SSO covers employees but not contractors, partners, or seasonal staff.
Hybrid identity: SAML or OIDC for employees, invited access for contractors, tenant-scoped SSO for partners, all mapped to the same role and access model.
For L&D and HR leads who need training records, role-based access, and reporting connected to their organisation, we build the platform around the work.
Discuss your platformTeams responsible for training completion, role clearance, and manager visibility across employees, contractors, and partners. The platform has to fit the organisation chart, not the other way around.
Financial services, healthcare, safety, and energy organisations where a missing training record is a compliance failure and evidence has to survive an external audit, not just look good in a dashboard.
Companies training external distributors, franchisees, or partners under separate branding, permissions, and reporting boundaries inside one operational platform.
Employees on SSO, contractors on invite links, partners in isolated tenants. One platform, one identity model, and correct access on day one.
Hybrid identity: SAML or OIDC for employees, invited access for contractors, tenant-scoped SSO for partners, all mapped to the same role and access model.
Scheduled or event-driven HRIS sync (Workday, BambooHR, Rippling, HiBob, custom) with role, department, and manager relationships propagated automatically.
Structured evidence: attempts, acknowledgement, expiry, certificates, and material version, queryable and exportable per person, per role, per period.
Immutable audit log spanning training assignments, completions, admin actions, and role changes, with the reporting queries pre-built rather than assembled under pressure.
Role-scoped dashboards: a line manager sees their team; a regional lead sees their region; nobody sees another client's records. Permissions enforced in the data layer, not just the UI.
Multi-tenant partner portals with separate identity, theming, and reporting boundaries, so each partner runs their own space inside one operational platform.
SAML 2.0 and OIDC integration with Okta, Azure AD / Entra ID, Google Workspace, Ping, and custom IdPs. Just-in-time provisioning, group-to-role mapping, and clean deprovisioning when someone leaves.
Workday, BambooHR, Rippling, HiBob, and custom HRIS integrations for people, roles, departments, and manager relationships. Change events flow to training assignments and access rules automatically.
Assignment rules by role, region, and start date; renewal windows; grace periods; auto-escalation; and material versioning, so a policy change is a controlled rollout with an audit trail rather than an email chain.
Immutable, exportable audit log covering training assignments, completions, admin actions, role changes, and evidence access. Pre-built queries for the questions auditors actually ask.
Role-scoped dashboards and scheduled reports for line managers, regional leads, L&D, and compliance. Answers management questions instead of dumping data into a shared drive.
Fine-grained roles and permissions modelled on your organisation: employees, managers, contractors, partners, and administrators, with permissions enforced at the API and data layer, not just the UI.
Multi-tenant workspaces with separate identity, branding, admin, and reporting boundaries. Each partner runs their own space; you keep operational visibility across all of them.
Trace one training requirement from policy to manager report. The handoffs where people email, export, or manually confirm reveal what the first release must solve.
SSO, HRIS, and role modelling proved before the interface gets polished. A beautiful dashboard with the wrong access model is expensive wallpaper.
Pilot with a real department using realistic role changes and completion states. Feedback from actual managers rather than a staged demo.
Access acceptance tests, audit-report validation, operational runbooks, and code plus infrastructure handed over with continued support available on your terms.
Corporate training work moves on a small set of decisions: the identity model (SSO, roles, contractors, partners), which HR system is the source of truth, what compliance evidence has to survive an audit, whether partner or multi-tenant training is in scope, and how much historic record migration is required. We scope the reporting questions before estimating, because reporting is where vague requirements become expensive. Once the plan is specific we quote against it and show the assumptions.
We scope in the open. You see the assumptions, what is excluded, and what would change the estimate. A fixed price without those details is only a delayed surprise.
xAPI
Source: xAPI Spec (ADL)
Managers get an answer they can act on. Learners receive the training that applies to them. The L&D team stops spending the last afternoon of the month turning exports into evidence.
The moving parts are SSO, HRIS connections, compliance evidence, partner training, and migrating historic records. We scope the reporting questions before quoting, because that is where vague requirements get expensive. Every estimate we share is tied to a specific scope, not a marketing range.
Around 8 to 12 weeks for the core, in weekly builds. Identity and role data get proven first, because a polished dashboard with the wrong access model is expensive wallpaper.
That's usually the point. We confirm the identity provider, the systems of record, and the exact sign-in flow during discovery, then place people into the right roles automatically instead of asking a manager to update a group by hand.
We record attempts, acknowledgement, expiry, certificates, and the version of the material a learner saw, so an audit is a report rather than a scramble. Historic records either migrate or move to a retained archive with a clear audit path, decided before cutover.
We will map the real constraint, tell you whether a custom build makes sense, and outline a first release that does not pretend to solve every future problem.
Book a 30-minute call