CMS customer guide

Your Strata support portal

Strata is where you tell CMS about starters, leavers and app access, report anything that isn't working, and see where everything has got to. This guide walks through the everyday jobs, one at a time.

Go to https://strata.cms-group.net Sign in with your normal work Microsoft account, the one you use for email. There is no new password to remember. Bookmark the address so you can come straight back.

How do I sign in?

  1. Open strata.cms-group.net in your web browser.
  2. Click Sign in with Microsoft.
  3. Choose your work Microsoft account. If you're already signed in to Outlook or Teams, you may go straight in.

Nothing happens when you click? Your browser may have blocked the pop-up. Click Sign in in this window underneath the button instead.

The Strata sign-in page with a red Sign in with Microsoft button
The sign-in page.

How do I find my way around?

You start on Tickets. Above your ticket list it shows what needs you today: tickets and requests waiting for your answer, the starters, leavers and access changes you've asked for, and your recent tickets. The two buttons at the top right let you Report an incident or Log a ticket straight away.

The menu has these sections:

On a phone? The menu runs along the top of the screen. Swipe it sideways to see every section.

The Tickets page: Needs you, Your requests and Recent tickets above the ticket list
Tickets. Example data.

How do I set up a new starter?

Every staff request (starters, leavers, app access and more) begins at Raise a request.

Pick what you need

  1. Click Raise a request in the menu.
  2. Click Someone is starting. You can also type what you need in the search box, for example "new starter", "signature" or "VPN".
Raise a request: a grid of cards such as Someone is starting, Someone is leaving and Access to an app
Raise a request. Pick a card to start. Example data.

About them

  1. Enter their first name, last name and first day.
  2. If someone with that name already exists, the portal tells you. Carry on if it's a different person; they'll get a different email address.
  3. Click Next. Not ready? Click Save for later and come back to it.
Starter step 1: first name, last name, a warning that a person with that name already exists, and first day
Step 1: about them. Example data.

Their job

  1. Choose where they'll work and their job. Picking a job fills in the usual apps, groups and equipment for that role. You can change anything.
  2. Check the job title. It appears in their email signature and the staff directory.
  3. Start typing their manager's name and pick them from the list.
Starter step 2: site, job template, job title, department and manager search
Step 2: their job. Example data.

Check and send

  1. Read the summary. It says when they start, who their manager is, and who will be asked to approve it.
  2. Click Send request.

What happens next. You'll see a confirmation and the request appears under Your requests. If your company needs an approval, the approver is asked first. Once it's approved, CMS sets up the account and the login details come to you, ready for their first day.

Check and send: a plain-English summary and a table of the starter's details, with a Send request button
Last step: check and send. Example data.

How do I close a leaver's account?

  1. On Raise a request, click Someone is leaving.
  2. Start typing their name and pick them from the list.
  3. Check their site. We fill it in where we can, and it decides who approves the request.
  4. Enter their last working day. The green box confirms exactly when their account closes: 23:59 on that day.
  5. Tell us what to do with their email, files and equipment, then check and send.
Leaver step 1: the person leaving, their site, last working day, and a green box saying when the account closes
Leaver, step 1. Example data.

How do I get someone access to an app?

  1. On Raise a request, click Access to an app.
  2. Pick the person.
  3. Tick every app they need. Each app says whether CMS sets it up, or whether we pass it on to the app's owner.
  4. Say what they need to be able to do, then check and send.
Access to an app: the person, and a list of apps to tick
Tick all the apps they need. Example data.

How do I track my requests?

Everything you've asked for is listed under Your requests, newest first, at the bottom of Raise a request. Each one shows its status:

Awaiting approval
Waiting for someone at your company to approve it. You can still withdraw it.
In progress
Approved and being worked on.
Blocked
We need an answer from you. See the next section.
Actioned
Done.
Rejected
The approver said no. Open it to see their note.

Tidy list. Tick Hide completed to see only the requests that are still open.

Your requests: a list of starter, leaver, app access and remote access requests with status labels and Track buttons
Your requests. Example data.

See progress and talk to us

  1. Click Track on a request.
  2. The steps on the left show where it's got to: Sent, Approved, Being set up, Done.
  3. Underneath is the conversation with the CMS team, oldest first.
  4. To add something, type in the reply box and click Send reply. Replying to our email does the same thing.
A tracked request showing progress steps, the conversation with CMS, and a reply box
Progress, conversation and reply box. Example data.

How do I answer "We need more information"?

Sometimes we need one more detail before we can carry on, such as which person is the new starter's line manager. The request shows as Blocked, and a card opens inside it. Nothing has been set up yet; it carries on as soon as you answer.

