- Reduces admin workload through complete automation of user management tasks.
- Improves data accuracy with real-time MIS-to-cloud synchronisation.
- Strengthens security by enforcing consistent permissions across all systems.
- Accelerates onboarding and leaver processes across every school and Trust.
- Enhances reliability with unified, Trust-wide identity oversight and control.
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 0 3 4 7 7 4 5 9 9 1 8 1 8 9
Contact
JOSKOS SOLUTIONS LIMITED
Tom Singh
Telephone: 07950914002
Email: tenders@joskos.com
About your service
- Service categories
-
Applications
Production and operations
Service industry and public sector operations
- Education
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Lontra extends Microsoft 365, Azure AD, Google Workspace, and local Active Directory by automating identity, group, and timetable synchronisation from MIS platforms such as Arbor, Bromcom, SIMS, ScholarPack, and Integris. It also enhances SaaS tools including Jova, Sentry, and InCircle through consistent identity and access management.
- Cloud deployment model
-
- Public cloud
- Hybrid cloud
- Service constraints
- Lontra requires access to the organisation’s MIS, Microsoft 365, Google Workspace, or Active Directory environment to enable synchronisation. Initial setup depends on the availability of API credentials and administrative permissions. Service updates and enhancements are deployed with minimal downtime during planned maintenance windows. Local AD integrations may require a lightweight connector. Some advanced features depend on MIS vendors’ API availability and rate limits.
- System requirements
-
- Access to MIS API credentials for data synchronisation.
- Microsoft 365 or Google Workspace administrator permissions enabled.
- Optional: Local Active Directory connector installed on server.
- Stable internet connection for continuous synchronisation processes.
- Valid organisational domain for email and username creation.
- Approved API access to timetable and group data.
- Modern browser for administration dashboard access.
- Secure authentication configured for all integrations.
- Appropriate role-based permissions for Trust-level oversight.
- MIS platform configured to allow external data queries.
User support
- Email or online ticketing support
- Yes
- Support response times
- We respond to all questions through our service desk within standard business hours, typically within one working hour for priority issues and within four working hours for general enquiries. Weekend and bank holiday responses follow our out-of-hours arrangements, where urgent issues are monitored and addressed, and routine queries are handled on the next working day.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- WCAG 2.2 AA
- Web chat accessibility testing
- We have tested our web chat and ticketing interface with common assistive technologies to ensure accessibility. Testing included NVDA and VoiceOver screen readers, keyboard-only navigation, high-contrast mode, and zoom and reflow checks for users with visual impairments. We also reviewed compatibility with speech-to-text tools and browser accessibility extensions. Internal accessibility champions provided feedback on focus order, form labels, and colour contrast. Automated WCAG 2.2 AA checks were completed, and we continue reviewing new features to maintain accessibility for users relying on assistive technologies.
- Onsite support
- Yes, at extra cost
- Support levels
-
We provide three support levels: Standard, Enhanced, and Premium. Standard support is included within the service cost and provides access to our service desk during business hours, with response and resolution times aligned to our published SLAs. Enhanced support includes extended hours, priority handling, and faster response times for an additional monthly fee. Premium support provides full extended-hours coverage, proactive monitoring, and scheduled technical reviews.
All support requests are managed through our online ticketing system, email, or phone. Each customer is assigned a named technical account manager who oversees onboarding, configuration, and ongoing service performance. Cloud support engineers are available for escalations, integration support, and advanced troubleshooting.
Support costs are transparent and based on the level selected, with pricing provided in the accompanying rate card. We also offer optional onboarding and configuration packages for organisations requiring additional setup assistance or complex integrations. - Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
-
We support users in getting started through a structured onboarding process that includes configuration workshops, access setup, and data validation. Each customer is assigned a technical account manager who guides them through initial configuration, synchronisation rules, and integration with Microsoft 365, Google Workspace, Active Directory, and their chosen MIS platform.
We provide online training sessions for administrators, covering user management, group configuration, timetable synchronisation, dashboard use, and audit features. Step-by-step documentation, video guides, and knowledge articles are available to support ongoing use. Optional onsite training can be arranged where needed.
