Orinoco 365: Automated Records Management and Governance tool in Microsoft 365
The easy way to manage records and guest users in Microsoft 365. Orinoco 365 automates the creation of SharePoint Sites, Microsoft Teams and Viva Engage Communities while applying your default retention labels and policies to them, allowing you to take advantage of the rich retention capabilities in Microsoft Purview.
Features
- In place, immutable records management within SharePoint Online and M365
- Expert translation of your file plan into retention labels
- Automated site and team request, configuration and provisioning processes
- File plan and retention schedule definition and integration services
- Dynamic application of SharePoint metadata to your content
- Automatically apply sensitivity labels across your Sites & Teams
- Avoid need for bespoke scripting or development to apply retention
- Harness the value of E5; extend the capabilities of E3
- Significantly improved ability to understand and govern your Sites/Teams
- Automatically apply retention to private channels and new libraries
Benefits
- Records Management by-stealth: automated application of retention
- Enable your staff, by minimising need for ongoing manual classification
- Ensure contextual retention labels are applied to content by default
- Expert-led adoption; work with the leading M365 retention specialists
- Easy onboarding and offboarding process - don't get locked in
- Flexibility to safely extend the service to meet specific objectives
- Improved return from your existing investment in Microsoft 365
- Simplified records management in SharePoint Online / Microsoft Teams
- Quickly align with Microsoft allowing old systems to be decommissioned
- Understand the purpose, ownership and value of your organisation's sites
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 9 3 4 7 9 4 2 5 3 1 2 2 1 4
Contact
INTELOGY LIMITED
Andrew Tomlins
Telephone: 02037473506
Email: info@intelogy.co.uk
About your service
- Service categories
-
Applications
Collaborative
- Team collaboration
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Microsoft 365
- Cloud deployment model
- Public cloud
- Service constraints
- No service constraints are imposed by Orinoco 365. Orinoco 365 can only make use of the capabilities that are provided by your Microsoft 365 licenses.
- System requirements
-
- A licensed Microsoft 365 tenant is required
- Orinoco 365 enterprise app requires your consent
User support
- Email or online ticketing support
- Yes
- Support response times
- All tickets raised with our helpdesk are prioritised by impact and triaged accordingly. Our helpdesk operates during UK-based office hours (Mon-Fri 9-5). Tickets will be responded to in a priority order: P1 tickets within 2 hour; P2 within 4 hours; P3 and above 10 hours. Our service response targets are guidelines for resolution times for incident tickets which Intelogy intend to meet or beat.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Support is provided as a service offering for the accelerator. This covers issue investigation and resolution where appropriate. Provision is also included for feature enhancements and change requests, which may (or may not) be prioritised into the product roadmap for future release. You will be provided with access to a named technical account manager.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- We provide a range of hosting options, which we will discuss with your team. Once determined, the service is rapid to deploy and enable allowing you to get going rapidly. Included within the onboarding service, our team will train you on how to configure your workspace types and templates, complete with how you map you retention to each. We will also provide full user documentation. Further consultancy days can be easily procured to help translate your file plan / retention schedule into our architecture.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- All data remains entirely inside your tenant. This includes all files, all configuration settings and all retention/metadata/sensitivity that has been applied. This makes the offboarding process simple and clean.
- End-of-contract process
- At the end of the contract, if you decide that you don't wish to renew your licences, we will simply turn off your ability to apply default settings to new Teams / Sites. Existing Teams, Sites and all of your content will be unaffected by this process, but new workspaces will not benefit from out default application of retention. There are no additional costs associated with the end of contract process
- Documentation accessibility standard
- WCAG 2.2 A
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- N/a
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 A
- Description of service interface
- The application is based in Orinoco 365's Azure tenant and interacts with your instance of M365 via a service interface (using Microsoft owned APIs). All configuration settings are stored in a SharePoint site in your tenant, which we support you with setting up in the first instance.
- Accessibility standards
- WCAG 2.2 A
- Accessibility testing
- The service interface is entirely via the use of SharePoint based UI so is dependent on the Microsoft levels of accessibility. The workspace request form will be configured with your bespoke questions and can meet any accessibility criteria/standards that is required.
- API
- Yes
- What users can and can't do using the API
- All requests for new workspaces and new guests are submitted into Orinoco 365 through our request APIs. The configuration of each workspace and each guest is determined by a combination of the way your have chosen to configure the Orinoco 365 product and also the information submitted into the request APIs that has been collected in request forms.
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Orinoco 365 is highly customisable, offering significant flexibility to our clients. The product can support the creation of any number of different types of workspace, using any supported combination of SharePoint site, Microsoft 365 Group, Microsoft Team, Viva Engage Community and Planner Plans. Each workspace type can have any combination of different libraries, folders and channels, combined with your selected content types, site columns, views and site/team/library settings. Default metadata values, retention labels, retention policies and sensitivity labels can all be configured. Guest Management can be configured with your departments and approvers. All notification emails can be configured.