  1. Open Your requests and find the request marked Blocked.
  2. Pick the right option, or type your answer in the box.
  3. Click Send answer. You can also reply to our email instead. Either works.
A We need one detail card asking which person is the line manager, with options and a Send answer button
Answer the question and the request carries on. Example data.

How do I log a ticket?

Use a ticket when something isn't working, you need something that isn't a staff change, or you have a question.

What's happening

  1. Open Tickets and click Log a ticket at the top right.
  2. Choose the type: Something's not working, I need something or I have a question.
  3. Write a short summary. The portal may suggest a guide that fixes it straight away. If not, click None of these, keep logging my ticket.
  4. Pick a Category, then a Sub-category, then the Issue that fits best. Or search all categories, for example "printer".
  5. Tell us more: what you were doing, what happened, and any error message.
Log a ticket: summary, a suggested fix, Category and Sub-category drop-downs, and a Tell us more box
Logging a ticket. Example data.

Who, where and how bad

  1. Choose the site, and who's affected: Just me, A colleague or A whole site.
  2. Raising it for someone else? Put their work email under Raising on behalf of someone? Leave it blank if it's for you.
  3. Set the Impact and Urgency. Together they set the ticket's priority. If you're not sure, leave both blank and the service desk will set it.
  4. Add a screenshot if you have one, then send.
Impact: how many people or systems are affected?
Multiple Systems / All UsersSingle System / Multiple usersSingle System / Single UserNo Impact
Urgency: how soon does it need fixing?
HighMediumLow
Site, who's affected, raising on behalf of someone, Impact and Urgency choices, and an attachment drop zone
Who's affected, Impact and Urgency. Example data.

How do I follow up on a ticket?

  1. Open Tickets. Use the filter next to the search bar (All open, Awaiting me, On hold, In quarantine, Closed or All), or search.
  2. Click a ticket. The bar at the top shows where it's got to: Logged, In progress, Resolved.
  3. Below are the ticket's details and everything that's been said.
  4. To add information, type in the reply box and click Send reply. If it's fixed, click Mark resolved.
One ticket: a progress bar, ticket details, the activity conversation and a reply box
One ticket: progress at the top, the conversation below, reply at the bottom. Example data.

How do I approve a request?

Only for people who approve requests for their company.

From the email

  1. You get an email when a request needs you.
  2. Click the link. The page shows who it's for, the site and the stage.
  3. Click Approve or Reject. Nothing is set up until every approval is in.
The approval page: new starter approval for Jane Sample, with Approve and Reject buttons
The page you reach from the approval email. Example data.

In the portal

  1. Open Approvals to see everything waiting for you.
  2. Add a note if you like, then click Approve or Reject.

"Not actionable"? Some requests need more than one approval. This label means someone else has to approve it first.

Approvals: one request awaiting you with Approve and Reject buttons, and one marked Not actionable
Approvals in the portal. Example data.

How do I see my team?

For managers and approvers.

  1. Click Raise a request and scroll down to Your team. Everyone at your company is listed by site.
  2. Starting and leaving soon shows people from your requests. Click Track it to see where each one has got to.
  3. On a person, click Change to change their role, They're leaving to book a leaver, or Copy their access for a new starter.
Your team: Starting and leaving soon, and people grouped by site with Change and They're leaving buttons
Your team. Example data.

How do I deal with a security risk?

For managers, if your company has the Risk & Health service.

  1. Click Risk in the menu. It lists the accounts at your company that need attention: disabled accounts, people without multi-factor sign-in (MFA, worse for admins) and accounts nobody has signed in to for a while.
  2. Click a tile at the top to show only that kind of risk. Click it again to see them all.
  3. Click a person's name or Details. A panel opens showing the risk, how serious it is (Critical or Warning), its impact and likelihood with the reasons, and what we recommend you do.
  4. Click Log a ticket about this risk. The ticket form opens already filled in: the summary, the risk's details, the recommended action and a link back to the risk. Check it, change anything you like, then send it.

Tip: a disabled account is logged as something that's not working; everything else as a request. You can change the type before you send.

Who approves requests at my company?

The Approvers for your company card on Tickets shows who approves what, in three groups:

  1. Each person is listed once, with their job title, email address and the sites they cover. If they're in more than one group, an Also… label shows the others.
  2. Long groups are shortened. Click Show all to see everyone, and Show fewer to shorten the list again.
  3. If an approver is away, their note is shown next to their name.
  4. If a kind of request has no approver, the card warns you. Tell us who it should be and we'll add them.

How do I use the portal in Microsoft Teams?

Coming soon

Strata will also be available as an app inside Microsoft Teams, so you can raise requests and log tickets without leaving Teams. It will use the same sign-in. We'll add how to find and open it here once it's ready for your company.