Our onboarding team validates the first synchronisation cycle with the customer, ensures appropriate permissions are in place, and supports any adjustments during the early stages of deployment. We also offer follow-up check-ins and monitoring to ensure the service is fully embedded and operating as expected. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Users can extract all relevant data at the end of the contract through a structured offboarding process. Administrators can download synchronisation logs, configuration settings, audit records, and user or group data directly from the service interface in standard formats such as CSV, JSON, or PDF. If required, we can provide a full data export via secure transfer, including all current synchronisation mappings, system settings, and event histories.
We support customers throughout the extraction process to ensure that exported data is complete and meets their internal or regulatory requirements. Once extraction is confirmed, all customer data is securely removed from our systems in line with our data retention and deletion policy. - End-of-contract process
-
At the end of the contract, we provide a structured and fully supported offboarding process. Customers are notified in advance of contract expiry and given guidance on data extraction, system access, and transition planning. Data exports, including configuration settings, synchronisation mappings, audit logs, and user or group information, are included within the contract price and can be downloaded directly or provided securely on request.
Once the customer confirms successful extraction, access to the service is suspended and customer data is securely deleted in line with our retention and deletion policy. Deletion is performed at no additional cost.
If customers require extended access beyond the contract end date, assisted migration support, or bespoke reporting, these services can be arranged as additional chargeable options. We work with customers to ensure continuity and minimise disruption during any transition to an alternative solution. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- No
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service interface is a secure, web-based administration portal accessible through modern browsers. Administrators can view and manage synchronisation status, user records, groups, timetable data, audit logs, and system configuration. The interface provides dashboard reporting, manual sync controls, role-based access, and detailed event visibility. Changes made in the interface are reflected across connected systems according to configured rules.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
We have tested the service interface with users who rely on assistive technologies to make sure it is easy to use and accessible. Testing included NVDA and VoiceOver screen readers, keyboard-only navigation, high-contrast settings, and zoom and reflow checks for users with visual impairments. We also checked compatibility with speech-to-text tools and common browser accessibility extensions.
Internal accessibility testers provided feedback on focus order, labels, buttons, and general usability. - API
- No
- Customisation available
- No
Scaling
- Independence of resources
- We prevent one customer’s activity from affecting others by isolating workloads and scaling resources independently. Each organisation’s sync tasks, data processing, and API calls run in separate queues, so heavy usage in one tenant cannot slow another. The platform automatically scales compute and processing capacity during peak periods, and rate-limit controls stop any single tenant from consuming disproportionate resources. Monitoring alerts us to unusual load so we can adjust capacity quickly. This approach ensures stable, predictable performance for every customer regardless of demand elsewhere on the service.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
- Users can export their data at any time through the administration portal, where synchronisation logs, configuration settings, user and group records, and timetable mappings can be downloaded in standard formats. Exports are available as CSV, JSON, or PDF, depending on the data type. For full data extraction, administrators can request a complete export which is provided securely. All exports are self-service, with optional support available for organisations requiring assistance or complex migration requirements.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
We guarantee a minimum availability of 99.9 percent for the Lontra service, excluding scheduled maintenance windows. Availability is monitored continuously and supported by a resilient cloud infrastructure with automated scaling and failover. Any planned maintenance is notified in advance and scheduled outside standard operating hours wherever possible.
Our SLA includes response and resolution times for incident categories, with priority issues addressed immediately and lower-impact issues handled within agreed timeframes. If availability falls below the guaranteed level in any calendar month, customers are eligible for service credits, applied as a percentage reduction on the following billing period.