Scaling
- Independence of resources
- We use Microsoft Azure to host the application and can scale the performance using standard Cloud scaling controls.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Every workspace request that is submitted into Orinoco 365's API is logged in a list in your tenant. This provides full metrics on every workspace that has been created, along with all request metadata and the URLs of the site and team that has been created.
- Reporting types
- Real-time dashboards
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Records Management Solutions Limited
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
- Other
- Other data at rest protection approach
- All data is stored in Microsoft 365; Orinoco 365 does not store client data.
- Data sanitisation process
- No
- Equipment disposal approach
- In-house destruction process
Data importing and exporting
- Data export approach
- Orinoco 365 does not store data. All data is stored in the client's Microsoft 365 tenant and can be exported via Microsoft's APIs as required.
- Data export formats
- Other
- Other data export formats
- Any format supported by Microsoft 365
- Data import formats
- Other
- Other data import formats
- Any format supported by Microsoft 365
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- We mirror Microsoft Azure's availability guarantee and will directly pass on any refunds provided by Microsoft if service levels fall below their publicly stated levels (99.9%). https://azure.microsoft.com/en-gb/support/legal/sla/summary/
- Approach to resilience
- The Microsoft Azure platform provides a 14 day restore to point in time. Further information is available on request.
- Outage reporting
- The following is available to us: - a public dashboard https://azure.microsoft.com/en-gb/status/ - an API - email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Other
- Other user authentication
- Access to configuration and triage data is controlled by permissions in Microsoft 365. As such, clients have full control to apply any security approaches that are provided by M365, such as MFA etc.
- Access restrictions in management interfaces and support channels
- Access to configuration and triage data is controlled by permissions in Microsoft 365. As such, clients have full control to apply any security approaches that are provided by M365, such as MFA etc.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Other
- Description of management access authentication
- Access to configuration and triage data is controlled by permissions in Microsoft 365. As such, clients have full control to apply any security approaches that are provided by M365, such as MFA etc.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
- We are working towards ISO27001 accreditation so we adopt the "Plan-Do-Check-Act" (PDCA) model, which is applied to all Information Security Management Systems (ISMS). We have a set of policies defined at a Board level and all staff are contracted to follow them. They are available via our internal ISMS and any breeches of policies should be reported to our Operations Director who will decide on the course of action. Our policies are reviewed and adapted annually. All changes are highlighted to staff via internal meetings.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All changes are applied via standard processes. i.e. A set of potential changes are assessed for inclusion in a point release of a new version. Assessment of risk, value to the end users, technical feasibility and complexity are taken into account and changes batched into priorities as a result. Changes are conducted on an internal development environment and are subject to ongoing manual and automated testing. The update is then deployed by an authorised platform administrator to a staging environment, tested and signed off by a product manager, before repeating the process on a production environments.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Intelogy has configured the service through Azure Security Center to have constant monitoring and logging turned on for all nodes (web VMs and databases). Any high priority threats are notified to our platform team instantly and action will be taken if possible and applicable at the soonest opportunity. In addition, customers can access the following public status page: https://azure.microsoft.com/en-gb/status
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Yes, we have a defined process for common events: 5.2 Detection * Identification and reporting of the incident. * Incident details must be captured. * Categorization of incident. * Classify the incident. High, Medium, Low * Identification of stakeholder who all should be involved for managing the incident 5.3 Response * Preventive action of the incident minimize the re-occurrence of the incident * Corrective Action 5.4 Analysis * Data collection * Root Cause Analysis of the incident 5.5 Report * Preventive action of the incident minimize the reoccurrence of the incident * Learning communicated to either whole organisation and stakeholders
- Incident management type
- Supplier-defined controls
- Incident management approach
- Users can report incidents via phone, email and the helpdesk service. Detection * Identification and reporting of the incident. * Incident details must be captured. * Categorization of incident. * Classify the incident. High, Medium, Low * Identification of stakeholder who all should be involved for managing the incident Response * Preventive action of the incident minimize the re-occurrence of the incident * Corrective Action Analysis * Data collection * Root Cause Analysis of the incident Report * Preventive action of the incident minimize the reoccurrence of the incident * Learning communicated to either whole organisation and stakeholders
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- If you meet our qualification criteria, we can offer a free trial for 60 days, for up to 2 predefined templates.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 30%
- Over £5,000,001
- 40%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 94fe1d5d-42c6-4fd1-9e8a-4354344ecdb4
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 2ea592d2-831b-45df-8786-117854e250a0
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-