We continually monitor system performance and uptime, with automated alerts and 24/7 infrastructure monitoring in place to maintain reliability for all users. - Approach to resilience
- Available on request
- Outage reporting
- Due to the nature of the service we are providing, users would not be aware of an outage. If an outage became prolonged, we would notify our users by email
Identity and authentication
- User authentication needed
- No
- Access restrictions in management interfaces and support channels
- We restrict access to management interfaces and support channels using layered controls. Administrative consoles are limited to approved IP ranges, VPN connections or trusted network locations. Access is authenticated using SSO or federated identities, supported by MFA for all privileged accounts. Role-based access controls ensure users only see the functions and data required for their role. ACLs are applied across systems, APIs and support tools to prevent unauthorised access. All activity within management interfaces is logged and monitored, and support channels require verified user authentication before any changes, queries or actions are carried out.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- You control when users can access audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
We operate a comprehensive Information Security Management System (ISMS) aligned to ISO 27001, which provides the framework for all our security policies, controls and operational processes. Our ISMS is formally certified and audited through both annual surveillance audits by our certification body and regular internal audits led by an independent third-party security consultant.
Our policies cover core areas including access control, data classification and handling, asset management, secure configuration, supplier management, business continuity, incident response, vulnerability management, change control, and staff security screening. These policies define mandatory requirements for all staff and contractors, supported by role-based training and regular compliance checks.
Operationally, our processes include risk assessment and treatment, secure system administration, logging and monitoring, patch and update management, backup and recovery routines, and formal procedures for onboarding, offboarding, and privilege management. All processes follow recognised good practice and are reviewed on a scheduled basis to ensure they remain effective.
We use a security-by-design approach for service delivery, embedding controls throughout the lifecycle from planning through to ongoing operation. Governance is overseen by senior leadership, with risks, incidents, and audit findings tracked through our ISMS improvement cycle to maintain continuous alignment with ISO 27001 requirements. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- We use a controlled configuration and change-management process aligned to our internal ISO-based service standards. All service components are tracked throughout their lifecycle in our configuration repository, including version, ownership, change history and deployment status. Any proposed change is logged, risk-assessed and approved through our change-control workflow. As part of this, we explicitly assess potential security impacts, including dependency changes, access implications and data-handling risks. Security-related changes follow an enhanced review and require sign-off from our technical leads. All approved changes are tested in a controlled environment before release to ensure stability and protect service integrity.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- We have a Vulnerability Management process that implements the following: Receives information about zero day threats from the National Cyber Security Center; subscribe to newsletters from vendors and used products, in contact with special interest groups; Technical vulnerabilities are handled either using the Incident management process or the Change management process; Patches are tested following the Installation of software on operational systems.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- All devices run our monitoring agent, which continuously checks performance, security status, and early signs of failure. Any anomaly is automatically reported to our service desk, where it is triaged and prioritised. We operate an internal four-hour SLA for initiating remedial action, ensuring issues are addressed promptly. The severity of each incident is assessed as soon as it is detected so that high-priority or service-affecting problems receive an immediate response. This approach allows us to resolve risks early, reduce downtime, and maintain stable, reliable service for users across the estate.
- Incident management type
- Supplier-defined controls
- Incident management approach
- We operate a defined Incident Management Process with standard workflows for common events, enabling quick triage and resolution. Users report incidents through our service desk via phone, email, or the ticketing portal, where issues are logged and prioritised. Our engineers gather relevant system logs and evidence, apply a fix, patch, or workaround, and document all actions taken. Each incident is reviewed to determine whether improvements or control changes are needed to prevent recurrence. We provide incident reports on request or for major incidents, summarising root cause, impact, actions taken, and recommended preventative measures. Periodic trend reviews ensure continual improvement.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 2%
- Between £250,000 and £500,000
- 4%
- Between £500,001 and £1,000,000
- 6%
- Between £1,000,001 and £2,500,000
- 8%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 12%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Citation ISO Certification Limited
- ISO/IEC 27001 accreditation date
- Thursday 28 March 2024
- What the ISO/IEC 27001 doesn’t cover
- We are fully covered by ISO27001:2022 and includes all aspects of information security
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Centre for Assessment
- ISO 9001 accreditation date
- Friday 28 February 2003
- What the ISO 9001 doesn’t cover
- We are fully covered by ISO 9001:2015
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 6c1e4683-a09c-4f3a-9565-5e0d03893e08
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 6ecf48af-af04-49be-bd9e-3df16ca6910c
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
-